Computer Vision

AI Identity Document Verification Engine for Oneex

Designed and built the AI engine of Oneex's identity-verification platform, which processes over 10 million identity documents a year in airports, banking, defence and sovereign infrastructure. OCR, multi-spectral authenticity analysis, print-technique forensics and biometrics, all running on CPU-only edge hardware.

AI Identity Document Verification Engine for Oneex
  • 10M+ documents / year
  • 99.65% MRZ accuracy
  • 10s → 2s on CPU

The problem

Oneex builds identity-verification systems used where a wrong answer is expensive: airports, banking, defence and sovereign infrastructure. Its platform processes over 10 million identity documents a year, covering passports, ID cards, visas and driving licences from 197 countries.

Verifying an identity document is two problems. The first is reading it: extracting every field correctly, from a document type that may be one of thousands of versions in circulation. The second is deciding whether the document is genuine, which is harder, because a good forgery is designed to read correctly. A system that only reads documents will accept a well-made fake.

The deployment environment adds a third constraint. Kiosks and desks in these settings often cannot send identity data to the cloud, for regulatory, contractual or security reasons. Everything has to run on the device, on CPU-only edge hardware, fast enough that a person standing at a kiosk is not left waiting.

Our approach

We designed and built the AI engine of the platform as a layered system: it reads the document, then interrogates it for forgery from several independent angles. Each layer looks at different evidence, so a forgery has to defeat all of them at once rather than one.

Universal OCR. Full-document OCR runs on CPU in milliseconds. A dedicated engine handles the machine readable zone (MRZ), the standardized lines defined by ICAO Doc 9303 at the bottom of passports and ID cards, and reaches 99.65% character accuracy. Coverage spans 197 countries and every passport, ID card, visa and driving licence version in circulation.

Multi-spectral authenticity analysis. The document is imaged under visible, infrared and ultraviolet light at hyper-resolution. Each sub-region is compared against a model of a genuine specimen of that exact document type. Rather than learning what known forgeries look like, the system learns what genuine looks like, so forgeries surface as statistical outliers. That is what lets it flag fakes it has never seen before.

Print-technique forensics. Genuine security documents and reproductions are physically made in different ways. This layer identifies how a document was produced, such as offset, inkjet or laser engraving, which is often the clearest tell that separates a genuine document from a copy. We built it with a former forensic document-fraud expert from the IRCGN, the French gendarmerie's criminal research institute, so the model's categories reflect how forensic examiners actually reason about documents.

Biometrics. Face matching between the holder and the document photo, validated in real kiosk conditions rather than only on curated datasets, plus presentation-attack detection (liveness) to reject photos, screens and other artefacts held up to the camera.

CPU-only, on-device inference. The core constraint, and the core engineering achievement, was running all of this on CPU-only edge hardware. Through ONNX export, quantization and OpenVINO, we brought the full pipeline from 10 seconds to 2 seconds, fully on-device, with no cloud dependency. The engineering write-up covers how that kind of speedup is achieved.

This work draws on both our computer vision and research & development practices: the forensic layers required new methods, and the edge deployment required careful inference engineering.

Results

  • 10M+ documents a year: the engine runs in production on the Oneex platform, in airports, banking, defence and sovereign infrastructure.
  • 99.65% MRZ character accuracy: from the dedicated MRZ engine, with full-document OCR on CPU in milliseconds.
  • 197 countries covered: every passport, ID card, visa and driving licence version in circulation.
  • Unseen forgeries detected: anomaly-based multi-spectral analysis flags fakes that were never in the training data.
  • 10s to 2s on CPU: the full pipeline, fully on-device, with full data sovereignty.

The speed figure is what makes the rest deployable. A five-fold reduction in end-to-end time on the same CPU hardware is the difference between a check that slows a queue and one a traveller or customer barely notices, and it removes any reason to send identity data off the device.

What it takes to deploy

An identity-verification engine is a security system, and it is judged in the field, not on a benchmark. Bringing a similar system to production typically involves:

  • Reference data per document type. Anomaly-based authenticity checks need genuine specimens of each document version, and new versions enter circulation every year.
  • Evaluation in real conditions. Lighting, worn documents, camera variation and kiosk ergonomics all shift accuracy, which is why the face matching was validated in real kiosk conditions.
  • Separate error budgets. False rejections frustrate genuine users and create manual work; false acceptances are security failures. Each layer needs its own thresholds and monitoring.
  • Inference engineering for the target hardware. Latency targets on CPU are met by designing the models, quantization and runtime together, then re-validating accuracy after every optimization.
  • Domain expertise. Forensic knowledge of how documents are made and attacked has to be built into the system, not added after the fact.

Where this applies

The same architecture, layered checks with each one grounded in a model of what genuine looks like, applies wherever identity has to be verified on-site and under data-sovereignty rules: KYC and customer onboarding in banking & finance, and access control, border and critical-site security across the industrial & public sector. The CPU-first inference work transfers to any computer vision system that must run on modest edge hardware.

Building a verification or vision system that has to run on-device? Talk to our team.

Capabilities & industries

More projects