Skip links

Edge Biometrics Authentication: A new, post-quantum way to authenticate users with biometrics

The current landscape of facial biometric authentication

Today, facial biometrics used for authentication generally follow two well-known approaches:

1. Local biometrics (passkeys, Face ID, Touch ID)

This is the model used by passkeys and modern operating systems. Your face or fingerprint unlocks a cryptographic key stored locally on your device. Examples include Face ID on iOS, Windows Hello, or passkeys used by Google and Apple.

This approach is privacy-friendly because biometric data never leaves the device. However, it comes with an important limitation: authentication is tied to that specific device. If you change devices, you must re-enroll. There is no true portability by design, unless you remain within a closed ecosystem.

2. Centralized biometrics

In centralized systems, biometric data, such as a facial template, is sent to a server where identity matching is performed.

This model enables cross-device access, but it introduces major concerns:

  • Biometric data is stored centrally
  • Strong regulatory exposure under GDPR
  • High security requirements to protect extremely sensitive data

There have already been multiple GDPR enforcement cases and significant fines related to improper handling of biometric data, reinforcing how risky this model can be.

Introducing Edge Biometrics Authentication

Edge Biometrics Authentication introduces a third model, one where biometric storage and GDPR exposure are no longer inherent problems.

This model, like all Secrets Vault technology, derives a post-quantum cryptographic key from an image, but simplifies authentication significantly.

With a user-selected image and the user鈥檚 live presence, key derivation happens entirely on the user鈥檚 device, at the edge, using a browser-based app with no installation required.

The only requirement is that the image contains the user鈥檚 face as it appeared during enrollment. The image itself does not need to be secret and does not need to be stored securely. Importantly, neither the image nor the derived cryptographic key ever leaves the user鈥檚 device.

How it works

  1. The user provides the same image used during enrollment
  2. The device activates the camera and the web app validates:
    • the user鈥檚 liveness
    • that the person in front of the camera matches the person in the image
  3. If validation succeeds, the post-quantum key is derived from the image and used to perform a strong cryptographic authentication against the server

Facial biometrics are used only as a secondary factor:

  • To confirm liveness
  • To confirm that the person present matches the registered image

Biometric data is:

  • Never stored
  • Never transmitted
  • Used only transiently in memory

Once authentication is complete, all biometric processing ends.

Why this matters: key advantages

Post-quantum by design

Unlike passkeys and traditional biometric systems that rely on classical cryptography, keys are derived using cryptographic constructions designed to resist future quantum attacks. The system is built for long-term security, not retrofitted later.

Reduced deepfake risk

All facial biometric systems share a fundamental limitation: facial recognition is ultimately a pattern-matching process. With the rapid evolution of AI-generated deepfakes, relying on facial biometrics alone is becoming increasingly fragile.

With this approach, a deepfake alone is not sufficient. An attacker would need:

  • The exact image used to derive the cryptographic key
  • A successful live biometric match

By separating cryptographic key material from biometric verification, the attack surface is significantly reduced.

No biometric data liability (GDPR-friendly)

Under GDPR and similar regulations, stored biometric data is classified as highly sensitive personal data. Centralized biometric systems must manage consent, storage, protection, and breach risks.

Edge Biometrics Authentication avoids these implications entirely:

  • No biometric data is stored
  • No biometric data is processed or retained server-side
  • True device independence

Passkeys are secure, but they bind users to a specific device or ecosystem. With Edge Biometrics Authentication, there is no local key to migrate.

Users can authenticate from any device, anywhere, by re-deriving the key from the image and completing edge-based biometric verification. Biometric validation can also be combined with other factors, or omitted when appropriate.

A simple comparison

FeatureCentralized BiometricsPasskeys (Local)Edge Biometrics Authentication
Biometric data storedCentral serversLocal deviceNowhere
Server-side biometricsYesNoNo
GDPR exposureHighVery lowLow
Device independentYesNoYes
Post-quantum readyNoNo (migration required)Yes
Biometrics as sole factorOftenOftenNo

Final thoughts

Edge Biometrics Authentication is not about replacing passkeys or biometrics. It is about evolving authentication.

By combining:

  • Image-derived post-quantum cryptographic keys
  • Edge-only biometric verification
  • Zero biometric data storage

We enable an authentication model that is portable, privacy-preserving, and future-proof.

If you want to see it in action, you can watch a short demo video here. If you would like to explore the technical details further, we would be happy to continue the conversation. Reach us here.

Leave a comment

Privacy Summary

This website uses cookies so that we can provide you with the best possible user experience. The cookie information is stored in your browser and performs functions such as recognizing you when you return to our site or helping our team understand which sections of the site you find most interesting and useful.