C#环境下如何用APDU命令读取NTAG标签的原创签名?
Great question! I’ve worked with NTAG213/215/216 tags and ACS readers (including the ACR1281U-C1) extensively, so I can help you map the NTAG READ_SIG command to a valid APDU that your setup can send via ModWinsCard.
First, let’s recall the READ_SIG command from the NXP datasheet: it’s a native NTAG command with opcode 0x3C, no input parameters, and it returns the 32-byte original signature of the tag. To send this command via an APDU (since ModWinsCard uses ISO 7816-4 APDU framing for reader communication), you need to wrap the native NTAG instruction in a valid APDU structure.
The Valid APDU for READ_SIG
Here’s the exact APDU you need to send:
00 3C 00 00 20
Let’s break down each component to make it clear:
00: CLA (Class byte) – standard value for non-secure commands with this reader/tag combination3C: INS (Instruction byte) – directly maps to NTAG’sREAD_SIGopcode00 00: P1/P2 (Parameter bytes) – no parameters needed for this command, so both are set to 020: Le (Expected response length) – 32 bytes (hex0x20) which is the size of the NTAG’s original signature
How to Use This in Your C#/ModWinsCard Setup
In your existing code, when you want to retrieve the signature, construct this APDU as a byte array and pass it to the SCardTransmit method (via ModWinsCard’s wrapper). For example:
byte[] readSigApdu = new byte[] { 0x00, 0x3C, 0x00, 0x00, 0x20 }; // Assuming you have an established connection handle (hCard) byte[] response = TransmitApdu(hCard, readSigApdu); // The response array will contain the 32-byte signature (plus the 2-byte SW1/SW2 status word at the end)
Key Notes
- ACS Reader Compatibility: The ACR1281U-C1 fully supports this APDU – it’s designed to handle native NTAG commands framed as ISO 7816-4 APDUs.
- Tag Compatibility: This only works with NTAG213/215/216 tags (as per your datasheet reference). Other NXP tags (like MIFARE Classic) don’t support the
READ_SIGcommand. - Response Handling: The response will include the 32-byte signature followed by the standard status word
0x9000if the command succeeds. Make sure to strip the status word before passing the signature to your verification logic.
内容的提问来源于stack exchange,提问作者protossscout

