how to

How to Encode UHF RFID Tags with a USB Desktop Writer

To encode a UHF RFID tag, isolate it on a desktop writer, write a new EPC in hex, read it back, then lock it with an access password. Steps and fixes.

Key takeaways

  • EPC Gen2 tags have four memory banks: Reserved (passwords), EPC, TID (factory ID) and User. Encoding usually means rewriting the EPC bank.
  • Keyboard mode only types tag numbers into software. Writing and locking need the writer in command mode with its demo tool or SDK.
  • Encode one tag at a time at low RF power, write whole 16-bit words, and read the tag back before moving on.
  • Set a non-zero access password before you lock. With a zero password, a locked bank can still be rewritten by anyone.
  • For access control, number tags so that the bytes the lane reader sends over Wiegand are unique across the site.

To encode a UHF RFID tag, place one tag on a USB desktop writer, run an inventory to confirm the writer sees only that tag, write a new EPC in hexadecimal, and read it back to verify. If the number must never change in the field, set a non-zero access password and lock the EPC bank. Below: the memory map, writer modes, locking and numbering that make it reliable at volume.

Gen2 memory banks: Reserved, EPC, TID and User

Passive UHF tags that follow EPC Gen2 (ISO/IEC 18000-63) divide their memory into four banks. Memory is addressed and written in 16-bit words.

Bank Name Contents Size Typical factory state
00 Reserved Kill password (words 0–1), access password (words 2–3) 64 bits (2 × 32-bit passwords) Both 00000000, unlocked
01 EPC StoredCRC (word 0), Protocol Control word (word 1), EPC from word 2 EPC commonly 96 or 128 bits; Gen2 allows up to 496 bits Default EPC, not always unique, unlocked
10 TID Class identifier, mask-designer (chip maker) ID, model number, often a unique serial Chip-dependent Programmed and permalocked by the chip maker
11 User Optional application data 0 bits to several kilobits, chip-dependent Blank, or absent on many chips

A few rules follow from this layout:

  • You encode the EPC bank. It is the number every reader returns during an inventory, and the one access control, warehouse and asset software store.
  • The Protocol Control (PC) word states the EPC length. Its top five bits give the length in words, so a 96-bit EPC normally shows PC = 3000h and a 128-bit EPC 4000h. Some chips also set the user-memory indicator, giving 3400h. The tag calculates the CRC itself.
  • The TID identifies the chip. On most current chips it includes a factory serial number that cannot be changed, which makes it a useful companion to the EPC. Confirm serialization in the chip datasheet before you rely on it.
  • User memory varies. Some tags have none. Use it only for data that must travel with the tag, not data your database already holds.

HID keyboard mode vs COM and SDK mode

USB desktop UHF writers usually offer two ways of working, selected in the writer’s configuration tool. The mode decides what you can do.

HID keyboard mode (“active” reading) Command mode: USB HID or virtual COM with SDK (“passive” read/write)
Driver None; the PC sees a keyboard None for USB HID; a virtual COM port may need a USB-serial driver
What happens Each tag’s EPC, or a configured TID or User field, is typed into the active text box, usually followed by Enter Software sends commands: inventory, read, write, lock, set RF power and region
Can it write or lock tags? No, output only Yes
Software Any application with a text field The vendor demo tool, or your own code using the SDK or serial protocol
Best for Enrolling tags into access, parking, library or POS software Encoding, locking, batch jobs, integration
Watch for Host keyboard layout, hex vs decimal output, cursor focus Correct port, only one program can open the port at a time

Our guide to USB reader output formats covers keyboard mode in detail. For encoding, use command mode.

Step by step: read, write EPC, verify

  1. Check the band. Desktop writers come in regional versions: 902–928 MHz for the US and other FCC-aligned markets, 865–868 MHz for Europe and other ETSI markets. Use the version for the country where you encode, and tags tuned for the band where they will be read. Our UHF frequency by country guide lists the bands.
  2. Connect in command mode. Open the demo tool, select the device or port and confirm it responds.
  3. Turn RF power down. Desktop writers read from a few centimeters to a few tens of centimeters. Set power just high enough to read one tag lying on the pad, and keep the stack of blanks, other tags and metal away from it.
  4. Inventory one tag. Exactly one EPC should appear. Note it, then read the TID bank so you can identify this tag even after its EPC changes.
  5. Prepare the new EPC. Enter it as hexadecimal, with a length that is a multiple of four hex digits: 24 digits for 96 bits, 32 for 128 bits. Check the chip’s maximum EPC length.
  6. Target the right tag. If more than one tag might be in the field, use the Select or mask option with the tag’s current EPC or TID, so the write reaches only that tag.
  7. Write. Use the tool’s “Write EPC” function, which normally updates the PC length bits for you. For a raw write, choose the EPC bank, start at word 2 and write 6 words for 96 bits. If the length changes, update the PC word as well. Enter the access password, or 00000000 if none is set.
  8. Verify. Run the inventory again and compare the EPC digit by digit. Log the EPC and TID pair, then test the tag on the reader it will actually be used with.

Writing a tag needs more energy than reading it. A tag that reads at the edge of the field can still fail to write, so center it on the pad before you raise the power.

Access passwords and locking

Gen2 locking is set separately for the kill password, the access password, and the EPC, TID and User banks. Each area takes one of four states:

Lock state Who can write Reversible? Typical use
Unlocked Anyone Yes Encoding and testing
Locked Only a reader that supplies the access password Yes, with the password Field tags you may need to re-encode
Permanently unlocked Anyone, forever No Rare: tags that must always stay rewritable
Permanently locked Nobody, ever No Data that must never change

For the EPC, TID and User banks, locking controls writing only; the data stays readable. For the two passwords, locking also blocks reading, unless the reader has entered the secured state with the access password.

Apply locks in this order:

  1. Write the EPC and any User data, and verify them.
  2. Write a non-zero 32-bit access password to Reserved words 2–3. A tag with a zero access password goes straight to the secured state, so a “locked” bank on such a tag can still be rewritten by anyone.
  3. Lock the EPC bank, and the User bank if it is used.
  4. Lock the access password itself. Otherwise anyone can simply read it from the Reserved bank.
  5. Leave the kill password at zero unless you plan to kill tags, for example for consumer privacy at retail. A tag with a zero kill password cannot be killed.

Store passwords securely: if a locked tag’s password is lost, that tag cannot be re-encoded. Gen2 passwords are exchanged cover-coded with a random number from the tag, which deters casual misuse but is not strong cryptography. Locking also does not stop copying: an EPC can be read and written onto another tag. Where cloning matters, check the TID as well, or specify chips and readers that support cryptographic authentication under Gen2 v2 with an ISO/IEC 29167 crypto suite.

Bulk encoding and numbering schemes

For more than a few dozen tags, plan the numbering before you encode the first one.

Closed-loop numbering. For a site or a single system, a fixed-length hex structure works well. Example 96-bit EPC:

A5C1 0012 0001 000000012B3C

Here A5C1 is a project code, 0012 a site code, 0001 the tag type (for example windshield label) and 000000012B3C a 48-bit serial. Keep the serial in the low bytes and never reuse a number.

GS1 numbering. If tags leave your system, for example on shipped goods or returnable containers, use a GS1 EPC scheme with your own GS1 Company Prefix. Common 96-bit schemes are SGTIN-96 (header 30h) for trade items, SSCC-96 (31h) for logistics units, GRAI-96 (33h) for returnable assets and GIAI-96 (34h) for individual assets. Encoding follows the GS1 EPC Tag Data Standard.

Batch workflow:

  • Prepare a CSV with one row per tag: serial, EPC, printed number and the person, vehicle or asset it belongs to.
  • Use the demo tool’s batch or auto-increment function, or a short script against the SDK: write, read back, log, next.
  • Set aside any tag that fails verification. Don’t retry it blindly.
  • Export an EPC–TID report for the whole batch and keep it with the password records.
  • Print a human-readable number that matches the EPC, or the part of it that the site reader outputs.

For runs of many thousands, pre-encoding the tags before delivery is faster than a desktop writer. We can arrange encoding to your data file on request, along with an EPC–TID report.

Enrolling UHF cards and vehicle tags into access systems

Access controllers rarely see the whole EPC. A long-range reader wired to a controller sends a Wiegand frame: Wiegand 26 carries 24 data bits (an 8-bit facility code and a 16-bit card number) plus two parity bits, and Wiegand 34 carries 32 data bits plus two parity bits. The reader chooses which EPC or TID bytes go into that frame, and that is a reader setting.

With the example EPC above, a reader sending the last three bytes (01 2B 3C) in 26-bit mode delivers facility code 1 and card number 11,068. A reader sending the last four bytes (00 01 2B 3C) in 34-bit mode delivers 76,604. Plan the serial so the transmitted bytes are unique across the site. Our UHF reader Wiegand wiring guide covers byte selection and wiring.

There are two ways to enroll:

  • At the admin PC. Set the desktop writer’s keyboard output to the same bytes and number format as the lane reader, click the card field in the access software and present the tag.
  • Through the site reader. Use the software’s read-card or enrollment mode and present the tag to the real reader. This guarantees the stored number matches what the controller receives.

Vehicle tags. Encode and enroll windshield labels before you hand them out, and record the plate, EPC and TID together. Metallized or heat-reflective windshields attenuate UHF, so mount tags in an uncoated area if the glass has one, or use headlamp or license-plate tags. Tamper-evident labels that break when peeled stop tags moving between vehicles. See RFID vehicle access control for lane layouts.

UHF cards. A card held against the body or carried in a wallet reads at shorter range than a windshield tag, because the body absorbs UHF energy. Dual-technology cards carry separate chips, each with its own number, so enroll the one your reader uses.

Common errors and fixes

Symptom Likely cause Fix
Demo tool cannot find the writer Writer in keyboard mode, wrong port, or port held by another program Switch to command mode, close other programs, reselect the port
Inventory shows several EPCs Neighboring tags in the field, RF power too high Lower power, move blanks away, use Select with EPC or TID
Tag reads but write fails Tag at edge of field; writing needs more power Center the tag, raise power one step, keep metal away
“Access denied” or password error Bank locked with an access password Enter the correct password; permalocked tags cannot be rewritten
EPC reads shorter or longer than written PC length bits not updated after a raw write Use “Write EPC”, or set PC to 3000h for 96 bits, 4000h for 128 bits
Write rejected for length Not a multiple of 16 bits, or longer than the chip’s EPC memory Pad to whole words; check the chip’s EPC size
Wrong characters in keyboard mode Non-US keyboard layout, Caps Lock or output format Match layout and format; test in a plain text editor
Controller number differs from label Different bytes, byte order, hex vs decimal, 26 vs 34 bit Align reader output and enrollment; enroll through the lane reader
Two tags report the same number Blanks shipped with identical default EPCs Encode unique EPCs, or output TID bytes
Reads on the desk, not at the gate Band mismatch, coated windshield, mounting or orientation Check band and mounting; test the tag in place

Checklist: before a bulk encoding run

  • Writer and tags match the region: 902–928 MHz (FCC) or 865–868 MHz (ETSI)
  • EPC length (96 or 128 bits) supported by the chip
  • Numbering scheme written down: closed-loop structure or GS1 scheme with company prefix
  • Bytes the site readers output (Wiegand 26, Wiegand 34 or TID) are unique across the batch
  • Access password policy set, stored securely, and never 00000000 on locked tags
  • Lock plan: EPC bank, access password, User bank; kill password left at zero unless needed
  • CSV prepared: serial, EPC, printed number, holder or asset
  • Sample batch encoded, locked and tested on the real reader
  • EPC–TID report exported and archived

Next steps

Tell us your tag type, quantity, region band and numbering plan, and whether tags must be locked. We will recommend a desktop writer and suitable UHF tags, send samples so you can test the full encode-lock-enroll workflow, and quote pre-encoding if you prefer tags delivered ready to use. Request a quote or samples.

Frequently asked questions

Can any UHF RFID tag be rewritten?

Any EPC Gen2 tag whose EPC bank is unlocked can be rewritten with a Gen2 writer. A bank locked with an access password can be rewritten only by someone who has that password, and a permalocked bank can never be changed. The TID is programmed at the factory and is normally permalocked.

What is the difference between the EPC and the TID?

The EPC is the rewritable identifier you encode, commonly 96 or 128 bits. The TID is written and locked by the chip maker and identifies the chip model, and on most current chips it includes a unique serial number. Many systems record both.

How many characters can I write to the EPC?

EPC memory is written in 16-bit words, so the hex string must be a multiple of four hex digits: 24 digits for 96 bits or 32 digits for 128 bits. The maximum depends on the chip; EPC Gen2 allows up to 496 bits, but many tags support 96 or 128.

Can a USB desktop writer in keyboard mode write tags?

No. Keyboard mode outputs data only: it types the tag's EPC or another configured field into whatever text box has focus. To write or lock tags, switch the writer to command mode and use the demo tool or SDK.

Does locking a UHF tag stop cloning?

No. Locking stops the tag from being rewritten, but its EPC can still be read and written onto another tag. Checking the factory TID raises the bar, and true clone resistance needs chips and readers that support cryptographic authentication.

Why does my access controller show a different number than the EPC?

Wiegand carries only 24 or 32 data bits, so the reader sends part of the EPC or TID, and the controller may display it in decimal or as facility code plus card number. Match the byte selection and format at both ends, or enroll tags through the reader the site actually uses.

Want a second opinion on your spec?

Send us your controller, credential type and environment — we'll recommend compatible hardware and quote within 24 hours.

Products mentioned

Hardware for this job

LR-110

30 m Long-Range UHF RFID Reader for Parking, IP66

IP66 integrated UHF reader that identifies vehicle tags at up to 12 m (9 dBi) or 30 m (12 dBi), with Wiegand 26/34, RS485, USB and optional TCP/IP.

Up to 12 m (9 dBi) / up to 30 m (12 dBi)865–868 MHz (EU) or 902–928 MHz (US)Wiegand 26/34, RS485, USB; TCP/IP optional
Details →
LR-150

Standalone UHF RFID Access Controller, Bluetooth, IP66

IP66 all-in-one UHF reader and access controller: stores 5,000 users, controls the gate lock, opens by Bluetooth and reads tags at up to 10 m or 20 m.

5,0002–10 m (309 mm) / 10–20 m (445 mm)865–868 MHz (EU) or 902–928 MHz (US)
Details →
LR-140

20 m Long-Range UHF RFID Reader, 12 dBi, Wiegand & RS485

445 mm IP66 integrated UHF reader with a 12 dBi linear antenna that reads vehicle tags at 10–20 m and reports over Wiegand, RS485 or optional TCP/IP.

10–20 m865–868 MHz (EU) or 902–928 MHz (US)Wiegand, RS485; TCP/IP on -NET-BT
Details →
LR-130

10 m UHF RFID Reader, 9 dBi, Wiegand & RS485, IP66

309 mm integrated UHF reader that reads EPC Gen2 cards and tags at 2–10 m, with Wiegand and RS485 output, IP66 housing and a TCP/IP plus Bluetooth option.

2–10 m865–868 MHz (EU) or 902–928 MHz (US)Wiegand, RS485; TCP/IP on -NET-BT
Details →

Keep reading

Tell us what you are building

Send your card type, interface and quantity. You get a quote, lead time and compatibility notes within 24 hours — samples available for most items.

Email us
sales@valenid.com

Request a quote

Tell us what you need — an engineer replies within 24 hours with pricing, lead time and compatibility notes.

We reply within 24 hours on working days. Your details are used only to answer this inquiry — see our privacy policy.