Invalidity dossier

US 11693938

Facial recognition authentication system including path parameters

Current assignee: FaceTec, Inc.

Added 6/18/2026, 6:00:47 AM

At a glanceNo PTAB challenges3 lawsuits on fileasserted by FaceTec, Inc.Financial Technology (FT)

Active provider: DeepSeek · deepseek-v4-flash

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

US patent 11693938, titled "Facial recognition authentication system including path parameters," was issued to Facetec Inc. The sole inventor listed is Kevin Alan Tussy. The patent has a filing date of August 27, 2020, and an issue date of July 4, 2023.

Abstract:
A facial recognition authentication system includes path parameters. A mobile device may obtain enrollment images as a user moves the mobile device to different positions relative to the user's head. The mobile device records an enrollment movement of the mobile device during imaging and obtains enrollment biometrics from the enrollment images. During authentication, the mobile device obtains authentication images as the user moves the mobile device. The mobile device records an authentication movement of the mobile device during imaging and obtains authentication biometrics from the authentication images. The authentication movement and the authentication biometrics are compared with the enrollment movement and the enrollment biometrics, respectively, to determine whether to authenticate the user.

Plain-Language Overview of Independent Claims:

  • Independent Claim 1: This claim describes a system for facial recognition authentication. The system includes a mobile computing device with a camera and sensors (like an accelerometer, magnetometer, and gyroscope). It also has an authentication server with a database. The mobile device captures enrollment images of a user's face while being moved, and the sensors record the movement path (enrollment movement). The server receives these images and movement data, extracts biometric information (enrollment biometrics), and stores it. For authentication, the mobile device again captures images of the user's face while being moved, and the sensors record this new movement (authentication movement). The system then compares the authentication biometrics from these new images and the authentication movement with the stored enrollment biometrics and enrollment movement to decide if the user is legitimate.

  • Independent Claim 10: This claim outlines a method for facial recognition authentication. It involves a mobile computing device capturing a series of enrollment images of a user's face while the device is moved, and recording the device's movement path during this enrollment. Biometric information from these enrollment images is extracted and stored. Later, for authentication, the mobile device captures another series of images of the user's face while the device is moved, recording this new movement. Biometric information is extracted from these authentication images. Finally, the authentication biometric information and movement are compared to the stored enrollment biometric information and movement to perform authentication.

  • Independent Claim 18: This claim describes a system for facial recognition authentication similar to Claim 1, but with slightly different emphasis on the components and processes. It specifies a mobile computing device with a camera and at least one movement detecting sensor, and a server. The mobile device obtains a plurality of enrollment images of a user's face while moving the device and collects movement data from the sensor during this enrollment. The server receives this enrollment data, calculates enrollment biometric information, and stores it. For authentication, the mobile device obtains authentication images while moving and collects authentication movement data. The server then compares the authentication biometric information and authentication movement data against the stored enrollment data to determine authentication.

Regarding CAFC 2026 dockets for US patent 11693938:
The provided patent information indicates that there is family litigation, and specifically, a PTAB case IPR2025-00108 was filed (Pending - Instituted) and US cases were filed in the California Northern District Court (5:24-cv-03623 and 3:24-cv-03623). These show active legal proceedings related to the patent. However, the prompt specifically asked for CAFC 2026 dockets. The provided patent information does not explicitly list any CAFC (Court of Appeals for the Federal Circuit) dockets for 2026. The IPR case and District Court cases are lower level proceedings. Therefore, I do not have authoritative information to confirm CAFC 2026 dockets for patent 11693938.US patent 11693938, titled "Facial recognition authentication system including path parameters," was issued to Facetec Inc. The sole inventor listed is Kevin Alan Tussy. The patent has a filing date of August 27, 2020, and an issue date of July 4, 2023.

Abstract:
A facial recognition authentication system includes path parameters. A mobile device may obtain enrollment images as a user moves the mobile device to different positions relative to the user's head. The mobile device records an enrollment movement of the mobile device during imaging and obtains enrollment biometrics from the enrollment images. During authentication, the mobile device obtains authentication images as the user moves the mobile device. The mobile device records an authentication movement of the mobile device during imaging and obtains authentication biometrics from the authentication images. The authentication movement and the authentication biometrics are compared with the enrollment movement and the enrollment biometrics, respectively, to determine whether to authenticate the user.

Plain-Language Overview of Independent Claims:

  • Independent Claim 1: This claim describes a system for facial recognition authentication. The system includes a mobile computing device with a camera and sensors (like an accelerometer, magnetometer, and gyroscope). It also has an authentication server with a database. The mobile device captures enrollment images of a user's face while being moved, and the sensors record the movement path (enrollment movement). The server receives these images and movement data, extracts biometric information (enrollment biometrics), and stores it. For authentication, the mobile device again captures images of the user's face while being moved, and the sensors record this new movement (authentication movement). The system then compares the authentication biometrics from these new images and the authentication movement with the stored enrollment biometrics and enrollment movement to decide if the user is legitimate.

  • Independent Claim 10: This claim outlines a method for facial recognition authentication. It involves a mobile computing device capturing a series of enrollment images of a user's face while the device is moved, and recording the device's movement path during this enrollment. Biometric information from these enrollment images is extracted and stored. Later, for authentication, the mobile device captures another series of images of the user's face while the device is moved, recording this new movement. Biometric information is extracted from these authentication images. Finally, the authentication biometric information and movement are compared to the stored enrollment biometric information and movement to perform authentication.

  • Independent Claim 18: This claim describes a system for facial recognition authentication similar to Claim 1, but with slightly different emphasis on the components and processes. It specifies a mobile computing device with a camera and at least one movement detecting sensor, and a server. The mobile device obtains a plurality of enrollment images of a user's face while moving the device and collects movement data from the sensor during this enrollment. The server receives this enrollment data, calculates enrollment biometric information, and stores it. For authentication, the mobile device obtains authentication images while moving and collects authentication movement data. The server then compares the authentication biometric information and authentication movement data against the stored enrollment data to determine authentication.

Regarding CAFC 2026 dockets for US patent 11693938, the provided patent information indicates active litigation, including a PTAB case IPR2025-00108 (Pending - Instituted) and US cases filed in the California Northern District Court (5:24-cv-03623 and 3:24-cv-03623). However, the information does not explicitly list any dockets specifically for the Court of Appeals for the Federal Circuit (CAFC) for the year 2026 for patent 11693938. Therefore, I do not have authoritative information to confirm CAFC 2026 dockets for this specific patent.

Generated 6/18/2026, 6:45:45 AM

Cases on file (3)

Group view →

Specific litigation cases in our database that name US patent 11693938. The free-form analysis below may also discuss cases beyond this list.

  • 3:24-cv-03623-RFLUnited States District Court for the Northern District of California, San Francisco DivisionActive and ongoing

    Defendants: Jumio Corporation

  • IPR2025-00108Patent Trial and Appeal Board (PTAB) of the USPTOPending - Instituted

    Defendants: FaceTec, Inc.

  • 5:24-cv-03623California Northern District Court

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

As a patent attorney, I have reviewed the provided patent text and conducted a targeted search for litigation involving US patent 11693938. The following litigation cases have been identified:

1. PTAB Case: IPR2025-00108

2. US District Court Case:

  • Plaintiff(s): FaceTec, Inc.
  • Defendant(s): Jumio Corporation
  • Jurisdiction: United States District Court for the Northern District of California, San Francisco Division
  • Case Number: 3:24-cv-03623-RFL
  • Filing Date: June 14, 2024
  • Outcome/Current Status: Active and ongoing. The court has issued an "ORDER DENYING MOTION TO VOLUNTARILY DISMISS WITHOUT PREJUDICE AND GRANTING MOTION TO INTERVENE". Additionally, FaceTec, Inc. has filed a "MEMORANDUM IN OPPOSITION TO MOTION FOR STAY".

3. US District Court Case:

  • Jurisdiction: California Northern District Court
  • Case Number: 5:24-cv-03623
  • Filing Date: Not explicitly found in the provided search results.
  • Outcome/Current Status: Not explicitly found in the provided search results.

Please note that while the Google Patents page for US11693938B2 lists two distinct District Court cases (3:24-cv-03623 and 5:24-cv-03623) in the Northern District of California, detailed information regarding the plaintiff, defendant, and filing date for case 5:24-cv-03623 was not readily available in the targeted search snippets.

Generated 6/18/2026, 6:45:59 AM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: FaceTec, Inc.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

One AIA trial proceeding has been filed against US Patent 11,693,938. This proceeding, IPR2025-00108, has reached a Final Written Decision, which currently gives a defendant a clearer understanding of the patent's scope.

IPR2025-00108 — Jumio Corporation v. FaceTec, Inc.

  • Type: Inter Partes Review
  • Filed: 2024-11-07
  • Status: Final Written Decision
  • Judge panel: Information regarding the specific judge panel for this proceeding is not publicly available in the provided patent text or readily accessible via general search without direct access to the PTAB E2E system.
  • Petition grounds: Details of the specific claims challenged, prior art references, and statutory bases (§ 102 / § 103 / § 112) for the petition are not available in the provided patent text or general Google search results. This information is typically found within the institution decision or the petition itself, which requires access to the PTAB E2E system.
  • Institution decision: The institution decision details (date and panel's reasoning) are not publicly available in the provided patent text or readily accessible via general search without direct access to the PTAB E2E system.
  • Final Written Decision (if issued): The specific verdict at a claim-level granularity for IPR2025-00108 is not publicly available in the provided patent text or readily accessible via general search results. While the status indicates "Final Written Decision" as of 2026-06-17, the outcome regarding which claims were canceled, sustained, or held patentable, along with the panel's reasoning, requires access to the official FWD document from the USPTO PTAB Decisions portal.
  • Settlement / termination: There is no public information available regarding a settlement or termination for this proceeding.
  • Appeal: There is no public information available regarding an appeal of this FWD to the Federal Circuit.
  • Defensive value: Without the specific claim-level outcomes of the Final Written Decision, it is impossible to determine the defensive value. The impact could range from complete invalidation of asserted claims to the patent owner prevailing, thus hardening the patent.

Strategic summary

As of today, June 18, 2026, only one AIA trial proceeding, IPR2025-00108, has been filed against US Patent 11,693,938. This IPR has reached a "Final Written Decision" status, meaning a definitive ruling on the challenged claims has been issued by the PTAB. However, the specific details of this decision—namely, which claims, if any, were canceled or sustained—are not publicly available in the provided patent text or accessible through general web searches. Therefore, it is currently unknown whether the patent has been narrowed, hardened, or otherwise impacted at a claim level.

The estoppel landscape for IPR2025-00108, governed by § 315(e)(2), will bar Jumio Corporation (and its privies) from asserting in future civil actions or other USPTO proceedings any ground that it raised or reasonably could have raised during this IPR. Without knowing the grounds asserted by Jumio, it's difficult to identify which prior-art grounds are still available for other potential challengers. The "Petitioner: Jumio Corporation" and "Patent Owner: FaceTec, Inc." information indicates a dispute between these specific entities. There are no pattern signals suggesting multiple IPRs by the same petitioner or aggressive PTAB appeals by the patent owner, nor is there an indication of a defensive aggregator like Unified Patents being directly involved in this specific proceeding (though Unified Patents has provided data links related to other litigation involving the patent family).

Recommended next steps

To understand the defensive posture regarding US Patent 11,693,938, a defendant should:

  • Immediately obtain and review the Final Written Decision for IPR2025-00108. This document will explicitly state which claims, if any, were found unpatentable or patentable. The FWDs are generally public on the USPTO PTAB Decisions portal.
  • Analyze the claims that were challenged and the prior art relied upon in IPR2025-00108 to understand the scope of the decision and potential estoppel implications for any existing or future litigation.
  • Check the Federal Circuit's docket and CourtListener for any appeals related to IPR2025-00108, as an appeal could alter the final outcome of the PTAB's decision.
  • Given the patent's active status and the existence of other litigation (as indicated in the Google Patents sidebar), thoroughly evaluate the remaining claims (if any were found patentable) and their relevance to any accused infringement.

https://patents.google.com/patent/[US11693938](/patent/US11693938)/en

Generated 6/18/2026, 6:45:53 AM

Ownership chain (1)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 2020-08-27 · recorded 2022-05-04 · reel 058866/0588 · ASSIGNMENT OF ASSIGNORS INTEREST

    TUSSY, KEVIN ALANFACETEC, INC.

    Correspondent: HOOPES, JEFFREY · HOOPES & ADAMS

    inventor-to-company transfer

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

Original assignee

The original assignee, Facetec Inc., develops and provides a biometric authentication platform called "Zoom" which embodies facial recognition and liveness detection technologies as described in the patent claims. Facetec Inc.'s primary line of business is biometric identity verification and anti-spoofing solutions for enterprise clients. Facetec Inc. is currently operating.

Assignment timeline

There is only one assignment record for US11693938 in the USPTO Assignment Center.

  • 2020-08-27 (executed) / recorded 2022-05-04 — Reel 058866/0588
    • Conveyance: ASSIGNMENT OF ASSIGNORS INTEREST
    • Assignor: TUSSY, KEVIN ALAN
    • Assignee: FACETEC, INC.
    • Correspondent: HOOPES, JEFFREY, HOOPES & ADAMS, PC, 19570 VENTURA BLVD, SUITE 300, TARZANA, CA 91356.
    • Context: Inventor assigned intellectual property rights to his company, Facetec Inc.

Timeline diagram

timeline
    title Ownership of US 11693938
    2020 : Inventor assigned to Facetec
         : Application filed by Facetec
    2023 : Patent issued to Facetec
    2024 : US litigation filed
    2025 : PTAB IPR case filed

NPE / troll-pattern signals

  1. Shell-entity transferNot present. The only recorded assignment is from the inventor, Kevin Alan Tussy, to Facetec Inc., which is an operating company.
  2. Known asserter in the chainNot present. Facetec Inc. is an operating company known for its biometric authentication products. Litigation associated with the patent (e.g., California Northern District Court cases and PTAB IPR2025-00108) appears to be initiated by the operating company.
  3. Repeat correspondent across the chainUnclear. Jeffrey Hoopes of Hoopes & Adams, PC is listed as the correspondent for the single assignment recorded (Reel 058866/0588). There is no recurrence of this correspondent within this specific patent's assignment chain to identify a pattern.
  4. Cascading transfersNot present. There is only one recorded assignment in the chain.
  5. Pre-litigation transferNot present. The assignment from the inventor to Facetec Inc. was executed on 2020-08-27 (recorded 2022-05-04), while the earliest identified litigation for the patent was filed in 2024.
  6. Bankruptcy fire-saleNot present. Facetec Inc. is an actively operating company, and there is no indication of bankruptcy proceedings.
  7. PrivateeringNot present. No transfer from an operating company to a third-party NPE for assertion is indicated in the assignment records.
  8. Defensive aggregator (anti-NPE)Not present. The patent is currently held by Facetec Inc. and is actively being asserted in litigation, not aggregated by a defensive entity.

Verdict

Operating-company assertion
This patent is held by Facetec Inc., an operating company that develops and markets biometric authentication products. The sole recorded assignment is from the inventor to Facetec Inc. (Reel 058866/0588, executed 2020-08-27), and the patent is actively involved in litigation where Facetec Inc. appears to be the plaintiff.

Verification: USPTO Assignment Center for US11693938

Generated 6/18/2026, 6:46:00 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

To identify the most relevant prior art for US patent 11693938, I will search the USPTO database for the patent and then analyze its cited references.

USPTO Search for US Patent 11693938

I have accessed the full patent text for US11693938B2, "Facial recognition authentication system including path parameters," directly from Google Patents, which is a reliable source for patent information. The Google Patents page for US11693938B2 also lists prior art documents. I will use this information.

Most Relevant Prior Art for US Patent 11693938

The "Prior art keywords" listed on the Google Patents page are "user," "image," "data," "authentication," and "distance." The "Prior art date" is listed as 2014-08-28. I will now examine the "Cited by" and "References" sections of the patent to identify the most relevant prior art.

Understanding 35 U.S.C. § 102:
35 U.S.C. § 102 defines the conditions for patentability, specifically novelty. Under this statute, an invention is not patentable if it was described in a patent, printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. There are exceptions to what qualifies as prior art, such as disclosures made by the inventor within one year or less before the effective filing date.

Based on the information available on the Google Patents page for US11693938B2, here are some of the most relevant prior art documents cited:

  • US20150063625A1 (Priority date: 2014-08-28, Publication date: 2015-03-05)

    • Full Citation: US20150063625A1 - Facial recognition authentication system including path parameters.
    • Publication/Filing Date: Published March 5, 2015. The priority date is August 28, 2014.
    • Brief Description: This patent application describes a facial recognition authentication system that uses a mobile device to obtain enrollment images as a user moves the device, recording the movement path and obtaining biometric information. During authentication, similar images and movement data are collected and compared to the enrollment data to authenticate the user. This is a direct antecedent to US11693938B2, sharing the same title and inventor, suggesting it is an earlier publication of related subject matter.
    • Potential Anticipation (35 U.S.C. § 102): This reference is highly relevant and likely anticipates many aspects of Claims 1, 10, and 18, as it appears to describe essentially the same core invention. Given the filing date of US11693938 (August 27, 2020) and the earlier publication of US20150063625A1 (March 5, 2015), this earlier publication would generally be considered prior art. However, it is noted that US11693938B2 lists US20200394290A1 as an "other version" and shares the priority date of 2014-08-28 with US20150063625A1. If US11693938B2 is a continuation or divisional of an application that claimed priority back to 2014-08-28, then US20150063625A1 might not be statutory prior art against the claims of US11693938B2 under 35 U.S.C. § 102(a)(2) if the claimed invention was invented by the same inventor and effectively filed before the effective filing date of the claimed invention. Without a full prosecution history, a definitive statement is difficult, but based purely on publication dates, it describes the same invention prior to the filing of the granted patent.
  • US20200394290A1 (Publication date: 2020-12-17)

    • Full Citation: US20200394290A1 - Facial recognition authentication system including path parameters.
    • Publication/Filing Date: Published December 17, 2020.
    • Brief Description: This is listed as an "other version" of the patent, suggesting it is a published application that matured into US11693938B2. It describes the same facial recognition authentication system using path parameters from a mobile device.
    • Potential Anticipation (35 U.S.C. § 102): As an earlier publication of the same application family that led to US11693938B2, this document would not typically be considered prior art under 35 U.S.C. § 102 against the claims of US11693938B2, assuming proper priority claims. Instead, it represents the published application stage of the granted patent.

To provide a comprehensive analysis, a deeper dive into the patent's prosecution history would be necessary to understand the exact relationships between these applications and their effective filing dates. However, based on the provided information, US20150063625A1 is the most chronologically relevant prior art publication from the same inventor/assignee that predates the filing date of US11693938B2.

Generated 6/18/2026, 6:45:58 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

The provided patent text for US patent 11693938 includes a "Prior art keywords" section listing "user, image, data, authentication, distance," and a "Prior art date" of 2014-08-28. However, it does not contain a "References Cited" section that lists specific prior art patents or publications. Therefore, a direct obviousness analysis by combining specific prior art references, as typically performed under 35 U.S.C. § 103, cannot be conducted with the information at hand.

Instead, this analysis will proceed by considering the general state of the art as implied by the patent's background and the common knowledge of a Person Having Ordinary Skill in the Art (POSITA) around the priority date of August 28, 2014, in the fields of mobile computing, biometric authentication, and facial recognition.

Background State of the Art (as described by the patent):

The patent itself acknowledges several relevant aspects of the prior art:

  • Biometric security methods were known, including fingerprint systems, though these were often "prohibitively expensive for use on a small electronic device or are often considered unreliable and unsecure."
  • Facial recognition was "generally known and may be used in a variety of contexts."
  • "Two-dimensional facial recognition is commonly used to tag people in images on social networks or in photo editing software."
  • Crucially, 2D facial recognition was "not considered secure enough" for widespread authentication, because "faces may be photographed or recorded, and then the resulting prints or video displays showing images of the user may be used to trick the system." This highlights a known problem: the vulnerability of 2D facial recognition to spoofing attacks.
  • Mobile devices with cameras and movement detecting sensors (e.g., accelerometers, magnetometers, gyroscopes) were commonplace.

Elements of the Independent Claims (1, 10, 18):

The independent claims (1, 10, 18) of US 11693938 generally describe a system and method for facial recognition authentication involving:

  1. A mobile computing device with a camera and movement detecting sensors (accelerometer, magnetometer, gyroscope).
  2. Capturing a plurality of enrollment images of a user's face while the mobile device is moved.
  3. Recording an "enrollment movement" (path parameters) of the mobile device during this imaging using the sensors.
  4. Obtaining "enrollment biometrics" from the enrollment images.
  5. Storing this enrollment information (biometrics and movement data).
  6. For authentication, capturing authentication images while the mobile device is moved.
  7. Recording an "authentication movement" (path parameters) of the mobile device during authentication imaging.
  8. Obtaining "authentication biometrics" from the authentication images.
  9. Comparing the authentication biometrics and authentication movement with the stored enrollment biometrics and enrollment movement to determine whether to authenticate the user.

The core contribution revolves around integrating the device's physical movement during image capture into the biometric authentication process, specifically by recording and comparing "path parameters" from built-in motion sensors.

Obviousness Analysis based on General Knowledge:

Given the patent's description of the prior art, a POSITA in August 2014, seeking to improve the security of facial recognition authentication on mobile devices, would have been motivated to combine existing technologies in a manner that would likely render the claimed invention obvious.

Motivation for Combination:

The primary motivation would be to overcome the well-known vulnerability of 2D facial recognition systems to "spoofing" attacks (e.g., using a photograph or video of an authorized user). A POSITA would recognize that merely matching a static face image is insufficient for secure authentication.

Therefore, the POSITA would seek ways to introduce "liveness detection" or "realness" verification into the authentication process. Integrating dynamic elements that prove the presence of a live, three-dimensional user, interacting with the mobile device, would be a logical step.

Combination of Known Elements:

  1. Known Problem: 2D facial recognition was known, but its susceptibility to spoofing by photographs or videos rendered it insecure for high-stakes authentication.
  2. Known Technologies:
    • Facial Recognition: Algorithms for detecting and recognizing faces were established.
    • Mobile Devices with Cameras: Smartphones and tablets with front-facing cameras were ubiquitous.
    • Mobile Device Sensors: Accelerometers, gyroscopes, and magnetometers were standard components in mobile devices, providing data on device orientation, movement, speed, and direction.
    • Biometric Liveness Detection: The concept of liveness detection in biometrics (e.g., detecting blinking, head movements, depth perception) was an active area of research to combat spoofing.

Obvious Combination:

A POSITA, faced with the insecurity of 2D facial recognition, would find it obvious to combine:

  • 2D Facial Recognition (C): As the primary means of identifying a user visually.
  • Mobile Device Camera (A): To capture the user's face.
  • Mobile Device Motion Sensors (B): To capture data related to the device's movement.

The motivation for this specific combination arises from the need for enhanced liveness detection. If a fraudster presents a static image or a video, the facial recognition might match, but the device's movement during the authentication process would not correspond to the physical interaction of a live user moving the device to capture varied images.

Therefore, a POSITA would be motivated to:

  • Require dynamic interaction: Instead of a static image, instruct the user to move the mobile device relative to their face during image capture.
  • Record device movement: Utilize the readily available accelerometer, gyroscope, and magnetometer in the mobile device to record the "path parameters" (e.g., acceleration, angle, speed, distance changes) of this movement during both enrollment and authentication.
  • Compare movement data: Compare the recorded authentication movement with a previously enrolled movement pattern. A mismatch in movement data, even if the face itself matches, would strongly indicate a spoofing attempt.

The patent highlights moving the device "in an arc like path horizontally about his or her face" (FIGS. 6A, 6B) or "far away from his or her face, and then brings the mobile device 112 forward closer to his or her face" (FIGS. 7A, 7B). These are straightforward movements that a POSITA would conceive of to generate dynamic image data and corresponding motion sensor data.

The step of comparing "authentication biometrics" with "enrollment biometrics" is a standard facial recognition practice. The crucial addition is the comparison of "authentication movement" with "enrollment movement." This is a direct application of pattern matching techniques (already known in other fields) to the newly collected motion sensor data, motivated by the clear need for anti-spoofing in mobile facial authentication.

In essence, the solution described in the claims – leveraging a mobile device's inherent motion-sensing capabilities to record and verify the dynamic path taken during facial image capture for authentication – addresses a known problem (spoofing in 2D facial recognition) by combining existing technologies (facial recognition, mobile cameras, mobile motion sensors) in a predictable way for a POSITA.

Generated 6/18/2026, 6:46:11 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

✓ Generated

I'll research the USPTO records for US patent 11693938 to detail its term adjustments, family members, and expiration.

Let me get more specific data on the patent's family, term adjustment, and related applications.

Data-provenance note (read first)

Two things to flag before the substance:

  1. Date inconsistency in the inputs. This task states "Current Date: April 26, 2026," while the system header and the source page fetch are dated 2026-09-15, and the previously generated "PTAB challenges" section is framed "As of today, June 18, 2026." I am treating the authoritative patent full text fetched 2026-09-15 from https://patents.google.com/patent/US11693938/en as the ground truth for bibliographic data, and I flag the mismatch rather than silently reconciling it.
  2. Verification limits. I was able to retrieve the Google Patents record for US11693938B2 (which reproduces the front-page/family metadata) but I was not able to pull the USPTO Patent Center / Patent Public Search record that carries the explicit "Patent Term Adjustment" day count, the PTA certificate, or the continuity (parent/child) data set. Statements below are labeled accordingly, and I do not fabricate a PTA figure.

1. Bibliographic anchor data (verified from the fetched record)

Field Value
Patent number US11693938B2
Title Facial recognition authentication system including path parameters
Application number US17/004,412
Pre-grant publication US20200394290A1 (published 2020-12-17)
Filing date (this application) 2020-08-27
Issue/publication date 2023-07-04
Priority date (as listed) 2014-08-28
Inventor Kevin Alan Tussy
Assignee Facetec Inc. (assignment recorded 2022-05-04; executed 2020-08-27)
Legal status Active — "expires 2036-02-07"; page also shows a field labeled "Adjusted expiration 2036-02-07"
First classification G06F21/32; also G06V40/16, G06V40/40, H04L9/3231, H04W12/06, G06Q20/40145
Family litigation markers IPR2025-00108 (instituted); N.D. Cal. 5:24-cv-03623 and 3:24-cv-03623

2. Patent Term Adjustment (PTA) — 35 U.S.C. § 154(b)

What the record shows: The "Adjusted expiration 2036-02-07" label is the only term-adjustment-relevant datum exposed by the source page. Google Patents' "adjusted expiration" is an automated derived field — it is not the USPTO's PTA determination and is expressly not a legal conclusion.

Mechanics that govern this patent:

  • PTA is computed from the actual filing date of this application (2020-08-27), per 37 CFR 1.702–1.703 — not from the 2014 priority date.
  • B-delay (post-3-year): 3 years from 2020-08-27 = 2023-08-27. Because the patent issued 2023-07-04 — roughly seven weeks before the three-year mark — the B-delay component is 0 days (assuming no RCE tolling analysis is needed). This means essentially all PTA, if any, must come from A-delay (late first/s subsequent actions, late issue after fee) and/or C-delay (appeal/interference).
  • Subsequent actions: the front-page "References Cited"/prosecution history was not retrievable, so I cannot quantify A-delay.
  • 37 CFR 1.703(g) caveat: if a terminal disclaimer was filed (e.g., to overcome an obviousness-type double-patenting rejection over an earlier family member), PTA cannot carry the patent past the disclaimed date. Whether a terminal disclaimer exists here is unverified.

Arithmetic cross-check (inference, not confirmed): The 20-year term runs from the earliest non-provisional U.S. filing in the benefit chain. If that date is 2015-08-28 (i.e., one year after the 2014-08-28 priority), the unadjusted expiration would be 2035-08-28, and the step to 2036-02-07 equals 163 days. If instead the 20-year clock is measured from 2014-08-28, the implied PTA would be ~528 days — which is difficult to reconcile with an issuance that beat the three-year B-delay clock. I could not confirm the earliest non-provisional filing date, so I present this as an estimate only.

Bottom line: The projected/adjusted expiration is 2036-02-07, but the exact USPTO-certified PTA day count is not verified in the material available to me. The definitive source is the "(*) Notice" block printed on the front page of the issued patent ("...extended or adjusted under 35 U.S.C. 154(b) by ___ days") and the Patent Center "Patent Term Adjustment" data field.


3. Patent Term Extension (PTE) — 35 U.S.C. § 156

Not applicable. PTE under § 156 is available only for patents claiming a human/veterinary drug product, a medical device, a food additive, or a color additive whose term was consumed by FDA pre-market regulatory review. US11693938 claims a facial-recognition/biometric authentication system (software + mobile-device hardware), with no FDA-regulated product nexus shown in the specification. No PTE application or grant is indicated in the record, and none would be legally available on these facts.


4. Continuation and divisional applications

Status of US17/004,412 itself: Application 17/004,412 (filed 2020-08-27) is clearly a continuation-type filing in an existing chain — it has a 2014-08-28 priority date but was filed in 2020, and its own pre-grant publication US20200394290A1 appeared ~4 months after filing (consistent with expedited publication of a continuation whose 18-month window had already elapsed).

Children claiming priority to US11693938 (verified from the source page):

Child Filed Resulting publication/patent Notes
US18/205,968 2023-06-05 US12346423B2 ("Authentication system") Continuation filed ~1 month before the '938 issued. FaceTec's June 4, 2025 press release describes this as having five independent claims directed to three-dimensionality evaluation and states it was examined "in full view of all known prior art."
US19/030,681 2025-01-17 US20250173414A1 Later continuation-type filing claiming priority to the '938.

Divisional applications: I found no evidence of a divisional application (i.e., one filed in response to a restriction requirement) in this record. The 18/205,968 and 19/030,681 filings present as continuations on the available metadata. If any were filed responsively to a restriction requirement, that status would appear in the USPTO continuity data, which I could not retrieve.

Corporate-level confirmation: FaceTec's 2025 announcements state the portfolio reached 39 issued patents with 33 pending, and expressly note that "numerous additional continuation-type patent applications are also currently pending" directed to this technology family — consistent with an ongoing continuation strategy around the '938 disclosure.


5. Related family members (earlier in the chain)

  • US20150063625A1 — "Facial recognition authentication system including path parameters." Same title, priority 2014-08-28, published 2015-03-05. This is the earliest same-family publication identified; it predates US11693938B2 and shares the title/inventor, making it an antecedent family member. (Note: the previously generated "Prior art" section characterizes it as a potential § 102 anticipation reference — that framing should be treated cautiously, since a same-family/same-inventor earlier application is normally not § 102(a)(2) prior art under the common-ownership/common-inventor provisions of AIA § 102(b)(2)(C); the prior section itself hedged on this, and I would characterize it as a family member and potentially a § 102(a)(1)/§ 102(b)(1) reference only if it published more than one year before the '938's effective filing date, which the dates do not clearly establish.)
  • US20200394290A1 — the pre-grant publication of 17/004,412; not prior art against the '938, it is the '938.
  • Family litigation node: IPR2025-00108 and the N.D. Cal. actions (already addressed in the previously generated sections — not repeated here).

6. Projected expiration date

  • Adjusted expiration (per source record): 2036-02-07.
  • The unadjusted nominal expiration is 20 years from the earliest non-provisional U.S. filing date in the benefit chain (2014-08-28 is the priority date, which may be a provisional and therefore does not itself start the 20-year clock). I could not confirm the earliest non-provisional date from the available material.
  • No PTE applies, so the only potential extension beyond the nominal 20 years is PTA (and any terminal disclaimer would cap it).
  • Because the '938 shares a common priority chain with US12346423B2 (and US20250173414A1), and the '938 appears to carry PTA while the children may not, note the obviousness-type double patenting exposure framework of In re Cellect / Allergan v. MSN: a first-filed, first-issued, later-expiring family member can be attacked where family members share priority. This is a legal risk to monitor, not a term-adjustment fact.

7. What to pull to close the gaps (recommended verification)

  1. USPTO Patent Center for application 17/004,412 → "Patent Term Adjustment" field and the PTA determination (and any § 1.705(b) reconsideration).
  2. Front page of the issued US11693938B2 → the "(*) Notice ... extended or adjusted under 35 U.S.C. 154(b) by NNN days" line (the certified PTA).
  3. Patent Public Search / Global Dossier continuity data → to confirm the earliest non-provisional filing date and whether any divisional was filed under a restriction requirement.
  4. Terminal disclaimer check → any TD recorded against the '938 (37 CFR 1.321) would cap the term under 37 CFR 1.703(g) and affect both expiration and ODP defenses.
  5. Assignment/recordation and maintenance-fee status → confirm the patent remains in force at the 3.5-, 7.5-, and 11.5-year windows (next relevant window: 2026-07-04 for the 3.5-year fee, already passed if paid; 2030 for 7.5-year).

Explicit uncertainty statement: I do not know, with high confidence, the exact certified PTA day count for US11693938B2, nor the identity of the earliest non-provisional filing date setting its 20-year term. I have not fabricated either. The one date I can state as sourced is the 2036-02-07 adjusted expiration from the fetched patent record, and the child filings US18/205,968 → US12346423B2 and US19/030,681 → US20250173414A1.

Generated 9/15/2026, 12:20:13 AM

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

✓ Generated

I'll first ground the analysis in the record before generating derivatives.

DEFENSIVE DISCLOSURE DOCUMENT

DD-US11693938 — Facial-Recognition Authentication with Motion-Path Parameters

Disclosing entity: Independent defensive-publication record
Document date: 2026-04-26 (publication/timestamp target: as close to drafting as possible — see §8)
Subject patent analyzed: US 11,693,938 B2 (application US 17/004,412; filed 2020-08-27; granted 2023-07-04; priority 2014-08-28; inventor Kevin Alan Tussy; assignee FaceTec, Inc.)
Framework: 5 derivation axes × 3 independent-claim families + 4 standard-based combination scenarios


§0. Record anchors and corrections to earlier sections (read before using this document)

Live retrieval of the PTAB and docket record returned facts that contradict or supersede statements in the previously generated sections. Flagging explicitly, per instructions:

Item Earlier section said Verified record (2026-09-15 retrieval)
IPR2025-00108 outcome "Final Written Decision issued, outcome unknown" FWD issued June 2026 (reported 2026-06-04/09); PTAB held no challenged claim of US 11,693,938 unpatentable. Petition filed 2024-11-07; instituted 2025-06-09; APJs Bach V. Hoang, Garth D. Baer, Nabeel U. Khan; Director-Review request denied 2025-08-05.
Scope of attacks Not stated Grounds were §103 combinations: Derakhshani (US 8,437,513) + Tanii (US 2002/0113884); Zhang (US 2011/0299741) + Tanii; plus Tahk (US 2014/0028823) and Suzuki (US 2004/0239799) as secondary references. Independent claims implicated: 1, 10, 22 (as recited for the sibling '910; the '938 claims 1–24 were challenged).
Parallel proceedings Only '108 and N.D. Cal. cases Four coordinated Jumio IPRs: IPR2025-00106 ('471), -00107 ('606), -00108 ('938), -00109 ('910) — all lost by Petitioner. Separate iProov litigation (D. Nev. 2:21-cv-02252, stayed; IPR2025-00106/-00107).
"Prior art" section leader US 2015/0063625 A1 treated as the key §102 reference That reference is a same-family/same-inventor antecedent publication, not the art the Office or the Board actually litigated. The operative art of record is Derakhshani / Tanii / Zhang / Tahk / Suzuki.
Judge for 3:24-cv-03623 Rita F. Lin Docket aggregators show Lisa J. Cisneros on 3:24-cv-03623 and the FaceTec v. Jumio N.D. Cal. matter also appears as 5:24-cv-03623 (Judge Rita F. Lin per press coverage). Treat the judge assignment as unresolved; both identifiers appear in the record.

Legal premise for this document (stated plainly so the record is not overstated): a defensive publication dated 2026 cannot be prior art against US 11,693,938 (effective priority 2014-08-28), and cannot invalidate it. Its utility is narrow and specific:

  • It becomes §102(a)(1) prior art as of its publication date against later-filed third-party applications — i.e., competitors' incremental improvements filed after publication, with no §102(b)(1) grace available to them for a third party's disclosure;
  • It becomes §102(a)(2) art against third-party applications effectively filed after publication;
  • It builds an anticipation/obviousness record and a written-description/possession record for the disclosing entity.
    Additionally, because the '938 was adjudicated valid over §103 combinations in a FWD, the derivative space below is deliberately aimed at the space beyond Derakhshani/Tanii/Zhang/Tahk/Suzuki — i.e., at the improvements a competitor would need to file on to design around the '938.

§1. Target-element index (functional handles used throughout; not a claim summary)

Structural strain can substitute for inertial measurement (see DD-10.1). The following handles are used to map derivatives to claim scope:

  • E1 camera capture of a user's face at one or more instants
  • E2 at least one movement-detecting sensor (accelerometer / gyroscope / magnetometer class)
  • E3 enrollment biometric extraction from enrollment image(s)
  • E4 enrollment movement (path parameter) recorded during enrollment imaging
  • E5 storage/binding of enrollment template to an identity profile
  • E6 authentication image capture + authentication path-parameter recording
  • E7 authentication biometric extraction
  • E8 biometric comparison against a similarity threshold
  • E9 movement comparison against an "expected movement" (enrolled movement or prompted/anticipated movement)
  • E10 device information / GPS / context binding
  • E11 anti-spoof and liveness sub-signals (banding, screen-edge, glare, perspective/fish-eye distortion rate, blink, thermal, projected-pattern reflectance)
  • E12 on-screen guidance prompts (frames/ovals, feedback video, meters)
  • E13 variable / elastic match thresholds
  • E14 split of processing between device and remote server

§2. Axis 1 — Material & Component Substitution

DD-1.1 — Fiber-optic and piezoelectric inertial front end with sapphire optics (targets E1, E2, E4, E6, E9)

Axis: Material & Component Substitution (sensor and optical materials).

Enabling description. Replace the MEMS capacitive IMU with a tri-axis interferometric fiber-optic gyroscope (FOG) using a 1550 nm superluminescent diode, a Y-junction integrated-optic chip, and a 200 m polarization-maintaining sensing coil, giving bias instability < 0.02 °/hr and scale-factor error < 20 ppm — necessary in high-EMI, high-shock industrial handheld use where capacitive MEMS drift corrupts the path parameter. Replace the MEMS accelerometer with an AlN piezoelectric (or PVDF) accelerometer having a charge amplifier with 10¹² Ω transimpedance, 0.5 Hz–2 kHz passband, and ±0.5 mg resolution. Replace the camera cover glass with chemically strengthened alkali-aluminosilicate or sapphire (Mohs 9) to preserve distortion metrology after abrasive wear, and replace the visible CMOS sensor with an InGaAs SWIR 900–1700 nm array for operation through smoke and under 1550 nm eye-safe illumination. Attitude is propagated by a quaternion EKF whose measurement update uses camera-IMU temporal offset calibrated against a MEMS-mirror-modulated fiducial flashed at 50 Hz. The path descriptor comprises arc length s, curvature κ = |r′×r″|/|r′|³, torsion τ, and jerk j = d³r/dt³, compared by Sakoe-Chiba-banded DTW (band = 8 % of samples) after gravity-alignment.

flowchart LR
  A["Camera SWIR InGaAs 900 to 1700 nm"] --> E["Frame buffer with HW timestamps"]
  B["Fiber-optic gyro 3-axis 1550 nm"] --> F["Quaternion EKF fusion"]
  C["AlN piezo accelerometer 2 kHz"] --> F
  D["3-axis fluxgate magnetometer"] --> F
  E --> G["Visual-inertial odometry 6-DoF relative pose"]
  F --> G
  G --> H["Path descriptor arc length curvature torsion jerk"]
  H --> I["DTW matcher band 8 percent"]
  I --> J["Score vs sealed enrollment template"]

DD-1.2 — Event-camera and SPAD depth sensing as the path source (targets E1, E2, E4, E6, E11)

Axis: Material & Component Substitution (silicon architecture: frame-based → event-based + single-photon).

Enabling description. Substitute a rolling-shutter CMOS imager with (a) a dynamic vision sensor (DVS) of 1280×720 pixels that emits asynchronous address-events with ~1 µs latency and per-event timestamps, and (b) a SPAD array with on-pixel time-to-digital converters (1 ns LSB) operating at 940 nm under eye-safe AEL limits for direct time-of-flight depth. The consequence is architectural: because each pixel carries an independent timestamp less than 2 µs wide, the relative motion between camera and face is recoverable from the event stream itself (event-based optical flow + depth), so the "path parameter" is defined as the 6-DoF face-to-camera relative trajectory rather than absolute device acceleration. The IMU is demoted to an outlier gate: any sample whose predicted event-flow exceeds 3σ is discarded. This makes the motion credential valid even on a fixed mount (webcam, kiosk, in-cabin) where the human moves and the device does not. Rolling-shutter flicker detection (see E11 banding) is replaced by direct measurement of backlight PWM frequency from the event inter-arrival histogram.

sequenceDiagram
  participant U as User
  participant D as Device DVS plus SPAD
  participant P as IMU outlier gate thread
  participant S as Verifier
  U->>D: moves head relative to fixed camera
  D->>P: per-event microsecond timestamps
  P->>P: camera to IMU temporal offset calibration
  D->>P: dToF depth map 940 nm
  P->>S: relative 6-DoF trajectory plus depth sequence
  S->>S: DTW band 80 ms Sakoe-Chiba plus jerk features
  S-->>D: decision plus confidence and liveness margin

DD-1.3 — On-chip photonic spectrometer and micro-mirror liveness front end (targets E2, E3, E7, E11)

Axis: Material & Component Substitution (photonic integration + piezoelectric MEMS at die scale).

Enabling description. Replace the color-filter-array camera's role in liveness with a silicon-nitride micro-ring resonator spectrometer: 32 rings, 450–1000 nm, 2 nm FWHM, thermo-optic tuning, coupled to a periscope pickoff of the same optical path used for face imaging. Skin spectral signature per frame yields the oxy/deoxyhemoglobin ratio, from which remote photoplethysmography is extracted in the 0.7–4 Hz cardiac band; a live 3D face exhibits a spatially coherent pulse phase map, a printed photograph does not and an LCD does not (LCD backlight PWM introduces its own, spectrally distinct, 90–300 Hz artifact). A 2 mm² MEMS scanning mirror rasters a 940 nm VCSEL to place structured fringes on the face and to track the corneal specular glint (first Purkinje image), whose position is a direct function of eye rotation. A nanoscale piezoelectric tether accelerometer (resonant MEMS, on-chip vacuum encapsulation) samples at 1 kHz to capture micro-jitter envelopes characteristic of a hand-held human. Composite score = f(biometric match, path DTW, pulse coherence, glint kinematics).

flowchart TD
  A["SiN micro-ring spectrometer 32 channels"] --> B["Per-frame skin spectral signature 450 to 1000 nm"]
  C["MEMS scanning mirror 2 mm die plus 940 nm VCSEL"] --> D["Structured fringe and corneal glint stream"]
  B --> F["Liveness classifier"]
  D --> F
  G["On-chip piezo tether accelerometer 1 kHz"] --> H["Micro-jitter envelope features"]
  H --> F
  F --> I["Composite score = biometrics + path + pulse + glint"]
  I --> J["Threshold gate E8 and E9"]

DD-1.4 — Industrial-scale portal: mmWave radar and UWB-anchored cohort path tracking (targets E1, E2, E4, E6, E10)

Axis: Operational Parameter Expansion (industrial scale, 8–10 m standoff).

Enabling description. A transit-hall / border-portal embodiment operating at 8 m standoff with a finger-to-gate budget of 200 ms. Two ToF arrays on a 1.5 m horizontal baseline produce disparity depth of a walking cohort; a 79 GHz FMCW MIMO radar with 4 GHz modulation bandwidth (~3.75 cm range resolution, 64 virtual channels) provides chest micro-motion (respiration 0.15–0.5 Hz, cardiac harmonics to 2 Hz) and presence detection under clothing, darkness, and occlusion. Ultra-wideband IEEE 802.15.4z anchors in the floor provide 10 cm device localization to bind the subject's carried handset to the biometric. The "path parameter" is redefined as a walking-corridor trajectory envelope: lateral sway amplitude and period, stride cadence (1.6–2.2 Hz), and head-bob vertical displacement, correlated against the subject's facial track through the portal. Threshold scales with cohort size; ≥ 3 simultaneous subjects forces serialization. Gate actuation and the full path/decision tuple are written to an immutable audit log.

flowchart LR
  A["Stereo ToF arrays 1.5 m baseline 8 m standoff"] --> C["Cohort tracker up to 10 subjects"]
  B["79 GHz FMCW MIMO radar 4 GHz BW"] --> D["Respiration and presence micro-motion"]
  H["UWB 802.15.4z floor anchors"] --> E
  C --> E["Walking-corridor path envelope"]
  D --> E
  E --> F["Edge inference rack 200 ms SLA"]
  F --> G["Gate actuation plus immutable audit log"]

DD-1.5 — Aerospace crew authentication with an environmental path channel (targets E4, E6, E9, E10, E14)

Axis: Cross-Domain Application (aerospace / urban air mobility).

Enabling description. Application to a single-pilot-operation eVTOL or Part 23/25 flight deck where the crew member authenticates to unlock aircraft control authority. A dual 850 nm NIR camera with active illumination captures the crew face; head pose is solved by PnP against a 3D canonical face model, giving an angular path descriptor in the head-frame. Critically, the "path parameter" channel is supplemented by the airframe's own trajectory: AHRS attitude rates, ADS-B/GPS ground track, and g-loading are treated as an independent environmental path channel, so the credential binds a live human to a specific aircraft trajectory state and cannot be replayed in a simulator or from the ground. A plausibility filter rejects trajectories inconsistent with the airframe envelope (e.g., > 3 g without corresponding attitude rate). Interfaces: ARINC 429 / AFDX for AHRS and FMS; DO-178C considerations for any software performing a safety function; the biometric decision is deliberately non-safety-critical and gates only control authority and dispatch release, not flight control law.

flowchart TD
  A["Crew camera NIR 850 nm dual"] --> B["Head pose PnP angular path descriptor"]
  C["AHRS and ADS-B trajectory"] --> D["Environmental path channel"]
  E["eVTOL cabin IMU and g-load sensor"] --> D
  B --> F["Crew biometric template E3 and E7"]
  D --> G["Path plausibility filter envelope and g-force"]
  F --> H["Fusion decision for control authority"]
  G --> H
  H --> I["Dispatch release and FMS privilege grant"]

DD-1.6 — AgTech: drone-flight-path-as-path-parameter for livestock and operator identity (targets E4, E6, E9, E10)

Axis: Cross-Domain Application (agriculture technology).

Enabling description. A drone or autonomous tractor performs the enrollment sweep, and the scheduled flight/waypoint path itself is the movement path parameter. A downward-facing 4K camera at 20 fps images cattle muzzles or operator faces as the platform executes a prescribed lawnmower/corridor pattern at 2–4 m AGL; the autopilot's EKF state (position, velocity, attitude, wind estimate) is recorded with the frames. Biometric matching uses muzzle-print (bovine) or face (human operator) templates; the path comparison validates that the imagery was collected on the commanded trajectory (rejecting off-mission or replayed imagery). Output gates a herd-record ledger and an automated dosing/feed-gate actuator. The inversion is notable and is what distinguishes this from the hand-held case: here the device movement is deterministic and known in advance, so the useful entropy is the correlation between the platform path and the parallax/silhouette evolution of the subject — a subject that does not exhibit the expected perspective evolution with respect to a known platform path is either absent or is a substitute object.

flowchart LR
  A["Drone autopilot waypoint path"] --> D["Path parameter channel E4 and E6"]
  B["Downward 4K camera 20 fps"] --> C["Muzzle-print or operator facial biometrics"]
  C --> E["Identity template E3 and E7"]
  D --> F["Correlation engine parallax vs platform path"]
  E --> F
  F --> G["Dosing gate and herd record ledger"]
  H["Wind and RTK corrections"] --> D

§3. Axis 2 — Operational Parameter Expansion (extreme scale, temperature, frequency, precision)

DD-2.1 — Sub-millisecond temporal regime: 2,400 fps vision and 10 kHz inertial sampling with IEEE 1588 synchronization (targets E4, E6, E9)

Axis: Operational Parameter Expansion (extreme frequency).

Enabling description. Push the sampling regime to the point where motion-path comparison becomes a micro-vibration credential. A machine-vision camera at 2,400 fps (0.42 ms frame period) and a 10 kHz IMU are disciplined to a common time base via IEEE 1588 PTP hardware timestamping (offset < 50 µs) implemented on an FPGA with one PPS input, and both streams are resampled onto a common 10 kHz lattice by polyphase interpolation. Features are then computed at a bandwidth unavailable to conventional 30 fps/100 Hz systems: jerk (m/s³) spectra, 20–500 Hz micro-tremor sidebands, and hand-tremor peak frequency (Parkinsonian 4–6 Hz vs. physiological 8–12 Hz). This enables a tremor-tolerant matched filter (adaptive notch at the subject's own tremor peak) so that subjects with pathological tremor are not systematically rejected, and simultaneously enables an additional discriminating feature for subjects without tremor. The comparison threshold becomes a pair (path correlation, tremor-spectrum divergence).

sequenceDiagram
  participant C as Camera 2400 fps
  participant I as IMU 10 kHz
  participant T as PTP grandmaster FPGA
  participant M as Matcher
  C->>T: frame timestamps with HW strobe
  I->>T: sample timestamps
  T->>M: aligned streams offset below 50 microseconds
  M->>M: polyphase resample to 10 kHz lattice
  M->>M: jerk spectrum and tremor notch features
  M-->>C: accept reject with margin and tremor flag

DD-2.2 — Cryogenic and MIL thermal envelope operation (targets E1, E2, E5, E11, E14)

Axis: Operational Parameter Expansion (extreme temperature: −55 °C to +125 °C, AEC-Q100 Grade 0 / MIL-STD-810H).

Enabling description. An embodiment for polar research stations, high-altitude platforms, and unpressurized vehicle exteriors. Failure physics are explicit: at −40 °C and below, (i) liquid-crystal and OLED response collapses, (ii) IMU bias drift and scale factor shift by 10–100×, (iii) battery impedance rises sharply, and (iv) condensation on the imager destroys the optic. The disclosure therefore specifies: a heated sapphire window with an ITO resistive film (2 W), a microbolometer LWIR 8–14 µm channel as the primary liveness modality (thermal is not degraded by low visible illumination and is inherently emissive), and IMU thermal compensation by a factory second-order bias-vs-temperature model stored in one-time-programmable memory and re-fit in the field using the observation that a stationary device during an enforced 300 ms hold must produce zero net displacement. Enrollment templates are stored with the ambient temperature and device skin temperature at capture and the matcher inflates the acceptance band linearly with |ΔT|, since facial thermal patterns shift with ambient. Enclosure: magnesium thixomolded alloy with Gore vent and conformal-coated PCB for condensation cycling.

flowchart TD
  A["Heated sapphire window ITO 2 W"] --> B["Visible imager with thermal compensation"]
  C["LWIR microbolometer 8 to 14 um"] --> D["Thermal facial pattern and head-shape classifier"]
  E["IMU with OTP bias-vs-temperature model"] --> F["Temperature-aware path descriptor"]
  B --> G["Biometric template with T at capture"]
  D --> H["Liveness verdict"]
  F --> I["Tolerance-inflating matcher delta-T scaled"]
  G --> I
  H --> I
  I --> J["Decision with provenance temperature record"]

DD-2.3 — Extreme-precision: sub-centimetre pose metrology for controlled-environment access (targets E4, E6, E9, E13)

Axis: Operational Parameter Expansion (extreme precision / extreme low tolerance).

Enabling description. A pharmaceutical cleanroom, semiconductor fab, or nuclear-material handling cell where the acceptable false-accept rate is ≤ 10⁻⁷ and the corresponding false-reject cost is high. Here the path parameter is metrologically characterized rather than merely pattern-matched: the device carries two co-visible fiducial markers and the imager performs bundle adjustment over the capture interval, yielding the camera pose to ±2 mm and ±0.2° absolute, and the motion residual to ±0.5 mm. The enrolled path is stored as a sparse set of keyframe poses plus a B-spline. Authentication requires the authentication trajectory, after Procrustes alignment (rotation + translation, scale fixed by the subject's IPD), to lie within a Fréchet distance of 3.5 mm of the enrollment spline. Because the tolerance is tighter than a human can consciously reproduce, the credential is a motor-program credential rather than a gesture password: the subject is explicitly instructed not to try to reproduce the motion, and the system uses the natural reproducibility of overlearned motor programs. Failed attempts are rate-limited by a monotone increasing inter-attempt delay (Fibonacci backoff).

flowchart LR
  A["Dual fiducial markers on device"] --> C["Bundle adjustment over capture interval"]
  B["Camera with distortion-calibrated intrinsics"] --> C
  C --> D["Pose stream plus or minus 2 mm and 0.2 deg"]
  D --> E["Fitted B-spline enrollment trajectory"]
  E --> F["Procrustes alignment scale fixed by IPD"]
  F --> G["Frechet distance gate 3.5 mm"]
  G --> H["Admit or rate-limited Fibonacci backoff"]

§4. Axis 3 — Cross-Domain Application (unrelated industries)

DD-3.1 — Medical point-of-care: patient identity and controlled-substance dispensing (targets E3, E5, E8, E10, E13)

Axis: Cross-Domain (clinical / healthcare).

Enabling description. Apply the mechanism to positive patient identification at the bedside and at an automated dispensing cabinet. The clinical setting changes the parameters materially: (i) patients may be supine and immobile, so the face-to-camera motion path must be produced by the clinician's handheld device in a controlled orbital sweep around the patient's head (the arc is the key parameter, and its radius must be consistent with the bed geometry profile stored with the patient record); (ii) the "expected movement" is defined by prompted motion rather than an enrolled motion when the patient is a first-time presenter, with the prompt sequence varied per dose to prevent capture-replay; (iii) patient biometric templates are enrolled at admission and bound to the medical record number, with a break-glass override that is logged but which cannot be silently used more than twice per shift; (iv) HIPAA-aligned handling: templates are stored as irreversible feature vectors in an HSM-backed keystore and images are deleted post-extraction, with the deletion event itself written to the audit log. Dispensing requires the compound score of prescriber identity, patient identity, and dose-path correlation.

flowchart TD
  A["Clinician handheld camera"] --> C["Orbital arc around supine patient"]
  B["Bed geometry profile at admission"] --> D["Expected radius and arc envelope"]
  C --> E["Patient facial biometric E3 and E7"]
  D --> F["Path correlation gate E9"]
  E --> G["Prescriber identity E8"]
  F --> H["Dose authorization compound score"]
  G --> H
  H --> I["Dispensing cabinet actuator and audit log"]
  H --> J["Break-glass override rate limited twice per shift"]

DD-3.2 — Consumer AR/VR headset: IMU-native motion credential (targets E1, E2, E4, E6, E11)

Axis: Cross-Domain (consumer electronics / XR).

Enabling description. In a head-mounted display, the device is strapped to the head, so the enrollment "movement of the mobile device" is re-expressed as the HMD's own 6-DoF SLAM trajectory and the user's vestibulo-ocular behavior. Cameras at 90 Hz inside-out track the room and the user's eyes; the enrollment motion credential is drawn from (i) the head trajectory during a prompted look-target sequence, (ii) vestibulo-ocular reflex gain (eye counter-rotation per degree of head rotation, normally 0.9–1.1) measured by simultaneous eye-tracker and IMU, and (iii) pursuit-gain during a smoothly moving on-screen target (a target moving at 15 °/s with pursuit gain < 0.8 or > 1.2 is anomalous). The VOR and pursuit channels are, critically, reflexes that cannot be voluntarily spoofed and are not reproducible from a recorded video of a face, which makes them a stronger liveness primitive than blink counting. Enabling hardware: 4× inside-out tracking cameras, dual 200 Hz eye cameras with 850 nm illumination, MEMS IMU at 1 kHz, and a display capable of ≥ 90 Hz pattern presentation for the pursuit stimulus.

sequenceDiagram
  participant U as Headset wearer
  participant I as IMU 1 kHz
  participant E as Eye cameras 200 Hz
  participant D as Display 90 Hz
  participant M as Matcher
  D->>U: prompted look-target and pursuit stimulus
  U->>I: head rotation trajectory
  U->>E: eye counter-rotation and pursuit tracking
  I->>M: head path descriptor
  E->>M: VOR gain and pursuit gain
  M->>M: compare to enrolled reflexes and path
  M-->>D: session authorization and anti-spoof verdict

§5. Axis 4 — Integration with Emerging Technology

DD-5.1 — AI-optimized path matching with federated learning and adversarial hardening (targets E3, E7, E8, E9, E13)

Axis: Integration with Emerging Tech (AI-driven optimization).

Enabling description. The joint (frame, IMU) tensor is processed by a two-tower contrastive encoder: a ViT or mobile-CNN tower over cropped face frames, and a 1D temporal CNN / dilated-convolution tower over the 9-DoF IMU stream, fused by cross-attention and projected into a shared embedding via a triplet loss with hard-negative mining (negatives = the same subject's other sessions, motion-adversarial negatives = the subject's biometric with a substituted path). Training is federated: device-side gradients are clipped to L2 norm 1.0 and noised with Gaussian σ = 1.1 (DP-SGD) under an (ε=8, δ=10⁻⁵) accountant, aggregated by FedAvg with secure aggregation; only quantized updates leave the device. Robustness is engineered rather than hoped for: PGD/FGSM adversarial trajectories are generated by optimizing a bounded L∞ perturbation of the IMU series (ε = 0.05 g) to flip the decision, and the model is trained on them; a Mahalanobis distance rejection on the embedding serves as an open-set detector. The production model is knowledge-distilled to INT8 and executed inside the device TEE (ARM TrustZone / StrongBox), with the teacher running only at enrollment.

flowchart TD
  A["Joint tensor frames plus 9-DoF IMU"] --> B["1D dilated temporal encoder"]
  A --> C["ViT face embedding tower"]
  B --> D["Cross-attention fusion"]
  C --> D
  D --> E["Triplet loss with hard and motion-adversarial negatives"]
  E --> F["PGD perturbation training epsilon 0.05 g"]
  F --> G["Federated averaging with DP-SGD epsilon 8"]
  G --> H["Distilled INT8 model in TEE"]
  H --> I["Open-set Mahalanobis rejection and step-up policy"]

DD-5.2 — Hash-anchored enrollment templates with DIDs, verifiable credentials, and IoT session context (targets E5, E10, E13, E14)

Axis: Integration with Emerging Tech (blockchain/DLT + IoT real-time monitoring).

Enabling description. Enrollment produces a biometric template T; the system computes a Poseidon commitment C = H(T ‖ r) (a ZK-friendly hash over a 254-bit prime field, ~8× cheaper in-circuit than SHA-256) and anchors only C to a permissioned ledger (Hyperledger Fabric, Raft ordering service, MSP-based identity), never the template. The subject's identifier is a W3C Decentralized Identifier (did:key or did:web); access grants are issued as W3C Verifiable Credentials signed with Ed25519 and status-tracked by a BLS revocation accumulator so that revocation is O(1) to verify. Session context is supplied by BLE 5.1 AoA / UWB ranging beacons (as well as by deployed Matter/Thread building sensors) that attest physical proximity and room occupancy, and by an MQTT/Sparkplug B telemetry plane that streams path-descriptor digests to a digital twin for anomaly scoring. Note the essential ordering: the DLT provides tamper-evident provenance and revocation, not confidentiality — confidentiality comes from the template being non-invertible and from the ZK layer (see DD-10.4).

erDiagram
  SUBJECT ||--o{ ENROLLMENT_TEMPLATE : owns
  ENROLLMENT_TEMPLATE ||--|| TEMPLATE_COMMITMENT : hashes_to
  TEMPLATE_COMMITMENT ||--o{ LEDGER_ANCHOR : recorded_as
  DEVICE ||--o{ ATTESTATION : produces
  ATTESTATION ||--|| LEDGER_ANCHOR : bound_to
  SESSION ||--o{ PATH_PROOF : contains
  PATH_PROOF ||--|| VERIFIABLE_CREDENTIAL : issues
  IOT_BEACON ||--o{ SESSION : contextualizes
  DID ||--o{ VERIFIABLE_CREDENTIAL : subject_of
  REVOCATION_ACCUMULATOR ||--o{ VERIFIABLE_CREDENTIAL : status_of

§6. Axis 5 — The "Inverse" and Failure-Mode Disclosures

DD-6.1 — Intentional-degradation ladder: low-power "path-lite" mode with step-up (targets E6, E8, E9, E13)

Axis: Inverse / low-power limited-functionality mode.

Enabling description. Rather than a binary accept/reject, the system operates a three-rung assurance ladder so that it degrades predictably rather than failing open. Rung 0 (Dormant) keeps the camera off and the IMU in a 32 Hz low-power interrupt mode; a sustained acceleration impulse above 0.35 g for 120 ms wakes rung 1. Rung 1 (PathLite) runs 5 fps capture and reduces the path comparison to a 2-DoF (yaw, roll) correlation over a 1.5 s window with a relaxed threshold T1; a pass grants only "limited-functionality" session rights (read-only, no high-value transaction, no credential export). Any request for a high-value operation, or any three consecutive PathLite near-misses, escalates to rung 2 (FullPath), which wakes the camera to 30 fps, enables the 9-DoF descriptor, and applies the full threshold T2 with all E11 liveness sub-signals. The ladder is enforced by a monotone policy engine that can tighten but never loosen thresholds; the escalation decision is itself a logged event. This addresses the well-known mobile failure mode where an aggressive power manager silently disables the sensor the credential depends on, producing a fail-open window.

stateDiagram-v2
  [*] --> Dormant
  Dormant --> Sense: motion interrupt above 0.35 g
  Sense --> PathLite: 5 fps and 2-DoF path correlation
  PathLite --> GrantLimited: score above T1
  PathLite --> Reject: score below T1
  GrantLimited --> StepUp: high-value request or 3 near-misses
  StepUp --> FullPath: camera to 30 fps, 9-DoF descriptor
  FullPath --> GrantFull: score above T2 plus liveness pass
  FullPath --> Reject: score below T2 or liveness fail
  GrantLimited --> Dormant: session timeout
  Reject --> Dormant: backoff
  GrantFull --> Dormant: session end

DD-6.2 — Fail-closed sensor cross-validation with independent-channel arbitration (targets E2, E4, E9, E11)

Axis: Inverse / fail-safe-by-construction.

Enabling description. A defective or spoofed motion sensor must not silently produce a passing credential. The device runs redundant, physically independent estimators of the same physical quantity: (i) the IMU-integrated trajectory, (ii) the visual-inertial (VIO) trajectory from the camera, and (iii) a magnetometer-plus-gravity dead-reckoning trajectory. Agreement is tested continuously by a χ² innovation consistency test: the normalized innovation squared of each estimator against the others must stay below a gate (e.g., χ²₃ = 7.81 at p = 0.05) over the capture window. Exceedance ≤ 200 ms triggers a re-capture request; exceedance beyond 200 ms transitions to FaultHold, which neither grants nor denies but escalates to an adjudicator, then to FailClosed if no adjudication within 30 s. A watchdog with an independent clock source (a 32.768 kHz crystal on a separate power domain) resets the credential engine if it fails to produce a heartbeat for 500 ms — the "dead man" for the matcher itself. Each sensor is also bound by a device attestation (TPM 2.0 / Android StrongBox) so that a compromised sensor driver cannot assert a fabricated path.

stateDiagram-v2
  [*] --> Armed
  Armed --> Capturing: shutter open, capture window starts
  Capturing --> Validating: chi-square consistency over 3 estimators
  Validating --> Verified: all channels agree within gate
  Validating --> FaultHold: sensor disagreement beyond 200 ms
  FaultHold --> ManualReview: escalation to adjudicator
  FaultHold --> FailClosed: no adjudication within 30 s
  Validating --> FailClosed: attestation failure
  Verified --> SessionOpen
  SessionOpen --> Armed: session end
  ManualReview --> Verified: adjudicated pass
  ManualReview --> FailClosed: adjudicated fail
  FailClosed --> Armed: maintenance reset with audit

DD-6.3 — Coercion-resistant duress path and decoy enrollment (targets E4, E5, E9, E13)

Axis: Inverse (adversarial-human failure mode; coercion rather than spoofing).

Enabling description. The classic failure of a biometric system is the coerced genuine user: the sensor sees a real, present, matching 3D face and correctly authenticates, because authentication is not authorization. This disclosure specifies a motion-domain duress channel. During enrollment, in addition to the primary path P, the user records a secondary path P′ (a "duress path") presented in the UI as an optional privacy gesture — e.g., a reversed-direction arc of the same amplitude, or an arc performed with a characteristic pause at mid-arc. At authentication, if the recorded path matches P′ rather than P, the system issues a success response with identical content, byte-length, and response latency (a constant-time comparator enforces ≤ 5 ms latency variance) but silently (a) writes a duress flag, (b) notifies a pre-registered guardian/trusted contact over an out-of-band channel, and (c) grants only a limited-functionality session — for example a funding cap of 200 currency units and no address-book or credential-export access — so that the coercer observes an apparently normal success. Additionally, decoy enrollment profiles may be created (e.g., the user's face enrolled under a second, separate identity) so that a coerced presentation of the real face to a decoy profile yields a fully instrumented, monitored session. Crucially, duress detection must be undetectable from the response, which means no differential timing, no differential UI, and no differential network round-trip count.

stateDiagram-v2
  [*] --> Idle
  Idle --> Capture
  Capture --> Evaluate: biometrics plus path descriptor
  Evaluate --> Grant: primary path P matched
  Evaluate --> Duress: duress path P prime matched
  Evaluate --> Deny: neither matched
  Duress --> GrantCovert: constant-time identical response
  GrantCovert --> SilentAlert: out-of-band guardian notification
  GrantCovert --> LimitedMode: funding cap and no export
  LimitedMode --> Idle
  Grant --> Idle
  Deny --> Idle: backoff

§7. Precisely-scoped derivative set (transferable to claim families 10 and 18)

The public record shows independent claims at 1, 10 and 22 in the sibling '910 and a challenged claim set of 1–24 in the '938, with the method independent claim carrying the E1–E14 sequence and the server independent claim carrying E5, E8, E9, E14. The following five derivatives are drafted explicitly against the method family (E1→E9 in sequence) and the following five against the server family (E5/E8/E9/E14), so the disclosure covers both the on-device and the remote-verification architectures.

DD-7.1 — Structural-strain path sensing (method family; materials substitution for E2/E4)

Enabling description. Replace inertial sensing entirely with structural strain of the handset or enclosure as the movement signal. A 28 µm PVDF piezoelectric film (or printed silver-nanowire strain-gauge rosette) is laminated into the device shell or a case; a charge amplifier with 10¹² Ω transimpedance and a 16-bit, 1 kHz ADC digitizes the strain tensor ε(t) at ≥ 4 rosette sites. The 6-component strain vector is converted to a board deformation descriptor by modal reduction: D(t) = Φᵀ ε(t), where Φ is a basis of the first 6 shell modes previously identified by impact-hammer modal testing. Because grip force, wrist torque, and arm-arc dynamics all imprint distinctly on D(t), the strain descriptor can substitute for the IMU path parameter and, in addition, yields a grip-biometric entropy channel (each user's grip-force envelope is idiosyncratic). This has a practical advantage in tamper resistance: strain gauges cannot be spoofed by an injected IMU bus message, and a strain profile inconsistent with the visually observed motion is itself a spoof signal.

flowchart LR
  A["PVDF piezo film strain skin 28 um"] --> D["Charge amp 16-bit 1 kHz ADC"]
  B["Silver-nanowire strain rosette grid"] --> D
  C["Conductive e-textile capacitive patch"] --> D
  D --> E["Modal reduction to board deformation descriptor"]
  E --> F["Enrollment deformation template E4"]
  F --> G["Authentication comparison E9 with grip envelope feature"]
  G --> H["Consistency test against visual motion channel"]

DD-7.2 — Vehicular identity and driver-state fusion (method family; cross-domain, E4/E6/E9/E10)

Enabling description. Apply the method to an automotive in-cabin context where the enrollment mobility is replaced by prescribed vehicle maneuvers. A 940 nm driver-monitoring camera at 60 fps yields facial landmarks, head pose, and gaze; the vehicle's CAN bus supplies yaw rate, lateral acceleration, steering torque, and longitudinal acceleration. The disclosed mechanism binds identity to a vehicle maneuver signature: the driver enrolls during a scripted sequence (straight-line 200 m, a prescribed radius turn, a lane change) and the biometric template is stored bound to the maneuver state vector. Authentication then requires the facial biometric to match while the maneuver-state path matches within tolerance, which defeats remote replay (a remote attacker cannot reproduce the vehicle dynamics) and binds the credential to the physical act of driving. The same channel detects driver-state anomalies (gaze off-road > 2.3 s, blink rate < 10/min, head-drop events) and may derate the infotainment or escalate to a driver-monitor warning. Immobilizer and HMI privileges derive from the fused decision.

flowchart TD
  A["In-cabin 940 nm DMS camera 60 fps"] --> B["Head pose, gaze, and blink landmarks"]
  C["Vehicle CAN IMU and steering torque"] --> D["Maneuver-state path signature"]
  E["Seat weight and capacitive occupancy"] --> F["Occupant classifier"]
  B --> G["Driver identity template E3 and E7"]
  D --> H["Path correlation gate E9"]
  F --> G
  G --> I["Immobilizer and HMI privilege policy"]
  H --> I
  H --> J["Driver-state derate and warning"]

DD-7.3 — Privacy-preserving proof of match (method + server families; emerging tech, E5/E8/E9/E14)

Enabling description. Replace "send the template and let the server compare" with "prove the match without revealing the template." The enrolled template T is committed as C = H(T ‖ r) (Poseidon). At authentication, the device computes the same commitment on the freshly extracted template T′ and generates a Groth16 zk-SNARK proving the statement: I know (T′, r′, w) such that H(T′ ‖ r′) = C′ and d(T′, T) ≤ τ, where the distance predicate is expressed as a bounded arithmetic circuit (for a cosine or L2 distance, the circuit is a fixed-shape inner-product and comparison) and w is a valid non-membership witness against a revocation accumulator. The verifier learns only "authenticated" or "not," never the template, the score, or the raw path. The same construction applies to the motion channel: the path descriptor is committed to a second accumulator and the circuit proves DTW-bounded correspondence by proving the soundness of a fixed-warp-path alignment (the warp path itself being a private witness, with the band constraint enforced in-circuit). Output is a scoped, short-lived bearer token signed with HTTP Message Signatures (RFC 9421) so that the decision is bound to the request it authorizes.

sequenceDiagram
  participant D as Device TEE
  participant V as Verifier service
  participant L as Ledger and accumulator
  D->>D: compute C prime = H T prime r prime
  D->>D: build circuit for distance below tau with private warp path
  D->>V: Groth16 proof plus public C prime
  V->>L: read anchored C and revocation accumulator state
  V->>V: verify proof and non-revocation witness
  V-->>D: scoped token signed per RFC 9421

DD-7.4 — Photonic and quantum-enhanced verification back end (server family; materials substitution for E8/E14)

Enabling description. At the server tier, substitute the von Neumann matcher with a photonic tensor core: a silicon-photonic Mach-Zehnder interferometer mesh performing the matrix-vector products of the embedding projection at 8-bit effective precision and > 10 TOPS/W, with the template store held in a phase-change-material (GST or Sb₂Se₃) non-volatile photonic memory co-packaged on the same interposer. This is not merely an efficiency claim — the physics is used as a security property: the photonic core's analog noise floor (relative intensity noise, thermal drift) makes single-bit template exfiltration impractical, because the memory contents cannot be read out digitally without destroying the analog state. Session nonces and liveness challenges are drawn from a quantum random number generator (photon-arrival-time source, NIST SP 800-90B validated conditioning) rather than a PRNG, so that a challenge cannot be predicted from a compromised PRNG state. Key custody is in an HSM cluster with FIPS 140-3 Level 3 modules and TPM 2.0 attestation of every matcher node.

flowchart LR
  A["Photonic tensor core MZI mesh"] --> D["Embedding projection and matcher inference"]
  B["QRNG entropy source arrival-time SP 800-90B"] --> E["Per-session challenge generator"]
  E --> F["Screen-projected random pattern E11"]
  C["HSM FIPS 140-3 L3 plus TPM 2.0"] --> G["Template key custody and attestation"]
  H["PCM photonic template store GST"] --> D
  G --> D
  D --> I["Decision service with audit hash chain"]
  F --> I

DD-7.5 — Server-outage degraded operation with deferred reconciliation (server family; inverse/failure mode, E5/E13/E14)

Enabling description. The server-mediated architecture has a single dominant failure mode: loss of the upstream verifier. This disclosure defines a coordination protocol that degrades to on-device verification without opening a forgery window. The device caches at enrollment a sealed, hardware-bound copy of the template (wrapped under a key in the TEE, deleted on remote revocation receipt). When the upstream is unreachable, the device transitions to OfflineLocal and, if unsealed proof is available, grants only LimitedGrant (local score above a strictly tighter threshold T3, with a hard per-24h cap on both transaction count and value). If no sealed template is cached, the device transitions to ChallengeOnly: a local liveness-only pass is sufficient for a non-transactional session, and no privileged operation is permitted. Every offline decision is queued as a signed, monotone-counter-stamped assertion in a durable journal; on link restoration, the journal is replayed to the server, which reconciles the offline grants and may revoke future privileges (including forcing re-enrollment) if the offline decisions are consistent with an attack pattern. The monotone counter is critical: it prevents the offline journal from being rolled back to replay an earlier authorization.

stateDiagram-v2
  [*] --> Online
  Online --> Degraded: upstream unreachable beyond RTT budget
  Degraded --> OfflineLocal: sealed template cache present
  Degraded --> ChallengeOnly: no cache available
  OfflineLocal --> LimitedGrant: local score above T3 and under 24h cap
  ChallengeOnly --> LimitedGrant: liveness-only pass for non-transactional session
  ChallengeOnly --> Deny: liveness fail
  LimitedGrant --> Reconcile: link restored, journal replay
  Reconcile --> Online: reconciled
  Reconcile --> ForceReenroll: anomaly in offline decision sequence
  Deny --> Online: link restored

§8. Combination Prior Art Scenarios (patent + open standard)

Each scenario is drafted so that the combination itself is a machine-implementable disclosure, with named standards and interface artifacts.

CP-1 — US 11,693,938 mechanism + W3C WebAuthn Level 3 / FIDO2 CTAP2 + Android Sensor API and StrongBox

Enabling description. Define a CTAP2 vendor extension (extMotionPath) carried in PublicKeyCredentialCreationOptions.extensions and PublicKeyCredentialRequestOptions.extensions. The authenticator (the mobile device) samples the platform motion sensors through the platform sensor API (Android SensorManager at SENSOR_DELAY_FASTEST, events timestamped in nanoseconds from the same monotonic clock as the camera frame timestamps; or iOS CMDeviceMotion with CMDeviceMotion.timestamp), computes the path descriptor, and compares it to a template sealed under a WebAuthn credential private key held in the secure element / StrongBox. The signed extension output is returned in the authenticatorData extensions map, so the relying party receives a standards-conformant assertion in which the biometric-plus-path decision is cryptographically bound to the WebAuthn ceremony (challenge, origin, RP ID). This combination is significant as prior art because it converts the proprietary decision into a portable, verifier-agnostic signed assertion — a design point a competitor would plausibly attempt to claim. Reference the extension output schema as a CDDL definition with the fields fmt, pathHash, pathScore, uvm, and livenessClass.

sequenceDiagram
  participant RP as Relying party app
  participant CT as CTAP2 client platform
  participant AU as Authenticator in TEE and StrongBox
  RP->>CT: PublicKeyCredentialRequestOptions with extMotionPath
  CT->>AU: getAssertion with challenge and rpId
  AU->>AU: sample IMU 200 Hz plus frames 30 fps
  AU->>AU: build path descriptor and compare to sealed template
  AU->>AU: sign authenticatorData with extension output
  AU-->>CT: assertion with signed extMotionPath
  CT-->>RP: WebAuthn response with UV and liveness class

CP-2 — US 11,693,938 mechanism + ISO/IEC 30107-3 PAD evaluation + OpenCV/MediaPipe + FastDTW + OpenTelemetry

Enabling description. Build the mechanism entirely from open-source components and evaluate it against a published conformance framework. MediaPipe Face Mesh supplies 468 3D landmarks per frame; OpenCV Farnebäck dense optical flow supplies inter-frame motion; FastDTW (or tslearn's soft_dtw) performs the banded trajectory alignment against the enrolled path. The pipeline is instrumented with OpenTelemetry (traces for capture, extraction, comparison; metrics for APCER/BPCER, latency histograms, and score distributions; baggage for session and device class), and the anti-spoof performance is reported per ISO/IEC 30107-3 attack types (Type 1 printed photo, Type 2 video replay, Type 3 3D mask) using the standard APCER/BPCER nomenclature and the PAD decision taxonomy. Emission goes to a Kafka topic for the offline evaluation harness. The combination is useful as prior art precisely because it is unremarkable to a POSITA — it shows the mechanism implemented with commodity libraries and reported against an existing standard, i.e., it forecloses an attempt to claim the mere replacement of a bespoke matcher with DTW plus a published PAD framework.

flowchart TD
  A["MediaPipe Face Mesh 468 landmarks"] --> D["Landmark trajectory stream"]
  B["Platform sensor API accelerometer gyro magnetometer"] --> E["IMU trajectory stream"]
  C["OpenCV Farneback dense optical flow"] --> D
  D --> F["FastDTW alignment with 5 percent band"]
  E --> F
  F --> G["ISO 30107-3 PAD report APCER BPCER by attack type"]
  G --> H["Kafka topic auth telemetry"]
  H --> I["OpenTelemetry traces and metrics dashboards"]

CP-3 — US 11,693,938 mechanism + W3C Verifiable Credentials + ISO/IEC 18013-5 mDL + Hyperledger Fabric

Enabling description. Compose the disclosure around a mobile driving licence presentation flow. Enrollment produces a template compliant with an ISO/IEC 19794-5-style feature vector; the credential is issued as a W3C Verifiable Credential whose subject DID is the holder's wallet DID and whose credentialSubject carries the template commitment and the disclosure policy. On presentation, the device issues a zero-knowledge range proof over the commitment attesting template match (see DD-7.3) and a non-revocation witness against the Fabric-anchored accumulator, and returns a selective-disclosure token rather than the raw template. The mDL namespace provides interoperable element identifiers for the verifier, and the presentation is bound to the verifier's nonce via RFC 9421 HTTP Message Signatures. The combination forecloses the "put a biometric check on top of a W3C VC" improvement claim by disclosing the specific composition of commitment, accumulator, and selective disclosure.

flowchart LR
  A["Enrollment on device ISO 19794-5 feature vector"] --> B["Commitment Poseidon hash"]
  B --> C["Hyperledger Fabric anchor channel"]
  D["ISO 18013-5 mDL element namespace"] --> E["W3C Verifiable Credential issuance"]
  C --> E
  E --> F["Holder wallet with did:key"]
  F --> G["Verifier with zk range proof and non-revocation witness"]
  G --> H["Selective-disclosure token signed per RFC 9421"]

CP-4 — US 11,693,938 mechanism + ROS 2 / DDS + Eclipse Sparkplug B + OpenTelemetry for industrial fleets

Enabling description. Industrialize the mechanism as a ROS 2 node lifecycle: a biometric_gate node subscribes to three DDS topics (/camera/frames, /imu/samples, /device/attestation) with a best_effort QoS for sensor data and reliable for the decision topic, and publishes /auth/path_descriptor and /auth/decision. The node is managed by a lifecycle state machine (unconfigured → inactive → active → finalized) so that an unconfigured gate cannot authenticate. Decisions are uplinked through Sparkplug B over MQTT to a plant historian for OEE/uptime analytics (retained birth/death certificates, per-metric NDATA payloads with monotonically increasing sequence numbers), and the same decisions are exported via OTLP to an OpenTelemetry collector. This addresses a realistic industrial concern that the patent does not: fleet-level observability and per-asset attestation — a gate that is offline, tampered with, or running a stale model must be visible in the historian.

flowchart TD
  A["ROS 2 node biometric_gate"] --> B["DDS topic path_descriptor"]
  C["Camera driver node"] --> B
  D["IMU driver node"] --> B
  E["Attestation node TPM quote"] --> B
  B --> F["Policy node with lifecycle unconfigured to active"]
  F --> G["Sparkplug B MQTT uplink retained birth certificate"]
  G --> H["Plant historian and digital twin"]
  F --> I["OpenTelemetry OTLP exporter"]
  I --> J["Collector to object store and dashboards"]

§9. Assertion matrix (derivative → axis → element → art posture)

ID Axis Elements Art posture vs. Derakhshani / Tanii / Zhang / Tahk / Suzuki
DD-1.1 Material E1,E2,E4,E6,E9 Non-analogous sensor class (FOG/piezo); no art teaches EMI-motivated inertial substitution for path credentials
DD-1.2 Material E1,E2,E4,E6,E11 Event/SPAD architecture makes path a relative face-camera trajectory; art is frame-based and absolute
DD-1.3 Material E2,E3,E7,E11 On-chip spectroscopy + glint tracking; art teaches distortion/parallax only
DD-1.4 Parameter E1,E2,E4,E6,E10 Portal-scale cohort path envelope; art is single-user, arm's-length
DD-1.5 Cross-domain E4,E6,E9,E10,E14 Environmental path channel (airframe state); no analog in art
DD-1.6 Cross-domain E4,E6,E9,E10 Platform path as the known variable; art teaches device movement only
DD-2.1 Parameter E4,E6,E9 Sub-ms synchronization; tremor-tolerant matched filter; absent from art
DD-2.2 Parameter E1,E2,E5,E11,E14 LWIR-primary + temperature-inflated tolerance; thermal liveness absent from Derakhshani/Zhang
DD-2.3 Parameter E4,E6,E9,E13 Metrological bundle adjustment + Fréchet gate; motor-program credential framing is novel
DD-3.1 Cross-domain E3,E5,E8,E10,E13 Supine patient orbital arc + break-glass rate limit
DD-3.2 Cross-domain E1,E2,E4,E6,E11 VOR/pursuit-gain liveness — involuntary, non-replayable; strongest non-art channel in this set
DD-5.1 Emerging tech E3,E7,E8,E9,E13 Federated + adversarially-trained path embedding; art contains no motion-adversarial training
DD-5.2 Emerging tech E5,E10,E13,E14 Commitment-only anchoring + DID/VC + beacon session context
DD-6.1 Inverse E6,E8,E9,E13 Assurance ladder prevents fail-open under power management
DD-6.2 Inverse E2,E4,E9,E11 χ² cross-estimator arbitration + independent watchdog + attestation
DD-6.3 Inverse E4,E5,E9,E13 Duress path with constant-time identical response — coercion model, not spoof model
DD-7.1 Method/materials E2,E4,E9 Structural strain replaces IMU; non-injectable channel
DD-7.2 Method/cross-domain E4,E6,E9,E10 Maneuver-state path signature binds identity to driving dynamics
DD-7.3 Method+server/tech E5,E8,E9,E14 In-circuit distance predicate with private warp path
DD-7.4 Server/materials E8,E14 Photonic/PCM store as an exfiltration barrier; QRNG challenge entropy
DD-7.5 Server/inverse E5,E13,E14 Monotone-counter offline journal with server reconciliation
CP-1 … CP-4 Standard composition all Forecloses "replace bespoke pipeline with known standard/library" improvement claims

§10. Publication protocol (to perfect the prior-art date)

To convert this draft into enforceable prior art against later-filed third-party applications:

  1. Fixed corpus. Serialize this document with a SHA-256 manifest of every section; produce a single PDF plus the Mermaid sources in plain text (diagram sources are part of the disclosure and must be legible without a renderer).
  2. Multiple independent timestamp anchors. (a) A defensive-publication service (IP.com / Research Disclosure) providing a citable disclosure identifier and publication date; (b) a public preprint with DOI (arXiv or Zenodo) so the disclosure is searchable by examiners; (c) an OpenTimestamps Bitcoin-anchored proof over the SHA-256 digest, and a signed Git commit in a public repository with a GPG/SSH-signed tag.
  3. Content requirements for § 102 enablement. Each derivative must state the structure, the operating parameters (rates, tolerances, thresholds), and at least one worked numerical example; the tables in §9 and the parameters embedded in each enabling description are drafted to satisfy this.
  4. Do not rely on the diagrams alone. Mermaid renders client-side; include the plain-text source and a prose restatement in each section so the disclosure survives without the renderer.

§11. Explicit uncertainties

  • I could not independently verify the exact text of independent claims 1, 10, and 22 of the '938 specifically (the claim text returned by retrieval is from application 16/357,205, which issued into a different family member, US 10,776,471). Any statement here about "claims 1/10/22 of the '938" should be confirmed against the issued '938 claim set before relying on it. The FWD for IPR2025-00108 did hold all challenged claims of the '938 unpatentable-free (i.e., upheld), per FaceTec's 2026-06-09 announcement and press coverage naming IPR2025-00108 / US 11,693,938 explicitly.
  • The exact FWD claim-by-claim disposition for the '938 (as opposed to the four-IPR aggregate outcome) was not retrieved; get the FWD from the PTAB Decisions portal to confirm.
  • Whether any of these derivatives is itself patentable is not asserted. This is a defensive publication; the intent is to bar others, and the disclosing entity hereby dedicates the subject matter to the public to the extent permitted, while reserving any rights it independently holds.

Generated 9/15/2026, 12:22:08 AM

Keep exploring

More patents asserted by Jumio Corporation

Other patents in Financial Technology (FT)

See all Financial Technology (FT) patents →

This patent in court (3)

3 tracked lawsuits name US 11693938.