Strong authentication method and device
Patent Information
- Application Number
- EP2023790045
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-10-13
- Filing Date
- 2023-09-19
- Publication Date
- 2025-08-20
AI Technical Summary
There is a need for a strong user authentication method in virtual reality environments that provides high security without disrupting the immersive experience, allowing users to authenticate without leaving the virtual world or removing their VR headset.
A method that combines biometric and knowledge factors using a VR headset, where a user's hand is detected, and virtual authentication objects are projected onto their hand in the virtual space, allowing interaction movements to verify a secret sequence, ensuring secure authentication without leaving the immersive environment.
This solution provides strong, seamless authentication with a high level of security, capturing two authentication factors with a single user action, enhancing the immersive experience while utilizing existing VR equipment, ensuring privacy and security.
Smart Images

Figure 1.1
Abstract
Description
[0001] DESCRIPTION
[0002] TITLE: Strong authentication method and device
[0003] Technical field
[0004] This description relates to the general field of virtual or augmented reality, and more particularly concerns a method of authenticating a user wearing an immersion device in a virtual environment, called hereinafter "virtual reality headset", "VR headset" (VR, for "Virtual Reality") or more generically "immersion device".
[0005] More specifically, it concerns a strong authentication method and device applicable during the restitution of audiovisual content in a virtual space by means of such a device.
[0006] Technical background
[0007] In the case of a virtual reality environment, virtual audiovisual content is digitally created and represented in a virtual space, which is usually three-dimensional. In the case of augmented reality, also called hybrid or mixed reality, virtual content (sounds, images, graphics, GPS positioning information, etc.) is mixed in the virtual space with real content resulting from a capture of the real world, for example by means of a camera. The feeling of immersion in the virtual space is usually enhanced by a stereoscopic or three-dimensional reproduction of the video component and by the spatialization of the audio component of the audiovisual content.
[0008] There is a need for a strong user authentication solution applicable in a virtual environment, allowing a high level of security, a seamless immersive experience ("frictionless"), in particular which does not require the user to leave the virtual world, to interrupt the reproduction of audiovisual content by the headset or to remove their VR headset.
[0009] Summary
[0010] The scope of protection is defined by the claims.
[0011] According to a first aspect, the present description relates to a method for authenticating a user carrying an immersion device in a virtual space. The method comprises
[0012] - detection of a first hand of the user placed in front of a camera of the immersion device;
[0013] - a display of a representation of the user's first hand in the virtual space while the first hand is detected; - a display of at least one virtual authentication object projected onto the representation of the first hand in the virtual space;
[0014] - detection of interaction movements made by the user in the virtual space with said at least one virtual authentication object while said at least one virtual authentication object is displayed in projection on the representation of the first hand in the virtual space;
[0015] - obtaining a user authentication decision taken on the basis of at least two authentication factors including a first biometric factor verified from a biometric fingerprint acquired by the immersion device for the first hand while the first hand is detected and a second knowledge factor verified by comparing the detected interaction movements with a temporal succession of secret interaction movements known to the user.
[0016] According to one or more embodiments, the representation of the first hand is a representation of the palm of the first hand.
[0017] According to one or more embodiments, the representation of the first hand is displayed at a position in the virtual space corresponding to the position of the first hand in the real space where the user is located while the interaction movements are performed; the representation of the first hand in the virtual space as well as said at least one virtual authentication object projected onto the representation of the first hand follow a possible movement of the first hand in the real space.
[0018] According to one or more embodiments, the representation of the user's first hand in the virtual space is obtained from at least one image of the user's first hand acquired by a camera of the immersion device.
[0019] According to one or more embodiments, the display of said at least one virtual authentication object in projection onto the representation of the first hand is carried out so that, when the user performs the interaction movements with said at least one virtual authentication object, physical contact with the first hand occurs.
[0020] According to one or more embodiments, the detection of interaction movements includes detecting movements made with the user's second hand detected by the immersion device and represented in the virtual space at the same time as the first hand. Physical contact may occur between the first hand and the second hand when the user performs the interaction movements.
[0021] According to one or more embodiments, the detection of interaction movements comprises the detection of movements made by a virtual interaction object represented in the virtual space. The virtual interaction object may be, for example, a virtual object present in audiovisual content rendered by the immersion device or a virtual object representing a real object manipulated by the user. In the case of a real object manipulated by the user, physical contact may occur between the first hand and the real object when the user performs the interaction movements.
[0022] According to one or more embodiments, the detection of interaction movements comprises detecting movements made in the real world with the first hand of the user such that the representation of the first hand in the virtual space moves relative to a fixed virtual object of interaction present in the virtual space, the representation of the first hand being displayed at a position in the virtual space corresponding to the position of the first hand in the real space where the user is located while the interaction movements are made. The virtual object of interaction can be for example a fixed virtual object in audiovisual content rendered by the immersion device or a virtual object representing a fixed real object. In the case of a fixed real object, physical contact can occur between the first hand and the fixed real object when the user makes the interaction movements.
[0023] According to one or more embodiments, said at least one virtual authentication object comprises a device for entering a secret code corresponding to a temporal sequence of entry actions forming the temporal succession of secret interaction movements known to the user; the detection of interaction movements comprising the detection of entry actions carried out by the user by interaction with the entry device.
[0024] According to one or more embodiments, said at least one virtual authentication object comprises several virtual authentication objects each associated with at least one respective interaction movement, the temporal succession of interaction movements known to the user being a temporal succession of interaction movements each of which is an interaction movement associated with one of the virtual authentication objects. An interaction movement with a virtual authentication object may comprise, for example, at least one movement from among a movement of moving the virtual object, a movement of rotating the virtual object, a movement of selecting the virtual object and a movement of modifying the appearance of the virtual object.
[0025] According to a second aspect, the present description relates to a device comprising means for implementing a method according to the first aspect.
[0026] The means may be software and / or hardware means. The means may comprise, for example, one or more circuits configured to execute one or more or all of the steps of the method according to the first aspect. The means may comprise, for example, at least one processor and at least one memory comprising program instructions configured to, when executed by the processor, cause the device to execute one or more or all of the steps of the method according to the first aspect.
[0027] According to another aspect, the present disclosure relates to a data processor-readable recording medium having recorded thereon a program comprising program instructions configured to cause the data processor to execute one or more or all of the steps of the method according to the first aspect.
[0028] According to another aspect, the present disclosure relates to a computer program comprising program instructions configured to cause a data processor to execute one or more or all of the steps of the method according to the first aspect.
[0029] Brief description of the figures
[0030] Other characteristics and advantages will result from the detailed description which follows, carried out on the basis of embodiments and examples given for illustrative and non-limiting purposes, with reference to the appended figures.
[0031] [Fig.1] schematically represents a virtual reality system according to an exemplary embodiment.
[0032] [Fig.2] is a block diagram of an immersion device according to an exemplary embodiment.
[0033] [Fig.3] is a flowchart illustrating a user enrollment process according to an exemplary embodiment.
[0034] [Fig.4] is a flowchart illustrating a method of authenticating a user according to an exemplary embodiment.
[0035] [Fig.5] illustrates aspects of an authentication method according to an exemplary embodiment.
[0036] [Fig.6] illustrates aspects of an authentication method according to an exemplary embodiment.
[0037] Detailed description
[0038] Various exemplary embodiments will now be described in more detail with reference to the drawings. However, the specific structural and / or functional details disclosed herein are used to enable an understanding of the various possible embodiments. However, those skilled in the art will understand that the exemplary embodiments may undergo various modifications and may be implemented without all of these details.
[0039] The present description relates to a method and device for strong authentication applicable during the restitution of audiovisual content in a virtual space by means of a device for immersion in a virtual space such as a virtual reality headset.
[0040] This strong authentication solution is applicable to all types of virtual reality (VR) systems, including augmented reality (AR), mixed reality (MR) or extended reality (XR) systems. In the context of this document, the term "virtual reality" will cover all virtual reality technologies in the broad sense, including augmented reality, mixed reality or extended reality, as well as variants or technologies derived from these technologies.
[0041] The strong authentication solution described here can be used for various applications and / or transactions requiring authentication (e-commerce, video games, payment, banking management, etc.).
[0042] Strong authentication means authentication based on the verification of at least two authentication factors of different types. There are three types of authentication factors:
[0043] - biometric factors (based on biometric data);
[0044] - knowledge factors (based on secret information known only to the user);
[0045] - ownership factors (based on the use of a user-specific hardware device).
[0046] The strong authentication method described here combines at least two authentication factors of different types including a biometric factor (e.g. palm print) and a knowledge factor based on a secret sequence known to the user (which may be a PIN code, a secret code or a secret sequence of at least one action performed on at least one authentication object represented in the virtual world). The secret sequence is entered by the user by interaction with at least one virtual authentication object represented in the virtual world.
[0047] The authentication method comprises a display of a representation of a first hand of the user in the virtual space, a display of one or more virtual authentication objects in projection onto the representation of the first hand and a detection of the interaction movements carried out by the user in the virtual space with the virtual authentication object(s) while the virtual authentication object(s) are displayed in projection onto the representation of the first hand in the virtual space.
[0048] The user authentication decision is made on the basis of at least two authentication factors: a first biometric factor verified from a biometric fingerprint acquired by the immersion device for the first hand and a second knowledge factor verified by comparison of the detected interaction movements with a temporal succession of secret interaction movements known to the user.
[0049] The authentication process simplifies the user experience, streamlines the validation of transactions requiring authentication, and ensures the security of this validation. The authentication process allows two authentication factors to be captured simultaneously, with a single user action.
[0050] The authentication process enables strong authentication of an individual in the virtual world with a high level of security, an immersive, seamless, and privacy-compliant user experience. The authentication process allows capturing two authentication factors with a single interaction request for a single user action.
[0051] The authentication process enables strong authentication for transaction / payment validation for various immersive applications that rely on virtual reality.
[0052] This strong authentication solution is inexpensive because it is based solely on the equipment and sensors already available in user equipment for rendering virtual reality environments.
[0053] Sensors (cameras, gyroscopes, accelerometers, etc.) can thus be used to capture gestures made by the user. Gesture analysis means (software and / or hardware) can be used to analyze, categorize and / or decompose the captured gestures. These gesture analysis means can be used to analyze and characterize the user's behavior for the purpose of performing behavioral biometric authentication: this allows the consideration of a second biometric factor (in addition to the biometric fingerprint acquired for the hand) and strengthens the level of authentication security.
[0054] Gestures performed by the user may be represented in the virtual space, for example by displaying a representation of the hand or hands performing those gestures or by displaying information representative of the detected gestures.
[0055] The user can thus move around in the three-dimensional virtual universe and interact with virtual objects represented in the audiovisual content using simple gestures, with or without the use of interaction objects from the real world, with or without the use of interaction objects from the virtual world.
[0056] Fig. 1 schematically represents a virtual reality system according to an exemplary embodiment.
[0057] The system includes an immersion device 120 (e.g., VR headset) worn by a user 110. The immersion device 120 includes a display screen 125 (generally, on an inner face of the headset that is placed in front of the user's eyes) allowing the user to view the virtual environment in three dimensions (3D).
[0058] The immersion device 120 is in operational communication with a remote authentication server 140 associated with an authentication database 145. The immersion device 120 may be in communication with a remote content server 160 providing audiovisual content to be rendered by the immersion device 120.
[0059] In one embodiment, communication with a remote server 140 and / or with the remote content server 160 is established via a telecommunications network 150, either directly or through a local device 130, of the personal computer type.
[0060] In one embodiment, the immersion device 120 executes an interaction program implementing an authentication method.
[0061] In one embodiment, the interaction program is downloaded into the immersion device 120 from the remote server 140 and then executed locally by the immersion device 120 to interact with the user and capture behavioral, biometric, and other interaction data necessary for authentication.
[0062] The analysis of the captured data can also be performed locally. For example, the immersion device can locally perform the analysis of the biometric factor by comparing the acquired biometric fingerprint with a reference fingerprint (a reference biometric template). For example, the immersion device can locally perform the comparison of the time sequence of interaction movements with a reference sequence. For security reasons, the reference sequence is not stored in plain text but in encrypted form, for example as a digital digest.
[0063] In one or more embodiments, the verification of the two user authentication factors (biometric + secret sequence) is performed by the authentication server which transmits the authentication decision to the immersion device.
[0064] In one or more embodiments, the verification of the two factors (biometric + secret sequence) is performed locally by the immersion device. If this immersion device is not recognized as a trusted terminal, the risk level is higher than in the case of verification on the authentication server side. To reduce this risk, the authentication server can identify the user's immersion device (on the basis of a possession factor, in addition to the other two user authentication factors) and verify its authenticity. Different authentication procedures for the immersion device are conceivable. For example, the authentication server sends the immersion device a random challenge to be signed each time the user requests authentication.The immersion device signs the challenge and then transmits the signature with the result of the user authentication performed on the basis of the two authentication factors (biometric + secret sequence) to the authentication server. The authentication server verifies the authenticity of the immersion device based on the received data and decides whether or not to validate the result of the user authentication. In this way, the final decision always rests with the server.
[0065] Fig. 2 is a block diagram of an immersion device 200 according to an exemplary embodiment. The immersion device 200 may generally have the architecture of a computer, including components of such an architecture: data memory(s) 250, processor(s) 220, communication bus 270, communication interface(s) 240 for connecting this immersion device 200 to a telecommunications network or other local or remote equipment.
[0066] The immersion device 200 comprises a display screen 210 for the reproduction of images of audiovisual content and loudspeakers 211, 212 for the reproduction of the sound of the audiovisual content.
[0067] The immersion device 200 may comprise different acquisition devices: camera 231, infrared camera 234, depth camera, microphone 232, biometric sensor 235, gyroscope 233, accelerometer 236, etc.
[0068] The camera and / or the infrared camera and / or the gyroscope may for example be used to capture gestures performed by the user. Gesture analysis means (software and / or hardware) may be used to analyze, categorize and / or decompose the captured gestures. For example, the memory 250 may comprise program instructions 260 configured to be executed by the processor and implement gesture analysis functions. These gesture analysis functions may be provided in the form of libraries adapted to the immersion device 200.
[0069] Fig. 3 is a flowchart illustrating a method for enrolling a user according to an exemplary embodiment. This method corresponds to an enrollment phase. The enrollment method can be executed by means of an enrollment program executed by an immersion device 120, 200 described with reference to Fig. 1 or 2, this immersion device being in operational communication with an authentication server 140 as described for example with reference to Fig. 1.
[0070] In certain embodiments, the execution of certain functions (in particular calculation or data storage functions) can be transferred to a local device 130 (of the personal computer type) connected via a local link with the immersion device 120, 200. In this case the immersion device and the local device 130 cooperate for the implementation of the enrollment method.
[0071] In a step 310, the user is asked to create a user account for a given application (video game, e-commerce, payment, etc.). The creation of the user account can be carried out in various ways and typically includes the entry of a username and password. For example, the user enters an email address as a username and a password consisting of a numeric or alphanumeric sequence of their choice.
[0072] In a step 315, the data entered by the user in step 310 are received by the authentication server and then verified. If they comply with security rules, the user's account is effectively created and activated and the user is informed thereof. The identifier and password provided in step 310 are stored in association with an identifier of the user account. The identifier and password may be stored in the authentication database 145. The password may also be stored locally, for example in the immersion device, in encrypted form, usually by means of a digital hash which can be compared with a digital hash of a password subsequently entered by the user.
[0073] In a step 320, the user may be asked to specify one or more payment methods. For example, the user may enter banking data, for example, identification data of a payment card. In this case, the data relating to the payment methods provided are stored in association with the user account data, for example in the authentication database 145. When a payment card has been identified, a payment token (for example, “EMV token”) may be stored to avoid storing the identification data of a payment card.
[0074] In a step 330, the user may be asked to select an authentication method. Each authentication method corresponds to a type of secret sequence that can be used as a knowledge factor. For example, a list of types of secret sequences is proposed and the user can choose one or more depending on the expected degree of security.
[0075] The list of secret sequence types may include:
[0076] - a PIN code or numerical sequence;
[0077] - an alphanumeric sequence;
[0078] - a sequence of symbols or drawings or figures;
[0079] - a temporal sequence of interactions with one or more virtual objects;
[0080] - any other secret sequence that can be memorized and reproduced by the user in a virtual space.
[0081] Alternatively, instead of requiring the user to choose a secret sequence type, a secret sequence type (or authentication method) is selected by the authentication server or an administrator user from among the possible types.
[0082] In a step 340, the user authentication data corresponding to one or more knowledge factors are acquired and recorded for the authentication method(s) (or secret sequence types) selected in step 330.
[0083] The acquisition and recording of authentication data may be performed via the virtual environment, by using a representation of a first hand of the user in the virtual space, by displaying one or more virtual authentication objects in projection onto the representation of the first hand and by detecting interaction movements made by the user in the virtual space with the virtual authentication object(s) while the virtual authentication object(s) are displayed in projection onto the representation of the first hand in the virtual space as illustrated by Figures 6 and 7.
[0084] For example, if the chosen authentication method is based on a secret code (PIN code or alphanumeric sequence), the user is asked to enter this secret code by means of a virtual authentication object corresponding to a code entry device, for example a virtual numeric keyboard 01 or a virtual alphanumeric keyboard 01 represented in the virtual space as illustrated in Figure 5.
[0085] For example, if the chosen authentication method is based on a secret sequence of symbols, the user is asked to enter the secret sequence by means of a virtual authentication object corresponding to a virtual keyboard presenting keys with one symbol per key. The user can choose which symbols are displayed on the keys and / or the number of symbols on the keyboard. The selection of symbols can be carried out by selecting symbols from a predefined set of symbols that is presented to the user or by selecting (for example from virtual or non-virtual video content and / or from images) images or image blocks serving as symbols.
[0086] For example, if the chosen authentication method is based on the reproduction of a temporal sequence of interactions with predefined virtual objects, the user can choose virtual objects present in virtual content and carry out the temporal sequence of interactions with the chosen virtual objects.
[0087] An interaction with a virtual object can be, for example: an action of moving the virtual object, an action of rotating or pivoting the virtual object, an action of selecting the virtual object; an action of modifying the appearance of the virtual object, etc. Each interaction corresponds to an interaction movement that can be detected by analyzing the images acquired by a camera of the immersion device.
[0088] To record the secret reference sequence during enrollment, the user must select one or more secret virtual objects from his virtual environment and define a certain number of actions or combinations of actions on the secret virtual objects 710, 711, 713, 714, for example: rotate the object 710, change the color of the object 711, modify the size of the object 713, move the object 714 to the right, etc., as illustrated in Figure 6. This sequence of actions constitutes his secret reference sequence to be replayed during the authentication phase. In particular, during the authentication phase, the user must select the secret virtual objects selected during enrollment and interact on these objects in order to replay the succession of actions defined during the enrollment phase for the knowledge factor (see step 440 in particular).
[0089] Other embodiments are described with reference to Figs. 4 to 6.
[0090] Regardless of the authentication method chosen, reference authentication data corresponding to a knowledge factor are recorded at the end of step 340. This authentication data includes a description of a secret sequence (secret code or other), serving as a reference.
[0091] This reference authentication data is preferably stored in encrypted form or recorded as a digital hash. For example, the reference authentication data includes:
[0092] - a summary of the entered PIN code,
[0093] - a summary of the positions of virtual authentication objects on the hand;
[0094] - a condensate of the secret reference sequence.
[0095] Each of the interaction movements of the reference sequence can be rated by means of keywords identifying the type of interaction movement among types of interaction movement (selection of the virtual authentication object, translation of the virtual authentication object, rotation of the virtual authentication object, modification of the appearance of the virtual authentication object, etc.) with possible parameters specific to this type of interaction movement. The secret sequence is coded in the form of a list, ordered or not, of the keywords identifying the type of interaction movement.
[0096] Regardless of the authentication method chosen, the secret sequence is defined by a temporal succession of interaction movements with the virtual authentication object(s), this temporal succession of interaction movements having to be reproduced by the user in the virtual space to be authenticated.
[0097] In embodiments, multiple secret reference sequences are recorded and all are required for user authentication.
[0098] In embodiments, multiple secret reference sequences are recorded, but only one is randomly chosen for user authentication.
[0099] In a step 350, biometric authentication data of the user corresponding to one or more biometric factors are acquired and recorded. A biometric factor may relate, for example, to the eye, voice, face or hand of the user. The focus here is more particularly on the biometric factors associated with the hand of the user.
[0100] In this case, the biometric authentication data acquired for a hand may include one or more biometric prints from:
[0101] - a biometric imprint of the palm of the hand (palm print);
[0102] - an imprint of the venous network of the palm of the hand;
[0103] - fingerprints of the hand;
[0104] - a biometric handprint: overall shape of the hand and fingers in two or three dimensions, with or without palm image, with or without fingertip image, etc.;
[0105] - a combination of these prints.
[0106] In a known manner, each biometric fingerprint can be acquired by means of a suitable biometric sensor. According to one example, a palm print of the hand can be acquired from an image of the hand acquired by the camera. According to another example, an imprint of the venous network of the palm of the hand can be acquired from an image acquired by an infrared camera.
[0107] If the immersion device has both a camera and an infrared camera, it is possible, for example, to record not only the palm print acquired from an image of the palm of the hand, but also an imprint of the venous network of the hand acquired using the infrared camera as well as the 3D shape of the hand. This makes it possible to both improve recognition performance and, above all, to deal with presentation attacks ("spoofinq attacks") which consist of presenting a false biometric sample at the biometric sensor (digital image, printed photo of the hand, etc.)
[0108] In a step 360, user authentication data corresponding to one or more additional factors compared to those of steps 340 and 350 (e.g., possession factor) may be recorded.
[0109] For example, a possession factor based on the exchange of cryptographic keys between the immersion device 120 and the authentication server 140 may be implemented so as to enable authentication of the immersion device 120 by the authentication server 140 based on cryptographic keys. In this case, the recorded authentication data comprises one or more cryptographic keys.
[0110] In a step 370, the authentication data obtained in steps 340, 350 and 360 are verified and then stored (for example in an authentication database 145) in association with the data of the user account created in step 315. These data serve as reference authentication data. They are stored in encrypted form or recorded in the form of a digital hash. For example, the authentication data include:
[0111] - a summary of the entered PIN code;
[0112] - a summary of the positions of virtual authentication objects on the hand;
[0113] - a condensate of the secret reference sequence.
[0114] The verification carried out at this stage concerns, for example, the biometric data and more precisely the quality of the captures of the biometric sample (image of the palm of the hand) which may for example be blurred or not sufficiently illuminated, so as to allow extraction of the reference biometric template used for authentication. Indeed, if the extraction of the characteristics and the calculation of the reference biometric template go well then the acquired authentication data are validated and the biometric template will be stored. Otherwise, the step of acquiring the biometric authentication data is repeated as well as the step 370 of verification and recording.
[0115] Fig. 4 is a flowchart illustrating a user authentication method according to an exemplary embodiment. This method corresponds to an authentication phase carried out after the enrollment phase.
[0116] The authentication method may be performed for example by means of an immersion device 120, 200 described with reference to Fig. 1 or 2, this immersion device being in operational communication with an authentication server 140 as described for example with reference to Fig. 1. During a step 410, the authentication method starts and the user is asked to place a hand in front of a camera of the immersion device.
[0117] In a step 415, the hand is detected by the immersion device, for example by means of the camera. At least one image of the hand may be acquired while the hand is being detected by the immersion device.
[0118] In a step 420, a representation of the user's first hand is displayed in the virtual space while the first hand is detected.
[0119] The representation of the first hand may be a representation of the palm of the first hand. The representation of the user's first hand in the virtual space may be obtained from at least one image of the user's first hand acquired by the immersion device (by a camera of the immersion device).
[0120] The representation of the user's first hand can be a stylized or simplified representation, showing for example only the contours of the hand (contours of the fingers and palms) and main reliefs or correspond to a more detailed image of the hand.
[0121] During a step 430, one or more virtual authentication objects are displayed in projection onto the representation of the first hand in the virtual space.
[0122] In a step 435, the user is asked to authenticate by reproducing a secret reference sequence recorded during the enrollment phase. The reproduction of this secret sequence is to be carried out by interaction with the virtual authentication object(s) displayed in projection on the representation of the first hand in the virtual space.
[0123] During a step 440, gestures corresponding to interaction movements made by the user in the virtual space with the virtual authentication object(s) are detected while the virtual authentication object(s) are displayed in projection onto the representation of the first hand in the virtual space.
[0124] Behavioral biometric data representative of the user's interaction movements are captured using sensors present (accelerometer, gyroscope, camera, etc.) in the immersion device or its peripherals. These data represent the movements of his hands and / or the way in which the user holds and manipulates objects in his hand, and / or the user's behavior. The data acquired by these sensors can be analyzed in order to extract a certain number of parameters characteristic of the user's behavior such as for example: the speed of movements, the amplitude of movements, the duration of movements, the latency time between two movements, the coordination between head and hand movements, statistical parameters, etc.These behavioral biometric data can optionally be used for behavioral biometric authentication, in addition to the two authentication factors used during step 470.
[0125] During this interaction step 440, the representation of the first hand is displayed at a position in the virtual space corresponding to the position of the first hand in the real space where the user is located while the interaction movements are performed. In this way, the first hand serves as a spatial reference for the user in both the real space and the virtual space. In particular, it is easier to interact on a virtual authentication object because of this correspondence between what is viewed in the virtual space and the movements that the user performs in the real space to control these interaction movements with the virtual objects present only in the virtual space.
[0126] Furthermore, when the user performs the interaction movements with his second hand relative to the first hand in real space while having a visual representation of the progress of the interaction movements in virtual space, haptic feedback is provided to the user during the interaction with the virtual authentication objects when the user comes to touch the first hand with his second hand during this interaction.
[0127] The position of the virtual authentication objects relative to the first hand in the virtual space can be predefined and depends on the secret sequence to be entered. Alternatively, the positions of the virtual authentication objects change randomly at each authentication phase.
[0128] The virtual authentication objects can be positioned on the hand, in front of this hand or near this hand, in particular at a defined distance. Figure 6 illustrates examples of positioning the objects on phalanges of a finger, at the base of a finger, around a finger (when the object is a ring) or other positions. In the case of a keyboard, as illustrated by Figure 5, the keyboard can be represented as a single object 01 positioned in the palm of the first hand M1 or as several objects corresponding to the keys of the keyboard and distributed spatially. Whether it is a keyboard or objects to be manipulated, the virtual authentication objects can be distributed at randomly chosen positions on the representation of the first hand M1 at each new authentication in order to reinforce security.
[0129] The representation of the first hand in the virtual space as well as the virtual authentication object(s) projected onto the representation of the first hand follow any movement of the first hand in real space so that, for example, the relative position of each of the virtual objects with respect to the first hand in the virtual space does not change, except for any action by the user aimed at moving one of these virtual authentication objects with respect to the first hand.
[0130] According to embodiments, the interaction movements are performed with the second hand (in particular the fingers) of the user, the second hand being represented in the virtual space at a position corresponding to that of the second hand in the real space. The representation of the second hand thus serves as a pointer in the virtual space. In this case, the detection of interaction movements comprises the detection of movements performed with the second hand of the user detected by the immersion device and represented in the virtual space at the same time as the first hand.
[0131] According to embodiments, the interaction movements can be performed using a virtual interaction object (or virtual pointing object) which is represented in the virtual space and serves as a pointer to act on an authentication virtual object.
[0132] This virtual interaction object or pointer may be an interactive virtual object that is present in audiovisual content being rendered and that the user can manipulate to use it as a pointer in the virtual world. The movement of the virtual interaction object may be controlled in various ways by the user, for example by means of a device such as a keyboard, wheel, joystick, mouse, etc.
[0133] This virtual interaction object can also be a virtual object representing a real object manipulated by the user in the real world. In this case, a camera is used to detect the movements of the real object manipulated by the user in the real world.
[0134] According to embodiments, the interaction movements can be performed with the first hand of the user so that the representation of the first hand in the virtual space moves relative to a fixed virtual interaction object present in the virtual space: in this case also the representation of the first hand is displayed at a position in the virtual space corresponding to the position of the first hand in the real space where the user is located while the interaction movements are performed. In this mode of operation, the user only needs one hand. This virtual interaction object can be a virtual object that is present and fixed in the audiovisual content. This virtual interaction object can also be a virtual object representing a fixed real object.
[0135] Regardless of the pointer or the manner in which the interaction movements are performed, the secret sequence to be reproduced corresponds to an authentication method selected during the enrollment phase (see step 330) and the virtual authentication objects corresponding to the chosen method are represented in projection on the first hand.
[0136] According to an example illustrated by Figure 5, a virtual authentication object 01 may consist of a virtual keypad allowing the entry of a numeric sequence, an alphanumeric sequence or a sequence of symbols. The virtual keypad is displayed in the palm of a first hand M1. In this case, the user can perform interaction movements to press keys of this virtual keypad by means of his second hand M2 (for example by means of the index finger of his second hand) and thus enter a secret sequence.
[0137] During this interaction, the index finger of the second hand can come into contact with the palm of the first hand so that haptic feedback is provided to the user, allowing them to better control their gesture and to do so in a more precise and natural way (because the user knows when they are in contact with the key), notably with less risk of errors.
[0138] Instead of using a virtual keyboard to enter a secret code, another type of secret code entry device can be used with interaction movements other than key presses: for example, dials for entering a code to unlock a safe. The secret sequence in this case corresponds to a temporal sequence of rotation actions of the dials.
[0139] According to another example illustrated by Figure 6, one or more virtual authentication objects 710, 711, 713, 714 are used. Each of these virtual objects is associated with one or more respective interaction movements. The secret sequence may in this case be constituted by a temporal succession of interaction movements, each of which is an interaction movement associated with one of the virtual authentication objects. An interaction movement with a virtual authentication object may be: one of a movement of moving the virtual object, a movement of rotating the virtual object, a movement of selecting the virtual object, a movement of modifying the appearance of the virtual object, etc.
[0140] The embodiments, examples and details which have been described for the interaction step 440 concerning the reproduction of the secret sequence are also applicable to the step 340 executed during the enrollment phase for the acquisition of this secret sequence.
[0141] In a step 445, the interaction movements performed by the user in step 440 are analyzed and compared with a secret reference sequence recorded during the enrollment phase (see step 340). This secret sequence is constituted by a temporal succession of secret interaction movements known to the user. The comparison can be carried out from the respective digital condensates of the secret reference sequence and the interaction movement sequence newly performed by the user. This comparison makes it possible to determine whether a knowledge factor is verified or not, depending on whether the secret sequence recorded during the enrollment phase is correctly reproduced or not during step 430.
[0142] In a step 450, one or more biometric prints are acquired from a suitable sensor. According to one example, a palm print of the hand is acquired from an image of the hand acquired by the camera. According to another example, an print of the venous network of the palm of the hand is acquired from an image acquired by an infrared camera.
[0143] In a step 460, the biometric fingerprint(s) acquired in step 450 are compared with reference biometric fingerprints recorded during the enrollment phase (see step 350). This comparison makes it possible to determine whether a biometric factor is verified or not, depending on whether the acquired fingerprints correspond or not to the reference fingerprints recorded during the enrollment phase.
[0144] In a step 470, a user authentication decision based on at least two authentication factors is obtained. The two authentication factors include at least:
[0145] - a first biometric factor verified from a biometric fingerprint extracted from said at least one image; and
[0146] - a second knowledge factor verified by comparing the detected interaction movements with a temporal succession of secret interaction movements known to the user.
[0147] Other factors may be used to enhance the security level, such as a possession factor. For example, a possession factor may be verified by authentication of the immersion device 120 by the authentication server 140 based on at least one cryptographic key received during the enrollment phase.
[0148] During a step 480, the user is notified of the authentication decision: positive or negative depending on whether the user is authenticated or not.
[0149] The authentication process allows multiple authentication factors to be combined for strong authentication.
[0150] For example, strong authentication combines two factors, one based on a palm print and the other on entering a PIN code. In addition, a third factor can be used: a possession factor based on the exchange of cryptographic keys between the VR headset and the authentication server. The final authentication decision (rejection or acceptance) is based on the verification of all three factors.
[0151] For example, strong authentication combining two factors, one based on a palm print and the other on a secret sequence of interaction with virtual objects.
[0152] The authentication solution enables strong, transparent, multimodal, modular, customizable and adaptable authentication for different sensors (it is compatible with several types of sensors).
[0153] The authentication solution is inexpensive since it is based solely on the equipment and sensors available in VR headsets.
[0154] The authentication solution provides a good compromise between security and user experience.
[0155] In embodiments, because, during the interaction movements performed by the user, physical contact occurs with the first hand used to project the authentication objects, haptic feedback occurs. This significantly improves the user experience, which benefits from a sensory, immersive, ultra-realistic experience, and furthermore, assistance in guiding / manipulating objects precisely. The physical contact with the first hand can be made either with the second hand or with another real object, manipulated by the user and represented in the virtual environment at the same time as the first hand.
[0156] In describing the various phases and methods, although the steps are described sequentially, those skilled in the art will understand that certain steps may be omitted, combined, carried out in a different order and / or in parallel.
[0157] One or more or all of the steps of one or more methods described in this document may be implemented by software or computer program and / or by hardware, for example by circuit, programmable or not, specific or not.
[0158] The functions, steps and methods described in this document may be implemented by software (e.g., via software on one or more processors, for execution on a general purpose or special purpose computer) and / or be implemented by hardware (e.g., one or more electronic circuits, and / or any other hardware component).
[0159] The present description thus relates to a software or computer program, capable of being executed by a host device (for example, an immersion device) serving as an authentication device, by means of one or more data processors, this software / program comprising instructions to cause the execution by this host device of all or part of the steps of one or more methods described in this document. These instructions are intended to be stored in a memory of the host device, loaded and then executed by one or more processors of this host device so as to cause the execution by this host device of the method.
[0160] This software / program may be coded using any programming language, and may be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0161] The host device may be implemented by one or more physically distinct machines. The host device may generally have the architecture of a computer, including components of such architecture: data memory(s), processor(s), communication bus, hardware interface(s) for connecting this host device to a network or other equipment, user interface(s), etc.
[0162] In one embodiment, all or part of the steps of the authentication method or of another method described in this document are implemented by an authentication device provided with means for implementing these steps of this method.
[0163] These means may include software means (for example, instructions of one or more components of a program) and / or hardware means (for example, data memory(ies), processor(s), communication bus, hardware interface(s), etc.).
[0164] These means may comprise, for example, one or more processing circuits configured to execute one or more or all of the steps of one of the methods described herein. These means may comprise, for example, at least one processor and at least one memory comprising program instructions configured to, when executed by the processor, cause the device to execute one or more or all of the steps of one of the methods described herein.
[0165] Means implementing a function or a set of functions may correspond in this document to a software component, a hardware component or a combination of hardware and / or software components, capable of implementing the function or the set of functions, according to what is described below for the means concerned.
[0166] The present description also relates to an information medium readable by a data processor, and comprising instructions of a program as mentioned above.
[0167] The information carrier may be any material means, entity or device capable of storing the instructions of a program as mentioned above. Usable program storage media include ROM or RAM memories, magnetic storage media such as magnetic disks and magnetic tapes, hard disks or optically readable digital data storage media, or any combination of these media.
[0168] In some cases, the computer-readable storage medium is not transient. In other cases, the information medium may be a transient medium (e.g., a carrier wave) for the transmission of a signal (electromagnetic, electrical, radio, or optical signal) carrying the program instructions. This signal may be conveyed via a suitable transmission medium, whether wired or wireless: electrical or optical cable, radio or infrared link, or by other means.
[0169] An embodiment also relates to a computer program product comprising a computer-readable storage medium having stored thereon program instructions, the program instructions being configured to cause the host device (e.g., a computer) to perform some or all of the steps of one or more methods described herein when the program instructions are executed by one or more processors and / or one or more programmable hardware components of the host device.
Claims
CLAIMS 1. Method for authenticating a user carrying an immersion device in a virtual space, the method comprising - a detection (415) of a first hand of the user placed in front of a camera of the immersion device; - a display (420) of a representation of the user's first hand in the virtual space while the first hand is detected; - a display (430) of at least one virtual authentication object in projection onto the representation of the first hand in the virtual space; - a detection (440) of interaction movements carried out by the user in the virtual space with said at least one virtual authentication object while said at least one virtual authentication object is displayed in projection on the representation of the first hand in the virtual space; - obtaining (470) a user authentication decision taken on the basis of at least two authentication factors including a first biometric factor verified from a biometric fingerprint acquired by the immersion device for the first hand while the first hand is detected and a second knowledge factor verified by comparing the detected interaction movements with a temporal succession of secret interaction movements known to the user.
2. The method of claim 1, wherein the representation of the first hand is a representation of the palm of the first hand.
3. Method according to claim 1 or 2, wherein the representation of the first hand is displayed at a position in the virtual space corresponding to the position of the first hand in the real space where the user is located while the interaction movements are carried out; wherein the representation of the first hand in the virtual space as well as said at least one virtual authentication object projected onto the representation of the first hand follow a possible movement of the first hand in the real space.
4. Method according to any one of claims 1 to 3, wherein the display (430) of said at least one virtual authentication object in projection on the representation of the first hand is carried out so that, when the user performs the interaction movements with said at least one virtual authentication object, physical contact with the first hand occurs.
5. Method according to any one of claims 1 to 4, in which the detection of interaction movements comprises the detection of movements made with the second hand of the user detected by the immersion device and represented in the virtual space at the same time as the first hand.
6. The method of claims 4 and 5, wherein the physical contact occurs between the first hand and the second hand.
7. Method according to any one of claims 1 to 3, in which the detection of interaction movements comprises the detection of movements made by a virtual interaction object represented in the virtual space, in which the virtual interaction object is a virtual object present in audiovisual content rendered by the immersion device.
8. Method according to any one of claims 1 to 4, wherein the detection of interaction movements comprises the detection of movements made by a virtual interaction object represented in the virtual space, wherein the virtual interaction object is a virtual object representing a real object manipulated by the user.
9. Method according to claims 4 and 8, wherein the physical contact occurs between the first hand and the actual object manipulated by the user.
10. A method according to any one of claims 1 to 3, wherein the detection of interaction movements comprises detecting movements made in the real world with the first hand of the user such that the representation of the first hand in the virtual space moves relative to a fixed virtual interaction object present in the virtual space, the representation of the first hand being displayed at a position in the virtual space corresponding to the position of the first hand in the real space where the user is located while the interaction movements are made, wherein the virtual interaction object is a fixed virtual object in audiovisual content rendered by the immersion device.
11. A method according to any one of claims 1 to 4, wherein the detection of interaction movements comprises detecting movements made in the real world with the first hand of the user such that the representation of the first hand in the virtual space moves relative to a fixed virtual object of interaction present in the virtual space, the representation of the first hand being displayed at a position in the virtual space corresponding to the position of the first hand in the real space where the user is located while the interaction movements are made, wherein the virtual object of interaction is a virtual object representing a fixed real object.
12. Method according to claims 4 and 11, wherein the physical contact occurs between the first hand and the fixed real object.
13. Method according to any one of claims 1 to 12, wherein said at least one virtual authentication object comprises a device for entering a secret code corresponding to a temporal sequence of entry actions forming the temporal succession of secret interaction movements known to the user, the detection of interaction movements comprising the detection of entry actions carried out by the user by interaction with the entry device.
14. Method according to any one of claims 1 to 12, wherein said at least one virtual authentication object comprises several virtual authentication objects each associated with at least one respective interaction movement, the temporal succession of interaction movements known to the user being a temporal succession of interaction movements each of which is an interaction movement associated with one of the virtual authentication objects, wherein an interaction movement with a virtual authentication object comprises at least one movement from among a movement of moving the virtual object, a movement of rotating the virtual object, a movement of selecting the virtual object and a movement of modifying the appearance of the virtual object.
15. Device comprising means for implementing a method according to any one of the preceding claims.