Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 9:47 pm

All times are UTC + 1 hour




Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: Thu Dec 18, 2014 10:07 pm 
Offline

Joined: Tue Nov 18, 2014 9:14 pm
Posts: 95
Location: San Jose, CA
I noticed that one of the features of the Yubkey Neo is "Mifare Classic emulation".

This is mentioned on page 39 of the yubikey manual, but is otherwise not elaborated on.

What is this "Mifare Classic emulation" feature, and how is it intended to be used?


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Fri Dec 19, 2014 5:42 am 
Offline

Joined: Wed Nov 19, 2014 12:11 am
Posts: 31
The obvious and I guess primary application is using a NEO with legacy physical access control infrastructure designed for Mifare Classic tokens. Such infrastructure cannot be recommended for new deployment due to the well-known weaknesses in the Mifare CRYPTO algorithm, but there is a considerable deployed footprint.

If you want to deploy new physical access control infrastructure with a NEO, the obvious answer is to use PIV II compatible infrastructure against a certificate in the 9E slot of the NEO's PIV applet. Commercial PIV access control infrastructure tends to be expensive, though if you can control the points of failure sufficiently, you can always roll your own from a Raspberry Pi and a contactless smartcard reader.


Top
 Profile  
Reply with quote  
PostPosted: Fri Dec 19, 2014 11:14 am 
Offline
Site Admin
Site Admin

Joined: Mon Dec 08, 2014 2:52 pm
Posts: 314
Right,

A third alternative is to use KEYnTO, a new access control mechanism based on Yubico OTP https://www.keynto.com/


Top
 Profile  
Reply with quote  
PostPosted: Fri Dec 19, 2014 9:55 pm 
Offline

Joined: Tue Nov 18, 2014 9:14 pm
Posts: 95
Location: San Jose, CA
After I posted my question (and before I saw the answer) I had just assumed it was a way to emulate a type-2 NDEF tag. But if it really does emulate a mifare classic, then that's interesting. I guess it's just another place to squirrel away data.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group