Control circuitry for aerosol-generating device
By designing a control circuit system in the aerosol generation device, allowing a limited number of offline authentication and online conversion, the problem of offline YAP methods in the prior art being vulnerable to brute force attacks is solved, and higher security and reliability are achieved.
Patent Information
- Application Number
- CN202380061870.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-08-25
- Filing Date
- 2023-08-17
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, offline youth access prevention (YAP) methods of aerosol generation devices are vulnerable to brute force attacks and need to rely on device connections and applications, with technical challenges.
A control circuit system is designed that allows the user to unlock the aerosol generation device through a limited number of valid authentication information inputs during the offline phase and switch to the online phase after more than the number of attempts to enhance safety.
It effectively prevents unauthorized users from unlocking the aerosol generation device through brute force attacks, and ensures the safety and reliability of completing the authentication process without relying on device connections and applications.
Smart Images

Figure CN119947607A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to control circuitry for an aerosol generating device, an aerosol generating device comprising the control circuitry, an aerosol generating system comprising the aerosol generating device and a method for authenticating an aerosol generating device for use. Background Art
[0002] The aerosol generating system may also include a supporting device for storing the aerosol generating device. The aerosol generating device may be designed as a handheld device, and the user can use the handheld device to consume the aerosol generated by the aerosol generating product, for example, in one or more use processes. The aerosol generating product may include an aerosol-forming substrate, such as a tobacco-containing substrate, which is usually in the form of a rod. The shape and size of this rod can be configured to be at least partially inserted into the aerosol generating device, and the aerosol generating device may include a heating element for heating the aerosol-forming substrate. Other exemplary aerosol generating products may include a tube, and the tube contains a liquid that can be evaporated during the aerosol consumption by the user. The shape and size of this tube can also be configured to be at least partially inserted into the aerosol generating device. Alternatively, the tube can be fixedly mounted to the aerosol generating device and refilled by inserting the liquid into the tube. The aerosol generating product may include an aerosol generating substrate, and the aerosol generating substrate includes nicotine and / or (one or more) other active ingredients.
[0003] It is necessary to implement a youth access prevention (YAP) method to prevent underage users from accessing and using such aerosol generating devices. Some online YAP methods require the user to register the device and activate the device for use by connecting the device to a computing device (e.g., a smartphone, a personal computer, etc.) on which the registration application is running. The application can be provided as a USB application. The connection to the computing device can be achieved via Bluetooth Low Energy (BLE). However, the connectivity and application required to perform the online YAP method in the above manner may be technically problematic. Therefore, an offline YAP method for unlocking the device without the need for such connectivity or application has been proposed. However, some offline YAP methods are vulnerable to brute force attacks. Summary of the invention
[0004] It is desirable to provide a YAP method that at least partially overcomes the above technical problems. This problem is achieved by the subject matter of the independent claims. Optional features are provided by the dependent claims and the following description.
[0005] According to a first aspect, a control circuit system for an aerosol generating device or for an aerosol generating system including the aerosol generating device is provided. The aerosol generating device has a locked state and an unlocked state, in which the aerosol generating device is prohibited from delivering an aerosol, and in which the aerosol generating device is allowed to deliver an aerosol. The control circuit system is configured to perform an authentication process for authenticating a user. The control circuit system may be configured to allow the user to make a first predetermined number of attempts to enter valid authentication information using one or more user interface components during an offline phase of the authentication process. The control circuit system may also be configured to determine to convert the aerosol generating device from the locked state to the unlocked state in response to receiving valid authentication information from the user before the first predetermined number of attempts has been exceeded. The control circuit system may also be configured to perform an online phase of the authentication process in response to determining that the first predetermined number of attempts has been exceeded before the user has entered valid authentication information.
[0006] Starting from the offline phase enables the authentication process to be completed without relying on any device connectivity and without using any external application, such as the YAP method. In addition, the solution described herein prevents the use of brute force attacks to gain access to the locking feature of the aerosol generating device by switching to the online phase after too many brute force attempts to unlock the aerosol generating device during the offline phase. Thereby, unlocking of the aerosol generating device by an unauthorized user can be effectively and reliably prohibited, so that the use of the aerosol generating device by an unauthorized user to consume aerosol can be effectively and reliably prevented.
[0007] The control circuit system may also be configured to respond to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, wherein the second predetermined number of attempts is lower than the first predetermined number of attempts, and if the second predetermined number of attempts has been exceeded, delay the offline phase until a first delay period has expired. The control circuit system may be configured to continue the offline phase without delay if the second predetermined number of attempts has not been exceeded.
[0008] The control circuit system may also be configured to: respond to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a third predetermined number of attempts has been exceeded, wherein the third predetermined number of attempts is lower than the first predetermined number of attempts and higher than the second predetermined number of attempts; and if the third predetermined number of attempts has been exceeded, delay the offline phase until a second delay period has expired. The control circuit system may be configured to continue the offline phase without delay if the third predetermined number of attempts has not been exceeded. The second delay period may be longer than the first delay period.
[0009] The first predetermined number of attempts, the second predetermined number of attempts and / or the third predetermined number of attempts may be defined with respect to consecutive and / or non-consecutive attempts.
[0010] The control circuitry may be configured to delay the offline phase by prohibiting the user from entering additional authentication information using the one or more user interface components or by refraining from authenticating the user based on additional authentication information entered by the user.
[0011] The control circuit system may be further configured to receive user-entered authentication information from the one or more user interface components during each attempt in the offline phase, and to authenticate the user by determining validity of the user-entered authentication information.
[0012] The control circuit system may also be configured to control the user interface component to guide the user, for example, by inputting authentication information as part of the guided interactive input process as described below: in response to a control signal from the control circuit system, the user interface component is controlled to output a user-perceivable guidance signal for guiding the user during the guided interactive input process, for example, (i) prompting the user to take a predetermined action, (ii) providing the user with feedback related to the progress of the guided interactive input process, or both (i) and (ii). Therefore, the interactive input process is an example of a guided human-computer interaction process. The user-perceivable guidance signal may include any one or more of a visual signal, an audible signal, and a tactile signal. To this end, the user interface component may include one or more output elements, for example, any combination of one or more of the following elements: a visual indicator (e.g., a light source, such as an LED, an incandescent tube, a compact fluorescent lamp), a tactile output element (e.g., a centrifugal rotating mass motor, a linear resonant actuator, a vibrotactile actuator such as a C2 tactile actuator, a piezoelectric actuator), an audible output element, such as a speaker, etc. The user interface component also includes one or more input elements, such as buttons (e.g., push buttons), touch screens, microphones. In one embodiment, the user interface component includes a plurality of LEDs and buttons. In any of these approaches, the user interface component facilitates implementation of the offline phase of the authentication process while conserving device real estate in an aerosol generating device or ancillary device that may be small in size.
[0013] The control circuit system may be configured to receive authentication information input by a user during a plurality of time windows of a predetermined duration, each time window corresponding to a corresponding number of a digital sequence forming the authentication information, and to attribute the user input received via the one or more user interface components during the time window to the number corresponding to the time window. The control circuit system may be configured to trigger a timeout in response to the one or more user interface components not receiving a user input within a predetermined time period starting from the starting point of the corresponding time window in the time window. The control circuit system may be configured to start the first time window in the time window in response to the user interacting with the one or more user interface components. The control circuit system may be configured to start the first time window in the time window in response to receiving a predetermined signal generated by the user interacting with the one or more user interface components. One or more user interface components may include a button, and the predetermined signal may be generated by the user pressing the button a predetermined number of times. For example, the user may start the first time window by pressing the button a predetermined number of times (e.g., 5 times) within a predetermined amount of time (e.g., 30 seconds).
[0014] There may be a preparatory time window before and / or during one or more time windows (e.g., before and / or during the first time window). The control circuit system may be configured to determine that the user's attempt to enter valid authentication information was unsuccessful if no authentication input by the user is received during the preparatory time window, and to store the received authentication input by the user (to be attributed to the corresponding number) if the authentication input by the user is received during the preparatory time window, and to start the corresponding time window and / or continue to run the corresponding time window (to allow the corresponding number to be completed).
[0015] The control circuit system may be configured to control the user interface component to output a user-perceivable guidance signal indicating at least the starting point of the corresponding time window. The control circuit system may be configured to control the user interface component to output a user-perceivable guidance signal indicating that the time window is running. The control circuit system may be configured to control the user interface component to output a user-perceivable guidance signal indicating which number of the sequence the user is being guided to provide input for. The aerosol generating device may be provided with a certain number of output elements, the number of output elements corresponding to the number of numbers in the sequence. The control circuit system may be configured to use the position of the active output element relative to the inactive output element to indicate the position of the number within the sequence for which input is expected.
[0016] The control circuit system may be configured to interpret multiple signals generated by repeated user operation of the same user interface component during the time window as a coded input signal defining the sequence of digits corresponding to the time window. The user interface component may be a power button of the aerosol generating device.
[0017] The sequence of digits forming the authentication information may include a personal identification code or code, such as a PIN code. Thus, a separate time window is provided for each digit of the input sequence or PIN code, thereby providing certainty and security as to which digit is currently being input. "Attribution" means that the control circuit system associates the user input received during the time window with the digit corresponding to the time window, or the control circuit system uses the user input received during the time window to determine or calculate the value of the digit corresponding to the time window. In order to enhance security, the control circuit system may be configured to trigger a timeout in response to one or more user interface components not receiving a user input within a predetermined time period starting from the starting point of the corresponding time window in the time window. Therefore, the control circuit system may also be configured to determine not to convert the aerosol generating device to an unlocked state in response to the triggering of the timeout. "Timeout" means that the timer starts running at the beginning of a predetermined period and generates an interrupt or trigger signal at the end of the predetermined period, thereby "triggering" the timeout, provided that no predetermined action is taken during the predetermined period to cancel or reset the timer.
[0018] During the offline phase, the control circuit system may be configured to respond to an unsuccessful attempt by the user to input valid authentication information by determining not to convert the aerosol generating device from a locked state to an unlocked state. The control circuit system may also be configured to compare the authentication information input by the user with pre-stored reference authentication information, and determine whether to convert the aerosol generating device from a locked state to an unlocked state based on the result of the comparison. The reference authentication information may be stored in a data storage device and / or memory of the aerosol generating device and / or an associated device. For example, the reference authentication information may be obtained during an age verification process and stored upon completion of the age verification process, as discussed herein. The control circuit system may be configured to determine the validity of the authentication information input by the user using a key derivation mechanism.
[0019] The control circuit system may be configured to: transmit an unlock request to a server to transition the aerosol generating device from the locked state to the unlocked state during an online phase of the authentication process, wherein the unlock request includes unique device identification information identifying the aerosol generating device and a time-limited current information corresponding to an unlockable feature of the aerosol generating device; receive an unlock authorization from the server in response to the transmitted unlock request; and in response to receiving the unlock authorization, transition the aerosol generating device from the locked state to the unlocked state. The unlock authorization may be at least partially encrypted. The unlock authorization may be decryptable using a public key stored on the aerosol generating device. The control circuit system may be configured to, in response to receiving the unlock authorization, transition the aerosol generating device from the locked state to the unlocked state by: decrypting the unlock authorization; determining whether the decrypted unlock authorization includes the unique device identification information and the time-limited current information; and unlocking the unlockable feature in response to determining that the decrypted unlock authorization includes the unique device identification information and the time-limited current information. The control circuit system may be configured to terminate unlocking the unlockable feature if an unlock authorization is not received after a valid period of time after the unlock request is transmitted to the server. The control circuit system may be configured to limit the number of unlock authorizations transmitted to the aerosol generating device. The unique device identification may include a serial number. Additionally or alternatively, an online phase may be performed using an external computing device or telephone, whereby the user contacts the certification authority. In this way, a comprehensive and secure procedure for determining the age of a user may be implemented, for example based on the user's personal data or information, such as the user's identity card, passport, credit card, driver's license, social security number, etc. Therefore, the real age of the user can be reliably and unambiguously determined.
[0020] The authentication process may include a youth access prevention process. Performing the authentication process may include identifying the user, i.e. determining the identity of the user and / or verifying the identity of the user, and / or determining whether the user is authorized to convert the aerosol generating device to an unlocked state to allow delivery and / or generation of aerosol. Thus, a "successful authentication" of a user (e.g., a successful authentication after a successful attempt by the user to enter valid authentication information during an offline phase, or after receiving an unlock authorization during an online phase) may include verifying the identity of the user, or more specifically determining that the user is authorized to convert the aerosol generating device to an unlocked state. An "unsuccessful authentication" of a user may include a failure to verify the identity of the user, or more specifically, determining that the user is not authorized to convert the aerosol generating device to an unlocked state. For example, the authentication process may include an age verification process for determining whether the user of the aerosol generating device has reached a minimum age as indicated by an age threshold. The age threshold may include a predefined minimum age for the user of the aerosol generating device. For example, in some jurisdictions, consumption of aerosols may be permitted for citizens or individuals who have reached a certain minimum age and / or whose age is equal to or above the minimum age. In addition, at least in some jurisdictions, individuals who have reached this minimum age may be considered adults and / or adults. Therefore, the age threshold can indicate, represent and / or describe the minimum age that a user should have to consume aerosols using an aerosol generating device. In addition or alternatively, the age threshold can indicate, represent and / or describe the age of adulthood, and users above the age of adulthood can be considered adults. For example, the age threshold can be from 14 to 25 years old, such as 16, 18 or 21 years old. The age verification process can therefore be used to determine whether a user of an aerosol generating system is an adult, has reached the age of adulthood and / or is an adult. The age verification process can be associated with a registration procedure or a setup procedure before or during the user's first use of an aerosol generating device. By determining that a user has reached the age threshold based on the age verification process, it is possible to reliably and effectively prohibit users who have not reached the age threshold and / or have an age below the age threshold from abusing or legally abusing the aerosol generating device to consume aerosols. In particular, it is possible to reliably and effectively prohibit underage users from using an aerosol generating device to consume aerosols.
[0021] The control circuit system may also be configured to convert the aerosol generating device to an unlocked state in response to successfully authenticating the user. The control circuit system may also be configured to convert the aerosol generating device to an unlocked state by (i) modifying the value of the authentication indicator stored in the data storage device, (ii) adding the authentication indicator to the data storage device, (iii) deleting one or more of the authentication indicators from the data storage device. Additionally or alternatively, the control circuit system may also be configured to convert the aerosol generating device to an unlocked state by enabling one or more functions of the aerosol generating device that were previously disabled when the aerosol generating device was in a locked state. Additionally or alternatively, the control circuit system may also be configured to convert the aerosol generating device to an unlocked state by transmitting an unlock signal to a companion device for the aerosol generating device, the companion device being configured to enable one or more functions of the aerosol generating device and one or more of the companion devices that were previously disabled when the aerosol generating device was in a locked state in response to receiving the unlock signal. One or more functions enabled in the unlocked state may be necessary for the aerosol generating device to deliver an aerosol, and the enabling includes enabling one or more of the following: (i) an electrical energy supply component (e.g., charging the aerosol generating device), (ii) a vaporizable liquid supply component, (iii) a heating component, (iv) an airflow enabling component, and (v) an actuating element for a user to actuate one or more of the other components. For example, in the locked state, the insertion of an aerosol generating article into the aerosol generating device may be prohibited, and in the unlocked state, the insertion of an aerosol generating article may be allowed. Such functions that can be enabled or disabled may also be described herein with respect to lockable and unlockable features. In addition or alternatively, the control circuit system may also be configured to convert the aerosol generating device to an unlocked state by disabling one or more mechanical locking components and / or flow path blocking components, which are configured to prevent the delivery and / or generation of aerosols when in the enabled state. However, any other device that allows the generation of aerosols in the unlocked state and prohibits the generation of aerosols in the locked state may be implemented. The control circuitry may be further configured to determine not to transition the aerosol generating device from the locked state to the unlocked state based on an unsuccessful determination of user authentication. The control circuitry may be further configured to maintain the aerosol generating device in the locked state in response to determining not to transition the aerosol generating device from the locked state to the unlocked state.
[0022] The control circuitry may also control one or more functions or functionalities of the aerosol generating device. The control circuitry may include one or more processors for data processing. Additionally or alternatively, the aerosol generating device may include a data storage device and / or memory for storing data, such as software instructions, computer programs and / or other data.
[0023] According to a second aspect, there is provided an aerosol generating device comprising the control circuitry of the first aspect.
[0024] The aerosol generating device may be configured or designed as a handheld device that can be used by an authorized user to consume the aerosol generating article, for example, during one or more use processes (also referred to as "experiences" or "experience processes"). For example, an aerosol generating article that can be used with an aerosol generating device may include an aerosol-forming substrate, such as a tobacco-containing substrate, which can be assembled in the form of a stick that can be at least partially inserted into the aerosol generating device, optionally assembled with other elements or components. In addition or alternatively, an aerosol generating article that can be used with an aerosol generating device may include at least one cartridge containing a liquid that can evaporate during consumption of the aerosol by the user. Such a cartridge may be a refillable cartridge that is fixedly mounted at the aerosol generating device, or the cartridge may be at least partially inserted into the aerosol generating device.
[0025] According to a third aspect, there is provided a supporting device for an aerosol generating device, the supporting device comprising the control circuit system of the first aspect.
[0026] The accessory device (which may also be described as a receiving device) may generally refer to a supporting device for supporting and / or storing an aerosol generating device. The accessory device may be a portable accessory device. In the context of the present disclosure, the accessory device may be configured to at least partially receive the aerosol generating device. For example, the accessory device may be configured to be physically connected to the aerosol generating device. Such physical connection may, for example, include a mechanical connection based on an attachment device, such as a hook mechanism, a latch mechanism, a snap-fit mechanism, etc., and the aerosol generating device may be mechanically connected to the accessory device and / or its housing based on the mechanical connection. Additionally or alternatively, the aerosol generating device may be physically connected to the accessory device based on a magnetic or electromagnetic connection. Additionally or alternatively, the aerosol generating device may be at least partially inserted into the accessory device, such as into an opening of the accessory device. In addition, the aerosol generating device and the accessory device may refer to physically separate components or elements of the aerosol generating system.
[0027] In order to communicate with each other and / or with an external computing device and / or to exchange data or signals, the aerosol generating device and / or the supporting device may include at least one communication interface. The communication interface may be configured for wireless communication, for wired communication, or for both wireless communication and wired communication. For example, the communication interface may be configured for coupling via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection (including BLE), a mobile phone network, a 3G / 4G / 5G connection, etc., an edge connection, an LTE connection, a bus connection, a wireless connection, a wired connection, a radio connection, a near-field connection, an IoT connection, or any other connection using any appropriate communication protocol.
[0028] The aerosol generating device and / or the supporting device may include at least one energy storage device for storing electrical energy and / or supplying electrical energy to the aerosol generating device with electrical energy. For example, the supporting device may be configured to supply electrical energy to the aerosol generating device to charge at least one energy storage device of the aerosol generating device. In other words, the supporting device may be configured to charge the aerosol generating device and / or at least one energy storage device thereof. The at least one energy storage device of the aerosol generating device may, for example, include at least one battery, at least one accumulator, at least one capacitor or any other energy storage device. The supporting device may be configured to supply electrical energy to the energy storage device of the aerosol generating device when the aerosol generating device is at least partially received by the supporting device. The supporting device may include one or more batteries for supplying electrical energy to the energy storage device of the aerosol generating device. The supporting device may be configured to supply electrical energy to the energy storage device of the aerosol generating device wirelessly, for example based on induction. Additionally or alternatively, the supporting device may be configured to supply electrical energy to the energy storage device of the aerosol generating device via one or more electrical connectors between the supporting device and the aerosol generating device. For example, the aerosol generating device and the supporting device may each include at least one electrical connector, and the at least one electrical connector is used to electrically couple the supporting device with the aerosol generating device when the aerosol generating device is at least partially received by the supporting device. For example, the supporting device may include an opening for at least partially receiving the aerosol generating device. By inserting the aerosol generating device at least partially into the opening, one or more electrical connections can be established between the aerosol generating device and one or more electrical connectors of the supporting device. In addition or alternatively, the aerosol generating device may be physically and / or mechanically connected to the supporting device, for example, to the housing of the supporting device, so that the aerosol generating device is at least partially received by the supporting device, and so that one or more electrical connections can be established between the aerosol generating device and the supporting device. Optionally, establishing an electrical connection between the supporting device and the aerosol generating device, for example via one or more electrical connectors of the aerosol generating device and the supporting device, can establish a communication coupling and / or a communication connection between the supporting device and the aerosol generating device, for example, for transmitting an authentication signal. For example, at least one electrical connector of the supporting device can be combined and / or can include a communication interface of the supporting device. In other words, at least one electrical connector of the accessory device may be configured as a communication interface for communicatively coupling the accessory device with the aerosol generating device. Additionally or alternatively, at least one electrical connector of the aerosol generating device may be combined with and / or may include a communication interface of the aerosol generating device. In other words, at least one electrical connector of the aerosol generating device may be configured as a communication interface for communicatively coupling the aerosol generating device with the accessory device. Thus, the authentication signal may be transmitted from the accessory device to the aerosol generating device via one or more electrical connectors of the accessory device and the aerosol generating device.However, it should be noted that the communication interface of one or both of the accessory device and the aerosol generating device may be physically separated and independent from at least one electrical connector of the accessory device and / or the aerosol generating device. A charging cycle may refer to a period of time during which the aerosol generating device is continuously supplied with electrical energy by the accessory device. During a charging cycle, at least one energy storage device may be partially or fully charged.
[0029] According to a fourth aspect, there is provided an aerosol generating system comprising the control circuitry of the first aspect, optionally also comprising an aerosol generating device, and optionally also comprising an ancillary apparatus. The control circuitry may be fully contained within only one of the components of the system, or may be distributed between a plurality of components. The control circuitry may, for example, be distributed between the aerosol generating device and the ancillary apparatus.
[0030] According to a fifth aspect, a server is provided, which is configured to perform at least an online phase of an authentication process in conjunction with an aerosol generating device. More specifically, a server for unlocking an unlockable feature of an aerosol generating device is provided, the server comprising: a communication interface for transmitting data to and from the aerosol generating device; and a control circuit system operably connected to the communication interface, wherein the control circuit system is configured to: receive an unlock request from the aerosol generating device to unlock the unlockable feature, wherein the unlock request includes unique device identification information identifying the aerosol generating device and time-limited current information corresponding to the unlockable feature; and in response to the transmitted unlock request, transmit an unlock authorization to the aerosol generating device to unlock the unlockable feature. It should be understood that references to the aerosol generating device in the context of actions performed by the server may be replaced or supplemented by references to a companion device and / or an aerosol generating system and / or one or more external computing devices as appropriate.
[0031] According to a sixth aspect, a method for performing an authentication process for authenticating a user of an aerosol generating device is provided. The aerosol generating device has a locked state and an unlocked state, in which the aerosol generating device is prohibited from delivering an aerosol, and in which the aerosol generating device is allowed to deliver an aerosol. The method may include allowing a user to make a first predetermined number of attempts to enter valid authentication information using one or more user interface components during an offline phase of the authentication process. The method may also include determining to transition the aerosol generating device from the locked state to the unlocked state in response to receiving valid authentication information from the user before the first predetermined number of attempts has been exceeded. The method may also include performing an online phase of the authentication process in response to determining that the first predetermined number of attempts has been exceeded before the user has entered valid authentication information.
[0032] The method may further include responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, wherein the second predetermined number of attempts is lower than the first predetermined number of attempts, and if the second predetermined number of attempts has been exceeded, delaying the offline phase until a first delay period has expired. The method may include continuing the offline phase without delay if the second predetermined number of attempts has not been exceeded.
[0033] The method may further include responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a third predetermined number of attempts has been exceeded, wherein the third predetermined number of attempts is lower than the first predetermined number of attempts and higher than the second predetermined number of attempts; and if the third predetermined number of attempts has been exceeded, delaying the offline phase until a second delay period has expired. The method may further include continuing the offline phase without delay if the third predetermined number of attempts has not been exceeded. The second delay period may be longer than the first delay period.
[0034] The method may further include delaying the offline phase by prohibiting the user from entering additional authentication information using the one or more user interface components or by refraining from authenticating the user based on additional authentication information entered by the user.
[0035] The method may also include receiving user-entered authentication information from the one or more user interface components during each attempt in the offline phase, and authenticating the user by determining validity of the user-entered authentication information.
[0036] The method may further include receiving authentication information input by the user during a plurality of time windows of a predetermined duration, each time window corresponding to a corresponding number of a sequence of numbers forming the authentication information, and attributing user input received via the one or more user interface components during the time windows to the number corresponding to the time window. The method may further include triggering a timeout in response to the one or more user interface components not receiving user input within a predetermined time period starting from the start of a corresponding time window in the time windows. The method may further include starting a first time window in the time window in response to a user interacting with the one or more user interface components. The method may further include starting the first time window in the time window in response to receiving a predetermined signal generated by the user interacting with the one or more user interface components. The one or more user interface components may include a button. The predetermined signal may be generated by the user pressing the button a predetermined number of times. There may be a preparatory time window before and / or during one or more of the time windows. The method may further include determining that the user's attempt to enter valid authentication information was unsuccessful if no authentication input by the user was received during the preparatory time window; and if authentication input by the user was received during the preparatory time window, storing the received authentication input by the user, and starting the corresponding time window and / or continuing to run the corresponding time window. The method may further comprise controlling the user interface component to output a user-perceivable guidance signal indicating at least the starting point of the corresponding time window. The method may further comprise controlling the user interface component to output a user-perceivable guidance signal indicating that the time window is running. The method may further comprise controlling the user interface component to output a user-perceivable guidance signal indicating which number of the sequence the user is being guided to provide input for. The aerosol generating device may be provided with a number of output elements, the number of the output elements corresponding to the number of numbers in the sequence. The method may further comprise using the position of the active output element relative to the inactive output element to indicate the position of the number within the sequence for which input is expected. The method may further comprise interpreting a plurality of signals generated during the time window due to repeated operation of the same user interface component by the user as coded input signals defining the number of the sequence corresponding to the time window. The user interface component may be a power button of the aerosol generating device.
[0037] The method may further include: during an online phase of the authentication process: transmitting an unlock request to a server to transition the aerosol generating device from the locked state to the unlocked state, wherein the unlock request includes unique device identification information identifying the aerosol generating device and time-limited current information corresponding to an unlockable feature of the aerosol generating device; receiving an unlock authorization from the server in response to the transmitted unlock request; and transitioning the aerosol generating device from the locked state to the unlocked state in response to receiving the unlock authorization. The unlock authorization may be at least partially encrypted. The method may further include decrypting the unlock authorization using a public key stored on the aerosol generating device.
[0038] The method may further include, in response to receiving the unlock authorization, transitioning the aerosol generating device from the locked state to the unlocked state by: decrypting the unlock authorization; determining whether the decrypted unlock authorization includes the unique device identification information and the time limit present information; and unlocking the unlockable feature in response to determining that the decrypted unlock authorization includes the unique device identification information and the time limit present information. The method may further include terminating unlocking the unlockable feature if the unlock authorization is not received after a valid period of time after transmitting the unlock request to the server. The method may further include limiting the number of unlock authorizations transmitted to the aerosol generating device. The unique device identification may include a serial number.
[0039] The method may further comprise responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining not to transition the aerosol generating device from the locked state to the unlocked state.
[0040] The method may also include determining the validity of authentication information entered by the user using a key derivation mechanism.
[0041] The method may be performed by the aerosol generating device and / or by an aerosol generating system including the aerosol generating device and / or by an ancillary device for the aerosol generating device. More specifically, the method may be performed by a control circuit system of the aerosol generating device, by a control circuit system of the ancillary device, or by a control circuit system of a system including the aerosol generating device and the ancillary device. The method may be performed in a distributed manner, wherein different steps of the method are performed by different components of the system. The method of the fifth aspect may be computer-implemented.
[0042] According to a seventh aspect, a method for performing an online phase of an authentication process performed by a server in conjunction with an aerosol generating device and / or an associated device and / or an aerosol generating system and / or one or more other computing devices is provided. More specifically, a method for unlocking an unlockable feature of an aerosol generating device is provided, the method comprising: by the server: receiving an unlock request from the aerosol generating device to unlock the unlockable feature, wherein the unlock request comprises unique device identification information identifying the aerosol generating device and time-limited current information corresponding to the unlockable feature; and in response to the transmitted unlock request, transmitting an unlock authorization to the aerosol generating device to unlock the unlockable feature.
[0043] According to an eighth aspect, a computing system is provided, which is configured to execute the method of the sixth aspect and / or the seventh aspect.
[0044] According to a ninth aspect, there is provided a computer program comprising instructions which, when executed by a computing system, enable or cause the computing system to perform the method of the sixth aspect and / or the seventh aspect.
[0045] According to a tenth aspect, there is provided a computer readable medium comprising instructions, which when executed by a computing system enable or cause the computing system to perform the method of the sixth aspect and / or the seventh aspect. The computer readable medium may be transient or non-transient, volatile or non-volatile.
[0046] As used herein, "offline" refers to a stage of the authentication process that is connectivity-free, connectivity-agnostic, or connectivity-independent in the sense that the offline stage is performed when the aerosol generating device, or an aerosol generating system including the aerosol generating device, is in a disconnected or offline state. In other words, "offline" refers to a stage of the authentication process where the aerosol generating device transitions from a locked state to an unlocked state without depending on the control circuitry, the aerosol generating system, or the aerosol generating device receiving a signal from an external computing device. Additionally or alternatively, "offline" refers to a stage of the authentication process where the device transitions from a locked state to an unlocked state without depending on the control circuitry, the aerosol generating system, or the aerosol generating device being connected (or "paired") to an external computing device.
[0047] Accordingly, the term "online phase" is to be understood as a phase of the authentication process, which uses the device to be connected for the purpose of performing the authentication process when the aerosol generating device or an aerosol generating system including the aerosol generating device is in a connected or online state. The online phase and the offline phase may alternatively be described with respect to an online modality and an offline modality, respectively. In other words, "online" refers to a phase of the authentication process, wherein the aerosol generating device is switched from a locked state to an unlocked state depending on the control circuit system, the aerosol generating system or the aerosol generating device receiving a signal from an external computing device. Additionally or alternatively, "online" refers to a phase of the authentication process, wherein the device is switched from a locked state to an unlocked state depending on the control circuit system, the aerosol generating system or the aerosol generating device being connected (or "paired") to an external computing device.
[0048] For example, the control circuit system may also be configured to perform an offline phase of the authentication process without the aerosol generating device (or any part of a system including the aerosol generating device) being connected (or needing to be connected) to an external computing device (e.g., a mobile phone, a personal computer, or a tablet device). Additionally or alternatively, the control circuit system may also be configured to perform an offline phase without transmitting authentication-related data to the external computing device, or receiving authentication-related data from the external computing device, even when the aerosol generating device is connected to the external computing device, "authentication-related data" including, for example, data used by or required for the authentication process. The control circuit system may also be configured to perform an offline phase without being controlled by and / or controlling an external computing device. The control circuit system may also be configured to perform an offline phase without the aerosol generating device being connected to or forming part of a network (e.g., the Internet) including one or more external computing devices. "Offline" may refer to any existing connectivity of the aerosol generating device that is not used for authentication-related purposes or tasks, regardless of whether the aerosol generating device is connected to / connectable to an external computing device. For example, "offline" may refer to a state or stage in which data exchanged during the authentication process through any communication interface of the aerosol generating device providing its connectivity is not input to or output from the control circuit system, or more specifically, the thread or component of the control circuit system that is performing authentication-related tasks. In other words, the aerosol generating device may include a communication interface for managing a connection to an external computing device, wherein "offline" indicates that during the offline stage of the authentication process, the communication interface remains idle or performs only tasks unrelated to the authentication process.
[0049] It should be noted that when used with respect to the term "offline", the term "external computing device" does not include a companion device or an aerosol generating device, wherein the authentication is performed by another of these devices. Rather, in the context of the present disclosure, the term "external computing device" may refer to a computing device configured to communicate with an aerosol generating device and / or a companion device, for example, based on exchanging data or information. In general, the external computing device may be a handheld or portable device. Alternatively, the external computing device may be a stand-alone or fixed-mounted device. In addition, the external computing device may be owned by a user or another entity or individual (e.g., a retail store), or may be installed at the user or another entity or individual. For example, the external computing device may refer to a handheld device, a smart phone, a personal computer ("PC"), a tablet PC, a notebook, or a computer. The external computing device may include a user interface. The external computing device may include one or more processors for data processing, such as for processing one or more user inputs received at the user interface. Additionally or alternatively, the external computing device may include a data storage device and / or memory for storing data, such as software instructions, computer programs, and / or other data. In addition, the external computing device may include a communication interface, a communication module and / or a communication circuit system, which is used to communicatively couple the external computing device with the aerosol generating device and / or the supporting device, for example, via a communication interface of the aerosol generating device and / or the supporting device. Therefore, the external computing device can be configured to communicate wirelessly and / or wired with the aerosol generating device, the supporting device, or both. For example, the external computing device can be configured to communicatively couple with the aerosol generating device and / or the supporting device via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection, a mobile phone network, a 3G / 4G / 5G connection, etc., an edge connection, an LTE connection, a bus connection, a wireless connection, a wired connection, a radio connection, a near-field connection, an IoT connection, or any other connection using any appropriate communication protocol.
[0050] As used herein, the term "locked state" may refer to a locked configuration of the aerosol generating device, and the term "unlocked state" may refer to an unlocked configuration of the aerosol generating device. In the locked state or configuration, the aerosol generating device is prohibited from delivering and / or generating an aerosol. This may mean that the aerosol generating device is locked in the locked state so that the aerosol is not consumed by the user, and / or the aerosol generating device is configured in the locked state so that the aerosol cannot be delivered and / or generated. On the other hand, in the unlocked state or configuration, the aerosol generating device is allowed or permitted to deliver and / or generate an aerosol. This may mean that the aerosol generating device is unlocked in the unlocked state so that the aerosol is consumed by the user, and / or the aerosol generating device is configured in the unlocked state so that the aerosol can be delivered and / or generated. Thus, when the aerosol generating device is in a locked state, the aerosol generating device may not be actuated by the user to deliver and / or generate an aerosol, and when the aerosol generating device is in an unlocked state, the aerosol generating device may be actuated by the user to deliver and / or generate an aerosol. In other words, in the locked state of the aerosol generating device, the user may be prohibited from accessing one or more functions or functionalities of the aerosol generating device, including aerosol delivery and / or generation; and in the unlocked state of the aerosol generating device, the user may be allowed to access one or more functions or functionalities of the aerosol generating device, including aerosol delivery and / or generation. Additionally or alternatively, the accessory device may be configured to charge the energy storage device of the aerosol generating device only when the user has been successfully authenticated. In this example, the locked state may be regarded as a state in which the energy storage device of the aerosol generating device does not contain a charge sufficient to generate an aerosol, and the unlocked state may be regarded as a state in which the energy storage device contains a charge sufficient to generate an aerosol. The authentication signal may then be regarded as a charge provided by the accessory device to the energy storage device of the aerosol generating device. In the locked state, the control circuit system may, for example, be configured to prohibit activation of the heating elements based on at least one of: disabling at least one heating element, disabling an energy supply device for supplying electrical energy to at least one heating element, and disabling an input element for actuating at least one heating element by a user.
[0051] As used herein, the term "convert" may mean causing, configuring and / or switching the aerosol generating device to a locked or unlocked state, which may mean or include actuating and / or configuring the aerosol generating device so that the aerosol generating device is in a locked state or an unlocked state.
[0052] As used herein, the term "authentication" refers to verifying the identity of a user.
[0053] As used herein, the term "authorization" refers to determining the access rights of a user, i.e., their authority to switch the aerosol generating device from a locked state to an unlocked state. Since in the context of the YAP method, the identity of a user is inherently closely related to their access rights, the terms "authentication" and "authorization" may be used interchangeably in this disclosure.
[0054] As used herein, the term "authorized user" (also referred to as "authenticated user") may refer to or represent an owner of an aerosol generating device, an adult, an adult individual, an adult user, a user who has reached an age threshold, a user who has reached the age of majority, and / or a user who has been authorized by another authorized user (e.g., by the owner) to configure the aerosol generating device. In addition, an unauthorized user may refer to or represent a minor user, a user who has not reached the age threshold, a child, or any other user who is not authorized to configure the aerosol generating device, in particular a user who is not authorized to convert the aerosol generating device into an unlocked state to consume the aerosol.
[0055] As used herein, the term "circuitry" may include, for example, hard-wired circuitry, programmable circuitry (e.g., a computer processor including one or more individual instruction processing cores), state machine circuitry, and / or firmware storing instructions executed by the programmable circuitry, alone or in any combination. Modules may collectively or individually be embodied as circuitry that forms part of one or more devices or systems as described herein.
[0056] As used herein, the term "obtaining" may include, for example, receiving from another system, device, or process; receiving via interaction with a user; loading or retrieving from a storage device or memory; measuring or capturing using a sensor or other data acquisition device.
[0057] As used herein, the term "determining" encompasses a wide variety of actions and may include, for example, calculating, computing, processing, deriving, investigating, looking up (e.g., looking up in a table, a database, or another data structure), ascertaining, etc. Additionally, "determining" may include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), etc. Additionally, "determining" may include resolving, selecting, choosing, establishing, etc.
[0058] The indefinite article "a" or "an" does not exclude a plurality. In addition, unless otherwise indicated or clear from the context, the terms "a" and "an" as used herein should generally be interpreted as meaning "one or more" to refer to the singular.
[0059] Unless otherwise specified or clear from the context, the phrases "one or more of A, B, and C," "at least one of A, B, and C," and "A, B, and / or C" as used herein are intended to mean all possible permutations of one or more of the listed items. That is, the phrase "A and / or B" means (A), (B), or (A and B), and the phrase "A, B, and / or C" means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).
[0060] The term "comprising" does not exclude other elements or steps. In addition, the terms "including", "comprising", "having" and the like can be used interchangeably in this document.
[0061] A non-exhaustive list of non-limiting examples is provided below.Any one or more features of these examples may be combined with any one or more features of another example, embodiment or aspect described herein.
[0062] Ex. 1. A control circuit system for an aerosol generating device or for an aerosol generating system including the aerosol generating device, the aerosol generating device having a locked state and an unlocked state, in which the aerosol generating device is prohibited from delivering aerosol, and in which the aerosol generating device is allowed to deliver aerosol, the control circuit system is configured to perform an authentication process for authenticating a user, the control circuit system being configured to:
[0063] allowing the user a first predetermined number of attempts to enter valid authentication information using one or more user interface components during an offline phase of the authentication process;
[0064] in response to receiving valid authentication information from the user before a first predetermined number of attempts has been exceeded, determining to transition the aerosol generating device from the locked state to the unlocked state; and
[0065] In response to determining that the first predetermined number of attempts has been exceeded before the user has entered valid authentication information, an online phase of the authentication process is conducted.
[0066] Ex.2. The control circuit system according to Ex.1, wherein the control circuit system is configured to:
[0067] responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, wherein the second predetermined number of attempts is lower than the first predetermined number of attempts; and
[0068] If the second predetermined number of attempts has been exceeded, the offline phase is delayed until a first delay period has expired.
[0069] Ex. 3. The control circuit system of Ex. 2, wherein the control circuit system is configured to continue the offline phase without delay if the second predetermined number of attempts is not exceeded.
[0070] Ex.4. A control circuit system according to Ex.2 or Ex.3, wherein the control circuit system is configured to:
[0071] responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a third predetermined number of attempts has been exceeded, wherein the third predetermined number of attempts is lower than the first predetermined number of attempts and higher than the second predetermined number of attempts; and
[0072] If the third predetermined number of attempts has been exceeded, the offline phase is delayed until a second delay period has expired.
[0073] Ex. 5. The control circuit system of Ex. 4, the control circuit system being configured to continue the offline phase without delay if the third predetermined number of attempts is not exceeded.
[0074] Ex.6. A control circuit system according to Ex.4 or Ex.5, wherein the second delay period is longer than the first delay period.
[0075] Ex.7. A control circuit system according to any one of Ex.2-Ex.6, wherein the control circuit system is configured to delay the offline phase by prohibiting the user from using the one or more user interface components to input additional authentication information or by avoiding authenticating the user based on additional authentication information input by the user.
[0076] Ex.8. A control circuit system according to any one of Ex.1-Ex.7, wherein the control circuit system is configured to receive authentication information input by a user from the one or more user interface components during each attempt in the offline phase, and to authenticate the user by determining the validity of the authentication information input by the user.
[0077] Ex.9. According to the control circuit system of Ex.8, the control circuit system is configured to receive the authentication information input by the user during multiple time windows of predetermined duration, each time window corresponding to a corresponding number of the digital sequence forming the authentication information, and attribute the user input received via the one or more user interface components during the time window to the number corresponding to the time window.
[0078] Ex.10. A control circuit system according to Ex.9, wherein the control circuit system is configured to trigger a timeout in response to one or more user interface components not receiving user input within a predetermined time period starting from the starting point of a corresponding time window in the time window.
[0079] Ex.11. A control circuit system according to Ex.9 or Ex.10, wherein the control circuit system is configured to start a first time window among the time windows in response to a user interacting with the one or more user interface components.
[0080] Ex.12. A control circuit system according to Ex.11, wherein the control circuit system is configured to start a first time window among the time windows in response to receiving a predetermined signal generated by the user interacting with the one or more user interface components.
[0081] Ex.13. A control circuit system according to Ex.12, wherein the one or more user interface components include a button, and the predetermined signal is generated by the user pressing the button a predetermined number of times.
[0082] Ex.14. A control circuit system according to any one of Ex.9-Ex.13, wherein there is a preparatory time window before and / or during one or more of the time windows, and wherein the control circuit system is configured to determine that an attempt by the user to input valid authentication information is unsuccessful if no authentication input by the user is received during the preparatory time window, and to store the received authentication input by the user and start the corresponding time window and / or continue running the corresponding time window if authentication input by the user is received during the preparatory time window.
[0083] Ex.15. A control circuit system according to any one of Ex.9-Ex.14, wherein the control circuit system is configured to control the user interface component to output a user-perceivable guidance signal indicating at least the starting point of the corresponding time window.
[0084] Ex.16. A control circuit system according to any one of Ex.9-Ex.15, wherein the control circuit system is configured to control the user interface component to output a user-perceivable guidance signal indicating that the time window is running.
[0085] Ex.17. A control circuit system according to any one of Ex.9-Ex.16, wherein the control circuit system is configured to control the user interface component to output a user-perceptible guidance signal, wherein the user-perceptible guidance signal indicates which number of the sequence the user is being guided to provide input for.
[0086] Ex.18. A control circuit system according to Ex.17, wherein the aerosol generating device is provided with a certain number of output elements, the number of the output elements corresponding to the number of numbers in the sequence, and wherein the control circuit system is configured to use the position of the active output element relative to the inactive output element to indicate the position of the number within the sequence for its expected input.
[0087] Ex.19. A control circuit system according to any one of Ex.9-Ex.18, wherein the control circuit system is configured to interpret multiple signals generated by the user's repeated operation of the same user interface component during the time window as encoded input signals of the sequence of numbers that define the time window.
[0088] Ex.20. A control circuit system according to Ex.19, wherein the user interface component is a power button of the aerosol generating device.
[0089] Ex.21. A control circuit system according to any one of Ex.1-Ex.20, wherein the control circuit system is configured to: during an online phase of the authentication process:
[0090] transmitting an unlock request to a server to transition the aerosol generating device from the locked state to the unlocked state, wherein optionally the unlock request includes unique device identification information identifying the aerosol generating device and / or a time-limited presentment information corresponding to an unlockable feature of the aerosol generating device;
[0091] receiving an unlock authorization from the server in response to the transmitted unlock request; and
[0092] In response to receiving the unlock authorization, the aerosol generating device is transitioned from the locked state to the unlocked state.
[0093] Ex. 22. A control circuit system according to Ex. 21, wherein the unlockable feature includes the ability to heat the aerosol generating article using a heating element of the aerosol generating device to generate an aerosol therefrom.
[0094] Ex.23. A control circuit system according to Ex.21 or Ex.22, wherein the unlocking authorization is at least partially encrypted.
[0095] Ex.24. A control circuit system according to Ex.23, wherein the unlocking authorization is decryptable using a public key stored on the aerosol generating device.
[0096] Ex.25. A control circuit system according to any one of Ex.21-Ex.24, wherein the control circuit system is configured to, in response to receiving the unlock authorization, convert the aerosol generating device from the locked state to the unlocked state by: decrypting the unlock authorization; determining whether the decrypted unlock authorization includes the unique device identification information and the time limit current information; and unlocking the unlockable feature in response to determining that the decrypted unlock authorization includes the unique device identification information and the time limit current information.
[0097] Ex.26. A control circuit system according to any one of Ex.21-Ex.25, wherein the control circuit system is configured to terminate unlocking the unlockable feature if the unlock authorization is not received after a valid time period after transmitting the unlock request to the server.
[0098] Ex.27. A control circuit system according to any one of Ex.21-Ex.26, wherein the control circuit system is configured to limit the number of unlock authorizations transmitted to the aerosol generating device.
[0099] Ex.28. A control circuit system according to any of Ex.21-Ex.27, wherein the unique device identification includes a serial number.
[0100] Ex.29. A control circuit system according to any one of Ex.1-Ex.28, wherein the authentication process includes a youth access prevention process.
[0101] Ex.30. A control circuit system according to any one of Ex.1-Ex.29, wherein the control circuit system is configured to respond to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining not to transition the aerosol generating device from the locked state to the unlocked state.
[0102] Ex.31. A control circuit system according to any one of Ex.1-Ex.30, wherein the control circuit system is configured to determine the validity of authentication information input by a user using a key derivation mechanism.
[0103] Ex.32. An aerosol generating device comprising a control circuit system according to any one of Ex.1-Ex.31.
[0104] Ex.33. An aerosol generating system comprising a control circuit system according to any one of Ex.1-Ex.31 and the aerosol generating device.
[0105] Ex.34. A supporting device for an aerosol generating device, the supporting device comprising a control circuit system according to any one of Ex.1-Ex.31.
[0106] Ex. 35. A method for performing an authentication process for authenticating a user of an aerosol generating device, the aerosol generating device having a locked state and an unlocked state, wherein the aerosol generating device is prohibited from delivering an aerosol and wherein the aerosol generating device is permitted to deliver an aerosol, the method comprising:
[0107] allowing the user a first predetermined number of attempts to enter valid authentication information using one or more user interface components during an offline phase of the authentication process;
[0108] in response to receiving valid authentication information from the user before a first predetermined number of attempts has been exceeded, determining to transition the aerosol generating device from the locked state to the unlocked state; and
[0109] In response to determining that the first predetermined number of attempts has been exceeded before the user has entered valid authentication information, an online phase of the authentication process is conducted.
[0110] Ex.36. The method according to Ex.35, comprising:
[0111] responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, wherein the second predetermined number of attempts is lower than the first predetermined number of attempts; and
[0112] If the second predetermined number of attempts has been exceeded, the offline phase is delayed until a first delay period has expired.
[0113] Ex.37. A method according to Ex.36, comprising continuing the offline phase without delay if the second predetermined number of attempts is not exceeded.
[0114] Ex.38. A method according to Ex.36 or Ex.37, comprising:
[0115] responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a third predetermined number of attempts has been exceeded, wherein the third predetermined number of attempts is lower than the first predetermined number of attempts and higher than the second predetermined number of attempts; and
[0116] If the third predetermined number of attempts has been exceeded, the offline phase is delayed until a second delay period has expired.
[0117] Ex.39. A method according to Ex.38, comprising continuing the offline phase without delay if the third predetermined number of attempts is not exceeded.
[0118] Ex.40. A method according to Ex.38 or Ex.39, wherein the second delay period is longer than the first delay period.
[0119] Ex.41. A method according to any one of Ex.36-Ex.40, comprising delaying the offline phase by prohibiting the user from entering additional authentication information using the one or more user interface components or by avoiding authenticating the user based on additional authentication information entered by the user.
[0120] Ex.42. A method according to any one of Ex.35-Ex.41, comprising receiving authentication information input by a user from the one or more user interface components during each attempt in the offline phase, and authenticating the user by determining the validity of the authentication information input by the user.
[0121] Ex.43. The method according to Ex.42 includes receiving authentication information input by the user during multiple time windows of predetermined duration, each time window corresponding to a corresponding number of a numerical sequence forming the authentication information, and attributing the user input received via the one or more user interface components during the time window to the number corresponding to the time window.
[0122] Ex.44. A method according to Ex.43, comprising triggering a timeout in response to the one or more user interface components not receiving user input within a predetermined time period starting from the starting point of a corresponding time window in the time window.
[0123] Ex.45. A method according to Ex.43 or Ex.44, comprising starting a first time window of the time windows in response to a user interacting with the one or more user interface components.
[0124] Ex.46. A method according to Ex.45, comprising starting a first time window among the time windows in response to receiving a predetermined signal generated by the user interacting with the one or more user interface components.
[0125] Ex.47. A method according to Ex.46, wherein the one or more user interface components include a button, and the predetermined signal is generated by the user pressing the button a predetermined number of times.
[0126] Ex.48. A method according to any one of Ex.43-Ex.47, wherein there is a preparatory time window before and / or during one or more time windows in the time window, and the method further includes determining that an attempt by the user to input valid authentication information is unsuccessful if no user-input authentication is received during the preparatory time window, and if user-input authentication is received during the preparatory time window, storing the received user-input authentication and starting the corresponding time window and / or continuing to run the corresponding time window.
[0127] Ex.49. A method according to any one of Ex.43-Ex.48, comprising controlling the user interface component to output a user-perceivable guidance signal indicating at least the starting point of the corresponding time window.
[0128] Ex.50. A method according to any one of Ex.43-Ex.49, comprising controlling the user interface component to output a user-perceivable guidance signal indicating that the time window is running.
[0129] Ex.51. A method according to any one of Ex.43-Ex.50, comprising controlling the user interface component to output a user-perceptible guidance signal, wherein the user-perceptible guidance signal indicates which number of the sequence the user is being guided to provide input for.
[0130] Ex.52. A method according to Ex.51, wherein the aerosol generating device is provided with a certain number of output elements, the number of the output elements corresponding to the number of numbers in the sequence, and the method further comprises using the position of the active output element relative to the inactive output element to indicate the position of the number for its expected input within the sequence.
[0131] Ex.53. A method according to any one of Ex.43-Ex.52, comprising interpreting multiple signals generated by the user's repeated operation of the same user interface component during the time window as coded input signals of numbers that define a sequence corresponding to the time window.
[0132] Ex.54. A method according to Ex.53, wherein the user interface component is a power button of the aerosol generating device.
[0133] Ex.55. A method according to any of Ex.35-Ex.54, comprising during an online phase of the authentication process:
[0134] transmitting an unlock request to a server to transition the aerosol generating device from the locked state to the unlocked state, wherein the unlock request includes unique device identification information identifying the aerosol generating device and a time-limited nonce corresponding to an unlockable feature of the aerosol generating device;
[0135] receiving an unlock authorization from the server in response to the transmitted unlock request; and
[0136] In response to receiving the unlock authorization, the aerosol generating device is transitioned from the locked state to the unlocked state.
[0137] Ex.56. A method according to Ex.55, wherein the unlockable feature includes the ability to heat the aerosol-generating article using a heating element of the aerosol-generating device to generate an aerosol therefrom.
[0138] Ex.57. A method according to Ex.55 or Ex.56, wherein the unlocking authorization is at least partially encrypted.
[0139] Ex.58. A method according to Ex.57, comprising decrypting the unlocking authorization using a public key stored on the aerosol generating device.
[0140] Ex.59. According to any one of Ex.55-Ex.58, the method includes, in response to receiving the unlock authorization, converting the aerosol generating device from the locked state to the unlocked state by the following operations: decrypting the unlock authorization; determining whether the decrypted unlock authorization includes the unique device identification information and the time limit current information; and unlocking the unlockable feature in response to determining that the decrypted unlock authorization includes the unique device identification information and the time limit current information.
[0141] Ex.60. A method according to any of Ex.55-Ex.59, comprising terminating unlocking the unlockable feature if the unlock authorization is not received after a valid time period after transmitting the unlock request to the server.
[0142] Ex.61. A method according to any of Ex.55-Ex.60, comprising limiting the number of unlock authorizations transmitted to the aerosol generating device.
[0143] Ex.62. A method according to any of Ex.55-Ex.61, wherein the unique device identification includes a serial number.
[0144] Ex.63. A method according to any one of Ex.35-Ex.62, wherein the authentication process includes a youth access prevention process.
[0145] Ex.64. A method according to any of Ex.35-Ex.63, comprising responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining not to transition the aerosol generating device from the locked state to the unlocked state.
[0146] Ex.65. A method according to any one of Ex.35-Ex.64, comprising using a key derivation mechanism to determine the validity of authentication information input by a user.
[0147] Ex.66. A method according to any one of Ex.35-Ex.65, wherein the method is performed by the aerosol generating device.
[0148] Ex.67. A method according to any one of Ex.35-Ex.66, wherein the method is performed by an aerosol generating system including the aerosol generating device.
[0149] Ex.68. A method according to any one of Ex.35-Ex.67, wherein the method is performed by a supporting device for the aerosol generating device.
[0150] Ex.69. A computer program comprising instructions that, when executed by a computing system, cause the computing system to perform a method according to any one of Ex.35-Ex.68.
[0151] Ex.70. A computer-readable medium comprising instructions that, when executed by a computing system, cause the computing system to perform a method according to any one of Ex.35-Ex.68.
[0152] The present invention may include one or more aspects, examples or features in isolation or combination, whether specifically disclosed in that combination or disclosed separately.Any optional feature or sub-aspect of one of the above aspects is applicable to any other aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0153] Several examples will now be further described with reference to the accompanying drawings, in which:-
[0154] Figure 1 schematically illustrates an aerosol generating system comprising an aerosol generating device;
[0155] Figure 2 Schematically shows Figure 1 Part of an associated device in an aerosol generating system;
[0156] Figure 3 Schematically shows the Figure 1 An external computing device for use in conjunction with an aerosol generating system;
[0157] Figure 4For authentication purposes Figure 1 A flow chart of an authentication process for a user of an aerosol generating device;
[0158] Figure 5 A flowchart illustrating a method of generating authentication information and sending it to a user; and
[0159] Figure 6 A flow chart is provided to illustrate a method for activating a device, the method comprising steps from factory preparation to user activation.
[0160] The drawings are merely schematic and not drawn to scale. DETAILED DESCRIPTION
[0161] Figure 1 An aerosol generating system 500 for generating an aerosol, for example for consumption by a user, is shown. The system 500 comprises an aerosol generating device 100 for generating an aerosol and a companion device 300 for at least partially receiving the aerosol generating device 100 and for charging the aerosol generating device 100.
[0162] The aerosol generating device 100 comprises an insertion opening 101 for at least partially inserting an aerosol generating article (not shown). The aerosol generating article may comprise an aerosol forming substrate (eg a tobacco containing substrate), and / or a cartridge comprising a liquid. The aerosol forming substrate may comprise nicotine.
[0163] The aerosol generating device 100 also includes a control circuitry 102 having one or more processors 103. The control circuitry 102 may be configured to control actuation, activation and / or deactivation of the at least one heating element 120.
[0164] The aerosol generating device 100 also includes a user interface component that includes an input element in the form of a button 104. The button 104 can be actuated by a user to input a PIN code into the control circuit system 102, as further described below. After successfully completing the authentication process, the button 104 can also be used as a power button to activate or deactivate the heating element 120 for aerosol generation, thereby activating or deactivating the aerosol generating device 100. The button 104 can also include an output element (e.g., one or more waveguides that transmit light from (one or more) LEDs) for indicating the state of the device 100 to the user. These options simplify the device 100. When the aerosol generating device 100 is activated, the heating element 120 can be activated and heat can be applied to at least a portion of the aerosol generating article so that an aerosol can be generated for consumption by the user. When the aerosol generating device 100 is deactivated, the heating element 120 may be deactivated so that no heat may be applied to at least a portion of the aerosol generating article or reduced heat may be applied to at least a portion of the aerosol generating article so that an aerosol cannot be generated for consumption by the user. The user interface component also includes an output element in the form of an LED array 112 (or a single LED) and / or a tactile output element (not shown) for providing tactile pulses. The output element provides a user with a user-perceivable guidance signal. The LED array 112 may also be used to indicate the charge level of at least one energy storage device 122, for example, indicating that at least one energy storage device should be charged, etc. The LED array 112 may also be used to indicate the configuration or state of the aerosol generating device 100, for example, whether the aerosol generating device is in a locked state or an unlocked state.
[0165] The aerosol generating device 100 also includes a communication system 106 having one or more communication interfaces 108 for communicatively coupling the aerosol generating device 100 with a supporting device 300, for example via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection, a mobile phone network, a 3G / 4G / 5G connection, an edge connection, an LTE connection, a BUS connection, a wireless connection, a wired connection, a radio connection, a near-field connection, and / or an IoT connection.
[0166] The aerosol generating device 100 further comprises a data storage device 110 for storing information or data, such as at least one authentication indicator and / or other data.
[0167] The aerosol generating device 100 also includes at least one electrical connector 114 for connecting to a corresponding at least one electrical connector 313 of the accessory device 300. For example, when the aerosol generating device 100 is at least partially inserted into the opening 301 of the accessory device 300, one or more electrical connectors 114 of the aerosol generating device 100 can be connected to one or more electrical connectors 313 of the accessory device 300 to charge the at least one energy storage device 122 of the aerosol generating device 100.
[0168] In order to generate an aerosol during use or consumption of the aerosol-generating article, the aerosol-generating device 100 comprises at least one heating element 120 or heat source 120 for applying heat to at least a portion of the aerosol-generating article.
[0169] In order to power the at least one heating element 120 with electricity, the aerosol generating device 100 further comprises at least one energy storage device 122 or energy supply device 122 for storing electrical energy or electricity.
[0170] The aerosol generating device 100 has a locked state in which the aerosol generating device 100 is prohibited from delivering aerosol and an unlocked state in which the aerosol generating device 100 is permitted to deliver aerosol.
[0171] In use, the control circuit system 102 is configured to: during an offline phase of the authentication process, allow the user to make a first predetermined number of attempts to enter valid authentication information using one or more user interface components; in response to receiving valid authentication information from the user before the first predetermined number of attempts has been exceeded, determine to transition the aerosol generating device from the locked state to the unlocked state; and in response to determining that the first predetermined number of attempts has been exceeded before the user has entered valid authentication information, perform an online phase of the authentication process.
[0172] A non-limiting example of the authentication process will now be described. In this non-limiting example, the authentication process includes a YAP process, which is converted from an offline phase to an online phase after multiple failed attempts. In this non-limiting example, the user uses button 104 to enter a four-digit PIN code (where each digit is within the range of 1 to 9). Once the PIN has been entered incorrectly multiple times, the user must connect the aerosol generating device 100 to an external computing device, such as a smartphone via Bluetooth, or a personal computer via USB. This allows the user to use a website provided for this purpose to perform the online phase of the YAP process. Once the age verification process is successfully performed on the website, the aerosol generating device 100 is automatically unlocked.
[0173] To enter the offline phase of the YAP process, the user presses the button 104 five times within a 3 second period. The aerosol generating device 100 reacts with a 1 second tactile pulse, and the first LED (hereinafter referred to as LED1) of the LED array 112 begins to flash to indicate to the user that the first digit must be entered into the aerosol generating device 100. Therefore, the first LED (LED1) corresponds to the first digit of the PIN code. In this way, the control circuit system 102 controls the LED array 112 to indicate which digit of the PIN code the user is being guided to provide input for. In addition, the flashing of LED1 indicates to the user that the first time window is running, during which the first digit should be entered. The start of the flashing indicates the start of the time window. The control circuit system 102 interprets the multiple signals generated by the user's repeated operation of the button 104 during the first time window as coded input signals defining the first digit of the PIN code. In an illustrative example, if the user wishes to enter the PIN code 3521, the button 104 must be pressed three times while LED1 flashes during the first time window. The three signals generated by repeated presses of button 104 during the first time window define a coded input signal that is interpreted by control circuitry 102 as the number “3.” After having received the number during the first time window, the number is correspondingly attributed by control circuitry 102 to the first digit of the PIN code.
[0174] In order to allow the user enough time to start pressing button 104, a double timeout is implemented. The first timeout is configured at 15 seconds to allow the user enough time to understand the process. If button 104 is not pressed within this first 15 seconds, the control circuit system determines not to convert device 100 to an unlocked state. In one example, device 100 shuts down in response to triggering the first timeout. Once button 104 is pressed once (before the first timeout expires), the second timeout begins, and the user has another 7 seconds to complete the first digit before the end of the first time window. The end of the first time window defines the point in time when control circuit system 102 no longer attributes the received user input to the first digit.
[0175] At the end of the first time window, LED1 turns off and LED2 begins flashing to indicate that the user is being guided to enter a second digit during a second time window having a predetermined duration of 7 seconds. While LED2 is flashing during the second time window, the user must press button 104 five times (for the exemplary PIN code 3521) to generate a coded input signal defining the second digit of the PIN code.
[0176] At the end of the second time window, LED2 turns off and LED3 starts flashing to invite the user to enter a third number. Continuing with the exemplary PIN code 3521, the user must press button 104 twice while LED3 flashes during the 7 second third time window.
[0177] At the end of the third time window, LED3 turns off and LED4 starts flashing to invite the user to enter the fourth and last digit. After the above example, when LED4 flashes, the user must press button 104 only once. At the end of the fourth time window, LED4 turns off and all LEDs start flashing for 3 seconds simultaneously.
[0178] In this manner, control circuit system 102 receives user input during multiple time windows of predetermined duration. Each time window corresponds to a respective digit of the PIN code: the first time window corresponds to the first digit, the second time window corresponds to the second digit, etc. Control circuit system 102 attributes user input received via button 104 during one of the time windows to the digit corresponding to the time window: user input received during the first time window is attributed to the first digit, user input received during the second time window is attributed to the second digit, and so on.
[0179] After the final time window has ended, the control circuit system 102 compares the PIN code entered by the user with the pre-stored reference PIN code, and determines whether to switch the aerosol generating device 100 from the locked state to the unlocked state based on the result of the comparison. If the PIN code is successfully entered, the device 100 is switched to the unlocked state and the device 100 becomes usable. If the PIN is entered incorrectly, the control circuit system 102 determines not to switch the aerosol generating device 100 from the locked state to the unlocked state, and allows additional attempts according to the following protocol:
[0180] After 5 failed attempts, the user must wait 5 minutes;
[0181] After another 5 failed attempts, the user must wait 20 minutes;
[0182] After a further 5 failed attempts, the user must proceed to the online phase of the YAP process.The offline phase of the YAP process thus ends, and the aerosol generating device 100 can only be unlocked during the online phase.
[0183] In one non-limiting example, the online phase of the YAP process includes the following steps:-
[0184] 1. The device 100 transmits an unlock request to the server 1000 , the unlock request comprising unique device identification information (eg its serial number) and current information corresponding to the unlockable features of the aerosol generating device 100 .
[0185] 2. If the user is authorized, the device 100 receives an unlock authorization that is at least partially encrypted from the server 1000 .
[0186] 3. The device 100 decrypts the unlocking authorization using the public key stored on the aerosol generating device 100 .
[0187] 4. Device 100 determines whether the decrypted unlock authorization includes unique device identification information and nonce information.
[0188] 5. If included, the device 100 transitions from the locked state to the unlocked state.
[0189] In a variation of this example, the nonce is time-limited, so that if unlock authorization is not received after a validity period following transmission of an unlock request to the server, the process is terminated and optionally restarted from step 1 .
[0190] In another non-limiting example, the online phase of the YAP process includes the following steps:-
[0191] 1. Server 1000( Figure 3 ) requests the current state of the feature it wishes to lock or unlock.
[0192] 2. The aerosol generating device 100 returns to the characteristic state.
[0193] 3. If the server 1000 wishes to change the feature state, it requests unique information of the aerosol generating device 100, such as its serial number.
[0194] 4. The aerosol generating device 100 sends this to the server 1000 .
[0195] 5. Next, the server 1000 requests the aerosol generating device 100 to generate a unique value (nonce) associated with the lock or unlock feature.
[0196] 6. The aerosol generating device 100 generates a nonce and sends it to the server 1000 .
[0197] 7. The aerosol generating device 100 starts a validity timer during which the unlocking process must be completed. If the procedure is unsuccessful or is not completed within the validity time, the current process is invalidated and restarts from step 1.
[0198] 8. The server 1000 creates a string (hereinafter referred to as a "message") consisting of the lock / unlock request, the unique information of the aerosol generating device 100, a nonce and some additional padding.
[0199] 9. The server 1000 encrypts the message using the asymmetric private key and sends the result (the encrypted message) to the aerosol generating device 100 .
[0200] 10. The aerosol generating device 100 receives the encrypted message and decrypts it using the public key of the server 1000 (which is stored on the aerosol generating device 100 ).
[0201] 11. The aerosol generating device 100 verifies that the decrypted message complies with the predefined format and contains the original nonce, unique device information, and requests a state change of the feature associated with the nonce.
[0202] If all of the above conditions are met, and the validity timer has not been exceeded, the aerosol generating device 100 changes the state of the feature. If not, the process is invalid and must be restarted from step 1.
[0203] In any of the above non-limiting examples, the PIN code may be generated by a key derivation mechanism (not shown) on the aerosol generating device 100. The key derivation mechanism is symmetric, meaning that the server generates the same PIN code as the aerosol generating device 100.
[0204] It should be understood that the above operations described as being performed under the control of the control circuit system 102 of the aerosol generating device 100 may equally be performed by the control circuit system 302 of the companion device 100 (as described below), or by the system 500 as a whole, where control is distributed between the control circuit system 102 of the aerosol generating device 100 and the control circuit system 302 of the companion device 300. In addition, the user interface components for input and output of information may include user interface components of the aerosol generating device 100, user interface components of the companion device 300 (described below), or any combination of input and output elements of the aerosol generating device 100 and the companion device 300. To further illustrate these possibilities, the companion device 300 will now be described.
[0205] The accessory device 300 may be configured for physically coupling the aerosol generating device 100. In order to at least partially receive the aerosol generating device 100 and / or to physically couple the aerosol generating device 100 to the accessory device 300, the accessory device 300 comprises an opening 301 or a receiving opening 301 into which the aerosol generating device 100 may be at least partially inserted, for example to store and / or support the aerosol generating device 100. Optionally, the accessory device 300 may comprise a cover for opening and closing the opening 301. Additionally or alternatively, the accessory device 300 may be configured to at least partially receive the aerosol generating device 100 based on a mechanical attachment or coupling mechanism (e.g., a hook mechanism, a latch mechanism, a snap fit, etc.) that couples the aerosol generating device 100 to the accessory device 300. Additionally or alternatively, the accessory device 300 may be configured to at least partially receive the aerosol generating device 100 based on coupling the aerosol generating device 100 to the accessory device 300 by means of a magnetic or electromagnetic coupling. To this end, the accessory device 300 includes a charger module 312 or charger circuit system 312 connected to the electrical connector 313. The charger module 312 may, for example, be connected to a power grid for powering the energy storage device 122 of the aerosol generating device 100. In addition or alternatively, the accessory device 300 may include one or more batteries, accumulators, capacitors, etc. The accessory device 300 includes a user interface component, which includes a button 304 and a visual indicator 314, such as one or more LEDs 314 and / or an LED array 314. The accessory device 300 also includes a data storage device 306 for storing information or data (e.g., authentication indicators, reference authentication information, and / or other data). The control circuit system 302, the data storage device 306, and the user interface component may be embodied in a single unit. In this way, a user can be authenticated without the authentication information leaving the single unit, thereby improving security. The supporting device 300 also includes a communication device 308, which has one or more communication interfaces 310 for communicatively coupling the supporting device 300 with the aerosol generating device 100, for example via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection, a mobile phone network, a 3G / 4G / 5G connection, an edge connection, an LTE connection, a BUS connection, a wireless connection, a wired connection, a radio connection, a near-field connection and / or an IoT connection.
[0206] The accessory device 300 also includes a control circuit system 302 having one or more processors 303. The control circuit system 302 can be configured to control a charger module 312 and / or other components or functions of the accessory device 300. It should be noted that the charger circuit system or module 312 can also be combined with or included in the control circuit system 302. The control circuit system can be configured to perform the authentication process as described herein. Therefore, the user performs the offline phase of the authentication process by interacting with the accessory device 300 instead of interacting with the aerosol generating device 100. The control circuit system 302 can unlock or lock the aerosol generating device in various different ways (e.g., by sending an unlock signal to the aerosol generating device) after successfully authenticating the user.
[0207] Figure 2 300 is a block diagram showing the supporting device 300 in more detail. Specifically, Figure 2 At least a portion 305 of the control circuit system 302 is schematically shown, the at least a portion including at least one processor 303 and connected to the button 304 via a multiplexer 307. Part 305 may be connected to or include a charger circuit system 312 and / or other electrical components of the accessory device 300. For example, Figure 2 At least a portion 305 of the control circuit system 302 exemplarily shown in the figure may refer to the main controller 305 of the supporting device 300. In addition, a port 309 such as a single-line MT communication port (referred to as an "MTRTX" port) can be used to connect the control circuit system 302 to the multiplexer 307. This single-line communication can be converted into a two-line communication via the multiplexer 307. For example, a signal can be transmitted from the multiplexer 307 to the input port 315 (e.g., RX port) of the button 304, and a signal can be transmitted from the output port 317 (e.g., TX port) of the button 304 to the multiplexer 307. Among them, the multiplexer 307 can be controlled by the control circuit system 302 via the port 311. In addition, in Figure 2 In the example shown, at least one communication interface 310 is combined with or integrated into the electrical connector 313, so that an electrical connection for charging the energy storage device 122 of the aerosol generating device 100 and a communication coupling between the aerosol generating device 100 and the matching device 300 can be established via the (one or more) electrical connectors 114 of the aerosol generating device 100 and the (one or more) connectors 313 of the matching device.
[0208] Figure 3An external computing device 700 is shown, which may or may not be used in conjunction with the aerosol generating system 500. The external computing device 700 includes a user interface 702, control circuitry 704 including one or more processors 705 for data processing, a communication interface 706 for communicatively coupling the external computing device 700 to one or more of the server 1000 or the aerosol generating system 500, and a data storage device 708 for storing data or information.
[0209] Figure 4 A flow chart illustrating a method for performing an authentication process for authenticating a user of an aerosol generating device 100 is shown. Unless otherwise stated, the aerosol generating device 100 includes the same features, elements and / or functions as described elsewhere herein. Step 401 includes performing an offline phase of the authentication process, during which a user is allowed a first predetermined number of attempts to enter valid authentication information. Step 402 includes determining whether a successful authentication has been achieved during the offline phase. That is, whether valid authentication information has been received from the user before the first predetermined number of attempts has been exceeded. If so, the method proceeds to step 404, at which it is determined to transition the aerosol generating device 100 from a locked state to an unlocked state. Otherwise, the method proceeds to the online phase of the authentication process in step 403. After successfully resolving the online phase, the method again proceeds to step 404. Otherwise, as described above, the online phase may be repeated. Figure 4 The method shown in may include numerous alternative or additional steps as described elsewhere herein.
[0210] Figure 5 A flow chart illustrating a method is shown in which step 501 includes generating authentication information for an offline phase of an authentication process. Step 502 includes sending the authentication information to a user to be input as user-entered authentication information to the control circuit system 102 and / or 302. Unless otherwise stated, the aerosol generating device 100 and the control circuit system 102 and / or 302 include the same features, elements and / or functions as described elsewhere herein. Figure 5 The method shown in may include numerous alternative or additional steps as described elsewhere herein.
[0211] Figure 6To illustrate a flow chart of a method for device activation, the method includes steps from factory preparation to user activation. Step 601 includes storing a PIN code in the encrypted firmware of the aerosol generating device 100 at the factory. The user then obtains the device 100 and activates the device for use using one of the processes starting from steps 602, 607 and 609, respectively. In the case where the user has registered, the method proceeds to step 602, where the hard age verification is performed if it has not been completed. Step 603 includes registering the device 100 to the user if the registration has not been completed. Step 604 includes the user entering or scanning an identification code ("codentify") on a website to generate a PIN code as described elsewhere herein. Step 605 includes the user entering the PIN code into the device 100 using the button 104 in the manner described above. In the case where the user has not registered, the method then proceeds from step 601 to step 607, where the hard age verification is performed again on the website, which is only valid for one device and one process, where the user is a guest user. Step 608 includes the user entering or scanning an identity code on the website to generate a PIN code, as in step 604. The method then proceeds to step 605 again. In the event that the user cannot access the website, the user may call a call center, in which case the method proceeds from step 601 to step 609, where the user is authenticated as a registered user or a guest. For a guest user, the method proceeds to step 610, where a hard age verification is performed. Step 611 includes the user entering an identity code on a call center tool to generate a PIN code before the method proceeds to step 605. For a registered user, the method proceeds from step 609 to step 612, where a hard age verification is performed if such verification has not yet been performed. Step 613 includes registering the device 100 to the user if registration has not yet been completed. The method then proceeds to step 611. After step 605, a decision is made at 614 whether the entered PIN code is correct. If so, the method proceeds to step 606, where the device 100 is unlocked for use after successful authentication, as described above. If the entered PIN code is incorrect, the method proceeds to step 615, where the count of failed attempts is incremented by 1, and then proceeds to step 616, where a decision is made as to whether the count of failed attempts exceeds a predetermined threshold. If not, the method returns to step 605. Otherwise, the method proceeds to the online stage at step 617. Although not shown, the method may also include a time delay step as described herein between step 616 and step 605. Figure 6 In the generated PIN code, Figure 5The user obtains a PIN code via a website or call center in a step corresponding to step 501, while the user obtains a PIN code via a website or call center in a step corresponding to step 502. Hard age verification may also be referred to as an age verification process in this article. Importantly, entering a PIN code in step 605 does not require any communication between the aerosol generating device 100 (or the supporting device 300) and any external computing device (such as the above-mentioned devices), nor does it require the use of any application for this purpose.
[0212] Applicants hereby independently disclose each individual feature described herein and any combination of two or more such features, as long as such features or combinations can be implemented according to the common general knowledge of a person skilled in the art based on the specification as a whole, regardless of whether such features or combinations of features solve any problem disclosed herein, and are not limited to the scope of the claims. Applicants indicate that various aspects of the present invention may consist of any such individual features or combinations of features.
[0213] It must be noted that embodiments of the present invention are described with reference to different categories. Specifically, some examples are described with reference to methods, while other examples are described with reference to devices. However, a person skilled in the art will appreciate from this specification that, unless otherwise notified, any combination of features belonging to one category, in addition to any combination of features, any combination between features relating to different categories is also considered to be disclosed by the present application. However, all features may be combined to provide more synergistic effects than the simple addition of the features.
[0214] Although the present invention has been shown and described in detail in the drawings and the foregoing description, such showing and description are to be regarded as illustrative and not restrictive. The present invention is not limited to the disclosed embodiments. Other variations of the disclosed embodiments can be understood and implemented by those skilled in the art through study of the drawings, the present disclosure and the appended claims.
[0215] The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.
[0216] Any reference signs in the claims should not be construed as limiting the scope.
Claims
1. A control circuit system for an aerosol generating device or for an aerosol generating system including the aerosol generating device, the aerosol generating device having a locked state and an unlocked state, in which the aerosol generating device is prohibited from delivering aerosol, and in which the aerosol generating device is allowed to deliver aerosol, the control circuit system being configured to perform an authentication process for authenticating a user, the control circuit system being configured to: allowing the user a first predetermined number of attempts to enter valid authentication information using one or more user interface components during an offline phase of the authentication process; in response to receiving valid authentication information from the user before a first predetermined number of attempts has been exceeded, determining to transition the aerosol generating device from the locked state to the unlocked state; as well as In response to determining that the first predetermined number of attempts has been exceeded before the user has entered valid authentication information, an online phase of the authentication process is conducted.
2. The control circuit system according to claim 1, wherein the control circuit system is configured to: responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, wherein the second predetermined number of attempts is lower than the first predetermined number of attempts; and If the second predetermined number of attempts has been exceeded, the offline phase is delayed until a first delay period has expired.
3. The control circuitry of claim 2, the control circuitry configured to continue the offline phase without delay if the second predetermined number of attempts is not exceeded.
4. The control circuit system according to claim 2 or 3, wherein the control circuit system is configured to: responding to an unsuccessful attempt by the user to enter valid authentication information during the offline phase by determining whether a third predetermined number of attempts has been exceeded, wherein the third predetermined number of attempts is lower than the first predetermined number of attempts and higher than the second predetermined number of attempts; and If the third predetermined number of attempts has been exceeded, the offline phase is delayed until a second delay period has expired, and the control circuitry is further configured to continue the offline phase without delay if the third predetermined number of attempts has not been exceeded. 5 . The control circuit system of claim 4 , wherein the second delay period is longer than the first delay period.
6. A control circuit system according to any one of claims 2-5, wherein the control circuit system is configured to delay the offline phase by prohibiting the user from using the one or more user interface components to enter additional authentication information or by avoiding authenticating the user based on additional authentication information entered by the user.
7. A control circuit system according to any of the preceding claims, wherein the control circuit system is configured to receive authentication information input by a user from the one or more user interface components during each attempt in the offline phase, and to authenticate the user by determining the validity of the authentication information input by the user.
8. A control circuit system according to claim 7, wherein the control circuit system is configured to receive authentication information input by the user during multiple time windows of predetermined duration, each time window corresponding to a corresponding number of a digital sequence forming the authentication information, and to attribute the user input received via the one or more user interface components during the time window to the number corresponding to the time window.
9. A control circuit system according to any preceding claim, configured to, during an online phase of the authentication process: transmitting an unlock request to a server to transition the aerosol generating device from the locked state to the unlocked state, wherein the unlock request includes unique device identification information identifying the aerosol generating device and a time-limited nonce corresponding to an unlockable feature of the aerosol generating device; receiving an unlock authorization from the server in response to the transmitted unlock request; as well as In response to receiving the unlock authorization, the aerosol generating device is transitioned from the locked state to the unlocked state.
10. The control circuit system of claim 9, the control circuit system being configured to, in response to receiving the unlock authorization, transition the aerosol generating device from the locked state to the unlocked state by: decrypting the unlock authorization; determining whether the decrypted unlock authorization includes the unique device identification information and the time-limited nonce; and unlocking the unlockable feature in response to determining that the decrypted unlock authorization includes the unique device identification information and the time-limited nonce information.
11. Control circuitry as claimed in any preceding claim, configured to determine the validity of authentication information input by a user using a key derivation mechanism.
12. A control circuit system according to any preceding claim, configured to, during an online phase of the authentication process: transmitting an unlock request to a server to transition the aerosol generating device from the locked state to the unlocked state, wherein optionally the unlock request includes unique device identification information identifying the aerosol generating device and / or a time-limited presentment information corresponding to an unlockable feature of the aerosol generating device; receiving an unlock authorization from the server in response to the transmitted unlock request; as well as In response to receiving the unlock authorization, the aerosol generating device is transitioned from the locked state to the unlocked state.
13. An aerosol generating device comprising control circuitry according to any preceding claim.
14. An aerosol generating system comprising the control circuit system according to any one of claims 1 to 12 and the aerosol generating device.
15. A supporting device for an aerosol generating device, the supporting device comprising a control circuit system according to any one of claims 1-12.