Diffie-hellman would not be enough if there is a MITM at the time of the exchange, would it?
Somehow the control panel and the reader must authenticate each other. I'm no security expert but only way I can think of is to use some pre-shared key. A key set via a trusted side channel, or at a time when the osdp channel is known to not be intercepted.