Short answer: The card verifies the fingerprint on the card itself, and the things worth protecting never leave it – the fingerprint data and the private keys stay on the card. Credentials are only presented after a successful match, and removing the biometric protection is itself protected. What the card can open is decided in your systems, not on the card.
Your fingerprint stays on the card
Your fingerprint is never stored as an image. It is converted into an encrypted template that cannot be reconstructed outside the card, and it is stored on the card only – not in central systems or the cloud. Verification happens locally, and IDEX cannot access or recover the template. See: How fingerprint matching on the card works.
Your credentials
Door credentials and sign-in keys are stored by their respective applications on the card, each according to its own standard – DESFire for physical access, FIDO2 for digital sign-in. Once the card is enrolled, a successful fingerprint match is required before the card presents them, adding an extra layer of security that the credential technology itself does not have.
For digital sign-in, the private keys never leave the card. Only a one-time signature is shared, and each key is bound to the service it was registered with. See: What FIDO2 sign-in gives you.
What it takes to remove the biometric protection
For an attacker to remove the biometric protection from a card they would need to compromise both the sensor and the secure element. The sensor's biometric data is protected by payment grade cryptography. The secure element, where biometric match results are authenticated and used, is designed to resist tampering and physical attack. The communication between the sensor and the secure element is also encrypted.
Enrolling fingerprints onto a card, or deleting them from it, is protected in one of two ways, depending on how the card was enrolled.
- PIN protection – biometric management requires the user's PIN, entered in the IDEX Card app. This is how self-enrolled cards are protected. See: Security management for mobile enrolment.
- Key protection – biometric management requires a master key held by the enrolment station – generated there or entered from your own key management; the user's PIN – where the card has FIDO – is used for registering with services and as the sign-in fallback. Every change to a card's biometrics then happens under operator supervision, with the person's identity verified first – which is what gives centralised enrolment its assurance. See: Enrolment station trust model and Fingerprint enrolment options.
If the biometrics on a card are reset, the effect differs by credential type. For FIDO2, a reset also removes all sign-in keys from the card, so no usable credentials remain. For door credentials, the data stays on the card after the templates are deleted, and whether it can then be used depends on how the application and your access system are configured. See: What happens when there is no biometric match? and The door opens without a fingerprint match.
Locking door credentials to the fingerprint
For door access, the card can be configured so that a biometrically registered application cannot be selected without a successful match. The setting is one-way: once applied, it cannot be reversed. See: How do I register an application to use biometrics?.
Where control sits
What the card can open is decided in your systems: door credentials in your access control system, passkeys in your identity provider. Revoking a card happens there too, and a replacement card is set up as new. See: Lost or stolen card: revoke and replace.