A practical guide to access control, credentials, mobile access, biometrics, readers, controllers, locks, visitor systems and interoperability.
Identity and credential are not the same thing
An identity represents a person, role or sometimes a vehicle or device. A credential is the token used to claim that identity. Traditional credentials include proximity cards and smart cards; newer systems use smartphones, digital wallets or biometrics. A credential alone does not prove that the correct person is presenting it, which is why higher-security applications may combine something a user has with something they are or something they know.
Readers and controllers
The reader captures the credential. The access controller applies rules and makes or supports the authorization decision, either locally at the door, by a central server, or through a hybrid model. Local intelligence matters for resilience: critical doors may need to continue operating against locally stored permissions if the network becomes unavailable.
Locking hardware
The electronic system ultimately controls physical hardware: electric strikes, magnetic locks, motorized locks, turnstiles or speed gates. Life-safety and egress requirements can override security logic, so door hardware selection must consider local fire and building codes as well as security.
Interoperability
Multi-vendor access control has historically required significant custom integration. ONVIF Profile A defines functions for configuring credentials, schedules and access rules; Profile C covers basic door control and event management; Profile D supports peripherals such as readers, biometric devices, keypads and locks. ONVIF’s access-control specifications have also been adopted into IEC 60839-11-1 requirements.
Mobile credentials and biometrics
A smartphone can act as a credential using technologies such as NFC or Bluetooth, simplifying issuance and revocation. Fingerprint, face and iris systems bind access decisions more closely to the person rather than the token, but introduce privacy, accuracy and governance questions—matching thresholds affect the trade-off between false accepts and false rejects.
How to design a system
Begin with access policy, not hardware. Define zones, user groups, schedules, exception handling, emergency behavior, visitor processes and audit requirements. Only then choose credentials, readers, controllers and software. The real security value of an access-control system is making authorization consistent, reviewable and resilient across the life cycle of every identity.
FAQ
Are mobile credentials replacing cards? They are growing quickly, but cards will remain relevant in many environments because of cost, legacy infrastructure, user requirements and offline operation.
Is facial recognition the same as access control? No. Facial recognition can be one authentication method within an access-control system.
What is ONVIF Profile A? It is an ONVIF profile for access-control configuration, including credentials, schedules and access rules.
Verification note: Local egress and fire-code requirements must be checked before publishing hardware recommendations for controlled doors.

Leave a Reply