The MIFARE Ultralight EV1 is the current version of NXP Semiconductors' Ultralight family, dedicated to limited-use ticketing: public transport tickets, event tickets, day passes. Succeeding the original MIFARE Ultralight with full backward compatibility, it comes in two capacities of 48 and 128 bytes of user memory. Compliant with the ISO/IEC 14443 Type A standard and compatible with the NFC Forum Type 2 format, it can be read and written by virtually all NFC-enabled smartphones.
Information
| Manufacturer | NXP Semiconductors |
| Family | MIFARE Ultralight (current version) |
| References | MF0UL11 (48 bytes) and MF0UL21 (128 bytes) |
| Standard | ISO/IEC 14443 Type A (parts 2 and 3) |
| NFC Forum type | Type 2 Tag compatible |
| Operating frequency | 13.56 MHz |
| Data rate | 106 kbit/s |
| Unique identifier (UID) | 7 bytes, factory programmed |
| Operating distance | Up to approximately 10 cm, depending on the antenna and reader |
| Data retention | 10 years |
| Write endurance | 100,000 cycles (1,000,000 for the counters) |
| Total memory (EEPROM) | 80 bytes (MF0UL11) or 164 bytes (MF0UL21) |
| User memory | 48 or 128 bytes |
Memory
The EEPROM memory is organized into pages of 4 bytes (20 pages for the MF0UL11, 41 pages for the MF0UL21) with the first 512 bits reproducing exactly the structure of the original MIFARE Ultralight:
| Content | MF0UL11 (48 bytes) | MF0UL21 (128 bytes) |
|---|---|---|
| UID, internal data and static lock bytes | Pages 0 to 2 | Pages 0 to 2 |
| OTP area (One Time Programmable, 32 bits) | Page 3 | Page 3 |
| User memory | Pages 4 to 15 | Pages 4 to 35 |
| Dynamic lock bytes | — | Page 36 |
| Configuration: AUTH0, ACCESS, password (PWD) and PACK | Pages 16 to 19 | Pages 37 to 40 |
In practice, the user memory can hold an NDEF record containing a URL of around 40 characters on the MF0UL11 and around 115 characters on the MF0UL21, as the common prefix (https://www. for example) is compressed into a single byte by the NDEF format: encoding a short redirect link is recommended. During NDEF formatting, the Capability Container is written into the OTP page. The chip's three counters reside in a separate area, accessible only through dedicated commands.
Features & security
- Password protection: a 32-bit password (PWD), combined with a 16-bit acknowledgement (PACK), restricts write access, or even read access, from a page defined by the AUTH0 parameter, with an optional limit of unsuccessful attempts.
- Three 24-bit counters: three independent one-way counters, protected against tearing (anti-tearing) and accessible through the READ_CNT and INCR_CNT commands, designed to count down uses with an endurance of one million cycles.
- OTP area: 32 one-time programmable bits, which can be set but never erased, usable as a 32-tick counter to mark the uses of a ticket.
- Permanent locking: page-by-page static locking on the first 512 bits, complemented on the MF0UL21 by dynamic locking in blocks of two pages, an operation that can be performed directly from NFC Tools.
- Originality signature: an ECDSA signature programmed at the factory verifies that the chip genuinely comes from NXP and helps detect certain counterfeits.
The EV1 succeeds the original MIFARE Ultralight (MF0ICU1) with full backward compatibility and is available in 17 pF (TFC.0 and TFC.1 ticket formats) and 50 pF versions. For cryptographic authentication, the range offers the MIFARE Ultralight C (3DES) and the MIFARE Ultralight AES.
Compatibility
The MIFARE Ultralight EV1 is compatible with virtually all NFC smartphones. On Android, reading and writing work natively with NFC Tools, without any particular restriction. On iPhone, automatic background reading is available from the iPhone XS and XR onwards; models from the iPhone 7 can read and write the chip via NFC Tools on iOS 15.6 or later, by starting the scan manually from the app.
With NFC Tools, the MIFARE Ultralight EV1 chip supports reading technical information, writing records, erasing, permanent locking and password protection. The list of compatible models is available in the article on compatibility.
MIFARE Ultralight vs Ultralight C vs Ultralight EV1
| Chip | User memory | Security | Typical use |
|---|---|---|---|
| MIFARE Ultralight (MF0ICU1) | 48 bytes | Locking and OTP area | Limited-use ticketing, first generation |
| MIFARE Ultralight C | 144 bytes | 3DES authentication | Ticketing and access control |
| MIFARE Ultralight EV1 | 48 or 128 bytes | Password, counters, signature | The current version of the range |
All three chips share the same ISO/IEC 14443 Type A foundation and the same smartphone compatibility. The EV1 is the version to choose for any new ticketing deployment: it fills the gaps of the original (password, counters, signature, tenfold endurance) without the key management of the Ultralight C. For a general-purpose NFC tag, the NTAG213 remains the reference choice.
Frequently asked questions
How much data can be stored on a MIFARE Ultralight EV1?
The chip offers 48 or 128 bytes of user memory depending on the reference, which corresponds to a URL of around 40 or 115 characters once the NDEF envelope is taken into account. Encoding a short redirect link is recommended.
What is the difference between MIFARE Ultralight EV1 and NTAG?
Both NXP families rely on the same ISO/IEC 14443 Type A foundation, compatible with the NFC Forum Type 2 format. The Ultralight EV1 is ticketing-oriented, with its three one-way counters and its OTP area, while the NTAG21x chips are optimized for NFC tags, with the ASCII mirror and the read counter.
Is the MIFARE Ultralight EV1 compatible with iPhones?
Yes. Background reading works from the iPhone XS and XR onwards, and both reading and writing are possible via NFC Tools from the iPhone 7 on iOS 15.6 or later.
Can a MIFARE Ultralight EV1 be protected against rewriting?
Yes, in two ways: a permanent, irreversible read-only lock, or a reversible 32-bit password protection. Both operations can be performed with NFC Tools.
Useful links
