The MIFARE Ultralight C is an NFC chip from NXP Semiconductors that adds cryptographic authentication to the Ultralight family. Compliant with the ISO/IEC 14443 Type A standard and compatible with the NFC Forum Type 2 format, it offers 144 bytes of user memory that can be protected by 3DES mutual authentication. It can be read and written by virtually all NFC-enabled smartphones.
Information
| Manufacturer | NXP Semiconductors |
| Family | MIFARE Ultralight |
| Reference | MF0ICU2 |
| Standard | ISO/IEC 14443 Type A (parts 2 and 3) |
| NFC Forum type | Type 2 Tag compatible |
| Operating frequency | 13.56 MHz |
| Data rate | 106 kbit/s |
| Unique identifier (UID) | 7 bytes, factory programmed |
| Operating distance | Up to approximately 10 cm, depending on the antenna and reader |
| Data retention | 10 years |
| Write endurance | 100,000 cycles |
| Encryption | 3DES authentication (16-byte key) |
| Total memory (EEPROM) | 192 bytes |
| User memory | 144 bytes |
Memory
The EEPROM memory of the MIFARE Ultralight C is organized into 48 pages of 4 bytes (pages 0 to 47), with the first 512 bits reproducing exactly the structure of the original MIFARE Ultralight:
| Pages | Content | Access |
|---|---|---|
| 0 to 2 | UID, internal data and static lock bytes | Read-only (UID) / OTP |
| 3 | OTP area (One Time Programmable, 32 bits) | OTP |
| 4 to 39 | User memory (144 bytes) | Read / write |
| 40 | Dynamic lock bytes | OTP |
| 41 | 16-bit one-way counter | Increment only |
| 42 to 43 | Authentication configuration: AUTH0 and AUTH1 | Read / write, protectable |
| 44 to 47 | 3DES key (16 bytes) | Write only |
In practice, the 144 bytes of user memory can hold an NDEF record containing a URL of around 130 characters, as the common prefix (https://www. for example) is compressed into a single byte by the NDEF format (a capacity equivalent to that of an NTAG213). The 3DES key, written into pages 44 to 47, can never be read: only its use during an authentication proves that it is held.
Features & security
- 3DES authentication: a challenge-response mutual authentication, based on a 16-byte secret key, reserves access to part of the memory for readers holding the key.
- Configurable protected areas: the AUTH0 parameter defines the first page requiring authentication, and AUTH1 specifies whether the restriction applies to writing only or to both reading and writing.
- 16-bit counter: a one-way counter, which can be incremented but never decremented, counts down uses: trips, entries, passages.
- OTP area: 32 one-time programmable bits, which can be set but never erased, usable as a 32-tick counter.
- Permanent locking: page-by-page static locking on the first 512 bits, complemented by block-based dynamic locking for the following pages, with anti-tearing on lock bit writes. The operation can be performed directly from NFC Tools.
The MIFARE Ultralight C offers neither the simple password nor the originality signature of the MIFARE Ultralight EV1: its security relies on the 3DES key. As triple DES is an aging algorithm, NXP offers the MIFARE Ultralight AES, its modern-cryptography replacement, for new projects.
Compatibility
The MIFARE Ultralight C is compatible with virtually all NFC smartphones. On Android, reading and writing work natively with NFC Tools, without any particular restriction. On iPhone, automatic background reading is available from the iPhone XS and XR onwards; models from the iPhone 7 can read and write the chip via NFC Tools on iOS 15.6 or later, by starting the scan manually from the app.
With NFC Tools, the MIFARE Ultralight C chip supports reading technical information, writing records, erasing and permanent locking. Configuring the 3DES authentication (loading the key, choosing the protected pages), however, is a specialized encoding process. The list of compatible models is available in the article on compatibility.
MIFARE Ultralight vs Ultralight C vs Ultralight EV1
| Chip | User memory | Security | Typical use |
|---|---|---|---|
| MIFARE Ultralight (MF0ICU1) | 48 bytes | Locking and OTP area | Limited-use ticketing, first generation |
| MIFARE Ultralight C | 144 bytes | 3DES authentication | Ticketing and access control |
| MIFARE Ultralight EV1 | 48 or 128 bytes | Password, counters, signature | The current version of the range |
All three chips share the same ISO/IEC 14443 Type A foundation and the same smartphone compatibility. The MIFARE Ultralight C stands out when access to the memory must be conditioned on a shared secret, in ticketing as in access control; for a simple locked or password-protected tag, the EV1 or the NTAG213 are sufficient.
Frequently asked questions
How much data can be stored on a MIFARE Ultralight C?
The chip has 144 bytes of user memory, which corresponds to a URL of around 130 characters once the NDEF envelope is taken into account, a capacity equivalent to that of an NTAG213.
What is the 3DES authentication for?
It conditions the reading or writing of part of the memory on the knowledge of a 16-byte secret key, which can never be read from the chip. A reader that does not hold the key cannot access the protected pages, which suits ticketing and access control.
Is the MIFARE Ultralight C compatible with iPhones?
Yes. Background reading works from the iPhone XS and XR onwards, and both reading and writing are possible via NFC Tools from the iPhone 7 on iOS 15.6 or later.
Can a MIFARE Ultralight C be protected against rewriting?
Yes, in two ways: a permanent, irreversible read-only lock, which can be performed with NFC Tools, or protection through 3DES authentication, configurable and reversible by the key holder. The chip does not offer the simple password of the NTAG21x and the Ultralight EV1.
Useful links
