Method for authenticating user via authentication device uniquely associated with user

By using a rotation gesture sequence for authentication in a virtual reality system, combined with server processing and hardware detection, the problem of user authentication being not intuitive and secure in the existing technology is solved, and a highly secure and easy-to-use authentication method is achieved.

CN120693609APending Publication Date: 2025-09-23BANKS & ACQUIRERS INT HLDG SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480013088.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-02-15
Filing Date
2024-02-12
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

Existing user authentication methods in virtual reality systems have problems such as being unintuitive, uneasy to use, and insufficiently secure. In particular, it is difficult to achieve highly secure authentication without removing the VR headset.

Method used

Authentication is performed by the user performing a rotation gesture sequence on the authentication device, and the server is used to process the rotation gesture data, including the initial angular position, final angular position and rotation direction. Authentication is combined with hardware and memory factors, and gestures are detected using a rotating plate or circular touch surface. It supports authentication sequences with multiple security levels.

Benefits of technology

It achieves highly secure and intuitive user authentication without removing the VR headset. It has a high number of combinations and is difficult to forge. It is suitable for various transactions and consent verification, providing a strong authentication solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120693609A_ABST
    Figure CN120693609A_ABST
Patent Text Reader

Abstract

The invention relates to a method for authenticating a user, characterized in that it involves using data processing means (21) of a server (2) to perform the following steps: (a) obtaining, from an authentication device (10) uniquely associated with the user and connected to said server (2), data representing a sequence of rotation gestures performed by the user on said authentication device (10), each rotation gesture is defined by an initial angle position, a final angle position and a rotation direction; (b) validating the data representative of the sequence of rotation gestures performed by a user on the authentication device (10).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of authentication, and in particular in the context of virtual or mixed reality. More particularly, the present invention relates to a method for authenticating a user, in particular a user of a virtual or mixed reality system. Background Art

[0002] It is well known that computer-generated environments can be perceived in virtual (or mixed, that is, coexisting with the real world) reality, and in particular the "metaverse", which will be a persistent, shared virtual world and is seen as the future of the internet.

[0003] To interact in such a world, users use a virtual reality (VR) or appropriate mixed reality (MR) headset.

[0004] This type of headset typically works by pairing it with two controllers (or joysticks) held in each hand by the user. The controller is primarily used for interaction: it acts as a pointing device and also exposes various mechanical buttons, each of which can be assigned a specific interaction function, depending on the choice of VR application.

[0005] This type of headset and controller is also equipped with motion sensors (usually accelerometers) specifically for visual tracking, hand tracking, and physical motion zone management.

[0006] In some models, the user can alternatively not use a controller and interact with the application freely with his hands (e.g., we therefore have a fixed external camera observing his hands).

[0007] In these environments, it is sometimes necessary to obtain proof of the user's consent and thereby verify his identity, for example to authenticate transactions and, in particular, payments (if the user purchases real or virtual objects in the Metaverse).

[0008] Traditional technologies can be used like a PIN or password, for example via a paired smartphone, but the headphones have to be taken off and put back on, which is cumbersome.

[0009] Biometric authentication factors (voice, iris, fingerprint) could extend these mechanisms in the more or less near future, but they require dedicated acquisition devices (e.g., fingerprint scanners on controllers) and there are no known implementations. Note that headsets have eye sensors, but they are limited to simple eye tracking functionality and are far from having the performance to allow iris recognition.

[0010] Alternatively, a natural way to obtain user consent in a virtual space is to ask them to perform a specific gesture. This approach is even more interesting if each user has a unique way of performing this gesture (a so-called "recognition" gesture). Application FR2214116 thus provides a reliable, secure, and repeatable identification or authentication solution, particularly for proving user consent.

[0011] The disadvantage of the latter solution is that it is still single-factor and therefore does not allow "strong" authentication, which requires the use of an external device such as a mobile terminal or a physical token.

[0012] In addition to the solution described in application FR2214116, a very high security solution is desired that remains intuitive and easy to implement by the user, for example without necessarily requiring the removal of the VR headset. Summary of the Invention

[0013] Therefore, according to a first aspect, the present invention relates to a method for authenticating a user, the method being characterized in that it comprises the following steps carried out using data processing means of a server:

[0014] (a) obtaining, from an authentication device uniquely associated with a user and connected to the server, data representing a sequence of rotation gestures performed by the user on the authentication device, each rotation gesture being defined by an initial angular position, a final angular position, and a rotation direction;

[0015] (b) verifying said data representing said sequence of rotation gestures performed by a user on said authentication device.

[0016] According to the advantageous and non-limiting features:

[0017] The verification of step (b) is a comparison of the rotation gesture sequence performed by the user on the authentication device with at least one expected rotation gesture sequence.

[0018] Step (a) includes the sub-step (a2) of issuing an invitation to the user to perform the rotation gesture sequence on the authentication device.

[0019] The user is a user of a virtual or mixed reality system connected to a server and comprising a display device of an immersive space.

[0020] The method comprises a step (c) of implementing or not implementing a transaction initiated by the user (particularly in the immersive space) according to the result of step (b).

[0021] Step (a) comprises a sub-step (a1) of receiving a request to authenticate the transaction, in response to which sub-step (a1) the invitation to the user to perform the rotation gesture sequence on the authentication device is issued.

[0022] The authentication device includes a rotation gesture detection surface selected from a rotating pad and a touch surface.

[0023] The rotational gesture detection surface extends circularly around the central element.

[0024] The rotation gesture detection surface has at least one touch mark, in particular a raised mark.

[0025] The rotation gesture detection surface has a plurality of touch marks arranged at regular intervals around the central element.

[0026] The plurality of markers consists of a single primary marker and one or more secondary markers different from the primary marker.

[0027] The authentication device is paired with the user's mobile terminal, through which the authentication device is connected to the server.

[0028] According to a second aspect, the present invention provides a server for authenticating a user, characterized in that it comprises a data processing device configured to:

[0029] - obtaining, from an authentication device uniquely associated with the user and connected to said server, data representing a sequence of rotation gestures performed by the user on said authentication device, each rotation gesture being defined by an initial angular position, a final angular position and a rotation direction;

[0030] - verifying said data representative of said sequence of rotation gestures performed by the user on said authentication device.

[0031] According to the third and fourth aspects, the present invention proposes a computer program product comprising code instructions for executing the method described in the first aspect for authenticating a user; and proposes a computer-readable storage device having a computer program product recorded thereon, the computer program product comprising code instructions for executing the method described in the first aspect for authenticating a user. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Other features and advantages of the present invention will become apparent upon reading the following description of the preferred embodiment. This description will be made with reference to the accompanying drawings, in which:

[0033] [ Figure 1 ] Figure 1 is a schematic diagram of a system for implementing the method according to the present invention;

[0034] [ Figure 2 ] Figure 2 represents an example of an authentication device used in the method according to the present invention;

[0035] [ Figure 3 ] Figure 3 It schematically shows how to define a rotation gesture on the authentication device.

[0036] [ Figure 4 ] Figure 4 is a flow chart illustrating the steps of an embodiment of a method according to the present invention. DETAILED DESCRIPTION

[0037] Architecture

[0038] The present invention relates to a method for authenticating a user (preferably Figure 1 The invention provides a method for a user of the virtual or mixed reality system 1 shown, in particular for carrying out transactions in an immersive space to which the system provides access.

[0039] It should be noted that even though, as will be seen, the present method is particularly effective in virtual / mixed reality, it is not limited to this application and can be used for any user authentication, e.g., verifying transactions in stores, unlocking devices, accessing personal spaces in applications, etc. In the context of VR, the present method can also be used to sign contracts, transfer rights, or even grant users access to secure virtual rooms (particularly personal rooms).

[0040] A possible system 1 comprises display means 12 of said immersive space (that is, with which the user can interact and in which he is "immersed"), typically headphones, and means 14 for detecting movements in said immersive space, typically a controller (or joystick) held by a hand and equipped with an accelerometer and / or a gyroscope, or alternatively a fixed external camera observing the hand.

[0041] The various devices of system 1 (eg, headphones and controllers) are interconnected in a wired or wireless (eg, via Bluetooth) manner.

[0042] Said "reality" is:

[0043] - virtual, meaning the immersive space is entirely artificial, or

[0044] - Hybrid, that is to say only partially virtual, and the immersive space superimposes the real environment and the virtual environment.

[0045] In addition to the display device 12, the mixed reality system 1 typically includes a camera that continuously captures the real world, and the rendering of the display device 12 includes virtual elements in this "real" stream. In the rest of this description, for convenience, the example of virtual reality (abbreviated as "VR") will be used, but those skilled in the art will be able to convert the environment to mixed reality (MR).

[0046] In a known manner, in each case, the display means 12 are coupled to the movements of the headset worn by the user, so that the display of the immersive environment evolves according to these movements in order to simulate reality. To this end, the system 1 generally includes means for detecting the movements of the headset worn by the user 13, such as an accelerometer or a camera, either externally viewing the head or attached to the headset and viewing the environment.

[0047] The system 1 further comprises data processing means 11, such as a processor, for implementing an application in the immersive space. For example, in a sports game, the interactive controller simulates a ball, and pressing a button corresponds to kicking the ball.

[0048] The method is implemented by a server 2, which may be the same as the system 1, or remote and connected via a network 20, such as the Internet.

[0049] The server 2 further comprises a data processing device 21 (typically a processor) and a data storage device 22 (a memory, such as a hard disk).

[0050] Finally, the method uses an authentication device 10 that is uniquely associated with the user (ie a personal device) and connected to the server 2, as will be described in more detail later.

[0051] in principle

[0052] The present method aims to authenticate a user by means of a sequence of rotational gestures (called an "authentication sequence" as an alternative to known techniques such as gesture recognition or code entry, for example) that the user performs on his personal authentication device 10. As will be seen, in practice, such a sequence allows many more combinations than a PIN code, is very easy to remember, and can be performed intuitively without looking at the device, which is very advantageous for VR applications (without having to remove the headset).

[0053] The authentication is performed specifically to obtain the user's consent (i.e., confirmation) in the immersive space. This method can be implemented whenever there is a need to verify the identity of a person using the system 1. A suitable example is transaction verification (if a user purchases a real or virtual object in the immersive space).

[0054] A "rotation gesture" should be understood as a gesture corresponding to a rotational movement, typically made by at least one finger (usually one or two fingers) or by the user's entire hand. Figure 2As shown in the example of , the authentication device 10 preferably comprises a rotation gesture detection surface 100 selected from a rotating plate and a particularly circular touch surface (and therefore typically disc-shaped), but alternatively the authentication device 100 can be a simple smartphone type mobile terminal with a full touch screen serving as surface 100, or a camera to photograph the user's hands, or even a controller 14 (in the latter case the sequence of rotation gestures is performed in the air). However, a dedicated device 10 with a physical surface 100 is still preferred to ensure strong authentication, a preferred example would be a disc-shaped device 10 with a rotating plate or a circular touch surface, and according to Figure 2 A particularly preferred embodiment of the authentication device 10 will be described later.

[0055] In all cases, each rotation gesture is defined by an initial angular position, a final angular position, and a direction of rotation. The advantages are numerous:

[0056] - The number of combinations is very high, much higher than a simple PIN, and therefore the security is very strong;

[0057] - Rotation gestures can be performed precisely even while not looking at the device and therefore holding the headset.

[0058] In the first so-called "discrete" embodiment, we have a number of predefined angular positions (number N), and each initial / final angular position is selected from one of the predefined angular positions. In other words, we have basic sectors of angular width 360 / N degrees numbered from 1 to N. Then we have 2N 2 possible gestures (note that a gesture with the same initial and final positions corresponds to a complete rotation), and the data describing a rotation gesture is typically a triplet of identifiers of the initial and final positions and an indicator of the direction of rotation (n i ,n f ,s)∈[1;N]x[1;N]x{-1,+1} (there are 2 possible values ​​for clockwise and counterclockwise, arbitrarily set here to -1 and +1). Alternatively, the gesture can be simply represented by a unique identifier i∈[1;2N 2 ]express.

[0059] Preferably, we have N≥4, and preferably, N is selected from 4, 6, 8 and 12, which allows for an intuitive division of the circle.

[0060] exist Figure 3 In our example, we have N=12, that is, 12 sectors of 30° are numbered clockwise from 1 to 12, where sector 12 is facing north (1 is facing NNE, 2 is facing ENE, 3 is facing east, and so on). We have 288 possible gestures, Figure 3The gesture 3→5 represents counterclockwise rotation (represented by the triple (3, 5, -1)). We learned that there are nearly 7 billion possible sequences of just four of these rotation gestures, which guarantees that it is impossible to find the sequence by chance.

[0061] With only N=4, we already have 32 possible rotation gestures, and a sequence of only two gestures already guarantees more than a thousand combinations.

[0062] According to one embodiment, more than one rotation may be authorized, and then the value s is where the sign of s specifies the direction of rotation and |s-1| represents the number of additional full rotations. For example:

[0063] -(3, 5, -2) would correspond to another rotation counterclockwise from 3 to 5, where one full rotation is completed (that is, a full rotation starting from 3 and then from 3 to 5).

[0064] -(3, 3, 2) would correspond to two complete clockwise rotations starting from 3 (that is, a full rotation starting from 3 and then from 3 to 3, which is the second complete rotation).

[0065] In the case where T is the maximum number of full rotations authorized (that is, s∈[-(T+1);+(T+1)]), the number of possible gestures increases to 2(T+1)N 2 .

[0066] In a second so called "continuous" embodiment we may not have predefined angular positions and just make the most accurate possible measurements of the initial and final angular positions. In other words, the initial and final angular positions may take any possible value.

[0067] method

[0068] refer to Figure 4 The method is implemented by the data processing means 21 of the server 2 and starts with step (a): obtaining data representing a sequence of rotation gestures performed by the user on the authentication device 10 from the authentication device 10 uniquely associated with the user.

[0069] It will be appreciated that, since we combine a hardware factor (the user proving that he possesses a specific authentication device 10 uniquely associated with him) and a memory factor (the sequence of rotation gestures), we have a strong authentication. If the server 2 receives data representing a sequence of rotation gestures performed by the user on an authentication device other than the one uniquely associated with him, this data will be ignored and authentication will be rejected.

[0070] What we call a "candidate" authentication sequence is the sequence that is directly executed by the user (such as a code entered on a keyboard) and based on which authentication will be attempted, as opposed to a "reference" authentication sequence, which is actually the expected sequence(s).

[0071] In this respect, step (a) preferably comprises a sub-step (a4) of encoding the candidate sequence of rotation gestures, that is, generating said data representing said sequence of rotation gestures performed by the user on said authentication device 10 from the raw data acquired by the device 10, that is, converting the measured electrical signals into a set of k triplets (n i ,n f ,s), where k is the number of gestures in the sequence. Note that the encoding can be performed directly by the device 10 or the server 2. Step (a) preferably includes obtaining (a3) ​​the raw data by the device 10 when the user performs the gesture.

[0072] In a subsequent step (b), the processing means 21 of the server 2 authenticate the user by verifying the representative data obtained from the candidate sequence of rotation gestures, that is to say the data representing the sequence of rotation gestures performed by the user on the authentication device 10 .

[0073] More specifically, the rotation gesture sequence performed by the user on the authentication device 10 must correspond to at least one expected authentication sequence.

[0074] Advantageously, the expected authentication sequence is a reference authentication sequence of the user, that is to say a predefined sequence known (and usually previously selected) by the user.

[0075] Note that there may be multiple reference authentication sequences, in particular sequences of more or less length, corresponding to various possible security levels.

[0076] For example, for authentication before transactions over a certain amount, we could have a sequence of four gestures expected, while for simple consent verification, we could have a sequence of a single gesture designed to avoid user errors. The desired security level could also be manually adjusted by the user.

[0077] Depending on the transaction and / or security level, there is therefore a reference sequence that is chosen as the "expected" sequence and compared with the sequence of rotation gestures performed by the user on the authentication device 10. Note that there may be multiple alternative expected sequences, as higher security level sequences can be made equivalent to lower security level sequences: for example, if a simple consent verification sequence (1 gesture) is expected and the user performs the full authentication sequence (4 gestures), he is authenticated.

[0078] Alternatively, the expected authentication sequence is an authentication sequence generated by the server 2 (in particular randomly generated), which the user has to reproduce in a "challenge-response" type of logic (the expected authentication sequence can be considered a one-time password OTP), see below.

[0079] In all cases, verification is similar regardless of the nature of the intended authentication sequence.

[0080] According to a first embodiment, typically when there are N possible angular positions, the data representing the two sequences (that is to say their codes) are directly compared. In this case, there must be an exact match; otherwise, at least one gesture is wrong.

[0081] According to a second embodiment, typically in the case of angular positions with continuous values ​​(as opposed to N possible angular positions), a "fuzzy matching" algorithm is used, in particular a classification model capable of calculating a proximity score between a candidate sequence and (each) expected sequence and comparing this score with a certification threshold. In fact, in this mode, it is impossible to reproduce the same sequence exactly, and we only verify that the candidate sequence is sufficiently similar to the expected reference sequence.

[0082] Transactions & Consent

[0083] Preferably, the method is part of the context of transaction verification, and more particularly of the user's consent to the performance of said transaction.

[0084] It then advantageously comprises a step (c) of implementing or not implementing, in said immersive space, a transaction initiated by said user, depending on the result of step (b), ie the result of the sequence verification performed by said user and therefore his authentication.

[0085] In other words, if the user has performed the expected authentication sequence (which means that he has given his consent), the verification result is positive and the transaction is carried out. On the other hand, if the verification result is negative, this is because the user did not give his consent after all (the system 1 may have mistakenly believed that the latter wanted to carry out the transaction after an error in the user's operation), or a third party tried to steal his identity by stealing his authentication device 10 (and therefore the user did not give his consent in the first place), and the transaction is not carried out.

[0086] We will understand “transaction” broadly, meaning it could be a payment, but also the signing of a contract, the transfer of rights, the granting of access to a secure virtual room, etc.

[0087] Preferably, step (a) comprises a sub-step (a2) of issuing an invitation to perform a candidate sequence of rotation gestures to the system 1. It will be understood that this invitation is issued to the user and displayed by the device 12 (in any form).

[0088] In a "challenge-response" type mode, in which the expected authentication sequence is an authentication sequence generated by the server 2 that the user must reproduce, the expected authentication sequence is advantageously presented to the user in the invitation, for example in the form Figure 3 Thus, the invitation sent is more precisely an invitation to reproduce a given rotation gesture sequence generated by the server 2.

[0089] This invitation may be issued in response to sub-step (a1 ) of receiving a request to authenticate said transaction from the system 1 or another server, in particular the transaction server (which in turn may be identical to the server 2 ).

[0090] Typically:

[0091] -Users want to conduct transactions in an immersive space and perform associated actions (such as photographing virtual objects).

[0092] - System 1 communicates with the remote transaction server by indicating that the user wishes to conduct a transaction;

[0093] - The transaction server sends a transaction verification request to the server 2 to ensure that the user gives his consent (sub-step (a1));

[0094] - In response, the server 2 issues an invitation to the system 1 to perform a rotation gesture sequence on its authentication device 10 (sub-step (a2)). It should be understood that, in particular, the invitation is interpreted by the system to be understood by the user, for example by displaying text in the immersive space ("Please verify the transaction by performing your rotation gesture sequence"), an audio message, etc.

[0095] - the user uses his authentication device 10 and the latter acquires the corresponding raw data (sub-step (a3));

[0096] - the device 10 and / or the server 2 encodes the gesture (sub-step (a4)), that is to say generates, from the acquired raw data, said data representing said sequence of rotation gestures performed by the user on his candidate authentication device 10;

[0097] - the server 2 may then carry out a verification of these data on said candidate sequence representing the rotation gesture in order to ensure that this candidate authentication sequence is consistent with the expected authentication sequence (step (b));

[0098] If the result of the verification of said obtained data representing the rotation gesture sequence is that said candidate authentication sequence is consistent with the expected authentication sequence (step (c)), the transaction is authenticated and the server 2 can inform the potential transaction server so that the latter can carry out the transaction.

[0099] Authentication equipment

[0100] As explained, the authentication device 10 may be any device uniquely associated with the user and connected to said server 2 and on which the user can perform a sequence of rotation gestures.

[0101] Preferably, the device 10 comprises a rotation gesture detection surface 100, which is typically a touch surface, for example made of a flexible material such as silicone. It should be understood that the touch surface is not a screen.

[0102] Reference Figure 2 The rotation gesture detection surface 100 advantageously extends circularly around a central element 101. In other words, it has a substantially annular shape, with the central element marking the center, and it will be appreciated that performing rotation gestures on such a surface is natural. Thus, the entire device 10 has a disc shape, with its housing typically having a diameter of several centimeters and a thickness of approximately one centimeter. The housing may also house the processing means and battery of the device 10.

[0103] It should be noted that the central element 101 may be a button 101 used in particular to control the device 10, for example to perform actions in the immersive space, and also to turn on / off (multiple quick presses) or trigger pairing (long press).

[0104] In fact, the authentication device 10 is preferably paired with the user's mobile terminal 3 (in particular via short-range wireless communication, in particular Bluetooth), through which the authentication device 10 is connected to the server 2, the terminal 3 actually allowing connection to a network 20, such as the Internet. The device 10 can also be attached to the mobile terminal 3, for example magnetically, which makes it possible to charge it inductively. Alternatively or additionally, the device 10 can include a port, such as a USB, in particular on the side of the housing.

[0105] The central element 101 may alternatively or additionally comprise additional biometric recognition means, such as a fingerprint sensor.

[0106] To guide the gestures, the rotational gesture detection surface 100 advantageously has at least one touch mark 102a, 102b, or even a plurality of touch marks 102a, 102b, which are arranged at regular intervals around the central element 101, that is, at regularly distributed angular positions. The marks can be physical, in particular raised marks (which can be studs, hollows, or any textured pattern), or simulated marks, such as tactile feedback (that is, vibration) that is triggered when the user reaches the position of one of these marks 102a, 102b on the surface 100.

[0107] Thus, the user can directly feel the position of the marker(s) 102a, 102b and thus orient himself on the surface 100 of the device 10 without looking. In the case of multiple markers, the user knows by feeling them that he has traveled a certain angular range and can therefore control his gestures to achieve greater precision.

[0108] In a particularly preferred manner, the plurality of markers 102a, 102b consists of a single primary marker 102a and one or more secondary markers 102b different from the primary marker 102a in order to distinguish them. Thus, the primary marker makes it possible to orient the device 10 absolutely (by identifying a reference direction, for example, north), and the other markers make it possible to control a rotation gesture. Figure 2 In the example of FIG. 1 , there are physical markings on the circular touch surface 100 , including a primary marking 102 a having three studs and three secondary markings 102 b having a single stud.

[0109] Note that the presence of multiple markers 102a, 102b is particularly effective in combination with embodiments where we have N predefined angular positions, since a marker can be directly associated with some of these predefined angular positions.

[0110] For example, using Figure 3 Configuration with 12 predefined angular positions, Figure 2 The marks are associated with position 12 (primary mark 102a), position 3, position 6 and position 9 (secondary mark 102b), respectively. Figure 3 The counterclockwise gesture 3→5 corresponds to starting from the first marker 102b after the main marker 102a, and the finger movement passes through the main marker 102a and the other two sub-markers 102a in sequence. This is very intuitive for users.

[0111] Furthermore, the device 10 may include light regions 103a, 103b arranged around the surface 100. The light regions may include extended light strips 103a (that is, occupying at least a portion of the circumference of the surface 100) and / or point light sources 103b.

[0112] The light strip 103a can illuminate as the rotation gesture progresses, and a new light source 103b can be turned on with each gesture in the sequence. Thus, if the user gets lost, he can always look at the light zones 103a, 103b to know where he is and resume the sequence.

[0113] register

[0114] The method advantageously comprises a pre-registration step (a0) to generate said data representing at least one reference sequence of rotation gestures to be used as the expected authentication sequence in the verification of step (b).

[0115] To this end, the user can perform said reference sequence of rotation gestures on said authentication device 10 in a controlled environment, that is to say for example after having authenticated himself via another existing authentication mode (biometrics, code, use of a smartphone, etc.).

[0116] Therefore, there is a step (A) of obtaining from an authentication device 10 uniquely associated with the user and connected to said server 2 data representative of a sequence of rotation gestures performed by the user on said authentication device (10), which corresponds to step (a).

[0117] We can make sub-steps (A1), (A2), (A3), and (A4) consistent with sub-steps (a1), (a2), (a3), and (a4) of step (a):

[0118] (A1) receiving a request to register at least one rotation gesture sequence as a reference authentication sequence for authentication;

[0119] (A2) issuing an invitation to said system 1 to perform said sequence of rotation gestures on its device 10 one or more times (it will be understood that it is a matter of the user choosing his sequence here, and preferably repeating it to ensure that the user is sure that he has not made a mistake);

[0120] (A3) obtaining raw data from each executed sequence;

[0121] (A4) Encode the reference authentication sequence.

[0122] In step (B), corresponding to step (b), a validation algorithm is configured or, where appropriate, a possible classification model is trained.

[0123] server

[0124] According to a second aspect, the invention relates to a server 2 for implementing the method according to the first aspect.

[0125] Thus, as explained, the server 2 comprises at least data processing means 21 and a memory 22. This is typically an authentication server for the immersive space.

[0126] The data processing device 21 is configured to implement the following steps:

[0127] - obtaining, from an authentication device 10 uniquely associated with the user and connected to said server 2, data representing a sequence of rotation gestures performed by the user on said authentication device 10, each rotation gesture being defined by an initial angular position, a final angular position and a direction of rotation;

[0128] - verifying said data representative of said sequence of rotation gestures performed by the user on said authentication device 10 .

[0129] According to a third aspect, the invention proposes a system comprising said server 2 and at least one connected system 1 (via a network 20). Advantageously, said system also comprises said authentication device 10, which is also connected to the first server 2 via the network 20 and, where appropriate, via the user's mobile terminal 3.

[0130] Computer program product

[0131] According to the fourth and fifth aspects, the present invention relates to a computer program product comprising code instructions for executing (on a data processing device 21 of a server 2a) a method for authenticating a user according to the first aspect, and to a storage device readable by a computer device where the computer program product is located (for example, a data storage device 22 of a server 2).

Claims

1. A method for authenticating a user, said method comprising the steps of: (a) obtaining, from an authentication device (10) uniquely associated with the user and connected to the server (2), data representing a sequence of rotation gestures performed by the user on the authentication device (10), each rotation gesture being defined by an initial angular position, a final angular position, and a rotation direction, the authentication device (10) being paired with a mobile terminal (3) of the user, the authentication device being connected to the server (2) via the mobile terminal; (b) verifying the data representing the sequence of rotation gestures performed by the user on the authentication device (10).

2. The method according to claim 1, wherein The verification of step (b) is a comparison of the rotation gesture sequence performed by the user on the authentication device (10) with at least one expected rotation gesture sequence.

3. The method according to claim 2, wherein: Step (a) comprises the sub-step (a2) of issuing an invitation to the user to perform the rotation gesture sequence on the authentication device (10).

4. The method according to any one of claims 1 to 3, wherein The user is a user of a virtual or mixed reality system (1) connected to the server (1) and comprising a display device (12) of an immersive space.

5. The method according to any one of claims 1 to 4, comprising the step (c) of implementing or not implementing the transaction initiated by the user according to the result of step (b).

6. The method according to claim 3 and 5, wherein: Step (a) comprises a sub-step (a1) of receiving a request to authenticate said transaction, in response to which said invitation to perform said sequence of rotation gestures on said authentication device (10) is issued to said user.

7. The method according to any one of claims 1 to 6, wherein The authentication device (10) includes a rotation gesture detection surface (100) selected from a rotation plate and a touch surface.

8. The method according to claim 7, wherein: The rotational gesture detection surface (100) extends circularly around a central element (101).

9. The method according to claim 8, wherein The rotation gesture detection surface (100) has at least one touch mark (102a, 102b), in particular a raised mark.

10. The method according to claim 9, wherein: The rotation gesture detection surface (100) has a plurality of touch marks (102a, 102b) arranged at regular intervals around the central element (101).

11. The method according to claim 10, wherein: The plurality of marks (102a, 102b) consists of a single primary mark (102a) and one or more secondary marks (102b) different from the primary mark (102a).

12. A server (2) for authenticating a user, characterized in that It comprises a data processing device (21), which is configured to: - obtaining, from an authentication device (10) uniquely associated with the user and connected to the server (2), data representing a sequence of rotation gestures performed by the user on the authentication device (10), each rotation gesture being defined by an initial angular position, a final angular position and a rotation direction, the authentication device (10) being paired with a mobile terminal (3) of the user, the authentication device being connected to the server (2) via the mobile terminal; - verifying said data representing said sequence of rotation gestures performed by said user on said authentication device (10).

13. A computer program product comprising code instructions for executing the method for authenticating a user according to any one of claims 1 to 11 when the program is executed on a computer.

14. A storage device readable by a computer device, on which a computer program product is recorded, the computer program product comprising code instructions for executing the method for authenticating a user according to any one of claims 1 to 11.