RFID & NFC Labels
NTAG424 DNA NFC Labels
NTAG424 DNA labels for NFC product authentication and connected packaging. Specify the physical label and the delivery state your integrator needs: labels for your own personalisation, or agreed preparation through our encoding service. Validate the configured sample with your verification system before a bulk order.
Photo: a generic NFC label format example. It does not identify an NTAG424 DNA chip or confirm the construction of the quoted product.
Free standard samples · Quotation within one business day
Product details
Specify the label and delivery state
Use NTAG424 DNA when your project needs cryptographic tag verification beyond a static product link. Select the label for the actual packaging, then agree the personalisation and verification workflow. A valid tag message alone does not prove the contents of a package are genuine.
| Specify | Include in your request |
| Chip variant | Standard NTAG424 DNA, or a request for TagTamper opening detection; confirm the exact offered variant. |
| Physical label | Dimensions or available space, packaging material and contents, adhesive needs, artwork and required supply format. |
| Delivery state | Your integrator personalises the labels, or Proud Tek prepares an agreed configuration through the encoding service. Define how the sample will be accepted. |
| Verification | System provider, destination domain and intended phones; Proud Tek does not supply the verification service. |
| Order | Sample needs, batch quantity, delivery country and target date; exact construction and commercial terms are confirmed in the quotation. |
NTAG424 DNA chip capabilities
| Chip feature | NTAG424 DNA (NT4H2421Gx) |
| NFC interface | 13.56 MHz; ISO/IEC 14443 Type A; ISO/IEC 14443-4; NFC Forum Type 4 Tag |
| User memory | 416 bytes across three files: a 32-byte capability container, a 256-byte NDEF file and a 128-byte protected data file |
| Cryptography | AES-128; five on-chip AES-128 keys; access rights and Secure Dynamic Messaging depend on configuration |
| Identifier | Manufacturer-programmed 7-byte UID; optional Random ID mode; NXP originality signature |
| Dynamic messages | Configurable SDM mirroring of UID/counter data and an AES-CMAC into NDEF; protection depends on the settings |
| Read counter | 24-bit SDM read counter; behaviour depends on the read sequence and authentication state |
| Physical label | Antenna, dimensions, face material and adhesive confirmed for the quotation |
These are chip features described in the NXP NTAG424 DNA data sheet. The label image on this page is a generic format example, and the quoted chip and construction must be confirmed before ordering.
How Secure Dynamic Messaging (SUN) works
Secure Dynamic Messaging (SDM) powers the Secure Unique NFC (SUN) message. When configured for SDM, the chip inserts authentication data into an NDEF URL as it is read. The verification server checks the message and the counter history; reading an ordinary static URL is not a SUN verification.
- Tap. A compatible phone reads the configured NDEF URL. Confirm the phone models and reading behaviour in the pilot.
- On-chip. The chip generates the configured SDM fields, such as encrypted UID and counter data and an AES-CMAC. Successive reads within the same read sequence can use the same counter.
- Open. The phone opens the URL with the authentication fields, for example `https://verify.example.com/t?picc_data=…&cmac=…`.
- Verify. The server checks the configured cryptographic fields and the counter history for that tag.
- Result. The service displays the agreed outcome for a valid message, a previously seen message or invalid data.
The verifier should reject counters it has already seen or receives out of order. This detects those replays, but a message collected earlier and never submitted can still pass a later check. NXP describes this remaining risk in data sheet section 9.3. Your integrator must decide whether that is acceptable for the application; counter checks are not proof of a live tap. For configuration and verification details, use NXP AN12196.
Why a SUN tag resists cloning: the CMAC authentication tag
In AES mode, the NTAG424 DNA CMAC authentication tag is an 8-byte truncated AES-CMAC (NIST SP 800-38B). The chip computes it on each new tap from a session key derived from a secret key and, as configured, the UID and counter, and mirrors it into the URL (data sheet 9.3.7–9.3.9). Only a verifier holding the key can recompute it: a cloned tag can only replay messages the genuine tag produced, while a copied static URL works like the original.
What the brand's verification server must check
- Decrypt the UID and counter with the SDM meta-read key, if encrypted.
- Recompute the CMAC from the tag's file-read key, UID, counter and any covered URL data; reject a mismatch.
- Reject a repeated or out-of-order counter, then store the new one.
- Look up the UID: issued or not, and its product, order and market; check any TagTamper status mirrored in the message.
The five AES-128 keys and what each does
NTAG424 DNA holds five independent AES-128 keys, numbered Key 0 to Key 4. Key 0 is fixed as the application master key. The other four are assigned to roles by the integrator during personalisation; the mapping below is a common arrangement rather than a hard-wired one.
| Key | Typical role | What it controls |
| Key 0 | Application master key | Authenticates the changes that set up the tag: changing keys, file settings and the SUN configuration. Losing it locks the tag out of reconfiguration. |
| Key assigned as SDM meta-read key | Encrypts the PICC data | Encrypts the UID and read counter carried in the URL. The server uses the same key to decrypt them. |
| Key assigned as SDM file-read key | Authenticates SDM messages | Derives the per-read session key that produces the AES-CMAC. This is the key the server re-derives to recompute and compare the signature. |
| Key assigned to file read access | Gates reading | Controls whether the NDEF or protected data file is read freely or only after authentication. |
| Key assigned to file write / change access | Gates writing | Controls who may rewrite the NDEF template or the protected data file after issue. |
In production the SDM file-read key is usually diversified per tag from the key owner's master key, so one recovered key does not expose other tags. If the UID is encrypted in the URL, the meta-read key must not be UID-diversified, because the server decrypts the UID with it; that shared key needs especially strong protection (AN12196 section 3.4.2). Separately, the NXP originality signature supports a chip-provenance check. It does not authenticate package contents and is distinct from verification of an SDM message.
The TagTamper variant
NTAG424 DNA TagTamper (NT4H2421Tx) is a separate chip variant connected to a detection loop in the label. With the feature enabled, the chip checks the loop when powered and activated or when a relevant command triggers a measurement. Once it records the permanent status as Open, that status cannot be reset to Closed, including by re-personalisation. The permanent and current states can be included in SDM. See NXP TagTamper data sheet, section 10. An opening-detection project also needs a label that routes the loop across the seal; confirm the offered variant and construction in the quotation.
Secure NFC tags for luxury apparel authentication
For luxury apparel, use a tag that adds a fresh authentication code to every tap, such as NTAG424 DNA with SUN, rather than a fixed link: a copied tag cannot generate a new valid code. Proud Tek supplies the labels and any agreed configuration; the brand's system provider runs verification. NXP names authenticating goods and identifying sales outside authorised markets as uses (data sheet section 3).
| Placement | What it covers | Confirm per order |
| Hang tag | Checks up to purchase; usually removed, and a cut-off tag can move to another item | Card stock, attachment, print; a TagTamper loop if a seal must show opening |
| Sewn-in or care label | Stays with the garment for resale and returns checks unless cut off | Construction, metal trims, reading through fabric; care survival tested on samples (no wash rating given) |
Proud Tek produces NFC labels and custom tags; each construction is confirmed per order and tested on samples.
Luxury apparel sold in the United States
The same 13.56 MHz label serves US sales; the phones vary. iPhone XS and later read https URL tags in the background without an app (Apple); pilot with iPhone and Android models. A US retailer may also require a UHF tag for inventory (RFID for retail and apparel); Proud Tek makes UHF labels and hang tags too. Test both together.
Factory overruns and diversion: what NFC authentication can and cannot prove
A verified SUN message shows that a tag holding your key produced it, not how the item reached the seller. Overruns are units your contract manufacturer makes beyond the authorised quantity (US Justice Department example) and sells outside your channels, with genuine tags if spare personalised labels are at the factory. Diverted goods are authorised stock sold outside the agreed market. Controls around the tag:
- Control keys and personalisation: issue labels per purchase order; reconcile used and spoiled ones.
- Record each chip UID against product, factory, order and market.
- Activate on receipt, so surplus tags return “not issued”.
- Watch scan locations: scans outside a UID's issued market can flag possible diversion, not prove it. Scan IP addresses and locations can be personal data (GDPR Article 4(1)); agree what is logged.
Agree who delivers each part
Proud Tek can prepare an agreed label configuration through the RFID encoding service. The quotation must state which work is included. Labels we configure are each read back, and the order ships with a data report; labels with a printed serial also get a file that links each UID to its serial, and both come as Excel, CSV or XML. The buyer and integrator define the configuration and acceptance criteria; never send secret keys in an enquiry form, ordinary email or artwork file.
| Part of the project | Agree before sample preparation |
| Label construction | Proud Tek confirms the offered chip and physical construction against your packaging requirements. |
| Personalisation | Name the party preparing the labels and agree NDEF/SDM settings, access rights, key versions and delivery state. |
| Key management | The key owner and integrator define generation, diversification, protected transfer and access. Approve that process separately from the enquiry. |
| Verification service | Your nominated provider operates the endpoint, verifies messages, tracks counters and defines the user-facing results. |
| Batch acceptance | Agree the sample reference and the configuration record the batch must match. |
Sample acceptance checklist
| Check | Record before approving the batch |
| Physical reading | Test on the actual package with the intended phones; record placement, orientation and readability. |
| Verification | Check a valid message, a previously accepted URL and altered authentication data. Have the integrator assess a captured but previously unseen message. |
| TagTamper, if quoted | Test intact and opened samples with the agreed loop construction. Confirm the permanent Open state remains after power cycling. |
| Handover | Keep the approved label reference, non-secret configuration version, responsible parties and acceptance results. |
How NTAG424 DNA compares with other anti-counterfeit options
| Option | What is checked | What the project must provide |
| NTAG213 URL label | A static link or identifier | A destination page; no cryptographic proof from the URL record |
| Static or serialised QR code | A printed link or serial | A destination service; the printed code can be copied |
| NTAG424 DNA with SDM | A keyed authentication message and counter history | Personalisation, protected keys and a verifier; residual replay risk must be assessed |
For a product-information URL with no cryptographic verification requirement, NTAG213 NFC labels are the simpler and lower-cost choice. If you are still weighing a tap against a printed code for the same link, the RFID vs QR code guide compares them. Choose NTAG424 DNA when your integrator requires cryptographic verification and can provide the configuration and verification workflow. For closed-loop reader systems rather than consumer taps, compare a DESFire tag instead.
Request an NTAG424 DNA label quotation
Send the label dimensions or available space, mounting surface, quantity, artwork needs, destination and required date. Add the chip variant, requested delivery state and your integrator’s non-secret configuration summary. If any detail is unknown, identify it so it can be resolved before sample preparation. Use the product’s quotation or sample button to keep the NTAG424 label selected; see the sample arrangements and RFID label range for further options.
Plan the NFC verification workflow
Discuss your specification →Frequently asked questions
Does SUN reject every copied or photographed URL?
No. A verifier should reject a counter already accepted or received out of order, but a message captured earlier and never submitted can still be accepted later. The integrator must assess that remaining risk and define the verification policy. A valid SDM message is not, by itself, proof of a live tap or of the contents of a package.
How many keys does NTAG424 DNA have and who should hold them?
The chip holds five AES-128 keys. Key 0 is the application master key; the integrator assigns the remaining keys to the required roles. Agree the key owner, diversification scheme and protected transfer process before personalisation. Proud Tek can prepare an agreed configuration through the RFID encoding service; never include secret keys in an enquiry, ordinary email or artwork file.
Is a verification website included with the labels?
No. Proud Tek supplies the labels and can prepare an agreed configuration, but does not supply verification software or hosting. Name your system provider in the enquiry and agree who supplies the software, domain, personalisation and ongoing operations. Any additional preparation work must be specified in the quotation.
Do consumers need an app to verify a tap?
Compatible phones can read a configured NDEF URL and open a browser without a dedicated verification app. Behaviour depends on the phone, software and settings, so include the intended models in the pilot. A printed QR code can provide a fallback link, but it does not contain a fresh NFC authentication message.
Does Random ID make all tag data private?
No. Random ID changes the identifier presented during anti-collision; it does not encrypt every NDEF field or control what the verification website records. Have the integrator check the SDM fields and access rights, and keep personal data out of the tag and URL. Agree the verification service’s data handling separately.
Is NTAG424 DNA the same as NTAG424 DNA TagTamper?
No. TagTamper is a separate variant connected to a detection loop in the label. Once an enabled chip measures the loop as open, its permanent Open status cannot be reset to Closed, including by re-personalisation. Specify opening detection explicitly and confirm the chip, loop construction and sample test; it is not included by default with standard NTAG424 DNA.
Can NFC tags stop factory overruns or grey-market sales of apparel?
Not on their own: a valid tap authenticates the tag, not the garment's route to the seller. Per-order label issue, UID records and scan monitoring help detect overruns and diversion but cannot prove how a garment was obtained.
Should I choose NTAG213 or NTAG424 DNA?
Start with the application. For a straightforward product link with no cryptographic verification, see NTAG213 NFC labels. Choose NTAG424 DNA when your integrator requires its authentication features and can provide the configuration and server-side verification workflow.
Buyer guides
- How NFC Tags Work with Smartphones How NFC tags work with smartphones: the 13.56 MHz link, NDEF records, iPhone background reading, Android behaviour, metal and antenna position.
- How to Read an RFID Tag Quotation, Line by Line What decides RFID card and tag prices, and how to compare quotations line by line: unit-price basis, tooling, encoding, samples, freight and Incoterms.
- RFID RFP Template: Questions to Ask Every Supplier An RFID RFP template for distributors: the supplier questions that produce comparable quotes, and how to read the replies against one specification.
Ready to specify your order?
Send the product, quantity and application so we can confirm the options and pricing for your project.