Select your language

The NTAG424 DNA is NXP Semiconductors' flagship secure NFC chip, the successor of the NTAG413 DNA within the NTAG DNA range. Compliant with the ISO/IEC 14443-4 standard and the NFC Forum Type 4 format, it combines AES-128 cryptography, the SUN authentication feature and Common Criteria EAL4 certification. It can be read and written by virtually all NFC-enabled smartphones.

Information

Manufacturer NXP Semiconductors
Family NTAG DNA
Standard ISO/IEC 14443 Type A (parts 2 to 4)
NFC Forum type Type 4 Tag (NFC Forum certified)
Protocol APDU as per ISO/IEC 7816-4
Operating frequency 13.56 MHz
Data rate 106 to 848 kbit/s
Unique identifier (UID) 7 bytes, with Random ID option
Operating distance Up to approximately 10 cm, depending on the antenna and reader
Data retention 50 years
Write endurance Minimum 200,000 cycles
Encryption AES-128 (5 application keys, LRP option)
Certification Common Criteria EAL4 (hardware and software)
User memory 416 bytes
NDEF file 256 bytes

Memory

Unlike the NTAG21x chips organized in pages, the memory of the NTAG424 DNA follows a file structure compliant with the ISO/IEC 7816-4 standard:

File Size Content Default access
CC file (no. 01) 32 bytes Capability Container (NFC Forum Type 4) Free read
NDEF file (no. 02) 256 bytes NDEF message, SUN mirrors (UID, counter, CMAC) Free read, key-configurable write
Proprietary file (no. 03) 128 bytes Sensitive data AES key access, encrypted communication by default

In practice, the 256-byte NDEF file holds a URL of around 240 characters. When SUN authentication is enabled, the mirrors (UID, counter and CMAC code) take up part of this space (around forty characters) with the link then pointing to a server in charge of verifying the cryptographic validity of each read. The 128-byte proprietary file additionally stores confidential data, accessible only after AES authentication.

Features & security

  • SUN authentication: at each read, the chip inserts into the URL a dynamic authentication code (AES CMAC) derived from the UID and a 24-bit read counter, verifiable server-side: the content can be neither cloned nor replayed. The mirrored data can also be transmitted encrypted.
  • Five AES-128 keys: five 128-bit application keys, with version management, control reading, writing and configuration on a file-by-file basis.
  • Protected proprietary file: 128 bytes of data accessible only after authentication, with fully encrypted communication by default.
  • Random ID: the chip can present a random identifier at each activation to prevent tracking, with the real UID then only transmitted in encrypted form.
  • LRP mode: an AES variant (Leakage Resilient Primitive) strengthens resistance against side-channel attacks.
  • Mutual authentication: a three-pass challenge-response protocol authenticates both the chip and the reader holding the keys.
  • Originality signature: an ECDSA signature programmed at the factory, complemented by AES originality keys, verifies that the chip genuinely comes from NXP.

An NTAG424 DNA TT variant adds tamper detection (Tag Tamper) to the same security foundation, following the principle of the NTAG213 TT.

Compatibility

The NTAG424 DNA is compatible with virtually all NFC smartphones. On Android, reading and writing work natively with NFC Tools, without any particular restriction. On iPhone, automatic background reading is available from the iPhone XS and XR onwards; models from the iPhone 7 can read and write the chip via NFC Tools on iOS 15.6 or later, by starting the scan manually from the app.

With NFC Tools, the NTAG424 DNA chip supports reading technical information, writing NDEF records and erasing. Configuring the cryptographic functions (AES keys, enabling SUN authentication), however, is a specialized encoding process, usually carried out with a dedicated reader and a server-side infrastructure. The list of compatible models is available in the article on compatibility.

NTAG413 DNA vs NTAG424 DNA

Chip User memory NDEF file AES keys
NTAG413 DNA 160 bytes 128 bytes 3
NTAG424 DNA 416 bytes 256 bytes 5

Both chips share the SUN principle and AES-128 cryptography. Compared with the NTAG413 DNA it replaces, the NTAG424 DNA offers more memory, two additional keys, the protected proprietary file, the Random ID option and EAL4 certification: it is the chip to choose for any new authentication or anti-counterfeiting project.

Frequently asked questions

How much data can be stored on an NTAG424 DNA?

The NDEF file offers 256 bytes, which corresponds to a URL of around 240 characters, and the proprietary file adds 128 bytes for protected data. With the 32-byte CC file, the total user memory reaches 416 bytes.

What is SUN authentication?

SUN (Secure Unique NFC message) generates a unique cryptographic code at each read, inserted into the URL. The server receiving this link verifies that the read comes from the original chip and has not been replayed, making any copy of the content ineffective.

Is the NTAG424 DNA compatible with iPhones?

Yes. Background reading works from the iPhone XS and XR onwards, and both reading and writing NDEF are possible via NFC Tools from the iPhone 7 on iOS 15.6 or later. SUN verification takes place server-side, when the link is opened.

Can an NTAG424 DNA be protected against rewriting?

Yes. Each file has access rights configurable by AES key, up to prohibiting any unauthenticated write, and the proprietary file is encrypted by default. The chip does not use the simple password mechanism of the NTAG21x: protection relies entirely on the AES-128 keys.

 

About

Creator of innovative solutions
Android | iOS | Web | NFC

Keep in touch