How RFID Cards Work

How Does an RFID Card Work? The Tech Inside

Illustrated cutaway of an RFID card and reader mid-tap: the card's embedded antenna coil and rice-grain microchip borrow power from the reader's electromagnetic field and reply by load modulation, completing the whole handshake in 50-200 milliseconds with no battery anywhere on the card.

Quick answer

An RFID card runs on two parts and zero batteries: an antenna coil harvests power from the reader's field and a 1-2mm chip replies in 50-200 milliseconds. This guide slices the 0.76mm sandwich open — the laminated layers, the five-step tap handshake, why RFID beat the magnetic stripe, and which chip is hiding in which card.

  • Zero batteries, ever: the card steals its power from the reader's electromagnetic field the instant you tap — electromagnetic induction, the same trick a wireless phone charger uses.
  • The entire cast is two actors: a coil antenna laminated into the plastic and a microchip smaller than a grain of rice (1-2mm square) that stores data and processes commands.
  • The whole conversation — power up, authenticate, exchange data, power down — takes 50-200 milliseconds. Blink and you have missed the entire exchange.
Since 2008 ISO 9001 500+ Clients 50+ Countries

At a glance

Use these short answers to decide whether this page matches the project before moving into the detail.

Key takeaway

Zero batteries, ever: the card steals its power from the reader's electromagnetic field the instant you tap — electromagnetic induction, the same trick a wireless phone charger uses.

What's inside an RFID card?

Inside an RFID card there is no battery, no buttons, no blinking lights — just a hair-thin loop of wire and a fleck of silicon the size of a pepper flake. Slice a finish...

Next step

Ready to move forward? Start your inquiry to get specific answers for this project.

Order custom RFID cards

What's inside an RFID card?

Inside an RFID card there is no battery, no buttons, no blinking lights — just a hair-thin loop of wire and a fleck of silicon the size of a pepper flake. Slice a finished card in half (metaphorically, please — don't butcher your hotel key) and that is the entire inventory. The sleepy little fleck lies there doing absolutely nothing until a reader wakes it up and hands it power through thin air; it is, technically, the laziest genius you will ever meet. Here is everything laminated inside that 0.76mm plastic sandwich.

Exploded view of the four laminated layers of an RFID card: a printed top layer with logos and security print, the antenna coil and microchip inlay that does all the thinking, a structural PVC or PETG core, and a printed bottom layer — fused under heat and pressure into a standard CR80 card, 85.6 x 54mm and 0.76mm thick.

A passive RFID card is basically a wind-up toy — except someone else winds it up for you, from a few centimeters away, using invisible radio waves. It stores no power and holds no opinions until it is summoned.

  • Antenna coil — a flat loop of thin copper or aluminum wire laminated between PVC card layers, working two jobs with no lunch break: it captures electromagnetic energy from the reader to power the chip, and it flings the chip's data back to the reader by modulating the reader's field.
  • Microchip (IC) — a silicon integrated circuit typically 1-2mm square (genuinely smaller than a grain of rice), bonded to the antenna at a connection point. Packed inside: a processor, memory (ROM, EEPROM, RAM), and a radio frequency interface. It stores the card's unique identifier and any application data it has been given.
  • PVC card body — the standard CR80 card (85.6 x 54mm, 0.76mm thick) made from layers of PVC or PETG plastic. The antenna and chip inlay is laminated between inner PVC sheets, then the outer printed layers are fused on top under heat and pressure.
  • No battery. None. — the entire card is passive: no battery, no power button, no active electronics. Every joule it uses is borrowed from the reader's electromagnetic field when the card comes within range, which is exactly why these cards soldier on for years without maintenance while your phone begs for a charger by 3 p.m.
  • Printing layers — the card's outer surfaces can carry full-color artwork, logos, text, barcodes, photos and security features using offset, digital or thermal transfer printing. The chip and antenna underneath could not care less: bury them under the busiest brand guidelines marketing can produce and the RFID functionality inside is unaffected.

How the card communicates with the reader

A tap is a five-step handshake — power up, prove identity, swap data, power down — finished in 50-200 milliseconds, before your hand has completed the gesture. On its own the chip is inert: no power, nothing to say, no opinions worth having. Bring it into a reader's field and the whole conversation plays out below, stretched from milliseconds to human speed.

Five-step flow of the RFID tap handshake: the reader energizes its electromagnetic field, the card wakes by induction, the reader sends commands, the card replies by load modulation, and the transaction completes with the chip back asleep — the full round trip taking 50-200 milliseconds.

Nerd corner: a passive card never actually "transmits." It has no transmitter and no power to run one. Load modulation means it replies by tightening and loosening its grip on the reader's own field — the electromagnetic equivalent of answering questions by squeezing someone's hand harder and softer. The reader does all the shouting; the card just changes how heavily it leans.

  • Step 1: Reader energizes. The card reader generates an alternating electromagnetic field at the card's operating frequency (13.56 MHz for most smart cards, 125 kHz for legacy access cards). This field extends a few centimeters from the reader surface — precisely why you have to actually tap, and can't open doors from the car park.
  • Step 2: Card powers up. When the card enters the reader's field, the antenna coil captures electromagnetic energy through induction (the very same trick a wireless phone charger uses). The energy is rectified into DC power and the chip flickers to life on entirely borrowed electricity.
  • Step 3: Reader sends commands. The reader modulates its field to transmit commands: request the card's UID, authenticate the card, or read data from specific memory sectors. The card, having just woken up with no memory of the last conversation, complies.
  • Step 4: Card responds. Here's the clever bit — the chip can't transmit, it has no power to spare. So it sends its response by modulating the load on the reader's field (called load modulation), subtly changing how much energy it draws. The reader detects these tiny variations and decodes the card's data. Morse code performed entirely by flinching.
  • Step 5: Transaction completes. The entire exchange (power, authenticate, read/write data) takes 50-200 milliseconds. When the card moves away from the reader's field, the chip powers down and retains its data in non-volatile memory until the next interaction.

Why do RFID cards beat magnetic stripe and barcode?

RFID cards replaced magnetic stripes in hotels, transit and access control for five concrete, unglamorous reasons that show up in everyday operation, not just the spec sheet. The stripe never lost on charisma; it lost on wear, weather, cloning, capacity and throughput — all five at once.

Durability comparison chart: a magnetic stripe wears out after 200-500 swipes, drawn as a stubby red bar, while an RFID antenna endures 100,000+ read cycles, drawn as a full-width teal bar — with pills below noting RFID reads through wallets, gloves and water, uses rotating cryptography, holds many applications on one card, and reads 50-200 cards per second at gates.

A magstripe is a static playback device. Modern RFID is a live cryptographic conversation.

  • Contactless reads — no physical contact between card and reader means no wear on either side, no friction, nothing to grind down. Magnetic stripes wear out in 200-500 swipes; an RFID card's antenna shrugs off 100,000+ read cycles with no mechanical degradation whatsoever.
  • Tolerance to dirt and weather — rain, dust and lint on a magstripe head causes immediate read failures. RFID reads straight through plastic wallets, leather, gloves and a few millimeters of water without dropping signal.
  • Active anti-cloning — a magstripe is copied once and owned forever. NTAG 424 DNA and DESFire EV3 sign every read with rotating cryptographic challenges that magnetic stripes simply cannot match. Photograph versus live interrogation.
  • Multi-application capability — one DESFire card can hold separate applications for room access, employee ID and cashless payment in walled-off memory zones. Magstripe forces one application per track, three tracks max — and that's the whole menu.
  • Bulk read at gates — RAIN UHF cards (used at toll booths and stadium entries) read 50-200 cards per second from 3-5 m. Magstripe and barcode demand single-file scanning and never approach this throughput.

Frequency families and chip selection — 125 kHz, 13.56 MHz HF, 860-960 MHz UHF

RFID operates in three frequency bands, and each trades range, security, smartphone-compatibility and cost differently. It is less one technology than a family of them, bickering across the radio spectrum. Choose the wrong band and you are locked into a multi-year deployment that can't reach the use case you actually needed.

Frequency spectrum with three personality panels: 125 kHz LF legacy cards read at 5-15 cm, cost $0.05-$0.15 per chip, no phone taps and clone trivially; 13.56 MHz HF is the default smart-card band every phone taps, home to NTAG, MIFARE, and DESFire; 860-960 MHz UHF RAIN cards read from 3-12 m with chips around a penny, phone-readable only via sled.

A friendly heads-up: if a vendor quotes you MIFARE Classic 1K for anything security-sensitive in 2026, raise an eyebrow. Its encryption has been crackable with roughly $20 of hardware for over fifteen years. A fine choice for a gym locker; a terrible one for your building's front door.

  • 125 kHz LF (low frequency) — the grandpa band: legacy proximity cards (HID Prox, EM4100, EM4200, T5577). Range 5-15 cm via card readers. Cheapest chip ($0.05-$0.15) but no encryption — every commodity NFC writer can clone the card UID. Still deployed for door-only access at low-security facilities; fine for a stockroom door, a genuinely bad idea for anything worth protecting.
  • 13.56 MHz HF (high frequency, ISO 14443 / ISO 15693) — the main event and the dominant smart-card frequency. NFC chips like NTAG 213/215/216 ($0.05-$0.15), MIFARE Classic 1K ($0.10-$0.18), MIFARE Ultralight C ($0.07-$0.12), MIFARE DESFire EV2/EV3 ($0.65-$1.40), MIFARE Plus EV2 SL3 ($0.45-$0.85) and NTAG 424 DNA ($0.18-$0.30) all live here. Smartphone tap support is universal on iPhone (iOS 13+) and Android (5.0+).
  • 860-960 MHz UHF (RAIN RFID, ISO 18000-63) — long-range cards (3-12 m) for parking, vehicle access, sports timing and large-venue badges. Chips like NXP UCODE 9 ($0.012-$0.018 wafer) and Impinj M730/M770 ($0.014-$0.020) make per-card cost extremely low. Smartphone-readable only with external UHF sled.
  • Dual-frequency cards (HF + UHF combo) — why choose? These combine NFC tap-to-verify with UHF gate-throughput in a single piece of plastic. Premium $0.50-$1.50 per unit. Used at large stadiums and transit systems where the same card must work as a smartphone wallet AND a long-range gate badge.
  • Smart-card chip security tiers — MIFARE Classic 1K is broken (Crypto-1 cipher publicly attacked since 2008); only use it where security doesn't matter. MIFARE DESFire EV3 and Plus EV2 use AES-128 with EAL5+ Common Criteria certification — the secure floor for hotel access, payment, transit and corporate badges. NTAG 424 DNA brings DESFire-grade AES-128 SUN authentication into the consumer NFC tier.

Real card families and where they're deployed in 2026

Knowing the chip family on your card tells you 80% of what you need about security, smartphone compatibility and cloning risk — and where a family lives says a lot about how much its owners trust it. The reference deployments below give procurement teams concrete benchmarks for sourcing decisions, arranged here as a ladder of trust.

Rising trust ladder of card chips in four steps: MIFARE Classic 1K at the bottom, broken Crypto-1 cloneable with about $20 of hardware; MIFARE Ultralight C with 3DES as a cheap step up; MIFARE DESFire EV3 and NTAG 424 DNA with AES-128 and EAL5+ running hotels, transit and badges; and EMV secure elements at bank grade on top.

The higher the rung, the more it costs a would-be cloner. The floor is "photocopy me for $20 of hardware"; the ceiling is the same silicon your bank trusts with your money.

  • Hotel key cards — globally dominated by MIFARE Classic 1K (legacy) and MIFARE DESFire EV2/EV3 (modern installs). Marriott Bonvoy, Hilton Honors, IHG and Accor all moved to DESFire EV2/EV3 since 2020 because of the 2008+ MIFARE Classic Crypto-1 break. ASSA ABLOY VingCard, dormakaba Saflok, Salto and Onity are the lock vendors.
  • Transit and metro — Octopus (Hong Kong, Sony FeliCa), Suica (Tokyo, FeliCa), Oyster (London, MIFARE DESFire), MetroCard (NYC, magstripe being replaced by OMNY DESFire EV3), Compass (Vancouver, DESFire). Most new transit deployments since 2020 use DESFire EV2/EV3 for AES-128 anti-cloning.
  • Corporate and government ID — HID iCLASS Seos, MIFARE DESFire EV3, US Federal PIV (FIPS 201, Java Card OS) and German neuer Personalausweis (eID, Mifare Plus). Global Fortune 500 standardising on HID Seos + Apple Wallet / Google Wallet for hybrid plastic + mobile.
  • Cashless payment — EMV contactless on Visa, Mastercard, Discover and Amex uses NXP-derived secure elements; banking-grade EAL5+ certification. Apple Pay and Google Wallet store the same EMV credentials in the phone Secure Element via tokenised PAN.
  • Loyalty and brand — NTAG 213/215/216 dominate single-tap loyalty; NTAG 424 DNA for anti-counterfeit luxury (Estée Lauder, Hennessy, LVMH Aura). Chip selection drives the SUN or static-UID dichotomy that decides whether the card is clone-proof or trivially cloned at $20 of hardware.

Useful next pages

Use these linked product, guide and comparison pages to keep the next click specific and practical.

FAQ

How long do RFID cards last?

Surprisingly long — the microchip can endure over 100,000 read/write cycles, because there is no battery and no moving parts to fail. The PVC card body is the real weak link, typically lasting 3-5 years under normal use: daily tapping, wallet cohabitation and temperature swings. Treat one gently and it will happily function for 10+ years.

Can RFID cards be hacked or cloned?

It depends entirely on the chip type. Older chips like MIFARE Classic 1K use proprietary encryption that has been publicly broken, making them cloneable with cheap, specialized equipment. Modern chips like MIFARE DESFire EV3 use AES-128 encryption that is considered secure against cloning with current technology. For security-sensitive applications, always specify a chip with current-generation encryption — and don't let price talk you down a rung.

Do RFID cards stop working near magnets or phones?

No — and this is the big upgrade over magstripe. RFID cards are not affected by magnets, phone proximity, or static electricity, because the chip stores data electronically in non-volatile memory, not magnetically on a stripe. This is why hotels are migrating from magstripe to RFID key cards: RFID cards do not demagnetize from phone contact, which is the number one complaint about traditional hotel key cards.

Why do iPhone and Android phones read some RFID cards but not others?

Because a phone's NFC controller only speaks 13.56 MHz HF — the ISO 14443 / ISO 15693 / FeliCa stack. It physically cannot read 125 kHz LF proximity cards or 860-960 MHz UHF cards. So an iCLASS Seos badge, a MIFARE DESFire EV3 hotel key or an NTAG 213 NFC tag all read fine on a phone; an HID Prox 125 kHz access card or a Walmart UHF apparel tag does not. iPhones since iOS 13 (2019) support full NFC tag reading; Android has supported it since 5.0 (2014). For LF or UHF cards, you need a USB sled or BLE handheld reader.

Are NTAG 215, MIFARE Ultralight C, MIFARE Classic 1K and DESFire EV3 interchangeable for the same use case?

No — they sit at very different security and memory tiers. NTAG 215 (504 bytes user memory, password protection only) is fine for tap-and-launch loyalty and product authentication where cloning isn't catastrophic. MIFARE Ultralight C (192 bytes, 3DES authentication) is a step up at low cost. MIFARE Classic 1K (1KB, broken Crypto-1 cipher) is suitable only when security doesn't matter; widely deployed historically but cloned with $20 of hardware. MIFARE DESFire EV3 (8KB+, AES-128, mutual auth) and NTAG 424 DNA (416 bytes, AES-128 SUN) are the secure floor for hotels, transit, payment and brand protection. Choose based on the data you need to store + whether cloning is a real threat in your application.

Since 2008 RFID Manufacturing
ISO 9001 Certified Factory
500+ Enterprise Clients
50+ Countries Served

Proud Tek is a Shenzhen-based RFID & NFC manufacturer supplying hotel chains, transit operators, event venues and retail brands worldwide. Every order includes free samples, RF testing and dedicated project support.

Get a Quick Quote

Tell us about your project and we'll respond within one business day. Fields marked (asterisk) are required.

We'll only use this to reply to your inquiry.
Optional, but helps us route your inquiry faster.
e.g. 5,000 pcs
e.g. hotel, event, asset tracking
Helps us quote shipping and compliance correctly
Chip preference, timeline, special requirements...

Next step

Ready to discuss your project?

Use the contact route when you are ready for pricing, samples, or compatibility help, or continue into the linked product and comparison pages below.