Security authentication token
By capturing and analyzing user gestures in an XR environment, the complexity and repeatability of gesture passwords are ensured, solving the problem of easy copying of gesture passwords in existing technologies and improving security and usability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BRITISH TELECOM PLC
- Filing Date
- 2023-02-27
- Publication Date
- 2026-05-22
AI Technical Summary
In extended reality (XR) environments, existing gesture passwords are easy to copy and difficult to ensure security and memorability without affecting user experience.
By capturing user gestures, analyzing their complexity and repeatability, and repeatedly capturing until the complexity and repeatability requirements are met, and proposing modifications to gesture fragments to increase or decrease complexity when necessary, the similarity of gestures is detected using machine learning techniques to ensure the security and usability of gesture passwords.
It implements gesture passwords that are difficult to replicate in XR environments, which are both secure and easy for users to remember, thus improving the security and user experience of XR environments.
Smart Images

Figure CN118946883B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a method for verifying a security authentication token. Background Technology
[0002] Computers can control human user interfaces to create extended reality (XR) environments, where some or all of the XR environment perceived by the user is computer-generated. These XR environments can be virtual reality (VR), augmented reality (AR), and / or mixed reality (MR) environments, where some or all of the XR environment can be generated by the computer in part using data describing the environment. This data can describe, for example, virtual objects, which can be presented in a way that the user feels or perceives as part of the physical world, and can be interacted with. As a result of presenting and displaying the data through a user interface device such as a head-mounted display, the user can experience these virtual objects. The data can be displayed to the user for viewing or can be controlled to play audio for the user to hear, or it can control a tactile (or haptic) interface, allowing the user to experience the tactile sensation of the virtual objects.
[0003] XR applications allow users to share and work within the same virtual environment. This provides cybersecurity analysts with access to multiple security tools, and therefore access to sensitive data, necessitating the assurance that only authorized personnel can access and manage that data. Therefore, robust authentication methods are required within the XR environment to maintain environmental security and secure use.
[0004] In XR environments, keyboards and mice are uncommon. XR devices obscure or even completely hide the real-world environment with virtual objects and scenes. Therefore, finding and using a mouse and keyboard is very difficult, resulting in a frustrating experience, and ultimately, users prefer to remove the keyboard and mouse entirely from the experience.
[0005] Interactions within XR environments (such as the Oculus Quest) can preferably be performed using handheld motion controllers or sticks, or more recently, simply using vision-based hand tracking with bare hands. Realistic hand tracking will allow people to be more expressive in VR and benefit from a more natural form of interaction. For those unfamiliar with or uncomfortable with game controllers, hand tracking will also reduce barriers to VR. Your hands are always with you and always engaged—there's no need to hold a controller, keep it powered on, or pair it with headphones to enter VR.
[0006] Basic systems that use gestures for authentication purposes are known. However, simple gesture passwords can be copied by observing a user's gestures while using access control applications. Therefore, there is a need for users to be able to create gesture passwords that are not easily copied. Summary of the Invention
[0007] According to a first aspect of this disclosure, a method for verifying a security authentication token for accessing an application is correspondingly provided, the method comprising:
[0008] Capture user gestures as authentication tokens;
[0009] Analyze the gesture to evaluate its complexity.
[0010] Specifically, in response to determining that the complexity metric does not satisfy the defined complexity metric,
[0011] Repeat the capture step and the analysis step until the gesture meets the defined complexity metric; and then
[0012] The user is asked to repeat the approved gesture;
[0013] Capture repetitive gestures provided by the user;
[0014] Determine whether the repeated gestures meet the defined repeatability requirements;
[0015] Specifically, in response to determining that the repeated gesture does not meet the repeatability requirement,
[0016] Repeat the method described above; and
[0017] In response to determining that the repeated gestures do indeed meet the repeatability requirement,
[0018] The gesture is verified as a security authentication token.
[0019] First, user-provided gestures are repeatedly captured and analyzed until they meet a complexity metric, and then it is determined whether the gesture is repeatable. The initial analysis of the captured gestures determines whether they are complex enough to be difficult to replicate and whether they are too complex to be remembered or repeated. This analysis is preferably performed by a computer program, and therefore it is based on a numerical analysis of the user-provided gestures. However, this disclosure also includes additional determinations by checking whether the user can actually correctly repeat the gesture before validating it as a secure authentication token. While the initial check analyzes a gesture's complexity metric, the second check analyzes the repeatability of multiple gestures, which is also indirectly a complexity metric. The more complex the gesture, the harder it is to repeat. Therefore, this method is a control mechanism that prevents or invalidates overly complex gesture authentication tokens that are too difficult to repeat.
[0020] Preferably, the repeatability requirement includes determining a measure of similarity between the repeated gestures and approved gestures. How repeatable a gesture is can be determined by having the user repeat the gesture and then comparing the similarity of the gestures. If a user is able to perform gestures that appear similar, they can be considered repeatable.
[0021] Preferably, the step of requesting the user to repeat the approved gesture includes repeating it a predetermined number of times. The more times the user repeats the gesture, the more repeatability aspects are tested for verification purposes. If users can repeat their gestures multiple times, it means the gesture is not too complex and they will be more likely to remember it. Preferably, all gestures repeated a predetermined number of times are determined to achieve a measure of similarity between the repeated gestures and the approved gestures. If users are able to repeat their gestures multiple times each time, it also means the gesture is not too complex and they will be more likely to remember it.
[0022] Preferably, the defined repeatability requirement includes comparing the complexity measure of repeated gestures with the complexity measure of approved gestures. Gestures can be analyzed in various ways regarding complexity measures, and by comparing how complex they are, it can be determined how similar they are and, consequently, how repeatable the gestures are. If the various measures of complexity are similar, the gestures can be considered less complex and therefore repeatable.
[0023] Preferably, the gesture comprises one or more gesture segments. Preferably, the gesture also includes at least one redirection segment, and some gesture segments correspond to at least one or more portions of the redirection segment, or correspond to portions of the gesture adjacent to the redirection segment.
[0024] Gestures can be analyzed as a whole, but it is preferable to consider them as a series of connected sub-gestures or as gesture fragments. The analysis becomes more precise and refined if the individual parts can be analyzed and compared. Gestures typically involve several redirected movements, and it is preferable to analyze gesture fragments that make up different redirected segments or gesture fragments adjacent to the redirection point.
[0025] Preferably, the defined complexity metric includes a minimum complexity metric, and the method further includes: determining and proposing modifications to the gesture to increase the complexity metric of the gesture; and repeating the capture step and the analysis step until the gesture meets the minimum complexity metric.
[0026] When users are prompted to choose a gesture password as their authentication token, they will try out several gestures, but they will not know whether the gestures are secure enough. The method according to this disclosure is advantageous for users in helping them understand how they can change their gestures to increase the complexity measure and thus make the gesture more secure and harder for a malicious person to replicate. It also facilitates guiding users through the process by prompting them to modify their suggested gesture passwords to increase the complexity measure, rather than considering potentially more complex different gesture passwords. This guided process significantly speeds up the process of choosing a gesture password, which is often very frustrating and time-consuming, especially for older people or those less tech-savvy.
[0027] Furthermore, simple (straightforward) gesture passwords, such as names or locations, or simple geometric symbols (e.g., squares, circles, or triangles), are easily recognizable to an observer, and even if it's impossible to easily see all parts of the gesture strokes, an observer can still potentially deduce the missing parts from the recognized portions by guessing what the whole password might be. However, it is difficult for an observer to detect one or more changes that deviate from the user's suggested simple gesture, even if they can correctly assume what those changes might be.
[0028] Preferably, the proposed modification includes proposing to add additional gesture segments to increase the complexity of the gesture. Preferably, the proposed modification includes proposing to change at least one gesture segment to increase the complexity of the gesture.
[0029] There are at least two main approaches to increasing the complexity of gesture passwords. Gesture fragments can be added to user-suggested gestures, or user-suggested fragments can be modified. Gestures typically consist of several user-suggested redirection gesture fragments, and by simply adding another gesture fragment or modifying just one of them, the complexity increases, making it potentially more secure and harder to replicate. Conversely, users don't need to change the entire gesture or most of it, but only the distinctive parts, which simplifies the modification process.
[0030] Preferably, the complexity metric is evaluated based on the recognition of one or more features of the user-provided gesture. Preferably, the recognized features include one or more of the following: length, velocity, acceleration, redirection segment or point, amplitude, zero-velocity event, covered mesh volume or mesh area, total transaxial variation, entropy, angle, and gesture overlap. Preferably, proposing modifications to the user-provided gesture includes modifying one or more of the recognized features to increase the complexity metric.
[0031] Therefore, there are multiple ways to suggest users modify their gestures to make them more secure. The degree of variability in the complexity of a gesture is virtually limitless, achieved by changing one or more of the aforementioned features throughout or in parts of the gesture. Thus, the method according to this disclosure provides a comprehensive way to implement a secure password that is difficult for an observer to copy.
[0032] Preferably, the identified features x Weighted separately w and complexity metric from The arithmetic mean of the features is derived as follows:
[0033]
[0034] Among them, based on the complexity metric used to evaluate Features x To determine the minimum complexity metric.
[0035] Preferably, the complexity metric is based on at least a portion of the gesture or on fragments of the gesture. Preferably, the defined repeatability requirement necessitates a complexity factor for the repeated gestures. Complexity factor of approved gestures Similarity measure between them.
[0036] The method according to this disclosure becomes very general and measurable, whereby the selected features, along with their corresponding weights, can be averaged according to a formula and compared with other gestures or gesture fragments (e.g., repetitive gestures and gesture fragments). This disclosure is not limited to using the formula described above, but can use any type of formula suitable for recognizing and comparing gestures and gesture codes, including complex metrics and / or repeatability measures.
[0037] Therefore, operators who verify the secure authentication tokens used to access applications have advanced and highly accurate tools at their disposal. Operators can choose from a large number of features and limit analysis to very specific gesture fragments. This ensures a robust authentication system and is user-friendly when users are guided to choose a gesture password that is both secure and repeatable (i.e., not too difficult to remember).
[0038] Preferably, in response to determining that the analyzed gesture exceeds a defined maximum complexity metric, the method further includes determining and proposing modifications to the gesture to reduce the complexity metric of the gesture, and repeating the request step, the capture step, and the analysis step; and wherein determining that the gesture meets the minimum complexity metric further includes determining that the gesture does not exceed the maximum complexity metric.
[0039] Correspondingly, there exists a defined maximum complexity metric when gestures are considered very secure but overly complex—that is, gestures deemed too difficult to remember or repeat. Therefore, for insecure gesture passwords, users are similarly prompted to modify their gestures, but to make them less complex so they are easier for users to remember. A common phenomenon is that users choose overly complex and overly grandiose passwords because even if they can remember the password when making the choice, they are more likely to forget it after a period of time.
[0040] Preferably, the method further includes comparing the captured gesture with gestures in a database that includes compromised or commonly used gestures; and, in response to determining that the captured gesture meets a similarity level with at least one gesture in the database, considering the captured gesture as not meeting a minimum complexity metric. Preferably, machine learning techniques are used to perform the determination of the similarity between the captured gesture and gestures in the database.
[0041] Machine learning techniques can include algorithms trained on gestures or elements from gesture input (such as the number of redirections or pauses within a gesture) to detect the similarity between a gesture and gestures stored in a database. The algorithms used can be a single technique or several techniques applied together. Several techniques that can be applied include artificial neural networks, dynamic time warping, and decision tree classifiers. Similarity can be output as a continuous variable, which is scored relative to a threshold to determine whether a match is sufficient.
[0042] Preferably, the application is a virtual reality application, an augmented reality application, a mixed reality application, an extended reality application, or a 3D application.
[0043] When users use an XR system, a defined virtual environment exists, allowing users to see their basic actions, such as hand movements. Furthermore, when gestures are provided for authentication, it is advantageous for users to have visual cues that enable them to correctly perform those gestures.
[0044] According to a second aspect of this disclosure, a computer system is provided, the computer system including a processor and a memory storing computer program code for performing the steps of the methods described above.
[0045] According to a third aspect of this disclosure, a computer program unit comprising computer program code is provided, which, when loaded into and executed on a computer system, causes the computer to perform the steps of the above-described method. Attached Figure Description
[0046] To better understand this disclosure, examples will now be described by way of example only with reference to the accompanying drawings, in which:
[0047] Figure 1 These are examples of different gestures with increased complexity.
[0048] Figure 2 It shows the relationship with Figure 1 The same gesture and gesture fragments extracted from the gesture;
[0049] Figure 3 This is an example of a process that proposes additional gesture fragments to increase the complexity of a gesture;
[0050] Figure 4 This is an example of modifying gestures to increase their complexity; and
[0051] Figure 5 This is a flowchart of a method for verifying a security authentication token according to an exemplary implementation of this disclosure. Detailed Implementation
[0052] The following description is presented to enable those skilled in the art to make and use the systems and / or perform the methods of the invention, and is provided in the context of a particular application. Various modifications to the disclosed embodiments will be readily apparent to those skilled in the art.
[0053] The methods according to this disclosure are preferably performed in XR environments with head-mounted displays (such as the Oculus Quest or smart goggles), but they can also be applied to conventional real-world camera-based capture setups, such as the Xbox Kinect. Newly developed interactive sensors using radar technology, for example, in Google Soli project, can track submillimeter movements of the fingers at high speed and with high precision, and are also advantageous and applicable applications. All these different systems are capable of capturing and tracking user gestures.
[0054] Figure 1 The diagram illustrates different hand gestures and their trajectories with increasing complexity. Gestures with low complexity are insecure because they are easy to replicate, but also easy to repeat and remember. As the complexity increases with more advanced gestures, security increases, but the gesture becomes harder to replicate and remember, especially over time. Therefore, a trade-off is needed to find a repeatable, secure gesture cipher. Figure 1 In the example, the first two gestures are too easy to copy, while the last gesture is too complex and impossible to repeat and remember. The third gesture illustrates an example of a secure and repeatable gesture password.
[0055] Figure 2 It shows the relationship with Figure 1The same gesture and gesture segments extracted from said gesture. The extracted gesture segments can preferably be used to help identify the complexity and repetitiveness of the gesture. The gesture segments are preferably selected from portions of a gesture or gesture trajectory that begin exactly before and end after a redirection segment, but the gesture segments can also cover portions between two redirection points or even longer portions that span multiple redirection segments. A redirection segment is defined as an adjacent portion before and after a redirection point, and a redirection point is a point where there is a substantially significant change in the direction of the gesture trajectory. A substantially significant change can be defined with respect to a predefined change in the derivative of any chosen number axis with respect to the gesture trajectory.
[0056] When analyzing a user-provided gesture according to this disclosure, one or more identifying features associated with the gesture are determined. The determined features may be, for example, one or more of the following: length, velocity, acceleration, redirection segment or point, amplitude, zero velocity event, covered grid volume or grid area, total transaxial change, entropy, angle, and gesture overlap, but they may also be other similar related features.
[0057] The identified features can be based on the entire gesture or on one or more gesture segments. For example, the features can be based on the average speed, acceleration, or amplitude of the entire gesture, or on the average speed, acceleration, or amplitude of one or more gesture segments. This results in a more advanced and complex authentication system than one based solely on the entire gesture.
[0058] Zero-velocity events can include pause points (typically at redirection points) where a gesture stops very shortly along the path. Zero-velocity events include their number and their duration (individually and collectively). Amplitude can refer to the dominant amplitude peak of the gesture's velocity or acceleration as a whole or for certain gesture segments. The covered grid volume or grid region can refer to how many grid volumes or grid regions the gesture traverses in a defined 3D space or a defined 2D plane (the plane to which the 3D gesture is chosen to be projected (e.g., a vertical plane parallel to the camera plane behind the user)). Total transaxial variation can refer to how the gesture (or velocity or acceleration) varies across the x, y, and z axes or across any other applicable coordinate system (such as spherical or cylindrical coordinates). Entropy can include multiple possible variations of the authentication factor, i.e., a measure of variation. If something has low entropy, it is easy to guess randomly. For example, a coin has lower entropy than a die. Therefore, a more varied gesture will produce higher entropy than a simpler gesture. Angle can refer to the angle of the individual redirection segments. Each such segment will define the plane and angle of the gesture trajectory. Gesture overlap can be simply represented as the number of times a gesture trajectory crosses its own path. This can be applied to a defined mesh volume, but will produce more overlap in a 2D plane on which the 3D gesture has been selected to be projected.
[0059] Return to reference Figure 1 The third exemplary gesture, and as a brief example, the exemplary method according to this disclosure can in particular detect 6 redirection segments and 6 redirection points, 1 zero-velocity event, 8 square or grid areas used, average velocity v, and length. l This could correspond, for example, to a 60% complexity score and could satisfy a minimum complexity metric, which could be predefined or pre-selected. The minimum requirement is the minimum complexity metric that a gesture must satisfy or exceed. However, for... Figure 1 The fourth exemplary gesture contains some of these features and can therefore be identified as a very complex gesture that is too difficult or impossible to reliably repeat and remember. For completeness, it can be seen that the gestures in the first two examples lack sufficient complexity measure and thus have a complexity measure that does not meet the minimum requirement as the minimum complexity measure.
[0060] In use, the exemplary authentication system according to the examples of this disclosure may employ gesture tracking devices or systems to monitor and analyze user movements. The following situations may occur:
[0061] 1. The user initiates an XR environment or simply places themselves at the starting point of the authentication system, where a camera or EM radiation device can see or reach the user's arm and hand, requesting access to high-security resources or applications and requiring authentication.
[0062] 2. Since the user has not yet registered with the system, the user is asked to provide a gesture as an authentication token.
[0063] 3. Users provide gesture passwords using their arms and hands or by waving motion-based controllers.
[0064] 4. User-provided gestures are captured by a gesture tracking device or system.
[0065] 5. Gestures are analyzed in a computing device, on a dedicated chip, or on an on-board chip using appropriate software to determine one or more identifying features associated with the gesture (e.g., length, velocity magnitude of certain gesture segments, covered grid volume, and corresponding angles at all redirection points).
[0066] 6. If the analyzed gesture does not meet the defined complexity metric, then identify and propose modifications to the user-provided gesture to achieve a gesture that meets the defined complexity metric. For example, the proposal could be to add additional gesture segments or modify at least one gesture segment to increase the gesture's complexity metric.
[0067] 7. Repeat steps 3 through 6 of the previous method if the user attempts to combine the proposed modifications, until the gesture meets the defined complexity metric.
[0068] 8. The authentication system approves the gesture as a security authentication token.
[0069] 9. Optionally, if the analyzed gesture exceeds the defined maximum complexity metric—for example, if it is so complex that repeatability and reliability would be compromised—then a modification to the gesture can be identified and proposed to reduce its complexity metric. The request, capture, and analysis steps are then repeated. Determining that a gesture meets the minimum complexity metric also includes determining that the gesture does not exceed the maximum complexity metric.
[0070] Optionally, external checks can be performed on gesture passwords, such as comparing them against a database to verify their security. Gestures can be categorized based on a list of known / common or leaked gestures, and if a gesture closely resembles any such gesture in the database, it can be considered to fail to meet the minimum complexity requirement, regardless of how complex the gesture provided by the user is. Optionally, even if the password is complex, the user can be alerted that their password may be vulnerable to hacking.
[0071] 10. The user is also required to repeat the approved gesture, for example, N times. If it is determined that the gesture does not meet the requirements for repeatability, all previous method steps are repeated until the gesture meets the requirements; then, the gesture is approved as a security authentication token. This is to ensure that when the computer software believes the repeatability is high, the user can actually repeat the gesture. If the match is below the lower defined threshold, the repeatability is proven to be low, and the system returns to step 3. Furthermore, if the user can repeat the gesture N times with high precision above the higher defined threshold, the gesture can be registered as a valid authentication token for that user. It is worth noting that the repeatability threshold can be provided by comparing gesture iterations, for example, by determining a similarity measure between iterations.
[0072] 11. Finally, the user is asked to log in, where they will enter their credentials and perform an approved gesture.
[0073] Another example will be given to illustrate and emphasize other aspects of this disclosure. Regarding the determination of the identified features... x They can be weighted individually. w and complexity metric from The arithmetic mean of the features is derived as follows:
[0074]
[0075] Figure 3This is an example of a process that proposes additional gesture fragments to increase the complexity of a gesture. The user provides the initial gesture as... Figure 3 The system uses a) the gesture password and analyzes the gesture to determine its complexity. If it does not meet the defined complexity metric, the system proposes to increase the complexity metric by adding additional fragments, such as... Figure 3 As shown in b) of the diagram. In the background, a lookup table with gesture fragments is preferably used to find the next suitable fragment to increase the complexity metric. Therefore, the user is prompted to improve the complexity and security metrics of their gesture cipher by adding new fragments. This process can be repeated several times until the proposed final gesture fragment produces a gesture cipher with a sufficient complexity metric, see [reference]. Figure 3 c) and Figure 3 (d) in the comparison Figure 3 a) and Figure 3 In section d), we can see how the complexity of the gesture increases due to its significantly longer length, the presence of three additional reorientation segments, a greater gesture overlap, coverage of three additional mesh regions (and potentially more additional mesh volumes if it is a 3D system), etc. Furthermore, there is a potential increase in the characteristics of virtually any other measurement if those characteristics are selected for analysis.
[0076] A lookup table can be a component that helps the system determine which of the following next recommended types is best to add to a gesture cipher to appropriately increase its complexity. For example, if the user inputs a long straight line, the system can, for instance, use a representation of that line such that it can be looked up in a lookup table that may contain recommendations for angles or intersections to be added to the gesture. The lookup table can be viewed as a hash graph, where the input (i.e., part of the gesture) is used to compute an address in the lookup table such that if k is part of the gesture and h is a function forming the address, then h(k) = v, where v is the value of the next suggested action for the gesture.
[0077] To illustrate the process of using weighted and complex metrics, suppose the user provides a fairly simple gesture, and when analyzing the gesture fragment, the system finds three distinct features: "distance," "total cross-axis variation (dimension)" (each of XYZ will be counted as 1), and "zero-speed event." Then, d = 5.
[0078] The parameter w can be configured based on the application's requirements. In this example, it is defined as w_distance = 0.8, w_dimensionality = 1, and w_zero-speed_events = 0.8. This allows us to ensure that the dimension has the greatest impact on the overall value of y, which is chosen as the most important parameter for the application.
[0079] 1. The total length of the user-generated gesture is 100 cm (x1 = 0.2 represents the distance value). This will trigger the system to suggest a longer gesture (a single threshold is defined as 150 cm (x1 = 0.3)).
[0080] 2. The magnitude of the acceleration across the axis produces certain values:
[0081] x2 = 0.9 (representing the magnitude of acceleration along the X-axis);
[0082] x3 = 0.8 (representing the magnitude of acceleration on the Y-axis);
[0083] x4 = 0.1 (representing the magnitude of the acceleration along the Z-axis);
[0084] Therefore, this will trigger the system to suggest that users use the z-axis more (a single threshold is defined as 0.5).
[0085] 3. The user uses continuous, non-pausing hand gestures (x5 = 0 will represent the value of a zero-speed event). This will trigger the system to suggest at least one pause (a single threshold is defined as x5 = 0.5).
[0086] Using the formula for y, we get (x1.w_distance + x2.w_dimensionality + x3.w_dimensionality + x4.w_dimensionality + x5.w_zero-speed_events) / 5 = ((0.2 × 0.8) + (0.9 × 1) + (0.8 × 1) + (0.1 × 1) + (0 × 0.8)) / 5 = 0.392. This result is below the average threshold for the complexity metric score (using the single threshold above would yield an approved complexity metric of 0.568). This will indicate to the system that the password is not complex enough, and therefore modifications will be proposed accordingly to use longer gestures, greater gesture depth relative to the camera pointing direction (assuming it's an axis), and smaller pauses.
[0087] This process can be repeated until the gesture reaches an approved complexity metric, y = 0.568. The magnitude or relative percentage factor of the complexity metric is preferably given to the user throughout the process so that they can see or hear the effect of the gesture changes they are gradually achieving. This encourages users to keep progressing or experimenting with different gesture variations or features and not to give up, as they don't know how close they are to success and cannot understand the effect of their efforts.
[0088] Multiple suggestions to the user can be made one after another, or several simultaneously, and they can be made through visual suggestions on the screen of the gesture segment, through text instructions, or as audible read-out text. The pause instruction can be indicated by a marker in the visual suggestion, or it can be a general pause instruction used anywhere within the gesture. It can also provide direct feedback to the user while they are performing the gesture segment, such as encouraging them to extend the distance of the gesture movement; that is, the user needs to maintain the movement, while the displayed number decreases based on the required length, reminding the user of the gesture segment's duration. Furthermore, preferably, it can display colors along the path to indicate changes in speed the user must make, and for example, the user is stimulated by red at the beginning and end of the gesture to accelerate, and by blue in the middle to slow down. This can be accomplished with different audio signals. Similarly, the user can be signaled when, for example, a sudden change in direction or an increase in angle.
[0089] Each threshold is defined according to the application / use case. The higher the threshold, the more complex the gestures need to be. If the application owner or operator truly wants secure and complex gestures, then a higher threshold will be set.
[0090] Figure 4 This is an example of modifying a gesture to increase its complexity. The user completes a full gesture password that has not been approved due to insecurity. As in the previous example, they are then preferably presented with suggested changes to certain parts via a lookup table, which increases the gesture's complexity. The user will be prompted to redo their gesture using the suggested changes. These stages can be repeated as needed until the gesture password contains sufficient complexity.
[0091] Similarly, if a gesture complexity metric is too complex (i.e., above a certain threshold), it may be deemed unsuitable for use. At this point, the system can use the same process, such as a lookup table, to suggest changes to make the gesture less complex but still complex enough to meet the complexity metric requirements.
[0092] Figure 5This is a flowchart of a method for verifying a secure authentication token according to an exemplary implementation of this disclosure. Initially, in step 502, the method captures a user gesture provided by the user as an authentication token. In step 504, the method analyzes the captured gesture to evaluate its complexity metric. In step 506, the method determines whether the evaluated complexity metric meets a minimum complexity metric. If it is determined that the evaluated complexity metric does not meet the minimum metric, the method determines and proposes a modification to the gesture in step 508 to increase the gesture's complexity metric, and repeats steps 502, 504, and 506. In step 506, if the method determines that the gesture does indeed meet the minimum complexity metric, the gesture is repeated in step 510. In step 512, if the method determines that the gesture is not repeatable, steps 502, 504, 506, and 510 are repeated. In step 512, if the method determines that the gesture is repeatable, the method approves the gesture as a valid authentication token in step 514.
[0093] Based on this specification, embodiments of the present invention will be apparent to those skilled in the art. This specification is to be considered exemplary only.
[0094] Where this application lists one or more method steps, the presence of precursor, subsequent, and intermediate method steps is not excluded unless explicitly stated otherwise. Similarly, where this application lists one or more components of an apparatus or system, the presence of separate or inserted additional components is not excluded unless explicitly stated otherwise.
[0095] Furthermore, where the steps of a method or process have been listed in a specific order in this application, it may be possible or even advantageous to change the order in which some steps are performed in certain circumstances, and unless such order specificity is expressly stated in the claims, the specific steps of the method or process claims set forth herein are not to be interpreted as order specific. That is, unless otherwise stated, operations / steps may be performed in any order, and embodiments may include more or fewer operations / steps than those disclosed herein. It is also contemplated that, according to the described embodiments, a particular operation / step may be performed before, simultaneously with, or after another operation.
[0096] The scope of this invention includes any novel features or combinations of features disclosed herein. Therefore, the applicant notes that new claims may be formulated for these features or combinations thereof during the examination of this application or any other application derived therefrom. In particular, with reference to the appended claims, features of dependent claims may be combined with features of independent claims, and features of individual independent claims may be combined in any suitable manner, not merely in the specific combinations listed in the claims.
[0097] In cases where the described embodiments of the invention can be implemented at least in part using a software-controlled programmable processing device (e.g., a microprocessor, digital signal processor, or other processing device, data processing apparatus, or system), it should be understood that a computer program for configuring the programmable device, apparatus, or system to implement the aforementioned methods is contemplated as an aspect of the invention. For example, such a computer program may be implemented as source code or compiled for implementation on a processing device, apparatus, or system, or it may be implemented as object code.
[0098] Such a computer program can be encoded as executable instructions contained in a carrier medium, a non-transitory computer-readable storage device, and / or a machine- or device-readable storage device, such as volatile memory, non-volatile memory, solid-state memory, magnetic storage such as a magnetic disk or magnetic tape, optical or magneto-optical readable storage such as magnetic tape, compact disc (CD), digital versatile disc (DVD), or other media capable of storing code and / or data. Such a computer program can be provided alternatively or additionally from a remote source contained in a communication medium, such as an electrical signal, radio frequency carrier, or optical carrier. Such a carrier medium is also contemplated as an aspect of the invention.
[0099] When executed by a processor (or one or more computers, processors and / or other devices), such instructions can cause the processor (one or more computers, processors and / or other devices) to perform at least a portion of the methods described herein.
[0100] When referring to a processor in this document, it should be understood as referring to a single processor or multiple processors operatively connected to each other. Similarly, when referring to memory in this document, it should be understood as referring to a single memory or multiple memory modules operatively connected to each other.
[0101] The methods and processes may also be embodied, in part or in part, in hardware modules or devices or firmware, such that when the hardware modules or devices are activated, they execute the associated methods and processes. The methods and processes may be implemented using a combination of code, data, and hardware modules or devices.
[0102] Examples of processing systems, environments, and / or configurations applicable to the embodiments described herein include, but are not limited to, embedded computer devices, personal computers, server computers (dedicated or cloud (virtual) servers), handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, mobile phones, smartphones, tablet computers, network personal computers (PCs), minicomputers, mainframes, and distributed computing environments including any of the above systems or devices. The hardware modules or devices described in this disclosure include, but are not limited to, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), dedicated or shared processors, and / or other hardware modules or devices.
[0103] The receivers and transmitters described herein may be separate or may be included in a transceiver. The communication link described herein includes at least one transmitter capable of transmitting data to at least one receiver via one or more wired or wireless communication channels. The wired communication channels may be configured for electrical or optical transmission. Such a communication link may optionally further include one or more repeater transceivers.
Claims
1. A method for verifying a security authentication token used to access an application, the method comprising: Capture user gestures as authentication tokens; Analyze the user gestures to evaluate the complexity metric of the user gestures; In response to determining that the complexity metric does not satisfy the defined minimum complexity metric, Repeat the capture step and the analysis step until the user gesture meets the defined minimum complexity metric; In response to determining that the complexity metric exceeds the defined maximum complexity metric, Identify and propose modifications to the user gesture to reduce the complexity of the user gesture, and Repeat the capture and analysis steps until the user gesture does not exceed the defined maximum complexity metric; and then... The user is asked to repeat the approved gesture; Capture repetitive gestures provided by the user; Determine whether the repeated gestures meet the defined repeatability requirements; In response to determining that the repeated gesture does not meet the repeatability requirement, Repeat the above method; as well as In response to determining that the repeated gestures do indeed meet the repeatability requirement, The user's gesture is verified as a security authentication token.
2. The method according to claim 1, wherein, The repeatability requirement includes determining a measure of similarity between the repeated gesture and the approved gesture.
3. The method according to claim 2, wherein, The step of requesting the user to repeat the approved gesture includes repeating the approved gesture a predetermined number of times.
4. The method according to claim 3, wherein, Determine that all user gestures repeated a predetermined number of times satisfy a similarity measure between the repeated gestures and the approved gestures.
5. The method according to claim 1, wherein, The defined repeatability requirement includes comparing the complexity metric of the repeated gesture with the complexity metric of the approved gesture.
6. The method according to claim 1, wherein, The user gestures include one or more gesture segments.
7. The method according to claim 6, wherein, The user gesture includes at least one redirection segment, and some gesture segments in the gesture segment correspond to at least one or more portions of the redirection segment or portions of the user gesture adjacent to the redirection segment.
8. The method of claim 6, further comprising, in response to determining that the complexity metric does not satisfy a defined minimum complexity metric: Before repeating the capture step and the analysis step, modifications to the user gesture are identified and proposed to increase the complexity metric of the user gesture.
9. The method according to claim 8, wherein, The step of proposing modifications to the user gesture to increase the complexity metric of the user gesture includes proposing to add additional gesture fragments to increase the complexity metric of the user gesture.
10. The method according to claim 8 or 9, wherein, The step of proposing a modification to the user gesture to increase the complexity metric of the user gesture includes proposing to change at least one gesture segment in order to increase the complexity metric of the user gesture.
11. The method according to claim 8, wherein, The complexity metric is evaluated based on the recognition of one or more features of the gesture provided by the user.
12. The method according to claim 11, wherein, The one or more features include one or more of the following: length, velocity, acceleration, redirection segment or point, amplitude, zero velocity event, covered mesh volume or mesh area, total transaxial variation, entropy, angle, and gesture overlap.
13. The method according to claim 11 or 12, wherein, The step of proposing a modification to the user-provided gesture to increase the complexity metric of the user gesture includes modifying one or more of the identified features to increase the complexity metric.
14. The method according to claim 11 or 12, wherein, Identified features x Weighted separately w and complexity metric from The arithmetic mean of the features is derived as follows: The complexity metric is based on the features used to evaluate the complexity metric y. x It was determined that.
15. The method according to claim 14, wherein, The complexity metric is based on at least a portion of the user's gesture or on some gesture segments within the gesture fragments.
16. The method of claim 14, wherein, The defined repeatability requirement necessitates a complexity factor for the repeated gestures. Complexity factor of approved gestures Similarity measure between them.
17. The method according to claim 1, further comprising: The captured gestures are compared with gestures in a database that includes leaked or commonly used gestures; as well as In response to determining that the captured gesture meets a similarity level with at least one gesture in the database, the captured gesture is considered to be at the minimum level of not meeting the complexity metric.
18. The method according to claim 17, wherein, The determination of the similarity between the captured gestures and gestures in the database is performed using machine learning techniques.
19. The method according to claim 1, wherein, The application is a virtual reality application, an augmented reality application, a mixed reality application, an extended reality application, or a 3D application.
20. A computer system comprising a processor and a memory, the memory storing computer program code for performing the steps of the method according to any one of claims 1 to 19.
21. A computer program product comprising computer program code, which, when loaded into and executed on a computer system, causes the computer system to perform the steps of the method according to any one of claims 1 to 19.