High-security AES 13.56 MHz hotel credential

VingCard Plus 4K Explained: Multi-Application AES Hotel Credential

VingCard Plus 4K is the high-security, AES-secured 13.56 MHz credential tier used by ASSA ABLOY Global Solutions hotel locks, in the larger 4K memory size. The extra memory lets one hardened card carry several applications, while 128-bit AES mutual authentication, a message authentication code, and an encrypted channel protect each one — the credential VingCard introduced for door-lock keys in 2024.

Last updated 2026-07-29

What is VingCard Plus 4K?

VingCard Plus 4K is the high-security tier of VingCard's AES-secured 13.56 MHz guest credential, in the larger 4K memory size. "Plus" is the hardened credential ASSA ABLOY Global Solutions brought to its door-lock keys in 2024; the 4K size adds enough memory to hold multiple applications on one card — a guest room key plus, for example, cashless charging, spa or amenity access, parking, or loyalty data — each protected by the same AES cryptography.

VingCard has issued electronic hotel keys since the first recodable electronic keycard lock at the Westin Peachtree Plaza in Atlanta in 1978, and reintroduced Vingcard as its hospitality brand in 2024. Plus 4K is the multi-application, high-security member of that credential family, read by Signature RFID locks and managed by Visionline on-premise or Vostio in the cloud.

How does Plus 4K secure multiple applications on one card?

VingCard Plus 4K secures multiple applications by giving each one its own place in an AES-protected memory structure and authenticating with per-card diversified keys. The card and lock perform 128-bit AES mutual authentication before any application is accessed, and a cipher-based message authentication code (CMAC) protects every command and response so data cannot be silently altered in transit.

This per-application, per-card key separation is exactly why a multi-application card can be trusted: the loyalty or cashless application cannot be repurposed to forge the room-access application, because each is gated by different keys. A secure-messaging mode encrypts the exchange over the air, and an optional randomized ID stops the card from being tracked by a fixed serial. The underlying AES credential tier is certified to Common Criteria EAL3+.

Plus 4K vs Plus 2K — which does a property need?

The choice between VingCard Plus 4K and Plus 2K is about application capacity, not security level — both are high-security AES credentials on the same 13.56 MHz standard. Plus 4K earns its place when one card must do more than open a door.

ConsiderationVingCard Plus 2KVingCard Plus 4K
On-card memory2K tier4K tier (roughly double)
Applications per cardOne (room / staff key)Multiple (room + services)
Best fitRoom-only hotelsResorts / cashless multi-service
Security model128-bit AES + CMAC + encrypted RF128-bit AES + CMAC + encrypted RF
CertificationCommon Criteria EAL3+Common Criteria EAL3+

Why did VingCard introduce the Plus AES credential in 2024?

VingCard introduced its AES high-security credential in May 2024 to move hotels off legacy access technologies and onto a modern cryptographic key. Richard Eastburn, Vingcard's Sr. Director and Head of Product Management, said the change lets "Vingcard lock solutions continue to represent ultimate guest peace of mind," and an industry executive framed it as "a more secure contactless way to transition away from legacy access technologies."

The reason is the weakness of the older credentials. Legacy 125 kHz proximity cards broadcast a fixed number with no encryption, and earlier 13.56 MHz guest cards were issued with "no sector crypto" — no per-sector encrypted authentication. For a property consolidating many services onto one credential, the AES protections of Plus 4K are what make putting cashless and loyalty data on the same card defensible.

How is Plus 4K managed in Visionline and Vostio?

VingCard Plus 4K is provisioned and revoked through the property's back end — Visionline on-premise or Vostio Access Management in the cloud. The multi-application layout is defined in software: the operator decides which applications live on the card, the encoder writes them under their AES keys, and Signature RFID locks validate the room-access application at the door while other systems read their own applications.

ASSA ABLOY's documented direction moves backend management from on-premise Visionline to cloud Vostio, which adds remote key issuance, property-management and third-party integrations that can populate the extra applications, and mobile keys over BLE and NFC on the same Signature readers. Plus 4K is the physical high-capacity credential inside that workflow.

Can a VingCard Plus 4K card be copied?

A VingCard Plus 4K card holds each of its applications behind 128-bit AES mutual authentication with per-card diversified keys and a CMAC on every exchange, so the data is not exposed as a plain readable serial during a normal read. Reproducing the credential, or any single application on it, would require the site-specific diversified keys held inside the property's system.

The honest position for any hotel is that clone-resistance depends on key management rather than on the card blank. A Plus 4K credential run with properly managed site keys and current locks reflects the security model VingCard designed; the risk on a property lives wherever legacy, unencrypted guest cards are still in service. Consolidating services onto a hardened multi-application card only helps if the keys behind it are managed well.

Does VingCard Plus 4K support mobile keys?

VingCard Plus 4K sits alongside mobile keys on the same VingCard system rather than competing with them. The Signature RFID locks that read the Plus 4K card also support mobile access over BLE and NFC through Vostio, so a property can offer phone-based keys while issuing high-security multi-application cards to guests or staff who need the physical credential.

Because both the Plus 4K card and the mobile key are managed by the same Vostio back end, a property can mix them by use case: a phone key for a repeat guest who opted in, a Plus 4K card for a suite that also unlocks cashless spend and amenities. The multi-application capacity is a property of the physical card; mobile keys carry the room-access function on the same readers.

VingCard credential formats we supply

Even properties standardizing on high-security credentials keep legacy 13.56 MHz guest cards circulating through a migration. These open VingCard-compatible formats are ones we encode and supply, ready to read on your existing Signature and Visionline locks.

Sources & references

ASSA ABLOY Global Solutions and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

VingCard Plus 4K (AES high-security) — common questions

What is VingCard Plus 4K?

VingCard Plus 4K is the high-security, AES-secured 13.56 MHz credential tier for ASSA ABLOY Global Solutions hotel locks, in the larger 4K memory size. The extra memory lets one hardened card carry several applications — room access plus cashless, amenity, or loyalty data — each protected by 128-bit AES authentication, a CMAC, and an encrypted channel.

How is Plus 4K different from Plus 2K?

Plus 4K and Plus 2K are both high-security AES credentials on the same 13.56 MHz standard; they differ only in memory. Plus 2K is a single-purpose key, while Plus 4K holds roughly double the memory, enough for multiple applications on one card. The security model and Common Criteria EAL3+ certification are identical.

How does a Plus 4K card keep multiple applications secure?

A Plus 4K card gives each application its own AES-protected space and per-card diversified keys, with 128-bit AES mutual authentication before access and a CMAC on every command. That key separation stops one application, such as loyalty, from being used to forge another, such as room access; the RF channel is also encrypted.

Can a VingCard Plus 4K card be cloned?

A VingCard Plus 4K card protects each application with 128-bit AES mutual authentication, per-card diversified keys, and a CMAC, so its data is not exposed as a plain serial like a 125 kHz proximity number. Reproducing it would require the property's site-specific keys; clone-resistance depends on that key management.

Why did VingCard add the Plus AES credential?

VingCard added its AES high-security credential in May 2024 to move hotels off legacy access technologies. Older 125 kHz proximity cards send a fixed unencrypted number and earlier 13.56 MHz guest cards had no sector crypto; the AES protections of Plus make consolidating multiple services onto one card defensible.