LEAF Verified, a pioneering credential platform, has been launched today, offering a transformation in the deployment and management of physical access credentials for organisations.
Developed using NXP® Semiconductors' MIFARE DUOX™ technology, LEAF Verified incorporates Public Key (PK) cryptography to eradicate encryption key management complexities. It ensures true interoperability across compatible devices, aligning with the LEAF Community's objective of a universal credential for various environments. The LEAF Community is a global forum that unites organisations and technology experts to offer customers adaptable and secure access solutions.
Advanced security and interoperability
The platform integrates security at the initial chip manufacturing stage, making credential cloning nearly impossible. This ensures that the authenticity of credentials is protected from the outset.
"For decades, organisations have accepted that vulnerable credentials, time-intensive key management, and long configuration projects are unavoidable burdens," stated Julia Webb-Twoomey, Vice President, Credentials at Wavelynx. "LEAF Verified challenges these assumptions, solving problems at the chip level, deploying quickly, and transforming every credential into a platform that delivers unprecedented value."
Innovative security measures
LEAF Verified utilises a certificate-based PK authentication with asymmetric encryption, diverging from traditional shared-key practices. Each credential is equipped with a public and private key pair, alongside a certificate securely signed by the LEAF Certificate Authority during wafer manufacturing.
By leveraging MIFARE DUOX, an EAL 6+ certified platform, the platform effectively deters credential cloning, eliminating a primary vulnerability of conventional systems. "The security landscape is evolving rapidly, and organisations need credentials that can keep pace without adding complexity," commented Andre Perchthaler, Senior Director, NXP. "LEAF Verified, powered by our MIFARE DUOX product, represents a crucial innovation in access control."
Compliance and seamless integration
This integration allows employees to use one credential for multiple access points and systems
Designed to aid enterprises with SOC 2, PCI-DSS, HIPAA, and FIPS compliance, LEAF Verified facilitates audit trails and mitigates key distribution risks. Its certificate-based framework ensures complete authentication transparency without compromising sensitive data.
The public key cryptography enables a single credential to function across any LEAF Verified-compatible device, offering organisations the freedom to select top-tier solutions for various applications. This integration allows employees to use one credential for multiple access points and systems, removing the need for multiple keys and enabling seamless scalability without added management burdens.
Extending functionality through NFC
The LEAF Community's dedication to interoperability is further enhanced by LEAF Verified's capabilities, showcasing the platform's progress. Utilising NFC Data Exchange Format (NDEF) technology, LEAF Verified extends beyond basic access control.
When tapped to an NFC-enabled smartphone, the credential leads users to a unique URL for creating personalised experiences, facilitating self-service enrolment, access to support portals, or modern visitor management workflows. This evolution turns the credential into a continuing service delivery platform.
Today marks the launch of LEAF Verified, a next-generation credential platform that transforms how organisations deploy and manage physical access credentials.
Built on NXP® Semiconductors' MIFARE DUOX™ product, LEAF Verified uses Public Key (PK) cryptography to eliminate encryption key management while enabling true interoperability across any compatible device, fulfilling the LEAF Community's mission of a single credential that works everywhere. The LEAF Community is a global forum uniting organisations and technology experts to provide customers with flexible, secure access solutions.
Delivering unprecedented value
LEAF Verified leverages a platform that embeds security at the chip manufacturing stage, making the credential’s authenticity secure from the moment it's produced. This makes credential cloning virtually impossible.
"For decades, organisations have accepted that vulnerable credentials, time-intensive key management, and long configuration projects are unavoidable burdens," said Julia Webb-Twoomey, Vice President, Credentials at Wavelynx. "LEAF Verified challenges these assumptions, solving problems at the chip level, deploying quickly, and transforming every credential into a platform that delivers unprecedented value."
Shared-key methods
LEAF Verified uses certificate-based public key (PK) authentication with asymmetric encryption instead of traditional shared-key methods. Each credential contains a public and private key pair along with a certificate that is securely signed by the LEAF Certificate Authority during wafer manufacturing. Building on MIFARE DUOX, an EAL 6+ certified platform, LEAF Verified makes credential cloning virtually impossible, eliminating the primary attack vector of traditional systems.
"The security landscape is evolving rapidly, and organisations need credentials that can keep pace without adding complexity," said Andre Perchthaler, Sen. Director, Head of Payment / SecID / MIFARE Solutions at NXP. "LEAF Verified, powered by our MIFARE DUOX product, represents a crucial innovation in access control. By eliminating key management overhead and enabling true interoperability, we're helping organisations focus on what matters most—keeping their people and assets secure while delivering seamless user experiences."
Seamless user experiences
For enterprises managing SOC 2, PCI-DSS, HIPAA, and FIPS compliance requirements, LEAF Verified simplifies audit trails and eliminates the key distribution vulnerabilities that traditionally create compliance risk. The certificate-based approach provides complete authentication transparency without exposing sensitive data.
LEAF Verified's public key cryptography enables one credential to work across any LEAF Verified compatible device from any manufacturer—eliminating single vendor constraints. Organisations gain the flexibility to choose best-in-class solutions for each application. Employees carry a single credential that unlocks every door, logs them into every system, and grants them access to every resource. With no encryption keys to provision or manage, interoperable solutions deploy simply, enabling organisations to scale without adding overhead.
NFC-enabled smartphone
The LEAF Community brings together manufacturers committed to interoperability by design, and LEAF Verified represents the next evolution of this innovation.
NFC Data Exchange Format (NDEF) technology transforms LEAF Verified beyond simple access control. When users tap their LEAF Verified card to any NFC-enabled smartphone, it directs them to a unique URL where partners can create personalised experiences, enabling self-service enrolment, access to support portals, or modern visitor management workflows with just a tap. This transforms the credential from a one-time sale into a platform for ongoing service delivery.