Secure Palm Vein Biometric Door Lock
by techiesms in Circuits > Sensors
8464 Views, 79 Favorites, 0 Comments
Secure Palm Vein Biometric Door Lock
Overview
Fingerprints can be lifted with silicone, and Face ID can sometimes be fooled by a high-res 3D print. If you want a biometric door lock that is genuinely difficult to spoof, you have to look underneath the skin. That is where palm vein recognition comes in.
Every person's palm contains an internal network of veins. Because deoxygenated blood in your veins absorbs near-infrared (NIR) light, an infrared camera can map this pattern instantly. It works entirely under the surface, it is completely unique to you (even identical twins have different vein patterns), and it requires a live blood flow to read.
In this project, we built a fully offline, high-security smart door lock using the DFRobot Offline AI Binocular 3D Vision Sensor paired with an ESP32. It controls a 12V solenoid lock, features a custom power-management circuit, and includes an OLED display alongside an onboard web dashboard for admin user management.
Key Features
- Under-the-Skin Biometrics: Uses NIR light to map internal vein structures—virtually impossible to copy or spoof.
- 100% Offline Processing: The DFRobot vision module handles all AI matching and stores up to 1,000 user profiles locally. No cloud latency or privacy risks.
- Dual Registration System: Register new users via an onboard physical button or through a local ESP32 Wi-Fi dashboard (192.168.4.1).
- Admin Security Verification: Enrolling any new user requires an existing Admin palm authorization to prevent unauthorized access.
- Integrated Power Management: Custom onboard regulation converts 220V AC down to 12V DC for the solenoid lock, 5V DC for relays/sensors, and 3.3V DC for the ESP32.
- Hardware Safety Interlocks: Includes an optocoupled relay with a snubber circuit to protect against inductive kickback, an exit switch input, and a tamper switch hookup.
Supplies
To build this biometric palm vein door lock, you will need the components, materials, and assembly tools listed below.
Core Electronics & Modules:
- DFRobot Offline AI Binocular 3D Vision Sensor: Main sensor unit capable of palm vein extraction and offline matching.
- ESP32-WROOM-32 Development Board: Main microcontroller with onboard Wi-Fi / Bluetooth and 4MB Flash.
- 0.96" I2C OLED Display (128x64): Visual interface for user feedback and dashboard status.
- 12V DC Solenoid Door Lock Actuator: Heavy-duty locking mechanism.
- 5V Sugar Cube Relay Module (Optocoupled): Switched trigger interface for the high-current lock solenoid.
- Piezo Buzzer: Audible status and feedback indicator.
Power & Voltage Regulation Components:
- Hi-Link HLK-20M12 AC-DC Module: Converts 220V AC input down to a steady 12V DC rail.
- LM2596 Buck Converter IC / Module: Steps 12V DC down to 5V DC for logic and relay driving.
- AMS1117-3.3 Linear Voltage Regulator: Regulates 5V down to 3.3V DC for the ESP32 and OLED display.
- CH340 Serial Converter IC: USB-to-UART auto-programming bridge for the ESP32.
- Passives & Circuit Protection: Assorted SMD resistors, capacitors, RC snubber network, status LEDs, and a USB Type-C connector.
How Palm Vein Recognition Works
Traditional biometric systems like fingerprints or facial recognition analyze features on the surface of the skin, making them vulnerable to being copied using lifted prints or 3D-printed silicone masks. Palm vein recognition overcomes this security risk by reading an internal structure inside the body rather than surface features.
Here is how the technology works step-by-step:
- Infrared Light Emission: The sensor consists of a camera paired with an infrared light system. When you present your palm to the sensor, infrared light is emitted onto your hand.
- Light Absorption & Contrast: The veins carrying blood inside your palm absorb the infrared light, while the rest of the hand reflects it.
- Camera Capture: This difference in reflection creates a unique, high-contrast map of your internal vein network, which is captured by the camera.
- High Security & Uniqueness: Because blood vessels sit beneath the skin, the pattern cannot be copied, lifted, or replicated. Furthermore, even identical twins have completely different palm vein patterns, making it far more secure than traditional Face ID or fingerprint scanners.
Circuit Schematic
Before designing the custom PCB, we mapped out the full system schematic in KiCad. The design is structured into distinct functional blocks: power conversion, microcontroller control, biometric sensor interfacing, actuator driving, and user feedback.
Below is the detailed breakdown of how each section operates and connects.
1. Power Supply Architecture:
The board features a dual-input power path capable of handling either AC mains directly or an external DC power source:
- AC Input (220V AC): Mains AC power enters through a terminal block, passing through a high-voltage fuse and filtering components into the Hi-Link HLK-20M12 isolated power supply module. This steps down the mains voltage to a clean 12V DC rail.
- 12V DC Rail: Dedicated primarily to driving the inductive 12V solenoid door latch.
- 5V DC Logic Rail: An LM2596 buck converter circuit steps the 12V rail down to 5V DC to power the relay coil, piezo buzzer, and logic side of the palm vein sensor.
- 3.3V DC Rail: An AMS1117-3.3 LDO regulator steps the 5V line down to 3.3V DC to supply stable logic power to the ESP32-WROOM module and the I2C OLED display.
2. Microcontroller & Auto-Programming Circuit:
- MCU: ESP32-WROOM-32 with 4MB Flash.
- USB-to-UART Interface: A CH340C IC combined with a USB Type-C connector allows direct programming and serial debugging over USB.
- Auto-Reset/Flashing Logic: Utilizes a dual-transistor (S8050 / NPN) circuit driving the EN (Reset) and IO0 pins, enabling seamless flashing directly from the Arduino IDE or ESP-IDF without holding manual buttons.
3. Biometric Sensor Interface (UART):
The DFRobot Offline AI Vision Sensor connects using a dedicated 4-pin JST connector linked to the ESP32’s hardware serial port (Hardware Serial 2):
- TX (Sensor) → RX2 (ESP32 / GPIO16)
- RX (Sensor) → TX2 (ESP32 / GPIO17)
- VCC → 5V DC Rail
- GND → Common Ground
4. Solenoid Actuator & Relay Driver Circuit:
To safely switch the high-current 12V solenoid lock from a low-voltage ESP32 pin, we use an optocoupled relay circuit:
- Isolation: An EL817 Optocoupler isolates the ESP32 GPIO pin (GPIO26) from the relay coil driving voltage, preventing ground noise and current spikes from reaching the MCU.
- Flyback & Snubber Protection: A 1N4007 freewheeling diode across the relay coil absorbs inductive back-EMF spikes. Additionally, an RC Snubber network (100Ω resistor + 100nF high-voltage capacitor) is placed across the relay’s switching contacts to suppress arc discharge caused by the solenoid coil when deactivated.
5. User Interface & Auxiliary Inputs:
Peripheral / Feature ESP32 GPIO Pin Circuit Configuration
0.96" OLED (I2C):
- SDA: GPIO21
- SCL: GPIO22
- 4.7kΩ pull-up resistors to 3.3V.
Admin Enrollment Button:
- GPIO25
- Active-LOW push button with internal pull-up enabled.
Exit Door Switch:
- GPIO34
- Input-only pin pulled HIGH with external 10kΩ resistor; pulls to GND when pressed.
Tamper Emergency Switch:
- GPIO35
- Optional cut-off interlock switch.
Status LED & Buzzer:
- LED: GPIO2
- Buzzer: GPIO27
- Transistor-driven buzzer for audio feedback; LED driven via current-limiting resistor.
Custom PCB & Assembly
When routing the board in our KI-CAD software, we intentionally placed all components on the top layer, leaving the bottom layer completely empty as a ground plane. This single-sided layout makes solder paste application and reflow baking much easier.
Once the design was finalized, we exported the Gerber files and ordered the boards from NextPCB, making sure to include a top-layer framework stencil with the order. The PCBs arrived a week later in vacuum-sealed packaging.
Sponsored by NextPCB:
The custom PCB used in this project was manufactured by NextPCB featuring a matte black finish and a framed stencil for solder paste application. NextPCB provides PCB prototyping, SMT assembly solutions, multilayer manufacturing, and automated DFM (Design for Manufacturing) analysis to ensure reliable PCB production.
Uploading the Firmware
With the custom PCB fully assembled and inspected for shorts using a multimeter, it was time to flash the custom firmware onto the onboard ESP32 microcontroller.
1. Development Environment Setup:
- Software & Board Package: Open the Arduino IDE, go to Preferences, and add the ESP32 board manager URL. Open Board Manager, search for esp32 by Espressif Systems, and install version 2.0.x or later.
- Required Libraries: Install the following libraries via the Library Manager:
- Adafruit_SSD1306 & Adafruit_GFX (for driving the 0.96" I2C OLED display).
- DNSServer, WebServer, & WiFi (built-in libraries for the captive portal web interface).
2. Hardware Connection & Driver Setup:
- Connect the PCB to your PC using a USB Type-C cable.
- Ensure the CH340 driver is installed on your computer so a new COM port (e.g., COM3 / COM7) is recognized in Device Manager.
3. Configuring Board Settings & Code Upload:
- In Arduino IDE, select Tools → Board → ESP32 Dev Module.
- Set Flash Size to 4MB (32Mb), Upload Speed to 921600, and select the correct COM port.
- Download the project source code from our GitHub repository and open Code.ino. The firmware configures Hardware Serial 2 (Serial2.begin(115200, SERIAL_8N1, 16, 17)) to send packet commands to and parse responses from the DFRobot palm vein sensor at 115,200 baud.
- Click Upload. Thanks to our onboard CH340 auto-programming transistor network, the ESP32 automatically enters bootloader mode and flashes without needing to press any physical boot/reset buttons.
- Open the Serial Monitor at 115200 baud. You should see boot logs confirming I2C OLED initialization, UART link startup with the DFRobot sensor, and creation of the Wi-Fi Access Point.
Installation & Physical Assembly
With the firmware flashed and the PCB tested, we proceeded to replace an old legacy RFID door lock system with our high-security palm vein setup.
1. Mounting the Lock & Core Cabling:
- Reusing Existing Hardware: We retained the pre-mounted heavy-duty 12V solenoid latch mounted on the door frame and the internal push-to-exit mechanical button.
- Control Box Mounting: Mount the main PCB enclosure securely on the interior side of the door or wall near the power outlet.
2. Wiring Diagram & Terminal Connections:
- Solenoid Latch: Connect the two heavy wires from the 12V solenoid lock to the PCB’s relay output terminal block.
- Exit Switch: Connect the 2-wire push-button cable from the interior exit button to the EXIT_SW screw terminal (GPIO34 and GND).
- AC Mains / DC Input: Wire the 220V AC live and neutral lines into the dedicated AC terminal block (protected by the onboard Hi-Link supply and fuse).
3. Exterior Sensor & Display Mounting:
- Placement: Mount the DFRobot Binocular Vision Sensor at chest/chest-high level on the outside door frame where visitors can comfortably place their hand 5 to 10 cm in front of the lens.
- Display Positioning: Secure the 0.96" OLED screen directly below the sensor so users get clear visual instructions ("Scan Palm", "Welcome Alex", "Access Denied").
- Cable Routing: Pass the 4-pin JST sensor cable and 4-pin I2C OLED cable through a neat drill hole in the door frame and plug them directly into their respective top-layer connectors on the interior PCB.
Enrolling Users
To make user onboarding flexible, our firmware supports two distinct registration workflows: an intuitive phone/browser web portal and a standalone hardware push-button method. Both methods rely on a strict security hierarchy enforced by the Admin Palm.
The Admin Security Rule:
- First-Palm Priority: The very first palm scan enrolled on a clean system is automatically assigned administrative privileges (User ID: 10001, Tagged: "Admin").
- Authorization Gate: Any future enrollment attempt—whether triggered via the Web Dashboard or the physical Register Button—will instantly halt and display: "Present Admin Palm to Authorize." No new user can be added to the internal sensor memory unless authorized by the registered master user.
Method A: Web Dashboard Registration (via Smartphone/PC):
- Connect to AP: On your smartphone or laptop, scan for Wi-Fi networks and connect to the local Access Point hosted by the lock:
- SSID: PalmLock-Setup
- Password: palmlock123
- Open Portal: Open any web browser and navigate to http://192.168.4.1.
- Login: A prompt will appear asking for authentication credentials. Enter:
- Username: techiesms
- Password: techiesms
- Enroll New User: On the web control panel, enter the new user's name (e.g., "Alex") into the input box and click Enroll.
- Authorize & Scan: The OLED screen will prompt for the Admin Palm. Hold the Admin's hand in front of the sensor. Once authorized, the screen changes to "Present New Palm." Position the new user's palm 5–10 cm away. The sensor saves the biometric template, links it to "Alex", assigns a unique UID, and logs it onto the web table.
Method B: Physical Hardware Button Registration:
- Trigger Mode: Press and hold the tactile Register Switch on the custom PCB for 1.5 seconds.
- Screen Feedback: The OLED display enters Enrollment Mode and displays "Present Admin Palm to Authorize."
- Authorize: Scan the master user's palm. The buzzer gives a short beep.
- Scan New User: The display changes to "Present New Palm." Scan the new person's hand. The sensor generates an internal UID (e.g., UID 1004) and saves it directly to its onboard offline database without needing a phone or internet connection.
Final Testing & Demo
Once installation was complete, we powered up the system to evaluate real-world unlock performance, accuracy, and ease of use.
1. Entering (Palm Verification):
- Approach: As you approach the door, the infrared LEDs on the binocular camera automatically illuminate your hand.
- Scan & Recognition: Hover your palm 5–10 cm away from the lens. The NIR light penetrates the outer skin layer, capturing the unique subcutaneous vein pattern.
- Unlock Speed: Within under 0.5 seconds, the sensor verifies the pattern offline. The onboard buzzer gives a short confirmation beep, the OLED displays "Access Granted: Welcome Alex", and the ESP32 fires GPIO26, instantly pulling the 12V solenoid back to unlock the door.
- Auto-Lock: After a 5-second timeout, the relay releases and the door latch automatically snaps back into its locked state.
2. Unregistered Palm Attempt:
- If an unknown hand is presented, the system processes the image offline, finds no matching template in its 1,000-user database, triggers a long error beep on the buzzer, and displays "Access Denied" on the OLED without firing the lock relay.
3. Exiting (Exit Push-Button):
- To leave the room from the inside, simply press the physical exit switch on the interior wall. GPIO34 detects the active-LOW signal, briefly energizes the solenoid relay for 5 seconds to open the latch, and re-locks automatically once closed.
Conclusion
And that's it: a fully offline biometric door lock that reads the vein pattern inside your palm instead of anything on the surface of your skin.
Resources:
- Firmware, schematic and Gerber files: GitHub
- Palm vein sensor: techiesms.com
- PCBs: NextPCB
- Full build video: techiesms on YouTube
If you build your own version, share it in the comments. We'd love to see where you use palm vein recognition next!