Aug 1, 2026Ixana Team12 min read
Proof of Presence

The internet is learning to mark what is synthetic. It still has no shared way to show who was physically there.
Proof of Presence
The internet is learning to mark what is synthetic. It still has no shared way to show who was physically there.

Since 2 August 2026, Article 50 of the EU AI Act has required providers of covered generative AI systems to mark synthetic or manipulated audio, images, video, and text in a machine-readable form, subject to specified exceptions. For systems placed on the market before that date, a limited grace period delays the Article 50(2) marking and detection obligation until 2 December 2026 [1].
This is a useful step. It helps people and platforms understand how a file was made.
It does not show that the event in the file occurred.
Synthetic and false are not the same. Neither are captured and true. A generated diagram can be accurate. A real camera can record a staged scene. A valid signature can protect a claim without making the claim correct.
Forensic detection also faces a structural problem. A detector trained on today's generators must still recognize content from generators it has never seen. Research continues to treat generalization to unseen models as a central challenge [2].
Signed provenance takes a different route. It carries information about origin and editing instead of trying to recover that history from traces left in the content.
Both approaches tell us about the file. The harder question is about the world: what physical encounter took place?
Provenance is not presence
C2PA Content Credentials are an important part of the provenance layer. They bind signed assertions to a digital asset. Those assertions can describe its origin, capture device, edit history, use of AI, time, location, and other facts supplied by the signer [3].
C2PA does not judge whether those facts are true. It lets a verifier check who signed the assertions, whether they belong to the asset, and whether they changed later. That is the correct boundary for a media standard.
Presence attestation would add another layer, not replace C2PA. A local encounter protocol could create a signed record that several participant-bound devices completed defined physical checks. A camera could bind that record to an image or video. C2PA could then preserve the provenance of both the media and the encounter claim.
The missing piece is the physical evidence behind that claim.
What a presence claim could look like
Four friends enter a concert. They bring their hands together for a moment. Their wearables exchange fresh cryptographic challenges, and each person consents to a short-lived co-presence session.
A photograph taken while that session remains current could carry a narrow claim:

The specified participant credentials completed the required local encounter protocol during this capture window. The statement does not certify that the photograph is truthful or that the group stayed together all night. It identifies the physical checks that took place, the credentials that passed them, and the period for which the result remained valid.
Now change the setting.
A contractor arrives at a substation and must establish that they were on site with a specific colleague and item of equipment. A nurse completes a home visit without creating a continuous record of the patient's location. A fan receives access to a release reserved for people at a live event.
The products differ. The missing primitive is the same: a fresh, signed claim about a local physical encounter.
We do not know of a widely deployed system that combines tight locality, current wearer binding, ring-scale readiness, a natural interaction, and participant-controlled privacy.
A useful claim needs more than proximity
Locality must match the action being claimed. A hand-to-hand gesture may require a boundary of a few centimeters. A room-level event may allow several meters. The credential must state which boundary the system tested.
Short native range helps, but it does not stop a relay. An attacker can place one relay device near each legitimate endpoint and forward the exchange over another communication link. Distance-bounding protocols address this problem through timed, authenticated challenge-response exchanges that establish an upper bound on distance [4].
The system must also separate three questions: which device participated, whether the device was being worn, and whether the current wearer was the person linked to the credential. A hardware-protected key can identify a device. A body-coupled link can provide wear-state evidence. A recent phone unlock, biometric check, or enterprise credential can bind the device to a person. The required combination depends on the risk of the application.
Then there is the form factor. A presence system must remain ready within the energy budget of a ring or another small wearable. The real budget includes standby, wake-up, synchronization, cryptography, sensing, and failed exchanges. A radio can be efficient while transmitting and still be a poor fit for an always-ready device.
The interaction must also disappear into the gesture. People will not hold a pose while several radios connect and a cloud service responds. The critical exchange should happen locally and finish before the user notices it.
Finally, the proof must remain under participant control. A system that can establish who met whom can also create a surveillance graph. Privacy is not an option to add after the protocol works. It is one of the protocol requirements.
Existing radios solve part of the problem
Bluetooth Channel Sounding deserves serious treatment. It combines phase-based ranging with round-trip-time measurements. The Bluetooth SIG describes the RTT method as secure distance bounding intended to add protection against relay attacks [5].
UWB is also a strong choice when precise device-to-device range is the main requirement. IEEE 802.15.4z added features intended to improve the integrity and accuracy of UWB ranging [6]. Implementation still matters. The Ghost Peak researchers demonstrated practical distance-reduction attacks against commercial devices using 802.15.4z HRP ranging [7].
The lesson is not that UWB is weak. It is that a radio standard is not a complete security system.
NFC solves a different problem. It provides a deliberate tap at very short range, with a typical operating range of up to 2 cm [8]. That makes it useful for consent or session initiation. A persistent, multi-person context still has to be built above the tap.
All three technologies can support presence attestation. Bluetooth Channel Sounding and UWB measure device geometry. NFC records a deliberate close interaction. In their standard roles, none of them derives current wear state from the communication path itself.
That is the signal a body-coupled link can add.
What Wi-R adds
A device can be close without being worn. Bluetooth Channel Sounding, UWB, and NFC can establish device proximity or a deliberate interaction. Wi-R BAN changes the geometry: the wearer's body surface forms part of the coupling path. The live link therefore carries a wear-state signal that distance alone does not provide.
Ixana's published YR23 specifications list data rates from 100 kbit/s to 5 Mbit/s, latency below 1 ms, energy of 0.12 nJ/bit at 5 Mbit/s, reach of 10 to 15 m along the coupled surface, and up to 0.1 m perpendicular to it [9].
Wi-R NFE provides the deliberate device-to-device link. The published XA-NFE2001 specifications list a range of 5 to 25 cm, extendable to 1 m, data rates up to 5 Mbit/s, latency below 1 ms, and energy of 0.08 nJ/bit at 5 Mbit/s in low-power mode [10]. A presence application would use and validate the short-range configuration.
The two links answer different physical questions.
Wi-R BAN asks whether a wearable is coupled to the user's body-area network. Wi-R NFE asks whether participating devices completed a local encounter.
A presence protocol could use both.
How reliably the BAN signal distinguishes real wear from conductive substitutes is an empirical security question. Wi-R also does not establish human identity or secure distance by itself. A high-assurance design may combine it with Bluetooth Channel Sounding, UWB, or another tested distance-bounding method.
The useful claim is specific: Wi-R can contribute low-energy body-coupled wear evidence and a short-range encounter link to a larger attestation stack. Identity, consent, secure ranging, credentialing, expiry, and revocation complete the system.
From a link to a credential
Bind the current wearer → Complete a local encounter → Sign a short-lived credential → Bind it to an action
Wi-R can contribute the body-coupled wear signal and the local encounter link. Identity, secure ranging, and credentialing complete the claim.

Bind the wearable to its current user. The wearable holds a hardware-protected key and establishes a fresh association with a trusted phone, glasses, or another personal device. The application chooses an identity check that matches its risk. A social product may accept an authenticated account. An industrial site may require a recent biometric or enterprise credential.
Complete a fresh local encounter. The participants make a deliberate gesture. Their devices exchange unpredictable challenges, verify the current wearer associations, and record consent. When the claim requires a measured distance bound, the system adds a tested secure-ranging method.
Sign a short-lived record. Each participant device signs the same encounter record. It includes the protocol version, freshness data, wear-state result, ranging result if used, consent, assurance level, and expiry time. One gesture should not support an all-day claim.
Bind the record to the action. A camera can attach it to an image or video through C2PA. A ticketing system can bind it to entry. An industrial system can bind it to a work order or machine state.
The resulting statement should remain precise:
At time T, devices bound to credentials X and Y completed protocol V. Both passed wear-state check W. The system recorded distance assurance D. The claim expired at time E.
The statement should name people only when the identity layer supports that conclusion.
Proof should belong to participants
A database of physical association is one of the most sensitive datasets a service can create.
It can reveal medical care, political activity, intimate relationships, immigration status, commercial negotiations, religious attendance, and the movements of children.
The default should be participant custody. Consent should apply to each encounter, not to a setting accepted once during account creation. Credentials should expire unless a participant chooses to keep them. Different services should not receive the same stable participant identifier.
Verification should disclose only the fact needed for the transaction. The W3C Verifiable Credentials Data Model supports selective disclosure and zero-knowledge proof methods, which can let a holder prove a fact without revealing the full credential [11].
Cryptography is only part of the privacy design. An application log, stable account identifier, or network address can still connect encounters. The service must limit collection at every layer.
The strongest privacy control is data the service never receives.
Where this matters first
Social and shared media. A group could attach a co-presence claim to a specific capture window. The claim would not certify the truth of the image. It would establish that the required participant credentials completed the stated protocol near the time of capture.
Ticketing and live events. A venue could verify a deliberate local encounter without tracking each attendee throughout the day. A creator could release a digital object to people who were present, while the attendance credential stays with the fan.
Field and care work. A worker could create a signed record that links a current credential, a colleague, a machine, and a defined procedure. A patient and carer could create a visit record without continuous location tracking. These applications need stronger identity controls than a social product, but the physical primitive is the same.
Why this has not been built
The idea sits between four fields that rarely share one product architecture.
Wireless engineers think about links and ranging. Identity teams think about credentials and authentication. Provenance teams think about files. Product teams think about consent, habit, and social meaning.
Each group owns part of the answer. No group owns the whole system.
Ixana works on the physical layer. Our role is not to build the social network, the ticketing platform, or the identity standard. Our role is to contribute physical links designed for small, low-power devices, and to add a signal that conventional ranging does not provide: evidence that a wearable is coupled to a body-area network.
The next step is not another architecture diagram. It is a test bench.
Wear-state detection must be tested against devices left on tables, conductive objects, body phantoms, borrowed wearables, modified firmware, compromised endpoints, and relay equipment. The results should include false accepts, false rejects, placement variation, complete encounter energy, and latency. Failed cases matter as much as successful ones.
Those results should be published so that customers, researchers, and standards groups can challenge them.
The internet is learning to show how a file was made.
The next task is to show what physical encounter supports the claim, without building a permanent map of everyone who met.
That is proof of presence.
Ixana is looking for partners in live events, social products, identity, field systems, and care applications. If you are building a presence-attestation system, or want to test Wi-R in your own hardware, get in touch.
References
[1] European Commission, "Transparency obligations under Article 50 of the AI Act."
[2] Jeongsoo Park and Andrew Owens, "Community Forensics: Using Thousands of Generators to Train Fake Image Detectors," CVPR 2025.
[3] Coalition for Content Provenance and Authenticity, "C2PA Technical Specification, Version 2.4."
[4] Gildas Avoine et al., "From Relay Attacks to Distance-Bounding Protocols," in Security of Ubiquitous Computing Systems, 2021.
[5] Bluetooth SIG, "Bluetooth Channel Sounding."
[6] IEEE Standards Association, "IEEE 802.15.4z-2020: Enhanced Ultra-Wideband Physical Layers and Associated Ranging Techniques."
[7] Patrick Leu et al., "Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging," USENIX Security Symposium, 2022.
[8] NFC Forum, "NFC Technology."
[9] Ixana, "Wi-R Body Area Network Chips."
[10] Ixana, "Wi-R Near Field Electric Chips."
[11] World Wide Web Consortium, "Verifiable Credentials Data Model v2.0."
Wi-R BANWi-R NFEPresence AttestationProvenanceC2PA
Ixana Team
Developing ultra-low-power near-field wireless technology for the next generation of mobile and wearable devices
Illustrative use case only. This page describes example workflows and interoperability concepts involving Ixana Wi‑R technology and third-party systems. Unless expressly stated otherwise, Ixana provides communications silicon, circuit boards and firmware components for E-field based body-area-network and near-field data transfer and is not offering complete medical device, clinical triage system, or finished end products.