Intellectual property

Patent
pending.

Confrmo’s verification technology is the subject of the following United Kingdom patent applications. Each one came out of a problem met while building the product rather than from a research programme. All are pending: applications, not granted patents. Each number links to that application’s own entry on the United Kingdom public register.

A common thread runs through them. Each is about what a verification system should refuse to reveal, and to whom: an attacker probing it, a business asking too many questions and someone trying to read a private list out of an error message. Verifying someone is the easy half. Doing it without leaking what you learn is the half that needs inventing.

Method and system for detecting substitution of an identity document during re-verificationGB2619016.5Someone can pass a face check using a different genuine passport that happens to look like them. Confrmo compares the photograph read from the chip today against the one read when the account was opened, so it has to be the same document, not just a convincing one.Inventor: Louis-James Davis
Method and system for limiting cumulative disclosure of a credential attribute across a plurality of predicate responsesGB2619018.1“Is this person over 18?” gives away almost nothing. Ask enough narrow questions and you have worked out the date of birth without ever being told it. Confrmo keeps a running total of what each business has learned about a person, and stops answering before the answers add up.Inventor: Louis-James Davis
Method and system for selectively uniform denial of a context-gated access request according to the probeability of each failed conditionGB2619020.7A refusal that explains itself is a set of instructions. “Wrong location” tells someone to move; “wrong day” tells them to come back tomorrow. Confrmo sorts refusals by whether naming the reason would help someone get in, and answers plainly only where it would not.Inventor: Louis-James Davis
Method and system for detecting forgery of a certification mark from unresolvable verification requests under a bounded linkability windowGB2619034.8A good forgery cannot be caught by looking at it. It shows up when people keep scanning a mark that was never issued. Confrmo treats those failed checks as the signal, so a counterfeit is found through the people it was shown to, without tracking any of them.Inventor: Louis-James Davis
Method and system for re-verifying a subject by challenges whose occurrence is decoupled from suspicion by rate modulationGB2619035.5A check that only appears when you look suspicious tells an attacker exactly where the line is, so they stay under it. Confrmo lets suspicion set how often a check happens, never whether it happens. Any check is possible for anyone, so no single one gives anything away.Inventor: Louis-James Davis
Method and system for explaining an automated decision at a disclosure tier selected according to whether the explanation would permit enumeration of a protected data setGB2619062.9Tell someone the name they want is too close to a protected brand and you have confirmed that brand is on the list. Ask again and again and the error message becomes a search tool for a private list. Confrmo decides, rule by rule, how much of a reason can safely be given back.Inventor: Louis-James Davis
Method and system for concealed class-wide escalation and disjoint notification following failed authorisationGB2619116.3A failed request can betray whether a security system noticed the attempt: a changed message, a slower reply or a tougher next check gives the attacker the answer. This application raises the authorisation requirement across every route to the same high-consequence action and alerts another authority holder over a separate channel, while returning the same ordinary refusal.Inventor: Louis-James Davis
Multi-party identity certificate with conditional disclosureGB2619195.7A certificate proving who several people are becomes a liability the moment it is forwarded, because it is legible to anyone who ends up holding it. This one is issued with the sensitive parts sealed, and they open only for a reader whose presence is vouched for by the premises they are standing in, such as a bank or a law firm, rather than by their own phone claiming a location.Inventor: Louis-James Davis
Grading of verified events by evidence qualityGB2619198.1A Wi-Fi network shared with a whole building proves someone is in the lobby, not at their desk. Most systems add that up with everything else and call it a strong record. Confrmo lets each piece of evidence set a ceiling instead, so no amount of vague evidence can ever produce a record that only precise evidence could justify.Inventor: Louis-James Davis
Continuity of identity across repeated enrolmentGB2619220.3A face enrolled at five recognises nobody at twenty-five, so anyone holding a record for decades has to re-enrol the person again and again. Each of those renewals proves who is standing there today and nothing about whether they are the person enrolled last time. Confrmo makes every renewal prove continuity with the one before it, and serves the older parts of a record only where that chain is unbroken.Inventor: Louis-James Davis
Data disclosure control in a verification systemGB2619663.4Systems decide how much of your details to hand over by asking how sensitive the field is called. That is the wrong question when the party asking could look the answer up anyway. Here what is released depends on what that party could have found out without your cooperation, so a fact anyone can read off a public register is given in full, and a fact only you could have proved is answered yes or no and never handed over.Inventor: Louis-James Davis
Verification of a device-computed result in a data processing systemGB2619665.9A face check runs on the phone, so all the server ever receives is the word 'passed'. Signing that word proves which phone said it and never that it is true. Here the phone commits to the evidence at the moment it answers, keeps it for a while, and can be asked to produce it afterwards at a moment it cannot predict. Anything granted on an answer that cannot be produced is taken back, along with everything built on it.Inventor: Louis-James Davis
Identifier allocation in a namespaceGB2619669.1Refuse a name for being too close to a protected one and the alternatives offered are usually small changes to the same name, which are still too close. Either they are refused in turn and the person is offered nothing, or they slip through a check the original never faced. Here every suggestion is put back through the rule that refused the request, and the one offered first is the person's own verified name joined to what they asked for, which says who they are instead of imitating somebody else.Inventor: Louis-James Davis
Determining qualifying interactions in a networked systemGB2619670.9Referral schemes are gamed by one person holding several accounts and introducing themselves, and every defence against it is a threshold somebody learns to sit under. Here an introduction only counts when the person introduced goes on to deal with somebody the introducer cannot reach through any chain of shared devices or instruments. It is the one condition a ring cannot arrange for itself, and adding more accounts to the ring only makes it harder.Inventor: Louis-James Davis
Attendance recording in a verification systemGB2619672.5Clocking out proves you were at the door when you said you were leaving. It does not prove you actually left. Confrmo treats a departure as a claim it keeps open rather than a fact it has established, lets the phone's own signal contradict that claim if you are in fact still on site, and never lets that signal invent a departure on its own, because a phone is not a person.Inventor: Louis-James Davis
Entitlement management in a verification systemGB2619674.1Proving you are old enough once says nothing about who is using the account afterwards, which is exactly why verified accounts get sold and shared. Confrmo never treats the link between the person who was checked and the person now using the account as settled: the phone's own signals can break that link, they are never allowed to confirm it, and the permission is tied to unbroken possession rather than to the account, so it cannot be sold on with it.Inventor: Louis-James Davis
Response control in an attribute disclosure systemGB2619675.8New rules say a company may only receive certain kinds of information about you, and everyone will police that by checking what is asked for. The leak is what can be worked out from a run of perfectly permitted answers: ask enough questions you are entitled to ask, and you end up holding something you were never authorised to have. Confrmo checks each answer against everything already given, and refuses when the combination would hand over a category the company is not registered for, even though the question itself was allowed.Inventor: Louis-James Davis
Committing events in a verification systemGB2619676.6A log committed to a public ledger so nobody can edit it afterwards has to carry two kinds of entry with opposite requirements: registrations anybody should be able to list, and reliance events only the party to them should be able to prove. Keeping them in separate logs breaks the ordering between them. Here they share one anchored tree, and which class an entry belongs to decides whether anyone can list it or only its own party can prove it.Inventor: Louis-James Davis
Method and system for atomic settlement of a credential-borne asset across a fiat rail, a public blockchain and a private credential ledger, in which transfer is conditioned upon an affirmative ownership attestation by a biometrically verified holderGB2619714.5An asset can exist in three places at once: a bank rail, a public chain and a private register of credentials. Moving it normally means one of the three updates first while the others catch up. That gap is the window everything goes wrong in. Here none of the three moves unless the holder, checked as a living person at that moment, affirmatively says the thing is theirs. An attestation that is absent or refused does not slow the transfer down. It stops it.Inventor: Louis-James Davis
Account enrolment in a verification systemGB2619748.3Confrmo keeps the photograph from your passport chip so it can check it is still you when you come back on a new device. That same store would make it easy to work out whether one person is holding several accounts, and Confrmo deliberately cannot do it: every photograph is locked to its own account, so there is no way to compare one account's against another's. Whether a document has been used before is worked out from the document's number instead, and the answer is never handed back to whoever presented it.Inventor: Louis-James Davis
Access control in a verification systemGB2619767.3Confrmo can tell the person inside a locked room exactly who is standing on the other side of the door, and it deliberately cannot open that door. There is no wire between the check and the lock. Anyone who broke into Confrmo's systems could put a false name on a screen, and still could not get into the room, because the only thing that moves the lock is a hand inside it. The check also keeps running while the person decides, so a permission that is withdrawn in those few seconds comes off the screen before they reach for the handle.Inventor: Louis-James Davis
Evidence handling in a verification systemGB2620244.0Some people cannot use a phone to prove who they are. A child, someone living with dementia, someone who has been sedated. Today a carer has two options and both are bad. Borrow the person's identity, which nobody can then tell apart from the real person. Or speak for them, which proves nothing about whether the person was even in the room. Confrmo keeps the two apart and always shows which is which. Evidence that the person themselves was there comes from the band on their wrist and stops the moment the band comes off, so a carer holding it cannot produce that evidence by holding it. Everything the carer is allowed to say about the person then depends on how much the person's own evidence currently supports. It narrows on its own when the band comes off, without anyone having to take permission away. If it is an emergency the alarm always goes through. It says plainly when nobody can tell who is wearing the band, because a responder should never read silence as reassurance.Inventor: Louis-James Davis
Proximity verification in a challenge-response systemGB2620249.9Asking somebody to prove they are a real live human is solved. Proving they are stood in front of you is not. An attacker at the door who cannot answer the question simply passes it to an accomplice stood next to the real person, gets the answer back and walks in. Every check still passes: the question was unpredictable, a living human answered it, the timing looked human. Here the question cannot be passed on at all, because it never exists as anything that can be forwarded. It is derived inside the tap itself and goes nowhere else, so anybody wanting to relay it has to be at the reader to get it, which is the very thing being proved. Answering is a short pattern of presses on the band, so it needs no microphone, no camera and nothing stored about the person.Inventor: Louis-James Davis
Prompt handling in a monitoring systemGB2620250.7Asking somebody how they are gives two different people two different things. The system needs to know only that a person was awake enough to answer and how quickly. The people caring for them need to know what the answer was. Hand both to the platform and you have quietly built a diary of the moods of somebody who often cannot consent to it existing. So the answer is sealed to the care team and travels through the platform unread, while the platform takes what it needs from the fact of a reply and how long it took. When a check is needed, the care team asks for it without saying why, because a run of reasons would rebuild the diary the sealing prevented. The question asked is chosen by what this person actually answers rather than by what is hardest to fake. A hard question nobody answers is worth less than an easy one they do. One that annoys them ends with the band in a drawer.Inventor: Louis-James Davis
Media capture in a verification systemGB2620256.4You can already prove a photograph came from a real camera and reached you unedited. None of that says the person in it was ever there. So somebody can verify themselves, sign a synthetic video of themselves, and every existing check passes, because the thing that authorised the signature was never the recording. Here the checks on the face are run on frames taken out of the recording itself, and the key that signs is not released unless those frames pass. The signature becomes evidence about the footage rather than a claim attached to it, and anyone holding the file can rerun the check instead of believing it.Inventor: Louis-James Davis
Capture session initiation in a verification systemGB2620262.2Proving who somebody is and proving where they were are done by different systems that never meet, so the two facts arrive separately and nothing joins the person to the thing they were standing next to. Here scanning the code on the article is what opens the recording at all, the checks on the person run on frames of that recording, and one signature covers the footage and the code together. Without the scan there is no session and nothing to sign, which is what stops footage being taken first and attached to an article afterwards.Inventor: Louis-James Davis
Presence determination in a verification systemGB2620266.3The test everybody uses to tell a person from software asks you to perform a task, and a task can be bought. There are businesses that do nothing but pay people to solve them, so a test establishing only that some human somewhere did something is answered by hiring one. Watching the face through the camera does not fix it either, because on a web page nothing stops somebody feeding the camera output with material of their own, and every check then runs on that material. Here a contact is held throughout, and what is examined is whether the response the camera sees arrives at the moment the server asked for it, with the contact unbroken across that moment. Two things arriving by different routes have to stay in step, on a schedule the page cannot know in advance, and letting go ends it with nothing produced. It answers whether a person is there rather than which person, and asks for no identity at all.Inventor: Louis-James Davis
Custody recording in a verification systemGB2621380.1A custody record is read when something has gone wrong. The question is often who tried to take an item as well as who held it, yet most systems record what they allowed and discard what they refused. An attempt by the wrong party then leaves no trace. Here every decision about an item is numbered in order, refusals included, so a missing one shows as a gap. The record is witnessed by a second system on a public ledger rather than by the one that made the decisions. The owner of an item can then prove to a customer that it went only through permitted hands and that nobody else tried, without revealing the route or which carriers handled it.Inventor: Louis-James Davis
Verification of an identity document using automated comparison and witnessed image captureGB2621443.7Most identity checks give up when a photo will not match. A driving licence photo is often a small engraving taken years ago, so honest people fail. Here a licence is first checked quietly against the passport the person has already proved, allowing for how old and how faint its photo is, with nobody shown the result. Only when that is not enough does a second, already verified person help: their own phone captures the person standing in front of them and the photos are compared out of sight, so the helper never sees either photo. Someone with only a driving licence can join the same way, with their own first face check as the reference.Inventor: Louis-James Davis