Idemia SIGMA Series Instruction manual

All descriptions illustrations, and specifications in this brochure should be
considered approximate and may relate to optional equipment or feature
Quick User Guide
SIGMA Series

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Table of Contents
293732943-F2
Color
Step
Content
One
Overview
Two
Wiring
Three
Communications
Four
SDAC (Single Door Access Control)
Five
Software
Six
Administration
Seven
Capture
basics

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
SIGMA Overview
293732943-F3
The SIGMA terminal has a simple and ergonomic
man-machine interface designed for access
control and Time & Attendance, with fingerprint
recognition, contactless card authentication and
PIN authentication options.
USB port (for
configuration and
settings with a
USB mass
storage key)
Step one : overview
USB host port
WR* product
comes with a
sensor protection
cap (not displayed
here)
5“ WVGA
touchscreen LCD
Optical biometrical sensor
VGA Camera
Speaker
Microphone
HID® iCLASS™ 13,56MHz (SIGMA … ICLASS)
Or MIFARE™DESFire ™13,56MHz (SIGMA .. MULTI)
Or HID® Prox ® 125kHz (SIGMA .. PROX)
Optional Contactless Card reader.
Specific logo on cover when available
Status LED

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
SIGMA Checklist
293732943-F4
QTY
ITEM
1
SIGMA terminal
1
Micro SD card installed
in the terminal
1
Wall Mount Plate
1
POE module
1
ProtectionAccessory
1
Connection cable
1
Documentation package
Step one : overview
Electronic documentation is provided in Adobe® Acrobat® format (PDF). Adobe® Acrobat® Reader is available at http://www.adobe.com.
Product packaging checklist:
Micro SD card must be installed in the
terminal at start up (storage area for internal
database and terminal logs)
Micro SD card replacement:
Class 10 or higher, 1GB min, 32GB max
Formatted by the terminal. Windows® PC
may damage the content of the card and
make it inoperative.
Use only Brand Name cards. No name card
may have lower performances or lower life
time.

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
SIGMA Series
293732943-F5
Step one : overview
Product
designation Biometrics
(Fingerprint)
iCLASS
®MIFARE®
DESFire®Prox®Water
Resistant (*)
SIGMA
SIGMA
iClass
SIGMA Multi
SIGMA
Prox
The SIGMA Series contains the following product variants:
Contactless Smart card reader
(*) For water resistance, units must be installed according to installation guidelines on Quick
Installation Guide

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
SIGMA terminal implementation
293732943-F6
Step one : overview
The SIGMA Series terminal
Its role is to process the access request from the user. It performs access
right checks using one-to-many biometric identification or one-to-one
biometric verification, and/or RF card authentication, and/or PIN check.
A Door Electric Latch or equivalent such Deadbolt, Door Strike or Magnetic Lock (3rd party product)
The Access Controller sends a command to activate the latch if the access is granted (i.e. if the individual's User ID is listed in the
Controller White List). Control of the latch is made through a dry contact..
An Alarm (3rd party product)
The terminal sends a message to the Access Controller, to activate the Alarm
as soon as a malicious activity such as tamper or pulling, is detected.
To secure an access, IDEMIA recommends installing the SIGMA Series terminal as a part of a typicalAccess Control system, this
consists of the components described below.
An Access Controller (3rd party product)
The terminal interfaces with an Access Controller (using TCP/IP,
Wiegand, Data Clock or RS485 protocol):
After user’s access rights checks, the terminal sends the result to
the Access Controller (this message contains at least the User ID)
The Access Controller performs additional checks, and returns the
final decision (access granted/denied) to the terminal (which
displays the result to the user), and to the door controller which
opens the door (if the access has been granted).
A
A
B
B
D
D
C
C

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
SIGMA Access Control Modes
293732943-F7
Step one : overview
(1) or the user enter their Identifier on the keypad, or a Wiegand frame is received from an external device
(2) stored on the contactless card or in the user record in the terminal’s local database
(3) There is no fingerprint image stored in the terminal, but only points of interest (minutiae) of each fingerprint
Identification
Authentication
Multifactor
Proxy
Access
control
a
pplication
Application that runs
on the terminal when
it starts.
Application that runs
on the terminal when
it starts.
Application that runs
on the terminal when
it starts.
Remote application
that controls the
terminal through
network commands
Access
control
triggering
event
A
user places a
finger on the
biometric sensor.
A user places
a
contactless
card in
front of
the reader (1)
Both
Identification
and Authentication
triggers are enabled.
Triggering events are
selected
by the
remote application
Biometric
check (if
enabled)
The user’s captured
fingerprint template
is matched against
all fingerprint
templates in the
terminal database (3)
The user’s captured
fingerprint templated
is
matched against
his reference
fingerprint templates
(2)
As per Identification
or Authentication,
depending on the
triggering event
Selected
by the
remote application
Decision
to
display
result
signal to user
By Identification
standalone
application
By Authentication
standalone
application
By
running
s
tandalone
application
By remote
application
The terminal can be configured in one of the modes described in the table below

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Deployment Environments
293732943-F8
Step one : overview
General precautions
Do not expose the terminal to extreme temperatures.
When the environment is very dry, avoid synthetic carpeting near the SIGMA terminal, to reduce the risk of
unwanted electrostatic discharge.
Areas containing combustibles
Do not install the terminal in the vicinity of gas stations or any other installation containing flammable or
combustible gases or materials. The terminal is not designed to be intrinsically safe.
The terminal should be installed in controlled lighting conditions
Avoid biometric sensor exposure to a blinking light
Avoid direct exposure of the biometric sensor to sunlight or to UV lights.
Outdoor installations recommendations
Outdoor devices shall not encounter extreme weather such as torrential rains, harvest rains, flooding.
High humidity, direct sun exposure, frequent high temperature, outdoor careless uses may alter the
durability of the terminal.
When the terminal is exposed to such potential extreme conditions, IDEMIA recommends deploying an
enclosure to protect the terminal and thus ensure a long-lasting performance in the field.
Operating temperature
-
20°to + 60 °C (- 4°to 140°F)
Operating
humidity
10 % < RH < 80 % (non condensing)
Storage
temperature
-
25°to + 70 °C (-13°to 158°F)
Storage
humidity
5% < RH < 95 %
IP code
IP65 rated (once wall
-mounted)
For UL 294 compliance, the products are rated for indoor use
(*) For water resistance, units must be installed according to installation guidelines on Quick Installation Guide

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Wiring Overview
293732943-F9
Step two : wiring
RJ-45
USB
µSD
RS422 / RS485
17
RS422_RX+ (A)
Blue / Black
15
RS422_RX
-(B)
Blue / White
16
RS422_TX+ / 485_TX/RX+ (Y)
Green / Black
18
RS422_TX
- / 485_TX/RX- (Z)
Green / White
19
RS422/485_GND
Black /
Red
Wiegand IN & Wiegand OUT
22
WIEGAND_IN0
Green /
Red
23
WIEGAND_IN1
White /
Red
20
WIEGAND_GND
Black /
Red
24
WIEGAND_OUT0
Green
21
WIEGAND_OUT1
White
25
WIEGAND_LEDOUT1
Blue
26
WIEGAND_LEDOUT2
Blue /
Red
GP IN & OUT
8
GPIO_GND
Black /
Red
9
GPI0
Orange
11
GPI1
Orange /
Red
13
GPI2
Orange / Black
10
GPO0
Yellow
12
GPO1
Yellow /
Red
14
GPO2
Yellow / Black
Power supply, Tamper switch & Relay
1
Power +12V
Red
2
Power GND
Black
3
SWITCH_PIN1
Light Blue
4
SWITCH_PIN2
Pink
5
RLY_NO
Yellow / White
6
RLY_COM
Grey / White
7
RLY_NC
Orange / White
All connections of the terminal are of SELV (Safety Electrical Low Voltage) type.
Power supply from electrical source shall be switched off before starting the installation.
Before proceeding, make sure that the person in charge of installation and connections, is properly connected to
earth, in order to prevent Electrostatic Discharges (ESD).
Backup of the Date/Time of the terminal: the volatile settings (such as date/time) of the terminal are protected against
power failure, by a dedicated component during a least 24 hours (at 25oC) without external power supply.

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Power Wiring
293732943-F10
Power Over Ethernet (POE): power can be provided through RJ-45 connector using
a PSE (Power Sourcing Equipment) IEEE 802.3af or IEEE802.3at type 1 compliant.
This feature requires a specific electronic card plugged at the rear of the product.
Warning: after use, the temperature of the POE module may be high: after power cut
off, wait 5mn before working on connectors area.
Step two : wiring
Gauge
AWG
Diameter
(mm)
Maximum voltage drop
(V)
at 1m at 5m
at 10m
20 0.81 0.03 0.17 0.33
22 0.64 0.05 0.26 0.53
24 0.51 0.08 0.42 0.84
RJ-45
POE
Power supply, Tamper switch & Relay
1
Power +12V
Red
2
Power GND
Black
External Power Supply: 12-24 Volts (regulated and filtered) 1 Amp min @12V, CEE/EEC EN60950 standard
compliant. A12 Volts power supply compliant with SIA's Wiegand standard will also be suitable. If sharing power
between devices, each unit must receive 1A (e.g. two units would require a 12VDC, 2A supply)
A battery backup or uninterrupted power supply (UPS) with built-in surge protection is recommended.
WARNING: Under powering may cause memory and data corruption; over powering may cause hardware damage.
Both of these situations will void the warranty
IDEMIA recommends using a gauge AWG20 for 12V power supply.
The voltage measured on the product block connector of the
terminal must be equal to 12V-24V (-15% / +10%).
The table at the right, shows the maximum voltage drop between
the power source and the terminal, depending on the length of the
cable.

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
RS-485 Communication
293732943-F11
Step three : communications
RS-232
from the
Com Port
RS-232 to RS-
485 converter RS-485 to
1200m (4000ft)
RS485
16
RS422_TX+ / 485_TX/RX+ (Y)
Green / Black
18
RS422_TX
- / 485_TX/RX- (Z)
Green / White
19
RS422/485_GND
Black /
Red
For RS-485 installations, the cable should be run in a
daisy-chain configuration (i.e. converter > position 1 >
position 2 > position 3, etc.).
Choose one twisted pair of conductors to use for
RS-485 TX/RX+(Y) (Green / Black wire) and RS-485
TX/RX-(Z) (Green / White wire).
Another conductor should be used for Signal
Ground (Black / Red Wire) .
Use CAT-5 UTP (or better) cable (shielded recommended) with a impedance of 120 . AWG 24 should be the
minimum wire gauge used.
Choose a RS-232 to RS-485 converter that supports Sense Data to switch from Send to Receive mode.
A maximum of 31 devices may be installed on the same line.
The maximum total cable length is 4000 ft. (1200m).
The cable must be dedicated to this installation and not used for any other purpose

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
RS-422 Communication
293732943-F12
Step three : communications
RS-232
from the
Com Port
RS-232 to RS-
422 converter RS-422 to
1200m (4000ft)
RS422
17
RS422_RX+ (A)
Blue / Black
15
RS422_RX
-(B)
Blue / White
16
RS422_TX+ / 485_TX/RX+ (Y)
Green / Black
18
RS422_TX
- / 485_TX/RX- (Z)
Green / White
19
RS422/485_GND
Black /
Red
For RS-422 installations, the cable should be run
in a point to point configuration (i.e. PC > converter
> terminal)
Choose one twisted pair of conductors to use for RS-
422 RX+(A) (Blue / Black wire) and RS-422 RX-(B)
(Blue / White wire).
Choose one twisted pair of conductors to use for RS-
422 TX+(Y) (Green / Black wire) and RS-422 TX-(Z)
(Green / White wire).
Another conductor should be used for Signal Ground
(Black / Red wire).
Use CAT-5 UTP (or better) cable (shielded recommended) with a impedance of 120 . AWG 24 should be the
minimum wire gauge used.
The maximum total cable length is 4000 ft. (1200m).
The cable must be dedicated to this installation and not used for any other purpose

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Ethernet and Wireless LAN
293732943-F13
Step three : communications
Management
station
LAN Ethernet
IP address
Mode Parameter Factory value
Static
Terminal IP address 192.168.1.10
Gateway IP address 192.168.1.254
Sub network mask 255.255.254.0
Host name MAsigma
RJ-45 Ethernet connection
Ethernet connection to the terminal is made through a
standard RJ-45 connector on the back of the terminal.
Use a category 5 shielding cable (120 Ohms) or better.
It is strongly recommended to insert a repeater unit
every 90m.
By default, SIGMA Series terminal is configured in
Static IP mode.

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Wiegand Communication
293732943-F14
Step three : communications
Wiegand Out
Wiegand In
LED Out
Wiegand IN & Wiegand OUT
22
WIEGAND_IN0
Green /
Red
23
WIEGAND_IN1
White /
Red
20
WIEGAND_GND
Black /
Red
24
WIEGAND_OUT0
Green
21
WIEGAND_OUT1
White
25
WIEGAND_LEDOUT1
Blue
26
WIEGAND_LEDOUT2
Blue /
Red
GP IN & OUT
10
GPO0
Yellow
LED In
Three-conductor wire (shielded recommended) is required for Data 0, Data 1, and WGND.
Use 18-22 AWG cable in a homerun configuration from each unit to the Access Control Panel (ACP).
Connect WIEGAND_OUT0 (Green Wire) to ACP Data 0,
Connect WIEGAND_OUT1 (White Wire) to ACP Data 1,
Connect WIEGAND_GND (Black / Red Wire) to ACP reader common (0vDC).
For 18 AWG, the maximum cable distance is 500 ft. (150m); for 20 AWG, the maximum is 300 ft. (90m); for 22
AWG, the maximum is 200 ft. (60m).
Electrical interface conforms to the Security Industry Association's Wiegand standard March 1995, and it is 5V
TTL compatible.

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Wiegand Communication (continued)
293732943-F15
Step three : communications
Example Format Information
Type: Standard 26-bit
Alt Site Code and Fail Site Code Range: 0-255
Template ID Number Range: 1-65535
Extended ID Number Range: N/A
ID Start Bit: 9
Length of ID: 16
Site Code Start bit: 1
Length of Site Code: 8
Start Bit length : 0
Data Clock Out
Data Clock In
LED Out
Wiegand IN & Wiegand OUT
22
WIEGAND_IN0
Green /
Red
23
WIEGAND_IN1
White /
Red
20
WIEGAND_GND
Black /
Red
24
WIEGAND_OUT0
Green
21
WIEGAND_OUT1
White
25
WIEGAND_LEDOUT1
Blue
26
WIEGAND_LEDOUT2
Blue /
Red
GP IN & OUT
10
GPO0
Yellow
LED In
Data
Clock
Data
Clock
Important
By default, the Wiegand output format is not enabled.
Wiegand output must be configured before connecting to the
ACP.
Note
On installation, the system administrator will be prompted to
select either a pre-existing Wiegand frame format or create
a custom
Data Clock
The Wiegand port also supports the Clock & Data protocol.
The wiring is described below.

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Single Door Access Control (SDAC)
293732943-F16
Step four:ACP or SDAC
GPI1
GPO0
GPI0
GPO1
Relay_NO
Relay_Com
Deadbolt / Door strike
Power
supply
Single Door Access Control (SDAC) wiring sample : with Push Button
Door contact
Power
supply
Push Button
GP IN & OUT
8
GPIO_GND
Black /
Red
9
GPI0
Orange
11
GPI1
Orange /
Red
13
GPI2
Orange / Black
10
GPO0
Yellow
12
GPO1
Yellow /
Red
14
GPO2
Yellow / Black
Relay
5
RLY_NO
Yellow / White
6
RLY_COM
Grey / White
7
RLY_NC
Orange / White
Warning
•Please check next page for important information about internal relay rating
•If door contact is not used, GPI1 (Orange / Red wire) and GPO1 (Yellow / Red wire) shall be
connected together
•Power supply from electrical source shall be switched off before starting the installation.

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Internal Relay Wiring (Normally open)
293732943-F17
Deadbolt / Door strike
Push Button
on other side
of the door
Snubber Diode
Example for normally
open connection
Step four:ACP or SDAC
Warning
This applies only for small or
stand-alone applications where
access control panels are not
available.
In this mode it is strongly
recommended to monitor the
Tamper Detection of the device
Relay mode can be changed to “normally close” instead of “normally closed” (default)
Relay
5
RLY_NO
Yellow / White
6
RLY_COM
Grey / White
7
RLY_NC
Orange / White
Inductive load management requires a parallel diode for a better contact lifetime.
Warning
The internal relay is limited to a maximum current of 2A @ 30V. If the deadbolt / door strike
draws more than 2A, damage to the device may occur. If the deadbolt / door strike load exceeds
2A, an external relay must be used.
The internal relay is designed for 100.000 cycles. If more cycles are needed, an external relay
driven by GPO must be used.
Power supply
VCC < 30V
Imax < 2A

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
18
Step five: software
Terminals are compatible with MorphoManager
application, version 15.5 or higher
293732943-F
Software for Remote Administration and Enrollment

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Local Administration - First Boot Assistant
293732943-F19
Main settings managed by FBA
Date & Time & Time Zone Settings
Trigger Event: select event(s) to be
processed as an access request by a user
Language Settings: user interface
language selection,
Network Settings: LAN or WLAN
parameters
Password Settings: terminal
administration password modification
Boot assistant at next boot: Display this
screen on next boot.
Protocol Settings: select communication
protocol : Bioscrypt 4G terminals, MA 500
and J Series (MA2G), or MorphoAccess
SIGMA (MA5G)
Step five: administration
The First BootAssistant (FBA) helps the administrator
configure all the device fundamental settings.
It is automatically launched at first terminal startup.
It can also be launched on demand, through
administration menu, if available (shall not be done in a
secure system, as described below).

IDEMIA DOCUMENT –REPRODUCTION AND DISCLOSURE PROHIBITED
Enforced security configuration
20 293732943-F
Step six: administration
Configuration from on-screen menu
disabled, except for IP configuration
Thrift commands from
RS485 disabled
IP connection possible
only in TLS 1.2
Configuration with a script hosted on a
USB dongle not possible
Webserver disabled
The terminal with firmware version 4.12 or higher has a default configuration enforcing security:
The default configuration is recommended by IDEMIA for operations. To use the features non available
by default, the On-demand security state can be unlocked with MorphoBioToolBox.
This shall not be done unless the end customer is made aware and an assessment on the
system security is done.
This manual suits for next models
3
Table of contents
Other Idemia Control System manuals
Popular Control System manuals by other brands

Amerec
Amerec T100 operating instructions

DX Engineering
DX Engineering Top Ten Devices OPSWAPPER quick start guide

Daintree
Daintree WWD2-4SM installation guide

Invicta
Invicta VR2 Installation guidelines

Zonex
Zonex System 2000 GEN II Installation and application manual

Vertiv
Vertiv WSN Gateway Installer and user guide