What Is RFID? Proximity Authentication at a Glance

A beginner-friendly look at how RFID cards work for physical access, how they communicate, and where they fall short on security.

8 min read

The Basics

RFID stands for Radio-Frequency Identification. It’s the technology inside the badges you tap against a reader to open a door — or the stickers on retail merchandise that trigger alarms.

An RFID system has two pieces:

  1. Tag — a tiny chip + antenna embedded in a card, fob, or sticker. It stores a small amount of data (typically a serial number or ID).
  2. Reader — a device that emits radio waves, powers the tag when it’s nearby, and reads the data the tag sends back.

How It Works

sequenceDiagram
    participant Tag as RFID Tag<br/>(badge / fob)
    participant Reader as RFID Reader
    participant DB as Access Control<br/>Database

    Reader->>Reader: Emit RF field (13.56 MHz)
    Tag->>Tag: Enter field → harvest energy
    Tag->>Reader: Transmit stored ID (in the clear)
    Reader->>DB: Lookup ID + permissions
    DB->>Reader: Access granted / denied
    Reader->>Tag: Unlock door (or beep)

The reader continuously emits a low-power radio signal. When a tag enters the field, it harvests that energy (passive tags have no battery) and uses it to transmit its stored ID back to the reader. The reader checks the ID against its database and decides whether to unlock the door.

RFID Frequency Bands

graph LR
    classDef lf fill:#fef2f2,stroke:#ef4444,stroke-width:1px,color:#1d1d1f
    classDef hf fill:#e8f0fe,stroke:#0071e3,stroke-width:1px,color:#1d1d1f
    classDef uhf fill:#f0edff,stroke:#5856d6,stroke-width:1px,color:#1d1d1f

    LF["LF<br/>125-134 kHz<br/>~10 cm<br/>Animal ID, older access"]:::lf
    HF["HF<br/>13.56 MHz<br/>~10 cm<br/>Payments, MIFARE, NFC"]:::hf
    UHF["UHF<br/>860-960 MHz<br/>1-12 m<br/>Inventory, warehouse"]:::uhf
BandFrequencyRead RangeStandardCommon Use
LF125-134 kHz~10 cmISO 11784/11785Animal tracking, legacy access badges
HF13.56 MHz~10 cmISO/IEC 14443Contactless payments, MIFARE, NFC
UHF860-960 MHz1-12 mISO 18000-63Inventory, supply chain

Most office access badges use HF (13.56 MHz) — the same frequency as tap-to-pay credit cards and NFC.

Why It Matters for Security

Basic RFID is convenient but has real vulnerabilities:

graph LR
    classDef attack fill:#fef2f2,stroke:#ef4444,stroke-width:1px,color:#1d1d1f
    classDef def fill:#e8f0fe,stroke:#0071e3,stroke-width:1px,color:#1d1d1f

    Eavesdrop["Eavesdropping<br/>Tag ID sent in the clear"]:::attack --> Clone["Cloning<br/>Copy ID to blank tag"]:::attack
    Relay["Relay Attack<br/>Extend range via radio relay"]:::attack --> Bypass["Bypass door lock remotely"]:::attack

    Crypto["Cryptographic Card<br/>(PKI / PIV)"]:::def --> Prevent["Challenge-response<br/>key never leaves card"]:::def
  • Eavesdropping — The tag’s ID is sent in the clear. A cheap Proxmark3 can read or clone many badges from several feet away.
  • Cloning — Older 125 kHz badges (like HID Prox) transmit a fixed, unchanging ID that’s trivially copied to a T5577 blank.
  • Relay attacks — Two radios can extend the range of a badge so an attacker unlocks a door while the real badge is in the owner’s pocket — demonstrated over 1,960 km with HID Seos.
  • Downgrade attacks — Secure iCLASS credentials can be downgraded to legacy Prox format and cloned (Proxmark3 research).

Where RFID Meets Stronger Security

Because of these issues, organisations layer RFID with other controls:

  • RFID + PIN — Something you have (the card) plus something you know (the PIN).
  • Contactless smart cards (PKI/PIV cards) — The card doesn’t just broadcast an ID; it performs cryptographic operations. Prevents cloning and eavesdropping.
  • Multi-factor readers — Readers that require both a valid card and a PIN or biometric — common in data centres and government facilities.

RFID is the foundation, but for serious security (data centres, government buildings) you want the cryptographic guarantees that PKI cards provide.


RFID makes proximity access frictionless, but not all RFID is equal. Understanding the difference between a simple ID broadcast and cryptographic authentication is the first step to building a mature physical security program.

References