Introducing FIPSlink Access Reader Services (FARS)

 

September 1, 2026 – From the desk of Andrew Mahon & Stephen Mottram

FIPS 201 credential validation your team doesn’t have to build.

A federal customer asks whether your panel supports PIV authentication at the door. Technically, it could. The distance between “could” and “does” is where these projects stall.

Time-of-access FIPS 201 validation is not one feature. It is certificate validation and revocation checking, card authentication challenges, cryptographic verification, and OSDP command sequences that vary by reader model and by the assurance level a given door requires. Support one reader vendor, and you have solved it for one reader vendor. Add a second, and much of the work starts again. Then the standard evolves, or a reader manufacturer ships new firmware, and the maintenance never quite ends.

That work is specialized, and it has very little to do with what makes your access control platform good in the first place.

What FARS does

FIPSlink Access Reader Services is middleware that handles time-of-access FIPS 201 credential validation on behalf of panel manufacturers and access control software providers. It installs as a lightweight service and exposes REST APIs. Your platform makes a call and receives an authorization decision.

The design principle is that partners should be able to take as much or as little of it as they need. There are two integration models.

Option 1: Hand FARS the whole OSDP workflow

The fastest path to a working deployment. Your platform sends a validation request over REST and receives an authorization decision. FARS generates and processes the required OSDP commands and responses, selecting the appropriate sequence based on the connected reader platform and the configured assurance level.

FARS currently supports leading FIPS 201-capable reader platforms, including:

  • HID Signo PIV Series readers
  • Hirsch uTrust TS Series readers
  • Veridt Stealth Series readers
  • Wavelynx ETHOS Series readers

The practical benefit is in that list. Because FARS abstracts reader-specific details, a single integration on your side covers them all. As new reader platforms and capabilities arrive, support lands inside FARS rather than in your codebase. You are not redesigning your access control workflow every time the reader market moves.

Option 2: Keep your OSDP implementation, use the cryptography

Plenty of partners have already invested years in their own OSDP workflows and have no interest in replacing them. Reasonable.

For those environments, FARS exposes dedicated Cryptography Service Endpoints covering the operations that make FIPS 201 validation hard:

  • Credential authorization support
  • Active card challenge operations
  • Cryptographic verification workflows

You keep control of your OSDP communications. FARS handles the specialized cryptography underneath. It is a narrower dependency, and for a mature platform, it is often the more sensible one.

Where it runs

Deployment environments differ, so FARS can be installed:

  • At the secure edge, close to readers and controllers
  • Centrally, within enterprise infrastructure
  • Embedded within supported panel environments

The same REST interfaces apply in each case, which means the deployment decision gets made on security, performance, and operational grounds rather than on what the middleware will tolerate.

Why we built it

Supporting FIPS 201 should not require expertise in certificate validation, card authentication, and device-specific OSDP behavior. For most partners, that expertise is a cost of entry to the federal market, not a differentiator.

FARS exists to remove that cost. Take the delegated model to quickly reach a working integration, or take the cryptographic service layer to leave your existing architecture intact. Either way, the outcome is the same: standards-based FIPS 201 validation in your product, without a team dedicated to maintaining it.

If you are weighing what FIPS 201 support would take in your platform, we are happy to walk through both models against your architecture. 

PACS Manufacturer: Contact us if you want to integrate FARS into your panels to simplify and speed up the door process for end users.

End Users: Contact us if you want a PACS Manufacturer that has integrated FARS because you want a simplified and improved speed at door experience.

Click here to contact Andrew Mahon & Stephen Mottram to learn more.

About Identity One

Identity One builds on the FIPS 201 standard, creating innovative next generation registration, validation, PIV/PIV-I issuance, CAC/PIV/TWIC based visitor management, visitor PIV-I cards and derived credentials for CAC, PIV and TWIC.  Identity One’s solutions serve physical access and logical access for US Federal Government, US Armed Forces and TWIC compliance. We issue, register and verify identities for frictionless access and integration everywhere, protect identities from being impersonated, and secure intellectual property. Identity One software and services are BAA (Buy American Act) compliant and TAA (Trade Agreements Act) compliant. Identity One is headquartered in Atlanta, Georgia, USA and all our products are proudly made in the USA.