9.1 Electronic Access Control Architecture & Credentials

Key Takeaways

  • An online door is a four-device circuit: controller, reader, door position switch, and request-to-exit, plus the lock the controller drives.
  • Unencrypted 26-bit Wiegand proximity identifiers are readily cloned; a green reader LED is not cryptographic proof of a genuine token.
  • OSDP Secure Channel provides bidirectional, supervised, encrypted reader traffic; Wiegand is one-way and historically unencrypted.
  • Fail-safe locks release on power loss and fail-secure locks remain locked; egress doors still answer to the AHJ and life-safety codes.
  • Same-day HR termination must disable every credential on every panel, including parking gates and elevator readers that sit on a forgotten controller.
Last updated: September 2026

Why Electronic Access Control Shows Up in Domain 2

ASIS Physical Security Professional (PSP) Domain 2 spends its weight on applying, designing, and integrating physical security systems. Electronic access control systems (EACS) sit at the junction of doors, identity, databases, power, and life safety. A reader that flashes green is not a complete system. The exam expects you to know which device makes the grant decision, how that grant is logged, what happens when power or the network fails, and how a termination in Human Resources becomes a denied badge at every portal before a former employee reaches the parking garage.

Treat an EACS as a distributed decision engine, not as a box of cards. Security value lives in the policy database, the audit trail, and the integrity of the credential. Plastic, apps, and PIN pads are only tokens. If the token is cloneable, the database is stale, or the lock wiring ignores the fire alarm, the rest of the architecture is theater.

Knowledge of access control systems (ACS) in this chapter is operational: you should be able to walk a door, name each device, and predict the event log. Listing families such as UL 294 (access control system units) and IEC/EN 60839-11 (electronic access control systems) tell you how equipment is evaluated. They do not replace a door-by-door design narrative.

The Four-Device Door Architecture

A typical online door is a four-part sensing and control circuit: controller, reader, door position switch (DPS), and request-to-exit (REX) device, plus the electrified lock the controller drives.

The controller (intelligent field panel, door module, or networked lock brain) stores or caches authorization rules, energizes or drops the lock output, timestamps events, and reports to a host or server. In a true online architecture the host is the system of record, but many "online" doors still cache a recent allow-list so a brief network outage does not freeze a lobby. Cache windows are a design parameter, not a vendor slogan. If a badge is revoked at 09:12 and a cached door still opens at 09:18, that door was not live to the database you thought you had.

The reader is a sensor. It interrogates a card, phone, or PIN pad and forwards either a raw identifier or a cryptographically wrapped message. On older Wiegand readers the payload is often a facility code plus card number. On modern Open Supervised Device Protocol (OSDP) readers the conversation can be encrypted and bidirectional. The reader does not "know" company policy. It reports what it saw.

The DPS (magnetic contact, integrated lock monitor, or similar) answers a different question: is the leaf open or closed? Combined with the lock output, firmware can distinguish a valid unlock, a door-held-open after a grant, and a forced-open when the door leaves the frame without a valid unlock or REX. Operators routinely confuse "the door alarmed" with "someone presented a card." Forced-open without a grant is intrusion. Held-open after a grant is often a wedge, a conversation in the doorway, or a closer that lost its speed.

The REX tells the controller that someone is leaving. Motion sensors, crash-bar monitor switches, or dedicated push-to-exit buttons generate the REX. A well-designed REX shunts the DPS for a programmed interval so an authorized exit does not look like a forced door. A poorly aimed motion REX that sees hallway traffic creates nuisance shunts that hide real forced-open events. Push-to-exit buttons must be reachable under accessibility rules; a motion-only REX that misses a wheelchair user is both a nuisance-alarm problem and a civil-rights problem.

The electrified lock is the effector. Section 9.2 covers strikes, maglocks, mortise locks, and delayed egress. For architecture, match the controller output to the lock: wet versus dry contacts, voltage, inrush, and whether the lock is fail-safe or fail-secure. A panel relay rated for a dry contact will weld or chatter on a maglock coil if you omit the proper power supply and suppression.

In Practice: One Warehouse Man-Door

Walk a single man-door. An employee presents a card. The reader sends an identifier. The controller checks card status, door schedule, anti-passback state, and group permissions. If authorized, it releases the lock for a few seconds, starts a held-open timer, and logs access granted. If the door never opens, you still have a grant with no DPS change—useful when a tailgating complaint is really a reader that granted while the employee walked away. If the door opens with no grant and no REX, you have a forced-open, a shunt failure, or a contact that was taped.

DeviceJob in the circuitCommon exam trap
Controller / panelAuthorization, lock output, event logTreating the reader LED as the decision
ReaderCollect credential or PINAssuming the reader stores the company roster
Door position switchOpen/closed statusCalling every DPS event a "break-in"
Request-to-exitLegitimate egress shuntMotion REX that shunts the alarm for hallway traffic
Electrified lockMechanical/magnetic barrierWiring fail-safe hardware onto a door that must stay locked on power loss

Online Versus Offline Control

Online (host-based or networked) doors query a current database. Card revocation, time-zone edits, and holiday schedules propagate in seconds or minutes. Event logs return promptly. This is the default for high-value portals, control rooms, and any site that terminates people the same day.

Offline devices—standalone locksets, many battery locks, and some wireless locks in delayed-sync modes—store a local allow-list or carry a cryptographic schedule on the credential itself. They survive network loss and cost less to install on interior rooms, but revocation lags until the next audit, fob update, or lock wakeup. A scenario that says the badge was deactivated at 09:12 but the storeroom opened at 09:18 is asking whether that door was truly online.

Hybrid wireless locks often "phone home" on a schedule or when a credential is presented. Document the maximum revocation window: the longest time a terminated badge can still open a door. That window belongs in the design narrative and in the operations playbook, not only in a salesperson's range claim.

Wiegand Versus OSDP

Wiegand wiring is a one-way pulse interface that outlived the original Wiegand-effect cards. It remains common. The classic 26-bit format (8-bit facility code plus 16-bit card number, with parity bits) is a field failure magnet: the bit stream can be captured with inexpensive skimmers, and many panels still accept raw facility-code and card-number pairs with no cryptographic proof the token is genuine.

OSDP, published through the Security Industry Association, is a bidirectional, supervised bus. In Secure Channel mode the panel and reader share keys, so a tap on the cable does not yield a reusable card number. OSDP also carries reader tamper, LED and buzzer control, and richer keypad messaging. When a stem mentions supervised reader lines and encrypted reader traffic, think OSDP, not Wiegand.

Migration is physical work. You can keep a Wiegand reader on a new panel with a converter, but you inherit the clone risk. UL 294 listing of a control unit does not encrypt a Wiegand home run. Specify the interface, key management, and whether the panel consumes a secure application identifier or a raw card serial number.

Credential Technologies and PIN-plus-Card

125 kHz proximity cards remain common because they are cheap and work with gloves. They typically identify; they do not strongly authenticate. The 26-bit prox clone trap is the version you should be able to explain in one sentence: an attacker copies the clear identifier onto a blank and walks through any reader that still trusts that format. Larger bit lengths (35-bit, 37-bit, Corporate 1000 and similar) reduce accidental collisions but do not add cryptography if the air interface still speaks clear proximity.

13.56 MHz contactless smart cards in the ISO/IEC 14443 family, including modern DESFire-class tokens, can store keys, perform mutual authentication, and bind the card to diversified keys. They are not automatically safe. Legacy MIFARE Classic deployments have well-known weaknesses. A silent downgrade is reading the card serial number (CSN) as the credential while the marketing sheet talks about encryption. If the panel only checks the CSN, you bought an expensive prox card.

Mobile credentials use Bluetooth Low Energy or NFC in a phone wallet or vendor app. Revocation can be immediate at the identity provider, which is excellent after termination, but you inherit BYOD policy, operating-system updates, dead batteries, and questions about location telemetry. Treat mobile as another token type in the same cardholder database, not as a second security program with a second roster.

PIN plus card (or PIN plus biometric) is two-factor at the door: something you have plus something you know. Use it on high-risk rooms. High-throughput turnstiles may not tolerate the extra seconds. PINs are shared, shoulder-surfed, and taped to monitors. Rotate or disable PINs on termination even if the card is already off; a leftover PIN plus a borrowed card is a classic bypass.

CredentialTypical interfaceWhat it actually provesPrimary weakness
125 kHz 26-bit proxWiegandPossession of a cloneable numberField cloning, facility-code reuse
Larger-format proxWiegandA longer number, still often clearStill no mutual authentication
ISO/IEC 14443 smart cardEncrypted application, often OSDPKeys, if the panel uses themCSN-as-credential downgrade
Mobile BLE/NFCEncrypted app or walletPossession of an enrolled deviceBattery, BYOD, account recovery
PIN + cardKeypad plus tokenTwo factors at that readerShared PINs, shoulder surfing

Door Schedules, Databases, and HR Termination

The authorization database is the system of record: people, credentials (often many per person), groups, access levels, time schedules, holidays, and door assignments. Design with roles and groups (warehouse day shift, escorted contractors) rather than one-off door lists per person. Ghost cards—credentials with no living owner—are an audit finding waiting to happen.

Door schedules define when a portal unlocks for public hours, when it requires a credential, and when it is locked to everyone except emergency override. Unlock-on-schedule for a lobby is convenient and is also an open door if the holiday calendar is wrong. Pair unlock schedules with DPS monitoring so an unexpected open still alarms.

HR termination integration is a control, not a courtesy. The reliable pattern is: the HRIS or identity platform marks the person inactive; access software disables every credential and mobile token; controllers download the change; a report confirms doors that have not yet acknowledged. Same-day involuntary termination should include physical badge collection and electronic disable, because collection fails when the badge is "left in the car." Overlooked parking-gate panels and elevator readers are the usual holes.

Fail Modes, Power, and Life Safety

Fail-safe locks release on loss of power (typical magnetic locks). Fail-secure locks remain locked (typical storeroom strikes and many electrified mortise locks). Egress doors, stairwells, and maglock portals must satisfy the authority having jurisdiction (AHJ) and means-of-egress concepts in model codes such as the IBC/IFC family and NFPA 101: free egress, fire-alarm release, and accessible hardware. An access controller that ignores the fire panel is a life-safety defect.

Power design includes lock current, inrush, battery standby, and power-supply supervision. A controller that reboots into "all doors locked" during a fire-alarm test will fail commissioning. Section 9.2 returns to maglocks, delayed egress, and interlocks; this section's job is to keep fail mode, schedule, and database in the same mental model as the four-device door.

Name the standards families when you read a spec: UL 294 for access control units in North American listing practice, IEC 60839-11 / EN 60839-11 for electronic access control system requirements in many international specifications, and ISO/IEC 14443 for contactless IC cards. Use the names to interrogate a cut sheet. Do not memorize listing tables.

Loading diagram...
Online EACS door circuit and identity feed
Illustrative field-cloning difficulty (practitioner scale, not a lab rating)
Test Your Knowledge

A security director finds that cloned 125 kHz fobs still open the warehouse door after the original cards were collected. Which design choice most directly enabled that bypass?

A
B
C
D
Test Your Knowledge

Which statement best describes fail-safe versus fail-secure locking in electronic access control?

A
B
C
D
Test Your Knowledge

In a typical online door, which device makes the grant or deny decision and drives the lock output?

A
B
C
D