Method and device for behavioral biometric authentication
The behavioral biometric authentication method addresses authentication interruptions by analyzing user interactions with game consoles, providing continuous and secure authentication using machine learning, enhancing user experience and security in video games.
Patent Information
- Application Number
- FR2022008401
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-08-19
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2042-08-19
AI Technical Summary
Existing authentication methods in video games and digital platforms cause interruptions and discontinuities due to the need for passwords or additional devices for strong authentication, and are vulnerable to unauthorized access.
A behavioral biometric authentication method using machine learning to analyze user interactions with game consoles, generating behavioral models from raw data to provide continuous, seamless, and secure authentication without additional sensors.
Enables continuous, secure, and seamless user authentication within video games, reducing false negatives and positives, and ensuring high security without disrupting gameplay.
Smart Images

Figure 00000026_0000 
Figure 00000027_0000 
Figure 00000028_0000
Abstract
Description
Title of the invention: Method and device for behavioral biometric authentication Technical field
[0001] The present description relates to a method and device for behavioral biometric authentication. Technical background
[0002] In the context of video games, passwords are used to secure user accounts on game consoles: many users use passwords to protect their accounts from access by others (e.g., friends or family members). To enter a password, a user generally has to operate a virtual keyboard on a screen (e.g., a television) while navigating with their game console.
[0003] When a payment is required, users can save their payment information in their account and set a password, which can be the account password or specific to payment transactions to add an extra layer of security when paying (in case of console theft or also to prevent others from purchasing games from their account). Such a measure can introduce interruptions or discontinuities in the video game for users when they try to validate a transaction. In addition, users still cannot prevent payment if others manage to obtain their passwords.
[0004] In addition, strong authentication may be required for payments on a digital platform associated with the video game: strong authentication may cause unwanted “friction”, interruptions or discontinuities for users when making payments via the platform because most of the time users will need to use another device (e.g. a mobile phone) to finalize the authentication and validate the transaction.
[0005] There thus appears to be a need for a strong authentication solution that is suitable for video games or other application contexts requiring strong authentication that may be required at any time during the user's interaction with a given application system. Summary
[0006] The scope of protection is defined by the claims.
[0007] According to a first aspect, the present description relates to a method of behavioral biometric authentication of a user interacting with a application system by means of at least one interaction device. The method comprises - obtaining behavioral models of reference users; - obtaining a behavioral model of a legitimate user; - obtaining parameter values characteristic of user behavior determined from events produced by user interaction with the interaction equipment; - a determination of a first score by applying the behavioral model of the legitimate user to the values of the characteristic parameters; - a determination of second scores by applying respectively each of the behavioral models of the reference users to the values of the characteristic parameters; - a determination of a decision to authenticate the user as the legitimate user based on the first score and the second scores.
[0008] According to one or more embodiments, the first score represents a probability that the user is the legitimate user.
[0009] According to one or more embodiments, each second score represents a probability that the user is a reference user associated with the behavioral model used to generate the relevant score.
[0010] According to one or more embodiments, the steps of determining the first score, the second scores and the authentication decision are repeated for characteristic parameter values obtained respectively for a temporal succession of time intervals, the method comprising - an update of the current value of a weight for each time interval, the weight being decremented if one of the second scores obtained for this time interval is greater than an authentication threshold, the weight being incremented if the first score obtained for this time interval is greater than the authentication threshold; - the first score obtained for a time interval being modified by adding the current value of the weight after updating for this time interval, the first modified score being used for determining the authentication decision.
[0011] According to one or more embodiments, - the authentication decision is negative if the first score is lower than an authentication threshold; - the authentication decision is negative if the first score is greater than an authentication threshold and at least one of the second scores is greater than the authentication threshold; and - the authentication decision is positive if the first score is greater than an authentication threshold and all second scores are less than the threshold authentication.
[0012] According to one or more embodiments, - the authentication decision is negative if the first score is lower than an authentication threshold; - the authentication decision is positive if the first score is greater than an authentication threshold and less than N second scores are greater than the authentication threshold; - the authentication decision is negative if the first score is greater than an authentication threshold and at least N or more second scores are greater than the authentication threshold.
[0013] According to one or more embodiments N is an integer strictly greater than 1 and less than or equal to 10.
[0014] According to one or more embodiments, the reference users are users different from the legitimate user.
[0015] According to one or more embodiments, the behavioral models of the reference users are the most discriminating behavioral models among a set of behavioral models of reference users.
[0016] According to one or more embodiments, the application system is a video game system.
[0017] According to a second aspect, the present description relates to a device comprising means for implementing a method according to the first aspect.
[0018] The means may be software and / or hardware means. The means may comprise, for example, one or more circuits configured to execute one or more or all of the steps of the method according to the first aspect. The means may comprise, for example, at least one processor and at least one memory comprising program instructions configured to, when executed by the processor, cause the device to execute one or more or all of the steps of the method according to the first aspect.
[0019] According to another aspect, the present disclosure relates to a data processor-readable recording medium having recorded thereon a program comprising program instructions configured to cause the data processor to execute one or more or all of the steps of the method according to the first aspect.
[0020] According to another aspect, the present disclosure relates to a computer program comprising program instructions configured to cause a data processor to execute one or more or all of the steps of the method according to the first aspect. Brief description of the figures
[0021] Other characteristics and advantages will result from the detailed description which follows, carried out on the basis of embodiments and examples given for illustrative and non-limiting purposes, with reference to the appended figures.
[0022] [Fig-1] presents a block diagram illustrating a phase of constitution of common models reference behaviors according to an example of realization.
[0023] [Fig.2] presents a block diagram illustrating a phase of enrollment of one or more legitimate users according to an example of implementation.
[0024] [Fig.3] presents a block diagram illustrating an authentication phase of a user lizer according to an example of realization.
[0025] [Fig.4] presents a block diagram illustrating a phase of updating the bio template metric of a legitimate user according to an example implementation.
[0026] [Fig.5] represents a flowchart of a biometric authentication process behavioral according to an example of realization.
[0027] [Fig.6] schematically represents a system including a device behavioral biometric authentication according to an exemplary embodiment.
[0028] [Fig.7] is a diagram showing the performance of an authentication method behavioral biometrics according to an example of implementation.
[0029] [Fig.8] is a diagram showing the performance of an authentication method behavioral biometrics according to an example of implementation. Detailed description
[0030] Various exemplary embodiments will now be described in more detail with reference to the drawings. However, the specific structural and / or functional details disclosed herein are used to enable an understanding of the various possible embodiments. However, those skilled in the art will understand that the exemplary embodiments may undergo various modifications and may be implemented without all of these details.
[0031] The present description relates to a transparent behavioral biometric authentication method and device making it possible to streamline the authentication steps, simplify the user experience, enable a “seamless” experience (“frictionless” according to English terminology) and the validation of transactions while guaranteeing a high level of security.
[0032] This method also makes it possible to authenticate during a user experience that the user is indeed the legitimate user and that he is not being replaced or helped by cheating means, that is to say that the legitimate user is not a cheating user or "cheater" in English.
[0033] This authentication system is based on bio-behavioral data metrics collected during user interactions with an application system. From this biometric behavioral data, behavioral models of reference users are trained by machine learning, including users different from the legitimate user.
[0034] A behavioral model of a user is configured to receive as input parameter values characteristic of the behavior of this user and to generate as output a score. The score is representative of a probability that the behavior represented by the input characteristic parameter values is that of the user associated with the behavioral model. The value of this score can be normalized, for example between 0 and 1. By convention, it is agreed in this document that the higher the score, the higher the value for the probability.
[0035] The solution is inexpensive in that it uses only the behavioral data produced by the action of a user on one or more interaction devices (comprising different interaction elements such as button(s), wheel(s), joystick, mouse, etc.) during the interaction with the application system and does not require additional sensors or additional measurements.
[0036] This method and device can be used in particular for video games in the case of which biometric behavioral data can be collected during the user's gaming sessions from the raw behavioral data produced by the game console (buttons and / or controller) following the user's actions.
[0037] The authentication device allows continuous authentication of the user, for example throughout an interaction session. In the context of video games, this authentication can be carried out throughout a video game. It does not require any interruption in the interaction with the application system. The authentication is transparent to the user, not requiring specific actions from the user. The authentication level is that of strong authentication.
[0038] The behavioral data collected are, for example, those generated by a user interface, for example, interaction equipment, control equipment or a control table. In the case of a video game, this may be a game console including a keyboard and / or a controller or joystick or other interaction elements. The behavioral data typically includes information on the actions (in particular presses and releases) performed by means of the various interaction elements. It is not necessary to use specific sensors such as, for example, an accelerometer or a gyroscope. In the case where sensors are available on the game console (accelerometer, gyroscope, etc.), these can be used to enrich the user's behavioral data but are in no way essential for authentication.
[0039] The authentication process mainly comprises 4 phases:
[0040] - A phase 1 of generation of reference behavioral biometric models for reference users;
[0041] - A phase 2 of enrollment of one or more legitimate users comprising training a behavioral biometric model for these legitimate users;
[0042] - A phase 3 during which the trained behavioral biometric model of a user is used to perform continuous authentication during an interaction with an application system;
[0043] - A phase 4 during which the biometric template of a legitimate user can be updated with behavioral data acquired during phase 3.
[0044] In the present description, we will speak indifferently of behavioral model, behavioral biometric model to designate a behavior model of a given user, whether trained or not. We will use the term biometric template to designate the trained behavioral biometric model.
[0045] The reference users can be any users and / or legitimate users who are different from the target legitimate user (the one whose model we want to train or who we want to authenticate).
[0046] An imposter user corresponds to a user using another user's user account to play. In the context of this document, we are interested in the case of a user to be authenticated, which can be an imposter user seeking to simulate the behavior of the owner of the account to avoid being unmasked or the legitimate user, owner of the user account used for the interaction session.
[0047] The user to be authenticated may also be a cheating user, using different cheating methods allowing, for example in a video game, the rules of the game to be modified to obtain an unfair advantage during a game or an experience.
[0048] [Fig.l] presents a block diagram illustrating phase 1 of constituting discriminating reference behavioral models for reference users. The reference behavioral models (more precisely, the coefficients of these reference behavioral models) are stored in a database, called reference base 190.
[0049] This reference base 190 contains the raw behavioral data acquired for the reference users, the behavioral characteristics extracted from this raw data as well as the biometric templates of the reference users (more precisely, the coefficients of these reference biometric templates).
[0050] The phase of constituting the reference base 190 may comprise the following steps.
[0051] During step 110, raw behavioral data is collected during the game sessions carried out by any users called reference users. These may be legitimate users having an account and using the application system in real conditions.
[0052] These raw behavioral data correspond to a set of events representative of the interaction actions with the application system (here the video game) carried out by the user by means of one or more interaction devices (here also called user interface devices).
[0053] These interaction actions generate input data for the application system via a user interface of this application system. The raw behavioral data can be collected either during a time interval of predefined duration, or so as to obtain a minimum number of events (for example, 200, 300, 500 events).
[0054] These events correspond for example to the pressing and releasing of the different buttons, to the movements made with the joystick or a wheel, etc. Each event can be described by one or more descriptive parameters. For example for each button, a button press can be described by the duration of the press, the pressure force on the button, the rising or falling edge of the pressure variation curve, a time of start of press, a time of release of press, etc. For a joystick, the starting position, the release position, the distance traveled, etc. can be used.
[0055] The collected raw behavioral data may be preprocessed in a step 115 (typically including cleaning, for example by removing noise or inconsistent data). The raw behavioral data is stored in the reference database 190.
[0056] During step 120, in order to generate a biometric template specific to each user, the raw behavioral data collected or possibly preprocessed during step 115 are analyzed in order to extract values of characteristic parameters (“features” according to English terminology) of the user's behavior. We will also speak here of behavioral characteristics.
[0057] These characteristic parameters are, for example, statistical parameters determined over a time interval from one or more descriptive parameters of the detected events. Examples of statistical parameters include: minimum, maximum, average, standard deviation, frequency, periodicity, etc.
[0058] These characteristic parameters are determined for each of the time intervals of a succession of time intervals. A time interval can have a duration ranging from 0.1 s to 3 s. It is also possible to group the events into sequences of at least N events and to determine the values of the parameters characteristics for each sequence so that the statistical values calculated for the behavioral characteristics are meaningful. For example, we calculate values of the characteristic parameters for the first N events, then for the next N, and so on. For example, N=20, 30, 50, 100 is the number of events per sequence.
[0059] The following training step 130 may only be carried out when a minimum number G of event sequences and the corresponding characteristic parameter values have been obtained. For example G= 5, 10, 20, 30, 50.
[0060] The values of the characteristic parameters thus obtained are stored in the reference base 190.
[0061] In step 130, biometric templates of the reference users are generated by training a behavioral model from the values of the characteristic parameters obtained in step 120. For each reference user, a biometric template (a trained behavioral model) specific to this reference user is generated using a machine learning algorithm for training the model. A trained behavioral model specific to a reference user will be referred to as a 'reference model'.
[0062] A behavioral model of a user is configured to receive characteristic parameter values as input and generate a score as output. The score is representative of a probability that the behavior represented by the input characteristic parameter values is that of the user associated with the behavioral model. The value of this score can be normalized, for example between 0 and 1. By convention, it is agreed in this document that the higher the score, the higher the probability.
[0063] Different types of machine learning algorithms (supervised, unsupervised, semi-supervised, reinforcement, etc.) can be used to generate a behavioral model: for example, a neural network, a random forest (Random Forest), a boosting algorithm (for example XGBoost, Extreme Gradient Boosting), a support vector machine (SVM, Support Vector Machine), a hidden Markov model (HMM, Hidden Markov Model), etc.
[0064] Different training methods can be used, for example: supervised methods whose data are labeled or tagged (known classes), unsupervised methods (unlabeled data), semi-supervised methods (labeled and unlabeled data). In the example of the supervised method used here, the training is done with data from the legitimate user verifying the hypothesis “the user is legitimate” and data from reference users (different from the target legitimate user) verifying the opposite hypothesis “the user is not legitimate”. The data from the target legitimate user are therefore labeled “legitimate” and the reference user data is labeled “non-legitimate” in order to train the model to differentiate between the two classes (the behavior of the target legitimate user and that of an unknown user) and predict the correct class.
[0065] During step 140, a selection of the reference users is carried out so as to retain only reference users whose behavior is very discriminating with respect to the other reference users who are stored in the reference base 190.
[0066] Different statistical analysis methods can be used for this purpose.
[0067] This selection is carried out for example through a statistical analysis with cross-validation, by measuring each time the rates of false positives and false negatives.
[0068] This cross-validation may consist of comparing the reference users 2 by 2, for example by calculating a cross-score for a behavioral model of a given user A by providing as input to this behavioral model characteristic parameter values obtained for another user B. We then identify the users whose behavioral model generates a false positive rate (score rate above a threshold) that is too high and / or then the users whose cross-score is always below a threshold.
[0069] During step 150, all the data of the reference users whose behavioral model is not sufficiently discriminating are deleted from the reference base 190, so that these users will not be part of the definitive reference base (raw behavioral data, characteristic parameters of the behavior and biometric templates) which will be used in particular in phases 2 and 3 because their behavior was not established as sufficiently discriminating during step 140.
[0070] The reference users selected in this way can be any users and / or legitimate users. These are users with behavioral models that are not very sensitive and resistant to the behavior of imposter or unknown users.
[0071] [Fig.2] presents a block diagram illustrating phase 2 of enrollment of one or more legitimate users. This phase includes the training of a behavioral biometric model for these legitimate users and the creation of a database of legitimate users, also called the legitimate user database 290.
[0072] This base of legitimate users 290 includes the raw behavioral data acquired for the legitimate users, the values of the behavioral characteristics extracted from this raw data as well as the biometric templates of the legitimate users (more precisely, the coefficients of these biometric templates).
[0073] For each legitimate user, the enrollment steps may include the steps following.
[0074] During step 210, raw behavioral data is collected during the gaming sessions carried out by this legitimate user. This step is similar to step 110 described above but is carried out during gaming sessions carried out by this legitimate user.
[0075] The collected raw behavioral data may undergo preprocessing during a step 215, similar to that of step 115. The raw and preprocessed behavioral data are stored in the legitimate user database 290.
[0076] During step 220, in order to generate a biometric template specific to each legitimate user, the raw behavioral data collected during step 210 or preprocessed data obtained in step 215 are analyzed in order to extract therefrom parameter values characteristic of the behavior of this user. This step is similar to step 120 described above for the reference users, in particular the same characteristic parameters can be used as for the reference users. The characteristic parameter values are stored in the legitimate user database 290 to be used in step 230 but also later in phase 4 for updating the biometric template of the legitimate user following successful authentication.
[0077] During step 230, a biometric template of the legitimate user is generated. This step uses the characteristic parameters of the legitimate user, generated in the previous step 220, but also the characteristic parameters of the reference users obtained in step 120 and stored in the reference user database 190. The characteristic parameter values of the reference users of this database constitute a reduced set representative of behaviors allowing faster training than using characteristic parameter values for all the other users.In order to train the behavioral model to differentiate a relevant target legitimate user from another user (whether another legitimate user, an imposter or an unknown user) and in order to ensure that the training data is balanced, as many characteristic parameters of the reference users as characteristic parameters of the legitimate user are used for training the model of the legitimate user.
[0078] The biometric template is obtained by training a behavioral model based on a machine learning algorithm.
[0079] The same type of behavioral model is used for the reference users and with the same training method except that the behavioral model of a target reference user A is trained with the characteristic parameters of the reference user A (which represent the class of the legitimate user) and the characteristic parameters of the other reference users (which represent the class of illegitimate users).
[0080] During step 240 the biometric template of the legitimate user is stored in the legitimate user database 290 in order to be used later in authentication phase 3.
[0081] [Fig.3] shows a block diagram illustrating phase 3 of user authentication. This phase aims to authenticate any user (legitimate or not) using a user account for which a biometric template has been previously obtained for its legitimate owner during phase 2.
[0082] The user to be authenticated may therefore be the legitimate user, i.e. the owner of the user account used. This may be an imposter user, fraudulently using this user account and any associated means of payment, for example to avoid paying himself. It may also be a user who has obtained (fraudulently or not) the login data for this user account and is using this account to play, with or without the agreement of the owner of the user account. It may also be a user (for example a child or a friend) who does not have the login data for a user account but who, after connection by the owner of the user account, is authorized to use this user account to play.
[0083] This authentication can be carried out continuously, throughout the interaction session with the application system (here the game), by comparing its biometric behavior with that of the legitimate user, who is the owner of the user account via which the user to be authenticated interacts with the application system.
[0084] Phase 3 of user authentication may include the following steps.
[0085] During step 310, raw behavioral data is collected during the interaction with the application system carried out by the user to be authenticated. This step is similar to step 110 described above but is carried out during the current interaction session.
[0086] The collected raw behavioral data may undergo preprocessing during a step 315, similar to that of step 115. The raw and preprocessed behavioral data are stored in a temporary database, also called temporary database 390.
[0087] This temporary base 390 includes the raw behavioral data acquired for the users to be authenticated and the values of the behavioral characteristics extracted from this raw data, as well as the values of the authentication scores obtained on the basis of these values.
[0088] During step 320, the raw behavioral data collected during step 310 or preprocessed during step 315 are analyzed in order to extract values from them. characteristic parameters of the behavior of this user. This step is similar to step 120 described above for the reference users, in particular the same characteristic parameters can be used as for the reference users. The values of the characteristic parameters are stored in the temporary base 390 to be used in the following steps 330A, 330B, 340 but also during phase 4 for updating the biometric template of the legitimate user in the event of successful authentication with a sufficiently high level of confidence at the end of phase 3.
[0089] During a step 330A, the values of the characteristic parameters obtained in step 320 are tested against the biometric template obtained during phase 2 for the legitimate user, owner of the commonly used user account. For this purpose, the values of the characteristic parameters are provided as input to the biometric template of the legitimate user so as to obtain a first output score. This first score represents a probability that the user to be authenticated is the legitimate user.
[0090] During a step 330B, the values of the characteristic parameters obtained in step 320 are tested against the biometric template obtained during phase 1 for each of the reference users having the most discriminating behavioral models selected at the end of step 150. For this purpose, the values of the characteristic parameters are provided as input to the biometric template of each reference user so as to obtain output scores. Each of these scores (also called here 'second scores' or 'reference scores') represents a probability that the user to be authenticated is the reference user associated with the behavioral model used to generate the score.
[0091] In step 340, the scores obtained in steps 330A and 330B respectively are analyzed to make an authentication decision, i.e. to determine whether or not the user to be authenticated is the legitimate user. Different methods can be used to combine these scores to make the authentication decision.
[0092] An authentication threshold is defined for all scores. This score may be equal to, for example, 0.5 or 0.6 or 0.7 or 0.75 or 0.8. The authentication threshold may be set based on several parameters such as a desired security level, the level of risk associated with illegitimate use of a user's account, etc.
[0093] If the first score obtained in step 330A during the comparison with the legitimate user is lower than the authentication threshold, the behavior is considered to be different from that of the legitimate user and the user to be authenticated is not recognized as being the legitimate user (authentication failure).
[0094] If the first score obtained in step 330A during the comparison with the user legitimate user is greater than the authentication threshold and one or more reference scores obtained in step 330B during comparisons with the reference users are greater than the authentication threshold, the behavior is considered to be that of an unknown user and the user to be authenticated is not recognized as being the legitimate user (authentication failure).
[0095] If the comparison score with the legitimate user is greater than the authentication threshold and none of the reference scores obtained in step 330B during the comparisons with the reference users is greater than the authentication threshold, the behavior is considered to be that of the legitimate user and the user to be authenticated is recognized as being the legitimate user (authentication successful).
[0096] Cases of equality of a score with the authentication threshold can be treated as cases where the score is lower than the authentication threshold or as cases where the score is higher than the authentication threshold.
[0097] Alternatively, an integer N is defined strictly greater than 1, for example less than 10 (for example N=2 or 3 or 5) and the authentication decision is taken as follows: - if the first score obtained in step 330A is lower than the authentication threshold, the authentication fails; - if the first score is greater than the authentication threshold and less than N reference scores are greater than the authentication threshold, the authentication is successful - if the first comparison score with the legitimate user is higher than the authentication threshold and N or more reference scores are higher than the authentication threshold, authentication fails.
[0098] Steps 310 to 340 of authenticating a user may be repeated continuously throughout the interaction session with the application system, for example periodically, the characteristic parameter values being calculated in this case for a time interval of given duration and / or for a minimum number of interaction events detected. This makes it possible to have an authentication decision available at any time during the course of an interaction session and to detect a possible change of user during the interaction session.
[0099] This repetition also makes it possible to detect the temporal sequence of several positive authentication decisions (successful authentication) in a row (without time interval with authentication failure) obtained respectively during several steps 340 and to base the final authentication decision (step 350) on a set of authentication decisions obtained independently for distinct time intervals.
[0100] By basing the final authentication decision in step 350 on several decisions intermediate authentication decisions obtained in step 340, a stronger authentication level can be provided, corresponding to a higher security level if, for example, the final authentication decision obtained in step 350 is positive at a given time only if all the intermediate authentication decisions obtained for time intervals included in a time period preceding this time are also positive.
[0101] This repetition can also be exploited in order to add a bonus / penalty mechanism which modifies the current prediction over a given time interval based on previous intermediate authentication decisions over previous time intervals.
[0102] A positive or negative weight P is added to the score depending on whether a bonus or a penalty is to be applied. This weight P is continuously updated during the interaction session based on the scores obtained. The weight is initialized to 0 at the start of the interaction session. It is also reset to 0 after a period of inactivity of the user to be authenticated. The weight has a minimum value Pmin and a maximum value Pmax that it cannot exceed under any circumstances, for example Pmin = -0.5 and Pmax = 0.2.
[0103] The mechanism may be as follows for each newly obtained authentication score in step 330A for a given time interval: - If one of the reference scores is higher than the authentication threshold, a negative increment (penalty, equal for example to Pl=-0.1) is applied to the weight: P= P+Pl; - Otherwise, if the first score produced by the legitimate user's model is higher than the authentication threshold, a positive increment (bonus equal for example to P2=+0.01) is applied to the weight: P= P+P2;
[0104] The first score obtained for a given time interval in step 330A is thus modified by adding the current value of the weight to obtain the score used for the authentication decision in step 340, this modified score being compared to the authentication threshold.
[0105] This makes it possible to make predictions at a given time more precise by adding, in the decision-making process, additional information linked to the behavioral data of previous predictions.
[0106] [Fig.4] shows a block diagram illustrating phase 4 of updating the biometric template of a legitimate user.
[0107] This update of the biometric template of a legitimate user is carried out in the event of successful authentication with a sufficiently high level of confidence during phase 3 (intermediate authentication decision in step 340 or final authentication decision in step 350). This makes it possible to adapt to a possible evolution of the legitimate user's behavior over time and to have a biometric template very close to their behavior. The behavioral biometric template update phase may include the following steps.
[0108] During step 410, at the end of the interaction session (end of a game session, for example), all the authentication decisions (intermediate and final) obtained during step 340 and possibly step 350 are stored in the temporary base 390 and analyzed.
[0109] In step 420, if the confidence level of the authentication decisions during the session is sufficiently high (greater than a certain threshold set beforehand), the data stored in the temporary database 390 (raw collected data and the extracted characteristic parameter values) are then transferred to the legitimate user database 290. The confidence level can be evaluated in different ways. The confidence level can be equal to the minimum authentication score produced by the legitimate user's model during their entire session. The confidence level is then compared to a threshold set beforehand to determine whether or not step 430 is executed.
[0110] During step 430, if the determination in step 420 is positive, the update of the biometric template of the legitimate user is carried out. During this step 430, the biometric template of the legitimate user is recalculated taking into account the new values of the extracted characteristic parameters which have just been added to his profile. The behavioral model of the legitimate user is entirely retrained as in step 230 but taking into account the new values of the characteristic parameters which have just been added to his profile. Alternatively, some of the old values of the characteristic parameters can be deleted (in order to keep only the most recent data and avoid scalability problems and the storage of large quantities of data) before retraining the model.
[0111] In the context of the application of the invention to video games, the user's behavior may depend on the video game or the type of video game. To enable reliable prediction, it is possible to train a behavioral model specific to each video game or each type of video game. The specific behavioral model is then used for the authentication of a legitimate user.
[0112] Furthermore, from one or more behavioral models specific to one or more games of a user, a meta-model can be generated for a given user which can serve as a starting point for training a new behavioral model specific to a given game. To generate this meta-model, the data of a legitimate user collected on different games without distinction as well as his navigation data in the menus of the games and / or the game console can be used as well as the data of the reference users on all games without dis ting with their navigation data by applying one of the training methods described previously.
[0113] [Fig.5] represents a general flowchart of a method of behavioral biometric authentication of a user interacting with an application system by means of at least one interaction device.
[0114] The application system is for example a video game system. The behavioral biometric authentication method can be implemented by a corresponding behavioral biometric authentication device comprising means for implementing this method, this device being interconnected with the application system.
[0115] During a step 510, behavioral models of reference users are obtained. The behavioral models of the reference users may be the most discriminating behavioral models among a set of behavioral models of reference users. The reference users are for example any users, different from the legitimate user. These behavioral models or biometric templates may be obtained as described with reference to [Fig.l].
[0116] In a step 520, a behavioral model of a legitimate user is obtained. This behavioral model or biometric template can be obtained as described with reference to [Fig.2].
[0117] During a step 530, parameter values characteristic of the user's behavior calculated from events produced by the user's interaction with the interaction equipment are obtained. These characteristic parameter values can be obtained as described with reference to [Fig.3].
[0118] During a step 540, a first score is determined by applying the behavioral model of the legitimate user to the values of the characteristic parameters. The first score represents, for example, a probability that the user is the legitimate user.
[0119] During a step 550, second scores are determined by applying each of the behavioral models of the reference users to the values of the characteristic parameters. Each second score may represent a probability that the user is the reference user associated with the behavioral model used to generate the relevant score.
[0120] In a step 560, a decision to authenticate the user as the legitimate user is made based on the first score and the second scores. The authentication decision may be negative if the first score is less than an authentication threshold. The authentication decision may be negative if the first score is greater than an authentication threshold and at least one of the second scores is greater than the authentication threshold. The authentication decision can be positive if the first score is greater than an authentication threshold and all second scores are less than the authentication threshold.
[0121] Alternatively, an integer N strictly greater than 1 is defined. For example N is less than or equal to 10. For example N=2, 3 or 5. The authentication decision is: - negative if the first score is less than the authentication threshold; - positive if the first score is greater than an authentication threshold and less than N second scores are greater than the authentication threshold; - negative if the first score is greater than an authentication threshold and at least N or more second scores are greater than the authentication threshold.
[0122] For steps 540, 550 and 560, details of embodiment described for example with reference to [Fig.3] (in particular steps 330A, 330B, 340) can be used.
[0123] [Fig.6] schematically represents a system 600 including a behavioral biometric authentication device according to an exemplary embodiment.
[0124] The system includes several user equipments T1, T2, T3 used by respective users Ul, U2, U3. The user equipments T1, T2, T3 communicate by means of an application through at least one communication network with an application system 610, for example a video game server 610.
[0125] Interaction with the video game can be done by means of the user interface of one of the user equipments T1, T2, T3 or by means of interaction equipment dedicated (not shown) to the game (joystick, dedicated gaming keyboard, wheel, console, etc.).
[0126] A behavioral biometric authentication device 620 is operatively connected with this video game server 610 and comprises means for implementing a behavioral biometric authentication method according to what is described in this document.
[0127] This behavioral biometric authentication device 620 accesses one or more databases, comprising for example a reference base 190 for reference users, a base 290 of legitimate users and a temporary base 390 for users to be authenticated, according to what has been described in this document, for example with reference to FIGS. 1 to 5. Applications
[0128] The behavioral biometric authentication solution described in this document can be used, for example, to enable continuous strong authentication during the running of a video game so as to validate (possibly automatically or after confirmation by the user holding the user account) the execution of a payment transaction following a positive authentication decision, without the user needing to enter authentication data or use equipment other than the interaction equipment (console) with the game. video.
[0129] The authentication solution can also be used to perform parental control to protect children, or to unlock user accounts on game consoles (the account can be automatically locked if the behavior is not that of the legitimate user).
[0130] Experimental results in the field of video games.
[0131] Tests were carried out with a set of approximately 200 to 250 behavioral characteristics based solely on buttons and joysticks but without using raw data from gyroscopic or other sensors.
[0132] The length N of the event sequences can be varied in order to obtain more precise statistical characteristics.
[0133] After training with a random forest with these features, we were able to achieve an Equal Error Rate (EER) of only 0.3%. EER is the error rate when the False Acceptance Rate (FAR) is equal to the False Rejection Rate (FRR). The authentication threshold for scores was adapted to decrease either FRR (better user experience) or FAR (better security).
[0134] It appears that a single enrollment session (phase 2) may be sufficient to directly authenticate / identify the user during a subsequent game session, but a second enrollment session during which the training of the behavioral model is repeated makes it possible to reduce any risk.
[0135] By using a sliding window of 500 events to obtain a final authentication decision, it is possible to identify the user very accurately and detect a user change within approximately 5 to 10 seconds of gameplay. Identifying the new user may take up to an additional 5 to 10 seconds. This time may be reduced depending on the accuracy requirements of the authentication device.
[0136] The user's behavioral model may be updated with new data to track the user's progress, with a change in behavior often occurring as the user improves at the game.
[0137] Behavioral models also become more robust when trained on different game modes, because the actions performed by the user may be different depending on the game mode. However, it is possible to authenticate a player across these game modes by starting from a behavioral model obtained for a first specific game mode. It is possible to increase the authentication threshold when the game mode changes.
[0138] The reference user base may also be updated to take into account the emergence of new types of behavior among users and identify new reference users with discriminating behavioral patterns.
[0139] Generally speaking, the use of reference models for reference users makes it possible to verify whether the behavior of the user to be authenticated is similar or not to one of these reference users. Thus, instead of using only the behavioral model of the legitimate user, a counter-verification is carried out on the basis of the reference models.
[0140] Comparison of the performance indicators of a basic method, without reference users, with the method described here using reference users.
[0141] The performance indicators used are the false negative rate and the false positive rate. The experiments are carried out on the same test set with the same users to generate the biometric templates for each user. To carry out the experiment, 12 independent users were used in both cases who played for 2 to 3 game sessions of approximately 10 minutes, i.e. a little over 4 hours of play. Therefore, there is no bias between the basic method and the proposed method except for the use of reference users.
[0142] The confusion matrix obtained for the basic method is as follows:
[0143] [Tables 1] Predicted Class: Legitimate User Predicted Class: Non-Legitimate User Actual Class: Legitimate User 287 (True Positives) 5 (False Negatives) Actual Class: Non-Legitimate User 1906 (False Positives) 16043 (True Negatives)
[0144] The confusion matrix obtained for the method described in this document with reference users is as follows:
[0145] [Tables2] Predicted Class: Legitimate User Predicted Class: Non-Legitimate User Actual Class: Legitimate User 255 (True Positives) 37 (False Negatives) Actual Class: Non-Legitimate User 6 (False Positives) 17943 (True Negatives)
[0146] Comparing the two methods, we obtain the following ratios:
[0147] [Tables3] Baseline Method With Reference Users Ratio on False Negative Rate (%) 1.74% 12.85% Ratio on False Positive Rate (%) 11.88% 0.04%
[0148] To the extent that the authentication system seeks to provide a higher level of security, it is therefore the rate of false positives which mainly interests us (an imposter who manages to pass himself off as the legitimate user).
[0149] The false negative rate increases from 1.74% to 12.85%: this corresponds to a multiplicative factor of 7.4. However, the false positive rate decreases from 11.88% to 0.04%: this corresponds to a division factor of 297.
[0150] Thus the system with reference users effectively provides a much higher level of security, while maintaining the same authentication threshold.
[0151] With regard to the false negative rate, it can be shown that the use of a weighting of the score by a bonus / penalty system described in this document allows the reduction of the false negative rate due to the fact that a temporal succession of several scores is used.
[0152] Figures 7 and 8 show the variation over time over a period of approximately 400 seconds of the authentication score with and without bonus / penalty. These figures illustrate the improvement in the score (between 0 and 1) obtained by weighting with a bonus / penalty system. The horizontal line on the graphs corresponds to an authentication threshold arbitrarily defined at 0.5 for the experiment.
[0153] The temporal evolution of the final score over a game session of a legitimate user by applying the reference user method without a bonus / penalty system is illustrated in [Fig.7]. Several peaks are observed during which the score value is below the threshold, thus leading to false negatives during these periods.
[0154] Using the bonus / penalty system to weight the final score, we observe in [Fig.8] that the score remains above the authentication threshold, which makes it possible to avoid the occurrence of false negatives with this value of the authentication threshold. This bonus / penalty system therefore reduces the rate of false negatives. It can therefore be used to correct a negative authentication decision.
[0155] Each of the phases 1 to 4 described corresponds to a method that can be implemented independently of the other methods. Each of the steps of the different phases described can also be part of a biometric authentication method. behavioral, one or more or all of the steps of the different phases being able to be combined in various ways for the implementation of this behavioral biometric authentication process.
[0156] In describing the various phases and methods for behavioral biometric authentication, although the steps are described sequentially, those skilled in the art will understand that certain steps may be omitted, combined, performed in a different order and / or in parallel.
[0157] One or more or all of the steps of one or more methods described in this document may be implemented by software or computer program and / or by hardware, for example by circuit, programmable or not, specific or not.
[0158] The functions, steps and methods described in this document may be implemented by software (e.g., via software on one or more processors, for execution on a general purpose or special purpose computer) and / or be implemented by hardware (e.g., one or more electronic circuits, and / or any other hardware component).
[0159] The present description thus relates to a software or computer program, capable of being executed by a host device (for example, a computer) serving as a behavioral biometric authentication device, by means of one or more data processors, this software / program comprising instructions for causing the execution by this host device of all or part of the steps of one or more methods described in this document. These instructions are intended to be stored in a memory of the host device, loaded and then executed by one or more processors of this host device so as to cause the execution by this host device of the method.
[0160] This software / program may be coded using any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0161] The host device may be implemented by one or more physically distinct machines. The host device may generally have the architecture of a computer, including components of such architecture: data memory(s), processor(s), communication bus, hardware interface(s) for connecting this host device to a network or other equipment, user interface(s), etc.
[0162] In one embodiment, all or part of the steps of the behavioral biometric authentication method or of another method described in this document are implemented by a behavioral biometric authentication device provided with means for implementing these steps of this method.
[0163] These means may include software means (for example, instructions of one or more components of a program) and / or hardware means (for example, data memory(ies), processor(s), communication bus, hardware interface(s), etc.).
[0164] These means may comprise, for example, one or more circuits configured to execute one or more or all of the steps of one of the methods described herein. These means may comprise, for example, at least one processor and at least one memory comprising program instructions configured to, when executed by the processor, cause the device to execute one or more or all of the steps of one of the methods described herein.
[0165] Means implementing a function or a set of functions may correspond in this document to a software component, a hardware component or a combination of hardware and / or software components, capable of implementing the function or the set of functions, according to what is described below for the means concerned.
[0166] The present description also relates to an information medium readable by a data processor, and comprising instructions of a program as mentioned above.
[0167] The information carrier may be any hardware means, entity or device, capable of storing the instructions of a program as mentioned above. Usable program storage media include ROM or RAM memories, magnetic storage media such as magnetic disks and magnetic tapes, hard disks or optically readable digital data storage media, or any combination of these media.
[0168] In some cases, the computer-readable storage medium is not transient. In other cases, the information medium may be a transient medium (e.g., a carrier wave) for the transmission of a signal (electromagnetic, electrical, radio, or optical signal) carrying the program instructions. This signal may be conveyed via a suitable transmission means, wired or wireless: electrical or optical cable, radio or infrared link, or by other means.
[0169] An embodiment also relates to a computer program product comprising a computer-readable storage medium having stored thereon program instructions, the program instructions being configured to cause the host device (e.g., a computer) to implement some or all of the steps of one or more methods described herein when the program instructions are executed by one or more processors and / or one or more programmable hardware components of the host device.
Claims
Claims
1. Method for behavioral biometric authentication of a user interacting with an application system by means of at least one interaction device, the method comprising - obtaining (510) behavioral biometric models of reference users; - obtaining (520) a behavioral biometric model of a legitimate user, the behavioral biometric model of a legitimate user, respectively of a reference user, being configured to receive as input parameter values characteristic of the behavior of the user considered during interaction actions with the interaction device and to generate as output a score representative of a probability that the behavior represented by the input characteristic parameter values is that of the user considered;- obtaining (530) values of parameters characteristic of the user's behavior determined from events produced by actions of interaction of the user with the interaction equipment; - determining (540) a first score by applying the behavioral biometric model of the legitimate user to the values of the characteristic parameters; - determining (550) second scores by applying respectively each of the behavioral biometric models of the reference users to the values of the characteristic parameters; - determining (560) a decision to authenticate the user as being the legitimate user on the basis of the first score and the second scores.;
2. The method of claim 1, wherein the first score represents a probability that the user is the legitimate user.
3. The method of claim 1 or 2, wherein each second score represents a probability that the user is a reference user associated with the behavioral biometric model used to generate the relevant score.
4. A method according to any preceding claim, wherein the steps of determining the first score, the second scores and the authentication decision are repeated for values of pa- characteristic parameters obtained respectively for a temporal succession of time intervals, the method comprising - an update of the current value of a weight for each time interval, the weight being decremented if one of the second scores obtained for this time interval is greater than an authentication threshold, the weight being incremented if the first score obtained for this time interval is greater than the authentication threshold; - the first score obtained for a time interval being modified by adding the current value of the weight after updating for this time interval, the first modified score being used for determining the authentication decision.
5. Method according to any one of the preceding claims, wherein - the authentication decision is negative if the first score is lower than an authentication threshold; - the authentication decision is negative if the first score is higher than an authentication threshold and at least one of the second scores is higher than the authentication threshold; and - the authentication decision is positive if the first score is higher than an authentication threshold and all the second scores are lower than the authentication threshold.
6. Method according to any one of claims 1 to 3, wherein - the authentication decision is negative if the first score is lower than an authentication threshold; - the authentication decision is positive if the first score is higher than an authentication threshold and less than N second scores are higher than the authentication threshold; - the authentication decision is negative if the first score is higher than an authentication threshold and at least N or more second scores are higher than the authentication threshold; N being an integer strictly greater than 1 and less than or equal to 10.
7. A method according to any preceding claim, wherein the reference users are users different from the legitimate user.
8. A method according to any preceding claim, wherein the behavioral biometric models of the reference users are the most discriminating behavioral biometric models among a set of biometric models comprising reference user reports.
9. A method according to any preceding claim, wherein the application system is a video game system.
10. Device comprising means for implementing a method according to any one of the preceding claims.