<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Desfire EV2 : need to share master key ? in Secure Authentication</title>
    <link>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1255720#M477</link>
    <description>&lt;P&gt;I am designing a multi-purpose smartcard system using Mifare Desfire EV2.&lt;/P&gt;&lt;P&gt;I'd like to correctly understand the use of the different keys, and especially the master key.&lt;/P&gt;&lt;P&gt;As I read it, the master key allows to create applications on cards. It can be diversified to put a PICC key onto each card, so a the card don't carry the key, but a reader must know the master key to create applications on cards.&lt;/P&gt;&lt;P&gt;Each application has application master key, read or write keys, and off course, data.&lt;/P&gt;&lt;P&gt;For a determined reading use, e.g door control, the reader must read the accurate application, with the corresponding read key.&lt;/P&gt;&lt;P&gt;Am I right until here ?&lt;/P&gt;&lt;P&gt;So, I wonder out if I have to share the master key with different usage managers, i.e. the door control manager, the food service manager if the card is used to pay the meal...&lt;/P&gt;&lt;P&gt;Is the master key mandatory to read cards ?&lt;BR /&gt;If not, does the master key allow to read data on applications, without application read keys ?&lt;BR /&gt;Do I need to share the master key to allow managers to create applcations (I think I must), and do I need to share to write data on already made applications ?&lt;BR /&gt;Is it possible to create application on cards, just share the application master key to manager and let them rewrite application key, read and right keys ?&lt;/P&gt;&lt;P&gt;Thanks for your help !&lt;/P&gt;</description>
    <pubDate>Thu, 01 Apr 2021 09:35:24 GMT</pubDate>
    <dc:creator>MGO</dc:creator>
    <dc:date>2021-04-01T09:35:24Z</dc:date>
    <item>
      <title>Desfire EV2 : need to share master key ?</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1255720#M477</link>
      <description>&lt;P&gt;I am designing a multi-purpose smartcard system using Mifare Desfire EV2.&lt;/P&gt;&lt;P&gt;I'd like to correctly understand the use of the different keys, and especially the master key.&lt;/P&gt;&lt;P&gt;As I read it, the master key allows to create applications on cards. It can be diversified to put a PICC key onto each card, so a the card don't carry the key, but a reader must know the master key to create applications on cards.&lt;/P&gt;&lt;P&gt;Each application has application master key, read or write keys, and off course, data.&lt;/P&gt;&lt;P&gt;For a determined reading use, e.g door control, the reader must read the accurate application, with the corresponding read key.&lt;/P&gt;&lt;P&gt;Am I right until here ?&lt;/P&gt;&lt;P&gt;So, I wonder out if I have to share the master key with different usage managers, i.e. the door control manager, the food service manager if the card is used to pay the meal...&lt;/P&gt;&lt;P&gt;Is the master key mandatory to read cards ?&lt;BR /&gt;If not, does the master key allow to read data on applications, without application read keys ?&lt;BR /&gt;Do I need to share the master key to allow managers to create applcations (I think I must), and do I need to share to write data on already made applications ?&lt;BR /&gt;Is it possible to create application on cards, just share the application master key to manager and let them rewrite application key, read and right keys ?&lt;/P&gt;&lt;P&gt;Thanks for your help !&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 09:35:24 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1255720#M477</guid>
      <dc:creator>MGO</dc:creator>
      <dc:date>2021-04-01T09:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Desfire EV2 : need to share master key ?</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1256409#M478</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.nxp.com/t5/user/viewprofilepage/user-id/185202"&gt;@MGO&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The master key better be stored in SAM such as MIFARE SAM AV3, and we provide an app note on this topic, please kindly refer to&amp;nbsp;&lt;A href="https://www.nxp.com.cn/docs/en/application-note/AN10922.pdf" target="_blank"&gt;https://www.nxp.com.cn/docs/en/application-note/AN10922.pdf&lt;/A&gt;&amp;nbsp;for details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day,&lt;BR /&gt;Kan&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;-------------------------------------------------------------------------------&lt;BR /&gt;Note:&lt;BR /&gt;- If this post answers your question, please click the "Mark Correct" button. Thank you!&lt;BR /&gt;- We are following threads for 7 weeks after the last post, later replies are ignored&lt;BR /&gt;Please open a new thread and refer to the closed one, if you have a related question at a later point in time.&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Sat, 03 Apr 2021 02:29:56 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1256409#M478</guid>
      <dc:creator>Kan_Li</dc:creator>
      <dc:date>2021-04-03T02:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Desfire EV2 : need to share master key ?</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1256451#M479</link>
      <description>&lt;P&gt;Hi Kan_Li,&lt;/P&gt;&lt;P&gt;Thanks a lot for your answer.&lt;/P&gt;&lt;P&gt;I understand the SAM can be plugged on readers to use the keys. It is a good idea I am thinking about in a second step.&lt;/P&gt;&lt;P&gt;But on the beginning, can I have the cards read without the master key ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards, and happy Easter !&lt;/P&gt;&lt;P&gt;MGO&lt;/P&gt;</description>
      <pubDate>Sat, 03 Apr 2021 10:02:27 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1256451#M479</guid>
      <dc:creator>MGO</dc:creator>
      <dc:date>2021-04-03T10:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Desfire EV2 : need to share master key ?</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1349097#M593</link>
      <description>&lt;P&gt;Hi MGO,&lt;/P&gt;&lt;P&gt;I am dealing with DESFire cards right know. I found your questions very interesting. Did you get any answer?&lt;/P&gt;&lt;P&gt;Thank you in advance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 11:11:02 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1349097#M593</guid>
      <dc:creator>patricio</dc:creator>
      <dc:date>2021-09-30T11:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Desfire EV2 : need to share master key ?</title>
      <link>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1374227#M615</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No, not yet.&lt;/P&gt;&lt;P&gt;BR.&lt;/P&gt;&lt;P&gt;MGO&lt;/P&gt;</description>
      <pubDate>Fri, 19 Nov 2021 09:27:52 GMT</pubDate>
      <guid>https://community.nxp.com/t5/Secure-Authentication/Desfire-EV2-need-to-share-master-key/m-p/1374227#M615</guid>
      <dc:creator>MGO</dc:creator>
      <dc:date>2021-11-19T09:27:52Z</dc:date>
    </item>
  </channel>
</rss>

