HOME/KNOWLEDGE BASE/SECURITY & ACCESS CONTROL/ACCESS CONTROL SYSTEMS EXPLAINED
Guide

Access Control Systems Explained

A working reference to electronic access control: the components behind every controlled door, why the industry is migrating from Wiegand to OSDP, the credential security story from 125 kHz prox to DESFire and mobile, system architectures from standalone to cloud, and the maintenance regime that keeps access systems trustworthy.

The anatomy of a controlled door

Every access-controlled door is the same small system: a credential (card, fob, phone, PIN, biometric) presented to a reader, which passes it to a controller holding the decision logic (who, which door, when), which drives the locking hardware and watches the door’s state. The supporting cast completes it: request-to-exit devices (buttons, sensors) for free egress, door position switches reporting open/closed, break-glass overrides for emergency egress, and power with battery backup — because a door that fails wrongly is either a security hole or a fire-egress problem.

That last point deserves its own sentence: fail-safe (unlocks on power loss) versus fail-secure (stays locked) is a per-door engineering decision entangled with egress and fire compliance — emergency egress paths must always allow exit regardless of the access system’s state, and getting this wrong is the most serious mistake in the trade.

Wiegand vs OSDP — the migration that matters

For thirty years the reader-to-controller link was Wiegand: a one-way, unencrypted, unsupervised wiring convention from the 1980s. Its weaknesses are now textbook — signals can be sniffed or replayed by a device planted behind a reader, the controller can’t tell if a reader is offline or tampered, and cable runs are limited. The industry’s answer is OSDP (Open Supervised Device Protocol, an SIA standard): an RS-485-based, two-way channel with Secure Channel encryption, continuous supervision (a dead or substituted reader raises an alert), longer runs, and multi-drop wiring.

The practical guidance is unambiguous: specify OSDP with Secure Channel actually enabled on new work (readers shipped OSDP-capable but running unencrypted defaults are common — commissioning discipline matters), and treat Wiegand estates as migration candidates, prioritising exterior and high-risk doors where the sniffing attack is practical. Most modern readers and controllers — across Integriti, Protege, Gallagher, Challenger and the video-brand access lines — support OSDP today.

Credentials: a security history in four generations

Credential technology generations
GenerationTechnologySecurity statusField reality
125 kHz proxUnencrypted RFID (HID Prox, EM4100 era)Trivially cloneable — kiosk copiers duplicate them in secondsStill everywhere; migrate any site that cares about cloning
MIFARE Classic13.56 MHz smartcard, proprietary cryptoBroken (attacks published 2008+); clone tools commonplaceLarge legacy estates; treat as compromised
DESFire EV2/EV3 (and equivalents)13.56 MHz smartcard, AES cryptographyCurrent professional standard when properly keyedSpecify with custom keys — default-keyed cards squander the crypto
Mobile credentialsBLE/NFC phone-based (platform wallets and vendor apps)Strong crypto + the phone’s own security; revocable instantlyGrowing fast; convenience + lifecycle management are the killer features

The uncomfortable audit finding on a huge share of Australian sites: modern platforms reading legacy credentials. The controller can be flawless while the 125 kHz card opening the door came from a $30 cloner — credential generation is part of the security posture, and upgrades can usually ride multi-technology readers through a staged migration.

Architectures: standalone to cloud

Access systems come in four architectural sizes. Standalone (a keypad or battery lock per door) suits single doors with no audit needs. Embedded/web-based (Inception, Protege WX and peers) puts the software on the controller for small-to-medium sites — browser commissioning, no server. Server-based enterprise (Integriti, Protege GX, Gallagher Command Centre, Challenger estates) delivers multi-site scale, deep integration and high-security certification. Cloud/ACaaS hosts the management layer as a subscription — compelling for multi-site consistency, remote administration and managed-service business models, with the trade-offs (connectivity dependence, subscription economics, data governance) to weigh per client.

The unified trend matters in Australia: the dominant local platforms fold intrusion into the same controller (see the Inner Range and ICT pages) — one system arming areas and opening doors, which changes both specification and service economics.

The maintenance regime

  • Door hardware first: locks, strikes, closers and hinges fail mechanically long before electronics — test operation, alignment and REX behaviour per door
  • Fail-safe/fail-secure verification per door, every service: egress compliance is not a set-and-forget property
  • Controller and PSU batteries on an age register — the access system’s quiet single point of failure
  • Firmware currency across controllers and readers (security patches matter — these are networked devices)
  • Credential audits: leavers disabled, lost cards voided, shared credentials hunted, dormant accounts culled
  • OSDP Secure Channel confirmed enabled where hardware supports it
  • Event-log health: clocks synced, storage adequate, alerts routing to someone who reads them

How traqR fits

Access maintenance is per-door work, and traqR structures it that way: every door, reader, controller and PSU a QR-coded asset with install dates and configuration notes (fail mode, OSDP status, credential technologies); contract schedules generating the service rounds; per-asset results, photos and defects from the field; battery and firmware cycles tracked; and the audit-ready per-door history that enterprise clients, certifiers and insurers increasingly expect.

Standards & further reading

Inner Range deep-dive ICT deep-dive Gallagher deep-dive Inner Range vs ICT comparison Security maintenance & compliance guide

Frequently asked

What is OSDP and why replace Wiegand?

OSDP (Open Supervised Device Protocol) is the modern reader-to-controller standard: encrypted (Secure Channel), supervised (tampered or offline readers alert), two-way, and longer-range over RS-485. Wiegand — the 1980s convention it replaces — is unencrypted, unsupervised and sniffable, which is why new work should specify OSDP with encryption actually enabled.

Are prox cards secure?

125 kHz prox cards are trivially cloneable — kiosk copiers duplicate them in seconds — and MIFARE Classic smartcards are also long broken. The current professional standard is AES-based smartcards (DESFire EV2/EV3 class) with custom keys, or mobile credentials. Multi-technology readers allow staged migration off legacy cards.

What is the difference between fail-safe and fail-secure?

Fail-safe locks release on power loss (egress and fire-path friendly, security-weaker); fail-secure locks hold locked (security-stronger, egress-critical to engineer around). It is a per-door decision entangled with emergency egress compliance — every controlled door must still allow safe exit regardless of the system’s state.

Is cloud access control a good idea?

For multi-site consistency, remote administration and managed-service models, genuinely yes — the management layer as a subscription removes servers and centralises control. Weigh connectivity dependence, ongoing subscription economics and data governance per client; local unified platforms (Integriti, Protege) also offer their own hosted/remote options.

Back to security & access control

Run your whole trades business in one place

traqR does quoting, scheduling, invoicing, timesheets and compliance — built for Australian trades. Try it free for 14 days, no credit card required.

Start free trial View pricing