Hardware wallet for cold storage of private keys including enhanced user interface
By introducing a rack with a touch screen and an optimized RF antenna structure into the hardware wallet, the shortcomings of the hardware wallet in ergonomics and Bluetooth communication performance are solved, and higher operational convenience and stability are achieved.
Patent Information
- Application Number
- CN202380071537.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-09-16
- Filing Date
- 2023-09-11
- Publication Date
- 2025-05-27
AI Technical Summary
Existing hardware wallets have shortcomings in ergonomics, especially in terms of convenience of transaction operations and multi-device management, and their Bluetooth communication performance is poor.
A portable hardware wallet is designed, using a rack with a touch screen, and the touch screen is controlled by a security element, providing a large area of touch screen and non-touch display area to enhance the comfort of the user interface. At the same time, a combination of closed gap antenna and open gap parasitic antenna is adopted to optimize the RF antenna structure and improve the stability of Bluetooth communication.
Through enhanced touch screen human-computer interaction, the operation convenience and user experience of the hardware wallet have been significantly improved. At the same time, the optimized RF antenna structure ensures stable Bluetooth communication performance under different usage conditions.
Smart Images

Figure CN120051776A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a hardware wallet for cold storage of private keys from a blockchain. The present invention also relates to the ergonomics of portable electronic devices, and more specifically to the ergonomics of a hardware wallet for cold storage of private keys. Background Art
[0002] In recent years, the development of cryptocurrency or other types of crypto assets managed by blockchain, such as non-fungible tokens (NFTs) and smart contracts, has given rise to various ways of storing and holding private keys attached to these different types of crypto assets. Concepts such as "wallets", "cold storage", and "hot storage" of private keys have emerged in this way. A "wallet" is a device or program whose function is to manage crypto assets and thus store the private keys attached to them. The so-called "hot wallets" are connected to the Internet and exposed to hacking attacks or viruses and malware. These hot wallets can be wallets managed by centralized exchanges, which do not offer the highest level of security. Thus, over the years, many centralized platforms have been plundered by hackers for hundreds of millions of dollars. "Hot" wallets can also take the form of programs installed on mobile phones, tablets, or personal computers ("software wallets"). Such wallets are permanently connected to the Internet and are thus themselves vulnerable to attack.
[0003] Cold wallets are the safest solution for cold storage of private keys, i.e., avoiding direct access to the Internet, which reduces the risk of attack and thus the risk of being stolen by hackers. Signing transactions involving private keys takes place in an offline environment. Any transaction initiated online is temporarily transferred to an offline hardware wallet and then digitally signed at the offline hardware wallet before being sent to the online network. Since the private key is not transferred to an online server during the signing process, hackers cannot access it.
[0004] The simplest form of cold storage is a paper wallet. A paper wallet is a document on which the user's public key and private key are written. The document usually has a combined QR code that can be scanned to sign transactions. The disadvantage of this medium is that if the paper wallet is lost, illegible, or damaged, the user can no longer access their funds.
[0005] Hardware wallets are a convenient alternative to paper wallets for storing private keys. Additionally, hardware wallets are typically configured to generate a recovery phrase to recover the private key in case they are lost. Note that the crypto assets are never stored in the hardware wallet but are recorded on the blockchain. The hardware wallet only stores the private key to manage transactions on the blockchain. The public key corresponding to the private key points to the address where the asset on the blockchain is effectively located.
[0006] As Figure 1As shown, the hardware wallet HW is never directly connected to the Internet. To be operational, the hardware wallet HW must be connected to a host device HDV via a data link LNK (e.g., USB or Bluetooth). The host device HDV can be a computer, a mobile phone, or a tablet, and runs so-called "companion" software for conducting transactions on the blockchain BCN, such as the "Ledger live" software developed by the applicant. Alternatively, the hardware wallet HW can be used with a decentralized exchange or DEX via the HDV host device, where the user can conduct transactions while keeping their keys.
[0007] The hardware wallets HW sold by the applicant are commercially successful because they provide a high level of security by using a "secure element" to store private keys and sign transactions. A secure element is a hardware platform that can store and manipulate data in accordance with security rules and requirements set by a trusted authority. It comes in the form of a semiconductor chip that implements various countermeasures against attacker attacks.
[0008] Figure 2 The architecture of a hardware wallet HW1 sold by the applicant under the name "Nano S" is shown. The hardware wallet HW1 has a secure element SE1 paired with a microcontroller MCU1. The processor MCU1 has a USB interface U1 and acts as a proxy device for the secure element SE1 for communicating with an external host device HDV running a companion application (see Figure 1 ). The secure element SE1 has its own secure operating system OS (firmware) that allows it to run applications APP, and incorporates a cryptographic coprocessor CRY. The hardware wallet HW1 also has a display DISP1 and two buttons B1, B2.
[0009] The display DISP1 and the buttons B1, B2 are managed by the microcontroller MCU1. These two buttons play an important role in ensuring the security of certain operations: the user must press both buttons simultaneously to prove that they consent or authorize the execution or completion of an operation.
[0010] Figure 3 The architecture of a second hardware wallet HW2 sold by the applicant under the name "Nano X" is shown, which is described in more detail in the "Ledger Nano X Security Target" security information notice published on the website of the French National Agency for Information System Security (ANSSI).
[0011] (https: / / www.ssi.gouv.fr / uploads / 2019 / 10 / anssi-cible-cspn-2019_12en.pdf)
[0012] The hardware wallet HW2 (such as wallet HW1) includes a secure element SE2, a microcontroller MCU2 with a USB interface U1, a display DISP2, and two buttons B1 and B2. It also has a battery BAT that can be charged via the USB interface and a Bluetooth communication interface BT1 managed by the microcontroller.
[0013] As previously mentioned, when performing certain sensitive operations, the user must press both buttons simultaneously to express their consent or approval, as described in the aforementioned document "Ledger Nano X Security Target", paragraph 1.2 "Terms", line "Approval". The security concept of the Ledger Nano X is strengthened by the end user. Once a sensitive operation is required, the end user must use these two buttons to confirm the operation.
[0014] Different from the hardware wallet HW1, the display DISP2 and the buttons B1 and B2 of the hardware wallet HW2 are directly managed by the secure element SE2, which provides an additional level of security in the event of damage to the microcontroller MCU2. Therefore, the signal indicating that the user is pressing both buttons B1 and B2 simultaneously received by the secure element SE2 cannot be tampered with by the microcontroller. Similarly, the information presented to the user by the screen DISP2, such as the number of transactions that must be verified by the user, cannot be forged.
[0015] Generally speaking, in a hardware wallet for cold storage of private keys within the meaning of the present application, the microcontroller associated with the secure element does not execute any application programs and has the sole function of managing communication devices, USB, Bluetooth, etc., as well as other peripheral devices (battery, battery charger, etc.). All application programs are run by the secure element.
[0016] In addition, there is a device DV1 whose general architecture is shown in Figure 4 which includes a microcontroller SMCU with a trust zone TZ. The trust zone TZ can be associated with a secure element SE that delegates the most sensitive operations or cryptographic calculations in some cases. The specific implementation of this trust zone TZ is generally based on the use of two virtual processors combined with hardware access control. This allows the core of the application to switch between two states called "worlds" in order to prevent information from leaking from the most trusted world to the least trusted world. When using the same core, each world can operate independently of each other. Then, the memory and devices are informed of the operating world of the kernel and can use it to provide access control to the secrets and code of the device. Generally, the microcontroller SMCU runs a so-called "rich" operating system ROS in the least secure world and a smaller security-specific code in the most secure world to reduce exposure to attacks. The rich operating system is usually Android.
[0017] This type of device does not need to be attached to a host device to perform operations on the blockchain and typically includes a Wi-Fi communication interface WF1 in addition to the USB U1 and Bluetooth BT1 communication interfaces. Due to the rich operating system of this device, it offers a wide range of features and very advanced ergonomics, including large touchscreens like those found in smartphones. In some cases, the device DV1 can be equipped with mobile phone circuitry and form a full-fledged mobile phone with private key storage features.
[0018] In practice, although this device DV1 offers undeniable ergonomic advantages, it is not immune to attacks and does not meet the same strict security requirements as a hardware wallet used for cold storage of private keys, which has no internet connection and whose microcontroller never executes applications.
[0019] On the other hand, a hardware wallet for cold storage of private keys only offers poor ergonomics, which makes some transactions difficult due to the small display and the requirement to provide two buttons to verify certain sensitive operations.
[0020] Therefore, it may be necessary to improve the ergonomics of hardware wallets without changing the high level of security they provide.
[0021] In addition, some cryptocurrency holders use multiple hardware wallets to store different types or values of cryptocurrency assets. For example, a user can use a first hardware wallet dedicated to managing cryptocurrency accounts with low monetary value to perform daily transactions or payments for purchases, a second hardware wallet dedicated to managing cryptocurrency accounts with high monetary value, and a third hardware wallet dedicated to managing cryptocurrency assets such as non-fungible tokens. Therefore, for users who use several such wallets, it may also be desirable to improve the ergonomics of the hardware wallets.
[0022] More generally, it may be desirable to provide improvements applicable to portable electronic devices and specifically to hardware wallets for storing private keys that improve their ergonomics, or provide new features, or improve their performance in terms of Bluetooth communication when equipped with Bluetooth communication means. Summary of the Invention
[0023] An embodiment relates to a portable device that forms a hardware wallet for cold storage of cryptographic keys from a blockchain. The portable device includes a housing having a front panel and a rear panel, in which a microcontroller and a security element are arranged. The security element is connected to the microcontroller via a first data link. The microcontroller is configured to ensure data exchange between the security element and an external host device, but the device does not have the possibility of a direct connection to the Internet. The device includes a touch screen having a diagonal of 3.5 inches or greater, with at least 600 x 400 pixels, specifically controlled by the security element and covering most of the front of the housing. And wherein the security element is connected to the touch screen via at least one second data link to transmit graphic data to the touch screen and receive touch data from the touch screen, and the security element includes an operating system integrated with a graphics engine to generate and display text and images.
[0024] According to one embodiment, the security element is configured to detect two simultaneous touches on two separate areas of the touch screen before performing or completing at least one security operation that requires user consent.
[0025] According to one embodiment, the housing has a first side wall with rounded edges, and the touch screen has a non-touch display area that covers most of the rounded edges for displaying graphic data on the edges of the housing without touch feedback.
[0026] According to one embodiment, the device includes a second side wall that includes a longitudinal port forming a closed slot antenna, and the device includes means for applying a ground voltage to a first surface of the longitudinal slot and a radio frequency signal to a second surface of the longitudinal slot.
[0027] According to one embodiment, the security element is connected to the touch screen via a second serial data link for transmitting graphic data to the touch screen and via a third serial data link for receiving touch data from the touch screen, one of the data links being an SPI bus and the other being an I2C bus.
[0028] According to one embodiment, the touch screen includes an e-ink display covered by a touch module, and a protective layer covers the touch screen to allow the device to be stacked with similar devices without damaging the touch screen.
[0029] According to one embodiment, the housing is made of a non-magnetic material and includes at least four magnets for magnetically stacking the device with similar devices, and the magnets are arranged asymmetrically with respect to the longitudinal central axis of the housing and / or with respect to the transverse central axis of the housing to form a magnetic key.
[0030] According to one embodiment, the device includes a wireless communication device, and the device is configured to establish wireless communication with a similar device present in the stack when stacked with at least one similar device and positioned at the top of the stack, receive information provided by the similar device, and display the information on a touch screen.
[0031] According to one embodiment, the device is configured to receive commands provided by a user via the touch screen and send the commands to a similar device.
[0032] According to one embodiment, the device includes at least one sensor for detecting the presence of a similar device on the front or rear side thereof.
[0033] According to one embodiment, the device is configured to switch to a stacking operation mode automatically or in response to a user action, wherein the device communicates with at least one similar device.
[0034] According to one embodiment, the device is configured to transmit or receive data in a given frequency band and includes a radio frequency antenna for this purpose, the radio frequency antenna including a combination of a closed slot antenna and an open slot parasitic antenna, both antennas being configured such that: when the device is outdoors, the open slot parasitic antenna has a tuning frequency within the specified frequency band, while the closed slot antenna has a tuning frequency outside the specified frequency band, and when the device is stacked with a similar device, the closed slot antenna has a tuning frequency within the specified frequency band, while the open slot parasitic antenna has a tuning frequency outside the specified frequency band.
[0035] According to one embodiment, the closed slot antenna includes a through longitudinal port made in a side wall of the frame, the longitudinal port including two longitudinal surfaces facing each other, and means for applying a ground voltage to the first surface and a radio frequency signal to the second surface, and the open slot parasitic antenna includes a conductive arm parallel to the side wall of the frame and arranged near the longitudinal port, the conductive arm having a free end and an end electrically connected to the side wall.
[0036] According to one embodiment, the specified frequency band is a Bluetooth frequency band. Description of the Drawings
[0037] Exemplary embodiments of improvements to a portable device will be described below with reference to the drawings in a non - limiting manner, including:
[0038] Figure 1 A conventional example of using a hardware wallet by a host device is shown,
[0039] Figure 2 A conventional hardware wallet architecture is shown,
[0040] Figure 3 shows another conventional hardware wallet architecture
[0041] Figure 4 shows a conventional electronic device architecture that provides medium-level security
[0042] Figure 5 shows an advanced hardware wallet architecture
[0043] Figure 6 shows Figure 5 the organization of a part of the non-volatile memory in a hardware wallet
[0044] Figure 7 shows Figure 5 a usage example of a hardware wallet
[0045] Figure 8 is a flowchart describing the process of protecting certain operations when using Figure 5 a hardware wallet
[0046] Figure 9 shows Figure 5 an implementation of a hardware wallet
[0047] Figure 10 describes the steps for testing Figure 9 the components shown in
[0048] Figure 11 is Figure 5 a top view and a perspective view of an implementation of a hardware wallet
[0049] Figure 12 is Figure 11 a bottom view and a perspective view of a hardware wallet
[0050] Figure 13 is Figure 11 a cross-sectional view of a hardware wallet, showing some of the building blocks
[0051] Figure 14 is Figure 11 another cross-sectional view of a hardware wallet, showing other building blocks
[0052] Figure 15 is Figure 11 a top view of a hardware wallet display
[0053] Figure 16 is Figure 11 a top view of a touch module of a hardware wallet
[0054] Figure 17 is Figure 11Top view of the protective layer of a hardware wallet,
[0055] Figure 18 showing the cover for Figure 11 the hardware wallet,
[0056] Figure 19 Cross-sectional view of a magnetically stackable hardware wallet including a magnet,
[0057] Figure 20 is Figure 19 bottom view of the hardware wallet,
[0058] Figure 21 is the exploded view of the hardware wallet as seen from below, Figure 19 for
[0059] Figure 22 is an abstract representation of the magnet arrangement in the housing of a portable electronic device,
[0060] Figure 23 showing the dimensions of the magnet,
[0061] Figure 24 Cross-sectional view of the magnetic stack of the hardware wallet,
[0062] Figure 25 Cross-sectional view of a variant of the magnetically stackable hardware wallet,
[0063] Figure 26 Cross-sectional view of another variant of the magnetically stackable hardware wallet,
[0064] Figure 27 showing the magnetic stack of the hardware wallet,
[0065] Figure 28 showing an example of a menu displayed by a hardware wallet stacked with other hardware wallets,
[0066] Figure 29 describing operations performed by a hardware wallet stacked with other hardware wallets,
[0067] Figure 30 Cross-sectional view of a stack of hardware wallets equipped with sensors,
[0068] Figure 31 describing a method for automatically managing a stack of hardware wallets,
[0069] Figure 32 showing another example of a menu on the screen of a hardware wallet stacked with other hardware wallets,
[0070] Figure 33 describing the process for manually managing a stack of hardware wallets,
[0071] Figure 34 is an exploded view of a hardware wallet including an antenna,
[0072] Figure 35 is Figure 34 the front view of the hardware wallet and shows the antenna element,
[0073] Figure 36 is the top view of another antenna element,
[0074] Figure 37 is the bottom view of another antenna element,
[0075] Figure 38 is Figure 34 the cross-sectional view of the hardware wallet,
[0076] Figure 39 is Figure 34 the cross-sectional view and perspective view of the hardware wallet,
[0077] Figure 40 is Figure 36 、 Figure 37 the electrical diagram of the antenna element,
[0078] Figure 41 is Figure 34 the equivalent diagram of a part of the hardware wallet antenna,
[0079] Figure 42 and Figure 43 is Figure 34 the bottom view and perspective view of the hardware wallet,
[0080] Figure 44 shows Figure 42 、 Figure 43 the antenna elements existing in,
[0081] Figure 45 is existing in Figure 34 the equivalent diagram of the antenna in the hardware wallet,
[0082] Figure 46 、 Figure 47 shows Figure 45 the characteristics of the antenna in two different applications,
[0083] Figure 48 shows the stacking of two hardware wallets,
[0084] Figure 49A 、 Figure 49B 、 Figure 50A and Figure 50B shows Figure 45 the other characteristics of the antenna in two different applications. Detailed implementation manners
[0085] Improvements to hardware wallets for cold storage of private keys are described below. Some improvements can be implemented in all types of portable electronic devices and thus have an application scope far beyond the single manufacture of hardware wallets.
[0086] Example of a hardware wallet with a touch screen controlled by a security element
[0087] As described above, a secure element is a hardware platform that implements various countermeasures to prevent attackers from launching attacks.
[0088] Schematically, attacks can include:
[0089] - Inspection and / or reverse engineering attacks (grinding, layer removal, thermal imaging, X-ray, scanning electron microscopy),
[0090] - Side-channel attacks (analysis of power consumption, electromagnetic radiation, computation time, or any other measurable physical quantity related to the secret value the attacker is trying to discover), or
[0091] - Fault injection attacks using lasers or test spikes (e.g., injecting parasitic or "false" signals on power lines, clock lines, or data buses).
[0092] There are many countermeasures provided in secure elements. Some are software, while others are hardware (devices for preventing attacks, protecting volatile and non-volatile memories, masking power consumption, data desensitization, devices for masking the topology of integrated circuits, voltage sensors, frequency sensors, light sensors, temperature sensors, allowing detection of attacks, etc.). In the event of an attack, the operating system of the secure element is designed to initiate defensive actions such as interrupting ongoing computations, permanently blocking the circuit, or self-destructing by completely erasing its memory.
[0093] Due to the many countermeasures they implement, the manufacture of secure elements is complex and expensive. Therefore, the functions they provide are limited, especially when it comes to the number of input / output parts they provide. Thus, secure elements are generally not used to control screens, and when they do control a screen as in the product "NanoX" sold by the applicant, they will control a small screen without any touch-sensitive functions.
[0094] Therefore, considering commercially available secure elements, and especially those that provide a security level of at least equal to 5 (which corresponds to level E4 of the European Information Technology Security Evaluation Criteria (ITSEC) and level B2 of the United States Trusted Computer System Evaluation Criteria (TCSEC)), so far, the applicant is not aware of any secure element with more than 10 input / output parts. In fact, the higher the number of IOs, the greater the attack exposure of the secure element.
[0095] It should be noted here that "IO" refers to a 1-bit digital port that can be used to send or receive logic signals, and the number of such IOs is less than the number of electrical pins of the security element, which in addition to the IO pins also includes power pins, ground pins, and possibly reset pins, etc.
[0096] However, in this improved scenario, it has been found that the security element can be utilized to manage the touchscreen. In fact, a security element with 10 IOs can handle the following serial links:
[0097] 1) The ISO / IEC 7816 link, which has only three logic signals: CLK (clock), I / O (data), and RST (reset);
[0098] 2) The SPI (Serial Peripheral Interface) bus that uses only 4 signals:
[0099] - SCLK (Serial Clock) (generated by the master device),
[0100] - MOSI (Master Output, Slave Input),
[0101] - MISO (Master Input, Slave Output), and
[0102] - SS (Slave Select);
[0103] 3) The I2C bus (Inter-Integrated Circuit bus) that has only two signals:
[0104] - SDA (Serial Data Line): a bidirectional data line,
[0105] - SCL (Serial Clock Line): a bidirectional synchronous clock line,
[0106] That is, a total of 9 IOs are required.
[0107] It has also been found that the SPI bus or the I2C bus can be used to control specific types of displays and specific types of touch modules. The security element and the microcontroller can also be connected via the ISO / IEC 7816 smart card link or SPI, I2C, USB links, etc.
[0108] Finally, managing the touchscreen requires handling the interrupt signal sent by the touchscreen whenever a touch event is detected. This interrupt signal activates the touch event handling routine. Therefore, the reception of such a signal requires engaging another I / O of the security element, that is, a total of 10 IOs. Thus, in this improved scenario, it has been found that it is not impossible to use the security element to control the touchscreen.
[0109] Thus, according to the initial improvement, a hardware wallet is provided, which includes a touch screen specifically controlled by a secure element via one or more serial links. According to certain precautions to be elaborated below, such a touch screen can significantly improve the comfort of the user interface while meeting the security requirements applicable to hardware wallets. According to this improvement, the touch screen has a diagonal greater than or equal to 3 inches (i.e., 7.62 cm, one inch equals 2.54 cm), but preferably greater than or equal to 3.5 inches (i.e., 8.89 cm), and has at least 600×400 pixels. In one embodiment, the screen has a diagonal of 3.9 inches (9.906 cm) and has 670×496 pixels.
[0110] Specific implementation example of hardware wallet hardware
[0111] Figure 5 The general architecture of the hardware wallet HW3 according to this improvement is shown. The device HW3 includes a secure element SE3, a microcontroller MCU3, and a touch screen TS. The touch screen TS includes an E-Ink display EID and a touch module TM. The touch screen TS is under the specific control of the secure element SE3. For this purpose, the I / O resources of the secure element SE3 are divided into three I / O groups: IOGA, IOGB, IOGC. The I / O group IOGA is assigned to implement a bus BS1, which connects the secure element SE3 to the microcontroller MCU3. The I / O group IOGB is assigned to implement a bus BS2, which connects the secure element SE3 to the display EID, and the I / O group IOGC is assigned to implement a bus BS3, which connects the secure element SE3 to the touch module TM. The bus BS1 is, for example, an IEC / ISO 7816 bus, the bus BS2 is, for example, an SPI bus, and the bus BS3 is an I2C bus. The opposite arrangement can be provided, where BS2 is an I2C bus and BS3 is an SPI bus, or another serial link protocol compatible with the resources of the secure element. The SPI bus is managed on the display EID side by a chip integrated into the display EID (such as UC8177). The I2C bus is managed on the touch module TM side by a chip integrated into it (for example, GT1151QM chip). The secure element is, for example, an ST33K1M series chip, and the microcontroller is an STM32 series chip.
[0112] The device HW3 also includes various peripheral devices controlled by the microcontroller MCU3, such as:
[0113] - a battery BAT;
[0114] - A power management IC, PMIC, such as the NXP PCA9420 chip. The circuit PMIC receives the voltage Vat from the battery when the battery is being charged, supplies the voltage Vat to the battery when the battery needs to be charged, and provides a regulated supply voltage Vdc to the microcontroller MCU3, the security element SE3, and the touch screen TS;
[0115] - An antenna QiA for inductive battery charging according to the Qi technology (https: / / www.wirelesspowerconsortium.com / qi / ). The antenna QiA is connected to a wireless charging integrated circuit (WCIC), such as the 103AHQI01 chip. The circuit WCIC provides a voltage Vqi to the circuit PMIC for battery charging;
[0116] - A USB port U1. The USB port provides a voltage Vusb to the circuit PMIC for battery charging, provides data DTu received from an external device connected to the USB port to the microcontroller MCU3, and sends the data DTu to an external device;
[0117] - A Bluetooth antenna BTA that receives a radio frequency signal RFS provided by the circuit BTM for managing Bluetooth communication. Although shown as a block separate from the microcontroller MCU3, the circuit BTM may be included in the microcontroller MCU3. The circuit BTM provides data DTb exchanged with an external device via a Bluetooth link, or sends the data DTb to an external device via a Bluetooth link.
[0118] Therefore, the device HW3 has the advantage of having a touch screen specifically controlled by the security element SE3, so it will not be damaged even in the case of an attack on the microcontroller MCU3. The latter does not run any applications and does not store any cryptographic secrets used by the security element. It only manages peripheral devices and acts as a proxy processor relative to the security element, sending the data DTb, DTu received from the communication interfaces selected by the user to the security element, or sending the data DTb, DTu provided by the security element to an external device. Therefore, the device HW3 does not provide any possibility of direct connection to the Internet, and despite its touch screen, it still retains a hardware wallet for cold storage of private keys, thus providing a high level of security.
[0119] The security element SE3 also includes a memory space MEM, which includes a read-only memory area (ROM memory), a programmable and electrically erasable non-volatile memory area (flash memory), and a volatile memory area (RAM). The programmable and electrically erasable non-volatile memory area receives an operating system OS3 from the security element. The OS is configured to allow the use of the touch screen TS by an application.
[0120] Specific implementation example of hardware wallet software
[0121] In combination with the example of the hardware architecture just described, Figure 6 An example of the organization of the programmable and electrically erasable non-volatile memory region of the memory space MEM is schematically shown. The memory space MEM includes a region APP for storing application programs APP1, APP2... APPn and a region for receiving the operating system OS3. The operating system OS3 includes a privileged application memory region PAP for storing the dashboard DB for privileged applications and an operating system module memory region OSMD for storing operating system modules. The memory region OSMD includes:
[0122] - A user interface management module USINT,
[0123] - A device customization module PERS,
[0124] - A cryptographic module CRY, which is combined with a cryptographic coprocessor integrated into a security element or a hardware accelerator for advanced cryptographic functions,
[0125] - An authentication and application attestation module EAA,
[0126] - An IO management module IOM, which is used to manage communication interfaces.
[0127] According to this improvement, the memory region OSMD further includes a graphics engine GENG configured to manage an electronic ink display EID. The GENG graphics engine includes:
[0128] - A pre-configured page PG,
[0129] - A pre-configured layout LY,
[0130] - A pre-configured object OB, and
[0131] - The basic form of BF.
[0132] Therefore, the access of application programs to the EID viewer is under the control of the OS3 operating system of the security element, and the OS3 operating system first verifies the authenticity and legality of the programs before making the graphics engine available to them.
[0133] According to this improvement, the memory region OSMD further includes a touch management engine TME, which provides the possibility for authorized application programs to access and interpret the information sent by the touch module TM.
[0134] The graphics engine GENG also includes an event management engine EVENG that receives touch information provided by the touch engine TME and searches for relevance to the display area to distinguish between non-valid and valid taps by the user on the screen.
[0135] In an embodiment where limited resources of the secure element are reserved according to the random access memory (RAM), the graphics engine GENG operates without RAM allocation. Image pixels are transferred to the RAM in the display without reloading them. In another embodiment that can be combined with the previous one, the graphics engine GENG does not process pre-configured pages PG, pre-configured layouts LY, and pre-configured objects OB. Thus, the "work" implemented by the operating system is minimized and limited to a basic form BF as it does not need to dynamically create objects. The processing of complex shapes is left to the application, the code of which is designed with pre-configured graphical elements that minimize the operations that the graphics engine must perform.
[0136] Figure 7 An example of the use of the hardware wallet HW3 is shown. Since the wallet cannot be directly connected to the Internet, a connection is established to a host device HDV that is connected to the Internet ("WB") and runs an accompanying application CA such as the "Ledger Live" application (https: / / www.ledger.com / fr / ledger-live). Then, the device HW3 can interact with the accompanying software to conduct transactions on the blockchain BCN or a decentralized exchange DEX.
[0137] The hardware wallet HW3 is also managed by a transaction black box (i.e., a hardware security module HSM) located in a data center to which the hardware wallet HW3 is connected via a secure HTTPS link. The transaction black box does not store any private keys and only ensures the verification of the authenticity of the device, its debugging, the update of its operating system, the download of authenticated applications, etc.
[0138] Implementation scheme including verification of sensitive transactions through two virtual buttons
[0139] Although the secure use of the touch screen specifically controlled by the secure element provides certain ergonomic advantages, giving up the simultaneous pressing of two conventional buttons that ensure certain sensitive operations may prove harmful to the security of the device.
[0140] Therefore, in one embodiment, the operating system is configured to simulate two hardware buttons of the prior art through the touch screen. Figure 8 As an example, the execution of a sensitive operation that must ensure user approval is illustrated:
[0141] - At step S1, the device HW3 connects to the companion application CA or the HSM module according to the type of operation to be performed, such as executing a transaction or displaying a recovery phrase, activating and configuring the device through the companion application CA, or downloading an application through the HSM, etc.
[0142] - At step S2, the device HW3 initiates the execution of a sensitive operation.
[0143] - At step S3, the device HW3 displays on the display EID a request for the user to confirm that the sensitive operation can be performed and waits for confirmation.
[0144] The confirmation waiting includes step S31, where the device HW3 displays at least two virtual buttons preferably far apart on the display EID. These buttons can have any graphics or fancy graphics selected by the designer. This step is followed by a waiting phase S32, where the device HW3 cyclically reads the information provided by the touch module TM within time T. Before time T expires, if the device HW3 detects at step S33 two simultaneous presses by the user on the two buttons, then the device then executes (or completes) the operation at step S4. When time T expires, if the device HW3 finds at step S34 that the user has not submitted the operation, the device cancels the operation at step S5.
[0145] Exemplary implementation scheme of a hardware wallet with certain types of peripheral components with specific constraints
[0146] As mentioned above, commercially available certified security elements only provide a small number of input / output parts, usually at most 10 input / output parts. In fact, security elements are usually designed to be included in smart cards or objects connected to the Internet to protect the Internet of Things, especially in the field of professional applications. A security element with only 10 input / output parts is therefore not designed to drive a large touch screen (other electrical pins in the security element such as power pins or ground pins are not considered input / output parts as described above).
[0147] Therefore, in the above, the following use of the resources of the security element has been proposed as an example:
[0148] - Two input / output parts (SDA, SCL signals) for managing the I2C bus connected to the touch module TM.
[0149] - Four input / output parts (SCLK, MOSI, MISO, SS) for managing the SPI bus of the display EID.
[0150] - Three input / output parts (I / O, CLK, and RST) for managing the ISO / IEC 7816 bus between the security element and the microcontroller.
[0151] In addition to these nine input / output parts, another input / output part of the security element is reserved for receiving an interrupt signal sent by the touch module TM upon detection of a touch event, in order to place the security element in a touch event handling routine. Under these conditions, all ten input / output parts of the security element are used.
[0152] However, in some embodiments, the display EID may include a configuration component that needs to be set and can only be accessed via a dedicated serial link to the component. As Figure 9 shown, the display EID may include, for example, a display module EID0 and a configuration component WM of the display module EID0. The configuration component WM is, for example, a programmable and electrically erasable non-volatile memory that receives a waveform library and is connected to the display module EID0 through an internal circuit. The configuration component WM has its own input / output part compatible with the SPI bus.
[0153] Since the security element SE3 accesses the configuration device WM to program or delete data therein, the bus BS2 is used to control both the display module EID0 and the configuration component WM. In particular, the wires of the bus BS2 that transmit the SCLK, MOSI, and MISO signals are connected to the input / output parts of both the display module IED0 and the configuration component WM. The SS signal of the bus BS2 is only applied to the chip select input part CSEL1 of the display module EID0, and this SS signal applies a selection signal SEL1 to the chip select input part CSEL1.
[0154] Generally speaking, Figure 9 the I / O allocation of the security element SE3 shown in
[0155] 1) Bus BS1 (ISO / IEC 7816), IOGA I / O group:
[0156] - The input / output part IO1 of the security element SE3 is used to manage the signal RST and is connected to the input / output part IOM1 of the microcontroller MCU3,
[0157] - The input / output part IO2 of the security element SE3 is used to manage the signal CLK and is connected to the input / output part IOM2 of the microcontroller MCU3,
[0158] - The input / output part IO3 of the security element SE3 is used to manage the signal RST and is connected to the input / output part IOM3 of the microcontroller MCU3,
[0159] 2) Bus BS2 (SPI), IOGB I / O group:
[0160] - The input / output unit IO4 of the security element SE3 is used to manage the MISO signal and is connected to both the input / output unit of the display module EID0 and the input / output unit of the configuration component WM of the display module EID0.
[0161] - The input / output unit IO5 of the security element SE3 is used to manage the MOSI signal and is connected to both the input / output unit of the display module EID0 and the input / output unit of the configuration component WM of the display module EID0.
[0162] - The input / output unit IO6 of the security element SE3 is used to manage the SCLK signal and is connected to both the input / output unit of the display module EID0 and the input / output unit of the configuration component WM of the display module EID0, and
[0163] - The input / output unit IO7 of the security element SE3 is used to manage the signal SEL1 and is only connected to the input unit CSEL1 of the display module EID0. The input / output unit IO7 provides the selection signal SEL1 to this input unit CSEL1.
[0164] 3) Bus BS3 (I2C), IOGC I / O group:
[0165] - The input / output unit IO8 of the security element SE3 is used to manage the SCL signal and is connected to the input / output unit of the touch module TM, and
[0166] - The input / output unit IO9 of the security element SE3 is used to manage the SDA signal and is connected to the input / output unit of the touch module TM.
[0167] 4) Finally, the last input / output unit IO10 of the security element SE3 is used to receive the interrupt signal sent by the touch module TM, which is represented here by the reference ITR.
[0168] Since both the configuration component WM and the display module EID0 are connected to the same bus BS2, one is active while the other is disabled, and vice versa, otherwise the security element cannot communicate with either of them. For this reason, the configuration component WM also includes a chip select input unit CSEL2 for the selection signal SEL2.
[0169] Therefore, in this case, it seems that the security element SE3 does not have enough input / output units to generate the selection signal SEL2 for the input unit CSEL2 of the configuration component WM.
[0170] In one embodiment, a method is implemented to still be able to control the touch screen via the secure element SE3. According to this method, the selection input unit CSEL2 is controlled by the input / output unit IOM4 of the microcontroller MCU3 that provides the selection signal SEL2. This is because, unlike the secure element, the microcontroller usually has available I / O. The binary value of the signal SEL2 provided by the input / output unit IOM4 of the microcontroller is controlled by the secure element SE3, and the secure element SE3 transmits a command to the microcontroller via the bus BS1 for this purpose. The microcontroller is configured to execute these commands "substantially". Preferably, in addition to the application required to execute the commands transmitted by the secure element, it does not have any application that can control the input / output unit IOM4.
[0171] An example of a method for controlling the input unit CSEL2 of the configuration component WM by the secure element SE3 via the microcontroller MCU3 is described Figure 10 in
[0172] At step S01, the secure element SE3 transmits a command to select the configuration component WM to the microcontroller MCU3. At step S02, the microcontroller executes the command and applies the selection signal SEL2 of the configuration component to the input unit CSEL2 via its input / output unit IOM4. The value of this signal can be 0 (ground voltage) or 1, depending on the specification provided by the manufacturer of the configuration component WM. At step S03, the microcontroller confirms to the secure element that the configuration component has been selected. At step S04, after the secure element SE3 has invalidated the input unit CSEL1 of the display module EID0 through the signal SEL1 previously, it establishes communication with the configuration component WM via the bus BS2. The secure element then performs a target operation on the configuration component, such as deleting and / or writing data if it is a non-volatile memory. Once the operation is completed, at step S05, the secure element transmits a command to deselect the configuration component WM to the microcontroller. At step S06, the microcontroller deselects the configuration component WM, and then at step S07, it confirms the deselection to the secure element. Then, after reselecting the display module EID0 via the input unit CSEL1 of the display module EIDO through the signal SEL1, the secure element can re-establish communication with the display module EID0 via the bus BS2.
[0173] Those skilled in the art will be clear that the method just described can have various alternatives, especially regarding the command execution confirmation (which can be optional) and the command transmission protocol between the secure element and the microcontroller.
[0174] Moreover, those skilled in the art will appreciate that the method can be applied to a variety of other peripheral components. In one embodiment, in addition to the display module EID0 and the configuration component WM, the bus BS2 is also connected to a third peripheral device. The security element selects / deselects the third device via another I / O of the microcontroller, and after deselecting the display module EID0 and the configuration component, communicates with the device via the data bus BS2.
[0175] Finally, those skilled in the art will appreciate that the method can have various applications and is not limited to the control of touchscreens. It can be any circuit configuration that combines a microcontroller and a security element, where the number of peripheral components controlled by the security element is greater than the number of peripheral components it can control when managing all the inputs or input / outputs (including their select inputs) of these peripheral components.
[0176] Exemplary embodiments of a hardware wallet with a large touchscreen and a rack-edge display
[0177] Figure 11 and Figure 12 show the rack 10 of the hardware wallet HW3 constructed according to the second improvement. In Figure 11 the rack of the device HW3 is seen from the front side FS of the device HW3 and in Figure 12 the rack of the device HW3 is seen from the rear side RS of the device HW3. The rack 10 is a one-piece rectangular part made of machined or die-cast aluminum. It includes a first longitudinal sidewall 101, a second longitudinal sidewall 102, a first transverse sidewall 103, a second transverse sidewall 104, and a plate 105 covering its entire front side FS. Inside the rack, the battery BAT has a printed circuit 11 that houses various components of the device HW3, and the architecture of the device HW3 has been described with respect to Figure 5 this.
[0178] Figure 13 and Figure 14 are cross-sections of the device HW3 with the rear side RS of the rack facing up. The device HW3 includes a touchscreen 20 (previously designated as TS) arranged on the front plate 105 of the rack. The touchscreen 20 is obtained by assembling an electronic ink display 21 ( Figure 15 ) previously designated as EID, which is covered by a touch module 22 ( Figure 16 ) previously designated as TM, and the touch module itself is covered by a protective layer 23 ( Figure 17 ).
[0179] Figure 15The display 21 is shown in more detail therein. It includes an active area or display area 211, a painted frame 212, and is fabricated on a flexible substrate 213 according to the COP (Chip on Plastic) technology. The display is, for example, an organic active matrix electrophoretic display that combines a source driver, a gate driver, and an IC controller directly bonded to the display substrate, such as UC8177 controller. The display provides 670×496 pixels with a pixel pitch of 119 microns and has 16 gray levels. Its size is, for example, 3.9 inches (9.906 cm), with a total length of 77.4 mm and a total width of 81.7 mm. The size of the active area is, for example, 79.73×59.03 mm. The flexible substrate 213 extends beyond the active area 211 and houses row and column multiplexers 214. It is extended by an SPI bus connector 215 made in a flexible printed circuit board, allowing the display 21 to be connected to the printed circuit board 11 in the rack. The connector includes an auxiliary component 216 and a non-volatile memory 217 that receives a waveform library, which, for example, corresponds to Figure 9 the configuration component WM mentioned in the implementation of device HW3 in
[0180] The touch module 22 is shown in detail in Figure 15 It has a cover area 220 and a painted frame 221, and is integrally fabricated on a flexible printed circuit (FPC) board 222. The cover area 220 includes a touch area 220a and a non-touch area 220b. The flexible board 222 has an extension 224 that houses a module control chip 225 (such as GT1151QM chip). The end of the extension 224 houses an I2C bus connector 226 to connect the touch module 22 to the PCB 11 present in the rack. The touch module has, for example, a total length of 65.7 mm and a total width of 81.3 mm. For example, the touch area 220a has a surface area of 79.73×48.10 mm, and the non-touch area 220b extends 34.0 mm beyond the touch area.
[0181] Figure 17 The protective layer 23 is shown in Figure 24 It has a transparent area 230 and a painted frame 231. For example, the layer has a total length of 67.9 mm and a total width of 83.7 mm. The layer includes a moisture-proof layer, an anti-reflection hard layer, and an optically transparent adhesive on its back surface to assemble it on the touch module 22. In one implementation, in the case of stacking device HW3 with other similar devices HW3-1, HW3-2 to be described later, the layer is designed to be scratch-resistant ( Figure 24 ).
[0182] In Figure 13 and Figure 14In [description], it can be seen that the longitudinal side wall 101 of the frame has a rounded outer edge 101r, and the rounded outer edge has a generally semi-circular cross-section indicated by the dashed arrow. Due to its thickness, the wall 101 also has a flat part extension plate 105, which forms part of the front side FS of the frame. After the rounded edge 101r, it also has a flat part, which forms part of the rear side RS of the frame. The remaining part of the rear side of the frame is enclosed by the cover 110. It should be noted that in Figure 18 In the embodiment of the cover shown, the cover 110 has an antenna coil connected to the circuit board 11.
[0183] According to the improvements described herein, and as Figure 13 shown, the effective area 211 of the display 21 extends over the following areas:
[0184] - Most of the front plate 105,
[0185] - Most of the flat part of the wall 101, which extends the plate 105 and forms part of the front side of the frame,
[0186] - Most of the rounded edge 101r of the wall 101, and optionally
[0187] - The flat part of the wall 101, which forms part of the rear side of the frame.
[0188] The flexible substrate 213 extending beyond the effective area 211 penetrates the frame to allow the SPI bus connector 215 to be attached to the PCB 11, and this part of the circuit is hidden by the cover 110.
[0189] Similarly, in Figure 14 [description], the touch module 22 that covers the display 21 and is itself covered by the layer 23 extends over the following areas:
[0190] - Most of the front plate 105,
[0191] - Most of the flat part of the wall 101, which extends the plate 105 and forms part of the front side of the frame,
[0192] - Most of the rounded edge 101r of the wall 101, and optionally
[0193] - The flat part of the wall 101, which forms part of the rear side of the frame.
[0194] The term "most" means, for example, at least 90% of the area involved.
[0195] Then, the extension 224 of the touch module passes under the cover 110 and penetrates the frame to allow the I2C bus connector 226 to be attached to the PCB 11.
[0196] Preferably, the touch area 220a of the module 22 only covers the front panel 105 and the flat portion of the wall 101 that extends the panel 105 and forms part of the front side of the rack, while its non-touch area 220b covers the rounded edge 101r and the flat portion of the wall 101 that forms part of the rear side of the rack.
[0197] Thus, the touch screen TS enables the security element to:
[0198] - display information on the front side of the rack and collect tactile information,
[0199] - display information on the rounded edge 101r without the risk of collecting unintentional tactile information due to user manipulation of the rack.
[0200] The device HW3 provides significant ergonomic advantages typically reserved for medium-security devices while meeting the strict security requirements demanded by its function as a hardware wallet. The screens of these devices are not controlled by a security element running on Android or an equivalent system and have the additional possibility of displaying specific information on the edges of the rack.
[0201] Exemplary implementation scheme of a hardware wallet including a magnetic stacking device
[0202] As mentioned above, some cryptocurrency asset holders can use multiple hardware wallets to manage different types or values of cryptographic resource accounts, such as low-currency-value accounts, high-currency-value accounts, non-fungible token or smart contract accounts, etc.
[0203] The third improvement (which may or may not be combined with the previous improvements) provides a hardware wallet that can be magnetically stacked with similar hardware wallets.
[0204] More specifically, a hardware wallet is provided that includes at least four magnets arranged to magnetically cooperate with four magnets from at least one similar hardware wallet to ensure magnetic stacking of the hardware wallet with the similar hardware wallet, regardless of which hardware wallet is on top of the other.
[0205] In one embodiment, the magnets are arranged asymmetrically to form magnetic keying for stacking, where the edges of the rack of the hardware wallet are aligned with the same edges of a similar hardware wallet, and where each magnet faces the corresponding magnet of the similar device.
[0206] Figure 19 、 Figure 20 、 Figure 21 Shows the device HW3 according to this embodiment. Figure 19 Is a cross-sectional view of the device HW3, Figure 20is a top view, and Figure 21 is an exploded perspective view. In Figure 19 , the front side FS of the frame 10 is at the top. In Figure 20 and Figure 21 , the frame is viewed from its rear side RS.
[0207] The frame 10 is provided with four magnets M1, M2, M3 and M4, which preferably have the same magnetic orientation, for example with the north pole facing the front of the frame. The magnets M1 and M2 are arranged in slots 103-1, 103-2 formed in the lateral side walls 103 of the frame, which slots extend substantially through the entire thickness of the frame. The magnets M1 and M2 thus generate a magnetic field on both sides of the frame.
[0208] As Figure 19 shown, each of the magnets M3, M4 comprises two superposed magnets M3a-M3b and M4a-M4b. The magnets M3a and M4a are arranged in slots 105-3, 105-4 provided in the front plate 105 of the frame ( Figure 20 , Figure 21 ), while the magnets M3b, M4b are attached in recesses provided in the covering member 110 opposite the slots 105-3, 105-4 for this purpose. As Figure 19 shown, the magnets M3a and M3b, M4a and M4b extend through less than half of the thickness of the frame, and the space between them advantageously allows the printed circuit board 11 to pass through.
[0209] Hereinafter, the magnets M3 and M4 will be considered as integral, similar to the magnets M1 and M2, since their structure in the two superposed magnets does not modify the reasoning given below.
[0210] The arrangement of the magnets M1, M2, M3, M4 is chosen here to form a magnetic adaptation during the magnetic stacking of the device HW3 with a similar device HW3-1, as Figure 24 schematically shown. The expected stacking arrangement is one in which the edges of the frame of the device HW3 are aligned with the same edges of the device HW3-1 and in which each magnet of the device HW3 faces the corresponding magnet of the similar device HW3-1. This arrangement should preferably be unique, such that there is only one magnetic stacking position in which the devices HW3, HW3-1 align their respective edges. In other words, when the stacking arrangements are different (for example, if the devices are arranged head to tail), the devices do not magnetically attach. The arrangement of the magnets thus prevents the devices from being misaligned, such that the devices do not magnetically attract each other in such a case.
[0211] For this purpose, and with reference to Figure 20 and Figure 22, the longitudinal central axis L-L' of the frame is defined, which is located at the middle position between the longitudinal side edges 101 and 102 of the frame, and the transverse central axis T-T' of the frame is defined, which is located at the middle position between the transverse side edges 103 and 104 of the frame. The axes L-L' and T-T' define four quadrants Q1, Q2, Q3, Q4, and each magnet is arranged in one of these quadrants. The magnets M1, M2, M3, M4 are arranged asymmetrically with respect to the longitudinal central axis L-L' or with respect to the transverse central axis T-T'. The combination of these two asymmetries can also be used for all or some of the magnets. To more precisely formulate this asymmetry, each magnet M1, M2, M3, M4 is defined as having a center point cm1, cm2, cm3, cm4 (cmi), a longitudinal dimension lm1, lm2, lm3, lm4 (lmi), and a transverse dimension tm1, tm2, tm3, tm4 (tmi), as Figure 23 shown.
[0212] In addition, the following axes and distances are defined, as Figure 20 and Figure 22 shown in:
[0213] - L1-L1' is the longitudinal axis passing through the center point of magnet M1 and parallel to the longitudinal central axis L-L',
[0214] - t1 is the transverse distance between the axes L1-L1' and L-L',
[0215] - L2-L2' is the longitudinal axis passing through the center point of magnet M2 and parallel to the longitudinal central axis L-L',
[0216] - t2 is the transverse distance between the axes L2-L2' and L-L',
[0217] - L3-L3' is the longitudinal axis passing through the center point of magnet M3 and parallel to the longitudinal central axis L-L',
[0218] - t3 is the transverse distance between the axes L3-L3' and L-L',
[0219] - L4-L4' is the longitudinal axis passing through the center point of magnet M4 and parallel to the longitudinal central axis L-L',
[0220] - t4 is the transverse distance between the axes L4-L4' and L-L',
[0221] - T1-T1' is the transverse axis passing through the center point of magnet M1 and parallel to the transverse central axis T-T',
[0222] - l1 is the longitudinal distance between the axes T1-T1' and T-T',
[0223] - T2 - T2' is a transverse axis passing through the center point of magnet M2 and parallel to the transverse center axis T - T'.
[0224] - l2 is the longitudinal distance between axes T2 - T2' and T - T'.
[0225] - T3 - T3' is a transverse axis passing through the center point of magnet M3 and parallel to the transverse center axis T - T'.
[0226] - l3 is the longitudinal distance between axes T3 - T3' and T - T'.
[0227] - T4 - T4' is a transverse axis passing through the center point of magnet M4 and parallel to the transverse center axis T - T', and
[0228] - l4 is the longitudinal distance between axes T4 - T4' and T - T'.
[0229] In one embodiment, it can be specified that the at least two magnets have different transverse distances t1 to t4 or longitudinal distances l1 to l4.
[0230] In one embodiment, one of the following design rules or a combination of two or more of these rules is implemented:
[0231] - The transverse distances t1 to t4 are all different from each other,
[0232] - The longitudinal distances l1 to l4 are all different from each other,
[0233] - Some of the transverse distances t1 to t4 are different, and some of the longitudinal distances l1 to l4 are different.
[0234] In another, even more stringent, asymmetric embodiment, one of the following rules is added to one of the above rules or a combination of these rules:
[0235] - The difference between each transverse distance t1, t2, t3, t4 and each of the other transverse distances is at least equal to the sum of half of the transverse dimensions tm1, tm2, tm3, tm4 of the corresponding magnets, or
[0236] - The difference between each longitudinal distance l1, l2, l3, l4 and each of the other longitudinal distances is at least equal to the sum of half of the longitudinal dimensions lm1, lm2, lm3, lm4 of the corresponding magnets.
[0237] Alternatively, by combining two rules:
[0238] - The differences between the specific lateral distances T1, T2, T3, T4 are at least equal to the sum of half of the lateral dimensions tm1, tm2, tm3, tm4 of the corresponding magnets, and the differences between the specific longitudinal distances L1, L2, L3, L4 are at least equal to the sum of half of the longitudinal dimensions lm1, lm2, lm3, lm4 of the corresponding magnets.
[0239] In Figure 20 the embodiment shown, the center cm2 of the magnet M2 is arranged on the lateral axis T1 - T1' of the magnet M1, and the center cm4 of the magnet M4 (M4a, M4b) is arranged on the lateral axis T3 - T3' of the magnet M3 (M3a, M3b). The longitudinal distances l1, l2 are equal, and the longitudinal distances l3, l4 are also equal, but the longitudinal distances l1, l2 are different from the longitudinal distances l3, l4. In addition, the lateral distances t1, t2, t3, t4 are all different, and the minimum deviation between the lateral distances (here the differences between the distances t1 and t3 and between the distances t2 and t4) is approximately equal to the sum of half of the lateral dimensions of the corresponding magnets (i.e., on the one hand M1, M3, and on the other hand M2, M4). The term "approximately" is understood here to be within a few tenths of a millimeter.
[0240] It will be clear to those skilled in the art that the improvements just described can have various other variations and embodiments. In particular, the magnets M1 and M2 themselves can include two stacked magnets, as Figure 25 shown, Figure 25 showing a variant HW4 of the device equipped with the magnet M1 formed by a pair of magnets M1a, M1b. Conversely, the magnets M3 and M4 can be integral and extend through the entire thickness of the frame, as Figure 26 shown, Figure 26 showing a variant HW5 of the device equipped with the same integral magnet M3 as the magnet M1. Similarly, the attachment of the magnets to the frame can be achieved in a variety of ways different from those described. In particular, if the printed circuit board is strong enough to withstand the separation forces applied to each magnet when separating two magnetically stacked devices, the magnets or some of them can be directly attached to the printed circuit board. Finally, although this improvement does not require it, in some embodiments, the polarities of the magnets may not all be the same. It will also be clear to those skilled in the art that the improvements just described can be applied to any type of portable electronic device to be stacked with similar devices.
[0241] Exemplary implementation scheme of a portable electronic device with an interactive stacking function
[0242] Examples of magnetically stackable devices according to the third improvement have been described above. According to the fourth improvement, the stacked device implements an interactive stacking management method that allows them to be used when they appear in the stack, even though the front screens are no longer accessible.
[0243] For example, as Figure 27 shown, the user may have three hardware wallets HW3, HW3-1, HW3-2 and stack them magnetically. The user may want to access their content or check their status (battery level, cryptocurrency wallet, value of private keys, etc.) without unstacking. The user may also want to use one of the devices in the stack by linking it to a host device HDV to complete a transaction on a blockchain BCN or decentralized exchange DEX, or to update or download an application via a module HSM.
[0244] According to this embodiment, when requested by the user, the device at the top of the stack makes its display available to other devices. The term "makes available" means that the user can use the screen of the device at the top of the stack to view or use the devices inside the stack.
[0245] To this end, the devices communicate with each other via a wireless data link. In the case of the device HW3 described above, after pairing the devices and preferably pairing the devices with the host device HDV, this link is, for example, a multi-point Bluetooth link.
[0246] The organization of data exchange between stacked devices can be done according to a mesh, chain, or hierarchical communication strategy. In a mesh communication strategy, each device can communicate with any other device. In Figure 27 the example shown, this strategy involves wireless links SLNK1, SLNK2, SLNK3 between the devices. In a chain communication strategy, each device can communicate with the device immediately below or above it in the stack. In Figure 27 the example shown, this strategy involves wireless data links SLNK1 and SLNK2. In a hierarchical communication strategy, the device at the top of the stack communicates with the devices below it, and two devices within the stack do not communicate with each other. In this case, in Figure 27 the example only links SLNK1 and SLNK3 are used.
[0247] Since this improvement applies to any type of electronic portable device including a wireless communication device (especially Wi-Fi), the choice of communication strategy can vary according to the type of wireless data link used. The hierarchical communication strategy may be preferred, for example, in the case of a Bluetooth link. In the case of a Wi-Fi link, the mesh communication strategy may be preferred.
[0248] In one embodiment, each device in the stack is assigned one of the following operating modes according to the improved interactive stacking method:
[0249] - Mode SM0, or "stacking mode disabled",
[0250] - Mode SM1, or "overlay" mode,
[0251] - Mode SM2, or "top" mode,
[0252] - Mode SM3, or "middle" mode.
[0253] In modes SM1, SM2, and SM3, the stacking mode is enabled, and each mode transforms the positions of the devices in the stack and corresponds to the specified displays "F" and "E":
[0254]
[0255]
[0256] To best utilize the display possibilities provided by the above-described touch screen TS, each mode is assigned an "F" display ("front display") on the front side and an "E" display ("edge" display) on the edge of the device. In the above embodiment, the "E" display corresponds to the display of information on the non-touch area above the rounded edge 101r of the rack of the touch screen TS. The "F" display can correspond to one or more different menus, thereby allowing the management of the stack or the management of one of the devices that make up the stack individually.
[0257] Operating mode SM0 corresponds to the normal operating mode of device HW3. Devices HW3 in mode SM1 or SM3 are covered by another device and are therefore unavailable without the method described herein. The device in mode SM2 is located at the top of the stack and can be used normally because its screen is accessible to the user, but it can also make its screen available to other devices upon the user's request. Depending on the interactive management needs of the stack, it may not be necessary to provide operating mode SM3. In particular, when the devices in the "top" mode address each of them, it may not be necessary to know which devices are at the bottom or in the middle of the stack.
[0258] Display F0 is the normal display presented to the user when the device is used with the stacking mode disabled. Displays F1 (“overlay”) or F3 (“intermediate”) can be arbitrary as the user cannot see the device's screen. The display can be blank or show an image or information such as “This device is in stacking mode”. However, it can also show instructions such as “Disable stacking mode”, which can be useful if the user interrupts the stack without first notifying the device at the top of the stack that the stacking mode should be disabled (the device will send this information to other devices).
[0259] Display F2 can include a pre - display of a menu through which the user selects the device they wish to control via the screen. Figure 28 An example of such a menu is shown. The user is prompted to select between “This device” or one of the other two devices HW3 - 1, HW3 - 2. If the user selects “This device”, the display F2 switches to a display F0' similar to display F0, with an added “Return” button to allow the user to make a new selection. If the user selects “HW3 - 1” or “HW3 - 2”, the display F2 switches to a display F0” similar to display F0, but with an additional indication that the device in use is not “This device” but the device that has been selected. A return button is also provided to allow the user to make a new selection.
[0260] Thus, using a device located inside the stack via the screen of the device at the top of the stack can be similar to using the device when the stacking mode is disabled, where the display F0' or F0” includes the same menu as the display F0. For example, the user can choose to connect the device to a host device HDV using data links LNK1, LNK2, or LNK3 for a transaction, as Figure 27 shown.
[0261] Edge displays E0 to E4 are optional, but can provide additional comfort to the user as the edge display is visible even though the devices are stacked. These displays can be the same or different. For example, they can show the name of the device or its serial number. When a device in mode SM1 or SM3 is selected by a device in mode SM2, the display of the device name or serial number can blink or scroll instead of remaining stationary.
[0262] Figure 29 Depicts when placed in the “top” mode SM2 ( Figure 27)Operations to be performed by device HW3 afterwards. At step S10, device HW3 queries all devices in the stack to identify them. It should be noted that, for security reasons, the specific implementation of these various data links preferably requires a previous device configuration step during which each device is notified of the devices with which it can be stacked. Thus, devices that have not been previously declared by the user are not allowed in the stack. Similarly, before agreeing to communicate with each other, it is desirable for devices HW3, HW3-1, HW3-2 to use their cryptographic means to authenticate each other securely.
[0263] At step S11, device HW3 presents a list of devices to the user and requests them to make a choice, for example, in the manner as shown above. Figure 28 At step S12, device HW3 establishes communication or re - establishes communication with the device specified by the user. At step S13, device HW3 receives the information to be displayed from the selected device and displays the information on its touch screen. At step S14, device HW3 detects a user action on its touch screen and, at step S15, sends it to the selected device. The process can continue indefinitely as long as the user is using the selected device until step S16, where the user returns to the selection menu ( Figure 28 ) to select another device or request that all devices be placed in sleep mode.
[0264] The specific implementation of this interactive stack management process assumes that each device is capable of activating the stack mode and knows its position in the stack to place itself in the corresponding mode SM1 or SM2, or optionally in mode SM3. For this purpose, the stack management method can be implemented automatically or manually.
[0265] As part of the automatic specific implementation of this method, each device HW3, HW3-1, HW3-2 is equipped with sensors 108a, 108b, as shown. Figure 30 These sensors allow the devices to detect the presence of another device below or above them. If the devices are equipped with magnets, sensors 108a, 108b can be Hall - effect sensors capable of detecting the presence of magnets below or above each device. Sensors 108a, 108b can be directly connected to the security element SE3, as shown, Figure 5 or connected to the microcontroller MCU3. A variety of other types of sensors can be used, such as optical, acoustic, piezoelectric, electromagnetic, thermal, capacitive sensors, etc., especially when the devices in the stack do not have magnets.
[0266] In one embodiment, it is not necessary for the sensor to be able to positively identify that an object detected above or below devices HW3, HW3-1, HW3-2 is a similar device suitable for placement in a stacked mode. This uncertainty can be eliminated by a device in "top" mode based on the reply received to its identification request. Similarly, a device that detects an object placed on it and does not receive any identification request will understand that the object is not a compatible device.
[0267] Figure 31 is a state diagram showing an example of an automatic implementation of an interactive stacking management method. In this example, four operating modes SM0, SM1, SM2, SM3 are managed. Device HW3 is by default in mode SM0. At step S22, the device detects the presence of a device on it and switches to mode SM1, where the device waits to be queried by a device in "top" mode. As an alternative, the device detects the presence of a device below it at step S23 and switches to "top" mode to query and identify other devices in the stack. If the device is in mode SM2 and detects at step S24 that a device has been placed on top of it, it switches to mode SM3. Once in mode SM3, if at step S25 it no longer detects a device on it, the device reverts to mode SM2. Finally, regardless of which of modes SM1, SM2, SM3 it is in, if the device detects at step S20 that there are no longer devices above or below it, it automatically returns to mode SM0.
[0268] In a manual implementation of this method, the user accesses a menu for manually activating the stacking mode, an example of which is shown in Figure 32 The user first activates the stacking mode and then selects between an "overlay" mode SM1 and a "top" mode SM2. In this example, mode SM3 is not supported.
[0269] Figure 33 is a state diagram showing an example of a manual implementation of an interactive stacking management method. Device HW3 is by default in mode SM0. At step S30, the user activates the stacking mode. At step S31, the user selects mode SM1, or at step S32 selects mode SM2. At any time, the user can return to step S31 or S32 to change the operating mode of the device while changing its position in the stack. Similarly, at step S33, the user can invalidate the stacking mode at any time.
[0270] When applying this method to a hardware wallet of the above type, modes SM0, SM1, SM2 and optionally SM3 are preferably managed by the operating system OS3 of the secure element SE3. To this end, a module for automatic stacking management ASM is provided in the operating system, asFigure 6 as shown. Alternatively, the operating system OS3 provides a module MSM for manual stacking management. In some embodiments, the two modules can coexist, providing the user with a choice between automatic management or manual management. Each of these modules allows the device to be placed in different operating modes and operate according to what is required by these modes. When the operating mode SM3 is not supported, it is included in the mode SM1, which supports the case where the device is at the bottom of the stack and the case where the device is in the middle of the stack.
[0271] Those skilled in the art will appreciate that the method according to this improvement can be applied to any type of portable electronic device including a wireless communication device (especially Wi-Fi), and its scope is not limited to a hardware wallet for cold storage of private keys. Similarly, the method does not exclusively involve using magnets to stack the devices, as stacking can be provided without the devices being magnetically held against each other. In addition, the method can be applied to devices that do not have a display (display E) at the edge of the rack but only have a display (display F) on the front side.
[0272] In some embodiments, the interactive stacking management method may also involve a host device HDV. In this case, the accompanying software menu has a "Stacking Management" option that allows the user to select the hardware wallet they want to use for transactions ( Figure 27 ). Then, the accompanying software notifies the hardware wallet at the top of the stack that it should make its screen available to the selected hardware wallet via the host device.
[0273] Exemplary implementation scheme of an adaptive Bluetooth antenna with two radiation axes specifically for stackable devices
[0274] Above, a hardware wallet equipped with a Bluetooth antenna BTA ( Figure 5 ) and a touch screen TS has been described. A hardware wallet made of an aluminum rack has also been described, which includes a front panel covering a conductive wall 105 that receives the touch screen TS ( Figure 9 ). Finally, a hardware wallet that can be magnetically stacked with similar hardware wallets ( Figure 27 ) and a method for interactively managing the stacking of hardware wallets through wireless communication (especially via a Bluetooth link) between stacked hardware wallets have also been described.
[0275] Tests carried out by the applicant on commercially available Bluetooth antennas in the form of integrated components have shown that due to the metal mass of the rack 10, especially the conductive wall 105 covering the front of the rack ( Figure 9), this type of assembly is not suitable for obtaining good quality Bluetooth communications. In normal use (device HW3 is outdoors), this metal mass causes a strong attenuation of the gain of these conventional antennas by acting as a barrier (in the sense of shielding) with respect to the electromagnetic fields emitted by these conventional antennas. The gain is so low that it does not allow a stable Bluetooth connection to be established.
[0276] The applicant also conducted tests using an IFA antenna ("inverted F antenna"), which is an antenna commonly used in mobile phones, where the antenna is placed close to the edge of the frame. In normal use (device HW3 is not stacked and outdoors) a relatively small gain is obtained, but Bluetooth communication is still allowed. On the other hand, when two devices HW3 and HW3-1 are stacked (e.g., Figure 30 ), the device at the top of the stack will see its antenna gain weakened, which may result in unstable Bluetooth communications.
[0277] It may therefore be desirable to provide an advanced RF antenna structure that may be used, but not exclusively used, in a portable electronic device that includes a conductive chassis and that provides relatively stable performance under two conditions of use, including use outdoors on the one hand and use in the presence of conductive surfaces on the other hand, such as when the device is stacked with similar devices.
[0278] According to a fifth improvement, a radio frequency antenna is provided, which includes a combination of a closed slot antenna made in a side wall of a frame, the closed slot antenna having a radiation axis substantially perpendicular to the wall, and an open slot parasitic antenna having a radiation axis perpendicular to the radiation axis of the closed slot antenna. Taking into account the above two operating conditions, a radio frequency field simulation computer tool is used to configure (i.e., adjust) the two antennas. The result is that the performance of the antenna under these two operating conditions is more or less the same. A detailed non-limiting example of the construction of such an antenna will be described below.
[0279] Exemplary implementation scheme of a closed slot antenna
[0280] exist Figure 34 The main components of the closed slot antenna embodiment are shown in the exploded view of FIG. The assembled antenna structure is as follows Figure 38 , Figure 39 , Figure 42 , Figure 43 As shown. Figure 34 , Figure 39 , Figure 42 , Figure 43 In FIG. 1 , the frame 10 is seen from its rear side RS, with the plate 105 located at the bottom. Figure 38 In the cross-sectional view of FIG. , plate 105 is at the top. Therefore, compared with the other figures, Figure 38The positions or orientations of the components therein are opposite.
[0281] Reference Figure 34 , the closed slot antenna includes a longitudinal port 40 made in a wall of the frame (in this case, the longitudinal side wall 102). The antenna also includes a radio frequency signal injector 50 to apply a ground voltage and a radio frequency signal RFS to the port 40, and the signal is provided by a circuit BTM ( Figure 12 ) arranged on a circuit board ( Figure 5 ).
[0282] Viewed from the front of Figure 35 , the longitudinal port 40 includes two longitudinal surfaces 41, 42 facing each other, and the two longitudinal surfaces are connected by two lateral surfaces 44, 45, and the two lateral surfaces are substantially rounded in shape here. It has a length Ls (which is also the length of the longitudinal surfaces 41, 42) and a height Hs. The wall 102 also has a non-transverse recess 45, and this non-transverse recess is not considered to be included in the port 40.
[0283] The injector 50 is made of a flexible printed circuit board and has two electrodes 51, 52. The electrode 51 is placed on the surface 41 of the port 40, and the electrode 52 is placed on the surface 42 of the port. The injector 50 also includes a connecting portion 53 extending between the electrodes 51, 52 and an extension 54 extending the electrode 51.
[0284] Figure 36 And Figure 37 show the injector 50 in a top view and a bottom view respectively. The top view shows the outer surface of the injector in contact with the surfaces 41, 42. Before the folding that occurs when the injector is inserted into the port 40, the injector is a flat part as seen in these figures. The injector includes various conductors 500, some of these conductors are on the surface and some of these conductors are buried. It also includes contact pads Pc1, Pc2, Pc3, Pc4, Pc5, Pc6 for welding components, and in this case, the welding components are capacitors C1, C2, C3 participating in the closed slot antenna configuration. Finally, the injector 50 includes a connector 540 arranged on the extension 54, thus allowing it to be connected to the printed circuit board to receive a ground voltage and a radio signal RFS.
[0285] When the injector 50 is inserted into the port 40, a compression element 55 or spacer is inserted between the electrodes 51, 52, as visible for example in Figure 38 . The compression element 55 is made of a soft material such as silicone rubber and presses the electrodes 51, 52 against the surfaces 41, 42. It should be noted that the electrodes 51, 52 only cover the edges of the surfaces 41, 42 here, and the outer part of the port 40 is blocked by a non-conductive plug 47 ( Figure 38)。The electrodes 51, 52 may be coated with a gold layer 520 to ensure good electrical contact with the surfaces 41, 42. These surfaces may also be made by milling to provide good electrical conductivity, especially if the aluminum frame has been pre-anodized.
[0286] Advantageously, the electrodes 51, 52 herein have a large contact surface with the surfaces 41, 42, and the length of the contact surface is at least equal to one-fourth of the length Ls of the surfaces 41, 42. They are preferably inserted in the middle of the port 40 such that the distances from their edges to the walls 44 and 45 of the port are the same.
[0287] Figure 40 is the circuit diagram of the injector. The connector 540 has a plurality of ground contacts 541 connected to the electrode 51 forming the ground layer (GND). It is further characterized by a contact 542 for receiving the radio frequency signal RFS. The contact 542 is connected to the pad Pc3' through a conductor 500. The capacitor C3 has a first terminal connected to the pad Pc3' and a second terminal connected to the pad Pc3, and the pad Pc3 is in turn connected to the electrode 51. The capacitor C1 has a first terminal connected to the pad Pc1' and a second terminal connected to the pad Pc1. The capacitor C2 has a first terminal connected to the pad Pc2' and a second terminal connected to the pad Pc2, and the pad Pc2 is in turn connected to the electrode 51. The conductor 500 connects the pad Pc1 to the pad Pc3', connects the pad Pc1' to the pad Pc2' and the electrode 520. As Figure 41 shown, the surface 42 receives the radio frequency signal RFS via the capacitor C3, and the second terminal of the capacitor C3 is connected to the surface 41 via the capacitor C3. The surface 41 is at the ground voltage and is connected to the surface 42 via the capacitor C2.
[0288] The configuration just described is essentially only exemplary, and those skilled in the art can provide various other arrangements of the components involved in the antenna configuration and the selection of components.
[0289] Exemplary implementation scheme of an open slot parasitic antenna
[0290] In Figure 34 the exploded view shows the main components of an example of an open slot parasitic antenna. The structure of the assembled antenna is as Figure 42 , Figure 43 shown. The open slot parasitic antenna has an arm 70 made of a conductive metal (e.g., stainless steel or nickel-plated mild steel). The arm 70 has a rectangular cross-section with a small thickness to make it flexible and has a length Lb. It extends along the wall 102 of the rack in a plane parallel to the surface 42 ( Figure 38 ) and close to this plane, at a distance Db from the port 40 ( Figure 38 ), that is, at a distance Db from the inner edges of the surfaces 41, 42 of the port 40.
[0291] The arm 70 has a free end 701 and a moored end 702. The end 702 is wider than the rest of the arm and extends towards the wall 102, where it has a protruding contact portion 71 obtained, for example, by stamping, which rests on a contact surface 107 formed in the wall 102( Figure 43 ).
[0292] As an extension of the end 702, the arm 70 also has a base 703 with a hole 704. A screw 705 passing through the hole 704 is screwed into a threaded hole 106 formed in a receiving surface 108 provided in the wall 102( Figure 34 、 Figure 43 ). Figure 34 )
[0293] The arm 70 is attached to the wall 102 while an elastic bending is applied to it between its base 703 and the protruding contact portion 71, the base being threadedly connected to the receiving surface 108 and the protruding contact portion resting on the contact surface 107. This bending applies sufficient pressure on the contact portion 71 to ensure that the electrical contact between the arm 70 and the surface 107 does not change over time.
[0294] The electrical contact portion of the arm 70 with the wall 102 (in this case the contact surface 107) is preferably close to the surface 42 that receives the RF signal, such that the parasitic antenna is indirectly fed by the radio frequency signal applied to the closed slot antenna. In particular, this point is preferably close to the end of the surface 42. As Figure 42 can be seen, the protruding contact portion 71 is here close to the lateral surface 44 of the port.
[0295] Referring Figure 34 or Figure 43 , the open slot parasitic antenna also has a portion 80 with a guiding wall for the arm 70 to ensure parallelism with the wall 102. Figure 44 The guiding portion 80 is also shown in . The free end 701 of the arm 70 is shown in two positions: the relaxed position P1(701) before being mounted in the rack; and the position P2(701) subjected to the above-mentioned elastic bending, at which position the protruding contact portion 71 resting on the surface 107 forces the arm to reach a horizontal position.
[0296] Figure 45It is a schematic diagram showing an antenna produced by the combination of a closed slot antenna and an open slot parasitic antenna. The closed slot antenna includes surfaces 41 and 42 connected by walls 43 and 44 of port 40. The open slot parasitic antenna includes an arm 70 connected to wall 102 through a protruding contact portion 71 provided on the tether end 702. The closed slot antenna has a Y radiation axis substantially perpendicular to the side wall 102 of the frame, while the open slot parasitic antenna has an X radiation axis substantially perpendicular to the Y axis, thus parallel to the side wall 102 and perpendicular to the plane of the frame 10.
[0297] Example of tuning and optimizing the resulting antenna
[0298] The closed slot antenna and the open slot parasitic antenna together form the resulting antenna, and its design and tuning parameters can be determined by computer simulation. For this purpose, first, the frequency band in which the antenna is to be used is determined. For example, this can be the Bluetooth frequency band or the 2.45 GHz Wi-Fi frequency band, where the channel width can vary according to the selected technology.
[0299] In an embodiment providing the results to be described below, the simulation aims to optimize the antenna in a Bluetooth communication environment, that is, the antenna in the target frequency band TFB between the frequency Fmin of 2.4 GHz and the frequency Fmax of 2.483 GHz, to obtain at least one of the following results:
[0300] (1) When the frame 10 of device HW3 is outdoors, the resulting antenna gain in the target frequency band is greater than -5 dB, and when the rear side of the frame faces a conductive surface (especially the plate 105 of the frames of similar devices HW3-1 and HW3-2), the resulting antenna gain in the target frequency band remains greater than -5 dB.
[0301] (2) When the frame 10 is outdoors, the open slot parasitic antenna has a tuned frequency within the target frequency band,
[0302] and
[0303] (3) When the rear side of the frame 10 faces a metal surface, and especially the front plate 105 of the frame of a similar device, the closed slot antenna has a tuned frequency within the target frequency band.
[0304] In other words, depending on the operating conditions, the radiation from the closed slot antenna will be dominant over the radiation from the open slot parasitic antenna, or vice versa.
[0305] Among the numerous parameters for tuning the antenna to achieve the desired results, the most important parameters include:
[0306] - The length Ls of the longitudinal port 40, that is, the length of the closed slot antenna,
[0307] - The height Hs of the longitudinal port 40, i.e., the aperture of the closed slot antenna,
[0308] - The length Lb of the arm 70, which is the length of the open slot parasitic antenna,
[0309] - The distance Db between the previously described arm 70 and port 40, i.e., the aperture of the parasitic open slot antenna.
[0310] As a starting point for the simulation, the theoretical length of the longitudinal port 40 was chosen to be equal to one quarter of the wavelength of the frequency of 2.45 GHz, i.e., 30.6 mm. Due to the presence of the open slot parasitic antenna, the tests and simulations established to achieve the above purposes led to significantly different values accurate to within a few millimeters or tenths of a millimeter. Thus, at the end of the simulation and testing, as an example, the following values were obtained:
[0311] - The length Ls of the longitudinal port 40: 30 mm;
[0312] - The height Hs of the longitudinal port 40: 2.1 mm;
[0313] - The length Lb of the arm 70: 22 mm;
[0314] - The distance Db: 1.6 mm.
[0315] Those skilled in the art will appreciate that these values may vary depending on other parameters of the antenna, such as the electronic components of the injector 50 (here capacitors C1 to C3), the shape of the rack and the position of the port on one of its walls, the amount of metal constituting the rack, etc.
[0316] Figure 46 and Figure 47 shows the curve of the resulting antenna reflection loss or return loss obtained using the dimensions provided above. Figure 46 Shows the reflection loss curve RL1 when the device HW3 is outdoors. Figure 47 Shows the reflection loss curve RL2 when the device HW3 is stacked on top of a similar device HW3-1 (as Figure 48 shown). Each curve shows two low values of the reflection loss at frequencies corresponding respectively to the tuning frequency FT1 of the closed slot antenna and the tuning frequency FT2 of the open slot parasitic antenna. In particular:
[0317] - FT1a ( Figure 46 ) is the tuning frequency of the closed slot antenna when the device is outdoors or when the device is below another similar device (e.g., Figure 48 the device HW3-1 in
[0318] -FT1b( Figure 47 ) is the tuning frequency of the closed slot antenna when the device is placed on a metal surface or on another similar device (e.g., Figure 48 the device HW3 in
[0319] -FT2a( Figure 46 ) is the tuning frequency of the open slot parasitic antenna when the device is outdoors or when the device is under another similar device (e.g., Figure 48 the device HW3-1 in
[0320] -FT2b( Figure 47 ) is the tuning frequency of the open slot parasitic antenna when the device is placed on a metal surface or on another similar device (e.g., Figure 48 the device HW3 in
[0321] When the tuning frequencies of the closed slot antenna and the open slot parasitic antenna are selected for the lowest reflection loss, the following results are obtained:
[0322] Figure 46 (Outdoors):
[0323] -FT1a = 2.32 GHz, i.e., FT1a < Fmin
[0324] -FT2a = 2.42 GHz, i.e., Fmin < FT2a < Fmax
[0325] Figure 47 (Placed on a metal surface or other device):
[0326] -FT1b = 2.475 GHz, i.e., Fmin < FT1b < Fmax
[0327] -FT2b = 3.15 GHz, i.e., Fmax << FT2b
[0328] Where (for record):
[0329] -Fmin = 2.4 GHz
[0330] -Fmax = 2.483 GHz
[0331] At Figure 46In the case where the tuning frequency FT1a of the closed slot antenna is "out-of-band", while the tuning frequency FT2a of the open slot parasitic antenna is within the target frequency band. The radiation from the parasitic open slot antenna is dominant over the radiation from the closed slot antenna.
[0332] In Figure 47 the case where the tuning frequency FT1b of the closed slot antenna is within the target frequency band, while the tuning frequency FT2b of the open slot parasitic antenna is out-of-band. In fact, in Figure 48 it can be seen that the parasitic open slot antenna sees two electromagnetic barriers above and below it along its X radiation axis. The upper barrier is formed by the wall 105 of the rack in which it is located, and the lower barrier is formed by the wall 105 of the device HW3-1. Therefore, in this case, the radiation from the closed slot antenna is dominant over the radiation from the parasitic open slot antenna.
[0333] Finally, Figure 49A and Figure 49B show the gains CG1, CG2 of the resulting antennas when the device HW3 is in the open air, and Figure 50A 、 Figure 50B show the gains CG3, CG4 of the resulting antennas when the device HW3 is placed on a metal surface or on a device similar to HW3-1. In particular, Figure 49A 、 Figure 50A show the gains CG1, CG3 of the resulting antennas in the Y-Z plane, which is the rack plane or the horizontal plane when the rack is lying flat. Figure 49B 、 Figure 50B show the gains CG2, CG4 of the resulting antennas in the vertical plane X-YZ, which is the plane perpendicular to the rack or the vertical plane when the rack is lying flat. In the first case, a peak gain of -1.5 dB is obtained at a horizontal angle of 225 degrees and a vertical angle of 105 degrees. In the second case, a peak gain of -3.4 dB is obtained at a horizontal angle of 90 degrees and a vertical angle of 120 degrees.
[0334] Therefore:
[0335] (1) When the device rack is outdoors, the resulting antenna gain in the target frequency band is greater than -5 dB, and when the rear side of the rack of the device HW3 faces a conductive surface (including the plate 105 of the racks of devices similar to HW3-1, HW3-2), the resulting antenna gain in the target frequency band remains greater than -5 dB,
[0336] (2) When the rack 10 is outdoors, the open slot parasitic antenna has a tuning frequency within the target frequency band, while the closed slot antenna has a tuning frequency outside the target frequency band, and
[0337] (3) When the rear side of the frame faces a metal surface, and especially the front panel 105 of a frame of a similar device, the closed slot antenna has a tuning frequency within the target frequency band, while the open slot parasitic antenna has a tuning frequency outside the target frequency band.
[0338] In other words, when the resulting antenna is located between two conductive plates, it radiates mainly from the side of the frame, while when the frame is outdoors, the resulting antenna radiates mainly from the lower side of the frame with a plastic cover.
[0339] Those skilled in the art will appreciate that the above improvements are variable and not limited to the application environment in which they are designed. Generally speaking, the combination of the above closed slot antenna and open slot parasitic antenna is independent of the above frame structure 10, and its application is not limited to hardware wallets. Such a combination can be used for a variety of applications and portable electronic devices, including but not limited to usage conditions where the metal environment of the antenna can vary widely.
[0340] Those skilled in the art will also appreciate that although described above in connection with a hardware wallet for storing private keys, the second, third, fourth, and fifth improvements are independent of each other and can be the subject of separate embodiments and various applications other than those applied to hardware wallets.
Claims
1. A portable device (HW3) that forms a hardware wallet for cold storage of cryptographic keys from a blockchain, the portable device comprising a chassis (10) having a front panel (FS) and a rear panel (RS), a microcontroller (MCU3) and a security element (SE3) being arranged in the chassis, the security element being connected to the microcontroller via a first data link (BS1), the microcontroller being configured to ensure data exchange between the security element and an external host device (HDV), but the device not having the ability to be directly connected to the Internet, characterized in that, the portable device comprises a touch screen (TS, 20) having a diagonal of 3.5 inches or greater, the touch screen having at least 600×400 pixels, being specifically controlled by the security element (SE3) and covering most of the front side (FS) of the chassis (10), and characterized in that: - the security element is connected to the touch screen via at least one second data link (BS2, BS3) to transmit graphic data to the touch screen and receive touch data from the touch screen, and - the security element comprises an operating system (OS3) integrated with a graphics engine (GENG) to generate and display text and images.
2. The device according to claim 1, wherein the security element is configured to detect (S4) two simultaneous touches on two separate areas of the touch screen (TS, 20) before performing or completing at least one security operation that requires user consent.
3. The device according to one of claims 1 and 2, wherein: - the chassis (10) has a first side wall (101) having a rounded edge (101r), and - the touch screen (TS, 20) has a non-touch display area (220b) that covers most of the rounded edge (101r) for displaying graphic data on the edge of the chassis without touch feedback.
4. The device according to one of claims 1 to 3, the device comprising a second side wall (102), the second side wall comprising a longitudinal port (40) forming a closed slot antenna, the device comprising means (50) for applying a ground voltage to a first surface (41) of the longitudinal slot and a radio frequency signal (RFS) to a second surface (42) of the longitudinal slot (40).
5. The device according to one of claims 1 to 4, wherein the security element is connected to the touch screen via a second serial data link (BS2) for transmitting graphic data to the touch screen and via a third serial data link (BS3) for receiving touch data from the touch screen, one of the data links being an SPI bus and the other data link being an I2C bus.
6. The device according to any one of claims 1 to 5, wherein the touch screen (TS, 20) comprises an electronic ink display (EID, 21) covered by a touch module (TM), and wherein a protective layer (23) covers the touch screen to allow the device to be stacked with similar devices (HW3-1, HW3-2) without damaging the touch screen.
7. The device according to any one of claims 1 to 6, wherein the frame (10) is made of a non-magnetic material and comprises at least four magnets (M1, M2, M3, M4, M3a, M3b, M4b) for magnetically stacking the device with similar devices (HW3-1, HW3-2), the magnets being arranged asymmetrically with respect to the longitudinal central axis (LL') of the frame and / or with respect to the transverse central axis (TT') of the frame so as to form a magnetic key.
8. The device according to any one of claims 1 to 7, the device comprising wireless communication means (BTA, BTM), and the device being configured to establish wireless communication with the similar devices (HW3-1, HW3-2) present in the stack when stacked with at least one similar device (HW3-1, HW3-2) and positioned at the top of the stack, receive information provided by the similar devices and display the information on the touch screen (TS, 20).
9. The device according to claim 8, the device being configured to receive a command provided by a user via the touch screen (TS, 20) and send the command to the similar devices (HW3-1, HW3-2).
10. The device according to one of claims 8 and 9, the device comprising at least one sensor (108a, 108b) for detecting the presence of a similar device (HW3-1, HW3-2) on the front side (FS) or the rear side (RS) of the frame (10).
11. The device according to one of claims 9 and 10, the device being configured to (ASM, MSM) automatically (S22, S23) or in response to an action of the user (S30, S31, S31) switch to a stacking operation mode (SM1, SM2, SM3) in which the device communicates with at least one similar device (HW3-1, HW3-2).
12. The device according to any one of claims 1 to 11, the device being configured to send or receive data in a given frequency band and for this purpose comprising a radio frequency antenna, the radio frequency antenna comprising a combination of a closed slot antenna (40, 50) and an open slot parasitic antenna (70, 102), both antennas being configured such that: - when the device is outdoors, the open slot parasitic antenna has a tuning frequency within the specified frequency band, while the closed slot antenna has a tuning frequency outside the specified frequency band, and - When the device is stacked with similar devices (HW3-1, HW3-2), the closed slot antenna has a tuned frequency within the specified frequency band, while the open slot parasitic antenna has a tuned frequency outside the specified frequency band.
13. The device according to claim 12, wherein: - The closed slot antenna includes a through longitudinal port (40) made in the side wall (102) of the rack (10), the longitudinal port (40) includes two longitudinal surfaces (41, 42) facing each other, and means (50) for applying a ground voltage to the first surface (41) and a radio frequency signal (RFS) to the second surface (42), and - The open slot parasitic antenna includes a conductive arm (70) parallel to the side wall (102) of the rack (10) and arranged near the longitudinal port (40), the conductive arm (70) having a free end (701) and an end (702) electrically connected to the side wall (102).
14. The device according to one of claims 12 and 13, wherein the specified frequency band is a Bluetooth frequency band.