A method of authenticating and preventing spoofing of an optically readable security element
The method and device authenticate optically readable security elements by detecting display apparatus presence and verifying identities to prevent spoofing, ensuring robust security against fraudulent attempts.
Patent Information
- Application Number
- GB2023011616
- Authority / Receiving Office
- GB · GB
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-07-28
- Publication Date
- 2025-07-23
- Estimated Expiration
- 2043-07-28
AI Technical Summary
Existing optically readable security elements are vulnerable to spoofing, where fraudulent elements are passed off as authentic, compromising security.
A method and device for authenticating optically readable security elements by checking for the presence of a display apparatus, verifying the element's identity, and calculating confidence measures to prevent spoofing, including detecting optical artifacts and emitting excitation radiation to ensure authenticity.
Enhances security by preventing false positives and negatives, alerting users to potential risks, and disabling spoofed elements, thereby maintaining high accuracy and reliability.
Smart Images

Figure 00000001_0000 
Figure 00000001_0001
Abstract
Description
TECHNICAL FIELD 5 The present disclosure relates to a method of authenticating an optically readable security element and an image capturing device for authenticating an optically readable security element. BACKGROUND Security elements or tags are used to provide security in relation to an object to which 10 they are attached. These security elements provide security in relation to the object by labelling the object. For example, a security element may be encoded with a unique identity that can be extracted from the security element, thereby enabling authentication of the object. However, security elements, or devices for reading such elements, may be vulnerable 15 to spoofing (i.e., passing off a fraudulent / inauthentic security element as authentic). For example, a nefarious party may attempt to spoof a security element or device by displaying a duplicate (e.g., an image, such as a photograph) of an authentic security element on a device such as a smartphone. Hence, there is a desire to provide a method of authenticating a security element that 20 prevents or inhibits spoofing thereof. SUMMARY It is one aim of the present disclosure, amongst others, to provide a method of authenticating an optically readable security element which at least partially obviates or mitigates at least some of the disadvantages of the prior art, whether identified herein 25 or elsewhere, or to provide an alternative approach. For instance, it is an aim of embodiments of the invention to provide a method of authenticating an optically readable security element that prevents or inhibits spoofing of the optically readable security element. According to the present invention there is provided a method of authenticating an 30 optically readable security element and an image capturing device for authenticating an optically readable security element, as set forth in the appended claims. Other features 02 05 25 of the invention will be apparent from the dependent claims and the description that follows. According to a first aspect, there is provided a method of authenticating an optically readable security element by an image capturing device. The method comprises 5 determining whether a spoofing attempt is taking place by checking for a presence of a display apparatus. The presence causes it to be determined that a spoofing attempt is taking place. The method also comprises reading the optically readable security element and verifying the optically readable security element as authentic based on the reading of the optically readable security element and the determining of whether a 10 spoofing attempt is taking place. The optically readable security element may be verified as authentic only if it is determined that a spoofing attempt is not taking place. The method may further comprise extracting an identity from the optically readable security element, retrieving a stored identity from a data store and verifying the optically 15 readable security element as authentic by comparing the extracted identity with the retrieved stored identity. The optically readable security element may be verified as authentic only if the extracted identity matches the retrieved stored identity within a preset range. The display apparatus may be configured to duplicate an optically readable security 20 element, and determining whether a spoofing attempt is taking place may comprise determining whether the display apparatus is duplicating the optically readable security element. The method may further comprise calculating a confidence measure that the display apparatus is present and determining that spoofing is taking place only if the confidence 25 measure is above a threshold value. Checking for the presence of the display apparatus may comprise detecting an optical artifact associated with the display apparatus. The optical artifact is a moire pattern. The optical artifact may also be at least one of: a pictorial element, reflection, emission. 30 In the event that it is determined that a spoofing attempt is taking place, the method may further comprise delaying the reading for a predetermined period of time. 02 05 25 In the event that it is determined that a spoofing attempt is taking place, the method may further comprise transmitting an output signal. The output signal may be an alert signal. The method may further comprise disabling one or more authentic optically readable 5 security elements based on the output signal. In the event that it is determined that a spoofing attempt is taking place, the method may further comprise narrowing the preset range. The method may further comprise illuminating the optically readable security element and determining whether a spoofing attempt is taking place based on an optical 10 response of the optically readable security element to the illuminating. According to a second aspect, there is provided an image capturing device for authenticating an optically readable security element. The image capturing device comprises a reader, a sensor and a processor. The reader is configured to read the optically readable security element. The sensor is configured to check for a presence 15 of a display apparatus. The processor is configured to determine whether a spoofing attempt is taking place based on an output of the sensor. The presence of a display apparatus causes it to be determined that a spoofing attempt is taking place. The processor is also configured to verify the optically readable security element as authentic based on the reading of the optically readable security element reader and 20 the determining of whether a spoofing attempt is taking place. BRIEF DESCRIPTION OF DRAWINGS For a better understanding of the invention, and to show how embodiments of the same may be brought into effect, reference will be made, by way of example only, to the accompanying Figures, in which: 25 Figure 1 shows a flowchart for a method of authenticating an optically readable security element; Figure 2 shows an optically readable security element being read by an image capturing device; and Figure 3 shows an image capturing device. 30 DETAILED DESCRIPTION Figure 1 shows a flowchart for a method of authenticating an optically readable security element (as yet unknown whether to be authentic or inauthentic, for example a spoofing 02 05 25 attempt or otherwise). The method of Figure 1 is best understood in conjunction with Figure 2, which shows an image capturing device 10 reading an optically readable security element 20 in a field of view 30 (e.g., in a same image frame) of the image capturing device 10. 5 The method comprises determining S1 whether a spoofing attempt is taking place by checking for a presence (e.g., at least partially in the field of view 30 of the image capturing device 10) of a display apparatus 40, whereby the presence causes it to be determined that a spoofing attempt is taking place. In other words, the method comprises determining S1 whether there is any sign of a display apparatus 40 (e.g., 10 using machine vision), because the presence of a display apparatus 40 is likely indicative of a spoofing attempt (e.g., a nefarious party displaying an image of an authentic optically readable security element 20 on a smartphone or otherwise duplicating the authentic optically readable security element 20). This is a subtle but powerful feature, which at first glance might not be apparent. For 15 example, it is known to take a picture or image of a barcode or QR code (RTM) and store this image, all using a first image capturing device. Then, someone could use a second image capturing device to read and extract information from that image, provided by a display of the first image capturing device. For instance, this process may be used to share product information, access details or access login permissions. 20 However, the present invention is effectively the opposite of this process. That is, rather than improving or facilitating such methodology, the present invention seeks to prevent or inhibit this process to ensure that a real, live, physical optically readable security element 20 is being read and used. Therefore, the present invention vastly improves the security provided by such an optically readable security element 20. 25 It may be determined that a spoofing attempt is taking place only if it is determined that the display apparatus 40 is present (including being used to display an optically readable security element 20) with a certain degree of confidence, thereby, advantageously, avoiding false positives. To this end, the method may comprise calculating a confidence measure that that the display apparatus 40 is present and 30 determining that spoofing is taking place only if the confidence measure is above a first threshold value (e.g., 90%, 95%). The method also comprises reading S2 the optically readable security element 20 and verifying S3 the optically readable security element 20 as authentic based on the reading S2 of the optically readable security element 20 and the determining S1 of 02 05 25 whether a spoofing attempt is taking place. For example, the optically readable security element 20 may be verified as authentic only if it is determined that a spoofing attempt is not taking place. Thus, advantageously, verification of the authenticity of the optically readable security element 20 is based on two factors, such that enhanced security is 5 facilitated. The method preferably comprises extracting (e.g., as part of the reading S2) an identity from the optically readable security element 20. This extracting may include, for example, retrieving a stored identity from a data store and verifying the optically readable security element 20 as authentic by comparing the extracted identity with the 10 retrieved stored identity. Therefore, advantageously, irrespective of whether it is determined that a spoofing attempt is taking place, authentication of the optically readable security element 20 is contingent on the identity. The optically readable security element 20 may be verified as authentic only if the extracted identity matches the retrieved stored identity within a preset range. For 15 instance, the method may comprise calculating a confidence measure that the extracted identity matches the retrieved identity and only verifying the optically readable security element 20 as authentic if the calculated confidence measure is above a second threshold value (e.g., 90%, 95%). In this way, advantageously, false negatives are avoided while maintaining high accuracy. Further advantageously, as noted above, 20 reliability of the verification of the authenticity of the optically readable security element 20 may be enhanced by requiring both the confidence measure that the display apparatus 40 is present to be above the first threshold and the confidence measure that the extracted identity matches the retrieved identity to be above the second threshold. Checking for the presence of the display apparatus 40 may comprise detecting at least 25 one optical artifact associated with the display apparatus 40 (which includes an artifact in or around any displayed image of the optically readable security element 20). In other words, in order to determine whether a display apparatus 40 is present, the presence of a display apparatus 40 being indicative of spoofing, the method may comprise detecting (e.g., sensing) an optical characteristic from which the presence of the display 30 apparatus 40 may be inferred. The optical artifact may be one or more a pictorial element (typically a picture element - i.e., a pixel), reflection, emission and a moire (i.e., fringe or interference) pattern. For instance, in the case of a nefarious party attempting to spoof using an image of an authentic optically readable security element 20 displayed on a screen of a display 02 05 25 apparatus 40, the screen of the display apparatus 40 will typically reflect ambient light differently to how light would be reflected by the authentic optically readable security element 20. Therefore, this reflection and / or light interference may be used to infer the presence of the display apparatus 40 and, hence, determine that there is a spoofing 5 attempt. In the event that it is determined that a spoofing attempt is taking place, the method may comprise transmitting an output signal. The output signal may be an alert signal. For instance, the alert signal may cause the image capturing device 10 to output an audio alert via a speaker and / or to output a visual alert via a display. Advantageously, 10 in this way, a user is alerted to a potential security risk. The method may comprise delaying the reading S2 and / or disabling one or more (authentic) optically readable security elements 20 based on the output signal. For example, the optically readable security element 20 of which an attempt at spoofing was made may be disabled based on the output signal. In more detail, if, for instance, 15 an identity is extracted from an inauthentic optically readable security element 20 during the method shown in Figure 1, but it is determined that a spoofing attempt is taking place, the identity may be used to identity the corresponding authentic optically readable security element 20 in order to disable it and, optionally, other optically readable security elements 20, such as those part of the same manufacturing batch. 20 The delaying and / or disabling may be permanent or time limited (i.e., for a predetermined period of time). Advantageously, this delaying and / or disabling thwarts repeat spoofing attempts. Relatedly, in the event that it is determined that a spoofing attempt is taking place, the method may comprise narrowing the preset range (e.g., raising the second threshold 25 value). In other words, extracted identity may be deemed as matching the retrieved identity less readily if is determined that a spoofing attempt is taking place. Analogously, in the event that it is determined that a spoofing attempt is not taking place, the method may comprise widening the preset range (e.g., lowering the second threshold). In general, the method may comprise adjusting the second threshold based on the 30 confidence measure that the display apparatus 40 is present. Advantageously, therefore, the level of the enhanced security provided by the method is congruent with the security risk. It could be that these actions in the event that a spoofing event is taking place are performed after a single application of the method of Figure 1 or after more than one 02 05 25 application of the method of Figure 1. For example, a first determining S1 could indicate a spoofing attempt is taking place, and a further determining S2 may be prompted to confirm the spoofing attempt is taking place. The aforementioned data store may be part of the image capturing device 10 or part of 5 an external device in electronic communication (e.g., via a server) with the image capturing device 10. The data store may also be part of the optically readable security element 20. For example, the optically readable security element 20 may comprise an engineered component, such as a hologram, bar code, QR code (RTM) or similar programmable component, encoded with, or generally comprising information such as 10 the stored identity. Preferably, the optically readable security element 20 comprises a unique (e.g., randomised) component (e.g., a random deterministic feature), encoding the identity. The randomised component encoding the identity, compared with the engineered component encoding the identity, advantageously engenders a more robust barrier to 15 fraudulent reading of the optically readable security element 20. More preferably, the optically readable security element 20 comprises at least one optical emitter arranged to be read via emission radiation emitted therefrom. Relatedly, the at least one optical emitter may be arranged to be excited by excitation radiation. The one or more emitters may serve as the component that provides or serves as the 20 unique identity. Advantageously, the optically readable security element 20 being read via emission emitted therefrom provides a more robust barrier to fraudulent reading, more readily preventing spoofing or copying by, for instance, simply replicating (e.g., by printing) a barcode, QR code (RTM) or similar. This advantage is particularly true when one or more (e.g., hundreds, thousands or millions or more) of emitters are distributed 25 randomly. For instance, this effect may be achieved using quantum dots, flakes of 2D materials, (e.g., small) molecules, atomic defects or vacancies, plasmonic structures or similar. The method may comprise illuminating the optically readable security element 20 and determining whether a spoofing attempt is taking place based on an optical response 30 of the optically readable security element 20 to the illuminating. For example, the data store may store an expected optical response in the case that the optically readable security element 20 is authentic, and the method may comprise retrieving the expected optical response, comparing the expected optical response to the optical response and determining that a spoofing attempt is not taking place only if the optical response does 02 05 25 not match the expected optical response within a preset range. Illuminating may be a particularly powerful way by which to determine whether spoofing attempt is taking place in the case of the authentic optically readable security element 20 comprising at least one optical emitter. For example, the authentic optically readable security element 5 20 may comprise optical emitters that can be excited and emit with a known emission profile by which its authenticity is verifiable. Of course, a spoofing attempt, comprising an image of an authentic optically readable security element provided by a display apparatus 40, cannot be excited or caused to emit, and so would fail this test. The steps of the method may be performed in any order. At least two of the steps S1, 10 S2, S3 of the method may be simultaneous. Advantageously, performing two or more of the steps simultaneously may reduce the time taken to authenticate the optically readable security element 20. The image capturing device 10 may be a terminal device, such as a smartphone. The image capturing device 10 may be configured to emit excitation radiation to excite the 15 at least one optical emitter (e.g., from an electromagnetic radiation source, such as a flash or LED). By being configured to emit excitation radiation, the image capturing device 10, advantageously, facilitates the aforementioned robust security. Further, emitting the excitation radiation from the image capturing device 10, advantageously, allows convenient control of excitation of the at least one optical emitter. 20 Figure 3 shows the image capturing device 10 of Figure 2 in more detail. The image capturing device comprises a reader 11, a sensor 12 and a processor 13. The reader 11 is configured to perform the reading S2. The sensor 12 is configured to check for a presence of a display apparatus 40, as described above. The processor 13 is configured to perform the determining S1 and the verifying S3. The sensor 12 may be 25 part of the processor 13. The processor 13 may perform the determining S1 and the verifying S3 locally or externally (e.g., at a server). The processor 13 may be dedicated hardware or existing hardware specifically configured to perform the determining S1 and the verifying S3. The image capturing device 10 may include a communication unit (not shown) to communicate with, for example, the server. As mentioned, the image 30 capturing device may comprise speakers and / or a display (not shown). In summary, the present disclosure has described a method that prevents or hinders spoofing of an optically readable security element over the short term or the long term and in a manner sensitive to the level of risk. Again, this method is in stark contrast with, and opposite to, how some optically readable security elements are currently used, 05 25 where the use and sharing of displayed images of optically readable security elements are encouraged and even required. Although preferred embodiments have been shown and described, it will be appreciated by those skilled in the art that various changes and modifications might be made without 5 departing from the scope of the invention, as defined in the appended claims and as described above. The optional features set out herein may be used either individually or in combination with each otherwhere appropriate and particularly in the combinations as set out in the accompanying claims. The optional features for each aspect or exemplary embodiment 10 of the invention, as set out herein are also applicable to all other aspects or exemplary embodiments of the invention, where appropriate. In other words, the skilled person reading this specification should consider the optional features for each aspect or exemplary embodiment of the invention as interchangeable and combinable between different aspects and exemplary embodiments. 15 CM 02 05 25
Claims
1. A method of authenticating an optically readable security element, by an image capturing device, the method comprising:5 determining whether a spoofing attempt is taking place by checking for a presence of a display apparatus, whereby the presence causes it to be determined that a spoofing attempt is taking place;reading the optically readable security element; andverifying the optically readable security element as authentic based on the 10 reading of the optically readable security element and the determining of whether a spoofing attempt is taking place;wherein checking for the presence of the display apparatus comprises detecting an optical artifact associated with the display apparatus, and wherein the optical artifact is a moire pattern.
152. The method of claim 1, wherein the optically readable security element is verified as authentic only if it is determined that a spoofing attempt is not taking place.
3. The method of any preceding claim, further comprising:20 extracting an identity from the optically readable security element;retrieving a stored identity from a data store; andverifying the optically readable security element as authentic by comparing the extracted identity with the retrieved stored identity.25 4. The method of claim 3, wherein the optically readable security element is verified asauthentic only if the extracted identity matches the retrieved stored identity within a preset range.
5. The method of any preceding claim, wherein the display apparatus is configured to 30 duplicate an optically readable security element, and wherein determining whether a02 05 25spoofing attempt is taking place comprises determining whether the display apparatus is duplicating the optically readable security element.
6. The method of any preceding claim, further comprising:5 calculating a confidence measure that that the display apparatus is present; and determining that spoofing is taking place only if the confidence measure is above a threshold value.
7. The method of claim 6, wherein the optical artifact is also at least one or more of: a 10 pictorial element, reflection, emission.
8. The method of any preceding claim, wherein, in the event that it is determined that a spoofing attempt is taking place, the method further comprises:delaying the reading for a predetermined period of time.
159. The method of any preceding claim, wherein, in the event that it is determined that a spoofing attempt is taking place, the method further comprises:transmitting an output signal.20 10. The method of claim 9, wherein the output signal is an alert signal.
11. The method of any one of claims dependent on claim 4, wherein, in the event that it is determined that a spoofing attempt is taking place, the method further comprises:narrowing the preset range.2512. The method of any preceding claim, further comprising:illuminating the optically readable security element; anddetermining whether a spoofing attempt is taking place based on an optical response of the optically readable security element to the illuminating.05 2513. An image capturing device for authenticating an optically readable security element, the image capturing device comprising:a reader configured to read the optically readable security element;5 a sensor configured to check for a presence of a display apparatus; anda processor configured to:determine whether a spoofing attempt is taking place based on an output of the sensor, whereby the presence of a display apparatus causes it to be determined that a spoofing attempt is taking place; and10 verify the optically readable security element as authentic based on thereading of the optically readable security element reader and the determining of whether a spoofing attempt is taking place;wherein checking for the presence of the display apparatus comprises detecting an optical artifact associated with the display apparatus, and wherein the optical artifact15 is a moire pattern.CM
Citation Information
Patent Citations
Apparatus, method and system for determining the source of an optical code presentated to an optical code scanner
US20130134217A1
Method for improving the accuracy of a convolution neural network training image data set for loss prevention applications
US20200192608A1