Access control credentials: proximity cards, smart cards, biometrics and mobile
125 kHz proximity cards, 13.56 MHz smart cards, fingerprint, face and mobile credentials compared for access control, with the security trade-offs of each.
Ahuva Electronic Technologies · Published
Key points
- An access control system decides who may pass a door, turnstile or barrier, and records every attempt. The credential that proves who someone is can be a card, a biometric trait or a phone.
- Most 125 kHz proximity cards send a fixed number with no cryptographic check, so the number can be read and copied onto another card.
- 13.56 MHz smart cards such as MIFARE DESFire EV3 support AES cryptography. They resist cloning only when the system actually uses those features and the keys are managed well.
- Researchers at Radboud University showed in 2008 that the older MIFARE Classic card's secret key can be recovered and the card cloned, so it is not a secure choice for new systems.
- Biometrics tie access to the person, but a leaked biometric cannot be reissued like a card. Biometric data is personal data under India's Digital Personal Data Protection Act, 2023.
- The link from reader to controller matters as much as the card. OSDP, published as IEC 60839-11-5:2020, supports an AES-128 secure channel between reader and controller.
What does an access control system consist of?
An access control system has five parts: the credential, the reader, the controller, the locking or barrier hardware, and the management software. The credential is presented to the reader. The reader passes it to the controller. The controller checks it against the rules for that door and time, and releases the lock or barrier. The software holds the users, the rules and the log of every event.
Most systems also connect to others. CCTV can show the door when an alarm is raised. HR and time attendance can take entry and exit records. The fire alarm must release locks on escape routes when it operates, and that release should not depend on the access control software working. The last point is covered in our note on integrating fire detection, PA and BMS.
Card, biometric or mobile: how do the credentials compare?
Each credential answers a different question. A card proves that someone holds the card, not who they are. A biometric proves which enrolled person is present. A phone proves that someone holds an enrolled phone, and often that they could unlock it. Combining two factors, such as card and PIN, or card and fingerprint, closes the gap each one leaves.
The right choice depends on the risk of the space and the flow of people. A main gate with hundreds of people a minute needs a fast credential. A server room or records store with a handful of users can afford two factors.
| Credential | What it proves | Main weakness | If lost or leaked |
|---|---|---|---|
| 125 kHz proximity card | Someone holds the card | Easily copied | Cancel and reissue |
| 13.56 MHz smart card | Holder of a genuine card | Weak if keys are poorly managed | Cancel and reissue |
| Fingerprint | The enrolled person | Spoofing, worn fingers, contact | Cannot be reissued |
| Face | The enrolled person | Spoofing, lighting, error rates vary | Cannot be reissued |
| Mobile credential | Holder of an enrolled phone | Depends on phone and provider | Revoke remotely |
| Card plus PIN or biometric | Card and person together | Slower at busy entries | Cancel card, keep other factor |
Why are 125 kHz proximity cards a risk, and what makes a smart card better?
Most 125 kHz proximity cards simply transmit a fixed number when powered by a reader. There is no cryptographic check, so anyone with a suitable reader can read the number, often without the holder noticing, and write it to a blank card. The principle is set out in NIST Special Publication 800-116 Revision 1: data copied verbatim from a card is enough to clone it for any check that only reads data, while cryptographic keys held inside a secure card cannot be copied that way.
13.56 MHz contactless smart cards, which communicate under ISO/IEC 14443, can hold keys and prove they are genuine through cryptographic authentication. NXP describes its MIFARE DESFire EV3 as supporting DES, 3DES and AES algorithms, with Common Criteria EAL5+ certification for hardware and software. Not every 13.56 MHz card is secure, though. The researchers at Radboud University who published 'Dismantling MIFARE Classic' in 2008 showed that the older MIFARE Classic's secret key can be recovered from one or two authentication attempts with a genuine reader, which lets an attacker clone a card.
A secure card is also only as good as the way it is used. Many installations read only the card's serial number, which any reader can obtain without keys, and so waste the card's security. Others keep default or installer-held keys. A buyer should require that the system uses the card's cryptographic authentication, that keys are unique to the site, and that the owner, not the installer, controls them.
When do biometrics make sense?
Biometrics make sense where it matters who passes, not just which card passed, and where card sharing is a real problem, such as time attendance or high-security rooms. Fingerprint readers are common and low-cost. Face recognition is touchless and fast, but more sensitive to lighting, angle and masks.
Every biometric system trades false accepts against false rejects, and the threshold is set in the software. Error rates are not the same for everyone. NIST's study of 189 face recognition algorithms from 99 developers, published in December 2019 as NISTIR 8280, found that false positive rates varied across demographic groups for many algorithms. Buyers should ask which independent evaluations the algorithm has been through, and test it on their own users. Readers should also detect spoof attempts, such as a photo or a fake fingerprint. The ISO/IEC 30107 series, Biometric presentation attack detection, covers how such detection is specified and tested.
A biometric cannot be cancelled and reissued if it leaks. Systems should store templates, not images, protect them with encryption and access control, and keep them only as long as needed. In India, biometric data is personal data under the Digital Personal Data Protection Act, 2023. The DPDP Rules, 2025 were notified on 14 November 2025, with an eighteen-month period for phased compliance. Our note on the DPDP Act, CCTV and access control data covers what that means for these systems.
How secure are mobile credentials?
A mobile credential is an access right stored in an app or phone wallet and presented to the reader over NFC (near-field communication) or Bluetooth. Its security depends almost entirely on how the provider implements it, so it has to be judged product by product.
Mobile credentials have real advantages. They can be issued and revoked remotely, so a leaver loses access the moment the record changes. There are no cards to print or collect. Where the phone must be unlocked to present the credential, the phone's own PIN or biometric becomes a second factor. The limits are practical ones. Not every user has a suitable phone. A flat battery locks the user out. The system depends on the provider's cloud service and app updates. Most sites run mobile credentials alongside cards, not instead of them.
Where do turnstiles, boom barriers and visitor management fit?
Turnstiles, flap barriers and boom barriers turn an access decision into a physical control. A door lets through whoever follows the cardholder. A turnstile lets through one person per valid credential, which stops tailgating at busy entries.
Anti-passback rules stop one card being passed back to let a second person in. Boom barriers control vehicles, using long-range tags, cards at the window or number plate recognition. Our note on ANPR accuracy covers the last. Visitor management issues temporary credentials, records who is visiting whom, and makes sure visitor access ends on time. Every barrier on an escape route must open when the fire alarm operates.
What should an access control tender specify?
A tender should specify how each credential is checked, not just the card type, because the same card can be used securely or insecurely.
- Credential technology, and that the system uses its cryptographic authentication, not only the card's serial number
- Site-unique keys, held by the owner, with a documented key handover
- Reader-to-controller link: OSDP with secure channel, which the Security Industry Association designed as a more capable alternative to the legacy Wiegand interface
- Controllers that keep working offline if the server or network is down
- For biometrics: template storage and encryption, presentation attack detection, and independent evaluation of the algorithm
- Fire alarm release of escape-route locks and barriers, independent of the software
- Integration with CCTV, HR and time attendance, and the command centre where there is one
- Event log retention, and who may view and export it
- A migration plan from existing 125 kHz cards, such as dual-technology readers during the changeover
How Ahuva approaches access control
Ahuva's access control and time attendance line covers smart card, biometric and mobile credentials; turnstiles, boom barriers and visitor management; and CCTV and HR integration. It holds ISO 27001:2022 certification for information security management.
Frequently asked questions
- Can 125 kHz proximity cards be cloned?
- Most can. They transmit a fixed number without a cryptographic check, so the number can be read with a suitable reader and written to a blank card.
- Is MIFARE DESFire more secure than MIFARE Classic?
- Yes. MIFARE Classic's key can be recovered, as Radboud University researchers showed in 2008. MIFARE DESFire EV3 supports AES and holds Common Criteria EAL5+ certification, provided the system uses those features.
- Is fingerprint or face recognition better for access control?
- Fingerprint readers are common and low-cost but need contact. Face recognition is touchless and fast but more sensitive to lighting and angle, and error rates can vary across groups of users.
- Is biometric attendance data covered by India's data protection law?
- Yes. Biometric data is personal data under the Digital Personal Data Protection Act, 2023. The DPDP Rules, 2025 were notified on 14 November 2025 with an eighteen-month phased compliance period.
- What is OSDP in access control?
- OSDP, the Open Supervised Device Protocol, is an access control standard for communication between readers and controllers, published as IEC 60839-11-5:2020. Its secure channel supports AES-128 encryption.
Sources
- NIST Special Publication 800-116 Revision 1, Guidelines for the Use of PIV Credentials in Facility Access · National Institute of Standards and Technology (NIST)
- Dismantling MIFARE Classic (ESORICS 2008) · Radboud University Nijmegen
- MIFARE DESFire EV3, Secure Contactless IC · NXP Semiconductors
- Open Supervised Device Protocol (OSDP) · Security Industry Association
- NIST Study Evaluates Effects of Race, Age, Sex on Face Recognition Software (NISTIR 8280) · National Institute of Standards and Technology (NIST)
- DPDP Rules, 2025 Notified (17 November 2025) · Press Information Bureau, Ministry of Electronics and Information Technology
Related
Scoping a system like this? Talk to the team that designs, builds and maintains it.
Contact us