2415771_en-US

キャンセル
次の結果を表示 
表示  限定  | 次の代わりに検索 
もしかして: 

2415771_en-US

2415771_en-US

PN7150/NCI: Unable to update MIFARE Classic 1K Sector Trailer with Custom Embedded Key B

Hello NXP Community,

I am working with a MIFARE Classic 1K card and an NXP PN7150 NFC controller running over the standard NCI protocol layer. I am trying to implement a provisioning feature where I write a custom secret password into Key B of a target sector (Sector 7), but the card chip consistently rejects the write command.
Here is the exact state of my card and the implementation details:

  • Current Sector 7 State: The sector is currently blank/unformatted. A read dump shows it is in the factory default state with access bits FF078069 and both Key A and Key B set to 0xFFFFFFFFFFFF.
  • The Goal: I want to keep Key A as the read key, preserve the open access bit layout, and overwrite Key B with a personal custom key payload (0x01 0x02 0x03 0x04 0x05 0x06).
  • The Issue: When I attempt to write the 16-byte raw block layout string (FFFFFFFFFFFFFF078069010203040506) to Block 3 (Sector 7 Trailer), the write transaction fails.

Note: i did the card NDEF format with an App and access bytes are showing 7F078840

Any guidance would be greatly appreciated!
 
Kind Regards


 

Re: PN7150/NCI: Unable to update MIFARE Classic 1K Sector Trailer with Custom Embedded Key B

Hello @Saqib1

Hope you are doing well.

Please consider that PN7150 is Not Recommended for New Designs; we recommend using PN7160 instead. Additionally, MIFARE Classic is also Not Recommended for New Designs; MIFARE DESFire Light can be considered.

Before sending the write command make sure the authentication with Key A (FFFFFFFFFFFFh) on block 1Fh (Sector 7 trailer) is performed successfully.

Now, after authentication on block 1Fh, please verify that the write command is being sent following the procedure described in the MIFARE Classic EV1 1K datasheet, section 12.3. The WRITE operation consists of two parts that must be sent sequentially:

Part 1: Send the command byte and block address, including CRC: A0 + XX +CRC where XX is the block address (e.g., 1Fh for the Sector 7 Trailer). The card must respond with ACK before proceeding.

Part 2: Only after receiving the ACK, send the 16 bytes of data including CRC: [16 bytes payload] + CRC. The card will respond with a final ACK to confirm the write was accepted.

Regards,
Eduardo.

タグ(1)
評価なし
バージョン履歴
最終更新日:
火曜日
更新者: