Select your language

The MIFARE DESFire Light is the single-application member of the MIFARE DESFire family from NXP Semiconductors, designed for services managed by a single issuer: access management, event and transport ticketing, account-based services, electronic vouchers, gaming and loyalty. Compliant with the ISO/IEC 14443A standard and ISO/IEC 7816-4 frames, and compatible with the NFC Forum Type 4 format, it carries the AES security of the family (enriched with the LRP mode resistant to side-channel attacks) on a predefined 640-byte file structure, ready to use out of the box. It can be read and written by the vast majority of recent NFC smartphones.

Information

Manufacturer NXP Semiconductors
Family MIFARE DESFire (single-application member)
References MF2DL10 and MF2DLH10
Standard ISO/IEC 14443A (levels 2 to 4)
Protocol ISO/IEC 7816-4 APDU
NFC Forum type Type 4 Tag compatible
Operating frequency 13.56 MHz
Data rate 106 to 848 kbit/s
Unique identifier (UID) 7 bytes, factory programmed; optional Random ID
Encryption AES-128, with optional LRP mode
Keys 5 application AES 128-bit keys
Certification Common Criteria EAL4 (hardware and software)
Operating distance A few centimeters (up to 10 cm depending on the antenna)
Data retention 10 years
Write endurance 200,000 cycles minimum
User memory 640 bytes

Memory

The memory of the MIFARE DESFire Light is organized as a single, predefined application of six files, compliant with ISO/IEC 7816-4 (a fixed, ready-to-use structure whose identifiers remain changeable):

File Content Typical use
Three data files Two of 256 bytes and one of 32 bytes, i.e. 544 bytes Application data, information, NDEF file
Value file 4-byte signed integer, with upper and lower limits Balance, points, counter (controlled credit and debit)
Cyclic record file 4 records of 16 bytes History of the latest transactions
Transaction MAC file Transaction counter and MAC Proof of transaction for the backend

The 640 bytes of user memory are equivalent to the available user memory of a MIFARE Classic 1K, with modern security on top. The files are factory created and cannot be deleted (only the Transaction MAC file can be re-created, to change its key), but their identifiers and access rights can be freely reconfigured. Used as an NFC Forum Type 4 tag, one of the 256-byte files hosts the NDEF message, which corresponds to a URL of around 240 characters.

Features & security

  • AES-128 encryption and LRP mode: three-pass mutual authentication and AES secure messaging (compatible with a subset of the DESFire EV2 secure messaging) at three levels: plain, CMAC-signed or fully encrypted. The LRP mode, which can be permanently enabled, wraps AES in a construction resistant to side-channel and fault attacks, without any proprietary cryptography.
  • Five keys and per-file rights: five versioned AES 128-bit keys, including the application master key; each file defines its read, write and configuration rights (per key, free access or "never"). A failed-authentication counter, with progressive slowdown, hampers brute-force attacks.
  • Transaction MAC: each transaction can be sealed with a MAC computed with a key shared only between the card and the backend: the terminal can neither forge nor replay a transaction; the reader identifier can be required and a transaction limit is configurable.
  • Atomic transactions: the value file and the cyclic record file benefit from a backup mechanism (writes only take effect upon transaction commit, as one unit: the card never remains in an inconsistent state, even when removed from the field mid-operation).
  • Dual originality check: an ECC signature readable with the Read Sig command and four AES originality keys, verifiable through LRP authentication, attest that the silicon genuinely comes from NXP.
  • Privacy and integration: the optional Random ID meets data-protection regulations, the fully encrypted mode hides the exchanges, and the functional compatibility with the DESFire EV2 makes it possible to later integrate the application into a multi-application card.

The MIFARE DESFire Light comes in two antenna capacitances, 17 pF (MF2DL10) and 50 pF (MF2DLH10) for small form factors (key fobs, wristbands). For multi-application schemes or the SUN message, the MIFARE DESFire EV2 and EV3 take over.

Compatibility

The MIFARE DESFire Light uses NFC-A technology (ISO/IEC 14443A), supported by the vast majority of recent NFC smartphones. On Android, reading and writing work natively with NFC Tools, without any particular restriction. On iPhone, automatic background reading is available from the iPhone XS and XR onwards; models from the iPhone 7 can read and write the chip via NFC Tools on iOS 15.6 or later, by starting the scan manually from the app.

With NFC Tools, the chip supports reading technical information as well as reading and writing NDEF records once the card is configured as Type 4. Managing the keys, the access rights and the Transaction MAC requires specialized encoding through the chip's dedicated commands. The list of compatible models is available in the article on compatibility.

MIFARE DESFire Light vs DESFire EV3

Chip Memory Security Typical use
MIFARE DESFire Light 640 bytes EAL4, AES-128 and LRP, five keys The single application, simple and secure
MIFARE DESFire EV3 2 to 16 kB EAL5+, unlimited applications, SUN message The multi-application platform

The Light concentrates the family's AES security on a predefined structure, ready to use and more economical; the EV3 opens up multi-application schemes, delegated management and the SUN message. The functional compatibility with the EV2 secure messaging allows a Light application to migrate to an EV2 or EV3 card without redesign; on the sticker tag side, the NTAG 424 DNA shares the same LRP mode.

Frequently asked questions

How much data can be stored on a MIFARE DESFire Light?

The chip offers 640 bytes of user memory (the equivalent of a MIFARE Classic 1K) split between 544 bytes of data files, a value file and a four-entry cyclic record file. Used as a Type 4 tag, the 256-byte NDEF file corresponds to a URL of around 240 characters.

What is the difference between the DESFire Light and the DESFire EV2 or EV3?

The Light is single-application, with a fixed, ready-to-use file structure, whereas the EV2 and EV3 are freely structured multi-application platforms. The AES security is shared (the Light even adds the LRP mode) and its compatibility with the EV2 secure messaging allows a later migration without redesign.

Is the MIFARE DESFire Light compatible with iPhones?

Yes. Background reading works from the iPhone XS and XR onwards, and both reading and writing are possible via NFC Tools from the iPhone 7 on iOS 15.6 or later.

Can a MIFARE DESFire Light be protected against rewriting?

Protection relies on the keys: each file defines its read and write access rights, which can require authentication or be set to "never" (writing then becomes permanently impossible). There is no OTP-bit locking as on NTAG chips: everything is configured through the access rights.

 

About

Creator of innovative solutions
Android | iOS | Web | NFC

Keep in touch