Skip to main content

6 PalmAI M4 Device User Manual

The User Manual is available for Max and Standard. Use the tabs below to switch between editions.

6.1 Device Introduction and Installation

This section describes the main components, ports, operating environment, cable connections, power-on and power-off procedures, and Palm Scan precautions for the M4.

6.1.1 Device Appearance and Palm Print Scanning Module

The main components of the M4 include the display, indicator light, Palm Print scanning module, RGB and infrared cameras, speaker, port area, and power button.

ComponentDescription
DisplayDisplays device pages, operation prompts, and processing results.
Indicator lightLocated next to the Palm Print scanning module.
Palm Print scanning moduleCaptures palm information.
RGB and infrared camerasLocated inside the Palm Print scanning module.
SpeakerPlays device voice prompts and notification sounds.
Port areaConnects power, network, and USB devices.
Power buttonStarts or shuts down the device.

Indicator light status

Light statusDevice status
Dim blueSleep mode
Dim whiteStandby
Bright white fill lightRegistering or recognizing a palm
Flashing orangeThe palm is too close to the device
GreenRecognition succeeded
RedRecognition failed

6.1.2 Device Ports

The M4 provides USB Type-C, USB Type-A, DC-IN, and RJ45 ports.

No.PortFunction
1USB Type-CDebug port.
2USB Type-AUSB host port that can connect a Host serial cable.
3DC-INConnects the device power supply.
4RJ45Connects to a wired network.

Note

The M4 does not support PoE power supply. Do not power the device through PoE.

6.1.3 Installation and Operating Environment

The M4 is suitable for indoor or sheltered semi-outdoor environments. Observe the following requirements when using the device:

  • Place the device on a stable, level surface and adjust its position based on the average height of users at the site.
  • The device is dustproof but not waterproof. Avoid using it in humid environments and prevent liquids from entering the device.
  • Avoid using the device in extremely cold or hot environments or near heat sources.
  • Do not drop, throw, or bend the device.
  • Avoid placing the device near a window or outdoors in strong backlight. If necessary, adjust the device angle so that light falls evenly on the user's palm.

6.1.4 Device Placement and Cable Connections

  1. Place the M4 on a stable, level surface.
  2. Connect the original power adapter to the DC-IN port.
  3. To use a wired network, connect a network cable to the RJ45 port.
  4. To connect a mouse, USB flash drive, or another USB device, connect it to the USB Type-A port.

Description

USB Type-C is a debug port. It does not need to be connected during normal deployment. Connect the serial cable provided by the manufacturer only when using Host Input or serial output.

6.1.5 Power-On, Startup, and Shutdown

Start the Device

  1. Confirm that the original power adapter is connected to the device.
  2. Briefly press the power button to start the device.
  3. Wait for the device to finish starting and display the operation page.

Shut Down the Device

  1. Press and hold the power button for about 8 seconds to put the device into shutdown sleep mode.
  2. To start the device again, briefly press the power button once.

Note

After disconnecting power from the device, wait at least 5 seconds before reconnecting it. Reconnecting power immediately after disconnection may prevent the device from starting normally. If this occurs, unplug and reconnect the power adapter, waiting at least 5 seconds before reconnecting power.

6.1.6 Palm Registration and Recognition Precautions

Before registering or recognizing a palm, confirm that the protective film over the camera area has been removed and keep the camera and palm clean.

Observe the following requirements during a Palm Scan:

  1. Extend your palm naturally and keep the palm center facing the center of the Palm Print scanning module.
  2. Keep your palm approximately 5–12 cm from the device.
  3. Keep your palm steady and complete the Palm Scan at a uniform speed.
  4. Keep your palm facing the device with a tilt angle of less than 30°.
  5. Keep the palm rotation angle below 180°.
  6. Do not obstruct the palm or perform a Palm Scan in strong backlight.

If recognition is slow, check whether the camera is clean, the palm is positioned correctly, the palm center has visible dirt or sweat, and strong light or backlight is present at the site.

6.2 Initial Access and Activation

6.2.1 Initial Access Process

When connecting an M4 to the Palm Application Platform for the first time, complete activation in the following order:

  1. Configure a wired network or WiFi based on the network environment at the site and ensure that the device can connect to the network.
  2. Complete device authorization and confirm that the device is licensed to use Palm Scan capabilities.
  3. Enter the device name and Device SN in the PalmAI Admin Web.
  4. Use the device to scan the activation QR code generated by the PalmAI Admin Web to bind the device to the current backend environment.
  5. Associate the device with the corresponding scene in the PalmAI Admin Web, and configure the Scene Strategy and Verification Rule.

Description

Device authorization and device activation are separate processes. Device authorization grants a license to use Palm Scan capabilities, while device activation connects the device to the current PalmAI Admin Web environment.

Note

The device must be connected to a network before authorization can be performed.

6.2.2 Configure the Device Network

The M4 must be connected to a network before it can perform operations such as device authorization, backend environment activation, configuration synchronization, Verification Record reporting, and OTA upgrades. The device supports wired networks and WiFi.

  1. Tap the settings button in the upper-left corner of the device home page.
  2. Enter the device settings password in the Please input password window. The initial password is 000000.
  3. Tap Confirm to open the Setting page.
  4. Tap Network setting.
  5. Select WiFi or Ethernet based on the network environment at the site.

Tip

Use a wired network whenever site conditions permit. WiFi is not recommended for deployments of more than 10 devices.

6.2.2.1 Connect to a Wired Network

  1. Use a network cable to connect the M4 RJ45 port to a router or switch.
  2. Go to Setting > Network setting.
  3. If WiFi is enabled, open the WiFi page and turn off Wireless LAN.
  4. Return to the Network setting page and tap Ethernet.
  5. Enable Ethernet.

Note

When using a wired network, turn off WiFi to avoid using both network connections at the same time.

6.2.2.2 Select an Ethernet IP Mode

The M4 Ethernet page supports two IP modes: DHCP and Static. The device uses DHCP by default.

Select DHCP

  1. Go to Setting > Network setting > Ethernet.
  2. Enable Ethernet.
  3. Tap IP Mode.
  4. Select DHCP under Select IP Mode.

Select Static

  1. Go to Setting > Network setting > Ethernet.
  2. Enable Ethernet.
  3. Tap IP Mode.
  4. Select Static under Select IP Mode.
  5. Tap Apply.

6.2.2.3 Connect to WiFi

  1. Go to Setting > Network setting > WiFi.
  2. Enable Wireless LAN.
  3. Select the target WiFi network under KNOWN NETWORKS or OTHER NETWORKS.
  4. If the target WiFi network requires a password, enter the password and connect.
  5. Wait for the device to establish the connection. After the connection succeeds, a selection mark appears to the left of the target WiFi network. After you return to the Network setting page, the current network name appears to the right of WiFi.

If the connection fails, return to the WiFi list and reconnect.

Note

The M4 supports only 2.4 GHz WiFi and does not support 5 GHz WiFi. If the device cannot find the target network, confirm that the router has enabled the 2.4 GHz band. Use a combination of letters and numbers for the WiFi password and avoid special characters.

6.2.2.4 Manage Saved WiFi Networks

  1. Go to Setting > Network setting > WiFi.
  2. Tap Saved in the upper-right corner of the page.
  3. View saved WiFi networks on the Saved networks page.

To delete a saved WiFi network, tap the delete button to the right of the corresponding network.

To manually add a WiFi network:

  1. Tap Add Wifi on the Saved networks page.
  2. Enter the WiFi name in the ssid field.
  3. Enter the WiFi password in the password field.
  4. Tap Confirm. To cancel, tap Cancel.

6.2.2.5 Connect to a Hidden WiFi Network

  1. Go to Setting > Network setting > WiFi.
  2. Enable Wireless LAN.
  3. Tap Other... in the WiFi list.
  4. On the Join hidden network page, tap Network and enter the SSID of the hidden WiFi network.

  1. Tap Security and select the security type for the target network:
    • (none)
    • WPA-PSK
    • WPA2-PSK
    • WPA3-SAE
  2. If the target network requires a password, enter 8–63 characters in the Password field.
  3. Tap Join and wait for the device to connect.

Note

The SSID of a hidden WiFi network is case-sensitive. Enter it exactly as configured on the router.

6.2.2.6 Reset Network Settings

The Network setting page provides the Network Reset function. After a reset, all network settings return to their defaults.

  1. Go to Setting > Network setting.
  2. Tap Network Reset.
  3. Tap Reset in the confirmation window. To cancel the operation, tap Cancel.
  4. After the reset is complete, reconfigure WiFi or Ethernet based on the network environment at the site.

6.2.3 Complete Device Authorization

Before using an M4 for the first time, confirm its authorization status. Device authorization grants a license to use Palm Scan capabilities and is separate from the activation process that connects the device to the PalmAI Admin Web environment.

6.2.3.1 Authorization Preparation

Complete the following preparations before authorization:

  • Confirm whether the device received permanent authorization at the factory. A permanently authorized device does not need to be authorized again at the site.
  • If the device has not been authorized or its authorization has expired, contact the relevant sales representative to obtain an authorization QR code.
  • Use online authorization by default. Use offline authorization only in special circumstances.
  • Connect the device to power and start it.
  • For online authorization, confirm that the device is connected to a network. An offline authorization QR code already contains authorization information, so injecting it by scanning does not require a network connection. Because other device functions generally require a network connection, configuring the network first is still recommended.
  • Print the authorization QR code on paper to facilitate scanning by the device camera.

To obtain an authorization QR code, provide the APP ID to the relevant sales representative or technical support and specify the following authorization information:

  • Number of authorized devices
  • License Term, including permanent authorization or authorization for a specified period
  • Authorization method, including online or offline authorization

To obtain an authorization QR code, provide the APP ID to the relevant sales representative or technical support and specify the following authorization information:

  • Number of authorized devices
  • License Term, including permanent authorization or authorization for a specified period
  • Authorization method, including online or offline authorization

Sales or technical support generates an authorization QR code based on the information above. After obtaining the authorization QR code, open the authorization scanning page on the device and scan it.

An unauthorized device displays Unauthorized on the Device authorization page.

6.2.3.2 Online and Offline Authorization

The M4 supports online and offline authorization. Online authorization is recommended by default. Offline authorization is a fallback method used only in special circumstances.

Authorization methodNetwork requirements during authorizationUse after authorization
Online authorizationThe device must access the authorization service over a network.Use the device while it is connected to a network.
Offline authorizationThe authorization QR code already contains authorization information, so injecting it by scanning does not require a network connection.After authorization, the device can operate completely offline as a standalone device.

For online authorization, use one of the following network access methods based on the deployment environment:

  • LAN with external network access: The device accesses the external authorization service through the Backend Service Gateway in the same network environment to complete authorization and authentication.
  • LAN without external network access: The device can access only the Backend Service Gateway in the same network environment, and the gateway cannot access the external network.
  • Network with external network access: The device can access the authorization service directly or complete authorization and authentication through the Backend Service Gateway.

Note

After authorization expires, obtain a new authorization QR code and authorize the device again.

6.2.3.3 Scan the Authorization QR Code

  1. On the Device authorization page, tap Scan the QR code.
  2. Align the authorization QR code with the device camera and keep it approximately 10 cm away.
  3. Wait for the device to scan the QR code.
  4. After the scan succeeds, wait for the module to restart.

After the scan succeeds and the module restarts, the device displays the authorization result. If the scan fails, return to the authorization page and scan the authorization QR code again.

6.2.3.4 View Authorization Status and Validity Period

After authorization succeeds, the device displays Authorization successful. Confirm the APP ID and Authorization path on the page, and then tap the upper-left corner to return to the home page.

You can subsequently view authorization information under Setting > Authorization. When the device has valid authorization, the page displays Authorization Active and provides the following information:

  • Authorization status
  • Validity period
  • APP ID
  • Authorization path

6.2.4 Register the Device in the PalmAI Admin Web

After connecting and authorizing the device, register it in the PalmAI Admin Web:

  1. Log in to the PalmAI Admin Web and go to Device Management > Device List.
  2. Click Add Device.
  3. Enter the device name and the Device SN on the chassis label.
  4. Verify the information and click Submit.
  5. Return to the device list and confirm that the device name and Device SN are correct. Before QR code activation is complete, the device status is shown as not activated.

Device SN is the unique device identifier and cannot be changed after it is entered. Verify it carefully before submitting. To enter multiple devices at once, use Batch import. For details, see "3.1.1.1 Device Registration" in the PalmAI Admin Web User Manual.

6.2.5 Activate the Device and Bind the Backend Environment

After registering the device, scan the activation QR code generated by the PalmAI Admin Web to connect the device to the current backend environment. For details about generating an activation QR code in the PalmAI Admin Web, see "3.1.1.2 Device Activation and Environment Binding" in the PalmAI Admin Web User Manual.

  1. Confirm that the device has completed License authorization, is connected to a network, and has been registered in the current PalmAI Admin Web environment.
  2. On the Device List page in the PalmAI Admin Web, click Device Activation to generate an activation QR code.
  3. Use the M4 to scan the activation QR code.
  4. After activation succeeds, return to the device list and confirm that the device status changes from not activated to online/offline.

Note

The activation QR code has a limited validity period. If it expires, generate a new one in the PalmAI Admin Web.

Description

Device activation and License authorization are separate processes. Completing device activation means that the device has connected to the current backend environment. Online or offline in the device list indicates the current operating status of the device.

If activation fails, follow the device prompt:

  • This device is not registered: Confirm that the Device SN of the current device has been entered in the PalmAI Admin Web.
  • The QR code is not a valid activation code: Confirm that you scanned a device activation QR code generated by the PalmAI Admin Web.
  • This activation code has expired: Generate a new activation QR code in the PalmAI Admin Web.
  • Network error or prolonged lack of response: Check the device network and scan again after restoring the connection.

6.2.6 Manage Device and Scene Associations

A scene represents the actual location where the M4 is used, such as an office entrance, campus entrance, or verification service desk. After activating the device, associate the M4 with the corresponding scene and configure the Scene Strategy. To restrict users and times for access, also associate a Verification Rule.

Associate the device with a scene

  1. Log in to the PalmAI Admin Web and go to Verification > Scene Management.
  2. Select the target Scene Group on the left side of the page.
  3. If the scene already exists, find it and click Edit. If it has not been created, click Add Scene.
  4. Select the M4 under Associated device.
  5. Select a recognition strategy under Scene Strategy.
  6. To restrict users and times for access, enable Verification Rule and select a rule.
  7. Click Submit.

Disassociate the device from a scene

  1. In Scene Management, find the scene currently associated with the device.
  2. Click Edit.
  3. Remove the target M4 under Associated device.
  4. Click Submit.

Move the device to a new scene

  1. First disassociate the device from its original scene.
  2. Open or create the new scene.
  3. Select the target M4 under Associated device.
  4. Configure Scene Strategy. To restrict users and times for access, enable and select Verification Rule.
  5. Click Submit.

Note

A device cannot be associated with multiple scenes at the same time. Associating or disassociating a scene does not change the activation status of the device.

Scene Strategy

Scene StrategyBrief description
100 User Demo On-device RecognitionSuitable for product demonstrations or small-scale trials. Uses only On-device Recognition and supports a Palm Database of up to 100 users.
10k User Access Control and Attendance On-device RecognitionSuitable for enterprise Access Control and office attendance. Uses only On-device Recognition and supports a Palm Database of up to 50,000 users.
1M User eKYC Cloud RecognitionSuitable for high-security identity verification. Uses Cloud Recognition and supports a Palm Database of up to 1 million users.
1M User eKYC Hybrid RecognitionSuitable for large campuses or large-scale services. Uses Hybrid Recognition and supports up to 50,000 users in the on-device Palm Database and up to 1 million users in the cloud Palm Database.

Hybrid or cloud-only strategies support security capabilities such as High Similarity detection and assisted Additional Verification.

After the Scene Strategy is changed, the M4 displays Device Configuration Update when it receives the new configuration and restarts automatically. The new strategy takes effect after the restart.

Verification Rules and access scope

A Verification Rule can configure:

  • All users, specified users, or user tags that are allowed to verify.
  • The rule's effective dates, restricted verification dates, weekly verification days, and time periods.
  • Whether external system verification is enabled.

Restricted Dates takes precedence over the date range and weekly verification days. After External Verification is enabled, both the local rule and the external system decision must pass for the verification to succeed.

For complete instructions on creating and editing scenes and associating devices, see "3.2.2 Scene Management" in the PalmAI Admin Web User Manual. For complete instructions on Verification Rules, see "3.4 Verification Rules" in the PalmAI Admin Web User Manual.

6.3 Basic Device Settings

This section describes the M4 language, volume, screen brightness, time, settings password, device information, and restart functions.

6.3.1 Open the Setting Page

  1. Tap the settings button in the upper-left corner of the device home page.

  1. Enter the device settings password in the Please input password window. The initial password is 000000.
  2. Tap Confirm to open the Setting page. To cancel, tap Cancel.

6.3.2 Set the Device Language

  1. Go to Setting > System setting.
  2. Tap Language.
  3. Select the language to use:
    • English
    • Simplified Chinese
    • Traditional Chinese
    • Français

A selection mark appears to the right of the current language.

6.3.3 Set the Device Volume

  1. Go to Setting > System setting.
  2. Find the slider next to the speaker icon.
  3. Drag the slider left or right to adjust the volume of device voice prompts and notification sounds.

6.3.4 Set the Screen Brightness

  1. Go to Setting > System setting.
  2. Find the slider next to the light bulb icon.
  3. Drag the slider left or right to adjust the screen brightness.

6.3.5 View and Synchronize the Device Time

  1. Go to Setting > Time Configuration.
  2. View Time Zone and Current Time.
  3. To synchronize the time again, tap Resync Time.
  4. After synchronization succeeds, the device displays Resync Time successful.

Description

You can only view and resynchronize time on the device. You cannot change the time zone directly. After the device is activated for the current Tenant, its time zone synchronizes with the time zone in the current PalmAI Admin Web. The Super Administrator manages the PalmAI Admin Web time zone under System > System Settings > Timezone Settings. Basic Administrators cannot view or modify it.

6.3.6 Change the Device Settings Password

  1. Go to Setting.
  2. Tap Password.
  3. Enter and submit a new password.

Note

Store the new password securely.

6.3.7 View Device Information

Go to Setting > Device information to view the following information:

FieldMeaning
O-codeTenant Identifier currently bound to the device. This corresponds to the Tenant Identifier under PalmAI Admin Web - Tenant List - Edit Tenant.
Scene nameName of the scene currently associated with the device.
EndpointService Endpoint to which the device is currently connected.
Device SNUnique device identifier used to register, search for, and manage the device in the PalmAI Admin Web.
IP addressIP address currently used by the device.
Ethernet MACMAC address of the device's wired network adapter.
WLAN MACMAC address of the device's wireless network adapter.

You can also view the Device SN at the top of the device interface or on the label on the back of the device.

To view device component versions, return to the Setting page and scroll down:

EntryDisplayed content
System updateSystem version
App updateApplication version
Module updateModule version
Algo updateAlgorithm version

6.3.8 Restart the Device

The M4 supports automatic and manual restart. Automatic restart releases system resources accumulated during prolonged operation and is recommended.

Configure automatic restart

  1. Go to Setting > Soft reboot.
  2. Enable Soft reboot mode.
  3. Select a start time under Select start time. The page displays the corresponding End time.
  4. Tap Confirm. To cancel the setting, tap Cancel.

After this function is enabled, the automatic restart time range appears to the right of Soft reboot on the Setting page. Each day, the device restarts automatically within this time range when no one is performing a Palm Scan.

To disable automatic restart, open Soft reboot, turn off Soft reboot mode, and tap Confirm. After the function is disabled, Off appears to the right of Soft reboot.

Restart manually from the settings page

  1. Open the Setting page and scroll to the bottom.
  2. Tap Device Restart to restart the device.

Restart manually using the restart hole

  1. Locate the restart hole in the port area on top of the M4.
  2. Use a pin-shaped tool to press and hold the button inside the restart hole for approximately 5 seconds.
  3. Release the button and wait for the device to restart.

6.4 Service Activation and Palm Scan Usage

6.4.1 Switching Device Registration and Recognition Modes

The M4 supports five user Palm Registration methods. Phone Scan QR Registration, Device Input Registration, Host Input, and Device Scan QR Registration require selecting the corresponding registration mode on the device. For Mobile Palm Registration, first preregister a palm through the mobile App or Mobile Palm Registration H5, and then use the device's Recognition mode for initial activation.

Registration methodBrief descriptionDevice mode
Phone Scan QR RegistrationThe user first captures a palm on the M4, scans the QR code displayed by the device with a phone, and enters user information on the mobile page to complete registration.Registration - Phone Scan QR
Device Input RegistrationThe user captures a palm on the M4 and enters user information directly on the device to complete registration.Registration - Device Input
Host InputAn administrator enters user information and starts registration through Host Demo on a computer. The user captures a palm on the M4 connected to the computer.Registration - Host Input
Device Scan QR RegistrationThe user first generates a registration QR code through an H5 page. After the M4 captures the palm, the device scans the QR code on the phone to complete registration.Registration - Device Scan QR
Mobile Palm RegistrationThe user first preregisters a palm through the mobile App or Mobile Palm Registration H5, and then performs the first Palm Scan on the M4 to complete activation.Recognition

Before using a method, switch the device mode:

  1. Tap the settings button in the upper-left corner of the device home page.
  2. Enter the device settings password. The initial password is 000000.
  3. Tap Confirm to open the Setting page.
  4. Tap Mode.
  5. Select the required mode in the Select mode window. A selection mark appears to the right of the current mode.

Before using a registration function, confirm that the device has completed authorization, network connection, backend activation, and scene association.

Phone Scan QR Registration, Host Input, Device Scan QR Registration, and Mobile Palm Registration must first be enabled in the PalmAI Admin Web. Go to System > Tenant Management, edit the current Tenant, and enable the corresponding registration method. Device Input Registration is not controlled by this switch.

In a closed scene, the administrator must first open the user list in the PalmAI Admin Web, click Add new user, enter the User ID and Username, and submit. The user information entered during registration must match the information in the backend. In an open scene, users do not need to be created in advance and can register themselves using an enabled registration method.

6.4.2 Phone Scan QR Registration

For Phone Scan QR Registration, the user first completes palm capture on the M4, scans the QR code displayed by the device with a phone, and enters user information on the phone registration page to bind the palm to the user information.

Prerequisites

  • Phone Scan QR Registration is enabled for the current Tenant in the PalmAI Admin Web.
  • In a closed scene, the administrator has created the corresponding user in the PalmAI Admin Web.
  • In an open scene, users do not need to be created in advance. The system creates the user automatically after the user submits registration information.

Procedure

  1. Select Registration - Phone Scan QR under Setting > Mode.
  2. Place an unregistered palm above the Palm Print scanning module and follow the device prompts to complete capture.
  3. After palm capture succeeds, the device displays a registration QR code.

  1. Scan the QR code displayed by the device with a phone. After the scan succeeds, the device waits for the user to submit information.

  1. Enter registration information such as User ID and Username on the phone registration page. In a closed scene, the information must match the user information created in the PalmAI Admin Web.
  2. Tap Submit.

  1. After submission succeeds, the mobile page indicates success. The device binds the palm to the user information and displays a registration success message.

6.4.3 Device Input Registration

For Device Input Registration, the user captures a palm directly on the M4 and enters user information such as User ID and Username on the device. This method does not require a phone or another terminal.

Prerequisites

  • In a closed scene, the administrator has created the corresponding user in the PalmAI Admin Web.
  • In an open scene, users do not need to be created in advance. The system creates the user automatically after the user submits registration information.
  • Device Input Registration is not controlled by the Tenant registration method switch.

Procedure

  1. Select Registration - Device Input under Setting > Mode.
  2. Place an unregistered palm above the Palm Print scanning module and follow the device prompts to complete capture.
  3. After palm capture succeeds, tap Enter ID.

  1. Enter the User ID and Username. In a closed scene, the information must match the user information created in the PalmAI Admin Web.
  2. Verify the information and tap Confirm.

  1. The device binds the palm to the user information and displays a registration success message.

6.4.4 Host Input

For Host Input, an administrator or staff member enters user information and starts registration on a computer, and the user captures a palm on the M4 connected to the computer. This function applies only to M4, not M3.

The Host Demo, addresses, and configurations in this section are based on the Indonesia Production Environment and are intended only for feature evaluation and integration reference. Customers can see the Palm Developer documentation, go to API Reference > Device-Side, and integrate the Host communication protocol or supporting SDK to develop a Host application. The interface, service process, and environment configuration of a production project depend on the customer's actual integration.

Prerequisites

  • Host Input is enabled for the current Tenant in the PalmAI Admin Web.
  • In a closed scene, the administrator has created the corresponding user in the PalmAI Admin Web.
  • In an open scene, users do not need to be created in advance. The system creates the user automatically after the user submits registration information.
  • The serial cable supplied by the manufacturer is available and Host Demo is installed on the computer. If you have not obtained the serial cable, contact your account manager.

Download Host Demo

  1. Visit the PalmAI Enterprise KYC website.
  2. Under Host Demo Download, download the Windows or macOS version of Host Demo for the computer's operating system.

Before using the Host, confirm that the computer meets the following requirements:

ItemRequirement
Operating systemWindows // macOS // Linux
Serial driverPL2303 driver
Physical connectionUSB-to-serial cable (PL2303 chipset)
Serial parametersBaud rate 115200, 8 data bits, 1 stop bit, no parity, and no flow control

macOS users must also install and enable the PL2303 driver:

  1. Install PL2303 Serial App.
  2. After opening the App for the first time, the system displays a prompt that "PL2303 Serial App" wants to use a new driver extension. Click Open System Settings.

  1. The system opens Login Items & Extensions. Locate the PL2303Serial driver extension and turn on its enable switch.

Description: If the prompt above does not appear, uninstall and reinstall the application. Windows and Linux users can obtain the appropriate driver from the Prolific website.

Connect the device and enter registration mode

  1. Connect the computer and M4 using the serial cable.
  2. Select Registration - Host Input under Setting > Mode on the M4.
  3. Open Host Demo, select the serial port, and click Connect Device.

  1. Select Register.

Register through the Host

  1. Select Username Register on the Register page.
  2. Enter user information such as User ID and Name (username).
  3. Enable or disable High Similarity Detection as required.
  4. Click Register New User.

  1. After the user is created, the Host indicates that the device has awakened and prompts the user to place a palm.

  1. Follow the prompts on the M4 to complete palm capture.

  1. After palm capture is complete, the Host displays Palm recording completed, and the device indicates that registration is complete.

Implement Device Scan QR Registration through the Host

In addition to direct registration using Username Register, the Host can control the M4 to enter the Device Scan QR Registration process. The user must still generate a registration QR code through the H5 registration page, and the Host controls the device to enter the corresponding QR code registration state.

Prerequisites:

  • In a closed scene, the administrator has created the corresponding user in the PalmAI Admin Web.
  • In an open scene, users do not need to be created in advance. The system creates the user automatically after the user submits registration information.
  • The user has entered information on the H5 registration page and generated a registration QR code. This link is an evaluation environment entry point. The actual address depends on the project configuration.
  • The registration QR code is valid for 15 minutes and must be scanned by the device within this period.

Procedure:

  1. Select QR Code Register on the Host Register page.
  2. Enter the serial number of the target device in the Device SN field.
  3. Click Check Device. If the device serial number is incorrect, the Host displays a prompt.
  4. After confirming that the device information is correct, click Submit.
  5. The Host controls the M4 to switch to the Controlled by host state.

  1. Place an unregistered palm above the M4 Palm Print scanning module and follow the prompts to complete palm capture.
  2. After palm capture succeeds, the device enters the QR code scanning state.
  3. Align the registration QR code generated by the H5 page with the device camera.
  4. After the device scans the QR code successfully, the Host and device display the user information confirmation page.
  5. Verify the information and follow the page prompt to confirm registration.
  6. After registration is complete, the device indicates that Palm Registration is complete.

Return a user list for High Similarity detection

Before using High Similarity detection, complete both of the following configurations:

  • Select Username Register on the Host Register page and enable High Similarity Detection.
  • Enable High Similarity deduplication in the Tenant configuration in the PalmAI Admin Web.

During registration with Username Register or QR Code Register, if a High Similarity palm is detected, the system rejects the registration and displays a list of registered High Similarity users in the Host.

6.4.5 Device Scan QR Registration

For Device Scan QR Registration, the user generates a registration QR code through the H5 registration page. After the M4 captures the palm, the device scans the QR code on the phone to complete registration. This method does not require manually entering a User ID on the device.

Prerequisites

  • Device Scan QR Registration is enabled for the current Tenant in the PalmAI Admin Web.
  • In a closed scene, the administrator has created the corresponding user and entered the User ID and Username in the PalmAI Admin Web.
  • In an open scene, users do not need to be created in advance. The system creates the user automatically after the user submits registration information.
  • The user has entered the User ID, Username, and mobile number on the H5 Device Scan QR Registration page and generated a registration QR code. This link is an evaluation environment entry point. The actual address depends on the project configuration.
  • The registration QR code is valid for 15 minutes and must be scanned by the device within this period.

Procedure

  1. Open the H5 registration page, enter user information, and generate a registration QR code. In a closed scene, the user information must match the user created in the PalmAI Admin Web.

  2. Select Registration - Device Scan QR under Setting > Mode on the M4.

  3. Place an unregistered palm above the Palm Print scanning module and follow the device prompts to complete capture.

  4. After palm capture succeeds, the device opens the QR code scanning page.

  1. Align the registration QR code generated on the phone with the device camera.

  1. After the scan succeeds, the device displays the user information confirmation page.
  2. Verify the information and tap to confirm registration.

  1. The device binds the palm to the user information and indicates that Palm Registration is complete.

Note

The registration QR code is valid for 15 minutes. If it expires, refresh the H5 registration page to generate a new one. If the device fails to scan the code, clean the camera, increase the phone screen brightness, and try again.

6.4.6 Mobile Palm Registration

Mobile Palm Registration allows a user to preregister a palm using a phone camera through a mobile App or Mobile Palm Registration H5, and then perform the first Palm Scan on the M4 to complete activation. After mobile preregistration, the palm cannot yet be used for normal verification.

Prerequisites

  • Mobile Palm Registration is enabled for the current Tenant in the PalmAI Admin Web.
  • In a closed scene, the administrator has created the corresponding user in the PalmAI Admin Web.
  • In an open scene, users do not need to be created in advance. The system creates the user automatically after the user submits registration information.
  • The user has installed a mobile App that supports Mobile Palm Registration or can access Mobile Palm Registration H5.

This section uses the PalmMa demo App connected to the Indonesia Production Environment to describe the Mobile Palm Registration process. You can also use Mobile Palm Registration H5 to evaluate the same service. These entry points are intended only for feature evaluation and integration reference. To implement Mobile Palm Registration in a customer service, integrate the Mobile Palm Registration App SDK or H5 SDK according to the Palm Developer documentation and develop the required functionality. The pages, processes, and environment configuration of a production project depend on the customer's actual integration.

Log in to the PalmMa demo App or Air Enrollment H5

  1. Open the PalmMa demo App or the Air Enrollment H5 page, then enter the User ID.
  2. Select a tenant name. Available tenants include open tenants and closed tenants that already contain this User ID. You can check whether a tenant uses an open scene or a closed scene in PalmAI Admin Web under System Management > Tenant Management.
  3. Read and accept the privacy agreement, and then tap Submit to open the function home page.

Preregister the first palm

  1. Tap Registration on the function home page.

  1. In an open scene, enter the username in the Enter user name dialog during initial registration and tap OK. The system creates the user and opens the Palm Registration page. In a closed scene, the system uses the user information created in the PalmAI Admin Web.

  1. Ensure adequate lighting and a clean camera, and then tap Scan Palm.

  1. Scan the palm using the phone's rear camera and follow the page prompts to extend the palm, make a fist, and perform the other required actions in sequence.

  1. When the page displays Activate your palm, tap Done.

  1. Open the My Palm page and confirm that the preregistered palm displays Not Activated.

Activate the palm on the M4

  1. Confirm that the M4 has completed authorization, network connection, backend environment activation, and scene association.
  2. Select Recognition under Setting > Mode on the M4.
  3. Perform the first Palm Scan using the preregistered palm and wait for the device to display the Palm Scan success page.

  1. Return to the PalmMa demo App, open My Palm, and tap the corresponding palm. Confirm that its status has changed to Activated. The first activated palm displays the Main identifier.

Preregister and activate the second palm

  1. Open My Palm and tap Palm Registration or the position of the unregistered palm.
  2. Follow the preceding steps to preregister the other palm.
  3. Confirm that the first palm displays Activated and the newly preregistered palm displays Not Activated.

  1. Switch the M4 to Recognition and perform the first Palm Scan with the second palm to activate it.
  2. Return to My Palm and confirm that both palms display Activated. The first activated palm is the Primary Palm, and the subsequently activated palm is the Secondary Palm.

The device may display the following results:

  • Palm not registered: Confirm that mobile preregistration succeeded.
  • Palm registered and has access permission: The device displays the welcome page.
  • Palm registered but not in the access list, or the current time is outside the permitted verification period: The device indicates that the user has no permission. Contact the administrator.
  • Unstable network connection: The device prompts you to check the network. Check the device network connection.

6.4.7 Primary and Secondary Palm Rules

The same user can register both the left and right palms. To register the second palm, continue using the corresponding registration method and submit the same user's information.

Registration methodMethod for registering the second palm
Phone Scan QR RegistrationCapture the other palm, scan the device QR code with a phone, and enter the same user information as for the first palm.
Device Input RegistrationCapture the other palm, tap Enter ID, enter the same user information as for the first palm, and tap Confirm.
Host InputStart registration again using Username Register or QR Code Register, and capture the other palm.
Device Scan QR RegistrationCapture the other palm. After the device opens the QR code scanning page, scan the same user's registration QR code and confirm the user information.
Mobile Palm RegistrationPreregister the other palm through the mobile App or Mobile Palm Registration H5, and then perform its first Palm Scan in Recognition mode on the M4 to activate it.
  • The first activated palm is marked as the Primary Palm, Primary.
  • The other palm that is subsequently added and activated is marked as the Secondary Palm, Secondary.
  • Either the left or right palm can be the Primary Palm. Primary and Secondary Palm designations depend on activation order.
  • If a palm in the same direction has already been registered and is captured again, the system rejects the duplicate registration and indicates that the User ID is already registered.
  • When Dual Palm Registration is enabled for the current Tenant, each user can consume up to two Palm Database Quotas. Confirm that the Tenant has sufficient Palm Database Quota before registration.

6.4.8 Perform Routine Palm Scan Verification

After User Palm Registration is complete, switch the M4 to Recognition mode before performing routine Palm Scan verification.

Prerequisites

  • The M4 has completed authorization, network connection, backend activation, and scene association.
  • The Scene Strategy has taken effect.
  • If the scene is associated with a Verification Rule, the user and current time meet the rule requirements.
  • The user has completed Palm Registration. A Mobile Palm Registration user has completed initial activation on the M4.

Switch to Recognition mode

  1. Tap the settings button in the upper-left corner of the device home page.
  2. Enter the device settings password. The initial password is 000000.
  3. Tap Confirm to open the Setting page.
  4. Tap Mode.
  5. Select Recognition under Select mode.
  6. Return to the device home page.

Perform Palm Scan Verification

  1. Extend a registered palm naturally and keep the palm center facing the center of the Palm Print scanning module.
  2. Keep the palm approximately 5–12 cm from the device.
  3. Keep the palm steady and wait for the device to complete capture and verification.
  4. View the verification result displayed by the device. If both of the user's palms have been registered and activated, either activated palm can be used for verification. After recognition succeeds, the device displays Left Hand or Right Hand.
  5. If the device triggers Additional Verification, follow the page prompts to complete the corresponding additional identity confirmation.

After verification succeeds, the device displays a welcome or verification success page and the indicator light turns green. When reporting conditions are met, the device uploads the verification result to the Palm Application Platform.

If verification fails, check the following based on the device prompt:

  • Whether the palm has been registered and activated.
  • Whether the user is within the permitted user scope of the current scene.
  • Whether the current date and time are within the range allowed by the Verification Rule.
  • Whether the palm position, distance, and angle are correct.
  • Whether the camera and palm are clean.
  • Whether the device network is operating normally.

Description

The Primary Palm is the user's first activated palm. The Secondary Palm is the other palm added and activated later. If a user registers only one palm, the unregistered palm cannot be used for verification.

6.4.9 Configure High Similarity Palm Registration Deduplication

High Similarity palm registration deduplication determines during registration whether the current palm is highly similar to an existing palm. This function affects only Palm Registration results and differs from Additional Verification after Palm Scan verification.

Configure this function in the PalmAI Admin Web:

  1. Go to System > Tenant Management.
  2. Find the current Tenant and click Edit.
  3. Find High Similarity Deduplication and set the High Similarity Dedup switch.
  4. Click Submit to save.

The processing results for each switch state are as follows:

High Similarity Dedup enabled

If a High Similarity palm is detected during Palm Registration, the system rejects the registration. The M4 displays Palm Already Registered, and the user status in the PalmAI Admin Web is Unregistered.

High Similarity Dedup disabled

When a High Similarity palm is registered, the M4 still indicates that registration succeeded, but the user status in the PalmAI Admin Web is Abnormal.

When using Username Register on the Host for High Similarity detection, also enable High Similarity Detection on the Host. For complete Tenant configuration instructions, see "3.9.1 Create Tenant" and "3.9.3 Edit Tenant" in the PalmAI Admin Web User Manual.

6.4.10 Use Additional Verification

Additional Verification is an additional identity confirmation process performed after a user's Palm Scan passes. The M4 supports three Additional Verification methods: the last four digits of a mobile number, a custom numeric field, and Device QR Code Scan.

Configure an Additional Verification method in the PalmAI Admin Web

  1. Log in to the PalmAI Admin Web and go to System > Tenant Management.
  2. Find the target Tenant and click Edit.
  3. Find Verification Method under Verification Configuration.
  4. Select the Additional Verification method for the current Tenant:
    • Last 4 Digits of Phone Number
    • Custom Field
    • Device QR Code Scan
  5. Complete the corresponding configuration for the selected method and click Submit.

When Custom Field is selected, also add or select a verification field and specify the currently active field under Active Verification Field. When Device QR Code Scan is selected, use QR Code Expiration to set the authentication QR code validity period. For complete field descriptions, see "3.9.4 Tenant-Level Additional Verification Configuration" in the PalmAI Admin Web User Manual.

When a hybrid or cloud-only strategy is used and Additional Verification is enabled for the Tenant, the system may trigger Additional Verification in security risk-control scenarios such as High Similarity. It is not triggered for every Palm Scan.

6.4.10.1 Last Four Digits of Mobile Number

This Additional Verification method uses the last four digits of the user's mobile number for additional identity confirmation.

Prerequisites

  • The administrator has maintained a mobile number for the user in the PalmAI Admin Web.
  • The current Tenant has selected Additional Verification using the last four digits of a mobile number.

Procedure

  1. The user completes a Palm Scan and passes recognition on the device.
  2. The device displays a numeric input page and prompts the user to enter the last four digits of the mobile number.
  3. Enter and submit the last four digits. The system completes the additional identity check.

6.4.10.2 Custom Numeric Field

Custom numeric field Additional Verification uses project-specific numeric information, such as an employee ID or device number, for additional identity confirmation. It supports 4–8 digits.

Prerequisites

  • The administrator has enabled custom numeric field Additional Verification in the Tenant configuration.
  • The administrator has maintained the corresponding custom numeric field value for each user in the PalmAI Admin Web. A user without this field cannot complete Additional Verification.

Procedure

  1. The user completes a Palm Scan and passes recognition on the device.
  2. The device displays a numeric input page and prompts the user to enter the corresponding custom numeric field.
  3. Enter the digits using the device numeric keypad.
  4. Tap the confirmation button.
  5. The system validates the input. If validation succeeds, the verification succeeds and a log is recorded. If validation fails, the device displays a prompt and allows another attempt.

6.4.10.3 Device QR Code Scan

For Device QR Code Scan Additional Verification, after the user's Palm Scan passes, the M4 scans an authentication QR code generated by an H5 page to complete additional identity confirmation.

Prerequisites

  • The current Tenant has selected Device QR Code Scan under Verification Method.
  • The H5 Additional Verification address for the current project is available. The following address is for the Indonesia evaluation environment and is intended only for evaluation and testing: https://app.intl.palm.tencent.com/local_h5/login. For the production H5 address, contact the project owner or account manager.

Procedure

  1. The user completes a Palm Scan and passes recognition on the device.
  2. The device prompts the user to present an authentication QR code and automatically turns on the camera. The device waits 60 seconds for a scan.
  3. Open the H5 Additional Verification page in a mobile browser.
  4. On the Login page, enter the userID, select the Tenant, enter the mobile number, and obtain a verification code.
  5. Enter the Verification code, select the data processing agreement, and tap Login.
  6. Follow the page prompts to enter Additional Verification information and generate an authentication QR code.
  7. Align the authentication QR code on the phone with the device camera.
  8. After the device scans the code successfully, Additional Verification is complete and the verification process ends.

Note

The authentication QR code validity period is configured by QR Code Expiration in the PalmAI Admin Web and defaults to 60 seconds. The QR code expires when the countdown ends. If the device waits more than 60 seconds for a scan, the verification fails. Perform another Palm Scan to trigger Additional Verification again.

6.4.11 Set the Output Mode and Return Data to the Host

  1. Tap the settings button in the upper-left corner of the device home page.
  2. Enter the device settings password. The initial password is 000000.
  3. Tap Confirm to open the Setting page.
  4. Tap Output.
  5. Select UserID mode or Card number mode.

After configuration, the M4 returns the corresponding information to the Host when a user performs a Palm Scan.

Note

This function applies only to M4. To use it, contact your account manager in advance to obtain the serial cable supplied by the manufacturer.

6.4.12 Report and View Verification Records

After completing verification, the M4 uploads the result to the Palm Application Platform. The device must remain connected to the network and associated with a scene before Verification Records can be viewed by scene in the PalmAI Admin Web.

The M4 uploads Verification Records to the Palm Application Platform. Verification Record Push is the separate process by which the Palm Application Platform pushes received records to a third-party system.

View Verification Records

  1. Log in to the PalmAI Admin Web and go to Verification > Verification Records.
  2. Filter records by time range, scene, User ID, Username, verification status, or source.
  3. Click Search.
  4. View the verification time, status, user, scene, method, Device SN, and other information.
  5. To save records, click the export button to export Verification Records within the current permission scope to an Excel file.

Members can view and export only Verification Records under Scene Groups they manage. If no records are found, confirm the following in order:

  • The M4 has completed backend activation, is connected to the network, and is associated with the target scene.
  • The user has completed Palm Registration. A palm preregistered through Mobile Palm Registration has completed its first Palm Scan activation.
  • If the scene is associated with a Verification Rule, the user and current time meet the rule requirements.
  • The Scene Strategy and Additional Verification configuration have taken effect.

Configure Verification Record Push

To push Verification Records to a third-party business system in real time, configure Verification Record Push for the Tenant:

  1. Go to System > Tenant Management.
  2. Find the target Tenant and click Edit.
  3. Enter the Push URL under Verification Record Push.
  4. Confirm that Request Method is POST.
  5. Select the records to push under Push Range.
  6. Click Submit.

The Push URL must be a valid callback address beginning with http:// or https://. Leave it blank if Verification Records do not need to be pushed to a third-party system. For complete field descriptions, see "3.9.1 Create Tenant" and "3.9.3 Edit Tenant" in the PalmAI Admin Web User Manual.

6.5 Device Configuration and Routine Maintenance

6.5.1 Configure and Deploy a Custom UI

Administrators can configure the M4 home page, verification success page, verification failure page, and verification result countdown in the PalmAI Admin Web and deploy them by scene or Device SN:

  • By Scene: The configuration applies to devices in the selected scene. Devices subsequently added to the scene or Scene Group automatically use this configuration.
  • By Device SN: The configuration applies only to selected devices. Devices added later must be included manually.

The M4 checks for Theme Package changes every 10 minutes. When an update is detected, the device downloads the Theme Package in the background. After the download is complete, the device indicates that the Theme Package has been updated. The user can apply it immediately; if no action is taken, the device applies it automatically after 10 seconds. The device cannot obtain updates while offline or powered off and obtains them at the next check after the network connection is restored.

If a corresponding page is not configured, the M4 uses the system Default Template. After the template currently used by the device is deleted, the device returns to the system default style. After a general configuration is deleted, associated devices return to the default countdown.

For details, see "3.1.2 Device Configuration" in the PalmAI Admin Web User Manual.

6.5.2 Perform a Device Health Check

Device Health Check checks the device's current resources, network, module, and service function status. It is a one-time check initiated by the device and differs from continuous status monitoring in the PalmAI Admin Web.

  1. Open the Setting page.
  2. Tap Device Health Check.
  3. Wait for the device to complete the check. During the check, the page displays the current item, such as Checking: Device Network or Checking: Module Distance Sensor.
  4. If the check completes without detecting an exception, the device displays Device Normal.
  5. Tap View Report to view the results. To run the check again, tap Re-check.

  1. The device can display a report QR code. Scan the QR code below Scan to View Report with a phone to view the report, and then tap Close.

Check scope

Check moduleCheck content
Complete deviceCPU, memory, RAM/ROM, disk, WiFi and Ethernet, network quality, module connection, Device SN, system version, and daemon version.
ModuleRAM/ROM, disk, Device SN, uvc_app version, algorithm library version, and local Palm Print Database integrity.
Service functionsOptimal Palm Feature Selection, liveness detection, feature extraction, Palm Registration, Palm Scan, log reporting, basic performance, and IoT polling.

If a check result is abnormal, locate the relevant logs as described in "6.5.5 View Device Logs."

6.5.3 View Device Operating Status

Administrators can search for an M4 by Device SN or device name under Device Management > Device List and view its online status, component status, resource health information, and versions.

To view overall device trends and high-risk devices, open the device dashboard. For details, see "3.1.1 Device List" and "3.8.2 Device Dashboard" in the PalmAI Admin Web User Manual.

6.5.4 Report a Device Issue

When registration fails, a Palm Scan fails, a result is abnormal, or the interface is abnormal, report the issue from the device.

  1. Tap Report technical issue on the verification failure page.

  1. On the Report technical issue page, select the Issue Type that matches the situation:
    • Palm Scan Failed for Registered User
    • Palm Scan Failed for Unregistered User
    • Registration Failed
    • Palm Scan Result Does Not Match
    • Abnormal Interface Display
    • Palm scan took too long
    • Other Issues

  1. Tap Report.
  2. The device displays Collecting logs... and collects information related to the issue.

The device synchronizes the Issue Type and current Palm Scan information to the Operations Management Platform. A Super Administrator can locate and process the issue under Operation > Issue Report.

6.5.5 View Device Logs

The cloud platform log service must be enabled to use Device Logs.

  1. Log in to the PalmAI Admin Web and go to Device Management > Device Logs.
  2. Filter logs by Log ID, Log Date, Device, or Status.
  3. Find the target log and click Download Logs.

For details, see "3.1.4 Device Logs" in the PalmAI Admin Web User Manual.

6.5.6 Remote Device Maintenance

Administrators can dispatch remote commands to the M4 through the PalmAI Admin Web without operating the device on site.

  1. Log in to the PalmAI Admin Web and go to Device Management > Device Instruction.
  2. Select the command tab to use.
  3. Click Send Instruction.
  4. Select the target device and enter the parameters required on the page.
  5. Click Submit.
  6. Return to the command list to view execution status.

The M4 supports the following remote commands:

Command tabFunction and precautions
Device RestartRemotely restarts the entire device. The device is temporarily unavailable during restart.
App RestartRemotely restarts the device application, which differs from restarting the entire device.
Factory ResetRemotely restores the device to factory settings.
Reset Palm FeaturesRemotely resets palm print features on the device.
Reset Blacklist DataRemotely resets Blocklist data on the device.
Clear Local DataClears local device data.
WiFi SettingsRemotely dispatches a WiFi name and password.

Warning

Remote commands cannot be undone. Use them with caution.

View command execution status

After dispatching a command, view its dispatching, successful, or failed status in the list on the corresponding command tab.

Description

Remote Door Open does not support M4 and is outside the scope of remote maintenance in this manual.

6.5.7 OTA Upgrades and Version Maintenance

The M4 supports OTA Upgrade Tasks dispatched from the PalmAI Admin Web and manual installation of dispatched upgrades on the device. Maintainable components include System Firmware, Module Firmware, the application, and Algorithm Packages.

Before an upgrade, confirm that the device uses a stable power supply and remains connected to the network. Do not shut down or disconnect power, or repeatedly trigger an upgrade, during an upgrade or automatic restart.

6.5.7.1 Upload an Upgrade Package

Before creating an Upgrade Campaign, upload the corresponding component Upgrade Package supplied by the manufacturer to the PalmAI Admin Web:

  1. Log in to the PalmAI Admin Web and go to Device Management > Upgrade Package.
  2. Click Add Upgrade Package.
  3. Select and upload the Upgrade Package, enter the version description, and submit.
  4. After upload is complete, confirm the version, Device Model, and other information in the Upgrade Package list.

Upgrade Packages are provided by original manufacturer technical support. For instructions on adding, viewing details of, and deleting Upgrade Packages, see "3.1.6 Upgrade Package Management" in the PalmAI Admin Web User Manual.

6.5.7.2 Create an Upgrade Campaign and Upgrade Task in the PalmAI Admin Web

Create an Upgrade Campaign

  1. Log in to the PalmAI Admin Web and go to Device > Device OTA.
  2. Click Add Upgrade Campaign.
  3. Enter the Campaign Name and configure:
    • Campaign Type: Select System Firmware, Module, Application, or Algorithm.
    • Model: Select the target Device Model.
    • Select Version: Select the target version.
    • Task Expiration: Set the task validity period.
    • Version Name and Release Notes: Enter the version name and description.
  4. Click Submit.

Create an Upgrade Task

  1. Click Details in the target Upgrade Campaign.
  2. On the Campaign Details page, click Add Task.
  3. Enter the Upgrade task name and set Silent Upgrade.
  4. Under Select associated devices, select:
    • All Devices: Targets all currently eligible devices. Devices registered after task creation do not receive this push.
    • Specific Devices: Dispatches the task only to the devices specified for this task.
  5. When Specific Devices is selected, upload devices through Excel Upload or enter serial numbers under Enter Device SN.
  6. Click Check Device. If a device has not been registered, Check Result displays Devices are not recorded. Use Clear Invalid Devices to remove invalid devices.
  7. After validation passes, click Submit.

6.5.7.3 Silent and Active Upgrades

Upgrade methodBackend settingDevice behavior
Silent UpgradeEnable Silent UpgradeThe device automatically downloads and installs the task after receiving it.
Active upgradeDisable Silent UpgradeThe device receives the task but does not install it automatically. On-site personnel must tap Upgrade on the device.

For an active upgrade:

  1. Open the device Setting page and scroll down.
  2. When an upgrade is available, a red dot appears next to the corresponding component entry.
  3. Tap the upgrade entry with the red dot.
  4. View the target Version and Upgrade content:.
  5. Tap Upgrade.
  6. Wait for the device to complete installation and restart automatically.

Tip

The device checks for Upgrade Tasks every 10 minutes. To obtain a task sooner, manually tap the corresponding upgrade entry to trigger a check.

6.5.7.4 Upgrade the System, Module, Application, and Algorithm Package

Open the page for the component to upgrade, view its current version, and follow "6.5.7.3 Silent and Active Upgrades."

Upgrade targetDevice entryDescription
Main controller System FirmwareSetting > System updateAfter installation, wait for the device to restart automatically.
Biometric Module FirmwareSetting > Module updateA Module Firmware Upgrade Package can include an Algorithm Package, depending on the package selected in the PalmAI Admin Web.
Device applicationSetting > App updateAfter installation and automatic restart, open App update again to confirm that the version has been updated.
Algorithm PackageSetting > Algo updateAlgorithm Packages support independent upgrades. When creating an Upgrade Campaign, select Algorithm for Campaign Type. The algorithm can also be updated with a Module Firmware Upgrade Package.

When performing multiple upgrades, use the following order:

Module updateSystem updateApp update

Algorithm Packages can be upgraded independently of Application Packages, and a Module Firmware upgrade can also include an Algorithm Package.

6.5.7.5 View Upgrade Status and Results

After an Upgrade Task is created, view task dispatch progress, device upgrade status, and failure reasons in the PalmAI Admin Web. For details, see "3.1.3 Device OTA" in the PalmAI Admin Web User Manual.

After the device completes an upgrade and restarts automatically, open Setting and view the current version on the corresponding System update, Module update, App update, or Algo update page to confirm the result.

6.6 Device Cleanup and Removal

When a device no longer serves the current business, clean up or reset it as needed, or delete it from the current PalmAI Admin Web. For scene association and change procedures, see "6.2.6 Manage Device and Scene Associations."

6.6.1 Clean Up and Reset the Device

The device-side Data Reset and remote reset commands in the PalmAI Admin Web are different operations:

OperationOperation sideEntryFunction
Data ResetDeviceSetting > Device information > Data ResetResets device data.
Reset Palm FeaturesPalmAI Admin WebDevice Instruction > Reset Palm FeaturesResets palm print features on the device.
Clear Local DataPalmAI Admin WebDevice Instruction > Clear Local DataClears local device data.
Factory ResetPalmAI Admin WebDevice Instruction > Factory ResetRemotely restores the device to factory settings.

For remote command dispatch procedures, see "6.5.6 Remote Device Maintenance."

Warning

Remote cleanup and reset commands cannot be undone. Use them with caution.

6.6.2 Delete a Device from the PalmAI Admin Web

Before deleting a device from the PalmAI Admin Web, disassociate it from its scene. The PalmAI Admin Web prevents deletion while the device remains associated with a scene. For disassociation instructions, see "6.2.6 Manage Device and Scene Associations."

Delete a device

  1. Go to Device Management > Device List.
  2. Find the target device by Device SN or device name.
  3. Click Delete to the right of the target device.
  4. Confirm deletion in the confirmation window.

After the device is deleted:

  • The Palm Database and rules on the device are deleted.
  • The device can no longer perform Palm Scans.
  • Existing historical Verification Records are not affected.

Warning

Before deleting the device, confirm that it no longer serves the current business.

6.7 FAQ

6.7.1 No Display After Power-On

  1. Confirm that the 12 V power adapter supplied with the device is used.
  2. Check that the power socket, power adapter, and device power cable are securely connected.
  3. Check that the adapter output meets the device requirements.
  4. Reconnect power. If there is still no display, contact after-sales support.

6.7.2 Device Displays Not Registered or Not Activated

  1. Confirm the Device SN on the chassis label or under Device information.
  2. Ask the administrator to confirm that the Device SN has been entered in the PalmAI Admin Web.
  3. After confirming that the device is connected to the network, scan a valid device activation QR code again.
  4. If the device has been entered but still displays not registered, check that the current PalmAI Admin Web environment is correct.
  5. If the issue persists, contact after-sales support to check the system or application version.

6.7.3 How Do I Handle an Authorization Exception or Expiration?

  1. Distinguish License authorization from backend environment activation. An exception on the authorization page relates to the License. A device not registered or an abnormal activation code relates to backend environment activation.
  2. For online authorization, check the device network and time.
  3. Confirm that the authorization QR code corresponds to the current device and APP ID and remains valid.
  4. If authorization is abnormal, perform authorization again. Repeated authorization may consume the authorization quota, so confirm the Number of Licenses before proceeding.
  5. If authorization has expired, contact sales or technical support to obtain a new authorization QR code.

6.7.4 Palm Scan Is Slow or Recognition Fails

  1. Remove the camera protective film and clean the camera area.
  2. Keep the palm center clean and free of visible dirt or sweat.
  3. Keep the palm 5–12 cm from the device with the palm center facing the camera.
  4. Avoid strong backlight, obstruction, rapid movement, and excessive tilt.
  5. Check device network quality.
  6. After repeated failures, ask the administrator to check the user registration status, scene permissions, and palm data.

Use a wired network whenever possible. Wired networks are generally more stable than WiFi. WiFi is not recommended as the standard connection for deployments of more than 10 devices.

6.7.6 What Are the Wired Network Cabling Requirements?

  • Each network cable segment must not exceed 100 m; 80 m or less is recommended.
  • Do not place connectors in the middle of a network cable. Avoid tight bends, crushing, and high-voltage electrical interference.
  • Use CAT5e or higher-grade cables and standard RJ45 Connectors. Test the line with a Cable Tester before deployment.
  • Protect cables with PVC Conduit or Wiring Duct.
  • Use a stable power supply for each device and avoid sharing a power circuit with high-power equipment.

6.7.7 How Much Network Bandwidth Is Required for Different Device Counts?

The following values are recommended. Adjust actual bandwidth based on site network quality and business concurrency:

Number of devicesRecommended bandwidth and networking method
1–4Shared bandwidth of at least 20 Mbps; devices can connect directly to a router.
5–30Bandwidth of at least 100 Mbps; use an Enterprise-Grade Router and Managed Switch.
31 or moreUse a dedicated line of at least 100 Mbps and configure an Enterprise-Grade Router, Gigabit Switch, and VLAN according to the project network plan.

6.7.8 What Are the Switch Deployment Limits?

Do not cascade more than three levels of switches on the same LAN. Excessive link levels can increase network latency and reduce stability.

6.7.9 Ethernet Is Unavailable

  1. Go to Setting > Network setting > WiFi and turn off the wireless network.
  2. Check the network cable, RJ45 Connectors, router, and switch ports.
  3. Confirm that both ends of the network cable use the same standard Wire Sequence.
  4. Under Ethernet, confirm that the network is enabled and check the DHCP or Static configuration.

Enabling Ethernet and WiFi at the same time may cause a network conflict. Turn off WiFi when using a wired network.

6.7.10 Cannot Search for or Connect to WiFi

  1. Move closer to the wireless router and eliminate metal obstructions and weak-signal issues.
  2. Confirm that the router has enabled a WiFi band supported by the device.
  3. Use a combination of letters and numbers for the WiFi password and avoid special characters.
  4. Check that the network name and password are correct.
  5. Use a wired network in basements or locations with poor signal coverage.

6.7.11 WiFi Is Connected but the Network Is Inaccessible

  1. Confirm that Ethernet is turned off.
  2. Check whether the router and other devices on the same network can access the network normally.
  3. Check the DHCP or Static network parameters.
  4. Reconnect to WiFi and test again.

6.7.12 What Is the Difference Between Registration and Recognition Modes?

  • Registration mode captures a palm and binds it to user information. It is not used for routine Palm Scan verification.
  • Recognition is used for routine verification of registered users and the first on-site activation of Mobile Palm Registration users.

After registering users in batches, switch the device back to Recognition.

6.7.13 No Voice Prompt or Volume Is Too Low

  1. Go to Setting > System setting and increase the volume.
  2. Check whether a bracket, decoration, or foreign object obstructs the device speaker opening.
  3. Restart the device and test again.
  4. If there is still no sound, contact after-sales support.

6.7.14 Does the Device Support PoE Power Supply?

The M4 does not support PoE power supply. Use the 12 V power adapter supplied with the device.

6.7.15 What Lighting Conditions Does the Device Require?

Avoid using the device outdoors in strong backlight or where lighting changes dramatically. Adjust the device angle so that light falls evenly on the palm and strong light does not shine directly into the camera.

6.7.16 How Should I Perform a Palm Scan?

  • Extend the palm naturally with the palm center facing the camera center.
  • Keep the palm approximately 5–12 cm from the device.
  • Minimize palm tilt and rotation and keep the palm steady during recognition.

6.7.17 How Should the Device Be Positioned, and Is It Waterproof?

The M4 is not waterproof. Place it indoors or in a sheltered semi-outdoor area away from rain, humidity, and strong backlight. Place the device on a stable surface and adjust its height based on the average height of users at the site.

6.7.18 Mobile Web Mobile Palm Registration Fails

  1. Confirm that the mobile device camera has at least 3 megapixels.
  2. Confirm that the browser has camera permission and the network connection is normal.
  3. In a closed scene, ask the administrator to confirm that the corresponding user has been created in the PalmAI Admin Web.
  4. Check that the user information is correct, including letter case.
  5. Ensure adequate lighting and recapture the palm by following the page prompts.

6.7.19 Device Scan QR Registration Fails

  1. Check whether the registration QR code has expired. It is valid for 15 minutes; generate a new one on the H5 page after expiration.
  2. Clean the device camera and increase the phone screen brightness.
  3. Confirm that the corresponding user information has been entered in the PalmAI Admin Web.
  4. Confirm that the device is in Registration - Device Scan QR mode.
  5. Confirm that Device Scan QR Registration is enabled for the current Tenant.

6.7.20 Device QR Code Scan Additional Verification Fails

  1. Confirm that the Tenant has selected Device QR Code Scan Additional Verification.
  2. Check whether the authentication QR code has expired and generate a new one if necessary.
  3. If the device waits more than 60 seconds for a scan, perform another Palm Scan to trigger Additional Verification again.
  4. Clean the camera and increase the phone screen brightness.
  5. Confirm that the user meets the registration and Additional Verification requirements of the current project.

6.7.21 What Are the Resolution and Frame Rate of the RGB and Infrared Lenses?

Both the RGB and infrared lenses have a resolution of 1600 × 1200 and a frame rate of 30 FPS.

6.7.22 Does Mobile Palm Registration Have Camera Requirements for Mobile Devices?

A mobile device camera with at least 3 megapixels is sufficient.