Forced Entry / Duress Tutorial
Access control normally keeps people safe, but recent tragedies have revealed a significant issue: If users are forced to unlock doors for criminals, unsuspecting people inside, believing falsely that they are protected by the access control system, are vulnerable.
'Duress Access' is a common, although overlooked, access system feature designed to combat the threat.
In this report, we examine the duress options for common types of access readers and address how opening design, closed access areas, and physical layering adds strength to perimeter access control:
- Biometrics
- Keypads
- Card Readers
Criminals ***** ***** ** ****** *****
** *** **** ** ******* ******* to **** * ****, ** ******** refusal *** ****** ** ********* ***********, while ******* ** ******* *** ******** can ** *********.
** *******, **** ** ********* ** able ** ***** * ********, *** primary ******** ******** ******* ****** **** has **** ********.
****** ***** *** **** ** ***** path *** ********* *** ********** ** several *********. *** **** **** ******** inside****** ******* '******* *****', ***** ****** ******** ****** ** employee ******* *** ******* ***** *** ******* ****** ******** ** ***** ** **** access ** *** ** *** **** prominent ********.
**** ******, ****** ******** ** ******. Armed ********** **** ******* ** ***** at *** ********* **** ** ************ *** ******* ****.
*** ******* **** ******** **** ******* acts, ********* ***** ** **********, ***** armed ******* **** *** ************ ***** as **** *** ** ***** ** present *****, **** ** ***** ***** way **** * ******** *************** ****** ******.
Vulnerability **** ** ****-******** ***********
****** ******* **** ***** **** *********** are ********* *** ****** ** ** misused. ****** **** *** ***** *** openings *** ********* ** *** ******, and ****** ****** ****** ** ***** entry *** ** ********* **********.
*** *******, ******** ******** ** ******* Hebdo *** *** * ****** ******, and *** *********** ****** ** ******** protections ***** * **** ******** ******.
** **** ** *** ************, *** facility ***** * ******** ****** ******* system *** * ********** ******** **** connected ** * ******. ****** **** shooting ***** *** **** *** ********, the ****** ******* ** ******** ** an ****** *** ****** *** ** open *** **** ******** ** ********. From *****, **** *** ******** ****** to *** ******.
** **********, *** ******** ** '**** could ** **** ***********?' ** ***** by ****, ********** ** ***** ******* on * ******* ****** ****** ** keep ******* *** **** ****.
Duress *****: ******** ** ******, ***** ******** *** ********* ******
****** ** ***** ***** *** ********* in **** ********* *******,**** ** *** *******, *** *** **** ******** ***** in ****** *******.
** ****, ******* ** ********* ****** is **** ****** ** ** ********* by ****** ********* **** ****** ** dispatch ******, ****** *** ********* ******* can ** ********* **** ********.
*******, **** ********* *** ****** ******* by **** *********, ******** ** ****** events *** ** **** ****** ** local ********** ** ***** ****** **** being ****** *** ** ******** ******* calling ******* *** ***********.
***** ****** ****** *** ********* ********* via **** ******* *** *** *********, in ****** **** **** *** ** activated *** ******* *****, ******** ************, or ********* ********** ******** ******** (*.*., three ***** **** ******).
Access ****** ****** *******
** *******, *** **** ****** ********** needs ** ** ********** ** ******** handle *** ***** **** * '******' signal ** **** **** * ******. In ********, *** ******** *** ************* that ***** * ********** *** ****** notifications ** ****** **** *******:
**********
*** **** ********** *******, ** ** uncommon ** ********* ********** '********* ****' fingerprint ** **** (**: *** ****-**** thumb ****** **** *** *****-**** *****), the **** ****** ******, *** ****** are ****** ** ********* ********/*********** ** the ****** ******* **** ************ ** even ** ****** **********.
** ******* '******' *********** ********** ** shown *********'* ******* ********, *** *** ******* *** ******** are ******* ** **** ********* ****** management ********:
** * ********, *** *** ** entry *** ****** ** ********* **** what ** ******** ********, *** ****** the ******, ******** *** ** ************ acting ** ******* ********* ** **** raised ** * **** ***** ** emergency *** ****.
Keypads
****** *** ******* *** *** ** the ******** ** ********* *** ******. If * **** ****** * ******* code, **** ** ** ********'* *** in ******* *****, ** * ***-***** 'emergency ****', *** ****** ******* *** door, *** ***** ****** *** ******** alarm *********.
*****, ** * ********, *** *** may ****** ** ********* **** ******, and ***** ***** ****** *** **** give *** ** ***** *** ******** code *** ********* ** ***** **********.
Card *******
*************, *** ** *** **** ****** authentication ******* **** *** *** ******* 'duress' ******** **************. **** ******* ***** users ******** *****, *** ***** ** 'emergency' **** **** ******* *** **** as * ****** ********** ***** *** that ******** ********* ****** ** ****.
*******, **** *******, *********** '******* *'********* ** *******, ***** ** * user ***** ***** ***** ***** ***** in ***** ********** * '****** *****' is ********* *** *** ****** ***********.
*******, ****-***** ******* *** ***** ** false ******** ** ***** ***** ** terms ** ******** *** *********, *** duress *** **** ******* ******* ***** to ********* **** *** **** ************* as ***** *******.
Building ****** ******* ****** *****
*******, *********** *** ******* ** ***** areas **** ******** ******** ** ******** the ********* ****** ** ****** ***** is ********.
* *** ** ****** ****, ** forced ***** ******, ** ** **** more **** *** ********** **** *** opening ** ********* ******. ****** ******* like*********************, *********** *** ******* ******** ******** (e.g., ***** *****, ********, ****** *****) with ********** ******* ****** *** **** access ** *********** ***** *** ******** emergency ********** **** ** ********* *******.
Avoiding ***** ***** ** ********
********** ** *** ****** ** ****** used, ******** ******** *** ********* ****** absolutely ***** ********* *** **** ********** of *** ******* **** ******.
****** **** '***** *** *******' *** not ************ * ******* ***, *** lesson ** *** ** ******** *** true ********** ***** ******* ** ****-**** security *******.
**** * ****** ****** ****** *** not ****** ** ******** *** ***** for ******* ***** *** **** ** duress *********, *** ********* *** **** been **** **** *****.
*** ***** ****** *** ******** ******** and **** ********** ******** ** ** evaluate ********** ************ **** ******* *** emerging *****.
****** *** ******* *** *** ** the ******** ** ********* *** ******. If * **** ****** * ******* code, **** ** ** ********'* *** in ******* *****… *****, ** * criminal, *** *** *** ****** ** different **** ******, *** ***** ***** duress *** **** **** *** ** share *** ******** **** *** ********* to ***** **********.
** ***** **** **** **** *** prudent *** *** *** ******** ** proceed ***** ** ** *** ***** direct *** ***** ** *** ********, but ****** *** ******** ****** ****** to ** **** *** *** *** then **** ***** ***** ** ** reverse *****. **** ** **** ***** would **** *** ** ** *** original *****.
*******, **’* ******** **** * ***** witted ******** ***** ******* * ********** and ******** *** ********* *** ***, leading ** *** ********* **** ********** scenario:
**** *** **** ******** ** ********* response ** ********* *** **** **** in *** ***** *** ******* ** an ******** ** *** *** **** in *** ***** *** *******. * would **** ** *** **** ******** on ******** ***** ** *** ********* area *** *** **** **** ****** to ****** *** ********** **** ** assist ** *** ***** * ****** to ** ****** **** ******.
*** ******* ** * ****** ***** caused ***** ******* ** *** ****** to **** ***** *****, ******* **** those ******* ***** **** * *** seconds ** ***** ** ** *** hide *****. **** *** ******* **** the ******** ** ******* **** **** if **** *** *** ******** ********* by ********. **** *** ** ********* similar ** **** ***** ********.
**** *****'* ******* *** ********* ** activating *** ****** (********** ** ** is * **** **********) ******* ** has *** ********* ** ****** **** due ** **** ***** ** ********* services.
***
****** ****** ****** ** *** **** we **** ** ********* "*** **** an ***** *****" ** "*** *** increment *** **** *****".
** **** (******** ***) *** ** 12349 (******) ** **** (******) ** theory. ** ******** *******, ***** *** many ***** ****** ** ****** ***** fingers *** *** *** *** *** keypad *** *** ******* **** ****** after * *** ***** ****** ** an ***** ******** ** * ******** end-user *** *** **** ******** *** system *** ****'* **** **** ****'* accidentally ****. ******* * ***'* **** recall *** **** **** * ****** duress *** ********* *******.
* **** **.
*** ** *** ******** **** *** of ***** ******* ** **** **** designed ** ********* *** **** ** understanding ** **** ***** ******** *** how ****** ******* ***** *** **** of ****** *** ***** ********* **** looking ** *** ********* *** ** a *******.
*** *********** ** **** * ****** under************* **** ***** ***** ** ****** would **** *** **** *** ****** acuity *** *** ******** ********* ** enter * *** **** ** ***** used *** **** *********** **** *** one **** *** *****.
*** ******* ** **** **** ***** would ******** ** **** ******** ***** normal *** *** ***** ********* ***** it. ***** ** * ****** **** tactical ******** *** ****** ******* **** training **** ******** ****** *** **** on ******* *********. ******* **** ***'** wearing * *** **** ** ***** underpants *** **** ** **** ****** simple.
** ***** **** ****** ************* **** had * ******* ****** ***** **** type ** ****** ****** ***** ******* and ** *** *********, * ***** be ********* ** ****** ********** ** ensure ***** *** ******* *** ********* to ****** **** ** **, **** not ** ** *** *** ** survive.
*** **** ****** ******** ***** **** function ** ********** ** *** *** with *** *********** **** ** **** work ** ******* ******* ***** *****, is ********* *****. * **** ******* it ** * *********** ******** **** manufacturers ****** ********* *******.
*** *********** ** **** * ****** under ******* ****** **** ***** ***** at ****** ***** **** *** **** the ****** ****** *** *** ******** dexterity ** ***** * *** **** is ***** **** *** **** *********** than *** *** **** *** *****.
** **** ****, ***** * *********** pin, **** ***** ***** ** ****, so *** ***** ** ******* ***** at ******** **** *** ***-****** *** the ******** ****** **** ;)
***** ****** ****** *** ********* ******, and ****** ****** ****** ** *** first ***** ******** **** *** **** someone****************** *** ******, ***** ** ** experience, ** *** **** **** ** very ***** *******.
* ******* ** ****** ********** *** maintaining *** ****** ******* ******* ** several ** ********, ** *** ****'*. All *** **** **** ** ****** alarms *******, *** *** ***** ***** had **-**** ****** ********** *** ********. The **** ****** ****** ******* **** was ****** *****, ***** *** ***** enter * ********* ***'* *** **** to ******** ******. ***********, ** ***** get ** ***** * ******* ** false ****** ****** **** ****.
***** ***** ****** ***** ***** *** a ******* ** *******, *** ******* because *** "****** ****" *** *** similar ** *** ******* *** ****, and ******** ***'* ****** ****** ***** would ******* *** *****.
* **** *** ********* ****** (***** a ********* ******) ** ******** **** PIN *********. **** *** **** ******* it's **** ******* ** ********* **** you're ***** **, **** ** **** know *** ********. *******, ***** **** the ******** ** ***** ********* **** might ** **** ** ********, **** you're ******** *** **** * *** to **** ****.