Skip to main content

Solution Composition

The Embedded Biometrics solution is composed of a suite of on-device SDKs and a server-side Biometric Identification Service. Each component can be licensed independently or combined to match the requirements of a specific integration.

All on-device SDKs are built for client / edge deployment — handhelds, kiosks, PoS, cameras, AI boxes, access-control terminals. For centralized server-side identification workloads, see Biometric Identification Service.

Architecture at a glance

The map below shows where each component runs and how they combine. Capture is optional — the DOT Auto-capture components feed the on-device SDKs; the priority is on-device processing, which runs fully offline; and the server-side Biometric Identification Service handles centralized 1:N identification when a large or shared gallery is needed (hybrid deployment).

On-device / Edgeintegrator-owned · offline-capable
1Captureoptional
DOT Auto-capture · Android & iOSface & palm — guided capture
2On-device SDKs
SFE Toolkitface · iris · palm
Enrollment SDKfingerprint · face · iris
IDKitfingerprint
ANSI & ISOfingerprint
SFE Stream Processorface · camera / AI box — uses SFE Toolkit
On-device matching, fully offline — biometric data stays on the device
hybridREST / TLS
Server / Cloudintegrator-operated
Biometric Identification Service
  • 1:N identification — face & palm
  • watchlist management
  • passive liveness
inputs: images from capture components, or SFE Toolkit templates (compatible template version required)
Watchlist database
Centralized, large-gallery identification beyond the on-device limit
Fully on-device — offline identificationHybrid — on-device capture → server 1:NServer-side — thin clients → Biometric Identification Service

The integrator owns and controls all biometric data end-to-end. In on-device and offline deployments, templates and watchlists are stored and matched entirely on the integrator's own device and never leave it. In hybrid deployments, centralized identification runs on the integrator's own on-prem server or cloud — Innovatrics neither hosts nor processes the data.

Components at a glance

ComponentRole
SFE ToolkitOn-device face, iris, and palm — detection, matching, liveness, age; the only SDK with hardware acceleration.
Enrollment SDKOn-device fingerprint, face, and iris for enrollment-grade capture on PC and Android.
IDKit SDKOn-device fingerprint matching for embedded Linux targets.
ANSI & ISO SDKStandards-compliant fingerprint templates for interoperability.
SFE Stream ProcessorFace processing on cameras and AI boxes; built on the SFE Toolkit face engine.
Biometric Identification ServiceServer-side 1:N identification and watchlist management beyond the on-device gallery limit.

On-device SDKs

The on-device SDK suite consists of five production SDKs. Each targets a specific combination of platforms, modalities, and use cases — pick by what the target device runs and what needs to happen on it.

Each SDK implements a subset of the shared Features: Identification (1:N), Verification (1:1), Enrollment, Liveness, Auto-capture, and Hardware acceleration.

Common characteristics across the suite:

  • Multimodal coverage — face, iris, and fingerprint, including contactless palm
  • On-device liveness detection (PAD) for spoof prevention in challenging conditions
  • Low footprint suitable for embedded and edge devices, optimized for ARM / NPU targets
  • High accuracy retained on resource-constrained, low-end hardware while maintaining high processing speed — built on NIST top-ranked algorithm technology, shipped as embedded-optimized builds for the device
  • Engineering-led integration support

SFE Toolkit

  • Modalities: Face, Iris, Palm
  • Features: detection and basic quality; template extraction; 1:1 and 1:N; passive liveness; age & gender; auto-capture; hardware acceleration
  • Platforms: Windows, Linux, Android, Embedded Linux (custom porting supported)
  • Primary use cases: access control, time & attendance, PoS, handheld industrial devices

Enrollment SDK

  • Modalities: Fingerprint, Face, Iris
  • Features: detection and basic quality; template extraction; 1:N across all three modalities; face passive liveness; age & gender; ICAO face quality check; advanced fingerprint quality checks and slap segmentation; ANSI/ISO fingerprint template export (extraction only — matching standards-based templates requires the ANSI & ISO SDK)
  • Platforms: Windows, Linux, Android (no embedded / porting)
  • Primary use cases: enrollment, ID issuance, kiosks, gates, field enrollment

IDKit SDK

  • Modalities: Fingerprint
  • Features: quality check; proprietary template extraction; 1:N identification
  • Platforms: Embedded Linux / porting only — for Windows, Linux, or Android fingerprint integrations, use the Enrollment SDK (proprietary) or ANSI & ISO SDK (standards-based)
  • Primary use cases: access control and time & attendance when fingerprint is required on an embedded Linux target

ANSI & ISO SDK

  • Modalities: Fingerprint
  • Features: quality check; standards-compliant (ANSI/ISO) template extraction; optional 1:1 verification
  • Platforms: Windows, Linux, Android, Embedded Linux / RTOS / porting
  • Primary use cases: standards interoperability for fingerprint — national ID programs (e.g. UIDAI), fingerprint modules, scanners
  • Note: standards-based interop (ANSI/ISO) is fingerprint-only; face, iris, and palm all use proprietary templates

SFE Stream Processor

  • Modalities: Face
  • Features: detection and basic quality; template extraction; 1:N identification; passive liveness; single and multi-stream processing; built-in pipeline configuration, MQTT messaging, and direct camera / RTSP ingestion
  • Built on: the SFE Toolkit face engine — hardware acceleration on supported chipsets is provided by SFE Toolkit
  • Platforms: cameras, AI boxes, Android
  • Primary use cases: physical security and access control, live-stream identification
  • Note: not an SDK embedded into the customer's application — a standalone component configured and deployed as-is. Materially less integration effort than wiring a pipeline on top of an SDK, but still requires configuration.

Baselines and interoperability

  • Detection and basic quality are included in every SDK for its supported modalities. ICAO-grade face quality and advanced fingerprint quality checks are exclusive to the Enrollment SDK for enrollment-grade capture.
  • Standards-based (ANSI/ISO) template interchange is supported for fingerprint only. Face, iris, and palm always use proprietary templates.

Choosing an SDK

By use case:

  • Access control, time & attendance, PoS, handheld devices — SFE Toolkit (face / iris / palm) or IDKit SDK (fingerprint)
  • Enrollment, ID issuance, kiosks, gates, field enrollment — Enrollment SDK
  • Cameras and AI boxes processing live video streams — SFE Stream Processor
  • Standards interoperability (fingerprint only — NID, UIDAI, FP scanners / modules) — ANSI & ISO SDK
  • Fingerprint on embedded Linux / RTOS / custom porting — IDKit SDK (proprietary) or ANSI & ISO SDK (standards-based)

By platform:

  • Windows / Linux / Android — SFE Toolkit, Enrollment SDK, ANSI & ISO SDK (not IDKit — embedded Linux only)
  • Embedded Linux / RTOS / porting — SFE Toolkit (face / iris / palm), IDKit SDK (fingerprint, proprietary), ANSI & ISO SDK (fingerprint, standards)
  • Cameras / AI boxes — SFE Stream Processor

By modality:

  • Face — SFE Toolkit (1:1 + 1:N on-device), SFE Stream Processor (streams), Enrollment SDK (enrollment flows)
  • Fingerprint — Enrollment SDK (proprietary, non-embedded Linux), IDKit SDK (proprietary, including embedded Linux), ANSI & ISO SDK (standards-based, including embedded Linux)
  • Iris — SFE Toolkit or Enrollment SDK
  • Palm — SFE Toolkit

Supported Platforms — On-device SDKs

PlatformArchitecture
Windowsx86_64
Linuxx86_64
AndroidARMv7 and ARM64
iOSARM64 (custom porting required)
Embedded LinuxARMv7 and ARM64 (custom porting required)

Supported Hardware Accelerators — SFE Toolkit

Hardware acceleration is provided by the SFE Toolkit (face, iris, palm) — and, by extension, the SFE Stream Processor built on it. The fingerprint SDKs (Enrollment, IDKit, ANSI & ISO) run on CPU.

VendorModelsSupported Modalities
NVIDIA JetsonJetson platforms with CUDA/TensorRT, Jetpack 6.xFace, Iris, Palm
Ambarella CV FlowCV28, CV25, CV22, CV2Face, Face Liveness
Rockchip RKNPURV1126Face, Face Liveness
Rockchip RKNPU2RK3566/RK3568, RK3576Face, Face Liveness, Iris, Palm, Palm Liveness
NXPi.MX 8M PlusFace, Face Liveness
Android GPUs/NPUsQualcomm, MediaTek, ARM MaliFace, Face Liveness

Supported Edge Cameras and AI Boxes — SFE Stream Processor

VendorAcceleratorModels
AXIS — M seriesAmbarella CV25M4216-LV, M1055-L, M2035-LE, P12 Mk II, P1467-LE, P3267-LV, I8116-E
Hanwha — P seriesAmbarella CV2PND-A6081RV, PNV-A6081R, PND-A6081RF, PNO-A6081R, PND-A9081RV, PNO-A9081R
NVIDIA Jetson platformsCUDA, Tensor coresJetson Orin models (Jetpack 6.x)

Biometric Identification Service

Biometric Identification Service (formerly LFIS) is a high-performance, server-based biometric API for 1:N identification and verification using face and palm modalities. It is the path for centralized, large-gallery identification beyond the on-device 1:N limit (~1:50K). Built with cloud-native principles, it can be deployed on-premises or in the customer's cloud. Passive liveness detection is available as an add-on for both face and palm.

FeatureDescription
Detection & Quality AssessmentAutomatic detection of faces and palms from incoming images, including quality assessment to ensure compliance with recognition thresholds.
1:N IdentificationSearches a live-captured image or extracted template against a configurable watchlist and returns the most likely match with a confidence score.
Passive Liveness DetectionDetects presentation attacks without requiring user interaction, for both face and palm modalities.
Watchlist ManagementEnroll, update, and remove biometric data via API. Supports dynamic watchlist creation and unlimited watchlists within the standard database size.
RESTful APISupports real-time matching, asynchronous queries, and secure communications (TLS, authentication tokens). Integrates with web, mobile, or embedded client applications.
Cloud-ready DeploymentDeployable as a local server component or scaled in Kubernetes/Docker-based cloud infrastructure.

Supported Platforms — Biometric Identification Service

PlatformArchitecture
Linuxx86_64

See also