Shenzhen Kaisere Technology CO., Ltd.

Automotive safety and charging pile solutions

MIFARE Duox for Smart City

MIFARE Duox for Smart City

Ask For Price

As the first MIFARE® IC to combineasymmetric and symmetric cryptography on a single chip, MIFARE DUOX simplifies key management and accelerates asymmetric authentication in security demandingaccess-management applications.


Target applications

•  Access management

•  Secure car access

•  Electric vehicle (EV) charging


MIFARE DUOX meets the needs of applicationsdemanding flexibility, dynamic key provisioningand very high security by addressing thelimitations of symmetric-based installations.By adding asymmetric cryptography and certificate management capabilities to the smartcard IC,MIFARE DUOX reduces the complexity of keyprovisioning and management, and enables newlevels of design flexibility, protection and scalability for security-dependent applications



1. Dual-Key Architecture Innovation

DESFire Duox pioneers the integration of asymmetric encryption (PKI) and symmetric encryption (AES/DES) within the MIFARE series, establishing a dual-security mechanism. This architecture enables:

Rapid Asymmetric Authentication: Streamlines key management via Public Key Infrastructure (PKI), ideal for cross-system or cross-organization scenarios.

Efficient Symmetric Encryption: Maintains the high-speed data processing of traditional AES/DES algorithms, optimized for high-frequency transactions.


2. Enhanced Security Performance

Achieves Common Criteria EAL5+ certification (equivalent to bank-grade smartcards) with hardware-level safeguards, including side-channel attack resistance and physical tamper detection.

Supports layered security policies, enabling dynamic encryption-level adjustments for diverse applications (e.g., low-security access control vs. high-security payment systems).


3. Expanded Application Scenarios

EV Charging Authentication: Ensures mutual authentication between charging stations and vehicles via PKI, preventing unauthorized charging or data tampering.

Smart Car Keys: Integrates NFC technology to enable smartphones or wearables as digital keys, with dynamic keys to block relay attacks.

Smart City Integration: Compatible with NXP’s AppXpplorer Cloud Service, supporting multi-application convergence (e.g., public transit, shared mobility, e-payments).


4. Technical Compatibility

Backward compatibility withISO/IEC 14443-4 and NFC standards, ensuring seamless integration with existing MIFARE DESFire EV3 infrastructure.

Features Transaction MAC (Message Authentication Code) and Virtual Card Architecture for enhanced privacy and data integrity.


5. Market Positioning & Significance

As the first MIFARE product to support public-key cryptography, Duox addresses the limitations of traditional symmetric encryption in high-security IoT scenarios. It delivers a standardized solution for device trust in smart cities, Industry 4.0, and beyond.


Product features

MIFARE DUOX
IC characteristics for memory and RF interface
Non-volatile (NV) user memory size [KB]2/4/8/16
Write endurance and data retention1.000.000 cycles and 25 years
Frequency [MHz]13.56
Baud rate [kbits/s]106 up to 848 (and support of VHBR)
Standard compliance and certification
ISO/IEC 14443Layer 1-4
ISO/IEC 7816Yes, ISO/IEC 7816-4 commands and wrapped command format
ISO/SAE 21434Yes
Common CriteriaCertification on EAL 6+ AVA_VAN.5 (for HW and SW)
NFC ForumTag Type 4
Security
Symmetric cryptographyAES-128, AES-256
Asymmetric cryptographyECC with ECDSA, ECDH and NIST P-256 or brainpoolP256r1
Asymmetric authenticationECC-based mutual, reader-unilateral and card-unilateral authentication
Support of post-quantum-cryptoFuture-proof for post-quantum era (via AES-256 strength and key length)
Data confidentiality, authenticity, integrityAES-CMAC, AES-CBC encryption, secure channel establishment via
EV2 secure messaging, secure dynamic messaging (SUN feature)
Extended features and functionality
True multi-application supportUnlimited number of application and Delegated Application Management feature
Proximity CheckMechanism to detect relay attacks
Transaction MAC and Transaction SignatureGenerating a secure proof of executed transactions
Transaction TimerFunctionality to prevent man-in-the-middle attacks
Originality CheckVerification of genuineness of the IC by dynamic ECC authentication
EV-charging functionalityEV-charging specific command set as defined in VDE-AR-E 2532-100
Temperature range-40 to +105°C on silicon level