AES-secured 13.56 MHz fare card

Transit Agency Smart Fare Cards Explained (AES, Agency-Keyed)

A transit smart fare card is an AES-secured 13.56 MHz contactless smart card (ISO/IEC 14443) whose value and rights are protected by AES keys held privately by the transit agency. These cards come in memory tiers commonly labelled D23 (2K), D43 (4K), and D83 (8K). Because the keys belong to the agency's fare system, a working fare card is issued by the transit authority, not cloned or bought pre-loaded from a third party.

Last updated 2026-07-29

What is a transit smart fare card?

A transit smart fare card is a contactless AES-secured 13.56 MHz smart card used to pay fares and carry ride entitlements on a public-transport network. It operates over the ISO/IEC 14443 standard, the same high-frequency air interface used by modern access-control cards, and it is tapped against a faregate or on-board validator.

What makes a fare card a fare card is not the plastic but the agency's data model and keys written onto it. The card stores products — a stored-value balance, a monthly pass, a transfer — in memory sectors protected by AES cryptography. That is why a regional transit smart card (marketed under names like EZfare or MyRide, depending on the agency) is a secure token rather than a simple readable ID: the value it represents is cryptographically protected against tampering and copying.

What do D23, D43 and D83 mean?

D23, D43, and D83 refer to the card's on-chip memory size, not its security level — all three use the same AES cryptography. The number after the D roughly tracks the memory: 2K, 4K, and 8K respectively. An agency chooses a size based on how many fare products and applications the card must hold, so a simple single-agency fare card needs less memory than a regional card that also carries parking or identity functions.

Fare cardMemoryTypical role
D232KSingle-agency fare only
D434KFare plus a second application (parking, ID)
D838KRegional multi-agency / multi-application

Can a transit fare card be cloned or bought aftermarket?

No — a valid transit fare card cannot be cloned or bought pre-loaded from a third party, because its fare data is protected by AES keys that only the transit agency's system holds. Cloning would require reproducing a per-card diversified key that is never transmitted in the clear, and any card not written with the agency's keys is simply an unrecognised blank at the faregate.

This is a deliberate anti-fraud design. Early contactless fare cards that relied on weaker or broken ciphers were, in fact, defeated — which is exactly why agencies moved to AES-secured smart cards with mutual authentication and diversified keys. The practical upshot for a rider is that replacement fare cards come from the transit authority or its official outlets, and are then loaded and keyed by the agency's fare system.

Where do replacement fare-card blanks come from?

Blank AES-secured smart cards can be manufactured and supplied, but they become fare cards only when the transit agency encodes them with its keys and fare applications. Security ID Systems does not supply agency-keyed fare cards, and no legitimate third party can, because the keys never leave the agency's fare system.

Where we can help is the open, non-fare credential layer around a transit operation — 125 kHz proximity for staff doors and depots, and card-serial-number or generic Wiegand credentials for facility access that reads a plain identifier. Those formats we supply as fully compatible, encoded credentials that read identically on your existing readers, separate from the agency-keyed fare product.

Compatible formats we do supply

Agency-keyed fare cards are issued and loaded by the transit authority and cannot be sourced from a third party. For the open staff-access and facility credentials around a transit operation, these formats are ones we supply as fully compatible cards.

Sources & references

Transit agencies and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Transit fare cards — common questions

What is a transit smart fare card?

It is an AES-secured 13.56 MHz contactless smart card (ISO/IEC 14443) used to pay fares and carry ride entitlements. Fare products such as stored value or a monthly pass are stored in memory sectors protected by AES cryptography, and the card is tapped at faregates and validators.

What do D23, D43 and D83 mean on a fare card?

They indicate the card's on-chip memory — roughly 2K, 4K, and 8K respectively — not its security level. All three use the same AES cryptography; an agency picks the size based on how many fare products and applications the card must hold.

Can a transit fare card be cloned?

No. Fare data is protected by AES keys held only by the agency's fare system, with per-card diversified keys that are never transmitted in the clear. A card not written with those keys is an unrecognised blank at the faregate, so a working fare card cannot be copied.

Can I buy a replacement transit fare card from a third party?

No. A fare card becomes valid only when the transit agency encodes it with its keys and fare applications, so replacements come from the agency or its official outlets. Third parties can supply blank smart cards, but not agency-keyed fare cards.

Do transit agencies still use insecure cards?

Many agencies moved to AES-secured smart cards specifically because earlier contactless cards using weaker ciphers were defeated. Modern fare cards use AES mutual authentication and diversified keys, making the stored value far harder to tamper with or copy.