Not All MIFARE® Cards Are Created Equal

Understanding smart card technology, what separates a secure credential from a compromised one, and why MIFARE DESFire® is the specification that matters.

Published by PPC ID Solutions – Technology & Security

THE STANDARD YOU SHOULD BE SPECIFYING

MIFARE DESFire® EV3 — AES-128 · EAL5+ Certified · Originality Verified

If your access control system is not running on DESFire®, this article explains why that should change and what the risks of the alternatives really are.

Walk into almost any security integrator, card bureau, or ID supplier and you will see MIFARE® listed on the spec sheet. It has become shorthand for contactless smart card technology. However, this is what that label alone does not tell you: MIFARE® is a chip technology, not a card. More importantly, within that family, there is a profound difference between the legacy platforms still widely sold and the modern, cryptographically robust specification your systems should be running.

This article explains how MIFARE® technology actually works, who makes what, why MIFARE DESFire® represents a fundamentally different level of security, and why the manufacturing process behind the card body matters just as much as the chip inside it.

MIFARE® — The Technology, Not the Card

MIFARE® is a registered trademark of NXP Semiconductors, one of the world’s leading producers of secure identification chips.[1] NXP designs and manufactures the integrated circuit — the chip — at the heart of every genuine MIFARE® credential. NXP does not manufacture finished cards. Card manufacturers source NXP chips and build the complete credential around them.

The Supply Chain – Who Does What

  • NXP Semiconductors → produces the MIFARE® chip (IC) and licenses the technology platform
  • Card Manufacturers source the chip, select and attach an antenna, construct the card body, laminate, and finish the credential.
  • Distributors/ Integrators → the completed card reaches the end customer. At every stage NXP’s factory gate, manufacturers determine quality through their choices and standards.

Two Very Different Technologies Under One Name

MIFARE Classic® - A Legacy Platform with Known Limitations

MIFARE Classic® uses a proprietary security mechanism called Crypto-1. Since 2008, researchers have publicly broken Crypto-1, documenting the attacks in peer-reviewed academic literature and releasing exploit tools.

Security Advisory

MIFARE Classic® credentials can be cloned in seconds using widely available, low-cost equipment. Systems relying solely on MIFARE Classic® UID-based authentication provide no meaningful cryptographic security. NXP recommends migration to DESFire® for any application requiring genuine access control security.

THE RIGHT SPECIFICATION

MIFARE DESFire® EV3 — Built for Security That Actually Holds

MIFARE DESFire® is NXP’s advanced credential platform, engineered from the ground up for environments where security cannot be an afterthought. EV3 uses AES-128 encryption, implements full mutual authentication, and incorporates hardware-backed originality checking — a cryptographic signature that proves the device is a genuine NXP product. A counterfeit chip cannot replicate this signature.

AES-128

Encryption Standard

EAL5+

Common Criteria

Mutual Auth

Per-Application

Originality

Hardware Verified

Transaction MAC

Tamper Detection

FeatureMIFARE Classic®MIFARE DESFire® EV3 ✓
Security AlgorithmCrypto-1 (broken)AES-128 / 3DES
Card Cloning RiskHigh - trivially clonedNegligible with mutual auth
Originality VerificationNoneHardware-backed signature
Mutual AuthenticationNoneFull, per-application
Common Criteria Cert.NoneEAL5+
Recommended for New InstallsNo - Legacy OnlyYes

“Specifying MIFARE® without specifying DESFire® is like specifying a lock without specifying whether it can actually be picked. The brand name alone tells you almost nothing about the security you are getting.”

The Card Around the Chip: Why Manufacturing Quality Matters

Even with a genuine NXP DESFire® chip inside, a poorly manufactured card is still a poorly manufactured card. The chip is only one of three critical components. The others — the card substrate and the antenna — are selected and assembled entirely by the card manufacturer.

The Antenna — The Component NXP Does Not Make

NXP does not design or supply the antenna in your card. The coil is sourced, engineered, and attached by the card manufacturer. Their choices about coil geometry, wire specification, and connection method directly determine read range, reliability, and service life. A manufacturer targeting the lowest price point will make compromises on the antenna that reveal themselves over time as inconsistent reads, intermittent failures, and early card retirement.

Detecting Non-Genuine Cards: NXP TagInfo

NXP’s TagInfo app — free for Android and iOS — allows any NFC-equipped smartphone to interrogate a contactless card and report chip identity, manufacturer details, and for DESFire® EV3, originality signature status. A genuine card, whether from NXP or a licensed manufacturer, will be correctly identified. An unlicensed counterfeit will not. 

✓ Genuine NXP MIFARE® — TagInfo Result
IC Manufacturer: NXP Semiconductors · IC Type: MIFARE Classic EV1 (MF1S50) · NXP IC Detected ✔
✗ Non-Genuine Card — TagInfo Result

IC Manufacturer: Unknown Manufacturer ·
IC Type: Unknown MIFARE Classic IC, possibly cloned

Scanned with NXP TagInfo (free for Android & iOS). The app’s own words: “Unknown Manufacturer / possibly cloned.”
For best results use an Android Phon for NXP TagInfo (Results may vary on IOS)

What Good Manufacturing Looks Like: HID DBond™

HID Global’s DBond™ technology is a proprietary bonding and controlled-release process that permanently encapsulates the antenna inlay and chip module within the card substrate using fully automated, precision-controlled production.[8] Unlike conventional lamination — which introduces mechanical stress and delamination risk — DBond™ maintains tight control over antenna geometry and chip positioning throughout manufacture.

  • Permanent inlay integrity — antenna and chip fully protected against bending, impact, and handling stress
  • Stable RF performance — precise antenna geometry maintained across every card in a batch
  • Environmental resistance — high resistance to moisture, temperature variation, and chemical exposure
  • Automated, repeatable production — eliminates variability, supports batch traceability

PPC ID Solutions supplies MIFARE Classic 1K cards manufactured using HID’s DBond™ technology — combining NXP’s most advanced chip platform with one of the highest-quality card construction processes available.

Questions to Ask Your Supplier

  • Can you confirm the cards contain genuine NXP MIFARE® chips, verifiable with NXP TagInfo?
  • Are they MIFARE Classic® or MIFARE DESFire®? If Classic, what is the migration plan?
  • Who is the card manufacturer, and what quality certifications do they hold?
  • What antenna technology is used, and what is the specified read range tolerance across a batch?
  • For DESFire® cards: can the supplier confirm originality signature validity at issuance?

Specify DESFire®. Specify Quality.

Talk to PPC ID Solutions about MIFARE Classic 1K credentials manufactured with HID DBond™ technology.

References & Further Reading

  1. NXP Semiconductors. MIFARE technology. nxp.com/products/rfid-nfc/mifare-technology
  2. NXP Semiconductors. MIFARE Classic product page. nxp.com — MIFARE Classic
  3. NXP Semiconductors. MIFARE DESFire product page. nxp.com — MIFARE DESFire
  4. NXP Semiconductors. TagInfo by NXP. nxp.com — TagInfo
  5. HID Global. DBond™ manufacturing technology.

MIFARE® and DESFire® are registered trademarks of NXP Semiconductors N.V. HID and DBond™ are trademarks of HID Global Corporation. PPC ID Solutions is an independent authorised supplier and is not affiliated with NXP Semiconductors or HID Global.