NTAG 424 DNA Labels Now in Production: AES-128 Encrypted NFC Authentication
NTAG 424 DNA labels are now in regular production at QS Defender, closing the biggest gap between what an NFC label promises and what most NFC labels actually deliver. A standard NTAG21x tag stores one static URL: copy that URL onto a blank tag and the clone behaves identically. The NTAG 424 DNA chip from NXP changes the payload itself on every single tap, cryptographically, with no app required on the phone. This announcement covers what went live on our line, how the technology works when a consumer taps, what changes in the production and encoding process, and how to get evaluation samples.
Label conversion and die-cutting at the QS Defender production facility: encrypted NFC inlays now run through the same line as our holographic and VOID product families.
Why the Encrypted NFC Label Exists at All
The NFC tags most brands currently buy — the NTAG213/215/216 family — were designed for short links and pairing, not for defending authenticity. They store one fixed NDEF payload, protect it with at most a 32-bit password, and expose a UID that has never been a clone defense on its own. Once a single genuine tag's URL is skimmed, the counterfeiter's problem is solved: every fake unit can carry the same static link, and the consumer sees a valid page. For a structured comparison of the whole NFC and UHF lineup, see our RFID & NFC anti-counterfeiting labels buyer's guide.
| Capability | Static NFC (NTAG21x class) | NTAG 424 DNA |
|---|---|---|
| Tag authentication | 32-bit password (plaintext compare) | AES-128 SUN authentication on every read |
| URL content | Fixed at encoding | Unique per tap: encrypted chip data + 8-byte CMAC |
| Clone behavior | Copied URL passes as genuine | Copied URL replays an old tap; server detects the stale counter |
| Tamper detection | None | Optional TagTamper loop, status mirrored into the URL |
| User memory | 144–888 bytes, one NDEF file | 416 bytes: 32 CC + 256 NDEF + 128 protected data file |
| Typical unit price band | ≈ USD 0.05–0.20 | ≈ USD 0.2–1.0 (inlay size and volume dependent) |
What Happens on One Tap: SUN and SDM, Concretely
The marketing names confuse people, so here is the mechanism. SDM (Secure Dynamic Messaging) is the chip feature: during encoding, the tag is told the byte offsets of two placeholder parameters in its stored URL. On every read, the chip fills those parameters with fresh data. SUN (Secure Unique NFC) is the guarantee that falls out: a URL that is different every time and verifiable only by a server holding the keys.
Two values are mirrored into the URL on each tap:
- Encrypted PICC data (the
piccparameter): 16 bytes of AES-128-CBC output under the tag's SDMMetaRead key. The plaintext is one tag-type byte, the 7-byte UID, and a 3-byte read counter — so the UID never appears in clear in the URL. - The CMAC (the
cmacparameter): 8 bytes of a truncated AES-CMAC computed per NIST SP 800-38B, under a session key derived from the tag's SDMFileRead key, its UID and the current counter value.
Because the 24-bit read counter (maximum 16,777,215 taps) feeds the calculation and increments on every read, a URL captured from a past tap cannot be replayed to fake a new one — the server simply sees a counter value it has already accepted. And because the keys exist only inside the chip's protected key store and in the brand's verifier backend, nothing on the phone can forge a valid message: verification is server-side by necessity, which is also why any claim of offline verification for this chip family should be treated as false. For a line-by-line walkthrough of the SDM fields, NXP's application note AN12196 is the reference, and the NFCore SUN/SDM explainer is a good plain-language companion.
Inside the Line: Encoding, Key Custody, Verification
The chip is only half of the product. An encrypted NFC label is a manufacturing promise as much as a silicon feature, so the production flow matters:
- Inlay conversion and quality gates. Chip bonding, antenna connection and face printing run on the same conversion lines as our other smart-label families, with electrical yield checks between processes.
- Personalisation with five customer-defined AES-128 keys. Keys are written once during encoding and cannot be read back out. Key custody is a project decision: keys can be generated in the brand's environment and handed over as encoded inputs, or derived in our provisioning run under an agreed key management plan.
- SDM configuration matched to the backend. The ASCII offsets of the
piccandcmacplaceholders must line up exactly with the customer's verification endpoint query format — a mismatched offset still produces a URL, just one the server cannot parse. Every batch is validated against a reference decode before release. - 100% encode verification. Each finished label is read on fixed production readers after encoding, and sample tags from each roll are tapped with standard consumer phones to confirm the background-read behavior on both major platforms.
- ESD-safe roll packaging compatible with automated applicators.
Die-cutting and inspection of label sheets: encoding is followed by 100% read verification before any roll leaves the floor.
The digital printing and inspection line where variable data, including serialized URIs, is applied to the label face before personalisation.
The TagTamper Option: Seals That Report Their Own State
For closures, blister cards and seal-type applications, the NTAG 424 DNA TagTamper variant adds a conductive tamper loop to the inlay. When the loop is cut — the label is peeled off or the package opened along the designed line — the chip latches that event permanently and mirrors the status character into every subsequent SUN message: C while the seal is intact, O once broken. The backend can therefore serve different experiences before and after opening, and a returned product whose seal reports O has an auditable reason for inspection.
Chip Facts Worth Citing in a Supplier Evaluation
When a supplier pitches you an "encrypted NFC label," these are the datasheet lines to ask for. All figures below come from NXP's published documentation:
| Parameter | Value |
|---|---|
| Interface | ISO/IEC 14443-A, NFC Forum Type 4 Tag |
| Memory organization | 416 bytes in an ISO/IEC 7816-4 file system: 32-byte capability container, 256-byte NDEF file, 128-byte protected data file |
| Security certification | Common Criteria EAL4 for hardware and software, part of NXP's certified EdgeLock Assurance program |
| Cryptography | Standard AES-128, or LRP-wrapped AES for higher attack resistance; ECC-based NXP originality signature |
| Data rate | Up to 848 kbit/s |
| Data retention / endurance | 50 years / 100,000 write cycles |
| Privacy | Random ID and encrypted UID modes |
Where NTAG 424 DNA Labels Earn Their Cost Premium
The premium over static NFC buys a server-verifiable verdict, so it pays back where a cloned verdict is expensive: pharmaceutical closures and carton seals (where the TagTamper state pairs with serialization compliance), spirits and high-value beverage capsules, cosmetics refills, warranty registration and authorized-channel verification. The economic backdrop is unforgiving — as our 2026 industry statistics summary notes, roughly two thirds of seized fakes now move in small parcels, which is exactly the channel where a consumer-tappable, no-app verdict changes the odds.
Prepare These Five Things Before You Order
- A live verification endpoint. Encoding before the backend exists is the most common way projects stall; the serialized verification playbook covers the server-side design.
- A key custody decision — who generates, holds and rotates the five AES-128 keys.
- Your SDM URL format, so offsets and query parameters are agreed before personalisation begins.
- A counter policy — plan for the 16.7 million read limit and decide what the backend does with out-of-sequence taps.
- Real packaging for the pilot run — metal inserts, liquid contents and curvature all affect read range, so the finished inlay must be evaluated on the product itself.
Honest Boundaries of This Announcement
Chip specifications in this article are quoted from NXP's published product documentation; price bands come from public industry comparisons and vary with inlay size, volume and face construction, so treat them as magnitude rather than quotation. Production capacity, lead times and project pricing are provided per project in writing, and we do not publish client names or volumes. One more boundary worth repeating: NTAG 424 DNA authentication is server-side by design — if anyone offers you this chip "verified offline," the claim does not match how the silicon works.
Brands already comparing NFC against UHF and QR options should start with the RFID & NFC buyer's guide, then validate the choice with real inlays: sample NTAG 424 DNA labels ship encoded against a live demo verification endpoint, so the full tap-to-verdict flow can be tested with nothing but a phone.
Ready to evaluate? Request NTAG 424 DNA label samples and a project quote — include your product category, annual volume estimate and whether the closure needs tamper detection.

