Select your language

The ICODE DNA is the cryptographic member of the ICODE family from NXP Semiconductors, designed for brand protection and the fight against counterfeiting: consumer goods, high-value assets, documents, ski ticketing. Compliant with the ISO/IEC 15693 standard (known as vicinity) and compatible with the NFC Forum Type 5 format, it combines the long range of the family with AES-128 authentication performed by a dedicated coprocessor, with three user keys carrying separate privileges. It can be read and written by the vast majority of recent NFC smartphones.

Information

Manufacturer NXP Semiconductors
Family ICODE (cryptographic member)
Reference SL2S6002
Standard ISO/IEC 15693 (vicinity cards)
NFC Forum type Type 5 Tag compatible
Operating frequency 13.56 MHz
Data rate Up to 53 kbit/s
Unique identifier (UID) 8 bytes (64 bits), factory programmed
Encryption AES-128 with a dedicated coprocessor
Keys 3 user keys of 128 bits and 1 NXP key
Originality signature 32 bytes (ECC), customizable
Operating distance Up to 1.5 m with a long-range reader; a few centimeters with a smartphone
Data retention 50 years
Write endurance 100,000 cycles
Addressable memory (EEPROM) 256 bytes (2,048 bits)
User memory 252 bytes
Counter 16 bits, in the last block

Memory

The addressable memory of the ICODE DNA is organized into 64 blocks of 4 bytes: the first 63 form the user memory, the last one is reserved for the counter. A separate 48-block configuration area, accessible only through the Read Config and Write Config commands, hosts the AES keys, the privileges and the originality signature:

Area Content Access
Configuration area (48 blocks) AES keys and privileges, originality signature, customer ID, security settings Reserved for the dedicated configuration commands
Blocks 0 to 62 User memory (252 bytes) Read / write, lockable block by block, protectable through authentication
Block 63 16-bit counter and its protection indicator Read; increment through a write, preset protected by mutual authentication

In practice, the 252 bytes of user memory can hold an NDEF record containing a URL of around 230 characters, once the Capability Container (written into the first block during formatting) and the NDEF envelope are taken into account, with the common prefix (https://www. for example) compressed into a single byte. Enough for a link enriched with parameters, for example to associate each tag with an online authenticity check.

Features & security

  • AES-128 authentication: a dedicated coprocessor performs tag authentication (proving the chip is genuine through a challenge-response) and mutual authentication, which also verifies the reader's rights before opening access to protected data or features, all within the ISO/IEC 15693 protocol. A configurable authentication limit slows down brute-force attacks.
  • Three keys with privileges: three 128-bit user keys, each carrying chosen privileges (read, write, privacy, destroy, EAS/AFI or crypto configuration) to distribute roles between brand, logistics and application; a fourth key, programmed by NXP, is used for original tag authentication.
  • Customizable originality signature: a 32-byte signature based on elliptic curve cryptography is pre-programmed by NXP; it can be replaced with an application-specific signature during personalization, then permanently locked.
  • Memory segmentation and protection: the user memory can be segmented into areas with distinct access conditions, where reading or writing may require mutual authentication; the classic block-by-block locking (including AFI, DSFID and EAS) remains available.
  • 16-bit counter: located in the last block, it is incremented by one with a simple write, its preset being protected by mutual authentication (useful for counting uses or service cycles).
  • Privacy, destroy, EAS and AFI: the privacy and destroy modes as well as the EAS anti-theft and AFI filtering features are protected by mutual authentication, and the persistent quiet mode speeds up the inventory of large tag populations.

At delivery, the user memory is not protected: the chip reads and writes like a classic Type 5 tag, with AES security activated during personalization. The chip comes in a single antenna tuning version at 23.5 pF (reference SL2S6002).

Compatibility

The ICODE DNA uses NFC-V technology (ISO/IEC 15693), supported by the vast majority of recent NFC smartphones. On Android, reading and writing work natively with NFC Tools, without any particular restriction. On iPhone, automatic background reading is available from the iPhone XS and XR onwards; models from the iPhone 7 can read and write the chip via NFC Tools on iOS 15.6 or later, by starting the scan manually from the app.

With NFC Tools, the ICODE DNA chip supports reading technical information, writing records, erasing and permanent locking. The cryptographic configuration (AES keys, privileges, segmentation) requires specialized encoding through the chip's dedicated commands. The list of compatible models is available in the article on compatibility.

ICODE SLIX2 vs ICODE DNA

Chip User memory Security Typical use
ICODE SLIX2 316 bytes Five 32-bit passwords, signature, counter The password-based flagship
ICODE DNA 252 bytes AES-128 authentication, three keys with privileges, signature, counter Cryptographic brand protection

Both chips share the ISO/IEC 15693 protocol, the long range, the counter, the persistent quiet mode and the 50-year data retention. The SLIX2 offers more memory with password-based security; the DNA trades a few bytes for AES authentication that cannot be replayed (the choice whenever product authenticity is at stake). In close-range NFC, the NTAG 424 DNA plays the same role in the Type 4 format.

Frequently asked questions

How much data can be stored on an ICODE DNA?

The chip has 252 bytes of user memory, which corresponds to a URL of around 230 characters once the Capability Container and the NDEF envelope are taken into account, with the last block reserved for the counter.

What does AES authentication bring compared with the passwords of the SLIX generation?

Authentication relies on a challenge-response: the secret is never transmitted and each session uses a fresh random number, which defeats eavesdropping and replay. Mutual authentication additionally verifies the reader's rights. Passwords provide access control, not cryptographic proof of authenticity.

Is the ICODE DNA compatible with iPhones?

Yes. Background reading works from the iPhone XS and XR onwards, and both reading and writing are possible via NFC Tools from the iPhone 7 on iOS 15.6 or later.

Can an ICODE DNA be protected against rewriting?

Yes, in two ways: a permanent, irreversible block-by-block lock, including from NFC Tools, or write protection tied to mutual authentication, reversible by the holder of the relevant AES key.

 

About

Creator of innovative solutions
Android | iOS | Web | NFC

Keep in touch