What is the LEAF credential standard?
LEAF is an open credential standard for physical access control — described by its community as "a secure, open and interoperable data structure" that lives on standard AES-secured 13.56 MHz smart cards. Rather than a proprietary format tied to one manufacturer's readers, LEAF defines how a credential is structured so that any LEAF-compatible device can read it.
The point of LEAF is to decouple the credential from any single vendor's hardware. A building can issue a LEAF credential and have confidence it will work across the readers of multiple manufacturers that support the standard, while the credential itself stays encrypted and keyed. LEAF is promoted through the LEAF community at leaf-community.com.
Who governs LEAF, and is it really open?
LEAF is governed as a multi-vendor community rather than a single company's product, which is what its "open" claim rests on. It was founded by IDEMIA, RF IDEAS and WaveLynx, and its membership spans a wide set of access-control and silicon vendors across tiered roles.
| Community tier | Example members |
|---|---|
| Founding | IDEMIA, RF IDEAS, WaveLynx |
| Visionary | Dormakaba, LEGIC, Farpointe Data, TANlock, Any2Any |
| Innovator | Allegion, ASSA ABLOY, Hanwha, Hirsch, IDEX Biometrics, ACRE Security |
What credential tiers does LEAF define?
LEAF defines more than one security tier so buyers can match assurance to need. The base tier, LEAF Universal, uses 128-bit AES on an AES-secured 13.56 MHz smart card whose current generation is certified to Common Criteria EAL5+. LEAF describes "encrypted authentication with guaranteed unique badge IDs," following NIST key-management guidance for diversified keys.
The higher tier, LEAF Verified, replaces symmetric keys with elliptic-curve public-key cryptography on the NIST P-256 curve, using ECDSA and ECDH with an X.509 public-key infrastructure and certification to Common Criteria EAL6+ — described as having "zero symmetric keys." A buyer choosing between them is choosing between a symmetric-AES credential and a public-key credential, at different certification levels.
How does LEAF interoperability help a buyer?
LEAF's interoperability is meant to reduce vendor lock-in. Because a LEAF credential is an open data structure, LEAF community materials state that Universal credentials "work out of the box with any LEAF-compatible device," and that the standard "eliminates reliance on proprietary systems" and is "not driven by a single manufacturer's agenda."
For a building operator, that means a credential decision is not permanently tied to one reader brand: readers from different LEAF members can read the same credential, and a site can mix or change hardware vendors without re-badging everyone. This openness is about the ecosystem, not about weakening security — a LEAF card is still an encrypted smart card that authenticates before releasing data.
Is a LEAF card clone-resistant?
A LEAF card is clone-resistant because it is an encrypted smart card, not a readable proximity token. A base LEAF Universal credential authenticates with 128-bit AES on an EAL5+ smart card and releases its identity only after that exchange, so it cannot be copied by reading a serial number the way a 125 kHz proximity card can.
LEAF Verified goes further by removing shared symmetric secrets entirely, using ECC P-256 public-key cryptography at EAL6+. Openness and clone-resistance are not in tension here: LEAF is open in governance and interoperability, while remaining cryptographically protected at the credential level.
Can I buy a compatible LEAF card?
Not for the secure LEAF credential. A LEAF card — Universal or Verified — is an encrypted, keyed credential provisioned through a LEAF member such as WaveLynx and your integrator, so no third party can produce a working compatible version, and Security ID Systems does not offer one. Additional LEAF credentials come from the LEAF member managing your keys.
What we can supply is the 125 kHz proximity layer a LEAF-adopting site runs during migration — the prox sidecar on a combo card and the general HID, Indala, and AWID prox formats a mixed site carries. Those open low-frequency formats we encode as fully compatible credentials.
The 125 kHz layer we can supply during migration
While a site adopting LEAF still runs a 125 kHz prox layer alongside its encrypted credentials, these open formats are ones we encode as fully compatible credentials.
Sources & references
- LEAF Community — framework (open, interoperable data structure)
- LEAF Community — members roster (founding, visionary, innovator tiers)
- LEAF Community — LEAF Verified (ECC P-256, X.509 PKI, EAL6+)
- LEAF Community — FAQs
- WaveLynx — smart / LEAF credentials
- CIE Group — LEAF wallet credentials (open-standard rationale)
WaveLynx Technologies and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.