Hello,
I am using NFC Mifare Desfire EV3 cards and I am able to get the authentication sequence correct, and after that when we send the read command, I getting the response in which data part is correct but the CMAC is not matching with we calculated.
Reader is PN532 NFC HAT + Raspberry pi
prog language used - Python
Please find the detailed steps below :
1. Application is created with id 0xA1A2A3. (one time process)
2. File creation - file id = 0, type = plaintext
3. Authentication sequence is followed and received expected responses. Session key is generated.
4. Read command sent to read from file 0, location 0, no of bytes - 6
Session key - 0B C6 7C 01 B1 3F 82 2D C0 B7 59 1F 77 17 26 AF
read Request -
APDU CMD: BD 00 00 00 00 06 00 00
APDU RESP: 00 31 32 33 34 35 36 85 64 57 2D B0 B0 5C C7
CMAC calculations -
Subkey1: f3b468b1db783e3b5c0e0f24503a54cc
Subkey2: e768d163b6f07c76b81c1e48a074a91f
Status: 00
Data: 313233343536
CMAC from card: 8564572db0b05cc7
CMAC input data: 31323334353600
CMAC encryption key: 0bc67c01b13f822dc0b7591f771726af
Padded data: 31323334353600800000000000000000
Padding was added, XOR last block with subkey2
XOR output (last block after XOR): d65ae25783c67cf6b81c1e48a074a91f
CMAC encrypted: c8e5e3dda222026be99ab3ce4a5ff1b6
CMAC: c8e5e3dda222026b
Doubts-
1. After authentication, we are sending this first command, hence the iv being used should be 00000000000000000000000000000000, right ?
2. Can we get more details about the CMAC calculation.
note - the card was written from one of the third party Android app. Data written on card "123456"