Meta Patents a Dedicated Security Chip for Biometric Data in Wearables
Meta is designing smart glasses and wristbands that store your biometric data on a completely separate, locked-down chip that the rest of the device's software simply cannot reach.
What Meta's isolated biometric chip actually does
Imagine unlocking your smart glasses with your fingerprint, and then wondering: where does that fingerprint data actually live, and who can see it? That's the exact problem Meta is trying to solve.
Meta's idea is to add a second, smaller chip to its wearable devices alongside the main processor. This companion chip handles all biometric data, like fingerprints or face scans, entirely on its own. The main chip, which runs your apps and connects to the internet, is physically blocked from ever reading that data. It's a bit like keeping your safe inside a room with a separate lock that your housemates don't have a key for.
The companion chip uses a small AI model to check whether incoming sensor data looks legitimate (not a fake or a replay attack), then compares it against encrypted templates stored in a protected vault. The main processor only ever learns one thing: yes or no, authentication passed.
a machine-learning (ML) accelerator for biometric processing, wherein the ML accelerator is configured to: generate validated sensor data by applying a biometric sensor data to an ML model, and generate a biometric signature from the validated sensor data; …
Translation: A specialized mini processor handles the heavy lifting of turning raw physical scans into secure digital login keys.
How the companion SoC walls off your biometric data
The companion SoC (system-on-a-chip, meaning a self-contained processor) is purpose-built to be small and low-power, important constraints for wearables like glasses or wristbands. It contains two key parts that never directly talk to each other except through a tightly controlled internal bus.
The first part is an ML accelerator, a dedicated processor for running AI models. It takes raw sensor data (say, a fingerprint scan) and passes it through a machine-learning model that acts as a gatekeeper: it checks whether the data is real and valid before doing anything further. If it passes, the accelerator generates a biometric signature, a compact mathematical representation of the scan.
The second part is an isolated secure subsystem. It stores your encrypted biometric templates (the reference scans enrolled during setup) and compares incoming signatures against them. Crucially, it also encrypts the AI models themselves and verifies their authenticity before letting the accelerator use them, so an attacker cannot swap in a tampered model to fool the system.
- A network-on-chip (NoC) connects the two parts internally
- Hardware firewalls in that network ensure raw sensor data can only go to the ML accelerator
- Stored templates can only be read by the secure subsystem
The main SoC, which handles everything else the device does, is locked out entirely.
… a subsystem, isolated from general purpose processing of the main SoC, interconnected through a network-on-chip with access control firewalls restricting access to biometric sensor data to the ML accelerator and stored biometric templates to the subsystem.
Translation: A heavily guarded internal vault keeps your sensitive body data completely separated from the watch's normal operating system.
What this means for privacy in Meta's wearables
Biometric data is permanent. You can change a password; you cannot change your fingerprints. So if a wearable device leaks that data through a software bug or a compromised app, the damage is irreversible. Meta's approach moves the most sensitive data onto a chip that is physically isolated from the software layer where most attacks happen, meaning a hacked app or even a compromised operating system on the main processor cannot reach your biometric templates.
For anyone wearing a Meta device that uses facial recognition or fingerprint login, the practical payoff is that your biometric data stays locked in hardware you do not have to think about. The architecture also verifies the AI models themselves before use, which closes a subtle attack path where an adversary replaces the recognition model with one designed to accept fakes. This kind of chip-level security work is part of a broader wave of new Big Tech patents focused on hardening biometric systems inside wearable and AR hardware.
Meta's 51st filing in our smart glasses watchlist since May adds to a picture that includes circuits inside clear lenses and gesture and gaze learning.
A physical chip that blocks the main processor from ever touching your face or fingerprint data is a real security guarantee. Software promises can be undone by a future update. This one cannot.
Most people will never think about this chip. They will notice it the day a hack happens and their biometric data is not among what was stolen.
The design also closes a gap most people miss. Before any AI model runs on the device, a separate secure chip checks that the model has not been tampered with.
There are more where this came from
We read every patent application Big Tech publishes and send you the ones worth knowing. Plain English, free, every week.
The drawings
9 drawing sheets from US 2026/0244726 A1 · click any drawing to enlarge
Want this weekly breakdown for a company we don't cover? Patentlyze Pro →