The MIFARE DESFire EV1 is the multi-application smart card chip from NXP Semiconductors, certified Common Criteria EAL4+, designed for demanding systems: public transport, secure access management, closed-loop payment, event ticketing and government applications. Compliant with all four levels of the ISO/IEC 14443A standard and compatible with the NFC Forum Type 4 format, it organizes its 2, 4 or 8 kB memory as a true file system, protected by a hardware 3DES and AES cryptographic engine. It can be read and written by the vast majority of recent NFC smartphones.
Information
| Manufacturer | NXP Semiconductors |
| Family | MIFARE DESFire |
| References | MF3ICD21, MF3ICD41 and MF3ICD81 (2, 4 and 8 kB) |
| Standard | ISO/IEC 14443A (levels 1 to 4) |
| Protocol | ISO/IEC 7816-4 APDU |
| NFC Forum type | Type 4 Tag compatible |
| Operating frequency | 13.56 MHz |
| Data rate | 106 to 848 kbit/s |
| Unique identifier (UID) | 7 bytes, factory programmed; optional Random ID |
| Encryption | DES, 2K3DES, 3K3DES and AES-128 (hardware engine) |
| Certification | Common Criteria EAL4+ (hardware and software) |
| Operating distance | A few centimeters (up to 100 mm depending on the antenna) |
| Data retention | 10 years |
| Write endurance | 500,000 cycles (typical value) |
| Memory | 2, 4 or 8 kB depending on the version |
Memory
The memory of the MIFARE DESFire EV1 is not organized into fixed blocks but as a hierarchical file system, whose structure is freely defined during personalization:
| Level | Role | Security |
|---|---|---|
| Card (PICC) | General settings, management of free memory and applications | Card master key |
| Applications (up to 28) | Isolated containers, identified by a 3-byte AID | Up to 14 keys per application |
| Files (up to 32 per application) | Five types: standard data, backup data, value, linear record, cyclic record | Access rights defined file by file |
The size of each file is set at its creation, allowing the card to be precisely tailored to each project. Used as an NFC Forum Type 4 tag, the chip hosts an NDEF application whose file can occupy almost the entire memory: nearly 1,900 URL characters on the 2 kB version, and far more on the 4 and 8 kB versions. Capacity stops being a constraint (enough for a complete vCard or several combined records).
Features & security
- Mutual authentication and encrypted channel: a three-pass mutual authentication (in DES, 2K3DES, 3K3DES or AES-128, executed by a hardware cryptographic engine) generates a unique session key; exchanges can then be signed with an 8-byte CMAC or fully encrypted over the radio channel.
- Multi-application file system: up to 28 isolated applications, each with its own keys and up to 32 files; a single card can combine transport, access control and loyalty without the issuers sharing their secrets.
- Five file types: standard or backup data files, value files with controlled credit and debit, linear and cyclic record files (the latter automatically overwriting the oldest entries, perfect for transaction history).
- Atomic transactions: an anti-tearing mechanism validates or cancels all the writes of a transaction as one unit, and an automatic rollback protects the file structure: the card never remains in an inconsistent state, even when removed from the field mid-operation.
- Random ID and key diversification: the optional random identifier prevents card tracking, and deriving card-unique keys from the UID strengthens resistance to cloning.
- EAL4+ certification: both hardware and embedded software are Common Criteria EAL4+ certified, with exception sensors and countermeasures against power analysis.
The DES modes and the compatibility with the first DESFire (MF3ICD40) remain for existing fleets; AES-128 is the recommended choice for any new deployment. The chip comes in two antenna capacitances, 17 pF and 70 pF (MF3ICDH references for small form factors). The MIFARE DESFire EV2 and EV3 continue the line with extended features.
Compatibility
The MIFARE DESFire EV1 uses NFC-A technology (ISO/IEC 14443A), supported by the vast majority of recent NFC smartphones. On Android, reading and writing work natively with NFC Tools, without any particular restriction. On iPhone, automatic background reading is available from the iPhone XS and XR onwards; models from the iPhone 7 can read and write the chip via NFC Tools on iOS 15.6 or later, by starting the scan manually from the app.
With NFC Tools, the chip supports reading technical information as well as reading and writing NDEF records once the card is formatted as Type 4 (blank cards delivered with factory keys can be prepared during the first write). Creating applications, managing keys and fine-tuning the files require specialized encoding through the chip's dedicated commands. The list of compatible models is available in the article on compatibility.
MIFARE DESFire EV1: 2 kB, 4 kB or 8 kB
| Version | Memory | Typical use |
|---|---|---|
| MF3ICD21 | 2 kB | Ticketing and single-application access control |
| MF3ICD41 | 4 kB | Multi-service cards: transport, access, loyalty |
| MF3ICD81 | 8 kB | Rich deployments, numerous applications |
The three versions share strictly the same command set, the same security and the same performance: only the memory and the antenna capacitance vary. For new projects, the MIFARE DESFire EV2 and EV3 extend the line; on the consumer NFC tag side, the NTAG 424 DNA offers AES authentication in a sticker format.
Frequently asked questions
How much data can be stored on a MIFARE DESFire EV1?
The card offers 2, 4 or 8 kB distributed into freely sized files. Used as a Type 4 tag, it dedicates almost all of its memory to the NDEF file, which corresponds to nearly 1,900 URL characters on the 2 kB version (far beyond common needs).
What is the difference between MIFARE DESFire EV1 and MIFARE Classic?
The MIFARE Classic relies on the proprietary Crypto1 cipher, which is old and whose weaknesses are publicly documented. The DESFire EV1 builds on open standards (3DES and AES-128), mutual authentication with session keys and a Common Criteria EAL4+ certification.
Is the MIFARE DESFire EV1 compatible with iPhones?
Yes. Background reading works from the iPhone XS and XR onwards, and both reading and writing are possible via NFC Tools from the iPhone 7 on iOS 15.6 or later.
Can a MIFARE DESFire EV1 be protected against rewriting?
Protection relies on the keys: each file defines its read and write access rights, which can require authentication or be set to "never" (writing then becomes permanently impossible). There is no OTP-bit locking as on NTAG chips: everything is configured through the access rights.
Useful links
