Method for obtaining candidate biometric data from an individual for authentication of said individual.
The method of displaying a personalized graphic element to verify interface authenticity before acquiring biometric data addresses the vulnerability of biometric data to phishing, enhancing security and protecting against unauthorized access.
Patent Information
- Application Number
- FR2024014607
- Authority / Receiving Office
- FR · FR
- Patent Type
- Utility models
- Current Assignee / Owner
- Priority Date
- 2023-12-22
- Filing Date
- 2024-12-19
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2034-12-19
AI Technical Summary
Biometric data is vulnerable to phishing attacks and malicious use, such as identity theft and deepfakes, despite robust anti-spoofing mechanisms, necessitating a solution to protect personal biometric data during authentication.
A method involving displaying a personalized graphic element chosen by the user, verifying its authenticity through an authentication server, and integrating it into the interface to ensure the interface's legitimacy before acquiring biometric data, thereby preventing unauthorized access.
Enhances security by ensuring only legitimate interfaces can acquire biometric data, reducing the risk of phishing and unauthorized data theft, while maintaining user convenience and efficiency.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for obtaining candidate biometric data of an individual for authentication of said individual.
[0001] GENERAL TECHNICAL FIELD
[0002] The present invention relates to the field of biometric authentication. More specifically, it relates to a method for obtaining candidate biometric data of an individual for authentication of said individual.
[0003] STATE OF THE ART
[0004] Traditional authentication techniques using codes or passwords are gradually being replaced by much more secure and practical biometric techniques.
[0005] Thus, to access a service, a user of a mobile terminal, for example, may be asked to present his face in front of a camera or his finger on a fingerprint sensor.
[0006] One difficulty, however, is that biometric data is personal data that must be protected, unlike a meaningless code.
[0007] We are thus seeing the emergence of phishing techniques in which a page fraudulently requests a user's biometrics, for example asking them to present their face in front of the camera, to acquire an image, and to send it to a remote server. The user's personal data can thus be stolen.
[0008] Fortunately, biometric authentication processes are robust (so-called "anti-spoofing" mechanisms such as data freshness detection or liveness detection) and would not be fooled by stolen data, but this data could be used for other malicious purposes (identity theft, deepfakes, etc.)
[0009] It would thus be desirable to have a solution that reliably and universally prevents a malicious third party from being able to steal an individual's biometric data despite the increasing number of daily occasions where this individual is asked to present his or her biometrics for authentication.
[0010] The present invention also improves these situations. PRESENTATION OF THE INVENTION
[0011] The present invention therefore relates, according to a first aspect, to a method for obtaining candidate biometric data of an individual for authentication of said individual, comprising the implementation by data processing means of a terminal of steps of: a. Displaying an interface requiring the acquisition with a terminal sensor, on a biometric trait of the individual, of said candidate biometric data; b. Transmission of a request to verify the authenticity of said interface to an authentication server, said request uniquely identifying said individual; c. Receipt in response, from said authentication server, of a graphic personalization element associated with said individual; d. Displaying said customization graphic element in a manner associated with said interface; e. Acquisition with said sensor, on said biometric trait of the individual, of said candidate biometric data.
[0012] step (d) comprising adapting said interface so as to include said personalization graphic element, the personalization graphic element is an image previously chosen by the user.
[0013] According to a second aspect, the invention proposes a method for authenticating an individual, comprising implementing the method according to the first aspect of obtaining a candidate biometric data item of the individual, then a step (f) of verifying that said candidate biometric data item coincides with a reference biometric data item of the individual.
[0014] According to advantageous and non-limiting characteristics:
[0015] The method comprises a prior step (aO) of enrolling the individual for authentication including obtaining said reference biometric data of the individual.
[0016] Step (aO) comprises the selection of said graphic personalization element by the individual.
[0017] Said graphic personalization element is an image provided by the individual from said terminal.
[0018] According to a third and a fourth aspect, the invention provides a computer program comprising code instructions for executing a method according to the first aspect of obtaining a candidate biometric data item of an individual for authentication of said individual, or a method according to the second aspect of authentication of an individual; and a storage means readable by computer equipment on which is recorded a computer program product comprising code instructions for executing a method according to the first aspect of obtaining a candidate biometric data item of an individual for authentication of said individual, or a method according to the second aspect of authentication of an individual. PRESENTATION OF FIGURES
[0019] Other characteristics and advantages of the present invention will appear on reading the following description of a preferred embodiment. This description will be given with reference to the appended drawings in which:
[0020] [Fig.l] [Fig.l] is a diagram of a system for implementing the method according to the invention;
[0021] [Fig.2] [Fig.2] is a flowchart illustrating the steps of an embodiment of the method according to the invention. DETAILED DESCRIPTION
[0022] Architecture
[0023] The present invention relates to a method for obtaining candidate biometric data of an individual for authentication of said individual, in a system as represented in [Fig.l].
[0024] Said authentication is initiated by the individual, on the terminal 1 (see below), and typically aims to grant access to a service, to authorize a transaction, to unlock equipment, etc. We will see later, according to a second aspect of the invention, a method of authenticating the individual implementing said method of obtaining candidate biometric data of the individual.
[0025] This is thus a biometric authentication, which means that the user authenticates himself by presenting a biometric trait rather than a code or password, in particular his face, but also a fingerprint, his iris, etc. By biometric data, we mean a digital representation of his biometric trait, or encoding. For example, for a fingerprint, the biometric data can be the position of a set of minutiae. Those skilled in the art know numerous techniques for obtaining biometric data from the corresponding biometric trait, so this aspect will not be described further.
[0026] Said biometric data that one seeks to obtain is fresh biometric data acquired on the individual, called “candidate” in relation to “reference” biometric data of the individual, advantageously stored by the terminal 1 (or an authentication server which will be mentioned later).
[0027] The terminal 1 is preferably a terminal personal to the individual, in particular a mobile terminal (in particular of the smartphone type), but it can be any equipment such as a workstation, or even an access control terminal. In the case of a terminal personal to the individual, the authentication is advantageously a strong authentication, i.e. two-factor (possession of the terminal 1 and biometrics), and the present method proves to be particularly secure as will be seen later.
[0028] In all cases, the terminal 1 is connected via a network 20 (in particular the Internet network) to an authentication server 2, for example a server for implementing a service or a banking server (in the case of authentication), generally remote.
[0029] The terminal 1 and the authentication server 2 each have data processing means 11, 21 (typically a processor) and data storage means 12, 22 (a memory, for example flash). The latter store, as explained, advantageously a reference biometric data item of said individual.
[0030] The terminal 1 further comprises interface means 13 such as a screen, and a sensor 14 for acquiring biometric data, in particular a camera if the biometric trait concerned is the face, a fingerprint sensor if the biometrics
[0031] Method for obtaining candidate biometric data
[0032] With reference to [Fig.2], the present method, implemented by the data processing means 11 of the terminal 1, conventionally begins with a step (a) of displaying (on the display means 13) an interface requiring the acquisition with a sensor 14 of the terminal 1, on a biometric trait of the individual, of said candidate biometric data.
[0033] This interface typically takes the form of a page displayed on said means 13, which may, if necessary, be just a window or occupy the entire display surface (i.e. the entire screen). This interface may be that of an application executed on the terminal 1 requiring authentication of the individual, for example a payment application.
[0034] By “requiring the acquisition with a sensor 14 of the terminal 1, on a biometric trait of the individual, of said candidate biometric data”, it is meant that the interface displays a message indicating to the individual that the terminal 1 needs to acquire his biometric data and that he must therefore present his biometric trait to the sensor 14.
[0035] Originally, the method then comprises a step (b) of transmitting a request to verify the authenticity of said interface to an authentication server 2, said request uniquely identifying said individual.
[0036] Indeed, said interface could be fraudulent, and aim to steal the candidate biometric data of the individual, so that the user may wish to ensure that on the contrary it is authentic. Steps (b) and following will allow this.
[0037] Steps (b) and following can be implemented automatically after the display of the interface, but preferably they are implemented at the request of the individual. Thus, if the user has no doubt about the authenticity of the present interface, he can continue the process (go directly to step (e) which will be described further), or if in doubt, request verification of the authenticity of said interface.
[0038] For this, said interface proposes this verification of the authenticity of said interface, via an interface element such as a verification button or any other active zone. When this button is pressed or an action corresponding to this interface element is performed (for example a swipe gesture on touch-sensitive means 13), the verification (i.e. step (b)) is launched. The interface can explain this by means of text or a pictogram on the button or around it.
[0039] Note that the absence of the possibility of verifying the authenticity of said interface (absence of the button) may be a sign of fraudulent nature if the interface usually offers this verification.
[0040] Said request for verification of the authenticity of said interface transmitted to the authentication server 2 in step (b) uniquely identifies said individual, for example by including an identifier or at least data derived from an identifier (for example a cryptographic fingerprint of such an identifier). Indeed, this is an authentication method, i.e. the aim is to verify the identity of the individual and not to determine it (this would be identification). As such, the individual has normally previously entered an identifier (for example his e-mail address or a subscriber number, if applicable entered in another interface). If the terminal 1 is a terminal personal to the individual, the latter is generally automatically identified (the identifier is pre-recorded).
[0041] The server 2 processes this request by determining a graphical personalization element associated with said individual. More precisely, the data storage means 22 of the server 2 can store a plurality of graphical personalization elements each associated with an individual known to the authentication server 2 (i.e. already enrolled, see below), for example via the identifier or the derived data. Of course, only requests coming from known sources (for example an official application, in particular having a certificate) are processed. Indeed, a third party could attempt to integrate the verification button into a fraudulent interface, but the server 2 would detect that the request comes from a source that is not trusted, and therefore would not confirm its authenticity. A notification can be transmitted to the individual (to the terminal 1) to inform them of the fraudulent nature of the interface and of the phishing attempt.
[0042] By "personalization graphic element" is meant a graphic object such as an image, but also a texture, a video, etc. potentially unique and known to the individual. Said personalization graphic element is therefore preferably previously chosen by the user, even if one could alternatively arbitrarily (particularly randomly) assign its graphic customization element to it.
[0043] In any case, it is understood that this is an element normally known only to him, which the individual must be able to recognize. The personalization element can therefore represent absolutely anything (a photo, a drawing, a signature, a text, an abstract graphic object, etc.).
[0044] Thus, in step (c), the terminal 1 receives in response (to said verification request), from said authentication server 2, said graphic personalization element associated with said individual.
[0045] The method then comprises a step (d) of displaying said graphical personalization element in a manner associated with said interface. By "in a manner associated with said interface", it is meant that the interface and the personalization element are clearly linked, i.e. that the personalization element applies unambiguously to this interface and not another. To rephrase, step (d) is a step of personalizing said interface using said personalization element. Typically, step (d) comprises adapting said interface so as to include said graphical personalization element, as one would, for example, affix a signature to a document to prove its authenticity.
[0046] This can be done in many different ways: - If said customization element is a pattern or texture, it can simply be placed in the background of the interface; - If said customization element is an image, it can be embedded in a dedicated area of the interface; or displayed in another window; - If said customization element is a movie, it can be played over what is currently displayed by the interface, and then the previous display is restored; - Etc.
[0047] If the individual recognizes his personalization element (the one associated with him, i.e. the one he has chosen or at least that has been assigned to him), he can be certain that the associated interface is authentic, and therefore he can consent without fear to the candidate biometric data being acquired.
[0048] Indeed, the third party who would have added a false verification button to a fraudulent interface could try to reassure the individual by displaying a graphical personalization element but he does not know that of the individual unless he accesses the authentic interface, which significantly reduces the risk of phishing. And if this interface displays a false graphical personalization element, the individual will immediately recognize that it is not his own and will understand that the interface is fraudulent, and will not present his biometrics.
[0049] Note that in an embodiment with strong authentication, a third party could not access the authentic interface (since this would require access to the individual's terminal 1), and therefore the third party has absolutely no means of accessing the graphical personalization element and copying it, so that the verification of the authenticity of the interface is potentially inviolable.
[0050] Finally, the method comprises a conventional step (e) of acquisition with said sensor 14, on said biometric trait of the individual, of said candidate biometric data. It is understood that the possibility of acquiring the candidate biometric data can be opened as soon as the interface is displayed (step (a)), but in practice the individual will be able to authorize its implementation (by presenting his biometric trait to the sensor 14) only when he has been able to verify the authenticity of the interface and therefore the legitimacy of the request to acquire his biometric data. Again, the user can feel confident with the interface displayed in step (a) and not launch steps (b) to (d) (i.e. not press the authenticity verification button), and go directly to step (e), so that in the majority of cases the present method does not slow down authentication at all and therefore does not degrade the user experience.
[0051] This acquisition consists, for example, classically of taking a photo of the biometric feature (in particular the face) and processing it so as to obtain said candidate biometric data.
[0052] Authentication method
[0053] According to a second aspect, the invention relates to a method for authenticating an individual, comprising implementing the method according to the first aspect to obtain the candidate biometric data of the individual on the terminal 1 (steps (a) to (e)). This method can be triggered by the terminal 1 or the server 2 in response to any request requiring verification of the identity of the individual, in particular a request for access to a service, a transaction request, etc., initiated by the individual most often on the terminal 1.
[0054] Then, in a conventional manner, this method comprises, after obtaining the candidate biometric data, a step (f) of verifying that said candidate biometric data coincides with a reference biometric data of the individual.
[0055] Generally, this step (f) is implemented by the processing means 11 of the terminal 1 (and said reference biometric data is stored by the storage means 12 of the terminal 1), but alternatively, the biometric data can be transmitted (for example encrypted) to the server 2 so that its data processing means 21 implement said comparison.
[0056] The latter can be implemented in any known manner, depending on the nature of the biometric concerned, by counting the candidate biometric data and the reference biometric data and by verifying that they are sufficiently similar, for example example by calculating a distance between the candidate biometric data and the reference biometric data by a given distance function such as the Euclidean distance, and by verifying that this distance is less than a given threshold.
[0057] If the result is positive, i.e. if said candidate biometric data coincides with a reference biometric data, the individual is authenticated and an action is implemented by the server 2 (access to a requested service, authorization of the transaction, etc.).
[0058] Preferably, the authentication method comprises a prior step (aO) of enrolling the individual for authentication, comprising obtaining said reference biometric data of the individual.
[0059] This enrollment can be done in a conventional manner and include the acquisition (with said sensor 13 or another sensor), on said biometric trait of the individual, of said reference biometric data, in a secure environment. For example, this may have to be done in the presence of an authority, or while the individual is authenticated in another way (via a code or password for example).
[0060] Then step (aO) very advantageously comprises the assignment of said graphic personalization element to the individual, in particular the selection of said graphic personalization element by the individual. Indeed, this is the best time to do so due to the necessary secure environment.
[0061] This can be done in many ways: - As explained, said graphic personalization element can be arbitrarily selected and presented to the individual; - The individual may be presented on his terminal 1 with a plurality of possible graphic elements for personalization, so as to choose one; - said graphic personalization element may be an image directly provided by the individual from said terminal 1, in particular an image stored on the storage means 12.
[0062] Again, the present method will not be limited to any type of customization graphic element or to a way of selecting it.
[0063] Terminal
[0064] According to a second aspect, the invention relates to the terminal 1 for implementing the method according to the first aspect and at least partially the method according to the second aspect.
[0065] The terminal 1 comprises data processing means 11 and data storage means 12.
[0066] The data processing means 11 are configured to: - Display an interface requiring the acquisition with a sensor 13 of the terminal 1, on a biometric trait of the individual, of candidate biometric data, for authentication of said individual; - Transmit a request to verify the authenticity of said interface to an authentication server 2, said request uniquely identifying said individual; - Receive in response, from said authentication server 2, a graphic personalization element associated with said individual; - Display said customization graphic element in a manner associated with said interface; - Acquire with said sensor 13, on said biometric trait of the individual, said candidate biometric data.
[0067] According to a fourth aspect, the invention relates to the entire terminal 1 according to the third aspect and the authentication server 2, connected via said network 20.
[0068] Computer program product
[0069] According to a fifth and a sixth aspect, the invention relates to a computer program product comprising code instructions for the execution (on the data processing means 11, 21 of the terminal 1 and / or of the authentication server 2) of a method according to the first aspect of obtaining candidate biometric data of an individual for authentication of said individual, or of a method according to the second aspect of authentication of an individual; and a storage means (for example the data storage means 12, 22 of the terminal 1 and / or of the server 2) on which this computer program product is found.
Claims
Claims
1. Method for obtaining candidate biometric data of an individual for authentication of said individual, comprising the implementation by data processing means (11) of a terminal (1) of steps of: a. Displaying an interface requiring the acquisition with a sensor (14) of the terminal (1), on a biometric trait of the individual, of said candidate biometric data; b. Transmitting a request for verification of the authenticity of said interface to an authentication server (2), said request uniquely identifying said individual; c. Receiving in response, from said authentication server (2), a graphical personalization element associated with said individual; d. Displaying said graphical personalization element in a manner associated with said interface; e. Acquiring with said sensor (13), on said biometric trait of the individual, said candidate biometric data.step (d) comprising adapting said interface so as to include said personalization graphic element, the personalization graphic element is an image previously chosen by the user.
2. Method for authenticating an individual, comprising implementing the method according to claim 1 for obtaining a candidate biometric data item of the individual, then a step (f) of verifying that said candidate biometric data item coincides with a reference biometric data item of the individual.
3. Method according to claim 2, comprising a prior step (aO) of enrolling the individual for authentication comprising obtaining said reference biometric data of the individual.
4. The method of claim 3, wherein step (aO) comprises selecting said personalization graphic element by the individual.
5.
6.
7. Method according to claim 4, wherein said graphic personalization element is an image provided by the individual from said terminal (1). Computer program product comprising code instructions for executing a method according to claim 1 for obtaining candidate biometric data of an individual for authentication of said individual, or a method according to one of claims 2 to 5 for authentication of an individual, when said program is executed on a computer. Storage means readable by computer equipment on which is recorded a computer program product comprising code instructions for the execution of a method according to claim 1 for obtaining candidate biometric data of an individual for authentication of said individual, or of a method according to one of claims 2 to 5 for authentication of an individual.