Biometric hardware wallet and corresponding methods

The biometric hardware wallet enhances security by encrypting secrets with biometric data, ensuring only authentic users can decrypt and use them, thus preventing unauthorized access and fraudulent transactions.

FR3157621A3Active Publication Date: 2025-06-27IDEMIA IDENTITY & SECURITY FRANCE SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023014905
Authority / Receiving Office
FR · FR
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2023-12-21
Publication Date
2025-06-27
Estimated Expiration
2033-12-21

AI Technical Summary

Technical Problem

Existing hardware wallets with biometric sensors are not sufficiently secure, as they can be bypassed, allowing unauthorized access to the stored private keys and crypto-assets.

Method used

A biometric hardware wallet that uses a microcircuit and biometric sensor to acquire and record a user's biometric trait, encrypting a secret (such as a private key) with data specific to the biometric collection and recording procedure, making it impossible to recover the secret without authentic biometric validation.

Benefits of technology

The solution significantly enhances the security of the hardware wallet by ensuring that only the authentic user can decrypt and use the stored secrets, preventing unauthorized access and fraudulent transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Biometric hardware wallet, and corresponding methods The invention relates to a hardware wallet (1), for example a card, comprising a microcircuit (2) and a biometric sensor (4) configured to acquire a biometric trait of a user, for example a fingerprint. The wallet (1) comprises a memory (6) for storing at least one secret (S) in encrypted secret (Sc), and the wallet (1) is configured to collect and record at least one biometric data item from said biometric trait, during a collection and recording procedure. To store said secret in encrypted secret, the wallet (1) is configured to retrieve, at the time of storage, the value (N(s)) of at least one data item (N) related to the collection and recording procedure, and then to encrypt, with said retrieved value (N(s)) at the time of storage, said secret (S) in encrypted secret (Sc).The invention also relates to a method of storing and a method of identifying an operation carried out by such a hardware wallet. Figure for abstract: Fig. 1.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Biometric hardware wallet, and corresponding methods Technical field

[0001] The present invention relates to the field of crypto-asset wallets, and more particularly to hardware wallets configured to allow offline storage of private keys. Prior art

[0002] The use of crypto-assets, such as cryptocurrencies, requires the use of keys, for example private and public, to secure and control access to said crypto-assets. In particular, the keys make it possible to sign transactions, or operations, of crypto-assets, and thus to guarantee the security of the transfers of values ​​carried out. It is therefore crucial to keep the keys, in particular private keys, secure to avoid any unauthorized access to said crypto-assets.

[0003] A cryptoasset wallet is a tool used to store, manage and interact with cryptoassets, for example cryptocurrencies.

[0004] It is known to use so-called software wallets to store private keys online. Software wallets can include mobile applications, desktop software or even online sites, through which it is possible to access keys stored online.

[0005] However, using a software wallet requires trusting the company or organization storing the keys online on behalf of the user, since the user does not hold them himself and can only access them online.

[0006] It is also known to use so-called hardware wallets to store private keys offline. Hardware wallets can thus include physical storage devices, such as USB keys or microcircuit cards, on which it is possible to record the keys.

[0007] However, such hardware wallets must be kept carefully, to avoid their loss or damage, which would prevent the recovery of the keys stored therein. In addition, such hardware wallets are not always sufficiently secure, so that in the event of theft, the third party could freely access and use the keys stored in the hardware wallet to recover the corresponding cryptocurrencies.

[0008] In order to limit the risk of loss of cryptocurrencies in the event of theft, there are hardware wallets including a biometric sensor. Such hardware wallets, generally in the form of a microcircuit card, then require user authentication, during a transaction, via the biometric sensor. Such hardware wallets thus limit the risks of theft or fraud by a third party thanks to biometric authentication of the user. In order to be used, the biometric sensor then requires a prior procedure for collecting and recording the user's biometric trait, such a procedure being able to be repeated throughout the duration of use of the wallet, depending in particular on the successive owners of said wallet.

[0009] However, in the event of circumvention, particularly fraudulent, of validation via the biometric sensor, it remains theoretically possible for third parties to recover and use the keys stored in such a wallet. Statement of the invention

[0010] The present invention aims to solve the various technical problems stated above. In particular, the present invention aims to propose a more robust biometric hardware wallet, with security linked to biometric validation which is reinforced. Furthermore, the present invention also aims to propose a biometric hardware wallet allowing identification of transactions, in the event of bypassing biometric validation.

[0011] Thus, according to one aspect, there is provided a hardware wallet, for example a card, comprising a microcircuit and a biometric sensor configured to acquire a biometric trait of a user, for example a fingerprint. The wallet comprises a memory, preferably in the microcircuit, for storing at least one secret, or code, in encrypted secret, or encrypted code, and the wallet is configured to collect and record at least one biometric data from said biometric trait during a collection and recording procedure.

[0012] To store said secret in encrypted secret, the wallet is configured to retrieve, at the time of storage, the value of at least one data item linked to the collection and recording procedure, then to encrypt, with said value retrieved at the time of storage, said secret in encrypted secret.

[0013] The secret, or code, may be a private key or a seed used to derive one or more private keys. The private key is typically used to sign a transaction, or operation, in a decentralized (and online) digital ledger, for example a transaction involving a crypto-asset, typically a cryptocurrency.

[0014] The data linked to the collection and recording procedure is data specific to the corresponding collection and recording procedure, i.e. the value of such data, when storing a secret in the wallet or when providing a secret by the wallet, is linked to the last collection and recording procedure implemented before said storage or corresponding provision. In other words, the data linked to the collection and recording procedure is configured to change value at each implementation (or each iteration) of the collection and recording procedure. Thus, after each collection and recording procedure, the encryption (and decryption) of the secrets is modified, so as to ensure that the steps of storing and providing the secrets have been carried out with the same biometric trait of the user.

[0015] The data linked to the collection and recording procedure may be a counter of the number of procedures implemented by the biometric sensor, or even a random number initialized at each implementation, or iteration, of the collection and recording procedure, or even a random number derived from the biometric data itself.

[0016] Said value recovered at the time of storage can be used, when encrypting the secret into encrypted secret, as a mask, as an encryption key or as derivation data making it possible to obtain a derived encryption key from a master key.

[0017] Thus, thanks to the hardware wallet according to the invention, the secret to be stored is encrypted with a value specific to the procedure for collecting and recording the biometric trait. The circumvention, in particular fraudulent, of the biometric validation, in particular by implementing a new collection and recording procedure, then does not allow the secret to be recovered by decrypting the encrypted secret, since the value used after bypassing the biometric validation will not be the same as that used during storage. The recovery of the secret therefore requires the authentic implementation of the biometric validation, to allow a decryption which will correspond to the encryption carried out during the storage of said secret.

[0018] Preferably, the secret comprises a signature key for a transaction in a decentralized digital register, in particular online, for example a signature key for a transaction relating to a crypto-asset, typically a cryptocurrency.

[0019] This is more specifically a hardware wallet of crypto-assets, in particular a hardware wallet of crypto-currencies, intended to store the corresponding private keys.

[0020] Preferably, said data linked to the procedure for collecting and recording said at least one biometric data item comprises the number of collection and recording procedures carried out by said wallet.

[0021] Thus, with each new implementation of the collection and recording procedure, the value of the corresponding data is modified, which no longer makes it possible to decrypt the secrets encrypted before this collection and recording procedure.

[0022] The value of the data linked to the collection and recording procedure constitutes a sort of counter of the number of procedures implemented, without necessarily needing to be equal to zero at the start. On the contrary, the value can be initialized to a random number.

[0023] Preferably, the wallet is also configured to provide a decrypted secret, the wallet being configured to recover, at the time of provision, the value of said at least one data item linked to the collection and recording procedure, then to decrypt, with said value recovered at the time of provision, said encrypted secret into decrypted secret.

[0024] In order to recover the secret stored in the hardware wallet, the wallet implements steps that are the opposite of those for storage, namely decryption of the stored encrypted secret, from the value of the data linked to the collection and recording procedure, at the time of provision. Recovering a secret identical to that originally stored in the hardware wallet therefore involves performing the decryption from the same value of the data linked to the collection and recording procedure as that used during encryption, i.e. requires using the same biometric trait. Bypassing the biometric sensor authentication system therefore does not make it possible to recover the secret initially stored in the hardware wallet.

[0025] According to another aspect, there is also provided a method of storage on a hardware wallet, for example a card, said hardware wallet comprising a microcircuit and a biometric sensor configured to acquire a biometric trait of a user, for example a fingerprint. Said method comprises: a procedure for collecting and recording at least one biometric data from said biometric trait, and a step of storing, preferably in the microcircuit, at least one secret in encrypted secret.

[0026] The storage step comprises a step of recovering the value, at the time of storage, of at least one piece of data linked to the collection and recording procedure, then a step of encrypting, with said value recovered at the time of storage, said secret into encrypted secret.

[0027] Preferably, the secret comprises a signature key for a transaction in a decentralized digital register, for example a signature key for a transaction relating to a crypto-asset, typically a cryptocurrency.

[0028] Preferably, the method also comprises a step of counting the number of collection and recording procedures carried out by said wallet, and the recovery step uses said number of collection and recording procedures carried out by said wallet to obtain said at least one piece of data linked to the collection and recording procedure.

[0029] Preferably, the method also comprises a step of providing a decrypted secret, the providing step comprising a step of recovering the value, at the time of providing, of said at least one data item linked to the collection and recording procedure, then a step of decrypting, with said value recovered at the time of providing, said encrypted secret into decrypted secret.

[0030] Preferably, said value of said at least one data item linked to the collection and recording procedure is used, when encrypting the secret into an encrypted secret or when decrypting the encrypted secret into a decrypted secret, as a mask, as an encryption / decryption key, or as derivation data making it possible to obtain a derived encryption / decryption key from a master key.

[0031] According to another aspect, there is also provided a method of identifying an operation carried out by a wallet as described above, said operation having been carried out with the decrypted secret provided after a collection and recording procedure, in which: - we recover the said secret from the wallet, then - several decrypted secrets are determined by encrypting said recovered secret with one or more possible values ​​for said at least one data item linked to the collection and recording procedure, then by decrypting with one or more other possible values ​​for said at least one data item linked to the collection and recording procedure, then - identifying, among said determined decrypted secrets, a determined decrypted secret corresponding to said decrypted secret used by said wallet to carry out said operation.

[0032] In other words, the present invention relates to a method for identifying a user of a wallet as described above, the wallet having used a decrypted secret for at least one operation after having implemented a collection and recording procedure, in which the secret is recovered, then said decrypted secret is determined with the recovered secret and a value different from that recovered at the time of storage, then said at least one operation using said decrypted secret is identified with said determined decrypted secret.

[0033] This identification is not made by the hardware wallet, which does not know that the decrypted secret is erroneous, but is obtained separately from the hardware wallet, for example by observing the decentralized digital register of operations, in particular using a separate device. In particular, the recovered secret can be provided directly by the user who has lost or had his hardware wallet stolen, from another backup for example.

[0034] From the secret, it is then possible to obtain several decrypted secrets determined by different combinations of values ​​of the data linked to the collection and recording procedure. It is then sufficient to compare such determined decrypted secrets with those used during failed transactions, to find the determined decrypted secret corresponding to that used by the unauthorized third party and, subsequently, to identify the corresponding transaction(s).

[0035] In particular, it is then understood that the unauthorized third party, having carried out a new collection and recording procedure, will be able to obtain a decrypted secret through said wallet, but that this will not allow him to carry out the desired transaction since the decrypted secret will not correspond to the secret initially stored in the wallet. Conversely, such a decrypted secret will be able to be identified, from the initial secret provided by the owner of the wallet, to identify the transactions attempted by the unauthorized third party. Brief description of the drawings

[0036] [Fig.l] [Fig.l] schematically represents a hardware wallet according to the present invention;

[0037] [Fig.2] [Fig.2] represents a flowchart of a storage method on a hardware wallet as illustrated in [Fig.l]; and

[0038] [Fig.3] [Fig.3] represents a flowchart of a method for identifying a transaction performed with a hardware wallet as illustrated in [Fig.l]. Description of the embodiments

[0039] [Fig.l] schematically illustrates an example of a hardware wallet 1 according to the present invention. The hardware wallet 1 is a biometric hardware wallet, and notably comprises a microcircuit 2, a biometric sensor 4 and a memory 6, for example integrated in the microcircuit 2. The hardware wallet 1 may for example be in the form of a biometric microcircuit card. The hardware wallet 1 may for example be configured to communicate with a network 100, for example with a decentralized (online) digital ledger which records all transactions, or operations, linked to one or more crypto-assets.

[0040] The microcircuit 2 is configured, on the one hand, to receive, encrypt and store in the memory 6 one or more secrets S of the user, and, on the other hand, to provide said secret or secrets previously stored in the memory of the microcircuit 2. The secret or secrets S may be, for example, a private key or a seed used to derive a private key or several private keys. The private key is typically used to sign a transaction, or operation, in a decentralized (and online) digital register, for example a transaction relating to a crypto-asset, typically a cryptocurrency.

[0041] The biometric sensor 4 is intended to add additional protection to the hardware wallet 1 which can, via the biometric sensor 4, perform an authentication of a biometric trait of the user to validate an operation of retrieving the secret contained in the hardware wallet 1. The biometric trait can for example be a fingerprint, and the biometric sensor 4 be a fingerprint reader. Furthermore, and as will be described below, the hardware wallet 1 is configured to require the use of the same biometric trait when storing and providing a secret, in order to provide a secret identical to that initially stored.

[0042] In order to protect the secret S stored in the hardware wallet 1, it is encrypted before being recorded in the memory 6. Thus, the microcircuit 2 comprises an encryption means 8 configured to receive the secret S as input and to provide an encrypted secret Sc as output to the memory 6.

[0043] It should be noted that the secret S received as input by the encryption means 8 may have been previously generated by the hardware wallet 1, for example by random selection. Alternatively, the secret S received as input by the encryption means 8 may have been previously received by the hardware wallet 1 from an external device (not shown) or a person (not shown) via a communication interface (not shown) of the hardware wallet 1.

[0044] Similarly, to be able to recover, at output, the initial secret S, the hardware wallet 1 also comprises a decryption means 10 receiving at input the encrypted secret Sc recorded in the memory, as well as possibly a confirmation of an authentication of the user via the biometric sensor 4, and providing at output a decrypted secret Sd which is identical to the secret S when the hardware wallet 1 is used authentically by the user.

[0045] However, the recording, in particular fraudulent, of a new biometric trait with the biometric sensor 4 could potentially lead to a validation during decryption by the decryption means 10 even though the biometric trait authenticated during decryption is different from that used during storage. In order to avoid such an eventuality, and in order to increase the robustness of the hardware wallet 1, the encryption 8 and decryption 10 means are also configured to use data linked to the collection and recording of a biometric trait.

[0046] More precisely, to allow the use of the biometric sensor 4 by the user, it is necessary for the latter to first record at least one biometric trait, for example at least one fingerprint, so that it is recorded and used during a subsequent authentication step.

[0047] The hardware wallet 1 thus comprises a collection and recording means 12 receiving as input the biometric trait from the biometric sensor 4, and configured to authenticate said biometric trait, in particular during an operation of providing a secret S. It is the collection and recording means 12 which provides the decryption means 10 with confirmation of an authentication of the user by the biometric sensor 4.

[0048] In order to perform such authentication, the collection and recording means 12 firstly retrieves the user's biometric trait, in the form of one (or more) biometric data, and records it as reference biometric data. It is this biometric data that will then be used as reference data during the subsequent use of the biometric sensor 4 by the user, to authenticate an operation. Such retrieval and recording of biometric data is done during a collection and recording procedure during which the biometric trait is provided to the collection and recording means 12 so that the latter can determine a reference biometric data therefrom and record it. This collection and recording procedure is performed during the first use of the hardware wallet 1, by the user, in order to be able to be recognized subsequently with the biometric sensor 4.

[0049] The collection and recording means 12 is also configured to perform a new collection and recording procedure at any time, upon request of the user, to record a new biometric trait. Such a new procedure takes place in particular when the hardware wallet changes ownership, so that the new user can authenticate the operations he wishes to carry out with his hardware wallet.

[0050] In order to ensure that the user authenticating at the time of providing the secret stored in the hardware wallet 1 is indeed the same as the one who initially stored the secret, the encryption 8 and decryption 10 means are configured to use, during encryption and decryption, data N linked to the collection and recording procedure implemented by the collection and recording means 12.

[0051] Thus, the microcircuit 2 can comprise a means 14 for determining such data N, for example a counter of the number N of collection and recording procedures implemented by the collection and recording means 12. The collection and recording of a new biometric trait by the hardware wallet 1 will therefore result in the incrementation of the number N by the counter.

[0052] Furthermore, the hardware wallet 1 also comprises means 16, 18 for recovering the value of the data determined by the determination means 14. The recovery means 16, 18 each receive, as input, the value provided by the determination means 14 of the data N linked to the collection and recording of a biometric trait. The recovery means 16 is associated with the encryption means 8 and is configured to recover the value of the data N(s) at the time of storage, while the recovery means 18 is associated with the decryption means 10 and is configured to recover the value of the data N(f) at the time of provision.

[0053] The value N(s) of the data N at the time of storage is then used by the encryption means 8 to encrypt the secret S into an encrypted secret Sc. Said value N(s) can then be used, during encryption, as a mask, as an encryption key or as a derivation data item making it possible to obtain a derived encryption key from a master key.

[0054] The value N(f) of the data N at the time of provision is used by the decryption means 10 to decrypt the secret Sc into decrypted secret Sd. Said value N(f) is used, during decryption, in a similar manner to the value N(s) during encryption.

[0055] To be able to recover a decrypted secret Sd which is identical to the secret S initially recorded in the hardware wallet 1, it is therefore necessary that the values ​​N(s) and N(f) are identical. If this is not the case, then the decrypted secret Sd will be different from the initial secret S, and will therefore not allow the desired operation to be validated. To have the same values ​​N(s) and N(f), it is therefore necessary that no collection and recording procedure has been carried out between the storage and the provision of the secret S by the hardware wallet 1. The means 14 for determining the data item N linked to the collection and recording procedure makes it possible to change the value of such data item N at each iteration of the collection and recording procedure, and therefore to modify the encryption and decryption steps implemented, in the hardware wallet 1, by the means 8, 10.

[0056] Thanks to the hardware wallet 1 described above, it is therefore possible to ensure that a secret stored in the memory 6 cannot be recovered after the implementation of a collection and recording procedure.

[0057] It should be noted that the decrypted secret Sd obtained at the output of the decryption means 10, can be provided to an external device (not shown) or to a person (not shown) via a communication interface (not shown) of the hardware wallet 1. Alternatively, the decrypted secret Sd obtained at the output of the decryption means 10, can be used directly by the hardware wallet 1, thanks to an operation means (not shown) integrated in the hardware wallet 1 and configured to carry out a transaction, or an operation, with the decrypted secret Sd, for example configured to sign a transaction, or an operation, in a decentralized digital register, particularly online.

[0058] [Fig.2] illustrates a flowchart of a method 20 for storage on a hardware wallet 1 as described previously.

[0059] In a first step 22, the value N(s) is recovered, at the time of storage, of the data N linked to the collection and recording procedure. Then, in a second step 24, the secret S is encrypted into encrypted secret Sc, with said value N(s) recovered at the time of storage, and the encrypted secret Sc is recorded in a third step 26.

[0060] In a fourth step 28, the value N(f) is recovered, at the time of provision, of the data N linked to the collection and recording procedure. Then, in a fifth step 30, the encrypted secret Sc is decrypted into decrypted secret Sd, with said value N(f) recovered at the time of provision.

[0061] We therefore obtain, at the end of the method 20, a decrypted secret Sd which is identical to the secret S if the values ​​N(s) and N(f) of the data linked to the collection and recording procedure are identical, that is to say if the biometric trait recorded in the hardware wallet 1 is the same at the time of storage and at the time of provision of the secret.

[0062] If a collection and recording procedure has been carried out between the storage and the provision of the secret, then the value N(f) will be different from the value N(s), which will lead to a decrypted secret Sd different from the initial secret S. However, the hardware wallet 1 will not warn the user of such a difference, but will instead provide an erroneous decrypted secret Sd which will have the characteristics of an authentic secret but which will not authenticate the desired operation. Thus, the hardware wallet 1 makes it possible to prevent its fraudulent use to recover stored secrets. However, the hardware wallet 1 can also make it possible to identify the operation using the erroneous decrypted secret, or even to identify the person who used the erroneous decrypted secret Sd.

[0063] [Fig. 3] illustrates an example of a method 32 for identifying an operation carried out with the decrypted secret Sd provided after a collection and recording procedure, i.e. with an erroneous decrypted secret Sd as mentioned above. Such a method may in particular be implemented by a device 110 distinct from the hardware wallet 1, preferably independent of the hardware wallet 1, and configured to communicate with the network 100, for example with the decentralized (online) digital ledger which records all the transactions, or operations, linked to one or more crypto-assets of the hardware wallet 1.

[0064] In a first step 34, the secret S is recovered. This can be done by the authentic user of the hardware wallet 1 who, for example after the theft or loss of his hardware wallet 1, contacts the organization managing said hardware wallet 1 to report the theft or loss, and who at the same time provides the secret(s) S stored in the hardware wallet 1 at the time of the theft or loss, in order to be able to trace the activities carried out with his hardware wallet 1.

[0065] In a second step 36, several decrypted secrets Sdij are determined, obtained with a possible value at the time of storage (for example a value i), different from that at the time of provision (for example a value j). Several decrypted secrets Sdij are thus obtained corresponding to the different possible combinations of values ​​(i, j).

[0066] Then, in a third step 38, among said determined decrypted secrets Sdij, the determined decrypted secret Sd is identified, which corresponds to the erroneous decrypted secret Sd used by the wallet to carry out an operation. It is thus possible to find the various operations carried out, without success, with the hardware wallet 1, in order to then recover other information relating to these operations, or even to the person at the origin of these operations.

[0067] It is therefore understood that, for the implementation of said method 32 for identifying an operation, the data N linked to the collection and recording procedure is preferably deterministic data, preferably a counter of the number of procedures implemented by the biometric sensor 4, initialized to a predetermined value which may be different from zero. It is thus possible to limit the number of possible combinations for the values ​​of said deterministic data N, and consequently to limit the number of determined decrypted secrets Sdij.

[0068] Thus, not only does the hardware wallet 1 make it possible to reduce the risk of fraudulent use of the secrets stored therein, but it also makes it possible to identify, using a device 110 independent of the hardware wallet 1, the operations which have been carried out, unsuccessfully, by it, and to be able to recover information, or even the identity, of the person at the origin of the fraudulent use of the hardware wallet 1.

[0069] Thus, thanks to the present invention, it becomes possible to strengthen the robustness of a biometric hardware wallet by using data linked to biometric authentication to encrypt and decrypt the secrets stored in the hardware wallet. It therefore becomes more difficult to recover the secrets when the provisioning step is not carried out by the same person who previously carried out the step of storing said secrets. Furthermore, in the event of fraudulent use of the hardware wallet, It remains possible to identify attempted fraudulent operations with the secrets provided by the said hardware wallet, in order to possibly identify the person who carried out the fraudulent operations.

Claims

Claims

1. Hardware wallet (1), for example a card, comprising a microcircuit (2) and a biometric sensor (4) configured to acquire a biometric trait of a user, for example a fingerprint, wherein the wallet (1) comprises a memory (6), preferably in the microcircuit (2), for storing at least one secret (S) in encrypted secret (Sc), wherein the wallet (1) is configured to collect and record at least one biometric data item from said biometric trait during a collection and recording procedure, characterized in that, to store said secret in encrypted secret, the wallet (1) is configured to retrieve, at the time of storage, the value (N(s)) of at least one data item (N) linked to the collection and recording procedure, then to encrypt, with said value (N(s)) retrieved at the time of storage, said secret (S) in encrypted secret (Sc).

2. Wallet (1) according to claim 1, in which the secret (S) comprises a signature key of a transaction in a decentralized digital register, for example a signature key of a transaction relating to a crypto-asset, typically a cryptocurrency.

3. Wallet (1) according to claim 1 or 2, wherein said data (N) related to the procedure of collecting and recording said at least one biometric data comprises the number of collection and recording procedures carried out by said wallet.

4. Wallet (1) according to any one of the preceding claims, wherein the wallet (1) is also configured to provide a decrypted secret (Sd), the wallet (1) being configured to retrieve, at the time of provision, the value (N(f)) of said at least one data item (N) linked to the collection and recording procedure, then to decrypt, with said value (N(f)) retrieved at the time of provision, said encrypted secret (Sc) into decrypted secret (Sd).

5. Method (20) of storage on a hardware wallet (1), for example a card, said hardware wallet comprising a microcircuit (2) and a biometric sensor (4) configured to acquire a biometric trait of a user, for example a fingerprint, said method comprising: - a procedure for collecting and recording at least one biometric data item from said biometric trait, - a step of storing, preferably in the microcircuit (2), at least one secret (S) in encrypted secret (Sc), characterized in that the storage step comprises a step (22) of recovering the value (N(s)), at the time of storage, of at least one data item (N) linked to the collection and recording procedure, then a step (24) of encrypting, with said value (N(s)) recovered at the time of storage, said secret (S) in encrypted secret (Se).

6. Method (20) according to the preceding claim, in which the secret (S) comprises a signature key of a transaction in a decentralized digital register, for example a signature key of a transaction relating to a crypto-asset, typically a cryptocurrency.

7. Method (20) according to claim 5 or 6, also comprising a step of counting the number of collection and recording procedures carried out by said wallet, and wherein the retrieval step (22) uses said number of collection and recording procedures carried out by said wallet (1) to obtain said at least one data (N) linked to the collection and recording procedure.

8. Method (20) according to any one of claims 5 to 7, also comprising a step of providing a decrypted secret (Sd), the providing step comprising a step (28) of recovering the value (N(f)), at the time of providing, of said at least one data item (N) linked to the collection and recording procedure, then a step (30) of decrypting, with said value (N(f)) recovered at the time of providing, said encrypted secret (Sc) into decrypted secret (Sd).

9. Method (20) according to any one of claims 5 to 8, in which said value of said at least one data item (N) linked to the collection and recording procedure, is used as a mask or as an encryption / decryption key.

10. Method (32) for identifying an operation carried out by a wallet (1) according to claim 4, said operation having been carried out with the decrypted secret (Sd) provided after a collection and recording procedure, in which: - said secret (S) is recovered from the wallet (1), then - several decrypted secrets (Sdi j) are determined by encrypting said recovered secret (S) with one or more possible values ​​for said at least one data item linked to the collection and recording procedure, then by decrypting with one or more other possible values ​​for said at least one data item linked to the collection and recording procedure, then - a determined decrypted secret (Sd) corresponding to said decrypted secret (Sd) used by said wallet (1) to carry out said operation is identified from among said determined decrypted secrets (Sdij).