Begin with the security objective
Identification, authentication and authorization answer different questions. Identification provides a claimed identity. Authentication establishes evidence supporting a claim. Authorisation determines whether the authenticated entity may perform an action. Reading an identifier alone does not prove that a credential is genuine.
NIST’s RFID guidance treats security as a combination of management, operational and technical controls across the system lifecycle. Its 2007 publication remains a useful architectural reference, but current IC documentation and current organizational requirements must govern a new implementation. NIST SP 800-98: Guidelines for Securing RFID Systems, 2007.
Understand the selected IC mechanism
A password protected memory area is not equivalent to a cryptographic application transaction. NTAG213, NTAG215 and NTAG216 include a 32 bit password mechanism; NXP documents its function and limits in the data sheet. Assess it against the actual threat model. NXP: NTAG213, NTAG215 and NTAG216 data sheet.
DESFire EV3 offers cryptographic capabilities including AES. Those capabilities must be configured through an appropriate application and key management design. An IC evaluation or certification does not automatically certify the finished credential, reader installation or business process. NXP: MIFARE DESFire EV3 product specification.
Treat legacy compatibility as an engineering decision
An installed system may require an older IC family. That requirement should be documented alongside the migration plan and security expectations. NXP states that MIFARE Classic is not recommended for new designs. A legacy replenishment decision and a new system design therefore require different evaluations. NXP: MIFARE Classic EV1 product and design guidance.
For a migration, qualify the reader firmware, credential application and issuing process together. Preserve continuity of service through defined transition rules. Changing the external card or fob design does not resolve a protocol or security limitation.
Provisioning, privacy and operations
Assign responsibility for key generation, storage, access and replacement. Use an agreed secure provisioning process for production secrets. Define revocation, lost credential handling and service recovery before deployment. Test denied transactions and failure states as deliberately as successful access.
Minimize sensitive information stored directly on a tag. An opaque identifier linked to a controlled backend can reduce direct disclosure, but it does not by itself eliminate tracking or privacy risks. Reader placement, access controls, retention and operational policy remain relevant. NIST SP 800-98: Guidelines for Securing RFID Systems, 2007.
Security approval should cover the complete system and its intended use. Product selection provides the available mechanisms; implementation and operation determine how effectively those mechanisms address the identified risks.
