Skip to Content

Overview

What is

RFiD R-F-I-D noun
  1. A way to identify a person or object using data transmitted through radio-frequency fields.NIST

  2. A GRIT RFiD unit sends an identifier to the GRIT Hub, which finds the user or asset and applies the configured access, SignOn, or tracking action.

Cards, tags, and phones External readers

What every RFiD option does

One job: connect a card, tag, or phone to the right person or asset.

Present a card, tag, or phone; GRIT reads its identifier; the GRIT Hub applies the configured action.

GRIT Track RFiD
Illustrated GRIT RFiD reader options, card, phone, and tag

RFiD terms made simple

Know what the system needs to read.

Most RFiD decisions come down to the card technology, the identifier GRIT should read, and whether that identifier is protected.

A card identifier available without reading protected employee or student data. About 90% of cards present a stable UID; phones and some privacy-focused HID cards are common exceptions. Always verify with representative cards.

An employee, student, or card number stored inside protected card data. GRIT needs the correct card structure, encryption key, and read settings.

A secret value the reader needs to authenticate to protected card data. GRIT can use a supplied key but cannot recover a missing key.

A method that combines a master key with card-specific information to derive a different key for each card. One DESFire card can contain multiple applications or files with different keys and different diversification methods, including none.

Radio-frequency identification: radio communication used to identify a card, tag, phone, person, or object.
The radio band used by the card and reader. A shared frequency does not guarantee compatibility.
The low-frequency band used by HID Prox and other supported cards, tags, and stickers.
The high-frequency band used by MIFARE, MIFARE Classic, MIFARE DESFire, NFC, and some mobile wallet cards.
Ultra-high frequency, normally used for longer-distance reading; GRIT also offers short-range UHF readers.
The data format and security system inside the card. Frequency alone does not identify it.
A 13.56 MHz card technology with UID and protected sector/block data. Its legacy encryption can be broken.
A 13.56 MHz card technology that can contain multiple applications and files with separate keys and diversification methods.
A 125 kHz physical-access card technology available as a built-in GRIT reader option.
Physical access control system: the cards, readers, and access rules used for secured areas.
A reader interface that sends raw card bits for a GRIT Card Format to decode.
A USB reader that sends its result as if it were typed on a keyboard.
A USB smart-card reader interface, separate from keyboard-wedge input.
Bring Your Own Reader: the customer supplies a representative reader for a custom GRIT integration and enclosure.

Start here

Choose the least disruptive path.

Begin with the card the establishment wants to use, the identifier available in the user data, and whether the required keys are available.

Route Use it when What GRIT needs
Use the current card GRIT can read a stable UID, or the establishment can provide the keys and diversification details for the protected identifier. The card UID or protected employee/student identifier used in the GRIT profile data.
Add a GRIT card or RFiD sticker The current identification card has no usable RFiD, uses only a barcode or magnetic stripe, or another frequency is the cleaner option. A GRIT card or sticker assigned to the user’s GRIT profile.
BYOR The customer prefers to use existing encrypted cards but cannot provide the required keys. A representative reader, preferably Wiegand, plus the expected reader output format.

Supported technologies · Cards, tags, and phones

Match the reader to the credential.

Choose this family based on the card technology already in use, the identifier GRIT needs, and whether protected data must be read.

01 GRIT 13.56 MHz RFiD reader MIFARE and MIFARE Classic Temporary GRIT cards and existing MIFARE systems. Frequency · 13.56 MHz Reads · UID or protected block data
GRIT MIFARE card with lanyard

Compact spec

How it works.

GRIT can read the card UID or use supplied MIFARE Classic keys to read protected sector and block data.

Supported examples
  • MIFARE 1K temporary cards
  • MIFARE Classic cards
  • GRIT RFiD cards and stickers
Available configurations
2 paths
UID read
Frequency
13.56 MHz
Key
Not required
Protected MIFARE Classic read
Key
Key A or Key B
Location
Sector and block
02 GRIT 13.56 MHz RFiD reader MIFARE DESFire Preferred encrypted card technology for new physical access control deployments. Frequency · 13.56 MHz Reads · stable UID or protected file data
GRIT RFiD reader for a DESFire deployment

Compact spec

How it works.

GRIT can use an available stable public UID or authenticate to the selected application and file when the establishment provides the required keys and diversification details. Verify the UID with representative cards before choosing that path.

Supported examples
  • GRIT-managed encrypted DESFire cards
  • Allegion or Schlage DESFire access cards with supplied keys
  • Cards with multiple applications, files, keys, and diversification methods
Available configurations
2 paths
UID read
Key
Not required
Result
Verified stable public card UID
Protected file read
Requires
Application, file, key slot, key type, key, and diversification method
03 Mobile credential NFC mobile phones Add a mobile wallet credential alongside a physical card. Platforms · Apple and Android Options · encrypted or non-encrypted
GRIT mobile credential illustration

Compact spec

How it works.

GRIT supports encrypted and non-encrypted NFC mobile wallet cards on Apple and Android. GRIT-issued mobile cards work out of the box; supported third-party cards require separate Apple and Google configuration information and keys.

Supported examples
  • GRIT mobile wallet cards
  • supported non-GRIT Apple Wallet and Google Wallet cards
  • encrypted and non-encrypted NFC mobile cards
Available configurations
3 options
GRIT mobile wallet
Setup
Works out of the box
Apple Wallet
Requires
Pass Type ID and Apple EC Private Key
Google Wallet
Requires
Collector ID, Key Version, and Google EC Private Key
04 GRIT HID Prox reader HID Prox Built-in GRIT reader option for supported HID Prox cards. Frequency · 125 kHz Reader · HID Prox-specific
GRIT HID Prox RFiD reader

Compact spec

How it works.

The built-in HID Prox option reads supported 125 kHz HID Prox cards without requiring an external reader.

Compatibility note
  • HID Prox is separate from other 125 kHz tag technologies
  • some HID cards may contain more than one credential technology
  • test representative production cards before rollout
Available configuration
1 option
GRIT HID Prox reader
Frequency
125 kHz
Best fit
Supported HID Prox card populations
05 GRIT 125 kHz tag reader 125 kHz cards, tags, and stickers A separate low-frequency reader option for supported 125 kHz media. Frequency · 125 kHz Media · Cards, tags, and stickers
GRIT 125 kHz RFiD reader

Compact spec

How it works.

The reader returns the identifier from a supported 125 kHz card, tag, or sticker.

Use it when
  • the existing card has no usable RFiD
  • a 125 kHz sticker is being added to an identification card
  • the selected media is not HID Prox
Available configuration
1 option
GRIT 125 kHz reader
Frequency
125 kHz
Media
Supported cards, tags, and stickers
06 UHF tag option UHF tags and stickers Long-range or short-range UHF for tags and mixed card populations. Frequency · UHF Range · Long or short
UHF tag and reader illustration

Compact spec

How it works.

GRIT supports longer-distance UHF reading and short-range UHF readers that make a UHF tag behave like a normal close-range credential.

Use it when
  • the application requires longer read distance
  • one sticker technology is needed across 13.56 MHz and 125 kHz populations
  • a short-range UHF reader should limit the presentation distance
Available configurations
2 options
Long-range UHF
Best fit
Applications requiring longer read distance
Short-range UHF
Best fit
Close-range tag presentation across mixed card populations

Supported technologies · External readers

Keep the reader that already understands the card.

Choose an external reader when it should provide the identifier to GRIT or when the establishment prefers to keep using encrypted PACS cards without supplying the keys.

01 External RFiD reader installation USB keyboard-wedge reader Accept an identifier as keyboard input. Connection · USB Output · Text string
External reader connected to a GRIT installation

Compact spec

How it works.

The reader sends its result as keyboard input, and GRIT uses that string as the credential identifier.

Supported example
  • external USB RFiD readers operating as HID keyboard-wedge devices
Available configuration
1 option
USB keyboard wedge
Output
Text string
Best fit
GRIT Track SignOn or GRIT Asset Tracker stations using a desktop reader
02 CCID USB reader integration CCID USB reader Integrate a supported USB reader through CCID/PC/SC. Connection · USB Interface · CCID/PC/SC
External reader integration

Compact spec

How it works.

GRIT communicates with the reader through CCID/PC/SC. It does not treat the reader as a keyboard wedge.

Supported example
  • HID OMNIKEY 5025 CL for 125 kHz HID Prox cards
Available configuration
1 example
HID OMNIKEY 5025 CL
Connection
USB 2.0 Type-A; CCID/PC/SC
Card technology
HID Prox, 125 kHz
03 Third-party reader in a GRIT enclosure Wiegand / BYOR Keep using an existing PACS reader through a custom GRIT integration. Interface · Wiegand preferred Customer provides · Representative reader
Reader installed in a GRIT enclosure

Compact spec

How it works.

The customer supplies a representative reader. GRIT creates the custom enclosure and uses Card Formats to decode the reader output.

Supported examples
  • existing HID readers
  • existing Schlage or Allegion readers
  • other PACS readers that provide Wiegand output
  • compatible readers for protected Seos or iCLASS identity data

If GRIT must read protected HID Seos or iCLASS identity data, use BYOR with a compatible reader.

Available configuration
1 custom path
BYOR — Bring Your Own Reader
Connection
Wiegand preferred
Customer provides
Representative reader and expected identifier format
Applies to
GRIT Track SignOn, GRIT Asset Tracker, and custom tool-access installations

User data

The import feed changes the RFiD setup.

These Data Import fields determine whether the credential is linked during import, read from protected card data, assigned at first use, or delivered as a mobile card.

Data available GRIT field or setting Result
Card UID or reader-provided identifier Physical ID Number Associates the card with the correct GRIT profile during import.
Protected employee or student identifier External System Id Lets GRIT use protected card data to find the imported profile when keys and diversification details are available.
No card UID in the feed Prompt To Assign RFiD Tag SignOn prompts the identified user to assign a card, tag, or sticker.
User email for mobile onboarding Send Mobile Card Email Emails a GRIT mobile wallet card when Mobile Wallet is enabled and the user has an email address.

Configuration guide

Configure the identifier GRIT should return.

Test representative production cards at every step. A printed card brand or frequency alone does not prove compatibility.

UID path

Read the public card identifier.

  1. Present a representative card to the selected GRIT reader.
  2. Confirm that it returns the same identifier on repeated reads.
  3. Import the UID through Physical ID Number, or assign it during first-use SignOn.
  4. Confirm that the card resolves to the correct profile.

Protected PACS data

Authenticate to the required application and file.

  1. Use Probe Card to inspect a representative card.
  2. Select the application and file containing the required identifier.
  3. Enter the read-key slot, key type, encryption key, and diversification method.
  4. Set the read length and Card Format.
  5. Compare the decoded value with External System Id.

Customer inputs: application, file, read-key slot, key type, encryption key, offset, length, output format, and diversification method. Supported diversification selections include None, AN10922, SAM AV1, and SAM AV2. GRIT cannot recover missing keys.

MIFARE Classic

Use supplied Key A or Key B.

Select the sector and block, set the read length and Card Format, and test the decoded identifier. GRIT supports MIFARE Classic protected reads for existing systems, although its legacy encryption can be broken.

Wiegand and Card Formats

Turn raw card bits into the expected user string.

Capture the raw bitstream; identify facility-code and card-number groups; configure parity and zero-padding; then review the raw, decimal, hexadecimal, and formatted results. Save the Card Format, bind it to the Wiegand reader or supported DESFire file data, and test representative production cards. Changing the format later changes the identifier GRIT produces and can prevent existing card associations from resolving correctly.

USB keyboard wedge

Accept the reader output as keyboard input.

  1. Connect the reader by USB.
  2. Confirm that it sends the expected identifier as keyboard input.
  3. Configure the applicable GRIT workflow to accept that input.
  4. Test representative cards.

CCID reader

Use the separate CCID/PC/SC path.

  1. Connect the supported CCID reader by USB.
  2. Configure the CCID/PC/SC reader path.
  3. Confirm that the reader returns the expected card identifier.
  4. Test representative cards.

CCID is not a keyboard-wedge integration.

GRIT Hub Card Reader Configuration showing Card Types, Card Formats, Card Issuance, Mobile Wallet, and reader selection
Card Reader Configuration keeps Card Types, Card Formats, and Card Issuance in one workflow.
GRIT Hub Card Format editor showing a 26-bit Wiegand pattern, parity groups, padding, and calculated values
The Card Format editor maps Wiegand bits, parity, groups, padding, and the formatted identifier GRIT returns.
GRIT Hub Card Issuance screen for configured encrypted cards
Card Issuance uses the configured GRIT card key without displaying key values in the issuance workflow.

Card recommendations

Choose for the deployment you have.

Temporary GRIT cards

Typical GRIT temporary cards are MIFARE 1K cards. They are appropriate for temporary cards assigned by GRIT Track SignOn for use in the shop.

New encrypted door access

For new physical access control deployments, encrypted MIFARE DESFire cards are preferred. GRIT provides its built-in encryption scheme and keys for GRIT-managed cards.

Existing encrypted PACS cards

Use the card directly when GRIT has the required keys and diversification configuration. If the keys are unavailable, use a GRIT mobile wallet card, BYOR, or a GRIT card or sticker.

Existing MIFARE Classic cards

GRIT supports MIFARE Classic encryption for existing installations, even though the encryption can be broken. Do not choose it as the preferred technology for a new encrypted PACS deployment.

Mixed card populations

When an establishment uses both 13.56 MHz and 125 kHz cards, a common UHF sticker with a short-range UHF reader can avoid installing both reader types at every GRIT location.

Usage scenarios

See RFiD in real installations.

Reader technology changes by site. The physical installation still needs to fit the doorway, kiosk, or controlled area where people present their credential.

GRIT RFiD reader installed beside an exterior access-controlled door
Exterior door access with a GRIT RFiD reader installed beside the opening.
GRIT RFiD reader installed at the entrance to the Voltz Factory
A GRIT RFiD reader at a factory entrance.
GRIT Track SignOn and RFiD readers installed beside a manufacturing-floor entrance
GRIT Track SignOn and RFiD readers installed beside a manufacturing-floor entrance.