Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems
PERCo has released a new line of readers supporting Bluetooth Low Energy (BLE), accompanying mobile applications, and a joint facial identification solution developed with the CRТ group. These additions to the PERCo-Web access control platform offer a timely occasion to review how identification technologies in physical access control systems (СКУД) have evolved over recent years.
Access control systems have always followed the same core principle: a person possesses an identifier, presents it, and the system decides whether to grant entry. Earlier, this identifier was a paper pass checked by a guard who could also perform verification by comparing the visitor’s face with a photograph. Modern systems distribute this work across readers, controllers, and actuators while preserving the same logical sequence.
Proximity and MIFARE Cards as the Enduring Foundation
The first truly mass-market contactless cards operated at 125 kHz (proximity cards). Their simplicity and low cost turned access control from a specialized solution into a mainstream product used in offices, business centers, and educational institutions. The next generation, MIFARE smart cards, introduced protected memory and cryptographic authentication mechanisms originally developed for public transport. Today, cards are divided into two classes: those carrying only a factory identifier and those with cryptographically protected memory. Multi-format readers allow organizations to migrate gradually from legacy cards to protected ones without replacing the entire infrastructure at once.
QR Codes: Convenience for Temporary Access
QR codes gained popularity with the spread of smartphones because the phone’s camera and screen can serve as both reader and transmitter. They excel at issuing temporary passes for visitors, contractors, or parking lots without requiring physical cards or installed applications. Their main limitation is easy duplication, making them unsuitable for scenarios demanding strict identification.
NFC and BLE: Expanding Contactless Capabilities
NFC works well with existing MIFARE infrastructure, allowing NFC-enabled phones and bank cards to function as identifiers. However, platform restrictions on iOS and uneven NFC hardware support on low-cost Android devices have limited its universal adoption. BLE overcomes many of these constraints. It operates over several meters, supports “hands-free” passage, and lets installers adjust detection range via signal threshold settings. BLE also enables wireless configuration, firmware updates, and diagnostics of readers without physical connections.
Biometrics and Regulatory Transformation
Biometric methods—fingerprints, palm vein patterns, and face—offer the advantage that credentials cannot be transferred. Facial recognition, however, now operates under strict Russian regulation. Federal Law 572-FZ requires that facial biometric processing use either the state Unified Biometric System (EBS) or accredited commercial biometric systems (KBS). These platforms perform liveness detection and authentication before returning a standard digital identifier to the access controller. As a result, facial biometrics has shifted from a convenience feature to a regulated “technology of trust” primarily justified by compliance needs, such as construction site access in Moscow or critical infrastructure protection. Alternative identification methods must remain available for individuals who have not consented to biometric processing.
The overarching conclusion is that the oldest and simplest technology—identification by access card—continues to serve as the reliable foundation of most systems, while newer methods occupy specialized roles shaped by security, usability, and regulatory demands.
Related articles
Alfa-Bank Balances Cloud Trust and Zero Trust Models During Migration to Yandex Cloud
Alfa-Bank's head of container and cloud security, Sasha Chertok, detailed how the bank migrated regulated workloads to Yandex Cloud while preserving existing Zero Trust controls. The organization mapped on-premises network segmentation, Active Directory authentication, and firewall policies directly onto Yandex Cloud resources using interconnect links secured with GOST encryption. Responsibility for managed services is shared under a Cloud Trust model, yet the bank retains oversight through Terraform-managed Security Groups, custom CSPM checks, and internal CI/CD gates. User access continues to authenticate via on-premises Active Directory and KeyCloak federations, while authorization leverages granular Yandex Cloud IAM roles. Logging and detection rely on a combination of Yandex Cloud Audit Trail, Cloud Logging, and the YCDR service to compensate for incomplete control-plane visibility. The resulting hybrid architecture now supports 1,500 virtual machines, 100 managed services, and 1,000 identities across multiple environments without disrupting established security processes.
EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure
The EnvSpec Naming 1.0.0 standard proposes replacing ad-hoc hostnames with a strict hierarchical naming system based on environment, perimeter, system, slot and node. It defines exactly six environments—dev, test, stage, prod, infrastructure and workplace—and treats any test or pilot system processing real data as prod. The model projects names into SPIFFE IDs, Kubernetes namespaces, cloud projects and mandatory tags for automated policy enforcement. Rules prohibit direct communication between different linear environments and require all access from workplace devices through dedicated gateways. The standard is published under CC BY-SA 4.0 and includes machine-checkable criteria for compliance.
Russian Woman Fined 30,000 Rubles and Loses iPhone 11 for Posting AI-Generated Bear Photo
A resident of Duldurga village in Zabaykalsky Krai was fined 30,000 rubles under part 9 of article 13.15 of the Russian Code of Administrative Offenses for publishing an AI-generated image of a bear presented as authentic. The court also ordered confiscation of her iPhone 11 as the instrument of the administrative violation. The woman knew the photograph was fake before posting it, yet the image spread widely online and was even shared by a local Ministry of Natural Resources channel on 10 September. Local authorities used the case to warn residents that publishing neural-network-generated fake images carries real legal consequences. The incident highlights ongoing enforcement of Russian legislation against the distribution of knowingly false socially significant information under the guise of credible reports. Meanwhile, wildlife specialists continue to investigate separate reports of actual bears near populated areas in the region.
Inserting Contracts into ChatGPT Risks Major Fines Under Russia's 152-FZ Personal Data Law
A detailed analysis examines the legal consequences of uploading contracts containing personal data into foreign AI services such as ChatGPT under Russian Federal Law 152-FZ. The article clarifies that even standard supply agreements include names, positions, passport details, INN numbers, phones and emails that qualify as personal data. It breaks down applicable administrative penalties from Article 13.11 of the Code of Administrative Offenses, including 150-300 thousand rubles for processing without a proper legal basis and separate fines for failing to notify Roskomnadzor. Cross-border transfer rules under Article 12 require a dedicated notification to the regulator before sending data to services hosted in the United States or European Union. The piece also reviews recent court practice, including a Moscow district court ruling that treated uploading commercial information to DeepSeek as disclosure of trade secrets. No criminal liability under Article 272.1 of the Criminal Code applies to ordinary business use, yet the absence of a data processing agreement with OpenAI or similar providers creates ongoing compliance exposure.