Showing posts with label HID. Show all posts
Showing posts with label HID. Show all posts

Wednesday, July 15, 2026

Legal Considerations in Access Control

Legal Considerations in Access Control Implementation

When implementing an access control system, there are important legal considerations that need to be taken into account. Adequate security of information and information systems is a fundamental responsibility for us. Access control plays a vital role in determining the activities allowed for legitimate users and mediating any attempts to access system resources.

In order to ensure the integrity of access control configurations, it is crucial to prevent unauthorized principles from gaining access to sensitive permissions.

This is where legal frameworks such as the General Data Protection Regulation (GDPR), Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), Family Educational Rights and Privacy Act (FERPA), California Consumer Privacy Act (CCPA), and New York SHIELD Act come into play. These frameworks provide guidelines and requirements for the implementation of access control.

By adhering to these legal considerations, we can safeguard the privacy and security of data, ensure compliance with relevant regulations, and mitigate the risk of data breaches. In the following sections, we will explore specific compliance requirements related to GDPR, SOX, HIPAA, and the importance of access control in meeting these obligations.

For organizations operating in India, implementing access control requires compliance with a rapidly evolving legal landscape. The primary framework governing data security and access management is the Digital Personal Data Protection (DPDP) Act, 2023, supported by rules from the Indian Computer Emergency Response Team (CERT-In)

Core Door Components & Specifications

Locking Mechanism (Magnetic Lock / EM Lock): Use a minimum of 600 lbs (272 kg) holding force for internal doors, and 1200 lbs (544 kg) for perimeter doors. They must be wired as Fail-Safe (drops lock instantly when power cuts).

Egress Switch / Request to Exit (REX) Sensor: A PIR (Passive Infrared) motion sensor mounted on the secure inside frame. It automatically unlocks the door when someone approaches from the inside to exit.

Emergency Door Release (Break-Glass type (Green)): A physical manual override switch placed on the exit side of the door. Breaking the glass must physically cut power to the EM lock, bypassing all software or controller failures. Mount exactly adjacent to the door frame at 1.2 meters for easy reach during a fire evacuation.

Door Status Monitor (Magnetic Contact): A sensor that detects whether the door is physically open or closed. This is the hardware component that triggers the "Door Held Open Too Long" or "Forced Entry" alerts in your SOP.

Readers & Biometrics: Mount at 1.2 meters (4 feet) from the finished floor level. This complies with accessibility guidelines for differently-abled employees.

Access Management Software: While the physical locks and readers handle the hardware execution, the Access Management Software acts as the central brain of the entire door infrastructure. Without it, the hardware cannot enforce permissions, log events, or remain legally compliant.

1. Core Software Modules for Door Control

·        Credential Mapping Engine: Links an individual’s identity (Employee ID, Visitor Pass) to specific door controllers. It dictates who can open Door A but not Door B.

·        Time Zone & Access Level Manager: Restricts access by time. For example, standard employees can open doors from 9:00 AM to 6:00 PM, while the server room door requires 24/7 restriction.

·        Real-Time Event Viewer: Captures and displays active door states (e.g., "Door 01: Access Granted to User X" or "Door 04: Forced Entry Alert").

2. Software Configurations Required by Indian Law

Anti-Passback (APB) Engine (Prevention of Tailgating)

·        How it works: The software tracks the "In/Out" status of a credential. If a card is swiped at an entry reader, the software will block that same card from being used to enter again until it logs an exit swipe at the corresponding exit reader.

·        Legal Value: Prevents employees from passing their badge backward to let an unauthorized person into the facility, ensuring audit logs remain accurate for liability tracking.

Automated Data Lifecycle Management (DPDP Act Compliance)

·        Consent Flagging: The software user database must feature a mandatory checkbox or field indicating that biometric consent was explicitly captured.

·        Auto-Purge Rules: The system must be configured to automatically delete inactive user profiles (e.g., terminated employees or expired visitor profiles) from the local memory of the edge door controllers after a set period.

NTP Time Sync & Forensic Auditing (CERT-In Mandate)

·        Server-to-Controller Sync: The software must continuously broadcast the synchronized NIC/NPL network time down to every connected door controller panel.

·        Log Locking: Access logs stored within the software database must be configured as Read-Only / Append-Only. No administrator or security guard should have the software permissions to alter, edit, or delete a door access log event.

3. Hardware-Software Communication Security

·        Encrypted Protocols: The software must communicate with edge door controllers using encrypted protocols (like TLS 1.3 for network communication and OSDP - Open Supervised Device Protocol for the wiring between the reader and the door panel).

·        Legacy Risk: Avoid older Wiegand wiring configurations in your software setup, as Wiegand transmits card data in clear text, making it vulnerable to physical wire-tapping.

General Data Protection Regulation (GDPR) Compliance

The General Data Protection Regulation (GDPR) is a privacy regulation that safeguards the personal data of European Union (EU) citizens. As organizations collect and store personal data, it is crucial to prioritize customer awareness, consent, and data security to comply with the GDPR’s requirements.

When implementing an Identity and Access Management (IAM) solution for GDPR compliance, access management, access governance, authentication, and identity management should be key components. By incorporating these elements, organizations can effectively track access to personal data, manage access rights based on organizational changes and customer preferences, and empower consumers to exercise their rights to restrict data collection.

Key Considerations for GDPR Compliance:

1.   Customer Awareness: Organizations must inform individuals about the purpose and consequences of personal data collection, ensuring they are aware of their rights under the GDPR.

2.   Consent Management: Obtaining explicit and informed consent from individuals before collecting and processing their personal data is crucial for GDPR compliance.

3.   Data Security: Implementing robust security measures to protect personal data from unauthorized access, loss, or disclosure is essential.

4.   Access Management: Organizations should implement a comprehensive access management system to ensure that only authorized individuals can access personal data.

5.   Access Governance: Regularly reviewing and updating access rights based on organizational changes and customer preferences helps maintain compliance and prevent data breaches.

6.   Authentication: Implementing strong authentication mechanisms, such as multi-factor authentication, enhances security and strengthens GDPR compliance.

7.   Identity Management: Effective management of user identities and roles helps control access to personal data and maintain compliance with the GDPR.

By adhering to GDPR compliance requirements, organizations can demonstrate their commitment to data privacy and protection, fostering trust among their customers and avoiding potential legal consequences.

Sarbanes-Oxley Act (SOX) Compliance

The Sarbanes-Oxley Act (SOX) is a crucial legislation that aims to prevent corporate fraud and ensure the integrity of financial reporting for publicly-traded organizations, especially within the financial services sector. SOX compliance is of utmost importance to maintain data security and protect against financial malpractice.

For organizations to meet SOX compliance requirements, implementing robust IAM (Identity and Access Management) solutions is essential. These solutions enable centralized administration of access management and provide granular access controls, ensuring that only authorized personnel can access sensitive financial data.

Key Components for SOX Compliance:

1.   Centralized Administration: IAM solutions offer centralized administration, allowing organizations to efficiently manage user access rights and permissions.

2.   Separation of Duties (SoD) Policies: Implementing SoD policies ensures that no individual has complete control over financial reporting, minimizing the risk of fraudulent activities.

3.   Regular Auditing: Regular auditing helps to identify any potential access control gaps or vulnerabilities and ensures continuous compliance with SOX requirements.

4.   Logging and Tracking Tools: IAM solutions provide logging and tracking capabilities, allowing organizations to monitor user activity and track any unauthorized or suspicious access attempts.

5.   Granular Access Controls: IAM solutions enable organizations to define and enforce granular access controls, ensuring that users have appropriate access levels based on their roles and responsibilities.

By implementing IAM solutions for SOX compliance, organizations can significantly reduce the risk of data breaches and protect the integrity and security of their financial reporting processes.

Health Insurance Portability and Accountability Act (HIPAA) Compliance

HIPAA, the Health Insurance Portability and Accountability Act, plays a crucial role in protecting the privacy and security of protected health information (PHI) collected and stored by healthcare organizations. As healthcare data security becomes increasingly important, it is essential for organizations to implement robust IAM solutions that ensure HIPAA compliance.

An IAM solution designed for HIPAA compliance should prioritize credential protection, offering secure authentication methods to prevent unauthorized access. Additionally, the solution should provide multiple ways to onboard healthcare business partners, facilitating seamless collaboration while maintaining the integrity of PHI.

Centralized access governance is another critical component of HIPAA compliance. This ensures that access to protected health information is granted only to authorized healthcare providers, minimizing the risk of data breaches. Access logging and automated reporting mechanisms further enhance healthcare data security, allowing organizations to track and monitor access to patient records and generate comprehensive audit reports for HIPAA compliance purposes.

The DPDP Act, 2023 Compliance

·        Data Fiduciary Obligations: Organizations (Data Fiduciaries) must implement reasonable security safeguards to prevent personal data breaches, making strict logical and physical access controls a statutory mandate.

·        Purpose Limitation: Access to personal data must be strictly limited to the specific purpose for which the individual (Data Principal) gave consent.

·        Notice and Consent Management: Access control systems must integrate with consent management modules to dynamically revoke or grant employee access based on the user's current consent status.

·        Significant Data Fiduciaries (SDFs): If classified as an SDF by the government, your organization must appoint an independent Data Auditor to review your access logs and security frameworks regularly

CERT-In Cyber Security Directions

·        Mandatory Logs: Under the CERT-In directives, companies must securely maintain ICT system logs for a rolling period of 180 days.

·        Local Time Synchronization: All access control logs, server timelines, and identity management systems must connect to a standard time source using National Informatics Centre (NIC) or National Physical Laboratory (NPL) time servers to ensure legally defensible forensics.

·        Incident Reporting: Any unauthorized access that leads to a cyber incident or data breach must be reported to CERT-In within 6 hours of identification

Sector-Specific Regulations

·        Banking and Finance (RBI): The Reserve Bank of India mandates strict multi-factor authentication (MFA), role-based access control (RBAC) for core banking systems, and continuous privilege access management (PAM) monitoring.

·        Healthcare (DISHA / ABDM): Under the Ayushman Bharat Digital Mission, access to electronic health records requires patient consent, explicit digital signatures, and granular view-only permissions for medical practitioners.

Core Legal & Technical Principles

·        Principle of Least Privilege (PoLP): Users and devices must be given the minimum level of access required to perform their duties, preventing privilege creep and reducing the impact of a breach.

·        Identity and Access Management (IAM): Automating provisioning and deprovisioning is legally critical. Lingering access for former employees is one of the most common grounds for liability in negligence claims following a data breach.

·        Audit and Accountability: Legal defensibility requires undeniable proof of due diligence. Systems must log all access attempts, approvals, and denials, and keep this data secured against tampering

Legal Liabilities for Non-Compliance

·        Statutory Penalties: The DPDP Act penalises the failure to observe reasonable security safeguards to prevent data breaches with fines up to ₹250 Crore.

·        Criminal Liability: Section 66C (Identity Theft) and Section 66D (Cheating by Personation) of the Information Technology Act apply directly to individuals using stolen or unauthorized access credentials

Life Safety & Hardware Fail-Safe Integrity

·        Wire Fail-Safe Locks: Ensure all electromagnetic locks on emergency exit routes are wired as Fail-Safe (loss of power automatically cuts lock magnetism to open the door).

·        Integrate Fire Alarm Override: Connect the central Fire Alarm Control Panel (FACP) directly to the PACS power supplies via a physical relay. Triggering a fire alarm must cut power to all access-controlled exit doors instantly, independent of software status.

·        Install Break-Glass Units: Place green, emergency break-glass manual overrides next to every secured exit door along the evacuation route to bypass software crashes.


Tuesday, April 1, 2025

26-Bit Wiegand Format & Work

26-Bit Wiegand Format & Work? 

The name “Wiegand” comes from its creator, the German-born engineer, John R. Wiegand, who in the 1970’s discovered that wires made of a cobalt, iron and vanadium alloy will switch polarity when run through strong magnetic fields. Placing a sensor coil nearby will be capable of picking up the change in polarity as a high-voltage pulse, and then translate that pulse into data. He used these discoveries to create what became known as Wiegand wires and Wiegand cards.

A Wiegand card uses two short wires, which store data magnetically in the card; these two wires are known as Data low, or Data0 and Data high, or Data1. When the card is pulled through the reader, the wires transmit the either high or low voltage signal as 1 and 0’s, respectively, creating a binary data line for authenticating the swipe card’s credentials. (There actually is a third wire, as well, providing common ground).

There are a few different variations of the Wiegand protocol in existence, but the original is the most common, known as the 26-bit Wiegand format, or often just the 26-bit format. This is a very common open format, meaning that virtually anyone can buy compatible cards and readers and program them to work using the 26-bit Format. It uses one parity bit, followed by 8 bits of facility code, 16 bits of ID code, and another trailing parity bit, for a total of 26 bits. This was the standard for a long time and remains in use in many systems, though a variety of different extensions have now been built off it.

Card readers and other components of access control systems need to speak a common language to function and work properly. Like most other forms of technology, access control systems use a binary number system to communicate. One of the most common formats for access systems is the 26-bit Wiegand format. It was first developed over 50 years ago, and because it’s so simple and accessible, it’s still used today.

What is the 26 bit Wiegand format, how does it work, and where is it used? Learn more below. 

What is 26-Bit Wiegand Format? 

The 26-bit Wiegand format is a format for binary encoded data used mainly on access control devices. It’s an extremely common open format, and most access control systems are automatically designed to be able to read 26-bit Wiegand. Because it’s an open format, anybody can buy and use cards in this format, and it is possible for duplicate cards to exist.

Although various companies make access control systems, one of the most popular brands is HID. The brand is so popular that people often refer to any access control system as an HID system. However, various brands and manufacturers make 26-bit Wiegand format access cards, not just HID. If you buy or use any basic access system, it’s highly likely that the system runs using the 26-bit Wiegand format.

Key Features of the 26-Bit Wiegand Format

  1. 26-Bit Data: The format consists of 26 bits, divided into three parts: 8 bits for the facility code, 16 bits for the card number, and 2 bits for parity.
  2. Facility Code: The first 8 bits represent the facility code, which identifies the site or organization.
  3. Card Number: The next 16 bits represent the card number, which is unique to each cardholder.
  4. Parity Bits: The last 2 bits are parity bits, used for error detection.
  5. Even/Odd Parity: The parity bits use even/odd parity, where the first parity bit is the even parity of the first 12 bits, and the second parity bit is the odd parity of the last 12 bits.

This format is an industry standard known as H10301. The term “bit” refers to the numbers in the code, so each code consists of 26 numbers. Wiegand refers to the Wiegand protocol, which is the name for the wiring standard. It’s named after John R. Wiegand, whose discoveries in the 1970s laid the basis for the standard 26 bit format. 

The first and last numbers in the 26-bit Wiegand format are beginning and ending bits known as parity bits. They are not part of the unique identification laid out in the code. Bits two through nine make up the facility code. The facility code consists of eight bits. Bits 10 through 25 make up the ID number. The ID number consists of 16 bits. 

Here is how the code in 26-bit Wiegand appears when P stands for parity bit, F stands for facility code bit, and I stands for ID number bit: 

PFFFFFFFFIIIIIIIIIIIIIIIIP

The 26-bit Wiegand format allows for 256 possible facility codes and 65,535 possible ID numbers. When combining both unique identifiers, this allows for 16,711,425 unique access cards.

The 26-bit Wiegand format consists of a sequence of 26 bits, divided into three main parts:

·        Facility Code (FC): The first 8 bits (bits 1-8) represent the facility code, which identifies the specific facility or organization issuing the card.

·        Card Number (CN): The next 16 bits (bits 9-24) represent the card number, which is unique to each cardholder.

·        Parity Bit (PB): The last 2 bits (bits 25-26) are parity bits, used for error detection.

Rather than being written out with numbers or letters as in the example above, the code is represented in an access card or other access device with a series of wires. We’ll explain more about how that works below.

How Does 26-Bit Wiegand Format Work? 

Back in the 1970s, Weigand discovered that cobalt, iron, and vanadium alloy wires switch polarity when they enter a magnetic field. He also found that sensor coils can pick up the change in polarity. This laid the groundwork for the modern Weigand protocol where access card readers are able to translate and read the code that lies hidden in the wires inside access devices. 

26-bit Wiegand access cards have three wires inside: data low (data0), data high (data1), and a ground wire. Because binary numbers are expressed as 0 or 1, data0 and data1 are used to create those binary numbers that the access control system can read. When the data0 wire transmits a signal, the computer reads it as 0, and when the data1 wire transmits a signal, the computer reads it as 1. The wires are uniquely designed to create a different code for each cardholder.

When a device that’s encoded with the format passes through the field of a card reader, it picks up on the unique sequence of bits contained in the device. Then, it grants access if the facility code and ID number in the device are allowed access. Of course, the system can also deny access if the code in the card or other access device does not match an approved code.

Here's a step-by-step explanation:

1.   Card Swipe: A user swipes their access control card through a reader.

2.   Data Extraction: The reader extracts the 26-bit Wiegand code from the card's magnetic stripe or RFID chip.

3.   Bit Transmission: The reader transmits the 26-bit code, one bit at a time, to the access control panel or secure authentication device.

4.   Bit Representation: Each bit is represented by a specific voltage or signal level, with 0 volts typically representing a binary 0 and 5 volts representing a binary 1.

5.   Data Format: The 26-bit code consists of:

·        Facility Code (8 bits): Identifies the facility or organization issuing the card.

·        Card Number (16 bits): Unique to each cardholder.

·        Parity Bits (2 bits): Used for error detection.

6.   Authentication: The access control panel or secure authentication device verifies the received 26-bit code against stored data, ensuring the facility code, card number, and parity bits match.

7.   Access Decision: If the verification is successful, the device grants access or performs the desired action.

Where Is the 26-Bit Wiegand Format Used?

The 26-bit Wiegand format is most often used in standard access control systems. You’ll find wires corresponding to the 26 bits in access cards, key fobs, fingerprint readers, and other access control devices. 

The data on a standard Wiegand-formatted device is not encrypted. This, of course, presents a vulnerability and is one of the reasons this format has lost some of the popularity it previously held. It’s also possible for duplicate 26-bit Weigand access devices to exist, which is a major concern for industries that highly value security. 

You’ll often find access control systems that use the 26-bit Wiegand format in older buildings because it was once the gold standard. Unless there is a malfunction in the equipment, there isn’t often an immediate need for companies to upgrade to a different format even though the 26-bit Wiegand format is becoming a bit outdated. It still works very well for most use cases. 

However, newer buildings and newer access control systems are beginning to favor different formats, such as Open Supervised Device Protocol (OSDP). This can increase security because it is encrypted. For this reason, you’re also less likely to find 26-bit Wiegand formats in buildings and campuses where security is of utmost importance.

Nonetheless, the 26-bit Wiegand format is still used today for many reasons. It’s easy to use, it’s readily available, and most card reader door locks and access control systems are equipped to read the format. If you purchase or install an access control system and you don’t specify or request a particular format, it’s likely your system uses the 26-bit Wiegand format.

Advantages of the 26-Bit Wiegand Format

  1. Wide Compatibility: The 26-bit Wiegand format is widely supported by access control systems and RFID readers.
  2. High Security: The use of parity bits and a large data format provides high security against data tampering and unauthorized access.
  3. Easy Implementation: The 26-bit Wiegand format is easy to implement and integrate with existing access control systems.
  4. Scalability: The 26-bit format provides a large address space, allowing for a high number of unique card numbers and facility codes.

Limitations of the 26-Bit Wiegand Format

  1. Limited Data Capacity: The 26-bit Wiegand format has limited data capacity, which can make it difficult to store additional data, such as biometric information.
  2. No Encryption: The 26-bit Wiegand format does not provide encryption, which can make it vulnerable to eavesdropping and data interception.


Friday, January 1, 2021

Upcoming Trends in security & surveillance for 2021

Upcoming Trends in Security & Surveillance for 2021 

It’s fair to say 2020 has not been the year any of us were expecting. It has been challenging, we have all made sacrifices, and there are still further obstacles in our path as we try to get back to “normal”. SARS-CoV-2, the coronavirus strain that causes COVID-19, is a highly contagious respiratory illness that is affecting lives worldwide. Epidemics and pandemics have been threatening the human race time and again. SARS, H1N1, Ebola, and more have shown their teeth in the past, but with each such outbreak, we are learning new ways of fighting and managing such unexpected diseases that can potentially kill millions of people. Technology cannot prevent the onset of the pandemics; however, it can help prevent the spread, educate, warn, and empower those on the ground to be aware of the situation, and noticeably lessen the impact. The pandemic of 2020 has certainly changed the landscape for us all, not just the security industry. It has made us a lot more aware of touch points, crowded gatherings and personal space. It is inevitable that technology will adapt as our lives do. We have already seen manufacturers race to bring us solutions such as body temperature management, face mask detection and crowd control etc. It’s time to change. It’s time to get better. It’s time to learn more and sharpen our skills.’

During pandemic Webinar is boom through Zoom. Google meet, Gotowebiner etc in security safety automation industry. System Integrator, End Users, professionals are learn many things through OEM direct Webinar. US already ban China made surveillance product. In india Atmanirbhar Bharat (self-reliant India) is the vision of the Prime Minister of India Narendra Modi of making India a self-reliant nation. The first mention of this came in the form of the 'Atmanirbhar Bharat Abhiyan' or 'Self-Reliant India Mission' during the announcement of the coronavirus pandemic related economic package on 12 May 2020. Known china CCTV OEM are thrown out. Yes, it’s true, India don’t have much infrastructure to generate Camera manufacturing plant, it will take time at list 5 year. Within this time, we can follow BIS website to get information about selected camera / NVR model are china factory make or not. Low cost and high cost both option camera you can found. If you found that model belongs to china factory immediately change with Closest or Alternative Substitute. Now we check what will be next in 2021 for Security Safety & Automation.

OSHA new Policy:

The COVID-19 outbreak has caused almost all firms to deploy the work from home practice for employees. While some may be used to this, others may feel lost in the exercise. While not all Indian are able or fortunate enough to work from home, many have transitioned to telecommuting and virtual work over the last week or two.

While employers’ responsibilities for the safety and health of their at-home workers is less than those in the office or onsite, some do still exist. OSHA distinguishes between home offices and other home workplaces.
OSHA’s compliance directive on home offices is pretty clear:
·     “OSHA will not conduct inspections of employees’ home offices.
·     “OSHA will not hold employers liable for employees’ home offices, and does not expect employers to inspect the home offices of their employees.
·   “If OSHA receives a complaint about a home office, the complainant will be advised of OSHA’s policy. If an employee makes a specific request, OSHA may informally let employers know of complaints about home office conditions, but will not follow-up with the employer or employee.”
What about recording injuries while working at home? If an employee is working at home, when could the injury be considered work-related? OSHA answers the question:
How do I decide if a case is work-related when the employee is working at home? Injuries and illnesses that occur while an employee is working at home, including work in a home office, will be considered work-related if the injury or illness occurs while the employee is performing work for pay or compensation in the home, and the injury or illness is directly related to the performance of work rather than to the general home environment or setting.

Video Intercoms:

One of the newer phenomena we’ve faced in the world has been the concept of physical distancing, brought to light by the global coronavirus pandemic. This has created challenges not only socially, but for technologies that were not designed to accommodate what may be the new norm. Video intercoms are really going to be playing a bigger part in the way facilities are organized and processes are organized. We’re seeing some customers that are using this to limit having to actually go inside a room in a healthcare facility, for example, to limit the chances of transmitting something all while maintaining that frequency of checking. One of the main benefits of door intercoms is, simply put, the ability to limit — or even eliminate — human contact at the door. In this pandemic, an immediate need is providing [the customer with] a way to create physical distancing upon entry. This can also be applied to healthcare workers. Integrators have to understand this greater demand for security at the door and deliver solutions to their customers. Everybody is having food, groceries and other things delivered to their door. Demand for that is very high right now. Additional security at the door or the gate is something people want and need.

Home Over IP:

Amazon, Apple, Google and the Zigbee Alliance announced a new working group that plans to develop and promote the adoption of a new, royalty-free connectivity standard to increase compatibility among smart home products, with security as a fundamental design tenet. Zigbee Alliance board member companies such as IKEA, Legrand, NXP Semiconductors, Resideo, Samsung SmartThings, Schneider Electric, Signify (formerly Philips Lighting), Silicon Labs, Somfy and Wulian are also on board to join the working group and contribute to the project. The goal of the Connected Home over IP project is to simplify development for manufacturers and increase compatibility for consumers. The project is built around a shared belief that smart home devices should be secure, reliable and seamless to use. By building upon IP, the project aims to enable communication across smart home devices, mobile apps and cloud services, and to define a specific set of IP-based networking technologies for device certification.

Video Surveillance:

The global CCTV camera market is anticipated to generate substantial revenue of more than to USD 38 billion till 2021. Asia Pacific and America holds the largest share of the global market and act as one of the main driver for the market. According to “India CCTV Camera Market Outlook, 2021”, the India CCTV Camera market is expected to grow with a CAGR of more than 26 % in the period from 2016 to 2021. Technology wise non-IP dominates the Indian market but in the coming years IP is expected to take the lead soon. Non -IP technology constitutes of analog and HD CCTV cameras. Analog is technology which is in a depleting stage and it share is expected to be taken by the IP technology and the HD type CCTV camera. Dome typed cameras are the most widely used cameras in any sectors. Commercial segment is the driver of the CCTV market in India with the increasing count of SOHO’s and SME’s. With the increasing security concerns, residential sector would also be one of the factors for the increasing market. As criminal activities are more in the northern region of India, North dominates the market in terms of revenue.

Facial Recognition:

Facial recognition is the common theme of the week’s top digital identity news with retail applications, new edge servers, and biometric border control deployments around the world. A new software partnership on biometric cryptography has also been announced, a report shows the importance of selfie biometrics in fraud reduction published, and the industry, as well as society more broadly, continues to contend with the issue of algorithmic bias. Facial recognition solutions identify a person by forming a unique code built on algorithms from multiple points on a person’s face, including nose, chin, lips, eyes and jaw. However, when a person wears a mask, many of these key points are not visible. Faces were often completely missed, and unsuccessful or false identifications were high. Those are know this wearing masks can reduce the accuracy they avoid to take Facial recognition

Video Verification:

The city currently has over 1,000 video surveillance cameras deployed across the metropolitan area and is expected to reach over 1,700 security devices. Now it’s very difficult to watch every moment on comment control center. It’s very important to see what camera saw. Through Video Auditing software the task are easy. Day by day its increase.

Rise of Mobile Credentials:

There has been a tremendous uptick in the popularity of mobile credentials. Research firm IHS Markit has reported that mobile-based credentials are the fastest-growing access control product. Globally they have experienced nearly a 150 percent growth between 2017 and 2018. Estimates show that more than 120 million mobile credentials will be downloaded in 2023 by end users. A 2019 survey by HID estimated that 54% of businesses had upgraded or would upgrade to a mobile access control system in the next three years. Though access cards still play a powerful role in the access control market, we are seeing a strong shift towards mobile access control like various companies. The use of mobile-based credentials is the logical next step for the physical security and access control industry. The fact that people are always with their smartphone helps popularise this trend. Phones aren’t just phones anymore. They play a bigger role in day-to-day life and this also includes access control. Mobile credentials can revolutionise the industry, eliminating the need to carry and wipe a card. Instead, a phone’s technology can be used to authenticate identity and grant entry. This gives greater flexibility, improves privacy and can also lower the maintenance costs of credential management for end users. Additionally, a clear advantage is that employees are more likely to carry their smartphone with them and less likely to lose them compared to NFC transponders.

The advantages of using virtual access control cards, which are stored on smartphones, are obvious: less logistics when distributing, revoking or replacing cards and many more ways to integrate with technology on the phone or other hosts and devices in the network. Often also the user experience of mentioned as a benefit of mobile access: users do not have to fill up their wallets with a pile of RFID cards but can conveniently carry them around in their phone. The networking capacity of smartphones would even be a great way to overcome the limitations of offline access control installations where access rights would be stored on smartphones instead of cards.

Security in the cloud:

After the entrance of IP-networking in security around twenty years ago, it is one of the major current trends in our industry: cloud based security systems. In the context of physical security one could define cloud based systems as those systems with a topology that looks like this:
·       A server that is ‘in the cloud’ and can be accessed from virtually anywhere;
·       Devices that connect over an IP-network to that central server;
·       Web based administration of the system;
·       Commercially based on a service or transaction model with recurring fees.
Variations exist. But in general this pretty much sums up what to expect when reviewing a cloud based system.
We see this set-up currently already in several categories:
·               Video Intercom Systems, like the systems from Akuvox, which are based on video intercom stations that connect to a cloud based server, which also enables use of apps as virtual door phones.
·   Mobile access systems that enable the use of virtual credentials on smartphones. and that are managed from a cloud based server.
·               Video management software now also is offered by several vendors as a cloud service, for example: 3dEYE, Open Eye, and VIVOTEK.

IoT security topologies:

The Internet of Things idea has been around for ages. It was predicted over a decade ago that billions of device will connect to the Internet. Sensors all around us will deliver data to the cloud. Feeding data into ‘big data’ processing applications that will give us access to a wealth of information. Devices also connect the cloud. To be part of applications that can be used and managed from virtually any location. For security it would mean that it very much is related to cloud based security applications. The additional step here would be that camera’s, readers, intercoms, intrusion detection sensors and biometric stations would connect directly to the cloud based service. Installations would be easier and more scalable. Access control systems could be deployed at any door and still be real online access control systems. Video surveillance would be available at any location that would require security monitoring. Security sensors and devices can be rolled out everywhere.

Smartphones and wearables

Using smartphones or other wearable devices in security has been a popular idea for many years. Smartphones and tablets often can be used to access the administration Interface (GUI) of the access control, video management or PSIM systems. That hardly is considered an innovation. Smartphones can also be used as virtual access control and identity cards in mobile acess systems. In addition it appears that also biometrics like facial recognition and fingerprint identification are now available on smartphones. It appears logical that smartphones with their native connectivity features are an interesting extension of security systems.
Mobile credentials enable both multimodal and multi-factor authentication. Multimodal means proving identity and/or gaining access using at least two separate biometrics, or permitting access through any one of various credentials, such as a smartcard or PIN. Multi-factor authentication involves proving identity and/or obtaining access via at least two methods or credentials. Multi-factor authentication is widely used in digital access. For example, when an employee logs onto a company’s system, he or she must use a secondary method to verify identity via a one-time token via SMS or other app. It is also burgeoning in physical access applications. Although two-factor authentication has been mandated in regulated industries, it is emerging in unregulated verticals as well. The development of multimodal readers will continue to fuel this trend.
Believers say that people prefer carrying around their smartphone over additional cards. They refer to the technical possibilities that smartphones offer in areas like user convenience and integration of systems.

Identity analytics and AI

A relatively new field in security is identity analytics. Seeing through identity and security related data in an automated way. To monitor use of access priviliges and consequently alter those access rights. The idea comes from the IT industry and that is where you will see it deployed mostly now. Recent research indicates that this is an emerging market with high anticipated growth potential. It would make sense to include physical security into these applications.
Believers will say that, like with video analytics, many more security related events can be actively monitored, more incidents can be detected and a tighter security regime can be implemented without hindering users unnecessarily.
It remains to be seen what the future will bring exactly. But intelligent security related data analytics certainly will have a place in modern enterprise security management applications.

Centralized Control of Fire Detection:

The principle of networking involves connecting several panels together to form a system. Inputs on one panel may activate outputs on another, for example, or the network may allow monitoring of many systems. Networking is often used in situations where one panel is not large enough, or in multiple-building situations. Networking is also an effective way to decouple systems to reduce the risk of a large portion of a facility going offline at any time due to system failure or maintenance requirements. Sub-Networks can be created using either hardware or software architectures. Networked systems normally are more costly and involve additional training and system configuration for successful implementation.


From this year many customer implement centralised monitoring & controlling of Fire Panel through creating WLAN communication with Graphic software. Due to cost effective graphical monitoring control software only industrial & Enterprise business implement the same. Also it will possible if same brand panel is there in all location.

BMS Workforce:

The growth of IBMS market is observing hindrance due to lack of availability of skilled workforce. The Intelligent building management systems are usually complex and require skilled personals to operate. The cost of training operators to handle complex equipment such as HVAC control, outdoor controls, security and access control, energy management systems and smart meters is quite high. Owing to which, small scale companies cannot afford to invest large capital to train their operators. This factor is likely to affect the growth of the IBMS market in the country.
But due to COVID-19 many OEM & society presence webinar program to educate more. This will be effect in this 2021-22. The region segmentation for the IBMS market has been done by South IndiaWest IndiaNorth IndiaEast India. Which include general lighting controls, communication systems, security controls, HVAC controls, access controls, outdoor controls entertainment controls and others. The India IBMS market is segmented by application into: hospitality, residential and retail, life science, office space, manufacturing, and energy and infrastructure. All these segments have also been estimated on the basis of geography in terms of revenue (USD Million).

The goal of building management systems was—and still is—to help optimize building performance by

·       Providing data on core building operational systems, specifically HVAC. 

·       Enabling the automatic control of a building’s main operating functions. 

IoT for buildings has the same goal of performance optimization (and by extension, saving money) through data and automatic control, but advanced technology takes these aspects many steps further than a traditional BMS system can. 

We wish you all the very best for 2021 and we look forward to working with you for many years to come.