Access Control Technologies: Card Systems, Biometrics, and Mobile Credentials

Access control has moved well past mechanical locks and keys, into systems that verify identity through several different methods, log every access event, and tie into broader security and building…

Access control has moved well past mechanical locks and keys, into systems that verify identity through several different methods, log every access event, and tie into broader security and building management infrastructure. The credential technology a business picks determines what employees carry, how readers capture identity, and what actually stops an unauthorized person from getting in. Five technologies dominate commercial deployments today, each with a different balance of security, convenience, and cost, and most facilities end up running more than one at once, matched to the security level each area actually needs.

Access Control Fundamentals

The basic process is the same across every technology: present a credential, authenticate it against a database, grant or deny access. Credentials are what users present: cards, fobs, mobile devices, or biometric characteristics. Readers capture that credential information and pass it to controllers, which make the access decision based on programmed rules and report to a central management system that handles administration, monitoring, and reporting.

Proximity Cards and Fobs

Proximity cards are still the most common access control credential in commercial buildings. These credit-card-sized credentials contain an antenna and integrated circuit storing a unique ID number. Held near a reader, the reader’s RF field powers the card’s circuitry, which transmits the stored number for authentication.

Standard proximity cards operate at 125 kHz and transmit that ID number unencrypted, which keeps the technology simple and reliable but also means the number can be captured and cloned with inexpensive, readily available equipment. Key fobs work identically in a smaller keychain form factor for users who don’t want to carry a card.

Proximity hardware is inexpensive ($2 to $5 per card), familiar to users, and durable, with no battery to maintain. The tradeoff is the security gap described above: an unencrypted, easily cloned number, and no audit trail if a lost card is used before it’s deactivated, since the system authenticates the card rather than the person holding it. Proximity suits moderate-security, cost-sensitive applications: general office access, parking, common areas. Higher-security zones generally need something stronger.

Smart Cards

Smart cards solve the proximity card’s core security gap through encryption. Physically similar to proximity cards, they contain microprocessors capable of cryptographic operations, operating at 13.56 MHz using protocols like MIFARE, DESFire, or iCLASS that perform mutual authentication rather than simply broadcasting a fixed number. The card and reader run a cryptographic handshake that proves possession of a secret key without ever transmitting it, which is what makes the simple cloning attacks that work against proximity cards ineffective here.

High-security smart card implementations add encrypted on-card data storage and diversified keys, where each card carries unique encryption keys derived from a master key rather than sharing one key across an entire population of cards. Smart cards also support multi-application use: physical access, computer login, time and attendance, and payment on a single credential, which simplifies both administration and the user’s day.

Smart cards cost more than proximity, typically $5 to $15 per credential, and readers cost more too, sometimes requiring firmware updates to keep pace with evolving security standards. Migrating an existing proximity deployment to smart cards means replacing every reader in the facility, not just the cards, which is the real cost driver in a migration decision.

Mobile Credentials

Mobile credentials use smartphones in place of physical cards, leveraging a device users already carry everywhere and enabling management capability physical cards simply can’t match. Most mobile credential systems use Bluetooth Low Energy (BLE) or Near Field Communication (NFC) to communicate with readers, through an app that receives credential data from the access control platform. Administrators can provision and revoke credentials remotely and instantly, which matters most in the moment a phone is reported lost: deactivation doesn’t wait on the user finding and returning a physical card.

The convenience case is straightforward, employees rarely forget their phone the way they forget a badge, and the security case adds a layer proximity and smart cards can’t: requiring the phone to be unlocked before the credential will authenticate, time-limited credentials that expire automatically, and optional location-based presence confirmation.

The limitations are practical rather than technical: not every employee has a compatible or charged smartphone, and some resist using a personal device for work access. BLE’s read range can exceed what a facility actually wants (triggering from across a lobby rather than at the door), while NFC requires closer proximity but isn’t available on every phone. Most organizations running mobile credentials keep a card-based fallback during the transition and for employees who can’t or won’t use a phone for access, which adds administrative complexity but keeps the system usable for everyone.

Biometric Access Control

Biometrics authenticate against a physical characteristic instead of something carried. Fingerprint and facial recognition are the two most common modalities in commercial deployments; iris recognition appears in higher-security applications.

Fingerprint readers capture and match fingerprint patterns; modern capacitive sensors have mostly replaced older optical ones, with faster capture and better resistance to spoofing. Accuracy is high with proper enrollment, and the hardware is compact and relatively affordable, but enrollment can be difficult for some users (worn prints, certain skin conditions), touch-based readers raise hygiene concerns some workplaces want to avoid, and wet, dirty, or cold fingers can fail to read reliably.

Facial recognition uses cameras and matching algorithms against an enrolled template; systems using infrared and three-dimensional analysis resist simple photo-based spoofing. It’s touchless, which addresses both the hygiene concern and accessibility for users with hand injuries, and it supports high-throughput entry points. Accuracy depends on lighting, camera positioning, and changes to a person’s face over time (glasses, beards, aging); well-lit, controlled environments perform well, and challenging environments perform worse. Facial recognition also carries real regulatory exposure: some jurisdictions restrict biometric data collection specifically, and deployments need a clear data protection and consent posture before installation, not after.

Iris recognition reads the pattern in the colored ring around the pupil, a pattern that’s stable for life, giving very high accuracy and a low false-acceptance rate. It works through glasses and many eye conditions and can read from several feet away with some systems, but costs more than fingerprint hardware and some users find it intrusive, which generally limits adoption to high-security applications where the added cost is clearly justified.

Biometrics work best paired with another factor rather than alone: “something you have” (a card or phone) plus “something you are” (a biometric) is meaningfully stronger than either alone, and provides a fallback in both directions, the card covers a failed biometric read, and the biometric covers a stolen card.

Cost and Selection Comparison

Technology Security Level Convenience Typical Cost Best Applications
Proximity card Low to medium High $2 to $5 per card General access, parking
Smart card Medium to high High $5 to $15 per credential Office access, multi-application
Mobile credential Medium to high Very high $3 to $10/year Modern offices, remote management
Fingerprint High Medium $50 to $150 (reader) Secure areas, time and attendance
Facial recognition High High $500 to $2,000 (reader) High-security, touchless, high-throughput

Selection should weigh actual security requirements against user population, environmental conditions, integration needs with existing systems, and total cost including ongoing credential management, not just the up-front hardware price.

Implementation Details Worth Planning For

Every credential technology needs a defined process for enrollment, ongoing management, and eventual retirement: how new employees get credentialed, how a lost or damaged credential gets replaced, and how access gets pulled the moment someone departs. Biometric enrollment specifically needs a quality capture process; a poor initial enrollment creates ongoing authentication frustration and, worse, a security gap that’s easy to miss until it causes a problem.

Reader placement follows from the technology: proximity and smart cards need users within inches of the reader, mobile credentials using BLE can work from further away, and biometric readers have specific positioning requirements for a reliable capture. Traffic flow, accessibility, and weather exposure all factor into placement, exterior readers need weather-rated housings, and high-traffic entries may need multiple readers or a faster-authenticating technology to avoid a line forming at the door.

Access control rarely runs standalone. Integration with video surveillance, intrusion detection, elevator control, and visitor management is common, and integration with HR systems specifically enables automatic provisioning and deprovisioning tied to employment status, which closes one of the more common real-world security gaps: an access credential that should have been deactivated on someone’s last day and wasn’t.

Georgia Licensing and Local Considerations

Access control installation in Georgia requires the appropriate low voltage contractor license. The LV-A (Alarm) classification specifically covers access control work, and LV-U (Unrestricted) authorizes it as well, alongside the broader scope that license covers. Verifying a contractor’s license before signing is a concrete, checkable step worth taking directly rather than assuming.

Middle Georgia’s climate is also a practical factor for biometric hardware specifically: high humidity can affect fingerprint reader performance, and any exterior reader needs an environmental rating appropriate to the region’s heat and humidity rather than a baseline indoor-rated unit.

Key Takeaways

No single credential technology is the right answer everywhere; most commercial facilities run two or three matched to different security zones. Proximity cards remain common for general, lower-security access despite their cloning vulnerability. Smart cards close that gap through encryption at a modest cost premium. Mobile credentials trade physical cards for phones already in every employee’s pocket, with faster revocation when something goes wrong. Biometrics, paired with a second factor, fit the areas where the stakes justify the added cost and complexity.

Plan the full credential lifecycle, not just the initial purchase: enrollment quality, reader placement, and integration with HR and other building systems determine whether a well-chosen technology actually performs as intended day to day. And for Georgia installations, verify contractor licensing and account for the regional climate’s effect on biometric hardware before finalizing a system design.