P5DF081HN/T1AD2060 NXP Semiconductors, P5DF081HN/T1AD2060 Datasheet - Page 15

no-image

P5DF081HN/T1AD2060

Manufacturer Part Number
P5DF081HN/T1AD2060
Description
P5DF081HN/HVQFN32/REEL13//T1AD
Manufacturer
NXP Semiconductors
Series
MIFARE®r
Datasheet

Specifications of P5DF081HN/T1AD2060

Lead Free Status / RoHS Status
Lead free / RoHS Compliant
Lead Free Status / RoHS Status
Lead free / RoHS Compliant
NXP Semiconductors
Table 7.
P5DF081_SDS
Objective short data sheet
PUBLIC
Command
AV1 compatibility mode
SAM_ChangeKeyEntry
SAM_GetKeyEntry
SAM_ChangeKUCEntry This command updates any key usage counter entry stored in the MIFARE SAM AV2.
SAM_GetKUCEntry
SAM_DumpSessionKey The command SAM_DumpSessionKey can be used to retrieve the session key generated by the
SAM_DisableKeyEntry
AV2 Mode
The following rows give an outlook of the changes compared to the AV1 compatibility mode. All commands except
SAM_GetKUCEntry got partially or completely redefined for the AV2 mode. For more information see
SAM_ChangeKeyEntry
and
SAM_ChangeKUCEntry
SAM_GetKeyEntry
SAM key management commands
8.6.2 SAM key management commands
Description
This command updates any key entry of the KST.
The complete data set of the full key entry must always be sent, and it will be programmed to the
non-volatile memory of the MIFARE SAM AV2 as defined in the non-volatile ProMas.
The SAM_GetKeyEntry command allows reading the contents of the key entry specified in the
parameter KeyNo.
Instead of the full keys on positions a, b and c, only their key version will be returned, each
packed in one byte.
This command can be issued without valid (host) authentication.
Always limit, KeyNoCKUC and KeyVCKUC have to be sent; the parameter ProMas defines which
properties are programmed into the MIFARE SAM AV2 non-volatile memory.
Successful host authentication with the key specified in KeyNoCKUC of the current KUC entry is
required.
The SAM_GetKUCEntry command allows reading the data of the key usage counter entry
specified within the Parameter RefNoKUC.
This command can be issued without valid (host) authentication.
MIFARE SAM AV2.
The session key could be retrieved either in plain or encrypted with the session key of any logical
channel. A CRC is appended before encryption as usual.
This feature is necessary if cryptographic operations like en-/decipher should be handled by the
terminal microcontroller instead of the MIFARE SAM AV2.
potential security risk if not used in the correct way, it can be en-/disabled using the
configuration settings of every key entry.
The SAM_DisableKeyEntry command disables a key entry. After executing this command, the
corresponding disable flag in the key entry is set and the key entry cannot be used anymore for
authentication and key change procedures. The key entry can still be read by a
SAM_GetKeyEntry command. To reactivate the entry, a SAM_ChangeKeyEntry command has to
be issued. All fields in the key entry can still be changed by this command even if the entry has
been disabled.
In the AV1 version, there are two possibilities for changing key and KUC entries via the
SAM_ChangeKeyEntry and SAM_ChangeKUCEntry respectively. Which possibility is used,
depends on whether the "allow crypto with secret key" of the change key, i.e. the key referenced
by KeyNoCEK or KeyNoCKUC respectively, was set. If set, this allowed for offline preparation of
the key/KUC changing cryptogram.
In the new MIFARE SAM AV2 mode, these two possibilities are still supported, but which
possibility is used depends on the key class of the change key. Change keys are either Host Keys
or OfflineChange Keys. The second class will allow offline command generation.
The SAM_GetKeyEntry command allows reading the contents of the key entry specified in the
parameter KeyNo.
Instead of the full keys on positions a, b and c, only their key version will be returned, each
packed in one byte.
This command can be issued without valid (host) authentication.
All information provided in this document is subject to legal disclaimers.
Rev. 1 — 12 August 2010
191710
As this feature can be seen as a
Ref.
P5DF081
MIFARE SAM AV2
© NXP B.V. 2010. All rights reserved.
1.
15 of 36

Related parts for P5DF081HN/T1AD2060