Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems
PERCo has released a new line of readers supporting Bluetooth Low Energy (BLE), accompanying mobile applications, and a joint facial identification solution developed with the CRТ group. These additions to the PERCo-Web access control platform offer a timely occasion to review how identification technologies in physical access control systems (СКУД) have evolved over recent years.
Access control systems have always followed the same core principle: a person possesses an identifier, presents it, and the system decides whether to grant entry. Earlier, this identifier was a paper pass checked by a guard who could also perform verification by comparing the visitor’s face with a photograph. Modern systems distribute this work across readers, controllers, and actuators while preserving the same logical sequence.
Proximity and MIFARE Cards as the Enduring Foundation
The first truly mass-market contactless cards operated at 125 kHz (proximity cards). Their simplicity and low cost turned access control from a specialized solution into a mainstream product used in offices, business centers, and educational institutions. The next generation, MIFARE smart cards, introduced protected memory and cryptographic authentication mechanisms originally developed for public transport. Today, cards are divided into two classes: those carrying only a factory identifier and those with cryptographically protected memory. Multi-format readers allow organizations to migrate gradually from legacy cards to protected ones without replacing the entire infrastructure at once.
QR Codes: Convenience for Temporary Access
QR codes gained popularity with the spread of smartphones because the phone’s camera and screen can serve as both reader and transmitter. They excel at issuing temporary passes for visitors, contractors, or parking lots without requiring physical cards or installed applications. Their main limitation is easy duplication, making them unsuitable for scenarios demanding strict identification.
NFC and BLE: Expanding Contactless Capabilities
NFC works well with existing MIFARE infrastructure, allowing NFC-enabled phones and bank cards to function as identifiers. However, platform restrictions on iOS and uneven NFC hardware support on low-cost Android devices have limited its universal adoption. BLE overcomes many of these constraints. It operates over several meters, supports “hands-free” passage, and lets installers adjust detection range via signal threshold settings. BLE also enables wireless configuration, firmware updates, and diagnostics of readers without physical connections.
Biometrics and Regulatory Transformation
Biometric methods—fingerprints, palm vein patterns, and face—offer the advantage that credentials cannot be transferred. Facial recognition, however, now operates under strict Russian regulation. Federal Law 572-FZ requires that facial biometric processing use either the state Unified Biometric System (EBS) or accredited commercial biometric systems (KBS). These platforms perform liveness detection and authentication before returning a standard digital identifier to the access controller. As a result, facial biometrics has shifted from a convenience feature to a regulated “technology of trust” primarily justified by compliance needs, such as construction site access in Moscow or critical infrastructure protection. Alternative identification methods must remain available for individuals who have not consented to biometric processing.
The overarching conclusion is that the oldest and simplest technology—identification by access card—continues to serve as the reliable foundation of most systems, while newer methods occupy specialized roles shaped by security, usability, and regulatory demands.
Related articles
Russia Simplifies State Support Access for National AI Model Developers
Russian authorities have decided to shorten and clarify the path to government support for developers of large AI models. Following the entry into force of the law on artificial intelligence development, obtaining the status of a national or sovereign model will become easier, with decisions verified through a single set of test tasks. The reference test is planned to be published in open access and updated regularly, allowing developers to know in advance the exact criteria the state will use to evaluate their neural networks. Companies such as MWS AI and T-Bank will be able to apply for the new statuses and associated support measures. Expertise will be entrusted to several organizations that have passed state verification, with the main criterion being Russian company control over the entire model lifecycle rather than the origin of every line of code. The use of foreign components under open licenses will be permitted if the developer can independently modify, develop, and maintain the solution. Bureaucratic procedures will be reduced, missing documents can be submitted after the application, and computing infrastructure must be located in Russia but can be rented. The first areas of mandatory application of domestic models will be education and public services, with key provisions of the law taking effect on September 1, 2026, and requirements for sovereign models on March 1, 2027.
EU Extends Chat Control 1.0 Regulation to 2028 Despite Privacy Concerns and Parliamentary Opposition
The EU Council has extended Regulation (EU) 2021/1232, known as Chat Control 1.0, allowing voluntary scanning of unencrypted messages by providers such as Discord and Gmail until 2028. The measure targets detection of child sexual abuse material but has drawn criticism for its impact on encryption and privacy. A proposed Chat Control 2.0 version under COM(2022) 209 would mandate scanning of encrypted communications, which critics argue undermines end-to-end encryption. The extension passed after a July 2026 European Parliament vote failed to reach the required majority due to absent lawmakers. Investigations revealed lobbying ties between Commissioner Ilva Johansson's office and organizations including Thorn and WeProtect Global Alliance. The European Data Protection Supervisor found that targeted advertising supporting the regulation violated EU data rules.
NIST Bans Periodic Password Rotation While Russia's FSTEC Mandates 90-Day Changes for Government Systems
In July 2025, NIST released the final version of SP 800-63B, explicitly prohibiting periodic password changes with the requirement that verifiers and CSPs shall not require subscribers to change passwords periodically. Eight months later, in April 2026, FSTEC approved a methodological document requiring passwords in state information systems and critical information infrastructure to be changed at least every 90 days, with mobile devices limited to 30 days and no reuse of the last 12 passwords. The requirements originate from Order No. 117, which itself contains no mention of passwords, but delegates details to lower-level methodological documents including the April 2026 guide that defines measure IAF.3. Compliance is enforced through the KZI protected indicator calculation submitted to FSTEC twice a year, with penalties including zeroing of the 0.25 weight group for repeated failures and immediate zeroing during penetration testing. The policy applies to government bodies, state unitary enterprises, institutions, and CII subjects, while commercial organizations outside this scope retain flexibility to set their own policies based on threat models. NIST and FSTEC requirements align closely on minimum length, failed attempt limits, MFA for privileged accounts, and prohibition of default passwords, differing primarily on the rotation mandate.
Web Certificate Trust Chains and State Access Risks Explained Amid Russian Banking Sanctions
The article explains the hierarchical structure of web certificates used for site authentication and traffic encryption, starting from highly protected root certificates stored in air-gapped facilities with Shamir's secret sharing for key protection. Intermediate certificates extend the chain of trust down to leaf certificates deployed on websites. Russian banks have turned to certificates issued under the MinTsifry root after Western and Chinese CAs refused service due to sanctions. The piece highlights that any nation-state with access to a root private key, whether FSB, NSA, or others, could theoretically issue fraudulent certificates for any domain. It notes the limitations of the X.509 standard, which lacks native support for multi-CA signatures, and suggests that separate browsing environments or PGP-style web-of-trust models could mitigate risks. The author concludes that security is already reduced by reliance on any state-controlled CA and that the choice is ultimately which intelligence agency one prefers to trust.