Physical and logical access control in one security key

by Jan Quack
Physical and logical access control in one security key

Physical and logical access control often run on separate systems: one badge for the door, another method for the login. In this post, I explain why it pays off to look at both together. First, I will explain the difference, and then I will discuss the advantages of such a combined solution for companies. Finally, I present the solution that Swissbit offers.

What Identity and Access Management Does 

Identity and Access Management (IAM) is an integral building block in a defense in depth security strategy. Simplified, the IAM system with its policies defines which user has access to which resources.

It also defines which type of authentication is required to get access to a specific resource. Some might require no authentication at all, while others require strong multi-factor authentication using FIDO or an authentication method based on certificates.

All that is required to protect organizations from data leakage, unauthorized change of data or even attacks against the availability of systems. But is that enough?

Physical vs. Logical Access: The Difference

Of course not! A holistic defense in depth strategy requires more than logical/digital identity access management – it also requires that the access of individual users to physical objects, like buildings, floors and individual rooms needs to be managed and controlled as well.

Logical access governs who may sign in to computers, applications and cloud services. Physical access governs who may enter buildings, floors and rooms. The industry terms are logical access control (LAC) and physical access control (PAC). When both are managed through one shared identity, this is often called PIAM (physical identity and access management).

Logical accessPhysical access
Protects
Computers, applications, cloud services, data
Buildings, floors, rooms, parking
Typical credentials
Password, MFA, FIDO2 security key, smart card
Access card, transponder, key
Typical technology
FIDO2/WebAuthn, PIV, OTP
MIFARE DESFire, LEGIC, HID Seos
Owned by
Usually IT or IT security
Usually facility management or site security

Growing Demand for Unified Access Management

Currently, two developments can be observed in the market. First, there is a constantly growing demand for increasingly secure authentication solutions. This applies to both the logical/digital access such as workstation access or logins to cloud services as well as the physical access to the workplace itself.

Second, organizations require authentication methods which are secure by design and not prone to typical attacks such as phishing or man in the middle attacks. The increasing acceptance of the FIDO2 standard in enterprise environments is a clear signal: The commitment to passwordless, phishing-resistant authentication is key to success in the logical/digital IAM space.

However, organizations began to understand, that logical/digital access can be combined with physical access control. In the past, for example, large companies have introduced access cards to manage physical access. Sometimes these cards could be used for logical/digital access. This required in most cases the rollout of separate smart card readers.

Sometimes the physical access card couldn’t be used for logical/digital access at all which led to a conceptual separation of logical and physical authentication in the minds of users.

And while every employee always took their physical access card with them to be able to move through the building, the logical/digital access card was left in the workstation, which in the worst case was left unlocked.

How the iShield Key 2 Combines Door and Login 

And this is precisely where Swissbit with its next-generation FIDO and multiprotocol security keys, the iShield Key 2 series comes into play.

It eliminates the need for external readers, requires user interaction for verification and provides feedback via LED indicators, closing the usability and security gaps of legacy systems. It also provide reliable support for MIFARE DESFire, LEGIC or HID based physical access systems.

To sign in, users plug the key into a USB-A or USB-C port or hold it against a laptop or smartphone via NFC. Besides FIDO2 and passkeys, it supports PIV certificates and one-time passwords (OTP).

In other words: The iShield Key 2 combines physical and logical/digital access control in one robust device.

Benefits of Unified Access Management 

  • Foundation for a defense-in-depth architecture on which a zero-trust strategy can be built: Converged access contributes to a zero-trust architecture by ensuring that access to sensitive systems depends not just on login credentials, but also on physical presence in a verified location.
  • Company (cyber-) security is strengthened: Security benefits by implementing a more holistic approach to access controls. Security Operations can benefit from integrated systems that can consolidate monitoring of security events and improve incident response.
  • Improved user-friendliness for employees: User experience improvements by simplifying access by providing users with a single credential to manage. This has historically been a driving factor for issuing dual-interface smart cards or leveraging iOS and Android apps when smartphones are managed by the organization.
  • No conceptual separation between logical and physical access: Helping to improve user acceptance and awareness.
  • Simpler onboarding and offboarding: New employees receive one credential for the door and the login. When someone leaves, IT revokes both with that one token.
  • Financial benefits: By converging physical and logical access controls into a single token, less hardware is required to be purchased, resulting in lower costs, also less efforts to manage logical/digital and physical access tokens.

Swissbit's Hardware Authentication Solutions for Companies 

With reliable hardware for secure access, Swissbit helps companies stay in control of their digital sovereignty. The iShield Key 2 is at the forefront.

It is the first FIDO security key with MIFARE DESFire EV3 and combines digital and physical access control in one device, Swissbit’s answer to growing cyber and physical security requirements.

iShield Key 2: FIDO2, Building Access and Secure Updates 

The iShield Key 2 provides strong FIDO2 authentication and enables secure building access with a compact, robust USB token. Additionally, the device supports secure updates via encrypted channels, enabling companies to deploy on-site firmware and new applications, thereby maximizing flexibility and ensuring future compatibility.

As cyber threats increase and work environments become more hybrid, evolving regulations such as NIS2, DORA, the Cyber Resilience Act (CRA), the German KRITIS Regulation (KRITIS-V), OMB M-22-09, and the U.S. Executive Order on Cybersecurity require organizations to have strong, flexible authentication tools.

With its FIDO2-compliant iShield Key 2 series, which includes the first FIPS 140-3 Level 3-certified security key on the market, Swissbit serves organizations in all industries as well as federal agencies and organizations implementing Zero Trust architectures.

Physical and Logical Access: Frequently Asked Questions

Yes, if it includes an access control technology. The iShield Key 2 is available with MIFARE DESFire EV3, LEGIC or HID Seos and works with existing access control systems, without replacing door readers.

No. The iShield Key 2 plugs into a USB-A or USB-C port or connects via NFC. Separate smart card readers are not needed.

Both regulations call for strong authentication and well-designed access management. A phishing-resistant FIDO2 key that also controls building access covers digital and physical controls with one credential and makes compliance easier to document.

One key for the door and the login?
Jan Quack

Jan Quack worked as a Senior Solution Engineer at Swissbit, having joined the company in February 2025. He brought 20 years of professional experience, including 15 years specializing in PKI, IAM, FIDO, and Passwordless Authentication. In his role, he worked with organizations to enhance security and streamline authentication strategies, always focusing on practical, real-world solutions. With a passion for making complex topics accessible, Jan has shared insights through keynotes, workshops, and consultations, helping businesses adopt modern authentication practices in an ever-evolving digital landscape.

Follow him on LinkedIn

Sign up for the Swissbit newsletter

Receive the latest news and announcements about storage and security solutions as well as current events and new products.