← Showcase homePage status: Research · synthetic demo only

Verify · Research

Checking that a person is present — without overclaiming

A research design for voluntary, consented, one-to-one check-in. It combines cardiac and optical pulse measurements with document, credential and session checks — and keeps every result honest about what it cannot know.

Research only. Nothing here identifies anyone. The demonstration uses synthetic signals, its matcher returns not_evaluated, and every receipt states valid_for_authentication: false. No accuracy figures exist and none are claimed. This must never become a condition for voting.

The core idea

Four decisions, kept separate

None of these establishes the others. A real, living person can still present someone else's identity, and a correct identity match does not establish eligibility for anything.

Four separate decisions Presence: is there evidence of a live person at this session? Identity: does that person match the claimed, properly enrolled identity? Session integrity: did fresh evidence come from the expected devices without substitution? Eligibility or authorisation: does the responsible authority permit this action? Each is decided separately; the fourth belongs only to the responsible authority. 1 · Presence Is there evidence of a live personat this capture session? 2 · Identity Does that person match the claimed,properly enrolled identity? 3 · Session integrity Did fresh evidence come from the expecteddevices, without substitution? 4 · Eligibility / authorisation Decided only by the responsible authorityunder its own rules — never by this system.

Walkthrough video

See the synthetic session

A silent recording of the browser walkthrough: consent, synthetic enrolment, five capture windows (one fails its quality check and is retried), an honest “inconclusive” comparison, and a test receipt that cannot authorise anything.

  1. Consent, with the non-biometric alternative offered first.
  2. Five capture windows: quiet baseline, two neutral prompts, a quiet pause and a final confirmation.
  3. Comparison over all usable windows by a fixed rule — never the best single match.
  4. A minimal test receipt, marked simulated and not valid for authentication.

Silent screen recording with captions.

Read the transcript
  1. 00:00 This is the synthetic verification walkthrough. It uses no camera, microphone or sensor, and nothing is saved.
  2. 00:03 Consent comes first, and the non-biometric alternative is offered before anything else.
  3. 00:07 Synthetic enrolment: a service-specific pseudonym, a synthetic identity review and a test-only credential.
  4. 00:11 Five capture windows follow. Each is checked for quality before anything else.
  5. 00:15 Window two asks the participant to read a fresh number. Typing it is an accessible alternative.
  6. 00:19 That attempt failed its quality check because of motion. A capture problem is not a judgement about the person.
  7. 00:22 A bounded retry succeeds. The flow channel stays “unavailable”: there is no qualified hardware.
  8. 00:27 All usable windows are combined by a fixed rule. The matcher returns “not evaluated”, so the result is honestly inconclusive.
  9. 00:32 The person approves exactly one synthetic action. It cannot register, verify or authorise anything.
  10. 00:36 The test receipt holds no biometrics and no ballot choice, and says valid for authentication: false.
  11. 00:41 Redeeming it twice is rejected as a replay.
  12. 00:44 A production verifier rejects it outright: test issuer, simulated evidence.

Commitments

What the research will not do

  • No public-camera identification, covert location searches or global tracking index.
  • No lie detection: a physiological reaction is not evidence of dishonesty.
  • No automatic fraud labels, roll removals or denials from a failed sensor or an unanswered message.
  • No biometric data in ballots, receipts or audit exports, and no link between identity and ballot choices.
  • No treating five windows of one session as five independent proofs.

Before any real use

Gates that must be passed first

  • Qualified hardware with raw-data access and safety documentation.
  • A reviewed adult volunteer study with repeat visits, designed with a statistician.
  • Predefined error, capture-failure and attack-acceptance measures, reported with uncertainty.
  • For any election pilot: approval by the responsible authority, jurisdiction-specific legal review and an accessible non-biometric route.

Next step: read the 21 checks or see the election evidence programme.

Behind this page

A fuller research prototype runs privately

Private · local only The BB2G Verification Lab (version 0.1.0) is a synthetic-only working prototype on the BB2G Probox. It includes the enrollment simulator, five-window capture, the 21-check registry, test-only signed receipts, a review queue and an audit room. It is not published and has no public address; this page is its public explanation.

Its own tests run on synthetic data only. Passing them does not validate any biometric method, sensor or election use.