The Problem

Most authentication systems make a trust decision only once: at login. If the correct password or credentials are entered, the session is trusted. But the person behind the screen can change after authentication.

This creates a gap in security. Stolen credentials, session hijacking, replay attacks, deepfakes, and another person taking over an active session can remain undetected.

Our Solution — Mitra Verify

Mitra Verify is a continuous biometric verification platform that verifies the person, not just the credential.

Instead of stopping authentication after login, Mitra Verify continuously evaluates the user through the device camera and makes ongoing trust decisions.

The platform provides three verification levels:

API 1 — Fast Liveness API

The first layer checks whether a real person is present.

It uses face presence, motion, and liveness detection. Users are given biometric challenges such as looking up, looking down, looking left, looking right, centering their face, blinking, or opening their mouth.

If the challenge is completed correctly, verification continues.

If the user does not perform the required action within the verification window, the system treats the interaction as suspicious instead of waiting indefinitely.

API 2 — Advanced Anti-Spoof API

The second layer focuses on whether the interaction is genuine.

It introduces randomized biometric challenges and checks for active challenge-response behavior, replay attempts, spoofing, and deepfake-like interactions.

The challenge is not fixed. Different challenges can be selected during a session, making it harder to simply replay a previously captured interaction.

If the expected response is not detected or the interaction appears suspicious, the session can be flagged and access can be revoked.

API 3 — Enterprise Identity API

The third layer combines continuous identity verification with session monitoring.

It performs identity matching, continuous session authentication, multiple-face detection, and threat detection.

This allows an application to continuously ask:

"Is the authorized person still the person using this session?"

If the verified identity changes or a threat is detected, the system can terminate the session rather than continuing to trust the original login.

The Pipeline

Camera → Face Detection → Liveness → Anti-Spoof → Identity Match → Continuous Verification → Trust Decision

What We Built

We built a working web platform with separate demos for the three API levels, a verification dashboard, application management, API documentation, biometric challenge flows, live verification metrics, and developer diagnostics.

We also tested the challenge-processing pipeline with real webcam input and verified challenge detection for actions including face centering, blinking, mouth opening, and head movement.

Why Mitra Verify Is Different

Traditional authentication answers:

"Did the user provide the correct credentials?"

Mitra Verify asks:

"Is the authorized person still present and interacting with this session?"

That shift—from one-time authentication to continuous identity trust—is the core idea behind Mitra Verify.

Built With

Share this project:

Updates

Submission history