Method for authenticating a user via an authentication device uniquely associated with the user
Patent Information
- Application Number
- EP2024714232
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-02-15
- Filing Date
- 2024-02-12
- Publication Date
- 2025-12-24
AI Technical Summary
Current authentication methods in virtual or mixed reality environments, such as those in the metaverse, are restrictive and lack strong security, particularly when removing and reattaching headsets for PIN codes or requiring dedicated biometric devices, and often rely on single-factor authentication.
A method utilizing a uniquely associated authentication device with a rotation gesture detection surface that captures sequences of rotation gestures defined by initial and final angular positions and direction, allowing for secure and intuitive user authentication without removing the headset, combining a physical factor with a memory factor for strong authentication.
This method provides a highly secure, easy-to-implement authentication solution with a high number of possible combinations, ensuring strong authentication and intuitive user interaction, allowing transactions to proceed only if the correct sequence is verified, thus preventing unauthorized access.
Smart Images

Figure FR2024050189_22082024_PF_FP
Abstract
Description
[0001] Description
[0002] Title of the invention: Method for authenticating a user via an authentication device uniquely associated with the user.
[0003] GENERAL TECHNICAL FIELD
[0004] The present invention relates to the field of authentication, and in particular in the context of virtual or mixed reality. More specifically, it relates to a method for authenticating a user, in particular a user of a virtual or mixed reality system.
[0005] STATE OF THE ART
[0006] We know of environments artificially generated by computers that can be perceived in virtual reality (or mixed, i.e. coexisting with the real world) and in particular the "metaverse" which would be a persistent, shared virtual world, and presented as the future of the internet.
[0007] To interact in such a universe, a user uses a virtual reality (VR) headset, or where appropriate mixed reality (MR).
[0008] This type of headset typically works by pairing with two controllers (or joysticks), held in each hand by the user. A controller is primarily used for interactivity: it acts as a pointing device, and also exposes various mechanical buttons, each assignable to a specific interactivity function, depending on the choice of the VR application.
[0009] This type of headset and controllers are additionally equipped with motion sensors (typically accelerometers), dedicated to vision tracking, hand tracking and physical movement area management.
[0010] In some models, the user can alternatively do without the controllers, and use their hands free to interact with the application (for example, we have fixed external cameras that observe their hands). In these environments, it is sometimes necessary to obtain proof of consent from the user, and for this to verify their identity, for example for transaction validation, and in particular payment (if the user buys an object, real or virtual, in the metaverse).
[0011] You can use traditional techniques like a PIN code or password, for example via a paired smartphone, but you have to take the headset off and put it back on, which is cumbersome.
[0012] Biometric authentication factors (voice, iris, fingerprint) could expand these mechanisms in the more or less near future, but they require dedicated acquisition means (for example, a fingerprint scanner on the controller), and there is no known implementation. It is noted that the headsets have eye sensors, but they are limited to the simple function of eye tracking and they are far from having the performance that would allow iris recognition.
[0013] Alternatively, a natural way to obtain user consent in virtual space is to ask them to perform a particular gesture. The method is all the more interesting if each user has a characteristic way of performing this gesture (what is called an "identifying" gesture). Application FR2214116 thus allows a reliable, secure and reproducible identification or authentication solution, in particular for proof of user consent.
[0014] A disadvantage of this latter solution is that it remains single-factor, and therefore does not allow “strong” authentication, which involves the use of an external device such as a mobile terminal or a physical token.
[0015] In addition to the solution described in application FR2214116, it would therefore be desirable to have a very high security solution which also remains intuitive and easy to implement by the user, for example not necessarily requiring the VR headset to be removed.
[0016] PRESENTATION OF THE INVENTION The present invention therefore relates, according to a first aspect, to a method of authenticating a user, the method being characterized in that it comprises the implementation by data processing means of a server of steps of:
[0017] (a) Obtaining, from an authentication device uniquely associated with the user and connected to said server, data representative of a sequence of rotation gestures made by the user on said authentication device, each rotation gesture being defined by an initial angular position, a final angular position, and a direction of rotation;
[0018] (b) Verification of said data representative of said sequence of rotation gestures made by the user on said authentication device.
[0019] According to advantageous and non-limiting characteristics:
[0020] The verification of step (b) is a comparison of said sequence of rotation gestures performed by the user on said authentication device with at least one expected sequence of rotation gestures.
[0021] Step (a) comprises a sub-step (a2) of issuing an invitation to the user to perform said sequence of rotation gestures on said authentication device.
[0022] The user is a user of a virtual or mixed reality system connected to the server and comprising means for displaying an immersive space.
[0023] The method comprises a step (c) of implementing or not a transaction initiated by said user (in particular in said immersive space) depending on the result of step (b).
[0024] Step (a) comprises a sub-step (a1) of receiving a request to validate said transaction, in response to which said invitation from the user to perform said sequence of rotation gestures on said authentication device is issued.
[0025] The authentication device includes a rotation gesture detection surface selected from a rotating plate and a touch surface.
[0026] Said rotation gesture detection surface extends circularly around a central element.
[0027] Said rotation gesture detection surface has at least one tactile marker, in particular a raised marker.
[0028] Said rotation gesture detection surface has a plurality of tactile markers arranged at regular intervals around said central element.
[0029] Said plurality of markers is composed of a single main marker and one or more secondary markers different from said main marker.
[0030] The authentication device is paired with a user's mobile terminal through which it is connected to said server.
[0031] According to a second aspect, the invention proposes a user authentication server, characterized in that it comprises data processing means configured to:
[0032] - Obtain, from an authentication device uniquely associated with the user and connected to said server, data representative of a sequence of rotation gestures made by the user on said authentication device, each rotation gesture being defined by an initial angular position, a final angular position, and a direction of rotation;
[0033] - Verify said data representative of said sequence of rotation gestures made by the user on said authentication device.
[0034] According to a third and a fourth aspect, the invention provides a computer program product comprising code instructions for executing a method according to the first aspect of authenticating a user; and a storage means readable by computer equipment on which is recorded a computer program product comprising code instructions for executing a method according to the first aspect of authenticating a user.
[0035] PRESENTATION OF FIGURES
[0036] Other characteristics and advantages of the present invention will appear on reading the following description of a preferred embodiment. This description will be given with reference to the appended drawings in which:
[0037] [Fig. 1]Figure 1 is a diagram of a system for implementing the method according to the invention;
[0038] [Fig. 2]Figure 2 represents an example of an authentication device used in the method according to the invention;
[0039] [Fig. 3]Figure 3 schematically illustrates how a rotation gesture is defined on said authentication device.
[0040] [Fig. 4]Figure 4 is a flowchart illustrating the steps of an embodiment of the method according to the invention.
[0041] DETAILED DESCRIPTION
[0042] Architecture
[0043] The present invention relates to a method for authenticating a user, preferably a user of a virtual or mixed reality system 1 as represented in FIG. 1, in particular for implementing a transaction in an immersive space to which the system 1 provides access.
[0044] It should be noted that even if, as we will see, the present method is particularly effective in virtual / mixed reality, it is not limited to this application, and that the present method can be used for any authentication of a user, for example to validate a transaction in a store, to unlock equipment, to access a personal space in an application, etc. In the context of VR, the present method can also be used to sign a contract, transfer rights or even authorize a user's access to a secure virtual room (in particular a personal one).
[0045] The possible system 1 comprises display means 12 for said immersive space (i.e. with which the user can interact, and in which he is “immersed”), typically a headset, and means for detecting movement in said immersive space 14, generally controllers (or joysticks) held by the hands and equipped with accelerometers and / or gyrometers, or alternatively fixed external cameras observing the hands.
[0046] The various devices in system 1 (e.g. headset and controllers) are interconnected wired or wirelessly (e.g. Bluetooth).
[0047] The said “reality” is either:
[0048] - virtual, that is to say that the said immersive space is completely artificial, or
[0049] - mixed, that is to say only partially virtual, and said immersive space superimposes a real environment and a virtual environment.
[0050] A mixed reality system 1 generally comprises, in addition to the display means 12, a camera filming the real world continuously, the rendering of the display means 12 including virtual elements in this “real” stream. In the remainder of this description, the example of virtual reality, abbreviated “VR”, will be taken for convenience, but those skilled in the art will be able to transpose the environment to mixed reality (MR).
[0051] In a known manner, in all cases, the display means 12 are coupled with the movements of the headset worn by the user so that the display of the immersive environment evolves according to these movements so as to simulate reality. To do this, the system 1 generally comprises means for detecting the movement of the headset worn by the user 13, for example again accelerometers or cameras either external observing the head, or attached to the headset and observing the environment.
[0052] The system 1 further comprises data processing means 11 such as a processor, implementing applications in said immersive space. For example, in a sports game, the interactivity controller simulates a ball and pressing a button corresponds to kicking the ball.
[0053] The present method is implemented by a server 2 which can be confused with the system 1, or remote and connected by a network 20 such as the Internet network.
[0054] The server 2 also has data processing means 21 (typically a processor) and data storage means 22 (a memory, for example a hard disk).
[0055] Finally, the present method uses an authentication device 10, uniquely associated with the user (i.e. it is a personal device) and connected to said server 2, which will be discussed in more detail later.
[0056] Principle
[0057] The present method aims at authenticating the user using a sequence of rotation gestures performed by the user on his personal authentication device 10, called an “authentication sequence”, alternatively for example to known techniques such as gesture recognition or code entry. As will be seen, such a sequence allows in practice many more combinations than a PIN code, and is very easy to memorize, and can be performed intuitively without looking at the device, which is very advantageous for a VR application (no need to remove the headset).
[0058] Said authentication is in particular carried out to obtain the user's consent in said immersive space (i.e. confirmation). The method can be implemented at any time where the identity of the person using the system 1 may need to be verified. The case in point is a transaction validation (if the user purchases an object, real or virtual, in the immersive space).
[0059] By "rotation gesture" is meant a gesture typically of at least one finger (generally one or two fingers) or of the user's entire hand which corresponds to a rotation movement. As such, the authentication device 10 preferably comprises a surface 100 for detecting rotation gestures chosen from a rotating plate and a touch surface, in particular circular (and thus typically with a disc shape) as seen in the example of FIG. 2, but alternatively the authentication device 10 can simply be a smartphone-type mobile terminal with a complete touch screen acting as surface 100, or even a camera filming the user's hands, or even a controller 14 (in these latter cases, the sequence of rotation gestures is performed in the air).A dedicated device 10 with a physical surface 100 nevertheless remains preferred to guarantee strong authentication, the preferred example of a disc-shaped device 10 with a rotating plate or a circular touch surface will be taken below, and a particularly preferred embodiment of the authentication device 10 in accordance with FIG. 2 will be described later.
[0060] In all cases, each rotation gesture is defined by an initial angular position, a final angular position, and a direction of rotation. The advantages are numerous:
[0061] - the number of combinations is very high, much more than for a simple PIN code, and therefore the security is very strong;
[0062] - rotation gestures can be performed precisely, even without looking at the device and therefore while keeping the headset on.
[0063] In a first embodiment called "discrete", there are a plurality of predefined angular positions (a number N), and each initial / final angular position is chosen from one of the predefined angular positions. In other words, there are elementary sectors of angular width 360 / N degrees numbered from 1 to N. We then have 2N 2 possible gestures (note that a gesture with identical initial and final positions corresponds to a complete turn), and the descriptive data of a rotation gesture are typically a triplet (ni, nt, s)e[1 ;N]x[1 ;N]x{-1 ,+1} of the identifiers of the initial and final positions and an indicator of the direction of rotation (2 possible values for the clockwise and counterclockwise directions, here arbitrarily chosen at -1 and +1 ). Alternatively, we can simply represent the gesture by a unique identifier ie[1 ;2N 2 ].
[0064] Preferably, we have N>4, and preferably N is chosen from 4, 6, 8 and 12, which allows intuitive divisions of the circle.
[0065] In the example of Figure 3, we have N=12, i.e. 12 sectors of 30° numbered from 1 to 12 clockwise, with sector 12 to the north (1 to the NNE, 2 to the ENE, 3 to the East, etc.). We have 288 possible gestures, Figure 3 representing the counterclockwise 3-^5 gesture (represented by the triplet (3, 5, -1 )). We understand that there are nearly 7 billion possible sequences of just four of these rotation gestures, which guarantees that it is impossible to find the sequence by chance.
[0066] With only N=4, we already have 32 possible rotation gestures, and a sequence of only two gestures already guarantees more than a thousand combinations.
[0067] According to one embodiment, more than one revolution can be allowed, and the value s is then a value in TL, with the sign of s designating the direction of rotation and |s-11 the number of additional complete revolutions. For example:
[0068] - (3, 5, -2) would correspond to another rotation from 3 to 5 counterclockwise with a complete turn made (i.e. complete turn starting from 3 then 3 to 5).
[0069] - (3, 3, 2) would correspond to two complete hourly turns starting from 3 (i.e. complete turn starting from 3 then 3 towards 3 which is a second complete turn).
[0070] By noting T as the maximum number of complete turns allowed (i.e. se[- (T+1 );+(T+1 )]), the number of possible gestures increases to 2(T+1 )N 2. In a second embodiment called "continuous", there may be no predefined angular positions and simply the most precise measurement possible of the initial and final angular positions. In other words, the initial and final angular positions can take any possible value.
[0071] Process
[0072] With reference to Figure 4, the present method is implemented by the data processing means 21 of the server 2, and begins with a step (a) of obtaining from the authentication device 10 uniquely associated with the user, data representative of a sequence of rotation gestures made by the user on said authentication device 10.
[0073] We understand that we have strong authentication since we combine a material factor (the user proves that he has a specific authentication device 10, uniquely associated with him) and a memory factor (the sequence of rotation gestures). If the server 2 received data representative of a sequence of rotation gestures made by the user on an authentication device other than the one that is uniquely associated, then they would be ignored and the authentication would be rejected.
[0074] We speak of a "candidate" authentication sequence as being that carried out directly by the user (like a code entered on a keyboard) and on the basis of which authentication will be attempted, as opposed to "reference" authentication sequences, in practice the one(s) expected.
[0075] In this respect, step (a) preferably comprises a sub-step denoted (a4) of encoding this sequence of candidate rotation gestures, i.e. the generation of said data representative of said sequence of rotation gestures performed by the user on said authentication device 10 from raw data acquired by the device 10, i.e. the translation of the measured electrical signals into a code such as a vector of k triplets (ni, nt, s), where k is the number of gestures in the sequence. Note that this encoding can be performed directly by the device 10 or by the server 2. Step (a) preferably comprises the acquisition (a3), by the device 10, of said raw data, while the user performs the gestures.
[0076] In a following step (b), the processing means 21 of the server 2 authenticate said user by verifying said representative data obtained from a sequence of candidate rotation gestures (i.e. said data representative of the sequence of rotation gestures performed by the user on said authentication device 10).
[0077] More specifically, said sequence of rotation gestures performed by the user on said authentication device 10 must correspond with at least one expected authentication sequence.
[0078] Advantageously, the expected authentication sequence is the user's reference authentication sequence, i.e. a predefined sequence known (and generally previously chosen) by the user.
[0079] Note that there may be several reference authentication sequences, in particular more or less long, corresponding to various possible security levels.
[0080] For example, for authentication before a transaction above a certain amount, a sequence of four gestures may be expected, while for a simple consent check, a sequence of one gesture may be required to avoid false user manipulation. Alternatively, the user may have a manual setting of the desired security level.
[0081] Depending on the transaction and / or the security level, there is thus a reference sequence which is selected as the “expected” sequence, and it is compared with the sequence of rotation gestures made by the user on said authentication device 10. Note that there may be several alternative expected sequences, in that it can be provided that a high security level sequence is worth a lower security level sequence: for example, if the simple consent verification sequence (1 gesture) was expected and the user performs the complete authentication sequence (4 gestures), then he is authenticated.
[0082] Alternatively, the expected authentication sequence is an authentication sequence generated by server 2 (in particular randomly), and which the user must reproduce, in a “challenge-response” type logic (the expected authentication sequence can be considered as a one-time password, OTP), see further.
[0083] In all cases, regardless of the nature of the expected authentication sequence, the verification is similar.
[0084] According to a first embodiment, typically when there are N possible angular positions, the representative data of these two sequences, i.e. their codes, are directly compared. In this case, there must be an exact correspondence, otherwise at least one gesture is erroneous.
[0085] According to a second embodiment, typically in the case of angular positions with continuous values (as opposed to N possible angular positions), a "fuzzy matching" algorithm is used, in particular a classification model capable of calculating a proximity score between the candidate sequence and the (each) expected sequence and of comparing this score with an authentication threshold. Indeed, in such a mode it is impossible to reproduce exactly the same sequence, and it is just verified that the candidate sequence is sufficiently similar to the expected reference sequence.
[0086] Transaction & Consent
[0087] Preferably, the method is part of a transaction validation context, and more specifically the user's consent to the implementation of said transaction.
[0088] It then advantageously comprises a step (c) of implementing or not a transaction initiated by said user in said immersive space depending on the result of step (b), i.e. the result of the verification of the sequence carried out by said user, and therefore his authentication. In other words, if the user has carried out the expected authentication sequence (which means that he has given his consent), the result of the verification is positive and the transaction is implemented.Conversely, if the result of the verification is negative, it is either because the user has not finally given his consent (system 1 may have mistakenly believed, following poor manipulation by the user, that the latter wishes to implement a transaction) or because a third party has attempted to usurp his identity by stealing his authentication device 10 (and therefore the user in the first place never gave his consent), and the transaction is not implemented.
[0089] We will understand "transaction" in the broad sense, that is to say possibly payment but also signing of a contract, transfer of rights, authorization of access to a secure virtual room, etc.
[0090] Preferably, step (a) comprises a sub-step (a2) of sending to said system 1 an invitation to perform the candidate rotation gesture sequence. It is understood that this invitation is addressed to the user and is displayed (in any form) by the means 12.
[0091] In the “challenge-response” type mode where the expected authentication sequence is an authentication sequence generated by the server 2 that the user must reproduce, this expected authentication sequence is advantageously presented to the user in this invitation, for example in the form of pictograms representing the gestures as in figure 3. Thus, the invitation issued is more precisely an invitation to reproduce a sequence of given rotation gestures generated by the server 2.
[0092] This invitation can be issued in response to a sub-step (a1) of receiving a request to validate said transaction, received from the system 1 or another server, in particular a transaction server (which can in turn be confused with the server 2).
[0093] Typically: - The user wishes to make a transaction in the immersive space, and performs an associated action (such as taking a virtual object)
[0094] - System 1 communicates with a remote transaction server indicating that the user wishes to implement a transaction;
[0095] - The transaction server sends a transaction validation request to server 2, to ensure that the user gives his consent (sub-step (a1));
[0096] - In response, the server 2 sends to the system 1 the invitation to perform the sequence of rotation gestures on its authentication device 10 (sub-step (a2)). It is understood that in particular this invitation is interpreted by the system to be understood by the user, for example by displaying a text in the immersive space (“please validate the transaction by performing your sequence of rotation gestures”) but also with an audio message, etc.
[0097] - The user uses his authentication device 10, and the latter acquires the corresponding raw data (sub-step (a3));
[0098] - The device 10 and / or the server 2 encodes the gestures (sub-step (a4)), i.e. generates said data representative of said sequence of rotation gestures performed by the user on his candidate authentication device 10 from the acquired raw data;
[0099] - The server 2 can then implement the verification of this data representative of said candidate rotation gesture sequence, so as to ensure that this candidate authentication sequence coincides with an expected authentication sequence (step (b));
[0100] - The transaction is validated if the result of the verification of said data representative of a sequence of rotation gestures obtained is that said candidate authentication sequence coincides with the expected authentication sequence (step (c)), and the server 2 can notify the possible transaction server so that the latter implements the transaction.
[0101] Authentication device
[0102] As explained, the authentication device 10 can be any device uniquely associated with the user and connected to said server 2, and on which the user can perform a sequence of rotation gestures.
[0103] Preferably, the device 10 comprises a surface 100 for detecting rotation gestures, which is typically a touch-sensitive surface, for example made of a flexible material such as silicone. It is understood that this touch-sensitive surface is not a screen.
[0104] With reference to Figure 2, said surface 100 for detecting rotation gestures advantageously extends circularly around a central element 101. In other words, it has a substantially annular shape whose central element marks the center, and it is understood that it is natural to perform a rotation gesture on such a surface. The entire device 10 thus has a disc shape with a housing typically a few centimeters in diameter, and approximately one centimeter thick. The housing can also accommodate processing means and a battery for said device 10.
[0105] It will be noted that the central element 101 may be a button 101 used in particular to control the device 10, for example to perform an action in the immersive space, but also to turn it on / off (multiple quick presses) or trigger a pairing (long press).
[0106] Indeed, the authentication device 10 is preferably paired with a mobile terminal 3 of the user (in particular via short-range wireless communication, in particular Bluetooth) via which it is connected to said server 2, the terminal 3 in fact allowing a connection to the network 20 such as the internet network. The device 10 can also be attached to the mobile terminal 3, for example magnetically, which possibly allows it to be recharged by induction. Alternatively or in addition, the device 10 can comprise a port, for example USB, in particular on the side of the housing.
[0107] The central element 101 may additionally or additionally comprise an additional biometric identification means, for example a fingerprint sensor.
[0108] In order to guide the gesture, said surface 100 for detecting rotation gestures advantageously has at least one tactile marker 102a, 102b, or even a plurality of tactile markers 102a, 102b arranged at regular intervals around said central element 101, i.e. at regularly distributed angular positions. The markers may be physical, in particular raised markers (which may be studs, hollows, or any textured pattern), or simulated markers, for example with haptic feedback (i.e. a vibration) triggered when the user reaches the position of one of these markers 102a, 102b on the surface 100.
[0109] Thus, the user can directly feel the position of this(these) marker(s) 102a, 102b and therefore position himself on the surface 100 of the device 10 without needing to look. In the case of several markers, the user knows by feeling them that he has traveled a certain angular extent and therefore control his gesture for greater precision.
[0110] In a particularly preferred manner, said plurality of markers 102a, 102b is composed of a single main marker 102a and one or more secondary markers 102b different from said main marker 102a, so as to distinguish them. Thus, the main marker makes it possible to orient the device 10 absolutely (by identifying a reference direction, for example north), and the others make it possible to control the rotation gesture. In the example of FIG. 2, there are physical markers on a circular touch surface 100, including a main marker 102a with three pins, and three secondary markers 102b with a single pin. It is noted that the presence of several markers 102a, 102b is particularly effective in combination with the embodiment in which there are N predefined angular positions, since the markers can be directly associated with some of these predefined angular positions.
[0111] For example, taking the configuration with 12 predefined angular positions of Figure 3, the markers of Figure 2 are respectively associated with positions 12 (main marker 102a), 3, 6 and 9 (secondary markers 102b). The counterclockwise 3-^5 gesture of Figure 3 corresponds to a departure from the first secondary marker 102b after the main marker 102a, with a movement of the finger passing successively through the main marker 102a, and the other two secondary markers 102b. This is very intuitive for the user.
[0112] Furthermore, the device 10 may comprise a light zone 103a, 103b arranged around the surface 100. This light zone may comprise an extended light strip 103a (i.e. occupying at least part of the circumference of the surface 100) and / or point light sources 103b. The light strip 103a may light up as a rotation gesture progresses, and a new light source 103b may light up with each gesture in the sequence. Thus, if the user is lost, he can look at the light zone 103a, 103b at any time to know where he is, and resume the sequence.
[0113] Enrollment
[0114] The method advantageously comprises a prior enrollment step (aO) to generate said data representative of at least one sequence of reference rotation gestures, to use it as the authentication sequence expected in the verification of step (b).
[0115] To do this, the user can perform said sequence of reference rotation gestures on said authentication device 10 in a controlled environment, i.e. for example after having authenticated it via another existing authentication mode (biometrics, code, use of smartphone, etc.).
[0116] There is thus a step (A) of obtaining from the authentication device 10 uniquely associated with the user and connected to said server 2, data representative of a sequence of rotation gestures made by the user on said authentication device (10), which is the counterpart of step (a).
[0117] We can have the sub-steps (A1), (A2), (A3) and (A4) homologous to the sub-steps (a1), (a2), (a3) and (a4) of step (a):
[0118] (A1) receiving a request to enroll at least one sequence of rotation gestures as a reference authentication sequence, for authentication.
[0119] (A2) sending to said system 1 an invitation to perform said sequence of rotation gestures one or more times on its device 10 (it is understood that here it is for the user to choose his sequence, and it is preferable to repeat it to be sure that the user is sure that he has not made a mistake).
[0120] (A3) Acquisition of raw data from each sequence performed;
[0121] (A4) Encoding of the reference authentication sequence.
[0122] In a step (B) which is the counterpart of step (b), the verification algorithm is configured, or where appropriate, a possible classification model is trained.
[0123] Server
[0124] According to a second aspect, the invention relates to the server 2 for implementing the method according to the first aspect.
[0125] Thus, this server 2 comprises, as explained, at least data processing means 21 and a memory 22. It is typically an authentication server for an immersive space. The data processing means 21 are configured to implement steps consisting of:
[0126] - Obtain, from an authentication device 10 uniquely associated with the user and connected to said server 2, data representative of a sequence of rotation gestures made by the user on said authentication device 10, each rotation gesture being defined by an initial angular position, a final angular position, and a direction of rotation;
[0127] - Verify said data representative of said sequence of rotation gestures made by the user on said authentication device 10.
[0128] According to a third aspect, the invention proposes a system comprising said server 2, as well as at least one connected system 1 (via the network 20). Advantageously, said system also comprises said authentication device 10, connected to the first server 2 still via the network 20, where appropriate via a mobile terminal 3 of the user.
[0129] Computer program product
[0130] According to a fourth and a fifth aspect, the invention relates to a computer program product comprising code instructions for the execution (on the data processing means 21 of the server 2a) of a method according to the first aspect of authenticating a user, as well as storage means readable by computer equipment (for example the data storage means 22 of the server 2) on which this computer program product is found.
Claims
CLAIMS 1. Method for authenticating a user, the method being characterized in that it comprises the implementation by data processing means (21) of a server (2) of steps of: (a) Obtaining, from an authentication device (10) uniquely associated with the user and connected to said server (2), data representative of a sequence of rotation gestures performed by the user on said authentication device (10), each rotation gesture being defined by an initial angular position, a final angular position, and a direction of rotation, the authentication device (10) being paired with a mobile terminal (3) of the user via which it is connected to said server (2); (b) Verification of said data representative of said sequence of rotation gestures made by the user on said authentication device (10).
2. Method according to claim 1, wherein the verification of step (b) is a comparison of said sequence of rotation gestures made by the user on said authentication device (10) with at least one expected sequence of rotation gestures.
3. Method according to claim 2, in which step (a) comprises a sub-step (a2) of issuing an invitation to the user to perform said sequence of rotation gestures on said authentication device (10).
4. Method according to one of claims 1 to 3, in which the user is a user of a virtual or mixed reality system (1) connected to the server (1) and comprising display means (12) of an immersive space.
5. Method according to one of claims 1 to 4, comprising a step (c) of implementing or not a transaction initiated by said user depending on the result of step (b).
6. Method according to claims 3 and 5 in combination, wherein step (a) comprises a sub-step (a1) of receiving a request for validation of said transaction, in response to which said invitation of the user to perform said sequence of rotation gestures on said authentication device (10) is issued.
7. Method according to one of claims 1 to 6, in which the authentication device (10) comprises a surface (100) for detecting rotation gestures chosen from a rotating plate and a touch surface.
8. Method according to claim 7, wherein said surface (100) for detecting rotation gestures extends circularly around a central element (101).
9. Method according to claim 8, wherein said surface (100) for detecting rotation gestures has at least one tactile marker (102a, 102b), in particular a raised marker.
10. The method of claim 9, wherein said surface (100) for detecting rotation gestures has a plurality of tactile markers (102a, 102b) arranged at regular intervals around said central element (101).
11. The method of claim 10, wherein said plurality of markers (102a, 102b) is composed of a single main marker (102a) and one or more secondary markers (102b) different from said main marker (102a).
12. Server (2) for authenticating a user, characterized in that it comprises data processing means (21) configured to: - Obtaining, from an authentication device (10) uniquely associated with the user and connected to said server (2), data representative of a sequence of rotation gestures made by the user on said authentication device (10), each rotation gesture being defined by an initial angular position, a final angular position, and a direction of rotation, the authentication device (10) being paired with a mobile terminal (3) of the user via which it is connected to said server (2); - Verifying said data representative of said sequence of rotation gestures made by the user on said authentication device (10).
13. Computer program product comprising code instructions for executing a method according to one of claims 1 to 11 for authenticating a user, when said program is executed on a computer.
14. Storage means readable by computer equipment on which is recorded a computer program product comprising code instructions for the execution of a method according to one of claims 1 to 11 for authenticating a user.