AES-secured 13.56 MHz guest key credential

VingCard AES Memory Card Explained: The Secured Guest Key Credential

The VingCard AES memory card is the AES-secured 13.56 MHz guest key credential that ASSA ABLOY Global Solutions adopted for its hotel locks in 2024. It replaces the older, unencrypted guest card with 128-bit AES authentication, a message authentication code on every command, and an encrypted radio channel, and it is certified to Common Criteria EAL3+.

Last updated 2026-07-29

What is a VingCard AES memory card?

A VingCard AES memory card is the guest key credential ASSA ABLOY Global Solutions uses for its hotel locks, upgraded to AES cryptography. "Memory card" describes its role — a compact, often disposable guest key that carries dated room-access rights — while "AES" marks the security generation that replaced the earlier, unencrypted guest card. It is a 13.56 MHz ISO/IEC 14443-A credential read by VingCard Signature RFID locks and issued by Visionline or Vostio.

VingCard has produced hotel guest keys since installing the first recodable electronic keycard lock at the Westin Peachtree Plaza in Atlanta in 1978, and reintroduced Vingcard as its primary hospitality brand in 2024. The AES memory card is the current secure guest credential in that line: the same familiar disposable key form factor, but with cryptographic protection that the legacy card lacked.

How does the VingCard AES memory card differ from the legacy guest card?

The VingCard AES memory card differs from the legacy guest card by adding real cryptography to a credential that previously had none. Older VingCard guest cards were 13.56 MHz memory cards described as having "no sector crypto" — no per-sector encrypted authentication — so their data was readable rather than cryptographically protected. The AES memory card closes that gap on the same platform.

PropertyLegacy VingCard guest cardVingCard AES memory card
Frequency / standard13.56 MHz, ISO/IEC 14443-A13.56 MHz, ISO/IEC 14443-A
AuthenticationNone (no sector crypto)128-bit AES mutual authentication
Message integrityNoneCMAC on all commands/responses
RF channelCleartextEncrypted (secure messaging)
Anti-trackingFixed UIDOptional randomized ID
Independent certificationNoneCommon Criteria EAL3+

Why is the VingCard AES memory card considered secure?

The VingCard AES memory card is considered secure because it protects the guest key with 128-bit AES mutual authentication: the card and lock authenticate each other before any data is exchanged, using keys diversified per card. A cipher-based message authentication code (CMAC) is applied to every command and response, and a secure-messaging mode encrypts the data over the air, which defends the exchange against replay and man-in-the-middle attacks.

These are not vendor assertions alone — the AES credential tier is certified to Common Criteria EAL3+, an independent security evaluation, and it offers an optional randomized ID so a card cannot be tracked by a fixed serial. In plain terms, a guest key on this credential is protected by cryptography and per-card keys, so reading one card does not reveal the keys behind another.

Why did VingCard move guest keys to AES in 2024?

VingCard moved its guest keys to AES in May 2024 to retire legacy access technologies in favour of a modern cryptographic credential. Richard Eastburn, Vingcard's Sr. Director and Head of Product Management, said the change lets "Vingcard lock solutions continue to represent ultimate guest peace of mind," while an industry executive described the AES card as giving hotels "a more secure contactless way to transition away from legacy access technologies."

VingCard positioned the announcement around security, sustainability, and scalability. The security case is the AES cryptography above; the sustainability case reflects the industry shift toward recyclable and reusable guest-card stock; and scalability comes from managing the credential centrally through Visionline or Vostio. The AES memory card is how those three goals land on the physical guest key.

Can a VingCard AES guest card be cloned or copied?

A VingCard AES guest card protects its access data with 128-bit AES mutual authentication and a CMAC on every exchange, so the data is not exposed as a plain readable serial during a normal read — the opposite of a 125 kHz proximity card, whose fixed number can be captured and replayed. Reproducing the credential would require the site-specific diversified keys held inside the property's system.

The honest position for any hotel is that clone-resistance is decided by key management, not by the plastic. A guest key on the AES credential, issued with well-managed site keys and read by current locks, reflects the security model VingCard designed. Where a property still circulates legacy, unencrypted guest cards, those cards carry the older, readable-serial risk — which is exactly why the AES move is framed as a migration.

How is the AES memory card managed in Visionline and Vostio?

The VingCard AES memory card is encoded and revoked centrally through the property's back end — Visionline on-premise or Vostio Access Management in the cloud. At check-in the encoder writes the guest's dated access rights under the card's AES keys, the Signature RFID lock validates them at the door, and the software can revoke or re-issue a key remotely without touching the lock.

ASSA ABLOY's documented direction moves backend management from on-premise Visionline to cloud Vostio, which adds remote key issuance and integration with property-management systems, and enables mobile keys over BLE and NFC on the same Signature readers. For how the credential behaves across a stay — check-in encoding, checkout expiry, re-issue, and lost-card handling — see the VingCard AES guest-card lifecycle guide.

How does a property upgrade to the AES guest credential?

A property upgrades to the VingCard AES guest credential gradually rather than all at once. Because Signature RFID locks are multi-technology 13.56 MHz readers, they accept both the AES card and legacy guest cards at the same door, so a hotel can convert encoders and re-card in phases while unconverted doors keep working. The move typically pairs the new AES stock with current Visionline or Vostio software provisioned for the AES tier.

For most properties the realistic sequence is: confirm the back end and encoders support the AES credential, begin issuing AES guest cards at check-in, and retire legacy stock as it is used up — optionally adding mobile keys through Vostio. Throughout the changeover, legacy 13.56 MHz guest cards remain in service on doors not yet cut over.

VingCard credential formats we supply

During an AES guest-card rollout, most properties keep legacy 13.56 MHz guest cards circulating until the migration completes. These open VingCard-compatible formats are ones we encode and supply, ready to read on your existing Signature and Visionline locks.

Sources & references

ASSA ABLOY Global Solutions and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

VingCard AES memory (guest credential) — common questions

What is a VingCard AES memory card?

A VingCard AES memory card is the AES-secured 13.56 MHz guest key credential ASSA ABLOY Global Solutions adopted for its hotel locks in 2024. It is the familiar disposable guest-key form factor, but protected with 128-bit AES mutual authentication, a CMAC on every command, an encrypted RF channel, and Common Criteria EAL3+ certification.

How is the AES memory card different from an older VingCard guest card?

Older VingCard guest cards were 13.56 MHz memory cards with no sector crypto — their data was readable rather than cryptographically protected. The AES memory card adds 128-bit AES mutual authentication, a CMAC on commands and responses, an encrypted channel, and an optional randomized ID on the same platform.

Is the VingCard AES memory card certified?

Yes. The AES credential tier VingCard uses is certified to Common Criteria EAL3+, an independent evaluation of the security implementation. It provides 128-bit AES authentication with a CMAC on all commands and responses and a secure-messaging mode that encrypts data over the air.

Can a VingCard AES guest card be cloned?

A VingCard AES guest card protects its data with 128-bit AES mutual authentication, per-card diversified keys, and a CMAC, so the data is not exposed as a plain serial the way a 125 kHz proximity number is. Reproducing it would require the property's site-specific keys, so clone-resistance depends on that key management.

Do I have to re-card my whole hotel to use the AES memory card?

No. VingCard Signature RFID locks read both the AES card and legacy guest cards, so a property can convert encoders and re-card in phases while unconverted doors keep working. Most hotels issue AES cards at check-in and retire legacy stock as it is used up, optionally adding mobile keys through Vostio.