Solution Composition
The Embedded Biometrics solution is composed of a suite of on-device SDKs and a server-side Biometric Identification Service. Each component can be licensed independently or combined to match the requirements of a specific integration.
All on-device SDKs are built for client / edge deployment — handhelds, kiosks, PoS, cameras, AI boxes, access-control terminals. For centralized server-side identification workloads, see Biometric Identification Service.
Architecture at a glance
The map below shows where each component runs and how they combine. Capture is optional — the DOT Auto-capture components feed the on-device SDKs; the priority is on-device processing, which runs fully offline; and the server-side Biometric Identification Service handles centralized 1:N identification when a large or shared gallery is needed (hybrid deployment).
- 1:N identification — face & palm
- watchlist management
- passive liveness
The integrator owns and controls all biometric data end-to-end. In on-device and offline deployments, templates and watchlists are stored and matched entirely on the integrator's own device and never leave it. In hybrid deployments, centralized identification runs on the integrator's own on-prem server or cloud — Innovatrics neither hosts nor processes the data.
Components at a glance
| Component | Role |
|---|---|
| SFE Toolkit | On-device face, iris, and palm — detection, matching, liveness, age; the only SDK with hardware acceleration. |
| Enrollment SDK | On-device fingerprint, face, and iris for enrollment-grade capture on PC and Android. |
| IDKit SDK | On-device fingerprint matching for embedded Linux targets. |
| ANSI & ISO SDK | Standards-compliant fingerprint templates for interoperability. |
| SFE Stream Processor | Face processing on cameras and AI boxes; built on the SFE Toolkit face engine. |
| Biometric Identification Service | Server-side 1:N identification and watchlist management beyond the on-device gallery limit. |
On-device SDKs
The on-device SDK suite consists of five production SDKs. Each targets a specific combination of platforms, modalities, and use cases — pick by what the target device runs and what needs to happen on it.
Each SDK implements a subset of the shared Features: Identification (1:N), Verification (1:1), Enrollment, Liveness, Auto-capture, and Hardware acceleration.
Common characteristics across the suite:
- Multimodal coverage — face, iris, and fingerprint, including contactless palm
- On-device liveness detection (PAD) for spoof prevention in challenging conditions
- Low footprint suitable for embedded and edge devices, optimized for ARM / NPU targets
- High accuracy retained on resource-constrained, low-end hardware while maintaining high processing speed — built on NIST top-ranked algorithm technology, shipped as embedded-optimized builds for the device
- Engineering-led integration support
SFE Toolkit
- Modalities: Face, Iris, Palm
- Features: detection and basic quality; template extraction; 1:1 and 1:N; passive liveness; age & gender; auto-capture; hardware acceleration
- Platforms: Windows, Linux, Android, Embedded Linux (custom porting supported)
- Primary use cases: access control, time & attendance, PoS, handheld industrial devices
Enrollment SDK
- Modalities: Fingerprint, Face, Iris
- Features: detection and basic quality; template extraction; 1:N across all three modalities; face passive liveness; age & gender; ICAO face quality check; advanced fingerprint quality checks and slap segmentation; ANSI/ISO fingerprint template export (extraction only — matching standards-based templates requires the ANSI & ISO SDK)
- Platforms: Windows, Linux, Android (no embedded / porting)
- Primary use cases: enrollment, ID issuance, kiosks, gates, field enrollment
IDKit SDK
- Modalities: Fingerprint
- Features: quality check; proprietary template extraction; 1:N identification
- Platforms: Embedded Linux / porting only — for Windows, Linux, or Android fingerprint integrations, use the Enrollment SDK (proprietary) or ANSI & ISO SDK (standards-based)
- Primary use cases: access control and time & attendance when fingerprint is required on an embedded Linux target
ANSI & ISO SDK
- Modalities: Fingerprint
- Features: quality check; standards-compliant (ANSI/ISO) template extraction; optional 1:1 verification
- Platforms: Windows, Linux, Android, Embedded Linux / RTOS / porting
- Primary use cases: standards interoperability for fingerprint — national ID programs (e.g. UIDAI), fingerprint modules, scanners
- Note: standards-based interop (ANSI/ISO) is fingerprint-only; face, iris, and palm all use proprietary templates
SFE Stream Processor
- Modalities: Face
- Features: detection and basic quality; template extraction; 1:N identification; passive liveness; single and multi-stream processing; built-in pipeline configuration, MQTT messaging, and direct camera / RTSP ingestion
- Built on: the SFE Toolkit face engine — hardware acceleration on supported chipsets is provided by SFE Toolkit
- Platforms: cameras, AI boxes, Android
- Primary use cases: physical security and access control, live-stream identification
- Note: not an SDK embedded into the customer's application — a standalone component configured and deployed as-is. Materially less integration effort than wiring a pipeline on top of an SDK, but still requires configuration.
Baselines and interoperability
- Detection and basic quality are included in every SDK for its supported modalities. ICAO-grade face quality and advanced fingerprint quality checks are exclusive to the Enrollment SDK for enrollment-grade capture.
- Standards-based (ANSI/ISO) template interchange is supported for fingerprint only. Face, iris, and palm always use proprietary templates.
Choosing an SDK
By use case:
- Access control, time & attendance, PoS, handheld devices — SFE Toolkit (face / iris / palm) or IDKit SDK (fingerprint)
- Enrollment, ID issuance, kiosks, gates, field enrollment — Enrollment SDK
- Cameras and AI boxes processing live video streams — SFE Stream Processor
- Standards interoperability (fingerprint only — NID, UIDAI, FP scanners / modules) — ANSI & ISO SDK
- Fingerprint on embedded Linux / RTOS / custom porting — IDKit SDK (proprietary) or ANSI & ISO SDK (standards-based)
By platform:
- Windows / Linux / Android — SFE Toolkit, Enrollment SDK, ANSI & ISO SDK (not IDKit — embedded Linux only)
- Embedded Linux / RTOS / porting — SFE Toolkit (face / iris / palm), IDKit SDK (fingerprint, proprietary), ANSI & ISO SDK (fingerprint, standards)
- Cameras / AI boxes — SFE Stream Processor
By modality:
- Face — SFE Toolkit (1:1 + 1:N on-device), SFE Stream Processor (streams), Enrollment SDK (enrollment flows)
- Fingerprint — Enrollment SDK (proprietary, non-embedded Linux), IDKit SDK (proprietary, including embedded Linux), ANSI & ISO SDK (standards-based, including embedded Linux)
- Iris — SFE Toolkit or Enrollment SDK
- Palm — SFE Toolkit
Supported Platforms — On-device SDKs
| Platform | Architecture |
|---|---|
| Windows | x86_64 |
| Linux | x86_64 |
| Android | ARMv7 and ARM64 |
| iOS | ARM64 (custom porting required) |
| Embedded Linux | ARMv7 and ARM64 (custom porting required) |
Supported Hardware Accelerators — SFE Toolkit
Hardware acceleration is provided by the SFE Toolkit (face, iris, palm) — and, by extension, the SFE Stream Processor built on it. The fingerprint SDKs (Enrollment, IDKit, ANSI & ISO) run on CPU.
| Vendor | Models | Supported Modalities |
|---|---|---|
| NVIDIA Jetson | Jetson platforms with CUDA/TensorRT, Jetpack 6.x | Face, Iris, Palm |
| Ambarella CV Flow | CV28, CV25, CV22, CV2 | Face, Face Liveness |
| Rockchip RKNPU | RV1126 | Face, Face Liveness |
| Rockchip RKNPU2 | RK3566/RK3568, RK3576 | Face, Face Liveness, Iris, Palm, Palm Liveness |
| NXP | i.MX 8M Plus | Face, Face Liveness |
| Android GPUs/NPUs | Qualcomm, MediaTek, ARM Mali | Face, Face Liveness |
Supported Edge Cameras and AI Boxes — SFE Stream Processor
| Vendor | Accelerator | Models |
|---|---|---|
| AXIS — M series | Ambarella CV25 | M4216-LV, M1055-L, M2035-LE, P12 Mk II, P1467-LE, P3267-LV, I8116-E |
| Hanwha — P series | Ambarella CV2 | PND-A6081RV, PNV-A6081R, PND-A6081RF, PNO-A6081R, PND-A9081RV, PNO-A9081R |
| NVIDIA Jetson platforms | CUDA, Tensor cores | Jetson Orin models (Jetpack 6.x) |
Biometric Identification Service
Biometric Identification Service (formerly LFIS) is a high-performance, server-based biometric API for 1:N identification and verification using face and palm modalities. It is the path for centralized, large-gallery identification beyond the on-device 1:N limit (~1:50K). Built with cloud-native principles, it can be deployed on-premises or in the customer's cloud. Passive liveness detection is available as an add-on for both face and palm.
| Feature | Description |
|---|---|
| Detection & Quality Assessment | Automatic detection of faces and palms from incoming images, including quality assessment to ensure compliance with recognition thresholds. |
| 1:N Identification | Searches a live-captured image or extracted template against a configurable watchlist and returns the most likely match with a confidence score. |
| Passive Liveness Detection | Detects presentation attacks without requiring user interaction, for both face and palm modalities. |
| Watchlist Management | Enroll, update, and remove biometric data via API. Supports dynamic watchlist creation and unlimited watchlists within the standard database size. |
| RESTful API | Supports real-time matching, asynchronous queries, and secure communications (TLS, authentication tokens). Integrates with web, mobile, or embedded client applications. |
| Cloud-ready Deployment | Deployable as a local server component or scaled in Kubernetes/Docker-based cloud infrastructure. |
Supported Platforms — Biometric Identification Service
| Platform | Architecture |
|---|---|
| Linux | x86_64 |
See also
- Solution Overview — what the solution is, who it's for, deployment options, and integration approach
- Standards & Certifications — the NIST and ISO benchmarks the algorithms are evaluated against