RFID & NFC Labels

NTAG424 DNA NFC Labels

NTAG424 DNA labels for NFC product authentication and connected packaging. Specify the physical label and the delivery state your integrator needs: labels for your own personalisation, or agreed preparation through our encoding service. Validate the configured sample with your verification system before a bulk order.

Photo: a generic NFC label format example. It does not identify an NTAG424 DNA chip or confirm the construction of the quoted product.

Free standard samples · Quotation within one business day

Product details

Specify the label and delivery state

Use NTAG424 DNA when your project needs cryptographic tag verification beyond a static product link. Select the label for the actual packaging, then agree the personalisation and verification workflow. A valid tag message alone does not prove the contents of a package are genuine.

SpecifyInclude in your request
Chip variantStandard NTAG424 DNA, or a request for TagTamper opening detection; confirm the exact offered variant.
Physical labelDimensions or available space, packaging material and contents, adhesive needs, artwork and required supply format.
Delivery stateYour integrator personalises the labels, or Proud Tek prepares an agreed configuration through the encoding service. Define how the sample will be accepted.
VerificationSystem provider, destination domain and intended phones; Proud Tek does not supply the verification service.
OrderSample needs, batch quantity, delivery country and target date; exact construction and commercial terms are confirmed in the quotation.

NTAG424 DNA chip capabilities

Chip featureNTAG424 DNA (NT4H2421Gx)
NFC interface13.56 MHz; ISO/IEC 14443 Type A; ISO/IEC 14443-4; NFC Forum Type 4 Tag
User memory416 bytes across three files: a 32-byte capability container, a 256-byte NDEF file and a 128-byte protected data file
CryptographyAES-128; five on-chip AES-128 keys; access rights and Secure Dynamic Messaging depend on configuration
IdentifierManufacturer-programmed 7-byte UID; optional Random ID mode; NXP originality signature
Dynamic messagesConfigurable SDM mirroring of UID/counter data and an AES-CMAC into NDEF; protection depends on the settings
Read counter24-bit SDM read counter; behaviour depends on the read sequence and authentication state
Physical labelAntenna, dimensions, face material and adhesive confirmed for the quotation

These are chip features described in the NXP NTAG424 DNA data sheet. The label image on this page is a generic format example, and the quoted chip and construction must be confirmed before ordering.

How Secure Dynamic Messaging (SUN) works

Secure Dynamic Messaging (SDM) powers the Secure Unique NFC (SUN) message. When configured for SDM, the chip inserts authentication data into an NDEF URL as it is read. The verification server checks the message and the counter history; reading an ordinary static URL is not a SUN verification.

  • Tap. A compatible phone reads the configured NDEF URL. Confirm the phone models and reading behaviour in the pilot.
  • On-chip. The chip generates the configured SDM fields, such as encrypted UID and counter data and an AES-CMAC. Successive reads within the same read sequence can use the same counter.
  • Open. The phone opens the URL with the authentication fields, for example `https://verify.example.com/t?picc_data=…&cmac=…`.
  • Verify. The server checks the configured cryptographic fields and the counter history for that tag.
  • Result. The service displays the agreed outcome for a valid message, a previously seen message or invalid data.

The verifier should reject counters it has already seen or receives out of order. This detects those replays, but a message collected earlier and never submitted can still pass a later check. NXP describes this remaining risk in data sheet section 9.3. Your integrator must decide whether that is acceptable for the application; counter checks are not proof of a live tap. For configuration and verification details, use NXP AN12196.

Why a SUN tag resists cloning: the CMAC authentication tag

In AES mode, the NTAG424 DNA CMAC authentication tag is an 8-byte truncated AES-CMAC (NIST SP 800-38B). The chip computes it on each new tap from a session key derived from a secret key and, as configured, the UID and counter, and mirrors it into the URL (data sheet 9.3.7–9.3.9). Only a verifier holding the key can recompute it: a cloned tag can only replay messages the genuine tag produced, while a copied static URL works like the original.

What the brand's verification server must check

  1. Decrypt the UID and counter with the SDM meta-read key, if encrypted.
  2. Recompute the CMAC from the tag's file-read key, UID, counter and any covered URL data; reject a mismatch.
  3. Reject a repeated or out-of-order counter, then store the new one.
  4. Look up the UID: issued or not, and its product, order and market; check any TagTamper status mirrored in the message.

The five AES-128 keys and what each does

NTAG424 DNA holds five independent AES-128 keys, numbered Key 0 to Key 4. Key 0 is fixed as the application master key. The other four are assigned to roles by the integrator during personalisation; the mapping below is a common arrangement rather than a hard-wired one.

KeyTypical roleWhat it controls
Key 0Application master keyAuthenticates the changes that set up the tag: changing keys, file settings and the SUN configuration. Losing it locks the tag out of reconfiguration.
Key assigned as SDM meta-read keyEncrypts the PICC dataEncrypts the UID and read counter carried in the URL. The server uses the same key to decrypt them.
Key assigned as SDM file-read keyAuthenticates SDM messagesDerives the per-read session key that produces the AES-CMAC. This is the key the server re-derives to recompute and compare the signature.
Key assigned to file read accessGates readingControls whether the NDEF or protected data file is read freely or only after authentication.
Key assigned to file write / change accessGates writingControls who may rewrite the NDEF template or the protected data file after issue.

In production the SDM file-read key is usually diversified per tag from the key owner's master key, so one recovered key does not expose other tags. If the UID is encrypted in the URL, the meta-read key must not be UID-diversified, because the server decrypts the UID with it; that shared key needs especially strong protection (AN12196 section 3.4.2). Separately, the NXP originality signature supports a chip-provenance check. It does not authenticate package contents and is distinct from verification of an SDM message.

The TagTamper variant

NTAG424 DNA TagTamper (NT4H2421Tx) is a separate chip variant connected to a detection loop in the label. With the feature enabled, the chip checks the loop when powered and activated or when a relevant command triggers a measurement. Once it records the permanent status as Open, that status cannot be reset to Closed, including by re-personalisation. The permanent and current states can be included in SDM. See NXP TagTamper data sheet, section 10. An opening-detection project also needs a label that routes the loop across the seal; confirm the offered variant and construction in the quotation.

Secure NFC tags for luxury apparel authentication

For luxury apparel, use a tag that adds a fresh authentication code to every tap, such as NTAG424 DNA with SUN, rather than a fixed link: a copied tag cannot generate a new valid code. Proud Tek supplies the labels and any agreed configuration; the brand's system provider runs verification. NXP names authenticating goods and identifying sales outside authorised markets as uses (data sheet section 3).

PlacementWhat it coversConfirm per order
Hang tagChecks up to purchase; usually removed, and a cut-off tag can move to another itemCard stock, attachment, print; a TagTamper loop if a seal must show opening
Sewn-in or care labelStays with the garment for resale and returns checks unless cut offConstruction, metal trims, reading through fabric; care survival tested on samples (no wash rating given)

Proud Tek produces NFC labels and custom tags; each construction is confirmed per order and tested on samples.

Luxury apparel sold in the United States

The same 13.56 MHz label serves US sales; the phones vary. iPhone XS and later read https URL tags in the background without an app (Apple); pilot with iPhone and Android models. A US retailer may also require a UHF tag for inventory (RFID for retail and apparel); Proud Tek makes UHF labels and hang tags too. Test both together.

Factory overruns and diversion: what NFC authentication can and cannot prove

A verified SUN message shows that a tag holding your key produced it, not how the item reached the seller. Overruns are units your contract manufacturer makes beyond the authorised quantity (US Justice Department example) and sells outside your channels, with genuine tags if spare personalised labels are at the factory. Diverted goods are authorised stock sold outside the agreed market. Controls around the tag:

  • Control keys and personalisation: issue labels per purchase order; reconcile used and spoiled ones.
  • Record each chip UID against product, factory, order and market.
  • Activate on receipt, so surplus tags return “not issued”.
  • Watch scan locations: scans outside a UID's issued market can flag possible diversion, not prove it. Scan IP addresses and locations can be personal data (GDPR Article 4(1)); agree what is logged.

Agree who delivers each part

Proud Tek can prepare an agreed label configuration through the RFID encoding service. The quotation must state which work is included. Labels we configure are each read back, and the order ships with a data report; labels with a printed serial also get a file that links each UID to its serial, and both come as Excel, CSV or XML. The buyer and integrator define the configuration and acceptance criteria; never send secret keys in an enquiry form, ordinary email or artwork file.

Part of the projectAgree before sample preparation
Label constructionProud Tek confirms the offered chip and physical construction against your packaging requirements.
PersonalisationName the party preparing the labels and agree NDEF/SDM settings, access rights, key versions and delivery state.
Key managementThe key owner and integrator define generation, diversification, protected transfer and access. Approve that process separately from the enquiry.
Verification serviceYour nominated provider operates the endpoint, verifies messages, tracks counters and defines the user-facing results.
Batch acceptanceAgree the sample reference and the configuration record the batch must match.

Sample acceptance checklist

CheckRecord before approving the batch
Physical readingTest on the actual package with the intended phones; record placement, orientation and readability.
VerificationCheck a valid message, a previously accepted URL and altered authentication data. Have the integrator assess a captured but previously unseen message.
TagTamper, if quotedTest intact and opened samples with the agreed loop construction. Confirm the permanent Open state remains after power cycling.
HandoverKeep the approved label reference, non-secret configuration version, responsible parties and acceptance results.

How NTAG424 DNA compares with other anti-counterfeit options

OptionWhat is checkedWhat the project must provide
NTAG213 URL labelA static link or identifierA destination page; no cryptographic proof from the URL record
Static or serialised QR codeA printed link or serialA destination service; the printed code can be copied
NTAG424 DNA with SDMA keyed authentication message and counter historyPersonalisation, protected keys and a verifier; residual replay risk must be assessed

For a product-information URL with no cryptographic verification requirement, NTAG213 NFC labels are the simpler and lower-cost choice. If you are still weighing a tap against a printed code for the same link, the RFID vs QR code guide compares them. Choose NTAG424 DNA when your integrator requires cryptographic verification and can provide the configuration and verification workflow. For closed-loop reader systems rather than consumer taps, compare a DESFire tag instead.

Request an NTAG424 DNA label quotation

Send the label dimensions or available space, mounting surface, quantity, artwork needs, destination and required date. Add the chip variant, requested delivery state and your integrator’s non-secret configuration summary. If any detail is unknown, identify it so it can be resolved before sample preparation. Use the product’s quotation or sample button to keep the NTAG424 label selected; see the sample arrangements and RFID label range for further options.

Plan the NFC verification workflow

  1. Send with your enquiry

    Describe the verification use case, label surface and application. Identify who will configure the keys, personalise tags and operate the verification service.

  2. Approve a sample

    Have your integrator test valid taps and replay handling with the intended phone flow and backend. Verify the final configured sample before ordering a batch.

  3. Confirm the quotation

    Agree the exact chip, label format and supplied configuration, alongside the responsibilities for key handling and verification. Confirm any requested tamper feature by exact part number.

Discuss your specification →

Frequently asked questions

Does SUN reject every copied or photographed URL?

No. A verifier should reject a counter already accepted or received out of order, but a message captured earlier and never submitted can still be accepted later. The integrator must assess that remaining risk and define the verification policy. A valid SDM message is not, by itself, proof of a live tap or of the contents of a package.

How many keys does NTAG424 DNA have and who should hold them?

The chip holds five AES-128 keys. Key 0 is the application master key; the integrator assigns the remaining keys to the required roles. Agree the key owner, diversification scheme and protected transfer process before personalisation. Proud Tek can prepare an agreed configuration through the RFID encoding service; never include secret keys in an enquiry, ordinary email or artwork file.

Is a verification website included with the labels?

No. Proud Tek supplies the labels and can prepare an agreed configuration, but does not supply verification software or hosting. Name your system provider in the enquiry and agree who supplies the software, domain, personalisation and ongoing operations. Any additional preparation work must be specified in the quotation.

Do consumers need an app to verify a tap?

Compatible phones can read a configured NDEF URL and open a browser without a dedicated verification app. Behaviour depends on the phone, software and settings, so include the intended models in the pilot. A printed QR code can provide a fallback link, but it does not contain a fresh NFC authentication message.

Does Random ID make all tag data private?

No. Random ID changes the identifier presented during anti-collision; it does not encrypt every NDEF field or control what the verification website records. Have the integrator check the SDM fields and access rights, and keep personal data out of the tag and URL. Agree the verification service’s data handling separately.

Is NTAG424 DNA the same as NTAG424 DNA TagTamper?

No. TagTamper is a separate variant connected to a detection loop in the label. Once an enabled chip measures the loop as open, its permanent Open status cannot be reset to Closed, including by re-personalisation. Specify opening detection explicitly and confirm the chip, loop construction and sample test; it is not included by default with standard NTAG424 DNA.

Can NFC tags stop factory overruns or grey-market sales of apparel?

Not on their own: a valid tap authenticates the tag, not the garment's route to the seller. Per-order label issue, UID records and scan monitoring help detect overruns and diversion but cannot prove how a garment was obtained.

Should I choose NTAG213 or NTAG424 DNA?

Start with the application. For a straightforward product link with no cryptographic verification, see NTAG213 NFC labels. Choose NTAG424 DNA when your integrator requires its authentication features and can provide the configuration and server-side verification workflow.

Buyer guides

Ready to specify your order?

Send the product, quantity and application so we can confirm the options and pricing for your project.

Prefer to message us? WhatsApp or email about this product.

Get a quote WhatsApp
WhatsApp