RFID News

New RFID Implementations, Hardware and Tags

Turkish technology company MIA Teknoloji has completed a research and development project that stores biometric facial data directly on RFID identity cards, verifying a cardholder against the credential in their hand rather than against a central biometric database. The work began on 1 January 2025 at Gazi University Technopark, carried funding of roughly 98 million Turkish lira, and has now been certified complete by Turkey’s Ministry of Industry and Technology and by Gazi Teknopark.

The architecture is a familiar one in secure credentialling circles, and an unusually under-reported one in the RFID trade press. Each cardholder’s biometric reference is written to the card itself; at the point of use a camera captures a live facial image and the system performs a one-to-one comparison against the reference tied to that specific credential. That is verification, not identification: there is no search across a population-scale gallery, and according to the company no biometric record needs to travel to a back-end server for the decision to be made.

Match-on-card is the term of art here

The established name for this approach is match-on-card, also written as on-card biometric comparison, and it is standardised in ISO/IEC 24787. In a strict implementation the reference template never leaves the chip at all: the terminal extracts a template from the live capture, sends it to the card over the contactless interface, and the card’s own secure microcontroller runs the comparison and returns a match or no-match result. The credential becomes the biometric database, and it is a database of exactly one person.

MIA Teknoloji’s announcement is not explicit on where the comparison itself executes, describing only that a device compares the new capture against data associated with the card. That distinction matters more than it sounds. If the template is read off the card and compared in the reader, the privacy story rests on the reader discarding it; if the comparison runs inside the card’s secure element, the reference is never exposed to the terminal in the first place. Anyone evaluating the system commercially should establish which of the two it is.

This is HF contactless smart card territory, not UHF

Identity and access credentials of this type sit in the HF band at 13.56 MHz, almost always as ISO/IEC 14443 proximity cards read at a few centimetres, with ISO/IEC 7816 command handling on top and, in eID and ePassport work, the ICAO Doc 9303 security model (PACE, secure messaging, EAC) governing how the chip’s data groups are protected. It is not UHF RAIN RFID: the deliberately short read range is a security feature, the interface supports the APDU exchange that on-card cryptography and biometric comparison require, and the throughput of an ISO/IEC 14443 link at 106 kbit/s and above comfortably handles a facial template, which typically runs from a few hundred bytes to a few kilobytes rather than a full photograph.

Face is the harder modality to do this way. Fingerprint match-on-card has been shipping in volume for years, including Neurotechnology’s on-card matching algorithms and the fingerprint-authenticated NFC access credentials from Zwipe and LEGIC, because fingerprint templates and comparison routines fit the modest compute budget of a smart card chip. Doing the equivalent with facial templates on constrained silicon is a genuine engineering result, which is presumably where a sizeable chunk of that 98 million lira went.

The KVKK angle

MIA Teknoloji positions the design as aligned with Turkey’s Personal Data Protection Law (KVKK), and the logic is sound as far as it goes: keeping the reference on the card removes the centralised biometric honeypot and cuts the number of transfers of special-category data. It does not remove the obligations around it. Consent capture, access logging, retention limits and the handling of enrolment data all still have to be right operationally, and a lost or cloned card raises its own questions about how the on-chip reference is bound to the credential and to the issuer.

No customers, volumes or launch dates yet

What has been announced is the completion of an R&D programme, certified as such by the ministry, and nothing further. MIA Teknoloji has not named an initial customer, disclosed production quantities, or given a commercial launch date, and the company describes commercial deployment as the next stage rather than a current one. Until a pilot with a named issuer emerges, this is a validated design looking for a deployment, not a product in the field.

By Matt Houldsworth

Over 3 decades of experience in RFID, High Risk/Value Asset Management, Inspection Systems, Brand Protection Technology, Customer engagement technology, WIP management, Logistics tracking, Digital Product Passports (DPP), and Digital Twinning linked to physical products with RFID. My Veribli Tech Makes Circular Economies Work!

Newsletter

Get stories like this every Thursday

One email every Thursday: implementations, hardware and tag launches, and analysis. Free, and you can leave whenever you like.

We send one digest a week and nothing else. Unsubscribe in one click. See our privacy policy.