DEV Community

Cover image for System Design: Building an Offline-First RFID Access Control Pipeline for 10,000+ Users
stampiq
stampiq

Posted on

System Design: Building an Offline-First RFID Access Control Pipeline for 10,000+ Users

If you are a backend engineer tasked with building an event tech stack, it is easy to confuse event accreditation with access control.

Event accreditation is a standard web application problem: a user fills out a form on your registration platform, you run a background check, and you assign them a role (e.g., "VIP" or "Media") in a PostgreSQL database.

However, RFID delegate tracking management—the physical enforcement of those roles at the actual venue—is an entirely different beast. It is a high-stakes, high-concurrency IoT problem.

If you rely on cloud-connected mobile apps to scan QR codes at the venue doors, your system will collapse the moment the venue Wi-Fi drops or a local cellular tower saturates. When 500 VIPs are trying to enter a keynote hall and your API is returning 504 Gateway Timeout, the security guards will simply wave the crowd through, destroying your security perimeters.

To secure massive Vision 2030 exhibitions in Saudi Arabia, we had to eliminate the cloud dependency at the door. Here is how we architected an offline-first, passive RFID access control system.


1. The Edge Architecture: Moving Validation to the Portal

To eliminate doorway bottlenecks, we utilize passive Ultra-High Frequency (UHF) overhead portals. As delegates walk through an archway, the portal reads their embedded RFID badge.

Instead of sending that read event to the cloud for validation, the portal communicates via a local wired LAN to an Edge Controller (typically an industrial fanless PC or a hardened Raspberry Pi Compute Module).

The Edge Controller runs a lightweight daemon (often written in Go or Rust for memory safety and concurrency) and a local SQLite database containing the synchronized Access Control List (ACL).

The Edge Validation Logic (Go Concept)

When an RFID EPC (Electronic Product Code) is read, the daemon queries the local SQLite DB in microseconds. It does not wait for a cloud API.


go
package main

import (
    "database/sql"
    "fmt"
    "time"
    _ "[github.com/mattn/go-sqlite3](https://github.com/mattn/go-sqlite3)"
)

// ValidateAccess checks the local edge database for tier permissions
func ValidateAccess(db *sql.DB, epc string, portalZone string) (bool, error) {
    var isAllowed int

    // Query the local, synchronized Access Control List
    query := `
        SELECT COUNT(*) 
        FROM local_acl 
        WHERE epc_tag = ? AND allowed_zone = ? AND revoked = 0
    `
    err := db.QueryRow(query, epc, portalZone).Scan(&isAllowed)
    if err != nil {
        return false, err
    }

    // Log the transition locally for later cloud syncing
    logTransition(db, epc, portalZone, isAllowed > 0, time.Now().Unix())

    return isAllowed > 0, nil
}
If ValidateAccess returns true, the edge controller triggers a local GPIO relay to flash a green LED or open a physical turnstile. The entire round-trip takes less than 10 milliseconds.

2. The Sync Pipeline: MQTT Quality of Service 1
Just because validation happens offline does not mean the cloud stays blind. Operations teams still need a live real-time event analytics dashboard to monitor venue capacity.

To handle unreliable event networks, we use MQTT as our transport layer.

Cloud-to-Edge (ACL Sync): When a new VIP registers at a desk, the cloud pushes an MQTT message to the specific Edge Controller updating its local SQLite database.

Edge-to-Cloud (Telemetry Sync): As the edge controller validates badges, it queues those transition payloads. It uses MQTT Quality of Service (QoS) 1 to push the queue to the cloud. QoS 1 guarantees that the payload is delivered at least once.

If the internet goes down, the Edge Controller continues validating delegates perfectly using its local SQLite DB. Once the internet restores, the MQTT client automatically reconnects and flushes the queued telemetry to the cloud broker, backfilling the dashboard without any data loss.

Proven in the Desert: The AlFursan Endurance Cup
This architecture is not just a theoretical whiteboard exercise.

During the AlFursan Endurance Cup AlUla, the venue was spread across a remote desert environment with highly unstable cellular connectivity. By deploying offline-first edge controllers, StampIQ secured 5,000+ participants across 6 distinct security zones. Validation never went down, and the telemetry synced flawlessly whenever the connection stabilized.

Similarly, during the HUMAIN LEAP summit and the Gulf Cup Draw Ceremony, this edge architecture managed strict multi-tier access control seamlessly, feeding accurate capacity data directly to event directors without introducing doorway friction.

If you are an engineer or technical director tasked with modernizing access control for major GCC events, stop relying on cloud-dependent barcode scanners.

For enterprise-grade edge hardware and resilient RFID delegate tracking management, explore the infrastructure built by StampIQ.
Enter fullscreen mode Exit fullscreen mode

Top comments (0)