High-security access credentials

ProDataKey PDK Red Cards Explained: Security & Compatibility

ProDataKey PDK Red is ProDataKey's high-security credential line for the pdk.io platform, using AES-secured 13.56 MHz contactless smart cards and fobs rated to Common Criteria EAL5+. PDK Red credentials use AES with mutual authentication, and PDK Red readers output OSDP so the reader-to-controller link can be encrypted as well as the card-to-reader exchange.

Last updated 2026-07-29

What is ProDataKey PDK Red?

ProDataKey PDK Red is the high-security tier of ProDataKey's access-control ecosystem, which runs on the cloud-based pdk.io platform. Where ProDataKey's entry-level credentials are inexpensive 125 kHz proximity cards, the PDK Red line is an AES-secured 13.56 MHz contactless smart credential — cards and fobs that authenticate cryptographically instead of broadcasting a fixed number. ProDataKey rates the PDK Red credential to Common Criteria EAL5+, a high independent assurance level for the secure element.

PDK Red is designed as a matched system: high-security credentials, Red readers, and the pdk.io controllers and software. That end-to-end approach is what lets ProDataKey secure both halves of the transaction — the card-to-reader exchange and the reader-to-controller wiring — rather than only the card.

What frequency and cryptography do PDK Red credentials use?

PDK Red credentials operate at 13.56 MHz over the ISO/IEC 14443A air interface and are secured with AES encryption plus mutual authentication. Mutual authentication means the card and reader each prove their identity before any data is exchanged, so a reader will not release credential data to a rogue device and a card will not answer a rogue reader. That two-way check is the mechanism that stops the copy-the-number attack which defeats 125 kHz proximity cards.

ProDataKey rates the PDK Red credential to Common Criteria EAL5+, an internationally recognised evaluation assurance level for the secure element inside the card. Combined with AES and mutual authentication, that puts PDK Red firmly in the modern high-security smart-card class rather than the legacy proximity class it is meant to replace.

What is OSDP, and why does PDK Red use it?

OSDP (Open Supervised Device Protocol) is the modern, secure standard for the wiring between a reader and the access controller behind it. PDK Red readers output OSDP, which — unlike the legacy Wiegand wiring it replaces — can be encrypted, authenticated, and supervised. That closes a gap many buyers overlook: even a perfectly secure card is undermined if the wire from the reader to the controller can be tapped and replayed, which is exactly what Wiegand allows.

By supporting OSDP, PDK Red lets a site secure the whole path — an AES, mutually-authenticated exchange from card to reader, and an encrypted OSDP link from reader to controller. Wiegand output is typically still available for backward compatibility, but OSDP is the option that carries the reader-to-controller security a high-security deployment needs.

Is a PDK Red mobile credential as secure as a card?

ProDataKey also offers a mobile credential that unlocks over Bluetooth (BLE), and ProDataKey states that the mobile communication is encrypted. For most deployments a well-implemented encrypted mobile credential is comparable in security to a high-security smart card, with the added operational benefits that a phone can be issued and revoked remotely and is less likely to be shared or left in a drawer than a card.

The practical choice between a PDK Red card and a PDK mobile credential is usually about workflow, not a security downgrade: some sites prefer the tangibility and no-app simplicity of a card, others want phone-based issuance at scale. Both sit on the secure, encrypted side of ProDataKey's ecosystem, well above the legacy 125 kHz proximity cards they replace.

How do I migrate from 125 kHz prox to PDK Red?

ProDataKey's Red Reader V2 is the migration bridge: it reads 125 kHz proximity, 13.56 MHz high-security credentials, and BLE mobile all in one unit. That means a site can install Red readers, keep its existing proximity cards working, and issue PDK Red high-security cards or mobile credentials over time — no flag day where everyone has to swap at once.

CredentialFrequencySecurityThird-party compatible?
Legacy 125 kHz proximity (PDK default)125 kHz LFFixed number, no encryptionYes — openly supplied
PDK Red high-security card13.56 MHz HFAES, mutual auth, EAL5+No — via ProDataKey / integrator
PDK mobile credentialBLEEncrypted mobileNo — via ProDataKey / integrator

Which compatible cards we supply for PDK sites

PDK Red high-security cards and PDK mobile credentials are part of ProDataKey's secured ecosystem and are sourced through ProDataKey or your integrator — Security ID Systems does not produce a compatible PDK Red smart card. Where we help is the 125 kHz proximity side, which is what many ProDataKey sites run by default and what the Red Reader V2 still reads during a migration.

If your ProDataKey system uses 125 kHz proximity cards or PDK prox fobs on some or all doors, those open formats we encode as fully compatible credentials that read identically on your existing readers. They cover the openings still on proximity while a secure PDK Red or mobile rollout finishes.

Compatible formats we do supply

PDK Red high-security cards come from ProDataKey — but the 125 kHz proximity cards and fobs most ProDataKey sites run, which the Red Reader V2 still reads during migration, are ones we encode as fully compatible credentials.

Sources & references

ProdataKey and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

ProDataKey PDK Red — common questions

What chip and frequency do PDK Red credentials use?

ProDataKey PDK Red credentials are AES-secured 13.56 MHz contactless smart cards and fobs, operating over the ISO/IEC 14443A air interface. They use AES with mutual authentication and are rated to Common Criteria EAL5+, placing them in the modern high-security smart-card class rather than the legacy 125 kHz proximity class.

Are PDK Red credentials secure or EAL5+?

Yes. ProDataKey rates the PDK Red credential to Common Criteria EAL5+, a high independent assurance level for the card's secure element, and secures the card-to-reader exchange with AES and mutual authentication. That combination means there is no fixed number to copy and a rogue reader cannot extract the credential.

Does ProDataKey support OSDP?

Yes. PDK Red readers output OSDP, the modern secure standard for reader-to-controller wiring, which can be encrypted, authenticated, and supervised — unlike legacy Wiegand. Using OSDP lets a site protect the whole path, from the AES card exchange to the reader-to-controller link. Wiegand output is typically still available for backward compatibility.

Can PDK Red readers still read my old prox cards?

Yes. ProDataKey's Red Reader V2 reads 125 kHz proximity, 13.56 MHz high-security credentials, and BLE mobile in one unit. That lets a site install Red readers, keep existing proximity cards working, and issue PDK Red or mobile credentials over time rather than swapping everyone at once.

Is a PDK Red mobile credential as secure as a card?

For most deployments, yes. ProDataKey's mobile credential unlocks over Bluetooth with encrypted communication, and a well-implemented encrypted mobile credential is comparable to a high-security smart card — with the added benefit of remote issuance and revocation. The choice is usually about workflow rather than a security downgrade.