All work

Case studyKFTC2022

One Palm, 14 Airports: Privacy-⁠Preserving Biometric ID for Travel

TL;DR

One palm, enrolled once at a bank, clears the ID check at 14 airports.

  • Korea's first nationwide cross-industry biometric framework with 12 banks and 14 airports
  • Reframing the problem: making existing siloed trust portable across different user flows
  • Routed everything through KFTC as the neutral hub; phone number as the bridge identifier
  • 500K users enabled in year 1 · 75% reduction in airport registration time · 0 security incidents
  • Learned how to get multiple regulated orgs to ship one thing on time
palm check-in at the gate
Role
Product manager, go-to-market and rollout
Team
2 product managers, led by me, and 2 engineers
Timeline
5 months, May to September 2022
Partners
12 banks at launch, 14 airports, one scanner vendor
Enrolled
500K+ travelers in the first year
Check-in
From 20 minutes to under 5
Security
No incidents in the first year, verified by KFTC

01The problem

Travelers enrolled again at every airport.

Banks and airports used the same palm-vein readers, yet each airport asked travelers to enroll from scratch, which took about 20 minutes. People who had enrolled at their bank expected the airport to recognize them.

The reader was never the obstacle. Banks identify customers by resident registration number, Korea's SSN, and airports are not allowed to collect it. Regulators would not let financial identity mix with travel data either.

02What I decided

Four rules for sharing one enrollment.

  1. 1

    One neutral hub

    Every bank and every airport connects to KFTC, and each keeps its own rules. Linking them directly would have taken 168 integrations.

  2. 2

    The phone number as the key

    It was the one identifier both sides could hold. It is less sensitive than the resident number, and it is enough to match a traveler without rebuilding who they are.

  3. 3

    Financial identity stays with the bank

    The resident registration number never reaches an airport. Airports see a name and a phone number.

  4. 4

    A separate yes for airports

    A bank enrollment never extends to airports on its own. Travelers agree to airport use separately, and when a phone number changes hands, the old match is cancelled and the new owner has to agree again.

03How it works

12 banks, 14 airports, one hub.

Banks and airports each connect to KFTC, Korea's national payments and clearing institute, never to each other. KFTC holds partial, hashed biometric data. It matches a bank enrollment to a phone number, removes the resident number and passes the match to the airports, one way.

DIRECT · 12 × 14 = 168 INTEGRATIONS12 banks14 airportsTHROUGH KFTC · ONE HUBKFTCmatches byphone numberholds partial, hashedbiometric dataone way12 banksresident number stays here14 airportsname and phone number

At the gate, a traveler scans a boarding pass, agrees to the terms, enters a phone number and holds a palm over the reader.

The seven screens at the palm-vein gate, in Korean, with English step names: 1, show the boarding pass and enter the bio-gate. 2, the onboarding screen. 3, the terms of agreement. 4, enter the phone number to match the biometric data. 5, put the palm on the sensor. 6, identifying. 7, identification complete, gate 54.
The gate's screens, from the traveler's side.

04The readers

More on the biometrics.

What biometrics were used?

Banks and airports both used 'palm vein' for the main biometric data. Banks deployed the systems in the kiosks to identify the customer identity, whereas airports leveraged them at the check-in systems.

How are the biometric systems being tested and evaluated?

I worked with vendors whose biometric models were independently evaluated through national testing bodies (e.g., U.S. and Korean biometric test centers) to establish baseline accuracy and reliability. As the PM, I then defined deployment guardrails, including acceptable accuracy thresholds and zero-tolerance criteria for financial use cases. To stress-test edge cases, I led additional internal testing using synthetic and fake artifacts to measure false-positive risk, especially scenarios that could result in incorrect financial authentication.

the palm reader, gate 6

05Looking back

What I would do differently.

  1. 1

    Start from what both sides share

    Banks and airports already shared an enrollment the traveler had completed once, and an identity verified to a standard both trusted. I spent too long reconciling their differences. Leading with that shared layer would have reached the framework sooner.

  2. 2

    Show travelers when access turns on

    Airport access took up to 24 hours to turn on, and 8% of travelers tried the gate before then and thought it was broken. A status message and a temporary fallback would have caught them.

  3. 3

    Test accuracy across ages before launch

    We assumed the readers were equally accurate across age groups. I would test that before launch and make even accuracy a launch condition.

More work

Authorization for 60+ financial institutions, AI in research budgeting, and the builds in between.

All work