
Physical and logical access control often run on separate systems: one badge for the door, another method for the login. In this post, I explain why it pays off to look at both together. First, I will explain the difference, and then I will discuss the advantages of such a combined solution for companies. Finally, I present the solution that Swissbit offers.
Identity and Access Management (IAM) is an integral building block in a defense in depth security strategy. Simplified, the IAM system with its policies defines which user has access to which resources.
It also defines which type of authentication is required to get access to a specific resource. Some might require no authentication at all, while others require strong multi-factor authentication using FIDO or an authentication method based on certificates.
All that is required to protect organizations from data leakage, unauthorized change of data or even attacks against the availability of systems. But is that enough?
Of course not! A holistic defense in depth strategy requires more than logical/digital identity access management – it also requires that the access of individual users to physical objects, like buildings, floors and individual rooms needs to be managed and controlled as well.
Logical access governs who may sign in to computers, applications and cloud services. Physical access governs who may enter buildings, floors and rooms. The industry terms are logical access control (LAC) and physical access control (PAC). When both are managed through one shared identity, this is often called PIAM (physical identity and access management).
| Logical access | Physical access | |
|---|---|---|
Protects | Computers, applications, cloud services, data | Buildings, floors, rooms, parking |
Typical credentials | Password, MFA, FIDO2 security key, smart card | Access card, transponder, key |
Typical technology | FIDO2/WebAuthn, PIV, OTP | MIFARE DESFire, LEGIC, HID Seos |
Owned by | Usually IT or IT security | Usually facility management or site security |
Currently, two developments can be observed in the market. First, there is a constantly growing demand for increasingly secure authentication solutions. This applies to both the logical/digital access such as workstation access or logins to cloud services as well as the physical access to the workplace itself.
Second, organizations require authentication methods which are secure by design and not prone to typical attacks such as phishing or man in the middle attacks. The increasing acceptance of the FIDO2 standard in enterprise environments is a clear signal: The commitment to passwordless, phishing-resistant authentication is key to success in the logical/digital IAM space.
However, organizations began to understand, that logical/digital access can be combined with physical access control. In the past, for example, large companies have introduced access cards to manage physical access. Sometimes these cards could be used for logical/digital access. This required in most cases the rollout of separate smart card readers.
Sometimes the physical access card couldn’t be used for logical/digital access at all which led to a conceptual separation of logical and physical authentication in the minds of users.
And while every employee always took their physical access card with them to be able to move through the building, the logical/digital access card was left in the workstation, which in the worst case was left unlocked.
And this is precisely where Swissbit with its next-generation FIDO and multiprotocol security keys, the iShield Key 2 series comes into play.
It eliminates the need for external readers, requires user interaction for verification and provides feedback via LED indicators, closing the usability and security gaps of legacy systems. It also provide reliable support for MIFARE DESFire, LEGIC or HID based physical access systems.
To sign in, users plug the key into a USB-A or USB-C port or hold it against a laptop or smartphone via NFC. Besides FIDO2 and passkeys, it supports PIV certificates and one-time passwords (OTP).
In other words: The iShield Key 2 combines physical and logical/digital access control in one robust device.
With reliable hardware for secure access, Swissbit helps companies stay in control of their digital sovereignty. The iShield Key 2 is at the forefront.
It is the first FIDO security key with MIFARE DESFire EV3 and combines digital and physical access control in one device, Swissbit’s answer to growing cyber and physical security requirements.
The iShield Key 2 provides strong FIDO2 authentication and enables secure building access with a compact, robust USB token. Additionally, the device supports secure updates via encrypted channels, enabling companies to deploy on-site firmware and new applications, thereby maximizing flexibility and ensuring future compatibility.
As cyber threats increase and work environments become more hybrid, evolving regulations such as NIS2, DORA, the Cyber Resilience Act (CRA), the German KRITIS Regulation (KRITIS-V), OMB M-22-09, and the U.S. Executive Order on Cybersecurity require organizations to have strong, flexible authentication tools.
With its FIDO2-compliant iShield Key 2 series, which includes the first FIPS 140-3 Level 3-certified security key on the market, Swissbit serves organizations in all industries as well as federal agencies and organizations implementing Zero Trust architectures.
Yes, if it includes an access control technology. The iShield Key 2 is available with MIFARE DESFire EV3, LEGIC or HID Seos and works with existing access control systems, without replacing door readers.
No. The iShield Key 2 plugs into a USB-A or USB-C port or connects via NFC. Separate smart card readers are not needed.
Both regulations call for strong authentication and well-designed access management. A phishing-resistant FIDO2 key that also controls building access covers digital and physical controls with one credential and makes compliance easier to document.
Receive the latest news and announcements about storage and security solutions as well as current events and new products.