{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/onvif-profile-d-access-peripheral-decision-boundaries/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/",
        "slug": "onvif-profile-d-access-peripheral-decision-boundaries",
        "url": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/onvif-profile-d-access-peripheral-decision-boundaries/"
        },
        "title": "ONVIF Profile D: keep access decisions in the right place when integrating peripherals",
        "summary": "Profile D standardizes communication between access peripherals and a securely located client. It does not certify the complete door, credential, or life-safety design.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "advisory",
            "name": "Advisory"
        },
        "featured": false,
        "topics": [
            {
                "slug": "access-control",
                "name": "Access Control",
                "url": "https://update.dsesecurity.com/topic/access-control/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-19T21:28:39+00:00",
        "modified_at": "2026-07-19T21:28:39+00:00",
        "reviewed_on": "2026-07-19",
        "reading_minutes": 2,
        "word_count": 432,
        "potentially_affected": "Organizations integrating readers, biometric devices, keypads, locks, sensors, displays, door phones, recognition cameras, access-control units, or management platforms.",
        "dse_recommendation": "Document where credentials, rules, and decisions reside, verify exact Profile D conformance, and separately test network, door, credential, and life-safety behavior.",
        "primary_source": {
            "name": "ONVIF — Profile D",
            "url": "https://www.onvif.org/profiles/profile-d/",
            "published_on": null,
            "authority": "ONVIF"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>What Profile D connects</h2>\n<p><strong>Source fact:</strong> ONVIF Profile D addresses interfaces for access-control peripheral devices. The official scope includes token readers for cards, keys, mobile phones, or bar codes; biometric readers; keypads; sensors; locks; displays; LEDs; and cameras used for iris, facial, or license-plate recognition.</p>\n<p>The profile separates capture from the access decision. A peripheral device captures a credential identifier and passes it to a securely located Profile D client, such as an access-control unit or management system. The client holds the access rules, schedules, and credentials, decides whether access should be granted, and can command the peripheral to grant or deny access, show a message, or request another input such as a PIN.</p>\n<p>A conformant client can configure information such as the door or access point for which a device is responsible. It can also configure allowed or blocked credential identifiers when the device supports that capability. Profile D complements Profiles A and C and can be combined with Profiles M and T in an integrated video and access-control design.</p>\n\n<h2>Where the profile stops</h2>\n<p>Profile D defines an interface; it does not certify a complete opening. It does not establish lock suitability, egress behavior, fire-code compliance, power capacity, battery runtime, cable condition, credential cryptography, biometric accuracy, network segmentation, or the security of every stored record. A profile claim also belongs to an exact product and firmware or software version.</p>\n<p>Conditional capability matters. A product type appearing in the Profile D scope does not mean every conformant device provides every recognition, local-list, display, or integrated-video function. Project requirements must be matched to the official feature documents and then tested with the intended client.</p>\n\n<h2>DSE integration checklist</h2>\n<p><strong>DSE recommendation:</strong> This is DSE operational synthesis, not an ONVIF door-hardware or code-compliance procedure.</p>\n<ol>\n<li>Diagram each peripheral, securely located client, controller, server, door, network path, and stored-data location.</li>\n<li>Identify which component captures an identifier, stores rules, makes the decision, and operates the output.</li>\n<li>Verify exact Profile D records and feature documents for both client and device.</li>\n<li>Test valid, invalid, expired, blocked, and unknown credentials plus any PIN or second-input workflow.</li>\n<li>Test loss and restoration of the client or network, including documented offline behavior.</li>\n<li>Verify lock, sensor, message, audit, and video association functions required by the design.</li>\n<li>Validate power, wiring, egress, fire alarm, accessibility, and life-safety behavior through the appropriate qualified process.</li>\n<li>Retain the tested versions, results, exceptions, and recovery steps with commissioning records.</li>\n</ol>\n\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://www.onvif.org/profiles/profile-d/\" target=\"_blank\" rel=\"noopener noreferrer\">Profile D</a> — current peripheral, client, decision, and configuration scope.</li>\n<li><a href=\"https://www.onvif.org/pressrelease/onvif-releases-profile-d-for-access-control-peripherals/\" target=\"_blank\" rel=\"noopener noreferrer\">ONVIF Releases Profile D for Access Control Peripherals</a> — the July 14, 2021 release and architecture examples.</li>\n<li><a href=\"https://www.onvif.org/conformant-products/\" target=\"_blank\" rel=\"noopener noreferrer\">Conformant Products</a> — exact model, version, and profile verification.</li>\n</ul>",
        "content_text": "What Profile D connects\nSource fact: ONVIF Profile D addresses interfaces for access-control peripheral devices. The official scope includes token readers for cards, keys, mobile phones, or bar codes; biometric readers; keypads; sensors; locks; displays; LEDs; and cameras used for iris, facial, or license-plate recognition.\nThe profile separates capture from the access decision. A peripheral device captures a credential identifier and passes it to a securely located Profile D client, such as an access-control unit or management system. The client holds the access rules, schedules, and credentials, decides whether access should be granted, and can command the peripheral to grant or deny access, show a message, or request another input such as a PIN.\nA conformant client can configure information such as the door or access point for which a device is responsible. It can also configure allowed or blocked credential identifiers when the device supports that capability. Profile D complements Profiles A and C and can be combined with Profiles M and T in an integrated video and access-control design.\n\nWhere the profile stops\nProfile D defines an interface; it does not certify a complete opening. It does not establish lock suitability, egress behavior, fire-code compliance, power capacity, battery runtime, cable condition, credential cryptography, biometric accuracy, network segmentation, or the security of every stored record. A profile claim also belongs to an exact product and firmware or software version.\nConditional capability matters. A product type appearing in the Profile D scope does not mean every conformant device provides every recognition, local-list, display, or integrated-video function. Project requirements must be matched to the official feature documents and then tested with the intended client.\n\nDSE integration checklist\nDSE recommendation: This is DSE operational synthesis, not an ONVIF door-hardware or code-compliance procedure.\n\nDiagram each peripheral, securely located client, controller, server, door, network path, and stored-data location.\nIdentify which component captures an identifier, stores rules, makes the decision, and operates the output.\nVerify exact Profile D records and feature documents for both client and device.\nTest valid, invalid, expired, blocked, and unknown credentials plus any PIN or second-input workflow.\nTest loss and restoration of the client or network, including documented offline behavior.\nVerify lock, sensor, message, audit, and video association functions required by the design.\nValidate power, wiring, egress, fire alarm, accessibility, and life-safety behavior through the appropriate qualified process.\nRetain the tested versions, results, exceptions, and recovery steps with commissioning records.\n\nOfficial references\n\nProfile D — current peripheral, client, decision, and configuration scope.\nONVIF Releases Profile D for Access Control Peripherals — the July 14, 2021 release and architecture examples.\nConformant Products — exact model, version, and profile verification.",
        "content_markdown": "## What Profile D connects\n\nSource fact: ONVIF Profile D addresses interfaces for access-control peripheral devices. The official scope includes token readers for cards, keys, mobile phones, or bar codes; biometric readers; keypads; sensors; locks; displays; LEDs; and cameras used for iris, facial, or license-plate recognition.\n\nThe profile separates capture from the access decision. A peripheral device captures a credential identifier and passes it to a securely located Profile D client, such as an access-control unit or management system. The client holds the access rules, schedules, and credentials, decides whether access should be granted, and can command the peripheral to grant or deny access, show a message, or request another input such as a PIN.\n\nA conformant client can configure information such as the door or access point for which a device is responsible. It can also configure allowed or blocked credential identifiers when the device supports that capability. Profile D complements Profiles A and C and can be combined with Profiles M and T in an integrated video and access-control design.\n\n## Where the profile stops\n\nProfile D defines an interface; it does not certify a complete opening. It does not establish lock suitability, egress behavior, fire-code compliance, power capacity, battery runtime, cable condition, credential cryptography, biometric accuracy, network segmentation, or the security of every stored record. A profile claim also belongs to an exact product and firmware or software version.\n\nConditional capability matters. A product type appearing in the Profile D scope does not mean every conformant device provides every recognition, local-list, display, or integrated-video function. Project requirements must be matched to the official feature documents and then tested with the intended client.\n\n## DSE integration checklist\n\nDSE recommendation: This is DSE operational synthesis, not an ONVIF door-hardware or code-compliance procedure.\n\n- Diagram each peripheral, securely located client, controller, server, door, network path, and stored-data location.\n\n- Identify which component captures an identifier, stores rules, makes the decision, and operates the output.\n\n- Verify exact Profile D records and feature documents for both client and device.\n\n- Test valid, invalid, expired, blocked, and unknown credentials plus any PIN or second-input workflow.\n\n- Test loss and restoration of the client or network, including documented offline behavior.\n\n- Verify lock, sensor, message, audit, and video association functions required by the design.\n\n- Validate power, wiring, egress, fire alarm, accessibility, and life-safety behavior through the appropriate qualified process.\n\n- Retain the tested versions, results, exceptions, and recovery steps with commissioning records.\n\n## Official references\n\n- [Profile D](https://www.onvif.org/profiles/profile-d/) — current peripheral, client, decision, and configuration scope.\n\n- [ONVIF Releases Profile D for Access Control Peripherals](https://www.onvif.org/pressrelease/onvif-releases-profile-d-for-access-control-peripherals/) — the July 14, 2021 release and architecture examples.\n\n- [Conformant Products](https://www.onvif.org/conformant-products/) — exact model, version, and profile verification."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/",
                "url": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-19"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "ONVIF Profile D: keep access decisions in the right place when integrating peripherals",
                        "item": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/#article",
                "identifier": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/",
                "url": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/",
                "headline": "ONVIF Profile D: keep access decisions in the right place when integrating peripherals",
                "description": "Profile D standardizes communication between access peripherals and a securely located client. It does not certify the complete door, credential, or…",
                "abstract": "Profile D standardizes communication between access peripherals and a securely located client. It does not certify the complete door, credential, or life-safety design.",
                "articleBody": "What Profile D connects\nSource fact: ONVIF Profile D addresses interfaces for access-control peripheral devices. The official scope includes token readers for cards, keys, mobile phones, or bar codes; biometric readers; keypads; sensors; locks; displays; LEDs; and cameras used for iris, facial, or license-plate recognition.\nThe profile separates capture from the access decision. A peripheral device captures a credential identifier and passes it to a securely located Profile D client, such as an access-control unit or management system. The client holds the access rules, schedules, and credentials, decides whether access should be granted, and can command the peripheral to grant or deny access, show a message, or request another input such as a PIN.\nA conformant client can configure information such as the door or access point for which a device is responsible. It can also configure allowed or blocked credential identifiers when the device supports that capability. Profile D complements Profiles A and C and can be combined with Profiles M and T in an integrated video and access-control design.\n\nWhere the profile stops\nProfile D defines an interface; it does not certify a complete opening. It does not establish lock suitability, egress behavior, fire-code compliance, power capacity, battery runtime, cable condition, credential cryptography, biometric accuracy, network segmentation, or the security of every stored record. A profile claim also belongs to an exact product and firmware or software version.\nConditional capability matters. A product type appearing in the Profile D scope does not mean every conformant device provides every recognition, local-list, display, or integrated-video function. Project requirements must be matched to the official feature documents and then tested with the intended client.\n\nDSE integration checklist\nDSE recommendation: This is DSE operational synthesis, not an ONVIF door-hardware or code-compliance procedure.\n\nDiagram each peripheral, securely located client, controller, server, door, network path, and stored-data location.\nIdentify which component captures an identifier, stores rules, makes the decision, and operates the output.\nVerify exact Profile D records and feature documents for both client and device.\nTest valid, invalid, expired, blocked, and unknown credentials plus any PIN or second-input workflow.\nTest loss and restoration of the client or network, including documented offline behavior.\nVerify lock, sensor, message, audit, and video association functions required by the design.\nValidate power, wiring, egress, fire alarm, accessibility, and life-safety behavior through the appropriate qualified process.\nRetain the tested versions, results, exceptions, and recovery steps with commissioning records.\n\nOfficial references\n\nProfile D — current peripheral, client, decision, and configuration scope.\nONVIF Releases Profile D for Access Control Peripherals — the July 14, 2021 release and architecture examples.\nConformant Products — exact model, version, and profile verification.",
                "datePublished": "2026-07-19T21:28:39+00:00",
                "dateModified": "2026-07-19T21:28:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/onvif-profile-d-access-peripheral-decision-boundaries/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Access Control",
                    "Networks & Infrastructure",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Access Control",
                    "Networks & Infrastructure",
                    "Video Surveillance",
                    "Guide",
                    "Advisory priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Access Control",
                        "url": "https://update.dsesecurity.com/topic/access-control/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 432,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "ONVIF — Profile D",
                    "url": "https://www.onvif.org/profiles/profile-d/"
                }
            }
        ]
    }
}