Beruflich Dokumente
Kultur Dokumente
MIFAREWikipedia
MIFARE
FromWikipedia,thefreeencyclopedia
MIFAREistheNXPSemiconductorsownedtrademarkofaseriesofchipswidelyusedincontactlesssmartcardsand
proximitycards.
TheMIFAREnamecoversproprietarytechnologiesbaseduponvariouslevelsoftheISO/IEC14443TypeA13.56
MHzcontactlesssmartcardstandard.AccordingtoMIFAREthemselves,10billionoftheirsmartcardchipsand150
millionoftheirreadermoduleshavebeensold.[1]ThetechnologyisownedbyNXPSemiconductors,whichwasspun
offfromPhilipsElectronicsin2006.
Contents
1 Variants
1.1 MIFAREClassic
1.2 MIFAREClassicEV1
1.3 MIFAREUltralightandMIFAREUltralightEV1
1.4 MIFAREUltralightC
1.5 MIFAREDESFire
1.6 MIFAREDESFireEV1
1.7 MIFAREDESFireEV2
1.8 MIFAREPlus
1.9 MIFARESAMAV2
2 Applications
3 ByteLayout
4 History
5 SecurityofMIFAREClassic,MIFAREDESFireandMIFAREUltralight
6 Considerationsforsystemsintegration
7 Certification
8 Seealso
9 PlacesthatuseMIFAREproducts
9.1 Transportation
9.2 ApplicationReferences
9.3 Institutions
10 References
11 Furtherreading
12 Externallinks
Variants
Thetechnologyisembodiedinbothcardsandreaders(alsoreferredtoasaProximityCouplingDevicewhichis
suitabletouse).
TheMIFAREname(derivedfromthetermMIkronFARECollectionSystem)coverssevendifferentkindsof
contactlesscards:
MIFAREClassic
Employsaproprietaryprotocolcomplianttoparts13ofISO/IEC14443TypeA,withanNXPproprietary
securityprotocolforauthenticationandciphering.
MIFAREClassicEV1
https://en.wikipedia.org/wiki/MIFARE
1/25
28/10/2016
MIFAREWikipedia
MIFAREUltralight
LowcostICsthatemployaproprietaryprotocolcomplianttoISO/IEC144433TypeA.MIFAREUltralight
basedticketsareidealforhighvolumeapplicationssuchas,publictransport,loyaltycardsandeventticketing.
MIFAREUltralightC
ThefirstlowcostICsforlimiteduseapplicationsthatofferthebenefitsofanopenTripleDEScryptography.
TheMIFAREUltralightCcanbeactasasingletripmasstransittickets,eventtickets,lowcostloyaltycardsand
arealsousedfordeviceauthentication.
MIFAREDESFire
AresmartcardsthatcomplytoISO/IEC144434TypeAwithamaskROMoperatingsystemfromNXP.The
'DES'inthenamereferstotheuseofDES,2K3DES,3K3DESandAEShardwarecryptographicenginefor
securingtransmissiondatawhile'Fire'isanacronymfor'Fast,innovative,reliableandenhanced'.
MIFAREDESFireEV1
IncludesAESencryption.MIFAREDESFireEV1deliversabalanceofspeed,performanceandcostefficiency.
MIFAREDESFireEV2
ThesecondevolutionofourindustryleadingMIFAREDESFireopenarchitectureplatformforsmartcards
offerssuperiorperformance,stateoftheartsecurity,privacyandenhancedmultiapplicationsupporttoenable
newbusinessmodels.
MIFAREPlus
DropinreplacementforMIFAREClassicwithcertifiedsecuritylevel(AES128based)andisfullybackwards
compatiblewithMIFAREClassic.
MIFARESAMAV2
Secureaccessmodulethatprovidesthesecurestorageofcryptographickeysandcryptographicfunctions.
MIFAREClassic
TheMIFAREClassiccardisfundamentallyjustamemorystoragedevice,wherethememoryisdividedintosegments
andblockswithsimplesecuritymechanismsforaccesscontrol.TheyareASICbasedandhavelimitedcomputational
power.Thankstotheirreliabilityandlowcost,thosecardsarewidelyusedforelectronicwallet,accesscontrol,
corporateIDcards,transportationorstadiumticketing.
TheMIFAREClassic1Koffers1024bytesofdatastorage,splitinto16sectorseachsectorisprotectedbytwo
differentkeys,calledAandB.Eachkeycanbeprogrammedtoallowoperationssuchasreading,writing,increasing
valueblocks,etc.MIFAREClassic4Koffers4096bytessplitintofortysectors,ofwhich32aresamesizeasinthe1K
witheightmorethatarequadruplesizesectors.MIFAREClassicminioffers320bytessplitintofivesectors.Foreach
ofthesecardtypes,16bytespersectorarereservedforthekeysandaccessconditionsandcannotnormallybeused
foruserdata.Also,theveryfirst16bytescontaintheserialnumberofthecardandcertainothermanufacturerdataand
arereadonly.Thatbringsthenetstoragecapacityofthesecardsdownto752bytesforMIFAREClassic1K,3440
bytesforMIFAREClassic4K,and224bytesforMini.ItusesanNXPproprietarysecurityprotocol(Crypto1)for
authenticationandciphering.
TheSamsungTecTileNFCtagstickersuseMIFAREClassicchips.ThismeansonlydeviceswithanNXPNFC
controllerchipcanreadorwritethesetags.AtthemomentBlackBerryphones,theNokiaLumia610(August2012[2]),
theGoogleNexus4,GoogleNexus7LTEandNexus10(October2013[3])can'tread/writeTecTilestickers.
MIFAREClassicencryptionhasbeencompromisedseebelowfordetails.
MIFAREClassicEV1
Thisisanenhancedversiondevelopedtoimprovesecurity,performanceanddurabilityofthepreviosMiFAREClassic
Version.AsNXPexplains,intermsofhardenedfeaturesetitincludes:
TrueRandomNumberGenerator
RandomIDsupport(7ByteUIDversion)
NXPOriginalityChecksupport
https://en.wikipedia.org/wiki/MIFARE
2/25
28/10/2016
MIFAREWikipedia
IncreasedESDrobustness
Writeendurance200,000cycles(insteadof100,000cycles)
MIFAREUltralightandMIFAREUltralightEV1
TheMIFAREUltralighthasonly512bitsofmemory(i.e.64bytes),withoutcryptographicsecurity.Thememoryis
providedin16pagesof4bytes.Cardsbasedonthesechipsaresoinexpensivethattheyareoftenusedfordisposable
ticketsforeventssuchastheFootballWorldCup2006.Itprovidesonlybasicsecurityfeaturessuchasonetime
programmable(OTP)bitsandawritelockfeaturetopreventrewritingofmemorypagesbutdoesnotinclude
cryptographyasappliedinotherMIFAREbasedcards.
MIFAREUltralightEV[4]introducedinNovember2012thenextgenerationofpaperticketingsmartcardICfor
limiteduseapplicationsthatofferssolutiondevelopersandoperatorsthemaximumflexibilityfortheirticketing
schemesandadditionalsecurityoptions.ItcomeswithseveralenhancementsabovetheoriginalMIFAREUltralight
384and1024Bitsusermemoryproductvariants
OTP,LockBits,configurablecountersforimprovedsecurity
Threeindependent24bitonewaycounterstostopreloading
Protecteddataaccessthrough32bitpassword
NXPSemiconductorsoriginalitysignaturefunction,thisisanintegratedoriginalitycheckerandisaneffective
cloningprotectionthathelpstopreventcounterfeitoftickets.Howeverthisprotectionisapplicableonlyto
"masspenetrationofnonNXPoriginatedchipsanddoesnotpreventhardwarecopyoremulationofasingle
existingvalidchip"[5]
Keyapplications:
Limiteduseticketsinpublictransport
Eventticketing(stadiums,exhibitions,leisureparks)
Loyalty
MIFAREUltralightC
IntroducedattheCartesindustrytradeshowin2008,MIFAREUltralightCispartofNXP'slowcostMIFARE
offering(disposableticket).WithTripleDES,MIFAREUltralightCusesawidelyadoptedstandard,enablingeasy
integrationinexistinginfrastructures.TheintegratedTripleDESauthenticationprovidesaneffectivecountermeasure
againstcloning.
Keyfeatures:
FullycompliantwithISO/IEC14443parts13,TypeA(includinganticollision)
1536bits(192bytes)EEPROMmemory
Protecteddataaccessvia3passTripleDESauthentication
MemorystructureasinMIFAREUltralight(pagesof4byte)
BackwardscompatibilitytoMIFAREUltralightduetocompatiblecommandset
16bitonewaycounter
Unique7byteserialnumber(UID)
KeyapplicationsforMIFAREUltralightCarePublicTransportation,EventTicketing,LoyaltyandNFCForumTag
Type2.
MIFAREDESFire
https://en.wikipedia.org/wiki/MIFARE
3/25
28/10/2016
MIFAREWikipedia
TheMIFAREDESFire(MF3ICD40)wasintroducedin2002andisbasedonacoresimilartoSmartMX,withmore
hardwareandsoftwaresecurityfeaturesthanMIFAREClassic.Itcomespreprogrammedwiththegeneralpurpose
MIFAREDESFireoperatingsystemwhichoffersasimpledirectorystructureandfiles.Theyaresoldinfourvariants:
onewithTripleDESonlyand4KBofstorage,andthreewithAES(2,4or8KBseeMIFAREDESFireEV1).The
AESvariantshaveadditionalsecurityfeatures,e.g.,CMAC.MIFAREDESFireusesaprotocolcompliantwith
ISO/IEC144434.[6]Thecardisbasedonan8051processorwith3DES/AEScryptoaccelerator,makingveryfast
transactionspossible.
Themaximalread/writedistancebetweencardandreaderis10centimetres(3.9in),butactualdistancedependsonthe
fieldpowergeneratedbythereaderanditsantennasize.
In2010NXPannouncedthediscontinuationoftheMIFAREDESFire(MF3ICD40)afterithadintroducedits
successorMIFAREDESFireEV1late2008.InOctober2011researchersofRuhrUniversityBochum[7]announced
thattheyhadbrokenthesecurityofMIFAREDESFire(MF3ICD40),whichwasacknowledgedbyNXP.,[8]see
DESFireAttacks
MIFAREDESFireEV1
(previouslycalledDESFire8)
NewevolutionofMIFAREDESFirecard,broadlybackwardscompatible.Availablewith2KB,4KBand8KBNV
Memory.Otherfeaturesinclude:[9]
SupportforrandomID
Supportfor128bitAES
HardwareandOperatingSystemisCommonCriteriacertifiedatlevelEAL4+
MIFAREDESFireEV1waspubliclyannouncedinNovember2006.
Keyapplications:
Advancedpublictransportation
Accessmanagement
Loyalty
Micropayment
MIFAREDESFireEV2
NewevolutionofMIFAREDESFirecard,broadlybackwardscompatible.[10]Newfeaturesinclude:
MIsmartAppenablingtoofferorsellmemoryspaceforadditionalapplicationsof3rdpartieswithouttheneedto
sharesecretkeys
TransactionMACtoauthenticatetransactionsby3rdparties
VirtualCardArchitectureforprivacyprotection
Proximitycheckagainstrelayattacks
MIFAREDESFireEV2waspubliclyannouncedinMarch2016.
MIFAREPlus
MIFAREPlusisareplacementcardfortheMIFAREClassic.Itprovidesaneasyupgradeofexistinginfrastructures
towardhighsecurity.DatamanagementisidenticaltotheMIFAREClassichowever,thesecuritymanagement
requiresthemodificationoftheinstalledreaderbase.Otherfeaturesinclude:
https://en.wikipedia.org/wiki/MIFARE
4/25
28/10/2016
MIFAREWikipedia
2Kbytesor4Kbytesofmemory
7or4bytesUID,withoptionalsupportforrandomUID
Supportfor128bitAES
CommonCriteriacertifiedatlevelEAL4+
MIFAREPlusSforsimplemigrationorMIFAREPlusXwithmanyeXpertcommands
Securityupgradewithcardsinthefield.
Keyapplications:
PublicTransportation
Accessmanagement,e.g.employee,schoolorcampuscards
Electronictollcollection
Carparking
Loyaltyprograms
ItislessflexiblethanMIFAREDESFireEV1.
MIFAREPluswaspubliclyannouncedinMarch2008withfirstsamplesinQ12009.[11]
MIFAREPlus,whenusedinoldertransportationsystemsthatdonotyetsupportAESonthereaderside,stillleavesan
opendoortoattacks.ThoughithelpstomitigatethreatsfromattacksthatbroketheCrypto1cipherthroughtheweak
randomnumbergenerator,itdoesnothelpagainstbruteforceattacksandcryptoanalyticattacks.[12]Duringthe
transitionperiodfromMIFAREClassictoMIFAREPluswhereonlyafewreadersmightsupportAESinthefirst
place,itoffersanoptionalAESauthenticationinSecurityLevel1(whichisinfactMIFAREClassicoperation).This
doesnotpreventtheattacksmentionedabovebutenablesasecuremutualauthenticationbetweenthereaderandthe
cardtoprovethatthecardbelongstothesystemandisnotfake.InitshighestsecuritylevelSL3,using128bitAES
encryption,MIFAREPlusissecuredfromattacks.
MIFARESAMAV2
MIFARESAMsarenotcontactlesssmartcards.TheyareSecureaccessmodulesdesignedtoprovidethesecurestorage
ofcryptographickeysandcryptographicfunctionsforterminalstoaccesstheMIFAREproductssecurelyandtoenable
securecommunicationbetweenterminalsandhost(backend).MIFARESAMsareavailablefromNXPinthecontact
onlymodule(PCM1.1)asdefinedinISO/IEC78162andtheHVQFN32format.
Keyfeatures:
CompatiblewithMIFAREportfoliosolutions
SupportsMIFARE,3DESandAEScryptography
Keydiversification
Securedownloadandstorageofkeys
128keyentries
ISO/IEC7816baudrateupto1.5Mbit/s
Xmodefunctionality
IntegratingaMIFARESAMAV2inacontactlesssmartcardreaderenablesadesignwhichintegrateshighend
cryptographyfeaturesandthesupportofcryptoauthenticationanddataencryption/decryption.LikeanySAM,itoffers
functionalitytostorekeyssecurely,andperformauthenticationandencryptionofdatabetweenthecontactlesscard
andtheSAMandtheSAMtowardsthebackend.NexttoaclassicalSAMarchitecturetheMIFARESAMAV2
supportstheXmodewhichallowsafastandconvenientcontactlessterminaldevelopmentbyconnectingtheSAMto
themicrocontrollerandreaderICsimultaneously.
MIFARESAMAV2offersAV1modeandAV2modewhereincomparisontotheSAMAV1theAV2versionincludes
PublicKeyInfrastructure(PKI),HashfunctionslikeSHA1,SHA224,andSHA256.ItsupportsMIFAREPlusanda
securehostcommunication.Bothmodesprovidethesamecommunicationinterfaces,cryptographicalgorithms
https://en.wikipedia.org/wiki/MIFARE
5/25
28/10/2016
MIFAREWikipedia
(TripleDES112bitand168bitkey,MIFARECrypto1,AES128andAES192,RSAwithupto2048bitkeys),and
Xmodefunctionalities.
Applications
MIFAREproductscanbeusedindifferentapplications:[13]
Automatedfarecollectionsystem
IDCards
AccessManagement
Campuscards
Loyaltycards(rewardpoints)
Touristcards
Micropayment(Mobilewallet,contactlesspayment,cashlesspayment)
Roadtolling
Transportticketing
Eventticketing
Mobileticketing
Citizencard
Membershipcards
Parking
Librarycards
Fuelcards
Hotelkeycards
NFCTag(NFCapps,MIFARE4Mobile)
Taxicards
Smartmeter
MuseumAccessCards
ProductAuthentication
Productioncontrol
Healthcards
FerryCards
Carrentals
FleetManagement
Amusementparks
Bikerentals
Blooddonorcards
Informationservices
Interactiveexhibits
Interactivelotteries
Passwordstorage
Smartadvertising
Socialwelfare
Wastemanagement
FormerlymostaccesssystemsusedMIFAREClassic,buttodaythesesystemshaveswitchedtoMIFAREDESFire
becausethisproducthasmoresecuritythanMIFAREClassic.
ByteLayout
https://en.wikipedia.org/wiki/MIFARE
6/25
28/10/2016
MIFAREWikipedia
bytelevellayoutofMiFarecards.
History
1994MIFAREClassic1Kcontactlesstechnologyintroduced.
1996FirsttransportschemeinSeoulusingMIFAREClassic1K.
1997MIFAREPROwithTripleDEScoprocessorintroduced.
1999MIFAREPROXwithPKIcoprocessorintroduced.
2001MIFAREUltraLightintroduced.
2002MIFAREDESFireintroduced,microprocessorbasedproduct.
2004MIFAREDESFireSAMintroduced,secureinfrastructurecounterpartofMIFAREDESFire.
2006MIFAREDESFireEV1isannouncedasthefirstproducttosupport128bitAES
2008MIFARE4MobileindustryGroupiscreated,consistingofleadingplayersintheNearField
Communication(NFC)ecosystem.
2008MIFAREPlusisannouncedasadropinreplacementforMIFAREClassicbasedon128bitAES
2008MIFAREUltralightCisintroducedaspaperticketICfeaturingTripleDESAuthentication
2010MIFARESAMAV2isintroducedassecurekeystorageforreadersAES,TripleDES,PKI
Authentication
2012MIFAREUltralightEV1introduced,backwardscompatibletoMIFAREUltralightbutwithextra
security.
2014MIFARESDKwasintroduced,allowingdeveloperstocreateanddeveloptheirownNFCAndroid
applications.
2014MIIFARESmartMX2theworldsfirstsecuresmartcardplatformwithMIFAREPlusandMIFARE
DESFireEV1withEAL50wasreleased
2015MIFAREPlusSEtheentrylevelversionofNXPsprovenandreliableMIFAREPlusproductfamily
wasintroduced.
2016MIFAREPlusEV1wasintroduced,theprovenmainstreamsmartcardproductcompatiblewith
MIFAREClassicinitsbackwardcompatiblesecuritylevel
2016MIFAREDESFireEV2isannouncedwithimprovedperformance,security&privacyandmulti
applicationsupport.
TheMIFAREproductportfoliowasdevelopedbyMikronthenamestandsforMIkronFAREcollectionSystem.It
wasacquiredbyPhilipsin1998.MikronsourcedsiliconfromAtmelintheUS,PhilipsintheNetherlands,and
SiemensinGermany.
InfineonTechnologies(thenSiemens)licensedMIFAREClassicfromMikronin1994[14]anddevelopedbothstand
aloneandintegrateddesignswithMIFAREproductfunctions.Infineoncurrentlyproducesvariousderivativesbased
onMIFAREClassicincluding1Kmemory(SLE66R35)andvariousmicrocontrollers(8bit(SLE66series),16bit
(SLE7xseries),and32bit(SLE97series)withMIFAREemulations,includingdevicesforuseinUSIMwithNear
FieldCommunication.[15]
MotorolatriedtodevelopMIFARElikechipforwiredlogicversionbutfinallygaveup.Theprojectexpectedone
millioncardspermonthforstart,butthatfellto100,000permonthjustbeforetheygaveuptheproject.[16]
https://en.wikipedia.org/wiki/MIFARE
7/25
28/10/2016
MIFAREWikipedia
In1998PhilipslicensedMIFAREClassictoHitachi[17]HitachilicensedMIFAREproductsforthedevelopmentofthe
contactlesssmartcardsolutionforNTT'sICtelephonecardwhichstartedin1999andfinishedin2006.IntheNTT
contactlessICtelephonecardproject,threepartiesjoined:TokinTamuraSiemens,Hitachi(Philipscontractfor
technicalsupport),andDenso(Motorolaonlyproduction).NTTaskedfortwoversionsofchip,i.e.wiredlogicchip
(likeMIFAREClassic)withsmallmemoryandbigmemorycapacity.Hitachidevelopedonlybigmemoryversionand
cutpartofthememorytofitforthesmallmemoryversion.
ThedealwithHitachiwasupgradedin2008byNXP(bythennolongerpartofPhilips)toincludeMIFAREPlusand
MIFAREDESFiretotherenamedsemiconductordivisionofHitachiRenesasTechnology.[18]
In2010NXPlicensedMIFAREproductstoGemalto.In2011NXPlicensedOberthurtouseMIFAREproductson
SIMcards.In2012NXPsignedanagreementwithGiesecke&DevrienttointegrateMIFAREapplicationsontheir
secureSIMproducts.TheselicenseesaredevelopingNearFieldCommunicationproducts[19][20]
SecurityofMIFAREClassic,MIFAREDESFireandMIFAREUltralight
TheencryptionusedbytheMIFAREClassiccardusesa48bitkey.[21]
ApresentationbyHenrykPltzandKarstenNohl[22]attheChaosCommunicationCongressinDecember2007
describedapartialreverseengineeringofthealgorithmusedintheMIFAREClassicchip.Abstractandslides[23]are
availableonline.ApaperthatdescribestheprocessofreverseengineeringthischipwaspublishedattheAugust2008
USENIXsecurityconference.[24]
InMarch2008theDigitalSecurity[25]researchgroupoftheRadboudUniversityNijmegenmadepublicthatthey
performedacompletereverseengineeringandwereabletocloneandmanipulatethecontentsofanOVChipkaart
whichisaMIFAREClassiccard.[26]FordemonstrationtheyusedtheProxmarkdevice,a125kHz/13.56MHz
researchinstrument.[27]TheschematicsandsoftwarearereleasedunderthefreeGNUGeneralPublicLicenseby
JonathanWesthuesin2007.Theydemonstrateitisevenpossibletoperformcardonlyattacksusingjustanordinary
stockcommercialNFCreaderincombinationwiththelibnfclibrary.
TheRadboudUniversitypublishedthreescientificpapersconcerningthesecurityoftheMIFAREClassic:
APracticalAttackontheMIFAREClassic(http://www.cs.ru.nl/~flaviog/publications/Attack.MIFARE.pdf)
DismantlingMIFAREClassic(http://www.cs.ru.nl/~flaviog/publications/Dismantling.Mifare.pdf)
WirelesslyPickpocketingaMIFAREClassicCard(http://www.cs.ru.nl/~flaviog/publications/Pickpocketing.Mif
are.pdf)
Inresponsetotheseattacks,theDutchMinisteroftheInteriorandKingdomRelationsstatedthattheywould
investigatewhethertheintroductionoftheDutchRijkspascouldbebroughtforwardfromQ4of2008.[28]
NXPtriedtostopthepublicationofthesecondarticlebyrequestingapreliminaryinjunction.However,theinjunction
wasdenied,withthecourtnotingthat,"Itshouldbeconsideredthatthepublicationofscientificstudiescarriesalotof
weightinademocraticsociety,asdoesinformingsocietyaboutseriousissuesinthechip,becauseitallowsfor
mitigatingoftherisks."[29][30]
BothindependentresearchresultsareconfirmedbythemanufacturerNXP.[31]Theseattacksonthecardsdidn'tstop
thefurtherintroductionofthecardastheonlyacceptedcardforallDutchpublictransporttheOVchipkaartcontinued
asnothinghappened[32]butinOctober2011thecompanyTLS,responsiblefortheOVChipkaartannouncedthatthe
newversionofthecardwillbebetterprotectedagainstfraud.[33]
https://en.wikipedia.org/wiki/MIFARE
8/25
28/10/2016
MIFAREWikipedia
TheMIFAREClassicencryptionCrypto1canbebrokeninabout200secondsonalaptop,[34]ifapprox.50bitsof
known(orchosen)keystreamareavailable.Thisattackrevealsthekeyfromsniffedtransactionsundercertain
(common)circumstancesand/orallowsanattackertolearnthekeybychallengingthereaderdevice.
Theattackproposedin[35]recoversthesecretkeyinabout40msonalaptop.Thisattackrequiresjustone(partial)
authenticationattemptwithalegitimatereader.
Additionallythereareanumberofattacksthatworkdirectlyonacardandwithoutthehelpofavalidreaderdevice.[36]
TheseattackshavebeenacknowledgedbyNXP.[37]InApril2009newandbettercardonlyattackonMIFAREClassic
hasbeenfound.ItwasfirstannouncedattheRumpsessionofEurocrypt2009.[38]Thisattackwaspresentedat
SECRYPT2009.[39]ThefulldescriptionofthislatestandfastestattacktodatecanalsobefoundintheIACRpreprint
archive.[40]Thenewattackimprovesbyafactorofmorethan10allpreviouscardonlyattacksonMIFAREClassic,
hasinstantrunningtime,anditdoesnotrequireacostlyprecomputation.Thenewattackallowstorecoverthesecret
keyofanysectorofMIFAREClassiccardviawirelessinteraction,withinabout300queriestothecard.Itcanthenbe
combinedwiththenestedauthenticationattackintheNijmegenOaklandpapertorecoversubsequentkeysalmost
instantly.BothattackscombinedandwiththerighthardwareequipmentsuchasProxmark3,oneshouldbeableto
cloneanyMIFAREClassiccardinnotmorethan10seconds.Thisismuchfasterthanpreviouslythought.
MIFAREDESFireAttacks
InNovember2010,securityresearchersfromtheRuhrUniversityreleasedapaperdetailinga'sidechannel'attack
againstMIFAREcards,includingtheDESFireEVandEV1cards.[41]ThepaperdemonstratedthatDESFirecards
couldbeeasilyclonedatacostofapproximately$25in'offtheshelf'hardware.Theauthorsassertedthatthisside
channelattackallowedMIFAREcardstobeclonedinapproximately100ms.Furthermore,thepaper'sauthorsincluded
hardwareschematicsfortheiroriginalcloningdevice,andhavesincemadecorrespondingsoftware,firmwareand
improvedhardwareschematicspubliclyavailableonGitHub.[42]
InOctober2011DavidOswaldandChristofPaarofRuhrUniversityinBochum,Germany,detailedhowtheywere
abletoconductasuccessful"sidechannel"attackagainstthecardusingequipmentthatcanbuiltfornearly$3,000.
called"BreakingMIFAREDESFireMF3ICD40:PowerAnalysisandTemplatesintheRealWorld,"[43]Theystated
thatSystemintegratorsshouldbeawareofthenewsecurityrisksthatarisefromthepresentedattacksandcanno
longerrelyonthemathematicalsecurityoftheused3DEScipher.Hence,inordertoavoid,e.g.manipulationor
cloningofsmartcardsusedinpaymentoraccesscontrolsolutions,properactionshavetobetaken:ontheonehand,
multilevelcountermeasuresinthebackendallowtominimizethethreateveniftheunderlyingRFIDplatformis
insecure,"Inastatement[44]NXPsaidthattheattackwouldbedifficulttoreplicateandthattheyhadalreadyplanned
todiscontinuethecardattheendof2011.NXPalsostated"Also,theimpactofasuccessfulattackdependsontheend
toendsystemsecuritydesignofeachindividualinfrastructureandwhetherdiversifiedkeysrecommendedbyNXP
arebeingused.Ifthisisthecase,astolenorlostcardcanbedisabledsimplybytheoperatordetectingthefraudand
blacklistingthecard,howeverthisoperationassumesthattheoperatorhasthosemechanismsimplemented.Thiswill
makeitevenhardertoreplicatetheattackwithacommercialpurpose,"
MIFAREUltralightAttack
InSeptember2012asecurityconsultancyIntrepidus[45]demonstratedattheEUSecWesteventinAmsterdam,[46]that
MIFAREUltralightbasedfarecardsintheNewJerseyandSanFranciscotransitsystemscanbemanipulatedusingan
Androidapplication,enablingtravelerstoresettheircardbalanceandtravelforfreeinatalkentitled"NFCForFree
RidesandRooms(onyourphone)".[47]Althoughnotadirectattackonthechipbutratherthereloadingofan
unprotectedregisteronthedevice,itallowshackerstoreplacevalueandshowthatthecardisvalidforuse.Thiscan
beovercomebyhavingacopyoftheregisteronlinesothatvaluescanbeanalysedandsuspectcardshotlisted.NXP
https://en.wikipedia.org/wiki/MIFARE
9/25
28/10/2016
MIFAREWikipedia
haverespondedbypointingoutthattheyhadintroducedtheMIFAREUltralightCin2008with3DESprotectionand
inNovember2012introducedtheMIFAREUltralightEV1[48]withthreedecrementonlycounterstofoilsuch
reloadingattacks.
Considerationsforsystemsintegration
Forsystemsbasedoncontactlesssmartcards(e.g.publictransportation),securityagainstfraudreliesonmany
components,ofwhichthecardisjustone.Typically,tominimizecosts,systemsintegratorswillchoosearelatively
cheapcardsuchasaMIFAREClassicandconcentratesecurityeffortsinthebackoffice.Additionalencryptiononthe
card,transactioncounters,andothermethodsknownincryptographyarethenemployedtomakeclonedcardsuseless,
oratleasttoenablethebackofficetodetectafraudulentcard,andputitonablacklist.Systemsthatworkwithonline
readersonly(i.e.,readerswithapermanentlinktothebackoffice)areeasiertoprotectthansystemsthathaveoffline
readersaswell,forwhichrealtimechecksarenotpossibleandblacklistscannotbeupdatedasfrequently.
Certification
AnotheraspectoffraudpreventionandcompatibilityguaranteeistheMIFARECertificatecalledtolifein1998
ensuringthecompatibilityofseveralcertifiedcardswithmultiplereadersofMIFAREtechnology.Withthis
certification,themainfocuswasplacedonthecontactlesscommunicationofthewirelessinterface,aswellasto
ensureproperimplementationofallthecommandsofMIFAREcardsandreaders.Thecertificationprocesswas
developedandcarriedoutbytheAustrianlaboratorycalledArsenalResearch.TodayArsenalTesthouseperformsthe
certificationtestsandprovidesthecertifiedproductsinanonlinedatabase.[49]
Seealso
RFID
Physicalsecurity
NFC
Smartcard
PlacesthatuseMIFAREproducts
Transportation
https://en.wikipedia.org/wiki/MIFARE
10/25
28/10/2016
MIFAREWikipedia
Cardname
Locality
Type
EYCONeBus
Argentina(Baha
Blanca)
Initiallyforuseinthelocalpublictransportforshort
MIFAREClassic andmediumdistances.Howeveritisexpectedthatin
1K
thecardwillbeusedfortaxis,andfurthermorepurchase
itemsinshops.
SUBEcard
Argentina(Buenos
Aires)
MIFAREClassic Usedforpublictransportsuchas:Metro,trainsand
1K
buses[50]
RedBus
Argentina(Crdoba, MIFAREClassic
Forpaymentofpublictransport.
Mendoza,Salta)
1K
TarjetaSin
Contacto
MIFARE
Argentina(Rosario) DESFireEV1
SAMV2[51]
AdelaideMetro
metroCard
Australia(Adelaide)
MIFARE
DESFireEV1
Details
Meansofpaymentforurbantransportandasof2015
paymentforpublicbicycles.
AdelaideMetronetwork(Bus,TrainandTram)[52]
TransLinkGocard Australia(Brisbane)
MIFAREClassic
UsedontheTransLinkpublictransportnetwork.
1K
ACTIONMyWay Australia(Canberra)
MIFAREClassic Formofelectronicticketingusedonpublictransport
1K
serviceswithinCanberra
MetroGreenCard Australia(Hobart)
MIFAREClassic Greencardsimplifiespublictransportbyactinglikea
4
digitalwallet.Usedonbusesandthemetro.
SmartRider
Australia(Perth)
WidelyusedacrosstheTransperthpublictransportin
MIFAREClassic
metropolitanPerth,aswellastheregionaltownbus
1K
services.Usedforpublicbus,trainandferryservices.
Opalcard
Australia(Sydney)
MIFARE
DESFireEV1
Isvalidonallbus,rail,lightrailandgovernmentferry
servicesinSydneyandsurroundingareassuchas
CentralCoast.
Myki
Australia(Victoria)
MIFARE
DESFire
Usedonpublictransportsuchas,trains,buses,trams
andcoachesinVictoria
Bakumetrocard
Azerbaijan(Baku)
MIFAREClassic
1K,MIFARE
ForuseonthesubwayridesontheBakuMetro.
[53]
PlusS1K
TRI
Brazil(PortoAlegre)
MIFAREClassic
UsedforthebusesandtrainsinPortoAlegre.
1K
BHTrans
Brazil(Belo
Horizonte)
MIFAREClassic
1K
RioCard
Brazil(Riode
Janeiro)
Bilhetenico
Brazil(SoPaulo)
Orovale
Brazil(Teresopolis)
Canbeusedonthebusesforthisarea.
Carte
Occasionnelle
(STM,RTC),
CarteSolo
Canada(Montral,
MIFARE
QubecandQubec,
Ultralight
Qubec)
SMTUsedonthebus,rapidtransit,taxibusand
paratransitinMontreal.RTCusedforbusservies,bus
rapidtransitandparatransitinQuebec.CarteSoloused
forthecommuterrailandexpressbusserviceinGreater
Montreal.
https://en.wikipedia.org/wiki/MIFARE
TheRioCardcanbeusedonallmodesofpublic
transportwithinRiobus,ferry,subwayandtrain.
Howeveritcanonlybeusedamaximumofeighttimes
aday
MIFAREClassic
Canbeusedonbuses,rapidtransitandthetrain.
1K
11/25
28/10/2016
Cardname
MIFAREWikipedia
Locality
Type
Details
MCard
Canada(St.John's)
MIFAREClassic
UsedontheMetrobusTransitsystem.[54]
1K
PrestoCard
Canada(Toronto,
Ottawaand
Hamilton,Ontario)
MIFARE
DESFire
CompassCard
Canada(Metro
Vancouver)
NXP'sMIFARE
DESFireEV1
Usedforpublictransit(TransLink).$6refundable
4K,MIFARE
[56]
Ultralight(single deposit.
use)[55]
PeggoCard
Canada(Winnipeg)
MIFARE
DESFireEV1
4K
Tarjeta
Metroval[57]
Chile(Valparaso)
MIFAREClassic ValparasoMetrousesathiscardasuniquepayment
1K
method
TarjetaBip!
Chile(Santiagode
Chile)
MIFAREClassic
1Kand4K(if
bankbipor
MetrodeSantiago,Transantiago[58]
universitybip
areused)
StrongLink
China(Beijing)
Yikatong
China(Beijing)
Usedonvariouspublictransportsystemsinthegreater
TorontoandHamiltonAreaandOttawa.Buses,trains,
rapidtransitandstreetcars
UsedontheWinnipegTransitsystem.
Canbeusedonthesubway,buses,taxisandinsome
cooperatingretailersandrestaurants.Thecardcanalso
beusedforBeijingsbicyclesharingsystem
YangChengTong China(Guangzhou)
Usedonthemetro,buses,taxisandferriesin
Guangzhouandthesurroundingareas.
Cvica
Colombia(Medellin)
Canbeusedfortravelonthesubway,cablecars,some
busroutesandinthenearfutureforthetram
BusCARD
Croatia(Split)
MIFAREClassic
Usedforpublictransport
1K
BuTra
Croatia(Osijek)
MIFAREClassic
Usedbytrams&busesandsocialIDidentification
1K
RijekaCityCard
Croatia(Rijeka)
MIFAREClassic
1K,MIFARE
Usedbybuses,parkingspaces,libraries,museums...
Ultralight
ZETCard
Croatia(Zagreb)
Canbeusedfortravelonallpublictransportnetworks
MIFAREClassic
inZagreb.Alsoentitlesyoutogetdiscountsatover150
1K
locationssuchasthemuseumandzoo.
InKarta
Czechrepublic
(nationwide)
MIFARE
DESFire,
MIFARE
DESFireEV1
,[59]Usedfortransportontrains,aimedatregulartrain
users.Usingthecardenables25%discountonfares.
Opencard
Czechrepublic
(Prague)
MIFARE
DESFireEV1
UsedfortravelonthepublictransportinPrague.As
wellaspaidparkingandlibraries.
https://en.wikipedia.org/wiki/MIFARE
12/25
28/10/2016
Cardname
MIFAREWikipedia
Locality
Type
Details
Ltaka
Czechrepublic
(Prague)
MIFARE
DESFireEV1
SuccessorofOpencard,usedmostlyforpublictransport
inPrague,canbealsousedinmunicipallibraries.It
cannotbeusedaselectronicwalletforparkingasits
predecessor.
Pardubickakarta
Czechrepublic
(Pardubice)
CardisissuedbyDPMPa.s.(Transportcompanyof
MIFAREClassic
Pardubice),canalsobeusedasatickettolocaltheatre,
4K
andusedbymanyschoolsinPardubiceforstudentIDs.
Rejsekort
Denmark
MIFAREClassic Canbeusedfortravelontrains,busesandmetroin
4K
Copenhagen.
hiskaart
Estonia(Tallinn)
MIFAREClassic
Canbeusedfortravelontrams,buses,trolleybusesin
Tallinn,aswellasothertownsinsidethecountry.
Bussikaart
Estonia(Tartu)
MIFARE
UltralightC
UsedforbustravelinTartu.Worksalsoinother
locationsaroundthecountry.
Matkakortti
Finland(Helsinki)
MIFARE
DESFire
Canbeusedwithallformsofpublictransportsystems
withinHelsinkiMetropolitanArea.[60]
Metromoney
Georgia(Tbilisi)
MIFAREClassic Usedinmunicipaltransport(metro,bus)andwhile
1K
travelingbyRikeNarikalaropeway.[61]
MTRCitySaver
HongKong
MIFARE
UltralightC
Oldercardsonly.NewcardsuseSonyFeliCaLiteS.
IndianRailways
India
MIFARE
DESFire
Indianrailways(fivemajorcities)
CardzMe
India(Karnataka)
Metro/BusCard
Iran(Tehran,
Isfahan)
MIFAREClassic Usedforpublictransport,MetroandBus(Tehran
1K
Metro)
ManCard
Iran(Mashhad)
MIFARE
DESFireEV1
SmartCard
Ireland(Dublin)
MIFAREClassic
UsedfortraintransportforIarnrdireann
1K
Leapcard
Ireland(Dublin)
MIFARE
replacestheindividualLuas,DartandDublinBus
[62]
smartcards
DESFireEV1
LuasSmartcard
Ireland(Dublin)
MIFAREClassic beingreplacedbytheLeapcard
DublinBusSmart
Ireland(Dublin)
card
MIFAREClassic beingreplacedbytheLeapcard
DARTSmartcard Ireland(Dublin)
MIFAREClassic beingreplacedbytheLeapcard
AltoAdige/Sdtirol Italy(TrentinoAlto
Pass
Adige/Sdtirol)
MIFARE
DESFireEV1
SouthernTirolnetwork(Bus,TrainandCablecars)[63]
Etalons
Latvia
MIFARE
Ultralight
Canbeusedtopayfareforbuses,tramsandtrolleybus.
Travelcard
Lithuania
MIFAREClassic Introducedinsummerof2013
Touch'nGo
Malaysia
https://en.wikipedia.org/wiki/MIFARE
IssuedtostudentsintheIndianstateofKarnatakaby
CardzMiddleEast
Usedforpublictransport(MetroandBus)andlowvalue
payments(suchasbakeries)(MashhadMetro)
UsedforpayingroadtollsontheExpressway,public
transport,andparking.
13/25
28/10/2016
MIFAREWikipedia
Cardname
Locality
Type
Details
ATHOPcard
NewZealand
(Auckland)
MIFARE
DESFireEV1
Introducedastheregionalintegratedticketingcard.The
previousbrandedHOPcardaka"Snapper/HOP"uses
theJCOPstandardandwasphasedoutofusein
Aucklandin2013.[64]
Kolumbuskort
Norway(Rogaland)
MIFARE
DESFireEV1
Bus,Boat.http://www.kolumbus.no
Ruterreisekort
Norway(Osloand
Akershus)
MIFARE
DESFireEV1
(MF3ICD41)
Bus,boat,tram,subwayandtrains.Ruter(http://ruter.n
o/)andNSB(http://nsb.no)
BiaostockaKarta
Poland(Biaystok)
Miejska
MIFAREClassic
Usedonbuses
1K
KrakowskaKarta
Miejska
MIFAREClassic
UsedontramsandbusesandasIDforKrakwCity
1K/MIFARE
Bikesystem
Plus2K
Poland(Krakw)
WarszawskaKarta
Poland(Warsaw)
Miejska
MIFAREClassic
Usedonbuses,trams,subwayandrailroad
1K
eBilet
Poland(Gdynia)
MIFAREClassic
Usedontrolleybusesandbuses
1K
RATBActiv
Romania
(Bucharest)
MIFAREClassic Usedonallpublicsurfacetransportationandalso
1K
availableforsubway
Russia(Moscow)
MIFARE
Standard,
MIFARE
Ultralight,
MIFAREPlus
Disposableticket,eWallet"TROIKA"
MoscowMetro
EMcard
Slovakia
MIFARE
DESFireEV1
Usedbyalmosteverypublictransportsystemin
SlovakiaandsomeinCzechRepublic.Inmostcases
onlyreferredtoasBCKBezkontaktncipovkarta
(contactlesssmartcard)
Urbana
Slovenia(Ljubljana)
MIFARE
DESFireEV1
Usedbybuses,parkingspaces,libraries,museums,the
LjubljanaCastlefunicular,sportsinstitutesandcultural
events.[65]
Upass
SouthKorea
MifareClassic
(Seoul/Metropolitan)
UsedbyMetro,bus,lightmetro,andairportlink.
Discontinuedin2014,replacedbyTmoney.
Daekyung
TransportCard
SouthKorea
(Daegu)
MifareClassic
MainlyusedbyDaeguMetro,Daegubusand
Gyeongsanbus.Discontinuedin2014(exceptseveral
DaeguBankBCdebitcards),replacedby
Toppass/Onepass.
Consorciode
Transportesde
Madrid
Spain(Madrid)
MIFARE
DESFireEV1
MF3ICD41
Metro,trainsandbuses
Resekortet
Sweden
MIFAREClassic
Travelticketforbusesandtrains.
1K[66]
SknetrafikenJoJo Sweden
MIFAREClassic
UsedforpublictransportinSkne
1K
Karlstadsbuss
MIFAREClassic
KarlstadsbussResekort
4K
Sweden
https://en.wikipedia.org/wiki/MIFARE
14/25
28/10/2016
Cardname
MIFAREWikipedia
Locality
Type
Details
Sweden
MIFAREClassic
Stockholmslokaltrafik(Stockholmpublictransit)
4K
Vsttrafik
Sweden
MIFAREClassic
1K/4K,MIFARE
Vsttrafikkortet
Plus,MIFARE
Ultralight
EasyCard
Taiwan
MIFARE
Classic,
MIFAREPlus[67]
KGSCard
Turkey
MIFAREClassic
1K,MIFARE
Plus2K(in
TollHighways,KGS(acronymforContactlessCard
Classic
TollSystem)
compatibility
mode)
Muzekart
Turkey
MIFAREClassic
1K,MIFARE
UsedasamuseumpassforIstanbulsvariousmuseums
Plus2K
Istanbulkart
Turkey(Istanbul)
MIFARE
DESFireEV1
Buses,ferryboats,metro,lightmetro,tramsand
overgroundtrains
MiFarePlus&
customcard
securing
Metro,bus,passengership
UsedonCardiffBusservices.
SLAccess
zmirimKart(2015) Turkey(Izmir)
Iffcard
UnitedKingdom
(Cardiff)
MIFARE
DESFireEV1
SmartTech
Production
HongKong
NXPMIFARE
Golden
Partner[68]
Oystercard
UnitedKingdom
(London)
MIFARE
DESFireEV1
EasyRider
UnitedKingdom
(Nottingham)
BreezeCard
UnitedStates
(Atlanta,Georgia)
CharlieCard
UnitedStates
(Boston,
Massachusetts)
METROQCard
UnitedStates
(Houston,Texas)
TransitAccess
Pass
MIFAREPlus
UnitedStates(Los SecurityLevel
Angeles,California) [70]
1
GoToCard
UnitedStates
(Minneapolis,
Minnesota)
https://en.wikipedia.org/wiki/MIFARE
MigratedfromMIFAREClassictoMIFAREDESFire
EV1in2011[69]
Canbeusedaspaymentforbusesorthetramon
NottinghamCityTransport
MIFARE
CanbeusedaspaymentforMATRARapidRailand
Ultralightand
MARTABus.
MIFAREClassic
MBTAv.AndersonCivilcaserelatedtotheresponsible
disclosureofflawsinthesystem
MIFAREClassic UsedforpaymentoftheMETRORail,METROBusand
1K
METROLift.
Usedaselectronicticketingformostpublictransport
withinLosAngelesCounty.
MIFAREClassic
1K
15/25
28/10/2016
Cardname
MIFAREWikipedia
Locality
Type
Details
ConnectCard
UnitedStates
(Pittsburgh,
Pennsylvania)
Clippercard
UnitedStates(San
MIFARE
FranciscoBayArea,
DESFire
California)
ReplacingTransLink,whichusedaMotorolaCard.[71]
PATHSmartLink
UnitedStates(New
York/NewJersey)
UsedasafarepaymentmethodonthePATHtransit
systeminNewark.
EasyCard
UnitedStates(South MIFARE
Florida,Florida)
Ultralight
CompassCard
UnitedStates(San
Diego)
MIFAREClassic Usedonbuses,trolleys,CoasterandSprintertrainsin
1K
SDMTSandNCTD
SmarTrip
UnitedStates
(Washington
MetropolitanArea,
Washington,D.C.)
MIFAREPlusX
UsedontheWashingtonMetropolitanAreaTransit
Authorityandneighbouringtransitsystems
RabbitCard
Thailand
MIFARE
DESFireEV1
UsedonBTSSkytrain,BangkokBRT,restaurants,
shopsandcinemasthatacceptRabbitCard
SmartPurse
Thailand
MIFAREClassic UsedonMetrobus(buses),7Eleven,shopsand
1K
restaurantsthatacceptSmartPurse
BangkokMetro
Smartcard
Thailand
MIFAREClassic
BangkokMetro
1K
MIFAREClassic
MIFARE
DESFire
UsedonMetrobus,Metrorail,TriRail,CityofHialeah
Transit,andConchitaTransitExpress.
ApplicationReferences
https://en.wikipedia.org/wiki/MIFARE
16/25
28/10/2016
Application
MIFAREWikipedia
Application
Category
Project
AutomaticFare
SmartMobility MoscowMetro
Collection
RoadTolling
SmartMobility Touch'n'Go
NXPPartner
SmartTechnologies
Moscow
Group
SmartTechnologies
Moscow
Group
AutomaticFare
SmartMobility TouchnGo
Collection
Campuscard
Parking
Parking
Mobile
Ticketing
Multiapplication
Egeniversitesi
includingaccess
SmartMobility NOL
RTA
SmartMobility
PayonFoot
system
Access
Gemalto,Giesecke
&Devrient,
MIFARE4Mobile Oberthur
Technologies,
STMicroelectronics
TouristCard
SmartMobility MobilisCard
TouristCard
SmartMobility OysterCard
https://en.wikipedia.org/wiki/MIFARE
Locality
Skidata
used
Product
Usecase
MIFARE
Ultralight
Contactless
smartcardsfor
paymentinthe
AFCSystemof
theMoscow
Metro[72]
MIFARE
Ultralight
Contactless
smartcardsfor
paymentinthe
AFCSystemof
theMoscow
Metro[72]
Kuala
Lumpur
Malaysiantoll
expresswayand
highway
operators
paymentsystem
zmir
Mifare
Classic
Controlled
accesscampus
entranceby
thesecards
Dubai
MIFARE
DESFire
EV1
Multiapplication
Cardinteralia
usedfor
parking[73]
Usedfor
cashless
vending
applicationsfor
parking[74]
Ireland
AgenciaValenciana
deMobilidad
Valencia
(aVM)
London
MIFARE
SmartMX
Accessto
buildings
through
Smartphone[75]
MIFARE
SmartMX
Touristcard,
bikerental,
electriccar
rental,transport
ticketing,taxi
card,access
management
andpayment
function[76]
MIFARE Usedforpublic
Classic1K transport[72]
17/25
28/10/2016
Application
FuelCard
MIFAREWikipedia
Application
Category
Project
SmartMobility Shell
FuelCard
SmartMobility PetrolOfisi
TaxiCard
SmartMobility
TaxiCard
NXPPartner
Plastkart
Plastkart
TouchTravel
Card
SmartMobility NOL
RTA
FerryCard
SmartMobility Opalcard
Carsharing
SmartMobility Car2Go
Bikerental
SmartMobility OVfiets
Bikerental
SmartMobility
Corporate
Access
Access
Bikerental
SmartMobility
HomeAccess
Access
AirKey
HomeAccess
Access
Immobilienfirma
Salto
TopInvestsrl
HotelAccess
Access
MarriottHotel
Card
Access
CampusCard
Universityof
Cambridge
Access
CampusCard
Universityof
Oxford
Campuscard
CampusCard
EventTicketing Access
https://en.wikipedia.org/wiki/MIFARE
Locality
used
Product
Turkey
Loyalty
MIFARE Programsat
Classic1K petrol
stations[77]
Turkey
Loyalty
MIFARE Programsat
Classic1K petrol
stations[78]
SriLanka
MIFARE
DESFire
EV1
Daimler
MIFARE
DESFire
EV1
Cardfor
Transportand
Ferry
services[72]
MIFARE
DESFire
EV1
UsedforCar
sharing[81]
Bikerental
smartcard
Netherlands
Bikerental[82]
Callock
Nestl
MIFARE
DESFire
EV1
KABA
FCKln
MIFARE
SmartMX
EVVA
MIFARE
Luxemburg DESFire
EV1
Mobile
Access[82]
SmartLockfor
Home
Access[84]
HotelAccess
Card[85]
KABA
PaymentSolutions
AccessSecurity
Solution[83]
Bikerental[82]
Callock
Salto
payment
solutionin
taxis[79]
Muliapplication
cardalsoused
forTaxi
payment[80]
Dubai
Sydney
Usecase
MIFARE
Cambridge,
DESFire
UK
EV1
Multiapplication
Campus
Card[86]
MIFARE
Oxford,UK DESFire
EV14K
Multiapplication
Campus
Card[87]
MIFARE
DESFire
EV1
Eventticketing
applicationfor
soccergames[88]
Kln,
Germany
18/25
28/10/2016
Application
MIFAREWikipedia
Application
Category
EventTicketing Access
Project
NXPPartner
TicketFIFA2014
Locality
used
Product
Usecase
Brazil
Eventticketing
forSoccer
WM[89]
Scotland,
UK
MIFARE
SmartMX
30different
services
(identity,
transport,
financialand
healthrelated
services...)[90]
Berlin,
Germany
MIFARE
DESFire
EV1
LibraryID[91]
Germany
MIFARE
DESFire
EV1
Cashless
Paymentfor
LibraryFees[82]
Access,loyalty
&Micro
Payments[92]
CitizenCard
Access
National
EntitlementCard
(NEC)
LibraryCard
Access
BerlinDietrich
Bonhoeffer
library
LibraryCard
Access
CityLibrary
Reutlingen
Amusement
Park
Access
TransdevStudio
BankMega
Makassar
MIFARE
DESFire
EV1
MuseumCard
Access
MzeKart
Mapikart,Trsab
Istanbul,
Turkey
MIFARE Accessto
Classic1K Museum[93]
Loyalty
ManchesterCity
FootballClub
Stadium
Gemalto
Membership
Card
Membership
Card
Bibliotheca
LoyaltyCard
Loyalty
RabbitCard
CarrotRewards
LoyaltyCard
Loyalty
TransStudio
BankMega
AmusementPark
NFCTags
NFC
NFCTag
Identification
EuropeanHealth
InsuranceCard
Identification
SesamVitale
card
HealthCard
HealthCard
https://en.wikipedia.org/wiki/MIFARE
Manchester
Access,Loyalty,
Membership,
Payment
function[94]
Bangkok,
Thailand
MIFARE
DESFire
EV1
Usedfor
Transport,
shops,
restaurants,
Identification,
Accesscontrol,
securityand
Carrot
Reward[95][96]
Indonesia
MIFARE
DESFire
EV1
TransStudio
Amusement
Park[97]
NFCenabled
Smartphones[98]
SMARTRAC
Europe
JCOP
Healthand
Identification
Card[99]
France
MIFARE
SmartMX
Healthand
Identification
Card[100]
19/25
28/10/2016
MIFAREWikipedia
Application
Application
Category
Digital
Signature
Identification
Micropayment
Micropayment
Project
Vingcard
Yeldi
NXPPartner
SmartPaper
Ticket
Banking
Banking
used
Product
Identiv
EKart,EKent,
Aktifbank
Usecase
Digital
Signatureused
forAccess[101]
AssaAbloy
Multiapplication
TouchTravel
Multiapplication
Card
Card
Multiapplication
Multiapplication Passolig(TFF)
Card
Locality
India
MIFARE
DESFire
EV1
Cashless
paymentsvia
mobile
phones[102]
SriLanka
MIFARE
DESFire
EV1
MIFARE
SAMAV2
Transport,
Micropayment,
Paymentfor
ShopsorTaxis,
NFCMobile
Ticketing[79]
Turkey
JCOP
MIFARE
DESFire
EV1
StadiumAccess
Ticketing,
Micropayment,
Payment,
Transport[103]
Moscow
Metropolitan
Card
SmartTechnologies Moscow,
Group
Russia
MIFARE
Ultralight
Usedfor
electronicsmart
paperticketing
inpublic
transport[104]
TouchTravel
Card
SriLanka
MIFARE
DESFire
EV1
Payment
Solution[105]
Institutions
NorthwestUniversity,SouthAfricaStudent/staffID,accesscontrol,library,studentmeals,sportapplications,
payments[106]
Linkopinguniversity,SwedenStudent/staffID,accesscontrol,library,copy/print,studentdiscount,payments
LondonSchoolofEconomicsAccesscontrol(UnprotectedMIFAREClassic1K)
NewCollegeSchoolinOxfordBuildingaccess.
ImperialCollegeLondonStaffandstudentIDaccesscardinLondon,UK.
CambridgeUniversity[107]Student/StaffIDandaccesscard,librarycard,canteenpaymentsinsome
colleges[108]
UniversityofWarwickStaffandstudentIDcardandseparateEatingatWarwickstoredvaluecardinCoventry,
UK.
Regent'sCollege,LondonStaffandstudentIDaccesscardinLondon,UK.
UniversityofNewSouthWalesStudentIDaccesscard.
UniversityofAlbertaStaffOneCardtrialcurrentlyunderway.
NorthumbriaUniversityStudent/Staffbuildingandprinteraccess.
CityUniversityofHongKongStudent/Staffbuilding,Library,AmenitiesBuilding.
HongKongInstituteofVocationalEducationStudentIDcard,attendance,library,printersandcomputers
access.
TheChineseUniversityofHongKongStudentIDcard,attendance,library,printersanddooraccesscontrol
UniversityofBayreuthStudentIDcardandcanteencardforpaying.
https://en.wikipedia.org/wiki/MIFARE
20/25
28/10/2016
MIFAREWikipedia
UniversityofIbadan,NigeriaStudentIDcardandExaminationVerificationandAttendance.(SolutionsColony
Ltd)
BOWENUniversity,Iwo,NigeriaStudentIDcardandExaminationVerificationandAttendance.(Solutions
ColonyLtd)
AfeBabalolaUniversity,AdoEkiti,NigeriaStudentIDcardandExaminationVerificationandAttendance.
(SolutionsColonyLtd)
AchieversUniversity,Owo,NigeriaStudentIDcardandExaminationVerificationandAttendance.(Solutions
ColonyLtd)
AdekunleAjasinUniversity,Akungba,OndoState,NigeriaStudentIDcardandExaminationVerificationand
Attendance.(SolutionsColonyLtd)
AuchiPolytechnic,Auchi,NigeriaStudentIDcardandExaminationVerificationandAttendance.(Solutions
ColonyLtd)
UniversityCollegeHospital,Ibadan(UCH),NigeriaStudentIDcardandStaffAttendance.(SolutionsColony
Ltd)
FederalUniversityofTechnology,Minna,NigerState(FUTM),NigeriaStudentIDcardandExamination
VerificationandAttendance.(SolutionsColonyLtd)
BensonIdahosaUniversity,BeninCity,EdoState(BIU),NigeriaStudentIDcardandExaminationVerification
andAttendance.(SolutionsColonyLtd)
FederalUniversityofTechnology,Akure,OndoState(FUTA),NigeriaStudentIDcardandExamination
VerificationandAttendance.(SolutionsColonyLtd)
CovenantUniversity,NigeriaStudentIDcardandExaminationVerificationandAttendance.(SolutionsColony
Ltd)
LeadCityUniversity,NigeriaStudentIDcardandExaminationVerificationandAttendance.(SolutionsColony
Ltd)
HogeschoolUniversiteitBrussel,BelgiumStudentIDcard,canteencardforpaying,libraryandbuilding
access.
SouthamptonUniversityStudentIDcard,libraryandbuildingaccessMIFAREClassic4K.
DelftUniversityofTechnology,NetherlandsStudent/StaffIDcard,staffcoffeemachines,lockers,printersand
buildingaccess.
EindhovenUniversityofTechnology,NetherlandsStudent/StaffIDcard,staffcoffeemachines,lockers,
printersandbuildingaccesscurrently(2016)rollingoutDESfireEV1.
DresdenUniversityofTechnology,GermanyBuildingaccess,canteencardforpayment
ChemnitzUniversityofTechnology,GermanyStudentIDcard
LeipzigUniversity,GermanyStudentIDcard,canteencardforpayment
FreibergUniversityofMiningandTechnology,GermanyStudent/StuffIDcard,buildingaccess,canteencard
forpayment
UniversityofJena,GermanyStudent/StaffIDcard,buildingaccess,canteencardforpayment
TechnicalUniversityofDenmark,DenmarkStudentIDcard,buildingaccess
UniversityofDuisburgEssen,GermanyStudent/StaffIDcard,libraryaccess,canteencardforpayment
DisneyInfinityfigureandpowerdiscbases
WaltDisneyWorldResortusedfortickets,DisneyDiningPlan,androomkeyaccess
UniversityofNorthamptonCarparkaccess,buildingaccessMIFAREClassic1K.
AssumptionUniversity(Thailand),ThailandStudent/StaffIDcard,libraryandcomputersaccess,canteen,
transportationandparkingpayment,electionverificationMIFAREClassic4K
ClaudeBernardUniversityLyon1StudentID,accesscontrol,library(unprotectedMIFARE1K)
UniversityofStrasbourgStudentID,accesscontrol(MIFARE1K)
AberystwythUniversityStudent/staffID,accesscontrol,library,copy/print,studentdiscount,payments,
buildingaccess(MIFAREClassic4K)
References
1.MIFARE(20091218)."ThesuccessofMIFARE".Mifare.net.
2."nfctags".Nfcphones.org.Retrieved5August2012.
3."nfctags".Nfcbrief.com.Retrieved11August2013.
4.[1](http://www.mifare.net/files/8413/5167/2490/MIFARE_Ultralight_EV1_.pdf)
https://en.wikipedia.org/wiki/MIFARE
21/25
28/10/2016
MIFAREWikipedia
5."AN11340:MIFAREUltralightandMIFAREUltralightEV1FeaturesandHints"(PDF).Nxp.com.20130301.Retrieved
20160209.
6.SomeISO/IEC78164commandsareusedbyMIFAREDESFireEV1,includingaproprietarymethodtowrapnative
MIFAREDESFirecommandsintoaISO/IEC7816APDU.
7."GermanResearchersCrackMifareRFIDEncryption".Slashdot.Retrieved20160209.
8."SecurityofMF3ICD40".Mifare.net.Retrieved20160209.
9.http://www.gemalto.com/products/hybrid_card_body/download/DESFire_EV1_vs_DESFire.pdf
10."Mifare".Mifare.20140620.Retrieved20160209.
11."NXPintroducesnewsecurityandperformancebenchmarkwithMIFAREPlus"(Pressrelease).NXP.20080310.
12."BlackHat'08:MIFARELittleSecurity,despiteObscurity"(PDF).Blackhat.com.Retrieved20160209.
13."MIFAREaworldofpossibilities"(PDF)(Pressrelease).NXP.
14."SiemensAndMikronAgreeLicensingDeal".Telecompaper.com.19940407.Retrieved20160209.
15."InfineonAddsSecurityandConveniencetoSIMCardsforNFCApplicationsInfineonTechnologies".Infineon.com.2007
1113.Retrieved20160209.
16."MotorolasetssmartcardtargetsCNET".News.cnet.com.19971015.Retrieved20160209.
17."SmartCardNews"(PDF).Smartcard.co.uk.19980201.Retrieved20160209.
18."NXPSemiconductors::MediaCenter".Nxp.com.Retrieved20160209.
19.[2](http://www.gemalto.com/press/archives/2010/20101125_NXP_Gemalto_MIFARE_License_en.pdf)Archived(https://we
b.archive.org/web/20101206130027/http://www.gemalto.com/press/archives/2010/20101125_NXP_Gemalto_MIFARE_Lice
nse_en.pdf)December6,2010,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
20."NXPSemiconductors::MediaCenter".Nxp.com.Retrieved20160209.
21."MIFAREClassic1Kspecification".20090222.
22.KarstenNohl."KarstenNohl,PhD:UniversityofVirginia,C.S.Dept".Cs.virginia.edu.Retrieved20160209.
23.Nohl,KarstenHenrykPltz."Mifare:LittleSecurity,DespiteObscurity".ChaosCommunicationCongress.
24.Nohl,KarstenDavidEvans(20080801)."ReverseEngineeringaCryptographicRFIDTag".Proceedingsofthe17th
USENIXSecuritySymposium.
25."DigitalsecurityDigitalSecurity".Ru.nl.20150708.Retrieved20160209.
26.DigitalSecurityGroup(20080312)."SecurityFlawinMifareClassic"(PDF).RadboudUniversityNijmegen.
27."Proxmark".Retrieved20110125.
28."DutchPage".Retrieved20120324.
29.ArnhemCourtJudgeServices(20080718)."Pronunciation,PrimaryClaim".RechtbankArnhem.
30."JudgedeniesNXP'sinjunctionagainstsecurityresearchers".TheStandard.20080718.Retrieved20100213.
31."mifare.net::Security".Retrieved20110125.
32.[3](http://www.idnee.nl/037%20OVchipkaart%20hoofdtekst.htm#voorbereidinggaatgewoondoor)Archived(https://web.arch
ive.org/web/20120608164142/http://www.idnee.nl/037%20OVchipkaart%20hoofdtekst.htm#voorbereidinggaatgewoondoor)
June8,2012,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
33."NieuweOVchipgaatfraudetegenWebwereld".Webwereld.nl.Retrieved20160209.
34.Courtois,NicolasT.KarstenNohlSeanO'Neil(20080414)."AlgebraicAttacksontheCrypto1StreamCipherinMiFare
ClassicandOysterCards".CryptologyePrintArchive.
35.Garcia,FlavioD.deKoningGans,GerhardMuijrers,RubenvanRossum,PeterVerdult,RoelSchreur,RonnyWichers
Jacobs,Bart(20081004)."DismantlingMIFAREClassic"(PDF).13thEuropeanSymposiumonResearchinComputer
Security(ESORICS2008),LNCS,Springer.
36.Garcia,FlavioD.PetervanRossumRoelVerdultRonnyWichersSchreur(20090317)."WirelesslyPickpocketinga
MifareClassicCard"(PDF).30thIEEESymposiumonSecurityandPrivacy(S&P2009),IEEE.
37.[4](http://mifare.net/security/mifare_classic.asp)
38.Courtois,NicolasT.(20090428)."ConditionalMultipleDifferentialAttackonMIFAREClassic"(PDF).Slidespresentedat
therumpsessionofEurocrypt2009conference.
39.Courtois,NicolasT.(20090707)."TheDarkSideofSecuritybyObscurityandCloningMiFareClassicRailandBuilding
PassesAnywhere,Anytime".InSECRYPT2009InternationalConferenceonSecurityandCryptography,toappear.
40.Courtois,NicolasT.(20090504)."TheDarkSideofSecuritybyObscurityandCloningMiFareClassicRailandBuilding
PassesAnywhere,Anytime".IACRCryptologyPreprintArchive.
41.TimoKasperIngovonMaurichDavidOswaldChristofPaar."CloningCryptographicRFIDCardsfor25$?"(PDF).
Proxmark.org.Retrieved20160209.
42."emsec/ChameleonMini:TheChameleonMiniisaversatilecontactlesssmartcardemulatorcomplianttoNFC,ISO14443and
ISO15693.IthasbeendesignedandmaintainedbytheChairforEmbeddedSecurityoftheRuhrUniversityinBochum.The
freelyprogrammableplatformcanbeusedtoemulateandvirtualizecards(perfectclonesincludingtheUID),forpractical
penetrationtestsinRFIDenvironments,orserveasapassivelyoperatedNFCdevice,e.g.,asanNFCdoorlock".GitHub.
Retrieved20160209.
https://en.wikipedia.org/wiki/MIFARE
22/25
28/10/2016
MIFAREWikipedia
43."BreakingMifareDESFireMF3ICD40:PowerAnalysisandTemplatesintheRealWorld"(PDF).Iacr.org.Retrieved
20160209.
44.[5](http://www.mifare.net/links/news/updateonmifaredesfiremf3icd40/)
45.[6](http://intrepidusgroup.com)Archived(https://web.archive.org/web/20121206021831/http://intrepidusgroup.com)
December6,2012,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
46."EUSecWestAppliedSecurityConference:Amsterdam,NL".Eusecwest.com.Retrieved20160209.
47."NFCsubwayhack".YouTube.20120920.Retrieved20160209.
48.[7](http://www.mifare.net/products/mifaresmartcardics/mifareultralightev1/)
49.http://arsenaltesthouse.com/certifiedmifareproducts/
50."SUBE".Sube.gob.ar.Retrieved20160209.
51."AdquisicindeunSistemadeBicicletasPblicasparaRosario"(PDF).ProyectodeTransporteSostenibleyCalidaddelAire
SecretaradeTransportedelMinisteriodelInterioryTransporteatravsdelaUnidadEjecutoradeProyecto(UEP).
2013.Archivedfromtheoriginal(PDF)on2013.
52.[8](http://www.adelaidemetro.com.au/ticketing/metrocard)Archived(https://web.archive.org/web/20120704235802/http://ww
w.adelaidemetro.com.au/ticketing/metrocard)July4,2012,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
53.LOTltd."Integrator'swebsite(subwaysolutions)".Lotgate.com.Retrieved20160209.
54.[9](http://www.metrobus.com/mcard.asp)Archived(https://web.archive.org/web/20120306144707/http://www.metrobus.com/
mcard.asp)March6,2012,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
55."NXPSemiconductors::MediaCenter".Nxp.com.Retrieved20160209.
56."TransLink:IfyoulikeFareSavers,you'llloveCompassCard"(PDF).Translink.ca.Retrieved20160209.
57."MetroValparaisoMediosdepago".Metrovalparaiso.cl.20140620.Retrieved20160209.
58."Tarjetabip!:".Tarjetabip.cl.Retrieved20160209.
59."eskdrhy,a.s.|vodnstrnka".Cd.cz.Retrieved20160209.
60.[10](http://www.hsl.fi/EN/ticketsandfares/ticketsontravelcard/Pages/default.aspx)Archived(https://web.archive.org/web/2011
1229063900/http://www.hsl.fi/EN/ticketsandfares/ticketsontravelcard/Pages/default.aspx)December29,2011,attheWayback
Machine. ThetemplateWaybackisbeingconsideredformerging.
61."MetromoneycardTbilisiTransportCompany".Ttc.com.ge.20120630.Retrieved20160209.
62."TripleRFIDcardscan".Docs.google.com.20120919.Retrieved20160209.
63."SdtirolMobil|MobilitAltoAdige".Sii.bz.it(inItalian).Retrieved20160209.
64.[11](https://www.snapper.co.nz/newsroom/2013/11/20/snappercontinuestofocusonthecustomerduringathoptransition)
Archived(https://web.archive.org/web/20140221084837/https://www.snapper.co.nz/newsroom/2013/11/20/snappercontinuest
ofocusonthecustomerduringathoptransition)February21,2014,attheWaybackMachine. ThetemplateWaybackisbeingconsidered
formerging.
65.[12](http://www.jhl.si/holding/urbana)Archived(https://web.archive.org/web/20120628213622/http://www.jhl.si/holding/urba
na)June28,2012,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
66.ResekortetiSverigeAB."RKFspecifikationenSvenskKollektivtrafik".Sevenskkollektivtrafik.se.Retrieved20160209.
67."ContactlessSmartcardTechnologyNeedsMoreSecurity"(PDF).Iis.sinica.edu.tw.Retrieved20160209.
68.SmartTechProduction."CardManufacturerNXPMifareGoldenPartner".
69.DanBalaban."TransportforLondontoDiscardMifareClassic|NFCTimesNearFieldCommunicationandallcontactless
technology".Nfctimes.com.Retrieved20160209.
70."L.A.MetroTapsNXP'sMIFAREPlusforContactlessTAPTicketing".EETimes.Retrieved20160209.
71."PageRedirection".Clippercard.com.Retrieved20160209.
72."SMARTTECHNOLOGIESGROUPMoscowMetro,AFC,contactlesssmartcards".Smartek.ru.Retrieved20160209.
73."MultiapplicationandmobileticketingbasedonMIFAREDESFireEV1".Mifare.net.20140620.Retrieved20160209.
74."CorkUniversityHospital".Apsparking.com.Retrieved20160209.
75."NXPEnablesMobileTicketingforSmartMobileDevices"(PDF).Nxprfid.com.Retrieved20160209.
76."ThesecretofValencia'scuttingedgecontactlessticketingsystem"(PDF).Avmm.es.Retrieved20160209.
77."PetrolLoyaltyCardFuelRewardsShellDrivers'ClubUK".Shellsmart.com.Retrieved20160209.
78."PositiveCard".Positivecard.com.tr.Retrieved20160209.
79."Orik:NewsandPressreleases".Orik.lk.Retrieved20160209.
80."Dubai,ASKrenewsagreementforcity'smultimodalticketingsystem".SecureIDNews.Retrieved20160209.
81."Car2Go|NFCDevelopment&Consulting".Nfc.cc.Retrieved20160209.
82.[13](http://calllock.com/en/menu1/Solutions/)Archived(https://web.archive.org/web/20140528010042/http://calllock.com/en/
menu1/Solutions/)May28,2014,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
83."TechproNestlCompletesElectronicSecurityInstallation".Techpro.vn.20130914.Retrieved20160209.
84.[14](http://saltosystems.de/index.php?option=com_content&task=view&id=365)
85."RFIDNewsRoundup".RFIDJournal.Retrieved20160209.
86."SALTOsecurestheUniversityofCambridge"(PDF).Godrejlocks.com.Retrieved20160209.
https://en.wikipedia.org/wiki/MIFARE
23/25
28/10/2016
MIFAREWikipedia
87.[15](http://www.ox.ac.uk/enewsletters/aad_news_alert/student_administration_and_services/25_06_12_new.html)Archived(h
ttps://web.archive.org/web/20140528010049/http://www.ox.ac.uk/enewsletters/aad_news_alert/student_administration_and_ser
vices/25_06_12_new.html)May28,2014,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
88."1.FCKlnImplementsPhilipsChipTechnologyForContactlessTicketing".Rfidsolutionsonline.com.20050115.
Retrieved20160209.
89."ArchivePicturesoftheFutureInnovationHomeSiemensGlobalWebsite".Siemens.com.Retrieved20160209.
90."NewsmartcardsolutionforScotland".MIFARE.20140620.Retrieved20160209.
91."BerlinslibrariesimplementRFIDmodernization".MIFARE.20140620.Retrieved20160209.
92."NXPandBankMegaenhancecustomerexperiencewithmultiapplicationsmartcardsolutionforindoorthemeparks".
MIFARE.20111214.Retrieved20160209.
93."Mzekart".Muzekart.com.Retrieved20160209.
94."SoccerFansUseRFIDCardstoGainAdmissionandBuyFood".RFIDJournal.Retrieved20160209.
95."
".Carrotrewards.co.th.Retrieved20160209.
96."CultureshockNews:NewRabbitCardBringseMoneySystemtoBangkok".Freepressrelease.com.Retrieved
20160209.
97."NXPSemiconductors::MediaCenter".Nxp.com.Retrieved20160209.
98.[16](http://www.nfctags.com/nfcapplicationswhichtag)Archived(https://web.archive.org/web/20140330235143/http://ww
w.nfctags.com/nfcapplicationswhichtag)March30,2014,attheWaybackMachine. ThetemplateWaybackisbeingconsideredformerging.
99.[17](http://www.mifare.net/files/7113/4978/9303/NXP_JCOP.pdf)
100.[18](http://www.cn.nxp.com/documents/literature/75015874.pdf)Archived(https://web.archive.org/web/20140527214740/htt
p://www.cn.nxp.com/documents/literature/75015874.pdf)May27,2014,attheWaybackMachine. ThetemplateWaybackisbeing
consideredformerging.
101."VingCardSignatureRFIDASSAABLOYHospitality(VingCardElsafe)Electronichotellocks".VingCardElsafe.
Retrieved20160209.
102."YeldiselectsIdentiveandNXPforNFCcashlesspaymentsolutioninIndia|20121015".MicrowaveJournal.20121015.
Retrieved20160209.
103.EBiletSresiniUzat."SporveElenceDnyasnnAnahtar".Passolig.com.tr.Retrieved20160209.
104."NXPSemiconductors::MediaCenter".Nxp.com.Retrieved20160209.
105."Mifare".Mifare.20140620.Retrieved20160209.
106."NorthWestUniversity".NWU.20160128.Retrieved20160209.
107."ComputerLaboratory:Accessandsecurity".Cl.cam.ac.uk.Retrieved20160209.
108."WelcometoClareCollegeClareCollegeCambridge".Clare.cam.ac.uk.Retrieved20160209.
Furtherreading
Dayal,Geeta,"Howtheyhackedit:TheMiFareRFIDcrackexplainedAlookattheresearchbehindthechip
compromise(http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9069558
&pageNumber=1),Computerworld,March19,2008.
Externallinks
Officialwebsite(http://www.mifare.net/)
24C3TalkaboutMIFAREClassic(http://dewy.fem.tuilmenau.de/CCC/24C3/matroska/24c32378enmifare_se
curity.mkv)Videoofthe24C3TalkpresentingtheresultsofreverseengineeringtheMIFAREClassicfamily,
raisingserioussecurityconcerns
Presentationof24thChaosComputerCongressinBerlin(http://video.google.com/videoplay?docid=425236768
0974396650&hl=en)ClaimingthattheMIFAREclassicchipispossiblynotsafe
DemonstrationofanactualattackonMIFAREClassic(http://www.ru.nl/ds/research/rfid/)(abuildingaccess
controlsystem)bytheRadboudUniversityNijmegen.
Retrievedfrom"https://en.wikipedia.org/w/index.php?title=MIFARE&oldid=745476698"
Categories: Contactlesssmartcards NearFieldCommunications
https://en.wikipedia.org/wiki/MIFARE
24/25
28/10/2016
MIFAREWikipedia
Thispagewaslastmodifiedon21October2016,at10:43.
TextisavailableundertheCreativeCommonsAttributionShareAlikeLicenseadditionaltermsmayapply.By
usingthissite,youagreetotheTermsofUseandPrivacyPolicy.Wikipediaisaregisteredtrademarkofthe
WikimediaFoundation,Inc.,anonprofitorganization.
https://en.wikipedia.org/wiki/MIFARE
25/25