MIFARE
Smart Cards & RFID · 7 specs
Direct Answer
MIFARE is a proprietary contactless smart card technology developed by Mikron (now NXP Semiconductors) conforming to ISO/IEC 14443 Type A. Spanning MIFARE Classic, Ultralight, Plus, and DESFire EV1/2/3, it is widely cited by NXP and industry sources as the world's most widely deployed contactless smart card platform for transit ticketing and access control.
Source: NXP Semiconductors / ISO/IEC 14443-A · Last reviewed Aug 28, 2026
Specs
| Frequency Bands | 13.56 MHz |
| Standard Compliance | ISO/IEC 14443-A (Parts 1–4 for DESFire/Plus) |
| Communication Rate | 106 to 848 kbps |
| Typical Read Range | 2.5 to 10 cm |
| Primary Variants | Classic (1K/4K), Ultralight, Plus, DESFire EV1/EV2/EV3 |
| Security Ciphers | Crypto-1 (Classic, Broken), AES-128 (Plus/DESFire), 3DES (DESFire EV1) |
| Common Criteria Certification | EAL5+ (DESFire EV2/EV3) |
Product Family Architecture
The MIFARE portfolio is structured into distinct tiers:
- MIFARE Classic (1K/4K): Segmented into 16 or 40 sectors protected by dual 48-bit keys using the proprietary Crypto-1 stream cipher.
- MIFARE Ultralight: Low-cost memory tag (64 to 144 bytes) without cryptographic mutual authentication, common in single-use transit tickets.
- MIFARE Plus: Drop-in replacement for Classic offering AES-128 authentication across Security Levels (SL1 to SL3).
- MIFARE DESFire: Advanced smart card with a flexible file system, DES/3DES/AES hardware crypto engines, and Common Criteria EAL5+ security.
The 2008 Crypto-1 Cryptanalytic Break
In 2008, researchers reverse-engineered the silicon of MIFARE Classic and published practical attacks (DarkSide, Nested, Hardnested) against Crypto-1. Due to weak random number generation and a 48-bit key space, all sectors of a MIFARE Classic card can be recovered in seconds using consumer Proxmark or Flipper Zero hardware, driving modern deployments toward MIFARE DESFire EV3.