Dispelling myths from the past

Access & Identity Management Handbook 2012 Access Control & Identity Management

Gary Chalmers asks if the access control playing field has changed.

Access control has always been a key priority for business. Securing premises, people, possessions and property (the intellectual kind especially) is a non-negotiable requirement that companies overlook at their peril, a requirement around which an entire business sector has grown.

But has the playing field changed? Are the myths of the past holding back the solutions of the future, allowing unscrupulous market players to drive ageing products out to uneducated consumers? The answer to these questions, I believe, is a loud and resounding Yes.

Biometrics is a relatively new player on the security scene, and many people do not realise that the initial systems had significant weaknesses which, when combined with the legacy systems in place, resulted in today’s overly complex solutions.

Originally, security systems were designed around card-based readers, where the intelligence lay in the back-end controller. The better systems linked card readers to controllers in the ceiling which acted as a kind of digital doorman. Requests from readers are passed to the controller, which in turn passes these requests on to the server for verification. The server’s response is returned to the controller which, depending on the result received, would send the signal that releases the door. This meant that taking the card reader off the wall and trying to short circuit the cables had no effect whatsoever on the release of the door – you would need to have a ceiling breach in order to reach the cables that actually triggered the release signal.

When biometric readers first came onto the scene, their communication in a standalone mode was a direct, unsecured electrical pulse sent directly to the relay itself. The little-known yet terrifying flaw in this design is that you can bypass the average biometric device by removing it from the wall and shorting out the correct lines on the signal wire.

To avoid this situation, most security companies use biometric readers as nothing more than fancy card readers. Sitting behind the biometric reader is a connection to a controller in the ceiling, which still talks to a back-end, centralised system, and then sends a signal to the door to release based on the rules in its database.

The biometric reader is, in this case, a dumb terminal that resolves a fingerprint to an identity and sends a card number to the controller using a standard communication protocol called Wiegand.

The issue with this type of design is that it is mostly just smoke and mirrors: using old technology with a new front end to convince customers it is a modern solution. The result is a costly, highly complex solution which has multiple points of failure and requires high-value service level agreements and skilled personnel to maintain.

Modern solutions

With the advances in many biometric systems today, the need for this whole back-end system – and the separate door controllers – is completely redundant. Myth debunked.

Most modern readers have secure, encrypted communications to the relays while running the intelligence they need to deny or grant access internally, only using a back-end database for complex instructions when required. Many companies will tell you that not using a back-end controller means a lack of control, inability to do accurate anti-passback, and reduced security overall.

The truth, however, could not be further from this myth. All the features of the older systems are available with most of the new biometric systems, but without any of the additional overhead in terms of cost or maintenance. By removing the back-end system and the controllers from the equation, products are able to provide a significantly lower cost-per-door than the legacy systems, which is the true comparison a user should be making.

Many companies make the mistake of comparing one biometric reader’s price to another, without understanding that while the more intelligent readers may be similarly priced, or even more expensive than older technology, the overall cost per door is significantly reduced when you factor in the additional costs of the controllers and the back-end system on the legacy product.

Next generation biometric products offer simplicity over legacy systems, which translates to significant cost savings on purchase, support and maintenance of the system. In addition to this, the simplicity of use from an internal maintenance point of view results in system performance increases.

There is simply no reason anymore to tie an organisation into a single legacy system which has a limited life span, despite what the guys in the designer suits say.

For more information contact iPulse, 0860 IPULSE, [email protected], www.ipulse.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

AI agents become ‘First Class Identities’
Access Control & Identity Management
AI agents are now approving transactions, accessing systems, triggering workflows, and making decisions autonomously. But uncontrolled AI agents are becoming one of the largest security gaps in modern enterprises.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Securing water infrastructure for industry and community
Access Control & Identity Management Fire & Safety Government and Parastatal (Industry)
The Badirammogo Water User Association needed a solution that could secure remote sites, reduce reliance on physical guards, and ensure uninterrupted service delivery while remaining aligned with its values and long-term strategy.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
Paxton launches new phone-based security system: Solo
Paxton News & Events Access Control & Identity Management
Paxton has officially unveiled Solo, a phone-based, cloud-hosted access control system. As part of the launch, installers can claim a free Solo starter kit from Paxton, allowing them to trial the system and see how it can work for their business.

Read more...
Taking control of IAM in the AI era
Access Control & Identity Management AI & Data Analytics
AI and Shadow AI are proliferating, creating a series of new risks for organisations. To gain control over who and what has access to corporate data, organisations need unified control over their entire environment.

Read more...
Impro announces Primo update
News & Events Access Control & Identity Management Integrated Solutions
Impro Technologies recently held a launch event in which it introduced a series of new products, from new readers through to its updated Primo access management software.

Read more...
If you cannot prove identity, you cannot claim security
Access Control & Identity Management Information Security
Cybersecurity planning for 2026 is a structural change in how attacks are executed and how trust is exploited, demanding that companies stop layering tools on top of infrastructure and instead prioritise intelligence and identity.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.