Key takeaways
- EPC Gen2 tags have four memory banks: Reserved (passwords), EPC, TID (factory ID) and User. Encoding usually means rewriting the EPC bank.
- Keyboard mode only types tag numbers into software. Writing and locking need the writer in command mode with its demo tool or SDK.
- Encode one tag at a time at low RF power, write whole 16-bit words, and read the tag back before moving on.
- Set a non-zero access password before you lock. With a zero password, a locked bank can still be rewritten by anyone.
- For access control, number tags so that the bytes the lane reader sends over Wiegand are unique across the site.
To encode a UHF RFID tag, place one tag on a USB desktop writer, run an inventory to confirm the writer sees only that tag, write a new EPC in hexadecimal, and read it back to verify. If the number must never change in the field, set a non-zero access password and lock the EPC bank. Below: the memory map, writer modes, locking and numbering that make it reliable at volume.
Gen2 memory banks: Reserved, EPC, TID and User
Passive UHF tags that follow EPC Gen2 (ISO/IEC 18000-63) divide their memory into four banks. Memory is addressed and written in 16-bit words.
| Bank | Name | Contents | Size | Typical factory state |
|---|---|---|---|---|
| 00 | Reserved | Kill password (words 0–1), access password (words 2–3) | 64 bits (2 × 32-bit passwords) | Both 00000000, unlocked |
| 01 | EPC | StoredCRC (word 0), Protocol Control word (word 1), EPC from word 2 | EPC commonly 96 or 128 bits; Gen2 allows up to 496 bits | Default EPC, not always unique, unlocked |
| 10 | TID | Class identifier, mask-designer (chip maker) ID, model number, often a unique serial | Chip-dependent | Programmed and permalocked by the chip maker |
| 11 | User | Optional application data | 0 bits to several kilobits, chip-dependent | Blank, or absent on many chips |
A few rules follow from this layout:
- You encode the EPC bank. It is the number every reader returns during an inventory, and the one access control, warehouse and asset software store.
- The Protocol Control (PC) word states the EPC length. Its top five bits give the length in words, so a 96-bit EPC normally shows PC = 3000h and a 128-bit EPC 4000h. Some chips also set the user-memory indicator, giving 3400h. The tag calculates the CRC itself.
- The TID identifies the chip. On most current chips it includes a factory serial number that cannot be changed, which makes it a useful companion to the EPC. Confirm serialization in the chip datasheet before you rely on it.
- User memory varies. Some tags have none. Use it only for data that must travel with the tag, not data your database already holds.
HID keyboard mode vs COM and SDK mode
USB desktop UHF writers usually offer two ways of working, selected in the writer’s configuration tool. The mode decides what you can do.
| HID keyboard mode (“active” reading) | Command mode: USB HID or virtual COM with SDK (“passive” read/write) | |
|---|---|---|
| Driver | None; the PC sees a keyboard | None for USB HID; a virtual COM port may need a USB-serial driver |
| What happens | Each tag’s EPC, or a configured TID or User field, is typed into the active text box, usually followed by Enter | Software sends commands: inventory, read, write, lock, set RF power and region |
| Can it write or lock tags? | No, output only | Yes |
| Software | Any application with a text field | The vendor demo tool, or your own code using the SDK or serial protocol |
| Best for | Enrolling tags into access, parking, library or POS software | Encoding, locking, batch jobs, integration |
| Watch for | Host keyboard layout, hex vs decimal output, cursor focus | Correct port, only one program can open the port at a time |
Our guide to USB reader output formats covers keyboard mode in detail. For encoding, use command mode.
Step by step: read, write EPC, verify
- Check the band. Desktop writers come in regional versions: 902–928 MHz for the US and other FCC-aligned markets, 865–868 MHz for Europe and other ETSI markets. Use the version for the country where you encode, and tags tuned for the band where they will be read. Our UHF frequency by country guide lists the bands.
- Connect in command mode. Open the demo tool, select the device or port and confirm it responds.
- Turn RF power down. Desktop writers read from a few centimeters to a few tens of centimeters. Set power just high enough to read one tag lying on the pad, and keep the stack of blanks, other tags and metal away from it.
- Inventory one tag. Exactly one EPC should appear. Note it, then read the TID bank so you can identify this tag even after its EPC changes.
- Prepare the new EPC. Enter it as hexadecimal, with a length that is a multiple of four hex digits: 24 digits for 96 bits, 32 for 128 bits. Check the chip’s maximum EPC length.
- Target the right tag. If more than one tag might be in the field, use the Select or mask option with the tag’s current EPC or TID, so the write reaches only that tag.
- Write. Use the tool’s “Write EPC” function, which normally updates the PC length bits for you. For a raw write, choose the EPC bank, start at word 2 and write 6 words for 96 bits. If the length changes, update the PC word as well. Enter the access password, or 00000000 if none is set.
- Verify. Run the inventory again and compare the EPC digit by digit. Log the EPC and TID pair, then test the tag on the reader it will actually be used with.
Writing a tag needs more energy than reading it. A tag that reads at the edge of the field can still fail to write, so center it on the pad before you raise the power.
Access passwords and locking
Gen2 locking is set separately for the kill password, the access password, and the EPC, TID and User banks. Each area takes one of four states:
| Lock state | Who can write | Reversible? | Typical use |
|---|---|---|---|
| Unlocked | Anyone | Yes | Encoding and testing |
| Locked | Only a reader that supplies the access password | Yes, with the password | Field tags you may need to re-encode |
| Permanently unlocked | Anyone, forever | No | Rare: tags that must always stay rewritable |
| Permanently locked | Nobody, ever | No | Data that must never change |
For the EPC, TID and User banks, locking controls writing only; the data stays readable. For the two passwords, locking also blocks reading, unless the reader has entered the secured state with the access password.
Apply locks in this order:
- Write the EPC and any User data, and verify them.
- Write a non-zero 32-bit access password to Reserved words 2–3. A tag with a zero access password goes straight to the secured state, so a “locked” bank on such a tag can still be rewritten by anyone.
- Lock the EPC bank, and the User bank if it is used.
- Lock the access password itself. Otherwise anyone can simply read it from the Reserved bank.
- Leave the kill password at zero unless you plan to kill tags, for example for consumer privacy at retail. A tag with a zero kill password cannot be killed.
Store passwords securely: if a locked tag’s password is lost, that tag cannot be re-encoded. Gen2 passwords are exchanged cover-coded with a random number from the tag, which deters casual misuse but is not strong cryptography. Locking also does not stop copying: an EPC can be read and written onto another tag. Where cloning matters, check the TID as well, or specify chips and readers that support cryptographic authentication under Gen2 v2 with an ISO/IEC 29167 crypto suite.
Bulk encoding and numbering schemes
For more than a few dozen tags, plan the numbering before you encode the first one.
Closed-loop numbering. For a site or a single system, a fixed-length hex structure works well. Example 96-bit EPC:
A5C1 0012 0001 000000012B3C
Here A5C1 is a project code, 0012 a site code, 0001 the tag type (for example windshield label) and 000000012B3C a 48-bit serial. Keep the serial in the low bytes and never reuse a number.
GS1 numbering. If tags leave your system, for example on shipped goods or returnable containers, use a GS1 EPC scheme with your own GS1 Company Prefix. Common 96-bit schemes are SGTIN-96 (header 30h) for trade items, SSCC-96 (31h) for logistics units, GRAI-96 (33h) for returnable assets and GIAI-96 (34h) for individual assets. Encoding follows the GS1 EPC Tag Data Standard.
Batch workflow:
- Prepare a CSV with one row per tag: serial, EPC, printed number and the person, vehicle or asset it belongs to.
- Use the demo tool’s batch or auto-increment function, or a short script against the SDK: write, read back, log, next.
- Set aside any tag that fails verification. Don’t retry it blindly.
- Export an EPC–TID report for the whole batch and keep it with the password records.
- Print a human-readable number that matches the EPC, or the part of it that the site reader outputs.
For runs of many thousands, pre-encoding the tags before delivery is faster than a desktop writer. We can arrange encoding to your data file on request, along with an EPC–TID report.
Enrolling UHF cards and vehicle tags into access systems
Access controllers rarely see the whole EPC. A long-range reader wired to a controller sends a Wiegand frame: Wiegand 26 carries 24 data bits (an 8-bit facility code and a 16-bit card number) plus two parity bits, and Wiegand 34 carries 32 data bits plus two parity bits. The reader chooses which EPC or TID bytes go into that frame, and that is a reader setting.
With the example EPC above, a reader sending the last three bytes (01 2B 3C) in 26-bit mode delivers facility code 1 and card number 11,068. A reader sending the last four bytes (00 01 2B 3C) in 34-bit mode delivers 76,604. Plan the serial so the transmitted bytes are unique across the site. Our UHF reader Wiegand wiring guide covers byte selection and wiring.
There are two ways to enroll:
- At the admin PC. Set the desktop writer’s keyboard output to the same bytes and number format as the lane reader, click the card field in the access software and present the tag.
- Through the site reader. Use the software’s read-card or enrollment mode and present the tag to the real reader. This guarantees the stored number matches what the controller receives.
Vehicle tags. Encode and enroll windshield labels before you hand them out, and record the plate, EPC and TID together. Metallized or heat-reflective windshields attenuate UHF, so mount tags in an uncoated area if the glass has one, or use headlamp or license-plate tags. Tamper-evident labels that break when peeled stop tags moving between vehicles. See RFID vehicle access control for lane layouts.
UHF cards. A card held against the body or carried in a wallet reads at shorter range than a windshield tag, because the body absorbs UHF energy. Dual-technology cards carry separate chips, each with its own number, so enroll the one your reader uses.
Common errors and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| Demo tool cannot find the writer | Writer in keyboard mode, wrong port, or port held by another program | Switch to command mode, close other programs, reselect the port |
| Inventory shows several EPCs | Neighboring tags in the field, RF power too high | Lower power, move blanks away, use Select with EPC or TID |
| Tag reads but write fails | Tag at edge of field; writing needs more power | Center the tag, raise power one step, keep metal away |
| “Access denied” or password error | Bank locked with an access password | Enter the correct password; permalocked tags cannot be rewritten |
| EPC reads shorter or longer than written | PC length bits not updated after a raw write | Use “Write EPC”, or set PC to 3000h for 96 bits, 4000h for 128 bits |
| Write rejected for length | Not a multiple of 16 bits, or longer than the chip’s EPC memory | Pad to whole words; check the chip’s EPC size |
| Wrong characters in keyboard mode | Non-US keyboard layout, Caps Lock or output format | Match layout and format; test in a plain text editor |
| Controller number differs from label | Different bytes, byte order, hex vs decimal, 26 vs 34 bit | Align reader output and enrollment; enroll through the lane reader |
| Two tags report the same number | Blanks shipped with identical default EPCs | Encode unique EPCs, or output TID bytes |
| Reads on the desk, not at the gate | Band mismatch, coated windshield, mounting or orientation | Check band and mounting; test the tag in place |
Checklist: before a bulk encoding run
- Writer and tags match the region: 902–928 MHz (FCC) or 865–868 MHz (ETSI)
- EPC length (96 or 128 bits) supported by the chip
- Numbering scheme written down: closed-loop structure or GS1 scheme with company prefix
- Bytes the site readers output (Wiegand 26, Wiegand 34 or TID) are unique across the batch
- Access password policy set, stored securely, and never 00000000 on locked tags
- Lock plan: EPC bank, access password, User bank; kill password left at zero unless needed
- CSV prepared: serial, EPC, printed number, holder or asset
- Sample batch encoded, locked and tested on the real reader
- EPC–TID report exported and archived
Next steps
Tell us your tag type, quantity, region band and numbering plan, and whether tags must be locked. We will recommend a desktop writer and suitable UHF tags, send samples so you can test the full encode-lock-enroll workflow, and quote pre-encoding if you prefer tags delivered ready to use. Request a quote or samples.
Frequently asked questions
Can any UHF RFID tag be rewritten?
Any EPC Gen2 tag whose EPC bank is unlocked can be rewritten with a Gen2 writer. A bank locked with an access password can be rewritten only by someone who has that password, and a permalocked bank can never be changed. The TID is programmed at the factory and is normally permalocked.
What is the difference between the EPC and the TID?
The EPC is the rewritable identifier you encode, commonly 96 or 128 bits. The TID is written and locked by the chip maker and identifies the chip model, and on most current chips it includes a unique serial number. Many systems record both.
How many characters can I write to the EPC?
EPC memory is written in 16-bit words, so the hex string must be a multiple of four hex digits: 24 digits for 96 bits or 32 digits for 128 bits. The maximum depends on the chip; EPC Gen2 allows up to 496 bits, but many tags support 96 or 128.
Can a USB desktop writer in keyboard mode write tags?
No. Keyboard mode outputs data only: it types the tag's EPC or another configured field into whatever text box has focus. To write or lock tags, switch the writer to command mode and use the demo tool or SDK.
Does locking a UHF tag stop cloning?
No. Locking stops the tag from being rewritten, but its EPC can still be read and written onto another tag. Checking the factory TID raises the bar, and true clone resistance needs chips and readers that support cryptographic authentication.
Why does my access controller show a different number than the EPC?
Wiegand carries only 24 or 32 data bits, so the reader sends part of the EPC or TID, and the controller may display it in decimal or as facility code plus card number. Match the byte selection and format at both ends, or enroll tags through the reader the site actually uses.
Want a second opinion on your spec?
Send us your controller, credential type and environment — we'll recommend compatible hardware and quote within 24 hours.