What Lives Inside an RFID Tag: A Guide to Memory Banks
When you read about RFID tags, the conversation usually focuses on read range, form factor, or which frequency is best for a given application. What gets less attention is what actually lives inside the tag itself. Understanding RFID tag memory architecture matters more than most people realise, particularly if you are encoding tags, integrating data into backend systems, or trying to secure your deployment against unauthorised access.
This article covers the four memory banks defined in the EPC Gen2 (ISO 18000-63) standard, which governs passive UHF RFID tags. These are the tags you will encounter in retail, logistics, manufacturing, and most supply chain applications.
The Four Memory Banks
Every EPC Gen2 compliant tag has four distinct memory banks: Reserved, EPC, TID, and User. Each has a specific purpose, and they are not interchangeable.
Reserved Memory
Reserved memory holds two passwords: the Kill Password and the Access Password. Both are 32 bits long. The Kill Password, when transmitted to the tag by an authorised reader, permanently disables the tag, making it unreadable by any reader for the rest of its life. This was originally conceived as a privacy mechanism, allowing retailers to kill tags at point of sale. The Access Password restricts write access to the tag. If set, any attempt to write to the tag without presenting the correct password will be refused. Passwords are stored in clear by default, which means that if you set an Access Password, anyone with a reader can read it back unless you also lock the Reserved memory bank itself.
EPC Memory
The EPC bank is where the primary identifier lives. This is the Electronic Product Code, the number that most systems read and act upon. The minimum EPC length is 96 bits, which is the standard for most retail and logistics applications, but the bank can accommodate EPCs up to 496 bits if needed. The bank also contains a Protocol Control (PC) word that tells the reader how long the EPC is and a CRC for data integrity checking.
The EPC is what you encode when you commission a tag. In a retail scenario, this will typically be a GS1 SGTIN (Serialised Global Trade Item Number), encoding a company prefix, item reference, and serial number into the 96-bit field. In a manufacturing context it might be a custom encoding scheme tied to a work order or asset record. The encoding scheme matters because it determines how backend systems interpret the number and look it up in a database.
TID Memory
TID stands for Tag Identification. This bank is written by the chip manufacturer at the point of production and is, in most cases, permanently locked. It contains a unique identifier assigned to each individual chip, along with information about the chip manufacturer and model. Unlike the EPC, which you write during commissioning, the TID is fixed. This makes it useful for anti-counterfeiting applications: because TID cannot be easily cloned (it is part of the chip itself rather than a writable memory area), you can use it to verify that a tag is genuine hardware rather than a programmed counterfeit. Some systems use a combination of EPC and TID to create a tamper-evident link between the tag and a database record.
User Memory
Not all tags have User memory, and those that do vary widely in how much they provide. Typically, User memory ranges from 0 to 512 bytes, though some specialised tags offer more. It is a freely writable space that can store anything you like: a batch number, a maintenance record, a sensor reading, or application-specific data that does not fit neatly into the EPC field. In pharmaceutical serialisation, for example, User memory is sometimes used to store additional traceability data beyond what the EPC can hold. In industrial asset tracking, it might carry a calibration date or service interval.
Locking
Each memory bank can be locked in several ways. A permalock makes the bank permanently read-only and cannot be undone even with the correct password. A write-lock prevents changes but allows an authorised user to reverse the lock if they present the correct Access Password. Some banks, like TID, are permalocked by the manufacturer. Others, like EPC and User, can be locked during commissioning once you have finished encoding the tag. Getting your locking strategy right before deployment is important, because some of those decisions cannot be reversed.
Practical Takeaways
For most standard supply chain applications, you will interact primarily with the EPC bank and leave User memory empty and TID in its factory state. But if you are building a more sophisticated system involving anti-counterfeiting, secure access, or extended data storage, understanding all four banks gives you tools that most deployments leave unused. Set your Access Password if write security matters. Use TID verification if tag authenticity is a concern. And plan your locking strategy before you commission tags at scale, not after.

