Skip to main content

Smart Campus Attendance: A Three-Factor Biometric IoT System with Firebase-Powered Role-Based Web Da

Page 1


International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

Smart Campus Attendance: A Three-Factor Biometric IoT System with Firebase-Powered

Role-Based Web

Dashboards

1,2,3B.Tech Scholar, Dept. of Computer Science and Engineering, Raj Kumar Goel Institute of Technology, Ghaziabad, India

Abstract - Colleges in India still mark student attendance on paper or with basic card-swipe terminals. Both methods share one fundamental problem: a student can be marked present without being physically there. We built a system to make that impossible. Our Smart Campus Attendance System runs on an ESP32 microcontroller and requires three sequential identity checks before logging any attendance event: a tap of an RFID card, a fingerprint scan, and a face match against the enrolled photograph. All three must pass. A single failure aborts the process and logs a rejected attempt for administrative review. Once verified, the event travels over Wi-Fi to a Firebase Firestore backend, which persists the record and triggers a Socket.IO broadcast. Four separate React 19 dashboards, one each for students, faculty, Heads of Department, and parents, receive this update within milliseconds. Students can check their own attendance percentage and marks, compare their standing against classmates, and read messages from teachers. Faculty can see which students are falling behind, enter marks, and send notifications to parents. The HOD view covers departmentwide trends. Parents see only their ward's data, in real time. We tested the system across 50 enrolled students over 312 attempts. Three-factor verification passed at a combined rate of 94.2%. Average end-to-end latency from card tap to dashboard update was 6.7 seconds. Socket.IO propagation to open clients averaged 480 milliseconds. The full stack is open source: Python, React 19, Tailwind CSS, Recharts, Firebase, and Socket.IO.

Key Words: IoT,ESP32,RFID,fingerprintrecognition,face recognition,FirebaseFirestore,Socket.IO,React19, attendancemanagement,academicERP,role-based dashboard

1. INTRODUCTION

Walk into any undergraduate classroom in India during attendance time and the scene is the same: the teacher calls names, students say present, someone marks a register.Ittakestenminutesandproducesarecordthatis easy to manipulate. A student who skips class simply arrangesforafriendtoanswer.Bythetimeaparentfinds outtheirchildhas40%attendance,thesemesterisnearly over.

Card-based systems were introduced to speed this up. They work for speed but not for fraud. Owning a card is not the same as being the person whose name is on it. Single-factor systems share this weakness: defeating one factordefeatsthesystementirely.

We designed a three-factor terminal to remove that option. Our device, built on an ESP32 microcontroller, requires a student to tap their RFID card, pass a fingerprint match, and clear a face verification check in that order before any attendance event is recorded. The ESP32 costs under 300 rupees, the RC522 RFID module under 50, and the AS608 fingerprint sensor under 150. What has been missing from the literature is a system combining these factors with a real-time data layer and role-specificdashboardsthatdeliververifieddatatoevery stakeholderimmediately.

Theprimarycontributionsofthisworkare:

• A three-factor biometric attendance terminal on ESP32 (RFID, fingerprint, face) that removes proxy attendancewithoutexpensiveinfrastructure.

• A Firebase Firestore and Socket.IO pipeline propagating verified events to dashboards in under 500milliseconds.

• Four role-differentiated React 19 dashboards, Student, Faculty, HOD, and Parent, each scoped to whatthatuserneeds.

• A Python face verification service using the face_recognition library (dlibResNet backend) integratedintothehardwarepipeline.

2. RELATED WORK

2.1 RFID-Based Systems

Umar et al. [1] combined a GSM module with an RFID reader so that when a student swiped a card, the parent received an SMS. Useful for notification, but the system trusted whoever held the card. Patil et al. [2] stored RFID attendance in a structured database, though card sharing remainedanunresolvedvulnerability.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

2.2 Fingerprint Recognition

Shoewu and Idowu [3] achieved near-zero false acceptance in a university fingerprint deployment. Their FalseRejectionRaterosewhensensorsurfacesweredirty orstudentshaddryorinjuredfingertips.Theirconclusion was that a backup modality would make any fingerprintbasedsystemmorerobustinpractice.

2.3 Face Recognition

Adjabi et al. [4] reviewed a decade of face recognition literature and found that controlled environment 2D systems perform well, but performance drops when ambient conditions change. Guo and Zhang [5] surveyed over 330 deep learning contributions and documented CNN architectures achieving above 97% accuracy on standard benchmarks, while illumination sensitivity remainsadeploymentconstraint.

2.4 Multi-Factor and IoT Approaches

Bhatt and Bhatt [6] paired RFID with face recognition for campusaccessandshowed thattwo factors raisethecost of impersonation considerably. Their system lacked any dashboard layer. Sharma et al. [7] deployed an ESP8266 with RFID and cloud sync, demonstrating IoT-based captureisviable,butwithoutbiometricverificationorany stakeholder-facinginterface.

2.5

Gap in Literature

No published system identified in this review combines three biometric factors on IoT hardware with a real-time cloudpipelineandmultiplerole-differentiateddashboards in a single deployment. We address all three simultaneously.

3. SYSTEM ARCHITECTURE

3.1 Three Layers

The system has three layers: Hardware Verification, Backend Data, and Presentation. Attendance events originate at the hardware terminal, flow through the backendforpersistenceandbroadcast,andarereceivedin realtimebytherole-appropriatedashboard.Eachlayeris decoupled at its interface. The ESP32 communicates with thebackendonlythroughHTTPSRESTcalls.Thebackend emitsSocket.IOeventswithoutknowinghowmanyclients are connected. The frontend consumes typed payloads withoutdependingonhardwareimplementationdetails.

3.2 Hardware Terminal

Each terminal is built around the ESP32 microcontroller, chosen for its dual-core Xtensa LX6 processor, 520 KB of SRAM, and native 802.11 b/g/n Wi-Fi. Four peripherals attachtoit.

• RC522 RFID Reader (SPI): Detects Mifare-standard cardsupto5cmawayandreadsthe4-bytecardUID. Nocarddataisstoredonthedevice.

• AS608 Fingerprint Sensor (UART at 57,600 baud): Stores pre-enrolled templates in onboard flash and runs matching locally. Only a confidence integer is returned.Nofingerprintimageleavesthesensor.

• OV2640 Camera Module: Captures a JPEG frame after fingerprint clearance and transmits it to the PythonfaceverificationserviceoverHTTPSPOST.

• SSD1306 OLED Display (I2C): Shows step-by-step verification status to the student, reducing uncertaintyandtimespentattheterminal.

3.3 Three-Factor Verification Flow

The terminal uses a strict sequential gate model. Each factormustclearitsthresholdbeforethenextactivates.

1)StudenttapsRFIDcard.FirmwarereadstheUIDand sends an HTTPS GET to the backend to retrieve the studentprofile,includingfingerprinttemplateIDand storedfaceembedding.

2)Fingerprint sensor activates. Module compares againstthelinkedtemplateandreturnsaconfidence score.Anythingbelow60endsthesessionandlogsa factor-levelfailure.

3)Camerafiresoneframe.TheJPEGisbase64-encoded and sent to the Python Flask service, which returns anacceptorrejectwithadistancevalue.

4)If all three factors pass, firmware posts an attendance payload: student ID, terminal ID, UTC timestamp,andthethreeconfidencevalues.

5)OLED shows the result. Backend writes to Firestore andemitsa Socket.IO event. Open dashboardclients updatewithinmilliseconds.

3.4 Backend Layer

Firebase Firestore stores students, faculty, subjects, attendance records, marks, notifications, and roles. Firebase Authentication issues JWTs with custom claims encoding each user's role and linked entity ID. Firestore securityrulesenforcerow-levelaccess.Studentsreadonly their own records. Faculty write only to their assigned subjects.Parentsreadonlytheirlinkedward'ssubtree.

ASocket.IOserverrunsasaNode.jsprocess.Onreceiving a valid attendance event, the server writes the Firestore document and emits a role-filtered Socket.IO event

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

immediately. Session context stores role and entity ID fromtheJWT,soeachemitisscopedtotherightaudience withoutaper-eventdatabaselookup

3.5 Frontend Dashboards

Four React 19 modules share a common authentication context. React Router DOM v7 guards every dashboard route. Tailwind CSS handles styling. Recharts renders all charts.FramerMotionanimatesroutetransitions.

• Student Dashboard: attendance percentage per subject,sessionlog,marksperassessment,semester trendgraph,classattendanceranking,anda teacher notificationfeed.

• Faculty Dashboard: class attendance table with threshold alerts, marks entry form with perassessment granularity, and a notification composer forindividualparentsorentireclassgroups.

• HOD Dashboard: faculty-wise summaries, departmentattendancetrends,studentperformance distributions, notification log, and drill-down into individualprofiles.

• Parent Dashboard: read-only. Subject-wise and session-level attendance, marks per subject, and a livenotificationfeedfromfaculty.

4. IMPLEMENTATION

4.1 ESP32 Firmware

FirmwarewaswrittenintheArduinoIDEusingtheESP32 Arduino Core. The MFRC522 library handles SPI communication with the card reader. AS608 communication uses the Adafruit Fingerprint Sensor protocol over hardware UART2. ArduinoJSON builds and parses all JSON payloads. The main loop runs a state machine: idle state polls the RFID reader at 100 ms intervals,carddetectiontransitionstoverifystate,andthe machine returns to idle after each attempt regardless of outcome.AllHTTPScallsusecertificatepinning.Firmware updatesdeployviaArduinoOTAwithoutphysicalterminal access.

4.2 Face Verification Service

The Python service is a Flask application with one endpoint:POST/verify.Therequestbodycarriesabase64 JPEG. The service decodes it, calls face_recognition.face_locations() to find the largest face bounding box, then face_recognition.face_encodings() to compute the 128-dimensional embedding. It compares against the stored reference embedding using Euclidean distance.

Distance below 0.45 is a clean accept. Between 0.45 and 0.55 is flagged as low-confidence and logged for administrator review. Above 0.55 is rejected. We chose

this range by testing against 50 enrollment sets under three lighting conditions. Deploying this as a separate Flask microservice allows the recognition model to be replacedwithouttouchinganyothercomponent.

4.3 Firebase and Security

Firestoresecurity rulesare deployedvia theFirebaseCLI. The Socket.IO server decodes the Firebase JWT on connection and stores role and entity ID in session context. This controls which channels the client joins and whicheventsareemittedthroughoutthesession,avoiding per-eventdatabaselookups.

4.4

React Frontend

A context-based authentication provider decodes the FirebaseJWTonloginandexposesroleandentityIDtoall child components. Protected routes use a PrivateRoute wrapper that redirects unauthenticated users to the login screen. Each dashboard module is lazy-loaded to reduce initialbundlesize.TheSocket.IOclientconnectsonceafter login. A useReducer hook manages attendance state, updating only affected components when a new event arrives. Recharts ResponsiveContainer ensures charts adapt to viewport changes without additional breakpoint logic.

5. RESULTS AND EVALUATION

5.1

Biometric Accuracy

We ran 312 verification attempts across 50 enrolled students. RFID read success was 100% within 0 to 5 cm. Nomisreadsoccurredatthatdistance.

TheAS608fingerprintmodulerejectedvalidfingers2.6% ofthetime.Allrejectionsoccurredwithstudentswhohad dry skin or a recent fingertip cut. False acceptances numbered zero across all 312 attempts. We re-enrolled the three highest-rejection students with improved placement guidance; their rejection rate dropped to zero infollow-upsessions.

Face verification using the dlibResNet model accepted valid faces at 96.4% under overhead fluorescent lighting, droppingto90.5%underdirectwindowbacklight.Adding a positioning instruction to the OLED at the camera step recovered most of this gap in subsequent sessions. Combined across all three factors, 93.9% of attempts completedsuccessfully.

5.2 End-to-End Latency

Latency was measured from RFID card tap to Socket.IO eventreceivedbyanopen dashboardclient.Averageend-

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

to-end latency was 6.7 seconds. Table 1 shows the breakdownbystage.

Table 1: End-to-EndPipelineLatency

6. CONCLUSIONS

Wesetouttosolvetwoproblemsthatexistingautomated attendance systems leave open: weak identity confirmation at the point of capture, and the absence of a useful informationlayerfor thestakeholders whodepend onattendancedata.Oursystemaddressesboth.

The hardware terminal enforces three sequential biometricchecksbeforelogginganyevent.Across312test attempts the combined success rate was 93.9% with zero false acceptances. The Firebase and Socket.IO backend delivered verified events to open dashboard clients in under 500 milliseconds on average. The four React 19 dashboards gave students, faculty, HODs, and parents direct access to the data they needed, without exposing datatheyshouldnotsee.

The face verification step dominates total latency. Moving inferenceon-deviceusingTensorFlowLiteonanESP32-S3 istheplannedpathtoreducethis.

5.3 Dashboard Performance

Initial dashboard load from login to first data render averaged 1.3 seconds on campus Wi-Fi. Socket.IO events reached open clients within 480 milliseconds of each Firestorewriteonaverage.Theslowestobservedwas910 milliseconds during a session with eleven simultaneously logged-in clients. Faculty notifications reached parent dashboardswithin3secondsinalltests.

5.4 Comparative Analysis

Table 2 compares our system against prior single-factor approaches.

Table 2: FeatureComparisonAgainstPriorApproaches

Feature Prior Systems [17] This Work

Identitycheck Singlefactoronly RFID+fingerprint+ face

Proxyattendance Stillpossible Eliminatedby design

Hardware GSM/standalone modules ESP32withonboard Wi-Fi

Livedatasync Absent Firebase+Socket.IO Dashboards Noneorbasicpage 4role-differentiated views

Parentnotification SMSonlyorabsent Real-time dashboardfeed

Marksmanagement Notincluded Integratedfaculty interface

Peerranking Notavailable Liveclassranking

Three improvements are planned. First, Android and iOS companionappsusingReactNativesoparentscanreceive notifications without a browser session. Second, a TensorFlow Lite model running on the ESP32-S3, removing the network-dependent Python service and makingeachterminalself-contained.Third,anattendance predictionmodulethatflagsstudentstrendingtowardthe 75% minimum threshold early enough for faculty to intervene.

ACKNOWLEDGEMENT

We thank Mr. Lalit Saraswat, Guide and Assistant Professor, Department of Computer Science and Engineering, Raj Kumar Goel Institute of Technology, Ghaziabad, for his guidance, technical advice, and consistentsupportthroughoutthisproject.

REFERENCES

[1] I. Umar, A. Zulkifli, and N. A. Umar, "Student attendance management system using RFID and SMS," in Proc.ICEEOT,Chennai,India,2016,pp.468-472.

[2] S. S. Patil, S. S. Chitnis, and A. M. Bagade, "Automatic attendance marking system using RFID," Int. J. Innovative Research in Computer and Communication Engineering, vol.3,no.4,pp.3136-3142,Apr.2015.

[3] O.Shoewu and O. A. Idowu, "Development of attendance management system using biometrics," The Pacific Journal of Science and Technology, vol. 13, no. 1, pp.300-307,May2012.

[4] I.Adjabi,A.Ouahabi,A.Benzaoui,andA.Taleb-Ahmed, "Past, present, and future of face recognition: A review," Electronics,vol.9,no.8,p.1188,Aug.2020.

[5] G.GuoandN.Zhang,"Asurveyondeeplearningbased face recognition," Computer Vision and Image Understanding,vol.189,p.102805,2019.

International Research Journal of Engineering and Technology (IRJET) e-ISSN: 2395-0056

Volume: 13 Issue: 04 | Apr 2026 www.irjet.net p-ISSN: 2395-0072

[6] R.BhattandA.Bhatt,"Asecureaccesscontrolsystem using RFID and face recognition," in Proc. ICCCA, Greater Noida,India,2017,pp.1176-1180.

[7] R. Sharma, A. Dhingra, and P. K. Gupta, "Smart attendance system using IoT and cloud computing," in Proc.IoT-SIU,Bhimtal,India,2018,pp.1-5.

[8] R. Kumari, S. Gupta, and A. Khatri, "Web-based academic management system: A comprehensive review," Int.J.EngineeringResearchandApplications,vol.6,no. 3, pp.28-34,Mar.2016.

Turn static files into dynamic content formats.

Create a flipbook
Smart Campus Attendance: A Three-Factor Biometric IoT System with Firebase-Powered Role-Based Web Da by IRJET Journal - Issuu