In the next three articles, Mr.Q will systematically walk you through how communication protocols in access control systems affect their security.
This is Part One. Before we discuss how communication protocols affect access control system security, let's first understand which components affect the security of an access control system.
An access control system — in English, Physical Access Control System (abbreviated PACS, hereafter referred to as “access control system”) — is a system that opens doors using various types of credentials (such as facial recognition, fingerprints, a mobile phone, or an access card). An access control system is made up of a variety of components. Below is a typical structural diagram:
“How an Access Control System Works”

Figure 1: Access Control System Diagram
The front-end devices of a typical access control system consist of: access credentials (including access cards, fingerprint recognition, mobile apps, etc.), card readers, electric locks, exit buttons (for single-sided doors), door contact sensors, and so on. These front-end devices are all connected to the access controller via wiring and cables. On the back end of the access controller is the human-machine interface — the access control management software — which is usually connected over the network, though earlier controllers were sometimes connected via other means such as RS-485 or a serial port.
A brief introduction to how access control works

Figure 2: Access Control Workflow Diagram
When someone swipes a card, the card number is sent to the access controller. The controller checks whether this card number has permission — if it does, the door opens, and the swipe record is sent over the network to the server for display and storage. If it does not have permission, the swipe is rejected and that information is uploaded instead.
“Factors Affecting Access Control System Security 』
The overall workflow of an access control system is quite simple. So what factors should we consider when choosing a secure access control system?
Let's start with the architecture diagram below

Figure 3: Access Control System Architecture Diagram
During operation, the front end uses an access credential to swipe, the reader reads the card and sends the information to the local controller, which uploads the information to the main controller (*in some systems, the local controller is integrated into the main controller). After processing the information, the main controller both executes the door-opening action and passes the information on to the management software.
Every step here carries a security risk!
Figure 4: Access Control System Risk Diagram
For example:
If the access card's security isn't high enough, it may be at risk of being cloned;
Information between the card reader and the local controller is transmitted via cable, so card data could be intercepted and subjected to a replay attack;
If the signals passed between the local controller and the main controller — including uploaded card data and downstream control commands — are hijacked by a hacker, false or tampered door-opening control signals could be sent; the main controller and the management software are connected via a network cable, so network data could be intercepted or tampered with, using a fake host to take control of the main controller. Today's access control systems have corresponding security solutions for each of these threats (see the diagram below):

Figure 5: Access Control Security Countermeasures
- Use encrypted, high-security cards to prevent cloning
- Use an OSDP-encrypted reader channel to prevent replay attacks on data uploaded by the reader
- Use AES encryption between the main controller and local controllers to improve the security of information transfer
- On the network side, use TLS encryption to prevent hackers from intercepting information or issuing false control commands
Threats are everywhere — only when every link in the end-to-end chain has improved security can the entire access control system be considered reliable. That covers the factors affecting access control system security
In the next chapter, we'll look at the differences between the Open Supervised Device Protocol (OSDP) and various traditional communication protocols.
Coming Up Next:《OSDP vs. Traditional Communication Protocols》