文/3S Market 編輯部
從實體入侵弱點、身份驗證、門禁系統架構,到程序安全 —— 高安全場域真正需要建立的是一條完整的「進入信任鏈」。
一般辦公室的門禁,主要目的可能是把員工、訪客與非相關人員區隔開來;但是到了高度機密、高價值或高風險場域,問題完全不同。
這些地方真正擔心的,往往不是一個完全陌生的人拿著假卡闖進來,而是:
一個看起來具有合法身份的人,在不該出現的時間,以看似正常的方式,進入了一個他其實不應該進去的地方。
因此,高安全場域的 Physical Access(實體進出)不能再簡化成「刷卡—讀卡機—控制器—電鎖」的設備組合。它實際上牽涉 Identity、Credential、Authorization、Door、Network、Operation 與 Audit,也就是:
人是誰 → 憑什麼證明 → 有沒有權限 → 此時此地是否應該進入 → 實際是不是本人通過 → 發生異常誰知道 → 誰來處置。
少了其中任何一環,再昂貴的門禁設備,都可能留下一個可以被穿透的洞。
哪些地方真正屬於高度機密與高安全場域?
不是只有軍事基地才需要高安全門禁。
隨著半導體、AI、雲端資料中心、生技、關鍵基礎設施與企業研發的重要性提高,今天需要高度實體安全的場域,其實愈來愈多。
高安全場域 | 真正需要保護的資產 | 主要安全風險 |
國防、政府機密與情報設施 | 國家機密、情報、人員、系統 | 間諜、滲透、破壞、內部人員 |
半導體先進製程、研發中心 | 製程、Mask、設計、設備、營業秘密 | 商業間諜、技術外洩、承包商風險 |
Data Center、Cloud、電信核心機房 | Server、資料、網路、客戶環境 | 未授權維修、資料外洩、服務中斷 |
核能、電力、水務、能源控制中心 | OT、控制系統、關鍵設備 | 破壞、營運中斷、內部威脅 |
金融金庫、支付與清算中心 | 現金、金融資料、HSM、交易系統 | 竊取、勾結、脅迫、內部濫權 |
生技、製藥、特殊實驗室 | 樣本、配方、藥物、智慧財產 | 偷竊、污染、不當操作 |
航太、國防製造與特殊工業 | 設計、零組件、原型、製程 | 技術外洩、破壞、供應鏈滲透 |
機場、港口與重要交通控制中心 | 控制設備、Restricted Area、營運系統 | 非法進入、破壞、營運風險 |
以核能設施為例,美國 NRC 採取的不是「一道門做得非常強」,而是 graded approach,也就是依風險逐層提高安全等級。公開架構包含 Exclusion Area、Protected Area、Vital Area、Material Access Area;愈往核心區域,實體障礙、警報、身份授權與程序要求愈嚴格。部分 Material Access Area 更要求 Two-Person Rule,不允許一個人單獨留在其中。
這個觀念非常值得高科技廠房、Data Center、研發中心借鏡:
高安全不是一道最強的門,而是一層比一層難進去。
高安全門禁最常被忽略的第一個問題:卡是真的,人就是真的嗎?
傳統門禁很容易把「Credential」誤認為「Identity」。
卡片合法,系統便開門。
但是卡片能證明的,很多時候只是:「有一個合法 Credential 出現在讀卡機前。」
它不一定代表持有者就是原來被授權的人。
卡片可能遺失、借用、轉交;低安全等級的憑證也可能存在複製風險。因此,高安全場域首先必須區分:辨識 Credential,和驗證 Identity,是兩件不同的事情。
這也是為什麼 NIST 的 PIV 架構不是只使用卡片序號,而是建立不同等級的 authentication mechanism,並可以結合 Card、PIN、PKI 與 Biometrics。FIPS 201-3甚至明確把不同機制分成不同的身份可信程度;在需要更高 Assurance 的情況,可以採用兩個甚至三個 authentication factors。
因此,真正高安全門禁的方向並不是「全部改做人臉辨識」,而應該是:
依區域風險決定 Authentication Assurance。
例如一般行政區可能使用安全智慧卡或 Mobile Credential;研發限制區提高成 Credential+PIN;真正核心區域則可以再增加生物辨識或第二人授權。
重點不是生物辨識本身,而是不要把所有門都設定成同一種身份可信程度。
更難防的,其實是 Tailgating:合法的人開了門,不合法的人一起進去
門禁系統可以完美判斷卡片。
但門打開之後發生什麼事,卻經常是另一回事。
一名合法員工刷卡後,後方另外一名員工跟著進入;施工人員搬著器材,前面的人順手替他把門撐住;熟識的同仁說一句「我忘記帶卡」,前面的人便直接讓他一起進去。
這些行為未必帶有惡意。
卻可能直接繞過整套身份授權機制。
因此到了真正核心區域,門禁設計不能只管理 Door Unlock,而必須管理 Passage。
也就是:系統不只需要知道「門被授權打開」,還必須知道「實際有幾個人通過」。
因此才會出現 Anti-passback、Occupancy、Interlocking Door、Security Vestibule,以及依場域導入的人員計數、身份再次驗證等設計。
這也是高安全門禁與一般門禁非常重要的分界:
一般門禁管理「門」;高安全門禁開始管理「人通過這扇門的行為」。
第二個巨大盲點:有權進,不代表現在就應該進
這可能比卡片複製更加重要。
一位設備工程師確實有資格進入 Server Room。
可是:
凌晨兩點他有沒有理由進去?
一位半導體設備商確實需要進 Cleanroom。
可是:他的 Maintenance Job 已經結束三個星期,為什麼 Credential 還可以使用?
某位研發主管具有某實驗室權限。
可是:調職以後,原有權限有沒有取消?
因此高安全門禁真正需要管理的不是:Are you authorized?
而是:Are you authorized to enter this place, for this purpose, at this particular time?
這就是從 Access Control 走向 Access Governance 的差別。
NIST SP 800-53 的 PE-2 Physical Access Authorizations 特別要求建立授權人員名單、發給 Credential、定期檢視 Access List,並在不再需要進入時移除權限;同時也提出 Role-based physical access 與限制 Unescorted Access 的控制。
所以高安全場域不應該大量發放「永久權限」。更好的方法反而是:Need-to-Enter。即使一個人的身份可信、Security Clearance 足夠,也還要存在一個實際進入理由。這跟資訊安全裡的 Need-to-Know,本質上完全相同。
第三個盲點藏在牆壁後面:讀卡機安全,Reader 到 Controller 的通訊安全嗎?
這是許多既有門禁系統非常大的歷史包袱。
很多人花很多錢把 Credential 從舊式卡片換成 Smart Card,卻沒有更換 Reader 到 Controller 之間的 Communication Protocol。
前端憑證升級了,後面的通訊卻可能仍是 Legacy Architecture。
這也是 OSDP(Open Supervised Device Protocol)近年受到高安全場域重視的重要原因之一。
SIA 明確把 OSDP 定位為取代 Legacy Wiegand Interface 的現代化通訊標準,可以提供雙向通訊、設備監督與更好的 Cybersecurity;最新版 OSDP 2.2.2 支援 AES-128,SIA也特別建議政府與較高安全需求的環境採用。
但還有一個細節很重要:有 OSDP,不代表通訊就是安全的。
SIA 2026 年發布的實施指南特別提醒,應啟用 OSDP Secure Channel;如果只是使用沒有安全通道的 OSDP Mode,本身仍沒有得到預期的安全效益。
這也代表未來高安全門禁標案如果仍只寫:「Reader 支援 OSDP」恐怕不夠。更合理的要求應該是:
OSDP Secure Channel 必須實際啟用,而且驗收時要驗證。
第四個盲點:門禁控制器本身已經是一部網路電腦
這可能是今天高安全場域最值得重新認識的一件事。
很多人對門禁的想像仍然停留在:讀卡機 → 控制器 → 電鎖。
可是現代 Enterprise Access Control System 的 Controller、Server、Database、Web Management、API、Firmware與Network,本質上已經是一套 IT/OT 系統。
因此 Physical Access 與 Virtual Access 已經開始交會。
最典型的警告案例之一,就是 2022 年 Trellix 研究人員公開揭露 HID Mercury Intelligent Controller 的一系列安全漏洞,其中部分漏洞可能讓未經驗證的攻擊者影響控制器執行、通訊與 Relay;NIST NVD 後續也記載,受影響版本可能讓攻擊者修改控制器 Relay、Configuration,甚至監控通訊。
這個事件真正值得產業注意的,不是哪一家產品曾經出現漏洞。
任何大型軟硬體系統都有可能出現 Vulnerability。
真正值得注意的是:門禁的攻擊面已經從「門外」延伸到「網路裡」。
因此高安全門禁的安全設計,除了 Credential Security,也必須要求 Controller Hardening、Firmware Update、Signed Firmware/Secure Boot 能力、Network Segmentation、Admin MFA、權限管理、弱點通報與 Patch Management。
否則可能出現一個非常荒謬的結果:
門外的人進不來,但網路裡的人可以叫門自己打開。
第五個弱點,不在電子系統,而在「門」
這看似很簡單,實際卻常被忽略。一個門禁點的安全強度,是:
Credential、Reader、Communication、Controller、Power Supply、Lock、Door、Frame、Door Contact、Exit Mechanism,以及建築本體共同形成的結果。
其中最弱的一項,就是整個 Access Point 的安全等級。
如果裝了一套高安全 Credential,卻配上一扇結構強度不足的門;或者門鎖很強,門框與周邊結構卻沒有相應安全等級,最後只是:
把昂貴的身份驗證系統裝在一個實體弱點上。
而且還有另一個更複雜的問題:Security 不能破壞 Life Safety。
發生火災、災害或緊急事故時,人員仍必須安全撤離;某些特殊人員又必須迅速進入關鍵區域處理事故。
連 NRC 核設施安全規範都必須同時考慮高度 Access Control 與緊急狀況下 Authorized Personnel 快速進出需求。
因此高安全門禁真正困難的地方不是「永遠鎖住」。
而是:
正常時該擋住誰,事故時該放走誰,緊急時又該讓誰進去,而且每一次例外都必須留下紀錄。
最大的風險往往叫 Insider
高度機密場域最麻煩的威脅之一,從來不是完全沒有身份的人。
而是本來就具有身份的人。
員工、承包商、設備維護商、清潔人員、IT 人員、安全人員、Temporary Worker。
甚至是管理門禁系統的人本身。
這也是為什麼真正高安全設施不會把「Security Clearance」視為永久通行證。
例如 NRC 核能設施要求對具有 Unescorted Access 的人員建立 Access Authorization Program,核心考量包含 Trustworthiness、Reliability 與 Insider Threat。
到了更敏感的 Material Access Area,甚至要求 Two-Person Rule。
意思很清楚:安全架構不能假設「自己人一定可信」。
而應該設計成:即使其中一個人出了問題,整個系統也不應該立即失守。
因此 Dual Authorization、Two-Person Rule、Escort、Separation of Duties,其實不是古老官僚程序,而是一種非常實際的 Insider Risk Control。
那麼,高安全場域究竟應該選什麼樣的門禁系統?
答案並不是某一個品牌。
LenelS2、Software House C‧CURE、Genetec、HID 或其他 Enterprise PACS,都可能進入高安全專案;真正決定適不適合的,不應只是品牌知名度,而是它能不能承擔這個場域所要求的 Security Architecture。
高安全門禁至少應從以下幾個能力來判斷:
系統能力 | 高安全場域真正需要看的問題 |
Credential Security | 是否支援 Cryptographic Credential,而不是只讀 UID |
Authentication | 能否依區域使用 Card、PIN、Biometric、MFA |
Reader Communication | 是否真正啟用 OSDP Secure Channel |
Authorization | 是否支援 Role、Time、Zone、Schedule、Temporary Access |
Passage Control | Anti-passback、Door Held、Forced Door、Occupancy、Interlock |
Visitor / Contractor | 有沒有 Visitor、Escort、Temporary Credential、Expiration |
Controller Security | Firmware、Patch、Secure Configuration、弱點管理 |
Network Security | Network Segmentation、Encryption、Admin MFA、Audit |
Resilience | Server/Network 中斷時 Controller 如何運作,是否具備 HA |
Event Management | 異常是否會進入 Alarm Workflow,而不是只留下 Log |
Audit | 誰授權、誰修改、誰開門、誰 Override 能否追溯 |
Integration | 是否可與 HR、IAM、IT、Alarm、SOC/SIEM 等系統聯動 |
如果是高度機密場域,我甚至會把一個條件放得非常前面:
門禁系統不能只知道「Access Granted」,還必須知道「Access 是否符合情境」。
例如某工程師:
- 身份正確。
- 卡片正確。
- PIN 正確。
- 權限正確。
可是凌晨三點突然進入平常只在白天維修的機房。技術上可能是:Access Granted。
安全治理上卻應該是:Access Granted + Risk Event。這才是高安全門禁真正應該走向的下一階段。
程序管理一定要加入,這「本來就是門禁的一部分」
這也許是整篇最重要的一點。很多標案把門禁系統視為設備工程。
設備驗收完畢:讀卡成功、門可以開、卡片可以新增刪除、報表可以列印。專案就算完成。
但對高安全場域而言,這樣其實只完成了第一層的基礎安全。
真正的第二層,是 程序安全。
- 誰可以核准某個 Zone 的權限?
- 誰不能替自己增加權限?
- 新進員工什麼時候開始有效?
- 離職帳號多久必須撤銷?
- 調職後誰負責重新 Review Access?
- Vendor Credential 有效多久?
- Maintenance Access 是否必須綁 Work Order?
- 訪客由誰 Escort?
- Lost Credential 多久必須停用?
- Emergency Override 誰可以執行?
- Override 之後誰 Review?
- 哪些區域需要 Two-Person Authorization?
- 多久重新進行一次 Access Review?
- 誰負責 Firmware Update?
- Security Patch 多久必須評估?
- 每一個 Forced Door、Door Held Open、Anti-passback Violation 是否有人處置?
這些看起來全部是「管理問題」。
但是少了它們:門禁系統就只有門,沒有禁。
NIST SP 800-53本身就把 Physical Access Authorization、Physical Access Control、Monitoring Physical Access、Visitor Access Records 與 Incident Response 等不同控制串在一起;而且要求 Access Log 必須被 Review,發現異常還要與 Incident Response Capability 協同處理。
換句話說:
Log 沒有人看,等於沒有 Log。Alarm 沒有人處置,等於沒有 Alarm。規定沒有人執行,等於沒有 Access Control。
高安全門禁的標案,也許應該從「設備規格」改成「安全能力規格」
這也是台灣高安全場域未來值得思考的一個方向。
傳統標案容易寫成:
- 要幾台 Reader。
- 支援什麼卡。
- 多少 Door Controller。
- 多少 Server。
- 支援多少 User。
- 有沒有 Anti-passback。
- 有沒有 Biometric。
可是更關鍵的問題應該變成:
這個場域有哪些 Zone?每一個 Zone 需要什麼 Identity Assurance?誰可以授權?什麼情況可以進?什麼情況必須產生 Risk Event?Server 中斷時門怎麼運作?Controller 被攻擊時怎麼隔離?Emergency Mode 如何運作?誰可以 Override?Override 如何被 Audit?
如此一來,門禁標案就會從:Device Specification
往上提升成:Security Requirement。
再進一步變成:Security Operation Requirement。
高安全場域真正需要的是「五道信任關」
如果把整套架構濃縮,高度機密場域的 Physical Access 可以看成五道連續的信任關:
Identity → Credential → Authorization → Passage → Traceability
- 先確認「你到底是誰」。
- 再確認「你手上的 Credential 是否可信」。
- 再判斷「你現在是否真的有權進」。
- 接著確認「實際通過的人是不是被授權的人」。
- 最後留下可以被追溯、分析並觸發處置的紀錄。
而且這五道關卡不是所有門都做到最高規格。
真正合理的方法仍然是 Risk-Based、Graded Security:外圍比較低,往內逐層提高。
愈重要的資產,需要愈高的身份可信度、愈嚴格的授權、愈完整的 Passage Control,以及愈嚴格的程序。
NIST SP 800-116對政府設施採取的其實也是相同精神:不同安全區域使用不同 Authentication Assurance,越進入高影響區域,可以提高到多因素身份驗證。
結語:高安全門禁真正防的,是「合法身份下的不合法進入」
門禁發展幾十年後,我們可能需要重新問一次:Access Control 到底在 Control 什麼?
如果只是控制門鎖:卡片正確,門就打開。
但是高度機密與高安全場域真正需要控制的是:
Identity、Authority、Time、Location、Purpose、Behavior 與 Exception。
因此高安全門禁不應只追求:「誰進不來。」
而應該進一步追問:
誰進得來?他為什麼能進來?他現在為什麼要進來?進去之後有沒有人知道?行為異常時有沒有反應?權限不再需要時,有沒有立即消失?
做到這一步,Physical Access Control System 才真正從一套門禁設備,升級成為高安全場域的 Security Governance Infrastructure。
而這也說明了一件很重要的事:
程序管理不是門禁系統旁邊另外附加的一套 SOP。
在高度機密與高安全環境中:
程序本身,就是 Access Control System 的一部分。
設備決定「能不能做」。
程序決定「什麼時候做、誰可以做、出了問題怎麼辦」。
兩者合在一起,才真正形成高安全場域所需要的安全能力。
English version
What High-Security Environments Really Need: Five Gates of Trust
From physical intrusion vulnerabilities and identity verification to access-control architecture and procedural security — high-security environments need to build a complete “trust chain for entry.”
In a typical office, access control is mainly used to separate employees, visitors, and unrelated personnel. In highly confidential, high-value, or high-risk environments, however, the problem is entirely different.
What these environments truly worry about is often not a complete stranger trying to break in with a fake card, but rather this:
A person who appears to have a legitimate identity enters, at the wrong time and in an apparently normal way, a place that person should not actually be allowed to enter.
For that reason, Physical Access in a high-security environment can no longer be reduced to a simple chain of “credential — reader — controller — lock.” It involves Identity, Credential, Authorization, Door, Network, Operation, and Audit. In other words:
Who are you? → How do you prove it? → Are you authorized? → Should you be entering here, now? → Was it really you who passed through? → Who knows when something abnormal occurs? → Who responds?
If any one of these links is missing, even the most expensive access-control equipment can leave an opening that can be exploited.
Which Environments Truly Qualify as Highly Confidential and High-Security?
Military bases are not the only places that require high-security access control.
As semiconductors, AI, cloud data centers, biotechnology, critical infrastructure, and corporate R&D become increasingly important, the number of environments requiring high-assurance physical security is also growing.
High-Security Environment | Assets That Truly Need Protection | Primary Security Risks |
Defense, Classified Government & Intelligence Facilities | National secrets, intelligence, personnel, systems | Espionage, infiltration, sabotage, insider threats |
Advanced Semiconductor Manufacturing & R&D Centers | Processes, masks, designs, equipment, trade secrets | Industrial espionage, technology leakage, contractor risk |
Data Centers, Cloud & Telecom Core Facilities | Servers, data, networks, customer environments | Unauthorized maintenance, data leakage, service disruption |
Nuclear, Power, Water & Energy Control Centers | OT, control systems, critical equipment | Sabotage, operational disruption, insider threats |
Financial Vaults, Payment & Clearing Centers | Cash, financial data, HSMs, transaction systems | Theft, collusion, coercion, insider abuse |
Biotech, Pharmaceutical & Specialized Laboratories | Samples, formulas, drugs, intellectual property | Theft, contamination, improper operation |
Aerospace, Defense Manufacturing & Specialized Industry | Designs, components, prototypes, processes | Technology leakage, sabotage, supply-chain infiltration |
Airports, Ports & Critical Transportation Control Centers | Control equipment, Restricted Areas, operational systems | Unauthorized entry, sabotage, operational risk |
Nuclear facilities offer a useful example. The U.S. NRC does not rely on “one extremely strong door.” It uses a graded approach, raising the security level layer by layer according to risk. The public framework includes the Exclusion Area, Protected Area, Vital Area, and Material Access Area. The closer one gets to the core, the stricter the physical barriers, alarms, identity authorization, and procedural requirements become. Some Material Access Areas also require a Two-Person Rule, meaning no one may remain there alone.
This concept is highly relevant to high-tech plants, data centers, and R&D facilities:
High security is not one strongest door. It is a series of layers that become progressively harder to penetrate.
The First Often-Overlooked Problem in High-Security Access Control: If the Card Is Genuine, Is the Person Genuine Too?
Traditional access control can easily mistake a “Credential” for an “Identity.”
If the card is valid, the system opens the door.
But what the card can often prove is only this: “A valid Credential has appeared at the reader.”
That does not necessarily mean the holder is the person who was originally authorized.
A card can be lost, borrowed, handed to someone else, or — with lower-assurance credentials — copied. High-security environments must therefore make a clear distinction: identifying a Credential and verifying an Identity are two different things.
This is why the NIST PIV framework does not rely only on a card serial number. It defines different levels of authentication mechanisms and can combine Card, PIN, PKI, and Biometrics. FIPS 201-3 explicitly differentiates mechanisms by assurance level; where higher assurance is required, two or even three authentication factors can be used.
The direction of high-security access control, therefore, is not to “replace everything with facial recognition.” It should instead be:
Set Authentication Assurance according to the risk of each zone.
For example, a general administrative area may use a secure smart card or Mobile Credential; a restricted R&D area may require Credential + PIN; and a true core area may add biometrics or second-person authorization.
The point is not biometrics itself. The point is that every door should not be assigned the same level of identity assurance.
Even Harder to Prevent: Tailgating — One Authorized Person Opens the Door and an Unauthorized Person Enters With Them
An access-control system can judge a credential perfectly.
What happens after the door opens, however, is often another matter.
An authorized employee badges in and another employee follows behind; a contractor is carrying equipment and the person in front casually holds the door open; a familiar colleague says, “I forgot my card,” and is simply waved through together with the first person.
None of these actions necessarily involves malicious intent.
Yet each can bypass the entire identity-and-authorization mechanism.
In a true core area, access-control design therefore cannot manage only Door Unlock. It must manage Passage.
The system must know not only that “the door was opened with authorization,” but also “how many people actually passed through.”
That is why designs such as Anti-passback, Occupancy, Interlocking Door, Security Vestibule, personnel counting, and re-verification of identity are introduced according to the needs of the environment.
This marks an important dividing line between ordinary access control and high-security access control:
Ordinary access control manages the “door.” High-security access control begins to manage “the behavior of people passing through the door.”
The Second Major Blind Spot: Being Authorized Does Not Mean You Should Be Entering Right Now
This may be even more important than credential cloning.
An equipment engineer may indeed be qualified to enter a Server Room.
But:
Does that person have a valid reason to enter at 2:00 a.m.?
A semiconductor equipment vendor may indeed need access to the Cleanroom.
But if the Maintenance Job ended three weeks ago, why is the Credential still valid?
An R&D manager may have access rights to a particular laboratory.
But after a job transfer, was the original access permission removed?
What high-security access control needs to manage is therefore not simply: Are you authorized?
It is: Are you authorized to enter this place, for this purpose, at this particular time?
That is the difference between Access Control and Access Governance.
NIST SP 800-53 PE-2 Physical Access Authorizations specifically calls for maintaining lists of authorized personnel, issuing Credentials, periodically reviewing Access Lists, and removing access when it is no longer required. It also addresses Role-based physical access and restrictions on Unescorted Access.
High-security environments therefore should not issue large numbers of “permanent permissions.” A better principle is Need-to-Enter. Even when a person’s identity is trusted and the Security Clearance is sufficient, there still needs to be a legitimate reason for entering. In essence, this is the physical-security counterpart of Need-to-Know in cybersecurity.
The Third Blind Spot Is Behind the Wall: The Reader May Be Secure — but Is the Reader-to-Controller Communication Secure?
This is a major legacy burden in many installed access-control systems.
Organizations may spend heavily upgrading a Credential from an older card to a Smart Card, while leaving the Reader-to-Controller Communication Protocol unchanged.
The front-end credential has been upgraded, but the communication behind it may still rely on a Legacy Architecture.
This is one reason OSDP (Open Supervised Device Protocol) has gained increasing attention in high-security environments.
SIA explicitly positions OSDP as a modern communication standard intended to replace the Legacy Wiegand Interface. It provides bidirectional communication, device supervision, and stronger Cybersecurity. OSDP 2.2.2 supports AES-128, and SIA specifically recommends it for government and other higher-security environments.
But one detail is critical: supporting OSDP does not automatically mean the communication is secure.
SIA’s 2026 implementation guidance specifically emphasizes enabling OSDP Secure Channel. Using OSDP without the secure channel does not deliver the expected security benefit.
That means a future high-security access-control specification that simply says “Reader supports OSDP” is probably not enough. A more appropriate requirement is:
OSDP Secure Channel must actually be enabled, and it must be verified during acceptance testing.
The Fourth Blind Spot: The Access Controller Is Already a Networked Computer
This may be one of the most important changes high-security environments need to recognize today.
Many people still imagine access control as: reader → controller → electric lock.
But a modern Enterprise Access Control System — including the Controller, Server, Database, Web Management, API, Firmware, and Network — is essentially an IT/OT system.
Physical Access and Virtual Access are therefore beginning to converge.
One well-known warning case came in 2022, when Trellix researchers publicly disclosed a series of security vulnerabilities in HID Mercury Intelligent Controllers. Some of those vulnerabilities could allow unauthenticated attackers to affect controller execution, communications, and relays; the NIST NVD later documented that affected versions could allow attackers to modify controller Relay and Configuration settings, and even monitor communications.
The real lesson for the industry is not that one particular product once had vulnerabilities.
Any large hardware-and-software system can contain Vulnerabilities.
What matters is this: the access-control attack surface has expanded from “outside the door” to “inside the network.”
High-security access-control design must therefore address not only Credential Security, but also Controller Hardening, Firmware Update, Signed Firmware/Secure Boot, Network Segmentation, Admin MFA, privilege management, vulnerability disclosure, and Patch Management.
Otherwise, an absurd situation can occur:
People outside the door cannot get in, but someone inside the network can tell the door to open itself.
The Fifth Weakness Is Not in the Electronics — It Is in the “Door”
This sounds simple, but it is frequently overlooked. The security strength of an access point is formed by the combination of:
Credential, Reader, Communication, Controller, Power Supply, Lock, Door, Frame, Door Contact, Exit Mechanism, and the building structure itself.
The weakest element determines the security level of the entire Access Point.
If a high-security Credential is installed on a structurally weak door, or if the lock is strong while the frame and surrounding structure are not built to a corresponding security level, the result is simply this:
An expensive identity-verification system has been installed on top of a physical weak point.
There is also a more complicated issue: Security must not compromise Life Safety.
During a fire, disaster, or other emergency, occupants still need to evacuate safely, while certain authorized personnel may need rapid access to critical areas to respond.
Even NRC security requirements for nuclear facilities must balance stringent Access Control with the need for Authorized Personnel to move quickly during emergencies.
The real challenge of high-security access control is therefore not to “keep everything locked forever.”
It is:
Who must be kept out during normal operations? Who must be allowed out during an incident? Who must be allowed in during an emergency? And every exception must leave an auditable record.
The Biggest Risk Is Often the Insider
One of the most difficult threats in highly confidential environments is not a person with no identity at all.
It is someone who already has a legitimate identity.
Employees, contractors, equipment service providers, cleaning personnel, IT staff, security personnel, and Temporary Workers.
Even the people who administer the access-control system itself.
That is why truly high-security facilities do not treat a “Security Clearance” as a permanent pass.
For example, NRC nuclear facilities require an Access Authorization Program for personnel with Unescorted Access, with core considerations including Trustworthiness, Reliability, and Insider Threat.
In more sensitive Material Access Areas, a Two-Person Rule may even be required.
The message is clear: the security architecture cannot assume that “insiders are always trustworthy.”
It should instead be designed so that even if one person becomes the problem, the entire system does not immediately fail.
Dual Authorization, Two-Person Rule, Escort, and Separation of Duties are therefore not merely old-fashioned bureaucracy. They are practical forms of Insider Risk Control.
So What Kind of Access-Control System Should a High-Security Environment Choose?
The answer is not a single brand.
LenelS2, Software House C‧CURE, Genetec, HID, and other Enterprise PACS platforms may all be used in high-security projects. What determines suitability is not brand recognition alone, but whether the system can support the Security Architecture required by that particular environment.
At minimum, a high-security access-control system should be evaluated across the following capabilities:
System Capability | What a High-Security Environment Really Needs to Examine |
Credential Security | Does it support Cryptographic Credentials rather than merely reading a UID? |
Authentication | Can Card, PIN, Biometrics, and MFA be applied by zone? |
Reader Communication | Is OSDP Secure Channel actually enabled? |
Authorization | Does it support Role, Time, Zone, Schedule, and Temporary Access? |
Passage Control | Anti-passback, Door Held, Forced Door, Occupancy, Interlock |
Visitor / Contractor | Visitor, Escort, Temporary Credential, Expiration |
Controller Security | Firmware, Patch, Secure Configuration, vulnerability management |
Network Security | Network Segmentation, Encryption, Admin MFA, Audit |
Resilience | How does the Controller operate if the Server/Network fails? Is HA available? |
Event Management | Do anomalies enter an Alarm Workflow rather than merely remain as Logs? |
Audit | Can the system trace who authorized, who changed settings, who opened a door, and who performed an Override? |
Integration | Can it integrate with HR, IAM, IT, Alarm, SOC/SIEM, and related systems? |
For a highly confidential environment, I would put one requirement very near the top:
The access-control system must know not only “Access Granted,” but also whether the access makes sense in context.
For example, consider an engineer:
Identity is correct.
Credential is correct.
PIN is correct.
Authorization is correct.
But the engineer suddenly enters, at 3:00 a.m., a machine room that is normally serviced only during the day. Technically, the result may be: Access Granted.
From a security-governance perspective, however, it should be: Access Granted + Risk Event. This is where high-security access control should be heading next.
Procedural Management Must Be Included — It Is “Already Part of Access Control”
This may be the most important point in the entire article. Many projects still treat an access-control system as an equipment installation.
Acceptance testing is completed: the credential reads successfully, the door opens, cards can be added or deleted, and reports can be printed. The project is then considered finished.
For a high-security environment, however, that completes only the first layer: foundational security.
The true second layer is Procedural Security.
Who is allowed to approve access to a particular Zone?
Who is prohibited from granting privileges to themselves?
When does a new employee’s access become active?
How quickly must a departing employee’s account be revoked?
After a job transfer, who is responsible for reviewing access again?
How long should a Vendor Credential remain valid?
Must Maintenance Access be tied to a Work Order?
Who must Escort a visitor?
How quickly must a Lost Credential be disabled?
Who is authorized to perform an Emergency Override?
Who reviews an Override afterward?
Which areas require Two-Person Authorization?
How often must Access Reviews be repeated?
Who is responsible for Firmware Updates?
How quickly must Security Patches be assessed?
Is every Forced Door, Door Held Open, and Anti-passback Violation actually investigated and handled?
All of these may look like “management issues.”
But without them, an access-control system has a door — and no real control.
NIST SP 800-53 itself links Physical Access Authorization, Physical Access Control, Monitoring Physical Access, Visitor Access Records, and Incident Response. It also requires Access Logs to be reviewed, and anomalies to be coordinated with the Incident Response Capability.
In other words:
A Log that nobody reviews is effectively no Log. An Alarm that nobody responds to is effectively no Alarm. A rule that nobody executes is effectively no Access Control.
High-Security Access-Control Specifications May Need to Shift from “Equipment Specifications” to “Security Capability Specifications”
This is also a direction worth considering for high-security environments in Taiwan.
Traditional specifications often look like this:
How many Readers?
What types of cards are supported?
How many Door Controllers?
How many Servers?
How many Users are supported?
Is Anti-passback included?
Is Biometric authentication supported?
But the more important questions should become:
What Zones exist in this environment? What level of Identity Assurance does each Zone require? Who can authorize access? Under what conditions may someone enter? Under what conditions must a Risk Event be generated? How do doors operate if the Server goes down? How is a compromised Controller isolated? How does Emergency Mode work? Who may Override? How is an Override Audited?
The access-control specification then evolves from: Device Specification
To: Security Requirement.
And further to: Security Operation Requirement.
What High-Security Environments Really Need: Five Gates of Trust
If the entire architecture is condensed, Physical Access in a highly confidential environment can be viewed as five consecutive gates of trust:
Identity → Credential → Authorization → Passage → Traceability
First confirm: “Who are you, really?”
Then confirm: “Can the Credential in your hand be trusted?”
Then determine: “Are you truly authorized to enter now?”
Next confirm: “Was the person who actually passed through the authorized person?”
Finally, retain records that can be traced, analyzed, and used to trigger a response.
These five gates do not need to be applied at the maximum level to every door.
The rational approach remains Risk-Based, Graded Security: lower assurance at the perimeter, with progressively stricter controls toward the core.
The more important the asset, the higher the identity assurance, the stricter the authorization, the more complete the Passage Control, and the more rigorous the procedures must become.
NIST SP 800-116 applies the same basic principle to government facilities: different security zones use different levels of Authentication Assurance, and higher-impact areas can require multi-factor identity verification.
Conclusion: What High-Security Access Control Really Defends Against Is “Illegitimate Entry Under a Legitimate Identity”
After decades of access-control development, it may be time to ask the question again: What exactly is Access Control supposed to Control?
If it only controls the lock, the logic is simple: the card is valid, so the door opens.
But what highly confidential and high-security environments truly need to control is:
Identity, Authority, Time, Location, Purpose, Behavior, and Exception.
High-security access control therefore should not focus only on: “Who cannot get in?”
It should also ask:
Who can get in? Why are they allowed in? Why are they entering now? Does anyone know after they enter? Is there a response when their behavior is abnormal? When access is no longer needed, does the permission disappear immediately?
Only at that point does a Physical Access Control System evolve from a door-control system into Security Governance Infrastructure for a high-security environment.
And this leads to one final point:
Procedural management is not a separate SOP attached beside the access-control system.
In highly confidential and high-security environments:
The procedure itself is part of the Access Control System.
Equipment determines “what the system is capable of doing.”
Procedures determine “when it may be done, who may do it, and what happens when something goes wrong.”
Only when the two are combined can a high-security environment achieve the security capability it actually needs.

0 comments:
張貼留言