MF3ICD21 NXP Semiconductors, MF3ICD21 Datasheet - Page 6

no-image

MF3ICD21

Manufacturer Part Number
MF3ICD21
Description
Mifare Desfire Ev1 Contactless Multi-application Ic
Manufacturer
NXP Semiconductors
Datasheet
NXP Semiconductors
MF3ICD21_41_81_SDS_2
Product short data sheet
8.5 Available file types
8.6 Security
If this rollback is necessary, it is done without user interaction before carrying out further
commands. To ensure data integrity on application level, a transaction-oriented backup is
implemented for all file types with backup. It is possible to mix file types with and without
backup within one application.
As the commands are the same for MF3ICD81, MF3ICD41 and MF3ICD21, the command
details are available in
devices.
The files within an application can be any of the following types:
The 7 byte UID is fixed, programmed into each device during production. It cannot be
altered and ensures the uniqueness of each device.
The UID may be used to derive diversified keys for each ticket. Diversified MIFARE
DESFire EV1 keys contribute to gain an effective anti-cloning mechanism and increase
the security of the original key; see
Prior to data transmission a mutual three pass authentication can be done between
MIFARE DESFire EV1 and PCD depending on the configuration employing either 56-bit
DES (single DES, DES), 112-bit DES (triple DES, 3DES), 168-bit DES (3 key triple DES,
3K3DES) or AES. During the authentication the level of security of all further commands
during the session is set. In addition the communication settings of the file/application
result in the following options of secure communication between MIFARE DESFire EV1
and PCD:
Find more information on the security concept of the product in
levels of security are recommended. The recommended secure handling of the product
can be seen in
Standard data files
Backup data files
Value files with backup
Linear record files with backup
Cyclic record files with backup
Plain data transfer (only possible within the backwards-compatible mode to
MF3ICD40)
Plain data transfer with cryptographic checksum (MAC): Authentication with
backwards-compatible mode to MF3ICD40: 4 byte MAC, all other authentications
based on DES/3DES/AES: 8 byte CMAC
Encrypted data transfer (secured by CRC before encryption): Authentication with
backwards-compatible mode to MF3ICD40: A 16-bit CRC is calculated over the
stream and attached. The resulting stream is encrypted using the chosen
cryptographic method. All other authentications based DES/3DES/AES: A 32-bit CRC
is calculated over the stream and attached. The resulting stream is encrypted using
the chosen cryptographic method.
Ref. 2
MF3ICD21, MF3ICD41, MF3ICD81
and in
Ref.
Rev. 02 — 6 March 2009
1. Only the memory size is different between the three
Ref.
MIFARE DESFire EV1 contactless multi-application IC
10.
Ref.
6.
Ref.
1. Be aware not all
© NXP B.V. 2009. All rights reserved.
6 of 15

Related parts for MF3ICD21