High-security AES 13.56 MHz hotel credential

VingCard Plus 2K Explained: How the AES Guest Credential Works

VingCard Plus 2K is the high-security, AES-secured 13.56 MHz credential tier used by ASSA ABLOY Global Solutions hotel locks, in the compact 2K memory size. It protects a guest or staff key with 128-bit AES mutual authentication, a message authentication code on every command, and an encrypted radio channel — the hardened credential VingCard introduced for door-lock keys in 2024.

Last updated 2026-07-29

What is VingCard Plus 2K?

VingCard Plus 2K is the high-security tier of VingCard's AES-secured 13.56 MHz guest credential, in the compact 2K memory size. "Plus" denotes the hardened credential that ASSA ABLOY Global Solutions brought to its door-lock keys in 2024, layering 128-bit AES cryptography over the same platform its Signature RFID locks already read. The 2K size makes it a single-purpose key — a guest room or a staff door — rather than a multi-application card.

VingCard has issued electronic hotel keys since the first recodable electronic keycard lock at the Westin Peachtree Plaza in Atlanta in 1978, and reintroduced Vingcard as its primary hospitality brand in 2024. VingCard Plus 2K is the current high-security member of that lineage, managed by Visionline on-premise or Vostio in the cloud, and read at the door by Signature locks.

What makes the VingCard Plus 2K credential secure?

The VingCard Plus 2K credential is secured by 128-bit AES mutual authentication: the card and lock each prove their identity before any access data is exchanged, using keys diversified per card so no two credentials share the same derived key. On top of that authentication, the credential applies a cipher-based message authentication code (CMAC) to every command and response and runs a secure-messaging mode that encrypts data over the air.

These layers directly target the classic attacks on hotel keys. The CMAC and mutual authentication defend against replay and man-in-the-middle interception, and an optional randomized ID prevents a card from being tracked by a fixed serial. The credential tier VingCard adopted is certified to Common Criteria EAL3+, an independent evaluation of the security implementation rather than a vendor claim.

How is Plus 2K different from a standard VingCard smart card?

VingCard Plus 2K sits above the standard smart card as the high-security credential tier, while sharing the same 13.56 MHz standard and 2K memory size. The practical difference is the depth of cryptographic protection applied to the guest key and the certification behind it.

PropertyLegacy memory cardVingCard Plus 2K
Frequency / standard13.56 MHz, ISO/IEC 14443-A13.56 MHz, ISO/IEC 14443-A
AuthenticationNone (no sector crypto)128-bit AES mutual authentication
Message integrityNoneCMAC on commands/responses
RF channelCleartextEncrypted (secure messaging)
Anti-trackingFixed UIDOptional randomized ID
Independent certificationNoneCommon Criteria EAL3+

Why did VingCard add the Plus AES credential in 2024?

VingCard added its AES high-security credential in May 2024 to move hotels off legacy access technologies onto a modern cryptographic key. An industry executive described the upgrade as giving hotels "a more secure contactless way to transition away from legacy access technologies," and Richard Eastburn, Vingcard's Sr. Director and Head of Product Management, said it lets "Vingcard lock solutions continue to represent ultimate guest peace of mind."

The driver is the weakness of what came before. Legacy 125 kHz proximity cards transmit a fixed number with no encryption, and older 13.56 MHz guest cards were issued with "no sector crypto" — no per-sector encrypted authentication. VingCard Plus is the credential tier that closes that gap by adding AES authentication, message integrity, and an encrypted channel to the guest key.

How does VingCard Plus 2K fit Signature, Visionline and Vostio?

VingCard Plus 2K is encoded and revoked by the property's back end — Visionline on-premise or Vostio Access Management in the cloud — and validated at the door by Signature RFID locks. Because Signature is a multi-technology 13.56 MHz reader, the same lock can accept the Plus credential alongside legacy guest cards during a migration, so a property is not forced to swap every card and reader on one day.

ASSA ABLOY's documented path moves backend management from on-premise Visionline to cloud Vostio, which also brings mobile keys over BLE and NFC on the same Signature readers. VingCard Plus 2K is the compact, high-security physical credential within that system, sitting beside phone-based keys rather than replacing the reader hardware.

Can a VingCard Plus 2K key card be copied?

Copying a VingCard Plus 2K credential is a fundamentally different proposition from copying a legacy card. Its access data is protected by 128-bit AES mutual authentication with per-card diversified keys and a CMAC on every exchange, so the data is not exposed as a plain readable serial during a normal read. Reproducing the credential would require the site-specific diversified keys held inside the property's system.

The honest framing for any hotel is that credential clone-resistance rests on key management. A Plus 2K credential run with properly managed, site-specific keys and up-to-date locks reflects the security model VingCard designed; a property leaning on legacy, unencrypted guest cards elsewhere in the same building carries the older risk on those doors. The upgrade story is about closing that gap door by door.

What software and encoders does VingCard Plus 2K require?

Issuing VingCard Plus 2K requires a back end and encoders provisioned for the AES credential tier — current Visionline on-premise or Vostio in the cloud, with encoders configured to write the AES-protected keys. The Signature RFID locks that read the credential are multi-technology 13.56 MHz readers, so the reader side generally does not need replacing to accept the Plus credential; the change is concentrated in the software and the encoding step.

This is why VingCard positions the move as a migration a property manages centrally. The AES keys are held and diversified by the system rather than exposed on the card, so provisioning Plus 2K is chiefly about updating the issuance side — the encoders and software that write and revoke keys — while legacy cards keep working at the same doors until the changeover completes.

VingCard credential formats we supply

VingCard properties commonly keep legacy 13.56 MHz guest cards in circulation while newer credentials roll out. These open VingCard-compatible formats are ones we encode and supply, ready to read on your existing Signature and Visionline locks.

Sources & references

ASSA ABLOY Global Solutions and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

VingCard Plus 2K (AES high-security) — common questions

What is VingCard Plus 2K?

VingCard Plus 2K is the high-security, AES-secured 13.56 MHz credential tier for ASSA ABLOY Global Solutions hotel locks, in the compact 2K memory size. It protects a guest or staff key with 128-bit AES mutual authentication, a CMAC on every command, and an encrypted radio channel — the hardened door-lock credential VingCard introduced in 2024.

How is VingCard Plus different from a standard VingCard card?

VingCard Plus is the high-security credential tier. Compared with a legacy memory card that has no sector crypto, Plus adds 128-bit AES mutual authentication, a CMAC on commands and responses, an encrypted RF channel, an optional randomized ID, and Common Criteria EAL3+ certification, all on the same 13.56 MHz platform.

Is VingCard Plus 2K certified?

The AES credential tier VingCard uses for Plus is certified to Common Criteria EAL3+, an independent evaluation of the security implementation. It also provides 128-bit AES authentication with a CMAC on all commands and responses and a secure-messaging mode that encrypts data over the air.

Can a VingCard Plus 2K card be cloned?

A VingCard Plus 2K card protects its data with 128-bit AES mutual authentication, per-card diversified keys, and a CMAC on every exchange, so the data is not exposed as a plain serial like a 125 kHz proximity number. Reproducing it would require the property's site-specific keys; clone-resistance depends on that key management.

Why did VingCard introduce the Plus AES credential?

VingCard introduced its AES high-security credential in May 2024 to move hotels off legacy access technologies. Older 125 kHz proximity cards send a fixed unencrypted number, and earlier 13.56 MHz guest cards had no sector crypto; Plus closes that gap with AES authentication, message integrity, and an encrypted channel.