AWS Smart Building Access Control Case Study for Cloud-Based Physical Security
Executive Summary
Ficode developed a secure, cloud-based physical access control solution for a UK-based smart-building platform by integrating Paxton Net2 door reader hardware with AWS-hosted management services. Our team stabilized Windows container deployments, centralized user access management, and enabled secure, scalable door access control through a unified cloud-native platform.
Client Overview
Our client is a UK-based smart-building technology provider delivering cloud-based building management solutions for commercial properties. Their platform enables centralized management of building operations, tenant services, and security systems. To strengthen physical security and simplify access management, the client required a scalable AWS-based solution capable of integrating door access hardware with cloud-hosted user and policy management.
Business Challenges
As the platform expanded across multiple commercial buildings, managing physical access securely and efficiently became increasingly complex. The client required a reliable cloud-native solution that could centralize access control, simplify administration, and support future scalability without increasing operational overhead.
The platform’s access-control integration presented several challenges:
- Paxton Net2 door reader hardware communicates through proprietary libraries that are Windows-native there is no Linux equivalent, and rewriting the integration was not an option.
- The platform’s cloud deployment ran almost entirely on Linux infrastructure; adding a Windows service required deliberate configuration that standard deployment tooling does not assume.
- The access-control service needed to communicate with the platform’s authentication and business data services both running as Linux services within the same cluster.
- Before Ficode’s stabilisation work, the service was not deploying reliably the automated build pipeline was not producing consistent container images, and the service entered startup failures requiring manual intervention.
Ficode Solution
Deployment Stabilisation:
Three issues were preventing reliable deployment. The automated build pipeline was not producing correctly packaged Windows container images the application package structure needed correction to serve traffic correctly under IIS. The deployment configuration was not directing the Windows container to the Windows-capable infrastructure within the cluster. And the startup configuration was crashing when optional environment variables were absent rather than falling back gracefully. All three issues were resolved: the build pipeline corrected, scheduling configuration added, and startup handling updated to behave correctly across deployment environments.
Access-Control Management Interface:
The platform’s web interface provides building operators with the full range of access management capabilities for commercial multi-tenant environments: access levels defining which doors each user category can access; building user management; department grouping for simpler access policy management; door group definitions for policy assignment; visitor and contractor management with defined validity windows; and detailed access logs for security review and compliance audit.
Key Features
- Delivered physical access-control capability connecting door reader hardware to the platform’s central user management model.
- Stabilised the Windows-based access-control service deployment within a Linux-dominant cloud cluster.
- Connected physical access permissions to the platform’s central identity model managed in one place, enforced at the door.
- Gave building operators a web interface to manage access levels, building users, departments, door groups, visitor passes, and access logs.
Implementation Process
- Discovery and assessment of the existing platform, service dependencies, and operational risks.
- Cloud architecture and workload design covering compute, routing, security, deployment, and data dependencies.
- Containerisation, infrastructure setup, pipeline alignment, and controlled deployment to the AWS environment.
- Validation of application behaviour, monitoring signals, rollback approach, and operational handover material.
Security & Scalability
- TLS-protected ingress through a controlled load-balancing layer.
- Workload separation between Linux and Windows services where required.
- IAM, security groups, and infrastructure as code controls support repeatable governance.
- Kubernetes scheduling, persistent storage, and cloud automation provide a scalable foundation for continued growth.
Results & Business Impact
1 Central Cloud Access Model Created:
Access rights can be managed through the smart-building platform rather than separate local access-control tools, reducing administration overhead for building teams.
100% Alignment with Platform User Policy:
User access changes in the platform can flow into the access-control model, reducing the risk of removed users retaining physical access in a separate system.
24-Hour or Date-Based Access Windows Supported:
Temporary visitor and contractor access can be limited to defined dates and times, reducing standing access risk and improving governance for short-term building access.
Audit Trail for 3 Access Event Types:
Successful entries, access attempts, and denials are recorded for security reviews, compliance checks, and incident investigation.
2 Operating Systems Stabilised in 1 Release Model:
The Windows-based Paxton Net2 integration can be deployed alongside Linux services through a controlled cloud release model, reducing manual deployment handling.
Technology Stack
AWS Services & Infrastructure
Platform Dependencies
Delivery Tooling
Application Stack
Case Study Focus Tags
Conclusion
This project demonstrates Ficode’s expertise in AWS cloud solutions, smart-building platforms, Kubernetes deployments, and physical access control systems. By integrating cloud-based identity management with building security infrastructure, we delivered a scalable, secure, and future-ready solution that simplifies access management while supporting long-term business growth.
About Ficode
Ficode is a global software development and AWS consulting company specialising in cloud-native application development, AWS infrastructure, DevOps, QA & Software Testing, AI solutions, enterprise software engineering, and digital transformation. We help businesses worldwide build secure, scalable, and high-performance technology solutions that accelerate innovation and business growth.
Partner with Ficode to build secure, scalable, and cloud-native solutions on AWS.
Get in Touch