News analysis · Technology & Standards
NXP’s NTAG originality signature answers a narrower security question
The official NTAG21x datasheet documents an ECC originality signature. A static response does not establish freshness or stop replay on its own.
What the datasheet says
The official NXP NTAG213, NTAG215 and NTAG216 datasheet lists an ECC-based originality signature among the product features and describes its originality-signature operation in section 8.9. It also describes a manufacturer-programmed UID and password protection for memory operations. These are distinct features. A signature associated with an integrated circuit can support a check of manufacturer originality when correctly verified against the manufacturer’s public key. It is not, by that fact alone, proof that a tag is still attached to a particular physical product.
The NFC Forum specifications page describes the family of interoperable contactless specifications. Radio and data-format interoperability should not be confused with a system-level guarantee of anti-cloning performance or transaction freshness.
RFIDWire analysis
A static originality signature is useful only within its stated trust boundary. A reader may verify that signature bytes match the expected public key and associated identifier. But if an attacker can capture and reproduce the same visible values, verifying them again does not prove the tag is a live, uncompromised chip responding to a fresh request. Replay or emulation is a different threat from a counterfeit IC that cannot produce an authentic manufacturer signature.
For an application that merely wants to distinguish supported silicon from an obviously invalid tag, an originality check may be appropriate. For a valuable-product authenticity claim, access decision or anti-replay requirement, design a challenge-response mechanism whose response changes with a fresh challenge and whose secrets are protected. Separately bind the chip identity to the item record and define how physical substitution is detected. Do not label a static signature as dynamic authentication in a purchasing specification.
Password protection deserves the same precision. Restricting unauthorized memory operations is not the same as mutually authenticating a reader and a chip. A secure application has to decide what attack it is defending against, what the attacker can observe or emulate and which verification takes place on a trusted server rather than solely on a phone.
Questions and limits
What exactly is covered by the signed data? Where is the manufacturer public key obtained and how is it managed? Can an emulator return the same UID and signature to the same verifier? Is the application checking that this chip is attached to the intended object? How does it handle a copied NDEF message?
The NXP datasheet supports the feature description, not an end-to-end anti-counterfeit outcome for a particular deployment. No attack experiment is claimed here. The recommendation to separate originality, freshness and item binding is RFIDWire’s security analysis.



