Process for continuous authentication of an individual's identity

The method addresses the limitations of intrusive and unreliable continuous authentication by using passive physiological signal detection and individual-specific models, enhancing reliability and security through continuous verification and learning.

FR3159246A1Pending Publication Date: 2025-08-15VIGNAU BENJAMIN +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
FR2024001413
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-13
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Existing continuous authentication methods are intrusive, require active user interaction, and lack reliability due to the use of a single transformation rule for all individuals, making them susceptible to session theft and falsification.

Method used

A method utilizing passive physiological signal detection and machine learning to generate unique authentication models for each individual, incorporating data from known imposters to enhance reliability, and continuously verifying identity through iterative authentication without requiring active user interaction.

Benefits of technology

Provides transparent, secure, and reliable continuous authentication by passively generating and updating individual-specific models, reducing the risk of session theft and falsification, and maintaining high reliability over time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for continuous authentication of the identity of an individual, comprising a first authentication step by the recognition of at least one physiological signal of the individual transmitted by at least one sensor worn passively by the individual, and after the first authentication step, at least one iteration step of identity authentication by the recognition of said at least one physiological signal of the individual, the recognition of said at least one physiological signal of the individual during the first authentication step and during the authentication iteration steps, being executed from a group of authentication models dedicated to the individual, unique for each individual to be authenticated and resulting from automatic learning from data of said at least one physiological signal, collected at least previously in a so-called prior learning step,the authentication models dedicated to the individual being generated by the processing of a multitude of authentication test models designed by machine learning.,
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for continuous authentication of the identity of an individual

[0001] The invention relates to the field of continuous authentication of the identity of an individual, in particular to authorize access.

[0002] Authentication consists of proving the identity of a user so that an access authorization can be issued to him (access to a place, a physical object, software, etc.). To authenticate, the user must transmit to an authentication system, his identity associated with such or such proof and the system verifies the proof.

[0003] The most common authentication is based on proof of a password or a badge. However, this type of authentication poses the problem of session theft. In addition, once authenticated, the authentication system has no way of certifying that the user who continues to use the session after having had access to it is still legitimate. Also, in recent years, biometric authentication has been developed, for example by fingerprint recognition. However, fingerprint sensors can be fooled by latex forgery. In addition, this authentication method is one-time, it authenticates the person once to open a session without repeating the authentication.

[0004] Thus, in recent years, the need to develop so-called continuous authentication has been shown. Continuous authentication aims to re-authenticate the user several times during the session. For example, from American patent application US2022012317, a method and its implementation device are known consisting of repeating recognition by biometrics several times; the biometric recognition described in this document relates to voice recognition, recognition of a fingerprint, a palm print, or even the shape of the face, a hand or the pattern of veins. However, this type of recognition requires the user to actively interact with the biometric sensors at each recognition request, which undoubtedly represents a nuisance.Indeed, the user is already disturbed because the system informs him of the obligation to be recognized again, then he must take time to perform an action, that of interacting with a sensor like speaking or repositioning his finger, his hand, or his face in an ad hoc manner. Such a continuous authentication process is therefore too restrictive for the user.

[0005] Also known from patent application WO2012151680 is an authentication of an individual which can be continuous by repeating the authentication over time. This document advantageously describes the use of physiological signals for authentication, such as ECG (for electrocardiogram) and PPG (for "PhotoPlethysmoGraphy"), which are signals that are more difficult to falsify. However, regardless of the number of individuals in the population, the process described in this document requires having previously entered into a database a pre-recorded signal specific to each individual listed in the database. Authentication is achieved by matching a measured physiological signal of an individual with the pre-recorded signal for that individual in the database. The pre-recorded signal was designed by a transformation rule that is derived from machine learning from measured signals of a group of several individuals. However, such an authentication method that uses the "Template Machine" technique has the disadvantage of having to store all individuals with their pre-recorded authentication signal from the transformation rule in advance in a database to compare the measured signal with the pre-recorded signal. Another disadvantage is that the pre-recorded signal, although unique for each individual, is derived from the same transformation rule for all listed individuals.This process ultimately does not provide sufficient reliability.

[0006] The invention therefore aims to propose a continuous authentication method which does not have the aforementioned drawbacks, in particular which provides continuous authentication in a transparent manner for the user and above all which remains reliable and secure over time.

[0007] According to the invention, the method for continuous authentication of the identity of an individual (sometimes referred to hereinafter as a legitimate individual), comprises a first authentication step (called initial authentication of the identity) by the recognition of at least one physiological signal of the individual transmitted by at least one sensor worn passively by the individual, and after the first authentication step, at least one iteration step of authentication of the identity (to verify the authentication of the identity) by the recognition of said at least one physiological signal of the individual, the authentication method being characterized in that: - prior to the authentication and authentication iteration steps,the method comprises i) a so-called prior learning step (with respect to said individual) which consists of processing by automatic learning (called in English "machine learning") the data of at least one physiological signal specific to the individual (the data based on discriminating characteristics of said at least one physiological signal of the individual), to generate a multitude of authentication test models, ii) testing this multitude of authentication test models with the data of the individual which continue to be captured, iii) classifying the test models, authentication models according to their relevance of probability of correspondence with the individual's data and iv) to retain only a selection of a group of (a few) authentication test models classified with the best probability of correspondence (correspondence with the legitimate individual), these selected authentication test models being the so-called authentication models which are retained for the authentication and authentication iteration steps (these authentication models are specific to each individual and are therefore different from those of another individual to be authenticated; for each individual a preliminary step of generating several authentication models will be carried out); - the authentication and authentication iteration steps consist of comparing the data captured from the individual with the authentication models specific to the individual, associating a probability of correspondence with the comparison result with each of the authentication models and processing the probabilities to deduce a result of acceptance of the authentication or rejection of the authentication. An acceptance result implies that the individual is indeed legitimate.

[0008] According to a preferred characteristic, in step i) which consists of generating a multitude of authentication test models, the data processing uses not only the data of the individual but also the data of at least one known impostor (the learning is done with the data of the individual and the data of one or more known impostors), the quantity of data used from all the known impostors considered in the generation of the multitude of test models not having to exceed the ratio between the total quantity of data of the (legitimate) individual and the number of known impostors. The use of data from known impostors makes it possible, for example, to reject test models which could obtain a good probability of correspondence whereas in reality the probability should be poor, and also makes it possible to reinforce test models with a good probability because they were able to recognize the impostor data.This increases the reliability of the models selected for the authentication and authentication iteration stage. In addition, considering a limited amount of known imposter data relative to the amount of individual data avoids the risk of generating test models that would take into account more data from known imposters than from the individual.

[0009] Thus, several authentication models are used, the comparison results of which are analyzed to identify an individual, and furthermore, these authentication models are specific to a single individual because they are derived from models generated from the training data of the single individual and possibly from data of known imposters, and not from a transformation rule from data of a group of individuals who all had to be listed by storing their own data. Indeed, in the prior art, a single model is created from a transformation rule transformation and this transformation rule was designed from the data of a given group of individuals (by combining by learning all the data of all the individuals in the group). However, the method of the invention does not generate only one model (which is more reliable), and does not establish a single transformation rule and also does not require the data of all the individuals in a group. The method of the invention therefore uses the data of a single individual, possibly also uses the data of at least one known imposter individual to generate several authentication test models but does not need the data of all the individuals in a group to generate an authentication test model. The method of the invention therefore does not have to worry about processing data from all the individuals in a group to authenticate a single individual.There is also no need to consider a new group of individuals with all their data each time a new individual not initially listed must be newly integrated into a database for authentication (since the models retained for the authentication of the individual will be independent of the other authentication models of other individuals - there is no unique transformation rule).

[0010] According to one feature, in step ii), at least one test model is tested from the data of at least one other individual considered to be a known imposter, preferably from the data of several known imposters, which helps in the selection of said at least one of the authentication test models when the probability associated with this test model tested with the data of the known imposter is precisely low because the imposter has indeed been detected. Preferably, all the authentication models retained have been tested with the data of the known imposter (to confirm the relevance of the model when the associated probability was indeed low).

[0011] According to one feature, the data of a known imposter is that of a real individual or has been digitally generated. Digital generation can be useful for simulating one or more imposters while only the data of the legitimate individual is available.

[0012] In the prior art, a given group of authorized individuals is considered to create (by prior learning) a transformation rule. When a new individual must be integrated into the database of authorized individuals, the group having been modified, it is necessary to repeat the prior learning for the entire new group in order to create a new, more suitable authentication rule. On the contrary, the method of the invention does not require repeating learning for all the individuals as soon as a new individual must be integrated into the database of authorized persons. Indeed, the method of the invention generates test models from the data of the individual to be authenticated (legitimate user), the data of another individual (known imposter) being used if necessary (nevertheless preferentially) only to generate and test the test models and highlight that if the test model tested with the data of the known imposter gives a result too close to the result with the data of the individual to be authenticated, this test model will be assigned a very low, or even zero, probability value. This will help to design from the different test models, a group of even more reliable authentication models, but in no case will it be necessary to use the data of an entire exhaustive group of individuals which will correspond to a group of which each individual will be supposed to obtain authorization after authentication. The method of the invention is implemented independently of the number of individuals to be authenticated.

[0013] By "passively worn" relative to the sensor, we mean the fact that the individual does not need to perform any action on the sensor, nor worry about it, he adjusts to putting it on him and wearing it (the arrangement will depend on the type of physiological signal measured).

[0014] A physiological signal is understood to be any analog signal generated by the human body that can be measured and digitized.

[0015] Preferably, the processing of the probabilities which are associated with the results of comparison of the captured data with the authentication models, to deduce an acceptance or rejection result, is implemented by a decision tree.

[0016] According to one characteristic, the generation of the authentication models and the authentication by these authentication models are free of any active gesture to be imposed on the individual.

[0017] Consequently, the authentication method of the invention has several advantages: - the detection of signals which are necessarily physiological and the continuous repetition of the measurement of these physiological signals, make the request for authentication and its verification transparent for the individual who has no action to take; - the detection and processing of physiological signals reduces the risk of falsification because physiological signals have the advantage of being all different depending on the individual; - the additional steps in the identity authentication verification time, eliminates the risk of session theft. Indeed, during a session use, the fact that after the initial authentication, the authentication is continuously verified by repeated measurement of the signal and by its systematic analysis, allows to continuously verify that the user is always the same; if an authentication certificate has been issued, as long as the authentication verification continues, the session / access can remain open; - according to another intended use, the additional steps in the identity authentication verification time allow for a signal to be analyzed in detail continuously over a fairly long period, before issuing an authentication certificate; - the generation of several authentication models which are unique for each individual from artificial intelligence learning of the data of the individual to be authenticated (more reliable than with combined data from a necessary group of individuals) and their implementation during authentication by assigning each of them a probability of correspondence, reinforce the reliability of the authentication.Indeed, instead of providing an identical data transformation rule from the data of a group of individuals and comparing the data during authentication only with this single rule, the method of the invention by testing several authentication models from the data of the legitimate user (possibly additional data from one or a few known imposters) and by studying their relevance of correspondence for said user, this reinforces the reliability of the authentication evaluation. In addition, testing the authentication models with data from a known imposter increases the reliability of the ranking of the best models to retain for the individual to be authenticated; . - there is no need to keep the data of a multitude of individuals to establish a transformation rule from all this data, nor to carry out new learning to establish a new rule as soon as one or more individuals are added to the list of individuals to be authenticated.

[0018] According to one characteristic, the authentication method establishes the list of the Y best known impostors for each legitimate user and, at each authentication of the user, attempts to authenticate these Y best impostors (in relation to the other individuals known in the authentication system via the different recognition modules dedicated to each registered individual). In particular, this makes it possible to eliminate known individuals from the list of impostors.

[0019] According to one characteristic, during the preliminary learning step, the individual who will subsequently have to be authenticated will have to wear for a certain time a sensor of at least one type of physiological signal, the individual will go through phases of rest, sport, emotions (for example by listening to audio recordings and / or viewing videos), to record the associated signals, and the automatic learning will lead to authentication models dedicated to the individual, relatively reliable.

[0020] According to another characteristic, the authentication method comprises a step of issuing an authentication certificate when the recognition is accepted (TRUE), the authentication iteration steps being carried out after the first authentication step and the issuance of the authentication certificate, or the authentication iteration steps being carried out following the first authentication step and before issuance of the authentication certificate. The execution of the authentication iteration steps depends on the degree of security associated with the authentication. Thus, a first embodiment corresponds to high-frequency authentication, on the order of a second or a few seconds, to issue an authentication certificate if the authentication is considered TRUE, and the authentication iteration steps continue after issuance of the authentication certificate.A second embodiment corresponds to an authentication of a recognition duration which will be said to be long, in particular of a duration of at least several minutes, or even several tens of minutes, the authentication certificate being issued only if the authentication is considered TRUE, and this after the first authentication step and several authentication iterations over the chosen recognition duration; this analysis over a long measurement duration increases the legitimacy of the authentication result. This authentication embodiment which combines continuous authentication and the analysis of physiological signals of an individual, provides good reliability of the result, the falsification of physiological signals and this over a long duration is relatively unlikely. This embodiment can be very useful in high security applications.

[0021] Advantageously, the authentication method implements, during at least one iteration step of identity authentication, automatic learning so as to renew one or more authentication models dedicated to said individual. According to one characteristic, the dedicated authentication models which were generated and retained during the prior learning step constitute first authentication models which are updated by automatic learning during at least one iteration step of the continuous authentication to constitute new dedicated authentication models and preferably to be taken into account for the next authentication. Thus, the authentication method continues the learning of recognition of the physiological signals of the individual during the time that the authenticated individual continues to wear the connected device.The module providing the learning then benefits from more data, which increases the reliability of the dedicated authentication models and therefore the reliability of the authentication process.

[0022] Preferably, the authentication method renews by learning during the authentication iteration steps of an individual, the authentication models and records N last authentication models which correspond to those immediately renewed and to those of one or more previous iteration steps, and the execution of the authentication method during a new and subsequent authentication fication (when the user has not worn the sensor for a certain time) is carried out from the last recorded authentication models or from a combination of the last N recorded authentication models. These phases of recording and retrieving the last authentication models or from a combination of the last N models, further increase the reliability of the authentication process and reduce the risk of rejecting an authentication whose result should have been TRUE. Indeed, an individual can change mood over a period, his health can change, and the resulting physiological signals evolve accordingly, the method of the invention will then make it possible to generate authentication models which will correspond as closely as possible to the current physiological state of the individual.

[0023] According to another characteristic, the method takes into account, for evaluating the authentication result which is of binary type (TRUE / FALSE), the quality of the signal and preferably the quality of the signal over a certain duration, in particular the quality of the signal being evaluated by processing the noise of the signal.

[0024] According to another characteristic, the method measures and evaluates several types of physiological signals for a single authentication. According to one characteristic, the method implements a group of authentication models per type of physiological signal and the method comprises an algorithm for evaluating the authentication from the combination of the recognition results from each of the groups of authentication models for each of the types of physiological signals.

[0025] According to another characteristic, the physiological signal(s) are chosen from the PPG and / or ECG signal(s) and / or the physical activity of the individual and / or their bioimpedance. In particular, the authentication method further comprises a step of evaluating the state of health of the individual from the captured physiological signals. The PPG signals use plethysmography sensors, also called pulse oximetry sensors, and relate to the measurement of changes in blood volume by measuring the quantity of light absorbed and reflected by the blood vessels; the PPG signal is associated with a cardiac signal because fluctuations in blood volume are generated with each heartbeat. As each individual has their own PPG signal, it is a fairly reliable method of authenticating an individual. Furthermore, PPG has the advantage of being a non-invasive technique.

[0026] According to another characteristic (in one embodiment), the method measures and evaluates other data than one or more physiological signals of the individual, said other data being processed so that the results are combined with the results of the physiological signal(s) to establish recognition, in particular said other data being, taken alone or in combination, biometric data such as fingerprint, face, iris, vein pattern, or a password which can be single use, a smart card, badge, certificate or encryption key on a removable medium such as a USB key, a validation action on a second device such as a telephone.

[0027] According to another characteristic, the method comprises a step of detecting a replay attack and / or a step of detecting forged signals. A replay attack is a third party who manages to capture the physiological signal of the individual and to record it in order to then use it in order to usurp his identity, by sending it to the sensor which delivers to the device for implementing the method of the invention the data which should normally be those of the individual.

[0028] According to another characteristic, the method comprises a step of detecting forged signals (signals generated artificially and therefore not originating from the data of the individual wearing the sensor(s).

[0029] According to one characteristic, the method uses a secure communications protocol such as HTTPS or chosen from other cryptographic protocols, in particular between the sensor(s) worn by the individual and a server to which the device for implementing the authentication method is connected.

[0030] The invention also relates to a system for continuous authentication of the identity of an individual, comprising electronic processing means and algorithms for implementing the aforementioned authentication method, the processing means comprising at least one recognition module per individual (and for a single type of physiological signal), a so-called IAM module for identity and access management, and a data storage module, the recognition module per individual generating by automatic learning the authentication models dedicated to the individual and in relation to a physiological signal. The algorithms will be diverse, for example support vector machines (also called SVM for "Support Vector Machine" in English), neural networks, decision trees, principal component analysis, genetic algorithms, etc.

[0031] According to one characteristic, the processing means of the aforementioned authentication system comprise a replay detection module, a forged signal detection module, and a module for evaluating additional data specific to the individual including their state of health.

[0032] Finally, the invention relates to a computer program comprising code instructions for executing the steps of the aforementioned authentication method, when said program is executed by a processor. The program can in particular be loaded onto a network of the Internet type.

[0033] The present invention is now described using examples which are solely illustrative and in no way limitative of the scope of the invention, and from the attached illustrations, in which: - [Fig.l] represents a flowchart of the authentication system capable of implementing the authentication method according to the invention to authorize a user to access an object X, via a connected device carried by the user. - [Fig.2] illustrates a flowchart of the authentication system used to authenticate multiple individuals.

[0034] The continuous authentication method of the invention of the identity of an individual aims to verify the identity of the individual a first time (initial authentication) and this passively without intervention of the individual, then to continue to verify over time that it is always the same individual (continuous verification of the authentication), and again passively without intervention of the individual, the authentication being carried out from physiological signals of the individual.

[0035] The continuous authentication method can be applied to various uses such as access to a physical object X, access to software, access to a place (via access to an object of the door type), etc.

[0036] As schematically illustrated in [Fig.l], the continuous authentication method is implemented by at least one connected device 1 worn by the individual and by an authentication system 2 arranged remotely from the connected device 1 and receiving all the data from said connected device 1. The authentication system 2 is capable of communicating with the object X. The authentication system 2 is adapted to receive the information from the connected device 1 and process it to authenticate the individual carrying the connected device 1 in order to authorize his access to the object X and continue the verification of the authentication as long as the connected device 1 is worn by the individual. The authentication system 2 is adapted to receive information from several connected devices 1-1, 1-2, 1-3, etc. ([Fig.2]) to authenticate individuals carrying said connected devices in order to authorize them access to an object (to the same object or to a different object for each individual) if they have been properly authenticated.

[0037] The authentication system 2 (via a so-called IAM module) is capable of issuing, after authentication, an access authorization certificate which will be valid for a determined period or which will have to be renewed at each authentication reiteration request to validate again the correct identity and the validity of the access rights to be granted. Each certificate is signed using an asymmetric encryption system so that all actors can ensure the authenticity of each document and avoid document forging.

[0038] The connected device 1 is for example in the form of a connected watch, a connected garment worn next to the skin, or a bracelet connected to a telephone (the telephone being able, if necessary, to serve as an interface for controlling the authentication and transmitting the authorization certificate). connected device 1 must be worn by the individual and will be arranged on the individual appropriately depending on the nature of the physiological signals to be captured.

[0039] The connected device 1 comprises at least one sensor 3 detecting at least one physiological signal. The nature of the physiological signals detected is for example a PPG signal (via a photoplethysmography sensor) or an ECG (via a sensor measuring cardiac activity) or a physical activity signal of the individual (via a three-dimensional accelerometer and a gyroscope as sensors) or a bioimpedance signal (via electrode-type sensors).

[0040] The authentication system 2 comprises at least one authentication module 20, also called a recognition module, an identity and access management module 21, called an IAM module (acronym in English "Identity and Access Management"), and a data storage module 22. A recognition module 20 is dedicated to a single individual. The authentication system 2 comprises one recognition module per individual, and possibly several recognition modules per individual, each relating to the measurement of a type of physiological signal. The recognition module 20 has algorithms implementing FIA. The storage module 22 records numerous data, including all access requests.

[0041] The access request is made by the individual on the object X. The object X delivers an identifier ID to the connected device 1 carried by the individual, the identifier ID being specific to the object X. From this moment on, the individual no longer has to intervene and simply has to wait for access authorization. The main steps associated with the authentication method for authorizing access by an individual carrying the connected device 1 to the object X are as follows: - the connected device 1 automatically connects to the authentication system 2 and transmits to it the ID of the object X and a physiological signal from the individual; - in the event of recognition by the authentication system 2, in particular by the recognition module 20, the latter issues an authentication certificate which is sent to the connected device 1 and which is recorded in the storage module 22 of the authentication system 2; - the connected device 1 having received the authentication certificate requests from the authentication system 2, in particular from the IAM module 21, an access authorization certificate by transmitting the object ID and the associated authentication certificate. A preferably encrypted copy of the access authorization certificate is written in the storage module 22; - the authentication system 2, in particular the IAM module 21, delivers, on the one hand, to the object X a copy of an access token (usually also called by the English term "token") with an identifier IDustiiser of the individual requesting access, and on the other hand, to the connected device 1, the certificate of authorization of access to the object X; - the connected device 1 in turn transmits to the object X, the access token and the IDustiizer identifier of the individual, which unlocks the object X, the individual being able to access it.

[0042] The database of the authentication system 2 comprises a library which associates with the identifier ID of the object X, one or more user identifiers IDmi lisateur*

[0043] Once the individual has had access to the object X and for a given security time (for example one hour), the user also does not need to interact with his connected device 1 as long as he is wearing it, the continuous authentication continues transparently for the individual, the connected device 1 continues to measure physiological signals of the user and to transmit them to the authentication system 2 which, as long as the recognition is carried out, will issue authentication certificates validating that access is still authorized. Furthermore, it is possible to provide that even after the continuous authentication duration, a subsequent authentication verification during the time of the usage session can be implemented by the authentication system 2.Furthermore, as will be seen later, the authentication method of the invention advantageously continues to collect data from the individual during his session, even if the continuous authentication has stopped (because, for example, the duration of one hour has elapsed).

[0044] The authentication system 2 is therefore capable of: - recognize the connected device(s) 1; - process the data received from the connected device(s) 1, - issue and transmit the authentication certificate(s) following the access request, or reject the request for lack of authentication, - communicate with object X to deliver copies of access tokens to it, - issue access authorization certificates, - continuously issue and transmit authentication certificates, - store received and sent data, in particular a copy of authentication certificates and authorization certificates.

[0045] Furthermore, in addition to authentication and granting access authorization, the authentication system 2 may detect, evaluate and / or transmit other information, including: - provide stability over time of recognition through continuous learning, - assess the signal quality, - transmit alerts, - detect replay, - detect forged signals, - detect a brute force attack, - increase the performance of rejecting (unknown) imposters by using data from known imposters, i.e. those whose authentication model results are known to have been tested with known individuals who are not the individual to be authenticated, - provide multiple information regarding authentication / identification, such as • the state of health of the individual wearing the connected device (sleep, stress, physical exertion generating a cardiac health problem, etc.), if for example the heart rate is high and the individual makes no movement, the system deduces a potential state of stress, or if the heart rate is low and the individual makes no movement, the system deduces that the individual is in a phase of sleep or low consciousness; • the position or geolocation of the individual, or the detection of the individual's movement in an area.

[0046] Depending on the duration of the authentication and the number of iterations, the authentication method makes it possible to offer several levels of security.

[0047] In addition, the authentication system 2 has the advantage of being adaptable at any time by adding multiple recognition modules (each time a new user is added) which are specific to each individual. In particular ([Fig.2]), the authentication system 2 comprises a plurality of recognition modules 20-1, 20-2, 20-3, etc. which are each dedicated to an individual carrying a respective connected device 1-1, 1-2, 1-3, etc. This characteristic will be developed further. Thus, unique authentication models per individual (a group of authentication models per type of physiological signal) are generated by a recognition module dedicated to an individual, completely independently of the population of individuals.There is therefore no need, unlike in the prior art, to know and record the data of a multiplicity of individuals according to a targeted group in order to establish a data transformation rule dependent on all these individuals, nor to carry out new learning from the data of the ex-individuals (which may have evolved over time) and the data of one or more individuals who are to be added in order to establish a new transformation rule taking into account the ex-individuals and the added individuals.

[0048] The authentication method more particularly comprises the following steps: - Step 1: measurement and recording of the signals delivered by the measuring device such as the sensor 3 according to an acquisition duration and preferably an acquisition frequency; - Step 2: transmission to the authentication system 2 of the physiological signal data, which relate to initial identity information, and possibly actually concomitant transmission of a second identity information in the form of a unique key (encrypted or not) linked to the sensor 3. This unique key can be contained in a dedicated crypto-processor if the measuring device has one; - Step 3: selection by the authentication system 2 of the recognition module 20 dedicated to the user of the sensor 3; this is a personal recognition module 20 for each individual to be authenticated which has in memory a group of authentication models dedicated to the user. The generation of the group of authentication models is described later. The analysis of the authentication is obtained by comparing the data captured from the individual during the recognition step with the authentication models specific to the individual, which are in memory in the recognition module 20, then by associating a probability of correspondence with the comparison result with each of the authentication models and finally by processing the probabilities to deduce a result of acceptance of the authentication (TRUE) or rejection of the authentication (FALSE).Each recognition module 20 delivers, during an authentication request, a result which is binary, TRUE or FALSE, and which is associated with the different probability values ​​or confidence index which resulted from the comparison with each of the authentication models. Preferably, the result VRAFFAUX comes from a decision tree with respect to the probability values ​​resulting from the results of comparison of the captured data with the authentication models. Among the algorithms implemented by the recognition module 20, one of the algorithms provides an initial authentication and several iterations of the authentication, the iterations will be carried out before and / or after the delivery of the TRUE / FALSE result depending on the desired degree of security. - Step 4: the recognition module 20 (20-1 for a given individual) sends to the IAM module 21 the TRUE / FALSE value, associated with the user ID and the probability or confidence index values ​​of the comparison results with the authentication models, and preferably a list of the Y best identified impostors (which are known impostors because they are considered as other users and have their own recognition module 20-2, 20-3, etc.); - Step 5: this step is optional but preferred; the IAM module 21 requests recognition of the Y known impostors from the recognition modules of the other individuals registered in the authentication system 2. The recognition modules of the other individuals independently return to the IAM module 21 the TRUE / FALSE value for each of the Y known impostors, as well as the associated probability or confidence index; - Step 6: the IAM 21 module issues a unique identity certificate for each authentication mentioning several pieces of information which are listed below as example.

[0049] In step 1, the acquisition duration for measuring physiological signals for the purpose of initial authentication will in particular be adapted to the nature of the physiological signal and the degree of security required in relation to the intended application. The acquisition for the initial authentication will preferably be periodic, for example at a frequency of one second. Then, during the continuous verification iteration phase of the authentication, the measurement will be periodic and / or random.

[0050] Concerning steps 2 and 3, the authentication system 2 advantageously comprises several recognition modules 20 (20-1, 20-2, 20-3, etc.), each dedicated to a user. A recognition module 20 is a personal module because it is dedicated to a single individual from a group of unique authentication models which depend solely on the individual's data and which are independent of the data of other individuals. In addition, the recognition module 20 is dedicated to a type of signal, for example PPG or ECG or physical activity or bio-impedance. The authentication system 2 can therefore comprise several recognition modules 20A, 20B, 20C, etc., per individual and dedicated to the measurement and authentication with respect to a type of physiological signal (20A for PPG, 20B for ECG, etc.).Each type of physiological signal will be associated with a group of authentication models, said authentication models of a group having been generated beforehand as will be described later, in relation to the type of physiological signal measured.

[0051] More particularly, the recognition module 20 which is personal to each individual (and independent of other individuals) is capable of: - prior to an authentication request (i.e. prior to step 1), generate a group of unique authentication models for the individual by having processed at least one type of physiological signal over a period known as the prior learning period, this step being known as the prior learning step; - authenticate the individual when an authentication request is received (steps 1 to 6 cited above), by comparing the measured physiological signal(s) with the group(s) of unique authentication models generated at the end of the preliminary learning step by type of physiological signal; - continue learning during authentication requests, via the signals measured during each of the requests, to generate a group of authentication models that are always unique with respect to the individual and updated (to take into account the possible evolution of the physiological signals of the individual, which may vary over time, in particular depending on the state of health of the individual). Note that the prior art does not allow this step, which is subsequently called the step of updating the authentication models with respect to the individual (the prior art having a single transformation rule that remains the same over time).

[0052] For the purpose of initial authentication (step 1), prior learning of the user's data has therefore been carried out over a given duration and according to a recording protocol. The prior learning is carried out for example over a day, during which the individual has worn the connected device 1 and has passed during different periods through phases of rest and activity, or even also emotions, in order to obtain a large plurality of ranges of the individual's heart rate. Several variations of the recording protocol can be implemented. For example, the recording periods will be different for a sedentary individual, in particular by reducing them. During the prior learning step which corresponds to a first session, it is the operator of the authentication system 2 who manually associates the connected device 1 with a user.The connected device 1 contains a first token that can be used by the user as long as the user wears the connected device (such as a bracelet connected to the wrist). In parallel, the authentication system 2 therefore continuously records the data from the sensor(s) of the connected device 1 to carry out the preliminary learning, as indicated for, for example, one day. The more time passes during the day, the more reliable the authentication system 2 becomes. Once the preliminary learning step is complete, the first token is replaced by an automated authentication token issued by the authentication system 2 and the continuous authentication process can begin as soon as necessary.

[0053] During the preliminary learning, the recognition module 20 implements one or more algorithms by automatic learning, according to several steps to: i) generate from the extraction of characteristics relating to a type of physiological signal measured from the individual, a multitude of authentication test models (for example a hundred), then (ii) testing said authentication test models with the individual's signals considered to be authentic, iii) rank the best test models (those with the highest probability of recognizing the individual) and, iv) retain only a group of the best (for example around ten) tested models which are called authentication models.

[0054] The multitude of authentication test models is obtained by machine learning from discriminating characteristics of the captured data. The multitude of models generated with the individual's data and the fact of having tested them all to retain only a reduced group, the best models, provides authentication models that will be as reliable as possible for the authentication of the individual. The group of authentication models is coupled with a unique key linked to the identity of the user (IDustriizer).

[0055] Concerning the extraction of data regarding the physiological signals to carry out step i) of generating the multitude of test models, the recognition module 20 implements steps or phases known per se of data processing (via algorithms) which are the phases of pre-processing (in particular according to a given type of windowing), of filtering (for example using a Fourier Transform and / or by digital filtering) which can be carried out before the pre-processing, of extraction of (many) characteristics and of selection of these characteristics (advantageously by automatic learning, for example according to a PCA function (for “Principal Component Analysis” in English or APC for “Analysis en Composantes Principales” in French)) and finally of classification (for example by SVM for “Support Vector Machine” in English, or by neural network).Some neural networks are suitable for performing the extraction, selection and classification steps. The algorithms for performing these different phases may also be genetic algorithms. The steps or phases of preprocessing, filtering, extraction, selection and classification to generate a test model each time may each use different types of methods (as exemplified above: different types of windowing, different filtering methods (Fourier Transform or other), different extraction methods (PCA or APC), etc.). Preferably, according to the invention, the algorithms that make it possible to perform these phases and subsequently generate a multiplicity of test models, implement, possibly randomly in certain test model results, various combinations of the different methods specific to each of the phases.

[0056] Advantageously, in step i) of generating a multitude of authentication test models, the data processing uses not only the data of the individual but also the data of at least one known imposter, the quantity of data used from all the known imposters considered in the generation of the multitude of test models not having to exceed the ratio between the total quantity of data of the individual and the number of known imposters.

[0057] Preferably, at least the test models retained as authentication models have also been tested during step ii) with the data of at least one known imposter to verify that the probability of recognition confidence with this data of a known imposter is indeed extremely low or even zero. This test using data from an imposter makes the test models ultimately retained more reliable.

[0058] Concerning authentication, if imposters are detected, the recognition module 20 contains the list of Y people having the highest imposter score, and has advantageously compared this list with the other individuals registered and linked to their recognition module. If necessary, this makes it possible to eliminate from the list of impos- posters, known individuals.

[0059] Furthermore, very advantageously, the recognition module 20 presents its automatic learning algorithm which makes it possible to continue learning to recognize the physiological signals of the individual during the time that the individual continues to wear the connected device 1 after having been authenticated for the first time; the learning continues throughout the duration of the continuous authentication verification and even after, as long as the connected device is worn (according to a given number of times and / or periods). This continuous learning helps to increase the legitimacy of the continuous authentication result and of a next initial authentication (during a new access request), resulting in increased security. Indeed, it has been shown that the initial authentication performance drops by 15 to 30% when a relatively long period has elapsed, such as a week for a new access request by the same individual.However, the inventors have demonstrated that continuous learning during continuous authentication verification increases authentication performance not only during continuous verification but also during a next authentication. In particular, part of the signals used for continuous authentication over a day are retained, used to create a new dataset and to train new test models and deduce a new group of updated authentication models always dedicated to the user. This new group of updated authentication models is stored in a chain such as a blockchain, and thus makes it possible to trace all the learning of the authentication models.At each new authentication, it is the last recorded group of authentication models that will be used to determine the identity of the user, contributing to greater reliability of the authentication result. Alternatively, the recognition module 20 can respond to an authentication request from the last N authentication models (corresponding to the last recorded group of authentication models and to one or more other previously recorded groups), which further increases security. In addition, the conservation in the form of chains of the different versions of the authentication models and the associated results of the authentications, facilitates investigations in the event of an attack on the authentication system 2.If an attacker is able to modify the training set to insert his personal data in place of that of the user, the system will be able to recognize the attacker as an illegitimate user.

[0060] Concerning the authentication iterations, these can be carried out after determining a result in order to confirm the authentication over time, or can be carried out over a so-called long period in order to carry out several verifications before delivering the result.

[0061] In step 6 of generation of the identity certificate by the IAM module 21, the data which are included in this certificate are for example: - the timestamp (corresponding to the “timestamp” in English), - identity validation (TRUE) or rejection (FALSE), - the period / end date of validity of the access authorization, - certified identity (certified user ID), - the identity token (which is unique and random). Additional information may be included such as: - the list of signals used for authentication, - the decision taken by each recognition module and the associated confidence index, - the health status of the wearer, - the detected activity, - the number of signals and the signal quality, - the cryptographic signature of the certificate. This additional information is particularly useful in the event of an investigation and intrusion detection. This additional information could be stored in a specific processing module linked to the intrusion.

[0062] In order to further improve the relevance of the authentication system 2 and contribute to its overall security (so as to deceive attackers), various information relating to authentication and identification is preferably added, in addition to the data already listed above, and which is written in the individual's file recorded in the storage module 22. This additional information is in particular: - activity detected (walking, running, resting, working on a computer, etc.) via an accelerometer and a gyroscope, - emotional state (calm, stressed, excited, fear etc.), - overall health status (good, bad, average), - accident detection (fall, arrhythmias, heart attacks, sudden changes in blood pressure, etc.), - internal geolocation (area of ​​a radius defined using proximity sensors or terminals or badge systems, etc.), - GPS geolocation, - environmental information such as brightness, ambient noise, - body temperature of the individual (via appropriate sensor), - oxygen saturation in the blood (via appropriate sensor).

[0063] Among the information listed above, the health status of the individual after authentication may play an importance in security or safety depending on the intended application. For example, the rapid deterioration of the health level of the authenticated individual could result in a sudden health problem or an attack against him, which must be detected in ultra-sensitive environments such as military or nuclear centers. This change of state is intended to be taken into account by the authentication system 2 to alert and / or lead to automated decisions. The individual's state of health is notably checked from his heart rate, respiratory rate, sleep duration, body temperature and oxygen saturation, these parameters being measured from the connected device 1 which includes the appropriate sensors. The processing of this data provides a score relating to the state of health; depending on the value of the score compared to a reference value, for example below the reference value, the authentication system 2 will send an alert, temporarily block access, or request hierarchical validation.

[0064] In addition to the detection and processing of physiological signals, the authentication method may use other biometric parameters to complete the authentication, such as, for example and in a non-exhaustive manner: fingerprint, iris, face, geometry of the hand, shape of the veins of the hand, dedicated gestures.

[0065] In addition to authentication by physiological signals, the authentication method may use authentication protocols which do not use biometric data and relate to an interaction with the object to which access is requested by the individual, such as for example by password, single-use password, smart card, badge, certificate or encryption key on removable media (USB key, hard disk), action and / or validation on a second device such as a telephone.

[0066] Advantageously, the authentication method of the invention takes into account, in order to evaluate the authentication result (TRUE / FALSE), the quality of the signal sent by the connected device 1 and received by the authentication system 2. The evaluation of the quality of the signal corresponds to the evaluation at least of the noise of the signal. A poor quality signal may come from events such as movements on the sensor or external conditions. Such events may for example be for a bracelet as a connected device, a change in the way the wrist is worn, a change of wearer, a possible attack on the wearer of the bracelet, a fall or a loss of consciousness.

[0067] Thus, the authentication method comprises a step of evaluating the quality of the signal, this step combined with the step of processing the physiological signals received, leads to a step, before the generation of the recognition result, of rejecting the unusable signals instead of rejecting the identity of the individual. In addition, the temporal monitoring of the quality of the signal also makes it possible to detect the correct wearing of the sensor on a long duration (in particular at least ten minutes). Perfect signal quality over a long time can, for example, show a forging attack. In order to determine the proportion of poor quality signals, a Fourier Transform will be used, for example. In order to evaluate the quality of the signal, the authentication system 2 includes a signal quality evaluation module (over a certain duration) comprising at least one signal quality (noise) evaluation algorithm of the type, for example, KNN (for "K-nearest neighbors" in English or "K nearest neighbors" in French) or SVM. Thus, over a duration, for example, of one hour, the signal quality evaluation module determines the parts of the signal that are too noisy to be exploitable and gives probabilities on the actual wearing of the connected device 1 by the user.This evaluation can also be done over repeated time intervals, particularly between several minutes to several hours depending on the needs, which adds to the authentication security. In addition, it is possible to add modules dedicated to the analysis of user movements (via accelerometer and gyroscope) in order to improve predictions and associate noise with typical user movements. This will, for example, make it easier to detect incidents such as device removal or injection of forged signals.

[0068] Furthermore, the authentication system 2 may comprise a signal quality improvement module based on appropriate filters, such as Butterworth filters, FIR, auto-encoders, etc.

[0069] Advantageously, the authentication method of the invention includes a method for detecting forged signals and for accelerating the recording of the user's data (and therefore accelerating the prior learning by the recognition module 20). The authentication system 2 comprises for this purpose a forging detection module 23 with one or more associated algorithms and in connection with the recognition module 20. An example of a method for detecting forged signals and for accelerating the recording of the data is to artificially generate signals resembling those of the users being recorded (the generation of artificial signals such as ECG signals is known per se). By artificially modifying the data, it will be possible to detect a possible attack which would aim to reproduce only artificial data and not combined artificial and authentic data of an individual.

[0070] Advantageously, the authentication method of the invention makes it possible to detect attacks (a third party who will send into the sensor 3 data of the individual which will have been recorded previously without his knowledge). Various methods of detecting replay attacks can be implemented. For example, one method consists of using a hash function and keeping a large number of “hashes” of the signals. In addition, by coupling to the method of detecting replay attacks an algorithm of "picewise hashing", the authentication system 2 allows to detect the reuse of pre-recorded signals.

[0071] Advantageously, as already indicated above, the authentication method of the invention is capable of identifying the best imposters (users who attempt to pass themselves off as the authentic individual). For this purpose, the step of identifying the best imposters comprises the calculation of a success score for each user and the calculation of a success or imposture score for each imposter facing this user. Considering that the distributions of the scores for the user and the imposter scores follow two respective normal laws, their intersection and the size of this intersection, more or less large, will be considered to determine the probability for an imposter to succeed in being authenticated by the authentication system during an attack. The smaller the size of the intersection, the more the authentication system 2 guarantees reliable authentication of the user.Thus, in order to further improve authentication and identification, the authentication process establishes the list of the Y best impostors for each user and, at each authentication of the user, attempts to authenticate these Y best impostors (compared to the other individuals known in the authentication system via the different recognition modules dedicated to each registered individual); this makes it possible to reduce the probabilities and scores of each of these impostors finally known to the user in order to obtain a validation for the user and a rejection for each impostor. However, this step of identifying the best impostors being a resource-intensive task, it will only be advantageously used in case of doubts about the identity of the person or in case of authentication for an ultra-sensitive action.

[0072] An example of a connected device associated with an example of implementation of the authentication method of the invention is now described.

[0073] For the first example, a connected watch is used as connected device 1. The majority of connected watches have the following sensors: PPG (for heart rate and SpO2 for oxygen saturation), three-dimensional accelerometer (detection of sports activity), gyroscope, and bio-impedance sensor to detect whether or not the object is being worn. The authentication method then uses as sensors 3, the PPG sensors, the three-dimensional accelerometer and the gyroscope. Two recognition modules are implemented, a recognition module 20A for PPG and a recognition module 20B for movement using the signals from the accelerometer and the gyroscope. The data from the bio-impedance sensor will be used to determine whether or not the watch is being worn.The authentication process aims to determine whether the wearer of the watch is the correct user and, if so, to issue an identity certificate so that the user can use it to be authorized. to access, for example, software or a physical space. If the state of the bioimpedance sensor changes (the watch is no longer worn), the tokens and the watch's memory are reset.

[0074] In this example of a watch, an authentication frequency of, for example, once per minute with a measurement time of 30 seconds is considered. Wearing the watch by a good user can give access to a secure room; in the case of a secure room, it can be required that the continuous authentication be relatively long, for example according to a ten-minute verification. The watch continuously measures the signals from all the sensors and stores them in memory. Every minute, the watch transmits the last minute of signal to the authentication system 2 which analyzes the last 30 seconds in order to validate the identity of the user (authentication). The authentication analysis consists of implementing the aforementioned steps 1 to 6 of the authentication method.Previously, the watch was worn for a certain time so that the authentication system 2 generates a group of authentication models unique and specific to the individual from the selection of the multitude of authentication test models that were implemented by machine learning of the individual's personal data alone. Subsequently, during an authentication request, if the identity has been validated by the authentication system 2, it then produces an authentication certificate that may contain the following information: date, validation or rejection of the identity, the confidence level, the signal quality, the emotional state, the state of health, the SpO2 saturation, the validation of the non-change of state of the bio-impedance sensor (no removal of the watch), the detected activity, the identity token.In return, the identity token is transmitted to the user's watch 1, which can use it to authenticate to software services or access a physical space to which they are authorized. When the accredited user wants to access a secure room based on a continuous 10-minute authentication, the authentication system 2 will analyze the last ten minutes of physiological signals recorded via the smartwatch to validate a second time the identity and the continuity of the authentication states over the last ten minutes of wearing the watch. If successful, a new identity certificate and a token are issued so that the user can access the room.As long as the watch remains worn by the user who is in the room, the continuous authentication process continues, always transparently to the user, allowing the user's data to continue learning in order to update the user's authentication model pool.

[0075] In another example, the user wearing the connected watch implements the continuous authentication method of the invention to protect his telephone and his watch as well as his personal data. When first wearing the watch connected, the authentication system 2 (on server) collects a certain number of PPG signals transmitted by the connected watch to generate by machine learning the authentication models dedicated to the user. Once the group of authentication models has been generated, it is saved in the user's phone. Subsequently, each time the user needs to authenticate with the phone, the watch sends the PPG signals to the phone which implements (via a specific software application) the authentication analysis from the dedicated authentication models (of the group) saved in the phone in order to recognize the user. Regularly, part of the authentication data of the day will be transmitted from the phone to the recognition system 2 on server in order to continue training the user's dedicated authentication models and update them.

Claims

Claims

1. Method for continuous authentication of the identity of an individual, comprising a first authentication step by the recognition of at least one physiological signal of the individual transmitted by at least one sensor worn passively by the individual, and after the first authentication step, at least one iteration step of authentication of the identity by the recognition of said at least one physiological signal of the individual, characterized in that - prior to the authentication and authentication iteration steps, the method comprises i) a so-called prior learning step which consists of processing by automatic learning the data of at least one physiological signal specific to the individual to generate a multitude of authentication test models, ii) testing this multitude of authentication test models with the data of the individual which continue to be captured,iii) to classify the authentication test models according to their relevance of probability of correspondence with the individual's data and iv) to retain only a selection of a group of authentication test models classified with the best probability of correspondence, these selected authentication test models being the so-called authentication models which are retained for the authentication and authentication iteration steps; - the authentication and authentication iteration steps consist of comparing the captured data of the individual with the authentication models specific to the individual, of associating a probability of correspondence with the result of comparison with each of the authentication models and of processing the probabilities to deduce therefrom a result of acceptance of the authentication or of rejection of the authentication.,

2. Method according to claim 1 characterized in that in step i) which consists of generating a multitude of authentication test models, the processing of the data exploits not only the data of the individual but also the data of at least one known impostor, the quantity of data used from all the known impostors considered in the generation of the multitude of test models not having to exceed the ratio between the total quantity of data of the individual and the number of known impostors.

3. A method according to claim 1 or 2, characterized in that, in step ii), at least one test model is tested using data from at least one other individual considered to be a known imposter.

4. Method according to any one of the preceding claims, characterized in that the processing of the probabilities which are associated with the results of comparison of the captured data with the authentication models, to deduce an acceptance or rejection result, is implemented by a decision tree.

5. Method according to any one of the preceding claims, characterized in that it comprises a step of issuing an authentication certificate when the recognition is accepted, the authentication iteration steps being carried out after the first authentication step and the issuing of the authentication certificate, or the authentication iteration steps being carried out following the first authentication step and before issuing the authentication certificate.

6. Method according to any one of the preceding claims, characterized in that it implements, during at least one authentication iteration step, automatic learning to renew one or more authentication models dedicated to said individual.

7. Method according to the preceding claim, characterized in that it renews by learning during the iteration steps of authentication of an individual, the authentication models and records N last authentication models which correspond to those immediately renewed and to those of one or more previous iteration steps, and in that the execution of the authentication method during a new and subsequent authentication is carried out from the last authentication models recorded or from a combination of the N last authentication models recorded.

8. Method according to any one of the preceding claims, characterized in that it takes into account, when evaluating the authentication result which is of binary type (TRUE / FALSE), the quality of the signal and preferably the quality of the signal over a certain duration, in particular the quality of the signal being evaluated by processing the noise of the signal.

9. Method according to any one of the preceding claims, characterized in that the physiological signal(s) are chosen from the PPG and / or ECG signal(s) and / or the physical activity of the individual and / or his bio-impedance, in particular the authentication method also includes a step of evaluating the individual's state of health based on the physiological signals captured.

10. Method according to any one of the preceding claims, characterized in that it implements a group of authentication models per type of physiological signal and the method comprises an algorithm for evaluating the authentication from the combination of the recognition results from each of the groups of authentication models for each of the types of physiological signals.

11. Method according to any one of the preceding claims, characterized in that it measures and evaluates other data than one or more physiological signals of the individual, said other data being processed so that the results are combined with the results of the physiological signal(s) to establish recognition, in particular said other data being, taken alone or in combination, biometric data such as fingerprint, face, iris, vein pattern, or a password which may be single-use, a smart card, a badge, a certificate or an encryption key on a removable medium such as a USB key, a validation action on a second device such as a telephone.

12. Method according to any one of the preceding claims, characterized in that it comprises a step of detecting a replay attack and / or a step of detecting forged signals.

13. Continuous authentication system (2) of the identity of an individual, comprising electronic processing means and algorithms for implementing the authentication method according to any one of the preceding claims, the processing means comprising at least one recognition module per individual (20), a so-called IAM module (21) for identity and access management, and a data storage module (22), the recognition module per individual generating by automatic learning the authentication models dedicated to the individual and in relation to a physiological signal.

14. Authentication system according to the preceding claim, characterized in that the processing means comprise a replay detection module, a forged signal detection module, and a module for evaluating additional data specific to the individual including their state of health.

15. Computer program comprising code instructions for executing the steps of the authentication method according to any one of claims 1 to 12, when said program is executed by a processor.

Citation Information

Patent Citations

  • Systems and methods for providing a continuous biometric authentication of an electronic device

    US20220012317A1

  • System and method for enabling continuous or instantaneous identity recognition based on physiological biometric signals

    WO2012151680A1