Open-standard 13.56 MHz access credential

WaveLynx LEAF Cards Explained: Security, LEAF Verified & Options

A WaveLynx LEAF card is an AES-secured 13.56 MHz smart card that carries the open LEAF credential data structure, read by WaveLynx Ethos and APEX readers. Its base tier uses 128-bit AES on a Common Criteria EAL5+ smart card, and the higher LEAF Verified tier adds ECC P-256 public-key cryptography certified to EAL6+.

Last updated 2026-07-29

What is a WaveLynx LEAF card?

WaveLynx Technologies is an access-control reader manufacturer and a founder of the LEAF standard, and a WaveLynx LEAF card is an AES-secured 13.56 MHz smart card carrying the LEAF credential data structure. LEAF is described by its community as "a secure, open and interoperable data structure" that lives on standard 13.56 MHz smart-card silicon.

WaveLynx reads these credentials with its Ethos and APEX reader lines, and the same LEAF credential is designed to work across any LEAF-compatible reader, not just WaveLynx hardware. Unlike a proprietary single-vendor credential, a LEAF card is meant to be portable across an ecosystem of manufacturers while remaining encrypted.

How secure is a WaveLynx LEAF card?

A base WaveLynx LEAF card, sometimes called LEAF Universal, uses 128-bit AES on an AES-secured 13.56 MHz smart card whose current generation is certified to Common Criteria EAL5+. The credential releases its identity only after an AES exchange, and LEAF describes "encrypted authentication with guaranteed unique badge IDs," with key diversification managed through its LEAF Enterprise services following NIST key-management guidance.

Because the identity is never broadcast in the clear, a WaveLynx LEAF card cannot be cloned by copying a serial number the way a 125 kHz proximity card can. For most deployments that AES tier is the security model; sites needing the highest assurance step up to LEAF Verified.

What is LEAF Verified, and how is it different?

LEAF Verified is the public-key tier of the LEAF standard. Instead of symmetric AES keys, LEAF Verified uses elliptic-curve cryptography on the NIST P-256 curve, with ECDSA and ECDH and an X.509 public-key infrastructure, and it is certified to Common Criteria EAL6+. WaveLynx describes it as having "zero symmetric keys," meaning there is no shared secret to distribute or compromise.

The distinction matters for spec-conscious buyers. A base LEAF card is AES-128 on an EAL5+ smart card; LEAF Verified is ECC P-256 on an EAL6+ secure element. They are different chips and different certification levels — do not assume one card gives you the other. LEAF Verified is read by WaveLynx APEX readers.

AttributeLEAF (base / Universal)LEAF Verified
Cryptography128-bit AES (symmetric)ECC P-256 (public-key, ECDSA/ECDH)
Key modelDiversified symmetric keysX.509 PKI, zero symmetric keys
CertificationCommon Criteria EAL5+Common Criteria EAL6+
ReaderEthos and APEXAPEX
Third-party compatible card?No — via WaveLynxNo — via WaveLynx

Why is LEAF called an open standard?

LEAF is governed as an open, multi-vendor standard rather than a single company's proprietary format. It was founded by IDEMIA, RF IDEAS and WaveLynx, and its community materials state that it "eliminates reliance on proprietary systems" and is "not driven by a single manufacturer's agenda," with LEAF Universal credentials designed to "work out of the box with any LEAF-compatible device."

For a buyer, openness means interoperability and reduced lock-in: a LEAF credential is not tied to one reader brand, and multiple manufacturers can issue and read it. It does not mean the credential is copyable — a LEAF card is still an encrypted smart card that authenticates before releasing data. Openness is about the ecosystem, not about weakening the crypto.

How do WaveLynx readers handle a migration from prox?

WaveLynx Ethos and APEX readers are multi-technology, so they read legacy 125 kHz proximity, AES-secured 13.56 MHz smart cards, and mobile credentials. WaveLynx describes APEX as reading "past and present credential formats" simultaneously for a phased transition, which lets a site keep old prox cards working while it issues LEAF credentials.

During that phase, WaveLynx credentials are often supplied as combo cards that pair the AES-secured LEAF smart card with a 125 kHz proximity layer, commonly an HID Prox sidecar. The proximity half keeps older readers functioning until every holder carries a LEAF card, at which point the site can retire 125 kHz acceptance.

Can I buy a compatible WaveLynx LEAF card?

Not for the secure LEAF credential. A WaveLynx LEAF card — base AES or LEAF Verified — is an encrypted, keyed credential provisioned within the LEAF and WaveLynx ecosystem, so no third party can produce a working compatible version, and Security ID Systems does not offer one. Additional LEAF credentials come from WaveLynx or your integrator.

What we can supply is the 125 kHz proximity layer a WaveLynx site runs during migration — the HID Prox sidecar on a combo card and the general HID, Indala, and AWID prox formats a mixed site carries. Those open low-frequency formats we encode as fully compatible credentials.

The 125 kHz layer we can supply during migration

While a WaveLynx site still runs a 125 kHz prox sidecar alongside its LEAF credentials, these open formats are ones we encode as fully compatible credentials that read on your existing readers.

Sources & references

WaveLynx Technologies and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

WaveLynx LEAF credential — common questions

Is a WaveLynx LEAF card secure?

Yes. A base WaveLynx LEAF card uses 128-bit AES on an AES-secured 13.56 MHz smart card certified to Common Criteria EAL5+, releasing its identity only after an encrypted exchange. It cannot be cloned by copying a serial number, and the higher LEAF Verified tier adds ECC P-256 public-key cryptography at EAL6+.

What is the difference between LEAF and LEAF Verified?

Base LEAF (Universal) uses 128-bit symmetric AES on an EAL5+ smart card. LEAF Verified uses ECC P-256 public-key cryptography with ECDSA/ECDH and X.509 PKI on an EAL6+ secure element, with zero symmetric keys. They are different chips and certification levels, read by Ethos/APEX and APEX respectively.

Is LEAF really open, or controlled by one vendor?

LEAF is governed as an open, multi-vendor standard founded by IDEMIA, RF IDEAS and WaveLynx. Its materials state it eliminates reliance on proprietary systems and is not driven by a single manufacturer's agenda, with credentials designed to work across any LEAF-compatible reader.

Can WaveLynx readers still read my old prox cards?

Yes. WaveLynx Ethos and APEX readers are multi-technology and read legacy 125 kHz proximity, AES-secured 13.56 MHz smart cards, and mobile credentials. APEX reads past and present formats simultaneously, so a site can keep old prox cards working while it issues LEAF credentials.

Can I buy a compatible WaveLynx LEAF card?

No for the secure credential — a WaveLynx LEAF card, base or Verified, is encrypted and keyed within the LEAF and WaveLynx ecosystem and comes only through WaveLynx or your integrator. The 125 kHz prox sidecar used during migration can be supplied as a compatible card.