Analytics cookies. Can we use Google Analytics and its cookies to see how visitors use this site? Change this any time under Cookie settings in the footer. Privacy policy
A contactless tag or key fob built on NXP MIFARE DESFire, offering AES cryptography and a multi-application file structure for access control, transit and cashless systems. Available in ABS, PC, FR4 and wood. Confirm the DESFire generation, memory and encoding, then test a sample before ordering.
Free standard samples ยท Quotation within one business day
Product details
Features
1, Superior Security
The DESFire Tag is equipped with sophisticated cryptographic algorithms, is resistant to cloning and tampering. It suits applications that need resistance to cloning and tampering.
2, Flexibility and Scalability
Supports multiple applications on a single DESFire tag, allowing for easy expansion and future upgrades.
3, Enough Reading Distance
The tags pair a DESFire chip with a tuned antenna for reliable reading at close range; confirm the read distance with your reader.
Specification:
Item
DESFire Tag
Material
ABS, PC, FR4, wood, etc.
Chip
DESFire 8k EV2, 70PF
Frequency
13.56MHZ
Protocol
ISO14443
Color
White. Black, green, blue, etc., can be customized.
Size
45*30*2.5mm customized.
Reading distance
2โ4 cm, depending on the reader
Write Endurance
100000 times
Working Temperature
Confirmed per body in the quotation
Data Retention Time
10 years
Printing Options
Silk-screen printing, UV printing, etc
Crafts Available
laser engraving, Bar code, QR code, etc.
Different material for the DESFire Tag
Epoxy DESFire card
Printed PVC Tag coated with transparent epoxy
FR4 DESFire fob
Most durable key fob with DESFire chip
ABS DESFire key fob
DESFire keyfob with simple and strong design
What a DESFire tag is
A DESFire tag pairs an NXP MIFARE DESFire IC with a tuned antenna in a key fob, disc or industrial housing instead of an ID-1 card body. The chip works at 13.56 MHz on the ISO/IEC 14443 Type A air interface and communicates with the ISO/IEC 14443-4 transmission protocol. Data is held in an application-and-file structure addressed with ISO/IEC 7816-4 commands, and each application is protected by hardware cryptography: DES, 2K3DES and 3K3DES for compatibility, and AES with 128-bit keys for current designs. It is the same IC used in our MIFARE DESFire EV2 cards and the wider MIFARE DESFire family; a DESFire tag is simply that chip in a fob or tag form factor.
DESFire generation and memory
DESFire is a chip family, not a single part. The generations share the 13.56 MHz ISO/IEC 14443 Type A interface, the ISO/IEC 7816-4 file commands and the DES/2K3DES/3K3DES/AES engine, and each newer chip keeps a backward-compatibility mode for the one before it. Confirm the exact generation and memory your system was built for; a label on a finished tag does not prove which chip is inside.
Generation
Memory options
Notes
MIFARE DESFire EV1
2 KB / 4 KB / 8 KB
Up to 28 applications, Common Criteria EAL4+; NXP marks it not recommended for new designs
MIFARE DESFire EV2
2 KB / 4 KB / 8 KB
Adds multiple key sets, Transaction MAC and Proximity Check; EAL5+; not recommended for new designs, superseded by EV3
MIFARE DESFire EV3
2 KB / 4 KB / 8 KB
Adds Secure Dynamic Messaging (SUN) and a Transaction Timer; EAL5+; NXP's recommended part for new designs
NXP rates the DESFire EV2 IC for 25-year data retention and a typical 500,000 write cycles; the finished-tag figures in the table above are conservative construction values. The tags on this page are built by default around the DESFire EV2 8K chip in its 70 pF version, but we match the generation and memory to your reader and application. For the full EV1/EV2/EV3 comparison, reader-compatibility checklist and cloning notes, see the MIFARE DESFire EV2 cards page.
Read range, antenna and the H parts
A fob or disc carries a smaller antenna than an ID-1 card, so the read range is shorter โ a few centimetres at a typical access reader. NXP offers each DESFire memory size as a standard 17 pF part for card-sized antennas and as a 70 pF โHโ part (for example MF3DH82) tuned for the small antennas used in fobs, discs and wristbands, so the tag body and the chip variant are chosen together. Read range always depends on the reader and its antenna at least as much as on the tag, so test the intended reader with a sample before a bulk order rather than relying on a quoted distance.
Materials and form factors
The same DESFire chip goes into several tag bodies: an ABS key fob for everyday access, an epoxy-coated disc for badges and phone cases, and an FR4 tag for the most durable industrial use. Wood and PC bodies are available for brands that want a different finish. Choose the body for the environment โ FR4 and ABS for daily handling and outdoor gates, epoxy for a slim adhesive tag โ and the antenna is matched to the body so the read range stays consistent across a batch.
Reader compatibility and encoding
A reader that shows a tag number has only read the UID; it has not authenticated to a DESFire application. Before standardising on a DESFire tag, confirm these points with your reader or lock vendor.
Air interface: the reader implements ISO/IEC 14443-2/3 Type A and the ISO/IEC 14443-4 transmission protocol DESFire uses. A 13.56 MHz rating alone does not confirm 14443-4 support.
Command set and secure messaging: the firmware runs the DESFire and ISO/IEC 7816-4 commands your application needs, in the secure-messaging mode (D40, EV1 or EV2) and key type (AES or legacy 3DES) the system uses.
Keys and diversification: agree who holds the application master keys and how they are diversified per tag; encoding is done only for the organisation that administers the system.
Delivery state: decide whether we ship blank tags for your own issuing process, or pre-personalise them to an agreed application and file plan. Do not include live secret keys in the enquiry.
Sample test: authenticate and run the real transaction with production reader firmware before any bulk order.
Ordering DESFire tags
We produce DESFire tags and fobs with genuine NXP chips in our Shenzhen factory, built to your specification, with silk-screen or UV printing, laser engraving, barcodes, QR codes and serial numbering available for the selected body and material; serial-numbered tags are supplied with an Excel, CSV or XML record of each tag's UID and the number marked on it (see the RFID encoding service). Free standard samples are available for reader testing (a customised sample carries a setup fee), and the standard lead time is two to three weeks after the artwork and specification are approved. Pricing is by quotation. Send the DESFire generation and memory, the reader model, the tag body and quantity through the inquiry form, by email or on WhatsApp, and we confirm the exact part and its availability in the quotation. We do not supply access-control readers, locks or software, and we do not duplicate credentials from systems the buyer does not administer. Related choices: MIFARE DESFire EV2 cards, the MIFARE DESFire family, MIFARE Classic cards and RFID key fobs for access control.
DESFire is a family: EV1, EV2 and EV3 share the interface but differ in features and certification. The tags are built by default around DESFire EV2 8K, but we match the generation and memory (2K, 4K or 8K) to your reader and application. NXP recommends EV3 for new designs and marks EV1 and EV2 as not recommended for new designs, so tell us which chip your system was qualified for.
How far can a DESFire tag be read?
A fob or disc carries a smaller antenna than a card, so a typical access reader reads it at a few centimetres. Read range depends on the reader and its antenna as much as on the tag. Match the 70 pF โHโ chip variant to a small tag body and test the intended reader with a sample before ordering.
Can a DESFire tag be cloned?
A properly keyed DESFire application has no publicly known practical clone: the chip protects each application with AES-128 (or 3DES) mutual authentication, so the card and reader prove they share a key without transmitting it. General NFC tools can read the UID and any unprotected data but cannot recover the keys. Do not build access control on the UID alone; enrol and verify each tag through its authenticated application.
Do the tags arrive ready for my access system?
Only if that is agreed. A tag in its factory-default or transport state carries no project application or enrolment, although the chip still has its default configuration and key material. Decide whether we deliver tags in that state for your own issuing process or pre-personalise them to an agreed application and file plan, and who loads the production keys. After pre-personalisation each tag is read again before packing, and the order includes a data report. Encoding is performed only for the organisation that administers the system.
Which material should I choose?
ABS fobs suit everyday access; FR4 tags are the most durable for industrial use and outdoor gates; epoxy discs give a slim adhesive tag for badges and phone cases; wood and PC bodies are available for a different finish. The antenna is matched to the body so read range is consistent across the batch.
Will a DESFire tag work with my existing readers?
Only if the readers implement the ISO/IEC 14443-4 protocol, the DESFire command set and the secure-messaging mode and keys your application uses. Detecting the chip or reading its UID does not prove that. Confirm the reader firmware and test a sample end to end before a bulk order.
Buyer guides
How to Read an RFID Tag Quotation, Line by LineWhat decides RFID card and tag prices, and how to compare quotations line by line: unit-price basis, tooling, encoding, samples, freight and Incoterms.