NXP statement on the publication by Radboud University Nijmegen 

NXP Semiconductors regrets that the Radboud University Nijmegen has revealed just yet details of the protocol and the algorithm of MIFARE Classic as well as some practical attacks on MIFARE Classic infrastructures to a broad public at the European Symposium on Research in Computer Security (ESORICS) in Malaga/Spain on Oct. 6th 2008.

NXP has an open dialogue with the University Nijmegen and other researchers on the security of MIFARE Classic and has taken the lead in communicating the effects of attacks and possible countermeasures to industry partners who need to know. Nevertheless, NXP would like to point out that a broad publication of detailed information to carry-out attacks with limited means is, at this moment in time, contradictory to the scientific goal of prevention and the responsible disclosure of sensitive information.

Security upgrades, whether still based on MIFARE Classic or migrating to a different card format, are complex system modifications which may involve a combination of hardware and software in the cards as well as in the infrastructure and back-end equipment. As these upgrades can – based on the particular system security requirements – take up to a number of years, it is not conceivable that all MIFARE Classic infrastructures have their security upgraded to the necessary level yet.

In the interest of our customers and to allow them a reasonable time for appropriate system security upgrades NXP had requested a delay of the presentation by seeking an injunction at court. On July 18th 2008 the court in Arnhem decided to allow the publication by the University Nijmegen.

As the manufacturer of MIFARE Classic chips it is NXP’s objective to transparently update all system integrators and operators of infrastructures which use MIFARE Classic in a timely manner, so that they can strengthen the end-to-end security of their systems.

NXP will continue working closely with its MIFARE Classic customers and partners and advises them to urgently take appropriate security measures to protect their systems. More details on how NXP Semiconductors is recommending to address this situation are posted on http://www.mifare.net/security/mifare_classic.asp.

 


2010-07-26
MIFARE Plus: The secure choice for transport ticketing
2010-06-23
NXP’s MIFARE Plus Chosen to Power Turkey’s Road Tolling System
2010-06-13
Schlage and SCM form partnership to offer enhanced standards-based solutions for physical and logical access
more...

Nanjing moves to MIFARE DES...
The citizens of Nanjing, China are no strangers to contactless smart cards: they have been using them since 2001.
City fans support NFC
For football fans, the start of a new season brings new hope, new expectations and new anticipation.
ISIC card brings more benef...
Students in St Petersburg, Russia, can now use their International Student Identity Card (ISIC) on the city's public transport network.
The final whistle
The final whistle of the 2006 FIFA World Cup™ has been blown and Italy went home as champions. With millions of fans descending on Germany to sample the unique atmosphere, the tournament was a huge success.
Olympics spur China’s RFID ...
As host nation for the 2008 Olympic Games, China is busy modernizing many of its infrastructure systems. As part of these developments, Beijing saw the full commercial roll-out of RFID ticketing for its transport network.
more...

Suar PnGo Sistemindo (Suar Group)
Country: (Indonesia)
BioCARD Technologies
Country: (India)
Wuhan Lixing(Torch) Power Sources Company Ltd
Country: (China)
Omnicpromotional MFG., ltd
Country: (China)
Shin Yeh Smart Card Co.,Ltd
Country: (China)
Now 989 partners in database
more news
back to top