What is a WaveLynx LEAF card?
WaveLynx Technologies is an access-control reader manufacturer and a founder of the LEAF standard, and a WaveLynx LEAF card is an AES-secured 13.56 MHz smart card carrying the LEAF credential data structure. LEAF is described by its community as "a secure, open and interoperable data structure" that lives on standard 13.56 MHz smart-card silicon.
WaveLynx reads these credentials with its Ethos and APEX reader lines, and the same LEAF credential is designed to work across any LEAF-compatible reader, not just WaveLynx hardware. Unlike a proprietary single-vendor credential, a LEAF card is meant to be portable across an ecosystem of manufacturers while remaining encrypted.
How secure is a WaveLynx LEAF card?
A base WaveLynx LEAF card, sometimes called LEAF Universal, uses 128-bit AES on an AES-secured 13.56 MHz smart card whose current generation is certified to Common Criteria EAL5+. The credential releases its identity only after an AES exchange, and LEAF describes "encrypted authentication with guaranteed unique badge IDs," with key diversification managed through its LEAF Enterprise services following NIST key-management guidance.
Because the identity is never broadcast in the clear, a WaveLynx LEAF card cannot be cloned by copying a serial number the way a 125 kHz proximity card can. For most deployments that AES tier is the security model; sites needing the highest assurance step up to LEAF Verified.
What is LEAF Verified, and how is it different?
LEAF Verified is the public-key tier of the LEAF standard. Instead of symmetric AES keys, LEAF Verified uses elliptic-curve cryptography on the NIST P-256 curve, with ECDSA and ECDH and an X.509 public-key infrastructure, and it is certified to Common Criteria EAL6+. WaveLynx describes it as having "zero symmetric keys," meaning there is no shared secret to distribute or compromise.
The distinction matters for spec-conscious buyers. A base LEAF card is AES-128 on an EAL5+ smart card; LEAF Verified is ECC P-256 on an EAL6+ secure element. They are different chips and different certification levels — do not assume one card gives you the other. LEAF Verified is read by WaveLynx APEX readers.
| Attribute | LEAF (base / Universal) | LEAF Verified |
|---|---|---|
| Cryptography | 128-bit AES (symmetric) | ECC P-256 (public-key, ECDSA/ECDH) |
| Key model | Diversified symmetric keys | X.509 PKI, zero symmetric keys |
| Certification | Common Criteria EAL5+ | Common Criteria EAL6+ |
| Reader | Ethos and APEX | APEX |
| Third-party compatible card? | No — via WaveLynx | No — via WaveLynx |
Why is LEAF called an open standard?
LEAF is governed as an open, multi-vendor standard rather than a single company's proprietary format. It was founded by IDEMIA, RF IDEAS and WaveLynx, and its community materials state that it "eliminates reliance on proprietary systems" and is "not driven by a single manufacturer's agenda," with LEAF Universal credentials designed to "work out of the box with any LEAF-compatible device."
For a buyer, openness means interoperability and reduced lock-in: a LEAF credential is not tied to one reader brand, and multiple manufacturers can issue and read it. It does not mean the credential is copyable — a LEAF card is still an encrypted smart card that authenticates before releasing data. Openness is about the ecosystem, not about weakening the crypto.
How do WaveLynx readers handle a migration from prox?
WaveLynx Ethos and APEX readers are multi-technology, so they read legacy 125 kHz proximity, AES-secured 13.56 MHz smart cards, and mobile credentials. WaveLynx describes APEX as reading "past and present credential formats" simultaneously for a phased transition, which lets a site keep old prox cards working while it issues LEAF credentials.
During that phase, WaveLynx credentials are often supplied as combo cards that pair the AES-secured LEAF smart card with a 125 kHz proximity layer, commonly an HID Prox sidecar. The proximity half keeps older readers functioning until every holder carries a LEAF card, at which point the site can retire 125 kHz acceptance.
Can I buy a compatible WaveLynx LEAF card?
Not for the secure LEAF credential. A WaveLynx LEAF card — base AES or LEAF Verified — is an encrypted, keyed credential provisioned within the LEAF and WaveLynx ecosystem, so no third party can produce a working compatible version, and Security ID Systems does not offer one. Additional LEAF credentials come from WaveLynx or your integrator.
What we can supply is the 125 kHz proximity layer a WaveLynx site runs during migration — the HID Prox sidecar on a combo card and the general HID, Indala, and AWID prox formats a mixed site carries. Those open low-frequency formats we encode as fully compatible credentials.
The 125 kHz layer we can supply during migration
While a WaveLynx site still runs a 125 kHz prox sidecar alongside its LEAF credentials, these open formats are ones we encode as fully compatible credentials that read on your existing readers.
Sources & references
- LEAF Community — framework (open, interoperable data structure)
- LEAF Community — LEAF Verified (ECC P-256, X.509 PKI, EAL6+, zero symmetric keys)
- WaveLynx — smart / LEAF credentials
- WaveLynx — Ethos readers (multi-technology)
- WaveLynx — APEX reader and LEAF Verified
- CIE Group — LEAF wallet credentials (open-standard rationale, Joe Page, WaveLynx)
WaveLynx Technologies and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.