Hotels and resorts
MIFARE Classic vs Ultralight: which key card chip do you need?
By James Keltner, Owner · Last reviewed
The short answer
MIFARE Classic 1K is a 1 KB chip protected by NXP's older Crypto1 cipher. MIFARE Ultralight EV1 is a small, economical chip with password protection but no encryption, while Ultralight C adds 3DES authentication. The right chip is the one your door locks are set up to read, so confirm it before you order.
The four chips side by side
All four chips belong to NXP's MIFARE family, run at 13.56 MHz and follow ISO/IEC 14443 Type A, the standard for contactless cards held close to a reader. They look identical once they are sealed inside a printed card. The differences are in how much data they hold and how they protect it.
MIFARE Classic 1K, Ultralight EV1, Ultralight C and DESFire EV3, from NXP datasheets
MIFARE Classic 1K (EV1)
- Memory
- 1 KB, in 16 sectors of 4 blocks of 16 bytes
- Protection
- Crypto1, NXP's proprietary cipher, with two keys per sector
- Typical use
- The long-standing hotel standard; room access plus extras such as lifts or the spa
MIFARE Ultralight EV1
- Memory
- 48 or 128 bytes of user memory, depending on version
- Protection
- 32-bit password protection; no encryption
- Typical use
- Economical single-stay keys and tickets
MIFARE Ultralight C
- Memory
- 144 bytes of user memory (1,536 bits in total)
- Protection
- 3DES authentication
- Typical use
- Ultralight with added encryption; used on many newer lock systems
MIFARE DESFire EV3
- Memory
- 2, 4, 8 or 16 KB
- Protection
- AES with 128-bit keys, plus DES and 3DES
- Typical use
- Higher-security access control and some premium lock systems
| Chip | Memory | Protection | Typical use |
|---|---|---|---|
| MIFARE Classic 1K (EV1) | 1 KB, in 16 sectors of 4 blocks of 16 bytes | Crypto1, NXP's proprietary cipher, with two keys per sector | The long-standing hotel standard; room access plus extras such as lifts or the spa |
| MIFARE Ultralight EV1 | 48 or 128 bytes of user memory, depending on version | 32-bit password protection; no encryption | Economical single-stay keys and tickets |
| MIFARE Ultralight C | 144 bytes of user memory (1,536 bits in total) | 3DES authentication | Ultralight with added encryption; used on many newer lock systems |
| MIFARE DESFire EV3 | 2, 4, 8 or 16 KB | AES with 128-bit keys, plus DES and 3DES | Higher-security access control and some premium lock systems |
Two related chips also turn up in hotels. MIFARE Mini is a smaller-memory version of Classic used by some older systems, and MIFARE Classic 4K has four times the memory of 1K, for properties that also run cashless payments or loyalty on the card.
What the differences mean at a hotel
A room key does not need much memory. The encoder at the front desk writes the room, the stay dates and any extra areas the guest may use, and that fits comfortably on an Ultralight chip. Memory matters more when the card does several jobs at once.
- Room only, single stay: an Ultralight-family chip holds what the lock needs and is the most economical choice where your locks read it.
- Room plus lifts, spa, pool gates or parking: the sectors on a Classic 1K or 4K card, or the files on a DESFire card, let one card carry separate data for each area.
- Cashless spending or loyalty on the same card: larger-memory chips such as Classic 4K or DESFire give each application its own space.
Memory size is rarely the deciding factor, though. A lock reads the chip it was designed and configured for, and a card with a different chip will not open the door however much memory it has. That is why we confirm the chip before quoting, and why chip choice also affects what your key cards cost.
Security, in plain terms
Older chips such as MIFARE Classic have known, published weaknesses; newer chips such as Ultralight C and DESFire use stronger encryption. Which chip your locks need is set by your lock system, so ask your lock vendor before changing.
In more detail, the four chips sit at different points on the security scale:
- MIFARE Classic uses Crypto1, NXP's older proprietary cipher. NXP now offers AES-based chips, such as MIFARE Plus, as an upgrade path for Crypto1 installations.
- MIFARE Ultralight EV1 has no encryption. It relies on a 32-bit password to stop unintended changes to its memory.
- MIFARE Ultralight C adds 3DES authentication, so the card and reader prove to each other that they share a key before data is trusted.
- MIFARE DESFire EV3 uses AES with 128-bit keys, an open, widely reviewed standard, and supports several applications with separate keys.
A stronger chip only helps if the lock and encoder are set up to use its security features. Changing the chip on your cards without changing the lock configuration either does nothing or stops the cards working. Security upgrades are therefore a decision for your lock vendor and your lock settings, not for the card alone.
Hotel key cards are generally encoded with access data such as the room and the stay dates. They are not used to hold payment card details.
Which chip do your cards use?
A printed card gives no clue about the chip inside, so the quickest answer usually comes from the card itself or from your lock vendor.
Send us a card you use today
Post us a working key card and we read the chip type directly. We return it if you need it.
Or send a photo of the lock and encoder
The make is usually on the lock face and the model is on a label on the card encoder at the front desk. A photo of both is usually enough for us to identify the system.
Check with your lock vendor before any change
If you are changing locks, updating lock software or thinking about a more secure chip, your lock vendor can confirm which chips the new setup reads.
Try test cards on your own doors
We send blank test cards with the chip we propose. Encode them on your own system and try them on your doors, lifts and pool gates before anything is printed.
Our lock compatibility guide explains how chips are matched to lock systems. Once the chip is confirmed, it can go into any of our cards, from standard RFID hotel key cards and NFC and MIFARE smart cards to wooden and paper key cards. For the full hotel range, see key cards for hotels and resorts.
MIFARE, MIFARE Classic, MIFARE Ultralight, MIFARE DESFire and NTAG are trademarks of NXP B.V. Band and Key is not affiliated with NXP.
Questions buyers ask
Can we switch our cards from MIFARE Classic to Ultralight C or DESFire?
Only if your locks and encoder are set up to read the new chip. The card has to match the lock configuration, so ask your lock vendor first. If they confirm the change, we send test cards with the new chip to try on your doors before you order.
Is MIFARE Ultralight the same as an NFC tag?
They are closely related. Both run at 13.56 MHz under ISO/IEC 14443 Type A, and many phones can read Ultralight chips. Hotel locks, however, read the data your encoder writes, so a key card is matched to the lock rather than to phones.
Why do some cards stop working after a lock or software update?
An update can change which chip, or which chip settings, the locks accept. Cards with the old chip then fail at the door even though they look fine. Our guide to why hotel key cards stop working covers this and the other common causes.
