Methods for verifying biometric authentication of a user and identity authentication system
Patent Information
- Application Number
- BR102019001478
- Authority / Receiving Office
- BR · BR
- Patent Type
- Patents
- Current Assignee / Owner
- Publication Date
- 2026-09-15
Smart Images

Figure 00000120_0000 
Figure 00000121_0000 
Figure 00000122_0000
Abstract
Description
1 / 113 “METHODS FOR VERIFYING A USER'S BIOMETRIC AUTHENTICATION AND IDENTITY AUTHENTICATION SYSTEM” FIELD
[001] The disclosed modalities refer to biometric security. More specifically, the disclosed modalities refer to facial recognition authentication systems. RELATED TECHNIQUE
[002] With the advent of personal electronic devices that can be used to access many different user accounts, and the growing threat of identity theft and other security issues, there is an increasing need for ways to securely access user accounts through electronic devices. Account holders are therefore often required to have longer passwords that meet various criteria, such as the use of a mix of uppercase and lowercase letters, numbers, and other symbols. With smaller electronic devices, such as smartphones, smartwatches, the “Internet of Things” (“IoT”), and other devices, it can be difficult to try to type these long passwords into the device every time account access is desired, and if another individual knows the user's password, the user could be impersonated without actually being present.In some cases, users may even decide to disable these cumbersome security measures due to the inconvenience they pose to their devices. Therefore, users of such devices may prefer other secure methods of accessing their user accounts.
[003] Another such method may be through biometrics. For example, an electronic device may have a dedicated sensor that can scan a user's fingerprint to determine if the person requesting access to a device or account is authorized. However, such fingerprint systems are often prohibitively expensive for use in an electronic device. Petition 870260077099, dated 03 / 08 / 2026, page 7 / 246 2 / 113 small and often considered unreliable and insecure.
[004] Furthermore, facial recognition is generally known and can be used in a variety of contexts. Two-dimensional facial recognition is commonly used to tag people in images on social networks or in photo editing software. Facial recognition software, however, has not been widely implemented individually to securely authenticate users attempting to gain access to an account because it is not considered secure enough. For example, two-dimensional facial recognition is considered insecure because faces can be photographed or recorded, and then the resulting prints or videos showing images of the user can be used to deceive the system. Thus, there is a need for a reliable, economical, and convenient method to authenticate users attempting to log in, for example, to a user account. SUMMARY
[005] The embodiments disclosed were developed in light of the foregoing, and aspects of the invention may include a method for registering and authenticating a user in an authentication system through the user's mobile computing device. The user device includes a camera and at least one motion detection sensor, such as an accelerometer, magnetometer, and gyroscope.
[006] In one embodiment, the user can register with the system by providing registration images of the user's face. The registration images are obtained by the mobile device's camera as the user moves the mobile device to different positions relative to the user's head. The user can then obtain registration images showing the user's face from different angles and distances. The system can also use one or more motion sensors on a mobile device to determine a registration movement path that the Petition 870260077099, dated 03 / 08 / 2026, page 8 / 246 3 / 113 phone data was taken during image generation. At least one image is processed to detect the user's face within the image and to obtain biometric information from the user's face in the image. Image processing can be done on the user's mobile device or on a remote device, such as an authentication server or a user account server. Registration information (biometrics, movement, and other registration information) can be stored on the mobile device or remote device, or both.
[007] The system can then authenticate a user by having the user provide at least one authentication image via the mobile device's camera while the user moves the mobile device to different positions relative to the user's head. The authentication images are processed using facial biometrics and facial detection information. Path parameters can also be obtained during the image generation of the authentication images (authentication movement). The authentication information (biometrics, movement, and other authentication information) is then compared with the registration information to determine whether the user should be authenticated or denied. Image processing and comparison can be conducted on the user's mobile device or remotely.
[008] In some modes, multiple registration profiles can be created by a user to provide greater security. For example, a user can create a registration using accessories, such as a hat or glasses, or by making a funny face. In other modes, the user's registration information can be linked to the user's email address, phone number, or other unique identifier.
[009] The authentication system may include comments displayed on the mobile device to assist a user in learning and authenticating with the system. For example, an accuracy meter may provide comments on a Petition 870260077099, dated 03 / 08 / 2026, page 9 / 246 4 / 113 motion matching rate or biometric authentication. A motion meter can provide feedback on the motion detected by the mobile device.
[010] In some modes, the system may reward users who correctly use the authentication system or who otherwise take measures to prevent fraud. Such rewards may include leaderboards, status levels, reward points, coupons or other offers, and the like. In some modes, the authentication system may be used to log into multiple accounts.
[011] In addition to biometric and motion matching, some modalities may also utilize band detection, reflection detection, and screen edge detection to make the system more secure. In other modalities, other user attributes may be detected and matched, including the user's gender, age, and ethnicity, and the like.
[012] The system can also provide gradual access to the user account(s) when the user first sets up the authentication system. As the user correctly implements the system, authorization can be expanded. For example, over a period of time as the user becomes accustomed to the authentication system, lower transaction limits can be applied.
[013] In some modes, the mobile device may display video comments of what the user is photographing to assist the user in photographing their face during registration or authentication. The video comments may be displayed in only a portion of the mobile device's display screen. For example, the video comments may be displayed in an upper portion of the display screen. The display of video comments may be positioned in a portion of the display screen that corresponds to the location of a front-facing camera on the mobile device. Petition 870260077099, dated 03 / 08 / 2026, page 10 / 246 5 / 113
[014] To facilitate low-light imaging, portions of the screen, other than video commentary, may be displayed in a bright color, such as white. In some embodiments, LED or infrared light may be used, and near-infrared thermal imaging may be performed with an infrared camera. The mobile device used for imaging may then have multiple cameras for capturing infrared and visible light images. The mobile device may also have multiple cameras (two or more) imaging in a single spectrum or multi-spectrum to provide stereoscopic three-dimensional images. In this embodiment, close-up (zoomed) frames may create the greatest differentiation compared to images captured from a distance. In this embodiment, frames captured from a distance may be unnecessary.
[015] In some embodiments, to provide greater security, the mobile device may emit objects, colors, or patterns on the display screen to be detected during image generation. The predetermined object or pattern may be a single one-dimensional or two-dimensional barcode. For example, a QR code (two-dimensional barcode) may be displayed on the screen and reflected from the user's eye. If the QR code is detected in the image, then the person can be authenticated. In other embodiments, an object may move on the screen and the system may detect whether the user's eye follows the movement.
[016] In some modes, the system may provide instructions in a video comment display to assist the user in moving the device relative to the user's head during registration and / or authentication. The instructions may include ovals or squares displayed on the screen where the user must place their face by moving the mobile device until their face is within the oval or square. The instructions may preferably be of different sizes and may also be centered in different positions on the screen. When Petition 870260077099, dated 03 / 08 / 2026, page 11 / 246 6 / 113 When a real three-dimensional person's image is captured up close and from a distance, it is observed that the biometric results differ due to the barrel distortion effect of the lenses at different distances. Therefore, a three-dimensional person can be validated when the biometric results differ in close-up and distant images. This also allows the user to have multiple biometric profiles for each distance.
[017] In other modalities, image biometrics obtained between near and far images can be analyzed for incrementally different biometric results. In this way, the transformation of the face from a distant angle to the distorted near angle is captured and tracked. The incremental frames during authentication can then be combined with frames captured at similar locations during registration along the motion path and compared to ensure that the expected similarities and differences are found. This results in a motion path and captured image and biometric data that can prove that a three-dimensional person is currently being photographed. Thus, not only are near and far biometric data compared, but also the biometric data obtained between them.The biometric data obtained between them must also correspond to a correct transformation speed along the movement path, greatly increasing the system's security.
[018] The touchscreen can be used in several ways. For example, the user may need to enter or swipe a code or pattern in addition to the authentication system described here. The touchscreen can also detect the size and orientation of the user's finger and whether the right or left hand is used on the touchscreen. Voice parameters can also be used as an additional layer of security. The system can detect edge sharpness or other indicators to ensure that the images obtained are of sufficient quality for the Petition 870260077099, dated 03 / 08 / 2026, page 12 / 246 7 / 113 authentication system.
[019] When a camera has autofocus, the autofocus can be controlled by the system to validate the presence of the real three-dimensional person. Autofocus can verify that different features of the user or the environment are in focus at different focal distances. In other modes, authentication images can be saved to evaluate the person who attempted to authenticate with the system.
[020] In some modes, the required matching thresholds may be adapted over time. The system may therefore take into account changes in biometrics due to age, weight gain / loss, environment, user experience, security level or other factors. In other modes, the system may use image distortion before obtaining biometric information to further protect against fraudulent access.
[021] A method is also disclosed for verifying biometric authentication comprising receiving root biometric identification information, corresponding to a user, from a trusted biometric information source to establish the root biometric identification information as reliable and verified. Storing the root biometric identification information in a database and subsequently, during an authentication process, capturing a first image with an authentication camera. The first image is captured when the user is at a first distance from the authentication camera. Capturing a second image with the authentication camera, such that the second image is captured when the user is at a second distance from the authentication camera. The first distance is different from the second distance.The operating method also includes processing the first image to create the first biometric authentication information and processing the second image to create the second biometric authentication information. The method also compares the first image to the second. Petition 870260077099, dated 03 / 08 / 2026, page 13 / 246 8 / 113 Biometric authentication information with the second biometric authentication information and compares the root biometric identification information with the first biometric authentication information, the second biometric authentication information, or both. The method will authenticate the user when the comparison determines that the first biometric authentication information matches the second biometric authentication information within a boundary, but is not identical, and the comparison determines that the root biometric identification information matches the first biometric authentication information, the second biometric authentication information, or both, within a boundary.
[022] In one embodiment, the authentication camera is one of the following camera types: a camera on a user's mobile device, a camera on a user's computer, a camera in an ATM, a camera at a point of sale, and a camera in a financial institution. The trusted biometric information source is a first camera at a trusted source. The first camera may be located in a financial institution or in a government agency office. In one configuration, an authentication server receives the root biometric identification information, the first authentication biometric information, and the second authentication biometric information, and the authentication server performs the comparison and authentication.
[023] In one arrangement, the first and second images are of the user's face. As part of a liveness determination, one of the first and second images is distorted due to barrel distortion. The method may further comprise performing one or more additional liveness tests on the first or second image to verify that the user is a living person during the authentication process.
[024] A method is also disclosed for verifying a user's biometric authentication comprising storing identification information. Petition 870260077099, dated 03 / 08 / 2026, page 14 / 246 9 / 113 User root biometric data obtained from a trusted biometric detection device located in a trusted location to establish the root biometric identification information as reliable and verified. Then, during an authentication session, receive root biometric identification information, receive authentication biometric identification information from a computing device during an authentication session, and compare the root biometric identification information with the authentication biometric identification information. Authenticate the user when the root biometric identification information matches the authentication biometric identification information within a predetermined limit.
[025] In one embodiment, the trusted biometric detection device is located in one of the following locations: a financial institution, a point of sale, or a government entity. The computing device used during an authentication session is located in a financial institution, ATM, point of sale, or is the user's mobile device or personal computer. In one embodiment, the trusted biometric detection device includes a camera, and the computing device used during an authentication session includes a camera. The root biometric identification information and the authentication biometric identification information are based on a facial image of the user and at least one other item of biometric information.
[026] In one embodiment, this method further comprises capturing supplementary authentication biometric identification information from the user during the authentication session and comparing the supplementary authentication biometric identification information with the authentication biometric identification information. The method also compares the supplementary authentication biometric identification information with the root biometric identification information. The user is authenticated when the comparison determines that the biometric information Petition 870260077099, dated 03 / 08 / 2026, page 15 / 246 10 / 113 authentication corresponds to supplementary biometric authentication information within a first limit, but is not identical, and comparison determines that the root biometric identification information corresponds to the supplementary biometric authentication information within the predetermined limit.
[027] An identity authentication system is also disclosed comprising the following elements. A first computing device configured to request and receive root biometric identification information for a user from a trusted source, such that the trusted source is a government-affiliated entity or a financial institution. A second computing device configured to, during an authentication session, create biometric authentication information captured from the user during the authentication session, compare the biometric authentication information with the root biometric identification information, and perform a liveness determination on the user during the authentication session using the biometric authentication information.In response to the comparison and execution, authenticate the user if the comparison determines that the authentication biometric information matches the root biometric identification information within a certain limit, and the liveness check determines that the user is a living person.
[028] Root biometric identification information can be derived from an image. In one configuration, a user image cannot be recreated from the root biometric identification information. The first computing device and the second computing device can be the same computing device. It is also contemplated that the authentication biometric information is derived from at least one first image and one second image, which are captured by a camera associated with the second computing device. Thus, the first image is captured by the camera located at a first distance from the user and the second image is captured by the camera located at a second distance. Petition 870260077099, dated 03 / 08 / 2026, page 16 / 246 11 / 113 user distance, the second distance being less than the first distance. The proof-of-life determination comprises determining whether the second image has barrel distortion compared to the first image.
[029] A method for establishing a reliable biometric profile is also disclosed here, comprising capturing a user's biometric information when the user makes a financial payment to a third party, the financial payment to a third party creating financial payment data. Then, storing the user's biometric information with the financial payment data and creating a biometric trust profile associated with the user using the user's biometric information with the financial payment data to establish trust in the biometric profile.
[030] In one embodiment, capturing biometric information comprises capturing at least one first image at a first distance from the user, processing the first image to create first biometric information, and capturing at least one second image at a second distance from the user, such that the second distance is different from the first distance. This embodiment also processes the second image to create second biometric information, and compares the first biometric information with the second biometric information to determine whether the first biometric information matches the second biometric information within a limit. This method may further comprise performing a liveness test as part of the comparison, comparing the first biometric information with the second biometric information to verify that the first biometric information is not too similar to the second biometric information.
[031] In one arrangement, financial payment to a third party is not accepted when the first biometric information does not match the second biometric information within a certain limit, or the liveness test determines that the biometric information does not belong to a living person. It is also contemplated that this method may still Petition 870260077099, dated 03 / 08 / 2026, p. 17 / 246 12 / 113 Understand capturing additional biometric information from a user, beyond the previously acquired biometric information, when the user makes an additional financial payment to a third party. Then, compare the additional biometric information of a user with the previously acquired biometric information, and in response to a match between the additional biometric information and the previously acquired biometric information, update the biometric trust profile to increase the trust associated with the biometric trust profile. However, in response to a mismatch between the additional biometric information and the previously acquired biometric information, update the biometric trust profile with an indicator of a failed comparison.
[032] The method may also include generating a trust score for the user's biometric trust profile, the trust score being determined by at least one of the following: amount of financial payment, number of financial payments, and age of the biometric trust profile. The biometric trust profile may be shared or used by other entities to verify a person's identity based on the biometric trust profile.
[033] Also disclosed is a method for establishing a reliable biometric profile of a user comprising capturing a user's first biometric information when the user performs a first trust-building action and processing the first biometric information to generate a biometric information profile. Capturing the user's second biometric information when the user performs a second trust-building action and processing the second biometric information to compare the first biometric information with the second biometric information. If the processing determines that the first biometric information matches the second biometric information within a threshold, then updating the reliable biometric profile to reflect the match, but if the processing determines that the first biometric information does not match the second biometric information within the threshold, then updating the profile Petition 870260077099, dated 03 / 08 / 2026, page 18 / 246 13 / 113 reliable biometric to reflect the mismatch.
[034] In one modality, a trust-building action is one or more of the following: financial payment, attendance at workplace, payments to an escrow account, and medical consultation. The biometric information profile may include a trust score that is based on biometric information matches, the number of trust-building actions, and the nature of the trust-building actions.
[035] In one embodiment, biometric information capture comprises capturing at least one first image at a first distance from the user, and processing at least one first image to create the first biometric information. Capturing at least one second image at a second distance from the user, such that the second distance is different from the first distance, and processing at least one second image to create the second biometric information. Then, comparing the first biometric information with the second biometric information to determine if the first biometric information matches the second biometric information within a certain limit.
[036] This method may further comprise performing a liveness test as part of the comparison, comparing the first biometric information with the second biometric information to verify that the first biometric information differs from the second biometric information due to the change in the distance at which the images are captured. In one embodiment, financial payment to the third party is not accepted when the first biometric information does not match the second biometric information within a limit and the liveness test determines that the biometric information is from a living person. The biometric trust profile may be shared or used by other entities to verify the user's identity. It is contemplated that the biometric information is derived from an image of the user's face. Petition 870260077099, dated 03 / 08 / 2026, p. 19 / 246 14 / 113
[037] Also disclosed is a system for developing a biometric trust profile based on user action and user biometric information. In one embodiment, this system comprises a first computing device having a camera configured to capture a first set of images of the user when the user is making a first financial transaction, processing the first set of images to create first biometric information, and storing the first biometric information as part of a biometric trust profile for the user.A second computing device is also provided which has a camera configured for, or the first computing device is further configured to capture a second set of images of the user when the user is making a second financial transaction, process the second set of images to create second biometric information, and store the second biometric information as part of a biometric trust profile for the user.A third computing device is configured to compare the first biometric information with the second biometric information. In response to a match between the first and second biometric information within a predetermined limit, the biometric confidence profile is updated to a high confidence level. In response to a mismatch between the first and second biometric information within a predetermined limit, the biometric confidence profile is updated to reduce the confidence level.
[038] In one embodiment, the first set of images and the second set of images comprise at least one close-up image and one far-up image, the close-up image being captured when the camera is closer to the user than the far-up image. The first computing device or the second computing device may be further configured to perform a proof-of-life determination on the second set of images to verify that the Petition 870260077099, dated 03 / 08 / 2026, page 20 / 246 15 / 113 The user in the second set of images is a living person. In one embodiment, an image of the user cannot be recreated from the biometric information. The first computing device and the second computing device may be the same computing device. It is contemplated that the biometric trust profile may include a trust score representing a confidence level for the biometric trust profile, such that the trust score is based on one or more of the following: the amount of the financial transaction, the number of financial transactions, and how long ago the creation of the first biometric information occurred. In one arrangement, the financial transaction is a payment of money to a third party.
[039] Also disclosed is a method for capturing and storing biometric information comprising capturing a user’s first biometric information with a computing device, and converting the first biometric information into a first biometric template. Creating a first data block that is part of a blockchain, such that the first data block includes the first biometric template and first authentication information. The first data block is added to the blockchain, such that the blockchain exists in multiple locations in several different data memories.
[040] In one embodiment, this method further comprises capturing a second biometric information with a computing device and converting the second biometric information into a second biometric model, then comparing the second biometric model with the first biometric model and, in response to an authentication match between the second biometric model and the first biometric model, creating a second data block, the second data block including the second biometric model, the second authentication information, and the results of the comparison. Then, adding the second data block to the blockchain. It is contemplated that the first biometric information may be by Petition 870260077099, dated 03 / 08 / 2026, page 21 / 246 16 / 113 minus one image of the user captured with a camera, and the second biometric information comprises at least one image of the user captured with the camera. In one embodiment, the second biometric information may comprise a first image captured at a first distance from the user and a second image captured at a second distance from the user; the converter may convert the first image into a first biometric image model and convert the second image into a second biometric image model; and the comparison may compare the first biometric image model with the second biometric image model. The authentication match may comprise the first biometric image model matching the second biometric image model within a first limit and the first biometric image model being different from the second biometric image model within a second limit.
[041] In one embodiment, the authentication information comprises one or more of the following: device ID, a unique user ID, user identification information, algorithm type, encryption type, biometric sensor version, date and time stamp, GPS information. This method may further comprise encrypting a data block when a data block is added to the blockchain. The method may occur on a user's computing device, on an authentication server, or both. In one arrangement, a data block is downloaded to a user's computing device from the blockchain and a private key is held by the user to decrypt the downloaded data block. The data block may further include financial transaction information associated with the authentication match. The authentication comparison and match may occur on a blockchain edge server.In one mode, a user image cannot be recreated from the root biometric identification information. Petition 870260077099, dated 03 / 08 / 2026, page 22 / 246 17 / 113
[042] The system can use any number or combination of security features as security layers, as described in this document. When authentication fails, the system can be configured so that it is not evident which security layer triggered the failure in order to preserve the integrity of the security system.
[043] Other systems, methods, features and advantages of the invention will or will become apparent to one skilled in the art upon examining the Figures and detailed description that follow. It is intended that all systems, methods, features and advantages included in this description are within the scope of the invention and are protected by the appended claims. BRIEF DESCRIPTION OF THE DRAWINGS
[044] The components in the Figures are not necessarily to scale, emphasizing the principles of the invention. In the figures, the reference numbers designate corresponding parts along the different views.
[045] Figure 1 illustrates an example of a facial recognition authentication system usage environment, according to an exemplary modality.
[046] Figure 2 illustrates an exemplary embodiment of a mobile device.
[047] Figure 3 illustrates example software modules that are part of the mobile device and server.
[048] Figure 4 presents a method for performing facial recognition authentication according to a modality.
[049] Figure 5 presents a method for registering a user in a facial recognition authentication system, according to an exemplary modality.
[050] Figures 6A and 6B show an example of the movement of a Petition 870260077099, dated 03 / 08 / 2026, page 23 / 246 18 / 113 mobile device over a user's face according to an exemplary modality.
[051] Figures 7A and 7B show an example of a mobile device moving over a user's face according to an exemplary embodiment.
[052] Figure 8 presents a method of providing authentication information in a facial recognition authentication system, according to an exemplary modality.
[053] Figure 9 presents a method for verifying authentication credentials in a facial recognition authentication system, according to an exemplary embodiment.
[054] Figure 10 illustrates an example display showing graphical and numerical feedback in a facial recognition authentication system.
[055] Figures 11A, 11B and 11C illustrate examples of video comments corresponding to front camera positions in a facial recognition authentication system.
[056] Figure 12 presents an example video display commentary of a facial recognition authentication system in which border pixels on the sides of the display are extended horizontally.
[057] Figures 13A and 13B illustrate exemplary screen displays with facial alignment indicators shown as an oval to serve as a guide as the user moves the mobile device closer to or further away from their face.
[058] Figure 14 illustrates an exemplary mobile device screen showing a graphical code input interface with an image formation area.
[059] Figure 15 illustrates an example mobile device screen. Petition 870260077099, dated 03 / 08 / 2026, page 24 / 246 19 / 113 showing a graphical and numeric code input interface with an image formatting area.
[060] Figure 16 presents a system for biometric identification using root identification information, according to an exemplary embodiment.
[061] Figure 17 presents a method for authentication using a root identification system, according to an exemplary embodiment.
[062] Figure 18 presents a method for remotely establishing a biometric identity, according to an exemplary modality.
[063] Figure 19 presents a biometric authentication system using a blockchain, according to an exemplary embodiment.
[064] Figure 20 is a schematic view of a mobile or computing device, such as one of the devices described above, according to an exemplary embodiment. DETAILED DESCRIPTION OF MODALITIES
[065] A system and method for providing secure and convenient facial recognition authentication will be described below. The system and method can be achieved without the need for additional expensive biometric systems or readers while offering greater security compared to conventional facial recognition systems. Facial Recognition Authentication Environment
[066] Figure 1 illustrates an exemplary environment for using the facial recognition authentication system described in this document. This is one possible usage environment and system. It is anticipated that, after reading the specification provided below in connection with the Figures, a person ordinarily versed in the art may arrive at different usage environments and configurations.
[067] In this environment, a user 108 may have a mobile device 112 that can be used to access one or more user accounts through systems of Petition 870260077099, dated 03 / 08 / 2026, page 25 / 246 20 / 113 authentication. A user 108 may have a mobile device 112 that can capture a photo of user 108, such as an image of the user's face. The user may use a camera 114 on or connected to the mobile device 112 to capture one or more images or video of himself / herself. The mobile device 112 may comprise any type of mobile device capable of capturing an image, whether still or video, and performing image processing or communication over a network.
[068] In this embodiment, the user 108 can carry and hold the mobile device 112 to capture the image. The user can also wear or hold any number of other devices. For example, the user can use a watch 130 containing one or more cameras 134 or biosensors arranged in the watch. The camera 134 can be configured to create a visible light image as well as an infrared light image. The camera 134 can additionally or alternatively employ image intensification, active illumination, or thermal vision to obtain images in dark environments.
[069] When pointed at a user 108, the camera 134 can capture an image of the user's face. The camera 134 may be part of a module that may include communication capability that communicates with a mobile device 112, such as via Bluetooth®, NFC, or other format, or communicates directly with a network 116 via a wired or wireless link 154. The watch 130 may include a screen on its face to allow the user to view information. If the camera module 134 communicates with the mobile device 112, the mobile device 134 may transmit communications to the network 116. The mobile device 134 may be configured with more than one front camera 114 to provide a 3D or stereoscopic view, or to obtain images in different spectral ranges, such as visible light or near-infrared.
[070] Mobile device 112 is configured to communicate without Petition 870260077099, dated 03 / 08 / 2026, page 26 / 246 21 / 113 wired through a network 116 with a remote server 120. The server 120 can communicate with one or more databases 124. The network 116 can be any type of network capable of communicating with and from the mobile device, including, but not limited to, a LAN, WAN, PAN, or the Internet. The mobile device 112 can communicate with the network via a wired or wireless connection, such as via Ethernet, Wi-Fi, NFC, and the like. The server 120 can include any type of computing device capable of communicating with the mobile device 112. The server 120 and the mobile device 112 are configured with a processor and memory and are configured to execute machine instructions or machine-readable code stored in memory.
[071] The database 124, stored on the mobile device or remote location as shown, may contain facial biometric information and user authentication information 108 to identify users 108 to allow access to associated user data based on one or more images or biometric information received from the mobile device 112 or watch 134. The data may be, for example, information relating to a user account or instruction to allow access to a separate account information server 120B. The term “biometric data” may include, among other information, biometric information relating to facial features and path parameters.Examples of path parameters may include the acceleration and speed of the mobile device, the angle of the mobile device during image capture, the distance from the mobile device to the user, the direction of travel relative to the user's face position, or any other type of parameter associated with the movement of the mobile device or the user's face relative to a camera. Other data may also be included, such as GPS data, device identification information, and the like.
[072] In this mode, server 120 processes requests for Petition 870260077099, dated 03 / 08 / 2026, page 27 / 246 22 / 113 Mobile device identification 112 or user 108. In one configuration, the image captured by mobile device 112, using facial detection, comprises one or more images of the user's face 108 during the movement of the mobile device relative to the user's face, such as in a side-by-side or horizontal line or arc, a vertical line or arc, forward and backward from the user's face, or any other direction of movement. In another configuration, mobile device 112 calculates biometric information from the images obtained and sends the biometric information to server 120. In yet another embodiment, mobile device 112 compares the biometric information with the biometric information stored on mobile device 112 and sends an authentication result of the comparison to server 120.
[073] The data including the image(s), biometric information, or both, are sent over the network 116 to the server 120. Using image processing and image recognition algorithms, the server 120 processes the person’s biometric information, such as facial data, and compares the biometric information with the biometric data stored in the database 124 to determine the similarity of a match. In other embodiments, the image processing and comparison are done on the mobile device 112, and the data sent to the server indicates a result of the comparison. In other embodiments, the image processing and comparison are done on the mobile device 112 without accessing the server, for example, to gain access to the mobile device 112 itself.
[074] Using facial recognition processing, an accurate identity match can be established. Based on this and, optionally, on one or more other factors, access can be granted, or an unauthorized user can be denied access. Facial recognition processing is known in the art (or is an established process) and, as a result, does not Petition 870260077099, dated 03 / 08 / 2026, page 28 / 246 23 / 113 is described in detail here.
[075] A second server 120B with associated second database 124B is also shown, and a third server 120C with associated third database 124C. The second and third databases may be provided to contain additional information that is not available on server 120 and database 124. For example, one of the additional servers may only be accessed based on user authentication 108 performed by server 120.
[076] One or more software applications run on the mobile device. This software is defined here as an identification application (ID App). The ID App may be configured with one or both facial detection and facial recognition and one or more software modules that monitor path parameters and / or biometric data. Face detection, as used herein, refers to a process that detects a face in an image. Facial recognition, as used herein, refers to a process that can analyze a face using an algorithm, mapping its facial features, and converting them into biometric data, such as numerical data. The biometric data may be compared with those derived from one or more different images for similarities or dissimilarities. If a high percentage of similarity is found in the biometric data, the individual depicted in the images may be considered a match.
[077] With the ultimate goal of matching a user's face with an identity or image stored in a database 124, to authenticate the user, the ID App can first process the image captured by the camera 114, 134 to identify and locate the face that is in the image. As shown in Figure 1, it could be face 108. The authentication can be used to log into an online account or for various other access control functions.
[078] The part of the photo containing the detected face can then be cropped, Petition 870260077099, dated 03 / 08 / 2026, page 29 / 246 24 / 113 extracted and stored for processing by one or more facial recognition algorithms. By first detecting the face in the image and cropping only that part of the face, the facial recognition algorithm does not need to process the entire image. Furthermore, in modalities where facial recognition processing occurs remotely from the mobile device 112, such as on a server 120, it is necessary to send much less image data over the network to the remote location. It is contemplated that the entire image, a cropped face, or only biometric data can be sent to the remote server 120 for processing.
[079] Facial detection software can detect a face from a variety of angles. However, facial recognition algorithms are most accurate on upright images in well-lit situations. In one embodiment, the highest quality facial image for facial recognition captured is processed first, then images of the face that are of lower quality or at angles other than those that are straight toward the face are processed. Processing can occur on the mobile device or on a remote server that has access to large databases of image data or facial identification data.
[080] Facial detection preferably occurs on the mobile device and is performed by the mobile device software, such as App ID. This reduces the number or size of images (data) that are sent to the server for processing where faces are not found and minimizes the total amount of data that must be sent over the network. This reduces bandwidth requirements, and network speed requirements are reduced.
[081] In another preferred embodiment, facial detection, facial recognition, and biometric comparison all occur on the mobile device. However, it is contemplated that facial recognition processing may occur on the mobile device, on the remote server, or both. Petition 870260077099, dated 03 / 08 / 2026, page 30 / 246 25 / 113
[082] Figure 2 illustrates an exemplary embodiment of a mobile device. This is only one possible configuration of a mobile device and, as such, it is contemplated that one skilled in the art may configure the mobile device differently. The mobile device 200 may comprise any type of mobile communication device capable of performing as described below. The mobile device may comprise a PDA, mobile phone, smartphone, tablet, wireless electronic pad, an IoT device, a “wearable” electronic device or any other computing device.
[083] In this exemplary embodiment, the mobile device 200 is configured with an external compartment 204 configured to protect and contain the components described below. Inside the compartment 204 is a processor 208 and a first and second bus 212A, 212B (collectively 212). The processor 208 communicates via the buses 212 with the other components of the mobile device 200. The processor 208 may comprise any type of processor or controller capable of functioning as described herein. The processor 208 may comprise a general-purpose processor, ASIC, ARM, DSP, controller, or any other type of processing device. The processor 208 and other elements of the mobile device 200 receive power from a battery 220 or other power source.A 224 electrical interface provides one or more electrical ports for electrically interfacing with a mobile device, such as a second electronic device, computer, medical device, or power supply / charging device. The 224 interface may comprise any type of electrical interface or connector form factor.
[084] One or more memories 210 are part of the mobile device 200 for storing machine-readable code for execution on the processor 208 and for storing data, such as image data, audio data, user data, medical data, location data, accelerometer data, or Petition 870260077099, dated 03 / 08 / 2026, page 31 / 246 26 / 113 any other types of data. Memory 210 may comprise RAM, ROM, flash memory, optical memory, or micro-drive memory. The machine-readable code, as described herein, is non-transient.
[085] As part of this embodiment, the processor 208 connects to a user interface 216. The user interface 216 may comprise any system or device configured to accept user input to control the mobile device. The user interface 216 may comprise one or more of the following: keyboard, rollerball, buttons, discs, pointer key, touchpad, and touch screen. A touch screen controller 230 is also provided, which interfaces via the bus 212 and connects to a display 228.
[086] The display comprises any type of display screen configured to display visual information to the user. The screen may include an LED, LCD, thin-film transistor display, OEL CSTN (color super twisted nematic), TFT (thin-film transistor), TFD (thin-film diode), OLED (organic light-emitting diode), AMOLED display (active matrix organic light-emitting diode), capacitive touch screen, resistive touch screen, or any combination of these technologies. The display 228 receives signals from the processor 208, and these signals are translated by the display into text and images as understood in the art. The display 228 may further comprise a display processor (not shown) or controller that interfaces with the processor 208. The touch screen controller 230 may comprise a module configured to receive signals from a touch screen that is superimposed on the display 228.
[087] Also part of this exemplary mobile device is a loudspeaker 234 and a microphone 238. The loudspeaker 234 and the microphone 238 can be controlled by the processor 208. The microphone 238 is configured to receive and convert audio signals into electrical signals based on the control of the processor 208. Similarly, the processor 208 can activate the loudspeaker 234 to generate audio signals. These devices operate as understood in the art and are thus not discussed here. Petition 870260077099, dated 03 / 08 / 2026, page 32 / 246 27 / 113 described in detail.
[088] Also connected to one or more of the buses 212 is a first wireless transceiver 240 and a second wireless transceiver 244, each of which connects to the respective antennas 248, 252. The first and second transceivers 240, 244 are configured to receive input signals from a remote transmitter and perform analog front-end processing on the signals to generate analog baseband signals. The input signal may further be processed by conversion to a digital format, such as by an analog-to-digital converter, for subsequent processing by the processor 208. Similarly, the first and second transceivers 240, 244 are configured to receive output signals from the processor 208 or another component of the mobile device 208, and convert these baseband signals to RF frequency for transmission through the respective antenna 248, 252.Although it is shown with a first wireless transceiver 240 and a second wireless transceiver 244, it is contemplated that the mobile device 200 may have only one of these systems or two or more transceivers. For example, some devices have tri-band or quad-band capability, or possess Bluetooth®, NFC, or other communication capabilities.
[089] It is contemplated that the mobile device and therefore the first wireless transceiver 240 and a second wireless transceiver 244 can be configured to operate according to any wireless standard currently existing or developed in the future, including, but not limited to, Bluetooth, Wi-Fi, such as IEEE 802.11 a,b,g,n, wireless LAN, WMAN, fixed broadband access, WiMAX, any cellular technology including CDMA, GSM, EDGE, 3G, 4G, 5G, TDMA, AMPS, FRS, GMRS, citizen band radio, VHF, AM, FM and wireless USB.
[090] Also part of the mobile device are one or more systems connected to the second 212B bus, which also interface with the 208 processor. These devices include a system module of Petition 870260077099, dated 03 / 08 / 2026, page 33 / 246 28 / 113 Global Positioning System (GPS) 260 with associated antenna 262. The GPS module 260 can receive and process signals from satellites or other transponders to generate location data relative to the location, direction of travel, and speed of the GPS module 260. GPS is generally understood in the art and therefore will not be described in detail herein. A gyroscope 264 connects to the bus 212B to generate and provide orientation data relative to the orientation of the mobile device 204. A magnetometer 268 is provided to provide directional information to the mobile device 204. An accelerometer 272 connects to the bus 212B to provide information or data relating to shocks or forces experienced by the mobile device. In one configuration, the accelerometer 272 and the gyroscope 264 generate and provide data to the processor 208 to indicate a path of movement and orientation of the mobile device.
[091] One or more cameras (photo, video, or both) 276 are provided to capture image data for storage in memory 210 and / or for possible transmission via a wired or wireless link or for later viewing. The one or more cameras 276 can be configured to detect an image using visible light and / or near-infrared light. The cameras 276 can also be configured to use image intensification, active illumination, or thermal vision to obtain images in dark environments. The processor 208 can process image data to perform image recognition, such as in the case of facial detection, item detection, facial recognition, item recognition, or barcode / box reading.
[092] A flasher and / or flashlight 280, such as an LED light, is provided and is controllable by the processor. The flasher or flashlight 280 can serve as a strobe or traditional flashlight. The flasher or flashlight 280 can also be configured to emit near-infrared light. A power management module 284 interfaces with or monitors the battery 220 to manage consumption. Petition 870260077099, dated 03 / 08 / 2026, page 34 / 246 29 / 113 of energy, controlling battery charging and providing power supply voltages to various devices that may require different power requirements.
[093] Figure 3 illustrates exemplary software modules that are part of the mobile device and server. Other software modules may be provided to provide the functionality described below. It is anticipated that, for the functionality described here, compatible software (non-transient machine-readable code, instructions, or machine-executable code) will exist, configured to perform the functionality. The software would be stored in memory and executable by a processor.
[094] In this confirmation example, mobile device 304 includes a receiving module 320 and a transmitting module 322. These software modules are configured to receive and transmit data to remote devices such as cameras, glasses, servers, cell towers or Wi-Fi systems such as routers or access points.
[095] Also part of the mobile device 304 is a location detection module 324 configured to determine the location of the mobile device, such as by triangulation or GPS. An account configuration module 326 is provided to establish, store and allow a user to adjust account settings. A login module 328 is also provided to allow a user to log in, such as with password protection, to the mobile device 304. A facial detection module 308 is provided to execute facial detection algorithms, while a facial recognition module 321 includes software code that recognizes a user's facial features, such as to create numerical values that represent one or more facial characteristics (facial biometric information) unique to the user.
[096] An information display module 314 controls the display of information to the mobile device user. The display can occur on the screen of Petition 870260077099, dated 03 / 08 / 2026, page 35 / 246 30 / 113 mobile device or watch. A user input / output module 316 is configured to accept data and display data to the user. A local interface 318 is configured to interface with other local devices, such as using Bluetooth® or other shorter-range communication, or wired links using connectors for connected cameras, batteries, data storage elements. All software (with associated hardware) shown on the mobile device 304 functions to provide the functionality described herein.
[097] The server software module 350 is also shown in Figure 3. These modules are located remotely from the mobile device, but can be located on any remote server or processing element. As understood in the art, networks and network data utilize a distributed processing approach with multiple servers and databases operating together to provide a unified server. As a result, it is contemplated that the module shown in the server block 350 may not all be located on the same server or in the same physical location.
[098] As shown in Figure 3, server 350 includes a receiving module 352 and a transmitting module 354. These software modules are configured to receive and transmit data to remote devices such as cameras, watches, glasses, servers, cell towers, or WIFI systems such as routers or access points.
[099] An information display module 356 controls an information display on the server 350. A user input / output module 358 controls a user interface in connection with the local interface module 360. Also located on the server side of the system is a facial recognition module 366 which is configured to process image data from the mobile device. The facial recognition module 366 can process the image data to generate facial data (biometric information) and perform a function of Petition 870260077099, dated 03 / 08 / 2026, page 36 / 246 31 / 113 Comparison against other facial data to determine a facial match as part of an identification determination.
[0100] A database interface 368 enables communication with one or more databases containing information used by the server modules. A location detection module 370 can use the location data from the mobile device 304 for processing and to increase accuracy. Similarly, an account configuration module 372 manages user accounts and can interface with the account configuration module 326 of the mobile device 304. A secondary server interface 374 is provided for interfacing and communicating with one or more other servers.
[0101] One or more databases or database interfaces are provided to facilitate database communication and searching. In this exemplary embodiment, the system includes an image database containing images or image data for one or more people. This database interface 362 can be used to access users' image data as part of the identity matching process. Also part of this embodiment is a personal data database interface 376 and a privacy settings data module 364. These two modules 376, 364 function to establish privacy settings for individuals and to access a database that may contain privacy settings. Authentication System
[0102] An authentication system with path parameters that is operable in the environment and system described above will now be described as shown in Figure 4. Figure 4 presents a method for performing facial recognition authentication with path parameters according to an embodiment of the invention. As will be described in more detail below, the system uses the resources of the mobile device 112 and the server 120 defined above to generate a Petition 870260077099, dated 03 / 08 / 2026, page 37 / 246 32 / 113 A secure and convenient login system is used as an example of an authentication system. This reduces the user burden of having to type complex passwords on a small mobile device screen, prevents fraud through means such as key logging or screenshots, and increases security by combining various path parameters and / or device parameters that must be met before the user is authenticated.
[0103] In step 410, the system registers a user in the facial recognition authentication system. In one embodiment, an authentication server, such as server 120 (Figure 1), can be configured to authenticate a user to allow access to the user account, such as a bank or other account, through the mobile device 112. Authentication server 120 can be included as part of a server of the institution or entity that provides user accounts (hereinafter “account server”), or the authentication server can be provided separately. For example, in the environment shown in Figure 1, Servers 120B and 120C can represent account servers. In other embodiments, the account server and the authentication server are one and the same. In one embodiment, authentication server 120 can provide a user authentication application for installation on the mobile device 112.
[0104] A registration process according to a modality will be described with reference to Figure 5. In this modality, a user, through a mobile device 112, establishes a connection between the mobile device 112 and the account server 120B in step 510. As an example only, the user may establish a connection with a server of a financial institution, such as a bank, or this connection may occur later in the process after authentication. The user then provides typical login information to authenticate the user, such as a username and password for a financial account in step 512. In step 514, the user may receive a reminder on the mobile device 112 to Petition 870260077099, dated 03 / 08 / 2026, page 38 / 246 33 / 113 to register in the facial recognition authentication system. The user then indicates, through the user interface, that they would like to configure the authentication system in response to the reminder.
[0105] Next, in step 516, mobile device 112 can send device information to authentication server 120. The device information may include, among other information, a device identifier that uniquely identifies the user's mobile device. Such information may include information about the device manufacturer, model number, serial number, and mobile network. In step 518, when authentication server 120 is embedded with account server 120B, authentication server 120 associates and stores the device information with the user's account information. When authentication server 120 is separated from account server 120B, account server 120B can generate a unique identifier related to the account information and send the unique identifier to authentication server 120.The authentication server 120 can associate the device information and the unique identifier with each other and can store the information in a database 124.
[0106] Next, the user is prompted to provide a plurality of images of their face using a camera 114 on the mobile device 112 (hereinafter, “registration images”) in step 510. The registration images of the user’s face are taken as the user holds the mobile device and moves the mobile device to different positions relative to their head and face. Thus, the registration images of the user’s face are taken from many different angles or positions. In addition, the mobile device’s path parameters are monitored and recorded for future comparison in step 522. Some non-limiting examples of how a user might hold a mobile device and take a plurality of images of their face are shown in Figures 6A-7B. Petition 870260077099, dated 03 / 08 / 2026, page 39 / 246 34 / 113
[0107] In Figures 6A and 6B, the user holds mobile device 112 on one side of their face and moves mobile device 112 in an arc-like path horizontally around their face until mobile device 112 is on the other side of their face. In Figures 7A and 7B, the user holds mobile device 112 away from their face and then brings mobile device 112 closer to their face. Naturally, any number of other paths can be used in addition to those shown in Figures 6A-7B. Furthermore, the user can move their head while the camera is held fixed. The user can also hold the camera steadily and move their head relative to the camera. This method, therefore, can be implemented with a webcam on a laptop or desktop or any other device, such as an IoT device where a camera is mounted on a similarly stationary location or object.
[0108] Registration images can be obtained as follows. The user holds and orients a mobile device 112 with a camera 114 so that the camera 114 is positioned to photograph the user's face. For example, the user can use a front camera 114 on a mobile device 112 with a display screen and can confirm on the display screen that their face is in position to be photographed by the camera 114.
[0109] Once the user has oriented the device, the device can begin acquiring the user's registration images. In one embodiment, the user can press a button on the device 112, such as on a touchscreen or another button on the device, to initiate the acquisition of registration images. The user then moves the mobile device to different positions relative to their head as the device photographs the user's face from a plurality of angles or positions, as described above. When the aforementioned front camera is used, the user can continuously confirm that their face is being photographed by viewing the image on the display screen. The user can press Petition 870260077099, dated 03 / 08 / 2026, page 40 / 246 35 / 113 Press the button again to indicate that image formation is complete. Alternatively, the user can hold the button down during image formation and then release the button to indicate that image formation is complete.
[0110] As described above, mobile device 112 may include facial detection. In this mode, in step 524, the mobile device may detect the user's face in each of the registration images, crop the images to include only the user's face, and send the images over a network to the authentication server 120. In step 526, upon receiving the registration images, the authentication server 120 performs facial recognition on the images to determine the biometric information (“registration biometrics”) for the user. The authentication server 120 may then associate the registration biometrics with the device information and the unique identifier (or account information) and store the biometric information in the database 124 in step 528. For greater security, in step 530, mobile device 112 and authentication server 120 may be configured to delete the registration images after the user's registration biometrics are obtained.
[0111] In another embodiment, mobile device 112 can send images to authentication server 120 without performing facial detection. Authentication server 120 can then perform facial detection, facial recognition, and biometric information processing. In another embodiment, mobile device 112 can be configured to perform facial detection, facial recognition, and biometric processing, and then send the results or data resulting from the processing to authentication server 120 to be associated with the unique identifier or user account. This prevents sensitive personal data (images) from leaving the user's device. In yet another embodiment, mobile device 112 can perform each of the aforementioned steps, and mobile device 112 can store registration information without sending any of the registration images or biometrics to the server. Petition 870260077099, dated 03 / 08 / 2026, page 41 / 246 36 / 113
[0112] In one embodiment, the mobile device’s gyroscope, magnetometer, and accelerometer are configured to generate and store data as the user moves the mobile device over their head to obtain registration images (path parameters). The mobile device can process this data in step 532 to determine a path or arc along which the mobile device moved while the user photographed their face (“registration movement”). Using data from the accelerometer, magnetometer, and gyroscope, the system can verify when a user is ready to begin scanning their face, as well as determine the scan path. The data is used to determine when to start and stop the scan interval. The data may additionally include the elapsed time during the scan.This time can be measured from the moment the user presses the button to start and stop image formation, or it can be measured from the duration the button is pressed during image formation, or during further movement, or to complete the scan.
[0113] The mobile device registration movement 112 (which is data that defined the mobile device's movement during image capture) can be sent to the authentication server 120. The authentication server 120 associates and stores the registration movement, registration biometrics, device information, and the unique identifier or account information. Alternatively, data generated by the gyroscope, magnetometer, and accelerometer can be sent to the server 120, and the server 120 can process the data to determine the registration movement.
[0114] Thus, in the modality described above, registration information can then include device information, registration biometrics and registration movement (based on mobile device movement 112).
[0115] Returning to Figure 4, once registration is complete, authentication server 120 can subsequently receive credentials from a user attempting to Petition 870260077099, dated 03 / 08 / 2026, page 42 / 246 37 / 113 authenticate to the system, as shown in step 420. For example, a user may attempt to log in to a user account. When a user attempts to log in, instead of or in addition to providing typical account credentials such as username and password, the user may again produce a series of images or videos of their face while the mobile device 112 is held in their hand and moved to different positions relative to their head (“authentication images”) in the same manner as was done during registration (as shown in Figures 6A-7B).In this way, the user can provide the necessary images (the term images includes video, since video is a succession of images) from many different angles and / or positions, and can provide device path parameters while obtaining the images ("authentication movement") to confirm both the user's identity, as well as proof of life and reality of that individual to ensure that it is not a video, a screenshot, or another representation of the person.
[0116] In one embodiment described in Figure 8, the user, through mobile device 112, obtains several authentication images in step 810 while moving mobile device 112 to different positions relative to the user's head. Using facial detection in step 812, mobile device 112 detects the user's face in each of the authentication images, crops the images, and sends the images to authentication server 120. In another embodiment, mobile device 112 sends the images to server 124, and server 124 performs facial detection. In step 814, authentication routing 120 can perform facial recognition on the authentication images to obtain biometric information (“authentication biometrics”). In another embodiment, mobile device 112 performs facial recognition to obtain authentication biometrics and sends the authentication biometrics to server 120.
[0117] In step 816, mobile device 112 sends device information identifying the device and sends route parameters, such as Petition 870260077099, dated 03 / 08 / 2026, page 43 / 246 38 / 113 gyroscope, magnetometer and accelerometer information, defining the path of the mobile device obtained during image formation, as well as the time elapsed during image formation (“authentication movement”) for the server 120. The credentials received by the authentication server 120 for a login to the facial recognition system may thus comprise the device information, the authentication images or authentication biometrics and the authentication movement (path parameters).
[0118] Returning to Figure 4, in step 430, the authentication server 120 verifies that the credentials received from the mobile device 112 sufficiently correspond to the information obtained during registration. For example, as shown in step 910 in Figure 9, using algorithms to process facial features and light hitting the face between different images, the authentication server 120 can determine that the face in the authentication images is three-dimensional, i.e., it is not a representation in a printed image or video screen. When the mobile device 120 sends only the authentication biometrics 120 to the server, the server 120 can validate the real or three-dimensional aspects of the user's image by comparing the biometric results of the different images.
[0119] In step 920, the authentication server 120 can then compare the login credentials with the information stored from the registration process. In step 920, the server 120 compares the device identification obtained during the login process with that stored during registration. In step 930, the authentication biometrics can be compared with the registration biometrics to determine if it sufficiently matches the registration biometrics. In step 940, the authentication movement can be compared with the registration movement to determine if it sufficiently matches the registration movement.
[0120] In some modalities, a copy of the registration information may be stored on mobile device 112, and mobile device 112 may Petition 870260077099, dated 03 / 08 / 2026, page 44 / 246 39 / 113 verify that the credentials received on the mobile device 112 sufficiently match the registration information. This would allow a user to protect documents, files, or applications on the mobile device 112 itself, as well as protect the user account hosted on a remote device, such as the authentication server 120, even when a connection to the authentication server 120 might be temporarily unavailable, such as when a user does not have internet access. Furthermore, this would allow the user to protect access to the mobile device 112 itself. Or the registration information could be stored on the server.
[0121] Thus, in step 950, if the authentication server 120 or the mobile device 112 determines that the registration information sufficiently matches the received credentials, then the server or mobile device can verify that the identification of the user attempting to log in matches the account owner. This avoids the cumbersome process of the user having to manually type a complex password using the small screen of the mobile device. Many passwords currently require uppercase letters, special characters, lowercase letters, and numbers.
[0122] The level of matching required to determine that the registration information sufficiently matches the authentication information during the login attempt can be defined in advance. For example, the matching level could be a 99.9% match rate between the registration biometrics and the authentication biometrics, and a 90% match rate between the registration movement and the authentication movement. The required matching level can be static or elastic based on the established limits.
[0123] For example, the required level of matching may be based on GPS information from the mobile device 112. In one embodiment, the server of Petition 870260077099, dated 03 / 08 / 2026, page 45 / 246 40 / 113 authentication 120 may require a 99.9% match rate as the match level when the mobile device's GPS information matches the user's home location or other authorized location(s). Conversely, if the GPS information shows that the device is in a foreign country far from the user's home, the authentication server may require a 99.99% match rate as the match level or may deny it entirely. Therefore, the required match between pre-stored authentication data (registration information) and currently received authentication data (authentication information) is elastic, as the required percentage match between images or route parameters may change depending on various factors such as time of day, location, login attempt frequency, date, or any other factor.
[0124] The required level of matching may additionally depend on time. For example, if a second authentication attempt is made shortly after a first authentication attempt at a location distant from the first authentication location based on mobile device GPS information 112, the matching threshold level may be set higher. For example, a user cannot travel from Seattle to New York in one hour. Similarly, login attempts from midnight to three in the morning may be a sign of fraud for some users based on user usage patterns.
[0125] The level of correspondence between registration information and authentication information may be the result of the composition of various parameters of the registration information and the authentication information. For example, when the button press time in the authentication information is within 5% of the button press time in the registration information, the button press time correspondence may constitute 20% of the overall correspondence. Similarly, when the trajectory Petition 870260077099, dated 03 / 08 / 2026, page 46 / 246 41 / 113 of the movement path of the authentication information is within 10% of the registration information; the movement path trajectory can constitute 20% of the overall match. Other parameter match rates, such as face size matching and facial recognition in the authentication information compared to the registration information, can constitute the remaining 10% and 50% of the overall match level. In this way, the overall total match level can be adjusted (for example, if the total of all parameters exceeds 75%), or the match rate of individual parameters can be adjusted. For example, on a second login attempt, the match rate threshold for a parameter can be increased, or the overall match level for all parameters can be increased.Limit matching rates can also be adjusted based on the account being authenticated or other desired security levels.
[0126] Returning to Figure 4, in step 440, the authentication server 120 can grant or deny access based on the verification in step 430. For example, if the authentication server 120 verifies that the credentials match the registration information, then the server 120 can authenticate the user to allow access to the user's account. In the case where the authentication server 120 is separate from the account server 120B (such as a bank server), the authentication server 120 can transmit the unique identifier to the account server, along with an indication that the identity of the user associated with the unique identifier has been verified. The account server 120B can then authorize the user's mobile device 112 to transmit and receive data from the account server 120B. Obviously, all this can only occur on the account server 120B or on the mobile device 112 itself.
[0127] Alternatively, if the credentials provided by the user are not verified, the authentication server may transmit a message to display on Petition 870260077099, dated 03 / 08 / 2026, page 47 / 246 42 / 113 Mobile device screen 112, indicating that the login attempt failed. The authentication server 120 may then allow the user to try logging in again via the facial recognition login system, or the authentication server 120 may require the user to enter typical account credentials, such as a username and password.
[0128] In one embodiment, the 120 server may allow three consecutive failed login attempts before requiring a username and password. If, in one of the attempts, the required level of match is met, the user may be verified and access may be granted. According to one embodiment, the 120 authentication server may retain the information from each successive authentication attempt and combine the data from the multiple authentication attempts to obtain more accurate facial biometric information of the person attempting authentication. Furthermore, the level of match may be increased with each successive authentication attempt. Additionally, by averaging the path data (authentication movement) and / or image data (authentication images / biometrics) from multiple login attempts, the login data (registration information) is refined and improved.
[0129] Therefore, the authentication system described above allows authentication to a remote server 120 or on the mobile device itself 112. This can be accomplished as described above by the mobile device 112 capturing the authentication credentials, and the authentication server 120 processing and analyzing the credentials in comparison with the registration information (cloud processing and analysis); the mobile device 112 capturing the authentication credentials and processing the credentials, and the authentication server 120 analyzing the credentials in comparison with the registration information (mobile device processing, cloud analysis); or the mobile device 112 capturing the authentication credentials and processing and analyzing the Petition 870260077099, dated 03 / 08 / 2026, page 48 / 246 43 / 113 credentials compared to registration information (mobile device processing and analysis). Advantages and Characteristics of the Modalities
[0130] The system described above provides several advantages. As one advantage, the facial recognition authentication system provides secure login. For example, if during a login attempt, the mobile device's camera photographed a digital screen displaying a person turning their head while the phone was not moving, the accelerometer, magnetometer, and gyroscope data would not detect any movement. Thus, the registration movement and the authentication movement would not match, and the login attempt would be denied.
[0131] Furthermore, since a plurality of images are used as registration images and authentication images, histograms or other photo manipulation techniques can be used to determine if a digital screen is present in place of a human face in the images. For example, the system can check for changes in light frequency in the captured images, or bands in an image that indicate that an electronic viewfinder generated the image, backlighting, suspicious changes in lighting, or other analyses in the images by comparing the images to determine that the actual active user is indeed alive, present, and requesting authorization to log in.
[0132] Yet another advantage, as explained above, is that not only must the registration biometrics sufficiently match the authentication biometrics, but also the registration action must match the authentication action, and the device information must coincide with the registration device information. For example, an application can be downloaded to a mobile device that has a digital camera. The application could be a login application or it could be an application from a financial institution or other entity with which the user has an account. The user can then log in to the application. Petition 870260077099, dated 03 / 08 / 2026, page 49 / 246 44 / 113 using a typical login credential, such as a username and password from the website. Additionally, the user may have a device code to log in from another device, or may use the camera to scan a QR code or other code to pair the device with their user account.
[0133] The user then holds the mobile device to move the mobile phone to different positions relative to their head, while keeping their face visible to the camera as it moves. As the mobile device moves, the camera obtains registration images of the face. During image formation, the speed and angle of the current user's mobile device movement are measured using the accelerometer, magnetometer, and gyroscope to generate the registration movement. Continuous image formation and face detection throughout the process have been shown to prevent fraud. This is because a fraud attempt cannot be made by rotating the images forward and out of the front of the camera.
[0134] For example, a user can initiate movement from right to left or from left to right, as shown in Figures 6A and 6B. The movement can also be in the forward and backward direction, as shown in Figures 7A and 7B. Any other movement can be used, such as starting in the center, then going to the right, and then returning to the center. Vertical and diagonal movements can also be used to further increase the complexity of the registration movement. When the user attempts to log in later, the user must repeat the movement pattern in the authentication movement to match the registration movement, in addition to matching device information and biometric data. Thus, system security is greatly enhanced.
[0135] The system therefore provides enhanced security for authenticating a user who has a mobile device. As explained above, the system can use Petition 870260077099, dated 03 / 08 / 2026, page 50 / 246 45 / 113 at least one or more of the following in any number of combinations to securely authenticate the user: physical device verification, mobile network verification, facial recognition including face size in the image, one face detected in each frame during movement, accelerometer information, gyroscope information, magnetometer information, pixels per square inch, color bits per pixel, image type, user-entered code or pattern, and GPS information.
[0136] As another advantage, the facial recognition login system provides a convenient way for a user to log into an account with a mobile device. For example, once registered, a user does not need to enter a username and password on the small mobile device every time the user wishes to access the account. Instead, the user simply needs to photograph themselves while mimicking the registration movement with the mobile device. This is especially advantageous with smaller mobile devices such as cell phones, smartwatches, and the like.
[0137] The system can also be configured to allow a user to securely log in on multiple devices or to allow users to securely share devices. In one embodiment, registration information can be stored on an authentication server (or in the “cloud”) and is therefore not associated solely with the user’s original device. This allows the user to use any number of suitable devices to authenticate to the authentication server. In this way, a user can use a friend’s phone (third-party device) or another device to access their information, such as account information, calendar information, email or other messages, etc., by performing the authentication operation on any device.
[0138] For example, the user can provide an email address, username code, or similar identifier on a friend's phone, so that Petition 870260077099, dated 03 / 08 / 2026, page 51 / 246 46 / 113 The authentication server compares the login information with the user's account registration information. This would indicate to the authentication server which authentication profile should be used, but without allowing access to the user's data, accounts, or tasks. When logging out of the friend's phone, access to the user's information on the friend's phone is terminated. The feature provides the benefit of allowing a user to securely access their account or other information or tasks accessible through authentication using any device without needing to type the user's password on the third-party device, where it could be logged in or copied. In a sense, the username is the password.
[0139] Through cloud-based registration information, a single user can also securely transfer data between authenticated devices. In one embodiment, a user may own a first device, such as a mobile phone, and be authenticated on the first device through the authentication system. The user may then acquire a new device, such as a new phone, tablet, or other device. Using the cloud-based authentication system, the user can authenticate on the new device and transfer data from the first device to the new device. The data transfer can be completed via the Internet, a local network connection, a Bluetooth connection, a wired connection, or near-field communication. The authentication process can also be part of a security check to resend or restore a system after the loss or theft of the phone.Thus, the authentication system can be used to activate or authenticate a new device, with authentication used to verify the user of the new device.
[0140] Similarly, the system can facilitate secure access to a single device shared by multiple people to control the content or other features on the device. In many cases, passwords can be viewed, copied, guessed, or detected, particularly when a device is Petition 870260077099, dated 03 / 08 / 2026, page 52 / 246 47 / 113 shared by multiple users. Users can be, for example, family members, including parents and children, work colleagues, or have other relationships, such as students. The authentication system can allow each family member to log in based on their own unique registration information associated with a user account.
[0141] The device can restrict access to certain content or resources for one or more user accounts, such as child user accounts, while allowing access to content and resources for other users, such as parent accounts. When using the authentication system for the shared device, child users cannot use a password to attempt to gain access to restricted content because the authentication system requires the presence of a parent or guardian for authentication, as explained above. Thus, device sharing between users with different privileges is more secure and enhanced. Similarly, in a classroom environment, a single device can be securely shared among multiple people for testing, research, and grade reporting. Adaptations and Modifications
[0142] Various modifications can be made to the above system and method without departing from the scope of the invention. For example, images can be processed by a facial recognition algorithm on the device and can also be converted into biometric data on the device, which is then compared with previously created biometric data for an authorized user. Alternatively, images from a device can be transmitted over a wired or wireless network, where facial recognition algorithms running on a separate server can process the images, create biometric data, and compare that data with previously stored data assigned to that device. Multiple Profiles for a Single User Petition 870260077099, dated 03 / 08 / 2026, page 53 / 246 48 / 113
[0143] In addition, the photo registration process can be done multiple times so that a user creates multiple user profiles. For example, the user can register with profiles with and without glasses, with and without other portable devices, in different lighting conditions, wearing hats, with different hairstyles, with or without facial or ear jewelry, or making different and unique faces, such as closed eyes, blinking, or talking out loud to establish another level of exclusivity for each user profile. These “faces” made by the user will not be available on the user’s Social Media Pages and therefore will not be available for copying, manipulation, and use during a fraud attempt. Each set of registration images, registration biometrics, or both can be saved along with the separate registration movement. In one mode, at least three images are captured when the mobile device completes the journey.It is contemplated that any number of images can be captured. Linking Registration Information
[0144] It is also contemplated that the registration process may be linked to an email address, phone number, or other identifier. For example, a user may register with an email address, complete one or more registration forms as described above, and confirm the registrations using the same email address. The email address can then further enhance the system's security. For example, if a user unsuccessfully attempts to log in to the authentication system a predetermined number of times, such as three times, the authentication system blocks the account and sends an email to the email address informing the user of the unsuccessful login attempts. The email may also include one or more photos of the person who failed to log in and GPS data or other data from the login attempt.The user can then confirm whether this was a valid login attempt and reset the system, or the user can report the login attempt as fraudulent. If one is reported... Petition 870260077099, dated 03 / 08 / 2026, page 54 / 246 49 / 113 fraudulent login or if there are too many blocks, the system may delete the account associated with the email address to protect user security. Thus, future fraudulent attempts would not be possible. Return Meters
[0145] To further facilitate image formation, the mobile device may include various feedback meters, such as a motion meter or precision meter, as shown in Figure 10. In one embodiment, the mobile device 1012 may display a motion meter 1024 that indicates the amount of movement the mobile device 1012 makes as the user moves the mobile device 1012 to different positions relative to their head. For example, the motion meter 1024 may be represented as a line sliding along one side of the screen. In this way, the registration process may require a certain device movement threshold to register a user with the multidimensional authentication system. For example, the system may require the mobile device 1012 to be moved in an arc or straight line and rotated at least 45 degrees to create the registration information.In another example, the system might require the device to accelerate beyond a certain threshold. The motion meter can also help the user learn how to photograph themselves using the authentication system.
[0146] The 1012 mobile device may also display a 1026 accuracy meter or any other visual representation of authenticated frames to assist the user in authenticating using the authentication system and learning how to improve authentication. The 1026 accuracy meter may show the user a match rate (graphical, alphanumeric, or numeric) of a predetermined number of images obtained during the authentication process. The accuracy meter may be represented on the display in various ways, including numerical percentages, color representation, graphs, and the like. A combination of representations Petition 870260077099, dated 03 / 08 / 2026, page 55 / 246 50 / 113 can also be used.
[0147] For example, as shown in Figure 10, the match rates for a predetermined number of images obtained during authentication are represented in the accuracy meter. In the mode shown in Figure 10, each of the images can be represented by a column in a graph, and the accuracy can be shown for each image in each column. For example, the column with a larger bar represents higher accuracy, and a column with a smaller bar represents lower accuracy. In addition to the match rates for images, the match rates for the path parameter can also be displayed. Over time, the user can improve.
[0148] In another embodiment, each of the images can be represented in a table as a color that corresponds to the match rate. Dark green can represent a very high match rate, light green can represent a good match rate, yellow can represent a satisfactory match rate, red can represent a mediocre match rate, and gray can represent a low match rate. Other color schemes can also be used.
[0149] The height of the bars or colors used can correspond to predetermined match rates. For example, a full or dark green bar can have a match rate greater than 99.9%, a three-quarter or light green bar can have a match rate between 90% and 99.9%, a half bar or yellow can have a match rate of 50-90%, red can have a match rate of 20%-50%, and a single-quarter line or gray bar can have a match rate of 0-20%. A pie chart, line graph, or any other type of representation can also be used, or any other numerical or graphical display. An overall score can be displayed, or a score per image. Petition 870260077099, dated 03 / 08 / 2026, p. 56 / 246 51 / 113
[0150] The accuracy meter can also include a 1028 message indicating an overall match score. For example, the accuracy meter might indicate an average overall match score or the number of images that achieved a 99.9% match rate and display the message to a user. With the 1024 motion meter and the 1026 accuracy meter as described above, the user can quickly learn how to use the authentication system due to the feedback provided by the 1024 and 1026 meters. Gamification and Rewards
[0151] The 1024, 1026 motion and accuracy meters can also be configured to incorporate game features, aspects, or techniques into the authentication system to encourage a user to try to achieve the best possible match (such as a high score or high frame rate), increasing the user's skill in using the authentication system. This also creates user adoption rates for the technology.
[0152] For example, the user can compete with themselves to mimic or improve previous authentication scores to encourage or train the user to achieve a high score. Other modifications to the authentication meter can also be incorporated, such as the ability to share accuracy matching results with others to demonstrate the ability to use the system or compete with others. In other cases, the user may receive a reward, such as a gift or coupon, for high accuracy scores. While this may slightly increase costs, the reduction in fraud loss would far outweigh the additional cost.
[0153] Other gaming techniques can be incorporated into the authentication system to encourage users to take actions that prevent unauthorized or fraudulent authentication. In one embodiment, the authentication system can Petition 870260077099, dated 03 / 08 / 2026, page 57 / 246 52 / 113 Reward users who engage in fraud prevention activities. One such activity is the use of the facial recognition authentication system described herein. For example, based on the accuracy meter described above, the system may reward a user who successfully authenticates to the system above a certain matching rate. The system may award reward points, cash, or other prizes based on successful authentication or a predetermined number of successful authentications. When reward points are used, the points may be deducted from predetermined prizes.
[0154] Other game features may involve reward levels for users who earn a predetermined amount of experience using the authentication feature. For example, different reward levels may be based on users being successfully authenticated 100 times, 500 times, 1000 times, etc. As each instance of fraud loss can be significant and harm the company's or organization's clientele, the benefits for fraud prevention are substantial.
[0155] In one mode, the user may be notified that he or she has reached various levels of competence, such as a “silver level” upon achieving 100 successful authentications, a “gold level” upon achieving 500 successful authentications, or a “platinum level” upon achieving 1000 successful authentications. A number of points awarded for each authentication above a certain match rate may increase based on the user's experience level. Obviously, the names of the levels and the number of authentications for each level, as described above, are only examples and may vary as desired.
[0156] In one modality, authentication only counts towards reward levels when the transaction is completed on the site, while in others Petition 870260077099, dated 03 / 08 / 2026, page 58 / 246 53 / 113 modes, repeated attempts can be made, all of which count towards rewards. Another feature could incorporate a leaderboard in which a user can be notified of a user rating, comparing their proficiency or willingness to use the authentication system with other users.
[0157] The successful use of the authentication system benefits companies and organizations that use the system by reducing costs for fraudulent activities and the costs of preventing fraudulent activities. These cost savings can be used to fund the gaming features described above for the authentication system.
[0158] Other activities that correspond to the authentication system and contribute to fraud reduction can also be incorporated to allow a user to earn points or receive rewards. Such activities may include the user creating a sufficiently long and strong password that uses a specific number and character combination. This encourages and rewards users for setting passwords that are not easily compromised. Other examples may include rewarding users for taking the time to perform verification steps beyond initial authentication, such as mobile phone or email verification of authentication, answering one or more personal questions, or other known or subsequently developed secondary verifications. This rewards users for spending time and inconvenience to reduce the risk of fraud for a company or organization.
[0159] As another example, if the authentication service is used to access websites or applications that provide affiliate programs, then the prize or gift may be subsidized by affiliate commissions on purchases made on those websites. For example, if an e-commerce website (product or service) uses the method and device disclosed here to prevent fraud and thus increase profits, then a percentage of each purchase made by a user using the service will be paid. Petition 870260077099, dated 03 / 08 / 2026, page 59 / 246 54 / 113 authentication will be provided to the authentication service. By reducing fraud, consumer purchases are more likely and additional users will be willing to enter financial and personal information. A link, code, or referral source or affiliate identifier may be used to credit the authentication system with directing the consumer to the commerce site (product or service). Multiple Account Login
[0160] It is also contemplated that the authentication system can be configured to allow a user to access multiple different websites using a single authentication. As the authentication process and result are unique to the user, the user can first designate which participating websites the user chooses to log in to and, after selecting which one or more websites to log in to, the user performs the authentication described here. If secure authentication is successful, the user will be logged in to the selected websites. In this way, the authentication process is a universal access control for multiple different websites and prevents the user from having to remember multiple different usernames and passwords, as well as reducing fraud and password overload for each user. Automatic Start / Stop of Image Generation
[0161] It is also contemplated that the system can be configured to have the video camera running on the phone. The mobile device would capture frames and path parameter data as the phone moves (using the camera, gyroscope, magnetometer, and accelerometer), but would only process biometric data on the device or send the frames to the server if they contained a face. In this mode, the application running on the mobile device can trigger the software application to start saving frames when the phone is in motion, and then, if the phone continues to move in the correct path (a semicircle, for example) and the system detects a face in the frame, the mobile device would start sending images, a portion of the image, or biometric data to the server. Petition 870260077099, dated 03 / 08 / 2026, page 60 / 246 55 / 113 for processing. When the system detects movement, it can trigger image capture at specific intervals. The application can then process the frames to determine if the images contain a face. If the images include a face, the application will crop it and then check if the mobile device's movement path is similar to that used during registration. If the movement path is sufficiently similar, the application can send the frames, one at a time, to the server to be verified or processed, as described above. Edge and Stripe Detection
[0162] When a fraudulent attempt is made using a display screen, such as an LED, LCD, or other screen, the system can detect the fraudulent login attempt based on the expected attributes of the screen. In one embodiment, the authentication system will perform checks for streaks produced by digital screens. When streaks are detected, the system can recognize a fraudulent login attempt. In another embodiment, the system will perform checks for edge detection on digital screens. As the mobile device is moved to obtain the authentication motion during a login attempt, the system checks the captured images for screen edges to recognize a fraudulent login attempt. The system can also check for other image artifacts resulting from a screen, such as reflection detection. Any known or subsequently developed algorithm for screen streak and edge detection can be used.After fraud is detected, it will prevent authentication and access to the website, or prevent the transaction or access to the account. Estimation of Other Attributes
[0163] The authentication system can also conduct an analysis of the registration images to estimate at least one gender, approximate age, and ethnicity. Alternatively, the user can manually enter one or Petition 870260077099, dated 03 / 08 / 2026, page 61 / 246 56 / 113 plus their gender, an approximate age, and ethnicity, or this information can be captured or obtained from existing records that are known to be accurate. The authentication system can then further store a user's estimated gender, age, and ethnicity as registration credentials or user data. Thus, when the user later attempts to authenticate to the system, the system will compare gender, age, and ethnicity derived from the authentication images (using biometric analysis to determine such data or estimates based on processing) with the stored gender, age, and ethnicity to determine whether to authenticate the user. For example, if the derived data for gender, age, and ethnicity match the stored registration credentials, authentication will succeed, or that aspect of authentication will succeed.
[0164] The authentication system can make gender, age, and ethnicity estimates based on a single image during the authentication process or based on multiple images. For example, the authentication system can use one image from a plurality of images that has an ideal viewing angle of the user's face for analysis. In other modalities, a different image can be used for each age, gender, and ethnicity analysis, when different images reveal the best data for the analysis. Authentication can also estimate gender, age, and ethnicity from a plurality of images and average the results to obtain overall scores for a given gender, age, and ethnicity.
[0165] As an alternative to obtaining gender, age, and ethnicity as registration information, estimates of gender, age, and ethnicity as authentication credentials can be defined over a course of repeated use of the authentication system. For example, if, in previous successful authentications using biometric and motion information, the authentication system always estimates that a user's age is between 40 and 50, the authentication can define credentials for that user that require subsequent login information for Petition 870260077099, dated 03 / 08 / 2026, page 62 / 246 57 / 113 include images of a face estimated to be between 40 and 50 years old. Alternatively, gender, age, and ethnicity estimates can be implemented as one of many factors contributing to an overall authentication score to determine whether or not to authenticate a user.
[0166] For example, if the authentication process has a gender estimate of + or - 0.2 from a male classification of 1.9, then if the actual results are not within that range, the system may deny access to the user. Similarly, if the user's age range is always between 40 and 50 years during previous authentication or registration attempts, and an authentication attempt is outside that range, the system may deny access or use the result as a compounding factor to deny access.
[0167] In an additional embodiment, when a bracelet or watch capable of obtaining an EKG signature is used, a specific EKG signature may be required at login. The EKG signature may also be paired with facial recognition rotation to provide multi-stage login for critical security and identification applications. Furthermore, credentials may also include GPS information, where login is only permitted from specific geographic locations as defined during registration. In one configuration, the mobile device's GPS coordinates are recorded and logged for a login attempt or actual login. This is additional information about the user's location. For example, if the GPS coordinates are in a foreign country known for fraud, then the attempt would likely be fraudulent, but if the GPS coordinates indicate that the attempt or login was made from the user's home, fraud is less likely.Furthermore, some applications may only allow a user to log in when they are in a specific location, such as a secure government facility or a hospital.
[0168] Registration information may also include information from Petition 870260077099, dated 03 / 08 / 2026, page 63 / 246 58 / 113 distance. Because the arc of movement (speed, angle, duration...) is unique to each user, the facial detection software on the device can process the images and determine if the device is too close or too far from the individual. Or, in other words, the registration information can consider the size of the face in the images. Thus, potential registration information can also vary based on the user's arm length, head and face size, and the camera optics on the user's specific mobile device. The user may also be positioned at a computer or fixed camera, such as a laptop, desktop, or ATM. The user can then move their face back and forth, side to side, or up and down (or a combination) to create the images. Therefore, this method of operation is not limited to a mobile device.In one method, the camera is placed in a car, similar to a mirror, and the person moves their head or face for authentication. Access via Gradual Authentication
[0169] In one mode, the system is set to limit what the user can do when first registered and authenticated. Then, after further authentications or after a predetermined period of time and a number of authentications, additional resources may be granted. For example, during the first 20 authentications within the first 3 months, a maximum transaction of $100 may be allowed. This creates a database of known authentication data related to transactions not objected to by the user. Then, during the following 20 authentications, a transaction limit of $3000 may be established. This limits the total loss in case of fraud when authentication data is limited and the user is new to the system. For example, if an unauthorized user manages to fraudulently register in the authentication system. Video Display for Image Formation Petition 870260077099, dated 03 / 08 / 2026, page 64 / 246 59 / 113
[0170] When the user photographs themselves using a front-facing camera, the user can confirm that their face is being photographed by viewing the image in the viewfinder, as described above. The image shown in the viewfinder can be configured to have a smaller area than the entire viewfinder, and can be positioned in an upper part of the viewfinder towards the top of the device. When the user's image is displayed only in the upper part of the user's display screen, the user's eyes tend to look more closely at the front-facing camera. When the user's eyes are closer, the accuracy of facial recognition can be improved. In addition, tracking eye movement from one frame to another can allow the system to confirm whether the images are of a live person and not a photograph or video recording of the person.
[0171] The image shown on the display can also be positioned to match the location of a camera on the user's device, as shown in Figures 11A-11C. Currently available mobile devices may include front cameras arranged in several different positions. For example, a mobile device 1112a, 1112b may have a front camera 1114a, 1114b that is positioned above the display and off-center to one side or the other, as shown in Figures 11A and 11B. Consequently, the user's return image 1116a, 1116b shown on the display can be positioned to match the location of camera 1114a, 1114b, as shown. In Figure 11A, when a camera 1114a is above the display and is off-center in a position to the left of center, then image 1116a can be shown in an upper left corner of the display.In Figure 11B, when a camera 1114b is above the viewfinder and is off-center in a position to the right of center, then the image 1116b can be shown in an upper right corner of the viewfinder. As shown in Figure 11C, a mobile device 1112c can have a camera 1114c that is centrally positioned directly above the viewfinder. There, the image 1116c can be displayed. Petition 870260077099, dated 03 / 08 / 2026, page 65 / 246 The 60 / 113 aperture is centered at the top of the display. This way, the user's eyes are directed closer to and / or track as closely as possible to the camera, aiding in eye tracking and movement verification. The user can also better see the return image and other on-screen comments or information while moving the mobile device.
[0172] The image displayed on the screen by the user can also be modified in such a way that the border pixels on the sides are extended horizontally as shown in Figure 12. That is, a predetermined area 1206, 1208 on the right and left sides is deformed to extend to the right and left edges, respectively, of the screen. This allows a larger vertical portion of the displayed image to be shown on the screen. Simultaneously, this trains the user to use the system correctly, keeping their face centered on the screen, as their face becomes deformed on the screen if it is off-center and part of the face enters one of the deformed areas. Authentication in Low-Light Environments
[0173] To facilitate image creation, the mobile device screen can be additionally displayed with a white background, and the screen brightness can be increased to illuminate the user's face in dark environments. For example, part of the display can provide video feedback to the user to ensure that he or she is photographing themselves, while the remaining part of the display is set to display a bright white color. Referring to the example shown in Figure 11C, this can be done by displaying video feedback 1116c in the center of the display, with the surrounding areas being displayed as bright white bars around video feedback 1116c. In very dark situations, an LED flash on the back of the mobile device and the rear camera can be used. Alternatively, the camera can be configured to create an image using infrared light or other night vision techniques.
[0174] When infrared imaging is used as Petition 870260077099, dated 03 / 08 / 2026, page 66 / 246 61 / 113 Thermal imaging, other security improvements are possible. In particular, thermal imaging can be analyzed to indicate whether the images obtained are of a real user or are fraudulent images of a screen or other device. When a person is in front of an infrared thermal imaging camera, the detected heat radiation should have a fairly oval shape, designating the person's head. In contrast, the heat radiating from a screen is typically rectangular. Furthermore, the heat patterns detected on the real person's face, as well as the movement of the heat patterns in the images, can be compared to the expected heat patterns of a human face to distinguish images from fraudulent authorization attempts using a screen. Mobile Device Detection Output
[0175] The display or other light source on the mobile device can also be used to provide additional security measures. During the authentication process described above, light from the display or other light source is projected onto the user's face and eyes. This projected light can then be detected by the mobile device's camera during image formation. For example, the color tone detected on the skin or a reflection of light from the cornea of a user's eye can be captured by the camera on the mobile phone. Because of this, random light patterns, colors, and designs can be used to offer additional security and ensure that there is a live person attempting to authenticate and not just an image or video of a person being photographed by a fraudster.
[0176] As an example, when a user initiates authentication, the authentication server can generate and send instructions to the user's device to display a random sequence of colors at random intervals. The authentication server stores the randomly generated sequence for later comparison with the authentication information received from the mobile device. During authentication image formation, the colors displayed by the device are projected onto the face. Petition 870260077099, dated 03 / 08 / 2026, page 67 / 246 62 / 113 of the user and reflected onto the user's eyes (the cornea of the eyes) or any other surface that receives and reflects light from the screen. The camera on the user's mobile device detects the colors reflected on the user's skin or eyes (or other surface) and generates color data indicating the detected colors based on the screen projection. This data can be returned to the authentication server to determine if the color sequence or pattern sent to the mobile device matches that known sequence or pattern projected by the user's device screen. Based on this comparison on the authentication server, authentication is authorized or denied. Alternatively, the comparison with the random color sequence in the instructions can occur exclusively on the user's device to determine if an active user is being authenticated.
[0177] As another example, when a user begins authentication, the authentication server may send instructions to the user's device to display a randomly generated pattern that is then stored on the authentication server. This pattern may include graphics, text, lines or bars, flashing light patterns, colors, a QR code, or similar. The randomly generated pattern is displayed during authentication image formation, and the pattern is reflected in the user's eyes (cornea). The user's device camera detects the pattern reflected in the user's eye and processes the mirrored image of the displayed pattern. The processed pattern (such as being converted into a numeric value) is transmitted to the authentication server and compared to the pattern that was randomly generated and stored on the authentication server to verify that the pattern displayed on the screen and created after reflection on the user's face establishes a pattern match.
[0178] If a match occurs, this establishes or increases the probability that a living person is being photographed by the device. If the pattern is not a match or does not meet a threshold level of Petition 870260077099, dated 03 / 08 / 2026, page 68 / 246 63 / 113 correspondence, the authentication process may fail (access denied) or access to the account or the transaction amount may be limited. Note that this example can also be incorporated into a desktop computer with a webcam that does not incorporate the registration and authentication movements described above. Furthermore, this example can not only be incorporated with facial recognition, but can also serve as an additional layer of security for iris recognition or any other type of ocular blood vessel recognition, or any facial feature that is unique to a user.
[0179] When the above example is implemented on a desktop computer, eye tracking can also be used to further demonstrate the presence of a live user. For example, the screen might show a ball or other random object or symbol moving in a random pattern that the user observes with their eyes. The camera can detect this movement in real time to verify that the user is alive, and not an image or display, and to check if the eye or head movements correspond and coincide with the expected movement of the object or words on the screen, which are known to the authentication system. Eye tracking can also be done by establishing an anchor point, such as by clicking the mouse at a location on the screen (if the user is looking at the location where the mouse click occurs) and then estimating where the user is looking on the screen relative to the anchor position.
[0180] The use of a moving object on the screen can also be beneficial during registration on a mobile or stationary device. For example, when capturing registration images, the device can display a moving digital object (such as a circle or word(s)) that moves across the screen to encourage the user to follow it with their head and eyes. This movement can be Petition 870260077099, dated 03 / 08 / 2026, page 69 / 246 64 / 113 involuntary user movement or the device can be configured to instruct the user to follow the object. This results in head and / or eye movement, creating small changes in the orientation of the user's head and face relative to the device's camera, providing more complete registration information. With more complete registration information, the system can better ensure that the user is authenticated later, even at slightly different angles, during future authentication attempts. Intuitive User Training and Enhanced Security via Zoom
[0181] In one embodiment, the system is configured to assist the user in easily learning how to authenticate to the system. As shown in Figure 13A, once registration or authentication has begun as described above, the system causes the user's mobile device 1310 to display a small oval 1320 on the screen 1315 while the mobile device 1310 is photographing the user. Instructions 1325 displayed on the screen 1315 instruct the user to hold the mobile device 1310 so that their face or head appears in the oval 1320. Because the oval 1320 is small, the user is required to keep the mobile device 1310 away from their body, for example, by extending their arm while holding the mobile device 1310. The maximum arm length and face size are unique to the user. In another embodiment, the arm may not be fully extended to accommodate operation when space is limited, such as in a car or crowded location.Note that while the small oval 1320 is shown centered on the display, it can be positioned anywhere on the screen 1315.
[0182] Next, as shown in Figure 13B, the system causes the user’s mobile device 1310 to display a larger oval 1330 on the display 1315. The display 1315 may also show corresponding instructions 1335 directing the user to “zoom in” on their face to fill the oval 1330 with their face. The user does this by bringing the mobile device 1310 closer to their face in a generally straight line with Petition 870260077099, dated 03 / 08 / 2026, page 70 / 246 65 / 113 the user's face (as shown in Figures 7A and 7B) until the user's face fills the oval 1330 or exceeds the oval. In other embodiments, the large oval 1330 may simply be a prompt for the user to bring the mobile device 1310 closer to their face.
[0183] Thus, the system provides and teaches the user a simple method for providing registration and authentication images along with the registration and authentication movement, as explained above. The system can also teach variable registration and authentication movement by varying the location of the small oval 1320 on the screen 1315, and by changing the order and size of the displayed ovals. For example, the user can zoom in ½, then zoom out, then zoom in completely, by moving the mobile device. The system can be configured to monitor whether the camera's zoom function (when equipped) is not in use, which normally requires the user to touch the screen.
[0184] In one mode, the registration movement can be omitted, and the authentication movement can be compared to the expected movement based on on-screen reminders. For example, the authentication device or server generates a series of ovals of different sizes within which the user must position their face by moving the mobile device held in the user's hand. In this way, the authentication movement can be different during each login, depending on the order, size, and positioning of the ovals shown on the screen.
[0185] The system can also incorporate other safety features when the “zoom” movement is used as shown in Figures 13A and 13B. Typical cameras in a mobile device or any other device include a curved lens. This results in a barrel-like distortion effect in the resulting images obtained by the camera. In some cases, this curvature may not be visible to the human eye or may only be noticeable at certain focal lengths. The curvature or barrel-like distortion effect may vary with the focal length or Petition 870260077099, dated 03 / 08 / 2026, page 71 / 246 66 / 113 is the distance between the user and the lens. The degree of barrel distortion is therefore dependent on the type of optics used in the camera lens and other factors.
[0186] The barrel distortion effect becomes more pronounced in an image of a person's face when the person photographs their face close to the lens. The effect causes the relative dimensions of the person's face to appear different than when the image is taken with the person's face further from the lens. For example, a person's nose may appear up to 30% wider and 15% higher relative to the rest of their face when the image is taken up close compared to when the image is taken from a distance. The differences in relative dimensions are caused by the relatively larger differences between the camera and the various facial features when the person is photographed close to the lens compared to the relatively equal distances when the person is photographed further from the lens.
[0187] These differences have been considered significant in many facial recognition algorithms. That is, a facial recognition algorithm may not recognize a living person photographed up close and from a distance as the same person. In contrast, if a two-dimensional photograph of a person is taken by the camera both up close and from a distance, the relative focal lengths between the lens and the two-dimensional image do not change as significantly. Thus, a facial recognition algorithm would recognize the two-dimensional photograph as the same person when photographed up close and at distances further away from the lens.
[0188] This effect can be used to increase the security of the authentication system. For example, during registration, registration images can be provided by the user both close up and far from the lens, as well as other positions during movement. Subsequently, during authentication, authentication images can be obtained at close and far distances from the lens to determine if they correspond to the registration information obtained from the images. Petition 870260077099, dated 03 / 08 / 2026, page 72 / 246 67 / 113 registration. Furthermore, since the barrel distortion effect is expected when a real three-dimensional person is present, an absence of the relative change in the dimensions of facial features alerts the system to a fraudulent authentication attempt. This effect cannot be easily recreated with a two-dimensional image (photograph or printed screen) and therefore this step can serve as a safe test to prevent a two-dimensional image (instead of a live face) from being used for authentication.
[0189] In other words, using this “zoom” movement on the user’s face, two or more biometric profiles can be created for the same person. One of the multiple profiles for the person may have an image further away from the camera, and one of the multiple profiles may be for the person photographed closer to the camera. For the system to authenticate the person, the images and authentication biometrics must match the two or more profiles in the registration images and biometrics.
[0190] Furthermore, the system can detect the presence of a real person, compared to a fraudulent photograph of a person, by comparing the background of images obtained at close range and from a distance. When the mobile device 1310 is held in such a way that the person's face fits within the oval 1320, objects in the background that are almost directly behind the person may be visible. However, when the mobile device 1310 is held in such a way that the person's face fits within the larger oval 1330, the person's face blocks the cameras' ability to see the same objects that are almost directly behind the person. Thus, the system can compare the backgrounds of images obtained at close range and from a distance to determine if the real person is attempting to authenticate themselves to the system.
[0191] Evidently, in Figures 13A and 13B, shapes or guides other than the ovals 1320 and 1330 can be used to guide the user to hold the mobile device 1310 at the appropriate distance from their face. For example, the mobile device 1310 can display a full or partial square frame or Petition 870260077099, dated 03 / 08 / 2026, page 73 / 246 68 / 113 rectangular. Additionally, the system can vary the size and location of the frame, such as oval frames (1320, 1330) to add more security. For example, the system might require a medium-sized frame, a small frame, and then a large frame. As another example, the system might require a small frame in a first location and a second location, and then a large frame. This can be done randomly to teach different users different registration and authentication movements.
[0192] The number of frame sizes presented to the user may also vary for a single user based on the results of other security features described herein. For example, if the mobile device’s GPS coordinates show that the device is in an unexpected location, more frames at different distances may be required for authentication. One or more indicators, such as lights, words, or symbols, may be displayed on the screen to be visible to the user to guide the user to the desired distance the mobile device should be from the user.
[0193] In Figures 13A and 13B, the system can predict the expected barrel distortion of the images based on the mobile device used for registration and authentication, and based on known and reliable registration data. Furthermore, or alternatively, the known specifications of a mobile phone camera for a given model can be used to predict the expected distortion of the person's facial features at different distances from the lens. Thus, authentication can be device-dependent. Additionally, user registration information is not required at all possible distances from the camera.
[0194] For example, as described above, images and registration biometrics can be obtained for a user at two distances from the user. During authentication, multiple images are captured, in addition to images corresponding to the near and far distances of the biometrics and registration images. Based on Petition 870260077099, dated 03 / 08 / 2026, page 74 / 246 69 / 113 expected distortion of these intermediate images, according to the distance traveled by the device, the system can validate that the change in image distortion is occurring at the correct rate, even if only two registration profiles are obtained.
[0195] The capture of these images can be either still images or video, such that frames or images are extracted from the video that is captured during the movement from the first position furthest from the user and the second position closest to the user. Thus, it is contemplated that the operation can capture multiple frames during the zoom movement and ensure that the distortion is occurring at the correct rate for the head size and the movement distance from the mobile device based on data from accelerometers, magnetometers and the like.
[0196] Over time, based on accumulated data or data calculated during the design phase, the system will have data indicating that if a phone is moved a certain distance towards a user's face, then the distortion effect should be within a known percentage of the final distortion level or initial distortion level. Thus, to deceive or fool the authentication system disclosed here, the attempted fraud would not only need to distort the fraudulent two-dimensional image, but would also need to crop out the background and then incrementally and at the correct speed make a video of the face, distortion, and background, all without having any visible video screen bands or screen borders, which is highly unlikely.
[0197] Many currently known facial recognition and facial detection algorithms are configured to search for a small face within an image. Thus, to ensure that facial detection and recognition algorithms detect and recognize the user's face in the enlarged image (Figure 13B), the system can add a large safety zone around the image taken at close range. This creates a larger overall image and allows current algorithms to... Petition 870260077099, dated 03 / 08 / 2026, page 75 / 246 70 / 113 facial detection and recognition detects and recognizes the face, even when the user's face is large in the original image.
[0198] When the registration and authentication movement resulting from the process described in Figures 13A and 13B is used, the eye-tracking security features described above can also be enhanced. For example, when the user is instructed to bring the mobile device 1310 close to their face to fill in the oval 1330, a QR code, a random shape, a barcode, color, text, numbers, or any other visual indicator can be displayed on the screen. At this close distance, the reflection of the displayed indicator in the user's eye or face can be more easily captured by the camera. In addition, eye movements, blinks, and similar actions to determine the "proof of life" of the person being photographed can also be more easily obtained at close range.
[0199] In one mode, at least one blink is required to prove presence for authentication. In another mode, blinks can be counted and the number of blinks can be calculated over time during authentications. This allows an additional factor in authentication: the number of blinks observed during movement. If a pattern of when the user blinks during movement is observed, the system can verify whether the user blinks at the expected time and device location during movement during future authentication attempts.
[0200] In other embodiments, the size or location of the oval or frame may change to different sizes or locations than those shown in Figures 13A, 13B, such that the user must position and / or tilt the phone to position their face within the oval. This establishes yet another method to ensure the user's presence.
[0201] In an exemplary method, the mobile device is positioned at an initial distance from the user and an initial image is captured to Petition 870260077099, dated 03 / 08 / 2026, page 76 / 246 71 / 113 processing. This distance can be linearly away from the user and, in this mode, may not be in an arc or orbit. This can occur by the user moving the mobile device, manually or with the mobile device on a movable device or rail system. Or the lens system can be adjusted if, in a fixed system, to change the size of the user's face relative to the frame size. Alternatively, the user can remain stationary, multiple cameras can be used, or the camera can move without the user moving. Once some form of movement (of a device, camera, lens, or user) has occurred to establish the camera at a second distance, a second image is captured for processing. The movement from the first position to the second position can be direct towards the user. Processing occurs on both images.
[0202] Processing may include calculations to check for a difference between the two images, or a difference in the biometrics obtained from the two images, indicating that a real person is being photographed. Processing may occur to compare the first authentication image with a first registration image (corresponding to the first distance) to determine if a match is present, and then compare the second authentication image with a second registration image (corresponding to the second distance) to determine if a match is present. If a match occurs, authentication may continue.
[0203] Variations of these methods are also possible with the system requiring a match at the first distance but a match failure at the second distance, thus indicating that the second image is not a two-dimensional image. The resulting processing in a match or match failure can be any type of image processing or facial recognition algorithm. As with other processing described here, the Petition 870260077099, dated 03 / 08 / 2026, page 77 / 246 72 / 113 processing can occur on the mobile device, on one or more remote servers, or any combination of such devices.
[0204] All processing described here can occur only on the mobile device, only on a remote server, or a combination of both. Biometric data can be stored on the mobile device or on the server, or it can be split between the two for security purposes. For example, images can be processed on the mobile device but compared to registration data in the cloud or on a remote server. Or images can be sent to the cloud (remote server) for processing and comparison. Touchscreen Enhancements
[0205] Additional security modifications added may include information about a user's finger. Many mobile devices with touchscreens can detect the location and approximate size of a user's touch on the screen. Thus, an approximate size of a user's finger or thumb can be measured by the system. In addition to finger size, it is possible to detect a finger orientation angle or whether the fingers or thumbs of the right or left hand are used.
[0206] In one mode, a user selects an account to open, initiates the creation of registration images, or initiates the creation of authentication images by touching the touchscreen of the user's device. The authentication system can thus detect whether a user's touch during authentication matches previously stored registration information, including the size of the user's finger or thumb, the amount of pressure applied to the screen, and whether the user is right-handed or left-handed. This adds an additional layer of security to the authentication system.
[0207] In addition, the authentication system may require the user to initiate authentication by touching a fingerprint reader or the touchscreen of a Petition 870260077099, dated 03 / 08 / 2026, page 78 / 246 73 / 113 or more predetermined ways. In one embodiment, as shown in Figure 14, a touch screen 1410 can be divided into predetermined regions 1420. For example, there may be nine identical, circular, square, or other shaped regions 1420 on the touch screen 1410 of the mobile device. During registration, the user selects one of the regions 1420 of the screen 1410 to touch to initiate authentication. During authentication, if the pre-selected region 1420 is not touched to initiate authentication or during the entire authentication process, authentication is denied. This is only one possible design possibility, and other design options are contemplated.
[0208] Regions 1420 on the touchscreen may be visually represented by a grid, or may not be displayed on the touchscreen 1410. As shown in Figure 15, in addition to or instead of regions 1420, buttons 1520 may be displayed on a touchscreen 1510. Here, the user can initiate authentication by pressing one or more of the buttons 1520 in a predetermined pattern. The user can also initiate authentication by means of a predetermined sliding pattern. The position to be touched by the user may change with each authentication attempt and may be transmitted to the user through any instruction from the authentication server, such as code, number, letter, color, captcha, or other indicator. Voice Parameters
[0209] It is also contemplated that the user can record their voice speaking a phrase while recording their images during the registration process when using the system for the first time. Then, to authenticate, the user would also have to speak the phrase while moving the mobile device to capture an image of their face. Thus, an additional path parameter can be the user's spoken voice and the use of voice recognition as another layer or element of the authentication process. Petition 870260077099, dated 03 / 08 / 2026, page 79 / 246 74 / 113 Image Quality Guarantee
[0210] The authentication system can also process images received from the mobile device to determine if the images are of sufficient quality. For example, the system can check if the images are blurry due to out-of-focus images or if the camera lens is being obscured by fingerprints, oils, etc. The system can alert the user that the image quality is insufficient (either too bright or too dark) and direct the user to adjust a focus, exposure, or other parameter, or to clean the camera lens. Self-focus
[0211] The authentication system can also utilize an autofocus feature when the mobile device's camera is equipped with such a feature. For example, when a real three-dimensional person is being photographed, the system checks if the image sharpness changes as the camera performs autofocus. In another embodiment, the system can control autofocus so that the camera focuses on a first location or distance to check the sharpness (in focus) of a part of the image that contains a face. The system then controls the camera to focus on a second location or distance where the presence of a face is not detected and check the sharpness (in focus) of a part of the image. If a three-dimensional person in a real environment is being photographed, the focal length settings are expected to be different at the first and second locations, suggesting that a real person is currently being photographed.However, if the focal lengths of both locations are the same, this indicates that a two-dimensional photograph or screen is being captured, suggesting a fraudulent login attempt.
[0212] The system can also control the device's autofocus to check different focal distances for different features in the image. For example, when a person's face is photographed from the front, the ear is expected to be visible. Petition 870260077099, dated 03 / 08 / 2026, page 80 / 246 75 / 113 person has a different (further) focal distance than the tip of the person's nose. Login Attempt Images
[0213] The authentication server can also be configured to store authentication images for a predetermined period of time. The images can provide additional security benefits as proof that a person is attempting to log into a user's account. For example, the system can store a predetermined number of previous login attempts, such as twenty login attempts, or store images of login attempts for a predetermined period of time, such as during the last seven days or weeks. Any fraud or attempted fraud will result in photos of the person attempting to log in being stored or sent to the account server's authentication server.
[0214] The mere knowledge that photos will be taken and sent is a significant deterrent to any potentially dishonest person, because they know their photo will be taken and stored, and it is a security guarantee for the user. Similarly, any attempt or unsuccessful attempt can have the photo stored and indicate who is trying to access the account. It is also contemplated that an email or text message along with the image of the person who is trying to log in unsuccessfully can be sent to the authorized user, so that they know who is trying to access their account. This establishes the first line of security for the account, since the user with the photo or image is also in the possession of the authentication server. Adaptive Matching Boundaries
[0215] In addition, the level or percentage of matching between registration information and authentication information for authenticating the user may change over time. In other words, the system may understand a limit. Petition 870260077099, dated 03 / 08 / 2026, page 81 / 246 76 / 113 adaptive.
[0216] After a user regularly uses the authentication system described above, the user will have logged into the system by moving the mobile device along the predetermined path relative to their head many times. Thus, it can be expected that, as the user gains experience using the authentication system, the user will gradually establish a comfortable and standardized movement path. In contrast, a user's initial registration movement will likely be the strangest and most awkward, as the user has little experience with the authentication system.
[0217] To make the authentication system more convenient for the user without compromising security, the adaptive threshold system allows the registration movement to adapt so that the user is not stuck with the initial awkward and clumsy registration movement. To facilitate this, with each successful authorization, the successful authorization movement is stored, and the movement path is added to a list of acceptable movement paths. The list of acceptable movement paths can be limited to a predetermined number of paths. When a new successful authorization is completed and the list of acceptable movement paths is full, the oldest registration movement path will be deleted and the most recent one will be stored in its place. Alternatively, the movement path that is least similar to the other movement paths stored in the list can be deleted.Thus, by storing the most similar or most recent movement paths, the registration process can slowly adapt over time, as the user becomes familiar with the system and settles into a comfortable movement path for authentication.
[0218] In addition, other registration information can be adaptively changed in a similar way to user information. By Petition 870260077099, dated 03 / 08 / 2026, page 82 / 246 77 / 113 For example, biometric information or photos of successful authentications can be stored as part of the registration information, and old registration information can be discarded over time. In this way, the authentication system can be convenient for a user, even over a long period of time, as the user experiences aging, facial hair growth, different makeup styles, new glasses, or other subtle facial changes.
[0219] The determination of how much variation is allowed over time in movement path or biometric information, or both, can be defined by the entity requiring authentication to meet the entity's security requirements. The time or number of scans after initial registration can be used to modify the adaptive threshold. For example, during the first few days after registration, the threshold may be lower while a security threat is low and differences in paths are likely to be greater. After several authentications or several days, the threshold may increase. The threshold can also be defined based on trend data from the movement path or biometric information. For example, the threshold may be more lenient in the direction of data trend, while having a tighter tolerance for data in relation to trend.
[0220] A temporal aspect can also be added along with location information. For example, if the user conducts and authenticates a transaction near their home, and then an hour later another transaction is attempted in a foreign country, the transaction may be denied. Or it may be denied if the distance between the previous authentication location and the next authentication location cannot be traversed or is unlikely to be traversed within the time interval between login or authentication attempts. For example, if the user authenticates in Denver, but an hour later an attempt is made in New York, Russia, or Africa, the first or second attempt will be fraudulent because the user Petition 870260077099, dated 03 / 08 / 2026, page 83 / 246 78 / 113 will probably not be able to travel between these locations in one hour.
[0221] Furthermore, if the subsequent transaction is attempted at a more reasonable time and distance from the first transaction, the matching threshold level may be increased to provide additional security without automatically denying the transaction. Similarly, an altimeter may be used such that if the altitude determined by the mobile device differs from the altitude of the city where the user is located, this may indicate an attempted fraud. Thus, altitude or barometric readings from the mobile device may be used to verify location and may be referenced against GPS data, IP address or router location data, or location identified by the user. Random Image Distortion
[0222] To provide an additional layer of security to the facial recognition authentication system, the system may use random image distortion. For example, a user may receive a random distortion algorithm after registering with the system. The distortion algorithm may include such distortions in the image as widening or narrowing the person's face by a predetermined amount, adding or overlaying a predetermined shape in a predetermined position on the user's face. As an example, the distortion could be a circle superimposed 100 pixels above the user's left eye.
[0223] With the distortion uniquely attributed to the user's images, the biometric data for that user will be unique to the account or device used by the user. That is, the registration biometrics stored on the authentication server or mobile device will reflect not only the user's facial features but also the uniquely attributed image distortion. Thus, even if an accurate and fraudulent representation of a person were used on a different device or through a different account, the authentication biometrics offered would not correspond sufficiently due to distortion. Petition 870260077099, dated 03 / 08 / 2026, page 84 / 246 79 / 113 unique difference or absence of unique distortion. Thus, overall safety can be improved. Layers of Security
[0224] Note that each of the above modalities, modifications, and enhancements can be combined in any combination as needed to create multiple layers of security for authentication. For example, facial recognition can be combined with motion detection or path detection, or it can operate independently of these features for authentication. Furthermore, when more than one of the enhancements or modifications described above are combined, the authentication system can be configured so as not to provide any feedback or indication as to which layer failed to authenticate.
[0225] For example, when a predetermined touch pattern to initiate authentication is combined with the authentication motion and facial authentication, the system does not indicate whether a touch pattern was incorrect or whether the authentication motion or authentication images do not match the registration information. Instead, the system provides an identical authentication denial, regardless of the failure. This is the case when any number of the security features described above are combined. In this way, it is difficult for a fraudster to detect which aspect of the fraudulent credentials needs to be corrected, further increasing the system's security.
[0226] All of the above features can be incorporated together, or only some features can be used and others omitted. For example, when the device prompts the user to move the device so that the user positions their head within a first small frame (such as an oval) and then in a second large frame (as in Figures 7A, 7B, 13A and 13B), the system can be configured so that facial recognition does not need to be performed on the image(s) in the first frame (frames captured from a distance). Security Petition 870260077099, dated 03 / 08 / 2026, page 85 / 246 The 80 / 113 security of the system is maintained by performing facial recognition across the entire image at some point between the first and second frames, and within the second frame. This can be especially true when it also integrates another layer of security, such as eye-tracking verification following a moving object on the screen, or reading a reflection of a QR code or a random shape in the user's eye. In another modality, when two or more cameras are used to create three-dimensional stereoscopic images, facial recognition may not be performed in the distant first frame, but instead, proof of life can be validated in the closest frame only after the device moves. In still other modalities, other security layers can be used, and movement parameters can be omitted.Such combinations can be beneficial for larger or stationary devices, such as gaming laptops, personal desktop computers, a stationary kiosk, or similar. Examples of Applications
[0227] Similarly, although described here as financial account authentication, authentication using path parameters and image data can be implemented in any environment that requires verification of the user's identity before allowing access, such as automatic access, room access, computer access, website or data access, phone use, computer use, package delivery, event access, ticketing, court access, airport security, retail sales transactions, IoT access, or any other type of situation.
[0228] For example, one embodiment will be described where the above authentication system is used to securely conduct a retail sales transaction. In this embodiment, a user is registered on the authentication server or in an authentication application on the mobile device, as described above, and Petition 870260077099, dated 03 / 08 / 2026, page 86 / 246 81 / 113 generated registration information, including images and / or registration biometrics, and registration activity. In this example, the user initiates or attempts to complete a transaction at a retail establishment using a credit card, smart card, or a smartphone with NFC capabilities.
[0229] The user initiates the transaction by swiping a credit card, smart card, or using an app on a smartphone with NFC capabilities to pay for goods or services. The retail establishment would then authorize the card or account with the relevant financial institution's network (“Gateway”). For example, the retail establishment, through a Gateway, such as one operated by VISA or AMERICAN EXPRESS, would determine if the account is available and has sufficient funds available.
[0230] The Gateway would then communicate with the authorization server to authorize the transaction, verifying the user's identity. For example, the Gateway might send an authorization request to the authentication server, and the authentication server sends a notification, such as a push notification, to the user's mobile device to prompt the user to authenticate the transaction.
[0231] After receiving notification from the authentication server, such as via a vibration, beep, or other sound on the mobile device, the user can authenticate their identity with the mobile device. The authentication server can also send transaction information to the user for verification. For example, the authentication server can send information that causes the mobile device to display the seller, the seller's location, and the total purchase amount of the transaction.
[0232] Next, as before, the user can hold the mobile device and obtain a plurality of authentication images as the user moves the mobile device to different positions relative to the user's head. When moving the mobile device to obtain the authentication images, the mobile phone tracks Petition 870260077099, dated 03 / 08 / 2026, page 87 / 246 82 / 113 still uses the path parameters (authentication movement) of the mobile device through the gyroscope, magnetometer, and accelerometer to obtain the device's authentication movement. The mobile device can then send the device information, authentication images, and authentication movement to the authentication server. In other modes, the mobile device can process the images to obtain biometric data and send the biometric data to the server. Still in other modes, the mobile device can process the images, obtain authentication information, compare the authentication information with the registration information stored on the mobile device, and send the pass / fail results of the comparison to the authentication server.
[0233] The authentication server can then authenticate the user's identity and confirm that the user wishes to authorize the transaction on their account if the device information, images and / or biometric authentication, and authentication movement match the registration device information, images and / or biometric registration, and registration movement. The authentication server then transmits an authorization message to the Gateway. After the gateway receives confirmation of the authorization, the Gateway then communicates with the retail establishment to allow the retail transaction.
[0234] Several advantages can be gained when a retail transaction is authorized using the above system and method. Because user identity verification and transaction confirmation are completed through the authentication system and mobile device, there is no longer a need for a user to provide their credit card or signature or enter a PIN number into the retailer's point-of-sale system. Furthermore, the retail establishment does not need to verify a photo ID of the user. The above method and system also have the advantage of providing secure transactions that can function with transactions Petition 870260077099, dated 03 / 08 / 2026, page 88 / 246 83 / 113 mobile and online devices that do not have cameras, such as security cameras, on site.
[0235] In the secure retail transaction described above, the user obtains the total amount due on their mobile device from the retail establishment via the authentication server and gateway. However, in one embodiment, the mobile phone can use the camera as a barcode, QR code, or similar scanner to identify the items and prices of the items to be purchased. The mobile device can then total the amount due and act as the checkout to complete the transaction with the retail establishment.
[0236] In another mode, an app user may wish to pay an individual or a merchant anonymously. In this case, the user would designate an amount to be paid in an app, and the app would create a unique identification transaction number. This number can then be shown to the second user, so that the second user can enter the identification transaction number in an app on a separate device. The unique identification transaction number can also be sent from the user to the second user via NFC, Bluetooth, QR code, or other suitable methods. The second user can also enter the amount and request payment.
[0237] Upon receiving the payment request and the unique transaction identification number, the authentication server can send a notification to the first user's mobile device to authenticate the transaction. The user then verifies their identity using the facial recognition authentication system described above. Alternatively or additionally, the user can verify their identity using other biometric data, such as fingerprint or retinal scan, motion and path-based images, or the user can enter a password. After authentication, the user's device sends a request to the user's payment provider to request and authorize payment to the second user. Petition 870260077099, dated 03 / 08 / 2026, page 89 / 246 84 / 113 In this way, payment can be made securely, while the users of the transaction remain anonymous.
[0238] According to one embodiment, as an additional security measure, the mobile device's GPS information may also be sent to the authentication server to authenticate and enable the retail transaction. For example, the mobile device's GPS coordinates may be compared with the coordinates of the retail establishment to confirm that the user is actually present at the retail establishment. In this way, a criminal who has stolen a credit card and attempts to use the card from a distant location (compared to the retail location) cannot complete a transaction because the user's phone is not at the retail establishment's location. IP addresses may also be used to determine location.
[0239] As explained above, the level or percentage of matching between registration information and authentication information to authenticate the user can also be adjusted based on the mobile device's GPS coordinates. For example, if the retail establishment and the mobile device's GPS coordinates are close to a user's home, then the matching level can be set to a lower limit, such as a 99% matching rate. Alternatively, if the location is far from the user's residence and is in a foreign country, for example, the matching level can be set to a higher limit, such as a 99.999% matching rate. Biometric Identification using Root Identification Information
[0240] Most biometric identification systems in recent years use devices such as smartphones to capture biometric data (e.g., a digital photograph or fingerprint scan). This biometric data corresponds to pre-existing biometric data on the device (in Petition 870260077099, dated 03 / 08 / 2026, page 90 / 246 85 / 113 compliance with FIDO Alliance standards) or in the cloud (a remote computing device) where biometric data is sent to servers and compared to pre-existing data.
[0241] However, with the ability to convert images or other biometric data into biometric templates on the device without sending the raw data files to a server, an additional option is available. Existing raw biometric data, such as facial images, fingerprint scans, etc., or converted biometric templates can be downloaded to the device.
[0242] The downloaded biometric data can then be converted and / or compared to a biometric template that was created from data captured on that device and previously sent to the cloud, or captured and sent to the cloud from a different device.
[0243] This allows a third party to provide an existing root identification profile for comparison with the biometric information obtained from the device for authentication. For example, the root identification profile might comprise an image or other biometric reading of a customer that was captured and verified at a bank branch, from a DMV file, or from another authorized and trusted source. The bank branch, government entity (such as a DMV), or other trusted source might have a secure camera, fingerprint reader, or other type of biometric capture device that reliably captures the user's biometric information to create the root identification profile. The root identification profile might, alternatively or additionally, comprise biometric templates created from the verified image or biometric reading.In this way, the identification match on the device has a higher level of confidence based on the verified third-party root identification profile. The biometric template is defined as data derived from the biometric identity profile. For example, if a trusted image of a user is captured, that trusted image can be... Petition 870260077099, dated 03 / 08 / 2026, page 91 / 246 86 / 113 or be part of the root identification profile. This trusted image can be processed to create a biometric template or be part of a biometric template. The processing can transform the image into data (the biometric template) that can be used in the authentication process, but the original image cannot be recreated from the biometric template.
[0244] Figure 16 presents a system for biometric identification using root identification information, according to an exemplary embodiment. The system includes a user device 1612, such as a smartphone or a tablet-type computing device comprising one or more biometric sensors, such as a camera 1614 and a fingerprint scanner 1615. The device 1612 communicates with a network 116, such as the Internet.
[0245] A root identification server 1630 is also connected to the network 116. The root identification server 1630 may be a bank server, a government server, or another “trusted” server that stores root identification information including biometric information and / or biometric template(s). The root identification server 1630 is connected to biometric detection devices, such as a camera 1632 or fingerprint scanner 1634. It is contemplated that the camera 1632 may be part of a computer, a standalone device, or a mobile device, all of which are trusted. The camera may be fixed, or the distance between the user and the camera 1632 may vary during the capture of trusted images, such as an image captured at a distance versus an image captured up close. The distance may be similar to the distance a user might establish while holding their mobile device to take a selfie.An authentication server 1620 that provides an application, such as facial recognition algorithms and the like, is also connected to the network 116. Also part of the embodiment of Figure 16 is a third-party server 1640, which may be a root identification server or a third-party server, such as for a company. Petition 870260077099, dated 03 / 08 / 2026, page 92 / 246 87 / 113 or any other type of entity. As described above, a 1650 authentication server can also be part of the system. The 1650 authentication server can be configured to perform authentication processing, for example, by running one or more authentication algorithms on biometric data to evaluate and authenticate a user. In one embodiment, the 1650 authentication servers can be configured as one or more of the 120 servers, as shown and described above in Figure 1. Figure 20 illustrates exemplary server hardware. Any means of communication between the elements in Figure 16 can occur, including wired and wireless connections.
[0246] Figure 17 presents a method for authentication using a root identification system, according to an exemplary embodiment. Authentication using facial recognition as the biometric information analyzed for a root identification profile can function as explained in the following exemplary embodiment. Firstly, in step 1701, biometric information is captured through a trusted device (camera 1632 or scanner 1634 in Figure 16). The device is considered trusted because the biometric information collected on the device is verified by a trusted institution, such as a bank or government agency. This captured data can be defined as a root identification profile. It can be stored on a server 1630 or in any secure database.In one embodiment, the root identification profile may include DMV (Department of Motor Vehicle) images, or any trusted biometric information collected or based on government data. A root identification profile is established in step 1703 that comprises the trusted device biometric information and links the biometric information to a user identity, such as name, CPF number, other identification number, driver's license number, financial account number, account name, or any other type of information. This root identification profile is stored in... Petition 870260077099, dated 03 / 08 / 2026, page 93 / 246 88 / 113 server, such as server 1630, 1640, 1650 or any other database. The reliable source can be a commercial or governmental entity.
[0247] In step 1705, biometric information, such as an image containing data about an individual's face from the root identification profile, is sent from server 1630 to smart device 1612 upon an authentication request from smart device 1612. The term smart device (which is used as the authentication device) can be any type of computing device, such as a computer, mobile device (tablet, cell phone), ATM, kiosk, or any other device used to conduct an authentication session for identity verification. The smart device (authentication device) may belong to the user, company, government entity, or any other entity that intends to use the authentication system to verify identity. For example, a car dealership may wish to verify identification before releasing a new car for purchase.If the authentication device is an ATM, authentication may be required before a cash withdrawal can occur. If it's a point of sale, a jewelry store for example, they may want to verify identification before dispensing a diamond ring. In a government agency, the government agency may wish to verify identification before releasing a pension, retirement benefit, medical services, or tax return.
[0248] The smart device 1612 can be referred to as the authentication device because it is the device used for authentication. The user of the smart device 1612 then articulates the camera 1614 so that the user's face can be captured by the device's camera 1614, in step 1707. As described above, one or more images can be captured. Images can be captured with the camera at different distances from the user or the user at different distances from the camera. Biometric data (profile or model) Petition 870260077099, dated 03 / 08 / 2026, page 94 / 246 89 / 113 transferred from server 1630 to the authentication device can now be compared in step 1709. In one embodiment, the trusted template or trusted image can be downloaded to the smart device (authentication device). For example, each trusted image is converted into a biometric template by a facial recognition algorithm for comparison. In the comparison, if the templates are sufficiently similar based on the defined limits, for example, by a publisher or application entity requesting authentication, the image captured by the smart device (device identification) and the previously captured image (root identification) can be considered matching in step 1711. Thus, the person is who they claim to be and the identity is verified.Access may then be granted, or the commercial transaction completed, the trip authorized, or any other activity authorized, or the registration / enrollment process may be completed based on the matching images or modeled in step 1713. If there is no match in step 1711, access is denied in step 1715.
[0249] As described above, trusted biometric information (profile or template) is sent from a remote server to the authentication device. In other embodiments, other data exchange schemes are possible. In one embodiment, trusted biometric information stored on a root identification server 1630 and authentication biometric information (captured during an authentication session) are uploaded to the root identification server 1630. The root identification server 1630 is equipped with memory (storage software - machine-readable code) and a processor is configured to execute authentication algorithms. The authentication algorithms can be for identity verification, proof of life, or both. The results of the authentication request are returned to the authentication device, which can be any of the servers or devices shown in Figure 16. Petition 870260077099, dated 03 / 08 / 2026, p. 95 / 246 90 / 113
[0250] In another embodiment, a 1612 authentication device (or server) initiates an authentication session. Biometric authentication data is captured and processed. The resulting biometric authentication information is uploaded to a 1650 authentication server. The 1650 authentication server is configured with memory, machine-readable code, and a processor, and is configured to process / compare biometric information as part of an authentication session. After the authentication session begins, the 1650 authentication server obtains root biometric identification information corresponding to the user; the authentication retrieves root biometric identification information for the user. The root biometric identification information can be stored on the 1650 authentication server or requested and received from the root identification server.In some cases, such as with government-controlled identity data, the root biometric identification information may be stored on a secure government server that acts as the root identification server. Upon receiving the root biometric identification information from the root identification server 1630, the authentication server 1650 performs identity verification by comparing the root biometric identification information with the authentication biometric information (the profile information or the template).
[0251] In another embodiment, authentication (including liveness termination, identity verification, or both) occurs on the authentication device and on a remote server, such as the authentication server or the root identification server. In this configuration, the smart device will receive the biometric information from the authentication session captured from the user and also the trusted root identification information from the root identification server, and then make a comparison to determine if there is a match. If Petition 870260077099, dated 03 / 08 / 2026, page 96 / 246 If there is a match between 91 / 113, then the biometric information captured by the smart device (biometric information capture device of the authentication session) will be sent to authentication server 1650 from root identification server 1630, and the processing and comparison will be repeated there. This provides a double verification process and would prevent the smart device from accurately or fraudulently reporting a successful authentication.
[0252] It is also contemplated that proof-of-life determination can occur in all these modalities as part of authentication. While identity verification against trusted root identification information is a valuable part of the process, so is proof-of-life determination. Thus, it is contemplated that identity verification can occur independently, proof-of-life determination can occur independently, or both can occur as part of a verification session. In one modality, and as discussed above, proof-of-life detection is a comparison between two images of the user captured at different distances between the user and the camera (due to a change in the distance between the camera and the user from either camera movement, user movement, or both). In one modality, proof-of-life detection occurs before identity verification.It can serve as a prerequisite that must successfully occur before identity verification is attempted. In an exemplary embodiment, liveness detection occurs as described herein. If the process determines that another person is attempting authentication, then the authentication session is terminated and no additional biometric information is collected, and the trusted root identification information is not downloaded and compared, or the biometric information captured by the smart device is not uploaded to the authentication server or root identification server. Alternatively, if the liveness determination determines that the person who... Petition 870260077099, dated 03 / 08 / 2026, page 97 / 246 92 / 113 conducts the authentication session if a live person is involved, then the root biometric information is retrieved from the root biometric server, or the biometric information collected during authentication is sent to the authentication server or root identification server for identity verification. Using liveness termination as a prerequisite before identity verification provides several benefits. These benefits include the elimination of personal biometric data information from the network, reduced bandwidth usage, faster authentication session completion, and less overhead on the processing resources of the authentication server or root identification server, thus saving costs by requiring less network and server resources.
[0253] The benefits of this system include, but are not limited to, the ability to match previously captured biometric data from a different device with a new device, while no biometric data leaves the new device during the matching process. This is important in some regulatory environments and sectors.
[0254] For facial recognition systems with a server component, the same facial recognition algorithm can be loaded onto the server as it is running in an application on the smart device. This allows only the template to be transferred to the device instead of the biometric reading itself (e.g., facial images, fingerprint scans, etc.). For example, in step 1705, the biometric information could be the biometric template instead of an image of the root identification profile. Algorithms located on different devices / servers must be configured so that the created templates are homogeneous and comparable. That is, if the algorithms output data in different formats, the resulting biometric data / template format is incompatible, and no matching can occur because similar facial features would not be represented by patterns. Petition 870260077099, dated 03 / 08 / 2026, p. 98 / 246 93 / 113 of similar biometric template data. The term template is defined here as biometric data points represented by a sequence of numbers or other data formed in a consistently formatted pattern, such that similarities and differences can be determined through various comparison methods.
[0255] In an embodiment where no template is transferred to the device, the root identification established in step 1703 may include a biometric template created from a biometric algorithm, such as a facial recognition algorithm. For example, an image that includes an individual's face captured with a trusted device (camera 1632 in a bank branch, DMV, etc.) is sent to the server 1630, where it is converted into a biometric template with a facial recognition algorithm. As mentioned above, the biometric template of the root identification profile is sent to the smart device 1612 upon an authentication request in step 1705. This may be referred to as the root identification biometric template. The method proceeds as explained previously with reference to Figure 17, where the biometric templates are compared in step 1709.
[0256] In another example, two or more biometric modalities could be used together, such as fingerprints, face, and voice. Another example of the method in Figure 17 using two or more biometric modalities might work as follows. First, images of a user's face, scans of the user's fingerprints, as well as a recording of the user's voice are captured with trusted devices in step 1701 (e.g., devices 1632, 1634 in a bank branch, a DMV, etc., where the identity of the captured data is verified) to establish a root identification in step 1703. The images, scans, and records can be considered root identification biometric data, as this information is captured from a trusted source. In Petition 870260077099, dated 03 / 08 / 2026, page 99 / 246 94 / 113 step 1707, the smart device user (1) presses one or more of their fingers on a fingerprint sensor and / or takes a photograph of their fingers; (2) articulates the camera so that the user's face can be captured by the device's camera; and / or (3) speaks words into the device's microphone to be recorded. The data recorded by the device may be considered biometric identity data of the device.
[0257] Root identification biometric data and device identity biometric data are converted into biometric templates (root identification biometric templates and device identity biometric templates) by fingerprint recognition, facial recognition, and / or voice recognition algorithms. In some cases, root identification biometric data may be converted into root identification biometric templates on the server, and the templates may be sent to the device. Root identification biometric templates and device identity biometric templates are compared in step 1709, and if the templates are sufficiently similar based on defined boundaries, for example, by an application publisher, the root identification templates and device identity templates may be considered a match.Based on the correspondence, access may be granted or a registration / enrollment process may be completed in step 1713.
[0258] In another mode, in step 1709, the user device's biometric images and / or template(s) can be transferred to the server, where they can be stored and / or compared with the root identification biometric templates and / or images. Then, if the user wishes to replace the original device or add a second user device to the account, both the root identification image(s) and / or template(s) and the device identity image(s) and / or template(s) captured on the first device can be sent to the second device during setup or registration for comparison and matching. Petition 870260077099, dated 03 / 08 / 2026, page 100 / 246 95 / 113 This links the server's root ID to the device's first identity and, again, to the device's second identity. If no root ID image and / or template has been previously captured and stored on the server, the image and / or template that is uploaded from the first device can still provide additional security. If the user chooses to add a second device to an account, the image(s) and / or template(s) from the first device can be sent to the second device, and the comparison described above can occur again by the user using the second device to authenticate. Authentication compares the biometric information sent from the first device to the second device with the user's biometric data captured using the second device to verify that it is the same user.This allows the user to add a second device with greater security, as the user identities on both devices were considered to match.
[0259] Furthermore, when the image(s) and / or template(s) are uploaded to the server, server-side comparisons between the image(s) and / or template(s) can be performed independently of a comparison performed directly on the device. This offers a significant increase in security because, even if a hacker could manipulate the user's device to send a "matching" result back to the server, the server would also compare the same image(s) and / or biometric template(s). Therefore, authentication can occur on two or more devices or servers to make the system more secure. If fewer than all or a predetermined number of devices / servers fail to authenticate, then a match is not declared. Thus, the server would also need to determine if the image(s) and / or biometric template(s) were matching using the same boundaries.Therefore, the hacker not only needs to compromise the user's device, but also one or more servers to defeat the security. Petition 870260077099, dated 03 / 08 / 2026, page 101 / 246 96 / 113
[0260] In addition to biometric matching, liveness checks can be included on the device side of the matching as well as on the server side, as described in detail above. For example, additional information such as device movement, skin texture, three-dimensional depth information can be used to help determine whether the biometric data presented to the camera is from a living human being and not a fake photo, video, or mask. Remote Image Collection / Biometric Models
[0261] To verify biometric data, it is typically necessary for an individual to enter a bank branch, a government office such as a DMV or police station, or another “trusted” location to have their biometric data collected. For example, a bank may require a photograph, a fingerprint, or a voice recording to open certain types of accounts. The biometric data obtained is then linked to the person and the account. This in-person biometric data collection has typically been required because there was no other way to trust that an individual was indeed who they claimed to be. Through in-person collection, identification is verified, for example, by the person providing documents with their name and photograph issued by a governing body.
[0262] However, according to an exemplary embodiment disclosed herein, an individual may provide their own biometric data using any smart device with a biometric sensor or camera to be verified without in-person verification. Indeed, according to the embodiments disclosed, companies, organizations, government entities, accountability institutions, or financial institutions can trust with greater certainty than ever that the biometric data provided is from the correct individual and not from an imposter, hacker, or bad actor.
[0263] Figure 18 presents a method for remotely establishing a Petition 870260077099, dated 03 / 08 / 2026, page 102 / 246 97 / 113 Biometric identity, according to an exemplary embodiment. In this embodiment, an individual first downloads an application to their smart device from an institution with which they have an account, or with which they wish to open an account in step 1801. Upon opening the application and when prompted, the person presents their face, fingerprint, etc. to the camera or sensor. The biometric data is captured and stored on the device as “registration data” in step 1803. This process is described above in detail as the registration process or the storage of baseline biometric information. In some embodiments, the registration data is sent to a server and stored on a server or database.
[0264] Next, the user makes a payment or deposit to the institution in step 1805. For example, if a credit institution provided a mortgage to the user, the user would enter their payment account information into the application so that the institution could collect the payment. When the payment information and authorization are transmitted to the credit institution, some or all of the user's biometric registration data is collected and transferred to the credit institution's server along with it. Since the payment is made by the user for the user's debt, causing the money to leave the user's account and therefore not occurring through a potential hacker or fraudster, the resulting biometric data collected as part of the transaction is considered reliable. This step can be defined as performing an action that is detrimental to the user or an action from which the user does not benefit.Although this action may involve cash payments to third parties, it could also be an action such as performing a service or task, filing taxes, having a medical check-up, donating blood, taking a DNA test or sample, or any other event that a person intending to commit fraud would likely not do repeatedly. Petition 870260077099, dated 03 / 08 / 2026, page 103 / 246 98 / 113
[0265] Subsequently, when the user reopens the application to perform another transaction (such as payment or other action), the user is again prompted, as part of the payment, to present their biometric information to the camera or sensor, and new biometric templates may be created in step 1807. The new biometric templates are compared with the previous “registration data” on the device and / or the new templates may be sent to the server for comparison in step 1809. In some modes, the device may compare the templates by downloading the registration data templates from the server to the device for matching. Or the newly acquired template may be sent to an authentication server for comparison with the registration templates (biometric information) or previously recorded templates (biometric information).
[0266] If it is determined that the new biometric information and / or models do not match the registration data, then the transaction may be denied, as shown in step 1811, and the root ID will not have the mismatched biometric information added to it. Or the transaction may be completed, but the new mismatched biometric information is not added to the database, or the account may be flagged for a failed attempt to match biometric information. However, when the new biometric information sufficiently matches the registration data, the transaction may be authorized as shown in step 1813. Furthermore, when there is a match, the confidence level of the biometric data attached to the user profile is increased.
[0267] Since, in this modality, the user is sending funds to the account, for example, to pay a debt or to make a deposit, he / she (the user) has an incentive to be able to access the account containing these funds later or to have the debt reduced. Thus, over time, as Petition 870260077099, dated 03 / 08 / 2026, page 104 / 246 99 / 113 where multiple deposits and / or payments are made with matching biometric templates, trust in the identity of the user performing the transactions increases, as shown in the cycle of steps 1807, 1809, and 1813. Trust is high because a person attempting to commit fraud or identity theft is unlikely, now or in the future, to pay other people's debts (invoices) or perform other actions that do not benefit them or that cause them harm (such as, for example, a payment). This also provides repeated links or association between the user and the account to build trust that the user is who they claim to be associated with that account.
[0268] The resulting biometric information can be subsequently used in other environments and applications beyond that account after it becomes trusted. For example, once trust is built with a biometric profile for a user, that same biometric profile can be considered trusted and used for purchases or access control.
[0269] In one embodiment, to limit liability to third parties or other entities, access to withdrawals even for a trusted biometric profile may be limited to the same amount or less than the total amount deposited or paid by the user. For example, if a user makes a mortgage payment, loan payments, or bank deposits totaling $3,000 every month for three months using their smart device and using their face to identify themselves each time, the financial institution may be willing to allow that person to transfer up to $9,000 (or some other amount related to the trusted payments made) from a different account the bank holds for the user, such as a checking account. Similarly, if a trusted biometric profile is established, it may receive a trust score, which designates the amount or degree of trust associated with that trusted biometric profile.Based on the trust score, third parties, such as companies and suppliers, Petition 870260077099, dated 03 / 08 / 2026, page 105 / 246 100 / 113 government agencies can make decisions about how to do business with that user or how much to lend or sell them based on that trust score. For example, a different limit for the trust score may be set and the trust score must meet those limits (based on a comparison) before money is lent, a credit card is issued, or a product is sold / provided to the user, before an identification card is issued, or before access is granted to a secure location.
[0270] As banks and other credit institutions report outstanding balances, credit limits, and payment terms to credit bureaus, it is anticipated that the bank will also provide the biometric template (possibly in encrypted format) to a credit bureau, government entity, or other entity for storage as part of the identification information in the user's credit file. Then, if the user wishes to apply for credit from a different institution, that institution may require the user to access its version of the application with the same biometric data collection system (and / or trust score) used to create and maintain the template. Biometric templates may be sent to credit bureau servers and compared to the templates on file for that individual.With this process, the user can positively identify themselves and grant the financial institution access to view their credit information without providing or transmitting their CPF number (Brazilian taxpayer ID), date of birth, or other confidential information.
[0271] If a user does not have an outstanding debt to the account issuer or the issuer is not a financial institution, it is possible to simply offer a temporary deposit service (or other trust-building process) to provide assurance that the biometric data provided is true and correct for the claimed user. For example, a user might provide a credit card number with their name and address, the card could be charged $100, and the user Petition 870260077099, dated 03 / 08 / 2026, page 106 / 246 101 / 113 would provide their biometric data to the application on their smart device. The user would then correctly answer a series of knowledge-based authentication questions using their credit report, insurance information, medical information, or other potentially confidential information, and provide their biometric data back to the application to retrieve the funds or match them with biometrics stored in a trusted database or other means. The result is a biometric identity that can be trusted in future transactions up to the amount that was previously placed on deposit and successfully retrieved. In this way, credit can be offered up to the deposit amount or some amount based on the escrow account balance.
[0272] Although described in financial terms, it is also contemplated that other actions can be used to build trust that the biometric information captured when the action occurs and the resulting trusted biometric profile, developed over time, are accurate and reliable. For example, in one embodiment, the authentication system can be used as an access control or time tracking system at a person's workplace. Every time the user enters the workplace or building using the system for access control, their biometric information is captured and used to build trust in their identity. It is assumed that the person showing up for work is the real person and not someone attempting to commit fraud or establish a false identity.Similarly, this process can occur in a doctor's office as part of a medical exam, a dental office, a money donation, obtaining or renewing a driver's license or passport, attending school, or any other activity that would not be undertaken by a person attempting to commit fraud. GPS data can be combined with this process to verify whether a person clocking in is actually at the workplace. Decentralized Biometric Identity Ledger Petition 870260077099, dated 03 / 08 / 2026, page 107 / 246 102 / 113
[0273] There are numerous security and privacy benefits to an anonymous, decentralized biometric identity network compared to biometric authentication conducted on a centralized database or solely on a user device. As explained earlier, biometric identity information can comprise images with biometric data, such as digital photographs of a face or fingerprint, and / or biometric templates which are sequences of numbers representing data that have been captured by a sensor and converted into a sequence by a biometric recognition algorithm.
[0274] Decentralized Ledgers, such as Blockchains, Tangles, HashGraphs, etc., referred to below in Blockchains, can be used to create public or private ledgers that provide an immutable transaction history. The blocks can store various data and, in this embodiment, the blocks can store biometric data in the form of an image or a biometric model created from a biometric sensor (camera, fingerprint scanner, etc.) and / or an algorithm that analyzes an output from the biometric sensor (photograph, fingerprint scan, etc.). Figure 19 presents a biometric authentication system using a blockchain, according to an exemplary embodiment.
[0275] In an exemplary biometric authentication method, a smart device 1912 would run an application enabling a sensor 1916 or camera 1914 to capture biometric data and optionally convert the biometric data into one or more biometric templates. The biometric data and / or templates would be added to an encrypted block along with additional information such as a device ID, a unique user ID, user identity information, algorithm / sensor type / version information, date and time, GPS information and / or other data. Petition 870260077099, dated 03 / 08 / 2026, page 108 / 246 103 / 113
[0276] The block can be added to the 1940 blockchain, where it is stored. If the user attempts to open the application again or provide the public key or a unique user identifier that matches the block's public key in another application, then the user is again presented with the biometric data capture interface through which the user again presents their biometric data to the 1619 sensor or 1914 camera. The captured biometric data can optionally be converted into a biometric template on the 1912 device. Then, the user's previous block is requested from the 1940 blockchain and downloaded to the 1912 smart device, where a private key can be held in the application to decrypt the block. The block's biometric data and / or template(s) can now be compared with the newly captured biometric data and / or template(s).If a match is found, then the user will be authenticated and will have access to the application, will be able to make a transaction, etc., and the successful decoding of the block and the matching of the models can be recorded with any combination of the data, the transaction, the original model, the most recently matched model, or both can be stored in the new block.
[0277] Additionally, or as an alternative to the comparison and matching being done on the 1912 device, the comparison and matching can be completed on the 1940 blockchain registry servers. In this case, the biometric data obtained on the 1912 user device and / or biometric templates generated on the 1912 user device from the biometric data are encrypted and sent to the 1940 blockchain registry servers. Then, the public key and the private decryption key can be sent to the 1940 blockchain registry servers to decrypt one or more previous blocks of biometric information and / or user templates, as well as to decrypt the most recently acquired biometric data and / or templates. Petition 870260077099, dated 03 / 08 / 2026, page 109 / 246 104 / 113 sent. The 1940 blockchain registry servers then run matching algorithms to determine if the biometric information and / or templates stored in the blockchain and the most recently collected biometric information and / or templates are considered compatible by the limits previously defined in the matching algorithm. By providing template matching across all 1940 blockchain registry servers (which may be hundreds or thousands of servers), an account provider can be certain that the 1912 device running the application has not been compromised if the matching results are the same from the 1940 blockchain registry servers. The 1912 device and all 1940 blockchain registry servers would have to be compromised simultaneously for a hacker to alter them all, which, of course, would be highly improbable, if not impossible.
[0278] In yet another embodiment, a dedicated “correspondence server” 1950 could be employed, to which a copy of both the newly collected biometric information and / or templates from the device and the biometric information and / or templates in the block would be sent. The device 1912 could provide the decryption key directly to the corresponding server 1950, or the blockchain 1940 could be instructed to send the encrypted biometric template(s) to the corresponding server with a “smart contract,” which is a set of computer instructions encoded in the block. This is a feature of blockchains with decentralized processing capabilities such as Ethereum.
[0279] It is also foreseen that when a new device requests a lock using a unique user ID, for example, an email address, phone number, or public key, the device is only authorized to download blocks in the chain that contain biometric user templates that are associated with that unique ID because the device holds the private keys. Petition 870260077099, dated 03 / 08 / 2026, page 110 / 246 105 / 113 Thus, the user's most recent models can be compared with all models that have been captured and stored in the blockchain, allowing for multiple matches. This can provide fewer false rejections of the correct users that may result from changes in appearance due to lighting, aging, makeup, hair, beard, glasses, etc.
[0280] In a system configuration and method disclosed herein, there is a private key, and the private key will decrypt the block's contents, but the biometric data within the block is what is used in the comparison to determine if there is a match between new biometric data and stored biometric data. Thus, the private key is required to gain access to the biometric data block. The private key can be created by the user, by the system, or the private key can correspond to a combination of unique identifiers that are easier to remember, such as a phone number, a CPF number (Brazilian tax identification number), an email address, and a date of birth, etc., and thus also unique to the user. In this configuration, it is possible and contemplated that there are two block chains, one containing personal data, and one with anonymous storage of biometric templates only.The personal data blocks in the first blockchain would be decrypted by a private key or matching personal data combinations that only you know, and which you share only with specific vendors you want to be able to verify that identity. Then, within that data, the number(s) of another block(s) containing your biometric data is appended to that record, and then the application can unlock that block and associate / update your newly uploaded biometric data to the data in that biometric block.
[0281] In addition to biometric matching, the application that collects biometric data can perform liveness tests on the collected biometric data, such as those described above. If it is proven that the user exhibits traits that normally Petition 870260077099, dated 03 / 08 / 2026, page 111 / 246 106 / 113 only exist in living human beings at the exact moment their identity is verified, therefore, biometric data can be trusted as being from a real human being, not from a non-living object, such as a photo or video forgery.
[0282] Figure 20 is a schematic of a computing or mobile device, or server, such as one of the devices described above, according to an exemplary embodiment. Figure 20 presents an example of a computing device 2070 and a mobile computing device 2050, which can be used with the techniques described herein. The computing device 2070 is intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other suitable computers. The computing device 2050 is intended to represent various forms of mobile devices, such as personal digital assistants, cell phones, smartphones, and other similar computing devices.The components shown here, their connections and relationships, and their functions, are intended as examples only and should not limit the implementations described and / or claimed in this document.
[0283] The computing device 2070 includes a processor 2002, memory 2004, a storage device 2006, a high-speed interface or controller 2008 connecting to memory 2004 and high-speed expansion ports 2010, and a low-speed interface or controller 2012 connected to low-speed bus 2014 and storage device 2006. Each of the components 2002, 2004, 2006, 2008, 2010, and 2012 is interconnected using various buses and can be mounted on a common motherboard or in other ways as appropriate. The processor 2002 can process instructions for execution within the computing device 2070, including instructions stored in memory 2004 or storage device 2006 to display graphical information to a GUI on an external input / output device, such as Petition 870260077099, dated 03 / 08 / 2026, page 112 / 246 107 / 113 as the 2016 display coupled to the 2008 high-speed controller. In other implementations, multiple processors and / or multiple buses may be used, as appropriate, along with multiple memories and memory types. Furthermore, several 2070 computing devices may be connected, with each device providing portions of the necessary operations (e.g., as a server bank, a blade server group, or a multiprocessor system).
[0284] Memory 2004 stores information within computing device 2070. In one implementation, memory 2004 is a volatile memory unit or units. In another implementation, memory 2004 is a non-volatile memory unit or units. Memory 2004 may also be another form of computer-readable media, such as a magnetic or optical disk.
[0285] Storage device 2006 is capable of providing mass storage for computing device 2070. In one implementation, storage device 2006 may be or contain a computer-readable medium, such as a hard disk drive, an optical disk drive or tape drive, a flash memory or other similar solid-state memory device, or an array of devices, including devices in a storage area network or other configurations. A computer program product may be tangibly embodied in an information carrier. The computer program product may also contain instructions that, when executed, perform one or more methods, such as those described above. The information carrier is a computer-readable or machine-readable medium, such as memory 2004, storage device 2006, or memory in processor 2002.
[0286] The high-speed controller 2008 manages bandwidth-intensive operations for the computing device 2070, while the low-speed controller 2012 manages less resource-intensive operations. Petition 870260077099, dated 03 / 08 / 2026, page 113 / 246 108 / 113 bandwidth. This allocation of functions is merely illustrative. In one implementation, the high-speed controller 2008 is coupled to memory 2004, display 2016 (e.g., via a processor or graphics accelerator), and high-speed expansion ports 2010, which can accept various expansion cards (not shown). In the implementation, the low-speed controller 2012 is coupled to storage device 2006 and low-speed bus 2014. The low-speed bus 2014, which may include various communication ports (e.g., USB, Bluetooth, Ethernet, wireless Ethernet), can be coupled to one or more input / output devices, such as a keyboard, a pointing device, a scanner, or a network device, such as a switch or router, for example, via a network adapter.
[0287] The computing device 2070 can be implemented in several different ways, as shown in the figure. For example, it can be implemented as a standard server 2020 or multiple times in a group of such servers. It can also be implemented as part of a rack server system 2024. In addition, it can be implemented in a personal computer, such as a laptop 2022. Alternatively, the components of the computing device 2070 can be combined with other components in a mobile device (not shown), such as the device 2050. Each of these devices can contain one or more computing devices 2070, 2050, and an entire system can consist of multiple computing devices 2070, 2050 that communicate with each other.
[0288] The computing device 2050 includes a processor 2052, memory 2064, an input / output device, such as a display 2054, a communication interface 2066, and a transceiver 2068, among other components. The device 2050 may also be supplied with a storage device, such as a microdrive or other device, to provide additional storage. Each of the Petition 870260077099, dated 03 / 08 / 2026, page 114 / 246 The 109 / 113 components 2050, 2052, 2064, 2054, 2066, and 2068 are interconnected using multiple buses, and several of the components can be mounted on a common motherboard or in other ways, as appropriate.
[0289] The 2052 processor can execute instructions within the 2050 computing device, including instructions stored in memory 2064. The processor can be implemented as a chip set that includes multiple separate analog and digital processors. The processor can provide, for example, coordination of the other components of the 2050 device, such as control of user interfaces, applications executed by the 2050 device, and wireless communication by the 2050 device.
[0290] The 2052 processor can communicate with a user through the 2058 control interface and the 2056 display interface coupled to a 2054 display. The 2054 display can be, for example, a TFT LCD (Thin-Film Transistor Liquid Crystal Display) or an OLED (Organic Light-Emitting Diode) display, or other suitable display technology. The 2056 display interface may comprise a suitable circuit to drive the 2054 display to present graphical and other information to a user. The 2058 control interface can receive commands from a user and convert them for transmission to the 2052 processor. In addition, an external interface 2062 can be provided in communication with the 2052 processor, so as to allow near-area communication of the 2050 device with other devices.The 2062 external interface can provide, for example, wired communication in some implementations, or wireless communication in other implementations, and multiple interfaces can also be used.
[0291] Memory 2064 stores information within the computing device 2050. Memory 2064 can be implemented as one or more of a computer-readable medium, a volatile memory unit or units, or a non-volatile memory unit or units. Expansion memory 2074 Petition 870260077099, dated 03 / 08 / 2026, page 115 / 246 110 / 113 can also be supplied and connected to the 2050 device via the 2072 expansion interface, which may include, for example, a SIMM (Single In-Line Memory Module) card interface. Such 2074 expansion memory may provide extra storage space for the 2050 device, or it may also store applications or other information for the 2050 device. Specifically, the 2074 expansion memory may include instructions to execute or supplement the processes described above and may also include secure information. Thus, for example, the 2074 expansion memory may be supplied as a security module for the 2050 device and may be programmed with instructions that allow for the secure use of the 2050 device. Furthermore, secure applications may be supplied via SIMM cards, along with additional information such as placing identification information on the SIMM card in a way that is not hackable.
[0292] Memory may include, for example, flash memory and / or NVRAM memory, as discussed below. In one implementation, a computer program product is tangibly embedded in an information carrier. The computer program product contains instructions that, when executed, perform one or more methods, such as those described above. The information carrier is a computer-readable or machine-readable medium, such as memory 2064, expansion memory 2074, or memory in the processor 2052, which may be received, for example, by transceiver 2068 or external interface 2062.
[0293] The 2050 device can communicate wirelessly via the 2066 communication interface, which may include digital signal processing circuitry when necessary. The 2066 communication interface can provide communications under various modes or protocols, such as GSM voice calls, SMS, EMS or MMS messages, CDMA, TDMA, PDC, WCDMA, CDMA2000 or GPRS, among others. Such communication can occur, for example, via the transceiver of Petition 870260077099, dated 03 / 08 / 2026, page 116 / 246 111 / 113 radio frequency 2068. In addition, short-range communication may occur, such as with the use of Bluetooth, Wi-Fi, or another transceiver (not shown). Furthermore, the GPS (Global Positioning System) receiving module 2070 may provide additional wireless navigation and location-related data to device 2050, which may be used as appropriate by applications running on device 2050.
[0294] The 2050 device can also communicate audibly using the 2060 audio codec, which can receive spoken information from a user and convert it into usable digital information. The 2060 audio codec can also generate audible sound for a user, such as through a speaker, for example, on a portable device of the 2050 device. This sound can include sound from voice telephone calls, can include recorded sound (e.g., voice messages, music files, etc.), and can also include sound generated by applications operating on the 2050 device.
[0295] The 2050 computing device can be implemented in a variety of different forms, as shown in the figure. For example, it can be implemented as a 2080 mobile phone. It can also be implemented as part of a 2082 smartphone, personal digital assistant, a tablet, or other similar mobile device.
[0296] Thus, various implementations of the systems and techniques described herein can be carried out in digital electronic circuits, integrated circuits, specially designed ASICs (application-specific integrated circuits), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementation in one or more computer programs that are executable and / or interpretable in a programmable system including at least one programmable processor, which may be special-purpose or general-purpose, coupled to receive data and instructions from and to transmit data. Petition 870260077099, dated 03 / 08 / 2026, page 117 / 246 112 / 113 and instructions for a storage system, at least one input device and at least one output device.
[0297] These computer programs (also known as programs, software, software applications, or code) include machine instructions for a programmable processor and may be implemented in a high-level procedural and / or object-oriented programming language, and / or assembly / machine language. As used herein, the terms “machine-readable medium” and “computer-readable medium” refer to any computer program product, apparatus, and / or device (e.g., magnetic disks, optical disks, memory, Programmable Logic Devices (PLDs)) used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term “machine-readable signal” refers to any signal used to provide machine instructions and / or data to a programmable processor.
[0298] To provide interaction with a user, the systems and techniques described herein may be implemented on a computer with a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) to display information to the user, and a keyboard and pointing device (e.g., a mouse or a trackball) by which the user may provide input to the computer. Other types of devices may also be used to provide interaction with a user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and user input may be received in any form, including acoustic, speech, or tactile input.
[0299] The systems and techniques described here can be implemented in a computing system (e.g., 2070 and / or 2050 computing device) that includes a back-end component (e.g., such as a data server) or Petition 870260077099, dated 03 / 08 / 2026, page 118 / 246 113 / 113 which includes a middleware component (e.g., an application server) or which includes a front-end component (e.g., a client computer with a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein) or any combination of such back-end, middleware, or front-end components. The system components may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (“LAN”), a wide area network (“WAN”), and the Internet.
[0300] A computer system may include clients and servers. A client and a server are usually remote from each other and typically interact through a communication network. The client-server relationship arises by virtue of computer programs running on the respective computers and having a client-server relationship with each other.
[0301] Although several embodiments of the invention have been described, it will be evident to those skilled in the art that many more embodiments and implementations are possible, which are within the scope of the present invention. Furthermore, the various features, elements and embodiments described herein may be claimed or combined in any combination or arrangement. Petition 870260077099, dated 03 / 08 / 2026, page 119 / 246
Claims
1 / 6 CLAIMS 1. Method for verifying biometric authentication CHARACTERIZED in that it comprises: receiving root biometric identification information, corresponding to a user (108), from a trusted biometric information source to establish the root biometric identification information that is trusted and verified by an entity; storing the root biometric identification information in a database (124); subsequently, during an authentication process: capturing a first image with an authentication camera, the first image captured when the user (108) is at a first distance from the authentication camera; capturing a second image with the authentication camera, the second image captured when the user (108) is at a second distance from the authentication camera, such that the first distance is different from the second distance and the first image and the second image include a face of the user (108);process the first image to create the first biometric authentication information; process the second image to create the second biometric authentication information; compare the first biometric authentication information with the second biometric authentication information; compare the root biometric identification information with the first biometric authentication information, the second biometric authentication information, or both; authenticate the user (108) when: the comparison determines that the first biometric authentication information matches the second biometric authentication information within Petition 870260077099, dated 03 / 08 / 2026, page 120 / 246 2 / 6 a limit, but are not identical due to distortion causing the first image or the second image to be distorted;The comparison determines whether the root biometric identification information matches the first biometric authentication information, the second biometric authentication information, or both within a given limit.
2. Method according to claim 1, CHARACTERIZED in that the authentication camera is one of the following camera types: camera in a user's mobile device (112), camera in a user's computer, camera in an ATM, camera in a point of sale and camera in a financial institution.
3. Method, according to claim 2, CHARACTERIZED in that the reliable source of biometric information is a first camera on a reliable source.
4. Method according to claim 3, CHARACTERIZED in that the first camera is located in a financial institution.
5. Method according to claim 3, CHARACTERIZED in that the first camera is located in a government agency office.
6. A method according to claim 3, characterized in that an authentication server receives the root biometric identification information, the first biometric authentication information, and the second biometric authentication information, and the authentication server performs the comparison.
7. Method, according to claim 1, CHARACTERIZED in that it further comprises performing one or more additional liveness tests on the first image or the second image to verify that the user (108) is a living person during the authentication process.
8. Method for verifying biometric authentication of a user (108) CHARACTERIZED in that it comprises: Petition 870260077099, dated 03 / 08 / 2026, page 121 / 246 3 / 6 storing root biometric identification information of the user (108) obtained from a trusted biometric detection device that is located in a trusted location to establish the root biometric identification information as trusted and verified, the root biometric identification information based on at least one facial image of the user (108) and at least one user identification information item; during an authentication session: receiving root biometric identification information on a first computing device;generate biometric authentication identification information from at least one first image captured at a first distance from the user (108) and a second image captured at a second distance from the user (108) such that the first image and the second image of the user (108) are captured with an image capture device of the first computing device or of a second computing device during an authentication session; compare, with the first computing device, the root biometric identification information with at least a part of the biometric authentication identification information; compare the first image with the second image to determine if the first image or the second image is distorted due to the change in distance; and authenticate the user (108) when: the root biometric identification information matches the biometric authentication identification information within a predetermined limit;and the first image or the second image is distorted due to the change in distance between the user (108) and the image capture device of Petition 870260077099, of 03 / 08 / 2026, page 122 / 246 4 / 6 first distance to second distance.; 9. Method, according to claim 8, CHARACTERIZED in that the reliable biometric detection device is located in one of the following places: financial institution, retail point of sale or government entity.
10. Method according to claim 8, CHARACTERIZED in that the computing device used during an authentication session is located in a financial institution, ATM, point of sale, or is the user's mobile device (112) or personal computer (108).
11. Method according to claim 8, CHARACTERIZED in that the reliable biometric detection device includes a camera, and the computing device used during an authentication session includes a camera.
12. Method according to claim 8, CHARACTERIZED in that it further comprises: capturing complementary authentication biometric identification information of the user (108) during the authentication session; comparing the complementary authentication biometric identification information with the authentication biometric identification information; comparing the complementary authentication biometric identification information with the root biometric identification information; authenticating the user (108) when: the comparison determines that the authentication biometric identification information matches the complementary authentication biometric information within a first limit, but they are not identical; the comparison determines that the root biometric identification information matches the complementary authentication biometric information within the predetermined limit.
13. Identity authentication system CHARACTERIZED by the fact that Petition 870260077099, dated 03 / 08 / 2026, page 123 / 246 5 / 6 comprises: a first computing device configured to request and receive root biometric identification information, for a user (108), from a trusted source, the trusted source comprising a government-affiliated entity or a financial institution;a second computing device configured to, during an authentication session: create biometric authentication information captured from the user (108) during the authentication session, wherein the biometric authentication information is derived from at least one first image and one second image that are captured by a camera associated with the second computing device, the first image captured by the camera located at a first distance from the user (108) and the second image captured by the camera located at a second distance from the user (108), the second distance being less than the first distance; compare at least part of the biometric authentication information with the root biometric identification information;perform a liveness determination on the user (108) during the authentication session using the authentication biometric information, wherein one aspect of the liveness determination comprises determining whether the first image or the second image has distortion due to change in distance; in response to the comparison and execution, authenticate the user (108) if: the comparison determines that the authentication biometric information matches the root biometric identification information within a limit; and the liveness determination determines that the user (108) is a living person.
14. System, according to claim 13, CHARACTERIZED by the fact that the root biometric identification information is derived from an image.
15. System, according to claim 14, CHARACTERIZED in that an image of the user (108) may not be recreated from the root biometric identification information.
16. System according to claim 13, CHARACTERIZED in that the first computing device and the second computing device are the same computing device. Petition 870260077099, dated 03 / 08 / 2026, pp. 125 / 246