Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems
PERCo has released a new line of readers supporting Bluetooth Low Energy (BLE), accompanying mobile applications, and a joint facial identification solution developed with the CRТ group. These additions to the PERCo-Web access control platform offer a timely occasion to review how identification technologies in physical access control systems (СКУД) have evolved over recent years.
Access control systems have always followed the same core principle: a person possesses an identifier, presents it, and the system decides whether to grant entry. Earlier, this identifier was a paper pass checked by a guard who could also perform verification by comparing the visitor’s face with a photograph. Modern systems distribute this work across readers, controllers, and actuators while preserving the same logical sequence.
Proximity and MIFARE Cards as the Enduring Foundation
The first truly mass-market contactless cards operated at 125 kHz (proximity cards). Their simplicity and low cost turned access control from a specialized solution into a mainstream product used in offices, business centers, and educational institutions. The next generation, MIFARE smart cards, introduced protected memory and cryptographic authentication mechanisms originally developed for public transport. Today, cards are divided into two classes: those carrying only a factory identifier and those with cryptographically protected memory. Multi-format readers allow organizations to migrate gradually from legacy cards to protected ones without replacing the entire infrastructure at once.
QR Codes: Convenience for Temporary Access
QR codes gained popularity with the spread of smartphones because the phone’s camera and screen can serve as both reader and transmitter. They excel at issuing temporary passes for visitors, contractors, or parking lots without requiring physical cards or installed applications. Their main limitation is easy duplication, making them unsuitable for scenarios demanding strict identification.
NFC and BLE: Expanding Contactless Capabilities
NFC works well with existing MIFARE infrastructure, allowing NFC-enabled phones and bank cards to function as identifiers. However, platform restrictions on iOS and uneven NFC hardware support on low-cost Android devices have limited its universal adoption. BLE overcomes many of these constraints. It operates over several meters, supports “hands-free” passage, and lets installers adjust detection range via signal threshold settings. BLE also enables wireless configuration, firmware updates, and diagnostics of readers without physical connections.
Biometrics and Regulatory Transformation
Biometric methods—fingerprints, palm vein patterns, and face—offer the advantage that credentials cannot be transferred. Facial recognition, however, now operates under strict Russian regulation. Federal Law 572-FZ requires that facial biometric processing use either the state Unified Biometric System (EBS) or accredited commercial biometric systems (KBS). These platforms perform liveness detection and authentication before returning a standard digital identifier to the access controller. As a result, facial biometrics has shifted from a convenience feature to a regulated “technology of trust” primarily justified by compliance needs, such as construction site access in Moscow or critical infrastructure protection. Alternative identification methods must remain available for individuals who have not consented to biometric processing.
The overarching conclusion is that the oldest and simplest technology—identification by access card—continues to serve as the reliable foundation of most systems, while newer methods occupy specialized roles shaped by security, usability, and regulatory demands.
Related articles
Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants
The Bank of Russia has released methodological recommendations No. 3-MR dated 16 June 2026, providing detailed guidance on ensuring information security during the development and use of artificial intelligence systems in the financial sector. The document builds on the earlier Code of Ethics for AI in finance and integrates with existing risk management, operational resilience, and data protection frameworks already familiar to credit institutions and other market participants. It introduces standardized terminology for AI-specific threats such as hallucinations, data drift, and poisoned datasets while outlining six risk categories and a four-stage AI system lifecycle model. Organizations are advised to apply threat modeling based on FSTEC methodology, implement proportional controls across data preparation, development, training, and operation phases, and maintain human oversight for high-risk automated processes. Special attention is given to supply chain risks involving third-party vendors and open-source components, requiring due diligence, provenance tracking, and contractual safeguards aligned with existing outsourcing standards. The recommendations remain non-binding yet signal clear regulatory expectations that are likely to influence future compliance checks and audits.
Aladdin Obtains New FSB Certificate for CryptoFlash Encrypted USB Drive Valid Until 2029
Aladdin has received a new FSB Russia certificate for its Aladdin CryptoFlash hardware-encrypted USB drive. The certificate number СФ/124-5574 confirms compliance with cryptographic protection requirements for classes KS1 and KS2 and remains valid until 16 July 2029. The device now supports additional Russian Linux distributions including RED OS 7.3 and 8, Alt 8 SP Workstation, Alt Workstation 10, and the OS of the Moscow Electronic School. Read and write speeds have been increased to 11 MB/s while the graphical interface received improvements. The product uses the Magma encryption algorithm in hardware and operates as a clientless solution that requires no additional drivers or software. The previous certificate remains active until December 2028, allowing both versions of the device to be used in parallel for storing and transferring official and confidential information marked DSP.
Microsoft Tightens Corporate Windows Activation with TPM-Bound KMS Servers
Microsoft is strengthening its corporate Windows licensing controls by introducing new requirements for KMS servers used in volume activation. The changes will bind KMS hosts to TPM hardware attestation, preventing cloned or fake servers from issuing licenses to unlicensed devices. Warnings will begin appearing in Windows Server 2025 in August 2026, with mandatory enforcement planned for the next LTSC release. Existing KMS systems will continue operating normally until the new rules take effect. The update targets enterprise environments with on-premises KMS infrastructure and does not affect individual consumer devices or common non-KMS activation bypass methods. Administrators can already verify TPM support on physical servers using the Get-TpmSupportedFeature command.
Russia's Article 10.1 on Personal Data Dissemination: Apparent and Real Contradictions in Federal Law 152-FZ
Part II of the analysis examines how the rushed redrafting of Article 10.1 between the first and second readings created serious interpretive problems in Federal Law 152-FZ. The core issues include undefined terms such as 'disclosure', conflicting definitions of 'access', 'provision' and 'dissemination' between 152-FZ and 149-FZ, and the removal of the legal basis for processing publicly available data while retaining the consent mechanism that was meant to control it. Courts have consistently held that mere openness of data does not constitute a valid processing ground, forcing subsequent operators to find their own basis under Article 6. The article highlights that the mechanism for subjects to set conditions and prohibitions was preserved, yet the underlying legal foundation that would make those rules effective was eliminated. Two possible readings of the special consent are explored, with judicial practice leaning toward the narrower interpretation that leaves conditions and prohibitions as mere additional restrictions rather than a source of authorization.