RFID Cards

HITAG 2 Card

A HITAG 2 (HITAG2) card is a 125 kHz RFID card built on NXP’s HITAG 2 transponder IC, the chip family behind the PCF7936 car-key immobiliser transponder. It stores 256 bits in eight 32-bit pages, including a 32-bit read-only serial number and 128 bits of user memory, and runs in password mode, crypto mode (48-bit key) or a read-only public mode A, B or C.

Choose it to match HITAG 2 readers you already run: practical attacks on its cipher were published in 2012, so a new secure system should use an AES card instead. Send the reader type or a working card and we confirm the mode on a sample before production.

Free standard samples · Quotation within one business day

Download datasheet (PDF)

Product details

HITAG 2 card specifications

ItemHITAG 2 card
ChipHITAG 2 transponder IC (NXP HT2x family); exact part confirmed per order
Frequency125 kHz (low frequency), half-duplex
Memory256-bit EEPROM in 8 pages of 32 bits
Serial number32 bits, read-only, programmed at chip manufacture
User memory128 bits (pages 4–7)
ModesPassword mode, crypto mode (48-bit key) and read-only public modes A, B and C
Anti-collisionNone; a HALT function allows multi-tag operation in read/write mode
Chip data retention10 years
Chip write endurance100,000 erase/write cycles
Card materialPVC, PET, PETG, ABS
SizeCR80 / ISO ID-1 (85.6 × 54 mm) or custom
ColourCustom
Reading distance2–10 cm, depending on the reader and antenna
Working temperature-40 °C to 65 °C
Printing optionsSilk-screen, CMYK full colour, Pantone, digital printing, etc.
Crafts availableNumber printing, laser engraving, DOD, barcode, QR code, magnetic stripe, encoding, etc.

Chip figures come from NXP’s HITAG 2 data sheet. Card material, size, printing and read distance are confirmed for your order, and checked on a sample with your reader.

What is a HITAG 2 card?

HITAG 2 is a 125 kHz transponder IC from NXP (originally Philips), introduced in 1996. A HITAG 2 card is an ISO ID-1 card, key fob, epoxy tag or glass tube with that chip and a coil inside. It has no battery: the reader’s field powers the chip, and the two exchange data in half-duplex, the reader modulating its field to send commands and the chip answering by modulating that field in turn. NXP supplies the IC as sawn wafer and in two plastic module packages (HT2MOA4S20 and HT2DC20S20); the PCF7936 is its HITAG 2 security transponder for vehicle immobilisers.

NXP now lists the HITAG 2 transponder IC as not recommended for new designs, as it does HITAG 1 and HITAG S. HITAG 2 cards are still ordered because systems built around HITAG readers need replacement cards that speak the same protocol and mode.

HITAG 2 memory map

The 256-bit EEPROM is divided into 8 pages of 32 bits: 128 bits of control data and secrets in pages 0–3, and 128 bits of user data in pages 4–7. What pages 1 and 2 hold depends on the mode (NXP HT2x data sheet).

PageCrypto modePassword mode
032-bit serial number (read-only)32-bit serial number (read-only)
1Secret key, low 32 bitsReader password, 32 bits
2Secret key, high 16 bits (rest reserved)Reserved
3Configuration byte (8 bits) + tag password (24 bits)Configuration byte (8 bits) + tag password (24 bits)
4–7User data, 4 × 32 = 128 bitsUser data, 4 × 32 = 128 bits

The configuration byte selects the mode and the access rights. Memory flags can make pages read-only or block reading altogether, so a card can be locked after personalisation and its key pages kept unreadable.

Password mode, crypto mode and public modes A, B and C

ModeHow it worksTypical use
Password modeReader and card authenticate each other by exchanging passwords: the 32-bit reader password (page 1) and the 24-bit tag password (page 3). Data then travels unencrypted.Legacy access control and industrial identification
Crypto modeMutual authentication with a 48-bit shared secret key; commands and data are then encrypted with the proprietary HITAG 2 stream cipher.Vehicle immobilisers and HITAG systems built for crypto mode
Public mode ARead-only broadcast that emulates MIRO and EM H400x-type read-only transponders, so a reader for that EM format can normally read the card.Installations with EM-format 125 kHz readers
Public mode BRead-only broadcast in the ISO 11784/11785 animal-identification format.Animal identification
Public mode CRead-only broadcast compatible with PIT transponders (PCF793x).Older PIT-based systems

In a public mode the chip simply broadcasts the contents of its user pages as soon as it is powered, with no password and no encryption, so any compatible reader can read it. Data from the chip are Manchester or biphase coded, data to the chip use pulse-duration coding, and the link uses amplitude-shift keying. The mode is set in the configuration byte at encoding time to match your reader, which is why we need the reader type or a working card before production.

Is HITAG 2 secure?

Not by current standards. HITAG 2 uses a proprietary stream cipher with a 48-bit key. Its design was reverse-engineered in 2007, and in 2012 Roel Verdult, Flavio Garcia and Josep Balasch published three practical attacks that recover the secret key using only radio communication (“Gone in 360 Seconds: Hijacking with Hitag2”, USENIX Security 2012). The most serious needs a valid transponder ID and 136 partial authentication attempts, collected in about a minute from the reader (in the paper, the car) by an emulated card, and then less than five minutes on an ordinary laptop. The same paper found that the transponder has no random-number generator, which leaves its authentication open to replay; that password mode exchanges passwords in the clear; and that the tag password has only 24 bits of entropy.

In practice, a card in public mode can be read by anyone with a compatible reader and duplicated; in password mode the passwords can be captured and replayed; and in crypto mode the key can be recovered with the published attacks. Use HITAG 2 to stay compatible with readers you already run, or for low-risk identification such as asset, tool or gas-cylinder ID where the site accepts that cloning risk. Do not use it as the security layer of a new system.

For a new access-control system, or whenever the readers are being replaced anyway, choose a 13.56 MHz card with AES-based authentication such as MIFARE DESFire; our guide to RFID key fobs for access control compares 125 kHz and DESFire credentials. For immobilisers, the same paper notes that NXP’s HITAG AES / HITAG Pro transponders use AES.

How far can a HITAG 2 card be read?

NXP’s public short data sheet gives no read range for HITAG 2, only that the reading and writing distances are the same, so a card can be encoded at the distance at which it is read. Range is set by the reader’s antenna and power and by the size of the coil in the card or tag. On typical desk and wall readers an ID-1 card reads at about 2–10 cm; long-range 125 kHz readers with large antennas, and thicker clamshell cards with a bigger coil, read further. Test a sample on your own reader before writing a distance into a specification.

Where HITAG 2 is used: immobilisers, access control and industry

Car immobilisers are HITAG 2’s best-known use. When Verdult and colleagues studied it in 2012 it was the most widely used immobiliser transponder, fitted by at least 34 car makes in more than 200 models: a transponder in the key head authenticates in crypto mode to a reader coil around the ignition, and the engine starts only after a correct response. That installed base is why HITAG readers are common and why the protocol still turns up in vehicle and fleet systems. We supply cards, fobs and tags; for the automotive transponder see our car transponder chip page, and for gate and fleet set-ups the vehicle RFID identification guide.

In access control, HITAG 2 cards and fobs serve sites whose readers were installed for HITAG, working in password or crypto mode, or read in public mode A by EM-format readers. A replacement credential has to match the reader’s chip family, mode and data layout, which is why we ask for a working card.

NXP lists logistics, livestock tracking, asset tracking, gas cylinder ID, casino and gaming, and industrial automation among HITAG 2 applications. For tags fixed to metal or embedded in plastic, such as gas cylinders, tools, moulds and returnable containers, tell us the reader, the mode and the mounting surface, and we confirm the construction and test a sample before production.

HITAG 2 reader compatibility

A HITAG 2 card works only with a reader whose firmware supports HITAG 2 in the mode the card is set to; NXP’s own reader IC for the HITAG family is the HTRC110. Mode matters as much as chip: a reader that expects a public-mode broadcast gets nothing from a card in password or crypto mode, because the card then answers only HITAG 2 commands, and a password-mode reader cannot authenticate a card personalised with a crypto key.

Readers are rarely interchangeable across chip families. A HITAG 2 reader does not read HITAG 1 or HITAG S unless it supports several HITAG modes, and an EM4100-type reader can read a HITAG 2 card only in public mode A, which emulates EM H400x-type tags; confirm that on a sample with your reader. If your readers are EM-format readers, an EM4200 card, EM4305 card or T5577 card is the simpler order.

HITAG 1, HITAG 2 and HITAG S compared

HITAG 1HITAG 2HITAG S
Memory2048 bits (64 pages × 4 bytes)256 bits (8 pages × 4 bytes; 128-bit user data)256 or 2048 bits (HITAG S256 / S2048)
Anti-collisionYes (AC mode, mainly for long-range operation)No (HALT function for multi-tag operation)Yes (fast: 100 tags in 3.2 s)
SecurityMutual authentication, encrypted transmissionPassword mode, or crypto mode with a 48-bit key48-bit secret-key encrypted authentication
Frequency / standards125 kHz125 kHz; public modes A/B/C incl. ISO 11784/11785100–150 kHz; ISO 11784/11785, ISO 14223, ISO 18000-2
Applications named by NXPLogistics, asset tracking, gas cylinder ID, industrial automationLogistics, livestock, asset tracking, gas cylinder ID, casino, industrial automationAnimal ID, laundry, beer kegs and gas cylinders, brand protection
NXP statusNot recommended for new designsNot recommended for new designsNot recommended for new designs

The families are not interchangeable at the reader. HITAG µ is a further NXP family, aimed at ISO 11784/11785 and ISO 14223 animal identification, and is not read by a HITAG 2-only reader either. Figures are from NXP’s HITAG 1, HITAG 2 and HITAG S product pages.

Form factors and construction

  • ID-1 card: 85.6 × 54 mm PVC, PET, PETG or ABS, printable with your artwork and numbering. Thicker ‘clamshell’ versions give a longer read range because they carry a larger antenna.
  • Key fob: ABS fobs in several shapes and colours for residents and drivers; see our proximity fobs.
  • Epoxy tag: an epoxy-domed tag, with a metal eyelet for a key ring (as shown below) or an adhesive back for phone cases and badges.
  • Glass tube and industrial tag: for animal identification and for embedding in tools, moulds and containers.
  • Transponder: HITAG 2 transponders for keys and your own housings are covered on our car transponder chip page; the exact part and its availability are confirmed per order.
Black and white ABS key fob with a HITAG 2 transponder

HITAG 2 key fob

ABS key fob for access-control readers.

Green and white epoxy HITAG 2 key tags with metal eyelets

HITAG 2 epoxy tag

Epoxy-domed key tag with a metal eyelet and a printable face.

NXP HITAG 2 transponder modules marked HT2DC20S20

HITAG 2 transponder module

HITAG 2 transponder modules (NXP SOT385-1 package shown).

Before you order

  1. The reader or system brand, or a working card, so we can confirm HITAG 2 and the mode (password, crypto, or public mode A, B or C).
  2. Whether you need the serial number only, or a specific configuration and user data written and locked.
  3. Form factor, material, artwork and printed numbering.
  4. Quantity and delivery date. Samples are available for reader testing before a production run.

What Proud Tek produces and supplies

We produce the cards, fobs and tags in our Shenzhen factory, configured to the system owner’s specification; numbered cards are delivered with an Excel, CSV or XML file listing each card’s 32-bit serial number beside the number printed on it. We do not supply access-control readers or software and do not duplicate credentials from systems the buyer does not administer. Related pages: 125 kHz RFID cards, vehicle RFID identification and RFID key fobs for access control.

Sources: NXP HITAG 2 transponder IC data sheet (HT2x, Rev. 3.1) and product pages for HITAG 2, HITAG 1 and HITAG S; R. Verdult, F. D. Garcia and J. Balasch, “Gone in 360 Seconds: Hijacking with Hitag2”, USENIX Security 2012. Chip documentation describes IC capabilities; it does not establish stock or a finished card’s compatibility with your system.

Frequently asked questions

What is a HITAG 2 card?

A 125 kHz RFID card, fob or tag built on NXP’s HITAG 2 transponder IC. The chip has 256 bits of memory in 8 pages, including a 32-bit read-only serial number and 128 bits of user data, and works in password mode, crypto mode or a read-only public mode. Today it is best used to match HITAG readers already installed in access, vehicle and industrial systems.

What is HITAG 2 public mode A?

One of three read-only modes set in the configuration byte. In public mode A the card broadcasts its user data as soon as it is powered, emulating MIRO and EM H400x-type read-only transponders, so a reader for that EM format can normally read it without a password. Public mode B uses the ISO 11784/11785 animal-ID format, and public mode C is compatible with PIT (PCF793x) transponders.

What are password mode and crypto mode?

Both are read/write modes that require authentication first. In password mode the reader and card exchange passwords, the 32-bit reader password and the card’s 24-bit tag password, and data then travels unencrypted. In crypto mode they authenticate each other with a 48-bit secret key, and the session is encrypted with the HITAG 2 stream cipher. The mode is set in the configuration page at encoding time.

Is HITAG 2 secure?

Not for a new security-critical system. Its proprietary 48-bit cipher has been broken in published research: Verdult, Garcia and Balasch (USENIX Security 2012) recovered the secret key in minutes using only radio communication, and showed that its authentication can be replayed. NXP lists the chip as not recommended for new designs. Use HITAG 2 to stay compatible with installed HITAG readers; for a new system choose an AES card such as MIFARE DESFire.

What is the difference between HITAG 2 and HITAG 1 or HITAG S?

Memory, anti-collision and security. HITAG 2 has 256 bits, password and crypto modes and no anti-collision, although a HALT function allows multi-tag operation. HITAG 1 has 2048 bits and HITAG S 256 or 2048 bits, both with anti-collision so several tags can be read in one field. A reader configured for one family does not normally read the others.

Which readers work with HITAG 2 cards, and can an EM4100 reader read one?

Readers whose firmware supports HITAG 2 in the mode your cards use; NXP’s reader IC for the HITAG family is the HTRC110. An EM4100-type reader reads a HITAG 2 card only in public mode A, which emulates EM H400x-type read-only tags, and even then confirm it on a sample with your reader. In password or crypto mode the card does not broadcast; it answers only HITAG 2 commands, which an EM-only reader does not send. If all your readers are EM-format, an EM4200, EM4305 or T5577 card is usually the simpler choice. We supply the cards, fobs and tags, not the readers.

How far can a HITAG 2 card be read?

It depends on the reader and antenna far more than on the chip, and NXP’s public short data sheet gives no figure. On typical access readers an ID-1 card reads at about 2–10 cm; long-range 125 kHz readers with larger antennas, and clamshell cards with a bigger coil, read further. Test a sample on your reader.

Can you supply HITAG 2 cards pre-encoded for our readers?

Yes, for the organisation that administers the system. Send the reader type or a working sample and the data to be written, and we configure the mode, then write and lock the pages. Each encoded card is read back to confirm the write, and a data report goes out with the order; see the RFID encoding service.

Buyer guides

Ready to specify your order?

Send the product, quantity and application so we can confirm the options and pricing for your project.

Prefer to message us? WhatsApp or email about this product.

Get a quote WhatsApp
WhatsApp