CardLab says it is releasing a biometric FIDO authentication system after completing FIDO certification and field testing, positioning the offering as a hardware-based way to bring biometrics into phishing-resistant login flows.
Rather than relying on a phone or a cloud service to perform matching, CardLab’s design centers on smart-card execution. The company describes a model in which biometric templates and cryptographic keys are stored on the card, biometric matching happens on the card, and the private key does not leave the card. The pitch is straightforward: keep the most sensitive material and the biometric decision point inside a discrete device that can be carried, issued, and managed as an authenticator.
The release also ties the product to a longer-term goal. CardLab frames the work as part of a “biometrics-first” security platform aligned with the direction of the EU Digital Identity Wallet, where authentication assurance and credential security requirements are expected to shape which technologies are viable for higher-trust use cases.
On the server side, CardLab points to QuardLock for a FIDO-certified authentication server, describing it as the component that validates FIDO credentials in an end-to-end deployment. In practice, that pairing is aimed at organizations that want a FIDO-compatible architecture while keeping both biometric matching and key custody bound to a physical device rather than to a mobile app or browser-stored credential.
In the broader authentication market, FIDO has increasingly become the baseline for passkey-style sign-in, but implementations vary widely in how user verification is performed. CardLab’s bet is that moving the biometric match into the card itself can simplify the path to “something you have” plus “something you are,” without outsourcing matching to a separate device.
The approach highlights a broader design debate in mobile identity and authentication: whether to concentrate user verification and key material inside phones and platform enclaves, or to distribute those functions across purpose-built authenticators. A biometric smart card sits on the latter end of that spectrum, potentially appealing to environments that already issue cards and want biometric user verification without introducing new dependencies.
CardLab has not published detailed availability or pricing information in the write-up. Additional implementation specifics—such as which biometric modality is supported and how the card integrates into enterprise and wallet-adjacent workflows—will be central to how the product is evaluated in practice.
Sources: Innovation News Network
–
By the Mobile ID World Editorial Team