Something you are should reinforce something you have

Biometric & Multi-Factor Home Entry

A practical guide to fingerprint, face, palm, mobile, PIN and physical credentials—covering spoof resistance, false acceptance, privacy, revocation, mechanical security and safe operation during power or network failure.

Biometrics are convenient, but they are not secret

Fingerprints are left on objects and faces are visible. If a password leaks, it can be changed; a person cannot issue themselves a new face or finger. NIST’s digital identity guidance therefore treats a biometric characteristic as an activation factor bound to a physical authenticator—not a standalone authenticator by itself.

Something you are

Biometric

Fingerprint, face, palm, iris or another measured physical characteristic matched to an enrolled template.

Something you have

Possession

A phone, hardware key, encrypted fob, smart card or secure credential held by the authorised person.

Something you know

Knowledge

A PIN or passcode that can be changed, individually issued and protected against repeated guessing.

Compare entry methods

Method Strength Watch for
Fingerprint Fast, compact and familiar for one-to-one verification. Wet, dirty, worn or injured fingers; lifted prints; fallback PIN; template storage.
Face verification Hands-free entry and convenient visitor/user enrolment. Lighting, masks, ageing, twins, presentation attacks, camera privacy and demographic performance.
Palm / palm-vein Contactless or low-contact verification with potentially richer features. Cost, positioning, environmental tolerance, proprietary templates and replacement support.
PIN keypad Easy to issue, revoke and time-limit without physical media. Shoulder surfing, shared codes, smudge patterns, guessing and coercion.
Phone credential Revocable identity, proximity or tap entry, event logs and remote administration. Flat battery, stolen/unlocked phone, account takeover, Bluetooth/NFC design and cloud outage.
Encrypted fob or card Simple, fast and independently revocable possession factor. Loss, cloning risks in weak legacy formats, unmanaged copies and reader tampering.
Physical key Works without power, network, account or vendor service. Duplication, loss, picking/forced attack and insecure emergency cylinder placement.

Choose when two factors are justified

Everyday household door

A strong possession credential plus device-local biometric activation can balance convenience and security, with a protected physical fallback.

High-value room

Require two independent factors—such as credential plus biometric or credential plus PIN—and log access separately from the outer door.

Staffed or shared property

Issue named, revocable credentials; avoid one permanent shared code and provide a non-biometric alternative where appropriate.

Visitor access

Use time-bound mobile or PIN credentials with clear start/end times, not rushed biometric enrolment for occasional guests.

Duress situation

A duress PIN or workflow must summon a meaningful response without placing the user at greater immediate risk.

Remote unlock

Protect the administrator account with phishing-resistant MFA where possible; remote release is only as secure as the account controlling it.

Two steps are not always two factors. A password and PIN are both knowledge factors. A phone app and phone-based approval may depend on the same compromised device. Map the actual independence of each factor.

Understand matching errors and spoof resistance

Measure Meaning Security consequence
False acceptance An unauthorised sample is incorrectly matched. Set the threshold for the risk; marketing accuracy without test conditions is not enough.
False rejection An authorised person is denied. Too many failures drive users toward shared PINs, propped doors or weak fallbacks.
Failure to enrol The system cannot create a reliable template for a user. Provide an equally secure alternative without disadvantaging the person.
Presentation attack A print, photograph, mask, replay or replica is presented to the sensor. Ask for independent presentation-attack/liveness testing relevant to the modality.
Threshold The similarity level required for a match. Higher convenience and higher security can conflict; document changes rather than using defaults blindly.
Identification vs verification One-to-many search versus one-to-one comparison with a claimed credential. Verification is often more proportionate and constrained for home access.
  • Test with users wearing glasses, hats and expected seasonal clothing.
  • Test wet, dry, cold, dirty, worn and injured fingers where fingerprint access is proposed.
  • Verify performance in direct sun, darkness, rain and condensation at exterior readers.
  • Confirm the system detects repeated failures and cannot be brute-forced indefinitely.
  • Use a tamper-protected reader and keep the decision controller on the secure side where possible.
  • Do not rely on a cloud photo match as the only barrier to physical entry.

The lock and door still matter

A sophisticated reader connected to a weak latch, exposed relay or poorly fixed door does not create a secure entrance.

Secure-side control

The exterior reader should not expose a simple unlock relay that can be bridged after removing the cover.

Mechanical resistance

Door, frame, hinges, strike/keep, lock case, cylinder and wall fixings must resist the expected physical attack.

Door status

Monitor closed, locked, forced and held-open states rather than assuming a successful unlock means the door secured afterward.

Tailgating

Authentication proves a credential at the reader; it does not prove that only one person passed through.

Emergency egress

People must be able to escape safely and comply with fire requirements without making outside bypass easy.

Audit integrity

Protect clocks, logs and administrator actions so an access history cannot be silently rewritten.

Minimise biometric data

Prefer systems that store a protected template locally in the reader, credential or user device rather than retaining raw face or fingerprint images in a broad cloud database. A template can still be sensitive and needs strong protection.

  • Document whether raw images, templates, scores or only a yes/no result are stored.
  • Use encryption, access control and secure hardware for templates at rest and in transit.
  • Separate biometric administration from ordinary app or household accounts.
  • Delete templates promptly when a resident, contractor or worker no longer needs access.
  • Provide a non-biometric alternative for people who cannot or do not wish to enrol where required.
  • Do not reuse entry biometrics for attendance, profiling or unrelated surveillance.
  • Review vendor support access, subprocessors, countries of storage and breach procedures.
  • Plan what happens if the vendor is sold, closes the cloud service or stops updating the reader.

Design every failure mode

Failure Required plan
Mains outage Battery-backed access/egress time, low-battery reporting and protected mechanical entry.
Internet or cloud outage Local credential decisions and logs where possible; define which remote functions stop.
Reader damage Tamper alarm, secure-side controller and an emergency method that does not expose an easy bypass.
Lost phone/fob Immediate revocation from a separately secured administrator device/account.
Biometric injury or change Equivalent fallback credential, supervised re-enrolment and no weak universal override.
Vendor service ends Data export/deletion, continued local operation and a realistic replacement path.
Fire or emergency Code-compliant egress, responder access and clearly documented fail-safe/fail-secure behaviour.

Country and privacy considerations

United KingdomOrganisations using biometric recognition need a lawful basis and special-category condition, security controls and normally a DPIA. Domestic use still warrants restraint.
United StatesBiometric privacy duties vary significantly by state. Check notice, consent, retention and deletion requirements before enrolment.
CanadaFederal and provincial requirements apply; recent OPC guidance treats identifiable biometric information as sensitive and Quebec has specific processes.
AustraliaBiometric templates used for automated verification may be sensitive information under the Privacy Act for covered entities; state rules can also matter.
IrelandBiometric identification can involve special-category data under GDPR; necessity, proportionality, lawful basis, security and alternatives are important.

Product and installer checklist

  • Is the biometric performing one-to-one verification or one-to-many identification?
  • What independent accuracy and presentation-attack tests support the exact model?
  • Where are raw samples and templates processed, stored and deleted?
  • Does the biometric unlock alone, or activate a possession-based credential?
  • Are PINs, cards, fobs and mobile credentials individually issued and revocable?
  • Is the controller/relay on the secure side and protected from reader removal?
  • How are forced, held-open, tamper, battery, network and reader faults reported?
  • What happens during power, internet, cloud, phone and biometric failure?
  • How are emergency egress, responder access and mechanical override protected?
  • Will the installer provide user roles, factor map, data-flow diagram and handover tests?

Official references

Make identity convenient without making failure catastrophic

Use biometrics to activate a secure credential, preserve strong revocable alternatives, keep the physical door resistant and design power, network, privacy and emergency behaviour before installation.

Explore all specialist protection layers →

Editorial note: General security, privacy and buying information only. Access control, fire egress, electrical work and biometric data require site- and jurisdiction-specific professional assessment.