High-security AES 13.56 MHz hotel credential

VingCard Plus Explained: The AES High-Security Credential Tier

VingCard Plus is the high-security, AES-secured 13.56 MHz credential tier used by ASSA ABLOY Global Solutions hotel locks, available in 2K and 4K memory sizes. It hardens a hotel key with 128-bit AES mutual authentication, a message authentication code on every command, and an encrypted radio channel — the top of VingCard's guest-credential ladder above legacy memory cards.

Last updated 2026-07-29

What is VingCard Plus?

VingCard Plus is the high-security tier of VingCard's AES-secured 13.56 MHz guest credential, offered in both 2K and 4K memory sizes. "Plus" marks the hardened credential ASSA ABLOY Global Solutions brought to its door-lock keys in 2024, in which the guest or staff key is protected by full 128-bit AES cryptography rather than presented as a readable serial. It runs on the same platform VingCard's Signature RFID locks already read.

VingCard has produced electronic hotel keys since installing the first recodable electronic keycard lock at the Westin Peachtree Plaza in Atlanta in 1978, and reintroduced Vingcard as its primary hospitality brand in 2024. VingCard Plus is the current high-assurance member of that credential family — the same AES protections whether a property picks the compact 2K key or the multi-application 4K card.

How secure is the VingCard Plus credential?

The VingCard Plus credential is secured by 128-bit AES mutual authentication with per-card diversified keys: card and lock authenticate each other before any data is exchanged, and every card carries different derived keys. A cipher-based message authentication code (CMAC) is applied to each command and response, a secure-messaging mode encrypts the exchange over the air, and an optional randomized ID prevents tracking by fixed serial.

Together these defend against the standard attacks on hotel keys — replay, man-in-the-middle interception, and skimming a static identifier. The credential tier VingCard adopted is certified to Common Criteria EAL3+, meaning the implementation was independently evaluated rather than merely asserted. In plain hospitality terms, this is the credential built so that reading one key does not expose the keys behind any other key in the estate.

How does VingCard Plus compare to standard smart and legacy cards?

VingCard's guest credentials form a security ladder: legacy unencrypted memory cards at the bottom, the standard AES smart card in the middle, and VingCard Plus as the high-security tier. The table maps the ladder so a property can place whatever it currently issues.

PropertyLegacy memory cardStandard AES smartVingCard Plus
Frequency / standard13.56 MHz, 14443-A13.56 MHz, 14443-A13.56 MHz, 14443-A
AuthenticationNone (no sector crypto)128-bit AES128-bit AES mutual auth
Message integrity (CMAC)NoYesYes
Encrypted RF channelNoYesYes
Anti-tracking IDFixed UIDOptional randomized IDOptional randomized ID
CertificationNoneCommon Criteria EAL3+Common Criteria EAL3+

Can VingCard Plus cards be cloned or copied?

A VingCard Plus card protects its access data with 128-bit AES mutual authentication, per-card diversified keys, and a CMAC on every exchange, so the useful data is not exposed as a plain readable serial during a normal read — unlike a 125 kHz proximity card, whose fixed number can be captured and re-emitted. Reproducing a Plus credential would require the site-specific diversified keys held inside the property's system.

The candid answer for any hotel is that credential clone-resistance is decided by key management, not by the card blank. A VingCard Plus deployment run with well-managed, site-specific keys and current locks reflects the security model VingCard designed. Wherever a property still leans on legacy, unencrypted guest cards, those specific doors carry the older risk — which is why the upgrade is framed as a migration rather than a single switch.

How does VingCard Plus fit Signature, Visionline and Vostio?

VingCard Plus is encoded and revoked centrally through the property's back end — Visionline on-premise or Vostio Access Management in the cloud — and validated at the door by Signature RFID locks. Signature is a multi-technology 13.56 MHz reader, so a single lock can accept the Plus credential alongside legacy guest cards during a migration, letting a property upgrade gradually rather than all at once.

ASSA ABLOY's documented direction moves backend management from on-premise Visionline to cloud Vostio, which adds remote key issuance, mobile keys over BLE and NFC on the same readers, and third-party integrations. Whether a property standardizes on the 2K or 4K size, VingCard Plus plugs into that same issuance, validation, and revocation workflow.

What is VingCard's own guidance on moving to Plus?

VingCard frames the move to its AES credential as a transition, not a forced re-card. In its May 2024 announcement, an industry executive described the upgrade as giving hotels "a more secure contactless way to transition away from legacy access technologies," and Richard Eastburn, Vingcard's Sr. Director and Head of Product Management, said it lets "Vingcard lock solutions continue to represent ultimate guest peace of mind."

Because Signature locks read old and new credentials together, the practical path is to raise a property door by door: keep legacy 13.56 MHz guest cards working where they are still in service, and issue the AES-secured Plus credential as rooms, staff areas, and encoders are cut over. That gradual approach is what makes upgrading a live hotel operationally feasible.

Is VingCard Plus backward compatible with existing locks?

VingCard Plus is designed to be introduced without swapping every lock, because VingCard Signature RFID readers are multi-technology 13.56 MHz devices that read legacy and AES credentials at the same door. A property can begin issuing the Plus credential while existing readers continue to accept the 13.56 MHz guest cards already in circulation, so the high-security tier is added on top of the installed base rather than requiring a full reader replacement.

The practical consequence is that backward compatibility is what makes a phased upgrade feasible. As encoders and software are provisioned for the AES tier, new keys are issued as Plus credentials while unconverted doors keep working, and the property retires legacy stock over time — the transition approach VingCard described when it announced AES credential support in 2024.

VingCard credential formats we supply

Through a VingCard migration, most properties keep legacy 13.56 MHz guest cards in circulation on unconverted doors. These open VingCard-compatible formats are ones we encode and supply, ready to read on your existing Signature and Visionline locks.

Sources & references

ASSA ABLOY Global Solutions and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

VingCard Plus (AES high-security, 2K/4K) — common questions

What is VingCard Plus?

VingCard Plus is the high-security, AES-secured 13.56 MHz credential tier for ASSA ABLOY Global Solutions hotel locks, available in 2K and 4K memory sizes. It hardens a hotel key with 128-bit AES mutual authentication, a CMAC on every command, and an encrypted radio channel, sitting above VingCard's standard smart and legacy memory cards.

How does VingCard Plus compare to a standard VingCard smart card?

VingCard Plus is the high-security tier of the same AES credential family. Both use 128-bit AES on the 13.56 MHz platform, but Plus is positioned as the hardened, high-assurance credential. Both are certified to Common Criteria EAL3+ and add a CMAC, an encrypted RF channel, and an optional randomized ID over a legacy memory card.

Is VingCard Plus available in both 2K and 4K?

Yes. VingCard Plus comes in a compact 2K size for single-purpose room or staff keys and a larger 4K size for multi-application cards that also carry data such as cashless charging, loyalty, or amenity access. The AES security model and EAL3+ certification are identical across both sizes.

Can a VingCard Plus card be copied?

A VingCard Plus card protects its data with 128-bit AES mutual authentication, per-card diversified keys, and a CMAC, so the data is not exposed as a plain serial like a 125 kHz proximity number. Reproducing it would require the property's site-specific keys, so clone-resistance depends on how those keys are managed.

How do hotels upgrade to VingCard Plus?

Hotels upgrade to VingCard Plus gradually. Because Signature RFID locks read legacy and AES credentials together, a property keeps legacy 13.56 MHz guest cards working on unconverted doors while issuing the AES-secured Plus credential as rooms, staff areas, and encoders are cut over — the transition approach VingCard described in May 2024.