Critiquing HID's 'Access Control Goes Mobile' Presentation

By: Brian Rhodes, Published on Apr 11, 2012

Are Mobile Credentials ready for primetime?  ASSA ABLOY [link no longer available] / HID, who have invested heavily in the technology, posted a webcast of their joint 'Access Control Goes Mobile' event at ISC West. Using mobile devices to host access credentials is a growing trend, with recent development centering around the inclusion of NFC technology into credential readers, door hardware, and smartphone devices. In this note, we examine the key takeaways from that presentation.

We have embedded the entire webcast here for reference. (note: the player omits timestamps so its hard to track by time):

In the webcast, HID / ASSA makes a number of important points:

    • NFC credentials will be administered differently than traditional keys or cards. HID stated that (mobile keys are) "a quantum leap in access control" by "replicating existing credentials and depositing them on a mobile device". These differences were demonstrated by HID through "over the air provisioning and revocation" via a web based mobile services portal.
    • In what was introduced as "the next frontier" for IT management control, the growing issue of securing "foreign devices accessing corporate networks" was mentioned but not completely addressed. HID states that while "many different companies are looking it today", the problem still has no comprehensive solution. This point was clearly illustrated by a confusing software demonstration that enables secure VPN connections from mobile devices to a corporate networks, but does nothing to secure or ensure safe condition of end point devices.  
    • "NFC does not include support for Picture IDs" and the feature is not roadmapped for development.
    •  HID acknowledged that mobile credentials are not the answer for every access control situation. They clearly stated "card credentials are not going away" and mobile credentials are "not a direct replacement" for card credentials. ASSA declares that "NFC is only a portion of the complete access control envelope" and is most valuable applied to the 95% of openings currently not incorporated in any electronic access control system. ASSA illustrated this point through the following chart they titled 'The Security Continuum':

Analysis

1. Because NFC credentials rely on interoperability between credentials and devices, credential management becomes a huge operational concern. The process of provisioning  and managing NFC credentials will be unlike anything currently being used. This difference extends even to how these credentials are purchased and shared. Since NFC credentials are not physical objects they must have the ability to be transported from device to device. Therefore, because this technology is still in early versions, many of these interoperability issues have yet to be discovered.

2. BYOD, or 'Bring Your Own Device', is a growing trend and security concern for corporate IT/security departments. According to the presentation, 37% of all tablets sold are used in corporate environments, but owned by employees. As we noted in our NFC examination, successfully managing and administrating devices not owned by companies is an awkward situation. While a variety of policy and authentication programs are being developed, no 'clear answer' exists in the market. HID demonstrated a 'soft token' system in an early attempt to bridge this gap.

3. Not supporting Picture IDs significantly limits the value of NFC. For high security areas (where image verifications are used for dual authentication) NFC still requires carrying a badge photo which undermines the main claimed benefit of NFC. Since NFC technology is designed as a low bandwidth, low energy transmission medium, the time required to transmit high resolutions picture files is excessive and would be prone to transmission error. 

4. Despite being positioned as a game changer, we disagree that NFC will bring access control to new doors. Bringing access controls to the untapped "95%" of doors has not occured even though several cheap alternatives to hard wired access controlled door exist. If the major incentive to move to NFC is additional security, consider that multiple low-cost proximity card leversets have attempted to gain the same market. If NFC's convenience is the push, then consider that keypad operated locks (requiring no external credential at all) have been in the market for many years.

Conclusion

The concerns we raised in our initial NFC analysis still stand, and it is clear that 'mobile credential' technology is still being developed and working through growing pains. However, these vendors make it clear that NFC technology will continue to recieve development attention for the near future.

Comments : Members only. Login. or Join.

Related Reports

Milestone Presents XProtect On AWS on May 04, 2020
Milestone presented its XProtect on AWS offering at the April 2020 IPVM New...
Remote Network Access for Video Surveillance Guide on Jul 27, 2020
Remotely accessing surveillance systems is key in 2020, with more and more...
Use Access Control Logs To Constrain Coronavirus on Apr 09, 2020
Access control users have included capabilities that are not commonly used...
JCI Slashes ISC West Booth 88.8% on Mar 05, 2020
The mega-booth at the main entrance of the ISC West show floor is now...
NetApp Presents Hybrid Cloud Video Archive on May 11, 2020
NetApp presented its hybrid S3 cloud video archive at the April 2020 IPVM New...
Video Analytics 101 on Mar 16, 2020
This guide teaches the fundamentals of video surveillance...
Clinton Public View Monitor (PVM) Mask Detection Tested on Jul 09, 2020
Face mask detection, or more specifically not wearing one, is expanding...
"Fever Camera" Online Show June 2020 - On-Demand Recordings on Jun 03, 2020
IPVM has successfully completed the world's first "Fever Camera" show....
IPConfigure Presents Orchid Fusion VSaaS on Apr 30, 2020
IPConfigure presented Orchid Fusion VSaaS at the April 2020 IPVM New Products...
VSaaS Online Show June 2020 - On-Demand Recording of 25+ Manufacturers Presentations on Jun 24, 2020
The show featured 25+ VSaaS providers showcasing their latest services. The...
Milestone Launches Multiple Cloud Solutions on Feb 18, 2020
Milestone is going to the cloud, becoming one of the last prominent VMSes to...
Startup Videoloft Presents Cloud Storage on May 27, 2020
Videoloft presented offsite cloud storage at the May 2020 IPVM Startups...
Avigilon ACC Cloud Tested on Jul 08, 2020
Avigilon merged Blue and ACC, adding VSaaS features to its on-premise VMS,...
Faked Coronavirus Fever Detection, Athena Used Hikvision; Responds - Selling NDAA Compliant Cameras, Pledging 50% Of Profits to Victims on Mar 24, 2020
US company, Athena Security, faked its coronavirus fever detection marketing,...
Every VMS Will Become a VSaaS on Feb 21, 2020
VMS is ending. Soon every VMS will be a VSaaS. Competitive dynamics will be...

Recent Reports

VSaaS Will Hurt Integrators on Aug 06, 2020
VSaaS will hurt integrators, there is no question about that. How much...
Dogs For Coronavirus Screening Examined on Aug 06, 2020
While thermal temperature screening is the surveillance industry's most...
ADT Slides Back, Disappointing Results, Poor Commercial Performance on Aug 06, 2020
While ADT had an incredible start to the week, driven by the Google...
AHJ / Authority Having Jurisdiction Tutorial on Aug 06, 2020
One of the most powerful yet often underappreciated characters in all of the...
SIA Coaches Sellers on NDAA 889B Blacklist Workarounds on Aug 05, 2020
Last month SIA demanded that NDAA 899B "must be delayed". Now that they have...
ADI Returns To Growth, Back To 'Pre-COVID Levels' on Aug 05, 2020
While ADI was hit hard in April, with revenue declining 21%, the company's...
Exposing Fever Tablet Suppliers and 40+ Relabelers on Aug 05, 2020
IPVM has found 40+ USA and EU companies relabeling fever tablets designed,...
Indian Government Restricts PRC Manufacturers From Public Projects on Aug 04, 2020
In a move that mirrors the U.S. government’s ban on Dahua and Hikvision...
Directory of 201 "Fever" Camera Suppliers on Aug 04, 2020
This directory provides a list of "Fever" scanning thermal camera providers...
Face Masks Increase Face Recognition Errors Says NIST on Aug 04, 2020
COVID-19 has led to widespread facemask use, which as IPVM testing has shown...
Dahua Loses Australian Medical Device Approval on Aug 04, 2020
Dahua has cancelled its medical device registration after "discussions" with...
Google Invests in ADT, ADT Stock Soars on Aug 03, 2020
Google has announced a $450 million investment in the Florida-based security...
US Startup Fever Inspect Examined on Aug 03, 2020
Undoubtedly late to fever cameras, this US company, Fever Inspect, led by a...
Motorola Solutions Acquires Pelco on Aug 03, 2020
Motorola Solutions has acquired Pelco, pledging to bring blue back and make...
False: Verkada: "If You Want To Remote View Your Cameras You Need To Punch Holes In Your Firewall" on Jul 31, 2020
Verkada falsely declared to “3,000+ customers”, “300 school districts”, and...