The EM4333 holds a special place in the catalog of the Swiss manufacturer EM Microelectronic (a Swatch Group company): it is not a simple memory tag but a programmable contactless smart card, presented at its launch as the first to bring together the vicinity (ISO/IEC 15693) and proximity (ISO/IEC 14443A) protocols on a single chip and a single antenna. Designed for secure access control, public transportation, loyalty cards, electronic door locks and leisure parks, it embeds an 8051-compatible microcontroller, 4 kB of data shared between the two protocols and 64 kB of code for its embedded system, all defended by the Grain-128A and AES-128 ciphers.
Information
| Manufacturer | EM Microelectronic |
| Family | EM4333 (contactless smart card) |
| Reference | EM4333 |
| Standards | ISO/IEC 15693 and ISO/IEC 14443A (dual interface, single antenna) |
| NFC Forum type | Depends on the embedded software (ISO 15693 interface readable as NFC-V) |
| Operating frequency | 13.56 MHz |
| Data rate | Up to 848 kbit/s (ISO 14443A); 26 kbit/s (ISO 15693) |
| Identifiers | 8-byte UID (ISO 15693) and 7-byte UID (ISO 14443A); optional Random ID |
| Processor | 8051-compatible microcontroller, up to 30 MHz |
| Operating distance | Long range in ISO 15693; a few centimeters in ISO 14443A |
| Activation field | 0.05 A/m (ISO 15693); 0.5 A/m (ISO 14443A) |
| Memory | 4 kB of shared data, plus 64 kB of code |
Memory
The memory of the EM4333 reflects its dual nature as a smart card and a vicinity transponder:
| Area | Content | Access |
|---|---|---|
| User data (4 kB) | EEPROM shared between the two protocols | Controlled access (size exposed in ISO 15693 configurable, administration mode) |
| Code (64 kB) | The card's operating system and static data (pictures, for example) | Accessible through the ISO 14443A interface |
| Identifiers | 8-byte ISO 15693 UID and 7-byte ISO 14443A UID | Set at the factory; Random ID can be enabled for privacy |
Both worlds read the same data: a vicinity application (an ISO 15693 gate) and a proximity application (an ISO 14443A validator) access the same content, on the same card. The share of memory visible on the ISO 15693 side is configurable, and the whole is managed according to the secure access modes defined by the issuer.
Features & security
- Two protocols, a single antenna: an auto-detection mechanism recognizes, command by command, whether the reader speaks ISO/IEC 15693 or ISO/IEC 14443A; a field strength check only starts the proximity part in strong fields, keeping the long range of the vicinity side intact.
- A programmable core: the ISO 14443A part is driven by an 8051-compatible microcontroller (an accelerated architecture with 16-bit performance, up to 30 MHz, DMA for radio transfers): the card becomes whatever its software decides, developed in the Keil environment with EM's EMX43 emulator.
- Two-stage cryptography: the Grain-128A stream cipher (128-bit key) secures the ISO 15693 interface with three-pass mutual authentication and a message authentication code; on the processor side, AES-128 and DES/3-DES coprocessors serve the card's applications.
- Shared memory: the 4 kB of data are seen by both protocols, and the 64 kB of code host the system and static content: enough for a real badge or ticketing system.
- Privacy: the Random ID, when enabled, replaces the fixed identifier with a random value to prevent tracking of the holder.
- Low power: the card operates from 0.05 A/m in ISO 15693 and 0.5 A/m in ISO 14443A, a guarantee of range and reliability at the gates.
The ISO 15693 part is hardwired logic (it responds without the processor), while the ISO 14443A part lives under the control of the embedded software. The full datasheet is released by EM on request, with its public fact sheet summarizing the essentials.
Compatibility
The EM4333 is a programmable smart card: its behavior towards a smartphone depends on the software embedded by the card's issuer. Its ISO/IEC 15693 interface relies on NFC-V technology, which recent NFC smartphones can address: NFC Tools can then display the card's technical information, on Android as on iPhone (manual reading through the app from the iPhone 7 on iOS 15.6 or later). The ISO/IEC 14443A interface, driven by the processor, responds according to the loaded operating system.
Consumer NDEF encoding is not this chip's vocation: it lives in closed systems (access badges, transport tickets, electronic locks), deployed with their readers and applications. For a tag meant for smartphones, the NTAG213 or ST25TA are the way to go. The list of compatible models is available in the article on compatibility.
EM4333 vs EM4237
| Chip | Memory | Security | Positioning |
|---|---|---|---|
| EM4333 | 4 kB shared, plus 64 kB of code | Grain-128A, AES-128, programmable processor | Closed-system cards (access, transport) |
| EM4237SLIC / SLIX | 128 or 256 bytes | 32-bit password, EAS, privacy, destroy | Labels and memory tags |
Tag or card: that is the question. The EM4237 labels objects and talks to smartphones, while the EM4333 embodies the badge or transport ticket of a closed system, with its processor, its embedded system and its dual interface. On the NXP side, the MIFARE DESFire family covers the secure card segment; for a consumer tag, the NTAG213 remains the reference.
Frequently asked questions
How much data can be stored on an EM4333?
The card offers 4 kB of user data, shared between the ISO 15693 and ISO 14443A interfaces, plus 64 kB of code memory hosting the operating system and the issuer's static content.
What is the dual interface of the EM4333 for?
Making the same card live in two worlds: the long-range gates and inventories of the vicinity side (ISO 15693) and the fast validators of the proximity side (ISO 14443A, up to 848 kbit/s), which access the same data. Auto-detection recognizes the protocol command by command, and the proximity part only wakes up in strong fields so as to cost nothing in range.
Is the EM4333 compatible with smartphones?
Partially, and depending on the embedded software: the ISO 15693 interface can be addressed as NFC-V (NFC Tools then displays the technical information, including on iPhone through manual reading), while the ISO 14443A interface responds according to the system loaded by the issuer. It is not a consumer NDEF tag.
How is the memory of the EM4333 protected?
Through the mechanisms defined by the issuer: controlled access and an administration mode, a configurable memory size exposed in ISO 15693, Grain-128A mutual authentication with MAC on the vicinity side, and AES-128 and DES/3-DES coprocessors serving the embedded system on the proximity side.
Useful links
