User`s manual
S2000-2 Operating
31 www.bolid.com
TWO FACTOR AUTHENTICATION
Each of the two controller’s readers can operate in such a mode when not one but two keys (for ex-
ample, a Proximity card plus a PIN-code) are required to identify the same user so called two fac-
tor authentication. This mode can be activated separately for each reader by setting the Two Factor
Authentication flag (see the description of this configuration parameter in Reader Configuration Pa-
rameters Section of this Manual).
The main and additional keys are presented to the same reader of the S2000-2 controller, that is why
combinations of different keys can be used only with special combined readers providing reading dif-
ferent keys and transmitting them to the S2000-2 controller in a single format (Touch Memory, Wie-
gand, or ABA TRACK II).
While an access or alarm loop arming/disarming is requested, the two factor authentication process
starts with presenting the first key and reading the so called Main code. If the key is identified and
there is no access violation, the controller is switched to the second code waiting mode. The reader
LED starts flashing with green color 5 times per second. Within the subsequent 30 seconds the sec-
ond identifier, so called Additional code, has to be presented.
If the presented code does not coincide with the Additional code, the controller generates the AC-
CESS DENIED message with ADDITIONAL CODE ERROR attribute. If the presented additional code
is correct, the identification procedure is considered to be successfully finished and either the control-
ler grants access the green LED of the reader turns on, the lock opening relay is activated (deacti-
vated) and the ACCESS GRANTED message is generated, or the access granted procedure is con-
tinued the reader LED is lit with green for 2 s, the flashes 5 tome per second again and the IDEN-
TIFICATION message is generated, or alarm loops which these keys is controlled by are
armed/disarmed.
If the authentication procedure needs to be simplified for some of the keys, while using the two factor
authentication for all other keys, it is necessary to set the Without Additional Code parameter for such
keys. The Main code presenting will be sufficient to identify the keys in question (no additional code is
required).
If the Two Factor Authentication mode is set for a reader, it will be applied not only for identification of
User keys, intended for access and loop arming/disarming, but also for identification of special keys
such as Master, Unlocking, Locking, if of cause the Without Additional Code parameter is not set for
these keys.
NOTE: Taking into account that in two factor authentication mode the controller has to store in its
memory two codes (main and additional) instead of single codes, the maximal number of
keys being stored in the S2000-2 controller is twofold reduced (down to 2048), even if the
two factor authentication mode is used only for one reader.