You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为MIFARE 1K卡设置锁定命令、防克隆及防擦除权限?

Alright, let's walk through exactly how to lock down your MIFARE 1K card against erasure and cloning by configuring the sector trailer blocks correctly. This is the most reliable way to enforce access control, so let's break it down step by step for your project:

1. First, Clarify Our Security Goals

To prevent cloning/erasure, we need two key protections:

  • Make the data blocks (blocks 0-2 in each sector) read-only so no one can overwrite or erase their content.
  • Protect the sector trailer itself (block 3) so only your secret key can modify access rules or keys (stopping attackers from reconfiguring the card).
2. Step-by-Step Configuration Process

2.1 Authenticate to the Target Sector

Before modifying a sector's trailer, you need to authenticate using either Key A or Key B. By default, MIFARE 1K cards use FFFFFFFFFFFF as the default Key A for all sectors.

Use your reader's authentication command (usually MF_AUTH_KEY_A or MF_AUTH_KEY_B) with the target sector number and the current key. Here's a pseudocode example:

authenticate_result = reader.mifare_auth(sector_number, KEY_A, "FFFFFFFFFFFF")
if authenticate_result != SUCCESS:
    # Handle failure (wrong key, card not detected, etc.)

2.2 Define & Calculate Access Bits

The access bits (bytes 6-8 of the sector trailer) control what operations are allowed on each block. Let's use a secure configuration tailored to your needs:

  • Data blocks (0-2): Readable with Key A, but no write/erase permissions (so attackers can't modify content).
  • Sector trailer (block 3): Readable with Key A, but only Key A can modify the trailer (so attackers can't change access rules or keys).

Using the access bit structure you shared, we calculate the three bytes:

  • Byte 6: 0x78 (binary 01111000)
  • Byte 7: 0x7F (binary 01111111)
  • Byte 8: 0x08 (binary 00001000)

This setup ensures:

  • Data blocks are strictly read-only (only your secret Key A can read them; no writes/erases allowed).
  • The sector trailer can only be modified with Key A, keeping your security rules locked down.

2.3 Write the Sector Trailer Block

The sector trailer is 16 bytes total, structured as:
[Key A (6 bytes)] + [Access Bits (3 bytes)] + [GPB (1 byte)] + [Key B (6 bytes)]

Fill in each component:

  1. Key A: Replace the default FFFFFFFFFFFF with your own secret 6-byte key (e.g., 1234567890AB in hex).
  2. Access Bits: Use the pre-calculated bytes: 0x78, 0x7F, 0x08.
  3. GPB (General Purpose Byte): Leave this as 0x00 (we don't need special features like value blocks here).
  4. Key B: You can set this to FFFFFFFFFFFF or a custom key, but with our access bits, Key B won't be readable or usable for modifications—so it's irrelevant for our security goal.

Putting it all together, the 16-byte trailer data (using Key A 1234567890AB) would be:
0x12, 0x34, 0x56, 0x78, 0x90, 0xAB, 0x78, 0x7F, 0x08, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF

Write this to block 3 of the sector using your reader's write command (pseudocode):

trailer_data = bytearray([0x12, 0x34, 0x56, 0x78, 0x90, 0xAB, 0x78, 0x7F, 0x08, 0x00, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF])
write_result = reader.mifare_write(sector_block_3_address, trailer_data)
if write_result != SUCCESS:
    # Handle failure (authentication expired, card removed, etc.)

2.4 Verify the Configuration

After writing, confirm everything works with two checks:

  1. Read the sector trailer: Re-authenticate with Key A, then read block 3. Ensure the access bits match what you wrote.
  2. Test data block permissions: Try writing to block 0 of the sector—this should fail. Reading block 0 should succeed when authenticated with Key A.
3. Critical Mistakes to Avoid
  • Don't lose Key A: Once you set this configuration, you can't modify the sector again without Key A. Store it securely (e.g., encrypted vault, offline storage).
  • Test on a spare card first: Always validate the process with a blank MIFARE 1K card before applying it to production cards—mistakes here can make a sector permanently unreadable.
  • Double-check access bits: The access bit structure uses redundant coding (nCx_y = NOT Cx_y) to prevent corruption. A miscalculation could brick the sector.

内容的提问来源于stack exchange,提问作者Arjun saini

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 09:37:32