ELECTRONIC SYSTEM WITH TRIPARTITE AUTHENTICATION BETWEEN A USER, A SENSOR, AND THE ELECTRONIC SYSTEM
The electronic system addresses vulnerabilities in user authentication by using a sensor with a PUF and encryption keys to secure data exchange, ensuring high trust and integrity in emergency situations.
Patent Information
- Application Number
- FR2023003377
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-04-05
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2043-04-05
AI Technical Summary
Existing electronic systems fail to ensure the integrity and security of user authentication data throughout the entire processing chain, making them vulnerable to attacks that modify, inject, or extract sensitive user data.
An electronic system with challenge-response authentication using a sensor equipped with a PUF, where sensor and user authentication are validated through encryption keys shared between a computer and the sensor, ensuring secure data exchange and integrity.
The system provides high trust in emergency situations by preventing attackers from modifying or extracting sensitive data, ensuring data authenticity, confidentiality, and integrity throughout the system's lifecycle.
Smart Images

Figure 00000018_0000 
Figure 00000018_0001 
Figure 00000019_0000
Abstract
Description
Title of the invention: ELECTRONIC SYSTEM WITH TRIPARTITE AUTHENTICATION BETWEEN A USER, A SENSOR AND THE ELECTRONIC SYSTEM TECHNICAL FIELD OF THE INVENTION
[0001] The field of the invention is that of data security, and in particular that of electronic systems equipped with sensors for measuring user authentication of these systems and in which significant security of the processed data is required. STATE OF THE ART
[0002] Embedded electronic systems are increasingly close to users, or even embedded in them, as is the case, for example, with smartwatches, augmented, virtual, or mixed reality glasses, etc. As a result, these systems are likely to measure user-specific parameters that may be considered personal and / or confidential by the user. For example, smartwatches or extended reality glasses can measure physical parameters from which it is possible to extract information, or functions, considered critical or sensitive, such as physiological information that may indicate a state of fatigue, stress, mental or emotional state, or even the user's state of health.The measured parameters can also be used to generate help information or display action or decision-making information that the user must perform, for example, in an emergency situation. In this context, it is important to establish a high level of trust between the user and the information displayed by the system, especially in emergency situations, so that the user has no doubt about the reliability of this information.
[0003] US patent 2017 / 111356 A1 describes an electronic system in which user authentication is ensured by two biochemical measurements compared to databases of measurements previously performed on the user. However, such a system does not offer optimal security for the processed data because it does not guarantee the integrity of the measurements performed throughout the entire processing chain of the electronic system handling these measurements.
[0004] US patent 2019 / 312740 A1 deals with securing sensors based on the use of PUFs (Physical Unclonable Functions). A non-clonable physical PUF (Personal Unique Function) is generated from data from a first calibrated sensor. A second, uncalibrated sensor is also used, and the generated PUF is compared with a database of sensor identification PUFs. The data used to generate the PUF can correspond to physical or chemical signals obtained from the first sensor. This document does not propose a system in which user authentication is secured across the entire operating chain of the system processing the authentication measurements performed. Description of the invention
[0005] The present invention aims to remedy all or part of the disadvantages of the prior art mentioned above, and in particular to propose an electronic system equipped with a user authentication measurement sensor and in which the chain of processing of measurement data intended to be obtained from the user is completely secure.
[0006] To this end, an electronic system is proposed that is configured to perform challenge-response authentication of a user and a sensor, comprising at least:
[0007] - the sensor which is configured to perform at least one authentication measurement of the user and including a PUF;
[0008] - a memory device configured to store at least some data valid user identification and valid sensor identification data intended to be obtained prior to user challenge-response type authentication;
[0009] - a computer configured to communicate with the sensor and the device memory, and to process data intended to be sent by the sensor and the memory device to the computer;
[0010] the electronic system being configured for:
[0011] - implement challenge-response type authentication of the sensor, in which sensor response data is intended to be generated by the sensor's PUF, then
[0012] - when the sensor is authenticated as being valid, that is to say as being the sensor which is intended to perform the user authentication measure(s), implements challenge-response type authentication of the user, during which data intended to be exchanged between the computer and the sensor are encrypted using a first encryption key calculated from sensor challenge data and sensor response data, the first encryption key being intended to be shared between the computer and the sensor.
[0013] The proposed electronic system first authenticates the measuring sensor that will be used to authenticate the user. This sensor authentication uses a unique identifier (UFI) for the sensor to ensure high reliability. After the sensor has been authenticated as valid, the system user is then authenticated using this sensor to perform the authentication measurement(s) on the user. This authentication also uses a first encryption key calculated from the challenge and response data of the sensor obtained during the sensor authentication process. This first encryption key is shared between the computer and the sensor.Thus, the electronic system not only ensures that the authentication measurement is performed on the user by a previously authenticated sensor, but also ensures that the data subsequently exchanged with the sensor during user authentication is done so securely thanks to the first encryption key used.
[0014] Thus, the proposed electronic system makes it possible, for example, to achieve a very high level of trust between the user and the information displayed by the system, particularly in emergency situations, so that the user has no doubt about the reliability of this information.
[0015] The proposed electronic system can notably be used to counter the following threats:
[0016] - an attacker modifying the sensor so that it produces erroneous data;
[0017] - an attacker injecting fictitious data into the electronic system by substituting for the user (the electronic system thinking it is receiving measurements from one user but receiving those from another user or fictitious, falsified measurements) or by taking control of the link between the sensor and the computer to send fictitious data to the sensor (to trigger user authentication by the sensor and, for example, reuse the data in another context) or to the computer (for example, to allow authentication of another user);
[0018] - an attacker extracting confidential data from the sensor and the then exploiting it without the user's knowledge;
[0019] - an attacker modifying confidential data from the sensor to deceive the system.
[0020] In order to guarantee the security of the processed data, the proposed electronic system complies with the rules generally known as CIA rules, which are:
[0021] - guarantee of data authenticity, i.e. guarantee that the data originate from an authenticated device or part of a mutual authentication scheme (the device is authenticated and the device authenticates the user);
[0022] - guarantee of data confidentiality, i.e. that they are not accessible only to authorized persons, and this throughout the entire lifecycle of the system;
[0023] - guarantee of data integrity, i.e. that they are not altered by neither malicious intent, nor through failure.
[0024] The sensor of the electronic system corresponds to a biometric sensor or a sensor coupled to a biometric sensor (for example, a sensor providing complementary information to a biometric sensor from which user-specific information can be extracted, for example, an accelerometer, a gyroscope, etc.) configured to perform at least one measurement of at least one user-specific parameter, that is, to perform a measurement of at least one biochemical and / or biophysical parameter that is not reproducible by another user. For example, the sensor could be a fingerprint sensor.
[0025] The electronic system can be configured to implement, prior to challenge-response authentication of the sensor, sensor and / or user enrollment enabling the retrieval of valid user identification data and valid sensor identification data. For example, sensor enrollment can consist of applying various sensor challenge data to the sensor's PUF input and then storing, in the memory device, the responses generated by the sensor's PUF based on the challenge data applied to the sensor's PUF input. Such sensor enrollment can be implemented, in particular, when the sensor's PUF is of the "strong-PUF" type. Furthermore, user enrollment can consist of performing several user authentication measures and storing the data corresponding to these user authentication measures in the memory device.
[0026] The PUF of the sensor can belong to one of the two main families of PUFs, which are "weak-PUFs" and "strong-PUFs".
[0027] When the sensor PUF is of the "strong-PUF" type, the electronic system can be configured to perform challenge-response type authentication of the sensor by implementing the following steps:
[0028] - retrieval, by the computer, of the sensor challenge data stored in the memory device, then
[0029] - sending, from the computer to the sensor, the sensor challenge data, then
[0030] - sending, from the sensor to the computer, the sensor response data generated by the PUF of the sensor by applying the sensor's challenge data as input to the PUF, then
[0031] - sending the sensor response data from the computer to the memory device, Then
[0032] - comparison of sensor response data and identification data valid sensor, the sensor being authenticated as valid if the sensor response data matches the valid sensor identification data.
[0033] Thus, when the PUF of the sensor is of the "strong-PUF" type, the computer can send a challenge C to the sensor which generates, by its PUF, a response R specific to the challenge C. This response R is then sent to the computer and then to the memory device for comparison with the expected response.
[0034] When the sensor PUF is of the "weak-PUF" type, the electronic system can be configured to perform challenge-response type authentication of the sensor by implementing the following steps:
[0035] - sending, from the computer to the sensor, the challenge data of the sensor corresponding to a request for identification data generated by the sensor's PUF, then
[0036] - sending, from the sensor to the computer, the sensor response data which correspond to the identification data generated by the sensor's PUF, then
[0037] - sending the sensor response data from the computer to the memory device, Then
[0038] - comparison of sensor response data and identification data valid sensor, the sensor being authenticated as valid if the sensor response data matches the valid sensor identification data.
[0039] Thus, if the sensor's PUF is of the "weak-PUF" type, the computer sends the sensor a request for its identification data generated by the PUF (the identification data generated by the sensor's PUF corresponding, for example, to a unique key generated by the PUF or information derived from this key). This identification data is then sent to the computer and then to the memory device to be compared with the sensor's valid identification data.
[0040] The electronic system can be configured to perform challenge-response type authentication of the user by implementing the following steps:
[0041] - retrieval, by the computer, of user challenge data stored in the memory device then
[0042] - sending, from the computer to the sensor, the user challenge data encrypted in using the first encryption key, then
[0043] - user authentication measurement by the sensor using the data of user challenge deciphered, then
[0044] - sending user response data from the sensor to the computer corresponding to the user authentication measurement by the sensor, encrypted using the first encryption key, then
[0045] - sending user response data from the computer to the memory device deciphered, then
[0046] - comparison of user response data and identification data valid user, the user being authenticated as valid if the user's response data matches the user's valid identification data.
[0047] The electronic system can be configured to:
[0048] - calculate, after the challenge-response type authentication of the user, a second encryption key from user challenge data and user response data, the second encryption key being shared between the computer and the sensor, then
[0049] - calculate a third encryption key obtained from the first and second encryption keys and shared between the computer and the sensor, then
[0050] - exchange encrypted data between the sensor and the computer using the third encryption key.
[0051] The electronic system can be configured to implement, periodically or not, and after an initial challenge-response authentication of the user:
[0052] - another challenge-response type authentication of the sensor, in which the sensor response data is intended to be generated by the sensor's PUF, and / or
[0053] - another user challenge-response type authentication, during which The data exchanged between the computer and the sensor is encrypted using the first encryption key or another encryption key calculated from the sensor challenge data and the sensor response data obtained during another sensor challenge-response authentication.
[0054] In a particular configuration, the memory device may include a database remote from the sensor and the computer.
[0055] The sensor and the computer can be part of an electronic device corresponding to a smartphone, or an electronic watch connected to the Internet, or extended reality glasses connected to the Internet.
[0056] The invention also relates to a challenge-response type authentication method for a user, implemented in an electronic system as described above. BRIEF DESCRIPTION OF FIGURES
[0057] Other advantages, purposes and particular features of the present invention will become apparent from the following non-limiting description of at least one particular embodiment of the devices and methods of the present invention, with reference to the accompanying drawings, in which:
[0058] - Fig. 1 is a schematic representation of an electronic system, the subject of the present invention, according to a particular embodiment;
[0059] - [Fig. 2] is a schematic representation of the elements of a sensor of a electronic system, the subject of the present invention;
[0060] - [Fig. 3] is a diagram representing the steps implemented during a authentication of a user by the electronic system, the subject of the present invention, according to a particular embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0061] An example of an embodiment of an electronic system 100 according to a particular embodiment is described below in relation to [Fig.1].
[0062] The system 100 comprises at least the following elements: a computer 102, a sensor 104 and a memory device 106. In [Fig.1], the user is designated by reference 107.
[0063] The calculator 102 corresponds for example to a CPU (“Central Processing Unit”), a microcontroller, an application processor, or any other electronic computing device.
[0064] The sensor 104 is, for example, configured to perform at least one biometric authentication measurement of the user of the system 100 and includes a PUF. This PUF is obtained using one or more electronic components of the sensor 104. Alternatively, the sensor 104 may correspond to a sensor coupled to a biometric sensor (for example, a sensor providing additional information to a biometric sensor from which it is possible to extract user-specific information, for example, an accelerometer, a gyroscope, etc.).
[0065] The sensor 104, for example, comprises several elements as schematically shown in [Fig.2]:
[0066] - a measuring device 108 transforming biophysical information and / or biochemical measurement taken on the user as an analog electrical signal;
[0067] - a digital interface 110 performing the shaping of the analog signal of measurement into a digital signal and ensuring the digital communication of this signal to the computer 102;
[0068] - a volatile memory 112, advantageously secured against attacks physical, which allows the information necessary for the processing, exchange and / or securing of the measurement performed by sensor 104 to be kept temporarily accessible.
[0069] According to a particular embodiment, the sensor 104 can correspond to a biometric sensor such as, for example, a fingerprint sensor.
[0070] The sensor 104 may be part of a device also including the computer 102 and with which the user is intended to authenticate themselves or be authenticated, such as by For example, a smartphone, an internet-connected smartwatch, or internet-connected extended reality glasses.
[0071] According to an advantageous embodiment, the memory device 106 can correspond to a remote database for the sensor 104 and the control unit 102. In this case, the memory device 106 can communicate with the control unit 102 via at least one communication network, for example, the Internet. Alternatively, the memory device 106 can correspond to a local memory forming part of the device comprising the sensor 104 and the control unit 102 and communicating, for example, with the control unit 102 without going through a network external to the device.
[0072] In addition, the computer 102 communicates with the memory device 106 via a confidential link 114, and with the sensor 104 via a confidential link 116. The confidential links 114 and 116 correspond to secure communication channels, wired or wireless, which are protected in terms of confidentiality and integrity.
[0073] A challenge-response type authentication of the user, with prior challenge-response type authentication of the sensor 104 in which the response of the sensor 104 is generated by the PUF of the sensor 104, implemented by the system 100 are described below. Part of the data exchanges carried out during these authentications are schematically represented in [Fig. 3].
[0074] Before performing the authentication of sensor 104, an enrollment of sensor 104 and an enrollment of the user are first implemented.
[0075] When the PUF of the sensor 104 is of the "strong-PUF" type, the enrollment of the sensor 104 is, for example, carried out by sending many different challenge data to the sensor 104 and by recording in the memory device 106 the response data returned by the PUF of the sensor 104 when these challenge data are applied as input to the PUF of the sensor 104. In this case, the enrollment of the sensor 104 can correspond to the construction, in the memory device 106, of a table giving, for each of the different challenge data of the sensor, the expected sensor response data for each of these challenge data.
[0076] When the PUF of the sensor 104 is of the "weak-PUF" type, the enrollment of the sensor 104 can correspond to a memorization, in the memory device 106, of the identification data generated by the PUF of the sensor 104 corresponding for example to a key generated by the PUF or information derived from this key.
[0077] User enrollment is obtained for example by carrying out different measurements by the sensor 104 and by recording in the memory device 106 the response data corresponding to these user authentication measurements.
[0078] The authentication of sensor 104 is then implemented. When the PUF of sensor 104 is of type "strong-PUF", the computer 102 requests the device Memory 106 provides, from among all the stored challenge data of sensor 104 and via the confidential link 114, sensor challenge data, called Cc in [Fig. 3], enabling the implementation of a challenge on sensor 104. This sensor challenge data corresponds, for example, to calibration data with which sensor 104 can perform a reference measurement, or to a measurement of parameters (e.g., defects) specific to sensor 104 during its manufacturing process. The sensor challenge data Cc is then sent by the computer 102 to sensor 104. The sensor challenge data Cc is submitted as input to sensor 104 so that the PUF of sensor 104 generates sensor response data, called Rc in [Fig. 3]. The sensor response data Rc is specific to the sensor challenge data Cc used for the challenge applied to sensor 104.The response data from sensor Rc is sent to the computer 102, which forwards it to the memory device 106. The authenticity of sensor 104 is verified by the memory device 106 by comparing the response data from sensor Rc with the expected response, also called the valid identification data of the sensor, which corresponds to the response data obtained during the enrollment of sensor 102 when these challenge data from sensor Cc were applied as input to the PUF of sensor 104.
[0079] When the PUF of sensor 104 is of the "weak-PUF" type, the control unit 102 sends sensor 104 the challenge data from sensor Cc, which in this case corresponds to a request for identification data generated by the PUF of sensor 104. This identification request is submitted as input to sensor 104 so that the PUF of sensor 104 generates the response data from sensor Rc, which correspond, for example, to a key generated by the PUF or information derived from this key. The response data from sensor Rc is sent from sensor 104 to control unit 102, and then to the memory device 106. The authenticity of sensor 104 is then verified by comparing the response data from sensor Rc with the expected response obtained during the enrollment of sensor 102.
[0080] If sensor 104 is authenticated, the process can continue.
[0081] At this stage, a first encryption key, called Kc in [Fig. 3], is calculated, for example with a condensate function h taking as parameters the challenge data of the sensor Cc and the response data of the sensor Rc. This condensate function performs, for example, a concatenation of the data Cc and Rc and a condensate function, for example, of the SHA-256 type. In [Fig. 1], the secure link formed between the computer 102 and the sensor 104 and using the first encryption key Kc is symbolically designated by reference numeral 118. Thus, after the authentication of the sensor 104, the data exchanges between the sensor 104 and the Calculator 102 can be performed through the secure link 118 instead of the confidential link 116.
[0082] After authentication of sensor 104, user challenge-response type authentication is implemented, during which data exchanged between computer 102 and sensor 104 are encrypted using the first encryption key Kc shared between computer 102 and sensor 104.
[0083] To this end, the computer 102 retrieves user challenge data, referred to as Cu in [Fig. 3], stored in the memory device 106 and forming part of the valid user identification data obtained previously during user enrollment. For example, in the case of a sensor 104 corresponding to a fingerprint sensor, the user challenge data may correspond to a signal that triggers the illumination of the user's finger by the sensor 104. The Cu data is then transmitted to the sensor 104 using the secure link 118, i.e., by encrypting this data with the first encryption key Kc. In [Fig. 3], the Cu data encrypted with the key Kc is referred to as Ekc(Cu). The sensor 104 decrypts the received message to reconstruct the unencrypted CG data.An authentication measurement of user 107 by sensor 104 is then performed, and the user's response data, called Ru in [Fig. 3], corresponding to the authentication measurement of user 107 by sensor 104, is sent from sensor 104 to the computer 102. For this transmission, the data R( is encrypted using the first encryption key Kc, this encrypted data being called EKC(Ru) in [Fig. 3]. The data R( is decrypted by the computer 102, then transmitted to the memory device 106 and compared with the expected response data, i.e., the valid user identification data. The user is authenticated as valid if the data R( matches the valid user identification data.
[0084] After challenge-response authentication of the user, a second encryption key Ku can be calculated from the user's challenge data Cu and the user's response data RG, for example with the hash function h taking the Cu and RG data as parameters. Thus, the computer 102 and the sensor 104 share a key Kc specific to the sensor / computer pair and a key KG specific to the user / computer pair.
[0085] A third encryption key K can then be calculated from the first and second encryption keys Kc, KG and shared between the computer 102 and the sensor 104. This third key K is obtained, for example, by performing a hash of the two concatenated keys Kc, Ku, or by performing an "exclusive OR" operation between the two keys Kc, KG. Other ways of calculating the key K are possible. The third The calculated key K can then be used to exchange encrypted data between the sensor 104 and the computer 102, and guarantee the confidentiality of the data in the processing chain of system 100. The key K can be used to encrypt the stored data from the sensor 104, this key K is therefore required to decrypt the encrypted data from the sensor 104.
[0086] In a particular embodiment, the computer 102 can use a correction code to regenerate the encryption key used to encrypt the data exchanged between the sensor 104 and the computer 102 in case of disturbances. For example, a "helper data" element, such as that described in the document by Jeroen Delvaux et al., "Helper Data Algorithms for PUF-Based Key Generation: Overview and Analysis", 2015, can be included between the computer 102 and the sensor 104 to correct the extracted data in case of disturbances.
[0087] In the computer 102, a secure routine can be executed to interface the computer 102 with the sensor 104 and then securely generate the encryption key K. The use of a secure enclave of the "Trust Execution Environment" (TEE) type can thus enable the secure generation, storage, and use of this key. In the sensor 104, a dedicated digital circuit can be integrated into an integrated circuit of the sensor 104 to extract the authentication data and generate the encryption key K, which is stored in an internal register or secure memory of the sensor 104.
[0088] The electronic system 100 can be configured to implement, periodically or not, and after an initial challenge-response authentication of the user:
[0089] - another challenge-response type authentication of sensor 104, in which the sensor response data is intended to be generated by the sensor PUF 104, and / or
[0090] - another user challenge-response type authentication, during which the data exchanged between computer 102 and sensor 104 are encrypted using the first encryption key Kc or another encryption key calculated from the sensor challenge data and the sensor response data generated obtained during said other sensor challenge-response type authentication.
[0091] Thus, the security of the system 100 is improved because the authenticity of the sensor 104 and / or the user is verified again after the first authentication of the user.
Claims
1.
2. Demands Electronic system (100) configured to perform challenge-response authentication of a user (107) and a sensor (104), comprising at least: - the sensor (104) which is configured to perform at least one user authentication measurement (107) and includes a PUF; - a memory device (106) configured to store at least valid user identification data (107) and valid sensor identification data (104) intended to be obtained prior to challenge-response authentication of the user (107); - a computer (102) configured to communicate with the sensor (104) and the memory device (106), and to process data intended to be sent by the sensor (104) and the memory device (106) to the computer (102); characterized in that the electronic system (100) is configured to: - implement challenge-response type authentication of the sensor (104), in which response data from the sensor (104) are intended to be generated by the PUF of the sensor (104), then - when the sensor (104) is authenticated as valid, implement user challenge-response authentication (107), during which data intended to be exchanged between the computer (102) and the sensor (104) are encrypted using a first encryption key calculated from challenge data of the sensor (104) and response data of the sensor (104), the first encryption key being intended to be shared between the computer (102) and the sensor (104). Electronic system (100) according to claim 1, wherein the electronic system (100) is configured to implement,
3.
4. prior to the challenge-response type authentication of the sensor (104), an enrollment of the sensor (104) and / or the user (107) allowing the obtaining of valid identification data of the user (107) and valid identification data of the sensor (104). Electronic system (100) according to any one of the preceding claims, wherein the electronic system (100) is configured to perform challenge-response type authentication of the sensor (104) by implementing the following steps: - retrieval, by the computer (102), of the challenge data from the sensor (104) stored in the memory device (106), then - sending, from the computer (102) to the sensor (104), the challenge data from the sensor (104), then - sending, from the sensor (104) to the computer (102), the response data of the sensor (104) generated by the PUF of the sensor (104) after having applied the challenge data of the sensor (104) as input to the PUF, then - sending, from the computer (102) to the memory device (106), the response data from the sensor (104), then - comparison of the response data of the sensor (104) and the valid identification data of the sensor (104), the sensor (104) being authenticated as valid if the response data of the sensor (104) corresponds to the valid identification data of the sensor (104). Electronic system (100) according to claim 1 or 2, wherein the electronic system (100) is configured to perform challenge-response type authentication of the sensor (104) by implementing the following steps:
5. - sending, from the computer (102) to the sensor (104), the challenge data of the sensor (104) corresponding to a request for identification data generated by the PUF of the sensor (104), then - sending, from the sensor (104) to the computer (102), the response data from the sensor (104) which correspond to the identification data generated by the PUF of the sensor (104), then - sending, from the computer (102) to the memory device (106), the response data from the sensor (104), then - comparison of the response data of the sensor (104) and the valid identification data of the sensor (104), the sensor (104) being authenticated as valid if the response data of the sensor (104) corresponds to the valid identification data of the sensor (104). An electronic system (100) according to any one of the preceding claims, wherein the electronic system (100) is configured to perform challenge-response authentication of the user (107) by implementing the following steps: - retrieval, by the computer (102), of user challenge data (107) stored in the memory device (106), then - sending, from the computer (102) to the sensor (104), the user challenge data (107) encrypted using the first encryption key, then - user authentication measurement (107) by the sensor (104) using the decrypted user challenge data (107), then - sending, from the sensor (104) to the computer (102), user response data (107) corresponding to the user authentication measurement (107) by the sensor (104), encrypted using the first encryption key, then - sending, from the computer (102) to the memory device (106), the decrypted user response data (107), then - comparison of user response data (107) and valid user identification data (107), user (107) being authenticated as valid if user response data (107) matches valid user identification data (107).
6. Electronic system (100) according to any one of the preceding claims, wherein the electronic system (100) is configured to: - calculate, after user challenge-response authentication (107), a second encryption key from the user challenge data (107) and the user response data (107), the second encryption key being shared between the computer (102) and the sensor (104), then - calculate a third encryption key from the first and second encryption keys and shared between the computer (102) and the sensor (104), then - exchange encrypted data between the sensor (104) and the computer (102) using the third encryption key.
7. Electronic system (100) according to any one of the preceding claims, wherein the electronic system (100) is configured to implement, periodically or not, and after an initial challenge-response authentication of the user (107):
8.
9.
10. - another challenge-response type authentication of the sensor (104), in which the response data of the sensor (104) are intended to be generated by the PUF of the sensor (104), and / or - another challenge-response type authentication of the user (107), during which the data exchanged between the computer (102) and the sensor (104) are encrypted using the first encryption key or another encryption key calculated from the challenge data of the sensor (104) and the response data of the sensor (104) obtained during said other challenge-response type authentication of the sensor (104). An electronic system (100) according to any one of the preceding claims, wherein the memory device (106) comprises a database remote from the sensor (104) and the computer (102). An electronic system (100) according to any one of the preceding claims, wherein the sensor (104) and the computer (102) are part of an electronic device (100) corresponding to a smartphone, or an internet-connected smartwatch, or internet-connected extended reality glasses. A challenge-response type authentication method for a user (107), implemented in an electronic system (100) according to any one of the preceding claims, the method comprising the following steps: implementation by the sensor (104) of at least one user authentication measure (107); storage by the memory device (106) of at least valid identification data of the user (107) and valid identification data of the sensor (104) intended to be obtained prior to the challenge-response type authentication of the user (107); communication of the computer (102) with the sensor (104) and the memory device (106), and processing of the data intended to be sent by the sensor (104) and the memory device (106) to the computer (102); implemented challenge-response type authentication of the sensor (104), in which response data from the sensor (104) are intended to be generated by the PUF of the sensor (104), then when the sensor (104) is authenticated as valid, implement user challenge-response authentication (107), during which data intended to be exchanged between the computer (102) and the sensor (104) are encrypted using a first encryption key calculated from challenge data of the sensor (104) and response data of the sensor (104), the first encryption key being intended to be shared between the computer (102) and the sensor (104).