SECURE CONNECTION METHOD OF A WRISTWATCH TO A REMOTE SERVER
Patent Information
- Application Number
- DE602019075445
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2019-12-06
- Publication Date
- 2025-09-10
- Estimated Expiration
- 2039-12-06
AI Technical Summary
Existing methods for securely connecting a watch to a remote server face security vulnerabilities due to the storage of authentication elements in unprotected environments, such as paper or digital files, which can lead to unauthorized access.
A method and system that uses a connected mechanical watch with a hybrid display to securely connect to a remote server through a graphical representation of identification elements, where the user selects a sequence of identification portions within a limited time interval, validated against a reference sequence, ensuring secure authentication without direct entry of authentication codes.
Enables secure and reliable authentication of the watch user, preventing unauthorized access by requiring a timed sequence of graphical selections, thus enhancing security and reliability in connecting to remote servers.
Description
Technical field
[0001] The present invention relates to a method for securely connecting a watch to a remote server and a system implementing such a method.
[0002] The invention also relates to a computer program. Prior art
[0003] A watch includes a set of functions that can be used by the wearer. Such functions can allow access to remote servers implementing services such as banking services, commercial services (online stores, e-commerce companies), email services or instant messaging services. In such a context, the wearer of the watch must manage and store an increasing number of identifiers, passwords and access codes which are authentication elements. Such authentication elements are often worn by the wearer when he or she must initiate a connection to a remote server to benefit from a service.To do this, it is common for the holder, failing to memorize all this confidential data, to prefer to group them together on paper or in a standard computer file such as a spreadsheet archived on media allowing the storage of digital data, whether hard drives, flash memory, a USB key, etc. This situation has the disadvantage that the documents / files containing these authentication elements can be stored in a poorly or unprotected environment. This introduces a significant security flaw in the management of authentication elements. Documents US 2015 / 242605 A1 and US 2018 / 019994 disclose authentication processes on portable devices (watches, smartphones), using biometric and non-biometric sensors to continuously verify the user's identity.
[0004] Under these conditions, it is understood that there is a need to find an alternative solution, in particular one which does not have the drawbacks of the prior art. Summary of the invention
[0005] An aim of the present invention is therefore to propose a method for securely connecting a watch to a remote server which is reliable and robust.
[0006] For this purpose, the method for securely connecting a watch to a remote server of a service provider according to claim 1.
[0007] In other embodiments: the transmission step comprises a sub-step of selecting the authentication element relating to said selected function in anticipation of its sending to the remote server, from among authentication elements archived in the memory elements of the processing unit of the watch; the step of carrying out an authentication comprises a sub-step of comparing the authentication element received from the watch and a reference authentication element archived in the server; the identification step comprises a sub-step of presenting a graphical representation on an interface for broadcasting visual information of said watch; the presentation sub-step comprises a phase of generating the display of the graphical representation on the interface for broadcasting visual information; the presentation sub-step comprises a phase of triggering a countdown as soon as the generation phase is carried out;the identification step comprises a sub-step of selecting, within a limited time interval, a sequence of at least two identification portions included in said graphic representation aimed at identifying said wearer, said sequence corresponding to an identification code of the wearer; the identification step comprises a sub-step of validating the selected sequence; the validation sub-step comprises a phase of checking that the selection of the sequence of identification portions has been carried out within the limited time interval defined by a countdown.;
[0008] The invention also relates to a system for securely connecting a watch to a remote server implementing this method, the watch comprising the following elements connected together: a processing unit, an input interface, an interface for broadcasting visual information and a wireless communication interface for exchanging data with said remote server.
[0009] The invention also relates to a computer program comprising program code instructions for executing the steps of the method when said program is executed by the processing units of the watch and of a remote server in connection with said watch. Brief description of the figures
[0010] Other features and advantages will become clear from the description given below, for information purposes only and in no way limiting, with reference to the appended figures, in which: there figure 1is a schematic representation of a system for securely connecting a watch to a remote server, according to one embodiment of the invention, and the figure 2 is a flowchart relating to a method of securely connecting the watch to the remote server, according to the embodiment of the invention. Detailed description of the invention
[0011] On the figure 1 A system 1 for securely connecting a watch to a remote server 200 is shown. In this system 1, the watch 100 is preferably a connected mechanical watch 100 with a hybrid display. In this context, the watch 100 comprises a body such as a watch case, and a fastening element such as a bracelet making it possible to fix this body, for example, to the wearer's wrist. This watch 100 more precisely comprises, in a non-limiting and / or non-exhaustive manner: a processing unit 2 comprising hardware and software resources, in particular at least one processor cooperating with memory elements 6; an interface for broadcasting visual information 3 such as a hybrid display dial provided with a first analog display component and a second digital and / or alphanumeric display component; an interface for broadcasting sound information 4 such as a loudspeaker; a wireless communication interface 5 (for example cellular, WLAN Bluetooth, etc.), and an input interface 34 such as a keyboard or a touch interface included for example in the interface for broadcasting visual information 3.
[0012] In this watch 100, the processing unit 2 is connected, among other things, to the interfaces for broadcasting visual and sound information 3, 4, to the input interface 34 and the wireless communication interface 5.
[0013] In this system 1, the server 200 comprises a processing unit 210 and a communication interface 220. This server 200 is a remote server of a service provider, for example a server of a provider of banking services or commercial services (online stores, e-commerce companies), electronic messaging services or instant messaging. In this context, the processing unit 210 of this server 200 comprises memory elements comprising a reference authentication element 32. This reference authentication element 32 is capable of participating in the creation of a secure connection between the remote server 200 and said watch 100 and may comprise keys, certificates, authentication codes, passwords and personal codes, etc.
[0014] In this watch, the memory elements 6 of the processing unit 2 of the watch 100 comprise data relating to authentication elements 9 specific to each remote server 200 to which the watch 100 is required to connect. In other words, these authentication elements 9 are specific to the wearer and / or to the watch 100, and thus allow the wearer to connect to the server 200 that he desires by means of a selection of a function of the watch 100.
[0015] These memory elements 6 of the processing unit 2 also comprise at least one graphic representation 7 making it possible to identify the wearer as will be seen later. This graphic representation 7 may for example be an image comprising at least one object. For example, this image defines a scene comprising a plurality of objects such as dwellings, vehicles and / or a star such as the moon, etc. It is obviously understood that this image may define other types of scene comprising at least one object. These memory elements 6 also comprise data relating to a reference sequence 8 comprising reference identification portions of this graphic representation 7, said portions having been previously selected by the wearer of the watch 100 during a configuration process relating to the identification of the wearer.
[0016] The system 1 is capable of implementing a method of secure connection to the remote server 200 of a service provider, represented in the figure 2 Such a server 200 of a service provider may be, for example, a server of a provider of banking services or commercial services (online stores, e-commerce companies), electronic messaging services or instant messaging.
[0017] This method comprises a step 10 of authentication of the wearer of the watch 100 authorizing access to the use of functions of this watch 100. This authentication step 10 therefore makes it possible to identify with certainty the wearer of the watch so that he can have access to the use of all the functions of this watch 100. In other words, it allows the wearer to provide proof of his identity by providing for the entry of an authentication code or a secret code by means of an interaction between the wearer and the entry interface 34.
[0018] In addition, it is understood that the functions can be implemented by computer programs executed by the processing unit 2 of the watch 100 as soon as these programs are activated / selected following an interaction between the wearer and the input interface 34 of this watch 100. These computer programs thus executed allow the wearer to benefit from services, for example of the banking, commercial or instant messaging or electronic type.
[0019] Following this authentication step 10, the method comprises a step 11 of selecting one of said functions from the input interface 34 of said watch 100 aimed at establishing a connection between said watch 100 and the remote server 200. It is understood that the functions can be implemented by computer programs executed by the processing unit 2 of the watch 100 as soon as these functions which are displayed on / in the interface for broadcasting visual information 3, are activated / selected following an interaction between the wearer and the input interface 34 of this watch 100. These computer programs thus executed allow the wearer to benefit from services for example of the banking, commercial or instant messaging or electronic type.
[0020] The method then comprises a step 12 of identifying the wearer of the watch 100 from an interaction between the wearer of this watch and a graphic representation included in said watch 100, more particularly a graphic representation displayed on / in the interface for broadcasting visual information 3 of said watch 100. Such a step 12, according to the claimed invention, is carried out systematically following the selection of a function in order in particular to allow the processing unit 2 to check that the wearer of the watch 100 is still in possession of the latter and that he is indeed the originator of the selection of the function. This step 12 comprises a sub-step 13 of presenting a graphic representation 7 on / in the interface for broadcasting visual information 3 of said watch 100.This sub-step 13 comprises a phase 14 of generating the display, on / in the interface for broadcasting visual information 3, of the graphic representation 7 provided for the implementation of this identification. This phase 14 may comprise a sub-phase of selection by the wearer from a sample of at least two graphic representations 7 displayed on the interface for broadcasting visual information 3, of the graphic representation 7 provided for the implementation of this identification. It will be noted that the wearer is the only one to know the graphic representation 7 that he has chosen during a configuration process relating to this identification.
[0021] This presentation sub-step 13 then comprises a triggering phase 15 of a countdown as soon as the generation phase 14 is carried out. In other words, the preconfigurable countdown is triggered once the graphic representation 7 is presented on the broadcast interface 3. Such a phase 15 participates, from a limited time interval defined by this countdown, in counting down the estimated time necessary for entering the sequence of identification portions of the graphic representation 7 displayed on / in the broadcast interface 3.
[0022] Subsequently, the identification step 12 comprises a sub-step 16 of selection in the limited time interval of a sequence of at least two identification portions of said graphic representation 7 aimed at identifying said carrier, said sequence corresponding to an identification code of the carrier. Such identification portions are not directly visible in the graphic representation 7 presented on / in the broadcast interface 3. Under these conditions, the selection sub-step 16 comprises a phase 17 of visualization of at least one of said identification portions of the sequence in said graphic representation 7. This visualization phase 17 comprises a sub-phase of selection of at least one area of interest of the graphic representation 7 likely to comprise said at least one identification portion.During this sub-phase, the wearer selects for example a first area of interest or a second area of interest by enlarging this first area or this second area from the input interface 35. Once this first or second area of interest has been selected, the identification portions then become visible. In this configuration, each identification portion useful for the production / constitution of the sequence can be selected from the input interface 35.
[0023] It should be noted that the sequence comprises an ordered number of identification portions and that the selected area of interest may comprise, for example, three identification portions of which only two are ordered successively one after the other in the sequence. In this context, the remaining identification portion requires, in order to be part of the sequence, the selection of an identification portion included in another area of interest of the graphical representation 7.
[0024] Then, the identification step 12 comprises a validation sub-step 18 of the selected sequence. This validation sub-step 18 comprises a control phase 19 to ensure that the selection of the sequence of identification portions has been carried out within the limited time interval defined by the countdown. To the extent that this selection has not been carried out within the limited time interval, the validation sub-step 18 comprises a renewal phase 20 of the presentation 13 and selection 16 sub-steps. If subsequently, the selection of the sequence has again not been carried out within the limited time interval, the establishment of the connection to the remote server is suspended or even deleted. In addition, access to the watch 100 is also deleted and in particular access to the functions of this watch 100.In this context, the wearer of the watch is invited to authenticate himself again in order to provide proof of his identity by entering an authentication code or a secret code, through an interaction between the wearer and the input interface 34.
[0025] To the extent that this selection has been made in this limited time interval, the validation sub-step 18 then comprises a comparison phase 21, implemented by the processing unit 2, between said selected sequence and the reference sequence 8. This comparison phase 21 comprises a sub-phase of rejecting the identification of the wearer if said sequence is substantially different or different from the reference sequence 8. In this case, the establishment of the connection to the remote server is suspended or even deleted. In addition, access to the watch 100 is also deleted and in particular access to the functions of this watch 100. In this context, the wearer of the watch is invited to authenticate himself again in order to provide proof of his identity by entering an authentication code or a secret code, and this, by means of an interaction between the wearer and the input interface 34.Indeed, the wearer and owner of the 100 watch may no longer be in possession of it.
[0026] Conversely, the comparison phase 21 also comprises a sub-phase of successfully identifying the bearer if said sequence is substantially similar or similar to the reference sequence 8. In this case, the method then provides for the implementation of a transmission step 22 to said remote server 200 of the authentication element relating to the selected function as soon as the bearer is identified, said authentication element being specifically defined to participate in an authentication of the bearer with the remote server 200. This step 22 comprises a selection sub-step 23 of the authentication element relating to said selected function in anticipation of its sending to the remote server 200.During this sub-step 23, the selected function is identified, and on the basis of this identification a selection of the authentication element is made from among the authentication elements archived in the memory elements 6 of the processing unit 2 of the watch 100. As we have already mentioned previously, the authentication elements 9 can be keys, certificates, authentication codes, passwords and personal codes which are each dedicated to the authentication of the wearer of the watch 200 with the corresponding service provider and therefore with the remote server included in a technical platform of this provider. It is understood here that the authentication element is dedicated to an authentication of the wearer with a remote server of a given service provider.In addition, the authentication elements are archived in the memory elements 6 of the processing unit 2 of the watch 100, each being associated with a digital identification element of a corresponding function.
[0027] The method then comprises a step of performing an authentication 24 of the wearer by the remote server 200 from said authentication element in order to authorize an exchange of data between the watch 100 and this remote server 200. In this context, it is understood that this exchange of data which is authorized here corresponds to the data exchanged between the watch 100 and the server 200 within the framework of the service provision from which the wearer can benefit as soon as he is authenticated with the remote server 200 and therefore with the service provider. Such a step 24 comprises a comparison sub-step 25, performed by the processing unit 210 of the server 200, between the authentication element received from the watch and a reference authentication element 32 archived in the server 200.This comparison sub-step 25 includes a phase of rejecting the identification of the bearer 22 if the authentication element is significantly different or different from the reference authentication element 32. In this case, the establishment of the connection to the remote server 200 is suspended or even deleted.
[0028] The comparison sub-step 25 also includes a phase of successfully identifying the wearer if the authentication element is substantially similar or similar to the reference authentication element 32. In this context, an exchange of data between the watch 100 and this remote server 200 in connection with the provision of service is then authorized.
[0029] Thus, the invention allows the wearer and owner of the watch 200 to be able to be authenticated with all the remote servers of the service providers on the sole basis of his identification from an interaction between the wearer of this watch and a graphic representation included in said watch 100 and this, without having to directly enter the authentication element specific to each of these servers 200 in order to be able to authenticate himself with the corresponding service provider.
Claims
1. A method for securely connecting a watch (100) to a remote server (200) of a service provider comprising the following steps: - authenticating (10) the wearer of the watch (100) to enable access to the use of the functions of the watch (100), and - selecting (11) one of said functions from an input interface on said watch to establish a connection between said watch (100) and the remote server (200); - identifying (12) the wearer of the watch (100) based on an interaction between the wearer of this watch and a graphical representation comprised in said watch (100); - transmitting (22) to said remote server (200) an authentication element relating to the selected function once the wearer has been identified, and - authenticating (24) the wearer by the remote server (200) using the authentication element in order to authorise an exchange of data between the watch (100) and this remote server (200), characterised in that said identification step (12) is carried out systematically after the selection of a function and comprises a sub-step (13) involving the presentation, on / in the transmission interface, of a graphical representation (7) of an item of visual information 3 from said watch (100), this sub-step (13) comprising a phase (14) involving the generation of the display, on / in the transmission interface, of an item of visual information (3) from the graphical representation 7 provided for the implementation of this identification, this phase (14) comprising a sub-phase in which a wearer of the watch selects, from a sample of at least two graphical representations (7) displayed on the transmission interface, the graphical representation (7) provided for the implementation of this identification, said wearer being the only one to know the graphical representation (7) he chose in a configuration process relating to this identification.
2. The method according to the preceding claim, characterised in that the transmission step (22) comprises a sub-step (23) in which the authentication element relating to said selected function is selected from among authentication elements stored in the memory elements (6) of the processing unit (2) of the watch (100), in anticipation of its being sent to the remote server (200).
3. The method according to any of the preceding claims, characterised in that the authentication step (24) comprises a sub-step (25) in which the authentication element received from the watch (100) is compared with a reference authentication element (32) stored in the server 200.
4. The method according to any of the preceding claims, characterised in that the identification step (12) comprises a sub-step (13) in which a graphical representation (7) of an item of visual information (3) from said watch (100) is presented on a transmission interface.
5. The method according to the preceding claim, characterised in that the presentation sub-step (13) comprises a phase (14) in which the graphical representation (7) of the visual item of information (3) is generated for display on the transmission interface.
6. The method according to the preceding claim, characterised in that the presentation sub-step (13) comprises a phase (15) in which a countdown is triggered when the generation phase (14) has been completed.
7. The method according to the preceding claim, characterised in that the identification step (12) comprises a sub-step (16) involving the selection, within a limited time frame, of a sequence of at least two identification portions comprised in said graphical representation (7) for identifying said wearer, said sequence corresponding to an identification code of the wearer.
8. The method according to the preceding claim, characterised in that the identification step (12) comprises a sub-step (18) in which the selected sequence is validated.
9. The method according to the preceding claim, characterised in that the validation sub-step (18) comprises a phase (19) in which the selection of the sequence of identification portions is checked to ensure that it has been carried out within the limited time frame defined by a countdown.
10. A system (1) for securely connecting a watch (100) to a remote server using the method according to any of the preceding claims, the watch (100) comprising the following interconnected elements: a processing unit (2), an input interface (34), an interface (3) for the transmission of visual information, and a wireless communication interface for exchanging data with said remote server (200).
11. A computer program comprising program coding instructions for carrying out the steps (10 to 25) of the method according to any of claims 1 to 9 when said program is executed by the processing units (2) in the watch (100) and by a remote server (200) connected with said watch (100).