Stackable portable electronic device including a self-adaptive bluetooth antenna having two axes of radiation

EP4588135A1Pending Publication Date: 2025-07-23LEDGER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023793410
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-09-16
Filing Date
2023-09-11
Publication Date
2025-07-23

AI Technical Summary

Technical Problem

Hardware wallets for cold storage of private keys face limitations in ergonomics and Bluetooth communication performance, with existing secure elements having limited inputs/outputs, restricting their functionality and security features, and conventional antennas experiencing attenuation due to metallic chassis, leading to unstable Bluetooth connections.

Method used

A self-adaptive Bluetooth antenna with two radiation axes, combining a closed slot antenna and a parasitic open slot antenna, optimized through computer simulations to maintain performance in both open air and stacked conditions, and a hardware wallet design featuring a touch screen controlled by a secure element with enhanced user interface and magnetic stacking capabilities.

Benefits of technology

The solution enhances the ergonomic and security features of hardware wallets by enabling stable Bluetooth communication and improved user interaction, while maintaining high security standards, and allows for efficient management of multiple devices in a stack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The invention relates to an electronic device (HW3) comprising a frame (10), which is made of an electrically conductive material, and a radio frequency antenna, which comprises the combination of a closed slot antenna (40, 50) and an open slot parasitic antenna (70, 102). When the frame (10) is in the open air, the open slot parasitic antenna has a tuning frequency which is within a predetermined frequency band, while the closed slot antenna has a tuning frequency which is outside the predetermined frequency band. When the frame (10) faces the front face of a similar device or an electrically conductive surface, the closed slot antenna has a tuning frequency which is within the predetermined frequency band, while the open slot parasitic antenna has a tuning frequency which is outside the determined frequency band.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] Title of the invention: Stackable portable electronic device comprising a self-adaptive Bluetooth antenna having two radiation axes.

[0003] Technical Field

[0004] The present invention relates to hardware wallets for cold storage of private keys from the blockchain. The present invention also relates to the ergonomics of portable electronic devices, and in particular the ergonomics of hardware wallets for cold storage of private keys.

[0005] Background

[0006] In recent years, the development of cryptocurrencies or other types of cryptoassets managed by the blockchain, such as non-fungible tokens ("NFTs") and smart contracts, has given rise to various means of storing and preserving the private keys attached to these different types of cryptoassets. This is how the notions of "wallet", "cold storage" and "hot" storage of private keys emerged. A "wallet", also called a "currency holder", is a device or program whose function is to manage cryptoassets, and therefore to store the private keys attached to them. So-called "hot wallets" are connected to the Internet and susceptible to hacker attacks or exposure to viruses and malware. These may be wallets managed by centralized exchange platforms, which do not offer the highest level of security.For example, many centralized platforms have been looted of hundreds of millions of dollars by hackers over the years. Hot wallets can also take the form of programs installed on mobile phones, tablets, or personal computers ("software wallets"). Such wallets are permanently connected to the Internet and are therefore themselves susceptible to attack.

[0007] Cold wallets are the most secure solution for cold storage of private keys, i.e., away from any direct internet access, which reduces the attack surface and therefore the risk of theft by hacking. Transactions involving private keys are signed in an offline environment. Any transaction initiated online is temporarily transferred to the offline hardware wallet, where it is then digitally signed before being transmitted to the online network. Since the private key is not communicated to the online server during the signing process, a hacker cannot access it.

[0008] The simplest form of cold storage is the paper wallet. A paper wallet is a document on which the user's public and private keys are written. The document usually has an embedded QR code that can then be scanned to sign a transaction. The disadvantage of this medium is that if the paper wallet is lost, illegible, or destroyed, the user can no longer access their funds.

[0009] Hardware wallets are a convenient alternative to paper wallets for storing private keys. Additionally, they are typically configured to generate recovery phrases to restore private keys if they are lost. Remember that crypto assets are never stored in a hardware wallet, but are recorded on the blockchain. A hardware wallet simply stores private keys to manage transactions on the blockchain. Public keys corresponding to the private keys point to an address on the blockchain where the assets are actually located.

[0010] As shown in Figure 1, an HW hardware wallet is never directly connected to the Internet. To be usable, the HW hardware wallet must be connected to an HDV host device by means of a LNK data link, for example USB or Bluetooth. The HDV host device may be a computer, a mobile phone or a tablet, and runs so-called "companion" software for conducting transactions on the BCN blockchain, such as the "Ledger live" software developed by the applicant. Alternatively, the HW hardware wallet can be used, via the HDV host device, with decentralized exchange platforms or "DEX", on which the user can carry out transactions while retaining his keys.

[0011] The HW hardware wallets marketed by the applicant have achieved significant commercial success due to the high degree of security they offer, thanks to the use of a secure element to store private keys and sign transactions. A secure element is a hardware platform capable of storing and manipulating data in compliance with the security rules and requirements set by a trusted authority. It takes the form of a semiconductor chip implementing various countermeasures aimed at countering attacks by fraudsters.

[0012] Figure 2 shows the architecture of a hardware wallet HW1 of the type marketed by the applicant under the name “Nano S”. The hardware wallet HW1 comprises a secure element SE1 associated with a microcontroller MCU1. The processor MCU1 comprises a USB interface U1 and acts as a proxy device with respect to the secure element SE1, for communication with an external host device HDV running a companion application (see Fig. 1). The secure element SE1 has its own secure operating system OS (firmware) allowing it to run application programs APP, and integrates a cryptographic coprocessor CRY. The hardware wallet HW1 also comprises a display DISP1 and two buttons B1, B2.

[0013] The DISP1 display and the B1, B2 buttons are managed by the MCU1 microcontroller. These two buttons play an important role in securing certain operations: the user must press both buttons at the same time to indicate their agreement or consent to carry out or finalize these operations.

[0014] Figure 3 illustrates a second HW2 hardware wallet architecture of the type marketed by the applicant under the name “Nano X”, described in more detail in the security information notice “Ledger Nano X Security Target” published on the website of the National Agency for the Security of Information Systems (ANSSI).

[0015] (https: / / www.ssi.gouv.fr / uploads / 2019 / 10 / anssi-cible-cspn-2019_12en.pdf)

[0016] The HW2 hardware wallet includes, like the HW1 wallet, a SE2 secure element, a MCU2 microcontroller equipped with a USB interface U1, a DISP2 screen and two buttons B1, B2. It also includes a BAT battery rechargeable via the USB interface and a BT1 Bluetooth communication interface managed by the microcontroller. As before, the user must press both buttons at the same time to express his agreement or consent when carrying out certain sensitive operations, as indicated in the aforementioned document “Ledger Nano X Security Target”, paragraph 1.2 “Terminology”, line “Consent”: “The security concept of the Ledger Nano X is reinforced by the end user. As soon as a sensitive operation is required, the end user must confirm the operation using the two buttons”.

[0017] Unlike the HW1 hardware wallet, the DISP2 screen and the B1, B2 buttons of the HW2 hardware wallet are managed directly by the SE2 secure element, which provides an additional degree of security in the event of corruption of the MCU2 microcontroller. Thus, the signals received by the SE2 secure element, indicating that the user is simultaneously pressing the two B1, B2 buttons, cannot be falsified by the microcontroller. Similarly, the information presented to the user by the DISP2 screen, for example the amount of a transaction to be validated by the user, cannot be falsified.

[0018] In summary, in a hardware wallet for cold storage of private keys within the meaning of the present application, the microcontroller associated with the secure element does not execute any application program and has the sole function of managing communication peripherals, USB, Bluetooth, etc. as well as other peripherals (battery, battery charger, etc.). All application programs are executed by the secure element.

[0019] There are also DV1 devices whose classic architecture is shown in Figure 4, which include a microcontroller SMCU including a Trust Zone TZ. The Trust Zone TZ can in some cases be associated with a Secure Element SE to which it entrusts the most sensitive operations or cryptographic calculation. The implementation of such a Trust Zone TZ is generally based on the use of two virtual processors associated with hardware access control. This allows the core of an application program to switch between two states, called "worlds", in order to prevent information leakage from the more trusted world to the less trusted world. Each world can operate independently of the other while using the same kernel. Memory and peripherals are then informed of the kernel's operating world and can use it to provide access control to the device's secrets and code.Typically, the SMCU microcontroller runs a so-called "rich" ROS operating system in the less trusted world, and smaller, security-focused code in the more trusted world, to reduce the attack surface. The rich operating system is usually Android.

[0020] This type of device does not need to be connected to a host device to perform operations on the blockchain, and generally contains a WF1 wifi communication interface in addition to U1 USB and BT 1 Bluetooth communication interfaces. Thanks to its rich operating system, it has extensive functionalities and very advanced ergonomics, and in particular includes a large touch screen like those equipped with smart mobile phones. The DV1 device can also, in certain cases, be equipped with mobile telephony circuits and form a fully-fledged mobile phone equipped with a private key storage functionality.

[0021] In practice, and despite the undeniable ergonomic advantages it offers, such a DV1 device is not immune to attack and does not meet the same rigorous security requirements as hardware wallets for cold storage of private keys, which do not have an internet connection and whose microcontroller never executes application programs.

[0022] On the other hand, hardware wallets for cold storage of private keys offer only poor ergonomics, making certain transactions difficult to carry out, due to a small display and the requirement to provide two buttons to validate certain sensitive operations.

[0023] It might therefore be desirable to improve the ergonomics of hardware wallets, without altering the high degree of security they offer.

[0024] Furthermore, some cryptoasset holders use several hardware wallets to store cryptoassets of different types or values. For example, a user may use a first hardware wallet dedicated to managing low-value cryptocurrency accounts, to carry out daily transactions or pay for purchases, a second hardware wallet dedicated to managing high-value cryptocurrency accounts, a third hardware wallet dedicated to managing non-tangible token-type cryptoassets, etc. It may therefore also be desirable to improve the ergonomics of hardware wallets for users who use several of them.

[0025] More generally, it might be desirable to provide improvements applicable to portable electronic devices and in particular to hardware wallets for storing private keys, which improve their ergonomics, or which provide new functionalities, or which improve their performance in terms of Bluetooth communication when they are provided with such means of communication.

[0026] Summary

[0027] Embodiments relate to an electronic device comprising a chassis made of an electrically conductive material, comprising a front face, a rear face, a side wall and an electrically conductive plate on its front face, a radio frequency antenna intended to transmit or receive data in a determined frequency band, and a wireless communication circuit configured to provide a radio frequency signal to the radio frequency antenna. According to the invention, the radio frequency antenna comprises the combination of a closed slot antenna formed in the side wall of the chassis and having a radiation axis substantially perpendicular to the side wall of the chassis, and an open slot parasitic antenna having a radiation axis substantially perpendicular to the radiation axis of the closed slot antenna; the electrically conductive plate forms a first shield against the radiation emitted by the open slot parasitic antenna;the closed slot antenna and the open slot parasitic antenna are configured so that when the chassis is in the open air, the open slot parasitic antenna has a tuning frequency located in the determined frequency band while the closed slot antenna has a tuning frequency located outside the determined frequency band, and when the rear face of the chassis is facing the front face of a similar device or an electrically conductive surface forming a second screen for the radiation emitted by the open slot parasitic antenna, the closed slot antenna has a tuning frequency located in the determined frequency band while the open slot parasitic antenna has a tuning frequency located outside the determined frequency band.;

[0028] According to one embodiment, the closed slot antenna comprises: a longitudinal hole formed in the side wall of the chassis and passing through it, the longitudinal hole comprising first and second longitudinal surfaces facing each other, and means for applying to the first surface of the longitudinal hole a ground potential and applying the radio frequency signal to the second surface of the longitudinal hole, and the open slot parasitic antenna comprises an electrically conductive arm arranged parallel to and proximate to the longitudinal hole, the electrically conductive arm having a free end and an end electrically connected to the side wall of the chassis.

[0029] According to one embodiment, the connected end of the arm is electrically connected to the side wall of the frame near one end of the second surface of the longitudinal orifice receiving the radio frequency signal.

[0030] According to one embodiment, a length and a height of the longitudinal orifice, a length of the electrically conductive arm and an orthogonal distance between the electrically conductive arm and the side wall of the chassis are configuration parameters of the closed slot antenna and the open slot parasitic antenna. The closed slot antenna and the open slot parasitic antenna form a resulting antenna whose gain in the determined frequency band is greater than -5 dB when the chassis of the device is in the open air and remains greater than -5 dB when the rear face of the chassis is facing an electrically conductive surface.

[0031] According to one embodiment, the closed slot antenna and the open slot parasitic antenna are configured such that when the rear face of the chassis faces an electrically conductive surface, the radiation of the closed slot antenna is predominant over the radiation of the open slot parasitic antenna.

[0032] In one embodiment, the length of the longitudinal orifice is close to a quarter of the wavelength of a 2.4 GHz radio frequency signal, or about 30.6 mm to within a few millimeters or tenths of a millimeter to account for the presence of the parasitic open slot antenna. In one embodiment, the chassis is made of an electrically conductive non-magnetic material and includes magnets to magnetically stack the device with a similar device.

[0033] According to one embodiment, the device comprises a radiofrequency signal injector comprising: two substantially parallel flat electrodes connected by a connecting piece, the first electrode bearing on the first surface of the longitudinal orifice and the second electrode bearing on the second surface of the longitudinal orifice, and a compression piece made of a flexible and elastic material, arranged between the two electrodes and exerting on them a separation force which presses the first electrode against the first surface of the longitudinal orifice and presses the second electrode against the second surface of the longitudinal orifice.

[0034] According to one embodiment, the two electrodes have a large contact surface with the surfaces of the longitudinal orifice, the length of which is at least equal to a quarter of the length of said surfaces.

[0035] According to one embodiment, the radiofrequency signal injector comprises electrical conductors and electronic components connecting the first and second electrodes.

[0036] According to one embodiment, the electrically conductive arm comprises, in the extension of its end electrically connected to the side wall of the chassis, a base fixed to the side wall of the chassis, and a projecting contact bearing on a contact surface provided in the side wall of the chassis.

[0037] According to one embodiment, the electrically conductive arm is mounted under elastic bending stress between its base fixed to the side wall of the chassis and the projecting contact resting on the contact surface provided in the side wall of the chassis, the elastic bending stress exerting pressure on the projecting contact resting on the contact surface.

[0038] According to one embodiment, the electrically conductive arm is arranged in a plastic guide piece ensuring the parallelism of the arm relative to the side wall of the chassis. According to one embodiment, the device forms a hardware wallet for the cold storage of cryptographic keys from the blockchain and comprises a microcontroller and a secure element.

[0039] According to one embodiment, the determined frequency band is the Bluetooth band or a Wifi band.

[0040] Embodiments also relate to a method for improving the performance of a radio frequency antenna intended to transmit or receive data in a determined frequency band, the antenna being arranged in an electronic device comprising a chassis made of an electrically conductive material and a wireless communication circuit configured to provide a radio frequency signal to the radio frequency antenna, the chassis comprising a front face, a rear face, a side wall, and an electrically conductive plate on its front face. According to the invention, the radio frequency antenna comprises the combination of a closed slot antenna formed in the side wall of the chassis and having a radiation axis substantially perpendicular to the side wall of the chassis,and an open slot parasitic antenna having a radiation axis substantially perpendicular to the radiation axis of the closed slot antenna; the electrically conductive plate forms a first screen to the radiation emitted by the open slot parasitic antenna; the closed slot antenna and the open slot parasitic antenna are configured so that when the chassis is in the open air, the open slot parasitic antenna has a tuning frequency located in the determined frequency band while the closed slot antenna has a tuning frequency located outside the determined frequency band, and when the rear face of the chassis is facing the front face of a similar device or an electrically conductive surface forming a second screen to the radiation emitted by the open slot parasitic antenna,the closed slot antenna has a tuning frequency located in the determined frequency band while the open slot parasitic antenna has a tuning frequency located outside the determined frequency band. According to one embodiment, the closed slot antenna comprises a longitudinal orifice made in a side wall of the chassis and passing through the latter, the longitudinal orifice comprising first and second longitudinal surfaces facing each other, and means for applying a ground potential to the first surface of the longitudinal orifice and applying the radiofrequency signal to the second surface of the longitudinal orifice, and has a radiation axis substantially perpendicular to the side wall of the chassis, and the open slot parasitic antenna is produced by arranging an electrically conductive arm parallel to the longitudinal orifice and in the vicinity thereof,the electrically conductive arm having a free end and an end electrically connected to the side wall of the chassis.,

[0041] According to one embodiment, the method comprises the step of connecting the end of the arm to the side wall of the frame, near an end of the second surface of the longitudinal orifice receiving the radio frequency signal.

[0042] Summary description of the drawings

[0043] Examples of the implementation of improvements to portable devices will be described in the following without limitation, in relation to the attached figures among which:

[0044] Figure 1 shows typical examples of using a hardware wallet through a host device,

[0045] Figure 2 shows a classic hardware wallet architecture,

[0046] Figure 3 shows another classic hardware wallet architecture,

[0047] Figure 4 shows a typical electronic device architecture providing an average degree of security,

[0048] Figure 5 shows an improved hardware wallet architecture,

[0049] Figure 6 shows the organization of part of the non-volatile memory of the hardware wallet of Figure 5,

[0050] Figure 7 shows examples of using the hardware wallet from Figure 5,

[0051] Figure 8 is a flowchart describing a method for securing certain operations when using the hardware wallet of Figure 5,

[0052] Figure 9 shows an embodiment of the hardware wallet of Figure 5, Figure 10 describes steps for controlling a component shown in Figure 9,

[0053] Figure 11 is a top perspective view of one embodiment of the hardware wallet of Figure 5,

[0054] Figure 12 is a bottom and perspective view of the hardware wallet of Figure 11,

[0055] Figure 13 is a sectional view of the hardware wallet of Figure 11, showing certain constituent elements,

[0056] Figure 14 is another cross-sectional view of the hardware wallet of Figure 11, showing other constituent elements,

[0057] Figure 15 is a top view of a display of the hardware wallet of Figure 11,

[0058] Figure 16 is a top view of a touch module of the hardware wallet of Figure 11,

[0059] Figure 17 is a top view of a protective lens of the hardware wallet of Figure 11,

[0060] Figure 18 shows a cover of the hardware wallet of Figure 11,

[0061] Figure 19 is a cross-sectional view of a magnetically stackable hardware wallet including magnets,

[0062] Figure 20 is a bottom view of the hardware wallet of Figure 19,

[0063] Figure 21 is an exploded bottom view of the hardware wallet of Figure 19,

[0064] Figure 22 is an abstract representation of an arrangement of magnets in the chassis of a portable electronic device,

[0065] Figure 23 shows the dimensions of a magnet,

[0066] Figure 24 is a cross-sectional view of a magnetic stack of hardware wallets,

[0067] Figure 25 is a cross-sectional view of one variation of a magnetically stackable hardware wallet, Figure 26 is a cross-sectional view of another variation of a magnetically stackable hardware wallet,

[0068] Figure 27 shows a magnetic stack of hardware wallets,

[0069] Figure 28 shows an example of a menu displayed by a hardware wallet stacked with other hardware wallets,

[0070] Figure 29 depicts operations executed by a hardware wallet stacked with other hardware wallets,

[0071] Figure 30 is a cross-sectional view of a stack of hardware wallets equipped with sensors,

[0072] Figure 31 describes a method for automatically managing a stack of hardware wallets,

[0073] Figure 32 shows another example of a menu on the screen of a hardware wallet stacked with other hardware wallets,

[0074] Figure 33 depicts a method for manually managing a stack of hardware wallets,

[0075] Figure 34 is an exploded view of a hardware wallet including an antenna,

[0076] Figure 35 is a front view of the hardware wallet of Figure 34 and shows an antenna element,

[0077] Figure 36 is a top view of another antenna element,

[0078] Figure 37 is a bottom view of another antenna element,

[0079] Figure 38 is a sectional view of the hardware wallet of Figure 34,

[0080] Figure 39 is a sectional and perspective view of the hardware wallet of Figure 34,

[0081] Figure 40 is the electrical diagram of the antenna element of Figures 36, 37,

[0082] Figure 41 is the equivalent diagram of a part of the hardware wallet antenna of Figure 34,

[0083] Figure 42 and Figure 43 are bottom and perspective views of the hardware wallet of Figure 34, Figure 44 shows an antenna element present in Figures 42, 43,

[0084] Figure 45 is the equivalent diagram of an antenna present in the hardware portfolio of Figure 34,

[0085] Figures 46, 47 show a property of the antenna of Figure 45 in two different uses,

[0086] Figure 48 shows a stack of two hardware wallets,

[0087] Figure 49A, Figure 49B, Figure 50A and Figure 50B show other properties of the antenna of Figure 45 in two different uses.

[0088] Detailed description

[0089] The following describes improvements applied to hardware wallets for cold storage of private keys. Some improvements are likely to be implemented in all types of portable electronic devices, and therefore have a scope of application extending well beyond the sole creation of hardware wallets.

[0090] Example of a hardware wallet including a touch screen controlled by a secure element

[0091] As mentioned above, a secure element is a hardware platform that implements various countermeasures to counter fraudster attacks. Broadly speaking, this could be:

[0092] - attacks by inspection and / or reverse engineering (polishing, layer removal, thermal imaging, X-rays, scanning electron microscopy),

[0093] - side-channel attacks (analysis of power consumption, electromagnetic radiation, computing time, or any other measurable physical quantity correlated with the value of a secret that the attacker is seeking to discover), or

[0094] - attacks by laser or test probe fault injection (in particular injection of parasitic signals or “glitches” on power supply lines, clock lines or data buses).

[0095] There are many countermeasures included in a secure element. Some are software-based and others hardware-based (code protected against attacks, means of protecting volatile and non-volatile memories, means of masking power consumption, data masking, means of masking the topography of the integrated circuit, voltage, frequency, light, temperature sensors to detect attacks, etc.). In the event of an attack, the operating system of a secure element is designed to initiate defensive actions such as interrupting a calculation in progress, permanently blocking the circuit or self-destructing it by completely erasing its memory.

[0096] Due to the numerous countermeasures they implement, secure elements are complex and expensive to produce. The functionalities they offer are therefore limited, particularly with regard to the number of inputs / outputs they offer. As a result, secure elements are not generally used to control screens, and when they are, as in the “NanoX” product marketed by the applicant, it is to control small screens without any touch function.

[0097] Thus, if we consider the secure elements available on the market and in particular those which offer a security level at least equal to 5 on the Evaluation Assurance Level EAL, corresponding to level E4 of the European ITSEC (Information Technology Security Evaluation Criteria) system and to level B2 of the American TCSEC (Trusted Computer System Evaluation Criteria) system, there is currently no secure element to the applicant's knowledge which has more than 10 inputs / outputs. Indeed, the higher the number of inputs / outputs, the greater the attack surface of a secure element.

[0098] It will be noted here that "inputs / outputs" means 1-bit digital ports that can be used to transmit or receive logic signals, this number of inputs / outputs being less than the number of electrical pins (or "pins") of a secure element, which include, in addition to the input / output pins, power supply pins, ground pins, possibly reset pins, etc.

[0099] In the context of this improvement, however, it was found that it could be possible to manage a touch screen with a secure element. Indeed, a secure element with 10 inputs / outputs can manage the following serial links: 1) an ISO / IEC 7816 link, which only includes three logic signals CLK (clock), I / O (data) and RST (“Reset” or reset);

[0100] 2) an SPI (“Serial Peripheral Interface”) bus which only uses 4 signals:

[0101] - SGLK “Serial Clock” or Serial Clock (generated by the master),

[0102] - MOSI “Master Output, Slave Input” (generated by the master),

[0103] - MISO “Master Input, Slave Output” or “Master Input, Slave Output” generated by the slave), and

[0104] - SS “Slave Select”, or “Slave Selection”;

[0105] 3) an I2C bus (“Inter Integrated Circuit Bus”) which only has two signals:

[0106] - SDA (Serial Data Line): bidirectional data line,

[0107] - SCL (Serial Clock Line): bidirectional synchronization clock line, a total of 9 inputs / outputs required.

[0108] It has also been found that some types of displays and some types of touch modules can be controlled with an SPI bus or an I2C bus. It is also possible to connect a secure element and a microcontroller via an ISO / IEC 7816 smart card link, or an SPI, I2C, USB, and other links.

[0109] Finally, managing a touch screen requires processing an interrupt signal that the touch screen emits each time a touch event is detected. Such an interrupt signal makes it possible to activate a touch event management subroutine. Receiving such a signal therefore requires mobilizing another input / output of a secure element, i.e. 10 inputs / outputs in total. In the context of this improvement, it has therefore been found that the use of a secure element to control a touch screen is not impossible.

[0110] Thus, according to a first improvement, a hardware wallet is provided comprising a touch screen controlled exclusively by a secure element, via one or more serial links. Subject to certain precautions which will be described later, such a touch screen is capable of considerably improving the comfort of the user interface, while meeting the security requirements applicable to hardware wallets. According to the present improvement, the touch screen has a diagonal greater than or equal to 3 inches (i.e. 7.62 cm, one inch being equal to 2.54 cm), but preferably greater than or equal to 3.5 inches (i.e. 8.89 cm), and comprises at least 600 x 400 pixels. In one embodiment, the screen has a diagonal of 3.9 inches (9.906 cm) and offers 670 x 496 pixels.

[0111] Hardware Wallet Hardware Implementation Example

[0112] Figure 5 shows the general architecture of a hardware wallet HW3 according to the present improvement. The device HW3 comprises a secure element SE3, a microcontroller MCU3 and a touch screen TS (“Touch Screen”). The touch screen TS comprises an electronic ink display EID (“E-Ink Display”) and a touch module TM (“Touch Module”). The touch screen TS is under the exclusive control of the secure element SE3. For this purpose, the input / output resources of the secure element SE3 are divided into three input / output groups IOGA, IOGB IOGC. The input / output group IOGA is assigned to the implementation of a bus BS1 connecting the secure element SE3 to the microcontroller MCU3. The IOGB input / output group is assigned to the implementation of a BS2 bus connecting the SE3 secure element to the EID display, and the IOGC input / output group is assigned to the implementation of a BS3 bus connecting the SE3 secure element to the TM touch module.The BS1 bus is for example an IEC / ISO 7816 bus, the BS2 bus is for example an SPI bus and the BS3 bus is an I2C bus. A reverse arrangement could be provided, with a BS2 bus of type I2C and a BS3 bus of type SPI, or another serial link protocol compatible with the resources of the secure element. The SPI bus is managed on the EID display side by a chip integrated in it, for example the UltraChip® UC8177 chip. The I2C bus is managed on the TM touch module side by a chip integrated in it, for example the Goodix® GT1 151 QM chip. The secure element is for example an STMicroelectronics® chip of the ST33K1 M series and the microcontroller an STMicroelectronics® chip of the STM32 series.

[0113] The HW3 device also includes various peripherals controlled by the MCU3 microcontroller, for example:

[0114] - a battery BAT; - a power management PMIC integrated circuit, for example the NXP PCA9420 chip. The PMIC circuit receives a voltage Vat from the battery when it is charged, supplies the voltage Vat to the battery when it needs to be charged, and supplies a regulated supply voltage Vcc to the microcontroller MCU3, the secure element SE3 and the touch screen TS;

[0115] - a QIA antenna for inductive battery charging in accordance with Qi technology (https: / / www.wirelesspowerconsortium.com / qi / ). The QiA antenna is connected to a WCIC (“Wireless Charging Integrated Circuit”) wireless charging integrated circuit, for example the EPIC® 103AHQI01 chip. The WCIC circuit provides a Vqi voltage to the PMIC circuit for battery charging;

[0116] - a USB port U1. The USB port provides the PMIC circuit with a Vusb voltage for battery charging, provides the MCU3 microcontroller with DTu data received from an external device connected to the USB port, and transmits DTu data to the external device;

[0117] - a Bluetooth antenna BTA, receiving a radio frequency signal RFS provided by a BTM circuit for managing Bluetooth communications. Although represented as a separate block from the MCU3 microcontroller, the BTM circuit can be included in the MCU3 microcontroller. The BTM circuit provides DTb data exchanged with an external device via a Bluetooth link or transmits DTb data to the external device via the Bluetooth link.

[0118] The HW3 device therefore has the advantage of having a touch screen exclusively controlled by the SE3 secure element and therefore not susceptible to corruption, including in the event of an attack on the MCU3 microcontroller. The latter does not execute any application program and does not store any of the cryptographic secrets used by the secure element. It only manages the peripherals and operates as a proxy processor with respect to the secure element, transmitting to it the DTb, DTu data received via the communication interface chosen by the user, or by transmitting to the external device DTb, DTu data provided by the secure element. The HW3 device therefore offers no possibility of direct connection to the Internet and remains, despite its touch screen, a hardware wallet for the cold storage of private keys offering a high level of security.The SE3 secure element also includes a MEM memory space comprising a read-only memory area (ROM memory), an electrically erasable and programmable non-volatile memory area (Flash memory) and a volatile memory area (RAM memory). The electrically erasable and programmable non-volatile memory area receives an OS3 operating system of the secure element. This is configured to allow use, by application programs, of the TS touch screen.

[0119] Example of hardware wallet software implementation

[0120] In relation to the example of hardware architecture which has just been described, Figure 6 schematically shows an example of organization of the electrically erasable and programmable non-volatile memory area of ​​the MEM memory space. The MEM memory space comprises an APP area for storing application programs APP1, APP2... APPn and an area receiving the OS3 operating system. The OS3 operating system comprises a PAP (“Privileged Applications”) memory area comprising a DB (“Dashboard”) dashboard of privileged application programs, and an OSMD (“Operating System Modules”) memory area comprising operating system modules. The OSMD memory area comprises:

[0121] - a USINT module for managing the user interface,

[0122] - a PERS module for customizing the device,

[0123] - a CRY cryptography module associated with a cryptography coprocessor integrated into the secure element, or with hardware accelerators for advanced cryptographic functions,

[0124] - an EAA module for the approval and attestation of application programs (“Endorsement and Application Attestation”)

[0125] - an IOM module for managing communication interfaces (“IO Management”)

[0126] The OSMD memory area also comprises, according to the present improvement, a GENG graphics engine (“Graphie Engine”) configured to manage the EID electronic ink display. The GENG graphics engine comprises:

[0127] - preconfigured PG pages, - preconfigured LY forms (“Layout”),

[0128] - preconfigured OB objects, and

[0129] - basic BF forms.

[0130] Access by application programs to the EID display is therefore under the control of the OS3 operating system of the secure element, which first verifies the authenticity and legitimacy of the programs before making the graphics engine available to them.

[0131] The OSMD memory area also comprises, according to the present improvement, a touch module management engine TME ("Touch Management Engine") which provides authorized application programs with the possibility of accessing and interpreting the data emitted by the touch module TM.

[0132] The GENG graphics engine also includes an EVENG event management engine that receives touch information provided by the TME touch engine and looks for correlations with display areas, to distinguish between insignificant user touches on the screen and significant touches.

[0133] In an embodiment that allows for preserving the limited resources of the secure element in terms of RAM, the GENG graphics engine operates without allocating RAM. The image pixels are transferred into a RAM of the display without re-reading them. In another embodiment that can be combined with the previous one, the GENG graphics engine does not manage the preconfigured pages PG, the preconfigured shapes LY ("Layout") and the preconfigured objects OB. Thus, the "work" that the operating system must perform is minimized and is limited to the basic shapes BF, the latter not needing to dynamically create objects. The management of complex shapes is left to the application programs, whose code is designed with preconfigured graphic elements minimizing the operations that the graphics engine must execute.

[0134] Figure 7 illustrates examples of using the HW3 hardware wallet. Since the HW3 hardware wallet cannot connect directly to the Internet, a connection must be established with an HDV host device connected to the Internet (“WB”) and running a CA companion application, for example the “Ledger Live” application (https: / / www.ledger.com / fr / ledger-live). The HW3 device can then interact with the companion software to carry out transactions on the BCN blockchain or on decentralized exchanges (DEX).

[0135] The HW3 hardware wallet is also managed by a transactional black box (HSM) located in a data center, to which the HW3 hardware wallet connects via a secure HTTPS connection. The transactional black box does not store any private keys and only ensures the authenticity of the device, its commissioning, the updating of its operating system, the downloading of certified application programs, etc.

[0136] Embodiment comprising validation of sensitive operations by means of two virtual buttons

[0137] Although the secure use of a touch screen exclusively controlled by the secure element offers certain ergonomic advantages, abandoning the two classic buttons, the simultaneous pressing of which makes it possible to secure certain sensitive operations, could prove detrimental to the security of the device.

[0138] Thus, in one embodiment, the operating system is configured to emulate, by means of the touch screen, the two hardware buttons of the prior art. Figure 8 illustrates by way of example the execution of a sensitive operation in which the user's approval must be secured:

[0139] - in a step S1, the HW3 device connects to the CA companion application or to the HSM module according to the type of operation to be performed, for example performing a transaction or displaying a recovery phrase, via the CA companion application, activating and configuring the device, or downloading an application program via the HSM, etc.

[0140] - at a step S2, the device HW3 initiates the performance of the sensitive operation,

[0141] - in a step S3, the device HW3 displays on the EID display a request for confirmation, by the user, that the sensitive operation must be carried out, and waits for confirmation. The waiting for confirmation comprises a step S31 where the device HW3 displays at least two virtual buttons on the EID display, preferably distant from each other. The buttons can have any or fancy graphics at the designer's discretion. This step is followed by a waiting step S32 where the device HW3 reads in a loop, for a time T, the information provided by the touch module TM. If before the expiry of the time T the device HW3 detects, in a step S33, two simultaneous presses by the user on the two buttons, the device then carries out (or finalizes) the operation in a step S4. If at the end of time T the device HW3 finds, at a step S34, that the user has not validated the operation, the device cancels the operation at a step S5.

[0142] Example of implementation of the hardware portfolio with certain types of peripheral organs imposing specific constraints

[0143] As mentioned above, certified secure elements available on the market only offer a small number of inputs / outputs, generally a maximum of 10 inputs / outputs. Indeed, secure elements are generally intended to be arranged in smart cards or in objects connected to the Internet to secure the Internet of Things, particularly in the field of professional applications. A secure element with only 10 inputs / outputs is therefore not designed to drive a large touch screen (the other electrical pins of a secure element, such as power or ground pins, are not considered as inputs / outputs as mentioned above).

[0144] Thus, in the above, the following usage of secure element resources has been proposed as an example:

[0145] - two inputs / outputs to manage the I2C bus connected to the TM touch module (SDA, SCL signals),

[0146] - four inputs / outputs to manage the SPI bus of the EID display (SCLK, MOSI, MISO, SS),

[0147] - three inputs / outputs to manage the ISO / IEC 7816 bus between the secure element and the microcontroller (I / O, CLK and RST).

[0148] In addition to these 9 inputs / outputs, one input / output of the secure element must be reserved for receiving an interrupt signal emitted by the TM touch module when a touch event is detected, to send the secure element into a touch event processing subroutine. Under these conditions, the 10 inputs / outputs of the secure element are used

[0149] However, in some embodiments, the EID display may include a configuration member to be configured and which is only accessible via a serial link dedicated to this component. As shown in FIG. 9, the EID display may for example comprise an EIDO display module and a WM configuration member of the EIDO display module. The WM configuration member is for example a programmable and electrically erasable non-volatile memory receiving a library of waveforms, which is connected to the EIDO display module by circuitry internal to the latter. The WM configuration member has its own inputs / outputs which are compatible with an SPI bus.

[0150] Since the secure element SE3 must have access to the WM configuration device to program or erase data there, the BS2 bus is used to control both the EIDO display module and the WM configuration device. More specifically, the wires of the BS2 bus that carry the SCLK, MOSI, and MISO signals are connected to both inputs / outputs of the EIDO display module and inputs / outputs of the WM configuration device. The SS signal of the BS2 bus is applied only to a CSEL1 (“Chip Select”) input of the EIDO display module, to which it applies a SEL1 selection signal.

[0151] In summary, the input / output assignment of the SE3 secure element shown in Figure 9 is as follows:

[0152] 1) BS1 bus (ISO / IEC 7816), IOGA input / output groups:

[0153] - an input / output 101 of the secure element SE3 is used to manage the RST signal and is connected to an input / output IOM1 of the microcontroller MCU3,

[0154] - an IO2 input / output of the SE3 secure element is used to manage the CLK signal and is connected to an IOM2 input / output of the MCU3 microcontroller,

[0155] - an IO3 input / output of the SE3 secure element is used to manage the RST signal and is connected to an IOM3 input / output of the MCU3 microcontroller,

[0156] 2) BS2 bus (SPI), IOGB input / output groups: - an IO4 input / output of the SE3 secure element is used to manage the MISO signal and is connected both to an input / output of the EIDO display module and to an input / output of the WM configuration device of the EIDO display module,

[0157] - an IO5 input / output of the SE3 secure element is used to manage the MOSI signal and is connected both to an input / output of the EIDO display module and to an input / output of the WM configuration device of the EIDO display module,

[0158] - an input / output IO6 of the secure element SE3 is used to manage the SCLK signal and is connected both to an input / output of the EIDO display module and to an input / output of the WM configuration device of the EIDO display module, and

[0159] - an input / output IO7 of the secure element SE3 is used to manage the signal SEL1 and is connected only to the input CSEL1 of the display module EIDO, to which it provides the selection signal SEL1,

[0160] 3) BS3 bus (I2C), IOGC input / output groups:

[0161] - an IO8 input / output of the SE3 secure element is used to manage the SCL signal and is connected to an input / output of the TM touch module, and

[0162] - an IO9 input / output of the SE3 secure element is used to manage the SDA signal and is connected to an input / output of the TM touch module,

[0163] 4) Finally, the last input / output 1010 of the secure element SE3 is used to receive the interrupt signal emitted by the touch module TM, designated here by the reference ITR.

[0164] Since both the WM configuration device and the EIDO display module are connected to the same BS2 bus, one must be enabled while the other is disabled, and vice versa, otherwise the secure element cannot communicate with either of them. For this purpose, the WM configuration device also has a CSEL2 (Chip Select) selection input which must receive a SEL2 selection signal.

[0165] It therefore appears in this case that the secure element SE3 does not have enough inputs / outputs to generate the selection signal SEL2 to be applied to the input CSEL2 of the configuration device WM. In one embodiment, a method is implemented to nevertheless be able to control the touch screen by means of the secure element SE3. According to this method, the selection input CSEL2 is controlled by an input / output IOM4 of the microcontroller MCU3, which provides the selection signal SEL2. Indeed, a microcontroller does not generally lack available inputs / outputs, unlike the secure element. The binary value of the signal SEL2 provided by the input / output IOM4 of the microcontroller is controlled by the secure element SE3, which sends commands to the microcontroller for this purpose via the bus BS1. The microcontroller is configured to "slavishly" execute these commands.Preferably, it does not include any application programs that could take control of the IOM4 input / output, other than that necessary to execute commands sent by the secure element.

[0166] An example of a method for controlling the CSEL2 input of the WM configuration device by the secure element SE3, via the MCU3 microcontroller, is described in Figure 10.

[0167] In a step S01, the secure element SE3 sends a command to the microcontroller MCU3 to select the configuration device WM. In a step S02, the microcontroller executes this command and applies the selection signal SEL2 of the configuration device to the input CSEL2 via its input / output IOM4. The value of this signal can be 0 (ground potential) or 1 depending on the specifications provided by the manufacturer of the configuration device WM. In a step S03, the microcontroller confirms to the secure element that the configuration device has been selected. In a step S04, the secure element SE3 establishes communication with the configuration device WM by means of the bus BS2, after having previously deactivated the input CSEL1 of the display module EIDO by means of the signal SEL1. The secure element then performs the intended operation on the configuration device, for example erasing and / or writing data if it is non-volatile memory.Once the operation is complete, the secure element sends to the microcontroller, in a step S05, a command to deselect the configuration device WM. In a step S06, the microcontroller deselects the configuration device WM, then confirms this deselection to the secure element in a step S07. The latter can then reestablish communication with the EIDO display module by means of the bus BS2, after having reselected it via its CSEL1 input by means of the signal SEL1.

[0168] It will be clear to those skilled in the art that the method which has just been described is susceptible to various variants, in particular with regard to the confirmations of execution of commands, which could be optional, and the protocol for transferring commands between the secure element and the microcontroller.

[0169] Also, it will be clear to those skilled in the art that this method can be applied to various other peripheral devices. In one embodiment, the BS2 bus is connected to a third peripheral device in addition to the EIDO display module and the WM configuration device. The secure element selects / deselects this third peripheral device via another input / output of the microcontroller, and can communicate with this peripheral device by means of the BS2 data bus, after having deselecting the EIDO display module and the configuration device.

[0170] Finally, it will be clear to those skilled in the art that this method is capable of various applications and is not limited to the control of a touch screen. It may relate to any circuit structure combining a microcontroller and a secure element, in which the secure element controls a number of peripheral devices greater than the number of peripheral devices that it could control if it had to manage all the inputs or inputs / outputs of such peripheral devices, and in particular their selection inputs.

[0171] Example of a hardware portfolio including a large touchscreen with edge-of-frame display

[0172] Figures 11 and 12 show the chassis 10 of a hardware wallet HW3 produced in accordance with a second improvement. The chassis of the HW3 device is seen from its front face FS in Figure 11 and from its rear face RS in Figure 12. The chassis 10 is here a rectangular-shaped single-piece piece made of machined or die-cast aluminum. It comprises a first longitudinal side wall 101, a second longitudinal side wall 102, a first transverse side wall 103, a second transverse side wall 104, and a plate 105 which covers the entirety of its front face FS. Inside the chassis, the battery BAT and a printed circuit 11 receiving various components of the HW3 device, the architecture of which has been described in relation to Figure 5, can be seen.

[0173] Figures 13 and 14 are sectional views of the HW3 device, rear face RS of the chassis facing upwards. The HW3 device comprises a touch screen 20, previously designated TS, arranged on the front plate 105 of the chassis. The touch screen 20 is obtained by assembling an electronic ink display 21 (figure 15) previously designated EID, covered by a touch module 22 (figure 16) previously designated TM, itself covered by a protective lens 23 (figure 17).

[0174] The display 21 is shown in more detail in Figure 15. It comprises an active area 211 or display area, a painted frame 212, and is manufactured on a flexible substrate 213 using COP (“chip on plastic”) technology. The display is, for example, an organic active matrix electrophoretic display combining the source drivers, the gate drivers, and an integrated circuit controller bonded directly to the display substrate, for example, the UltraChip® UC8177 controller. The display offers 670 x 496 pixels with a pixel pitch of 119 micrometers with 16 gray levels. Its dimensions are, for example, 3.9 inches (9.906 cm) with a total length of 77.4 mm and a total width of 81.7 mm. The dimensions of the active area are, for example, 79.73 x 59.03 mm. The flexible substrate 213 extends beyond the active area 211, and receives a row and column multiplexer 214.It is extended by an SPI bus connector 215 made of a flexible printed circuit, allowing the display 21 to be connected to the printed circuit 11 present in the chassis. The connector comprises auxiliary components 216 and a non-volatile memory 217 receiving a library of waveforms, corresponding for example to the WM configuration member cited in the embodiment of the HW3 device in Figure 9.

[0175] The touch module 22 is shown in detail in Figure 15. It comprises a cover surface 220 and a painted frame 221, the assembly being produced on a flexible support 222 of the FPC (“Flexible Printed Circuit”) type. The cover surface 220 comprises a touch zone 220a and a non-touch zone 220b. The flexible support 222 comprises an extension 224 receiving a chip 225 for controlling the module, for example the Goodix® GT1151 QM chip. The end of the extension 224 receives an I2C bus connector 226 for connecting the touch module 22 to the printed circuit 11 present in the chassis. The touch module has for example a total length of 65.7 mm and a total width of 81.3 mm. The touch area 220a is for example 79.73 x 48.10 mm in area and the non-touch area 220b extends 34.0 beyond this.

[0176] The protective lens 23 is shown in Figure 17. It has a transparent area 230 and a painted frame 231. The lens has for example a total length of 67.9 mm and a total width of 83.7 mm. It includes a moisture protection layer, an anti-reflective hard layer and an optically clear adhesive on its back side for assembling it on the touch module 22. In one embodiment, the lens is designed not to be scratched in the case of stacking the device HW3 with other similar devices HW3-1, HW3-2, which will be described later (Fig. 24).

[0177] In Figures 13 and 14, it appears that the longitudinal side wall 101 of the chassis has a rounded external edge 101 r having a substantially semicircular section, marked by a dotted arrow. The wall 101 , due to its thickness, also has a flat portion in the extension of the plate 105, which forms a portion of the front face FS of the chassis. It also has, after the rounded edge 101 r, a flat portion which forms a portion of the rear face RS of the chassis. The remainder of the rear face of the chassis is closed by a cover 110. It will be further noted that in one embodiment of the cover shown in Figure 18, the cover 110 comprises an antenna coil which is connected to the printed circuit 11 .

[0178] According to the improvement described here, and as seen in Figure 13, the active zone 211 of the display 21 covers:

[0179] - most of the front plate 105,

[0180] - the major part of the flat part of the wall 101 which extends the plate 105 and forms part of the front face of the chassis,

[0181] - the major part of the rounded edge 101 r of the wall 101 , and, optionally,

[0182] - the flat part of the wall 101 which forms part of the rear face of the chassis. The flexible substrate 213 which extends beyond the active zone 211 penetrates inside the chassis to allow the connector 215 of the SPI bus to be fixed on the printed circuit 11, this part of the circuit being hidden by the cover 110.

[0183] Similarly, in Figure 14, the touch module 22, which covers the display 21 and is itself covered by the lens 23, extends over:

[0184] - most of the front plate 105,

[0185] - the major part of the flat part of the wall 101 which extends the plate 105 and forms part of the front face of the chassis,

[0186] - the major part of the rounded edge 101 r of the wall 101 , and, optionally,

[0187] - the flat part of the wall 101 which forms part of the rear face of the chassis.

[0188] The term "major part" means, for example, at least 90% of the area concerned.

[0189] The touch module extension 224 then passes under the cover 110 and enters the chassis to allow the I2C bus connector 226 to be attached to the printed circuit board 11.

[0190] Preferably, the touch-sensitive area 220a of the module 22 covers only the front plate 105 and the flat part of the wall 101 which extends the plate 105 and forms part of the front face of the chassis, while its non-touch-sensitive area 220b covers the rounded edge 101r and the flat part of the wall 101 which forms part of the rear face of the chassis.

[0191] Thus, the TS touchscreen allows the secure element to:

[0192] - to display information on the front of the chassis, and to collect tactile information,

[0193] - to display information on the rounded edge 101 r without the risk of collecting involuntary tactile information, linked to the handling of the chassis by the user.

[0194] The HW3 device, while meeting the rigorous security requirements required by its hardware wallet function, therefore offers remarkable ergonomic advantages usually reserved for moderately secure devices whose screen is not controlled by a secure element, operating under Android or equivalent, with the added possibility of displaying specific information on the edge of the chassis.

[0195] Example of a hardware wallet including magnetic stacking means

[0196] As indicated above, some cryptoasset holders may use multiple hardware wallets to manage cryptoasset accounts of different natures or values, for example, low-value accounts, high-value accounts, non-fungible token or smart contract accounts, etc.

[0197] According to a third improvement which may or may not be combined with the previous improvements, a hardware wallet is provided which can be magnetically stacked with similar hardware wallets.

[0198] More particularly, a hardware wallet is provided comprising at least four magnets arranged so as to magnetically cooperate with four magnets of at least one similar hardware wallet, in order to ensure the magnetic stacking of the hardware wallet with the similar hardware wallet, regardless of which hardware wallet is located above the other.

[0199] In one embodiment, the magnets are arranged asymmetrically to form a magnetic keying feature allowing stacking in which the edges of the hardware wallet chassis are aligned with the same edges of the similar hardware wallet, and in which each magnet faces the corresponding magnet of the similar device.

[0200] Figures 19, 20, 21 show a HW3 device according to this embodiment. Figure 19 is a cross-sectional view, Figure 20 is a top view and Figure 21 is an exploded perspective view of the HW3 device. In Figure 19, the front face FS of the chassis 10 is at the top. In Figures 20 and 21, the chassis is seen from its rear face RS.

[0201] The chassis 10 is here equipped with four magnets M1, M2, M3 and M4 preferably having the same magnetic orientation, for example North oriented towards the front face of the chassis. The magnets M1, M2 are arranged in housings 103-1, 103-2 made in the transverse side wall 103 of the chassis, which extend over substantially the entire thickness of the chassis. The magnets M1, M2 therefore generate a magnetic field on both faces of the chassis.

[0202] The magnets M3, M4 each comprise two superimposed magnets M3a-M3b, and M4a-M4b, as seen in Figure 19. The magnets M3a, M4a are arranged in housings 105-3, 105-4 provided in the front plate 105 of the chassis (Figs. 20, 21), while the magnets M3b, M4b are fixed on the cover 110, opposite the housings 105-3, 105-4, in indentations provided for this purpose in the cover. The magnets M3a and M3b, M4a and M4b are here of a thickness much less than half the thickness of the chassis, and the space which separates them advantageously allows the passage of the printed circuit 11, as seen in Figure 19.

[0203] In the following, magnets M3, M4 will be considered as being monobloc, like magnets M1, M2, their structure in two superimposed magnets not modifying the reasoning set out below.

[0204] The arrangement of the magnets M1, M2, M3, M4 is chosen here so as to form a magnetic keying device when magnetically stacking the device HW3 with a similar device HW3-1, as shown schematically in Figure 24. The intended stacking arrangement is one in which the edges of the frame of the device HW3 are aligned with the same edges of the device HW3-1, and in which each magnet of the device HW3 faces the corresponding magnet of the similar device HW3-1. This arrangement should preferably be unique, so that there is only one magnetic stacking position in which the devices HW3, HW3-1 have their respective edges aligned. In other words, when the stacking arrangements are not identical (e.g. if the devices are arranged head to tail) the devices should not adhere magnetically.The arrangement of the magnets must therefore prevent the devices from being mispositioned, so that the devices do not magnetically attract each other if this is the case.

[0205] For this purpose, and with reference to figures 20, 22, a longitudinal central axis L-L' of the chassis is defined, located midway between the longitudinal lateral edges 101, 102 of the chassis, and a transverse central axis T-T' of the chassis, located midway between the transverse lateral edges 103, 104 of the chassis. The axes L-L' and T-T' define four quadrants Q1, Q2, Q3, Q4 and each magnet is arranged in one of these quadrants. The magnets M1, M2, M3, M4 are arranged asymmetrically relative to the longitudinal central axis L-L' or relative to the transverse central axis T-T'. A combination of these two asymmetries can also be provided, for all or some of the magnets. To formalize this asymmetry more precisely, each magnet M1 , M2, M3, M4 is defined as having a central point cm1 , cm2, cm3, cm4 (cmi), a longitudinal dimension Im1 , Im2, Im3, Im4 (Imi) and a transverse dimension tm1 , tm2, tm3, tm4 (tmi), as shown in Figure 23.

[0206] Furthermore, the following axes and distances are defined, as shown in Figures 20 and 22:

[0207] - L1 -L1 'is a longitudinal axis passing a central point of the magnet M1 and parallel to the longitudinal central axis L-L',

[0208] - 11 is the transverse distance between the axes L1 -L1 ' and L-L',

[0209] - L2-L2' is a longitudinal axis passing a central point of the magnet M2 and parallel to the longitudinal central axis L-L',

[0210] - 12 is the transverse distance between the axes L2-L2' and L-L',

[0211] - L3-L3' is a longitudinal axis passing a central point of the magnet M3 and parallel to the longitudinal central axis L-L',

[0212] - 13 is the transverse distance between the axes L3-L3' and L-L',

[0213] - L4-L4' is a longitudinal axis passing a central point of the magnet M4 and parallel to the longitudinal central axis L-L',

[0214] - 14 is the transverse distance between the axes L4-L4' and L-L',

[0215] - T1 -T1 ' is a transverse axis passing a central point of the magnet M1 and parallel to the transverse central axis T-T',

[0216] - 11 is the longitudinal distance between the axes T1 -TT and T-T',

[0217] - T2-T2' is a transverse axis passing a central point of the magnet M2 and parallel to the transverse central axis T-T',

[0218] - 12 is the longitudinal distance between the axes T2-T2' and TT,

[0219] - T3-T3' is a transverse axis passing a central point of the magnet M3 and parallel to the transverse central axis T-T', - 13 is the longitudinal distance between the axes T3-T3' and T-T',

[0220] - T4-T4' is a transverse axis passing a central point of the magnet M4 and parallel to the transverse central axis T-T', and

[0221] - 14 is the longitudinal distance between the axes T4-T4' and TT, it may be provided, in one embodiment, that at least two magnets have different transverse distances t1 -t4 or longitudinal distances 11 -I4.

[0222] In one embodiment, one of the following design rules or a combination of at least two of these rules is implemented:

[0223] - the transverse distances t1 -t4 are all different from each other,

[0224] - the longitudinal distances 11 -I4 are all different from each other,

[0225] - some transverse distances t1 -t4 are different and some longitudinal distances 11 -14 are different.

[0226] In another even more rigorously asymmetrical embodiment, one of the following rules is added to one of the above rules or to a combination of these rules:

[0227] - the distance between each transverse distance t1, t2, t3, t4 and each of the other transverse distances is at least equal to the sum of the halves of the transverse dimensions tm1, tm2, tm3, tm4 of the corresponding magnets, or

[0228] - the gap between each longitudinal distance 11, I2, I3, I4 and each of the other longitudinal distances is at least equal to the sum of the halves of the longitudinal dimensions Im1, Im2, Im3, Im4 of the corresponding magnets,

[0229] Or, by combining the two rules:

[0230] - the gap between certain transverse distances t1, t2, t3, t4 is at least equal to the sum of the halves of the transverse dimensions tm1, tm2, tm3, tm4 of the corresponding magnets, and the gap between certain longitudinal distances 11, I2, I3, I4 is at least equal to the sum of the halves of the longitudinal dimensions Im1, Im2, Im3, Im4 of the corresponding magnets.

[0231] In the embodiment shown in Figure 20, the center cm2 of the magnet M2 is arranged on the transverse axis T1 -TT of the magnet M1, and the center cm4 of the magnet M4 (M4a, M4b) is arranged on the transverse axis T3-T3' of the magnet M3 (M3a, M3b). The longitudinal distances 11, I2 are equal, as are the longitudinal distances I3, I4, but the longitudinal distances 11, I2 are different from the longitudinal distances I3, I4. Furthermore, the transverse distances t1, t2, t3, t4 are all different, and the smallest differences between the transverse distances, here the differences between the distances t1 and t3 and between the distances t2 and t4, are substantially equal to the sum of the halves of the transverse dimensions of the corresponding magnets, namely M1, M3 on the one hand and M2, M4 on the other. The term "substantially" is here understood to within a few tenths of a millimeter.

[0232] It will be clear to those skilled in the art that the improvement which has just been described is susceptible to various other variants and embodiments. In particular, the magnets M1 and M2 may themselves comprise two superimposed magnets, as illustrated in Figure 25 which shows a variant HW4 of the device equipped with a magnet M1 consisting of a pair of magnets M1a, M1b. Conversely, the magnets M3 and M4 may be monobloc and extend over the entire thickness of the chassis, as illustrated in Figure 26 which shows a variant HW5 of the device equipped with a monobloc magnet M3 identical to the magnet M1. Similarly, the fixing of the magnets in the chassis may use various other means than those which have been described.In particular, the magnets or some of them could be directly fixed to the printed circuit, if the latter is robust enough to withstand the tearing force exerted on each magnet when separating two magnetically stacked chassis. Finally, although this improvement does not require it, the polarities of the magnets could, in certain embodiments, not all be identical. It will also be clear to those skilled in the art that the improvement just described is likely to be applied to any type of portable electronic device that one wishes to stack with a similar device.

[0233] Example embodiment of portable electronic devices having interactive stacking functionality

[0234] The above describes examples of embodiments of devices that can be magnetically stacked in accordance with the third improvement. According to a fourth improvement, stacked devices implement an interactive stacking management method allowing them to be used when they are present in a stack despite the fact that their front screen is no longer accessible.

[0235] For example, a user may own three hardware wallets HW3, HW3-1, HW3-2 and stack them magnetically as shown in Figure 27. The user may want to access their contents or check their status (battery charge, cryptoasset wallets, value of a private key, etc.) without unstacking the stack. The user may also want to use one of the devices by connecting it to an HDV host device to perform a transaction on the BCN blockchain or on a decentralized exchange DEX, or an update or download operation of an application program via an HSM module.

[0236] According to the present improvement, the device at the top of the stack makes its screen available to other devices if the user requests it. This "making available" means that the user can use the screen of the device at the top of the stack to view or operate a device present in the stack.

[0237] For this purpose, the devices communicate with each other by means of a wireless data link. In the case of an HW3 device as described above, this link is, for example, a multipoint Bluetooth link, after prior pairing of the devices, as well as, preferably, their pairing with an HDV host device.

[0238] The organization of data exchanges between stacked devices can be done according to a mesh, chained, or hierarchical communication strategy. In a mesh communication strategy, each device can communicate with any of the other devices. In the example shown in Figure 27, such a strategy involves wireless data links SLNK1, SLNK2, SLNK3 between the devices. In a chained communication strategy, each device can communicate with the device located immediately below or above it in the stack. In the example shown in Figure 27, such a strategy involves wireless data links SLNK1 and SLNK2. In a hierarchical communication strategy, the device at the top of the stack communicates with the devices below it, and two devices inside the stack do not communicate with each other.In this case, only the SLNK1 and SLNK3 links are used in the example in Figure 27.

[0239] Since this improvement is applicable to any type of portable electronic device comprising wireless communication means, in particular Wi-Fi, the choice of a communication strategy may vary depending on the type of wireless data link used. A hierarchical communication strategy may, for example, be preferred in the case of Bluetooth links. A mesh communication strategy may be preferred in the case of Wi-Fi links.

[0240] In one embodiment, the interactive stacking method according to the present improvement assigns each device in the stack one of the following operating modes:

[0241] - an SMO mode, or “Stacked Mode Off”.

[0242] - an SM1 mode, or “Covered” mode

[0243] - an SM2 mode, or “Summit” mode.

[0244] - an SM3 mode, or “Between two” mode.

[0245] In SM1, SM2, SM3 modes, stacked mode is enabled and each mode translates the device position in the stack and corresponds to specific “F” and “E” displays:

[0246] In order to make the best use of the display possibilities offered by the touch screen TS described above, each mode is assigned a display “F” on the front panel (“front” display) and a display “E” on the edge of the device (“Edge” display). The display “E” corresponds, in the embodiment described above, to an information display on the non-touch area of ​​the touch screen TS covering the rounded edge 101 r of the chassis. A display “F” may correspond to one or more different menus, making it possible to manage the stack or to individually manage one of the devices that make up the stack.

[0247] The SMO operating mode corresponds to the normal operating mode of the HW3 device. The HW3 device in SM1 or SM3 mode is covered by another device and therefore could not be used without the method described here. The device in SM2 mode is at the top of the stack and can be used normally since its screen is accessible to the user, but it can also make its screen available to other devices if the user requests it. Prediction of the SM3 operating mode may not be necessary, depending on the needs of interactive stack management. In particular, it may not be necessary to know which devices are at the bottom or in the middle of the stack when the device in the "top" mode addresses each of them.

[0248] The FO display is the usual display presented to the user when using the device with stacked mode disabled. The F1 ("covered") or F3 ("Between") display can be anything since the user does not see the device's screen. It can be no display, an image, or information, for example, "this device is in stacked mode." But it can also be a command, for example, "disable stacked mode," which can be useful if the user breaks stacking without first informing the device at the top of the stack that they wish to disable stacking mode, information that the device will then transmit to the other devices.

[0249] The F2 display may include the prior display of a menu by which the user selects the device he wishes to control by means of the display. An example of such a menu is shown in Figure 28. The user is asked to choose between "this device" or one of the two other devices HW3-1, HW3-2. If the user selects "this device" the F2 display switches to a FO' display which is similar to the FO display with the addition of a return key to enable the user to make a new choice. If the user selects "HW3-1" or "HW3-2" the F2 display switches to a FO" display which is similar to the FO display but with the additional indication that the device in use is not "this device" but the one that has been selected. A return key is also provided to enable the user to make a new choice.

[0250] Thus, operating a device located in the stack by means of the display of the device at the top of the stack may be similar to operating it when stacked mode is disabled, the FO' or FO” displays may include the same menus as the FO display. The user may, for example, choose to connect the device to an HDV host device by means of a data link LNK1, LNK2 or LNK3, to conduct a transaction, as shown in Figure 27.

[0251] The edge displays E0 to E4 are optional but can provide additional user convenience since they are visible even if the devices are stacked. These displays can be the same or different. For example, they can consist of the device name or serial number display. When a device in SM1 or SM3 mode is selected by the device in SM2 mode, the device name or serial number display can become flashing or scrolling instead of remaining fixed.

[0252] Figure 29 describes operations carried out by the device HW3 after being placed in the “top” mode SM2 (Fig. 27). At a step S10, the device HW3 interrogates all the devices present in the stack to identify them. It will be noted that for security reasons, the implementation of these various data links preferably requires prior device configuration steps during which each device is informed of the devices with which it could be stacked. A device that has not been previously declared by the user will therefore not be admitted to a stack. Similarly, it may be provided that the devices HW3, HW3-1, HW3-2 mutually authenticate each other securely using their cryptographic means, before agreeing to communicate with each other.

[0253] In a step S11, the device HW3 presents the list of devices to the user and asks him to make a choice, for example in the aforementioned manner shown in Figure 28. In a step S12, the device HW3 establishes communication or reestablishes communication with the device designated by the user. In a step S13, the device HW3 receives from the selected device information to be displayed and displays it on its touch screen. In a step S14, the device HW3 detects an action of the user on its touch screen and transmits it, in a step S15, to the selected device. This process can continue indefinitely as long as the user uses the selected device, until a step S16 where the user returns to the choice menu (Fig. 28) to select another device or to request that all devices be put into a standby mode.

[0254] The implementation of this interactive stacking management method assumes that each device is able to activate the stacking mode and knows where it is in the stack, to place itself in the corresponding SM1 or SM2 mode, or optionally in SM3 mode. For this purpose, the stacking management method can be implemented automatically or manually.

[0255] In the context of an automatic implementation of the method, each device HW3, HW3-1, HW3-2 is equipped with sensors 108a, 108b, as illustrated in Figure 30. These sensors allow the devices to detect the presence of another device below or above them. If the devices are equipped with magnets, the sensors 108a, 108b may be Hall effect sensors, capable of detecting the presence of a magnet below or above each device. The sensors 108a, 108b may be directly connected to the secure element SE3 as shown in Figure 5, or be connected to the microcontroller MCU3. Various other types of sensors may also be used, such as optical, acoustic, piezoelectric, electromagnetic, thermal, capacitive sensors, etc., especially if the stacked devices do not include magnets.

[0256] In one embodiment, it is not essential for the sensors to be able to identify with certainty that an object detected on or under a device HW3, HW3-1, HW3-2 is a similar device capable of being placed in the stacking mode. This indeterminacy can be lifted by the device in the “top” mode depending on the responses received to its identification requests. Similarly, a device detecting an object placed above it and not receiving any identification request will understand that the object is not a compatible device.

[0257] Figure 31 is a state diagram showing an example of automatic implementation of the interactive stack management method. In this example, the four operating modes SMO, SM1, SM2, SM3 are managed. The device HW3 is by default in the SMO mode. At a step S22, the device detects the presence of a device above it and switches to the SM1 mode, where it waits to be interrogated by the device in the "top" mode. As an alternative, the device detects the presence of a device below it at a step S23 and switches to the "top" mode to interrogate and identify the other devices present in the stack. If the device is in the SM2 mode and detects at a step S24 that a device has been placed above it, it switches to the SM3 mode. Once in the SM3 mode, the device returns to the SM2 mode if, at a step S25, the device on top is no longer detected.Finally, whatever the SM1, SM2, SM3 mode it is in, if the device detects at a step S20 that there is no longer any device above or below it, it automatically returns to SMO mode.

[0258] In a manual implementation of the method, the user accesses a menu for manually activating the stacking mode, an example of which is given in Figure 32. The user first activates the stacked mode, then chooses between the "covered" mode SM1 and the "top" mode SM2. In this example, the SM3 mode is not managed.

[0259] Figure 33 is a state diagram showing an example of manual implementation of the interactive stacking management method. The device HW3 is by default in the SMO mode. At a step S30, the user activates the stacked mode. At a step S31, the user chooses the SM1 or chooses the SM2 mode at a step S32. At any time, the user can return to step S31 or S32 to change the operating mode of the device while modifying its position in the stack. Similarly, at any time the user can, during a step S33, deactivate the stacked mode.

[0260] In an application of the method to hardware wallets of the type described above, the management of the SMO, SM1, SM2 modes, and optionally the SM3 mode, is preferably ensured by the OS3 operating system of the SE3 secure element. For this purpose, an ASM module for automatic stacking management is provided in the operating system as shown in Figure 6. Alternatively, an MSM module for manual stacking management is provided in the OS3 operating system. In certain embodiments, the two modules can coexist, the choice between automatic or manual management being offered to the user. Each of these modules allows the device to place itself in the different operating modes and to operate as these modes require.When SM3 operating mode is not supported, it is included in SM1 mode, which covers the case where the device is at the bottom of the stack and the case where it is in the middle of the stack.

[0261] It will be clear to those skilled in the art that the method according to the present improvement is applicable to any type of portable electronic device comprising wireless communication means, in particular Wi-Fi, and that its scope of application is not limited to hardware wallets for the cold storage of private keys. Similarly, the method is not exclusively linked to the use of magnets for stacking devices, since stacking can be provided without the devices being magnetically held against each other. Also, the method is applicable to devices that do not have a display at the edge of the chassis (display E) and only have a display on the front panel (display F).

[0262] In embodiments, the interactive stack management method may also involve the HDV host device. In this case, the companion software menu includes a "stack management" option allowing the user to select the hardware wallet they want to use to make a transaction (Fig. 27). The hardware wallet at the top of the stack is then informed by the companion software to make its screen available to the selected hardware wallet via the host device.

[0263] Example of the implementation of a self-adaptive Bluetooth antenna with two radiation axes, in particular for a stackable device

[0264] In the above, a hardware wallet equipped with a Bluetooth antenna BTA (Fig. 5) and a touch screen TS has been described. A hardware wallet made of an aluminum chassis and comprising a front face coated with an electrically conductive wall 105 receiving the touch screen TS (Fig. 9) has also been described. Finally, a hardware wallet capable of magnetically stacking with a similar hardware wallet has also been described (Fig. 27) and a method for interactively managing a stack of hardware wallets using wireless communication between the stacked hardware wallets, in particular via Bluetooth links.

[0265] Tests carried out by the applicant with Bluetooth antennas available on the market in the form of integrated components have shown that this type of component is unsuitable for obtaining good quality Bluetooth communication due to the metallic mass that the chassis 10 comprises, in particular the electrically conductive wall 105 which covers the front face of the chassis (Fig. 9). In normal use (HW3 device in the open air), this metallic mass causes a strong attenuation of the gain of these conventional antennas, by acting as a screen (in the sense of shield or shielding) with respect to the electromagnetic field that they emit. A low gain is obtained, not allowing a stable Bluetooth connection to be established.

[0266] The applicant also conducted tests with an inverted-F antenna of the IFA type ('Inverted-F Antenna'), a type of antenna generally used in mobile phones, the antenna being arranged close to the edges of the chassis. A relatively low gain was obtained in normal use (HW3 device not stacked and in the open air), but this did not prevent Bluetooth communication. On the other hand, when two HW3, HW3-1 devices are stacked (for example Figure 30), the device located at the top of the stack sees the gain of its antenna weaken, which can lead to unstable Bluetooth communication.

[0267] It might therefore be desirable to provide an improved radio frequency antenna structure which is usable in particular but not exclusively in a portable electronic device comprising an electrically conductive chassis, and which offers relatively stable performance under two conditions of use, comprising on the one hand use in the open air, and on the other hand use in the presence of an electrically conductive surface, for example when the device is stacked with a similar device.

[0268] According to a fifth improvement, a radiofrequency antenna is provided comprising the combination of a closed slot antenna produced in a side wall of the chassis, having a radiation axis substantially perpendicular to this wall, and an open slot parasitic antenna having a radiation axis perpendicular to the radiation axis of the closed slot antenna. The two antennas are configured - that is to say adjusted - using computer tools for radiofrequency field simulation, taking into account the two aforementioned operating conditions. A resulting antenna is obtained whose performance is substantially homogeneous under these two operating conditions. A detailed example of the production of such an antenna will be described below without limitation.

[0269] Example of the construction of a closed slot antenna

[0270] The main components of one embodiment of a closed slot antenna are shown in the exploded view of Figure 34. The structure of the antenna after assembly is shown in Figures 38, 39, 42, 43. In Figures 34, 39, 42, 43 the chassis 10 is seen in perspective from its rear face RS, the plate 105 being at the bottom. In the sectional view of Figure 38, the plate 105 is at the top. Therefore, the locations or orientations of the components are reversed in Figure 38 compared to the other figures.

[0271] With reference to Figure 34, the closed slot antenna comprises a longitudinal orifice 40 made in a wall of the chassis, here the longitudinal side wall 102. The antenna also comprises a radiofrequency signal injector 50, for applying to the orifice 40 a ground potential and a radiofrequency signal RFS, this signal being provided by the BTM circuit (Fig. 5) arranged on the printed circuit (Fig. 12).

[0272] The longitudinal orifice 40, seen from the front in Figure 35, comprises two longitudinal surfaces 41, 42 facing each other, connected by two lateral surfaces 44, 45, here of substantially rounded shape. It has a length Ls, or length of the longitudinal surfaces 41, 42, and a height Hs. The wall 102 also has a recess 45 which does not pass through it and is not considered to be included in the orifice 40.

[0273] The injector 50 is made from a flexible printed circuit and comprises two electrodes 51, 52. The electrode 51 bears on the surface 41 of the orifice 40 and the electrode 52 bears on the surface 42 of the orifice. The injector 50 also comprises a connecting piece 53 extending between the electrodes 51, 52, and an extension 54 in the extension of the electrode 51. Figures 36, 37 show the injector 50 respectively in a top view and a bottom view. The top view shows the outer face of the injector which is in contact with the surfaces 41, 42. Before its folding, which occurs during its insertion into the orifice 40, the injector is a flat part as seen in these figures. The injector comprises various conductors 500, some being on the surface and others buried.It also includes contact pads Pc1, Pc2, Pc3, Pc4, Pc5, Pc6 for soldering components, here capacitors C1, C2, C3, which participate in the configuration of the closed slot antenna. Finally, the injector 50 includes a connector 540 arranged on the extension 54, allowing it to be connected to the printed circuit in order to receive the ground potential and the RFS radio signal.

[0274] When the injector 50 is arranged in the orifice 40, a compression piece 55 - or spacer - is inserted between the electrodes 51, 52, as seen for example in Figure 38. The compression piece 55 is made of a flexible material such as silicone rubber, and presses the electrodes 51, 52 against the surfaces 41, 42. It will be noted that the electrodes 51, 52 here only cover the edges of the surfaces 41, 42, the outer part of the orifice 40 being obstructed by a non-electrically conductive plug 47 (Fig. 38). The electrodes 51, 52 can be covered with a layer of gold 520 to ensure good electrical contact with the surfaces 41, 42. The latter can also be produced by milling to provide good electrical conductivity, in particular if the aluminum chassis has been previously anodized.

[0275] Advantageously, the electrodes 51, 52 here have a large contact surface with the surfaces 41, 42, the length of the contact surface being at least equal to a quarter of the length Ls of the surfaces 41, 42. They are preferably inserted in the middle of the orifice 40, so that their edges are at the same distance from the walls 44, 45 of the orifice.

[0276] Figure 40 is the electrical diagram of the injector. The connector 540 comprises a plurality of ground contacts 541 connected to the electrode 51 which forms a ground plane (GND). It also comprises a contact 542 receiving the radio frequency signal RFS. The contact 542 is connected to the pad Pc3' by a conductor 500. The capacitor C3 has a first terminal connected to the pad Pc3' and a second terminal connected to the pad Pc3 which is connected to the electrode 51. The capacitor C1 has a first terminal connected to the pad Pc1' and a second terminal connected to the pad Pc1. Capacitor C2 has a first terminal connected to pad Pc2' and a second terminal connected to pad Pc2, which is connected to electrode 51. Conductors 500 connect pad Pc1 to pad Pc3', pad Pc1' to pad Pc2' and to electrode 520.As shown in Figure 41, the surface 42 therefore receives the radiofrequency signal RFS via the capacitor C3, the second terminal of which is connected to the surface 41 via the capacitor C3. The surface 41 is at ground potential and is connected to the surface 42 via the capacitor C2.

[0277] The configuration which has just been described is only exemplary and various other arrangements of components and choices of components participating in the configuration of the antenna may be provided by those skilled in the art.

[0278] Example of the construction of an open slot parasitic antenna

[0279] The main components of an exemplary embodiment of an open slot parasitic antenna are shown in the exploded view of Figure 34. The structure of the antenna after assembly is shown in Figures 42, 43. The open slot parasitic antenna comprises an arm 70 made of an electrically conductive metal, for example stainless steel or mild steel with nickel plating. The arm 70 has a rectangular section of small thickness to be flexible, and a length Lb. It extends along the wall 102 of the chassis, at a distance Db from the opening 40 (Figs. 38), or at a distance Db from the inner edges of the surfaces 41, 42 of the opening 40, in a plane parallel to the plane of the surface 42 (Fig. 38) and close to it.

[0280] The arm 70 has a free end 701 and a captive end 702. The end 702 is wider than the rest of the arm and extends to the wall 102 where it has a projecting contact 71, obtained for example by stamping, which comes to bear on a contact surface 107 made in the wall 102 (Fig. 43).

[0281] The arm 70 also comprises, in the extension of the end 702, a base 703 provided with a hole 704. A screw 705 which passes through the hole 704 is screwed into a threaded orifice 106 (Fig. 34) made on a receiving surface 108 provided in the wall 102 (Figs. 34, 43).

[0282] The arm 70 is fixed to the wall 102 by exerting on it an elastic bending stress between its base 703, which is screwed onto the receiving surface 108, and the projecting contact 71, which bears on the contact surface 107. This stress exerts sufficient pressure on the contact 71 so that the electrical contact between the arm 70 and the surface 107 does not deteriorate over time.

[0283] The electrical contact point of the arm 70 with the wall 102, here the contact surface 107, is preferably close to the surface 42 which receives the RF signal, so that the parasitic antenna is indirectly powered by the radiofrequency signal applied to the closed slot antenna. More particularly, this point is preferably close to the end of the surface 42. It can thus be seen in FIG. 42 that the projecting contact 71 is here close to the lateral surface 44 of the orifice.

[0284] With reference to Figure 34 or Figure 43, the open slot parasitic antenna also comprises a part 80 comprising walls for guiding the arm 70 in order to ensure its parallelism relative to the wall 102. The guide part 80 is also shown in Figure 44. The free end 701 of the arm 70 is shown in two positions: a released position P1 (701) before mounting in the chassis, and a position P2 (701) subjected to the elastic bending stress mentioned above, where the projecting contact 71 resting on the surface 107 forces the arm to occupy a horizontal position.

[0285] Figure 45 is a schematic diagram showing the antenna resulting from the combination of the closed slot antenna and the open slot parasitic antenna. The closed slot antenna comprises the surfaces 41 and 42 of the hole 40, connected by the walls 43, 44. The open slot parasitic antenna comprises the arm 70 connected to the wall 102 by the projecting contact 71 provided on the captive end 702. The closed slot antenna has a radiation axis Y substantially perpendicular to the side wall 102 of the chassis, while the open slot parasitic antenna has a radiation axis X substantially perpendicular to the radiation axis Y, therefore parallel to the side wall 102 and perpendicular to the plane of the chassis 10.

[0286] Example of tuning and optimization of the resulting antenna The closed slot antenna and the open slot parasitic antenna together form a resulting antenna whose dimensioning and tuning parameters must be determined by computer simulations. To do this, the frequency band in which the antenna will be used must first be determined. This could be, for example, the Bluetooth band or the 2.45 GHz Wi-Fi band, with channel widths that may vary depending on the technology chosen.

[0287] In an embodiment offering results which will be described later, these simulations aim at optimizing the antenna in the context of Bluetooth communication, either in a targeted frequency band TFB between a frequency Fmin of 2.4 GHz and a frequency Fmax of 2.483 GHz, to obtain at least one of the following results:

[0288] 1) the gain of the resulting antenna in the targeted frequency band must be greater than -5 dB when the chassis 10 of the HW3 device is in the open air, and must remain greater than -5 dB when the rear face of the chassis is opposite an electrically conductive surface, in particular the plate 105 of the chassis of a similar device HW3-1, HW3-2.

[0289] 2) when the chassis 10 is in the open air, the open slot parasitic antenna must have a tuning frequency located in the target frequency band, and

[0290] 3) when the rear face of the chassis 10 is opposite a metal surface and in particular the front plate 105 of the chassis of a similar device, the closed slot antenna must have a tuning frequency located in the targeted frequency band.

[0291] In other words, depending on the operating conditions, the radiation of the closed slot antenna will be predominant over that of the parasitic open slot antenna or vice versa.

[0292] Among the large number of parameters used to tune the antenna to obtain the desired results, the most important parameters include in particular: - the length Ls of the longitudinal orifice 40, i.e. the length of the closed slot antenna,

[0293] - the height Hs of the longitudinal orifice 40, i.e. the opening of the closed slot antenna,

[0294] - the length Lb of the arm 70, i.e. the length of the open slot parasitic antenna,

[0295] - the distance Db previously described between the arm 70 and the opening 40, i.e. the opening of the open slot parasitic antenna.

[0296] As a starting point for the simulations, the theoretical length of the longitudinal orifice 40 is chosen to be equal to a quarter of the wavelength of a frequency of 2.45 GHz, i.e. 30.6 mm. The tests and simulations lead to a value that is significantly different to within a few millimeters or tenths of a millimeter, due to the presence of the open-slot parasitic antenna, to achieve the objectives mentioned above. Thus, at the end of simulations and tests, the following values ​​were, for example, retained:

[0297] - length Ls of the longitudinal orifice 40: 30 mm;

[0298] - height Hs of the longitudinal orifice 40: 2.1 mm;

[0299] - length Lb of arm 70: 22 mm;

[0300] - distance Db: 1.6 mm.

[0301] It will be clear to those skilled in the art that these values ​​are likely to vary depending on other parameters of the antenna, for example the electronic components embedded in the injector 50 (here the capacitors C1 to C3), the shape of the chassis and the location of the opening on one of its walls, the quantity of metal constituting the chassis, etc.

[0302] Figures 46 and 47 show curves of the return losses of the resulting antenna, obtained with the dimensioning just indicated. Figure 46 shows the curve of the return losses RL1 when the HW3 device is in the open air. Figure 47 shows the curve of the return losses RL2 when the HW3 device is stacked on a similar device HW3-1, as shown in Figure 48. Each curve presents two low values ​​of the return losses, at frequencies which correspond respectively to the tuning frequency FT1 of the closed slot antenna and to the tuning frequency FT2 of the parasitic open slot antenna. More particularly:

[0303] - FT1 a (Fig. 46) is the tuning frequency of the closed slot antenna when the device is in the open air or when the device is under another similar device (e.g., the HW3-1 device in Fig. 48). These two cases are considered similar because the conductive plate 105 forms a screen that makes the antenna insensitive to what is above it;

[0304] - FT1 b (Fig. 47) is the tuning frequency of the closed slot antenna when the device is placed on a metal surface or placed on another similar device (for example the HW3 device in Fig. 48);

[0305] - FT2a (Fig. 46) is the tuning frequency of the open-slot parasitic antenna when the device is in the open air or when the device is located under another similar device (for example the HW3-1 device in Fig. 48). Indeed, in both cases the conductive plate 105 forms a screen which blocks the radiation that the parasitic antenna emits upwards along the X axis, and the presence of metal masses above the device does not modify its properties;

[0306] - FT2b (Fig. 47) is the tuning frequency of the open slot parasitic antenna when the device is placed on a metal surface or placed on another similar device (e.g. the HW3 device in Fig. 48). In this case the conductive plate 105 blocks the radiation emitted downwards by the parasitic antenna, along the X axis.

[0307] The following results are obtained, the tuning frequencies of the closed slot antenna and the open slot parasitic antenna being those for which the lowest reflection losses are obtained:

[0308] Figure 46 (open air):

[0309] - FT1 a = 2.32 GHz or FT 1 a <Fmin

[0310] - FT2a = 2.42 GHz or Fmin <FT2a<Fmax

[0311] Figure 47 (placed on a metal surface or other device):

[0312] - FT1 b = 2.475 GHz, i.e. Fmin <FT1 b<Fmax

[0313] - FT2b = 3.15 GHz or Fmax«FT2b With (for the record):

[0314] - Fmin = 2.4 GHz

[0315] - Fmax = 2.483 GHz

[0316] In the case of Figure 46, the tuning frequency FT1a of the closed slot antenna is "out of band" while the tuning frequency FT2a of the parasitic open slot antenna is in the target frequency band. The radiation of the parasitic open slot antenna is predominant over that of the closed slot antenna.

[0317] In the case of Figure 47, the tuning frequency FT1 b of the closed slot antenna is in the target frequency band while the tuning frequency FT2b of the open slot parasitic antenna is out of band. We see in fact in Figure 48 that the open slot parasitic antenna sees two electromagnetic screens above and below it, along its radiation axis X. The screen above is formed by the wall 105 of the chassis in which it is located, and the screen below is formed by the wall 105 of the chassis of the HW3-1 device. The radiation of the closed slot antenna is therefore in this case predominant over that of the open slot parasitic antenna.

[0318] Finally, Figures 49A and 49B show the gain CG1, CG2 of the resulting antenna when the HW3 device is in the open air, and Figures 50A, 50B show the gain CG3, CG4 of the resulting antenna when the HW3 device is placed on a metal surface or on a similar device HW3-1. More particularly, Figures 49A, 50A show the gain CG1, CG3 of the resulting antenna in the YZ plane, i.e. the plane of the chassis or horizontal plane when the chassis is placed flat. Figures 49B, 50B show the gain CG2, CG4 of the resulting antenna in the vertical plane X-YZ, i.e. a plane perpendicular to the chassis or vertical plane when the chassis is placed flat. In the first case, a gain peak of -1.5 dB is obtained at a horizontal angle of 225 degrees and a vertical angle of 105 degrees. In the second case, we obtain a gain peak of -3.4 dB at a horizontal angle of 90 degrees and a vertical angle of 120 degrees.

[0319] So :

[0320] 1) the gain of the resulting antenna in the targeted frequency band is greater than -5 dB when the chassis of the device is in the open air and remains greater than -5 dB when the rear face of the chassis of the HW3 device is opposite an electrically conductive surface, in particular the plate 105 of the chassis of a similar device HW3-1, HW3-2,

[0321] 2) when the chassis 10 is in the open air, the open slot parasitic antenna has a tuning frequency located in the target frequency band while the closed slot antenna has a tuning frequency located outside the target frequency band, and

[0322] 3) when the rear face of the chassis is opposite a metal surface and in particular the front plate 105 of the chassis of a similar device, the closed slot antenna has a tuning frequency located in the targeted frequency band while the open slot parasitic antenna has a tuning frequency located outside the targeted frequency band.

[0323] In other words, when the resulting antenna is between two conductive plates, it radiates mainly from the side of the chassis, while when the chassis is in the open air, the resulting antenna radiates mainly from the underside of the chassis, which is covered by a plastic cover.

[0324] It will be clear to those skilled in the art that the improvement just described is susceptible to numerous variations and is not limited to the application context in which it was designed. Generally speaking, the combination of a closed slot antenna and an open slot parasitic antenna just described is not linked to the structure of the chassis 10 which has been described in the foregoing and its application is not only reserved for a hardware wallet. Such a combination can be used in various applications and various portable electronic devices, in particular but not exclusively when the conditions of use are such that the metallic environment of the antenna can vary within large proportions.

[0325] It will also be clear to those skilled in the art that the second, third, fourth and fifth improvements, although having been described in the foregoing in relation to the provision of a hardware wallet for the storage of private keys, are independent of each other and may be the subject of separate implementations and various applications other than application to a hardware wallet.

Claims

CLAIMS 1. Electronic device (HW3) comprising: - a chassis (10) made of an electrically conductive material, comprising a front face (FS), a rear face (RS), a side wall (102) and an electrically conductive plate (105) on its front face (FS), - a radiofrequency antenna (40, 50, 70, 102) designed to transmit or receive data in a given frequency band, and - a wireless communication circuit (MCU3) configured to provide a radio frequency signal (RFS) to the radio frequency antenna, characterized in that: - the radiofrequency antenna comprises the combination of a closed slot antenna (40, 50) formed in the side wall (102) of the chassis and having a radiation axis (Y) substantially perpendicular to the side wall (102) of the chassis, and an open slot parasitic antenna (70, 102) having a radiation axis (X) substantially perpendicular to the radiation axis (Y) of the closed slot antenna, - the electrically conductive plate (105) forms a first screen against the radiation emitted by the parasitic open-slot antenna, and - the closed slot antenna and the open slot parasitic antenna are configured so that: - when the chassis (10) is in the open air, the open slot parasitic antenna has a tuning frequency located in the determined frequency band while the closed slot antenna has a tuning frequency located outside the determined frequency band, and - when the rear face (RS) of the chassis (10) is opposite the front face of a similar device (HW3-1, HW3-2) or an electrically conductive surface (105) forming a second screen to the radiation emitted by the open slot parasitic antenna, the closed slot antenna has a tuning frequency located in the determined frequency band while the open slot parasitic antenna has a tuning frequency located outside the determined frequency band.

2. Device according to claim 1, wherein the closed slot antenna comprises: - a longitudinal orifice (40) made in the side wall (102) of the chassis (10) and passing through it, the longitudinal orifice (40) comprising first (41) and second (42) longitudinal surfaces facing each other, and - means (50) for applying to the first surface (41) of the longitudinal orifice (40) a ground potential and applying the radiofrequency signal (RFS) to the second surface (42) of the longitudinal orifice (40), and the open slot parasitic antenna comprises: - an electrically conductive arm (70) arranged parallel to and in proximity to the longitudinal orifice (40), the electrically conductive arm (70) having a free end (701) and an end (702) electrically connected to the side wall (102) of the chassis.

3. Device according to claim 2, wherein the connected end (702) of the arm (70) is electrically connected to the side wall (102) of the frame near one end (44) of the second surface (42) of the longitudinal orifice (40) receiving the radio frequency signal (RFS).

4. Device according to one of claims 2 and 3, in which a length (Ls) and a height (Hs) of the longitudinal orifice (40), a length (Lb) of the electrically conductive arm (70) and an orthogonal distance (Db) between the electrically conductive arm and the side wall (102) of the chassis (10), are configuration parameters of the closed slot antenna and the open slot parasitic antenna, and in which the closed slot antenna and the open slot parasitic antenna form a resulting antenna whose gain in the determined frequency band is greater than -5 dB when the chassis (10) of the device is in the open air and remains greater than -5 dB when the rear face (RS) of the chassis (10) is opposite an electrically conductive surface (105).

5. Device according to one of claims 1 to 4, in which the closed slot antenna and the open slot parasitic antenna are configured so as to that when the rear face (RS) of the chassis (10) is opposite an electrically conductive surface (105), the radiation of the closed slot antenna is predominant over the radiation of the parasitic open slot antenna.

6. Device according to one of claims 4 and 5, in which the length (Ls) of the longitudinal orifice (40) is close to a quarter of the wavelength of a radiofrequency signal (RFS) of frequency 2.4 GHz, or approximately 30.6 mm to within a few millimeters or tenths of a millimeter to take into account the presence of the parasitic open slot antenna.

7. Device according to one of claims 1 to 6, in which the chassis (10) is made of an electrically conductive non-magnetic material and comprises magnets (Mi, M1, M2, M3a, M3b, M4a, M4b) for magnetically stacking the device with a similar device (HW3-1, HW3-2).

8. Device according to one of claims 1 to 7 comprising a radiofrequency signal (RFS) injector (50) comprising: - two substantially parallel flat electrodes (51, 52) connected by a connecting piece (53), the first electrode (51) bearing on the first surface (41) of the longitudinal orifice (40) and the second electrode (52) bearing on the second surface (42) of the longitudinal orifice (40), and - a compression piece (55) made of a flexible and elastic material, arranged between the two electrodes (51, 52) and exerting on them a separation force which presses the first electrode (51) against the first surface (41) of the longitudinal orifice (40) and presses the second electrode (52) against the second surface (42) of the longitudinal orifice (40).

9. Device according to claim 8, in which the two electrodes (51, 52) have a large contact surface with the surfaces (41, 42) of the longitudinal orifice (40) whose length is at least equal to a quarter of the length of said surfaces.

10. Device according to one of claims 8 and 9, in which the radiofrequency signal (RFS) injector (50) comprises electrical conductors (500) and electronic components (C1, C2, C3) connecting the first and second electrodes (51, 52).

11. Device according to one of claims 1 to 10, in which the electrically conductive arm (70) comprises, in the extension of its end (70a) electrically connected to the side wall (102) of the chassis (10), a base (703) fixed to the side wall (108, 102) of the chassis, and a projecting contact (71) bearing on a contact surface (108) provided in the side wall (102) of the chassis (10).

12. Device according to claim 11, in which the electrically conductive arm (70) is mounted under elastic bending stress between its base (703) fixed to the side wall (108, 102) of the chassis and the projecting contact (71) bearing on the contact surface (107) provided in the side wall (102) of the chassis, the elastic bending stress exerting pressure on the projecting contact (71) bearing on the contact surface (107).

13. Device according to one of claims 1 to 12, in which the electrically conductive arm (70) is arranged in a guide piece (80) made of plastic material ensuring the parallelism of the arm relative to the side wall (102) of the chassis (10).

14. Device according to one of claims 1 to 13, forming a hardware wallet for the cold storage of cryptographic keys from the blockchain and comprising a microcontroller (MCU3) and a secure element (SE3).

15. Device according to one of claims 1 to 14, in which the determined frequency band is the Bluetooth band or a Wifi band.

16. Method for improving the performance of a radiofrequency antenna intended to transmit or receive data in a given frequency band, the antenna being arranged in an electronic device (HW3) comprising a chassis (10) made of an electrically conductive material and a wireless communication circuit (MCU3) configured to provide a radiofrequency signal (RFS) to the radiofrequency antenna, the chassis comprising a front face (FS), a rear face (RS), a side wall (102), and an electrically conductive plate (105) on its front face (FS), method characterized in that: - the radio frequency antenna comprises the combination of a closed slot antenna (40, 50) formed in the side wall (102) of the chassis and having a radiation axis (Y) substantially perpendicular to the side wall (102) of the chassis, and an open slot parasitic antenna (70, 102) having a radiation axis (X) substantially perpendicular to the radiation axis (Y) of the closed slot antenna, - the electrically conductive plate (105) forms a first screen against the radiation emitted by the parasitic open slot antenna, - the closed slot antenna and the open slot parasitic antenna are configured so that: - when the chassis (10) is in the open air, the open slot parasitic antenna has a tuning frequency located in the determined frequency band while the closed slot antenna has a tuning frequency located outside the determined frequency band, and - when the rear face (RS) of the chassis (10) is opposite the front face of a similar device (HW3-1, HW3-2) or an electrically conductive surface (105) forming a second screen to the radiation emitted by the open slot parasitic antenna, the closed slot antenna has a tuning frequency located in the determined frequency band while the open slot parasitic antenna has a tuning frequency located outside the determined frequency band.

17. The method of claim 16, wherein - the closed slot antenna comprises a longitudinal orifice (40) formed in a side wall (102) of the chassis (10) and passing through the latter, the longitudinal orifice (40) comprising first (41) and second (42) longitudinal surfaces facing each other, and means (50) for applying to the first surface (41) of the longitudinal orifice (40) a ground potential and applying the radiofrequency signal (RFS) to the second surface (42) of the longitudinal orifice (40), and has a radiation axis (Y) substantially perpendicular to the side wall (102) of the chassis, and - the open slot parasitic antenna is produced by arranging an electrically conductive arm (70) parallel to the longitudinal orifice (40) and close to it, the electrically conductive arm (70) having a free end (701) and one end (702) electrically connected to the side wall (102) of the chassis.

18. The method of claim 17, comprising the step of connecting the end (702) of the arm (70) to the side wall (102) of the frame, near an end (44) of the second surface (42) of the longitudinal orifice (40) receiving the radio frequency signal (RFS).