Chip-Level Cryptographic Authenticity

Anti-counterfeiting upgraded from “reading a number” to
an on-chip AES dynamic-code challenge

An ordinary QR code or chip UID is a static number: a copy is indistinguishable from the genuine item. NTAG 424 DNA Secure Dynamic Messaging (SDM / SUN) makes the chip compute a fresh CMAC over “UID + read counter” on every tap, using an on-chip AES-128 key. The same tag therefore produces a different link each time — impossible to copy or pre-record.

NXP NTAG 424 DNA AES-128 CMAC (RFC 4493) EN 18220 Level 2 Carrier Read counter · clone-pool detection
Why static IDs fail

Static numbers can be copied; dynamic codes cannot

The key question: does the secret that verification relies on ever leave the chip?

Level 1 · Static carrier

QR code / ordinary NFC UID

  • QR content is plaintext; a photo or screenshot yields a complete copy
  • The UID of an ordinary NFC tag can be emulated by special devices (e.g. Proxmark, Chameleon)
  • Verification only checks “is the number in the database”, so a copy answers identically to the genuine item
  • No visibility into how many times a tag was read, and no way to detect a clone pool
Level 2 · Secure carrier

NTAG 424 DNA Dynamic CMAC

  • The AES-128 key never leaves the chip; the outside world only gets a one-time message authentication code
  • The read counter increments on every tap, the CMAC changes, and old links expire immediately
  • The server recomputes the CMAC with the registered key; without the key a forger cannot produce the next code
  • The read counter reveals clone signals such as abnormally high read volume and the same code appearing in multiple places
How SDM works

One tap, four cryptographic steps behind it

STEP 01

Chip read

The phone taps the tag; the chip outputs its UID and current SDM read counter.

STEP 02

On-chip CMAC generation

Using the on-chip SDM key, the chip derives a session key via SV2 and computes an AES-CMAC over the SDM input.

STEP 03

Redirect to verification URL

The chip places the encrypted PICC data and the truncated 8-byte CMAC into a URL, opening this page for verification.

STEP 04

Server-side recompute & compare

The engine retrieves the registered key by UID, recomputes in constant time, and links the result to the specific product passport.

Live verifier

Verify an NTAG 424 DNA tap link live

Paste the full link (or its query part) produced by a real tag; or choose a preset vector to run the calculation live.

The NXP vector carries the key registered in the documentation; the CMAC is genuinely recomputed server-side.
Honest scope of the demo vectors: The “NXP vector” above is taken from Section 4 of NXP’s official application note AN12196; its key is the factory-default key given in that document (16 bytes of 0x00). The server recomputes and compares against it, which is a genuine cryptographic self-verification. The “self-test vectors” are generated by this site with a fixed key and are internally consistent; they are not official material. These vectors prove that the verification algorithm matches the official specification — they do not correspond to any real product on sale. Verifying real products requires per-tag injection and registration of an independent key.
Specifications & sources

Specifications and sources

AN12196 · NTAG 424 DNA and NTAG 424 DNA TagTamper features and hints — NXP’s official application note; it defines SDM/SUN, SV2 session-key derivation, SDM encrypted UID (PICCData) and CMAC truncation rules, and provides the Section 4 example vector.
https://www.nxp.com/docs/en/application-note/AN12196.pdf

AN10922 · Key diversification — NXP’s official application note; the standard CMAC method for diversifying tag keys by UID.
https://www.nxp.com/docs/en/application-note/AN10922.pdf

RFC 4493 · The AES-CMAC Algorithm — Internet Engineering Task Force; the basis for this engine’s CMAC primitive, verified group by group against its official test vectors.
https://www.rfc-editor.org/rfc/rfc4493

CEN EN 18220 — The data-carrier and security-level framework for Digital Product Passports; carriers with a secure element supporting dynamic security features and anti-cloning correspond to its higher security level (commonly called the L2 carrier). This engine makes the SDM dynamic CMAC a verifiable fact, rather than merely claiming “the chip is anti-counterfeit”.