Now there is a Mifare card that can modify the UID on the market. The card can use special commands to change the content of 0-sector 0 blocks, thus achieving uid change.
The command to change uid is as follows:
Sent bits: 26 (7 bits)
Received bits: 04 00
Sent bits: 93 20
Reset ed bits: 01 23 45 67 00
Sent bits: 93 70 01 23 45 67 00 D0 6f
Stored ed bits: 08 B6 dd(SAK)
Sent bits: 50 00 57 CD
Sent bits: 40 (7 bits)(Special commands)
Received bits: A (4 bits)
Sent bits: 43 (Special Command)
Received bits: 0a
Sent bits: A0 00 5f B1
Received bits: 0a
Sent bits: 00 DC 44 20 B8 08 04 00 46 59 25 58 49 10 23 02 C0 10
Received bits: 0a
The method to prevent this card is as follows:
1. Determine the SAK returned by the SELECT command. The return value of the M1 card should be 08. If the first byte is 28, it may be the M1 card simulated by the CPU card.
2. After selecting the card, modify the 0th block and send two special commands. To prevent the card, check whether the two commands return values.
3. The Keya and keyb of the M1 card have already been cracked. Therefore, the key data in the card must be encrypted with the UID to ensure security.
Because of this reproducible M1 card, the system that has already used the M1 card is not safe. This method upgrades the existing M1 card system to prevent this copy card within a certain range.
However, I personally think that since there is such a card, other similar cards will also appear. I hope you can tell each other and take measures together!