Method for securing access to a data source

A method using a time-varying light signal and classifier for real-time image analysis addresses fraud vulnerabilities in remote biometric authentication, ensuring secure access by detecting injection and presentation attacks effectively.

FR3161972B3Active Publication Date: 2026-03-27IDEMIA PUBLIC SECURITY FRANCE
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2024-06-20
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing methods for remote biometric authentication, such as face recognition, are vulnerable to frauds like injection and presentation attacks, which are inconvenient for users, especially those with mobility disabilities, and lack robust security.

Method used

A method using a terminal with a light source and camera that applies a time-varying, randomly controlled light signal to capture images, estimates the contribution of this signal in the acquired video, and uses a classifier to determine fraud by analyzing temporal signals, ensuring the video was captured in real-time and not from a third-party object.

Benefits of technology

This method provides robust protection against fraud without user discomfort, requiring no specific synchronization or image-by-image analysis, and is adaptable to various devices, ensuring secure access to data sources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000027_0000
    Figure 00000027_0000
  • Figure 00000027_0001
    Figure 00000027_0001
  • Figure 00000028_0000
    Figure 00000028_0000
Patent Text Reader

Abstract

METHOD FOR SECURING ACCESS TO A DATA SOURCE The present invention relates to a method for securing access to a data source from a terminal (1) by a user of said terminal, the terminal comprising a light source (5) and a camera (3) oriented towards said user, said method comprising the steps of: - acquiring a time-domain signal; - controlling, during the acquisition step, the light source (5) according to a time-varying signal of imposed and randomly fixed fundamental frequency, - evaluating the presence of fraud by presentation by: - ​​estimating, by area of ​​interest, a contribution of the imposed signal to the acquired time-domain signal so as to form a return vector, - determining a score by applying a classifier to said vector, - authorizing continued access to the data source based on the determined score. Figure for the abstract: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for securing access to a data source. Technological background.

[0001] The present invention relates to the field of securing remote access to data sources, whether during enrollment (for example, to create an online account) or during account access. Indeed, mobile applications typically require biometric authentication of the user on their connected device (such as a mobile phone, smartwatch, tablet, or computer) for remote access. To this end, a camera on the connected device remotely acquires an image of the user's face in order to authenticate the user.Nevertheless, frauds exist during this type of acquisition, so it is necessary to secure this step and detect potential frauds, in particular injection frauds (emulation of a virtual camera) (called in English: "Injection Attack") or presentation frauds (called in English: "Presentation Attack"), which notably includes frauds shown on paper, screen.

[0002] It is known, for example in document FR3100074, to ask the user to perform a randomly determined gesture, but this can be inconvenient for the user, particularly if the latter suffers from a disability affecting their mobility. Presentation of the invention

[0003] The invention aims to remedy at least some of these drawbacks and preferably all of them, and in particular aims to provide a method of securing remote access to a data source which is robust to fraud by injection or presentation and accessible to all, without discomfort or effort on the part of the user.

[0004] According to one aspect of the invention, a method is proposed for securing remote access to a data source from a terminal by a user of said terminal, the terminal comprising a light source and a camera directed towards said user, said method comprising steps of: - video acquisition by the camera; - control, during the acquisition stage, of the light source according to an imposed time-varying signal of which at least one parameter is time-invariant and of randomly fixed value; - Evaluation, based on an initial series of images from the acquisition, of the presence of fraud by presentation by: - estimation, by area of ​​interest, of a contribution of the imposed signal to a temporal signal of the first series of images in order to form a return vector, - determination of a score by application of a classifier to said vector, - authorization to continue access to the data source according to the score determined.

[0005] This method addresses the drawbacks listed above and is preferably applied to a connected mobile terminal (such as a mobile phone, smartwatch, tablet, or computer). It thus secures access both in an enrollment context (for example, for creating a bank account) and in a consultation context (for example, for proof of identity in an administrative procedure or for accessing online accounts). The method can also be applied to a fixed terminal (such as an airport kiosk or a physical access system, where the remote data source is, for example, a list of authorized access persons). Indeed, this ensures that the acquired video was captured by the terminal's camera and provides robust protection against screen fraud or fraud by presenting a printed photo, for example.The process does not require estimation of the challenge parameter in the acquired signal, nor any specific synchronization with a dedicated event to identify a specific sequence. Therefore, there is no need to analyze the acquired images one by one, making the process more flexible and less memory-intensive. Furthermore, the contribution can be estimated from a periodic, imposed signal, but not exclusively; for example, from frequency-modulated signals (e.g., two color components whose invariant parameter is a fixed ratio of instantaneous frequencies between said components) by applying a bandpass time-domain filter covering the frequency band used during modulation. Finally, if the score indicates the presence of fraud per presentation, access to the data source cannot continue.

[0006] In one embodiment, at the evaluation stage: - at least one area of ​​interest is determined within a detected region of interest, said area of ​​interest being common to the images of the first series, - a time-domain signal representative of the pixel values ​​of the images in the first series of images over all or part of the area of ​​interest is determined; - during the estimation, the temporal signal of the first series of images is the temporal signal observed per area of ​​interest; this allows for the consideration of one or more dedicated areas significant from the point of view of the expected reflection in relation to the expected local shape of the user in said area, and also for reducing the size of the data to be transmitted in the case of an estimation step of the contribution and a scoring stage that is offloaded to a remote server, for example.

[0007] Advantageously, said classifier is implemented by a neural network, which allows for fast processing with good classification performance.

[0008] Advantageously, the method may include an intermediate step of determining the probability of fraud per presentation as a function of the score determined; with authorization to continue access to the data source if the probability of fraud per presentation is less than a first predetermined threshold.

[0009] Equivalently, a probability of no fraud per presentation can be determined and in this case the threshold condition applies if said probability is greater than another predetermined first threshold.

[0010] Advantageously, if several time-varying time signals are imposed, as many time signals are observed per area of ​​interest, the return vector being formed of as many sub-vectors as there are time-varying signals imposed, which makes it possible to have at the input of the classifier a vector of vectors (also called a matrix, with for example as many columns as there are imposed signals (periodic color components in particular) and as many rows as there are areas) making the classifier robust.

[0011] Advantageously, the method may include a step of determining, by area of ​​interest, the contribution of other lighting sources by subtracting the contribution of the imposed signal from the observed variable signal in order to form a subvector of the return vector. This allows the use of a vector of vectors as input to the classifier, making it more efficient. Furthermore, since the contribution of the imposed signal to the acquired signal is small, the contribution of other lighting sources can also be approximated by a simple time average of the acquired signal.

[0012] In one embodiment, the region of interest includes all or part of a face, which does not require any specific manipulation by the user of the terminal, the latter being accustomed to orienting it towards his face, the front camera performing the acquisition.

[0013] Advantageously, prior to the step of determining the area of ​​interest, a step of spatial alignment of said images of the first series with respect to a reference point of the detected region of interest is implemented for each image of the series, for example by eye registration, which makes it easier to determine the area of ​​interest corresponding for example to the same portion of the face in the different images of the first series.

[0014] Advantageously, the area of ​​interest is a triangle of a mesh of the region of interest, or a pixel in the vicinity of a point of interest of the region of interest, said A point of interest is present in all the images of the second series. For example, a point of interest is a semantic point on the face.

[0015] In one embodiment, the imposed time-varying signal is a periodic color component whose time-invariant parameter is a fundamental frequency, thus enabling a simple and rapid spectral analysis of a periodic signal. Said color component of the observed time signal is then extracted from the observed time signal representative of the pixel values ​​of the images in the second series of images over all or part of the detected region of interest in order to estimate said at least one time-invariant parameter of the observed time signal.In addition, several imposed time-varying signals corresponding to multiple color components (e.g., red and blue) can be driven, thereby increasing the diversity of the challenge, as each signal (color component) is analyzed, and the authorization to continue accessing the data source is a function of the multiple differences in values ​​of the invariant parameter, here the frequency, calculated for each of the components concerned between the imposed signal and the observed signal.

[0016] Preferably, in the visible spectrum, only the red component and the blue component are imposed time-varying signals, which facilitates analysis because this choice makes the process robust to color crosstalk, linked for example to the fact that the red channel of the camera sees a little of the neighboring green channel of the light source, the green component remaining invariant over time.

[0017] Advantageously, the imposed time-varying signal is applied to an infrared component, which makes it possible to implement the light variation process outside of visible wavelengths without the user noticing.

[0018] Advantageously, each imposed time-varying signal is periodic, the invariant parameter of each signal being its fundamental frequency, which facilitates the estimation of the invariant parameter in the observed signal, via spectral analysis.

[0019] In another embodiment, the imposed time-varying signal comprises at least two color components, and the invariant parameter of the signal is an instantaneous frequency ratio between said at least two components. This notably allows the use of non-periodic color components, for example, frequency-modulated components whose modulation follows a fixed ratio.

[0020] Alternatively, the imposed time-varying signal comprises at least two periodic color components of the same fundamental frequency or multiples thereof, with a phase shift between said at least two components, said at least one time-invariant parameter of the imposed signal being said fundamental frequency or the phase shift, preferably the two. This allows in particular to have several invariants: a fundamental frequency, preferably unique and identical for each time-varying color component of the signal, and the phase shift between said components, which makes the challenge more diverse.

[0021] In one embodiment, the imposed fundamental frequency is set randomly within a range [0.5Hz, 3Hz], which promotes user comfort and allows for the use of standard sampling of 15 frames per second, for example, the fundamental frequency being unique for all the components concerned or differentiated by component.

[0022] In one embodiment, the terminal comprises a display screen, the light source being all or part of the terminal's display screen, and the control of the light source corresponding to a display on all or part of the screen with a color that varies according to the time-varying signal imposed. This preferred method allows the terminal to be held in the usual way, particularly if the terminal is a tablet or a mobile phone, without having to, for example, turn it over, thus avoiding handling difficulties and remaining discreet.

[0023] Advantageously, at least one imposed time-varying color component is of the square wave type, which allows a simple signal to be driven.

[0024] In one embodiment, the imposed time-variable signal is sinusoidal, that is to say that the component or at least one of the imposed time-variable color components is sinusoidal, which is simple to control, and in particular if both time-variable color components of the signal are sinusoidal, the spectral analysis is further simplified because only one peak appears per color component.

[0025] Advantageously, at least one imposed time-varying color component is of the triangular type, which allows for easy control.

[0026] Advantageously, the imposed time-varying color components are of different types, with, for example, a triangular blue component and a sinusoidal red component, this mixture allowing the diversity of the challenge to be increased.

[0027] In one embodiment, the method includes a step of evaluating, from a second series of images from the acquisition, the presence of fraud by injection or recapture by: - estimation of said at least one invariant parameter of a time signal from the second series of images; - The step of authorizing continued access to the data source is a function of the fixed value and the estimated value of at least one invariant parameter. This additional verification, by analyzing the response of the captured object to the temporally variable lighting emitted by the controlled light source, helps to secure Access to the data is challenging. Indeed, the random (or alternatively pseudo-random) nature of the signal presents a challenge and allows verification that the acquired video was captured by the terminal's camera and shows the user facing the camera in real time at the moment of acquisition, and not from a third-party object or recorded at a different time. Furthermore, determining the temporally invariant property of the observed signal does not require specific alignment with a dedicated event to identify a specific sequence; therefore, there is no need to analyze the acquired images one by one, making the process more flexible and less memory-intensive. Several invariant parameters may exist, further complicating the challenge.Thus, if the time-invariant parameter is not found in the second series of images (particularly because the value of this parameter varies continuously in the acquired signal), access to the data source cannot continue.

[0028] In one embodiment, the evaluation, from a second series of images of the acquisition, of the presence of fraud by injection or recapture includes: - detection of the region of interest in the images of the second series of images; - determination of an observed time signal representative of the pixel values ​​of the images of the second series of images over all or part of the detected region of interest; - in the estimation of said at least one invariant parameter, said time signal of the second series of images is said observed time signal; - calculation of a ratio between said at least one invariant parameter of the observed time signal and said at least one invariant parameter of the imposed signal; the authorization to continue access to the data source being a function of the calculated invariant parameter ratio, which allows a simple implementation and in particular adaptable to a hybrid architecture in which calculations are offloaded to an external server because it is possible to send only the observed time signal, thus limiting the exchange of data.

[0029] Advantageously, the estimation of the invariant parameter can be carried out by a neural network either directly from the second series of images of the acquisition or from the determined observed time signal extracted from it.

[0030] In one embodiment, the ratio is a difference or a ratio, which allows for simple implementation and easy comparison of the fixed value to the estimated value of the or each parameter invariant between them.

[0031] Advantageously, the method may include an intermediate step of determining an injection or recapture probability based on the calculated ratio; with continued access to the data source permitted if the injection or recapture probability is below a second predetermined threshold, which notably allows for normalization of the calculated ratio, subsequently enabling a comparison of the probability obtained at the second predetermined threshold, regardless of the type of invariant parameter.

[0032] Equivalently, a probability of non-recapture or non-injection can be determined and in this case the threshold condition applies if said probability is greater than another second predetermined threshold.

[0033] In one embodiment, the method includes a step of evaluating, from a third series of images from the acquisition, the presence of specific fraud by recapture or injection by: -determination of an observed latency as a function of the fundamental frequency of the imposed periodic time-variable signal and an estimated phase shift between the imposed periodic time signal and an observed time signal representative of the pixel values ​​of the images of the third series of images on all or part of the detected region of interest common to said images of the third series of images, - calculation of a difference between the observed latency and a reference latency obtained previously for said terminal or for the same terminal model; and the authorization to continue accessing the data source depends on the calculated latency difference. This additional step verifies the consistency between the observed latency and the reference latency, thus improving the identification of recapture or injection fraud.

[0034] Advantageously, the method may include an intermediate step of determining the specific probability of fraud by recapture or injection as a function of the calculated latency difference, with authorization to continue access to the data source if the specific probability of fraud by recapture or injection is less than a third predetermined threshold, which notably allows a normalization of the calculated latency difference allowing then a comparison of the specific probability to said third predetermined threshold.

[0035] Equivalently, a specific probability of non-fraud by recapture or injection can be determined and in this case the threshold condition applies if said probability is greater than another predetermined third threshold.

[0036] Advantageously, a camera acquisition parameter, in particular an image size, is modified during acquisition with an increase in the specific probability of fraud by recapture or injection in the absence of a change in the latency observed during acquisition.

[0037] Advantageously, the second or third series of images of the acquisition and the first series of images of the acquisition are identical.

[0038] According to another aspect of the invention, a computer program is proposed comprising instructions adapted to the implementation of each of the steps of the process according to the invention when said program is executed on a computer.

[0039] According to another aspect of the invention, a non-transient information storage means is proposed, removable or not, partially or totally readable by a computer or a microprocessor comprising code instructions of a computer program for the execution of each of the steps of the process according to the invention.

[0040] Advantageously, a device according to the invention comprises said terminal and an information processing unit implementing said process, the processing unit comprising said non-transient information storage means, the processing unit being able to be located in the terminal or distributed between the terminal and a remote server, which makes it possible to have a device with a secure operating architecture. Presentation of the figures

[0041] The invention will be better understood from the following description, which relates to embodiments and variants of the present invention, given by way of non-limiting examples and explained with reference to the accompanying schematic drawings, in which:

[0042] [Fig-1] [Fig.1] schematically shows a person presenting their face to a terminal during the implementation of the security process according to one possible embodiment of the invention,

[0043] [Fig.2] [Fig.2] represents a schematic block diagram of an information processing unit of a device capable of implementing one or more embodiments of the invention,

[0044] [Fig.3] [Fig.3] shows a schematic diagram of the steps implemented in the securing process, according to one possible embodiment of the invention,

[0045] [Fig.4] [Fig.4] shows a schematic diagram of complementary steps implemented in the securing process, according to a possible embodiment of the invention, and [Fig.5] [Fig.5] shows a schematic diagram of additional steps implemented in the securing process, according to a possible embodiment of the invention.

[0046] Identical references will be used from one figure to another to designate identical or similar elements, in their form or in their function.

[0047] For the sake of brevity, the term "approximately" refers to values ​​to the extent of plus or minus 10%. Detailed description

[0048] The invention can be applied in various contexts. The illustrated embodiment is situated in the context of securing remote access to a data source from a user terminal, here a smartphone, by a user of the mobile terminal. comprising a light source, in this case a portion of the mobile phone screen, and a front-facing camera oriented towards the user to acquire images of their face. Another embodiment (not illustrated here) of the invention relates to the acquisition of another biometric characteristic, such as a dermatoglyph of the mobile phone user, for example by the (main) rear camera of the mobile phone, the light source being, for example, the flash of said rear camera. In all cases, the aim is to detect fraud by controlling the light signal in such a way that its variations have a time-invariant property, set randomly.

[0049] The method according to the invention can be used in various applications. In particular, the invention can be used to implement a method for monitoring a driver, or to implement fraud detection within the framework of biometric authentication for enrollment or data access. In all cases, an estimate, by area of ​​interest, of the contribution of the imposed signal to an acquired temporal signal is used to determine the presence or absence of fraud.

[0050] For the sake of simplicity and in an illustrative and non-limiting manner, the invention will be presented below in the context of a biometric method for authenticating a face, but the principles can be applied to any application involving the acquisition of a face. In this context, to verify the authenticity of the presented face, the action performed by the processing unit is an implementation of a fraud detection method based on the estimation, by region of interest, of a contribution of the imposed signal to an acquired temporal signal.

[0051] Latency time corresponds to the response time of the entire acquisition chain, namely the terminal, and is broken down in particular into a delay for illumination by the light source (in particular display by the screen) and an acquisition delay from the camera.

[0052] With reference to [Fig. 1], the authentication method can be implemented using a device comprising a terminal 1 to which a user's face 2 is presented. The terminal 1 includes an information processing unit and a camera 3 adapted to acquire image streams of objects presented in its acquisition field 4. Preferably, the terminal 1 also includes a screen 5 capable of displaying images to the user, and is configured so that the user can simultaneously present their face 2 in the acquisition field 4 of the camera 3 and view the screen 5. The terminal 1 can thus be, for example, a mobile terminal such as a mobile phone (in particular a "smartphone"), smartwatch, or tablet, which typically has a suitable configuration between the camera 3 and the screen 5.Terminal 1 can, however, be any type of computerized device, and in particular can be a computer with a camera or a fixed kiosk dedicated to identity checks, for example installed in an airport. Terminal 1 can also be a... An electronic device embedded in a vehicle forming a connected system for driver recognition, or for accessing applications for the driver or passenger. The information processing unit comprises at least one processor and memory, and allows the execution of a computer program for implementing the method according to the invention.

[0053] Figure 2 is an example of a schematic block diagram of an information processing unit 106 for implementing one or more embodiments of the invention. The information processing unit 106 typically comprises at least one calculator, computer, microprocessor, or other device enabling the execution of a computer program responsible for controlling the various stages of the process according to the invention. The information processing unit 106 includes a communication bus connected to: - a central processing unit 601, such as a microprocessor, denoted CPU; - a 602 transient memory, noted as RAM, to store the executable code of the process of implementing the invention as well as the registers adapted to record variables and parameters necessary for the implementation of the process according to embodiments of the invention; the memory capacity of the device can be supplemented by an optional RAM memory connected to an expansion port, for example; - a non-transient memory 603, denoted FLASH, for storing computer programs and calibration data for the implementation of the embodiments of the invention; the stored computer programs include in particular a computer program comprising instructions adapted to the implementation of each of the steps of the process according to the invention when said program is executed on the processing unit 106, said FLASH memory 603 is then an example of a non-transient means of storing information, removable or not, partially or totally readable by a computer or a microprocessor comprising code instructions of the computer program for the execution of each of the steps of the process according to the invention; - A 604 network interface, denoted NET, is normally connected to a communication network on which digital data to be processed is transmitted or received; The 604 network interface can be a single network interface, or composed of a set of different network interfaces (for example, wired and wireless, or different types of wired or wireless interfaces). Data packets are sent over the network interface for transmission or are read from the network interface for reception under the control of the software application running in the 601 processor; - a GUI 605 user interface to receive input from a user or to display information to a user, including guidance information (voice and / or visual), including here in particular screen 5; - a 607 input / output module for receiving / sending data from / to external devices such as hard drives, removable storage media or others.

[0054] The executable code can be stored in non-volatile memory 603, for example flash memory or read-only memory, or on removable digital media such as, for example, a disk. According to one embodiment, the executable code of the programs can be received by means of a communication network, via the network interface 604, in order to be stored in one of the storage means of the information processing unit 106, such as the FLASH memory 603, before being executed.

[0055] The central processing unit 601 is adapted to command and direct the execution of instructions or portions of software code of the program or programs according to one of the embodiments of the invention, instructions which are stored in one of the aforementioned storage means, such as the FLASH memory 603. After power-up, the CPU 601 is capable of executing instructions from the transient RAM memory 602, relating to a software application. Such software, when executed by the processor 601, causes the execution of the method according to the invention.

[0056] In this embodiment, the device is a programmable device that uses software to implement the invention. However, alternatively, the present invention can be implemented in hardware (for example, in the form of a specific integrated circuit or ASIC (application-specific integrated circuit) or in the form of a programmable logic component or FPGA (field-programmable gate array).

[0057] The information processing unit 106 as illustrated is local in the user terminal 1 of the device but can also be distributed and include multiple processing subunits, in particular physically remote (outside the user terminal which is the mobile phone as previously illustrated) communicating with each other via the network interface, similarly part of the memory can be physically remote, hosted for example on a remote server.For example, user terminal 1 is the master, and the initialization, acquisition, and control modules are hosted locally within user terminal 1. However, other modules may not be, or only partially, hosted locally, but rather in a physically remote processing entity (slave), such as a remote server. This sharing of computations between the local user terminal 1 and the remote server allows only the information necessary for decision-making to be sent to the remote server, thus minimizing response time related to data exchange and network throughput, without compromising client-side security related to reverse engineering. 1 can, for example, exchange the acquired biometric information with the remote server as illustrated in document FR1661737. This may include redundant calculations, with the remote server verifying all or part of what terminal 1 has done. Alternatively, the remote server is the master and the user terminal the slave, so that the invariant parameter is chosen and defined by the remote server, then transmitted to the user terminal so that the latter implements the control accordingly, which maximizes the security of user terminal 1 and prevents replay on the user terminal side, the latter being agnostic of the chosen invariant parameter and / or its value, one and / or the other being able to vary during the implementation of the method according to the invention.Similarly, the user terminal can then send to the remote server only the information necessary for decision-making (for example, only the observed signal or even the estimated value of the invariant parameter) to minimize the response time related to data exchange and network throughput, and reduce the risks associated with reverse engineering on the client side.

[0058] With reference to [Fig. 3], the user of terminal 1 uses the device to authenticate to an online account via an application. A biometric facial authentication process is then initiated, prompting the user to present their face 2 in the acquisition field 4 of the camera 3. Before generating the biometric template and accessing the user's enrolled template for comparison, the biometric authentication process calls the remote access security process P to detect fraud attempts during access to the online account.

[0059] When called by the biometric facial authentication process, the security process P, the information processing unit 106 of the device 1 implements the initialization step E0 of the security process P corresponding in particular to the verification of the operation of the camera 3 of the terminal 1 of the device.

[0060] The security process P then continues with the implementation, by the information processing unit 106, of the instructions to: - acquisition of biometric information video by the camera; - random selection (not shown) of a first value between 0.5 and 3 for the first invariant parameter (here the fundamental frequency of the imposed signal) and random selection of a second value between 0 and 2ir for the second invariant parameter (here phase shift between the blue component and the red component of the imposed signal), - E2 control, during the acquisition stage, of the display on more than half of the screen 5, with the color varying according to a time-varying signal whose red and blue components are periodic signals with a fundamental frequency equal to the first randomly drawn value and with a phase shift between them equal to the second randomly drawn value, the green component being time-invariant (and initialized, for example, at level 255), said signal imposed thus encoding two invariant parameters which are here (non-limitingly) parameters of the spectrum: fundamental frequency of the imposed signal and phase shift between the two time-varying components of the imposed signal; -E3 evaluation, based on an initial series of images from the acquisition, of the presence of fraud by presentation (on screen or by presentation of a printed photo, for example) by: - for each image in the first series, spatial alignment E3a of said images with respect to a reference point of the detected face, for example by eye registration - determination E3b of at least one area of ​​interest in the detected face, said area of ​​interest being common to the images of the first series, - determination E3c of an observed time signal by area of ​​interest, - estimation E3d, by area of ​​interest, of a contribution of the imposed signal to the observed signal in order to form a return vector, - determination E3e of a score by applying a classifier to this vector, said classifier being implemented in particular by a neural network, - determination E3f of a probability of fraud per presentation as a function of the determined score; - E6 authorization to continue access to the data source if the probability of fraud per presentation is less than a first predetermined threshold. Otherwise, the biometric authentication process is interrupted and an error message may be displayed on screen 5. In both cases, the time-stamped status, success (no fraud) or failure (fraud detected), is preferably recorded in a local RAM register or in an external register.

[0061] The E2 control of the display on a portion of the screen 5, with the color varying according to a time-varying signal of imposed fundamental frequency and phase shift between the blue and red components (fundamental frequency and phase shift having been randomly fixed), allows the color in the portion of the screen 5 to vary periodically and without repetition because it depends on two parameters drawn randomly and independently. This imposed time-varying signal is a periodic signal composed of two periodic color components and constitutes a challenge, the periodic component(s) of the imposed time-varying signal being sinusoidal, square wave, or triangular, the two components not necessarily being of the same type.

[0062] If the periodicity of the imposed time-varying signal can be, as here, the same for all its components, it can also be due to only one component of the Red Green Blue display signal, namely the blue, green, or red component: the controlled time-varying signal is then composed of a single periodic color component, the others maintaining a fixed level During the pilot phase, this level can vary between each implementation of the process, with these fixed levels advantageously being set randomly. However, it is preferable for the imposed time-varying signal to be composed of several color components, particularly periodic ones, to increase the diversity of the challenge, as in this case, and the choice of only red and blue components (not green) helps to limit color crosstalk.

[0063] For example, the red and blue components of the imposed time-varying signal can be square wave and written as follows: red = sign(co S ( 2,^ + 1) 'P' amètres ■ = «w„(sign(cos(2n- / Wœ q)+ 1) randomly are: - the frequencies fred and fblue in the range [0.5Hz, 3Hz], - the phase difference between the two components being here fixed at 0. The ared and abieu levels in the range are fixed non-randomly (no random selection) within the range [0, 255], preferably at 127.5. These amplitudes correspond to parameters that cannot be estimated in the observed signal (the captured object's response to the controlled lighting). Therefore, the amplitude levels are not randomly fixed invariant parameters.

[0064] Similarly, the green component has a fixed (non-random) warning level in the range [0, 255], preferably 255, but this level does not constitute an invariant parameter fixed randomly, especially since the green component is not time-variable.

[0065] Alternatively, the red and blue components of the imposed time-varying signal can be sinusoidal and written as follows: red = aroUge ( COS ( ^7rfroug / ) + 1 ) , where the parameters are set randomly blue = abieu ( cos ( J ) + 1 ) are : - the frequencies frouge and fHeu in the range [0.5Hz, 3Hz].

[0066] The phase shift between these two components is not fixed in this embodiment.

[0067] Furthermore, the ared and aMeu levels are fixed in the range [0, 255], preferably 127.5, as before, the green component then having an avert level fixed in the range [0, 255], preferably 255, as before.

[0068] In the preferred mode, illustrated in the embodiment specific to this figure, the red and blue components of the imposed time-varying signal are sinusoidal periodic and out of phase with each other, and are written as follows:

[0069] f red = arRouge ( cos ( 2æfrougJ ) + 1 ) ' where the parameters are fixed | blue — ( cos roug / + ) + ) randomly are: - the frequency fred in the range [0.5Hz, 3 / £weuHz] so as to have the frequencies of the two components in the preferred interval, and - the phase in the range [0, 2ir], which corresponds to the phase shift between the blue component and the red component of the imposed signal.

[0070] Furthermore, - the ared and abieu levels are fixed in the range [0, 255], preferably 127.5, as before, the green component then having an avert level fixed in the range [0, 255], preferably 255, as before; - and a natural number kblue in the range [1, 6] is preferably set to 1. Thus, the frequencies of the two components are chosen to be equal (multiple = 1), which allows for a constant phase shift that is easily measurable and verifiable on the observed signal. Alternatively, in the case where the fundamental frequency of the second component (here blue) is a multiple of the fundamental frequency of the first component (here red), it would be necessary, for example, during the evaluation step (E4) for the presence of fraud by injection or recapture, to estimate the phase of the second component of the observed signal when the phase of the first component of the observed signal is zero in order to determine the phase shift between these two components of the observed signal.

[0071] Fundamental frequencies above 3 Hz are preferentially avoided, both for user comfort and for sampling reasons, so that a video sequence can be processed as long as its sampling frequency is at least 6 Hz (Shannon criterion). However, it should be noted that mobile phones have cameras typically capable of recording video at at least 25 Hz locally (without external streaming) at high-density resolutions; therefore, the maximum value of this range can be increased, particularly if the acquired biometric information is not a face but a dermatoglyph, for example, as user comfort would then not be affected.

[0072] By way of non-limitation, the time-varying signal(s) with invariant parameters have been illustrated with periodic signals; however, the imposed time-varying signal characterized by at least one time-invariant parameter may also be non-periodic. For example, the imposed time-varying signal has at least two color components and the invariant parameter of the signal is a ratio of instantaneous frequency between said at least two components which are for example frequency modulated but whose modulation follows a fixed ratio, written such that: red = COS ( 2æs ( t ) ) with: blue-cos(2æ as(t) ) - s a strictly increasing function, the instantaneous frequencies being respectively s' (derivative of s) and a .s'. - a is the time-invariant parameter whose value is randomly fixed in the range [1; 3].

[0073] Equivalently, the optional alignment step E3a can consist of determining, in each image, the first series of regions of interest corresponding to the same portion of the face and preferably common to all images in the series. This alignment step E3a can include detecting the region of interest for each image using several approaches. One approach, for example, is to analyze the image to detect physical features such as the eyes. Since faces are made up of similar elements (eyes, noses, mouths, etc.) spatially organized in a similar way, the detection of these elements is facilitated. Another approach is, for example, to use a computational model such as a neural network, a support vector machine, or a decision tree, previously trained on a training set of images showing various faces.This area of ​​interest detection step can be implemented by the information processing unit 106 on the images of the second series transmitted by the camera 3. It is also possible that this face detection step is implemented by another element of the device than the information processing unit 106, such as the camera 3, and that the information processing unit 106 receives only the areas of interest rather than the complete images.

[0074] In the determination step E3b, the area of ​​interest is a triangle in a mesh of the detected face or a pixel in the vicinity of an interest point of the detected face, said area of ​​interest being present in all the images of the second series. Such an interest point is, for example, a semantic point of the face, such as the tip of the nose, the corner of the eye (position sometimes estimated), as taught by Guo, X., Li, S., Yu, J., Zhang, J., Ma, J., Ma, L., & Ling, H. (2019). PFLD: A practical facial landmark detector. arXiv preprint arXiv: 1902.10859. Preferably, the area of ​​interest is an area of ​​the face with a particularly remarkable shape and where there is the least possible distortion and / or obfuscation in order to reduce measurement noise during acquisition in particular. Thus, the area of ​​the nose is particularly interesting, but not exclusively so. Several areas of interest can be identified.

[0075] The step of determining E3c a temporal signal observed by area of ​​interest, representative of the pixel values ​​of the images of the first series of images, is therefore This approach is based on only a portion of the detected face, specifically skin areas, using, for example, the segmentation method described in Wang, B., Chang, X., & Liu, C. (2011). Skin detection and segmentation of human face in color images, International Journal of Intelligent Engineering and Systems, 4(1), 10-17. This choice avoids biases related to eyeglasses, for example. For each image in the first series, an average level calculation is used to construct a temporal signal observed for the area of ​​interest by component.

[0076] The E3d estimation step, by region of interest, of a contribution of the driven signal to the observed signal in order to form a feedback vector, is implemented, for example, by filtering the observed signal at the imposed fundamental frequency and calculating the amplitude. In the presence of several regions of interest, the amplitudes obtained for each region of interest are then combined into a feedback vector, also called an appearance vector. The feedback vector is then, for example, formed of as many sub-vectors as there are imposed time-varying signals, which allows the classifier to receive as input a vector of vectors (also called a matrix, with, for example, as many columns as there are imposed signals (periodic color components in particular) and as many rows as there are regions). This feedback vector shows, for example, stronger responses at the level of the glasses or eyes, and variations depending on the parts of the face.

[0077] Preferably, the invariant parameter (here the imposed fundamental frequency) is known to the computer implementing the E3d estimation step; otherwise, a suitable treatment can be applied regardless of the value of the invariant parameter, for example by applying a bandpass time filtering, or a prior estimation of said invariant parameter can be carried out.

[0078] Then the step of determining a score E3e involves the application of a classifier to this vector, said classifier being implemented in particular by a neural network.

[0079] Preferably, the classifier is said to be "deep" and constituted by supervised learning, previously trained from examples of real faces and frauds on screen or paper.

[0080] Then, the step of determining E3f the probability of fraud per presentation as a function of the determined score is implemented, for example by applying a sigmoid function or by using a table.

[0081] Finally, if the probability of fraud by presentation is less than a first predetermined threshold, then the continuation of the biometric authentication process for access to the account is authorized E6, and an accepted status of the request is recorded in a register linked to the security process, whereas otherwise the biometric authentication process is interrupted and a refused status of the request is recorded in the register linked to the security process.

[0082] This additional verification makes it possible to discriminate between screen fraud, i.e. if a fraudster positions a screen on which a video recording of the legitimate user is displayed, and paper fraud because then the return vector will not correspond to a correct return vector, for example because the responses will be substantially identical regardless of the areas, the screen or the paper presented, by the fraudster, facing the camera 3 being "flat".

[0083] Alternatively, not illustrated here, the method according to the invention could be applied to dermatoglyph capture, preferably using for acquisition El the main camera of the terminal (rear of a "smartphone", tablet for example): better resolution and by making the flash blink according to the time-varying signal of imposed fundamental frequency and imposed phase.

[0084] With reference to [Fig.4], the security process includes a supplementary verification by E4 evaluation, from a second series of images of the acquisition, of the presence of fraud by injection or recapture; by: - ​​detection E4a of a predetermined region of interest in the images of the second series of images; - determination E4b of an observed time signal representative of the pixel values ​​of the images of the second series of images over all or part of the detected region of interest; - estimation E4c of said at least one invariant parameter of the observed time signal; - calculation E4d of a difference between said at least one invariant parameter of the observed time signal and said at least one invariant parameter of the imposed signal.

[0085] The E4 evaluation, based on a second series of images from the acquisition, of fraud by injection or recapture relies on verifying the challenge parameter(s) by spectral analysis of the acquired signal: that is, the received signal, which therefore corresponds to the response of the object (supposed to be the user's face) to the controlled lighting. This E4 evaluation step is based on comparing the imposed signal with the observed signal, involving in particular an estimation of a time-invariant property of the observed, received signal. The second series of images does not necessarily include all the images acquired in step E1, as the spectral analysis is robust to the loss of, for example, an image and can be performed, for example, on the basis of a second series containing every other image.The selection of images acquired to form the second series of images may be based, for example, on ISO image quality criteria, or only images that include the entire face (as opposed to a face with part of it outside the frame) may be retained. Similarly, the second series may only include images from a specific time window within the acquisition period E1 by camera 3; preferably, this time window has a duration greater than or equal to two. times the maximum period of the imposed signal(s) (components) with a sampling frequency greater than or equal to twice the maximum frequency of the imposed signal(s) (components).

[0086] Said E4 evaluation of the presence of fraud by injection or recapture comprises the following steps: - E4a detection of the face (supposedly the user's) in the images of the second series of images; - determination E4b of an observed temporal signal representative of the pixel values ​​of the images of the second series of images on all or part of the detected face; - estimation E4c of the fundamental frequency frouge _obs and fMeu _obs of each periodic component of the observed time signal, here the blue and red components are concerned, and of the phase shift $hleu ofabetween these two periodic components of the observed time signal; - calculation E4d of the differences Afrouge=frouge -frouge _obs, Afbieu=fbieu - fMeu _obs (knowing that here bleufrouge ) between the estimated fundamental frequency of each periodic component of the observed time signal and the imposed fundamental frequency of each periodic component of the imposed signal and a difference ^bleu ~ " ^bleu 'c imposed phase shift and the estimated phase shift; - determination E4e of an injection or recapture probability as a function of the calculated frequency differences Afrouge, AfM eu and phase shift A0W.

[0087] The face detection step E4a includes determining a region of interest in an image corresponding to the location of the face in said image. The region of interest is typically a rectangular area (or box) encompassing the face in order to isolate the face from its surroundings appearing in the background of the image. Other types of regions of interest can be used. The region of interest can, for example, be defined by a contour between the skin and the background, delimiting the face from its background.

[0088] The region of interest can be detected using several approaches. One approach, for example, is to analyze the image to detect physical features such as the eyes. Since faces are made up of similar elements (eyes, noses, mouths, etc.) spatially organized in a similar way, the detection of these elements is facilitated. Another approach is, for example, to use a computational model such as a neural network, a support vector machine, or a decision tree, previously trained on a training set of images showing various faces.

[0089] This face detection step can be implemented by the information processing unit 106 on the images of the second series transmitted by the camera 3. It It is also possible that this face detection step is implemented by another element than the information processing unit 106, such as camera 3, and that the information processing unit 106 receives only the regions of interest rather than the complete images.

[0090] Preferably, the determination E4b of an observed temporal signal representative of the pixel values ​​of the images in the second series of images is based on only a detected portion of the face, specifically the skin areas, using, for example, the segmentation method described in Wang, B., Chang, X., & Liu, C. (2011). Skin detection and segmentation of human face in color images, International Journal of Intelligent Engineering and Systems, 4(1), 10-17. This approach avoids biases related to eyeglasses, for example. For each image in the second series, a calculation of the average levels on said portion of the face allows for the creation of an observed temporal signal for said facial area by component. Furthermore, there can be as many temporal signals as there are sub-regions of the face.

[0091] E4c estimation allows the values ​​of the invariant parameters in the observed time signal to be determined. Methods are known for estimating the fundamental frequency and the associated phase, such as in the document De Cheveigné, A., & Kawahara, H. (2002). YIN, a fundamental frequency estimator for speech and music. The Journal of the Acoustical Society of America, 111(4), 1917-1930. In the preferred case in which several subregions of the face are processed, there are as many time signals to process as there are subregions of the face, and in the case illustrated here, the fundamental frequency of each blue and red component, as well as the associated phase shift, must be estimated for each of them. Then, a voting mechanism is implemented, for example, to obtain only one value common to the subregions of each of the invariant parameters of the observed time signal. Alternatively, and without limitation, an average could replace the voting mechanism.

[0092] The calculation step E4d is then implemented, which determines the differences between the randomly fixed invariant parameter values ​​of the imposed signal and the values ​​estimated in the previous step E4c for the observed signal. This allows verification of whether the observed signal has the same spectrum as the imposed signal, i.e., whether the two randomly fixed invariant parameter values ​​correspond: i.e., here: froui,e = f , =f and ¢., = , • J mugeobs J bîeu_pbs bleu ^Ueu_ohs^ - determination E4e of the probability of injection or recapture as a function of the calculated differences, for example by normalization of the calculated differences using a normal law for example, or even concatenation as a function of said calculated differences for example by product of the probabilities obtained by normalization of each difference;

[0093] Then, if the probability of injection or recapture is less than a first predetermined threshold, this condition being preferentially concatenated with that described in step E6 with reference to the previous figure, i.e. that both conditions must be met to continue, then the continuation of the biometric authentication process for access to the account is authorized E6, and an accepted status of the request is recorded in a register linked to the security process, whereas otherwise the biometric authentication process is interrupted and a refused status of the request is recorded in the register linked to the security process.

[0094] This security method thus makes it possible to protect against fraudsters who might attempt to replay a previously acquired user video recording under the same conditions by showing said video to the camera of device 1, since the acquired video would not conform to the challenge, as would be the case if such a video were injected remotely. Furthermore, the method according to the invention does not require synchronization checks between an emitted signal and a received signal thanks to the nature of the imposed periodic signal and the associated use of frequency analysis, which simplifies processing.

[0095] Preferably, in the embodiment illustrated here, the first series of images is the same as the second, which allows only one selection of images to be made for said series.

[0096] With reference to [Fig. 5], in the case of a periodic imposed signal, the security process includes an additional check further improving robustness to specific recapture or injection, for example, by adding an evaluation step E5, from the third series of images of the acquisition, for the presence of specific fraud by recapture or injection by: -Determination E5a of an observed latency as a function of the imposed fundamental frequency, here fred, and of an estimated phase shift $ between the imposed periodic time signal and the observed time signal representative of the pixel values ​​of the images in the third series of images on all or part of the detected face common to said images in the third series of images. Based on these two elements, a response time tréponSe is then deduced to within one period: l, = —— + -A- with n: natural number, but equal to 0 by construction since, Due to the imposed fundamental frequency range of the imposed signal, in practice the expected latency is on the order of 100ms, therefore significantly lower than Vfrmige, which allows for precise calculation of the latency.

[0097] - calculation E5b of a difference between the observed latency latobset a latency of reference 1 at Ie[ obtained previously for said terminal or for the same terminal model, to obtain this reference latency, one can for example have from a latency bank per terminal model, or consult the latency obtained by other users of the same device, or have measured said reference latency during the enrollment of terminal 1, which is the simplest case but requires that terminal 1 has not changed in the meantime; - determination E5c of the specific probability of fraud by recapture or injection as a function of the calculated latency difference, for example using the function with o a standard deviation (for example here of approximately 10ms), which allows to evaluate a likelihood of the observed latency if we assume that the observed latency has a Gaussian distribution (normal law) centered on the reference latency with a standard deviation of 0.

[0098] Finally, if the specific probability of fraud by recapture or injection is less than a third predetermined threshold, this condition being concatenated to that described in step E6 with reference to the previous figures, then the continuation of the biometric authentication process for access to the account is authorized E6, and an accepted status of the request is recorded in a register linked to the security process, whereas otherwise the biometric authentication process is interrupted and a refused status of the request is recorded in the register linked to the security process.

[0099] Alternatively, as with steps E4 and E3, the intermediate probability calculation step is not limiting, the access authorization of step E6 may depend on the inferiority of the difference in latencies calculated to a threshold of approximately 10ms for example.

[0100] The image series used here is the second image series, for the same reasons as before.

[0101] This additional step makes it possible to verify the consistency between the observed latency and the reference latency and thus to better identify expert fraud by recapture or injection.

[0102] Preferably, an acquisition parameter, such as the camera image size, is modified during the acquisition El and the specific probability of fraud by recapture or injection is then increased in the absence of a change in the latency observed during the acquisition, because this means that the challenge is not checked since the change in image size necessarily changes the capture delay.

[0103] By way of non-limitation, the first, second and third thresholds are for example set at 0.5.

[0104] Without limitation, in figures 3 to 5 the video acquisition step E1 by camera 3 has been positioned upstream of the piloting step E2, but the two can be concomitant, or even the piloting step could launch the video acquisition by camera 3.

Claims

Demands

1. Method (P) of securing remote access to a data source from a terminal (1) by a user of said terminal, the terminal comprising a light source (5) and a camera (3) directed towards said user, said method comprising steps of: - video acquisition (E1) by the camera (3); - control (E2), during the acquisition step, of the light source (5) according to an imposed time-varying signal of which at least one parameter is time-invariant and of value fixed randomly;- evaluation (E3), from a first series of images of the acquisition, of the presence of fraud by presentation by: - ​​estimation (E3d), by area of ​​interest, of a contribution of the imposed signal to a temporal signal of the first series of images in order to form a return vector, - determination (E3e) of a score by application of a classifier to said vector, - authorization (E6) to continue access to the data source according to the score determined.;

2. A method according to claim 1, wherein at the evaluation step (E3): - at least one region of interest is determined (E3b) in a detected region of interest, said region of interest being common to the images of the first series, - an observed time signal representative of the pixel values ​​of the images of the first series of images over all or part of the region of interest is determined (E3c); - at the estimation (E3d) said time signal of the first series of images is said observed time signal per region of interest.

3. A method according to any one of the preceding claims, wherein said classifier is implemented in particular by a neural network

4. A method according to any one of the preceding claims, wherein the region of interest comprises all or part of a face.

5. A method according to any one of the preceding claims, wherein the imposed time-varying signal is a component periodic color whose time-invariant parameter is a fundamental frequency.

6. A method according to any one of claims 1 to 4, wherein the imposed time-varying signal comprises at least two color components and the invariant parameter of the signal is an instantaneous frequency ratio between said at least two components.

7. A method according to any one of claims 1 to 4, wherein the imposed time-varying signal comprises at least two periodic color components of the same fundamental frequency or multiples of the same fundamental frequency, with a phase shift between said at least two components, said at least one time-invariant parameter of the imposed signal being said fundamental frequency or the phase shift.

8. A method according to any one of claims 1 to 5, 7, wherein the imposed fundamental frequency is randomly fixed within a range [0.5Hz, 3Hz].

9. A method according to any one of the preceding claims, wherein the terminal comprises a display screen, the light source being all or part of the display screen (5) of the terminal (1) and the control of the light source corresponding to a display on all or part of the screen (5) of color varying according to the time-varying signal imposed.

10. A method according to any one of claims 1 to 5, 7 to 9, wherein the imposed time-varying signal is sinusoidal.

11. A method according to any one of claims 1 to 10, comprising an evaluation step (E4), from a second series of images of the acquisition, of the presence of fraud by injection or recapture by: - ​​estimation (E4c) of said at least one invariant parameter of a time signal of the second series of images; the authorization step (E6) of continued access to the data source being a function of the fixed value and the estimated value of said at least one invariant parameter.

12. A method according to the preceding claim in its dependence on claim 2, wherein the evaluation step (E4) of the presence of fraud by injection or recapture comprises: - detection (E4a) of the region of interest in the images of the second series of images; - determination (E4b) of an observed time signal representative of the pixel values ​​of the images of the second series of images over all or part of the detected region of interest; - during the estimation (E4c) of said at least one invariant parameter said time signal of the second series of images is said observed time signal; - calculation (E4d) of a ratio between said at least one invariant parameter of the observed time signal and said at least one invariant parameter of the imposed signal; said ratio being in particular a difference or a ratio; - the authorization (E6) to continue access to the data source being a function of the calculated invariant parameter ratio.

13. A method according to any one of claims 5, 7 to 12, comprising an evaluation step (E5), from a third series of images of the acquisition, of a presence of specific fraud by recapture or injection by: -determination (E5a) of an observed latency as a function of the fundamental frequency of the imposed periodic time-variable signal and of an estimated phase shift between the imposed periodic time signal and an observed time signal representative of the pixel values ​​of the images of the third series of images over all or part of the detected region of interest common to said images of the third series of images, -calculation (E5b) of a difference between the observed latency and a reference latency obtained previously for said terminal (1) or for the same model of terminal, and the authorization (E6) to continue access to the data source being a function of the calculated latency difference.

14. A computer program comprising instructions adapted to carry out each of the steps of the method for securing remote access to a data source according to any one of claims 1 to 13 when said program is executed on a computer.

15. A non-transient information storage means, removable or not, partially or totally readable by a computer or microprocessor, comprising code instructions of a computer program for executing each of the steps of the process according to any one of claims 1 to 13.