Thank your recommendation to use RFIDDiscover and TapLinx SDK. I already have a Omnikey 5022 smart reader I'm assuming that will work just as fine! I have requested access for the RFIDDiscover and hope I can code APDU commands with it.
I took a good look at section 6.16.1 but some things are unclear for me.
Step 1 KSesAuthMAC = 5529860B2FC5FB6154B7F28361D30BF9
Step 2 KSesAuthENC = 4CF3CB41A22583A61E89B158D252FC53
Where are these values coming from?
Step 3 clear
SteP 4 suddenly we get the diversified new key by UID: F3847D627727ED3BC9C4CC050489B966
My question would by how is it diversified? What UID is used (+ maybe extra input like in the symmetric key diversification file)? , and why can the diversified input be only 31 HEX characters?
In the Symmetric key versification document table 3. step 8 Diversification input (M) = 04782E21801D803042F54E585020416275
was used, which made it clear.
In case of the ntag424 do you still use CMAC too for diversification or just AES-encryption?
It is very interesting I really want to figure this out!
I know I can come up with my own diversification process and TagXplorer is discontinued but I still want to know how it works, I need to understand it.
But I need a few more puzzle pieces I hope you can help me out with this!
Let me know if something is unclear from my side or if you understand my confusion!
Greetings,
JamesUID