RFID LF (125 kHz)
125 kHz
Core Technical Specifications
Real-World Devices & Applications
Access Control
- EM4100 proximity cards and key fobs
- HID ProxCard II (26-bit Wiegand)
- AWID and Indala access cards
- Time attendance systems
Animal & Asset Tracking
- Pet microchips (ISO 11784/FDX-B)
- Livestock ear tags
- Industrial asset tracking tags
Reference Circuits & Schematics
125 kHz RFID Reader — EM4095 / MFRC523
LF RFID readers use a large coil antenna to generate a 125 kHz magnetic field. Passive tags draw power inductively and respond by modulating the field.
| Pin | Description |
|---|---|
VCC
|
5V supply (higher voltage = more field strength) |
GND
|
Ground |
COIL+/COIL−
|
Antenna coil connections (tuned LC circuit) |
DEMOD OUT
|
Demodulated tag data output |
MOD IN
|
Modulation input for writable tags |
Circuit Walk-Through
The reader drives a tuned LC circuit at 125 kHz, creating an alternating magnetic field. When a tag enters the field, it draws energy and modulates the field by switching a load resistor on/off (ASK) or shifting frequency (FSK). The reader’s demodulator recovers the data. EM4100 tags transmit a 64-bit frame: 9-bit header + 40-bit ID + 14 parity bits + stop bit.
Signal Structure & Waveform Analysis
EM4100 Tag Data Format
The EM4100 is a read-only 125 kHz tag with a 40-bit unique ID transmitted continuously.
Analysis & Capture Tips
- Proxmark3: lf search to auto-detect tag type and read ID
- T5577 can be programmed to emulate EM4100, HID, Indala, and more
- Check Wiegand output format for HID readers (26-bit or 37-bit)
- Verify reader antenna tuning at 125 kHz for maximum read range
Bench Troubleshooting & Repair Guide
1. Short Read Range
Oscilloscope / LCR meter125 kHz read range depends heavily on antenna size and tuning. Larger coil = longer range. Verify LC resonance at 125 kHz. Metal housings detune the antenna.
2. Cloning Issues
Proxmark3T5577 must be configured with correct modulation (ASK/FSK/PSK) and bit rate to emulate the target card format. Use Proxmark3 lf t55xx commands to verify configuration blocks.
3. Wiegand Interface
Wiegand sniffer / Logic AnalyserHID readers output Wiegand format (D0/D1 pulsed lines). Check wiring: DATA0 (green), DATA1 (white), GND. Verify 26-bit format: 1 parity + 8 facility + 16 card number + 1 parity.