Mobile device user authentication methods
Patent Information
- Application Number
- JP2023577596
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-06-15
- Filing Date
- 2022-06-14
- Publication Date
- 2025-06-23
AI Technical Summary
Mobile devices face security challenges in facial authentication due to limited computing power and memory capacity in trusted execution environments, making them vulnerable to tampering and unauthorized access.
A method that utilizes a normal execution environment for initial facial image analysis with a trained model to generate a multidimensional vector, which is then processed in a trusted execution environment for secure verification, ensuring enhanced security by preventing tampering.
This approach leverages the computational power of the normal execution environment for analysis while ensuring secure verification in the trusted environment, providing robust and tamper-proof facial authentication.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a method for authenticating a user of a mobile device, a method for authentication, a mobile device and various uses of the mobile device. The device, the method and the use according to the invention may in particular be employed in various fields, for example in everyday life, security technology, gaming, traffic technology, production technology, art, photography, such as digital photography or videography for documentary or technical purposes, safety technology, information technology, agriculture, crop protection, maintenance, cosmetics, medical technology or science, although other applications are also possible. [Background technology]
[0002] The use of Trusted Execution Environment (TEE) technology is known for use in mobile devices such as smartphones and tablet computers (see, for example, en.wikipedia.org / wiki / Trusted_execution_environment). However, the Trusted Execution Environment of the processor of a mobile device has limited computational power and memory capacity compared to the main processor, and in particular the normal execution environment.
[0003] Mobile devices are used in a wide range of applications, where security is often required. For example, mobile devices may be used for payments. To authorize the payment process, the identity of the user is usually confirmed using the face recorded by the camera. Neural networks may be used for facial analysis and used to reveal the identity of the user based on specified criteria. Based on the results, the payment process may be authorized. This sharing may be tampered with in the normal insecure environment of the processor of the mobile device. However, due to limited computing power and memory capacity, it is not possible to perform facial authentication and / or recognition in a trusted execution environment. Performing image analysis in a non-secure normal execution environment may expose the recording of the user's face in an accessible state, for example for modification, and therefore presents a security problem.
[0004] US2021 / 173916A1 describes systems, devices, methods, and computer-readable media in various embodiments for generating a dynamic challenge passphrase data object. The method includes establishing a plurality of data record clusters representing a set of mutually exclusive individual structured data records, ranking the plurality of feature data fields based on a determined contribution value of each feature data field to the establishment of the data record clusters, and identifying a first and a second feature data field of the plurality of feature data fields using the ranked plurality of feature data fields. The method includes generating a dynamic challenge passphrase data object, where the first or second feature data field is used to establish a statement string portion, and a remaining one of the first or second feature data fields is used to establish a question string portion and a correct answer string.
[0005] US2019 / 205518A1 describes a method for use on a mobile device to authenticate or identify a user based on a face. The method includes obtaining, in a trusted execution environment of the mobile device, a sequence of biometric face samples corresponding to successive image frames of a user, and modifying or replacing, in the trusted execution environment, a portion of the biometric face samples in the sequence to generate a modified sequence including a test biometric face sample. The method includes transmitting the modified sequence to a rich execution environment of the mobile device, and classifying, in the rich execution environment, at least a portion of the biometric face samples using a classifier to generate, for each classified biometric face sample, a sequence of intermediate outputs and a classification result. The method also includes transmitting, for each classified biometric face sample, at least a portion of the intermediate output or classification result and / or a digest of the intermediate output to the trusted execution environment. The method further includes verifying, in the trusted execution environment, for at least one test biometric face sample, at least a portion of the intermediate output and / or result and / or digest.
[0006] CN105138973A describes a face recognition method and apparatus, which includes the following steps: using a multi-layer deep convolutional network that has been previously subjected to multi-layer classification network joint training to sequentially extract multi-level feature vectors from a face image to be recognized and a face image template; sequentially mapping the multi-level feature vectors into a unified dimensional feature vector through a unified dimensional linear mapping matrix; concatenating the unified dimensional feature vector into a serially combined feature vector; performing dimensionality reduction mapping on the combined feature vector through a linear dimensionality reduction mapping matrix; normalizing the cosine value with the absolute value through linear discriminant analysis, and comparing and authenticating the obtained feature vector of the face image to be recognized and the feature vector of the face image template. Summary of the Invention [Problem to be solved by the invention]
[0007] It is therefore an object of the present invention to provide an apparatus and method for the above-mentioned technical problems of known apparatus and methods, in particular an object of the present invention to provide an apparatus and method for enabling authentication of a user of a mobile device with enhanced security. [Means for solving the problem]
[0008] This problem is solved by the invention with the features of the independent patent claims. Advantageous developments of the invention, which can be realized individually or in combination, are set out in the dependent claims and / or in the following description and detailed embodiments.
[0009] When used below, the terms "having", "comprises" or "including" or any grammatical variants thereof are used in a non-exclusive manner. These terms may therefore refer both to the situation in which, apart from the features introduced by these terms, no further features are present in the entity described in this context, and to the situation in which one or more further features are present. As an example, the expressions "A has B", "A comprises B" and "A includes B" may refer both to the situation in which no other elements are present in A apart from B (i.e., A is solely and exclusively composed of B) and to the situation in which, in addition to B, one or more elements are present in entity A, such as element C, elements C and D, or further elements.
[0010] Furthermore, it should be noted that the terms "at least one," "one or more," or similar language indicating that a feature or element may be present more than one time are typically used only once when introducing each feature or element. It should be noted that in most cases hereinafter, when referring to each feature or element, the language "at least one" or "one or more" will not be repeated, despite the fact that those features or elements may appear more than one time.
[0011] Furthermore, when used hereinafter, the terms "preferably", "more preferably", "particularly", "more particularly", "particularly", "more particularly" or similar terms are used in connection with any feature without limiting the possibility of alternatives. Features introduced by these terms are therefore optional features and are not intended to limit the scope of the claims in any way. The invention can be practiced with alternative features, as the skilled artisan will recognize. Similarly, features introduced by "in one embodiment of the invention" or similar expressions are intended to be optional features, without any limitation on alternative embodiments of the invention, without any limitation on the scope of the invention, and without any limitation on the possibility of combining the feature introduced in such a way with other optional or non-optional features of the invention.
[0012] In a first aspect of the present invention, a method for authenticating a user of a mobile device is disclosed.
[0013] The term "mobile device" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. The term may specifically refer to, but is not limited to, mobile electronic devices, more specifically mobile communication devices such as mobile phones or smartphones. Additionally or alternatively, a mobile device may refer to a tablet computer or other type of portable computer.
[0014] The term "user" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. The term may specifically refer, without limitation, to a person using a mobile device. A user may be the owner and / or other authorized person of a mobile device.
[0015] The term "authentication" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to a special or customized meaning. The term may specifically refer to, but is not limited to, verifying the identity of a user. Specifically, authentication can include distinguishing a user from other humans or objects, in particular distinguishing between authorized and unauthorized access. Authentication can include verifying the identity of each user and / or assigning an identity to a user. Authentication can include generating and / or providing identity information to other devices or units, such as at least one authentication unit for authentication to perform a payment process. Identity information can be proven by authentication. For example, identity information can be and / or include at least one identity token. If authentication is successful, a facial image recorded by a camera of the mobile device is verified to be a facial image of the user and / or the identity of the user is verified.
[0016] This method involves the following steps: a) imaging at least one first image of a face by using at least one camera of a mobile device; b) providing the first image to a normal execution environment of a processor of the mobile device, and providing the first image to a trusted execution environment of the processor; c) analyzing a first image using at least one trained model in a normal execution environment, thereby determining a multi-dimensional vector comprising image information; d) A face authentication step, comprising the steps of: di) providing the multi-dimensional vector to a trusted execution environment; dii) determining a second image from the multi-dimensional vector in a trusted execution environment by using at least one decoder; diii) comparing the first image and the second image, and if the first image and the second image are identical, validating the multi-dimensional vector; div) if the multi-dimensional vector is verified, the verified multi-dimensional vector is compared with a multi-dimensional vector of the user's face stored in the trusted execution environment, and if the multi-dimensional vector and the stored multi-dimensional vector of the user's face are identical, the user is authenticated; a face verification step including: Includes.
[0017] The method steps may be performed in a given order or in a different order, there may be one or more additional method steps not listed, and one, more than one, or even all of the method steps may be performed repeatedly.
[0018] The term "camera" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. The term may specifically refer to, but is not limited to, a device having at least one image element configured to record or capture spatially resolved one-dimensional, two-dimensional, or even three-dimensional optical data or information. As an example, the camera may comprise at least one camera chip, such as at least one CCD chip and / or at least one CMOS chip, configured to record an image. For example, the camera may be a color camera comprising at least three color pixels, as described in more detail below. The camera may be a color CMOS camera. For example, the camera may include black and white pixels and color pixels. The color pixels and black and white pixels may be combined within the camera. The camera may comprise at least one color camera and at least one black and white camera, such as a black and white CMOS. The camera may comprise at least one black and white CMOS chip. The camera may generally comprise a one-dimensional or two-dimensional array of image sensors, such as pixels.
[0019] The camera may include at least one camera chip or image chip as well as one or more optical elements, such as one or more lenses. As an example, the camera may be a fixed focus camera with at least one lens fixedly adjusted relative to the camera. Alternatively, however, the camera may be equipped with one or more variable lenses that can be adjusted automatically or manually. However, other cameras are possible.
[0020] The term "imaging" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. The term may specifically refer to, but is not limited to, capturing and / or generating and / or determining and / or recording at least one image by using a camera. Imaging may include capturing a single image and / or multiple images, such as a series of images. For example, imaging may include recording a series of images continuously, such as a video or movie. Imaging may be initiated by a user action or may be initiated automatically, for example, upon automatic detection of the presence of at least one object within the field of view and / or within a predefined sector of the camera's field of view. Imaging may be supported by a processor of the mobile device.
[0021] As used herein, without limitation, the term "image" may specifically relate to data recorded by using a camera, such as a plurality of electronic readings from a camera, such as pixels of a camera chip. The first image may be an initial image imaged by using a camera. The first image may include raw image data or may be a pre-processed image. For example, the pre-processing may include applying at least one filter, and / or at least one background correction, and / or at least one background subtraction to the raw image data. The first image may include a scene including a face. The pre-processing may include one or more of performing face detection and / or selecting a region of interest. The region of interest may be determined manually or automatically, such as by recognizing features in the first image.
[0022] The term "processor" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to a special or customized meaning. The term may specifically, but without limitation, refer to any logic circuitry configured to perform basic operations of a computer or system, and / or generally, a device configured to perform calculations or logical operations. In particular, a processor may be configured to process basic instructions that run a computer or system. As an example, a processor may comprise at least one arithmetic logic unit (ALU), at least one floating point unit (FPU), such as a mathematical coprocessor or numeric coprocessor, a number of registers, specifically registers configured to provide operands to the ALU and store operation results, and memory, such as L1 and L2 cache memories. In particular, a processor may be a multi-core processor. In particular, a processor may be or comprise a central processing unit (CPU). Additionally or alternatively, a processor may be or comprise a microprocessor, and thus in particular, elements of a processor may be included in one single integrated circuit (IC) chip. Additionally or alternatively, the processor may be or comprise one or more chips, such as one or more application specific integrated circuits (ASICs) and / or one or more field programmable gate arrays (FPGAs) and / or one or more tensor processing units (TPUs) and / or dedicated machine learning optimization chips, etc. The processor may be specifically configured, such as by software programming, to perform one or more evaluation operations.
[0023] The term "execution environment" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. The term may specifically refer to a set of hardware and software components that provide facilities configured to support the execution of applications, without limitation. The execution environment may be designed as described in GlobalPlatform Technology, TEE System Architecture, Version 1.2, Public Release November 2018, Document Reference: GPD_SPE_009, or www.qualcomm.com / media / documents / files / guard-your-data-with-the-qualcomm-snapdragon-mobile-platform.pdf, or www.arm.com / why-arm / technologies / trustzone-for-cortex-a / tee-reference-documentationni. Specifically, the execution environment may include at least one hardware processing unit, at least one memory, in particular a volatile memory and a non-volatile memory, connections between the hardware processing unit and other hardware resources, and peripheral interfaces.
[0024] As used herein, the term "regular execution environment", also referred to as Rich Execution Environment, is a broad term and should be given its ordinary and customary meaning to one of ordinary skill in the art and should not be limited to any special or customized meaning. A regular execution environment can be designed as described in GlobalPlatform Technology, TEE System Architecture, Version 1.2, Public Release November 2018, Document Reference: GPD_SPE_009, or www.qualcomm.com / media / documents / files / guard-your-data-with-the-qualcomm-snapdragon-mobile-platform.pdf, or www.arm.com / why-arm / technologies / trustzone-for-cortex-a / tee-reference-documentation. The term "normal execution environment" may specifically refer to the execution environment of a processor including, but not limited to, at least one device operating system (OS) and / or rich operating system (rich OS) and all other components of the device, in particular at least one system on chip (SoC), other discrete components, firmware, and software configured to run, host, and support the OS and / or rich OS. An SoC may be an electronic system with all its components included in a single integrated circuit. The normal execution environment may exclude the trusted execution environment and the secure element (SE) included in the mobile device. In particular, the normal execution environment may be everything outside of the trusted execution environment. The normal execution environment may be executed in an execution environment outside of the hardware of the trusted execution environment, in particular due to the size and the need for the OS and / or rich OS. The normal execution environment may have a much lower physical security boundary compared to the trusted execution environment.Thus, the normal execution environment may be considered untrusted, although internal trust structures may exist in the normal execution environment.
[0025] The term "Trusted Execution Environment (TEE)" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. A trusted execution environment can be designed as described in GlobalPlatform Technology, TEE System Architecture, Version 1.2, Public Release November 2018, Document Reference: GPD_SPE_009, or www.qualcomm.com / media / documents / files / guard-your-data-with-the-qualcomm-snapdragon-mobile-platform.pdf, or www.arm.com / why-arm / technologies / trustzone-for-cortex-a / tee-reference-documentation. The term "Trusted Execution Environment" may specifically refer to, but is not limited to, an execution environment that has at least one security feature and meets at least one security requirement. The Trusted Execution Environment may be configured to protect assets within the Trusted Execution Environment from common software attacks. The Trusted Execution Environment may be configured to define strict safeguards regarding data and functions that a program may access. The Trusted Execution Environment may be configured to resist a defined set of threats. Several techniques are known for implementing a Trusted Execution Environment, and the security level achieved may vary accordingly. In particular, the Trusted Execution Environment may meet security requirements such as those described in source.android.com / compatibility / 11 / android-11-cdd#7_3_10_biometric_sensors.The TEE may operate the camera, or a chip with a secure channel to the TEE, in a mode that prevents the camera frames from being read or modified outside the TEE, especially while biometric-based authentication or enrollment is taking place. In the case of an RGB single camera solution, the camera frames may be read outside the TEE to support operations such as preview for enrollment, but still cannot be modified. The TEE must not allow unencrypted access to identifiable biometric data or data derived therefrom (e.g., embedded data) to any part of the processor outside the context of the TEE. The TEE may have a secure processing pipeline so that data cannot be directly injected to falsely authenticate as a user by a compromise of the operating system or kernel. The TEE may have a hardware-backed keystore implementation. The TEE may encrypt and cryptographically authenticate all identifiable data so that it cannot be retrieved, read, or tampered with outside the TEE or a chip with a secure channel to the TEE. The TEE can prevent adding new biometrics without first establishing a chain of trust by having the user verify existing device credentials or add new device credentials, e.g., a PIN and / or pattern and / or password secured by the TEE.
[0026] A trusted execution environment may be an execution environment that is separated from the normal execution environment. The trusted execution environment may be separated from the normal execution environment by one or more of physical separation, hardware logic-based separation, or cryptographic separation methods. Specifically, the trusted execution environment may be separated from the normal execution environment by electronic access control via TEE system hardware that is configurable by TEE-resident boot software or runtime software.
[0027] The term "providing" the first image as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. The term may specifically refer to, but is not limited to, transferring image data recorded by a camera to a processor of a mobile device, in particular to a normal execution environment and a trusted execution environment. The first image may be provided to the normal execution environment via a regular path. The regular path may be an untrusted path. The regular path may be configured to allow access by software in the normal execution environment and / or the trusted execution environment. The first image may be provided to the trusted execution environment via a secure path, which may be configured to prevent the first image from being derived and / or modified by any software in the normal execution environment.
[0028] The analysis of the first image is performed in a normal execution environment, so that high computational power and memory capacity can be utilized for the analysis of the first image.
[0029] The analysis in step c) may include one or more of filtering and convolution of the first image. The trained model may include at least one face recognition model. The analysis of the first image may be performed by using a face recognition system such as FaceNet. Thus, the face recognition system may be designed as described in Florian Schroff, Dmitry Kalenichenko, James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering", arXiv:1503.03832.
[0030] The term "trained model" as used herein is a broad term and should be given its ordinary and customary meaning to one of ordinary skill in the art and should not be limited to a special or customized meaning. The term may specifically, without limitation, refer to a mathematical model trained with at least one training data set. A trained model can be retrained and / or updated based on additional training data. A trained model can be trained by using machine learning. The term "machine learning" as used herein is a broad term and should be given its ordinary and customary meaning to one of ordinary skill in the art and should not be limited to a special or customized meaning. The term may specifically, without limitation, refer to a method of using artificial intelligence (AI) for automatic model building, and in particular for model parameterization. A trained model may be parameterized by using one or more of machine learning, deep learning, neural networks, or other forms of artificial intelligence. A trained model may be trained using a record of training data. The record of training data may include training input data and corresponding training output data. The training output data of a record of training data may be the expected result produced by the model when given as input the training input data of the same record of training data. The deviation between this expected result and the actual result produced by the algorithm may be observed and evaluated by a "loss function". This loss function may be used as feedback to adjust the parameters of the model. For example, the parameters may be adjusted with an optimization goal of minimizing the value of the loss function obtained when all training input data is input to the model and the results are compared to the corresponding training output data. The results of this training are such that, given a relatively small number of records of training data as "ground truth", the model is able to perform its task well against a number of records of input data that are orders of magnitude larger.Thus, the model may include at least one algorithm and model parameters. The parameters of the model may be generated by using at least one artificial neural network.
[0031] The trained model can include at least one convolutional neural network. For example, the convolutional neural network may be designed as described in MD Zeiler and R. Fergus, "Visualizing and understanding convolutional networks," CoRR, abs / 1311.2901, 2013, or C. Szegedy et al., "Going deeper with convolutions," CoRR, abs / 1409.4842, 2014. For more information about convolutional neural networks for face recognition systems, see Florian Schroff, Dmitry Kalenichenko, James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering," arXiv:1503.03832.
[0032] As training data, labeled image data from an image database can be used. In particular, the labeled faces can be one or more of the Youtube® Faces database as described in G.B. Huang, M. Ramesh, T. Berg, and E. Learned-Miller, “Labeled faces in the wild: A database for studying face recognition in unconstrained environments,” Technical Report 07-49, University of Massachusetts, Amherst, October 2007, and Wolf, T. Hassner, and I. Maoz, “Face recognition in unconstrained videos with matched background similarity,” IEEE Conf. CVPR, 2011. Training of the convolutional neural network may be performed as described in Florian Schroff, Dmitry Kalenichenko, James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering", arXiv:1503.03832.
[0033] The output of the analysis in step c) using the trained model may be a multidimensional vector. The multidimensional vector may be an embedding, in particular a low-dimensional representation of the first image. Determining the multidimensional vector from the first image as input to the trained model is performed as described in Florian Schroff, Dmitry Kalenichenko, James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering", arXiv:1503.03832. In particular, the trained model may determine a vector of 128 numerical values from the first image. The entries of the multidimensional vector may be imaged facial features. Image information may be embedded and / or mapped into the multidimensional vector. The image information may be any parameter of the first image that characterizes and / or defines the first image. The image information may be information that allows comparison with other image information to verify facial similarity of a person.
[0034] The multi-dimensional vector is provided to the trusted execution environment. The provision of the multi-dimensional vector can be performed by using at least one interface between the normal execution environment and the trusted execution environment, in particular by access from the trusted execution environment to the normal execution environment.
[0035] In the trusted execution environment, a second image from the multi-dimensional vector is determined by using at least one decoder. The second image may be an image reconstructed from the multi-dimensional vector. Determining the second image may include the decoder reconstructing an image of the user's face from the multi-dimensional vector. The term "decoder" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to a special or customized meaning. The term may specifically refer, without limitation, to at least one element of the trusted execution environment configured to reconstruct an image from an embedding, in particular from a multi-dimensional vector. Such decoders and their operating principles are generally known to those skilled in the art, as described, for example, in papers.nips.cc / paper / 2014 / file / a14ac55a4f27472c5d894ec1c3c743d2-Paper.pdf.
[0036] The method includes comparing the first image and the second image. The comparison may be performed by a processor in a trusted execution environment. The comparison may include comparing at least one feature, in particular a plurality of features, of the first image and the second image. The features used in the comparison may be predefined. The features of the first image and the features of the second image are based on the same image data, but the features are generated by using different algorithms. In particular, the features included by the multi-dimensional vector were determined by the face recognition algorithm described above. The multi-dimensional vector was determined from the first image, which is also stored in the TEE. Additionally or alternatively, the first image and the second image may be compared, for example, with a pixel-wise similarity measure. If the first image and the second image are identical, the multi-dimensional vector is verified. The term "same" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. The term may specifically refer to being identical, at least within an acceptable range, without limitation. The first and second images may be considered to be identical within a tolerance of ±30%, preferably ±10%, more preferably ±5%.
[0037] If the multi-dimensional vector is verified, the verified multi-dimensional vector is compared to a multi-dimensional vector of the user's face stored in the trusted execution environment. If not, the procedure may be interrupted and / or resumed. If the multi-dimensional vector and the stored multi-dimensional vector of the user's face are identical, the user is authenticated. The multi-dimensional vector of the user's face may be stored in at least one memory of the TEE. As outlined above, an embedding describes a mathematical representation of facial features that can be compared to each other, for example by using a scalar product.
[0038] Performing image analysis in the non-secure normal execution environment can utilize all of the computational power and memory capacity of the normal execution environment. Proving the results of the image analysis obtained in the normal execution environment by comparing it with a first image stored in the trusted execution environment allows for enhanced authentication of the user.
[0039] In a further aspect, a method of authenticating a user is disclosed. The method includes implementing a method for authenticating a user of a mobile device according to the present invention. The method further includes the trusted execution environment outputting a signal for authenticating a process step. The process step includes one or more of making a payment, signing a document, accessing the mobile device, enabling an application such as BiometricPrompt and / or FIDO2 API (see source.android.com / security / biometric / measure).
[0040] The term "authentication" as used herein is a broad term and should be given its ordinary and customary meaning to those skilled in the art and should not be limited to any special or customized meaning. The term may specifically refer, without limitation, to the process of granting a user permission to perform further process steps.
[0041] For details, options and definitions, please refer to the previous method.
[0042] A further aspect is a computer program for user authentication of a mobile device configured to, when executed on a computer or a computer network, cause the computer or the computer network to fully or partially perform the method for user authentication according to the invention, the computer program being configured to perform and / or execute at least steps a) to d) of the method for authentication according to the invention. Similarly, a computer-readable storage medium is disclosed, which comprises instructions that, when the program is executed by the computer or the computer network, cause the computer or the computer network to perform the method for authentication according to the invention, such as according to any one of the embodiments disclosed above and / or any one of the embodiments disclosed in more detail below. The term "computer-readable storage medium" as used herein may in particular refer to a non-transitory data storage means, such as a hardware storage medium, on which computer-executable instructions are stored. The computer-readable data carrier or storage medium may in particular be or include a storage medium, such as a random access memory (RAM) and / or a read-only memory (ROM).
[0043] Thus, in particular, one, several or even all of the method steps a) to d) as set out above can be implemented by using a computer or a computer network, preferably by using a computer program.
[0044] Further disclosed and proposed herein is a computer program product having program code means for carrying out the method according to the invention in one or more of the embodiments encompassed herein when said program is executed on a computer or a computer network. In particular, said program code means may be stored on a computer readable data carrier and / or on a computer readable storage medium.
[0045] Further disclosed and proposed in this specification is a data carrier having a stored data structure which, after being loaded into a computer or computer network, e.g. a working memory or a main memory of the computer or computer network, is capable of performing the methods according to one or more of the embodiments disclosed in this specification.
[0046] Further disclosed and proposed herein is a non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform a method according to one or more of the embodiments disclosed herein.
[0047] Further disclosed and proposed herein is a computer program product having program code means stored on a machine-readable carrier for performing the method according to one or more of the embodiments disclosed herein when the program is executed on a computer or a computer network. As used herein, a computer program product refers to a program as a tradeable product. The product can generally be in any form, such as in paper form, or on a computer-readable data carrier and / or on a computer-readable storage medium. In particular, the computer program product can be distributed via a data network.
[0048] Also disclosed and suggested herein is a modulated data signal containing instructions readable by a computer system or computer network for implementing the methods according to one or more of the embodiments disclosed herein.
[0049] Specifically, further disclosed herein are: - a computer or a computer network comprising at least one processor, the processor being adapted to carry out a method according to one of the embodiments described herein; - a computer-loadable data structure adapted to carry out a method according to one of the embodiments described herein while said data structure is executed on a computer; - a computer program adapted to carry out a method according to one of the embodiments described herein while said program is run on a computer, - a computer program comprising program means for carrying out a method according to one of the embodiments described herein while said computer program is being run on a computer or a computer network; a computer program comprising program means according to the preceding embodiments, the program means being stored on a computer readable storage medium; and - a storage medium, on which a data structure is stored, the data structure being adapted to carry out a method according to one of the embodiments described herein after being loaded into a main and / or working storage of a computer or a computer network, - a computer program product having program code means, which may be stored on or is stored on a storage medium, such that, when said program code means are executed on a computer or a computer network, the computer program product performs a method according to one of the embodiments described herein; It is.
[0050] In a further aspect of the invention, a computer program for authenticating a user of a mobile device is disclosed. The computer program comprises instructions which, when the program is executed by a computer or a computer network, cause the computer or the computer network to perform an authentication method according to the invention, such as according to any one of the embodiments disclosed above and / or any one of the embodiments disclosed in more detail below. Similarly, a computer-readable storage medium is disclosed, comprising instructions which, when the program is executed by a computer or a computer network, cause the computer or the computer network to perform an authentication method according to the invention, such as according to any one of the embodiments disclosed above and / or any one of the embodiments disclosed in more detail below.
[0051] In a further aspect, a mobile device is disclosed. The mobile device comprises at least one camera and at least one processor. The mobile device is configured for carrying out at least steps a) to d) of the authentication method according to the invention and / or for carrying out the authentication method according to the invention, for example according to any one of the embodiments disclosed above and / or according to any one of the embodiments disclosed in more detail below. For details, options and definitions please refer to the method described above.
[0052] In a further aspect of the present invention, the use of a mobile device according to the present invention, such as according to one or more of the embodiments given above or in more detail below, is proposed for a use purpose selected from the group consisting of mobile device payment, document signing, BiometricPrompt and / or FIDO2 API (see source.android.com / security / biometric / measure), etc.
[0053] Overall, in the context of the present invention, the following embodiments are considered to be preferred: Embodiment 1. A method for authenticating a user of a mobile device, comprising the steps of: a) imaging at least one first image of a face by using at least one camera of the mobile device; b) providing the first image to a normal execution environment of a processor of the mobile device, and providing the first image to a trusted execution environment of the processor; c) analyzing the first image using at least one trained model in the normal execution environment, thereby determining a multi-dimensional vector comprising image information; d) A face authentication step, comprising the steps of: di) providing said multi-dimensional vector to said trusted execution environment; dii) determining a second image from said multi-dimensional vector in said trusted execution environment by using at least one decoder; diii) comparing the first image and the second image, and validating the multi-dimensional vector if the first image and the second image are identical; div) if the multi-dimensional vector is verified, the verified multi-dimensional vector is compared with a multi-dimensional vector of a user's face stored in the trusted execution environment, and if the multi-dimensional vector and the stored multi-dimensional vector of the user's face are identical, the user is authenticated; A face recognition step including: A method comprising:
[0054] Embodiment 2. The method of any preceding embodiment, wherein the trusted execution environment is an execution environment isolated from the normal execution environment.
[0055] Embodiment 3. The method of any preceding embodiment, wherein the trusted execution environment is isolated from the normal execution environment by one or more of physical isolation, hardware logic based isolation, or cryptographic isolation methods.
[0056]
[0023] Embodiment 4. The method of any one of the preceding embodiments, wherein the trusted execution environment comprises at least one security feature and satisfies at least one security requirement.
[0057] Embodiment 5. A method as in any one of the preceding embodiments, wherein the first image is provided to the normal execution environment via a normal path, the normal path being configured to allow access by software within the normal execution environment and / or the trusted execution environment.
[0058] Embodiment 6. A method as in any one of the preceding embodiments, wherein the first image is provided to the trusted execution environment via a secure path, the secure path being configured to prevent the first image from being derived and / or modified by any software within the normal execution environment.
[0059] Embodiment 7. The method of any one of the preceding embodiments, wherein determining the second image includes a decoder that reconstructs an image of the user's face from the multi-dimensional vector.
[0060]
[0023] Embodiment 8. The method of any one of the preceding embodiments, wherein the trained models include at least one facial recognition model.
[0061]
[0023] Embodiment 9. The method of any one of the preceding embodiments, wherein the trained model includes at least one convolutional neural network.
[0062] Embodiment 10. The method of any preceding embodiment, wherein the analysis in step c) includes one or more of filtering and convolution of the first image.
[0063] Embodiment 11. A method for authenticating a user, the method comprising implementing a method for authenticating a user of a mobile device as described in any one of the preceding embodiments, the method further comprising the trusted execution environment outputting a signal to authorize a process step, the process step comprising one or more of making a payment, signing a document, accessing the mobile device, and enabling an application.
[0064] Embodiment 12. A computer program for authenticating a user of a mobile device, configured, when executed on a computer or a computer network, to cause the computer or the computer network to fully or partially implement a user authentication method described in any one of the preceding embodiments relating to the authentication method, the computer program being configured to implement and / or execute at least steps a) to d) of the user authentication method described in any one of the preceding embodiments relating to the authentication method.
[0065] Embodiment 13. A computer program for authenticating a user of a mobile device configured, when executed on the computer or computer network, to cause the computer or computer network to fully or partially perform the method for authenticating a user described in embodiment 11.
[0066] Embodiment 14. A computer-readable storage medium comprising instructions which, when executed by a computer or computer network, cause at least steps a) to d) of the method according to any one of the preceding embodiments referring to methods relating to authentication, and / or cause the method for authenticating a user according to embodiment 11 to be performed.
[0067] Embodiment 15. A mobile device comprising at least one camera and at least one processor, the mobile device being configured to perform at least steps a) to d) of the method according to any one of the preceding embodiments referring to the authentication method and / or to implement the authentication method according to embodiment 11.
[0068] Embodiment 16. Use of a mobile device as described in the preceding embodiment for one or more of making a payment, signing a document. [Brief description of the drawings]
[0069] Further optional details and features of the invention are evident from the following description of preferred exemplary embodiments in conjunction with the dependent claims. In this context, certain features may be implemented in isolation or in combination with other features. The invention is not limited to the exemplary embodiments. The exemplary embodiments are illustrated diagrammatically in the figures. Identical reference numerals in the individual figures refer to identical elements or elements with identical functions or elements which correspond to each other in terms of function. [Figure 1] FIG. 1 illustrates an embodiment of a method for authenticating a user of a mobile device. [Diagram 2] FIG. 1 illustrates an embodiment of a mobile device according to the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0070] Detailed Description of the Embodiments: 1 shows a flow chart of one embodiment of a method for authenticating a user of a mobile device 110. The mobile device 110 may be a mobile electronic device, more specifically a mobile communication device such as a mobile phone or a smartphone. Additionally or alternatively, the mobile device 110 may also refer to a tablet computer or other type of portable computer.
[0071] A user may be a person using the mobile device 110. An embodiment of the mobile device 110 is shown very diagrammatically in FIG. 2. A user may be an owner of the mobile device 110 and / or other authorized person. Authentication may include distinguishing a user from other people or objects, in particular distinguishing between authorized and unauthorized access. Authentication may include verifying the identity of the respective user and / or assigning an identity to the user. Authentication may include generating and / or providing identity information, for example, to other devices or units, such as at least one authentication unit to other devices or units for authentication to perform a payment process. Identity information may be proven by authentication. For example, identity information may be and / or may include at least one identity token. In case of successful authentication, it is verified that the face image recorded by the camera 112 of the mobile device 110 is the face image of the user and / or the identity of the user is verified.
[0072] This method involves the following steps: a) imaging at least one first image 116 of a face by using at least one camera 112 of a mobile device 110 (denoted by reference numeral 114); b) providing the first image 116 (denoted by reference numeral 118) to a normal execution environment 120 of a processor 122 of the mobile device 110, and providing the first image 116 to a trusted execution environment 124 of the processor 122; c) analyzing the first image 116 using at least one trained model in a conventional execution environment 120 (denoted by reference numeral 126), thereby determining a multi-dimensional vector comprising image information; d) a face recognition step (denoted by reference numeral 128), comprising the steps of: di) providing the multi-dimensional vector (represented by arrow 130 in FIG. 2 ) to the trusted execution environment 124; dii) determining a second image from the multi-dimensional vector in the trusted execution environment 124 by using at least one decoder 132; diii) comparing the first image 116 and the second image, and validating the multi-dimensional vector if the first image 116 and the second image are identical; div) if the multi-dimensional vector is verified, the verified multi-dimensional vector is compared with a multi-dimensional vector of the user's face stored in the trusted execution environment 124, and if the multi-dimensional vector and the stored multi-dimensional vector of the user's face are identical, the user is authenticated; a face verification step including: Includes.
[0073] Camera 112 may refer to a device having at least one imaging element configured to record or capture spatially resolved one-dimensional, two-dimensional, or even three-dimensional optical data or information. As an example, camera 112 may comprise at least one camera chip, such as at least one CCD chip and / or at least one CMOS chip, configured to record an image. For example, camera 112 may be a color camera comprising at least three color pixels, as described in more detail below. Camera 112 may be a color CMOS camera. For example, camera 112 may include black and white pixels and color pixels. The color pixels and black and white pixels may be combined inside the camera. The camera may comprise at least one color camera and at least one black and white camera, such as a black and white CMOS. Camera 112 may comprise at least one black and white CMOS chip. Camera 112 may generally comprise a one-dimensional or two-dimensional array of image sensors, such as pixels.
[0074] The first image 116 may be an initial image captured by using the camera 112. The first image 116 may include raw image data or may be a pre-processed image. For example, the pre-processing may include applying at least one filter, and / or at least one background correction, and / or at least one background subtraction to the raw image data. The first image may include a scene including a face. The pre-processing may include one or more of performing face detection and / or selecting a region of interest. The region of interest may be determined manually or automatically, such as by recognizing features in the first image. The pre-processing of the first image 116 may be performed by the camera 112 and / or by the processor 122 of the mobile device 110.
[0075] Typical execution environment 120 can be designed as described in GlobalPlatform Technology, TEE System Architecture, Version 1.2, Public Release November 2018, Document Reference: GPD_SPE_009, or www.qualcomm.com / media / documents / files / guard-your-data-with-the-qualcomm-snapdragon-mobile-platform.pdf, or www.arm.com / why-arm / technologies / trustzone-for-cortex-a / tee-reference-documentation. Typical execution environment 120 can be an execution environment of a processor that includes at least one device operating system (OS) and / or rich operating system (rich OS) and all other components of processor 122, particularly at least one system-on-chip (SoC), other discrete components, firmware, and software configured to run, host, and support the OS and / or rich OS. An SoC can be an electronic system in which all of its components are included in a single integrated circuit. The normal execution environment 120 may exclude any trusted execution environment and secure element (SE) included in the mobile device. In particular, the normal execution environment 120 may be everything outside of the trusted execution environment. The normal execution environment 120 may execute in an execution environment outside of the hardware of the trusted execution environment, especially due to the size and need for an OS and / or rich OS. The normal execution environment 120 may have a much lower physical security boundary compared to the trusted execution environment. Thus, the normal execution environment 120 may be considered untrusted. However, an internal trust structure may exist in the normal execution environment 120.
[0076] The trusted execution environment 124 can be designed as described in GlobalPlatform Technology, TEE System Architecture, Version 1.2, Public Release November 2018, Document Reference: GPD_SPE_009, or www.qualcomm.com / media / documents / files / guard-your-data-with-the-qualcomm-snapdragon-mobile-platform.pdf, or www.arm.com / why-arm / technologies / trustzone-for-cortex-a / tee-reference-documentationni. The trusted execution environment 124 can be an execution environment that has at least one security feature and meets at least one security requirement. The trusted execution environment 124 can be configured to protect assets within the trusted execution environment 124 from common software attacks. The trusted execution environment 124 can be configured to define strict safeguards regarding data and functions that programs can access. The trusted execution environment 124 can be configured to resist a defined set of threats. Several techniques are known for implementing a trusted execution environment, and the security level achieved may vary accordingly. In particular, the trusted execution environment 124 may meet security requirements as described in source.android.com / compatibility / 11 / android-11-cdd#7_3_10_biometric_sensors. The TEE 124 may operate the camera 112, or a chip with a secure channel to the TEE 124, in a mode that prevents the camera frames from being read or modified outside the TEE 124, particularly while biometric-based authentication or enrollment is taking place. In the case of an RGB single camera solution, the camera frames may be read outside the TEE 124 to support operations such as preview for enrollment, but still cannot be modified.The TEE 124 must not allow unencrypted access to identifiable biometric data or data derived therefrom (e.g., embedded data) to any part of the processor outside the context of the TEE 124. The TEE 124 may have a secure processing pipeline so that a compromise of the operating system or kernel cannot directly inject data to falsely authenticate as a user. The TEE 124 may have a hardware-backed keystore implementation. The TEE 124 may encrypt and cryptographically authenticate all identifiable data so that it cannot be retrieved, read, or tampered with outside the TEE 124 or a chip with a secure channel to the TEE 124. The TEE 124 may prevent adding new biometrics without first establishing a chain of trust by having the user confirm existing device credentials, such as PIN and / or pattern and / or password secured by the TEE 124, or add new device credentials.
[0077] The trusted execution environment 124 may be an execution environment that is separated from the normal execution environment 120. The trusted execution environment 124 may be separated from the normal execution environment 120 by one or more of physical separation, hardware logic based separation, or cryptographic separation methods. In particular, the trusted execution environment 124 may be separated from the normal execution environment 120 by electronic access control via the TEE system hardware that is configurable by the TEE resident boot software or runtime software.
[0078] The first image 116 may be provided to the normal execution environment 120 via a normal path 134, which may be an untrusted path. The normal path 134 may be configured to allow access by software in the normal execution environment 120 and / or the trusted execution environment 124. The first image 116 may be provided to the trusted execution environment 124 via a secure path 136, which may be configured to prevent the first image 116 from being derived and / or modified by any software in the normal execution environment 120.
[0079] The analysis of the first image 116 is performed in a common execution environment 120. This allows for a high amount of computational power and memory capacity to be available for the analysis of the first image 116.
[0080] The analysis in step c) may include one or more of filtering and convolution of the first image 116. The trained model may include at least one face recognition model. The analysis of the first image may be performed by using a face recognition system such as FaceNet. Thus, the face recognition system may be designed as described in Florian Schroff, Dmitry Kalenichenko, James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering", arXiv:1503.03832.
[0081] The trained model can include at least one convolutional neural network. For example, the convolutional neural network may be designed as described in MD Zeiler and R. Fergus, "Visualizing and understanding convolutional networks," CoRR, abs / 1311.2901, 2013, or C. Szegedy et al., "Going deeper with convolutions," CoRR, abs / 1409.4842, 2014. For further details regarding convolutional neural networks for face recognition systems, see Florian Schroff, Dmitry Kalenichenko, James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering," arXiv:1503.03832.
[0082] As training data, labeled image data from an image database can be used. In particular, the labeled faces can be one or more of the Youtube® Faces database as described in G.B. Huang, M. Ramesh, T. Berg, and E. Learned-Miller, “Labeled faces in the wild: A database for studying face recognition in unconstrained environments,” Technical Report 07-49, University of Massachusetts, Amherst, October 2007, and Wolf, T. Hassner, and I. Maoz, “Face recognition in unconstrained videos with matched background similarity,” IEEE Conf. CVPR, 2011. Training of the convolutional neural network may be performed as described in Florian Schroff, Dmitry Kalenichenko, James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering", arXiv:1503.03832.
[0083] The output of the analysis in step c) using the trained model may be a multidimensional vector. The multidimensional vector may be an embedding, in particular a low-dimensional representation of the first image. Determining the multidimensional vector from the first image as input to the trained model is performed as described in Florian Schroff, Dmitry Kalenichenko, James Philbin, "FaceNet: A Unified Embedding for Face Recognition and Clustering", arXiv:1503.03832. In particular, the trained model may determine a vector of 128 numerical values from the first image. The entries of the multidimensional vector may be imaged facial features. Image information may be embedded and / or mapped into the multidimensional vector. The image information may be any parameters of the first image 116 that characterize and / or define the first image 116. The image information may be information that allows comparison with other image information to verify the similarity of the person's face. The image information may be information that allows reconstruction of the first image 116 using the embedding.
[0084] The multi-dimensional vector is provided to the trusted execution environment 124. The provision of the multi-dimensional vector can be performed by using at least one interface between the normal execution environment 120 and the trusted execution environment 124, in particular by access from the trusted execution environment 124 to the normal execution environment 120.
[0085] In the trusted execution environment 124, a second image from the multi-dimensional vector is determined by using at least one decoder 132. The second image may be an image reconstructed from the multi-dimensional vector. Determining the second image may include a decoder 132 reconstructing an image of the user's face from the multi-dimensional vector. The decoder 132 may be at least one element of the trusted execution environment 124 configured to reconstruct an image from the embedding, in particular from the multi-dimensional vector. Such decoders 132 and their operating principles are generally known to those skilled in the art, as described, for example, in papers.nips.cc / paper / 2014 / file / a14ac55a4f27472c5d894ec1c3c743d2-Paper.pdf.
[0086] The method includes comparing the first image 116 and the second image. The comparison may be performed by the processor 120 in a trusted execution environment. The comparison may include comparing at least one feature, in particular a plurality of features, of the first image 116 and the second image. The features used in the comparison may be predefined. The features of the first image 116 and the features of the second image are based on the same image data, but the features have been generated by using different algorithms. In particular, the features included by the multidimensional vector were determined by the face recognition algorithm described above. The multidimensional vector was determined from the first image, which is also stored in the TEE. Additionally or alternatively, the first image 116 and the second image may be compared, for example pixel by pixel, with a similarity measure. If the first image and the second image are identical, the multidimensional vector is verified.
[0087] If the multi-dimensional vector is verified, the verified multi-dimensional vector is compared to a multi-dimensional vector of the user's face stored in the trusted execution environment 124. If not, the procedure may be interrupted and / or resumed. If the multi-dimensional vector and the stored multi-dimensional vector of the user's face are identical, the user is authenticated. The multi-dimensional vector of the user's face may be stored in at least one memory of the TEE 124. As outlined above, an embedding describes a mathematical representation of facial features that can be compared to each other, for example by using a scalar product.
[0088] If the multi-dimensional vector is verified, the verified multi-dimensional vector is compared to a multi-dimensional vector of the user's face stored in the trusted execution environment. If not, the procedure may be interrupted and / or resumed. If the multi-dimensional vector and the stored multi-dimensional vector of the user's face are identical, the user is authenticated. The multi-dimensional vector of the user's face may be stored in at least one memory of the TEE. As outlined above, an embedding describes a mathematical representation of facial features that can be compared to each other, for example by using a scalar product.
[0089] 1, following the execution of the authentication method, an authentication step may be performed. The trusted execution environment 124 may output a signal for authenticating a process step (indicated by reference numeral 138). The process step may include one or more of making a payment, signing a document, accessing the mobile device 110, and enabling an application such as BiometricPrompt and / or FIDO2 API (see source.android.com / security / biometric / measure).
[0090] Performing image analysis in the non-secure normal execution environment 120 can leverage the full computational power and memory capacity of the normal execution environment 120. Proving the results of the image analysis obtained in the normal execution environment 120 by comparing it with the first image 116 stored in the trusted execution environment 124 allows for enhanced authentication of the user. [Explanation of symbols]
[0091] 110 Mobile Devices 112 Camera 114 Imaging 116 1st image 118 First image provided 120 Normal execution environment 122 processors 124 Trusted Execution Environment 126 Analysis of the first image 128 Step d) 130 Multidimensional Vectors 132 Decoder 134 Normal Pass 136 Secure Pass 138 Output of a signal to authenticate a process step
Claims
1. A method for user authentication of a mobile device (110), comprising the following steps: a) imaging at least one first image (116) of a face by using at least one camera (112) of the mobile device (110) (114); b) providing the first image (116) to the normal execution environment (120) of the processor (122) of the mobile device (110), and providing the first image (116) to the trusted execution environment (124) of the processor (122); c) analyzing the first image (116) by using at least one trained model in the normal execution environment (120), thereby determining a multi-dimensional vector including image information; d) a face authentication step, comprising the following steps: di) providing the multi-dimensional vector to the trusted execution environment (124) (130); dii) determining a second image from the multi-dimensional vector in the trusted execution environment (124) by using at least one decoder (132); diii) comparing the first image (116) with the second image, and when the first image and the second image are the same, verifying the multi-dimensional vector; div) when the multi-dimensional vector is verified, comparing the verified multi-dimensional vector with the multi-dimensional vector of the user's face stored in the trusted execution environment (124), and when the multi-dimensional vector and the multi-dimensional vector of the stored user's face are the same, authenticating the user; including the face authentication step; including the method.
2. The method according to claim 1, wherein the trusted execution environment (124) is an execution environment separated from the normal execution environment (120).
3. The method according to claim 2, wherein the reliable execution environment (124) is separated from the normal execution environment (120) by one or more of physical separation, hardware logic-based separation, or cryptographic separation methods.
4. The method according to claim 1 or 2, wherein the reliable execution environment (124) comprises at least one security function and meets at least one security requirement.
5. The method according to claim 1 or 2, wherein the first image (116) is provided to the normal execution environment (120) via a normal path (134), and the normal path (134) is configured to permit software access within the normal execution environment (120) and / or the reliable execution environment (124).
6. The method according to claim 1 or 2, wherein the first image (116) is provided to the reliable execution environment (124) via a secure path (136), and the secure path (136) is configured to prevent the first image (116) from being derived and / or modified by any software within the normal execution environment (120).
7. The method according to claim 1 or 2, wherein determining the second image includes a decoder (132) that reconstructs an image of the user's face from the multi-dimensional vector.
8. The method according to claim 1 or 2, wherein the trained model includes at least one face recognition model.
9. The method according to claim 1 or 2, wherein the trained model includes at least one convolutional neural network.
10. The method according to claim 9, wherein the analysis (126) in step c) includes one or more of filtering and convolution of the first image (116).
11. A method for authenticating a user, the method including implementing a method for authenticating a user of the mobile device (110) according to claim 1, the method further including outputting a signal for a trusted execution environment (124) to permit a process step, the process step including one or more of payment, signing a document, accessing the mobile device (110), and activating an application.
12. A computer program for authenticating a user of a mobile device (110), configured to cause a computer or computer network to fully or partially implement the method for authenticating a user according to claim 1 or 2 of the authentication method when executed on the computer or computer network, the computer program being configured to implement and / or execute at least steps a) to d) of the user authentication method according to claim 1 or 2 of the authentication method.
13. A computer program for authenticating a user of a mobile device (110), configured to cause a computer or computer network to fully or partially execute the method for authenticating a user according to claim 11 when executed on the computer or computer network.
14. A computer-readable storage medium including instructions that, when executed by a computer or computer network, cause the computer or computer network to execute at least steps a) to d) of the method according to claim 1 that refer to a method related to authentication and / or execute the method for authenticating a user according to claim 11.
15. A mobile device (110) including at least one camera (112) and at least one processor (122), the mobile device (110) being configured to execute at least steps a) to d) of the method according to claim 1 that refer to an authentication method and / or implement the authentication method according to claim 11.
16. Use of the mobile device (110) according to claim 15 for one or more of payment and signing of a document.