Category: Access Control & Identity

Credentialing, biometrics, smart locks and identity verification technologies that control who can enter a facility.

  • Facial Recognition in Security: Technology, Accuracy and Regulation

    Facial Recognition in Security: Technology, Accuracy and Regulation

    Facial recognition is one of the most capable and controversial technologies in modern security. It can speed identity verification, support controlled access and help investigators search authorized watchlists, but its use carries technical, legal and ethical risks that differ significantly from ordinary video analytics.

    How the Technology Works

    Most facial-recognition systems perform two related tasks. Verification compares a face against a claimed identity, such as a person presenting a credential at a secure entrance. Identification searches a captured face against a database to find possible matches. Identification is generally more demanding because the system may compare one image with thousands or millions of enrolled templates.

    Image quality is critical. Pose, lighting, motion blur, camera angle, occlusion and target size all affect matching performance. A high-performing algorithm cannot compensate for a camera that captures faces at extreme angles or insufficient resolution.

    Operational Considerations

    Accuracy should be evaluated using false-match and false-non-match rates rather than a single headline percentage. Security teams should also understand threshold settings. A stricter threshold may reduce false matches but increase the number of legitimate users who are rejected.

    Demographic performance has received significant scrutiny. Organizations should review independent test results, vendor documentation and applicable regulatory requirements before deployment. High-consequence decisions should not be based solely on an automated match.

    The safest operational model treats facial recognition as a decision-support tool. A match can prompt an authorized operator to review the evidence or request another authentication factor. This is very different from allowing an algorithm to make an irreversible decision without human oversight.

    Deployment and Risk

    Data governance is central. Facial templates are biometric data and require strong protection. Organizations need clear rules for enrollment, consent where required, retention, database access, sharing and deletion. A compromised password can be changed; a biometric characteristic cannot.

    Regulation is evolving globally, and requirements vary by jurisdiction and use case. Public-space identification, employee access and voluntary customer authentication may fall under different rules. Security planners should involve privacy and legal teams early rather than treating compliance as an afterthought.

    Conclusion

    Facial recognition can deliver real operational value when the use case is narrow, lawful and technically well designed. The best deployments combine high-quality capture, conservative thresholds, human verification, strong biometric governance and transparent policies.

  • Access Control and Identity Technologies Explained

    Access Control and Identity Technologies Explained

    A practical guide to access control, credentials, mobile access, biometrics, readers, controllers, locks, visitor systems and interoperability.

    Identity and credential are not the same thing

    An identity represents a person, role or sometimes a vehicle or device. A credential is the token used to claim that identity. Traditional credentials include proximity cards and smart cards; newer systems use smartphones, digital wallets or biometrics. A credential alone does not prove that the correct person is presenting it, which is why higher-security applications may combine something a user has with something they are or something they know.

    Readers and controllers

    The reader captures the credential. The access controller applies rules and makes or supports the authorization decision, either locally at the door, by a central server, or through a hybrid model. Local intelligence matters for resilience: critical doors may need to continue operating against locally stored permissions if the network becomes unavailable.

    Locking hardware

    The electronic system ultimately controls physical hardware: electric strikes, magnetic locks, motorized locks, turnstiles or speed gates. Life-safety and egress requirements can override security logic, so door hardware selection must consider local fire and building codes as well as security.

    Interoperability

    Multi-vendor access control has historically required significant custom integration. ONVIF Profile A defines functions for configuring credentials, schedules and access rules; Profile C covers basic door control and event management; Profile D supports peripherals such as readers, biometric devices, keypads and locks. ONVIF’s access-control specifications have also been adopted into IEC 60839-11-1 requirements.

    Mobile credentials and biometrics

    A smartphone can act as a credential using technologies such as NFC or Bluetooth, simplifying issuance and revocation. Fingerprint, face and iris systems bind access decisions more closely to the person rather than the token, but introduce privacy, accuracy and governance questions—matching thresholds affect the trade-off between false accepts and false rejects.

    How to design a system

    Begin with access policy, not hardware. Define zones, user groups, schedules, exception handling, emergency behavior, visitor processes and audit requirements. Only then choose credentials, readers, controllers and software. The real security value of an access-control system is making authorization consistent, reviewable and resilient across the life cycle of every identity.

    FAQ

    Are mobile credentials replacing cards? They are growing quickly, but cards will remain relevant in many environments because of cost, legacy infrastructure, user requirements and offline operation.

    Is facial recognition the same as access control? No. Facial recognition can be one authentication method within an access-control system.

    What is ONVIF Profile A? It is an ONVIF profile for access-control configuration, including credentials, schedules and access rules.

    Verification note: Local egress and fire-code requirements must be checked before publishing hardware recommendations for controlled doors.

  • PSIA Releases PKOC 2.0.1 to Strengthen Credential Interoperability

    PSIA Releases PKOC 2.0.1 to Strengthen Credential Interoperability

    The Physical Security Interoperability Alliance (PSIA) has released version 2.0.1 of its Public Key Open Credential (PKOC) specification, adding new capabilities and implementation guidance while preserving backward compatibility with existing PKOC cards and readers, according to Security Info Watch.

    What’s New

    PKOC 2.0.1 adds improved version handling, a new information command, APDU compatibility and expanded implementation guidance. PSIA’s PKOC Validated mode continues to support legacy identifiers alongside core PKOC credentials, and the specification’s two underlying transport profiles — PKOC BLE Transport Profile 2.0.1 and PKOC NFC Transport Profile 2.0.1 — were formally approved on August 13, 2026, according to PSIA.

    Why It Matters

    PKOC is a license-free, vendor-agnostic credential specification built on public-key cryptography rather than a shared PKI, an approach PSIA says lowers deployment costs and reduces vendor lock-in for access-control credentials. “Version 2.0.1 strengthens the technical foundation of the specification and makes it easier for manufacturers, integrators and end users to evaluate and deploy PKOC-based solutions,” said David Bunzel, Executive Director of PSIA. Jason Ouellette, Head of Product Management and Strategy at ELATEC and Chairman of the PSIA Board, said testing confirmed the update “functions properly while remaining compatible with existing PKOC cards and readers.”

  • March Networks Ships 2026 Mid-Year Release With Expanded AI Search and C•CURE Integration

    March Networks Ships 2026 Mid-Year Release With Expanded AI Search and C•CURE Integration

    March Networks, a video surveillance and business intelligence provider now combined with VIVOTEK, has released its 2026 mid-year software update, adding expanded AI-powered search, new cloud video intelligence tools, broader VIVOTEK camera support and integration with C•CURE access control, the company announced.

    What’s New

    The release connects C•CURE access control events with March Networks’ Command Enterprise Software, letting operators review access activity alongside related video from a single workflow to investigate incidents and verify events. The update also expands the AI-powered natural-language video search capabilities March Networks has been building into its platform.

    Why It Matters

    “Customers do not need more disconnected systems or more data. They need the intelligence that comes when video, data and AI work together,” said Peter Strom, President and CEO of the combined March Networks and VIVOTEK organization. The release follows March Networks and VIVOTEK’s joint showcase of connected-intelligence tools at the 2026 Security Exhibition & Conference in Australia, part of a broader push by video management vendors to unify video, access control and business-system data into a single investigative interface.