Method for continuously authenticating the identity of an individual
Patent Information
- Authority / Receiving Office
- CA · CA
- Patent Type
- Applications
- Current Assignee / Owner
- INST NAT DES SCI APPLIQUEES CENT VAL DE LOIRE
- Filing Date
- 2025-02-12
- Publication Date
- 2025-08-21
AI Technical Summary
Existing continuous authentication methods are restrictive for users, lack reliability, and are vulnerable to session theft and demographic biases due to the use of a single transformation rule for all individuals, requiring extensive data storage and re-learning when new users are added.
A method that generates personalized authentication models for each individual using machine learning on their unique physiological signals, incorporating data from known imposters to enhance reliability, and continuously verifies identity without active user interaction, updating models during use to adapt to changing physiological conditions.
Provides transparent, secure, and reliable continuous authentication by reducing demographic biases and session theft risks, with enhanced reliability through personalized models and continuous learning, eliminating the need for extensive data storage and re-learning.
Abstract
Description
Process for continuous authentication of an individual's identity
[0001] The invention relates to the field of continuous authentication of the identity of an individual, in particular to authorize access.
[0002] Authentication consists of proving a user's identity so that access authorization can be granted (access to a location, a physical object, software, etc.). To authenticate, the user must transmit their identity associated with a particular piece of evidence to an authentication system, and the system verifies the evidence.
[0003] The most common authentication is based on the proof of a password or a badge. However, this type of authentication poses the problem of session theft. In addition, once authenticated, the authentication system has no way of certifying that the user who continues to use the session after having had access to it is still legitimate. Also, in recent years, biometric authentication has been developed, for example by fingerprint recognition. However, fingerprint sensors can be fooled by latex forgery. In addition, this authentication method is one-time, it authenticates the person once to open a session without repeating the authentication.
[0004] Thus, in recent years, the need to develop so-called continuous authentication has been shown. Continuous authentication aims to re-authenticate the user several times during the session. For example, US patent application US2022012317 discloses a method and its implementation device consisting of repeating recognition by biometrics several times; the biometric recognition described in this document relates to voice recognition, recognition of a fingerprint, a palm print, or even the shape of the face, a hand or the pattern of veins. However, this type of recognition requires the user to actively interact with the biometric sensors for each recognition request, which undoubtedly represents a nuisance.Indeed, the user is already bothered because the system informs him of the obligation to be recognized again, then he must take time to perform an action, that of interacting with a sensor like speaking or repositioning his finger, his hand, or his face in an ad hoc manner. Such a continuous authentication process is therefore too restrictive for the user.
[0005] Patent application WO2012151680 also discloses an authentication of an individual that can be continuous by repeating the authentication over time. This document advantageously describes the use of physiological signals for authentication, such as ECG (for electrocardiogram) and PPG (for "PhotoPlethysmoGraphy"), which are signals that are more difficult to falsify. However, regardless of the number of individuals in the population, the method described in this document requires having previously entered into a database a pre-recorded signal specific to each individual listed in the database. Authentication is achieved by matching a measured physiological signal of an individual and the pre-recorded signal for this individual in the database. The pre-recorded signal was designed by a transformation rule that is derived from machine learning from measured signals of a group of several individuals.However, such an authentication method that uses the "Template Machine" technique (which can be translated into French as "Template Matching") has the disadvantage of having to store all the individuals with their pre-recorded authentication signal from the transformation rule in advance in a database to compare the measured signal with the pre-recorded signal. Another disadvantage is that the pre-recorded signal, although unique for each individual, comes from the same transformation rule for all the individuals listed. This method ultimately does not offer sufficient reliability.
[0006] Furthermore, the scientific publication ALEXA MURATYAN ET AL: “Opportunistic Multi-Modal User Authentication for Health-Tracking loT Wearables”, dated September 28, 2021, describes research work on optimizing a method for authenticating an individual by learning from physiological signals. This publication does not disclose a continuous authentication process. This publication only focuses on finding the best classification learning model to authenticate an individual. Several different learning models using a different classification (RF; KNN; NB; SVM-RBF; SVM-Poly) were tested on a group of individuals and it appears that the RF classifier model is the best. However, as previously explained, here again, the same authentication model (RF model) will be used for each individual, which ultimately lacks reliability.This state-of-the-art method presents numerous biases, particularly demographic ones. It has actually been shown that two individuals with very similar physiological signals will be inseparable.
[0007] The invention therefore aims to propose a continuous authentication method which does not have the aforementioned drawbacks, in particular which provides continuous authentication in a transparent manner for the user and above all which remains reliable and secure over time.
[0008] According to the invention, the method for continuous authentication of the identity of an individual is in accordance with claim 1. Consequently, for each individual, each of the steps of claim 1 is carried out, and the last step relating to the selection of the authentication models of each individual implies that each individual therefore has his own group of authentication models, that is to say that each individual has a group of authentication models which will be different from the group of authentication models of another individual.
[0009] In particular according to the invention, the method for continuous authentication of the identity of an individual (sometimes referred to hereinafter as a legitimate individual), comprises a first authentication step (called initial authentication of the identity) by the recognition of at least one physiological signal of the individual transmitted by at least one sensor worn passively by the individual, and after the first authentication step, at least one iteration step of authentication of the identity (to verify the authentication of the identity) by the recognition of said at least one physiological signal of the individual, the authentication method being characterized in that: - prior to the authentication and authentication iteration steps,the method comprises i) a so-called prior learning step (with respect to said individual) which consists of processing by machine learning the data of at least one physiological signal specific to the individual (the data based on discriminating characteristics of said at least one physiological signal of the individual), to generate a multitude of authentication test models, ii) testing this multitude of authentication test models with the data of the individual which continue to be captured, iii) classifying the authentication test models according to their relevance of probability of correspondence with the data of the individual and iv) retaining only a selection of a group of (a few) authentication test models classified with the best probability of correspondence (correspondence with the legitimate individual),these selected authentication test models being the so-called authentication models which are retained for the authentication and authentication iteration steps (these authentication models are specific to each individual and are therefore different from those of another individual to be authenticated; for each individual a preliminary step of generating several authentication models will be carried out); - the authentication and authentication iteration steps consist of comparing the data captured from the individual with the authentication models specific to the individual, of associating a probability of correspondence with the comparison result with each of the authentication models and of processing the probabilities to deduce a result of acceptance of the authentication or of rejection of the authentication. An acceptance result implies that the individual is indeed legitimate.,
[0010] According to a preferred feature, in step i) which consists of generating a multitude of authentication test models, the data processing exploits not only the data of the individual but also the data of at least one known imposter (the learning is done with the data of the individual and the data of one or more known imposters), the quantity of data used from all the known imposters considered in the generation of the multitude of test models not having to exceed the ratio between the total quantity of data of the (legitimate) individual and the number of known imposters. The use of data from known imposters makes it possible, for example, to reject test models which could obtain a good probability of matching when in reality the probability should be poor, and also makes it possible to reinforce test models with a good probability because they were able to recognize the imposter data.This increases the reliability of the models selected for the authentication and authentication iteration stages. Furthermore, considering a limited amount of known imposter data relative to the individual's data avoids the risk of generating test models that would take into account more known imposter data than the individual's.
[0011] Thus, several authentication models are used whose comparison results are analyzed to identify an individual and furthermore, these authentication models are specific to a single individual because they are derived from models generated from the training data of the single individual and possibly from data of known imposters, and not from a transformation rule from data of a group of individuals who all had to be listed by storing their own data. Indeed, in the prior art schematically illustrated in the, a single model is created (as in the aforementioned scientific publication) from a single transformation rule and this transformation rule was designed from the data of a given group of individuals (by combining by training all the data of all the individuals in the group).Today, the entire scientific community still uses only one model (one architecture) for all users. While in the prior art several instances of the model can coexist (for example concerning bagging), the implementation of a set of several different models (different architectures) selected for each individual is not proposed. The method of the invention personalizes the authentication models for each user. Consequently, the method of the invention does not generate only one model (which is more reliable), and does not establish a single transformation rule.Thus, the multitude of models generated with the individual's data and the fact of having tested them all according to a pre-training to retain only a reduced group of the best models and which will differ from one individual to another, provide authentication models which will be much more reliable for the authentication of the individual, and make it possible to reduce the demographic biases associated with each biometric system (a problem still widely present in biometric systems). In addition, the method of the invention also does not require the data of all the individuals in a group. The method of the invention therefore uses the data of a single individual, possibly also uses the data of at least one known imposter individual to generate several authentication test models but does not need the data of all the individuals in a group to generate an authentication test model.The method of the invention therefore does not have to worry about processing data from all the individuals in a group to authenticate a single individual. There is also no need to consider a new group of individuals with all their data each time a new individual not initially listed must be newly integrated into a database for authentication (since the models retained for the authentication of the individual will be independent of the other authentication models of the other individuals – there is no single transformation rule).
[0012] According to one feature, in step ii), at least one test model is tested using the data of at least one other individual considered to be a known imposter, preferably using the data of several known imposters, which helps in the selection of said at least one of the authentication test models when the probability associated with this test model tested with the data of the known imposter is precisely low because the imposter has indeed been detected. Preferably, all the authentication models retained have been tested with the data of the known imposter (to confirm the relevance of the model when the associated probability was indeed low).
[0013] According to one characteristic, the data of a known imposter is that of a real individual or has been digitally generated. Digital generation can be useful for simulating one or more imposters when only the data of the legitimate individual is available.
[0014] In the prior art, a given group of authorized individuals is considered to create (by prior learning) a transformation rule. When a new individual must be integrated into the database of authorized individuals, the group having been modified, it is necessary to repeat the prior learning for the entire new group in order to create a new, more suitable authentication rule. On the contrary, the method of the invention does not require repeating learning for all the individuals as soon as a new individual must be integrated into the database of authorized persons.Indeed, the method of the invention generates test models from the data of the individual to be authenticated (legitimate user), the data of another individual (known imposter) being used if necessary (nevertheless preferentially) only to generate and test the test models and to highlight that if the test model tested with the data of the known imposter gives a result too close to the result with the data of the individual to be authenticated, this test model will be assigned a very low, or even zero, probability value. This will help to design from the different test models, a group of even more reliable authentication models, but in no case will it be necessary to use the data of an entire exhaustive group of individuals which will correspond to a group in which each individual will be supposed to obtain authorization after authentication. The method of the invention is implemented independently of the number of individuals to be authenticated.
[0015] By "passively worn" relative to the sensor, we mean that the individual does not need to perform any action on the sensor, nor worry about it, they just have to put it on and wear it (the arrangement will depend on the type of physiological signal being measured).
[0016] A physiological signal is any analog signal generated by the human body that can be measured and digitized.
[0017] Preferably, the processing of the probabilities which are associated with the results of comparing the captured data with the authentication models, to deduce an acceptance or rejection result, is implemented by a decision tree.
[0018] According to one feature, the generation of authentication models and authentication by these authentication models are free of any active gesture to be imposed on the individual.
[0019] Therefore, the authentication method of the invention has several advantages: - the detection of signals that are necessarily physiological and the continuous repetition of the measurement of these physiological signals, make the request for authentication and its verification transparent for the individual who has no action to perform; - the detection and processing of physiological signals reduces the risk of falsification because the physiological signals have the advantage of being all different depending on the individual; - the additional steps in the time of identity authentication verification, eliminates the risk of session theft. Indeed, during a session use, the fact that after the initial authentication, the authentication is continuously verified by the repeated measurement of the signal and by its systematic analysis,allows continuous verification that the user is still the same; if an authentication certificate has been issued, as long as the authentication verification continues, the session / access can remain open;- according to another intended use, the additional steps in the identity authentication verification time allow for fine analysis of a signal continuously over a fairly long period, before issuing an authentication certificate;- the generation of several authentication models that are unique for each individual from artificial intelligence learning of the data of the individual to be authenticated (more reliable than with combined data from a necessary group of individuals) and their implementation during authentication by assigning each of them a probability of matching, reinforce the reliability of authentication. Indeed,instead of providing an identical data transformation rule from the data of a group of individuals and comparing the data during authentication only with this single rule, the method of the invention by testing several authentication models from the data of the legitimate user (possibly additional data from one or a few known imposters) and by studying their relevance of correspondence for said user, this reinforces the reliability of the authentication evaluation. In addition, testing the authentication models with data from a known imposter increases the reliability of the ranking of the best models to retain for the individual to be authenticated; - there is no need to keep the data of a multitude of individuals to establish a transformation rule from all this data,nor to carry out new learning to establish a new rule as soon as one or more individuals are added to the list of individuals to be authenticated.,
[0020] According to one feature, the authentication method establishes the list of the Y best known impostors for each legitimate user and, upon each authentication of the user, attempts to authenticate these Y best impostors (in relation to the other individuals known in the authentication system via the various recognition modules dedicated to each registered individual). In particular, this makes it possible to eliminate known individuals from the list of impostors.
[0021] According to one characteristic, during the preliminary learning stage, the individual who will subsequently have to be authenticated will have to wear for a certain time a sensor of at least one type of physiological signal, the individual will go through phases of rest, sport, emotions (for example by listening to audio recordings and / or viewing videos), to record the associated signals, and the automatic learning will lead to authentication models dedicated to the individual, relatively reliable.
[0022] According to another characteristic, the authentication method comprises a step of issuing an authentication certificate when the recognition is accepted (TRUE), the authentication iteration steps being carried out after the first authentication step and the issuing of the authentication certificate, or the authentication iteration steps being carried out following the first authentication step and before issuing the authentication certificate. The execution of the authentication iteration steps depends on the degree of security associated with the authentication. Thus, a first embodiment corresponds to high-frequency authentication, on the order of a second or a few seconds, to issue an authentication certificate if the authentication is considered TRUE, and the authentication iteration steps continue after issuing the authentication certificate.A second embodiment corresponds to an authentication of a recognition duration which will be said to be long, in particular of a duration of at least several minutes, or even several tens of minutes, the authentication certificate being issued only if the authentication is considered TRUE, and this after the first authentication step and several authentication iterations over the chosen recognition duration; this analysis over a long measurement duration increases the legitimacy of the authentication result. This authentication embodiment which combines continuous authentication and the analysis of physiological signals of an individual, provides good reliability of the result, the falsification of physiological signals and this over a long duration is relatively unlikely. This embodiment can be very useful in high security applications.
[0023] Advantageously, the authentication method implements, during at least one iteration step of identity authentication, automatic learning so as to renew one or more authentication models dedicated to said individual. According to one characteristic, the dedicated authentication models which were generated and retained during the prior learning step constitute first authentication models which are updated by automatic learning during at least one iteration step of the continuous authentication to constitute new dedicated authentication models and preferably to be taken into account for the next authentication. Thus, the authentication method continues the learning of recognition of the physiological signals of the individual during the time that the authenticated individual continues to wear the connected device.The module providing the learning then benefits from more data, which increases the reliability of the dedicated authentication models and therefore the reliability of the authentication process.
[0024] Preferably, the authentication method renews by learning during the iteration steps of authentication of an individual, the authentication models and records N last authentication models which correspond to those immediately renewed and to those of one or more previous iteration steps, and the execution of the authentication method during a new and subsequent authentication (when the user has not worn the sensor for a certain time) is carried out from the last authentication models recorded or from a combination of the last N authentication models recorded. These phases of recording and retrieving the last authentication models or from a combination of the last N models, further increase the reliability of the authentication process and reduce the risk of rejection of an authentication whose result should have been TRUE.Indeed, an individual can change mood over a period of time, their health can change, and the resulting physiological signals evolve accordingly. The method of the invention will then make it possible to generate authentication models which correspond as closely as possible to the current physiological state of the individual.
[0025] According to another characteristic, the method takes into account, when evaluating the authentication result which is of binary type (TRUE / FALSE), the quality of the signal and preferably the quality of the signal over a certain duration, in particular the quality of the signal being evaluated by processing the noise of the signal.
[0026] According to another feature, the method measures and evaluates several types of physiological signals for a single authentication. According to one feature, the method implements a group of authentication models per type of physiological signal and the method comprises an algorithm for evaluating the authentication from the combination of the recognition results from each of the groups of authentication models for each of the types of physiological signals.
[0027] According to another feature, the physiological signal(s) are chosen from the PPG signal(s) and / or ECG signal(s) and / or the physical activity of the individual and / or their bioimpedance. In particular, the authentication method further comprises a step of evaluating the state of health of the individual from the captured physiological signals. The PPG signals use plethysmography sensors, also called pulse oximetry sensors, and involve measuring changes in blood volume by measuring the amount of light absorbed and reflected by the blood vessels; the PPG signal is associated with a cardiac signal because fluctuations in blood volume are generated with each heartbeat. Since each individual has their own PPG signal, it is a fairly reliable method of authenticating an individual. Furthermore, PPG has the advantage of being a non-invasive technique.
[0028] According to another characteristic (in one embodiment), the method measures and evaluates other data than one or more physiological signals of the individual, said other data being processed so that the results are combined with the results of the one or more physiological signals to establish recognition, in particular said other data being, taken alone or in combination, biometric data such as fingerprint, face, iris, vein pattern, or a password which may be single-use, a smart card, a badge, a certificate or an encryption key on a removable medium such as a USB key, a validation action on a second device such as a telephone.
[0029] According to another characteristic, the method comprises a step of detecting a replay attack and / or a step of detecting forged signals. A replay attack is a third party who manages to capture the physiological signal of the individual and record it in order to then use it to usurp his identity, by sending it to the sensor which delivers to the device implementing the method of the invention the data which should normally be those of the individual.
[0030] According to another characteristic, the method comprises a step of detecting forged signals (signals generated artificially and therefore not coming from the data of the individual wearing the sensor(s).
[0031] According to one characteristic, the method uses a secure communications protocol such as HTTPS or chosen from other cryptographic protocols, in particular between the sensor(s) worn by the individual and a server to which the device for implementing the authentication method is connected.
[0032] The invention also relates to a system for continuous authentication of the identity of an individual, comprising electronic processing means and algorithms for implementing the aforementioned authentication method, the processing means comprising at least one recognition module per individual (and for a single type of physiological signal), a so-called IAM module for identity and access management, and a data storage module, the recognition module per individual generating by machine learning the authentication models dedicated to the individual and related to a physiological signal. The algorithms will be diverse, for example support vector machines (also called SVM for "Support Vector Machine" in English), neural networks, decision trees, principal component analysis, genetic algorithms, etc.
[0033] According to one characteristic, the processing means of the aforementioned authentication system comprise a replay detection module, a forged signal detection module, and a module for evaluating additional data specific to the individual including their state of health.
[0034] Finally, the invention relates to a computer program comprising code instructions for executing the steps of the aforementioned authentication method, when said program is executed by a processor. The program can in particular be loaded onto a network of the Internet type.
[0035] The present invention is now described using examples that are purely illustrative and in no way limitative of the scope of the invention, and from the attached illustrations, in which: - represents a flowchart of the authentication system capable of implementing the authentication method according to the invention to authorize a user to access an object X, via a connected device worn by the user. - illustrates a flowchart of the authentication system used to authenticate several individuals. - [] schematizes the steps of the prior learning leading to the selection of a group of authentication models specific to each individual. - schematizes the prior art relating to authentication by the choice of a single model for all individuals.
[0036] The continuous authentication process of the invention of the identity of an individual aims to verify the identity of the individual for the first time (initial authentication) and this passively without intervention from the individual, then to continue to verify over time that it is always the same individual (continuous verification of authentication), and again passively without intervention from the individual, the authentication being carried out from physiological signals of the individual.
[0037] The continuous authentication method can be applied to various uses such as access to a physical object X, access to software, access to a place (via access to an object such as a door), etc.
[0038] As schematically illustrated in the, the continuous authentication method is implemented by at least one connected device 1 worn by the individual and by an authentication system 2 arranged remotely from the connected device 1 and receiving all the data from said connected device 1. The authentication system 2 is capable of communicating with the object X. The authentication system 2 is adapted to receive the information from the connected device 1 and process it to authenticate the individual wearing the connected device 1 in order to authorize his access to the object X and continue the verification of the authentication as long as the connected device 1 is worn by the individual. The authentication system 2 is adapted to receive information from several connected devices 1-1, 1-2, 1-3, etc.() to authenticate individuals carrying said connected devices in order to authorize them access to an object (to the same object or to a different object for each individual) if they have been properly authenticated.
[0039] The authentication system 2 (via a so-called IAM module) is able to issue, after authentication, an access authorization certificate which will be valid for a specific period or which must be renewed at each authentication reiteration request to validate again the correct identity and the validity of the access rights to be granted. Each certificate is signed using an asymmetric encryption system so that all actors can ensure the authenticity of each document and avoid document forging.
[0040] The connected device 1 is, for example, in the form of a connected watch, a connected garment worn directly on the skin, or a bracelet connected to a telephone (the telephone being able, if necessary, to serve as an interface for controlling authentication and transmitting the authorization certificate). The connected device 1 must be worn by the individual and will be arranged on the individual in an appropriate manner depending on the nature of the physiological signals to be captured.
[0041] The connected device 1 comprises at least one sensor 3 detecting at least one physiological signal. The nature of the physiological signals detected is for example a PPG signal (via a photoplethysmography sensor) or an ECG (via a sensor measuring cardiac activity) or a signal of physical activity of the individual (via a three-dimensional accelerometer and a gyroscope as sensors) or a bio-impedance signal (via electrode-type sensors).
[0042] The authentication system 2 comprises at least one authentication module 20, also called a recognition module, an identity and access management module 21, called an IAM module (acronym in English "Identity and Access Management"), and a data storage module 22. A recognition module 20 is dedicated to a single individual. The authentication system 2 comprises one recognition module per individual, and possibly several recognition modules per individual, each relating to the measurement of a type of physiological signal. The recognition module 20 has algorithms implementing AI. The storage module 22 records numerous data, including all access requests.
[0043] The access request is made by the individual on the object X. The object X delivers an identifier ID to the connected device 1 worn by the individual, the identifier ID being specific to the object X. From that moment on, the individual no longer has to intervene and simply has to wait for access authorization.The main steps associated with the authentication method for authorizing access by an individual carrying the connected device 1 to the object X are as follows: - the connected device 1 automatically connects to the authentication system 2 and transmits to it the ID of the object X and a physiological signal of the individual; - in the event of recognition by the authentication system 2, in particular by the recognition module 20, the latter issues an authentication certificate which is sent to the connected device 1 and which is recorded in the storage module 22 of the authentication system 2; - the connected device 1 having received the authentication certificate requests from the authentication system 2, in particular from the IAM module 21, an access authorization certificate by transmitting the identifier ID of the object and the associated authentication certificate.A preferably encrypted copy of the access authorization certificate is written in the storage module 22; - the authentication system 2, in particular the IAM module 21, delivers, on the one hand, to the object X a copy of an access token (usually also called by the English term "token") with an identifier ID. utilisateur of the individual requesting access, and on the other hand, to the connected device 1, the certificate of authorization of access to the object X; - the connected device 1 transmits in turn to the object X, the access token and the identifier ID utilisateur of the individual, which unlocks object X, allowing the individual to access it.
[0044] The database of the authentication system 2 includes a library which associates with the identifier ID of the object X, one or more user identifiers ID utilisateur .
[0045] Once the individual has had access to the object X and for a given security time (for example one hour), the user also does not need to interact with his connected device 1 as long as he is wearing it, the continuous authentication continues transparently for the individual, the connected device 1 continues to measure physiological signals of the user and to transmit them to the authentication system 2 which, as long as the recognition is carried out, will issue authentication certificates validating that access is still authorized. Furthermore, it is possible to provide that even after the continuous authentication duration, a subsequent authentication verification during the time of the usage session can be implemented by the authentication system 2.Furthermore, as will be seen later, the authentication method of the invention advantageously continues to collect data from the individual during his session, even if the continuous authentication has stopped (because, for example, the duration of one hour has elapsed).
[0046] The authentication system 2 is therefore capable of:- recognizing the connected device(s) 1;- processing the data received from the connected device(s) 1,- issuing and transmitting the authentication certificate(s) following the access request, or rejecting the request for lack of authentication,- communicating with the object X to issue copies of access tokens to it,- issuing access authorization certificates,- continuously issuing and transmitting authentication certificates,- storing the data received and sent, in particular a copy of the authentication certificates and authorization certificates.
[0047] Furthermore, in addition to authentication and the issuance of access authorization, the authentication system 2 can detect, evaluate and / or transmit other information, in particular: - provide stability over time of recognition by continuous learning, - evaluate the quality of the signal, - transmit alerts, - detect replay, - detect forged signals, - detect a brute force attack, - increase the performance of rejecting (unknown) imposters by using data from known imposters, i.e. where it is known that the results of the authentication models have been tested with known individuals who are not the individual to be authenticated, - provide multiple information concerning authentication / identification, such as for example the state of health of the individual wearing the connected device (sleep, stress, physical effort generating a heart health disorder, etc.), if for example the heart rate is high and the individual does not make any movement, the system deduces a potential state of stress, or if the heart rate is low and the individual does not make any movement, the system deduces that the individual is in a phase of sleep or low consciousness; the position or geolocation of the individual, or even the detection of movement of the individual in an area.
[0048] Depending on the authentication duration and the number of iterations, the authentication process can offer several levels of security.
[0049] In addition, the authentication system 2 has the advantage of being adaptable at any time by adding multiple recognition modules (each time a new user is added) that are specific to each individual. In particular (), the authentication system 2 comprises a plurality of recognition modules 20-1, 20-2, 20-3, etc. that are each dedicated to an individual carrying a respective connected device 1-1, 1-2, 1-3, etc. This characteristic will be developed further. Thus, unique authentication models per individual (a group of authentication models per type of physiological signal) are generated by a recognition module dedicated to an individual, completely independently of the population of individuals.There is therefore no need, unlike in the prior art, to know and record the data of a multiplicity of individuals according to a targeted group in order to establish a data transformation rule dependent on all these individuals, nor to carry out new learning from the data of the ex-individuals (which may have evolved over time) and the data of one or more individuals who are to be added in order to establish a new transformation rule taking into account the ex-individuals and the added individuals.
[0050] The authentication method more particularly comprises the following steps:- Step 1: measurement and recording of the signals delivered by the measuring device such as the sensor 3 according to an acquisition duration and preferably an acquisition frequency;- Step 2: transmission to the authentication system 2 of the physiological signal data, which relate to a first piece of identity information, and possibly concomitant transmission of a second piece of identity information in the form of a unique key (encrypted or not) linked to the sensor 3. This unique key may be contained in a dedicated crypto-processor if the measuring device has one;- Step 3: selection by the authentication system 2 of the recognition module 20 dedicated to the user of the sensor 3; this is a personal recognition module 20 for each individual to be authenticated which has in memory a group of authentication models dedicated to the user.The generation of the group of authentication models is described later. The analysis of the authentication is obtained by comparing the data captured from the individual during the recognition step with the authentication models specific to the individual, which are stored in the recognition module 20, then by associating a probability of correspondence with the result of comparison with each of the authentication models and finally by processing the probabilities to deduce a result of acceptance of the authentication (TRUE) or rejection of the authentication (FALSE). Each recognition module 20 delivers, during an authentication request, a result which is binary, TRUE or FALSE, and which is associated with the different probability values or confidence index which resulted from the comparison with each of the authentication models.Preferably, the TRUE / FALSE result is derived from a decision tree with respect to the probability values resulting from the results of comparing the captured data with the authentication models. Among the algorithms implemented by the recognition module 20, one of the algorithms provides an initial authentication and several iterations of the authentication, the iterations will be carried out before and / or after the delivery of the TRUE / FALSE result depending on the desired degree of security.- Step 4: the recognition module 20 (20-1 for a given individual) sends to the IAM module 21 the TRUE / FALSE value, associated with the ID. utilisateurand the probability or confidence index values of the comparison results with the authentication models, and preferably a list of the Y best identified impostors (which are known impostors because they are considered other users and have their own recognition module 20-2, 20-3, etc.);- Step 5: this step is optional but preferred; the IAM module 21 requests recognition of the Y known impostors from the recognition modules of the other individuals registered in the authentication system 2. The recognition modules of the other individuals independently return to the IAM module 21 the TRUE / FALSE value for each of the Y known impostors, as well as the associated probability or confidence index;- Step 6: the IAM module 21 issues a unique identity certificate for each authentication mentioning several pieces of information which are listed below as examples.
[0051] In step 1, the acquisition duration for measuring physiological signals for initial authentication will be adapted in particular to the nature of the physiological signal and the degree of security required in relation to the intended application. The acquisition for initial authentication will preferably be periodic, for example at a frequency of one second. Then, during the iteration phase of continuous authentication verification, the measurement will be periodic and / or random.
[0052] Concerning steps 2 and 3, the authentication system 2 advantageously comprises several recognition modules 20 (20-1, 20-2, 20-3, etc.), each dedicated to a user. A recognition module 20 is a personal module because it is dedicated to a single individual from a group of unique authentication models which depend solely on the individual's data and which are independent of the data of other individuals. In addition, the recognition module 20 is dedicated to a type of signal, for example PPG or ECG or physical activity or bio-impedance. The authentication system 2 can therefore comprise several recognition modules 20A, 20B, 20C, etc., per individual and dedicated to the measurement and authentication with respect to a type of physiological signal (20A for PPG, 20B for ECG, etc.).Each type of physiological signal will be associated with a group of authentication models, said authentication models of a group having been generated beforehand as will be described later, in relation to the type of physiological signal measured.
[0053] More particularly, the recognition module 20 which is personal to each individual (and independent of other individuals) is capable of: - prior to an authentication request (i.e. prior to step 1), generating a group of unique authentication models for the individual by having processed over a period known as the prior learning period at least one type of physiological signal, this step being called the prior learning step; - authenticating the individual when an authentication request is received (steps 1 to 6 cited above), by comparing the measured physiological signal(s) with the group(s) of unique authentication models generated at the end of the prior learning step by type of physiological signal;- continue learning during authentication requests, via the signals measured during each of the requests, to generate a group of authentication models that are always unique with respect to the individual and updated (to take into account the possible evolution of the physiological signals of the individual, which may vary over time, in particular depending on the state of health of the individual). Note that the prior art does not allow this step, which is subsequently called the step of updating the authentication models with respect to the individual (the prior art having a single transformation rule that remains the same over time).;
[0054] For the initial authentication (step 1), a preliminary learning of the user's data was therefore carried out over a given duration and according to a recording protocol. The preliminary learning is carried out for example over a day, during which the individual wore the connected device 1 and went through different periods of rest and activity phases, or even emotions, in order to obtain a large plurality of ranges of the individual's heart rate. Several variations of the recording protocol can be implemented. For example, the recording periods will be different for a sedentary individual, in particular by reducing them. During the preliminary learning step which corresponds to a first session, it is the operator of the authentication system 2 who manually associates the connected device 1 with a user.The connected device 1 contains a first token that can be used by the user as long as the user wears the connected device (such as a wristband connected to the wrist). In parallel, the authentication system 2 therefore continuously records the data from the sensor(s) of the connected device 1 to carry out the preliminary learning, as indicated for, for example, one day. The more time passes during the day, the more reliable the authentication system 2 becomes. Once the preliminary learning step is complete, the first token is replaced by an automated authentication token issued by the authentication system 2 and the continuous authentication process can begin as soon as necessary.
[0055] During the preliminary learning, the recognition module 20 implements one or more algorithms by machine learning, according to several steps (diagrammatically shown in the) to: i) generate from the extraction of characteristics relating to a type of measured physiological signal of the individual, a multitude of authentication test models (for example a hundred; in the figure some models have been illustrated diagrammatically by different geometric symbols), then ii) test said authentication test models with the signals of the individual considered as authentic, iii) classify the best test models (those with a highest probability relating to the recognition of the individual) and, iv) retain only a group of the best (for example a dozen) tested models which are called authentication models (in the figure only a few models have been represented for simplicity by the different geometric symbols).Each individual has a custom set of authentication templates. Each individual will have a separate set of multiple authentication templates (not every individual has the same set of authentication templates).
[0056] The multitude of authentication test models is obtained by machine learning from discriminating characteristics of the captured data. The multitude of models generated with the individual's data and the fact of having tested them all to retain only a small group, the best models, provides authentication models that will be the most reliable possible for the authentication of the individual. The group of authentication models is coupled with a unique key linked to the user's identity (ID utilisateur ).
[0057] Concerning the extraction of data regarding the physiological signals to carry out step i) of generating the multitude of test models, the recognition module 20 implements steps or phases known per se of data processing (via algorithms) which are the phases of preprocessing (in particular according to a given type of windowing), filtering (for example using a Fourier Transform and / or by digital filtering) which can be carried out before the preprocessing, extraction of (many) characteristics and selection of these characteristics (advantageously by machine learning, for example according to a PCA function (for “Principal Component Analysis” in English or APC for “Analysis en Composantes Principales” in French)) and finally classification (for example by SVM for “Support Vector Machine” in English, or by neural network).Some neural networks are adapted to perform the extraction, selection and classification steps. The algorithms to carry out these different phases can also be genetic algorithms. The steps or phases, possibly preprocessing, filtering, segmentation, normalization (optional), extraction, selection (which is a feature selection phase, and it can be optional) and classification to generate a test model each time can each use different types of methods (as exemplified above: different types of windowing, different filtering methods (Butterworth filter or other), different segmentation methods (for example in duration or number of points), different extraction methods (Fourier Transform, PCA or APC or DWT-db2 Discrete wavelet transform), etc.), and different classification methods (then an SVM, CNN exploiting the raw signal, KNN db3, RF Random Forest a DWT- and ADABOOST,. Preferably, according to the invention, the algorithms which make it possible to carry out these phases and subsequently generate a multiplicity of test models, implement, possibly randomly in certain test model results, various combinations of the different methods specific to each of the phases.Thus, the examples of generated models are very diverse, notably depending on different combinations of extraction and classification algorithms. For example, for user No. 1, there will be at least one model implementing an extraction step by FFT (Fourier Transform) followed by an RF classifier. For user No. 2, there will be at least one model implementing a DWT (for “Discrete wavelet transform”) then an SVM (Support Vector Machine) as well as a CNN (neural network) exploiting the raw signal. For user No. 3, there will be at least one model implementing an FFT with k-NN, an FFT with RF, a DWT and ADABOOST, etc. In the end, each individual will have their own authentication models.
[0058] Advantageously, in step i) of generating a multitude of authentication test models, the data processing exploits not only the data of the individual but also the data of at least one known imposter, the quantity of data used from all the known imposters considered in the generation of the multitude of test models not having to exceed the ratio between the total quantity of data of the individual and the number of known imposters.
[0059] Preferably, at least the test models selected as authentication models have also been tested during step ii) with the data of at least one known imposter to verify that the probability of recognition confidence with this data of a known imposter is indeed extremely low or even zero. This test using data from an imposter makes the test models ultimately selected more reliable.
[0060] Regarding authentication, if imposters are detected, the recognition module 20 contains the list of Y people with the highest imposter score, and has advantageously compared this list with the other individuals registered and linked to their recognition module. If necessary, this makes it possible to eliminate known individuals from the list of imposters.
[0061] Furthermore, very advantageously, the recognition module 20 presents its automatic learning algorithm which makes it possible to continue learning to recognize the physiological signals of the individual during the time that the individual continues to wear the connected device 1 after having been authenticated for the first time; the learning continues throughout the duration of the continuous authentication verification and even after, as long as the connected device is worn (according to a given number of times and / or periods). This continuous learning helps to increase the legitimacy of the continuous authentication result and of a next initial authentication (during a new access request), resulting in increased security. Indeed, it has been shown that the initial authentication performance drops by 15 to 30% when a relatively long period has elapsed, such as a week for a new access request by the same individual.However, the inventors have demonstrated that continuous learning during continuous authentication verification increases authentication performance not only during continuous verification but also during a next authentication. In particular, part of the signals used for continuous authentication over a day are retained, used to create a new dataset and to train new test models and deduce a new group of updated authentication models always dedicated to the user. This new group of updated authentication models is stored in a chain such as a blockchain, and thus makes it possible to trace all the learning of the authentication models.At each new authentication, it is the last recorded group of authentication models that will be used to determine the identity of the user, contributing to greater reliability of the authentication result. Alternatively, the recognition module 20 can respond to an authentication request from the last N authentication models (corresponding to the last recorded group of authentication models and to one or more other previously recorded groups), which further increases security. In addition, the conservation in the form of chains of the different versions of the authentication models and the associated results of the authentications, facilitates investigations in the event of an attack on the authentication system 2.If an attacker is able to modify the training set to insert his personal data in place of that of the user, the system will be able to recognize the attacker as an illegitimate user.
[0062] Regarding authentication iterations, these can be carried out after determining a result in order to confirm the authentication over time, or can be carried out over a so-called long period in order to carry out several verifications before delivering the result.
[0063] In step 6 of generating the identity certificate by the IAM module 21, the data included in this certificate are for example: - the timestamp (corresponding to the "timestamp" in English), - the validation of the identity (TRUE) or the rejection (FALSE), - the period / the end date of validity of the access authorization, - the certified identity (ID utilisateurcertified),- the identity token (which is unique and random).Additional information can be integrated such as:- the list of signals used for authentication,- the decision taken by each recognition module and the associated confidence index,- the health status of the bearer,- the detected activity,- the number of signals and the quality of the signal,- the cryptographic signature of the certificate.This additional information is particularly useful in the event of an investigation and intrusion detection. This additional information could be stored in a specific processing module linked to the intrusion.
[0064] In order to further improve the relevance of the authentication system 2 and contribute to its overall security (so as to fool attackers), various information relating to authentication and identification is preferably added, in addition to the data already listed above, and which is written in the individual's file recorded in the storage module 22. This additional information includes in particular: - detected activity (walking, running, resting, working on a computer, etc.) via an accelerometer and a gyroscope, - emotional state (calm, stressed, excited, fear, etc.), - overall health (good, bad, average), - accident detection (fall, arrhythmias, heart attacks, gross changes in blood pressure, etc.), - internal geolocation (area of a radius defined using proximity sensors or terminals or badge systems, etc.),- GPS geolocation,- environmental information such as brightness, ambient noise,- individual's body temperature (via appropriate sensor),- blood oxygen saturation (via appropriate sensor).
[0065] Among the information listed above, the health status of the individual after authentication may play an important role in security or safety depending on the intended application. For example, the rapid deterioration of the health level of the authenticated individual could result in a sudden health problem or an attack against him, which must be detected in ultra-sensitive environments such as military or nuclear centers. This change of state is intended to be taken into account by the authentication system 2 to alert and / or lead to automated decisions. The health status of the individual is notably verified from his heart rate, respiratory rate, sleep duration, body temperature and oxygen saturation, these parameters being measured from the connected device 1 which includes the appropriate sensors.Processing this data provides a health score; depending on the score's value relative to a reference value, for example below the reference value, the authentication system 2 will send an alert, temporarily block access, or request hierarchical validation.
[0066] In addition to the detection and processing of physiological signals, the authentication process can use other biometric parameters to complete the authentication, such as, for example, but not limited to: fingerprint, iris, face, hand geometry, shape of the veins in the hand, dedicated gestures.
[0067] In addition to authentication by physiological signals, the authentication process may use authentication protocols that do not use biometric data and involve an interaction with the object to which access is requested by the individual, such as for example by password, one-time password, smart card, badge, certificate or encryption key on removable media (USB key, hard disk), action and / or validation on a second device such as a telephone.
[0068] Advantageously, the authentication method of the invention takes into account, in order to evaluate the authentication result (TRUE / FALSE), the quality of the signal sent by the connected device 1 and received by the authentication system 2. The evaluation of the quality of the signal corresponds to the evaluation at least of the noise of the signal. A poor quality signal may come from events such as movements on the sensor or external conditions. Such events may for example be for a bracelet as a connected device, a change in the way the wrist is worn, a change in the wearer, a possible attack on the wearer of the bracelet, a fall or a loss of consciousness.
[0069] Thus, the authentication process includes a step of evaluating the signal quality, this step combined with the step of processing the received physiological signals, leads to a step, before generating the recognition result, of rejecting unusable signals instead of rejecting the identity of the individual. In addition, the temporal monitoring of the signal quality also makes it possible to detect the correct wearing of the sensor over a long period (in particular at least ten minutes). A perfect signal quality over a long time can, for example, show a forging attack. In order to determine the proportion of poor quality signals, a Fourier Transform will be used, for example.In order to evaluate the quality of the signal, the authentication system 2 comprises a signal quality evaluation module (over a certain period) comprising at least one signal quality (noise) evaluation algorithm of the type, for example, KNN (for "K-nearest neighbors" in English or "K nearest neighbors" in French) or SVM. Thus, over a period, for example of one hour, the signal quality evaluation module determines the pieces of the signal that are too noisy to be usable and gives probabilities on the actual wearing of the connected device 1 by the user. This evaluation can also be made over repeated time intervals, in particular between several minutes to several hours depending on the needs, which adds to the authentication security.Additionally, it is possible to add modules dedicated to user movement analysis (via accelerometer and gyroscope) to improve predictions and associate noise with typical user movements. This will, for example, make it easier to detect incidents such as device removal or the injection of forged signals.
[0070] In addition, the authentication system 2 may include a signal quality improvement module from appropriate filters, such as Butterworth filters, FIR, auto-encoders, etc.
[0071] Advantageously, the authentication method of the invention includes a method for detecting forged signals and for accelerating the recording of the user's data (and therefore accelerating the prior learning by the recognition module 20). The authentication system 2 comprises for this purpose a forging detection module 23 with one or more associated algorithms and in connection with the recognition module 20. An example of a method for detecting forged signals and for accelerating the recording of the data is to artificially generate signals resembling those of the users being recorded (the generation of artificial signals such as ECG signals is known per se). By artificially modifying the data, it will be possible to detect a possible attack which would aim to reproduce only artificial data and not combined artificial and authentic data of an individual.
[0072] Advantageously, the authentication method of the invention makes it possible to detect attacks (a third party who will send into the sensor 3 data of the individual which will have been recorded previously without his knowledge). Various methods of detecting replay attacks can be implemented. For example, one method consists of using a hash function and keeping a large number of “hashes” of the signals. In addition, by coupling a “picewise hashing” algorithm to the replay attack detection method, the authentication system 2 makes it possible to detect the reuse of pre-recorded signals.
[0073] Advantageously, as already indicated above, the authentication method of the invention is capable of identifying the best imposters (users who attempt to pass themselves off as the authentic individual). For this purpose, the step of identifying the best imposters comprises calculating a success score for each user and calculating a success or imposture score for each imposter facing this user. Considering that the distributions of the scores for the user and the imposter scores follow two respective normal laws, their intersection and the size of this intersection, more or less large, will be considered to determine the probability for an imposter to succeed in being authenticated by the authentication system during an attack. The smaller the size of the intersection, the more the authentication system 2 guarantees reliable authentication of the user.Thus, in order to further improve authentication and identification, the authentication process establishes the list of the Y best imposters for each user and, at each authentication of the user, attempts to authenticate these Y best imposters (compared to the other individuals known in the authentication system via the different recognition modules dedicated to each registered individual); this makes it possible to reduce the probabilities and scores of each of these imposters finally known to the user in order to obtain a validation for the user and a rejection for each imposter. However, this step of identifying the best imposters being a resource-intensive task, it will only be advantageously used in case of doubts about the identity of the person or in case of authentication for an ultra-sensitive action.
[0074] An example of a connected device associated with an example of implementation of the authentication method of the invention is now described.
[0075] For the first example, a smartwatch is used as connected device 1. The majority of smartwatches have the following sensors: PPG (for heart rate and SpO2 for oxygen saturation), three-dimensional accelerometer (detection of sports activity), gyroscope, and bio-impedance sensor to detect whether the object is being worn or not. The authentication process then uses as sensors 3, the PPG sensors, the three-dimensional accelerometer and the gyroscope. Two recognition modules are implemented, a recognition module 20A for PPG and a recognition module 20B for movement using the signals from the accelerometer and the gyroscope. The data from the bio-impedance sensor will be used to determine whether the watch is being worn or not.The authentication process aims to determine whether the wearer of the watch is the correct user and, if so, to issue an identity certificate so that the user can use it to be authorized to access, for example, software or a physical space. If the state of the bioimpedance sensor changes (the watch is no longer worn), the tokens and the watch's memory are reset.
[0076] In this watch example, an authentication frequency of, for example, once per minute with a measurement time of 30 seconds is considered. Wearing the watch by a good user can give access to a secure room; in the case of a secure room, it can be required that the continuous authentication be relatively long, for example according to a ten-minute verification. The watch continuously measures the signals from all the sensors and stores them in memory. Every minute, the watch transmits the last minute of signal to the authentication system 2 which analyzes the last 30 seconds in order to validate the identity of the user (authentication). The authentication analysis consists of implementing the aforementioned steps 1 to 6 of the authentication method.Previously, the watch was worn for a certain time so that the authentication system 2 generates a group of authentication models unique and specific to the individual from the selection of the multitude of authentication test models that were implemented by machine learning of the individual's personal data alone. Subsequently, during an authentication request, if the identity has been validated by the authentication system 2, it then produces an authentication certificate that may contain the following information: date, validation or rejection of the identity, the confidence level, the signal quality, the emotional state, the state of health, the SpO2 saturation, the validation of the non-change of state of the bio-impedance sensor (no removal of the watch), the detected activity, the identity token.In return, the identity token is transmitted to the user's watch 1, which can use it to authenticate to software services or access a physical space to which they are authorized. When the accredited user wants to access a secure room based on a continuous 10-minute authentication, the authentication system 2 will analyze the last ten minutes of physiological signals recorded via the smartwatch to validate a second time the identity and the continuity of the authentication states over the last ten minutes of wearing the watch. If successful, a new identity certificate and a token are issued so that the user can access the room.As long as the watch remains worn by the user who is in the room, the continuous authentication process continues, always transparently to the user, allowing the user's data to continue learning in order to update the user's authentication model pool.
[0077] In another example, the user wearing the connected watch implements the continuous authentication method of the invention to protect his telephone and his watch as well as his personal data. When the connected watch is first worn, the authentication system 2 (on server) collects a certain number of PPG signals transmitted by the connected watch to generate by machine learning the authentication models dedicated to the user. Once the group of authentication models has been generated, it is recorded in the user's telephone. Subsequently, each time the user needs to authenticate with respect to the telephone, the watch sends the PPG signals to the telephone which implements (via a specific software application) the authentication analysis from the dedicated authentication models (of the group) recorded in the telephone in order to recognize the user.Regularly, part of the day's authentication data will be transmitted from the phone to the recognition system 2 on the server in order to continue training the user's dedicated authentication models and update them.
Claims
Method for continuous authentication of the identity of an individual, comprising a first authentication step by the recognition of at least one physiological signal of the individual transmitted by at least one sensor worn passively by the individual, and after the first authentication step, at least one iteration step of authentication of the identity by the recognition of said at least one physiological signal of the individual, characterized in that - prior to the authentication and authentication iteration steps, the method comprises for each individual i) a so-called prior learning step which consists of processing by automatic learning the data of at least one physiological signal specific to the individual to generate a multitude of authentication test models, ii) testing this multitude of authentication test models with the data of the individual which continue to be captured,iii) to classify the authentication test models according to their relevance of probability of correspondence with the individual's data and iv) to retain only a selection of a group of authentication test models classified with the best probability of correspondence, these selected authentication test models being the so-called authentication models which are retained for the authentication and authentication iteration steps, each individual having his own group of authentication models; - the authentication and authentication iteration steps consist of comparing the captured data of the individual with the authentication models specific to the individual, of associating a probability of correspondence with the result of comparison with each of the authentication models and of processing the probabilities to deduce therefrom a result of acceptance of the authentication or of rejection of the authentication., Method according to claim 1 characterized in that in step i) which consists of generating a multitude of authentication test models, the processing of the data exploits not only the data of the individual but also the data of at least one known impostor, the quantity of data used from all the known impostors considered in the generation of the multitude of test models not having to exceed the ratio between the total quantity of data of the individual and the number of known impostors. Method according to claim 1 or 2, characterized in that, in step ii), at least one test model is tested from the data of at least one other individual considered to be a known impostor, preferably in step ii) the list of the Y best impostors for each user is established and, at each authentication of the user, test models attempt to authenticate these Y best impostors in relation to the other known individuals in the authentication system. Method according to any one of the preceding claims, characterized in that the processing of the probabilities which are associated with the results of comparison of the captured data with the authentication models, to deduce an acceptance or rejection result, is implemented by a decision tree. Method according to any one of the preceding claims, characterized in that it comprises a step of issuing an authentication certificate when the recognition is accepted, the authentication iteration steps being carried out after the first authentication step and the issuing of the authentication certificate, or the authentication iteration steps being carried out following the first authentication step and before issuing the authentication certificate. Method according to any one of the preceding claims, characterized in that it implements, during at least one authentication iteration step, automatic learning to renew one or more authentication models dedicated to said individual. Method according to the preceding claim, characterized in that it renews by learning during the iteration steps of authentication of an individual, the authentication models and records N last authentication models which correspond to those immediately renewed and to those of one or more previous iteration steps, and in that the execution of the authentication method during a new and subsequent authentication is carried out from the last authentication models recorded or from a combination of the N last authentication models recorded. Method according to any one of the preceding claims, characterized in that it takes into account, when evaluating the authentication result which is of binary type (TRUE / FALSE), the quality of the signal and preferably the quality of the signal over a certain duration, in particular the quality of the signal being evaluated by processing the noise of the signal. Method according to any one of the preceding claims, characterized in that the physiological signal(s) are chosen from the PPG and / or ECG signal(s) and / or the physical activity of the individual and / or his bio-impedance, in particular the authentication method further comprises a step of evaluating the state of health of the individual from the physiological signals captured. Method according to any one of the preceding claims, characterized in that it implements a group of authentication models per type of physiological signal and the method comprises an algorithm for evaluating the authentication from the combination of the recognition results from each of the groups of authentication models for each of the types of physiological signals. Method according to any one of the preceding claims, characterized in that it measures and evaluates data other than one or more physiological signals of the individual, said other data being processed so that the results are combined with the results of the physiological signal(s) to establish recognition, in particular said other data being, taken alone or in combination, biometric data such as fingerprint, face, iris, vein pattern, or a password which may be single-use, a smart card, a badge, a certificate or an encryption key on a removable medium such as a USB key, a validation action on a second device such as a telephone. Method according to any one of the preceding claims, characterized in that it comprises a step of detecting a replay attack and / or a step of detecting forged signals. Continuous authentication system (2) for the identity of an individual, comprising electronic processing means and algorithms for implementing the authentication method according to any one of the preceding claims, the processing means comprising at least one recognition module per individual (20), a so-called IAM module (21) for identity and access management, and a data storage module (22), the recognition module per individual generating by automatic learning the authentication models dedicated to the individual and in relation to a physiological signal. Authentication system according to the preceding claim, characterized in that the processing means comprise a replay detection module, a forged signal detection module, and a module for evaluating additional data specific to the individual including their state of health. Computer program comprising code instructions for executing the steps of the authentication method according to any one of claims 1 to 12, when said program is executed by a processor.