Select your language

The MIFARE Plus is the bridge from NXP Semiconductors between two worlds: it carries over the memory organization of the MIFARE Classic (sectors, blocks, access bits) while bringing AES-128 cryptography, to migrate access badges, transport cards and student cards from Crypto1 systems to certified security, without replacing the whole infrastructure at once. Its security-level concept lets the same card live today in full Classic compatibility (SL1) and tomorrow in full AES (SL3), with the switch being permanent. Available in five versions (S, X, SE, EV1 and EV2, certified up to EAL5+), it targets closed systems; its compatibility with smartphones is real but partial, and detailed below.

Information

Manufacturer NXP Semiconductors
Family MIFARE Plus
Versions MIFARE Plus S, Plus X, Plus SE, Plus EV1 and Plus EV2
Standard ISO/IEC 14443A (levels 1 to 4)
NFC Forum type None (proprietary NDEF format through the MAD)
Operating frequency 13.56 MHz
Data rate 106 to 848 kbit/s
Unique identifier (UID) 7 bytes, or a 4-byte NUID; optional Random ID
Encryption AES-128; Crypto1 in compatibility mode, depending on the security level
Tuning capacitance 17 pF or 70 pF depending on the version
Operating distance A few centimeters (up to 100 mm depending on the antenna)
Certification Common Criteria, up to EAL5+ (EV generations)
Memory 1, 2 or 4 kB depending on the version

The versions of the family

The MIFARE Plus family was built in two stages: the historical versions (S, X, SE), then the EV generations that replace them:

Version Memory Highlights
MIFARE Plus S 2 or 4 kB The historical entry version (levels SL0, SL1 and SL3)
MIFARE Plus X 2 or 4 kB The historical full version, with the intermediate SL2 level
MIFARE Plus SE 1 kB The compact entry point, AES keys stored within the data blocks
MIFARE Plus EV1 2 or 4 kB Virtual Card, Proximity Check, Transaction MAC, sector-by-sector migration
MIFARE Plus EV2 2 or 4 kB The current generation: SL1SL3MixMode, Transaction Timer, EAL5+

All of them carry over the MIFARE Classic organization (16-byte blocks grouped into sectors, with their sector trailers): the 2K version offers 752 usable bytes and the 4K 3,440, value blocks included. The EV generations replace the historical versions, with the EV2 remaining backward compatible with all of them, MIFARE Classic included.

Memory

The memory of the MIFARE Plus is that of a Classic which learned AES: same sectors, same access bits, with 128-bit keys on top:

Area Content Access
Block 0 (sector 0) UID and manufacturer data Read only, set at the factory
Data blocks 16 bytes each; value blocks for counters and balances According to the access bits; in SL3, under AES authentication and secure messaging
Sector trailers and keys Access bits; Crypto1 keys (SL1) and two 128-bit AES keys per sector Keys and trailers protected by an anti-tearing mechanism

The card is delivered at level SL0, dedicated to personalization: data, Crypto1 keys and AES keys are written there before commissioning (the switching command then seals the chosen level). In SL1 and with the MAD format, an NDEF message of around 700 characters remains possible on the 2K, as on a Classic.

Features & security

  • Security levels, the heart of the concept: delivered in SL0 (personalization), the card moves to SL1 (full Classic compatibility) then to SL3 (full AES: authentication, integrity and encryption of exchanges), with switching only going upwards, for the whole card or sector by sector since the EV1: each infrastructure migrates at its own pace.
  • SL1SL3MixMode and restrictions (EV2): AES authentication steps into sectors still in SL1, and the SL1 update restrictions divide rights between the old and the new world (read with the legacy system, modify under AES).
  • Full Classic legacy: sectors, access bits, value blocks and transactions remain those of the Classic: readers already in place keep working in SL1, with no service interruption during the migration.
  • Transaction protections (EV generations): the Transaction MAC proves the authenticity of operations to the backend, the Transaction Timer (EV2) defeats man-in-the-middle attacks, and anti-tearing covers keys, trailers and, optionally, data writes.
  • Virtual Card and Proximity Check (EV generations): the virtual card selection (ISO/IEC 7816-4) serves multi-card and mobile environments, and the proximity check measures the response time of exchanges to detect relay attacks.
  • Certified and fast: up to 848 kbit/s, an originality check, and Common Criteria certifications up to EAL5+ (hardware and software) on the EV generations.

The historical MIFARE Plus S, X and SE paved the way; NXP directs new projects towards the EV generations, whose end-to-end secure channel also serves mobile services (remote top-up, MIFARE 2GO).

Compatibility

The MIFARE Plus relies on NFC-A technology (ISO/IEC 14443A), but its proprietary protocol places it outside the tag types standardized by the NFC Forum: compatibility depends on the device's NFC controller and on the card's security level. In SL1, it behaves like a MIFARE Classic: on Android, models equipped with an NXP controller read and write it with NFC Tools, while others may be limited to reading the UID; on iPhone, background reading is not available and NFC Tools is partially compatible: you need to enable the "compatibility" option in the app settings, then start the scan manually (iPhone 7 and later, on iOS 15.6 or later). In SL3, the card only talks AES with its system's readers: its operation then belongs to the deployed infrastructure.

With NFC Tools, the MIFARE Plus chip supports, depending on the device and the security level, reading technical information as well as reading and writing NDEF records on cards formatted with the MAD in SL1. Managing the keys, the security levels and the personalization requires specialized encoding through the chip's dedicated commands. The list of compatible models is available in the article on compatibility.

MIFARE Classic EV1 vs MIFARE Plus EV2

Chip Memory Security Typical use
MIFARE Classic EV1 1 or 4 kB Crypto1 Existing fleets, non-sensitive uses
MIFARE Plus EV2 2 or 4 kB EAL5+ certified AES-128, Classic compatibility in SL1 The migration to certified security

The MIFARE Plus is literally the Classic that learned AES: same memory, same readers in SL1, modern security in SL3. For an architecture built on applications and files rather than sectors, the MIFARE DESFire EV3 takes over; for a consumer tag readable by every smartphone, the NTAG213 remains the reference.

Frequently asked questions

How much data can be stored on a MIFARE Plus?

1 kB (Plus SE), 2 or 4 kB depending on the version, with the Classic structure: 752 usable bytes on the 2K and 3,440 on the 4K, once the configuration blocks are deducted. In SL1 and with the MAD format, the NDEF message represents around 700 characters on the 2K.

How does the security-level migration work?

The card is delivered in SL0 for personalization (data, Crypto1 and AES keys), then switched to SL1 (full Classic compatibility) or directly to SL3 (full AES). Switching only goes upwards, for the whole card or sector by sector since the EV1, and the EV2's SL1SL3MixMode lets both worlds coexist during the transition: the infrastructure migrates without ever stopping.

Is the MIFARE Plus compatible with iPhones?

Partially, like the Classic whose protocol it carries over: background reading is not available, and NFC Tools is partially compatible (enable the "compatibility" option in the settings, manual scan, iPhone 7 and later on iOS 15.6 or later). In SL3, the card belongs to its system's readers.

Is the MIFARE Plus more secure than the MIFARE Classic?

Yes, once it operates in SL3: AES-128 authentication and messaging, certifications up to EAL5+, Transaction MAC and a proximity check against relay attacks. In SL1, it deliberately inherits the limits of Crypto1, while waiting for the infrastructure to switch.

 

About

Creator of innovative solutions
Android | iOS | Web | NFC

Keep in touch