NXP Semiconductors MF4SAM3HN/9BA659Z
- Part No.:
- MF4SAM3HN/9BA659Z
- Manufacturer:
- NXP Semiconductors
- Category:
- RFID, RF Access, Monitoring ICs
- Package:
- 32-VFQFN Exposed Pad
- Datasheet:
-
MF4SAM3HN/9BA659Z.pdf
- Description:
- MF4SAM3HN
- Quantity:
- Payment:

- Shipping:

Inventory:1,274
Please send an inquiry. Send us your inquiry, and we will respond immediately.
Product details
Overview
MF4SAM3HN/9BA659 from NXP Semiconductors is a secure access module (SAM) designed for cryptographic offloading and secure key management in contactless reader systems. It implements ISO/IEC 7816-3 T=1 interface, supports AES-256, RSA-2048, ECC-256, and DES/TDEA, and delivers CC EAL6+ certified hardware security based on SmartMX2 P60 controller. It enables secure host-to-SAM communication, EMVCo terminal functionality, and X-mode direct interface with NXP RC663/RC52x/PN512 readers.
For engineers reviewing the MF4SAM3HN/9BA659 datasheet, MF4SAM3HN/9BA659 pinout, MF4SAM3HN/9BA659 application, or MF4SAM3HN/9BA659 equivalent, this page provides verified package mapping (HVQFN32), validated pin functions (e.g., TP1 as I2C_Enable, IO1 as bidirectional serial data), confirmed cryptographic capabilities (AES-256 offline crypto, TRNG compliant to AIS-31), and two industry-validated alternative SAMs for MIFARE infrastructure integration.
Technical Context
The MF4SAM3HN/9BA659 integrates the SmartMX2 P6022y VB secure controller with dedicated coprocessors for AES, DES, and Fame2 (RSA/ECC), enabling concurrent cryptographic operations at up to 96 MHz internal clock speed. Its architecture supports four logical channels, simultaneous multi-card authentication (MIFARE DESFire EV3/EV2, Plus EV2/EV1, Classic EV1), and secure messaging with Transaction MAC and CommitReaderID.
It operates across ISO/IEC 7816 Class A (5 V), B (3 V), and C (1.8 V) supply conditions, with dynamic current draw ranging from 80 µA in POWERDOWN mode to 10.5 mA during AES-96 MHz coprocessor activity. The HVQFN32 package includes optional I²C Target mode (TP1/TP2) - enabled only when TP1 is high - and supports both standard ISO/IEC 7816-3 T=1 and proprietary X-mode communication with NXP contactless reader ICs.
Key Specifications
| Parameter | Value and Actual Design Meaning |
|---|---|
| Security Certification | CC EAL6+ certified hardware platform; composite certified under MIFARE Security Evaluation Scheme (TÜViT/UL); FIPS 140-2 CAVP certified |
| Cryptographic Support | AES-128/192/256, RSA-2048, ECC-256, DES/TDEA-112/168, SHA-1/224/256, LRP, CMAC-based key derivation |
| Secure Storage Capacity | 128 symmetric key entries; 3 RSA key entries; 8 ECC public key entries; 48 EMV CA public keys; 32 kB EEPROM for programmable logic |
| Interface Standards | ISO/IEC 7816-2/3 (Class A/B/C), T=1 protocol; optional I²C Target mode (HVQFN only); X-mode direct interface with RC663/RC52x/PN512 |
| Supply Voltage Range | 1.62 V to 5.5 V (supports 1.8 V, 3 V, and 5 V contact interfaces per ISO/IEC 7816-3) |
| Operating Temperature | -25 °C to +85 °C ambient; qualified for industrial embedded reader applications |
| Package | HVQFN32 (5 × 5 × 0.85 mm); thermal-enhanced, leadless; reel pack, MOQ 6,000 units |
Pinout & Package
HVQFN32 plastic thermal enhanced very thin quad flat package; 32 terminals; body dimensions 5 mm × 5 mm × 0.85 mm; central pad isolated; RoHS-compliant; designed for surface-mount reflow assembly in space-constrained reader modules.
| Pin/Terminal | Circuit Role | Design Meaning |
|---|---|---|
| GND (Pad 1) | Ground reference | Primary system ground connection; required for stable voltage reference and ESD return path |
| IO3 (Pad 3) | I²C clock to reader IC (SCL) | Used exclusively for X-mode communication with NXP contactless reader ICs (e.g., RC663) |
| IO1 (Pad 5) | Bidirectional serial data | Primary ISO/IEC 7816 I/O or SDA in I²C Target mode; supports quasi-bidirectional operation with configurable pull-up/down |
| IO2 (Pad 7) | I²C data to reader IC (SDA) | Secondary X-mode signal line; connects directly to reader IC's SDA for accelerated host–SAM handshake |
| VCC (Pad 24) | Power supply input | Accepts 1.62–5.5 V; supports Class A/B/C operating conditions; decoupling capacitor required near pad |
| RST_N (Pad 22) | Active-low reset input | Asynchronous reset control; internal resistive pull-down active outside reset state; min pulse width 40 µs |
| CLK_N (Pad 18) | Clock input | External clock source (0.85–11.5 MHz); internal pull-up during reset, pull-down otherwise; rise/fall time ≤ 400 µs |
| TP2 (Pad 29) | I²C clock to host (SCL_Target) | Enables I²C Target mode for host microcontroller communication; functional only when TP1 = HIGH |
| TP1 (Pad 30) | I²C enable control | Hardware-enable signal for I²C Target interface; must be driven HIGH to activate SCL_Target/SDA_Target functionality |
Key Features
| Feature | Design Value |
|---|---|
| Programmable Logic (PL) | 32 kB EEPROM + 1 kB RAM for customer-defined business logic (e.g., custom key diversification, secure messaging extensions) |
| X-mode Communication | Direct parallel interface with NXP reader ICs (RC663/RC52x/PN512) enabling faster SAM–reader handshaking and reduced latency vs. standard ISO/IEC 7816 |
| EMVCo Terminal Support | Fully implements certificate verification, offline authentication, and PIN code verification per EMV terminal requirements |
| True Random Number Generator | AIS-31-compliant TRNG used for session key generation, nonce creation, and cryptographic seeding |
| Fine-Grained Key Access Control | Per-key permission flags (read/write/execute) enforce strict separation of duties across applications and security domains |
Applications
| Access Control Reader | Transit Fare Collection Terminal |
|---|---|
Use Scenario: High-security door access system using MIFARE DESFire EV3 cards with encrypted session keys and transaction MACs. IC Role / Device Role / Timing Role: Secure cryptographic co-processor handling mutual authentication, key derivation, and secure messaging between reader MCU and card. Use Value: Enables EMV-level transaction integrity and prevents cloning via CC EAL6+ certified hardware isolation and AES-256 protected key storage. |
Use Scenario: Contactless transit validator supporting MIFARE Plus EV2 and Ultralight EV1 cards with fast tap-and-go response. IC Role / Device Role / Timing Role: Dedicated SAM managing diversified keys, sector-level security switching, and offline crypto for fare calculation and balance updates. Use Value: Reduces transaction time by 40% via X-mode interface and supports post-delivery configuration for fleet-wide firmware updates without hardware change. |
| Banking POS Terminal | eID Document Reader |
Use Scenario: EMVCo-certified point-of-sale terminal performing offline PIN verification and cardholder certificate validation. IC Role / Device Role / Timing Role: SAM acting as trusted execution environment for EMV terminal functions including certificate chain validation and signature verification. Use Value: Meets PCI PTS v6.0 and EMVCo Level 1 security requirements through composite MIFARE Security Evaluation Scheme certification. |
Use Scenario: National eID document reader verifying chip authenticity via ECC originality signatures and performing secure document signing. IC Role / Device Role / Timing Role: Hardware root of trust executing ECC-256 signature verification against stored CA keys and generating cryptograms for key injection. Use Value: Supports ICAO Doc 9303 compliance with fine-grained key access control and AIS-31 TRNG for non-reproducible cryptographic material. |
Equivalent & Alternatives
The following parts are listed as comparable options for similar secure access module applications.
| Alternative Part | Technical Difference | Application Difference | Selection Advice |
|---|---|---|---|
| MF4SAM3U15/9BA659 | Unbumped 150 µm wafer die; no package; requires customer packaging and wire bonding | Suitable for integrated module manufacturers embedding SAM into custom ASIC packages or hybrid substrates | Select when full control over mechanical integration and thermal design is required; not drop-in replaceable with MF4SAM3HN/9BA659 |
| MF4SAM3X84/9BA659 | PCM1.5 contact chip card module (8-pin, super 35 mm tape format); end-of-life manufacturing announced | Designed for legacy card-reader designs using ISO/IEC 7816-2 contact pads; limited to 11.9k MOQ | Only for continuity in existing PCM1.5-based designs; no long-term supply assurance; migration path to HVQFN recommended |
Compared with MF4SAM3U15/9BA659 and MF4SAM3X84/9BA659, the MF4SAM3HN/9BA659 offers immediate production readiness in HVQFN32, full I²C Target support, and guaranteed long-term availability - making it the optimal choice for new reader designs requiring solderable, certified, and field-upgradable SAM integration.
Availability
MF4SAM3HN/9BA659 is available at Aetrix Electronics and suitable for access control readers, transit fare validators, banking POS terminals, and eID document readers requiring stable component supply, long-lifecycle support, and certified cryptographic assurance.
Supply support for MF4SAM3HN/9BA659 includes scheduled delivery planning, volume procurement assistance, BOM continuity management, traceable sourcing, and lifecycle availability coordination for OEM customers, industrial embedded developers, connected-device designers, and electronics production programs.
Manufacturer
NXP Semiconductors is a global semiconductor leader specializing in secure connectivity solutions for automotive, industrial, and IoT applications, with deep expertise in contactless technologies and smart card security.
The MF4SAM3HN/9BA659 belongs to the MIFARE SAM AV3 product line, engineered specifically to deliver CC EAL6+ certified cryptographic acceleration and secure key lifecycle management for next-generation MIFARE-based infrastructure systems.
FAQ
What is the primary security certification level of the MF4SAM3HN/9BA659?
The MF4SAM3HN/9BA659 is built on the SmartMX2 P6022y VB controller and holds Common Criteria EAL6+ certification for its hardware platform. It also achieves composite certification under the MIFARE Security Evaluation Scheme - equivalent to EMVCo Security Evaluation - validated by TÜViT and UL. This dual certification ensures protection against high-potential physical and logical attacks, making MF4SAM3HN/9BA659 suitable for payment-grade and government-issued ID applications.
Does the MF4SAM3HN/9BA659 support I²C communication with a host microcontroller?
Yes, the MF4SAM3HN/9BA659 supports I²C Target mode for host communication, but only in the HVQFN32 package. This functionality requires TP1 (Pad 30) to be driven HIGH to enable the interface, after which TP2 (Pad 29) and IO1 (Pad 5) operate as SCL_Target and SDA_Target respectively. I²C is not supported on wafer or PCM1.5 variants, and the feature is disabled by default until TP1 is asserted.
Which NXP contactless reader ICs are compatible with the X-mode interface of the MF4SAM3HN/9BA659?
The MF4SAM3HN/9BA659 X-mode interface is explicitly validated for use with NXP's RC663, RC52x, and PN512 contactless reader ICs. In X-mode, IO2 and IO3 serve as dedicated SDA and SCL lines connecting directly to the reader IC, bypassing traditional UART-based protocols to achieve lower latency and higher throughput in secure messaging exchanges such as MIFARE DESFire EV3 authentication and Transaction MAC generation.
What cryptographic algorithms does the MF4SAM3HN/9BA659 support for offline operations?
The MF4SAM3HN/9BA659 supports AES-256, RSA-2048, and ECC-256 for offline cryptographic operations, including key diversification, secure messaging, and signature verification. Its Fame2 coprocessor handles RSA/ECC math, while dedicated AES and DES coprocessors accelerate symmetric encryption. Offline crypto is used in scenarios like transit fare calculation, eID document signing, and EMV offline PIN verification - all executed within the certified secure boundary of the MF4SAM3HN/9BA659.
Is the Programmable Logic feature available for general use in the MF4SAM3HN/9BA659?
The Programmable Logic (PL) feature of the MF4SAM3HN/9BA659 - offering 32 kB EEPROM and 1 kB RAM for custom code - is restricted to a limited set of qualified customers under NXP's PL licensing program. While the hardware capability is present in all MF4SAM3HN/9BA659 units, code upload and execution require NXP-provided toolchain access and contractual authorization. Standard users retain full access to all certified cryptographic services without PL activation.
MF4SAM3HN/9BA659Z Specifications
- Product attributes
- Attribute value
- Manufacturer:
- NXP Semiconductors
- Series:
- -
- Package/Case:
- 32-VFQFN Exposed Pad
- Packaging:
- Tape & Reel (TR)
- Product Status:
- Active
- Type:
- RFID Reader
- Frequency:
- -
- Standards:
- ISO 7816, Mifare
- Interface:
- I2C, UART
- Voltage - Supply:
- 1.62V ~ 1.98V, 2.7V ~ 3.3V, 4.5V ~ 5.5V
- Operating Temperature:
- -25°C ~ 85°C (TA)
- Grade:
- -
- Qualification:
- -
- Mounting Type:
- Surface Mount
- Supplier Device Package:
- 32-HVQFN (5x5)
MF4SAM3HN/9BA659Z FAQ
1.How can I place an order for MF4SAM3HN/9BA659Z through Aetrix?
Please submit a Request for Quotation (RFQ) for MF4SAM3HN/9BA659Z on Aetrix. Our sales agent will provide a competitive quotation and guide you through the order confirmation once you accept the terms.
2.Are the price and stock information for MF4SAM3HN/9BA659Z reliable?
The price and inventory of MF4SAM3HN/9BA659Z are updated periodically and may fluctuate due to market conditions. Stock and pricing data are typically refreshed every 24 hours. Quotation validity for MF4SAM3HN/9BA659Z is usually 5 days.
3.What payment methods are accepted for MF4SAM3HN/9BA659Z?
We accept Wire Transfer, PayPal, Credit Card, Western Union, MoneyGram, and Escrow for MF4SAM3HN/9BA659Z transactions.
Note: Certain payment methods may incur a processing fee.
4.How is shipping managed for MF4SAM3HN/9BA659Z?
MF4SAM3HN/9BA659Z orders can be shipped via leading logistics carriers, including DHL, UPS, FedEx, TNT, or Registered Mail.
Once your MF4SAM3HN/9BA659Z order is processed, you will receive an email with the shipment details and tracking number.
Note: Tracking information may take up to 24 hours to appear. Express delivery typically takes 3–5 business days.
5.How can I obtain technical support or documentation for MF4SAM3HN/9BA659Z?
For technical support, including MF4SAM3HN/9BA659Z datasheets, pinout diagrams, or application guidance, please contact our engineering support team. They can provide detailed documentation and assistance for your MF4SAM3HN/9BA659Z requirements.
6.How does Aetrix verify that MF4SAM3HN/9BA659Z is sourced from the original manufacturer or authorized distributors?
All MF4SAM3HN/9BA659Z products on Aetrix are procured from qualified distributors and authorized channels. Our dedicated quality assurance team conducts strict verification, including traceability checks and, if necessary, third-party testing. This ensures that MF4SAM3HN/9BA659Z meets industry standards.
7.What is the process for return or replacement of MF4SAM3HN/9BA659Z?
All MF4SAM3HN/9BA659Z units undergo pre-shipment inspection (PSI). If there is an issue with MF4SAM3HN/9BA659Z, returns or replacements are accepted under the following conditions:
1.Quantity discrepancies, incorrect items, or visible external defects (such as breakage or corrosion), acknowledged by Aetrix.
2.The issue is reported within 90 days of delivery.
3.The MF4SAM3HN/9BA659Z part is unused and in its original packaging.
Return procedure for MF4SAM3HN/9BA659Z:
1.Submit a request within 90 days.
2.Obtain a Return Material Authorization (RMA) from Aetrix.
MF4SAM3HN/9BA659Z Tags

-
SL2S2602FTBX
NXP Semiconductors

-
ST25DV04K-IER6S3
STMicroelectronics

-
ST25DV04K-IER6C3
STMicroelectronics

-
LXMSJZNCMD-217
Murata Electronics

-
NT3H2111W0FTTJ
NXP Semiconductors

-
NT3H2111W0FHKH
NXP Semiconductors

-
M24LR04E-RMC6T/2
STMicroelectronics

-
ST25DV04KC-JF6D3
STMicroelectronics

-
ST25DV64KC-IE6S3
STMicroelectronics
-
ST25DV64K-IER6T3
STMicroelectronics

-
NT3H2211W0FTTJ
NXP Semiconductors

-
NT3H2211W0FHKH
NXP Semiconductors
Tech Hub
A practical engineering guide to 3.3V and 5V logic compatibility, input thresholds, resistor dividers, translator ICs, MOSFET level shifting, I2C pull-ups, timing limits and power-sequencing risks.
The 74HC595 uses push-pull logic outputs, while the TPIC6B595 uses 50 V open-drain DMOS sinks for higher-power loads. This guide compares timing, current limits, 3.3 V interfacing, load wiring, thermal…
The 74HC595 converts serial data into eight stable parallel outputs. This guide covers pin functions, shift and storage timing, OE and MR behavior, drive-current limits, cascading, voltage compatibilit…
A technical comparison of level-sensitive latches and edge-triggered flip-flops, covering timing windows, setup and hold limits, master–slave operation, time borrowing, race-through, HDL inference and…
A D latch stores one bit while Enable controls when data can pass. This reference covers gate-level operation, truth tables, transparency, setup and hold timing, LE versus OE, common ICs and practical …
An SR latch stores one bit through cross-coupled feedback. This engineering reference covers NOR and NAND implementations, truth tables, forbidden-state recovery, gated operation, switch debouncing, fa…
Latch circuits retain one bit through feedback. This technical reference covers SR and D latches, truth tables, transparency, timing limits, latch-versus-flip-flop behavior, applications and common log…
An engineering guide to LED driver operation, constant-current and constant-voltage outputs, linear and switching topologies, dimming, IC selection, calculations, replacement compatibility, and fault c…
Operational amplifier guide covering op amp basics, feedback, ideal vs real op amps, common configurations, buffer circuits, offset, bias current, gain-bandwidth, slew rate, rail-to-rail limits and sel…
Jumper cables guide covering safe connection order, red and black clamp placement, final ground connection, cable gauge, length, clamp quality, copper vs CCA cables, jump starter comparison and battery…
