{"id":74933,"date":"2026-09-12T08:08:43","date_gmt":"2026-09-12T11:08:43","guid":{"rendered":"https:\/\/a3aengenharia.com\/?post_type=articles&#038;p=74933"},"modified":"2026-09-12T08:08:43","modified_gmt":"2026-09-12T11:08:43","slug":"multifactor-authentication-physical-access-control","status":"publish","type":"articles","link":"https:\/\/a3aengenharia.com\/en-us\/content\/technical-articles\/multifactor-authentication-physical-access-control\/","title":{"rendered":"Multifactor Authentication in Physical Access Control: Card, PIN, Biometrics, and Design Criteria"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Multifactor authentication in physical access control requires two or more independent pieces of evidence before passage is authorized. At a door, turnstile, mantrap, or other controlled point, this may mean combining a card and PIN, a mobile credential and biometrics, a card and biometrics, or another combination consistent with the risk. The objective is not simply to add a second step: it is to reduce the likelihood that a single lost, copied, shared, or compromised credential will be sufficient to release a critical area.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the design of an EACS \u2014 Electronic Access Control System \u2014 MFA must be treated as an engineering requirement. It is necessary to define where two factors are actually required, which combinations are accepted, in what order they are presented, how the system behaves offline, how flow and accessibility are handled, which exceptions are permitted, which events must be logged, and how all of this will be demonstrated during FAT, SAT, and commissioning. Applying MFA without this architecture can produce queues, false rejections, operational bypasses, and contingencies that weaken the very control intended to be strengthened.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">IEC 60839-11 provides the functional framework for physical electronic access control, while digital identity references such as NIST SP 800-63B help organize the concept of independent factors. These sources are not interchangeable: login authentication and authentication at a door have different operational requirements. Physical access design must additionally address controllers, readers, actuators, door sensors, continuity, emergency operation, anti-passback, passage capacity, integration, and field evidence.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">What MFA means in a physical access control system<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An access point typically executes a chain of actions: it receives an entry request, identifies or verifies a person, checks authorization rules, commands the physical point, and records the result. MFA appears when policy requires more than one category of evidence before authentication is considered sufficient.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The three classic categories are:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>something the person has<\/strong>, such as a smart card, mobile credential, or token;<\/li><li><strong>something the person knows<\/strong>, such as a PIN or another memorized secret;<\/li><li><strong>something the person is<\/strong>, such as a fingerprint, face, or palm, when biometrics is appropriate to the context.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Two methods from the same category do not necessarily create multifactor authentication. Two cards are still two pieces of possession evidence; two memorized questions are still knowledge. The gain comes from factor independence and the difficulty of compromising both through the same attack vector.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Identification, authentication, and authorization are different decisions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A user&#8217;s ID number may only locate a record. A card may identify the person or act as an authenticator, depending on the architecture. Biometrics may verify an identity already indicated by another credential or perform 1:N identification against a gallery. And even after the identity is authenticated, the person may still not be authorized for that area, time, or operating state.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This separation must appear in the event model. A denial due to an incorrect PIN is not the same as a denial due to schedule, anti-passback, or lack of privilege. Collapsing everything into \u201caccess denied\u201d makes investigation, maintenance, and auditing more difficult.<\/p>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">In critical areas, the decision to require two factors must come from risk analysis, flow capacity, and failure behavior \u2014 not from the reader catalog.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/programa-necessidades-requisitos-engenharia\/\">Structure system requirements<\/a><\/p>\n<\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\">Physical MFA is not the same as login MFA<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">NIST SP 800-63B-4 organizes digital authentication into factors and assurance levels. The concept of requiring distinct factors is useful for physical access control, but an EACS must manage variables that do not exist in an ordinary login.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Physical access involves mechanical barriers, opening time, passage, position sensors, held-open doors, forced doors, emergency conditions, loss of power, people flow, accessible routes, and tailgating risk. A policy that works well in a web application may be impractical at a turnstile during a shift change.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NIST SP 800-116 Rev. 1, focused on the use of PIV credentials for facility access, reinforces a particularly useful principle: the authentication mechanism should be selected according to risk and protection level rather than applied uniformly to every door.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">When to require two factors<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The main criterion should be the risk of unauthorized access combined with operational impact. Low-criticality areas may be adequately controlled with one robust factor; high-criticality areas may justify two factors, dual custody, or additional rules.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Context<\/td><td>Risk example<\/td><td>Possible strategy<\/td><\/tr><tr><td>Common administrative area<\/td><td>limited impact<\/td><td>one strong factor and an authorization policy<\/td><\/tr><tr><td>Laboratory, restricted archive, or secondary data room<\/td><td>sensitive information or asset<\/td><td>MFA by profile, schedule, or area<\/td><\/tr><tr><td>Vault room, critical data center, or sensitive process<\/td><td>high operational or asset impact<\/td><td>mandatory MFA with governed exceptions<\/td><\/tr><tr><td>Area with segregation of duties<\/td><td>risk from individual action<\/td><td>MFA combined with dual custody<\/td><\/tr><tr><td>Temporary third-party access<\/td><td>temporary relationship<\/td><td>time-limited credential + second factor according to risk<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The matrix above is only a reasoning model. The design should relate each area to its risk and define the requirement in an access matrix. Merely stating that \u201cthe system shall support MFA\u201d demonstrates product capability but does not determine where the function will be applied.<\/p>\n\n\n\n<figure class=\"a3a-mermaid\"><svg id=\"a3a-diagram-1\" width=\"100%\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"flowchart\" style=\"max-width:min(568.4609375px, 100%);height:auto;display:block;margin:0 auto\" viewBox=\"0 0 568.4609375 1053.5\" role=\"graphics-document document\" aria-roledescription=\"flowchart-v2\" aria-labelledby=\"chart-title-a3a-diagram-1\"><title id=\"chart-title-a3a-diagram-1\">Engineering decision for applying multifactor authentication at an access point<\/title><style>#a3a-diagram-1{font-family:Roboto,sans-serif;font-size:15px;fill:var(--a3a-diag-text, #0a0a0a);}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#a3a-diagram-1 .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#a3a-diagram-1 .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#a3a-diagram-1 .error-icon{fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .error-text{fill:#000000;stroke:#000000;}#a3a-diagram-1 .edge-thickness-normal{stroke-width:1px;}#a3a-diagram-1 .edge-thickness-thick{stroke-width:3.5px;}#a3a-diagram-1 .edge-pattern-solid{stroke-dasharray:0;}#a3a-diagram-1 .edge-thickness-invisible{stroke-width:0;fill:none;}#a3a-diagram-1 .edge-pattern-dashed{stroke-dasharray:3;}#a3a-diagram-1 .edge-pattern-dotted{stroke-dasharray:2;}#a3a-diagram-1 .marker{fill:var(--a3a-diag-stroke, #2e42a2);stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 .marker.cross{stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 svg{font-family:Roboto,sans-serif;font-size:15px;}#a3a-diagram-1 p{margin:0;}#a3a-diagram-1 .label{font-family:Roboto,sans-serif;color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 .cluster-label text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster-label span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster-label span p{background-color:transparent;}#a3a-diagram-1 .label text,#a3a-diagram-1 span{fill:var(--a3a-diag-text, #0a0a0a);color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 .node rect,#a3a-diagram-1 .node circle,#a3a-diagram-1 .node ellipse,#a3a-diagram-1 .node polygon,#a3a-diagram-1 .node path{fill:var(--a3a-diag-fill, #eef2fd);stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:1px;}#a3a-diagram-1 .rough-node .label text,#a3a-diagram-1 .node .label text,#a3a-diagram-1 .image-shape .label,#a3a-diagram-1 .icon-shape .label{text-anchor:middle;}#a3a-diagram-1 .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#a3a-diagram-1 .rough-node .label,#a3a-diagram-1 .node .label,#a3a-diagram-1 .image-shape .label,#a3a-diagram-1 .icon-shape .label{text-align:center;}#a3a-diagram-1 .node.clickable{cursor:pointer;}#a3a-diagram-1 .root .anchor path{fill:var(--a3a-diag-stroke, #2e42a2)!important;stroke-width:0;stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 .arrowheadPath{fill:var(--a3a-diag-stroke, #0b0b0b);}#a3a-diagram-1 .edgePath .path{stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:2.0px;}#a3a-diagram-1 .flowchart-link{stroke:var(--a3a-diag-stroke, #2e42a2);fill:none;}#a3a-diagram-1 .edgeLabel{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-1 .edgeLabel p{background-color:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .edgeLabel rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .labelBkg{background-color:rgba(255, 255, 255, 0.5);}#a3a-diagram-1 .cluster rect{fill:var(--a3a-diag-surface, #f8f8f8);stroke:var(--a3a-diag-border, #e2e8f0);stroke-width:1px;}#a3a-diagram-1 .cluster text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:Roboto,sans-serif;font-size:12px;background:var(--a3a-diag-canvas, #ffffff);border:1px solid hsl(0, 0%, 90%);border-radius:2px;pointer-events:none;z-index:100;}#a3a-diagram-1 .flowchartTitleText{text-anchor:middle;font-size:18px;fill:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 rect.text{fill:none;stroke-width:0;}#a3a-diagram-1 .icon-shape,#a3a-diagram-1 .image-shape{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-1 .icon-shape p,#a3a-diagram-1 .image-shape p{background-color:var(--a3a-diag-canvas, #ffffff);padding:2px;}#a3a-diagram-1 .icon-shape rect,#a3a-diagram-1 .image-shape rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#a3a-diagram-1 .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#a3a-diagram-1 :root{--mermaid-font-family:Roboto,sans-serif;}<\/style><g><marker id=\"a3a-diagram-1_flowchart-v2-pointEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 0 L 10 5 L 0 10 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-pointStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"4.5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 5 L 10 10 L 10 0 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-circleEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"11\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-circleStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"-1\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-crossEnd\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"12\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-crossStart\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"-1\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><g class=\"root\"><g class=\"clusters\"><\/g><g class=\"edgePaths\"><path d=\"M281.93,60.5L281.93,64.667C281.93,68.833,281.93,77.167,281.93,84.833C281.93,92.5,281.93,99.5,281.93,103L281.93,106.5\" id=\"L_A_B_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_A_B_0\" data-points=\"W3sieCI6MjgxLjkyOTY4NzUsInkiOjYwLjV9LHsieCI6MjgxLjkyOTY4NzUsInkiOjg1LjV9LHsieCI6MjgxLjkyOTY4NzUsInkiOjExMC41fV0=\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M281.93,163L281.93,167.167C281.93,171.333,281.93,179.667,281.93,187.333C281.93,195,281.93,202,281.93,205.5L281.93,209\" id=\"L_B_C_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_B_C_0\" data-points=\"W3sieCI6MjgxLjkyOTY4NzUsInkiOjE2M30seyJ4IjoyODEuOTI5Njg3NSwieSI6MTg4fSx7IngiOjI4MS45Mjk2ODc1LCJ5IjoyMTN9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M218.559,424.63L204.366,441.233C190.172,457.836,161.785,491.043,147.592,513.022C133.398,535,133.398,545.75,133.398,551.125L133.398,556.5\" id=\"L_C_D_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_D_0\" data-points=\"W3sieCI6MjE4LjU1OTQyNjY2NDE2MTc1LCJ5Ijo0MjQuNjI5NzM5MTY0MTYxN30seyJ4IjoxMzMuMzk4NDM3NSwieSI6NTI0LjI1fSx7IngiOjEzMy4zOTg0Mzc1LCJ5Ijo1NjAuNX1d\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M345.3,424.63L359.493,441.233C373.687,457.836,402.074,491.043,416.267,513.022C430.461,535,430.461,545.75,430.461,551.125L430.461,556.5\" id=\"L_C_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_E_0\" data-points=\"W3sieCI6MzQ1LjI5OTk0ODMzNTgzODMsInkiOjQyNC42Mjk3MzkxNjQxNjE3fSx7IngiOjQzMC40NjA5Mzc1LCJ5Ijo1MjQuMjV9LHsieCI6NDMwLjQ2MDkzNzUsInkiOjU2MC41fV0=\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M430.461,613L430.461,617.167C430.461,621.333,430.461,629.667,430.461,637.333C430.461,645,430.461,652,430.461,655.5L430.461,659\" id=\"L_E_F_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_E_F_0\" data-points=\"W3sieCI6NDMwLjQ2MDkzNzUsInkiOjYxM30seyJ4Ijo0MzAuNDYwOTM3NSwieSI6NjM4fSx7IngiOjQzMC40NjA5Mzc1LCJ5Ijo2NjN9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M430.461,738L430.461,742.167C430.461,746.333,430.461,754.667,430.461,762.333C430.461,770,430.461,777,430.461,780.5L430.461,784\" id=\"L_F_G_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_F_G_0\" data-points=\"W3sieCI6NDMwLjQ2MDkzNzUsInkiOjczOH0seyJ4Ijo0MzAuNDYwOTM3NSwieSI6NzYzfSx7IngiOjQzMC40NjA5Mzc1LCJ5Ijo3ODh9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M430.461,840.5L430.461,844.667C430.461,848.833,430.461,857.167,430.461,864.833C430.461,872.5,430.461,879.5,430.461,883L430.461,886.5\" id=\"L_G_H_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_G_H_0\" data-points=\"W3sieCI6NDMwLjQ2MDkzNzUsInkiOjg0MC41fSx7IngiOjQzMC40NjA5Mzc1LCJ5Ijo4NjUuNX0seyJ4Ijo0MzAuNDYwOTM3NSwieSI6ODkwLjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M430.461,943L430.461,947.167C430.461,951.333,430.461,959.667,430.461,967.333C430.461,975,430.461,982,430.461,985.5L430.461,989\" id=\"L_H_I_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_H_I_0\" data-points=\"W3sieCI6NDMwLjQ2MDkzNzUsInkiOjk0M30seyJ4Ijo0MzAuNDYwOTM3NSwieSI6OTY4fSx7IngiOjQzMC40NjA5Mzc1LCJ5Ijo5OTN9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><\/g><g class=\"edgeLabels\"><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_A_B_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_B_C_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\" transform=\"translate(133.3984375, 524.25)\"><g class=\"label\" data-id=\"L_C_D_0\" transform=\"translate(-11.2734375, -11.25)\"><foreignObject width=\"22.546875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><p>Yes<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\" transform=\"translate(430.4609375, 524.25)\"><g class=\"label\" data-id=\"L_C_E_0\" transform=\"translate(-9.5078125, -11.25)\"><foreignObject width=\"19.015625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><p>No<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_E_F_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_F_G_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_G_H_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_H_I_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><\/g><g class=\"nodes\"><g class=\"node default\" id=\"flowchart-A-0\" transform=\"translate(281.9296875, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-107.703125\" y=\"-26.25\" width=\"215.40625\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-77.703125, -11.25)\"><rect><\/rect><foreignObject width=\"155.40625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Identify area and asset<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-B-1\" transform=\"translate(281.9296875, 136.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-106.8203125\" y=\"-26.25\" width=\"213.640625\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-76.8203125, -11.25)\"><rect><\/rect><foreignObject width=\"153.640625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Assess risk and impact<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-C-3\" transform=\"translate(281.9296875, 350.5)\"><polygon points=\"137.5,0 275,-137.5 137.5,-275 0,-137.5\" class=\"label-container\" transform=\"translate(-137, 137.5)\"><\/polygon><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>Does one factor address the risk?<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-D-5\" transform=\"translate(133.3984375, 586.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-125.3984375\" y=\"-26.25\" width=\"250.796875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-95.3984375, -11.25)\"><rect><\/rect><foreignObject width=\"190.796875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Define credential and policy<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-E-7\" transform=\"translate(430.4609375, 586.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-121.6640625\" y=\"-26.25\" width=\"243.328125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-91.6640625, -11.25)\"><rect><\/rect><foreignObject width=\"183.328125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Select independent factors<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-F-9\" transform=\"translate(430.4609375, 700.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-130\" y=\"-37.5\" width=\"260\" height=\"75\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>Validate flow and accessibility<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-G-11\" transform=\"translate(430.4609375, 814.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-94.671875\" y=\"-26.25\" width=\"189.34375\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-64.671875, -11.25)\"><rect><\/rect><foreignObject width=\"129.34375\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Define contingency<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-H-13\" transform=\"translate(430.4609375, 916.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-100.921875\" y=\"-26.25\" width=\"201.84375\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-70.921875, -11.25)\"><rect><\/rect><foreignObject width=\"141.84375\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Define logs and tests<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-I-15\" transform=\"translate(430.4609375, 1019.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-71.2265625\" y=\"-26.25\" width=\"142.453125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-41.2265625, -11.25)\"><rect><\/rect><foreignObject width=\"82.453125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Commission<\/p><\/span><\/div><\/foreignObject><\/g><\/g><\/g><\/g><\/g><\/svg><figcaption>Engineering decision for applying multifactor authentication at an access point<\/figcaption><\/figure>\n\n\n\n\n<h2 class=\"wp-block-heading\">Common combinations and their engineering effects<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Card + PIN<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Card and PIN combine possession and knowledge. It is a mature architecture, but it requires a defined PIN policy covering lifecycle, use, recovery, and administrative protection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The PIN must be individual. A shared PIN by department reduces accountability and makes selective revocation difficult. Logs must not record the PIN value; they should record only whether the factor was requested, accepted, or rejected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At high-flow access points, entering a PIN increases transaction time. The design must measure this impact and ensure that operational pressure does not lead to weaker operating practices during peak periods.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Card + biometrics<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The credential can indicate the identity and biometrics can verify that the person presenting the card is its holder. This enables an efficient 1:1 architecture because the system does not need to search the entire gallery.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Biometrics adds its own requirements: enrollment quality, FAR, FRR, failure to acquire, liveness\/PAD when required, privacy, accessibility, and an equivalent alternative for people who cannot use the modality. The performance of the second factor must be tested with the actual user population.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Mobile credential + device authentication<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A smartphone can protect the credential with local biometrics or a PIN. This increases resistance to use by another person, but the design must document where the second factor is actually validated. The access terminal may receive only a credential already released by the device without visibility into the local authentication performed on the phone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This architecture may be appropriate, provided that the security model, evidence, and responsibility of each layer are understood. It should not be assumed that \u201cphone with biometrics\u201d automatically means MFA in the EACS.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">PIN + biometrics<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This combination joins knowledge and inherence without necessarily using a card. It is technically possible, but a typed identifier must be distinguished from a secret. If a person enters a public employee ID only to locate a template, that identifier should not be counted as a knowledge factor.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Card + PIN + biometrics<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Three steps may be justified in highly critical areas, but operational cost rises quickly. More factors do not automatically mean greater security if the process becomes impractical, contingency controls are weak, or the team cannot sustain the policy.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Factor order and user experience<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The sequence affects performance and diagnostics. With card + biometrics, presenting the card first allows the system to locate the correct template and perform 1:1 verification. With card + PIN, the credential can indicate which policy and which PIN should be validated. In other architectures, the factors are collected before any decision is made.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The terminal must provide clear feedback. The user should know whether the system expects a card, PIN, biometric sample, another attempt, or contact with the security desk. A generic \u201cerror\u201d message increases repeated attempts and support calls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is also important to limit how much the feedback reveals. Telling an unauthorized user in detail which factor failed may expose unnecessary information. The design should balance usability and information exposure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Capacity, latency, and queue formation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">MFA adds time to each transaction. The actual impact cannot be estimated only from the processing time stated by the manufacturer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The complete cycle may include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>approaching the access point;<\/li><li>presenting the first factor;<\/li><li>terminal feedback;<\/li><li>presenting the second factor;<\/li><li>local or central processing;<\/li><li>authorization;<\/li><li>barrier command;<\/li><li>opening;<\/li><li>passage;<\/li><li>rearming;<\/li><li>repetition in case of failure.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">At a turnstile, additional seconds multiplied by a peak entry period can create a significant queue. In industrial areas, this may affect shift changes. At reception areas, it may transfer operational pressure to the security desk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design should use service throughput, not only nominal time. It should consider latency percentiles, additional attempts, and users who need assistance.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Local, centralized, and hybrid architecture<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">MFA connects credentials, readers, controllers, servers, and, in enterprise environments, directories and IAM. Reviewing interfaces before deployment reduces incompatibilities and unintended weak points.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/revisao-validacao-tecnica-projetos-design-review\/\">Review architecture and interfaces<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The MFA decision may occur in the controller, an intelligent terminal, the central server, or a combination of these layers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Local decision<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sufficient rules and data remain close to the access point. The advantage is continuity during loss of communication. In return, local storage must be protected, changes must be synchronized, and revocation must be enforced across distributed devices.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Centralized decision<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The server processes the logic. The policy can be richer and easier to administer, but the door becomes dependent on the network, server, identity services, and latency. Behavior during failure must be defined.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hybrid architecture<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some rules remain local while others are coordinated centrally. This is common in distributed corporate systems. The design must explicitly list what continues to operate when each dependency fails.<\/p>\n\n\n\n<figure class=\"a3a-mermaid\"><svg id=\"a3a-diagram-2\" width=\"100%\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"flowchart\" style=\"max-width:min(1054.09375px, 100%);height:auto;display:block;margin:0 auto\" viewBox=\"0 0 1054.09375 222.25\" role=\"graphics-document document\" aria-roledescription=\"flowchart-v2\" aria-labelledby=\"chart-title-a3a-diagram-2\"><title id=\"chart-title-a3a-diagram-2\">Possible layers for MFA decision-making in physical access control<\/title><style>#a3a-diagram-2{font-family:Roboto,sans-serif;font-size:15px;fill:var(--a3a-diag-text, #0a0a0a);}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#a3a-diagram-2 .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#a3a-diagram-2 .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#a3a-diagram-2 .error-icon{fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-2 .error-text{fill:#000000;stroke:#000000;}#a3a-diagram-2 .edge-thickness-normal{stroke-width:1px;}#a3a-diagram-2 .edge-thickness-thick{stroke-width:3.5px;}#a3a-diagram-2 .edge-pattern-solid{stroke-dasharray:0;}#a3a-diagram-2 .edge-thickness-invisible{stroke-width:0;fill:none;}#a3a-diagram-2 .edge-pattern-dashed{stroke-dasharray:3;}#a3a-diagram-2 .edge-pattern-dotted{stroke-dasharray:2;}#a3a-diagram-2 .marker{fill:var(--a3a-diag-stroke, #2e42a2);stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-2 .marker.cross{stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-2 svg{font-family:Roboto,sans-serif;font-size:15px;}#a3a-diagram-2 p{margin:0;}#a3a-diagram-2 .label{font-family:Roboto,sans-serif;color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-2 .cluster-label text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-2 .cluster-label span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-2 .cluster-label span p{background-color:transparent;}#a3a-diagram-2 .label text,#a3a-diagram-2 span{fill:var(--a3a-diag-text, #0a0a0a);color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-2 .node rect,#a3a-diagram-2 .node circle,#a3a-diagram-2 .node ellipse,#a3a-diagram-2 .node polygon,#a3a-diagram-2 .node path{fill:var(--a3a-diag-fill, #eef2fd);stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:1px;}#a3a-diagram-2 .rough-node .label text,#a3a-diagram-2 .node .label text,#a3a-diagram-2 .image-shape .label,#a3a-diagram-2 .icon-shape .label{text-anchor:middle;}#a3a-diagram-2 .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#a3a-diagram-2 .rough-node .label,#a3a-diagram-2 .node .label,#a3a-diagram-2 .image-shape .label,#a3a-diagram-2 .icon-shape .label{text-align:center;}#a3a-diagram-2 .node.clickable{cursor:pointer;}#a3a-diagram-2 .root .anchor path{fill:var(--a3a-diag-stroke, #2e42a2)!important;stroke-width:0;stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-2 .arrowheadPath{fill:var(--a3a-diag-stroke, #0b0b0b);}#a3a-diagram-2 .edgePath .path{stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:2.0px;}#a3a-diagram-2 .flowchart-link{stroke:var(--a3a-diag-stroke, #2e42a2);fill:none;}#a3a-diagram-2 .edgeLabel{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-2 .edgeLabel p{background-color:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-2 .edgeLabel rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-2 .labelBkg{background-color:rgba(255, 255, 255, 0.5);}#a3a-diagram-2 .cluster rect{fill:var(--a3a-diag-surface, #f8f8f8);stroke:var(--a3a-diag-border, #e2e8f0);stroke-width:1px;}#a3a-diagram-2 .cluster text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-2 .cluster span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-2 div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:Roboto,sans-serif;font-size:12px;background:var(--a3a-diag-canvas, #ffffff);border:1px solid hsl(0, 0%, 90%);border-radius:2px;pointer-events:none;z-index:100;}#a3a-diagram-2 .flowchartTitleText{text-anchor:middle;font-size:18px;fill:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-2 rect.text{fill:none;stroke-width:0;}#a3a-diagram-2 .icon-shape,#a3a-diagram-2 .image-shape{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-2 .icon-shape p,#a3a-diagram-2 .image-shape p{background-color:var(--a3a-diag-canvas, #ffffff);padding:2px;}#a3a-diagram-2 .icon-shape rect,#a3a-diagram-2 .image-shape rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-2 .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#a3a-diagram-2 .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#a3a-diagram-2 :root{--mermaid-font-family:Roboto,sans-serif;}<\/style><g><marker id=\"a3a-diagram-2_flowchart-v2-pointEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 0 L 10 5 L 0 10 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-pointStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"4.5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 5 L 10 10 L 10 0 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-circleEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"11\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-circleStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"-1\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-crossEnd\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"12\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-crossStart\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"-1\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><g class=\"root\"><g class=\"clusters\"><\/g><g class=\"edgePaths\"><path d=\"M199.953,136.75L204.12,136.75C208.286,136.75,216.62,136.75,224.286,136.75C231.953,136.75,238.953,136.75,242.453,136.75L245.953,136.75\" id=\"L_A_B_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_A_B_0\" data-points=\"W3sieCI6MTk5Ljk1MzEyNSwieSI6MTM2Ljc1fSx7IngiOjIyNC45NTMxMjUsInkiOjEzNi43NX0seyJ4IjoyNDkuOTUzMTI1LCJ5IjoxMzYuNzV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M437.859,136.75L442.026,136.75C446.193,136.75,454.526,136.75,462.193,136.75C469.859,136.75,476.859,136.75,480.359,136.75L483.859,136.75\" id=\"L_B_C_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_B_C_0\" data-points=\"W3sieCI6NDM3Ljg1OTM3NSwieSI6MTM2Ljc1fSx7IngiOjQ2Mi44NTkzNzUsInkiOjEzNi43NX0seyJ4Ijo0ODcuODU5Mzc1LCJ5IjoxMzYuNzV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M597.338,110.5L604.568,106.333C611.799,102.167,626.259,93.833,638.908,89.667C651.557,85.5,662.396,85.5,667.815,85.5L673.234,85.5\" id=\"L_C_D_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_D_0\" data-points=\"W3sieCI6NTk3LjMzODQxNDYzNDE0NjQsInkiOjExMC41fSx7IngiOjY0MC43MTg3NSwieSI6ODUuNX0seyJ4Ijo2NzcuMjM0Mzc1LCJ5Ijo4NS41fV0=\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M801.141,59.25L809.766,55.083C818.391,50.917,835.641,42.583,847.766,38.417C859.891,34.25,866.891,34.25,870.391,34.25L873.891,34.25\" id=\"L_D_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_D_E_0\" data-points=\"W3sieCI6ODAxLjE0MTM4NzE5NTEyMiwieSI6NTkuMjV9LHsieCI6ODUyLjg5MDYyNSwieSI6MzQuMjV9LHsieCI6ODc3Ljg5MDYyNSwieSI6MzQuMjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M597.338,163L604.568,167.167C611.799,171.333,626.259,179.667,636.989,183.833C647.719,188,654.719,188,658.219,188L661.719,188\" id=\"L_C_F_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_F_0\" data-points=\"W3sieCI6NTk3LjMzODQxNDYzNDE0NjQsInkiOjE2M30seyJ4Ijo2NDAuNzE4NzUsInkiOjE4OH0seyJ4Ijo2NjUuNzE4NzUsInkiOjE4OH1d\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M801.141,111.75L809.766,115.917C818.391,120.083,835.641,128.417,848.455,132.583C861.268,136.75,869.646,136.75,873.835,136.75L878.023,136.75\" id=\"L_D_G_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_D_G_0\" data-points=\"W3sieCI6ODAxLjE0MTM4NzE5NTEyMiwieSI6MTExLjc1fSx7IngiOjg1Mi44OTA2MjUsInkiOjEzNi43NX0seyJ4Ijo4ODIuMDIzNDM3NSwieSI6MTM2Ljc1fV0=\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><\/g><g class=\"edgeLabels\"><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_A_B_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_B_C_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_C_D_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_D_E_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_C_F_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_D_G_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><\/g><g class=\"nodes\"><g class=\"node default\" id=\"flowchart-A-0\" transform=\"translate(103.9765625, 136.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-95.9765625\" y=\"-26.25\" width=\"191.953125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-65.9765625, -11.25)\"><rect><\/rect><foreignObject width=\"131.953125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Credential or factor<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-B-1\" transform=\"translate(343.90625, 136.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-93.953125\" y=\"-26.25\" width=\"187.90625\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-63.953125, -11.25)\"><rect><\/rect><foreignObject width=\"127.90625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Reader or terminal<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-C-3\" transform=\"translate(551.7890625, 136.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-63.9296875\" y=\"-26.25\" width=\"127.859375\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-33.9296875, -11.25)\"><rect><\/rect><foreignObject width=\"67.859375\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Controller<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-D-5\" transform=\"translate(746.8046875, 85.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-69.5703125\" y=\"-26.25\" width=\"139.140625\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-39.5703125, -11.25)\"><rect><\/rect><foreignObject width=\"79.140625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>EACS server<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-E-7\" transform=\"translate(961.9921875, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-84.1015625\" y=\"-26.25\" width=\"168.203125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-54.1015625, -11.25)\"><rect><\/rect><foreignObject width=\"108.203125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>IAM or directory<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-F-9\" transform=\"translate(746.8046875, 188)\"><rect class=\"basic label-container\" style=\"\" x=\"-81.0859375\" y=\"-26.25\" width=\"162.171875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-51.0859375, -11.25)\"><rect><\/rect><foreignObject width=\"102.171875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Door or barrier<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-G-11\" transform=\"translate(961.9921875, 136.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-79.96875\" y=\"-26.25\" width=\"159.9375\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-49.96875, -11.25)\"><rect><\/rect><foreignObject width=\"99.9375\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Logs and audit<\/p><\/span><\/div><\/foreignObject><\/g><\/g><\/g><\/g><\/g><\/svg><figcaption>Possible layers for MFA decision-making in physical access control<\/figcaption><\/figure>\n\n\n\n\n<h2 class=\"wp-block-heading\">Offline mode cannot be an unknown<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One of the greatest weaknesses in MFA appears when the network goes down. If a door normally requires card + biometrics, what happens when the terminal loses access to the biometric server? If card + PIN depends on an external directory, which rule remains available locally?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design must define contingency states:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>maintain two factors locally;<\/li><li>deny access until service is restored;<\/li><li>accept a degraded mode for specific groups;<\/li><li>require supervisor authorization;<\/li><li>use a controlled emergency credential.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Any relaxation must have an expiration period, an accountable owner, and a log. Otherwise, the \u201ccontingency mode\u201d may become a permanently weaker configuration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Factor failures and exception policy<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Predictable failures must be addressed before deployment:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>lost or damaged card;<\/li><li>forgotten or blocked PIN;<\/li><li>unavailable biometric sensor;<\/li><li>smartphone without battery power;<\/li><li>failure to acquire;<\/li><li>user unable to provide the biometric modality;<\/li><li>outdated local database;<\/li><li>identity server unavailable;<\/li><li>isolated controller;<\/li><li>clock or synchronization error.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The exception should preserve an equivalent level of security. If a critical area normally requires two factors, automatically reducing the requirement to a single card whenever a problem occurs turns failure into a path around the intended control.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">MFA, dual custody, and duress are not the same thing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">MFA validates multiple factors for the same identity. Dual custody requires two distinct identities. Duress is a function used to indicate that access is occurring under threat. These controls can coexist.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A highly critical room may require card + PIN from each person and also require two authorized people to be present. The logic must be defined as a state machine so that the integrator and the inspection team do not implement different interpretations.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Integration with anti-passback, schedules, and access levels<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Correct authentication does not mean authorization. After validating the factors, the EACS may still deny access because of:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>schedule;<\/li><li>calendar;<\/li><li>area;<\/li><li>profile;<\/li><li>anti-passback;<\/li><li>occupancy;<\/li><li>lockdown;<\/li><li>suspended credential;<\/li><li>expired relationship;<\/li><li>lack of temporary authorization.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The final decision must record the cause. This makes it possible to distinguish authentication problems from policy problems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Integration with HR, directories, and IAM<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In enterprise environments, the EACS may receive identity and attributes from corporate sources. HR may be the source of the employment relationship; a directory may provide identifiers; an IAM platform may orchestrate groups and lifecycle. Physical MFA then becomes part of a broader identity chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Changes in role, transfer between locations, leave, and termination must be reflected in physical permissions. Integration must define which system is the source of truth for each attribute, the propagation SLA, and how discrepancies are reconciled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This automation reduces manual work but creates dependencies. An incorrect group mapping may grant access broadly; an integration failure may prevent revocations. Therefore, integrations need logs, monitoring, and negative testing.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Logs and evidence for a multifactor transaction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A useful log should allow the decision to be reconstructed without storing unnecessary secrets. Typical fields include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>user identifier;<\/li><li>access point;<\/li><li>synchronized date and time;<\/li><li>applied policy;<\/li><li>requested factors;<\/li><li>result of each step;<\/li><li>online or offline condition;<\/li><li>final authorization rule;<\/li><li>use of an exception;<\/li><li>origin of an administrative change.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">PINs should not be stored in plain text. Biometric data requires additional protection because it is sensitive personal data under Brazil&#8217;s LGPD.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">LGPD and biometrics as a second factor<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When the second factor is biometric, the organization must govern purpose, legal basis, minimization, retention, administrative access, security, and deletion. It is not necessary to retain a raw image if the process can operate with an appropriately protected template and the image has no legitimate later purpose.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The architecture must also consider copies stored on terminals. Distributing a template to hundreds of devices expands the protection surface and makes revocation and disposal more complex.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">MFA does not justify excessive collection. The question should be: which combination meets the risk with the lowest exposure compatible with the purpose?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Accessibility and an equivalent alternative<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Keypads, biometric readers, and mobile terminals must be positioned and configured for the actual user population. Height, reach, contrast, feedback, laterality, and motor limitations can affect use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design should provide an alternative for people who cannot use a factor. This alternative must have an equivalent level of control and a governed process. Creating an \u201caccessible door\u201d that permanently operates under a weaker policy can introduce a structural workaround.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to specify MFA by performance<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A manufacturer-independent specification describes behavior, not a catalog. Instead of requiring a specific reader, it may establish:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>at least two independent factor categories wherever the risk matrix requires them;<\/li><li>policy configurable by door, user, group, and schedule;<\/li><li>defined authentication sequence;<\/li><li>attempt limits and blocking;<\/li><li>offline operation according to the continuity matrix;<\/li><li>individualized logs for each step;<\/li><li>integration with a directory or IAM where applicable;<\/li><li>auditable contingency arrangements;<\/li><li>latency and throughput requirements;<\/li><li>protection of credentials and templates;<\/li><li>revocation and synchronization capability;<\/li><li>as-built documentation of the policy;<\/li><li>acceptance test matrix.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This format preserves competition and keeps decisions on risk and performance within the engineering scope.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">MFA matrix by area<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Area<\/td><td>Factor 1<\/td><td>Factor 2<\/td><td>Offline<\/td><td>Exception<\/td><td>Acceptance evidence<\/td><\/tr><tr><td>Administrative<\/td><td>card<\/td><td>not required<\/td><td>yes<\/td><td>security desk<\/td><td>reading and authorization<\/td><\/tr><tr><td>Data room<\/td><td>card<\/td><td>PIN<\/td><td>yes<\/td><td>supervisor<\/td><td>success, error, and blocking<\/td><\/tr><tr><td>Critical room<\/td><td>card<\/td><td>biometrics<\/td><td>restricted<\/td><td>formal process<\/td><td>matching, rule, and logs<\/td><\/tr><tr><td>Temporary access<\/td><td>temporary credential<\/td><td>according to risk<\/td><td>defined by design<\/td><td>security desk<\/td><td>validity and expiration<\/td><\/tr><tr><td>Dual-custody area<\/td><td>individual MFA<\/td><td>second identity<\/td><td>according to matrix<\/td><td>formal emergency procedure<\/td><td>complete state machine<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The matrix should be developed from the requirements program and risk analysis. It becomes the reference for configuration and commissioning.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAT, SAT, and commissioning<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">MFA is only deployed when its logic has been tested. FAT verifies policy, integration, and states before field deployment. SAT verifies behavior in the actual environment. Commissioning closes the chain from factor presentation to physical command and event recording.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Positive cases<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>two valid factors;<\/li><li>authorized user at the correct time;<\/li><li>offline operation according to the design;<\/li><li>restoration and synchronization.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Negative cases<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>valid first factor and invalid second factor;<\/li><li>factors from different users;<\/li><li>revoked credential;<\/li><li>authenticated but unauthorized user;<\/li><li>attempt limit exceeded;<\/li><li>nonmatching biometrics;<\/li><li>policy outside the permitted schedule.<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Contingency cases<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>network failure;<\/li><li>server failure;<\/li><li>reader failure;<\/li><li>use of emergency credential;<\/li><li>authorized exception;<\/li><li>return to normal mode;<\/li><li>event reconciliation.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Acceptance should not merely demonstrate that the door opened. It should demonstrate that it opened under the correct condition, denied under the correct condition, and generated the correct evidence.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Post-deployment indicators<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Assisted operation can monitor:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>rejection rate by factor;<\/li><li>average transaction time and transaction-time percentile;<\/li><li>blocks caused by repeated attempts;<\/li><li>exceptions and authorized workarounds;<\/li><li>lost credentials;<\/li><li>biometric reenrollment;<\/li><li>synchronization failures;<\/li><li>offline periods;<\/li><li>differences between policy and configuration;<\/li><li>support calls by access point.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">An increase in exceptions may indicate that the policy has become impractical. An increase in biometric rejections may reveal sensor degradation, poor enrollment, or a change in the user population. Indicators turn MFA from a static configuration into a manageable operational control.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to procure a design that includes multifactor authentication<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Procurement should require verifiable deliverables. A mature scope may include:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>risk analysis by area;<\/li><li>factor and rule matrix;<\/li><li>architecture diagram;<\/li><li>interface matrix;<\/li><li>integration requirements;<\/li><li>offline and contingency strategy;<\/li><li>logging and cybersecurity requirements;<\/li><li>capacity criteria;<\/li><li>test cases;<\/li><li>requirement\u2013test\u2013evidence matrix;<\/li><li>as-built documentation;<\/li><li>operation and exception procedures.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The expected result is not \u201cinstall readers with PIN and biometrics,\u201d but to demonstrate an authentication policy consistent with risk, operation, and continuity.<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Common design errors<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Requiring two factors at every door<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This increases cost and friction without a proportional gain in low-risk areas.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Confusing an identifier with a factor<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A typed employee ID may only locate the user record and may not constitute a secret.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Ignoring peak flow<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A policy that is secure in the laboratory can create queues and operational workarounds during real operation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Failing to define offline behavior<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The system works while all infrastructure is available and becomes unpredictable at the first network failure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Accepting exceptions without expiration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A temporary contingency becomes the new normal.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Treating biometrics as infallible<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">FAR, FRR, FTA, enrollment quality, and PAD must be considered.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Failing to separate authentication from authorization<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Diagnostics and auditing become weak, and the system begins reporting everything as \u201caccess denied.\u201d<\/p>\n\n\n\n\n<h2 class=\"wp-block-heading\">Final considerations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Multifactor authentication in physical access control should be a selective, risk-driven decision demonstrated through testing. Its value does not lie in accumulating readers or steps, but in combining independent factors, maintaining continuity, preserving flow capacity, controlling exceptions, and producing auditable evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the risk matrix, architecture, offline policy, logs, and tests are defined before procurement, MFA stops being a catalog feature and becomes a measurable engineering requirement. This approach also avoids two extremes: underprotecting critical areas and overburdening common areas with controls that operations tend to circumvent.<\/p>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">Acceptance must prove that the access point opens for the correct combination, denies access under the expected conditions, and preserves evidence during contingency operation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/servicos-transversais\/comissionamento-de-equipamentos\/\">Plan FAT, SAT, and acceptance<\/a><\/p>\n<\/div>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Technical references<\/summary>\n<p class=\"wp-block-paragraph\">[1] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60839-11-1:2013 \u2014 Alarm and electronic security systems \u2014 Part 11-1: Electronic access control systems \u2014 System and components requirements. 2013. Available at: <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/3662\">https:\/\/webstore.iec.ch\/en\/publication\/3662<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[2] INTERNATIONAL ELECTROTECHNICAL COMMISSION. IEC 60839-11-2:2014 \u2014 Alarm and electronic security systems \u2014 Part 11-2: Electronic access control systems \u2014 Application guidelines. 2014. Available at: <a href=\"https:\/\/webstore.iec.ch\/en\/publication\/3663\">https:\/\/webstore.iec.ch\/en\/publication\/3663<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[3] NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. NIST SP 800-63B-4 \u2014 Digital Identity Guidelines: Authentication and Authenticator Management. 2025. Available at: <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/63\/B\/4\/final\">https:\/\/csrc.nist.gov\/pubs\/sp\/800\/63\/B\/4\/final<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[4] NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. NIST SP 800-116 Rev. 1 \u2014 Guidelines for the Use of PIV Credentials in Facility Access. 2018. Available at: <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/116\/r1\/final\">https:\/\/csrc.nist.gov\/pubs\/sp\/800\/116\/r1\/final<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[5] BRAZIL. Law No. 13,709 of August 14, 2018 \u2014 General Personal Data Protection Law (LGPD). 2018. Available at: <a href=\"https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2015-2018\/2018\/lei\/l13709.htm\">https:\/\/www.planalto.gov.br\/ccivil_03\/_ato2015-2018\/2018\/lei\/l13709.htm<\/a>.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Frequently asked questions<\/summary>\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-o-que-autentica-o-multifator-no-controle-de-aces-80317066\"><strong class=\"schema-faq-question\">What is multifactor authentication in physical access control?<\/strong> <p class=\"schema-faq-answer\">It is the requirement for two or more independent factors before passage is authorized, such as card + PIN or card + biometrics.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-cart-o-mais-matr-cula-digitada-mfa-cdbfcffe\"><strong class=\"schema-faq-question\">Is a card plus a typed employee ID MFA?<\/strong> <p class=\"schema-faq-answer\">Not necessarily. If the employee ID only identifies the record and is not a secret, it is not an independent knowledge factor.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-toda-rea-cr-tica-precisa-usar-biometria-como-seg-37b94acd\"><strong class=\"schema-faq-question\">Does every critical area need biometrics as a second factor?<\/strong> <p class=\"schema-faq-answer\">No. The combination should result from risk, capacity, continuity, privacy, and user-population analysis. Card + PIN may be more suitable in many scenarios.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-mfa-pode-funcionar-quando-o-servidor-est-fora-do-8dddf40f\"><strong class=\"schema-faq-question\">Can MFA work when the server is offline?<\/strong> <p class=\"schema-faq-answer\">Yes, if the architecture keeps sufficient rules and data locally. Offline behavior must be defined and tested in the design.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-mfa-substitui-dupla-cust-dia-51b46af4\"><strong class=\"schema-faq-question\">Does MFA replace dual custody?<\/strong> <p class=\"schema-faq-answer\">No. MFA combines factors for the same identity; dual custody requires two different people. Both controls can be used together.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-comprovar-mfa-no-comissionamento-3cf232ab\"><strong class=\"schema-faq-question\">How is MFA demonstrated during commissioning?<\/strong> <p class=\"schema-faq-answer\">Through positive, negative, and contingency cases that validate factors, authorization, offline mode, blocks, revocation, exceptions, and log evidence through to the physical command.<\/p><\/div><\/div>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Additional technical materials<\/summary>\n<h4 class=\"wp-block-heading\">Related services<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/programa-necessidades-requisitos-engenharia\/\">Requirements Program and Engineering Requirements<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/revisao-validacao-tecnica-projetos-design-review\/\">Design Review for Engineering Projects<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/servicos-transversais\/comissionamento-de-equipamentos\/\">Equipment Commissioning: FAT, Installation, SAT, Startup, and Acceptance<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Main content on the topic<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/guias-tecnicos\/guia-completo-sobre-controle-de-acesso\/\">Access Control System: Types, Technologies, Standards, and Design<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Related technical content<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/mfa-2fa-autenticacao-multifator-acesso-remoto-ot\/\">MFA and 2FA: Multifactor Authentication for Remote Access and OT Environments<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/credenciais-moveis-nfc-ble-controle-de-acesso\/\">Mobile Credentials in Access Control: NFC vs. BLE, Security, and Design Criteria<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/mifare-desfire-controle-de-acesso-seguranca-chaves-migracao\/\">MIFARE and DESFire in Access Control: Security, Keys, and Migration<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/dupla-custodia-regra-duas-pessoas-controle-de-acesso\/\">Dual Custody in Access Control: Two-Person Rule, Dual Access, and Dual Occupancy<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/far-frr-eer-biometria-controle-de-acesso\/\">FAR, FRR, and EER in Biometrics: Measuring Performance and Setting the Threshold<\/a><\/li><\/ul>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>How to design multifactor authentication for physical access control by combining cards, PINs, and biometrics with risk, contingency, integration, and acceptance criteria.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"template":"","meta":{"_a3a_global_related_solutions":[],"_a3a_global_related_services":[],"_a3a_global_related_materials":[],"_a3a_post_lang":"en-us","_a3a_translation_group_id":"80fe058d-3a78-409c-8e1c-8f41ef313575","_a3a_i18n_canonical_slug":"multifactor-authentication-physical-access-control","_a3a_lang_url_en-us":"","_a3a_lang_url_es-es":""},"categories":[],"segments":[],"mercados":[],"etapas":[],"class_list":["post-74933","articles","type-articles","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74933","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles"}],"about":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/types\/articles"}],"author":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":2,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74933\/revisions"}],"predecessor-version":[{"id":74935,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74933\/revisions\/74935"}],"wp:attachment":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media?parent=74933"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/categories?post=74933"},{"taxonomy":"segments","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/segments?post=74933"},{"taxonomy":"mercados","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/mercados?post=74933"},{"taxonomy":"etapas","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/etapas?post=74933"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}