User authentication device.
Patent Information
- Application Number
- FR2023001424
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-02-15
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2043-02-15
Smart Images

Figure 00000015_0000 
Figure 00000016_0000 
Figure 00000017_0000
Abstract
Description
Title of the invention: User authentication device.
[0001] GENERAL TECHNICAL FIELD
[0002] The present invention relates to the field of authentication, and in particular to the context of virtual or mixed reality. More specifically, it concerns a device for authenticating a user, in particular a user of a virtual or mixed reality system.
[0003] STATE OF THE ART
[0004] We know of artificially generated computer environments that can be perceived in virtual reality (or mixed reality, i.e. coexisting with the real world) and in particular the "metaverse" which would be a persistent, shared virtual world, and presented as the future of the internet.
[0005] To interact in such a universe, a user uses a virtual reality (VR) headset, or where appropriate a mixed reality (MR) headset.
[0006] This type of headset typically works by pairing with two controllers (or joysticks), held in each hand by the user. One controller is primarily used for interactivity: it acts as a pointing device and also exposes various mechanical buttons, each assignable to a specific interactivity function, depending on the VR application's selection.
[0007] This type of headset and controllers are also equipped with motion sensors (typically accelerometers), dedicated to vision tracking, hand tracking and management of the physical movement area.
[0008] In some models, the user can alternatively do without the controllers, and use their hands free to interact with the application (for example, there are fixed external cameras that observe their hands).
[0009] In these environments, it is sometimes necessary to obtain proof of consent from the user, and for this to verify their identity, for example for a transaction validation, and in particular for payment (if the user buys an object, real or virtual, in the metaverse).
[0010] Classic techniques such as a PIN code or a password can be used, for example via a paired smartphone, but the headset must be removed and then put back on, which is inconvenient.
[0011] Biometric authentication factors (voice, iris, fingerprint) could enhance these mechanisms in the near or distant future, but they require dedicated acquisition methods (e.g., a fingerprint scanner on the controller), and there is no known implementation. It should be noted that the headsets have eye sensors, but these are limited to the simple function of eye tracking and They are far from having the performance that would allow for iris recognition.
[0012] Alternatively, a natural way to obtain user consent in the virtual space is to ask them to perform a particular gesture. The method is all the more interesting if each user has a characteristic way of performing this gesture (what is called an "identifying" gesture). Application FR2214116 thus provides a reliable, secure, and reproducible identification or authentication solution, particularly for proof of user consent.
[0013] One drawback of this latter solution is that it remains single-factor, and therefore does not allow "strong" authentication, which involves the use of an external device such as a mobile terminal or a physical token.
[0014] In addition to the solution described in application FR2214116, it would therefore be desirable to have a very high security solution which remains also intuitive and easy to implement by the user, for example not necessarily requiring the removal of the VR headset. PRESENTATION OF THE INVENTION
[0015] The present invention therefore relates in a first aspect to a user authentication device, uniquely associated with the user, characterized in that it comprises a circular touch surface for detecting rotational gestures, and is configured to transmit data representative of a sequence of rotational gestures made by the user on said circular touch surface, each rotational gesture being defined by an initial angular position, a final angular position, and a direction of rotation.
[0016] According to advantageous and non-limiting features:
[0017] The device has a disc shape.
[0018] Said circular touch surface extends circularly around a central element.
[0019] Said circular touch surface has at least one touch marker.
[0020] Said circular touch surface has a plurality of touch markers arranged at regular intervals around said central element.
[0021] Said plurality of reference frames consists of a single main reference frame and one or more secondary reference frames different from said main reference frame.
[0022] Each tactile marker is a raised marker.
[0023] The device is suitable for pairing with a user's mobile terminal via short-range wireless communication, in particular Bluetooth.
[0024] The device includes a luminous area arranged around the circular touch surface.
[0025] The luminous area comprises an extended luminous band that illuminates as a rotational movement progresses and / or light sources punctual lights that illuminate with each gesture in the sequence.
[0026] According to a second aspect, the invention proposes a method for authenticating a user, characterized in that it comprises the implementation of steps of: a. Transmission by the authentication device of said user according to the first aspect, to a server, of data representative of said sequence of rotation gestures performed by the user on the circular touch surface; b. Verification by means of data processing of said server, of said data representative of said sequence of rotation gestures performed by the user on the circular touch surface.
[0027] According to advantageous and non-limiting features:
[0028] The verification of step (b) is a comparison of said sequence of rotation gestures performed by the user on the circular touch surface with at least one expected sequence of rotation gestures.
[0029] Step (a) includes a substep (a2) of issuing by the data processing means of the server an invitation to the user to perform said sequence of rotation gestures on the circular touch surface.
[0030] The user is a user of a virtual or mixed reality system connected to the server and comprising means for displaying an immersive space.
[0031] The method includes a step (c) of implementing or not a transaction initiated by said user (in particular in said immersive space) depending on the result of step (b).
[0032] Step (a) includes a substep (al) of receiving by the server's data processing means, a request to validate said transaction, in response to which said invitation to the user to perform said sequence of rotation gestures on the circular touch surface is issued. PRESENTATION OF THE FIGURES
[0033] Other features and advantages of the present invention will become apparent from the following description of a preferred embodiment. This description will be given with reference to the accompanying drawings in which:
[0034] [Fig.1] [Fig.1] is a diagram of a system in which the authentication device according to the invention is used;
[0035] [Fig.2] [Fig.2] represents an example of an authentication device according to the invention;
[0036] [Fig.3] [Fig.3] schematically illustrates how a rotation gesture is defined on said authentication device.
[0037] [Fig.4] [Fig.4] is a flowchart illustrating the steps of an embodiment of a process using the authentication device according to the invention. DETAILED DESCRIPTION
[0038] Architecture
[0039] The present invention relates to a user authentication device 10, preferably a user of a virtual or mixed reality system 1 as represented in [Fig.1], in particular for the implementation of a user authentication method, preferably for a transaction in an immersive space to which the system 1 allows access.
[0040] It should be noted that even though, as will be seen, the present device 10 is particularly effective in virtual / mixed reality, its applications are not limited to this, and that the present device 10 can be used for any user authentication, for example to validate a transaction in a store, to unlock equipment, to access a personal space in an application, etc. In the context of VR, the present device 10 can also be used to sign a contract, transfer rights, or authorize a user's access to a secure virtual room (particularly a personal one).
[0041] Said authentication device 10 is uniquely associated with the user (i.e. it is a personal device) and is advantageously connected to a server 2, which can be confused with system 1, or remote and connected by a network 20 such as the internet network.
[0042] The server 2 has data processing means 21 (typically a processor) and data storage means 22 (memory, for example a hard disk).
[0043] The possible system 1 includes means for displaying said immersive space (i.e. with which the user can interact, and in which he is "immersed"), typically a headset, and means for detecting movement in said immersive space 14, generally controllers (or joysticks) held by the hands and equipped with accelerometers and / or gyroscopes, or alternatively fixed external cameras observing the hands.
[0044] The various equipment of system 1 (for example headset and controllers) are interconnected by wire or wireless means (for example by Bluetooth).
[0045] Said “reality” is either: - virtual, meaning that the said immersive space is completely artificial, or - mixed, meaning only partially virtual, and the said immersive space superimposes a real environment and a virtual environment.
[0046] A mixed reality system 1 generally comprises, in addition to display means 12, a camera filming the real world continuously, the rendering of the display means 12 including virtual elements in this "real" stream. In the remainder of this document, For the sake of convenience, we will use the example of virtual reality, abbreviated "VR", but a person skilled in the art will be able to transpose the environment to mixed reality (MR).
[0047] In a known manner, in all cases, the display means 12 are coupled with the movements of the headset worn by the user so that the display of the immersive environment evolves according to these movements in order to simulate reality. To achieve this, the system 1 generally includes means for detecting the movement of the user's headset 13, for example, accelerometers or cameras, either external, observing the head, or attached to the headset and observing the environment.
[0048] System 1 further includes data processing means 11 such as a processor, implementing applications in said immersive space. For example, in a sports game, the interactivity controller simulates a ball and pressing a button corresponds to kicking the ball.
[0049] Principle
[0050] The present personal authentication device 10 aims to authenticate the user through a sequence of rotating gestures performed by the user on this device 10, referred to as the "authentication sequence," as an alternative, for example, to known techniques such as gesture recognition or code entry. As will be seen, such a sequence allows in practice far more combinations than a PIN code, is very easy to remember, and can be performed intuitively without looking, which is very advantageous for a VR application (no need to remove the headset).
[0051] This authentication is specifically performed to obtain the user's consent within the immersive space (i.e., confirmation). The device can be used at any time when the identity of the person using system 1 may need to be verified. A specific example is transaction validation (if the user purchases an object, real or virtual, within the immersive space).
[0052] By “rotational gesture” is meant a gesture typically of at least one finger (generally one or two fingers) or of the entire hand of the user which corresponds to a rotational movement. As such, the authentication device 10 includes a circular touch surface 100 as seen in the example in [Fig.2].
[0053] Each rotation gesture is defined by an initial angular position, a final angular position, and a direction of rotation. The advantages are numerous: - the number of combinations is very high, much more than for a simple PIN code, and therefore the security is very strong; - rotational movements can be performed with precision, even without looking and therefore while keeping the headset on.
[0054] In a first embodiment called "discrete", there is a plurality of positions predefined angular positions (a number N), and each initial / final angular position is chosen from one of the predefined angular positions. In other words, we have elementary sectors of angular width 360 / N degrees numbered from 1 to N. We then have 2N2 possible gestures (note that a gesture with identical initial and final positions corresponds to a complete turn), and the descriptive data of a rotation gesture is typically a triplet (n, nf, s)e[l;N]x[l;N]x{-l,+l} of the identifiers of the initial and final positions and an indicator of the direction of rotation (2 possible values for clockwise and counterclockwise, here arbitrarily chosen to be -1 and +1). Alternatively, we can simply represent the gesture by a single identifier ie[l;2N2].
[0055] Preferably, we have N>4, and preferably N is chosen from 4, 6, 8 and 12, which allows intuitive divisions of the circle.
[0056] In the example in [Fig. 3], we have N=12, i.e., 12 sectors of 30° numbered from 1 to 12 clockwise, with sector 12 to the north (1 to the NNE, 2 to the ENE, 3 to the East, etc.). There are 288 possible gestures, [Fig. 3] representing the counterclockwise gesture 35 (represented by the triplet (3, 5, -1)). It is understood that there are nearly 7 billion possible sequences of just four of these rotational gestures, which guarantees that it is impossible to find the sequence by chance.
[0057] With only N=4, we already have 32 possible rotation gestures, and a sequence of only two gestures already guarantees more than a thousand combinations.
[0058] According to one embodiment, more than one revolution may be allowed, and the value s then takes a value in Z, with the sign of s indicating the direction of rotation and Is-11 the number of additional complete revolutions. For example: - (3, 5, -2) would correspond to another rotation from 3 to 5 in the an direction tihoraire with a complete circuit completed (i.e., a complete circuit starting from 3 then 3 to 5). - (3, 3, 2) would correspond to two complete clockwise rotations starting from 3 (i.e., rotation complete starting from 3 then 3 to 3 which is a second complete lap).
[0059] By noting T the maximum number of complete turns allowed (i.e. se[-(T+l);+(T+l)]), the number of possible gestures becomes 2(T+1)N2.
[0060] In a second embodiment, referred to as "continuous," there may be no predefined angular positions, and simply the most precise possible measurement of the initial and final angular positions. In other words, the initial and final angular positions can take any possible value.
[0061] Authentication device
[0062] As explained, the authentication device 10 is a device uniquely associated with the user and intended to be connected to a server 2, and on which the user can perform a sequence of rotation gestures.
[0063] The device 10 comprises a circular touch surface 100 for gesture detection rotation, for example in a flexible material such as silicone. It is understood that this touch surface is not a screen.
[0064] With reference to [Fig. 2], the circular touch surface 100 for detecting rotational gestures advantageously extends circularly around a central element 101. In other words, it has a substantially annular shape with the central element 101 at its center, and it is understandable that it is natural to perform a rotational gesture on such a surface. The entire device 10 thus has a disc shape with a housing typically a few centimeters in diameter and about one centimeter thick. The housing can also contain processing means and a battery for the device 10.
[0065] It should be noted that the central element 101 can be a button used in particular to control the device 10, for example to perform an action in the immersive space, but also to turn it on / off (multiple quick presses) or trigger a pairing (long press).
[0066] Indeed, the authentication device 10 can preferably be paired with a user's mobile terminal 3 (in particular via short-range wireless communication, notably Bluetooth) through which it is connected to said server 2, the terminal 3 enabling a connection to the network 20 such as the internet. The device 10 can also be attached to the mobile terminal 3, for example magnetically, which may allow for inductive charging. Alternatively or in addition, the device 10 may include a port, for example USB, notably on the side of the casing.
[0067] The central element 101 may carefully or additionally include an additional biometric identification means, for example a fingerprint sensor.
[0068] In order to guide the gesture, said circular tactile surface 100 for detecting rotational gestures advantageously has at least one tactile marker 102a, 102b, or even a plurality of tactile markers 102a, 102b arranged at regular intervals around said central element 101, i.e., at regularly distributed angular positions. The markers may be physical, in particular raised markers (which may be bumps, indentations, or any textured pattern), or simulated markers, for example with haptic feedback (i.e., a vibration) triggered when the user reaches the position of one of these markers 102a, 102b on the surface 100.
[0069] Thus, the user can directly feel the position of the marker(s) 102a, 102b and therefore position themselves on the surface 100 of the device 10 without needing to look. In the case of several markers, the user knows by feeling them that they have covered a certain angular range and can therefore control their movement for greater precision.
[0070] In a particularly preferred manner, said plurality of reference points 102a, 102b is composed of a single primary marker 102a and one or more secondary markers 102b, distinct from said primary marker 102a, so as to differentiate them. Thus, the primary marker allows for the absolute orientation of the device 10 (by identifying a reference direction, for example, north), and the others allow for control of the rotation gesture. In the example of [Fig. 2], there are physical markers on a circular tactile surface 100, including a primary marker 102a with three prongs, and three secondary markers 102b with a single prong.
[0071] It is noted that the presence of several reference frames 102a, 102b is particularly effective in combination with the embodiment in which there are N predefined angular positions, since the reference frames can be directly associated with some of these predefined angular positions.
[0072] For example, using the configuration with 12 predefined angular positions in [Fig. 3], the markers in [Fig. 2] are respectively associated with positions 12 (primary marker 102a), 3, 6, and 9 (secondary markers 102b). The counterclockwise gesture 35 in [Fig. 3] corresponds to a starting point at the first secondary marker 102b after the primary marker 102a, with the finger moving successively through the primary marker 102a and the two other secondary markers 102b. This is very intuitive for the user.
[0073] In addition, the device 10 may include a luminous area 103a, 103b arranged around the surface 100. This luminous area may include an extended luminous strip 103a (i.e., occupying at least part of the circumference of the surface 100) and / or point light sources 103b
[0074] The light strip 103a can illuminate as a rotational gesture progresses, and a new light source 103b can light up with each gesture in the sequence. Thus, if the user is lost, they can look at the illuminated area 103a, 103b at any time to see where they are and resume the sequence.
[0075] Process
[0076] With reference to [Fig.4], the invention also relates to a method of authenticating a user, using the authentication device 10 according to the first aspect.
[0077] The present method begins with a step (a) of transmission by the authentication device 10 uniquely associated with the user, to the server 2, of data representing a sequence of rotation gestures performed by the user on the circular touch surface 100 of said authentication device 10.
[0078] It is clear that we have strong authentication since we combine a hardware factor (the user proves that they possess a specific authentication device 10, uniquely associated with them) and a memory factor (the sequence of rotating gestures). If server 2 received data representative of a sequence If the user performs rotational gestures on an authentication device other than the one uniquely associated with it, they would be ignored and the authentication would be rejected.
[0079] We speak of a “candidate” authentication sequence as the one performed live by the user (like a code entered on a keyboard) and on the basis of which authentication will be attempted, as opposed to “reference” authentication sequences, in practice the one(s) expected.
[0080] Accordingly, step (a) preferably comprises a substep, denoted (a4), for encoding this candidate sequence of rotational gestures, i.e., generating said data representing said sequence of rotational gestures performed by the user on the circular touch surface 100 from raw data acquired by the device 10, i.e., translating the measured electrical signals into a code such as a vector of k triplets (n, nf, s), where k is the number of gestures in the sequence. Step (a) thus preferably comprises the prior acquisition (a3), by the device 10, of said raw data, while the user performs the gestures.
[0081] In a subsequent step (b), the processing means 21 of the server 2 authenticate said user by verifying said representative data obtained from a candidate rotation gesture sequence (i.e. said representative data of the rotation gesture sequence performed by the user on the circular touch surface 100).
[0082] More specifically, said sequence of rotation gestures performed by the user on the circular touch surface 100 must correspond with at least one expected authentication sequence.
[0083] Advantageously, the expected authentication sequence is the user's reference authentication sequence, i.e. a predefined sequence known (and usually previously chosen) by the user.
[0084] Note that there may be several reference authentication sequences, in particular longer or shorter, corresponding to various possible levels of security.
[0085] For example, authentication before a transaction exceeding a certain amount may require a sequence of four gestures, whereas a simple consent verification may require a single-gesture sequence to prevent accidental user actions. The user may also manually adjust the desired security level.
[0086] Depending on the transaction and / or the security level, a reference sequence is selected as the "expected" sequence and is compared with the sequence of rotation gestures performed by the user on the circular touch surface 100. Note that there may be several alternative expected sequences, in which case a high-security-level sequence can be expected to be valid. lower security level sequence: for example if we were waiting for the simple consent verification sequence (1 gesture) and the user performs the full authentication sequence (4 gestures), then they are authenticated.
[0087] Alternatively, the expected authentication sequence is an authentication sequence generated by server 2 (in particular randomly), and which the user must reproduce, in a "challenge-response" type logic (the expected authentication sequence can be considered as a one-time password, OTP), see later.
[0088] In all cases, regardless of the nature of the expected authentication sequence, the verification is similar.
[0089] According to a first embodiment, typically when there are N possible angular positions, the representative data of these two sequences, i.e. their codes, are directly compared. In this case, there must be an exact match; otherwise, at least one gesture is incorrect.
[0090] According to a second embodiment, typically in the case of continuous angular positions (as opposed to N possible angular positions), a "fuzzy matching" algorithm is used, in particular a classification model capable of calculating a proximity score between the candidate sequence and the expected sequence(s) and comparing this score with an authentication threshold. Indeed, in such a mode it is impossible to reproduce exactly the same sequence, and one simply verifies that the candidate sequence is sufficiently similar to the expected sequence.
[0091] Transaction & Consent
[0092] Preferably, the process takes place within a context of transaction validation, and more specifically of the user's consent to the implementation of said transaction.
[0093] It then advantageously includes a step (c) of implementing or not a transaction initiated by said user in said immersive space depending on the result of step (b), i.e. the result of the verification of the sequence carried out by said user, and therefore his authentication.
[0094] In other words, if the user has performed the expected authentication sequence (meaning that they have indeed given their consent), the verification result is positive and the transaction is implemented. Conversely, if the verification result is negative, it means that either the user did not ultimately give their consent (system 1 may have mistakenly believed, due to user error, that the user wished to implement a transaction) or that a third party attempted to impersonate them by stealing their authentication device 10 (and therefore the user never gave their consent in the first place), and the transaction is not implemented.
[0095] “Transaction” will be understood in a broad sense, that is to say possibly payment but also signing of a contract, transfer of rights, authorization of access to a secure virtual room etc.
[0096] Preferably, step (a) includes a substep (a2) of sending an invitation to said system 1 to perform the candidate rotation gesture sequence. It is understood that this invitation is addressed to the user and is displayed (in any form) by means 12.
[0097] In the "challenge-response" mode, where the expected authentication sequence is one generated by server 2 that the user must reproduce, this expected authentication sequence is advantageously presented to the user in the invitation, for example, in the form of pictograms representing the gestures, as in [Fig. 3]. Thus, the invitation issued is more precisely an invitation to reproduce a given sequence of rotational gestures generated by server 2.
[0098] This invitation can be issued in response to a substep (al) of receiving a validation request for said transaction, received from system 1 or another server in particular of transaction (which may in turn be confused with server 2).
[0099] Typically: - The user wishes to make a transaction in the immersive space, and performs an associated action (such as taking a virtual object) - System 1 communicates with a remote transaction server, indicating that the user wishes to implement a transaction; - The transaction server sends a transaction validation request to server 2, to ensure that the user gives their consent (substep (al)); - In response, server 2 sends an invitation to system 1 to perform the sequence of rotating gestures on the circular touch surface 100 of its authentication device 10 (substep (a2)). It is understood that this invitation is interpreted by the system to be understood by the user, for example by displaying text in the immersive space ("please validate the transaction by performing your sequence of rotating gestures") but also with an audio message, etc. - The user uses their authentication device 10, and the latter acquires the corresponding raw data (substep (a3)); - Device 10 encodes the gestures (substep (a4)), that is, it generates the data representing the sequence of rotational gestures performed by the user on their authentication device 10 candidate to starting from the raw data acquired, and transmitting it to server 2; - Server 2 can then implement the verification of this data representing said candidate rotation gesture sequence, so as to ensure that this candidate authentication sequence coincides with an expected authentication sequence (step (b)); - The transaction is validated if the result of the verification of said data representing a sequence of rotation gestures obtained is that said candidate authentication sequence coincides with the expected authentication sequence (step (c)), and server 2 can notify the eventual transaction server so that the latter can implement the transaction.
[0100] Enrollment
[0101] The method advantageously includes a preliminary enrollment step (aO) to generate said data representative of at least one reference rotation gesture sequence, for use as the expected authentication sequence in the verification of step (b).
[0102] To do this, the user can perform the said sequence of reference rotation gestures on the said authentication device 10 in a controlled environment, i.e. for example after authenticating it via another existing authentication method (biometrics, code, use of smartphone, etc.).
[0103] We thus have a step (A) of transmission by the authentication device 10, said server 2, of data representative of a sequence of rotation gestures made by the user on the circular touch surface 100, which is the counterpart of step (a).
[0104] We can have substeps (A1), (A2), (A3) and (A4) analogous to substeps (A1), (A2), (A3) and (A4) of step (A):
[0105] (A1) receiving a request to enroll at least one sequence of rotation gestures as a reference authentication sequence, for authentication.
[0106] (A2) issuing to said system 1 an invitation to carry out a or several times said sequence of rotation gestures on the circular touch surface 100 of his device 10 (it is understood that here the user chooses his sequence, and it is better to repeat it to be sure that the user is sure that he has not made a mistake).
[0107] (A3) Acquisition of raw data for each sequence performed;
[0108] (A4) Encoding of the reference authentication sequence.
[0109] In a step (B) which is the counterpart of step (b), the verification algorithm is configured, or where appropriate, a possible classification model is trained.
Claims
Demands
1. A user authentication device (10), uniquely associated with the user, characterized in that it comprises a circular touch surface (100) for detecting rotational gestures having at least one touch marker (102a, 102b), and is configured to transmit data representative of a sequence of rotational gestures performed by the user on said circular touch surface (100), each rotational gesture being defined by an initial angular position, a final angular position, and a direction of rotation.
2. Device according to claim 1, having a disc shape, and in which said circular touch surface (100) extends circularly around a central element (101).
3. Device according to claim 2, wherein said circular touch surface (100) has a plurality of touch markers (102a, 102b) arranged at regular intervals around said central element (101).
4. Device according to claim 3, wherein said plurality of markers (102a, 102b) is composed of a single principal marker (102a) and one or more secondary markers (102b) different from said principal marker (102a).
5. Device according to any one of claims 2 to 4, wherein each tactile marker (102a, 102b) is a raised marker.
6. Device according to any one of claims 1 to 5, adapted for pairing with a user's mobile terminal (3) via short-range wireless communication, in particular Bluetooth.
7. Device according to any one of claims 1 to 6, comprising a luminous area (103a, 103b) arranged around the circular touch surface (100).
8. Device according to claim 7, wherein the light area (103a, 103b) comprises an extended light strip 103a which lights up as a rotation gesture progresses and / or point light sources (103b) which light up at each gesture of the sequence.
9. A method for authenticating a user, characterized in that it comprises the implementation of the following steps: a. Transmission by the authentication device (10) of said user according to any one of claims 1 to 8, to a server (2), of data representative of said sequence of rotational gestures performed by the user on the circular touch surface (100); b. Verification by data processing means (21) of said server (2), of said data representing said sequence of rotation gestures performed by the user on the circular touch surface (100).
10. A method according to claim 9, wherein the verification of step (b) is a comparison of said sequence of rotation gestures performed by the user on the circular touch surface (100) with at least one expected sequence of rotation gestures.
11. A method according to claim 10, wherein step (a) comprises a substep (a2) of issuing by the data processing means (21) of the server (2) an invitation to the user to perform said sequence of rotation gestures on the circular touch surface (100).
12. A method according to any one of claims 9 to 11, wherein the user is a user of a virtual or mixed reality system (1) connected to the server (1) and comprising means for displaying (12) an immersive space.
13. A method according to any one of claims 9 to 12, comprising a step (c) of implementing or not implementing a transaction initiated by said user depending on the result of step (b).
14. A method according to claims 11 and 13 in combination, wherein step (a) comprises a substep (al) of receiving by the data processing means (21) of the server (2), a request to validate said transaction, in response to which said invitation to the user to perform said sequence of rotation gestures on the circular touch surface (100) is issued.