Biometric hardware wallet, and related processes
The biometric hardware wallet encrypts private keys with procedurally changing encryption keys based on biometric authentication, bolstering security against theft and enabling transaction identification, addressing vulnerabilities in existing hardware wallets.
Patent Information
- Application Number
- FR2023014905
- Authority / Receiving Office
- FR · FR
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2033-12-21
AI Technical Summary
Existing hardware wallets, including those with biometric sensors, are vulnerable to theft and fraudulent circumvention, allowing unauthorized access to crypto-assets, and lack robust security measures to prevent unauthorized use of stored private keys.
A biometric hardware wallet that encrypts private keys with data specific to the biometric authentication procedure, ensuring that each authentication step modifies the encryption key, making it impossible to recover the keys without authentic biometric validation, and includes a method to identify fraudulent transactions using independent ledger analysis.
Enhances security by preventing unauthorized access to crypto-assets and allows identification of fraudulent transactions, thereby safeguarding the integrity of stored private keys and user identity.
Smart Images

Figure 00000016_0000 
Figure 00000016_0001 
Figure 00000017_0000
Abstract
Description
Title of the invention: Biometric hardware wallet, and corresponding methods. Technical field
[0001] The present invention relates to the field of crypto-asset wallets, and more particularly to hardware wallets configured to allow offline storage of private keys. Previous technique
[0002] The use of crypto-assets, such as cryptocurrencies, requires the use of keys, for example private and public keys, to secure and control access to said crypto-assets. In particular, keys allow crypto-asset transactions, or operations, to be signed, and thus guarantee the security of the value transfers carried out. It is therefore crucial to keep the keys, especially private keys, secure to prevent any unauthorized access to said crypto-assets.
[0003] A crypto-asset wallet is a tool used to store, manage and interact with crypto-assets, for example cryptocurrencies.
[0004] It is known to use so-called software wallets to store private keys online. Software wallets can include mobile applications, desktop software, or even online sites, through which it is possible to access one's keys stored online.
[0005] However, the use of a software wallet requires trust in the company or organization storing the keys online on behalf of the user, since the user does not own them and can only access them online.
[0006] It is also known to use so-called hardware wallets to store private keys offline. Hardware wallets can thus include physical storage devices, such as USB keys or microcircuit cards, on which the keys can be stored.
[0007] However, such hardware wallets must be carefully maintained to prevent their loss or damage, which would prevent the recovery of the keys stored within them. Furthermore, such hardware wallets are not always sufficiently secure, so that in the event of theft, a third party could freely access and use the keys stored in the hardware wallet to recover the corresponding cryptocurrencies.
[0008] To limit the risk of cryptocurrency loss in case of theft, there are, in particular, hardware wallets incorporating a biometric sensor. Such hardware wallets, generally in the form of a microcircuit card, then require User authentication during a transaction is performed via a biometric sensor. Such hardware wallets thus limit the risks of theft or fraud by a third party through biometric user authentication. To be usable, the biometric sensor requires a prior procedure to collect and record the user's biometric data; this procedure may be repeated throughout the wallet's lifespan, depending on factors such as successive owners.
[0009] However, in the event of circumvention, particularly fraudulent circumvention, of the validation via the biometric sensor, it remains theoretically possible for third parties to retrieve and use the keys stored in such a wallet. Description of the invention
[0010] The present invention aims to solve the various technical problems mentioned above. In particular, the present invention aims to provide a more robust biometric hardware wallet with enhanced biometric validation security. Furthermore, the present invention also aims to provide a biometric hardware wallet that allows for transaction identification in the event of a biometric validation bypass.
[0011] Thus, according to one aspect, a hardware wallet, for example a card, is proposed, comprising a microcircuit and a biometric sensor configured to acquire a biometric trait of a user, for example a fingerprint. The wallet includes memory, preferably in the microcircuit, for storing at least one secret, or code, in encrypted form, and the wallet is configured to collect and record at least one biometric data point from said biometric trait during a collection and recording procedure.
[0012] To store said secret as an encrypted secret, the wallet is configured to retrieve, at the time of storage, the value of at least one piece of data related to the collection and recording procedure, and then to encrypt, with said value retrieved at the time of storage, said secret as an encrypted secret.
[0013] The secret, or code, may be a private key or a seed used to derive one or more private keys. The private key is typically used to sign a transaction, or operation, in a decentralized (and online) digital ledger, for example, a transaction involving a crypto-asset, typically a cryptocurrency.
[0014] The data related to the collection and recording procedure is data specific to the corresponding collection and recording procedure; that is to say, the value of such data, when a secret is stored in the wallet or when a secret is provided by the wallet, is linked to the last collection and recording procedure implemented before said storage or corresponding provision. In other words, the data linked to the collection and recording procedure is configured to change value with each implementation (or iteration) of the collection and recording procedure. Thus, after each collection and recording procedure, the encryption (and decryption) of the secrets is modified to ensure that the secret storage and provisioning steps were performed with the same biometric user trait.
[0015] The data related to the collection and recording procedure can be a counter of the number of procedures implemented by the biometric sensor, or a random number initialized at each implementation, or iteration, of the collection and recording procedure, or a random number from the biometric data itself.
[0016] Said value retrieved at the time of storage can be used, when encrypting the secret into an encrypted secret, as a mask, as an encryption key or as a derivation data allowing to obtain a derived encryption key from a master key.
[0017] Thus, thanks to the hardware wallet according to the invention, the secret to be stored is encrypted with a value specific to the biometric signature collection and recording procedure. Circumventing, particularly through fraud, the biometric validation, notably by implementing a new collection and recording procedure, does not allow the secret to be recovered by decrypting the encrypted secret, since the value used after circumventing the biometric validation will not be the same as that used during storage. Recovering the secret therefore requires the authentic implementation of the biometric validation to allow for decryption that corresponds to the encryption performed during the storage of said secret.
[0018] Preferably, the secret includes a signing key for a transaction in a decentralized digital ledger, in particular online, for example a signing key for a transaction relating to a crypto-asset, typically a cryptocurrency.
[0019] This refers more specifically to a hardware wallet for crypto-assets, in particular a hardware wallet for cryptocurrencies, intended to store the corresponding private keys.
[0020] Preferably, said data related to the procedure for collecting and recording said at least one biometric data includes the number of collection and recording procedures carried out by said wallet.
[0021] Thus, with each new implementation of the collection and recording procedure, the value of the corresponding data is modified, which makes it impossible to decipher the secrets encrypted before this collection and recording procedure.
[0022] The value of the data linked to the collection and recording procedure constitutes a kind of counter of the number of procedures implemented, without necessarily being equal to zero initially. On the contrary, the value can be initialized to a random number.
[0023] Preferably, the wallet is also configured to provide a decrypted secret, the wallet being configured to retrieve, at the time of provision, the value of said at least one data related to the collection and recording procedure, and then to decrypt, with said value retrieved at the time of provision, said encrypted secret into a decrypted secret.
[0024] In order to retrieve the secret stored in the hardware wallet, the wallet implements steps that are the reverse of those used for storage, namely, decrypting the stored encrypted secret from the value of the data linked to the collection and recording procedure at the time of provision. Retrieving a secret identical to the one originally stored in the hardware wallet therefore implies performing the decryption from the same value of the data linked to the collection and recording procedure as that used during encryption; that is, it requires using the same biometric trait. Bypassing the biometric sensor authentication system therefore does not allow the recovery of the secret initially stored in the hardware wallet.
[0025] According to another aspect, a method for storing information on a hardware wallet, for example a card, is also proposed. The hardware wallet comprises a microcircuit and a biometric sensor configured to acquire a biometric trait of a user, for example a fingerprint. The method comprises: a procedure for collecting and recording at least one biometric data point from said biometric trait, and a step of storing, preferably in the microcircuit, at least one secret in encrypted form.
[0026] The storage step includes a step of retrieving the value, at the time of storage, of at least one data related to the collection and recording procedure, and then an encryption step, with said value retrieved at the time of storage, of said secret into an encrypted secret.
[0027] Preferably, the secret includes a signing key for a transaction in a decentralized digital ledger, for example a signing key for a transaction involving a crypto-asset, typically a cryptocurrency.
[0028] Preferably, the method also includes a step of counting the number of collection and recording procedures carried out by said wallet, and the retrieval step uses said number of collection and recording procedures carried out by said wallet to obtain said at least one data related to the collection and recording procedure.
[0029] Preferably, the method also includes a step of providing a decrypted secret, the provision step including a step of recovering the value, at the time of provision, of said at least one data related to the collection and recording procedure, and then a decryption step, with said value recovered at the time of provision, of said encrypted secret into a decrypted secret.
[0030] Preferably, said value of said at least one data related to the collection and recording procedure is used, when encrypting the secret into an encrypted secret or when decrypting the encrypted secret into a decrypted secret, as a mask, as an encryption / decryption key, or as derivation data allowing a derived encryption / decryption key to be obtained from a master key.
[0031] According to another aspect, a method for identifying a transaction carried out by a wallet as described above is also proposed, said transaction having been carried out with the decrypted secret provided after a collection and recording procedure, in which: - we retrieve the said secret from the wallet, then - several decrypted secrets are determined by encrypting the recovered secret with one or more possible values for at least one piece of data related to the collection and recording procedure, then decrypting it with one or more other possible values for at least one piece of data related to the collection and recording procedure, then - we identify, among the said deciphered secrets determined, a deciphered secret determined corresponding to the said deciphered secret used by the said wallet to carry out the said operation.
[0032] In other words, the present invention relates to a method of identifying a user of a wallet as described above, the wallet having used a decrypted secret for at least one operation after having implemented a collection and recording procedure, in which the secret is retrieved, then said decrypted secret is determined with the retrieved secret and a value different from that retrieved at the time of storage, then said at least one operation using said decrypted secret is identified with said determined decrypted secret.
[0033] This identification is not performed by the hardware wallet, which is unaware that the decrypted secret is incorrect, but is obtained independently of the hardware wallet, for example by observing the decentralized digital ledger of transactions, notably using a separate device. In particular, the recovered secret can be provided directly by the user who lost or had their hardware wallet stolen, for example from another backup.
[0034] From the secret, it is then possible to obtain several decrypted secrets determined by different combinations of values of the data linked to the collection and recording procedure. It is then sufficient to compare such determined decrypted secrets with those used during failed transactions to find the determined decrypted secret corresponding to that used by the unauthorized third party and, subsequently, to identify the corresponding transaction(s).
[0035] In particular, it is understood that the unauthorized third party, having carried out a new collection and recording procedure, will be able to obtain a decrypted secret from said wallet, but that this secret will not allow them to carry out the desired transaction since the decrypted secret will not correspond to the secret initially stored in the wallet. Conversely, such a decrypted secret can be identified, from the initial secret provided by the wallet owner, to identify the transactions attempted by the unauthorized third party. Brief description of the drawings
[0036] [Fig.1] Fig.1 represents, schematically, a material wallet according to the present invention;
[0037] [Fig.2] Fig.2 represents a flowchart of a storage process on a physical portfolio as illustrated in [Fig. 1]; and
[0038] [Fig. 3] [Fig. 3] represents a flowchart of a method for identifying a transaction carried out with a physical wallet as illustrated in [Fig. 1]. Description of embodiments
[0039] Figure 1 schematically illustrates an example of a hardware wallet 1 according to the present invention. The hardware wallet 1 is a biometric hardware wallet and includes, in particular, a microcircuit 2, a biometric sensor 4, and a memory 6, for example, integrated into the microcircuit 2. The hardware wallet 1 may, for example, be in the form of a biometric microcircuit card. The hardware wallet 1 may, for example, be configured to communicate with a network 100, for example, with a decentralized (online) digital ledger that records all transactions, or operations, related to one or more crypto-assets.
[0040] The microcircuit 2 is configured, on the one hand, to receive, encrypt, and store in memory 6 one or more user secrets S, and, on the other hand, to provide said secret(s) previously stored in the memory of the microcircuit 2. The secret(s) S may be, for example, a private key or a seed used to derive one or more private keys. The private key is typically used to sign a transaction, or operation, in a decentralized (and online) digital ledger, for example, a transaction involving a crypto-asset, typically a cryptocurrency.
[0041] The biometric sensor 4 is intended to add additional protection to the hardware wallet 1, which can, via the biometric sensor 4, authenticate a user's biometric trait to validate a secret retrieval operation within the hardware wallet 1. The biometric trait could, for example, be a fingerprint, and the biometric sensor 4 could be a fingerprint reader. Furthermore, as will be described below, the hardware wallet 1 is configured to require the use of the same biometric trait when storing and providing a secret, in order to provide a secret identical to the one initially stored.
[0042] In order to protect the secret S stored in the hardware wallet 1, it is encrypted before being recorded in the memory 6. Thus, the microcircuit 2 includes an encryption means 8 configured to receive the secret S as input and to provide an encrypted secret Sc as output to the memory 6.
[0043] It should be noted that the secret S received as input by the encryption means 8 may have been previously generated by the hardware wallet 1, for example by random sampling. Alternatively, the secret S received as input by the encryption means 8 may have been previously received by the hardware wallet 1 from an external device (not shown) or a person (not shown) via a communication interface (not shown) of the hardware wallet 1.
[0044] Similarly, in order to be able to retrieve, at output, the initial secret S, the hardware wallet 1 also includes a decryption means 10 receiving as input the encrypted secret Sc stored in memory, as well as optionally a confirmation of user authentication via the biometric sensor 4, and providing at output a decrypted secret Sd which is identical to the secret S when the hardware wallet 1 is used authentically by the user.
[0045] However, the recording, particularly fraudulent, of a new biometric trait with the biometric sensor 4 could potentially lead to validation during decryption by the decryption means 10, even if the biometric trait authenticated during decryption is different from the one used during storage. To avoid such an eventuality, and to increase the robustness of the hardware wallet 1, the encryption means 8 and decryption means 10 are also configured to use data related to the collection and recording of a biometric trait.
[0046] More specifically, in order to allow the use of the biometric sensor 4 by the user, it is necessary for the user to register at least one biometric trait beforehand, for example at least one fingerprint, so that it can be recorded and used during a subsequent authentication step.
[0047] The hardware wallet 1 thus includes a collection and recording means 12 receiving as input the biometric trait of the biometric sensor 4, and configured to authenticate said biometric trait, in particular during an operation of providing a secret S. It is the collection and recording means 12 which provides the decryption means 10 with confirmation of user authentication by the biometric sensor 4.
[0048] To perform such authentication, the collection and recording means 12 first retrieves the user's biometric trait in the form of one or more biometric data points and records them as reference biometric data. This biometric data will then be used as reference data during subsequent use of the biometric sensor 4 by the user to authenticate a transaction. Such retrieval and recording of biometric data is performed during a collection and recording procedure in which the biometric trait is provided to the collection and recording means 12 so that it can determine and record reference biometric data. This collection and recording procedure is performed during the user's first use of the hardware wallet 1, so that the user can then be recognized by the biometric sensor 4.
[0049] The collection and recording means 12 is also configured to perform a new collection and recording procedure at any time, at the user's request, to record a new biometric trait. Such a new procedure takes place, in particular, when the hardware wallet changes ownership, so that the new user can authenticate the transactions they wish to perform with their hardware wallet.
[0050] In order to ensure that the user authenticating at the time of providing the secret stored in the hardware wallet 1 is indeed the same as the one who initially stored the secret, the encryption 8 and decryption 10 means are configured to use, during encryption and decryption, a data N linked to the collection and recording procedure implemented by the collection and recording means 12.
[0051] Thus, the microcircuit 2 can include a means of determining such data N, for example a counter of the number N of collection and recording procedures implemented by the collection and recording means 12. The collection and recording of a new biometric trait by the hardware wallet 1 will therefore result in the incrementing of the number N by the counter.
[0052] Furthermore, the hardware wallet 1 also includes means 16, 18 for retrieving the value of the data determined by the determination means 14. The retrieval means 16, 18 each receive as input the The value provided by the determination means 14 of the data N related to the collection and recording of a biometric trait. The retrieval means 16 is associated with the encryption means 8 and is configured to retrieve the value of the data N(s) at the time of storage, while the retrieval means 18 is associated with the decryption means 10 and is configured to retrieve the value of the data N(f) at the time of delivery.
[0053] The value N(s) of the data N at the time of storage is then used by the encryption means 8 to encrypt the secret S into the ciphertext Sc. Said value N(s) can then be used, during encryption, as a mask, as an encryption key or as a derivation data allowing to obtain a derived encryption key from a master key.
[0054] The value N(f) of the data N at the time of provision is used by the decryption means 10 to decrypt the secret Sc into the decrypted secret Sd. Said value N(f) is used, during decryption, in a similar manner to the value N(s) during encryption.
[0055] In order to retrieve a decrypted secret Sd that is identical to the secret S initially stored in the hardware wallet 1, it is therefore necessary that the values N(s) and N(f) be identical. If this is not the case, then the decrypted secret Sd will be different from the initial secret S, and will therefore not allow the desired operation to be validated. To have the same values N(s) and N(f), it is therefore necessary that no collection and recording procedure has been performed between the storage and provision of the secret S by the hardware wallet 1. The means 14 for determining the data N related to the collection and recording procedure makes it possible to change the value of such data N at each iteration of the collection and recording procedure, and thus to modify the encryption and decryption steps implemented in the hardware wallet 1 by means 8, 10.
[0056] Thanks to the hardware wallet 1 described above, it is therefore possible to ensure that a secret stored in memory 6 cannot be recovered after the implementation of a collection and recording procedure.
[0057] It should be noted that the decrypted secret Sd obtained at the output of the decryption means 10 can be provided to an external device (not shown) or to a person (not shown) via a communication interface (not shown) of the hardware wallet 1. Alternatively, the decrypted secret Sd obtained at the output of the decryption means 10 can be used directly by the hardware wallet 1, by means of an operation means (not shown) integrated into the hardware wallet 1 and configured to perform a transaction, or operation, with the decrypted secret Sd. for example configured to sign a transaction, or an operation, in a decentralized digital ledger, particularly online.
[0058] Figure [Fig. 2] illustrates a flowchart of a storage process 20 on a material portfolio 1 as described above.
[0059] In a first step 22, the value N(s) of the data N linked to the collection and recording procedure is retrieved at the time of storage. Then, in a second step 24, the secret S is encrypted into an encrypted secret Sc, using the aforementioned value N(s) retrieved at the time of storage, and the encrypted secret Sc is recorded in a third step 26.
[0060] In a fourth step 28, the value N(f) of the data N related to the collection and recording procedure is retrieved at the time of provision. Then, in a fifth step 30, the encrypted secret Sc is decrypted into the decrypted secret Sd, with the aforementioned value N(f) retrieved at the time of provision.
[0061] We therefore obtain, at the end of process 20, a decrypted secret Sd which is identical to the secret S if the values N(s) and N(f) of the data linked to the collection and recording procedure are identical, that is to say if the biometric trait recorded in the hardware wallet 1 is the same at the time of storage and at the time of provision of the secret.
[0062] If a collection and recording procedure has been performed between the storage and provision of the secret, then the value N(f) will be different from the value N(s), leading to a decrypted secret Sd that differs from the initial secret S. However, the hardware wallet 1 will not warn the user of such a difference, but will instead provide an erroneous decrypted secret Sd that has the characteristics of a genuine secret but will not authenticate the desired operation. Thus, the hardware wallet 1 prevents its fraudulent use to retrieve stored secrets. However, the hardware wallet 1 can also identify the operation using the erroneous decrypted secret, or even identify the person who used the erroneous decrypted secret Sd.
[0063] Figure 3 illustrates an example of a method 32 for identifying a transaction carried out with the decrypted secret Sd provided after a collection and recording procedure, i.e., with an erroneous decrypted secret Sd as mentioned above. Such a method can, in particular, be implemented by a device 110 separate from the hardware wallet 1, preferably independent of the hardware wallet 1, and configured to communicate with the network 100, for example with the decentralized (online) digital ledger that records all transactions, or operations, related to one or more crypto-assets of the hardware wallet 1.
[0064] In a first step 34, the secret S is retrieved. This can be done by the authentic user of the hardware wallet 1 who, for example after the theft or loss of his hardware wallet 1, comes forward to the organization managing said hardware wallet 1 to report the theft or loss, and who at the same time provides the secret(s) S stored in the hardware wallet 1 at the time of the theft or loss, in order to be able to trace the activities carried out with his hardware wallet 1.
[0065] In a second step 36, several decrypted secrets Sdij are determined, obtained with a possible value at the time of storage (for example, a value i), different from that at the time of provision (for example, a value j). This yields several decrypted secrets Sdij corresponding to the different possible combinations of values (i, j).
[0066] Then, in a third step 38, the determined decrypted secret Sd, which corresponds to the erroneous decrypted secret Sd used by the wallet to perform an operation, is identified among the decrypted secrets Sdij. This allows the various unsuccessful operations performed with the hardware wallet 1 to be traced, and further information relating to these operations, or even to the person who initiated them, to be retrieved.
[0067] It is therefore understood that, for the implementation of said method 32 for identifying an operation, the data N linked to the collection and recording procedure is preferably deterministic data, preferably a counter of the number of procedures implemented by the biometric sensor 4, initialized to a predetermined value which may be different from zero. This allows us to limit the number of possible combinations for the values of said deterministic data N, and consequently limit the number of decrypted secrets determined Sdij.
[0068] Thus, not only does the hardware wallet 1 reduce the risk of fraudulent use of the secrets stored in it, but it also makes it possible to identify, using a device 110 independent of the hardware wallet 1, the operations which have been carried out, without success, by it, and to be able to recover information, or even the identity, of the person at the origin of the fraudulent use of the hardware wallet 1.
[0069] Thus, thanks to the present invention, it becomes possible to strengthen the robustness of a biometric hardware wallet by using data related to biometric authentication to encrypt and decrypt the secrets stored in the hardware wallet. It therefore becomes more difficult to recover the secrets when the provisioning step is not carried out by the same person who previously carried out the storage step of said secrets. Furthermore, in the event of fraudulent use of the hardware wallet, It remains possible to identify attempts at fraudulent transactions with the secrets provided by said hardware wallet, in order to possibly identify the person who carried out the fraudulent transactions.
Claims
Demands
1. Hardware wallet (1), for example a card, comprising a microcircuit (2) and a biometric sensor (4) configured to acquire a biometric trait of a user, for example a fingerprint, wherein the wallet (1) includes a memory (6), preferably in the microcircuit (2), for storing at least one secret (S) in encrypted secret (Sc), wherein the wallet (1) is configured to collect and record at least one biometric data from said biometric trait during a collection and recording procedure, characterized in that, to store said secret in encrypted secret, the wallet (1) is configured to retrieve, at the time of storage, the value (N(s)) of at least one data (N) related to the collection and recording procedure, and then to encrypt, with said value (N(s)) retrieved at the time of storage, said secret (S) in encrypted secret (Sc).
2. Wallet (1) according to claim 1, wherein the secret (S) comprises a signing key for a transaction in a decentralized digital ledger, for example a signing key for a transaction involving a crypto-asset, typically a cryptocurrency.
3. Wallet (1) according to claim 1 or 2, wherein said data (N) related to the procedure for collecting and recording said at least one biometric data includes the number of collection and recording procedures performed by said wallet.
4. Wallet (1) according to any one of the preceding claims, wherein the wallet (1) is also configured to provide a decrypted secret (Sd), the wallet (1) being configured to retrieve, at the time of provision, the value (N(f)) of said at least one data (N) related to the collection and recording procedure, and then to decrypt, with said value (N(f)) retrieved at the time of provision, said encrypted secret (Sc) into a decrypted secret (Sd).
5. A method (20) of storing on a hardware wallet (1), for example a card, said hardware wallet comprising a microcircuit (2) and a biometric sensor (4) configured to acquire a biometric trait of a user, for example a fingerprint, said method comprising: - a procedure for collecting and recording at least one biometric data from said biometric trait, - a step of storing, preferably in the microcircuit (2), at least one secret (S) in encrypted secret (Sc), characterized in that the storage step comprises a step (22) of retrieving the value (N(s)), at the time of storage, of at least one data (N) related to the collection and recording procedure, and then a step (24) of encryption, with said value (N(s)) retrieved at the time of storage, of said secret (S) in encrypted secret (Se).
6. A method (20) according to the preceding claim, wherein the secret (S) comprises a signing key for a transaction in a decentralized digital ledger, for example a signing key for a transaction involving a crypto-asset, typically a cryptocurrency.
7. A method (20) according to claim 5 or 6, also comprising a step of counting the number of collection and recording procedures performed by said wallet, and wherein the retrieval step (22) uses said number of collection and recording procedures performed by said wallet (1) to obtain said at least one data point (N) related to the collection and recording procedure.
8. A method (20) according to any one of claims 5 to 7, also comprising a step of supplying a decrypted secret (Sd), the supply step comprising a step (28) of recovering the value (N(f)), at the time of supply, of said at least one data (N) related to the collection and recording procedure, and then a step (30) of decrypting, with said value (N(f)) recovered at the time of supply, said encrypted secret (Sc) into a decrypted secret (Sd).
9. Method (20) according to any one of claims 5 to 8, wherein said value of said at least one data (N) related to the collection and recording procedure, is used as a mask or as an encryption / decryption key.
10. A method (32) for identifying an operation carried out by a wallet (1) according to claim 4, said operation having been carried out with the decrypted secret (Sd) provided after a collection and recording procedure, wherein: - said secret (S) is retrieved from the wallet (1), then - several decrypted secrets (Sdi j) are determined by encrypting said retrieved secret (S) with one or more possible values for said at least one data related to the collection and recording procedure, then decrypting with one or more other possible values for said at least one data related to the collection and recording procedure, then - a determined decrypted secret (Sd) corresponding to said decrypted secret (Sd) used by said wallet (1) to carry out said operation is identified among said determined decrypted secrets (Sdij).