METHOD FOR PROCESSING DISPLAY DATA, DEVICE AND PROGRAM FOR THIS
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- BANKS & ACQUIRERS INT HLDG SAS
- Filing Date
- 2018-10-11
- Publication Date
- 2026-07-15
AI Technical Summary
Existing touchscreen-based data entry systems, particularly on mobile devices and payment terminals, are vulnerable to security breaches due to malicious applications intercepting sensitive information through screen observation, screenshot analysis, or memory mapping, with existing countermeasures like randomized keyboards being insufficient against sophisticated attacks.
A method involving the intelligent degradation of display images using retinal and screen persistence phenomena, generating multiple degraded images that require sequential perception to discern the original content, making it difficult for attackers to infer the actual data entry information.
The technique provides enhanced security by ensuring that individual degraded images do not reveal the original data layout, requiring multiple frames to discern the input, thus protecting against unauthorized data capture and enhancing security in touchscreen data entry.
Description
1. Domain
[0001] The invention relates to securing data entry. More specifically, the invention relates to a method for masking information displayed on a screen. One object of the invention is indeed to secure the entry of sensitive data on touchscreens. 2. Prior art
[0002] Securely capturing data on modern communication devices is a real challenge. In the case of mobile communication terminals (such as smartphones), most of which are now equipped with touchscreens, user input is made by touching the screen. This information is first processed by the operating system and sent to the appropriate applications. However, many applications handle sensitive data. This is the case, for example, with payment applications.
[0003] The possibility of making a payment using a smartphone or tablet-type communication terminal has been widely documented, particularly since consumer communication terminals have incorporated secure data processing environments (such as secure SIM cards). Among the numerous payment methods that have been disclosed, a substantial proportion use a specific application, installed on the communication terminal, which allows the saving and use of multiple payment cards: the payment card data is entered, or photographed using the communication terminal and saved, at least partially, within the secure environment of the user's communication terminal.When a user wishes to use their communication terminal to make a payment to a merchant, they open the appropriate application on their communication terminal, select the payment card they wish to use and validate the payment: this validation may require the entry of a personal identification code such as a PIN code.
[0004] Similarly, new payment terminals also incorporate touchscreens that can be used to enter confidential data such as personal identification codes (PINs): this is the case, for example, with so-called lightweight payment terminals, installed at a merchant's premises using a tablet. The tablet then acts as both a cash register and a payment terminal, using one or more appropriate applications.
[0005] Other security devices (e.g., securing access to buildings, resources, etc.) also incorporate touch screens on which users must enter passwords or access codes.
[0006] The widespread adoption of this type of screen for data entry has raised a significant security concern: malicious actors have exploited these new data entry devices to obtain confidential information. This is particularly prevalent on communication devices such as smartphones and tablets. Since the primary objective of these devices is to be user-friendly and multimedia-oriented, users have considerable freedom in installing applications. However, many applications contain spyware modules designed to fraudulently obtain information.
[0007] There are many ways an adversary can try to steal this information: by observing the screen remotely; by running a malicious application, such as an invisible window, to relay user input to a legitimate application; by having a malicious application that examines the device's memory or cache and maps the changes obtained to user actions; by using side-channel or hidden-channel analysis (on the device or user) to infer user action.
[0008] This list is by no means exhaustive. Each of these attacks can be successfully carried out on a current communication device.
[0009] A classic and widely documented countermeasure is to randomize the placement of the keyboard keys displayed on the touchscreen. This is the strategy employed by many solutions, with minimal effort. A company called myPinPad™ offered a mixed-signature keyboard so users could enter their personal identification codes (and other confidential data), with potential spyware applications receiving mixed information. However, this is unsatisfactory on several levels. For example, the proposed solution requires substantial infrastructure. Furthermore, it does not protect against all the attacks mentioned above if the adversary can obtain even a single copy of the screen image.Indeed, the major problem with a random keyboard is that it only secures on-screen input if the attacker cannot obtain a copy of that random keyboard. However, obtaining a screenshot is generally not a complex operation and can be performed by a malicious application. Once the screenshot is obtained, the malicious application can once again correctly interpret the user's input.
[0010] It is therefore necessary to have an input solution that resolves these prior art problems and allows for secure data entry on a touchscreen keyboard displayed on a terminal screen. Documents FR3023042 and EP2023333 describe alternative methods in which a large number of incomplete or noisy versions of the keyboard are generated and displayed. 3. Summary
[0011] The proposed technique does not present the drawbacks of the prior art. More specifically, the proposed technique implements a principle of image persistence and / or perception of information when it is displayed on a screen. This phenomenon is used to generate degraded images, which, when viewed, allow the user to guess and / or read the images on the screen. The disclosed technique relates to the intelligent degradation of the image, with the subsequent purpose of displaying the degraded images. The invention, however, is by no means limited to this single subsequent display function, but can also be implemented in other types of processes or fields concerning information security.
[0012] More particularly, the invention relates to a method for processing display data, the method being implemented within an electronic data processing device, said display data being representative of at least one piece of information to be displayed on a screen. The invention is as defined in claim 1.
[0013] Thus, unlike the techniques of the earlier art, information is degraded during the processing of reference images, information which therefore cannot be read subsequently.
[0014] Depending on a particular characteristic, the number of degraded images is greater than or equal to three.
[0015] Thus, a first level of security is achieved since a minimum of three degraded images are needed to hope to obtain an indication of the information present in that image.
[0016] According to a particular characteristic, the number of degraded images is greater than or equal to an image display frequency of the screen on which said degraded images are to be displayed.
[0017] Thus, when displayed, degraded images produce an afterimage effect, either on the display screen or on the retina of the user's eyes viewing said display screen.
[0018] According to a particular characteristic, characterized in that said step of generating at least one degraded image implements at least one degradation procedure among the following functions: extraction of portions of said reference image delivering at least one degraded image; addition of noise to said reference image, delivering at least one degraded image.
[0019] Thus, several degradation methods can be used, alone or in combination, to produce a set of degraded images from the original image, which has the advantage of not allowing an attacker to guess in advance which method will be used.
[0020] According to an unclaimed embodiment, said noise addition function to said reference image, delivering at least one degraded image, comprises, for a plurality of pixels of the reference image, the application of the following expression: D t x y = A thr F T x y in which: A represents an attribution value; D t ( x, y ) represents the pixel with coordinates ( x , y ) of the degraded image D t ; Thr is a thresholding function; F is a contrast function; and T ( x , y ) represents the pixel with coordinates ( x, y ) of the noted reference image T.
[0021] Thus, we perform a degradation of the reference image using the reference pixels as an input to a degradation procedure in order to obtain the pixels of the degraded image.
[0022] According to a particular characteristic, said contrast function is: F x = αx + β 255 α + β + γ in which: α is a degraded image density control parameter; β is a contrast control parameter; and γ is a noise level control parameter.
[0023] Thus, it is possible to adjust the contrast of a degraded image in a parameterized and / or dynamic manner: this allows the rendering of the degraded image to be adapted to the implementation conditions, particularly according to the desired subsequent effect (especially in terms of readability, safety, and screen characteristics). According to claim 1, said noise addition function to said reference image, delivering at least one degraded image, comprises the generation of a predetermined number (K) of degraded images using a degraded image generator implementing, for each pixel (x,y) of the reference image, a processing distinction according to the color of said pixel, said processing distinction comprising: assigning the same random color to the corresponding pixels (x,y) of the (K) degraded images when the color of the pixel (x,y) of the reference image is equal to a predetermined color; assigning a different random color to the corresponding pixels (x,y) of the (K) degraded images when the color of the pixel (x,y) of the reference image is different from the predetermined color.
[0024] Thus, in this embodiment, a set of degraded images is generated in a single pass: such an implementation makes it possible to achieve a certain correlation of the images that make up this set of images and to adjust this correlation in a single pass, which is advantageous from a procedural point of view, because it consumes less memory and / or computing power for the generation of a single image.
[0025] According to a particular embodiment, said process includes at least one iteration of a display step of said at least one degraded image.
[0026] Thus, the successive displays of degraded images make it possible to produce the afterimage effect. When this iterative display of the different degraded images is implemented (each degraded image being displayed once, then a new display iteration is implemented), an afterimage effect is produced, either directly on the screen on which the display is carried out (a screen which is not necessarily that of the electronic device which implements the present technique), or on the retina of the eyes of the user who views this screen.
[0027] According to a particular embodiment, said at least one reference image is representative of a random or pseudo-random keyboard to be displayed.
[0028] Thus, it is possible to generate a "persistent" version of the keyboard to be displayed on the screen of a terminal or device. This "persistent" version of the keyboard consists of a plurality of degraded images which, taken individually, cannot inform an attacker about the actual position of the random keys, and therefore cannot indicate the location of the keys to the attacker. This solves a number of the security problems currently encountered when displaying keyboards on a touch input device.
[0029] According to another aspect, a display data processing device is also described, according to claim 9.
[0030] The degraded images generated can then be displayed, either by the device (if it has display capabilities) or by another device to which the generated images are transmitted (either in advance or as they are generated, depending on the display needs of the device).
[0031] According to a preferred implementation, the various steps of the processes according to the proposed technique are implemented by one or more software or computer programs, comprising software instructions intended to be executed by a data processor of a relay module according to the proposed technique and designed to control the execution of the various steps of the processes.
[0032] Consequently, the proposed technique also aims at a program, capable of being executed by a computer or by a data processor, this program comprising instructions to control the execution of the steps of a process as mentioned above.
[0033] This program can use any programming language, and be in the form of source code, object code, or code somewhere between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0034] The proposed technique also aims for an information support readable by a data processor, and containing instructions from a program as mentioned above.
[0035] The information medium can be any entity or device capable of storing the program. For example, the medium can include a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a floppy disk or a hard disk drive.
[0036] On the other hand, the information medium can be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means. The program, according to the proposed technique, can in particular be downloaded from a network such as the Internet.
[0037] Alternatively, the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the process in question.
[0038] In one embodiment, the proposed technique is implemented using software and / or hardware components. In this context, the term "module" in this document may refer to a software component, a hardware component, or a set of hardware and software components.
[0039] A software component corresponds to one or more computer programs, one or more subroutines of a program, or more generally to any element of a program or software capable of implementing a function or set of functions, as described below for the module in question. Such a software component is executed by a data processor of a physical entity (terminal, server, gateway, router, etc.) and is capable of accessing the hardware resources of that physical entity (memory, storage media, communication buses, input / output cards, user interfaces, etc.).
[0040] Similarly, a hardware component corresponds to any element of a hardware assembly capable of implementing a function or set of functions, as described below for the module in question. This could be a programmable hardware component or one with an integrated processor for software execution, for example, an integrated circuit, a smart card, a memory card, an electronic board for running firmware, etc.
[0041] Each component of the system described above naturally implements its own software modules.
[0042] The different embodiments mentioned above, as well as the different characteristics that constitute them, can be combined with each other for the implementation of the proposed technique. 4. Figures
[0043] Other features and advantages of the invention will become clearer upon reading the following description of a preferred embodiment, given by way of simple illustrative and non-limiting example, and the accompanying drawings, among which: there figure 1 presents a first example of image degradation using a first technique; The figure 2 presents a second example of image degradation using a second technique; The figure 3 describes the implementation of this technique from a general perspective; The figure 4 discloses a communication terminal in a synthetic manner, capable of implementing the disclosed methods. 5. Description 5.1. General principle
[0044] The general principle of this technique is to degrade (or modulate) information before it is displayed on a screen (of a terminal or display device). More specifically, as explained previously, the subsequent perception of the modulated (or degraded) information takes advantage of a physiological phenomenon called "retinal persistence" and / or a physical phenomenon of image persistence on the screen (depending on the characteristics of the display screen). In the example of entering sensitive data, by using this phenomenon and modulating the display (for example, displaying a random keyboard), the user correctly perceives (distinguishes) what is being displayed (i.e.(for example, a random keyboard layout); Conversely, a malicious application only has partial information (frame by frame, for example): this information cannot be used to deduce any information about the layout and / or the information (for example, keyboard keys) displayed on the screen. The proposed technique, however, is not limited to this single case of displaying a random keyboard.
[0045] In a particular case, we assume that the information to be displayed on the screen takes the form of an image, an image which includes, for example, a set of keys from a keyboard. The image can advantageously represent a random keyboard, the order of which is defined according to a predetermined random number: this determination of the random number, and therefore of the order of the keys on the keyboard, can be made at the time of the generation of the keyboard image itself.
[0046] The disclosed technique relates to the intelligent degradation of the image, with the subsequent aim of displaying the degraded images. The invention, however, is by no means limited to this single subsequent display function, but can also be implemented in other types of processes or fields concerning information security.
[0047] As explained later, several different techniques can be used to modulate the display of information on the screen. Among these techniques, several different classes can be distinguished: A first class is based on the iterative display of random portions of the image; at a given moment, a portion of the image is displayed on the screen: this random portion is also defined according to a randomness, which is obtained during the display procedure; at the next moment, another random portion of the image is displayed on the screen; and so on, throughout the display of this screen; a second class is based on the iterative display of full images (i.e. a complete image) each full image being representative of a variation of the original image: at each iteration, a degraded image is displayed on the screen, this degraded image resulting from a processing carried out on the original image, in order to alter it; a third class consists of mixing the two techniques described above.
[0048] These techniques share the following characteristic: the (fixed) display of the original image is replaced by an iterative display of multiple so-called degraded (cropped and / or modified) versions of the original image (reference image). The iterative display is implemented to produce, on the user's retina and / or on the display screen, an afterimage resulting from the superimposition of the multiple degraded versions. This afterimage allows the user to recognize (or distinguish, guess) the original image (and thus perform the necessary input operations, if needed). The afterimage is also called a dynamic image. figure 1This presents the second class of display technique in which a reference image (IRef) is used to produce several degraded images (I1, I2, I3), these degraded images being variations of the original image. None of these degraded images (I1, I2, I3), individually, allows for the recognition of the original image. For illustrative purposes, a dynamic image (IDyn), resulting from the superposition of the three degraded images (I1, I2, I3), is also displayed. The digit 1 of the original image is more clearly visible in this image.
[0049] There figure 2This presents the first class of display technique in which a reference image (IRef) is used to produce several degraded images (I1, I2, I3, I4), these degraded images being a random portion of the original image. None of these degraded images (I1, I2, I3, I4), individually, allows for the recognition of the original image. For illustrative purposes, a dynamic image (IDyn), resulting from the superposition of the four degraded images (I1, I2, I3, I4), is also displayed. In this example of the figure 2The portions of the original image are continuous (to facilitate the construction of the figure). Of course, in a practical implementation, the portions of the original image are randomly obtained according to random parameters. It is therefore entirely possible (and desirable for the robustness of the process) that the image portions (the degraded images I1,..., In) correspond to a subset of pixels from the original image, a subset that is partially or totally non-continuous, corresponding to a random selection of a similarly random number of pixels from the original image.
[0050] According to current standards, data is displayed on a screen at a rate of approximately 30 frames per second. Some devices have higher refresh rates. However, a display is generally considered to be acceptable to the human eye at a rate of 24 frames per second or higher. The afterimage effect on the retina is perceived at this frequency.
[0051] Regardless of the technique used, the general display method, presented in relation to the figure 3 includes the following steps: a step of obtaining (10) a reference image (IRef) representative of at least one piece of information to be displayed; optionally, obtaining (20) at least one degraded image (ID1,..., IDn) as a function of said reference image (IRef) and at least one degradation parameter (PDeg) (also called random parameter); at least one iteration of the following steps: obtaining (30) a degraded image (IDx) (optionally as a function of said reference image (Iref) and at least one degradation parameter (PDeg), when this has not been obtained previously in the iterations or directly from the images obtained in step 20); displaying (40) said degraded image (IDx);
[0052] Depending on the embodiment, the iterations of obtaining degraded images can be implemented concurrently with or prior to the display iterations. In other words, obtaining the degraded images (potentially iteratively) can precede their iterative display.
[0053] In at least one embodiment, the degraded images are obtained probabilistically. More specifically, the degraded images are obtained from the reference image using at least one probabilistic degradation procedure. The advantage of this solution is that, statistically, the phenomenon of retinal persistence allows the user to read, or at least guess, what information is displayed on the screen, and therefore, in the case where the reference image is a random keyboard, where the numbers of this random keyboard are located. It should be noted that the proposed technique is not only applicable to masking a random keyboard, but also to any type of sensitive information that needs to be displayed on a screen and that one does not want to be intercepted by a screenshot, such as one taken by malware.
[0054] The number of degraded images generated also depends on the implementation method, in particular on the computing power of the device implementing the described technique, the display frequency of the screen (from 24Hz to 60Hz) and therefore on the number of images displayed on the screen per second.
[0055] The invention consists of replacing the original static image (reference image) with a dynamic image generated from the static image (the dynamic image being the result of a succession of degraded images): the dynamic image can be likened to a video or at least to a stream. This dynamic image is generated in such a way that users can easily see or infer the content, either through retinal persistence or through physical persistence (due to the persistence of vision of the display screen, for example). At the same time, no degraded image provides sufficient information about the reference image. The origin of this persistence is that images displayed in rapid succession are superimposed, which corresponds to a mathematical average of the preceding images (frames).
[0056] The dynamic image is therefore generated in such a way that the average of successive frames (images) allows the reference image, or an image reasonably close to it, to be perceived (visually). However, malicious computer programs can, most of the time, only capture one frame at a time (i.e., the graphics buffer), corresponding to a single degraded image, or at most a few spaced-out frames (for example, an overhead projector), but nothing close to capturing at the screen's display frequency, i.e., from 24Hz to 60Hz;
[0057] When the technique for obtaining degraded images is probabilistic, it is possible to verify the safety of each generated image before using it. For example, the original image may have been generated using one of the techniques described herein (albeit with an extremely low probability).
[0058] This can be avoided by using an algorithm that can be used by the attacker. For example, in the case of a keyboard, this would be an optical character recognition (OCR) algorithm (or other attack algorithms adapted to the specific situation of the displayed information). Before displaying an image, it is therefore possible to run one of these recognition algorithms and verify that it fails (to recognize one or more characters) before using the generated image. Note that since the attack algorithm (OCR algorithm) usually provides a confidence level (more precise than a simple yes / no), it is possible to combine several of these algorithms to measure security (using, for example, a soft max or an average).
[0059] The proposed solution has the clear advantage of being easily integrated as an additional layer of protection for display and / or data entry on touchscreens. Regarding the problem of entering identification or authentication information (for example, scrambled images as in CATPCHA-type input processes), and the broader problem of authentication on open third-party devices (for example, a random on-screen keyboard), the solution of the invention provides protection against software espionage via a malicious application.
[0060] Another advantage of this technique is that it exploits an intrinsic property of the human eye, and therefore requires no additional hardware or software components for users. In this sense, it is much less technology-dependent than other techniques. 5.2. Description of a first unclaimed embodiment
[0061] A first embodiment of the previously described technique is described, in which, according to a first variant, the reference image T is a greyscale image.
[0062] We consider a reference image T represented as a painting N × M of integers. We use the notation T(x,y) to designate the value of the pixel in position ( x,y) in the image T. We choose the convention that T(x,y)=0 if this pixel is black, and T(x,y)=255 if the pixel is white. This can be adjusted to match the screen's contrast range if necessary.
[0063] The goal is to define the content of at least one degraded image. Dt of identical dimensions (N×M), so that the average of several occurrences (K) images Dt provides an approximation of the reference image T. Note that Dtdepends implicitly on time - in fact, we describe a generator for Dt which is Probabilistic, and will therefore produce a Dt different each time it is called. In this embodiment, arbitrarily, we choose the reference K=32 , but any other number can be chosen, depending on the situation, based for example on the characteristics of the display screen.
[0064] It is also assumed that we have a probabilistic generator Rnd(), which returns a random or pseudo-random number between 0 and 1 using one of the well-known techniques for achieving this. We define the probabilistic generator as follows: thr r ← 1 Rnd < r
[0065] In which 1 A is the indicator on A. In other words, thr(r) returns 1 if Rnd() <r, et 0 sinon. Alors chaque pixel d'une image dégradée Dt est calculé comme : D t x y = 255 thr F T x y
[0066] In which F(x) is a contrast function. The role of the function F is to control the contrast and noise parameters of the image resulting from the superposition of degraded images (called a dynamic image). This function, in this embodiment, is as follows: F x = αx + β 255 α + β + γ
[0067] The parameter α (ramp) controls the density of the resulting image, β (level) controls the contrast and γ (Noise) controls the noise level. These parameters are adjusted to achieve the desired effect. More specifically, they can be obtained, for example, by minimizing the constrained error: Err α β γ = ∑ x , y N , M T x y − 255 32 ∑ t = 1 32 thr F T x y 2 + μ T x y − c 2 expression in which µ is a constant that determines how closely the degraded image resembles the original image (for example, a Lagrange multiplier that determines the strength of the dynamic image constraint as an average of the value c (for example, c=0)). In other words, µis a value that allows for adjustment of the degraded image: µ allows you to know whether you want the degraded image to look more or less like the reference image.
[0068] This optimization problem can be solved using generic methods. In this embodiment, the inventors suggest using the following parameters: α = 1 / 255 , β = 0.3 , γ = 0.1 .
[0069] Note that the values of these parameters can be adjusted using different statistical measures. For example, it is possible to use mutual information, which measures the dependence between two random variables. The objective might be to minimize the mutual information between the random variables used to generate the degraded images and the constant random variable representing the reference image T.
[0070] A non-linear contrast function can also be used to adjust to the screen's Gamma curve, if this proves useful.
[0071] An extension of the technique presented earlier can also be implemented for a color reference image. In this case, each pixel of the reference image T is represented by a color vector, a three-dimensional vector where each dimension represents a color value. The following expression can then be used to calculate the value of each pixel (x,y) of the degraded image: D t x y = T x y thr F T x y
[0072] In this embodiment, whether in the case of color processing or in the case of greyscale processing, the degraded images Dt are generated at a speed that allows them to be displayed at K frames per second.
[0073] In general (color or grayscale), the value of each pixel is defined by the expression: D t x y = A . thr F T x y , in which A represents an allocation value (127, 255, T ( x , y dependent on the implementation context.
[0074] This first embodiment has been described based on a complete modification of the reference image. It is clear, however, that depending on the actual operational conditions of implementation, only one or more parts of the reference image may be used. For example, when the reference image contains portions lacking contextual information (no contextual information, for example, no text), it is perfectly feasible not to modify these parts of the image when generating the degraded images, and to limit the modification, approximately or otherwise, to the portions (or locations) where information is present. This also applies to all other embodiments and variants. 5.3. Description of a second embodiment
[0075] A second embodiment of the previously described technique is outlined, in which a second degraded image generator is used. In this embodiment, an arbitrarily named generator is used. USk(T), which is created from a reference image T,a plurality (K) of degraded images. For the following explanation, the variable K has been arbitrarily limited to the value 3. It is understood, as with the previous embodiment, that this value can be adjusted, particularly according to the display screen parameters, and especially the refresh rate and / or the user's perception of afterglow. As before, the images are assumed to be rectangular and of a predefined size. The pixel with coordinates (0,0) represents the top-left pixel of the image. It is also assumed that the device has means for displaying color, for example, in RGB format. The described technique can, however, easily be implemented in other types of formats, whether color or black and white. In any case, given this RGB format, the color of a pixel is encoded according to the following expression: R + G + B ≪ 8 ≪ 8 with R, G and B respectively being variables between 0 and 255 and the << operator representing the left shift operation of a number of bits (here 8).
[0076] The reasoning behind the implementation of this generator USk(T), and for example Us3(T) (when three degraded images are generated) is that it is called a predetermined number of times per second (for example, eight times per second for Us3(T) to ensure that the afterimage effect is sufficient). Depending on the display frequency, it is also possible to call the generator more frequently. Depending on the embodiment, it is also possible to pre-calculate images from the generator and repeatedly display these images, although this solution is less secure (especially when the display frequency is high and the value of K is low). The generator USk(T) generates color patterns (or grey) randomly uniform. In general, in this embodiment, The procedure for adding noise to the reference image (IRef) includes the generation of a predetermined number (K) of degraded images using a degraded image generator (Usk) implementing, for each pixel (x,y) of the reference image, a processing distinction based on the pixel's color, the processing distinction comprising: assigning the same random color to the corresponding pixels (x,y) of the (K) degraded images when the color of the pixel (x,y) of the reference image is equal to a predetermined color; assigning a different random color to the corresponding pixels (x,y) of the (K) degraded images when the color of the pixel (x,y) of the reference image is different from the predetermined color. 5.3.1. First variant (saturated image)
[0077] We describe a first variant, in "saturated" mode. This mode is easy to implement and consumes up to 4 bits of random character per image, which is low. This mode is therefore well suited to devices that do not have extensive processing capabilities. In this variant, a function called random.choice, which selects one item uniformly at random from the provided collection.
[0078] This mode only generates fully saturated colors, meaning it does not use intermediate tones; other variants take advantage of this additional freedom, such as a second one presented later. US3(T):
[0079] 1. Create 3 frames F0, ..., F2 of the same dimensions as T. 2. Let c[0] = 0, c[1] = 1, c[2] = 2. 3. For each position (x,y) in T: a. Let k = random.choice(0, 1, 2) b. if T(x,y) is black i. let c = 2 8< << 8 k< ii. let F0(x,y) = F1(x,y) = F2(x,y) = c c. otherwise i. swap (c[0], c[k]) ii. k' = random.choice(0, 1) iii. swap (c[1], c[k'+1]) iv. for each j = {0, 1, 2}, update Fj(x,y) = 2 8< << 8 c[j]< . 5.3.2. Second variant (softer image)
[0080] This next variant uses more of the visual spectrum, but consumes up to 72 random bits per pixel. It is therefore not necessarily suitable for devices with limited processing power. US3(T):
[0081] 1. Create 3 frames F0, ..., F2 of the same dimensions as T. 2. Let c[0] = 0, c[1] = 1, c[2] = 2. 3. For each position (x,y) in T: a. if img(x,y) is black: i. either uR = random.choice(0, ..., 127) ii. either uG = random.choice(0, ..., 127) iii. either uB = random.choice(0, ..., 127) iv. either c = uR + (uG + (uB << 8) << 8) v. update F0(x,y) = F1(x,y) = F2(x,y) = c b. otherwise i. for each j in {0, 1, 2} 1. let uR = random.choice(0, ..., 255) 2. let uG = random.choice(0, ..., 255) 3. let uB = random.choice(0, ..., 255) 4. c = uR + (uG + (uB << 8) << 8) 5. update F j (x,y) = c. 5.3.3. Operating Principle
[0082] In both of the preceding variants, the underlying principle is that of correlation. Successive frames with low correlation move closer together, resulting in a light gray (which encodes white values in T). Successive frames with high correlation reinforce each other, producing a stronger shade (which encodes black values in T). In any case, at the end of this implementation, three images are generated and can be displayed one after the other. The algorithm is then executed again to generate three new degraded images. 5.4. Other variations
[0083] Variations of the previously described embodiments are described here. One objective of the embodiments and variants presented above was to enable a human reader to read an image, while making this impossible for a computer. In certain applications, such as random keypads, it is possible to reduce the level of readability, allowing only the displayed numbers to be distinguished. It may be desirable for the user to distinguish the number written on each key, while making this task impossible for the computer. Thus, it is possible not to add uniformly random noise to the image, but rather to add random noise generated from one or more previously obtained degraded images and / or the reference image (or other reference images when multiple reference images are used).
[0084] A first variant of the first embodiment, allowing only the distinction of numbers in an image, includes the substitution in the previously defined function F (for reference F x = αx + β 255 α + β + γ ), the constant γ by a function γ ( x ), in which x is the position of the pixel.
[0085] With this modification, the darker the pixel is across all images different from the one we are blurring, the greater the probability of its appearance. For example, for three images T _1, T _2, T _3, the noise T _1 could be a linear function of ( T _2 + T _3) or, more generally, a ( T _2, T _3), which can, for example, be an increasing function with respect to both variables, to increase the safety of the method. In practice, in order to maximize the safety of the method, the function of (T _2, T_ 3) is increasing on both variables.
[0086] A second variant of the second embodiment, allowing the distinction of numbers in an image, simply involves replacing the random function (called, for memory random.choice ), so that this function can take into account previous images and is no longer a uniform function. To do this, the previously described algorithm (Usk(T)) takes as arguments, in addition to the reference image, one or more previously obtained images (from one or more previous iterations of the algorithm) and / or one or more images provided elsewhere. The function random.choice can, in turn, take as arguments the (x,y) coordinates of points belonging to these previous images. Generally speaking (both for this variant and for the previously described embodiment), the function random.choicecan be chosen from a wide variety of functions. A constraint can be added stating that the pixel obtained at the end by the function is on average sufficiently close to the corresponding pixels of the other images.
[0087] Mutual information, in the case of using groups of images (as in the two previous variants), can, in another variant, be used more effectively by measuring the mutual information of all pairs of images (by measuring the correlation of the random variables representing each image). All of these measures (the random variables of the images) can then be combined into a single measure that we wish to minimize.
[0088] For example, if we want to measure the security level of three images produced successively (by any of the methods previously presented), we use the mutual information between two pairs of images in the image group. Suppose we have three images 1, 2, and 3. We denote I ( X, Y The mutual information between two images (X and Y) is calculated as follows. I (0.1), I (0.2), I (1,2). We then proceed to combine this information, for example by performing the following calculations: I_ 0 = min ( I (0.1), I (0,2)), I _1 = min ( I (1.0), I (1,2)), and I _2 = min (1(2,0),1(2,1)). Each of these quantities I _ iprovides information regarding the difficulty of determining whether the image is correlated with (derived from) image i. To achieve this result, it is necessary to have a random variable representing the current image that is far removed from the random variable representing the images being compared. Then, the following calculation is performed. max ( I_ 0, I_ 1 , I_ 2), which allows us to determine if the generated images are sufficiently secure (i.e., it is not possible to guess that a degraded image is derived from another image, that it is itself degraded, or that it is a reference image). 5.5. Other features and benefits
[0089] We describe, in relation to the figure 4 , a terminal implemented to manage the production, from a reference image representative of information to be displayed on the screen, of a plurality of degraded images.
[0090] For example, the terminal includes a memory 41 comprising, for example, a buffer memory, a general processing processor 42, equipped, for example, with a microprocessor, and controlled by a computer program 43, and / or a secure memory 44, a secure processing processor 45, controlled by a computer program 46, these processing units implementing data processing methods as described above to effect the transformation of a reference image into a plurality of degraded images according to at least one degradation parameter (also called a random parameter).
[0091] At initialization, the code instructions of computer program 46 are, for example, loaded into memory before being executed by the secure processing unit 45. The processing unit 45 receives as input at least one data point representing information to be displayed on the screen. The secure processing unit 45 implements the steps of the process, notably to obtain a reference image: this reference image can be generated directly by the secure processor or downloaded from secure memory; then to generate, from the reference image, at least one degraded image and optionally, to control the iterative display of the degraded images, according to the instructions of computer program 46, to obtain a persistence effect of the information from the reference image, either directly (via the display screen) or indirectly (via the user's retina).For this purpose, the terminal includes, in addition to memory 44, means of communication, such as network communication modules, means of data transmission and data transmission circuits between the various components of the terminal.
[0092] The terminal (or the device implementing the techniques described) also has all the necessary means to implement the methods, embodiments and variants described above.
[0093] The means described above may take the form of a specific processor implemented within a specific device embedded in the terminal. In one particular embodiment, the terminal implements a specific application responsible for performing the operations described above. This application may be provided, for example, by the processor manufacturer to enable its use. To this end, the processor includes unique identification means. These unique identification means ensure the processor's authenticity.
Claims
1. Method for processing display data, the method being implemented by an electronic data processing device, said display data representing at least one piece of information to be displayed on a screen, the method comprising: - a step (10) for obtaining at least one reference image (Ref) representing said at least one piece of information to be displayed; - a step (20, 30) for generating at least one altered image ((ID1,..., IDn) from said reference image (IRef) and from at least one alteration parameter (PDeg), characterized in that said generating step implements at least one procedure for adding noise to said reference image (IRef), comprising the generation of a pre-determined number (K) of altered images by means of a altered image generator which, for each pixel (x, y) of the reference image, carries out a processing distinction according to the color of said pixel, said processing distinction comprising: - the assigning of a same given random color for the corresponding pixels (x, y) of the (K) altered images when the color of the pixel (x, y) of the reference image is equal to a pre-determined color; - the assigning of a different random color for the corresponding pixels (x, y) of the (K) altered images when the color of the pixel (x, y) of the reference image is different from the pre-determined color.
2. Method according to claim 1, characterized in that the number of altered images (ID1, ..., IDn) is greater than or equal to three.
3. Method according to claim 1, characterized in that the number of altered images (ID1, ..., IDn) is greater than or equal to a frequency of display of the image of the screen on which said altered images must be displayed.
4. Method according to claim 1, characterized in that step (20, 30) for generating at least one altered image ((ID1, ..., IDn) delivers a procedure for extracting portions of said reference image (IRef) delivering at least one altered image.
5. Method according to claim 1, characterized in that said function of adding noise to said reference image (IRef) delivering at least one altered image comprises, for a plurality of pixels of the reference image, the application of the following expression: D t x y = A thr F T x y wherein: A represents a value of assigning; Dt(x, y) represents the pixel having co-ordinates (x, y) of the altered image Dt; Thr is a thresholding function; F is a contrast function; and T(x, y) r represents the pixel having co-ordinates (x, y) of the reference image denoted T.
6. Method according to claim 5, characterized in that said contrast function is: F x = αx + β 255 α + β + γ wherein: α is a parameter of control of density of the altered image; β is a contrast control parameter; and γ is a noise-level control parameter.
7. Method according to claim 1, characterized in that it comprises at least one iteration of a step (40) of display of said at least one altered image.
8. Method according to claim 1, characterized in that said at least one reference image (IRef) represents a random keypad to be displayed.
9. Device for processing of display data, said display data representing at least one piece of information to be displayed on a screen, device comprising: - means (10) for obtaining a reference image (Ref) representing said at least one piece of information to be displayed; - means (20, 30) for generating at least one altered image (ID1, ..., IDn) from said reference image (IRef) and from at least one alteration parameter (PDeg); characterized in that these means implement at least one procedure for adding noise to said reference image (IRef), comprising the generation of a pre-determined number (K) of altered images by means of a altered image generator which, for each pixel (x, y) of the reference image, carries out a processing distinction according to the color of said pixel, said processing distinction comprising: - the assigning of a same given random color for the corresponding pixels (x, y) of the (K) altered images when the color of the pixel (x, y) of the reference image is equal to a pre-determined color; - the assigning of a different random color for the corresponding pixels (x, y) of the (K) altered images when the color of the pixel (x, y) of the reference image is different from the pre-determined color.
10. Computer program product downloadable from a communications network and / or stored on a computer-readable medium and / or executable by a microprocessor, characterized in that it comprises program code instructions for the execution of a method of processing according to claim 1 when it is executed on a computer.