Preventing Facial Recognition from Becoming a Security Vulnerability! HID Amico Locks Facial Features Securely Into a Card

Preventing Facial Recognition from Becoming a Security Vulnerability! HID Amico Locks Facial Features Securely Into a Card

hid-amico-template-on-card-facial-access-control

Recent reports about suspected Chinese-made facial recognition tablets for attendance tracking being deployed in government agencies have drawn widespread attention. This incident has also prompted people to re-examine whether facial recognition systems, originally installed for contactless convenience, may carry overlooked risks at thecybersecurity levelthat have gone unnoticed.

According to related reports and discussions, if facial data of personnel at sensitive agencies lacks adequate protection during transmission, storage, or management, it could lead to leaked personal data, identity forgery, or even broader intelligence security concerns. As a result, beyond strengthening device-level auditing, more enterprises and agencies are refocusing on the data architecture itself: where the data is stored, who can access it, and how to reduce concentration risk are the real keys to long-term control.

"Distributed Storage" Addresses Data Leak Concerns from Centralized Management

hid-amico-template-on-card-facial-access-control

Most current facial recognition systems use an "image capture, feature extraction, central storage" architecture, consolidating everyone's biometric data on a central server. However,this "all eggs in one basket" model carries a fatal risk: if the database is attacked or a device is compromised with a backdoor, sensitive personal data could face a mass leak.

The HID Amico is a facial recognition reader designed for high-security environments, using「Template on Card(ToC)」technology, which returns data sovereignty to the individual. Biometric features are no longer stored centrally on a server, but instead areencrypted and locked onto the card the user carries, reducing the target and impact scope of attacks on a single centralized database. The product ismanufactured in Mexico, also aligning with the recent international trend toward supply chain transparency.

This is also a shared trend among major international access control manufacturers: enhancing privacy protection and reducing reliance on centralized databases, shifting from high-risk centralized storage to a distributed storage design that minimizes overall impact.

hid-amico-template-on-card-facial-access-control

Facial Recognition Matching Modes

hid-amico-template-on-card-facial-access-control

HID Amico's facial recognition supports multiple matching paths, including 1:N, 1:1, and Template on Card (ToC) mode using cards or mobile credentials, which can be flexibly deployed according to the security level required by different sites, balancing throughput efficiency with data security.

1:N Mode

After a user approaches the device and their facial features are captured, the system compares the image against all templates stored in the device's database.

How It Works:The device automatically captures the image and compares it against multiple records at once.Use Case:High-traffic, everyday office environments that require quick throughput.Pros:The fastest mode, achieving "tap and go" access.Risk:Lower precision, which may be insufficient for high-security sites.

1:1 Mode

The user first presents an identity credential, for example tapping a card so the system identifies the user as "No. 007," and the system then retrieves the single facial template corresponding to that identity from the device database for verification.

How It Works:The user presents a credential (such as a card), and the system performs a single match to confirm "is this the cardholder."Use Case:Areas requiring stricter identity verification, such as specific floors of an office building.Pros:High precision with an extremely low false acceptance rate.Risk:Requires an extra step, making throughput slightly slower than 1:N, but significantly improving security.

ToC Mode (Template on Card)

hid-amico-template-on-card-facial-access-control

After the user presents a card or mobile credential, Amico reads the facial template stored in encrypted form on the card directly for matching.

How It Works:Once verified, the card number is output to the access control system to grant entry, achieving dual protection of "precise identity verification" and "distributed biometric storage."Use Case:Suitable for highly regulated areas such as government agencies, correctional facilities, and server rooms, as well as sensitive checkpoints like airports and customs, and any site within an enterprise with higher requirements for data privacy and security.Pros:Offers the highest level of privacy. Biometric data is kept solely with the user, so even if the back-end system is breached, there is no centralized facial database to leak.Risk:Its distributed storage design makes it the most secure of the three.

Access Methods and MFA (Multi-Factor Authentication)

hid-amico-template-on-card-facial-access-control

Beyond two-factor authentication, HID Amico also supports MFA, providing more flexible protection for high-security environments

Multi-Factor Authentication (MFA)
Security levels can be raised further by requiring two or more verification methods to be combined before access is granted, ensuring more rigorous identity confirmation.

Freely Combinable, Flexibly Deployed
Supports free combinations of multiple verification methods, including face, card, phone, and PIN. For example, face plus card, or face plus PIN paired with an anti-peek randomized keypad, to build a more robust multi-factor authentication defense than any single method alone.

NIST Top 10 Algorithm

hid-amico-template-on-card-facial-access-control

HID Amico is powered by Paravision's facial recognition AI algorithm, ranked in the Top 10 globally on the NIST FRVT benchmark, with a matching speed of just 0.2 seconds, and supports liveness detection and anti-spoofing to better prevent photo or video spoofing attempts. Even in high-traffic access environments, it maintains NIST-leading accuracy and real-time performance, while the Template on Card design with irreversible template encryption complies with GDPR's privacy-by-design principle, making it suitable for enterprise and government applications.

Integrates with Existing Access Control Systems

hid-amico-template-on-card-facial-access-control

HID Amico supports both OSDP and Wiegand communication protocols, enabling seamless integration with existing access control systems so legacy equipment can smoothly upgrade to next-generation biometric solutions while maintaining compatibility between old systems and new technology.

As data security requirements continue to rise, access control systems must not only "recognize accurately" but also ensure "data security and controllable risk."A distributed architecture built around ToCcan remove biometric data from centralized risk points, allowing high-security environments to enjoy the convenience of facial recognition while maintaining data governance and risk control.