An IDEX total access card with DESFire will support all DESFire security settings for the DESFire applications, as well as the option of requiring a biometric match against the enrolled fingerprints.
Readers configured to accept a DESFire application will generally:
- Select the configured Application ID
- Authenticate with the configured key
- Read the desired data out of the configured file
- Return this data to the access control system
When a DESFire application is configured to require a biometric match, this match is performed at step 1 (select the configured Application ID). On a biometric success, the desired Application ID is selected.
Performing this biometric match adds roughly 250 milliseconds to the transaction time.
See: What happens when there is no biometric match? and Supported door readers.