The MIFARE DESFire EV3 is the fourth generation of the MIFARE DESFire family from NXP Semiconductors, certified Common Criteria EAL5+ and backward compatible with all previous generations. Designed for smart city services (public transport, access management, micro-payment and loyalty, student ID, road tolling and parking, ticketing), it introduces the SUN message, a dynamic NDEF cryptographically authenticated at every tap, along with the Transaction Timer against man-in-the-middle attacks. Compliant with all four levels of the ISO/IEC 14443A standard and certified NFC Forum Type 4 Tag, it can be read and written by the vast majority of recent NFC smartphones.
Information
| Manufacturer | NXP Semiconductors |
| Family | MIFARE DESFire (fourth generation) |
| References | MF3Dx3 and MF3DHx3 (from 2 to 16 kB) |
| Standard | ISO/IEC 14443A (levels 1 to 4) |
| Protocol | ISO/IEC 7816-4 APDU and file structure |
| NFC Forum type | Certified Type 4 Tag |
| Operating frequency | 13.56 MHz |
| Data rate | 106 to 848 kbit/s |
| Unique identifier (UID) | 7 bytes, factory programmed; optional Random ID |
| Encryption | DES, 2K3DES, 3K3DES and AES-128 (hardware engine) |
| Certification | Common Criteria EAL5+ (hardware and software) |
| Operating distance | A few centimeters (up to 100 mm depending on the antenna) |
| Data retention | 25 years |
| Write endurance | 1,000,000 cycles (typical value) |
| Memory | 2, 4, 8 or 16 kB depending on the version |
Memory
The memory of the MIFARE DESFire EV3 is organized as a hierarchical file system, with no fixed limit on the number of applications, whose structure is freely defined during personalization:
| Level | Role | Security |
|---|---|---|
| Card (PICC) | General settings, management of free memory and applications | Card master key |
| Applications (no fixed limit) | Isolated containers, identified by a 3-byte AID and an optional ISO name | Up to 14 keys and 16 key sets per application |
| Files (up to 32 per application) | Six types: standard data, backup data, value, linear record, cyclic record, Transaction MAC | Access rights per file, up to 8 keys per right |
The number of applications is limited only by the available memory (from 2 to 16 kB depending on the version) and the size of each file is set at its creation. Used as an NFC Forum Type 4 tag, the chip hosts an NDEF application whose file can occupy almost the entire memory: nearly 1,900 URL characters on the 2 kB version. With Secure Dynamic Messaging, this NDEF can also carry changing data, authenticated at every read.
Features & security
- SUN message and dynamic NDEF: Secure Dynamic Messaging (SDM) inserts into the NDEF message, as text, data unique to each presentation (counter, identifier, cryptographic authentication code) that a server can verify at the simple tap of a smartphone, without a dedicated app; the mechanism is compatible with that of the NTAG DNA chips.
- Transaction Timer: a timer bounds the duration of a transaction and defeats the man-in-the-middle attack that consists of keeping the card powered after it left the legitimate reader in order to delay the conclusion of the transaction.
- Mutual authentication and encrypted channel: a three-pass mutual authentication, executed by a hardware cryptographic engine (DES, 2K3DES, 3K3DES or AES-128), generates session keys; exchanges are signed with an 8-byte CMAC or encrypted over the radio channel, with the AES secure messaging recommended for any new project.
- Multi-application and delegated management: applications with no fixed limit, MIsmartApp with memory quotas and reuse of freed space (the EV3 ships with NXP's AppXplorer service keys preloaded), up to 16 key sets per application with fast rolling and 8 keys per access right.
- Transaction MAC, Proximity Check and Virtual Card: cryptographic proof of each transaction for the backend, with a reader identifier to pinpoint a fraud location; response-time measurement against relay attacks; card selection preserving the holder's privacy.
- Atomic transactions and anti-cloning: an anti-tearing mechanism validates or cancels writes as one unit, automatic rollback protects the structure, plus Random ID, an ECC originality signature and hardware sensors against physical attacks.
In its delivery configuration, the EV3 behaves like an EV2 or an EV1: the new features are activated during personalization. The chip comes in two antenna capacitances, 17 pF and 70 pF (MF3DHx3 references), and its write endurance doubles compared with the EV2.
Compatibility
The MIFARE DESFire EV3 uses NFC-A technology (ISO/IEC 14443A), supported by the vast majority of recent NFC smartphones. On Android, reading and writing work natively with NFC Tools, without any particular restriction. On iPhone, automatic background reading is available from the iPhone XS and XR onwards; models from the iPhone 7 can read and write the chip via NFC Tools on iOS 15.6 or later, by starting the scan manually from the app.
With NFC Tools, the chip supports reading technical information as well as reading and writing NDEF records once the card is formatted as Type 4 (blank cards delivered with factory keys can be prepared during the first write). Creating applications, managing keys and configuring Secure Dynamic Messaging require specialized encoding through the chip's dedicated commands. The list of compatible models is available in the article on compatibility.
MIFARE DESFire EV2 vs EV3
| Chip | Memory | Security | Typical use |
|---|---|---|---|
| MIFARE DESFire EV2 | 2 to 32 kB | EAL5+, Transaction MAC, anti-relay | The proven generation |
| MIFARE DESFire EV3 | 2 to 16 kB | EAL5+, SUN message, Transaction Timer | The current recommended generation |
The EV3 carries over everything from the EV2 (it can even replace it as is in an existing infrastructure) and adds the SUN message, the Transaction Timer, a communication buffer raised to 256 bytes and endurance doubled to one million cycles; only the 32 kB version remains specific to the EV2. The EV1, EV2 and EV3 trio is thus covered by dedicated pages; on the consumer NFC tag side, the NTAG 424 DNA offers the same SUN message in a sticker format.
Frequently asked questions
How much data can be stored on a MIFARE DESFire EV3?
The card offers 2 to 16 kB depending on the version, distributed into freely sized files. Used as a Type 4 tag, it dedicates almost all of its memory to the NDEF file, which corresponds to nearly 1,900 URL characters on the 2 kB version (far beyond common needs).
What is new compared with the MIFARE DESFire EV2?
The EV3 adds Secure Dynamic Messaging and its SUN message verifiable at every tap, the Transaction Timer against man-in-the-middle attacks, a 256-byte communication buffer, endurance doubled to one million cycles and preloaded AppXplorer service keys (while remaining backward compatible with the EV2, EV1 and D40).
Is the MIFARE DESFire EV3 compatible with iPhones?
Yes. Background reading works from the iPhone XS and XR onwards, and both reading and writing are possible via NFC Tools from the iPhone 7 on iOS 15.6 or later.
Can a MIFARE DESFire EV3 be protected against rewriting?
Protection relies on the keys: each file defines its read and write access rights, which can require authentication or be set to "never" (writing then becomes permanently impossible). There is no OTP-bit locking as on NTAG chips: everything is configured through the access rights.
Useful links
