Terminal authentication process

The authentication method addresses the lack of physical proximity assurance in existing methods by using distance comparisons between terminals, offering a robust and simple solution for ensuring security in proximity transactions.

FR3155924A1Pending Publication Date: 2025-05-30ORANGE SA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
FR2023013046
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-24
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing authentication methods lack assurance of physical proximity between terminals, are vulnerable to circumvention, and often require complex biometric solutions.

Method used

A method for authenticating a terminal based on its physical distance from another terminal, involving the comparison of measured distances with target distances associated with identification data, which can be used alone or in conjunction with other authentication methods.

Benefits of technology

This method provides a robust and technically simple authentication solution that ensures physical proximity, increases security, and is suitable for proximity transactions such as unlocking physical access or contactless payments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for authenticating a first communicating portable terminal with a second communicating terminal, comprising sending, by the first terminal to the second terminal, an authentication request including identification data, characterized in that it implements the following at the first terminal: - placing oneself (E202) at a distance from the second terminal, - receiving (E204a, E204b) a validation or a non-validation of the authentication in response to a comparison by the second terminal of said distance (DI) with a target distance (DC) associated with said identification data. Figure for the abstract: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for authenticating a terminal Field of invention

[0001] This invention relates generally to the field of terminal security and authentication.

[0002] More specifically, the invention relates to the authentication of a terminal by its position and / or its movements in space with respect to another terminal. Prior art

[0003] Authentication is a classic problem of verifying the legitimacy of access to a system. There are many examples of applications requiring this phase: - Payment via a mobile phone, - Unlocking physical access (badge door, smart lock, etc.), - etc.

[0004] Most of the solutions conventionally used imply that the person wishing to authenticate holds a communicating object, such as a mobile phone or a badge, for example. This object contains a digital signature that said object communicates to the system, by wireless communication for example, and which makes it possible to authenticate the person via verifications relating to this signature, typically, via cryptographic verifications.

[0005] Another authentication solution consists of measuring physiological characteristics of the individual wishing to authenticate, such as the shape of fingerprints, iris, etc.

[0006] Finally, many authentication solutions involve the simple use of a password, or a numerical combination. For example, many locks or padlocks are unlocked by a sequence of 4 to 6 digits known to the user. Similarly, some banking authentication methods require entering an alphanumeric combination, received for example in the form of a message, notably an SMS (Short Message Service) or from a specific application.

[0007] However, these methods do not offer any guarantee as to the physical proximity of the communicating object, which may be a useful verification / security measure, for example for unlocking physical access, and more generally for limiting circumvention of existing security methods.

[0008] Furthermore, despite their complexity, certain devices, in particular those based on biometric sensors, can be circumvented by duplicating the digital data relating to the biometric characteristics, when these are sent between terminals.

[0009] Finally, it should be noted that in many situations, several authentication methods are used jointly. The strengthening of the authentication methods therefore results from the implementation of a new authentication technique as well as from the implementation of said new authentication technique jointly with at least one of the multiple authentication techniques already known to those skilled in the art. Subject matter and summary of the invention

[0010] One of the objectives of the invention is to remedy at least one of the drawbacks highlighted by the aforementioned state of the art and by proposing an authentication method based on the physical distance between two terminals and constituting a new form of authentication, which can be used alone or in conjunction with other existing forms of authentication (password, PIN code, biometric fingerprint, etc.). By physical distance we mean: - the longitudinal distance(s) between two terminals, and / or - the angular distance(s) between a predefined axis of one terminal and a predefined axis of another terminal.

[0011] To this end, an object of the present invention relates to a method for authenticating a first communicating portable terminal with a second communicating terminal, comprising sending, by the first terminal to the second terminal, an authentication request including identification data, characterized in that it implements the following at the first terminal: - position yourself at a distance from the second terminal, - receive a validation or non-validation of the authentication in response to a comparison by the second terminal of said distance with a target distance associated with said identification data.

[0012] This authentication method represents a robust alternative or complement to existing authentication devices. Such an authentication solution, based on the physical presence of the user and / or the terminal being authenticated, and more precisely on a comparison of the distance which physically separates the first terminal from the second terminal, with a target distance associated with identification data of the first terminal, appears to be a technically simple solution to implement while being particularly suitable for proximity transactions, such as unlocking physical access, access to a secure premises or contactless payment.

[0013] According to a particular embodiment, the first terminal receives a validation of the authentication if the second terminal measures at least two distances from the first terminal with respect to the second terminal, corresponding to at least two target distances associated with the identification data of said first terminal.

[0014] Using authentication based on at least two distances at which the first terminal is placed relative to the second terminal advantageously makes it possible to increase the robustness of the authentication devices implementing the method.

[0015] According to another embodiment, the sending of an authentication request is preceded by a registration of the first terminal with the second terminal where a target distance, respectively the at least two target distances, is associated, respectively are associated, with the identification data of the first terminal.

[0016] This embodiment advantageously makes it possible to simplify the initialization of the authentication method. Indeed, the fact of being able to record the target distance, respectively the target distances, by physically positioning the first terminal relative to the second terminal, rather than by a textual indication or by an interface virtualizing the movement of said first terminal, allows the user to more easily understand the authentication method and to retain / understand the target distance, respectively the target distances, associated with the identification data.

[0017] According to another embodiment, the authentication request of the first terminal includes a secondary authentication among any one of the following authentication methods: - sending a secret code, - password, - model / diagram to be reproduced on a screen of the first terminal or a third-party terminal, - sending biometric data - ephemeral code.

[0018] This embodiment advantageously makes it possible to increase the overall robustness of the devices implementing this authentication method.

[0019] According to another embodiment, the reception of a validation of the authentication is associated with a complementary authentication where the first terminal receives from the second terminal an instruction to be carried out in order to finalize the authentication, said instruction requesting to place the first terminal at one or more target distance(s).

[0020] This embodiment advantageously makes it possible to increase the overall robustness of the authentication method by including an instruction, unknown a priori to the user of the first terminal, to be carried out in order to finalize the authentication.

[0021] According to another embodiment, the placement of the first terminal at a distance, respectively several distances, from the second terminal, includes a restitution (by example visual, sound or tactile / vibratory), on an interface associated with the first terminal, of the value of said distance, respectively of said distances.

[0022] This embodiment offers the advantage of limiting unsuccessful authentication attempts, i.e. those resulting in the second terminal not authenticating the first terminal due to a poor estimation of the distances (longitudinal or angular) on the part of the user trying to authenticate. The presentation of the distances in real time at which the first terminal has positioned itself in relation to the second terminal makes it possible to avoid this bias and therefore reinforces the relevance of the method by limiting “false negatives”.

[0023] The invention also relates to a computer program comprising program code instructions for implementing the authentication method according to any one of the particular embodiments described above, when this program is executed by a processor.

[0024] Such instructions can be stored permanently in a non-transitory memory medium of a communication terminal implementing the authentication method according to the invention.

[0025] This program may use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0026] The invention also relates to a recording medium or information medium readable by a computer, and comprising instructions of a computer program as mentioned above.

[0027] The recording medium may be any entity or device capable of storing the program. For example, the medium may comprise a storage means, such as a ROM (Read Only Memory), for example a CD ROM (Compact Disc Read-Only Memory), a synthetic DNA (deoxyribonucleic acid) or a microelectronic circuit ROM, or a magnetic recording means, for example a mobile medium, a hard disk or an SSD (Solid State Drive).

[0028] On the other hand, the recording medium may be a transmissible medium, such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means, so that the computer program it contains is remotely executable. The program according to the invention may in particular be downloaded over a network, for example an Internet-type network.

[0029] Alternatively, the recording medium may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the aforementioned authentication method.

[0030] The invention also relates to a communicating portable terminal configured to be authenticated by a communicating authenticator terminal, said communicating portable terminal being configured to send to the communicating authenticator terminal an authentication request including identification data, said communicating portable terminal being characterized in that it is further configured to implement the following: - position yourself at a distance from the communicating authenticator terminal, - receive a validation or non-validation of the authentication in response to a comparison by the communicating authenticator terminal of said distance with a distance associated with said identification data.

[0031] Such a communicating portable terminal is in particular suitable for implementing the authentication method according to any one of the embodiments described previously.

[0032] The invention also relates to a communicating authenticator terminal configured to authenticate a communicating portable terminal, said communicating authenticator terminal being configured to receive, from the communicating portable terminal, an authentication request including identification data, characterized in that the communicating authenticator terminal is further configured to: - receive, from the communicating portable terminal, a value of a distance at which the communicating portable terminal is placed in relation to the communicating authenticator terminal, - comparing said received distance value with a target distance associated with said identification data, - send to the communicating portable terminal a validation or non-validation of the authentication depending on the result of said comparison.

[0033] The invention also relates to a system for authenticating a first communicating portable terminal with a second communicating terminal, said system comprising: - the aforementioned portable communicating terminal, - the aforementioned communicating authenticator terminal.

[0034] According to an exemplary embodiment, the present technique is implemented by means of software and / or hardware components. In this regard, the term "module" or "interface" may correspond in this document to a software component, a hardware component or a set of hardware and software components. Brief description of the drawings

[0035] Other features and advantages will become apparent upon reading embodiments particular features of the invention, given as illustrative and non-limiting examples, and the appended drawings, among which:

[0036] [Fig. 1a] represents an example of architecture in which the authentication method is implemented,

[0037] [Fig.lb] represents another example of architecture in which the authentication method is implemented,

[0038] [Fig. 1c] represents another example of architecture in which the authentication method is implemented,

[0039] [Fig.2] represents the main actions implemented in the authentication process,

[0040] [Fig. 3] represents an authentication method according to another embodiment of the invention,

[0041] [Fig.4] represents an authentication method according to another embodiment of the invention,

[0042] [Fig. 5] represents an example of a portable communicating terminal according to an embodiment of the invention,

[0043] [Fig.6] represents an example of a communicating authenticator terminal according to an embodiment of the invention. Detailed description

[0044] Description of an example of architecture in which the authentication method is implemented

[0045] With reference to [Fig. 1a], an example of architecture is described in which the authentication method according to the invention is implemented.

[0046] This architecture includes: - a first communicating portable Tl terminal, for example a smartphone or a connected object equipped with an RFID tag (“radio frequency identification” in English), - a second communicating authenticator terminal T2, for example a wifi station or a connected lock.

[0047] The two terminals T1 and T2 are connected to a network R allowing the sending of information from one to the other of the terminals as well as, according to another embodiment, the connection of the terminal T1 and / or the terminal T2 to at least one third-party terminal (not shown in the figure).

[0048] The network R allows the first terminal T1 to send an authentication request to the second terminal T2. The terminals T1 and T2 thus form an authentication system Sys.

[0049] The two terminals T1 and T2 are each equipped with a module MMD1, respectively MMD2, capable of measuring a longitudinal distance d which separates them from one another. on the other, precisely (at least to the nearest centimeter). This may, for example, be a module using UWB technology ("Ultra Wide Band" in English) or any other technology making it possible to measure a distance between two terminals, known to those skilled in the art.

[0050] According to one embodiment, the distance d varies over time according to the movements of the first terminal T1 carried out by its user (not shown in the figure).

[0051] According to one embodiment, the terminal T1 has a user interface (for example a screen or a microphone) not shown in the figure, adapted to restore said measured distance to its user.

[0052] By default, the distance d corresponds to the distance between the barycenter bl of the terminal T1 and the barycenter b2 of the terminal T2. Alternatively, the distance d corresponds to the minimum distance between two points belonging respectively to the two terminals T1 and T2.

[0053] According to the embodiments, the longitudinal distance can be calculated according to a single plane for example defined by the x and y axes or through a three-dimensional space defined by the x, y and z axes.

[0054] Description of another example of architecture in which the authentication method is implemented

[0055] Figure [Fig.lb] represents another example of architecture in which the authentication method is implemented. This architecture comprises two terminals T1, T2 similar to those of figure [Fig.la]. For this reason, they will not be described again in detail. In the example of figure [Fig.lb], the first terminal T1 is positioned relative to the second terminal T2 in such a way that a reference axis AR1 (here the longitudinal axis) of the first terminal T1 is positioned at an angle or an angular distance a, relative to a reference axis AR2 (here the longitudinal axis) of the second terminal T2. The terminals T1 and T2 are for this purpose each equipped with a module MMD1, respectively MMD2, capable of measuring said angle a.It may for example be a module using UWB technology (“Ultra Wide Band” in English) with several antennas allowing angular measurement by triangulation, or any other technology allowing a distance to be measured between two terminals, known to those skilled in the art. Each of the modules MMD1, MMD2, may further be configured to measure a longitudinal distance separating the two terminals T1 and T2, as mentioned with reference to the figure [Fig.la].

[0056] According to one embodiment, the angle a varies over time according to the movements of the first terminal T1 made by its user (not shown in the figure) with respect to the second terminal.

[0057] According to the embodiments, the angular distance can be calculated according to a plane unique for example defined by the x and y axes or across a three-dimensional space defined by the x, y and z axes.

[0058] Description of another example of architecture in which the authentication method is implemented

[0059] Figure [Fig.1e] represents another example of architecture in which the authentication method is implemented. This architecture comprises two terminals T1, T2 similar or identical to those of figures [Fig.1a] and / or [Fig.1b]. For this reason, they will not be described again. In the example of figure [Fig.1e], the first terminal T1 is positioned relative to the second terminal T2 at at least two successive times i1 and i2. At time i1, the terminal T1 is positioned relative to the second terminal T2 at a longitudinal distance d11 and in such a way that the reference axis AR1 of the terminal T1 forms an angle a11 with respect to the reference axis AR2 of the terminal T2. At time i2, the terminal T1 is positioned relative to the second terminal T2 at a longitudinal distance di2 and in such a way that the longitudinal axis S1 of the terminal T1 forms an angle a12 with respect to the longitudinal axis S2 of the terminal T2.Of course, other positions are possible. At time 11, terminal T1 could, for example, be separated from terminal T2 by the longitudinal distance d1 while being in the same longitudinal axis as terminal T2.

[0060] Description of an authentication method according to a first embodiment

[0061] Figure [Fig.2] represents the steps implemented by the authentication method in a particular embodiment of the invention, within an architecture similar to that described with reference to any one of figures [Fig.1a], [Fig.1b], [Fig.1c],

[0062] In E201, the first terminal T1 sends, via the network R, an authentication request to the second terminal T2, said authentication request including identification data DID relating to the first terminal.

[0063] According to the embodiments, the identification data correspond for example to a unique identifier of the telephone, a user login or any other reference which is the subject of the authentication.

[0064] According to the embodiments, the authentication request from the first terminal to the second terminal gives rise to additional data exchanges between the first and second terminals, for example a notification of the acceptance of the authentication request by the second terminal T2 or a message inviting the user of the terminal T2 to continue the authentication.

[0065] In E202, the first terminal is placed at a distance DI from the second terminal.

[0066] According to other embodiments, the first terminal is placed successively at at least two DU, DI2 distances from the second terminal.

[0067] According to the embodiments, the longitudinal or angular distances between the terminals T1 and T2 at a given instant can be rendered textually on the first terminal T1 or on a third-party terminal, via their respective screen or be rendered vocally on the first terminal T1 or on a third-party terminal, via their respective loudspeaker.

[0068] In E203, the second terminal T2 compares the value of the distance DI between the terminal T1 and the terminal T2 to a target distance DC associated with said identification data DID.

[0069] In order to implement this comparison, the value of the distance DI can be measured by the terminal T2. Alternatively, the value of the distance DI can be measured by the terminal T1, then transmitted by the terminal T1 to the terminal T2 via the network R.

[0070] According to other embodiments, the comparison is between at least two distances DU, DI2 and respectively at least two target distances DC1, DC2.

[0071] If the distance DI corresponds to the distance DC (O in [Fig.2]), at E204a, the first terminal T1 receives from the second terminal T2, via the network R, a validation of the authentication. Otherwise (N in [Fig.2]), at E204b, the first terminal T1 receives from the second terminal T2, via the network R, a non-validation of the authentication.

[0072] The distance DI corresponds to the distance DC when the absolute value of their difference is less than a predefined threshold s: \D1-DC\ <e

[0073] According to the embodiments, the comparison between the distance DI and the target distance DC, or between the at least two distances DU, DI2 and respectively the at least two target distances DC1, DC2, is carried out directly by the terminal T2 or by a third-party terminal.

[0074] According to the embodiments, if the first terminal receives in E204b a non-validation of the authentication, the first terminal receives from the second terminal an invitation to place itself again at a distance from the terminal T2, with a view to a new authentication. According to other embodiments, if the first terminal receives one or more non-validations of the authentication, the authentication method is blocked and cannot be implemented before a given time.

[0075] According to the embodiments, this authentication request can be associated with at least one other authentication technique such as authentication based on, for example: - a secret code (for example a password or PIN code (“Personal Identification Number” in English), - a password, - a biometric print (e.g. a retinal print, a fingerprint digital, etc.), - an ephemeral code generated by a third-party application, - a model / diagram to be reproduced on a screen of the first terminal or on a third-party terminal, - etc.

[0076] According to the embodiments, this other authentication technique can be implemented before step E201 or after step E202 if the latter results in validation of the authentication.

[0077] Description of an authentication method according to a second embodiment

[0078] Figure [Fig.3] represents the steps implemented by the authentication method in a second particular embodiment of the invention, in an architecture similar to that described with reference to any one of figures [Fig.1a], [Fig.1b], [Fig.1e].

[0079] The authentication method according to this second embodiment is distinguished from that of the first embodiment in that it comprises, prior to the sending E201 of the authentication request mentioned with reference to the figure [Fig.2], a sending E300a from the first terminal T1 to the second terminal T2, via the network R, of a request for registration of the first terminal T1 with the second terminal T2. Said registration request includes the sending of identification data DID.

[0080] In E300b, the first terminal T1 receives a message from the second terminal T2, via the network R, confirming or not the registration request.

[0081] If the registration request is confirmed (O in [Fig.3]), the first terminal is placed at E300c at a given distance from the second terminal so that the terminal T2 defines the target distance DC. According to other embodiments, the first terminal is placed successively at least two distances from the second terminal so that the terminal T2 defines at least two target distances DC1, DC2 respectively.

[0082] If it is the distance DC that has been defined, the distance DC is associated at E300d by the terminal T2 with the identification data DID of the first terminal. If it is the at least two target distances DC1, DC2 that have been defined, the distances DC1 and DC2 are associated at E300c by the terminal T2 with the identification data DID of the first terminal.

[0083] According to one embodiment, the recording step includes a step of triggering the start of recording of the target distance.

[0084] According to another embodiment, the recording step includes a step of validation by the user of the terminal T1 of the target distance DC, respectively of the at least two target distances DC1, DC2.

[0085] According to one embodiment, the user has the possibility of iterating several times the step of recording the target distance DC, respectively the at least two target distances DC1 and DC2, before validating them, respectively.

[0086] If the registration request is not confirmed (N in [Fig.3]), in E300b the authentication process ends.

[0087] Following step E300d, the authentication method continues by implementing steps E301, E302, E303, E304a / E304b respectively identical or similar to steps E201, E202, E203, E204a / E204b described with reference to the figure [Fig.2],

[0088] Description of an authentication method according to a third embodiment

[0089] Figure [Fig.4] represents the steps implemented by the authentication method in a third particular embodiment of the invention, in an architecture similar to that described with reference to any one of figures [Fig.la], [Fig.lb], [Fig.le].

[0090] Such an authentication method includes steps E401, E402, E403, E404a / E404b respectively identical or similar to steps E201, E202, E203, E204a / E204b described with reference to figure [Fig.2] and to steps E301, E302, E303, E304a / E304b described with reference to figure [Fig.3].

[0091] The authentication method of figure [Fig.4] differs from the authentication methods described in figures [Fig.2] and [Fig.3], in that at E405, the first terminal T1 receives an instruction from the second terminal, via the network R, requesting the user of the first terminal T1 to position said first terminal T1 in accordance with at least a distance DC' from the second terminal T2.

[0092] According to the embodiments, said at least one distance DC' is random.

[0093] In E406, the first terminal T1 is placed, relative to the second terminal T2, according to at least one DF distance in order to comply with the instruction received in E405.

[0094] At E407, if the placement of the first terminal T1 carried out at E406 is in accordance with the instruction received at E405 (O in [Fig.4]), the first terminal T1 receives at 408, from the second terminal T2, via the network R, another validation of the authentication by the second terminal T2. In the opposite case (N in [Fig.4]), the first terminal T1 does not receive another validation of the authentication and the authentication process ends.

[0095] In E409 if the terminal T1 has received a validation of the authentication at the end of E404a and a validation of the authentication at the end of step E408, the terminal T1 receives a final validation from the second terminal T2, via the network R.

[0096] Depending on the embodiments, step E405 may, as in the figure [Fig.4], take place at the end of step 404b or, according to an embodiment not shown in the figure, take place before step E401.

[0097] Description of an embodiment of a portable communicating terminal

[0098] [Fig.5] shows the simplified structure of a communicating portable terminal T1 configured to implement the authentication method described with reference to any one of figures [Fig.2] to [Fig.4].

[0099] Such a terminal T1 comprises, according to the invention, a communication module El / R1 adapted to receive and transmit information respectively from and to the authenticator terminal T2, as well as a module MMD1 adapted to calculate a longitudinal and / or angular distance separating the terminal T1 from the terminal T2 and a user interface IU1 (for example a screen or a loudspeaker) adapted to restore the value of said distance.

[0100] According to a particular embodiment of the invention, the actions executed by the terminal T1, within the framework of the implementation of the authentication method of the present invention, are implemented by instructions of a computer program PG1. For this, the terminal T1 has the conventional architecture of a computer and notably comprises a memory MEM1, a processing unit UTR1, equipped for example with a processor PROC1, and controlled by the computer program PG1 stored in memory MEM1. The computer program PG1 comprises instructions for implementing the steps of the authentication method, in particular the aforementioned actions: - send to the second terminal T2 an authentication request including DID identification data, - position yourself at a distance DI from the second terminal T2, - receive a validation or non-validation of the authentication in response to a comparison by the second terminal T2 of said distance with a distance DC associated with the identification data DID.

[0101] Description of an embodiment of a communicating authenticator terminal

[0102] [Fig.6] shows the simplified structure of a communicating authenticator terminal T2 involved in the implementation of the authentication method described with reference to any one of the figures [Fig.2] to [Fig.4]. Such a terminal T2 comprises, according to the invention, a communication module E2 / R2 adapted to receive and transmit information respectively from and to the portable terminal T1, as well as a module MMD2 adapted to calculate a longitudinal and / or angular distance separating the terminal T1 from the terminal T2.

[0103] According to a particular embodiment of the invention, the actions executed by the terminal T2, within the framework of the implementation of the authentication method of the present invention, are implemented by instructions of a computer program PG2. For this, the terminal T2 has the classic architecture of a computer and includes in particular a MEM2 memory, a UTR2 processing unit, equipped for example with a PROC2 processor, and controlled by the PG2 computer program stored in MEM2 memory. The PG2 computer program includes instructions for implementing the following actions: - receive, from terminal T1, a value of a distance DI at which terminal T1 is positioned in relation to terminal T2, - comparing said received distance value DI with a target distance DC associated with said identification data, - send to the terminal Tl a validation or a non-validation of the authentication depending on the result of said comparison.

Claims

Claims

1. Method for authenticating a first portable terminal (T1) communicating with a second communicating terminal (T2), comprising sending, by the first terminal to the second terminal, an authentication request including identification data (DID), characterized in that it implements the following at the first terminal: - placing itself (E202) at a distance (DI) from the second terminal, - receiving (E204a, E204b) a validation or a non-validation of the authentication in response to a comparison by the second terminal of said distance (DI) with a target distance (DC) associated with said identification data (DID).

2. Authentication method according to claim 1, wherein the first terminal receives a validation of the authentication if the second terminal measures at least two distances from the first terminal with respect to the second terminal, corresponding to at least two target distances (DC) associated with the identification data (DID) of said first terminal.

3. Authentication method according to any one of claims 1 to 2, wherein the sending of an authentication request is preceded by a registration of the first terminal with the second terminal where a target distance, respectively the at least two target distances, is associated, respectively are associated, with the identification data (DID) of the first terminal.

4. Authentication method according to any one of claims 1 to 3, in which the authentication request of the first terminal includes additional authentication from any one of the following authentication methods: - secret code, - password, - pattern to be reproduced on a screen of the first terminal or a third-party terminal, - biometric data, - ephemeral code.

5. Authentication method according to any one of claims 1 to 4, in which the reception of a validation of the authentication is associated with a complementary authentication where the first terminal receives from the second terminal an instruction to be carried out in order to finalize the authentication, said instruction requesting to place the first terminal at one or more target distance(s).

6. Authentication method according to any one of claims 1 to 5, wherein the placement of the first terminal at a distance, respectively several distances, from the second terminal, includes a restitution, on an interface associated with the first terminal, of the value of said distance, respectively of said distances.

7. Portable communicating terminal (T1) configured to be authenticated by a communicating authenticator terminal (T2), said portable communicating terminal being configured to send to the communicating authenticator terminal an authentication request including identification data (DID), said portable communicating terminal being characterized in that it is further configured to implement the following: - position itself at a distance (DI) from the communicating authenticator terminal, - receive a validation or a non-validation of the authentication in response to a comparison by the communicating authenticator terminal of said distance (DI) with a target distance (DC) associated with said identification data (DID).

8. A computer program comprising program code instructions for implementing the authentication method according to any one of claims 1 to 6, when executed on a computer.

9. Computer-readable information medium comprising instructions of a computer program for implementing the authentication method according to any one of claims 1

10. d O. Communicating authenticator terminal (T2) configured to authenticate a communicating portable terminal, said communicating authenticator terminal being configured to receive, from the communicating portable terminal, an authentication request including identification data (DID), characterized in that the communicating authenticator terminal is further configured to: - receive, from the communicating portable terminal, a value of a distance (DI) at which the communicating portable terminal has positioned itself relative to the communicating terminal, - comparing said received distance value (DI) with a target distance (DC) associated with said identification data, - send to the communicating portable terminal a validation or non-validation of the authentication depending on the result of said comparison.

11. System for authenticating a first portable terminal (T1) communicating with a second communicating terminal (T2), said system comprising: - a portable communicating terminal according to claim 7, - a communicating authenticator terminal according to claim 10.

Citation Information

Patent Citations

  • Door opening system by code scanning parallel verification and method

    CN110021085A

  • Secure short-distance-based communication and access control system

    US20160055689A1

  • Multi-factor authentication with geolocation and voice command

    US20200204565A1