Smart Card Manufacturing
RFID Smart Card Manufacturer
Secure Contactless
Quick answer
Proud Tek manufactures secure RFID smart cards on AES-128 silicon — MIFARE DESFire EV3 and MIFARE Plus EV2 (both Common Criteria EAL5+ at the IC level), MIFARE Plus EV1, Java Card dual-interface and NTAG 424 DNA — with diversified per-card keys, secure in-factory personalization and 100% functional verification. 'Manufacturer' here means we own the crypto choices, the key handling and the read-test, not just the print: contactless (ISO/IEC 14443) and contact (ISO/IEC 7816) interfaces, key loading on air-gapped stations, and a documented migration path off the cryptographically broken MIFARE Classic. Below is the secure-card platform menu, the secure-issuance flow, and the certifications a procurement or security team can verify before the first order.
- High-security chip portfolio on AES-128: MIFARE DESFire EV3 and MIFARE Plus EV2 are Common Criteria EAL5+ certified at the IC level, while MIFARE Plus EV1 drops into a MIFARE Classic-compatible layout for reader-preserving migration.
- Dual-interface capability — a single chip module wired to both a contact pad (ISO/IEC 7816) and a contactless antenna (ISO/IEC 14443), typically on a Java Card platform, for transit, government ID and banking-adjacent programs alongside contactless-only DESFire and MIFARE Plus.
- Secure personalization in-factory: NXP AN10922 key diversification, application and file-access configuration, and data loading on air-gapped encoding stations — with 100% functional verification and documented key-handling procedures.
At a glance
Use these short answers to decide whether this page matches the project before moving into the detail.
What Proud Tek makes
Secure RFID smart cards on AES-128 silicon — MIFARE DESFire EV3, MIFARE Plus EV1/EV2, Java Card dual-interface and NTAG 424 DNA — personalized with diversified per-card...
How security is set
The chip fixes the ceiling: MIFARE DESFire EV3 and MIFARE Plus EV2 carry Common Criteria EAL5+ certification at the IC level, all using AES-128 with diversified keys so...
Next step
Ready to move forward? Start your inquiry to get specific answers for this project.
Discuss your smart card requirements- How keys are handled
-
Customer key material moves over encrypted channels under NDA, loads onto air-gapped encoding stations following NXP AN10922 diversification, and is deleted after production per your retention instructions; every card is authentication-handshake tested.
- Proof to pull first
-
ISO 9001:2015 production with records retained seven years, per-shipment conformity plus RoHS / REACH declarations, and buyer or third-party (TÜV, SGS, Intertek, Bureau Veritas) audit access — alongside the chip vendor's Common Criteria certificates for the silicon.
What a secure smart-card manufacturer actually ships
'Smart card manufacturer' covers everyone from a print shop laminating stock inlays to a factory that owns the cryptography — and on a security credential that gap is the whole risk. Proud Tek selects the secure IC, structures the application and keys, personalizes on air-gapped stations and read-verifies every card before it ships with its certifications attached. Most programs are migrations, so start with the two decisions that matter — the MIFARE DESFire EV3 card for new deployments, or the MIFARE Plus SE card when the reader estate has to keep working. The numbers below are the ones a security review checks first.
- Secure IC selection — we map your threat model, reader estate and offline-operation needs to a chip: MIFARE DESFire EV3 or MIFARE Plus EV2 for new AES-128 programs, MIFARE Plus EV1 for reader-preserving migration, Java Card where a dual-interface applet platform is required.
- Diversified key management — every card carries unique derived keys via NXP AN10922 diversification, not a single shared secret, so a cloned or lost card never exposes the population behind it.
- Secure personalization on the line — DESFire application directories, file structures and access conditions written to your script, keys injected on air-gapped stations, and the card locked before it leaves.
- Dual-interface construction — a single chip module bonded to both an ISO/IEC 7816 contact pad and an ISO/IEC 14443 contactless antenna, for programs that need contact-level assurance and tap convenience on one card.
- 100% functional verification — every personalized card is tested for contactless response, the authentication handshake and memory operations, with the results documented in the shipped test report.
Where a card printer stops — and where a secure manufacturer starts
A secure card program goes wrong in the gap between the datasheet and the card that ships — the blank card anyone can rewrite with a USB reader, the single shared master key, the 'AES-ready' inlay that was never actually keyed. A print shop laminates; a secure manufacturer owns the cryptography, the key handling and the read-test. When the credential controls a door or a fare, that difference decides whether it can be cloned at the doorstep — the same discipline behind our RFID access control and NFC brand authentication work.
What a card printer or trading desk hands you
- A stock card with your logo — the chip chosen for margin, sometimes a MIFARE Classic part still sold as 'secure'.
- Blank cards you key yourself, or a vague 'we can encode them' with no diversified keys and no read-back proof.
- One shared master key across the whole order — clone one card and the population is exposed.
- Keys emailed or loaded on an internet-connected PC and retained indefinitely with no disposal record.
- A datasheet for a security level the card was never actually configured to.
What Proud Tek's secure card line ships
- An engineered secure card — MIFARE DESFire EV3, MIFARE Plus EV1/EV2 or a Java Card dual-interface module matched to your threat model and reader fleet.
- Cards personalized on the line with your application structure and diversified per-card keys, then 100% authentication-handshake verified with the encoding log delivered alongside.
- NXP AN10922 key diversification, so every card carries unique derived keys and one compromised card never exposes the rest.
- Customer key material loaded on air-gapped stations under NDA and deleted after production per your retention instructions, with master-key escrow only on explicit instruction.
- Application directories, file access rights and the security level locked on a production traveler before issuance, and verified on your specified reader during sampling.
Secure issuance and key handling, step by step
The difference between a card vendor and a card manufacturer shows up in personalization. We run key management and encoding as a documented production discipline: customer key material moves over encrypted channels, loads onto air-gapped stations, and is deleted after production per your retention instructions — with escrow of master keys only on explicit customer instruction. Every personalized card is functionally verified before it ships, and we supply sample cards for reader-compatibility testing before any volume order. Prefer to start with parts in hand? Request a sample pack or read how our card encoding service fits the wider program.
- 1. Key exchange
Your key hierarchy and personalization scripts transfer over encrypted channels under NDA — never by email, never in the clear.
- 2. Scheme lock
Application structure, file access rights and the AN10922 diversification method are locked on the production traveler before any card is written.
- 3. Personalization run
Diversified keys are injected and your data written on air-gapped encoding stations in a controlled environment — key material never touches a networked system.
- 4. Verification
Every card gets a 100% functional test, including the authentication handshake and memory operations, with results recorded against the encoding lot.
- 5. Disposal & records
Key material is deleted per your retention instructions; encoding logs and QC records are retained seven years for traceability and audit.
Proof your security team can verify
Trust on a secure-card order is not a feeling; it is a stack of documents your supplier-qualification and security teams can check without us in the room. Everything below is verifiable before you commit — the certifications page lists each standard and how to confirm it with the registrar, the factory page documents the plant, and the chip vendor publishes the Common Criteria certificates for the silicon itself.
- ISO 9001:2015 quality system — certificate number and issuing registrar provided on request; production records retained seven years and retrievable by SKU or encoding lot.
- Chip-level Common Criteria certificates: MIFARE DESFire EV3 and MIFARE Plus EV2 are EAL5+ at the IC level, verifiable on the NXP datasheet and distinct from our own factory certification.
- Standards conformance: ISO/IEC 7810 card format, ISO/IEC 14443 contactless interface and ISO/IEC 7816 contact interface for dual-interface cards.
- Documented key handling: encrypted key transfer under NDA, air-gapped injection and deletion after production per your retention instructions, with an auditable production traveler per lot.
- Per-shipment documentation pack: commercial invoice and packing list by chip family and encoding lot, Certificate of Origin, radio-compliance conformity (FCC / CE as applicable) and RoHS / REACH material declarations.
- Audit access: buyer engineering and security audits by appointment across two Shenzhen sites, with third-party (TÜV, SGS, Intertek, Bureau Veritas) inspection accommodated when a program requires it.
Useful next pages
Use these linked product, guide and comparison pages to keep the next click specific and practical.
Verify us before you commit
The documents and access a supplier-qualification team pulls first.
Start with the strongest secure cards
The most-ordered secure smart cards by platform.
FAQ
Can you supply smart cards pre-personalized with our security keys?
Yes. Proud Tek performs secure personalization — master-key diversification via NXP AN10922, application-key loading, file-structure creation and initial data writing. You provide the key hierarchy and personalization script; we execute it with key injection on air-gapped systems and delete the key material after production per your instructions. Master-key escrow is offered only on explicit written instruction.
How does the MIFARE DESFire application and key model work?
A MIFARE DESFire EV3 card holds as many applications as its memory allows (2 KB to 32 KB), each an independent directory with its own files, access conditions and up to 14 diversified keys. Access rights are set per file, so a transit purse, a door credential and a loyalty balance can share one card without sharing a key. We configure that structure to your personalization script and lock it before issuance.
What is the difference between MIFARE DESFire EV2 and EV3?
MIFARE DESFire EV3 keeps EV2's AES-128 security and Common Criteria EAL5+ grade and adds a transaction MAC for offline verification, a proximity check against relay attacks and SUN secure messaging for smartphone authentication. EV3 is backward compatible with EV2 infrastructure, so we recommend EV3 for all new deployments.
Can we migrate off MIFARE Classic without replacing our readers?
Usually, yes. MIFARE Plus EV1 provides AES-128 in a MIFARE Classic-compatible layout, so most Classic reader estates keep working at security level SL1 while the card population upgrades to AES at SL3. We supply sample cards for your integrator to validate against the actual reader fleet before any volume commitment — never migrate cards and readers in the same step.
Do you make dual-interface cards with both contact and contactless interfaces?
Yes. We produce dual-interface smart cards with a single chip module connected to both a contact pad (ISO/IEC 7816) and an embedded contactless antenna (ISO/IEC 14443), typically on a Java Card platform. This is the standard construction for transit, government ID and healthcare cards that need both interface types on one credential.
What certifications back the cards, and what can our security team audit?
Two layers. The chip IC carries its own Common Criteria certification — EAL5+ for MIFARE DESFire EV3 and MIFARE Plus EV2, published by NXP. Our factory runs an ISO 9001:2015 quality system with production travelers, encoding logs and QC results retained seven years and retrievable by encoding lot. Buyer and third-party audits (TÜV, SGS, Intertek, Bureau Veritas) are accommodated by appointment.
Sources & references
Primary standards, OEM datasheets and regulatory documents cited by this article. All URLs were verified on the access date shown below.
- ISO/IEC 14443-4:2018 — Contactless proximity objects (Part 4: Transmission protocol)
The 13.56 MHz contactless proximity air-interface standard underlying MIFARE DESFire, MIFARE Plus and NTAG 424 DNA smart cards.
- ISO/IEC 7816-4:2020 — Identification cards, integrated circuit cards (Part 4: Organization, security and commands)
The integrated-circuit-card standard covering the contact interface and APDU command set used by dual-interface smart cards.
- MF3D(H)x3 MIFARE DESFire EV3 contactless multi-application IC — product data sheet
Confirms DESFire EV3 hardware AES-128, Common Criteria EAL5+ (banking / e-passport grade), transaction MAC, and applications limited only by 2 KB-32 KB memory.
- NXP MIFARE Plus EV2 — product fact sheet (MFPLUSEV2LF)
Confirms MIFARE Plus EV2 128-bit AES, Common Criteria EAL5+, MIFARE Classic backward compatibility and SL1-to-SL3 security-level switching.
- ISO 9001:2015 — Quality management systems
The quality-management standard our card production, 100% functional verification and seven-year record retention are certified against.
Proud Tek is a Shenzhen-based RFID & NFC manufacturer supplying hotel chains, transit operators, event venues and retail brands worldwide. Every order includes free samples, RF testing and dedicated project support.
Get a Quick Quote
Tell us about your project and we'll respond within one business day. Fields marked (asterisk) are required.
