When to change keys for MiFare Classic Cards?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

When to change keys for MiFare Classic Cards?

Jump to solution
1,461 Views
user_123
Contributor II

I have an empty Mifare Classic card and want to encrypt memory in just one sector by changing the key for that sector. 

However since this is an empty card all sectors have the default key FF FF FF FF FF FF. 

Should I change the key for all the other sectors as well even though they are unused and empty? 

Labels (1)
0 Kudos
1 Solution
1,441 Views
Florian_Mikulik
NXP Employee
NXP Employee

Hello!

Yes, it is advised to change ALL keys on MIFARE Classic cards away from the default values (even the key for Sector0)

Please refer to the document "AN11302 - End to end system security risk considerations for implementing MIFARE Classic" which describes possible attacks and countermeasures on MIFARE Classic. 

Please be also aware that for storing sensitive data, its not advised to use MIFARE Classic, but rather a more secure MIFARE card like DESFire Light.

Best regards,

Florian

Customer Application Support Engineer - Gratkorn - Austria

View solution in original post

1 Reply
1,442 Views
Florian_Mikulik
NXP Employee
NXP Employee

Hello!

Yes, it is advised to change ALL keys on MIFARE Classic cards away from the default values (even the key for Sector0)

Please refer to the document "AN11302 - End to end system security risk considerations for implementing MIFARE Classic" which describes possible attacks and countermeasures on MIFARE Classic. 

Please be also aware that for storing sensitive data, its not advised to use MIFARE Classic, but rather a more secure MIFARE card like DESFire Light.

Best regards,

Florian

Customer Application Support Engineer - Gratkorn - Austria