Unlocking aerosol-generating system for use

Transmit unlocking requests and authorizations in the aerosol generation system through connectionless communication, solving the problem of BLE pairing incompatibility, achieving 100% success rate of youth access prevention, and reducing the need for system updates and unlocking applications.

CN120201937APending Publication Date: 2025-06-24PHILIP MORRIS PRODUCTS SA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380077926.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-10
Filing Date
2023-11-02
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The existing aerosol generation system has incompatibility in the BLE pairing process with various external computing devices, resulting in difficulty in unlocking and unable to effectively prevent access and use by underage users.

Method used

By using connectionless communication, the aerosol generation system transmits an unlock request to an external computing device and receives an unlock authorization, directly changing the system from the locked state to the unlocked state, allowing the generation of aerosols.

Benefits of technology

Solve the BLE pairing incompatibility problem, improve the success rate of access prevention for teenagers, from 70-80% to 100%, while reducing the need for firmware updates and dedicated unlocking applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201937A_ABST
    Figure CN120201937A_ABST
Patent Text Reader

Abstract

An aerosol-generating system in a locked state in which it is prevented from generating an aerosol is provided. The aerosol-generating system is configured to: receive an unlock authorization from an external computing device using connectionless communication; and upon receiving the unlocking authorization, transitioning the aerosol-generating system from the locked state to an unlocked state in which the aerosol-generating system is allowed to generate the aerosol. There is also provided a server configured to: determine whether an aerosol-generating system is associated with an authorized user; and, if associated, transmitting an unlocking authorization to the aerosol-generating system. There is also provided a computing device configured to: receive an unlock authorization from a server; and transmitting an unlocking authorization to the aerosol-generating device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an aerosol generating system having a locked state preventing the generation of aerosol by the aerosol generating system and to a method of unlocking the aerosol generating system for use. Background Art

[0002] An aerosol generating system may include an aerosol generating device and optionally also a companion device for storing and / or charging the aerosol generating device. The aerosol generating device may be designed as a handheld device that a user may use, for example, to consume aerosol generated by an aerosol generating article during one or more use sessions. The aerosol generating article may include an aerosol-forming substrate, such as a tobacco-containing substrate, typically in the form of a rod. The shape and dimensions of such a rod may be configured to be at least partially inserted into the aerosol generating device, which may include a heating element for heating the aerosol-forming substrate. Other exemplary aerosol generating articles may include cartridges containing a liquid that may be vaporized during consumption of the aerosol by the user. The shape and size of such cartridges may also be configured to be at least partially inserted into the aerosol generating device. Alternatively, the cartridge may be fixedly mounted to the aerosol generating device and refilled by inserting liquid into the cartridge.

[0003] It is desirable to implement a Youth Access Prevention (YAP) method to prevent underage users from accessing and using such aerosol generating devices. Existing YAP methods typically require a Bluetooth Low Energy (BLE) connection to unlock the aerosol generating system for use. The aerosol generating system must be properly paired with an external computing device, such as a smartphone or a PC, which exchanges information with a server to obtain an unlock authorization for unlocking the aerosol generating system. The inventors have recognized that some aerosol generating systems have difficulty successfully completing the BLE pairing process, particularly with Android-based external computing devices. Exhaustive testing is performed to identify and resolve any BLE incompatibilities prior to commercial launch of the aerosol generating system. However, new external computing devices are released throughout the life cycle of the aerosol generating system, and even previously compatible devices may become incompatible after a firmware update. Taking action to resolve such incompatibilities is time-consuming and costly and typically requires modification of the firmware of the aerosol generating system. The affected system cannot be unlocked using BLE until a new firmware is released. Even if a firmware update has been released, the affected system cannot be updated using BLE due to pairing issues.

[0004] Accordingly, it is preferable to provide devices and methods for unlocking an aerosol generating system that mitigate or overcome problems caused by BLE pairing incompatibilities with various external computing devices, or other kinds of connection difficulties, or the need to install and use a dedicated unlocking application. Summary of the Invention

[0005] According to a first aspect, there is thus provided an aerosol generating system in a locked state that prevents the aerosol generating system from generating aerosols. The aerosol generating system may be configured to transmit an unlock request to an external computing device using connectionless communication. The aerosol generating system may be further configured to: receive an unlock authorization from the external computing device using connectionless communication; and, after receiving the unlock authorization, transition the aerosol generating system from the locked state to an unlocked state in which the aerosol generating system is permitted to generate aerosols.

[0006] In some examples described herein, the unlock authorization is issued by an entity capable of determining whether a user is authorized. The server described herein is one such entity. In other examples, the unlock authorization provides an implied permission to unlock the aerosol generating system, for example, based on detecting the proximity of a device known to be associated with an authorized user. In such a case, it may be reasonably assumed that the use of the aerosol generating system is under the supervision of an authorized user.

[0007] According to a second aspect, there is provided a server. The server may be configured to receive an unlock request identifying an aerosol generating system in a locked state. The server may be further configured to: determine whether the aerosol generating system is associated with an authorized user; and, if the aerosol generating system is associated with an authorized user, transmit directly or indirectly to the aerosol generating system an unlock authorization including an unlock code that enables the aerosol generating system to transition from the locked state to an unlocked state in which the aerosol generating system is permitted to generate aerosols.

[0008] According to a third aspect, there is provided a computing device. The computing device may be configured to receive an unlock request from an aerosol generating system using connectionless communication. The computing device may be further configured to: transmit the unlock request to a server; receive an unlock authorization from the server; and transmit the unlock authorization to the aerosol generating device using connectionless communication.

[0009] According to a fourth aspect, there is provided a system that includes the aerosol generating system of the first aspect and the computing device of the third aspect. The system of the fourth aspect may further include the server of the second aspect.

[0010] By using connectionless communication to exchange unlock requests and / or unlock authorizations, connection difficulties such as those caused by BLE pairing incompatibilities with various external computing devices are alleviated, while providing a YAP (Youth Access Prevention) method with a higher success rate. Specifically, information can be exchanged between the server and the aerosol-generating device without the need for BLE pairing or association with a WiFi access point. In this way, even if the aerosol-generating device cannot pair with or establish a connection to those devices, the online YAP method can be executed on all mobile devices via BLE or WiFi packet analysis, thereby increasing the successful YAP unlock percentage from the current low level of 70 - 80% towards 100%.

[0011] Using connectionless communication involving the basic features of BLE or WiFi packet analysis as described herein can provide improved compatibility between the aerosol-generating device and external computing devices such as mobile devices, and / or can reduce the need for firmware updates or dedicated unlock applications for the aerosol-generating device, and can reduce user frustration.

[0012] By using a pre-shared secret and a one-time random value to generate a device-unique and session-unique unlock code, the unlock code cannot be eavesdropped on and used for other devices. The unlock code cannot be easily guessed because it is based on the device secret and changes at the start of each unlock process. Additionally, using the pre-shared secret significantly reduces the online YAP execution time (by means of fewer bytes and a lighter cryptographic algorithm) without compromising security.

[0013] By using a mobile device (application) and a server, and using a secure data and account verification process (e.g., forced two-factor identification to start the application, credit card ID, GPS data provided by the mobile device to adjust the legal age according to national laws, etc.) to confirm that the user of the aerosol-generating device is a legal-age user / legal-age smoker (LAU / LAS), robust youth access prevention can be provided.

[0014] The unlock process can be easily made compliant with older versions of BLE, and only requires that the mobile device be able to alternate between different Generic Access Profile (GAP) roles (central and peripheral), which has been common since approximately 2015.

[0015] Additionally, using the non-connectable advertising mode of BLE (“ADV_NONCONN_IND”) to transmit advertising data (compared to the “connectable” mode) may have a higher power effect.

[0016] The unlock request may include a unique device identifier identifying the aerosol generation system. The aerosol generation system may be configured to include the unique device identifier in the unlock request before transmitting the unlock request. The server may further be configured to determine whether the unique device identifier included in the received unlock request is associated with an authorized user. More specifically, the server may be configured to use the unique device identifier (UID) to retrieve the device unique serial number (DUSN) that may be linked to only one user account, and permit the unlocking of the aerosol generation system only when the DUSN is linked to the user account of the authorized user. The unlock authorization transmitted by the server and received by the aerosol generation system may also include the unique device identifier. The aerosol generation system may further be configured to verify the unlock code only when the unique device identifier included in the unlock authorization matches the unique device identifier of the aerosol generation system.

[0017] The unlock authorization may also include an unlock code. The server may further be configured to generate the unlock code and include the unlock code in the unlock authorization. The unlock code may be at least partially based on a pre-shared secret unique to the aerosol generation system. The unlock code may be generated at the server or derived by the server. The unlock code may be at least partially based on a verification code provided as part of the unlock request by the aerosol generation system. The server may further be configured to generate the unlock code at least partially based on the verification code included in the unlock request. The aerosol generation system may further be configured to verify the unlock code using a pre-shared secret unique to the aerosol generation system after receiving the unlock authorization. The aerosol generation system may further be configured to transition the aerosol generation system from a locked state to an unlocked state in response to successfully verifying the unlock code. The unlock code may be unique for the current unlock session. This may be achieved by the unlock code being at least partially based on a one-time code (OTC) or including a one-time code. The OTC may alternatively be referred to as a one-time password (OTP) or a one-time authorization code (OTAC). The unlock code may include or constitute a message authentication code. More specifically, the unlock code may include a hash-based message authentication code.

[0018] The aerosol generating system may further be configured to obtain a verification code for comparison with an unlock code. The verification code may be generated at the aerosol generating system. In other words, the aerosol generating system may further be configured to generate a verification code, and the aerosol generating system verifies the unlock code based on the verification code. The aerosol generating system may further be configured to include the verification code in an unlock request and determine whether the unlock code included in the unlock authorization matches the verification code when verifying the unlock code. In other words, the aerosol generating system may further be configured to verify the unlock code by comparing the unlock code included in the unlock authorization with the verification code, and transition the aerosol generating system from a locked state to an unlocked state in response to the unlock code matching the verification code.

[0019] The unlock code included in the unlock authorization may be encrypted. The server may further be configured to encrypt the unlock code before transmitting the unlock authorization. Similarly, the aerosol generating system may further be configured to decrypt the encrypted unlock code. More specifically, the server may further be configured to encrypt the unlock code using a symmetric key algorithm, while the aerosol generating system may also be configured to decrypt the encrypted unlock code using the symmetric key algorithm. The server may further be configured to encrypt the unlock code using a key pair, while the aerosol generating system may also be configured to decrypt the encrypted unlock code using the key pair. The key used for encrypting and / or decrypting the unlock code may be derived at least in part from a pre-shared secret unique to the aerosol generating system. Additionally or alternatively, the key used for encrypting and / or decrypting the unlock code may be derived at least in part from a unique device identifier. Additionally or alternatively, the key used for encrypting and / or decrypting the unlock code may be derived at least in part from a one-time code. The aerosol generating system may be configured to verify the unlock code only when the encrypted unlock code can be decrypted using the key.

[0020] The unlock authorization may further include a challenge. The challenge may include a server challenge. The server may further be configured to generate a challenge for inclusion in the unlock authorization. The aerosol generating system may be configured to verify the unlock code at least in part based on the challenge. More specifically, the aerosol generating system may be configured to verify the unlock code only when the aerosol generating system provides a valid response to the challenge.

[0021] As used herein, the term "connectionless communication" specifically refers to communication that occurs without pairing devices and without associating with an access point. Connectionless communication can occur between two endpoints, where messages are sent from one endpoint to another without prior arrangement, i.e., without first ensuring that the recipient is available and ready to receive data. The term "connectionless communication" is used herein in contrast to communication that uses a pre-arranged fixed data channel, as in the case of connection-oriented communication, which is also referred to herein as the "connectable" mode. Connectionless communication can include multicast and / or broadcast operations, where the same data is transmitted to several recipients in a single transmission. For example, connectionless communication can include communication using at least one broadcast / advertising beacon and / or using at least one broadcast / advertising packet, as in the case of Bluetooth or Bluetooth Low Energy, and can thus be referred to in terms of communication using the advertising mode. In order to be able to both send and receive data using connectionless communication, the aerosol generating system can be configured to switch between operating in the peripheral mode and operating in the central mode. The aerosol generating system can be configured to transmit an unlock request when operating in the peripheral mode and to receive an unlock authorization when operating in the central mode. Similarly, the computing device can further be configured to switch between operating in the peripheral mode and operating in the central mode. The computing device can further be configured to receive an unlock request when operating in the central mode and to transmit an unlock authorization when operating in the peripheral mode. Connectionless communication can alternatively include monitoring network traffic using network sniffing or packet analysis, which is performed without any association between the aerosol generating system and the access point.

[0022] As used herein, the term "peripheral mode" refers to the mode or role in which a device advertises its presence and waits for a device operating in the central mode to connect to it, while the term "central mode" refers to the mode or role in which a device scans for other devices. The terms "central mode" and "peripheral mode" can refer to pre-connection modes or roles. After connection, a device operating in the central mode can operate as the master device, and a device operating in the peripheral mode can operate as the slave device.

[0023] An aerosol generation system may include an aerosol generating device. The aerosol generating device may be configured or designed as a handheld device for use by an authorized user to consume an aerosol generating article, for example, during one or more usage sessions (also referred to as “experiences” or “usage experiences”). For example, an aerosol generating article that may be used with the aerosol generating device may include an aerosol-forming substrate, such as a tobacco-containing substrate, which may be assembled in a rod form that can be at least partially inserted into the aerosol generating device, optionally assembled with other elements or components. Additionally or alternatively, an aerosol generating article that may be used with the aerosol generating device may include at least one cartridge containing a liquid that can be vaporized during consumption of the aerosol by the user. Such a cartridge may be a refillable cartridge fixedly mounted at the aerosol generating device, or the cartridge may be at least partially inserted into the aerosol generating device. The aerosol generating device may alternatively be referred to as a risk reduction device (RRD).

[0024] The aerosol generation system may further include a companion device. The companion device may include a charging case. The companion device (which may also be described as an accessory device, a receiving device, or a support device) may be configured to store and / or charge the aerosol generating device. The companion device may be portable. The companion device may be configured to at least partially receive the aerosol generating device. For example, the companion device may be configured to physically couple to the aerosol generating device. Such physical coupling may include, for example, mechanical coupling based on an attachment device, such as a hook mechanism, a latch mechanism, a snap-fit mechanism, etc., by which the aerosol generating device may be mechanically coupled to the companion device and / or its housing. Additionally or alternatively, the aerosol generating device may be physically coupled to the companion device based on magnetic or electromagnetic coupling. Additionally or alternatively, the aerosol generating device may be at least partially inserted into the companion device, for example, into an opening of the companion device.

[0025] To communicate with each other and / or with an external computing device and / or to exchange data or signals, the aerosol generating device and / or the companion device may include at least one communication interface. The communication interface may be configured for wireless communication, for wired communication, or for both wireless communication and wired communication. For example, the communication interface may be configured to communicate and couple via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection (including BLE), a mobile phone network, a 3G / 4G / 5G connection, etc., an edge connection, an LTE connection, a bus connection, a wireless connection, a wired connection, a radio connection, a near-field connection, an IoT connection, or any other connection using any suitable communication protocol.

[0026] An aerosol-generating device and / or a companion device may include at least one energy storage device for storing electrical energy and / or supplying electrical energy to the aerosol-generating device using the electrical energy. For example, the companion device may be configured to supply electrical energy to the aerosol-generating device to charge at least one energy storage device of the aerosol-generating device. In other words, the companion device may be configured to charge the aerosol-generating device and / or at least one of its energy storage devices. At least one energy storage device of the aerosol-generating device may include, for example, at least one battery, at least one accumulator, at least one capacitor, or any other energy storage device. The companion device may be configured to supply electrical energy to the energy storage device of the aerosol-generating device when the aerosol-generating device is at least partially received by the companion device. The companion device may include one or more batteries for supplying electrical energy to the energy storage device of the aerosol-generating device. The companion device may be configured to supply electrical energy to the energy storage device of the aerosol-generating device wirelessly, for example, based on induction. Additionally or alternatively, the companion device may be configured to supply electrical energy to the energy storage device of the aerosol-generating device via one or more electrical connectors between the companion device and the aerosol-generating device. For example, the aerosol-generating device and the companion device may each include at least one electrical connector for electrically coupling the companion device to the aerosol-generating device when the aerosol-generating device is at least partially received by the companion device. By way of example, the companion device may include an opening for at least partially receiving the aerosol-generating device. By inserting the aerosol-generating device at least partially into the opening, one or more electrical connections may be established between one or more electrical connectors of the aerosol-generating device and the companion device. Additionally or alternatively, the aerosol-generating device may be physically and / or mechanically coupled to the companion device, for example, to the housing of the companion device, such that the aerosol-generating device is at least partially received by the companion device and such that one or more electrical connections may be established between the aerosol-generating device and the companion device. Optionally, establishing an electrical connection between the companion device and the aerosol-generating device via one or more electrical connectors of the aerosol-generating device and the companion device may establish a communication coupling and / or a communication connection between the companion device and the aerosol-generating device, for example, for transmitting an authentication signal. By way of example, at least one electrical connector of the companion device may incorporate and / or may include a communication interface of the companion device. In other words, at least one electrical connector of the companion device may be configured as a communication interface for communicatively coupling the companion device to the aerosol-generating device. Additionally or alternatively, at least the electrical connector of the aerosol-generating device may incorporate and / or may include a communication interface of the aerosol-generating device. In other words, at least one electrical connector of the aerosol-generating device may be configured as a communication interface for communicatively coupling the aerosol-generating device to the companion device. Thus, an authentication signal may be transmitted from the companion device to the aerosol-generating device via one or more electrical connectors of the companion device and the aerosol-generating device.However, it should be noted that the communication interface of one or both of the accessory device and the aerosol generating device may be physically separated and independent from at least one electrical connector of the accessory device and / or the aerosol generating device. A charging cycle may refer to a period of time during which the accessory device continuously supplies electrical energy to the aerosol generating device. During the charging cycle, at least one energy storage device may be partially or fully charged.

[0027] The external computing device may be configured to communicate with the aerosol generating device and / or the accessory device, for example, based on exchanged data or information. Generally, the external computing device may be a handheld or portable device. Alternatively, the external computing device may be a stand-alone or fixed-mounted device. In addition, the external computing device may be owned by a user or another entity or individual (such as a retail store), or may be installed at a user or another entity or individual. For example, the external computing device may refer to a handheld device, a smart phone, a personal computer (“PC”), a tablet PC, a notebook or a computer. The external computing device may include a user interface. The external computing device may include one or more processors for data processing, such as for processing one or more user inputs received at the user interface. Additionally or alternatively, the external computing device may include a data storage device and / or a memory for storing data, such as software instructions, computer programs, and / or other data. Further, the external computing device may include a communication interface, a communication module, and / or communication circuitry for communicatively coupling the external computing device with the aerosol generating device and / or the accessory device, for example, via the communication interface of the aerosol generating device and / or the accessory device. Thus, the external computing device may be configured for wireless and / or wired communication with the aerosol generating device, the accessory device, or both. For example, the external computing device may be configured to communicatively couple with the aerosol generating device and / or the accessory device via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection, a mobile phone network, a 3G / 4G / 5G connection, etc., an edge connection, an LTE connection, a bus connection, a wireless connection, a wired connection, a radio connection, a near-field connection, an IoT connection, or any other connection using any suitable communication protocol.

[0028] The unlocking code may include a MAC address detected by the aerosol-generating system in network traffic, where the MAC address is associated with a computing device (e.g., a mobile device) of a known authorized user, such that a packet including the MAC address (implying the proximity of the authorized user) constitutes an implicit permission to unlock the aerosol-generating system. To this end, the aerosol-generating system may be configured to detect a MAC address in network traffic using packet analysis, for example when operating in a monitoring mode to monitor network traffic using packet analysis. The aerosol-generating system may further be configured to transition from a locked state to an unlocked state in response to successfully verifying an unlocking code including the MAC address. The verification code may include, for example, the MAC address of the computing device of the authorized user pre-stored on the aerosol-generating system for comparison with the unlocking code in the form of a MAC address detected by the aerosol-generating system in network traffic. Thus, a match between the pre-stored MAC address serving as the verification code and the detected MAC address serving as the unlocking code may cause the aerosol-generating system to transition from a locked state to an unlocked state. Accordingly, the aerosol-generating system may further be configured to verify the unlocking code by comparing the detected MAC address with the MAC address of the computing device of the authorized user, and to transition from a locked state to an unlocked state in response to a match between the detected MAC address and the MAC address of the computing device of the authorized user.

[0029] According to a fifth aspect, there is provided a method performed by an aerosol-generating system in a locked state that prevents the aerosol-generating system from generating aerosol. The method may include transmitting an unlocking request to an external computing device using connectionless communication. The method may further include: receiving an unlocking authorization from the external computing device using connectionless communication; and, after receiving the unlocking authorization, transitioning the aerosol-generating system from the locked state to an unlocked state in which the aerosol-generating system is permitted to generate aerosol.

[0030] The method of the fifth aspect may further include, after receiving the unlocking authorization, using a pre-shared secret unique to the aerosol-generating system to verify the unlocking code. The method may further include transitioning the aerosol-generating system from a locked state to an unlocked state in response to successful verification of the unlocking code. The method may further include obtaining a verification code for comparison with the unlocking code. The method may further include generating the verification code at the aerosol-generating system. The method may further include verifying the unlocking code by comparing the unlocking code with the verification code, and transitioning the aerosol-generating system from a locked state to an unlocked state in response to the unlocking code matching the verification code. The method may further include generating a verification code, and the aerosol-generating system verifying the unlocking code based on the verification code. The method may further include including the verification code in the unlocking request, and determining whether the unlocking code included in the unlocking authorization matches the verification code when verifying the unlocking code. In the case where the unlocking code included in the unlocking authorization is encrypted, the method may further include decrypting the encrypted unlocking code. The method may further include decrypting the encrypted unlocking code using a symmetric key algorithm. The method may further include decrypting the encrypted unlocking code using a key pair. The key may be derived at least in part from the pre-shared secret, and / or at least in part from a unique device identifier, and / or at least in part from a one-time code. The method may further include verifying the unlocking code only when the encrypted unlocking code can be decrypted using the key. The method may further include verifying the unlocking code only when the unique device identifier included in the unlocking authorization matches the unique device identifier of the aerosol-generating system. In the case where the unlocking authorization further includes a challenge, the method may further include verifying the unlocking code at least in part based on the challenge. The method may further include switching between operating in a peripheral mode and operating in a central mode. The method may further include transmitting an unlocking request when operating in the peripheral mode, and receiving the unlocking authorization when operating in the central mode.

[0031] The unlocking code may include a MAC address detected in network traffic. The method may include, for example, detecting a MAC address in network traffic using packet analysis, such as when operating in a monitoring mode to monitor network traffic using packet analysis. The verification code may include the MAC address of a computing device of an authorized user. The method may include comparing the detected MAC address with the MAC address of the computing device of the authorized user stored on the aerosol-generating system, and transitioning the aerosol-generating system from a locked state to an unlocked state in response to the detected MAC address matching the stored MAC address.

[0032] According to a sixth aspect, a method performed by a server is provided. The method may include receiving an unlock request identifying an aerosol-generating system in a locked state. The method may further include: determining whether the aerosol-generating system is associated with an authorized user; and if the aerosol-generating system is associated with an authorized user, transmitting, directly or indirectly, an unlock authorization including an unlock code to the aerosol-generating system, the unlock authorization enabling the aerosol-generating system to transition from the locked state to an unlocked state in which the aerosol-generating system is permitted to generate an aerosol.

[0033] In the case where the unlock request includes a unique device identifier identifying the aerosol-generating system, the method of the sixth aspect may further include determining whether the unique device identifier is associated with an authorized user. The method may further include generating an unlock code and including the unlock code in the unlock authorization. The method may further include generating the unlock code at least in part based on a verification code included in the unlock request. The method may further include encrypting the unlock code before transmitting the unlock authorization. The method may further include encrypting the unlock code using a symmetric key algorithm. The method may further include encrypting the unlock code using a key as described herein. The method may further include generating a challenge for inclusion in the unlock authorization.

[0034] According to a seventh aspect, a method performed by a computing device is provided. The method may include receiving an unlock request from an aerosol-generating system using connectionless communication. The method may further include: transmitting the unlock request to a server; receiving an unlock authorization from the server; and transmitting the unlock authorization to the aerosol-generating device using connectionless communication.

[0035] The method of the seventh aspect may further include switching between operating in a peripheral mode and operating in a central mode. The method may further include receiving an unlock request when operating in the central mode and transmitting an unlock authorization when operating in the peripheral mode.

[0036] The method of any one of the fifth-seventh aspects may be computer-implemented.

[0037] According to an eighth aspect, a computing system is provided, the computing system being configured to perform the method of any one of the fifth-seventh aspects.

[0038] According to a ninth aspect, a computer program (product) including instructions is provided, the instructions causing the computing system to perform or causing the computing system to execute the method of any one of the fifth-seventh aspects when executed by the computing system.

[0039] According to a tenth aspect, there is provided a computer-readable (storage) medium including instructions which, when executed by a computing system, enable the computing system to perform or cause the computing system to perform the method of any one of the fifth to seventh aspects. The computer-readable medium can be transient or non-transient, volatile or non-volatile.

[0040] As used herein, the term "locked state" may refer to a locked configuration of an aerosol-generating device, and the term "unlocked state" may refer to an unlocked configuration of the aerosol-generating device. In the locked state or configuration, the aerosol-generating device is prohibited from delivering and / or generating aerosol. This may mean that the aerosol-generating device is locked in the locked state so as not to be consumed by the user, and / or the aerosol-generating device is configured to be in the locked state such that aerosol cannot be delivered and / or generated. On the other hand, in the unlocked state or configuration, the aerosol-generating device is permitted or allowed to deliver and / or generate aerosol. This may mean that the aerosol-generating device is unlocked in the unlocked state so as to be consumed by the user, and / or the aerosol-generating device is configured to be in the unlocked state such that aerosol can be delivered and / or generated. Thus, when the aerosol-generating device is in the locked state, the aerosol-generating device may not be actuated by the user to deliver and / or generate aerosol, and when the aerosol-generating device is in the unlocked state, the aerosol-generating device can be actuated by the user to deliver and / or generate aerosol. In other words, in the locked state of the aerosol-generating device, access by the user to one or more functions or capabilities of the aerosol-generating device, including aerosol delivery and / or generation, may be prohibited; and in the unlocked state of the aerosol-generating device, access by the user to one or more functions or capabilities of the aerosol-generating device, including aerosol delivery and / or generation, may be permitted. Additionally or alternatively, the companion device may be configured to charge the energy storage device of the aerosol-generating device only when the user has been successfully authenticated. In this example, the locked state may be regarded as a state in which the energy storage device of the aerosol-generating device does not contain sufficient charge to enable aerosol generation, and the unlocked state may be regarded as a state in which the energy storage device contains sufficient charge to enable aerosol generation. The authentication signal may then be regarded as providing charge from the companion device to the energy storage device of the aerosol-generating device. In the locked state, the control circuitry may be configured, for example, to prohibit activation of the heating element based on at least one of the following: disabling at least one heating element, disabling the energy supply device for supplying electrical energy to at least one heating element, and disabling the input element for actuating at least one heating element by the user.

[0041] As used herein, the term "transition" may mean causing the aerosol-generating device to enter, be configured as, and / or switch to a locked or unlocked state, which may mean or include actuating and / or configuring the aerosol-generating device such that the aerosol-generating device is in the locked state or the unlocked state.

[0042] As used herein, the term "authentication" refers to verifying the identity of a user.

[0043] As used herein, the term "authorization" refers to determining a user's access rights, i.e., their right to transition an aerosol-generating device from a locked state to an unlocked state. Since, in the context of the YAP method, a user's identity is inherently closely related to their access rights, the terms "authentication" and "authorization" may be used interchangeably in this disclosure.

[0044] As used herein, the term "authorized user" (also referred to as "verified user") may refer to or denote the owner of an aerosol-generating device, an adult, an adult individual, an adult user, a user who has reached an age threshold, a user who has reached the legal age, and / or a user who has been authorized by another authorized user (such as by the owner) to configure the aerosol-generating device. Additionally, an unauthorized user may refer to or denote a minor user, a user who has not reached an age threshold, a child, or any other user who has not been authorized to configure the aerosol-generating device (in particular, a user who has not been authorized to transition the aerosol-generating device to an unlocked state to consume aerosol).

[0045] As used herein, the term "circuitry" may include, for example, hardwired circuitry, programmable circuitry (such as a computer processor including one or more individual instruction processing cores), state machine circuitry, and / or firmware storing instructions executable by the programmable circuitry, either singly or in any combination. Modules may be embodied jointly or separately as circuitry forming part of one or more devices or systems as described herein.

[0046] As used herein, the term "obtain" may include, for example, receiving from another system, device, or process; receiving via interaction with a user; loading or retrieving from a storage device or memory; measuring or capturing using a sensor or other data acquisition device.

[0047] As used herein, the term "determine" encompasses a wide variety of actions and may include, for example, gauging, calculating, processing, deriving, investigating, looking up (e.g., looking up in a table, database, or another data structure), ascertaining, etc. Additionally, "determine" may include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), etc. Additionally, "determine" may include parsing, selecting, picking, establishing, etc.

[0048] The indefinite articles "a" or "an" do not exclude a plurality. Additionally, unless otherwise specified or clear from the context, the terms "a" and "an" as used herein shall generally be construed to mean "one or more" as referring to the singular form.

[0049] Unless otherwise specified or clear from the context, as used herein, the phrases "one or more of A, B, and C", "at least one of A, B, and C", and "A, B, and / or C" are intended to mean all possible permutations of one or more of the listed items. That is, the phrase "A and / or B" means (A), (B), or (A and B), and the phrase "A, B, and / or C" means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).

[0050] The term "comprising" does not exclude other elements or steps. In addition, the terms "comprising", "including", "having", etc. may be used interchangeably herein.

[0051] A non-exhaustive list of non-limiting examples is provided below. Any one or more features of these examples may be combined with any one or more features of another example, embodiment, or aspect described herein.

[0052] Ex.1. An aerosol-generating system in a locked state, in which the aerosol-generating system is prevented from generating aerosol in the locked state, the aerosol-generating system being configured to:

[0053] Receive an unlock authorization from an external computing device using connectionless communication, and

[0054] After receiving the unlock authorization, transition the aerosol-generating system from the locked state to an unlocked state, in which the aerosol-generating system is allowed to generate aerosol.

[0055] Ex.1A. The aerosol-generating system according to Ex.1, the aerosol-generating system being further configured to transmit an unlock request to the external computing device using connectionless communication.

[0056] Ex.2. The aerosol-generating system according to Ex.1A, wherein the unlock request includes a unique device identifier identifying the aerosol-generating system.

[0057] Ex.3. The aerosol-generating system according to Ex.2, wherein the unlock authorization includes the unique device identifier and an unlock code.

[0058] Ex.4. The aerosol-generating system according to Ex.3, wherein the unlock code is generated or derived by another external computing device (such as a server) or the external computing device (as described herein).

[0059] Ex.5. The aerosol generating system according to Ex.3 or Ex.4, the aerosol generating system being further configured to use a pre-shared secret unique to the aerosol generating system to verify the unlock code after receiving the unlock authorization.

[0060] Ex.6. The aerosol generating system according to any one of Ex.3 - Ex.5, the aerosol generating system being further configured to transition the aerosol generating system from the locked state to the unlocked state in response to successful verification of the unlock code.

[0061] Ex.7. The aerosol generating system according to any one of claims Ex.3 - Ex.6, the aerosol generating system being further configured to obtain a verification code for comparison with the unlock code.

[0062] Ex.8. The aerosol generating system according to Ex.7, wherein the verification code is generated at the aerosol generating system.

[0063] Ex.9. The aerosol generating system according to any one of Ex.3 - Ex.8, the aerosol generating system being further configured to verify the unlock code by comparing the unlock code with the verification code, and transition the aerosol generating system from the locked state to the unlocked state in response to the unlock code matching the verification code.

[0064] Ex.10. The aerosol generating system according to any one of Ex.3 - Ex.9, the aerosol generating system being further configured to generate a verification code, the aerosol generating system verifying the unlock code based on the verification code.

[0065] Ex.11. The aerosol generating system according to any one of Ex.3 - Ex.10, the aerosol generating system being further configured to include a verification code in the unlock request, and determine whether the unlock code included in the unlock authorization matches the verification code when verifying the unlock code.

[0066] Ex.12. The aerosol generating system according to any one of Ex.3 - Ex.11, wherein the unlock code included in the unlock authorization is encrypted, and wherein the aerosol generating system is configured to decrypt the encrypted unlock code.

[0067] Ex.13. The aerosol generating system according to any one of Ex.3 - Ex.12, wherein the unlock code included in the unlock authorization is encrypted, and wherein the aerosol generating system is configured to decrypt the encrypted unlock code using a symmetric key algorithm.

[0068] Ex.14. The aerosol generating system according to any one of Ex.3 - Ex.13, wherein the unlocking code included in the unlocking authorization is encrypted, and wherein the aerosol generating system is configured to decrypt the encrypted unlocking code using a key derived at least in part from a pre - shared secret.

[0069] Ex.15. The aerosol generating system according to any one of Ex.3 - Ex.14, wherein the unlocking code included in the unlocking authorization is encrypted, and wherein the aerosol generating system is configured to decrypt the encrypted unlocking code using a key derived at least in part from the unique device identifier.

[0070] Ex.16. The aerosol generating system according to any one of Ex.3 - Ex.15, wherein the unlocking code included in the unlocking authorization is encrypted, and wherein the aerosol generating system is configured to decrypt the encrypted unlocking code using a key derived at least in part from a one - time code.

[0071] Ex.17. The aerosol generating system according to any one of Ex.14 - Ex.16, wherein the unlocking code included in the unlocking authorization is encrypted, and wherein the aerosol generating system is configured to verify the unlocking code only when the encrypted unlocking code can be decrypted using the key.

[0072] Ex.18. The aerosol generating system according to any one of Ex.3 - Ex.17, wherein the unlocking code is unique for the current unlocking session.

[0073] Ex.19. The aerosol generating system according to any one of Ex.3 - Ex.18, wherein the unlocking code is at least partially based on a one - time code.

[0074] Ex.20. The aerosol generating system according to any one of Ex.3 - Ex.19, wherein the unlocking code includes a message authentication code.

[0075] Ex.21. The aerosol generating system according to any one of Ex.3 - Ex.20, wherein the unlocking code includes a hash - based message authentication code.

[0076] Ex.22. The aerosol generating system according to any one of Ex.3 - Ex.21, the aerosol generating system is further configured to verify the unlocking code only when the unique device identifier included in the unlocking authorization matches the unique device identifier of the aerosol generating system.

[0077] Ex.23. The aerosol - generating system according to any one of Ex.3 - Ex.22, wherein the unlocking authorization further includes a challenge, and wherein the aerosol - generating system is configured to verify the unlocking code at least partially based on the challenge.

[0078] Ex.24. The aerosol - generating system according to any one of the foregoing examples, wherein the aerosol - generating system is configured to switch between operating in a peripheral mode and operating in a central mode.

[0079] Ex.25. The aerosol - generating system according to any one of Ex.1A - 24, wherein the aerosol - generating system is configured to transmit the unlocking request when operating in the peripheral mode and to receive the unlocking authorization when operating in the central mode.

[0080] Ex.26. The aerosol - generating system according to any one of the foregoing examples, wherein the connectionless communication includes communication using at least one advertisement packet.

[0081] Ex.27. The aerosol - generating system according to any one of the foregoing examples, wherein the connectionless communication includes communication using at least one broadcast beacon.

[0082] Ex.28. The aerosol - generating system according to any one of the foregoing examples, the system comprising an aerosol - generating device or an aerosol - generating device and an auxiliary device.

[0083] Ex.29. The aerosol - generating system according to Ex.28, wherein the auxiliary device is a charging case.

[0084] Ex.30. A server, the server being configured to:

[0085] Determine whether an aerosol - generating system is associated with an authorized user;

[0086] If the aerosol - generating system is associated with an authorized user, directly or indirectly transmit an unlocking authorization including an unlocking code to the aerosol - generating system, the unlocking authorization enabling the aerosol - generating system to transition from a locked state to an unlocked state, in which the aerosol - generating system is permitted to generate aerosol.

[0087] Ex.30A. The server according to Ex.30, the server further being configured to receive an unlocking request identifying an aerosol - generating system in a locked state.

[0088] Ex.31. The server according to Ex.30A, wherein the unlocking request includes a unique device identifier identifying the aerosol - generating system, and wherein the server is further configured to determine whether the unique device identifier is associated with an authorized user.

[0089] Ex.32. The server according to any one of Ex.30 - Ex.31, the server being further configured to generate an unlock code and include the unlock code in the unlock authorization.

[0090] Ex.33. The server according to Ex.32, wherein the unlock code is at least partially based on a pre - shared secret unique to the aerosol - generating system.

[0091] Ex.34. The server according to Ex.32 or Ex.33 when dependent on Ex.30A, the server being further configured to generate the unlock code at least partially based on a verification code included in the unlock request.

[0092] Ex.35. The server according to any one of Ex.32 - Ex.34, the server being further configured to encrypt the unlock code before transmitting the unlock authorization.

[0093] Ex.36. The server according to Ex.35, the server being further configured to encrypt the unlock code using a symmetric - key algorithm.

[0094] Ex.37. The server according to Ex.35 or Ex.36, the server being further configured to encrypt the unlock code using a key at least partially derived from the pre - shared secret.

[0095] Ex.38. The server according to any one of Ex.35 - Ex.37, the server being further configured to encrypt the unlock code using a key at least partially derived from a unique device identifier identifying the aerosol - generating system.

[0096] Ex.39. The server according to any one of Ex.35 - Ex.38, the server being further configured to encrypt the unlock code using a key at least partially derived from a one - time code.

[0097] Ex.40. The server according to any one of Ex.32 - Ex.39, wherein the unlock code is unique for the current unlock session.

[0098] Ex.41. The server according to any one of Ex.32 - Ex.40, wherein the unlock code is at least partially based on a one - time code.

[0099] Ex.42. The server according to any one of Ex.32 - Ex.41, wherein the unlock code includes a message authentication code.

[0100] Ex.43. The server according to any one of Ex.32 - Ex.42, wherein the unlocking code includes a hash - based message authentication code.

[0101] Ex.44. The server according to any one of Ex.30 - Ex.43, the server being further configured to generate a challenge for inclusion in the unlocking authorization.

[0102] Ex.45. A computing device, the computing device being configured to:

[0103] receive an unlocking authorization from a server; and

[0104] transmit the unlocking authorization to an aerosol - generating system using connectionless communication.

[0105] Ex.45A. The computing device according to Ex.45, the computing device being further configured to receive an unlocking request from the aerosol - generating system using connectionless communication and transmit the unlocking request to the server.

[0106] Ex.46. The computing device according to Ex.45A, wherein the unlocking request includes a unique device identifier identifying the aerosol - generating system.

[0107] Ex.47. The computing device according to Ex.46, wherein the unlocking authorization includes the unique device identifier and an unlocking code.

[0108] Ex.48. The computing device according to Ex.47, wherein the unlocking code is unique for the current unlocking session.

[0109] Ex.49. The computing device according to Ex.47 or Ex.48, wherein the unlocking code is at least partially based on a one - time code.

[0110] Ex.50. The computing device according to any one of Ex.47 - Ex.49, wherein the unlocking code includes a message authentication code.

[0111] Ex.51. The computing device according to any one of Ex.47 - Ex.50, wherein the unlocking code includes a hash - based message authentication code.

[0112] Ex.52. The computing device according to any one of Ex.47 - Ex.51, wherein the unlocking code is encrypted, and wherein the key used for encrypting and / or decrypting the unlocking code is at least partially derived from a pre - shared secret unique to the aerosol - generating system.

[0113] Ex.53. The computing device according to any one of Ex.47 - Ex.52, wherein the unlock code is encrypted, and wherein the key for encrypting and / or decrypting the unlock code is at least partially derived from the unique device identifier.

[0114] Ex.54. The computing device according to any one of Ex.47 - Ex.53, wherein the unlock code is encrypted, and wherein the key for encrypting and / or decrypting the unlock code is at least partially derived from a one-time code.

[0115] Ex.55. The computing device according to any one of Ex.47 - Ex.54, wherein the unlock code is at least partially based on a verification code provided by the aerosol generating system as part of the unlock request.

[0116] Ex.56. The computing device according to any one of Ex.45 - Ex.55, the computing device being further configured to switch between operating in a peripheral mode and operating in a central mode.

[0117] Ex.57. The computing device according to any one of Ex.45A - Ex.56, the computing device being further configured to receive the unlock request when operating in the central mode and transmit the unlock authorization when operating in the peripheral mode.

[0118] Ex.58. The computing device according to any one of Ex.45 - Ex.57, wherein the connectionless communication includes communication using at least one advertising packet.

[0119] Ex.59. The computing device according to any one of Ex.45 - Ex.58, wherein the connectionless communication includes communication using at least one broadcast beacon.

[0120] Ex.60. A system comprising an aerosol generating system according to any one of Ex.1 - Ex.29 and a computing device according to any one of Ex.45 - Ex.59.

[0121] Ex.61. The system according to Ex.60, the system further comprising a server according to any one of Ex.30 - Ex.44.

[0122] Ex.62. A method performed by an aerosol generating system in a locked state that prevents the aerosol generating system from generating aerosol, the method comprising:

[0123] Receiving an unlock authorization from an external computing device using connectionless communication; and

[0124] After receiving the unlocking authorization, the aerosol generating system is changed from the locked state to an unlocked state, in which the aerosol generating system is allowed to generate aerosol.

[0125] Ex.62A. The method according to Ex.62, the method further comprising transmitting an unlocking request to the external computing device using connectionless communication.

[0126] Ex.63. The method according to Ex.62A, wherein the unlocking request includes a unique device identifier identifying the aerosol generating system.

[0127] Ex.64. The method according to Ex.63, wherein the unlocking authorization includes the unique device identifier and an unlocking code.

[0128] Ex.65. The method according to Ex.64, wherein the unlocking code is generated or derived by another external computing device (such as a server) or the external computing device (as described herein).

[0129] Ex.66. The method according to Ex.64 or Ex.65, the method further comprising verifying the unlocking code using a pre-shared secret unique to the aerosol generating system after receiving the unlocking authorization.

[0130] Ex.67. The method according to any one of Ex.64 - Ex.66, the method further comprising changing the aerosol generating system from the locked state to the unlocked state in response to successful verification of the unlocking code.

[0131] Ex.68. The method according to any one of Ex.64 - Ex.67, the method further comprising obtaining a verification code for comparison with the unlocking code.

[0132] Ex.69. The method according to Ex.68, the method further comprising generating the verification code at the aerosol generating system.

[0133] Ex.70. The method according to any one of Ex.64 - Ex.69, the method further comprising verifying the unlocking code by comparing the unlocking code with the verification code, and changing the aerosol generating system from the locked state to the unlocked state in response to the unlocking code matching the verification code.

[0134] Ex.71. The method according to any one of Ex.64 - Ex.70, the method further comprising generating a verification code, and the aerosol generating system verifying the unlocking code based on the verification code.

[0135] Ex.72. The method according to any one of Ex.64 - Ex.71, the method further comprising including an authentication code in the unlock request, and determining whether the unlock code included in the unlock authorization matches the authentication code when the unlock code is verified.

[0136] Ex.73. The method according to any one of Ex.64 - Ex.72, wherein the unlock code included in the unlock authorization is encrypted, the method further comprising decrypting the encrypted unlock code.

[0137] Ex.74. The method according to any one of Ex.64 - Ex.74, wherein the unlock code included in the unlock authorization is encrypted, the method further comprising decrypting the encrypted unlock code using a symmetric key algorithm.

[0138] Ex.75. The method according to any one of Ex.64 - Ex.74, wherein the unlock code included in the unlock authorization is encrypted, the method further comprising decrypting the encrypted unlock code using a key at least partially derived from a pre - shared secret.

[0139] Ex.76. The method according to any one of Ex.64 - Ex.75, wherein the unlock code included in the unlock authorization is encrypted, the method further comprising decrypting the encrypted unlock code using a key at least partially derived from the unique device identifier.

[0140] Ex.77. The method according to any one of Ex.64 - Ex.76, wherein the unlock code included in the unlock authorization is encrypted, the method further comprising decrypting the encrypted unlock code using a key at least partially derived from a one - time code.

[0141] Ex.78. The method according to any one of Ex.75 - Ex.77, wherein the unlock code included in the unlock authorization is encrypted, the method further comprising verifying the unlock code only when the encrypted unlock code can be decrypted using the key.

[0142] Ex.79. The method according to any one of Ex.64 - Ex.78, wherein the unlock code is unique for the current unlock session.

[0143] Ex.80. The method according to any one of Ex.64 - Ex.79, wherein the unlock code is at least partially based on a one - time code.

[0144] Ex.81. The method according to any one of Ex.64 - Ex.80, wherein the unlock code includes a message authentication code.

[0145] Ex.82. A method according to any one of Ex.64 - Ex.81, wherein the unlock code comprises a hash - based message authentication code.

[0146] Ex.83. A method according to any one of Ex.64 - Ex.82, the method further comprising verifying the unlock code only when a unique device identifier included in the unlock authorization matches the unique device identifier of the aerosol - generating system.

[0147] Ex.84. A method according to any one of Ex.64 - Ex.83, wherein the unlock authorization further comprises a challenge, and the method further comprises verifying the unlock code at least in part based on the challenge.

[0148] Ex.85. A method according to any one of Ex.62 - Ex.84, the method further comprising switching between operating in a peripheral mode and operating in a central mode.

[0149] Ex.86. A method according to any one of Ex.62 - Ex.85 when dependent on Ex.62A, the method further comprising transmitting the unlock request when operating in the peripheral mode and receiving the unlock authorization when operating in the central mode.

[0150] Ex.87. A method according to any one of Ex.62 - Ex.86, wherein connectionless communication comprises communication using at least one advertisement packet.

[0151] Ex.88. A method according to any one of Ex.62 - Ex.87, wherein connectionless communication comprises communication using at least one broadcast beacon.

[0152] Ex.89. A method performed by a server, the method comprising:

[0153] Determining whether an aerosol - generating system is associated with an authorized user;

[0154] If the aerosol - generating system is associated with an authorized user, transmitting directly or indirectly to the aerosol - generating system an unlock authorization including an unlock code, the unlock authorization enabling the aerosol - generating system to transition from a locked state to an unlocked state, in which the aerosol - generating system is permitted to generate aerosol.

[0155] Ex.89A. A method according to Ex.89, the method further comprising receiving an unlock request identifying the aerosol - generating system in a locked state.

[0156] Ex.90. The method according to the method of Ex.89A, wherein the unlocking request includes a unique device identifier identifying the aerosol generating system, and the method further includes determining whether the unique device identifier is associated with an authorized user.

[0157] Ex.91. The method according to any one of Ex.89 - Ex.90, the method further includes generating an unlocking code and including the unlocking code in the unlocking authorization.

[0158] Ex.92. The method according to Ex.91, wherein the unlocking code is at least partially based on a pre - shared secret unique to the aerosol generating system.

[0159] Ex.93. The method according to Ex.91 or Ex.92 when dependent on Ex.89A, the method further includes generating the unlocking code at least partially based on a verification code included in the unlocking request.

[0160] Ex.94. The method according to any one of Ex.91 - Ex.93, the method further includes encrypting the unlocking code before transmitting the unlocking authorization.

[0161] Ex.95. The method according to Ex.94, the method further includes encrypting the unlocking code using a symmetric key algorithm.

[0162] Ex.96. The method according to Ex.94 or Ex.95, the method further includes encrypting the unlocking code using a key at least partially derived from the pre - shared secret.

[0163] Ex.97. The method according to any one of Ex.94 - Ex.96, the method further includes encrypting the unlocking code using a key at least partially derived from a unique device identifier identifying the aerosol generating system.

[0164] Ex.98. The method according to any one of Ex.94 - Ex.97, the method further includes encrypting the unlocking code using a key at least partially derived from a one - time code.

[0165] Ex.99. The method according to any one of Ex.91 - Ex.98, wherein the unlocking code is unique for the current unlocking session.

[0166] Ex.100. The method according to any one of Ex.91 - Ex.99, wherein the unlocking code is at least partially based on a one - time code.

[0167] Ex.101. The method according to any one of Ex.91 - Ex.100, wherein the unlocking code includes a message authentication code.

[0168] Ex.102. A method according to any one of Ex.91 - Ex.101, wherein the unlock code includes a hash - based message authentication code.

[0169] Ex.103. A method according to any one of Ex.89 - Ex.102, the method further comprising generating a challenge for inclusion in the unlock authorization.

[0170] Ex.104. A method performed by a computing device, the method comprising:

[0171] Receiving an unlock authorization from a server; and

[0172] Transmitting the unlock authorization to an aerosol - generating system using connectionless communication.

[0173] Ex.104A. A method according to Ex.104, the method further comprising receiving an unlock request from the aerosol - generating system using connectionless communication and transmitting the unlock request to the server.

[0174] Ex.105. A method according to Ex.104A, wherein the unlock request includes a unique device identifier identifying the aerosol - generating system.

[0175] Ex.106. A method according to Ex.105, wherein the unlock authorization includes the unique device identifier and an unlock code.

[0176] Ex.107. A method according to Ex.106, wherein the unlock code is unique for the current unlock session.

[0177] Ex.108. A method according to Ex.106 or Ex.107, wherein the unlock code is at least partially based on a one - time code.

[0178] Ex.109. A method according to any one of Ex.106 - Ex.108, wherein the unlock code includes a message authentication code.

[0179] Ex.110. A method according to any one of Ex.106 - Ex.109, wherein the unlock code includes a hash - based message authentication code.

[0180] Ex.111. A method according to any one of Ex.106 - Ex.110, wherein the unlock code is encrypted, and wherein the key used for encrypting and / or decrypting the unlock code is at least partially derived from a pre - shared secret unique to the aerosol - generating system.

[0181] Ex.112. A method according to any one of Ex.106 - Ex.111, wherein the unlock code is encrypted, and wherein a key for encrypting and / or decrypting the unlock code is at least partially derived from the unique device identifier.

[0182] Ex.113. A method according to any one of Ex.106 - Ex.112, wherein the unlock code is encrypted, and wherein a key for encrypting and / or decrypting the unlock code is at least partially derived from a one - time code.

[0183] Ex.114. A method according to any one of Ex.106 - Ex.113, wherein the unlock code is at least partially based on a verification code provided by the aerosol - generating system as part of the unlock request.

[0184] Ex.115. A method according to any one of Ex.104 - Ex.114, the method further comprising switching between operating in a peripheral mode and operating in a central mode.

[0185] Ex.116. A method according to any one of Ex.104A - Ex.115, the method further comprising receiving the unlock request when operating in the central mode, and transmitting the unlock authorization when operating in the peripheral mode.

[0186] Ex.117. A method according to any one of Ex.104 - Ex.116, wherein the connectionless communication comprises communication using at least one advertising packet.

[0187] Ex.118. A method according to any one of Ex.104 - Ex.117, wherein the connectionless communication comprises communication using at least one broadcast beacon.

[0188] Ex.119. A computer program (product) comprising instructions which, when executed by a computing system, enable the computing system to perform or cause the computing system to perform a method according to any one of Ex.62 - Ex.118.

[0189] Ex.120. A (transient or non - transient, volatile or non - volatile) computer - readable (storage) medium comprising instructions which, when executed by a computing system, cause the computing system to perform or cause the computing system to perform a method according to any one of Ex.62 - Ex.118.

[0190] Ex.121. An aerosol - generating system according to any one of Ex.1 - Ex.29, wherein the unlock code comprises a MAC address detected in network traffic.

[0191] Ex.122. The aerosol generating system according to Ex.121, wherein the aerosol generating system is configured to detect the MAC address in network traffic.

[0192] Ex.123. The aerosol generating system according to Ex.122, wherein the aerosol generating system is configured to detect the MAC address in network traffic using packet analysis.

[0193] Ex.124. The aerosol generating system according to Ex.123, wherein the aerosol generating system is configured to operate in a monitoring mode to monitor network traffic using packet analysis.

[0194] Ex.125. The aerosol generating system according to any one of Ex.121 - Ex.124, wherein the verification code includes the MAC address of a computing device of an authorized user.

[0195] Ex.126. The aerosol generating system according to Ex.125, wherein the aerosol generating system is further configured to verify the unlock code by comparing the detected MAC address with the MAC address of the computing device of the authorized user, and transition from a locked state to an unlocked state in response to a match between the detected MAC address and the MAC address of the computing device of the authorized user.

[0196] Ex.127. The aerosol generating system according to any one of Ex.121 - Ex.126, wherein the connectionless communication includes using packet analysis to monitor network traffic.

[0197] Ex.128. The method according to any one of Ex.62 - Ex.88, wherein the unlock code includes the MAC address detected in network traffic.

[0198] Ex.129. The method according to Ex.128, the method including detecting the MAC address in network traffic.

[0199] Ex.130. The method according to Ex.129, the method including detecting the MAC address in network traffic using packet analysis.

[0200] Ex.131. The method according to Ex.130, the method including operating in a monitoring mode to monitor network traffic using packet analysis.

[0201] Ex.132. The method according to any one of Ex.128 - Ex.131, wherein the verification code includes the MAC address of a computing device of an authorized user.

[0202] Ex.133. The method according to Ex.132, the method further comprising verifying the unlock code by comparing the detected MAC address with the MAC address of the computing device of the authorized user, and transitioning the aerosol generating system from a locked state to an unlocked state in response to a match between the detected MAC address and the MAC address of the computing device of the authorized user.

[0203] Ex.134. The method according to any one of Ex.128 - Ex.133, wherein the connectionless communication comprises using packet analysis to monitor network traffic.

[0204] The present invention may include one or more isolated or combined aspects, examples or features, whether specifically disclosed in that combination or separately. Any optional feature or sub - aspect of one of the above aspects is applicable to any other aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0205] A detailed description will now be given by way of example only with reference to the drawings, in which: -

[0206] Figure 1 An aerosol generating device is shown;

[0207] Figure 2 An aerosol generating device, a mobile device and a server system including Figure 1 are shown; and

[0208] Figure 3 A computing system that can be used according to the systems and methods disclosed herein is shown. DETAILED DESCRIPTION

[0209] Figure 1 A block diagram of an aerosol generating device 100 is shown. The aerosol generating device 100 may include an aerosol generating unit 110, a sensor 120, a controller 130, a storage unit 140, a communication unit 150 and a power supply 160.

[0210] The aerosol generating unit 110 is a unit for generating an aerosol from a precursor material (consumable material) for inhalation by a user of the aerosol generating device 100. For example, the aerosol generating unit 110 may include a vaporizer or a heating element. The precursor material may be provided in liquid or solid form. The aerosol generating unit 110 is powered by electrical energy provided by the power supply 160 and is controlled by the controller 130.

[0211] Sensor 120 delivers data that can be used to control the operation of the aerosol generating device 100. For example, the sensor can be configured to detect a user's interaction with the aerosol generating device 100, such as pressing a button, opening or closing a receptacle for the precursor material, performing a gesture by moving the device 100 in a specific manner, etc. Sensor 120 can also be configured to detect a puff performed by a user of the aerosol generating device 100. In another example, sensor 120 can be configured to detect voltage, current, resistance, charge, energy, or temperature related to the operation of the aerosol generating unit 110. Sensor 120 can also be configured to detect voltage, current, resistance, charge, energy, or temperature related to the power supply 160 of the aerosol generating device 100 and / or a charging device connected to the aerosol generating device 100. In another example, sensor 120 can be configured to detect the type or amount of a consumable material used by the aerosol generating unit 110.

[0212] Controller 130 is responsible for controlling the overall operation of the aerosol generating device 100, in particular operating the aerosol generating unit 110 (possibly based on data delivered by sensor 120), creating, encrypting, and storing data in the storage unit 140, receiving and transmitting data via the communication unit 150, monitoring and / or controlling the charging of the power supply 160, etc. Controller 130 can include a computing device, such as the computing device or microcontroller described herein. Controller 130 can also be equipped with additional storage means for storing computer programs and / or a memory for storing data related to the execution of the computer programs.

[0213] Storage unit 140 is connected to controller 130 and is configured to store therein data related to the unlocking process, such as a unique device identifier 142, a pre-shared secret 144, and / or a verification code 146. Storage unit 140 can be volatile or non-volatile. For example, a flash memory is provided as storage unit 140. Storage unit 140 can be an integrated part of controller 130 or a component external to controller 130. Storage unit 140 can include more than one physically or logically separate storage section or component for storing different data items. For example, the unique device identifier 142, the pre-shared secret 144, and the verification code 146 can be stored in different sections or components of storage unit 140. The pre-shared secret 144 can be stored in a section or component that is specifically protected against unauthorized access.

[0214] The unique device identifier 142 is a piece of data that is unique to the aerosol-generating device 100, such as a unique device identity (UID) assigned to the device 100 during the manufacturing phase. For example, the aerosol-generating device 100 may be equipped with a unique serial number that is stored as the unique identifier in the storage unit 140. In addition to or instead of the serial number, the unique device identifier 142 may further include information indicating at least one of a product identifier, a platform identifier, and a manufacturing location. The unique device identifier 142 may also be provided as a unique manufacturing information block (or manufacturing facility ID) MIB, i.e., as a data block including information related to the manufacturing process, such as product ID, platform ID, unique ID (or serialized device unit ID), and manufacturing location. In one example, the unique device identifier 142 is a "codentify" value, i.e., a unique multi-digit alphanumeric code that is provided and encrypted with unique manufacturing / time data during the manufacturing phase.

[0215] The pre-shared secret 144 is a value that can be used to derive an encryption key for encrypting data. The pre-shared secret 144 is secret in the sense that it is generally not known to the user or any other unauthorized person and is not (easily) derivable from the aerosol-generating device 100 or the data transmitted from or to it. During normal operation, the pre-shared secret 144 is not included in any data transmissions. The pre-shared secret 144 can be stored in a particularly secure part of the storage unit 140 that is not accessible to any external device. The pre-shared secret 144 is also stored in a database accessible by the manufacturer's server in association with the corresponding unique device identifier 142. In this way, the server can use the unique device identifier 142 in a look-up operation to obtain the pre-shared secret 144 of the aerosol-generating device 100, for example, in order to derive a cryptographic key for encrypting and / or decrypting data. Using the key so derived, the server can decrypt the encrypted data received from the aerosol-generating device 100 and / or the encrypted data to be transmitted to the aerosol-generating device 100. The pre-shared secret 144 can be a multi-byte value that is large enough to prevent brute-force attacks on the encrypted data. For example, the pre-shared secret 144 can include 8, 16, 32, 64, 128, or 256 bytes of data. Other sizes can also be used for the pre-shared secret 144, including sizes that are powers of two or different from powers of two. By way of example, a random or pseudo-random number generated during the manufacturing process can be used as the pre-shared secret 144. The pre-shared secret 144 can be generated by the aerosol-generating device 100 during the manufacturing process and preferably transmitted in encrypted form to the host computer, for example, using a public-key cryptosystem like RSA, and the host computer stores the pre-shared secret 144 in the database in association with the unique device identifier 142 for later reference by the manufacturer's server. For example, the device 100 can encrypt the pre-shared secret 144 and the unique device identifier 14 using the server's public key before sending them to the server, and the server decrypts them using its private key. The pre-shared secret 144 can also be generated by the host computer and transmitted to the storage unit 140 or written directly into the storage unit during a stage of the manufacturing process.

[0216] The verification code 146 includes any suitable information by which the aerosol-generating device 100 verifies an unlock authorization, for example, an unlock code included in an unlock authorization received from a server. The verification code 146 may be generated at the aerosol-generating device 100 or may be generated by an authorized party such as a device manufacturer who knows the pre-shared secret 144 included in the aerosol-generating device 100. The verification code 146 may be created and used for verification in a number of ways. One example involves the calculation of the verification code on the aerosol-generating device 100 and the parallel calculation of the unlock code on the server, and then the aerosol-generating device compares the unlock code received from the server with the verification code calculated by itself. In this example, the verification code and the unlock code may be calculated based on common information such as a pre-shared secret and / or based on a known time point or time slot. In another example, the verification process involves the server encrypting the verification code (plus an optional server challenge) that acts as a device challenge to create the unlock code, and receiving, decrypting the unlock code on the aerosol-generating device 100 and comparing it with the verification code (plus an optional server challenge). In yet another example, the verification code includes the MAC address of a mobile device belonging to an authorized user, as further described below.

[0217] The communication unit 150 acts as a communication interface for establishing a communication link to an external device (in particular, an external computing device such as a mobile device) and / or to a manufacturer server. The communication link may be based on any wired or wireless communication technology, including but not limited to serial communication links, Universal Serial Bus (USB), optical communication ports, Near Field Communication (NFC), Bluetooth, Bluetooth Low Energy (BLE), wireless communication, WiFi according to any of the standards in the IEEE 802.11x standard, mobile communication, etc. The communication with the manufacturer server may be direct or indirect, for example, via an intermediary such as a mobile device, a cradle or a docking station. The communication with the manufacturer server may also involve more than just one communication protocol, such as, for example, a Bluetooth connection between the aerosol-generating device 100 and a mobile device and a mobile communication between the mobile device and an Internet access point.

[0218] The power supply 160 acts as an energy storage unit that supplies power to all components of the aerosol-generating device 100. The power supply 160 may be a rechargeable battery, such as a lithium-ion battery or a lithium-polymer battery.

[0219] Figure 2A block diagram of a system is shown that includes an aerosol-generating device 100, an external computing device of a user, which in this example includes a mobile device 200, and a manufacturer server 300. The aerosol-generating device 100 and the mobile device 200 are connected by a communication link for transmitting data. In one non-limiting example described herein, the communication link between the aerosol-generating device 100 and the mobile device 200 is implemented using Bluetooth Low Energy (BLE). The mobile device 200 may include a smartphone, a tablet, or a PC running dedicated software, such as an application (app) or a web browser. The mobile device 200 and the server 300 are also connected by a communication link. Thus, a communication link is indirectly formed between the aerosol-generating device 100 and the server 300, with the mobile device 200 acting as an intermediary. The server 300 has access to a database (not shown) that stores a pre-shared secret 144 for the aerosol-generating device 100, particularly associated with the unique device identifier 142 of the aerosol-generating device.

[0220] The present disclosure relates to a process of unlocking the aerosol-generating device 100 using BLE without completing a full BLE pairing sequence. The unlocking process can be performed to confirm that the user of the aerosol-generating device 100 is a legal age user / legal age smoker (LAU / LAS). In this way, exposure of minors to nicotine-containing aerosols generated by the aerosol-generating device 100 can be prevented during normal use. However, the unlocking process can be used to unlock any device function for any reason. The unlocking process uses the open nature (advertising or beaconing) of BLE to exchange information between the aerosol-generating device 100 and the mobile device 200, and thereby with the server 300, which can be used to unlock the aerosol-generating device 100. To this end, each of the aerosol-generating device 100 and the mobile device 200 (particularly the app) is capable of supporting BLE in both central and peripheral Generic Access Profile (GAP) roles. A device operating in a peripheral role is capable of transmitting data (in the form of "advertising") that includes the identity of the device and other information. A device operating in a central role is capable of scanning such incoming data. This connectionless communication is typically used before pairing two BLE devices, where one advertises its presence and the other reads the advertisement and optionally initiates a pairing process to form a connection for subsequent connection-oriented communication.

[0221] Figure 2 A first non-limiting example of the unlocking process is also shown.

[0222] In an optional preliminary step of the unlocking process, the user inputs user identification data into the mobile device 200 at step 10.

[0223] When the user is ready to start the unlocking process, the user launches a dedicated application (or a general application) on the mobile device at step 12. Optionally, the application itself then verifies that the user is a LAU / LAS before the unlocking process can be activated. This step may involve the user uploading information such as an identity card via the mobile device 12 so that it can be verified at the mobile device and / or at the server whether the user is above an age threshold. If the user is a LAU / LAS, the application invites the user to activate the unlocking process, for example, by pressing a button on the aerosol generating device 100 (which is in a locked state at this time) so as to provide a signal to the sensor 120. If there are multiple locked aerosol generating devices 100, the application prompts the user to select the correct device. This indication can be given by the application simply by reading the advertisement sent by the device without the need for pairing.

[0224] At step 14, after the application is launched, the mobile device 200 is put in the central role of being ready to detect BLE advertisements from the aerosol generating device 100.

[0225] At step 16, as indicated by the application, the user presses a button on the aerosol generating device 100 to activate the unlocking process.

[0226] At step 18, the aerosol generating device 100 generates a verification code 146. In this non-limiting example, the verification code 146 includes a random one-time code (OTC) which changes for each initiated unlocking process.

[0227] At step 20, the aerosol generating device 100 is put in the peripheral role.

[0228] At step 22, the aerosol generating device 100 starts a BLE advertisement containing an unlocking request with a unique device identifier 142 (UID) and OTC 146.

[0229] At step 24, the mobile device 200 (and ultimately, the application) receives the unlocking request from the aerosol generating device 100.

[0230] At step 26, the mobile device 200 sends an unlocking request containing the UID 142, OTC 146 and optionally also user identification data (entered at step 10) to the server 300. Any suitable communication means can be used in this step.

[0231] At step 28, the server 300 determines whether to permit unlocking for the received UID. For example, UID 142 is used to retrieve the device unique serial number (DUSN), which can be linked to only one user account. The device is permitted to unlock only when the DUSN has been linked to a user account corresponding to the user identification data and only when the user is a LAU / LAS. If the device is not permitted to unlock, the unlocking process can be aborted.

[0232] At step 30, if the device is permitted to unlock, the server 300 encrypts the OTC 146 using the UID 142 and the pre-shared secret 144.

[0233] At step 32, the server 300 sends an unlocking authorization containing the UID 142 and the encrypted OTC 146 to the mobile device 200. The unlocking authorization may also optionally include a random value generated by the server 300 as a server challenge.

[0234] At step 34, the mobile device 200 enters the peripheral mode.

[0235] At step 36, the mobile device 200 advertises the unlocking authorization containing the UID 142, the encrypted OTC 146, and the server challenge (if used).

[0236] At step 38, after the aerosol-generating device 100 advertises an unlocking request in step 22, the aerosol-generating device alternates between the peripheral mode and the central mode.

[0237] At step 40, the aerosol-generating device receives a BLE advertisement containing the unlocking authorization in the central role.

[0238] At step 42, the aerosol-generating device 100 checks the UID 142 to ensure that the unlocking authorization is intended for that specific aerosol-generating device 100. If not, the aerosol-generating device 100 ignores the unlocking authorization. If so, the aerosol-generating device 100 decrypts the encrypted OTC 146 using the UID 142 and the pre-shared secret 144 to obtain the decrypted OTC that serves as the unlocking code.

[0239] At step 44, the aerosol-generating device 100 verifies the received unlocking code by comparing the received unlocking code (i.e., the decrypted OTC) with the OTC stored on the aerosol-generating device 100, i.e., the OTC included in the unlocking request. If the OTCs match, the aerosol-generating device 100 transitions to the unlocked state, for example, by unlocking the lockable function.

[0240] After the unlocking process has been completed or aborted, the aerosol generating device 100 may return to a peripheral role and continue to advertise its UID 142 and, optionally, also its locked state. Then, the UID 142 and the locked state may be retrieved by the mobile device 200 in a central role, and the mobile device may optionally transmit the locked state to the server 300. In other instances of the unlocking process, the server 300 may use the locked state to determine whether to send an unlocking authorization to the aerosol generating device 100. Additionally or alternatively, once the device 100 is in an unlocked state (which may be confirmed based on such other advertisements of the device 100 and / or manually in the application), the device 100 may restart in the BLE "connectable" mode, thereby allowing the aerosol generating device 100 to pair with the mobile device 200.

[0241] In this non-limiting example, encryption and decryption are performed using a symmetric key algorithm, such as AES128 in CTR mode. The symmetric key algorithm uses a master key and an initialization vector (IV) for encryption. The master key and the IV may be generated by a key derivation function (KDF) using the UID 142, a pre-shared secret 144, and an OTC 146. The KDF derives one or more cryptographic keys from a key provided as input material and parameters known as "salt" and "context". The KDF may include a hash-based key derivation function (HKDF), where HMAC-SHA1 is used as the hash function. In this example, the HKDF uses the pre-shared secret 144 as the input key material and the UID 142 and the OTC 146 for the other parameters (salt and context). By creating the IV using the OTC 146, the IV changes during each encryption process, making the encryption very secure.

[0242] The following table shows the server-side encryption process for encrypting the OTC based on the UID 142 and the OTC 146 received in the unlock request.

[0243] Server-side encryption process Result Obtain its pre-shared secret 144 using the UID 142 of device 100 Pre-shared secret 144 Execute HKDF using UID 142, secret 144, and OTC 146 Master key and IV Apply the AES128CTR mode (master key, IV) to OTC 146 Encrypt OTC

[0244] The following table shows the device-side decryption process for decrypting the encrypted OTC received from the server 300 in the unlock authorization.

[0245]

[0246] In a variant of the above non-limiting example, the server 300 hashes the encrypted OTC before sending it back, while the aerosol generating device 100 encrypts the original OTC using AES and then hashes it, and then compares the two hashes and determines that the user is a LAU in response to the two hashes matching.

[0247] In another variant, the aerosol-generating device 100 and the mobile device 200 may use BLE scan requests to exchange information. In this case, the aerosol-generating device 100, when in peripheral mode, may indicate that it has certain properties, including whether it is (or is not) a connectable device, or whether it is (or is not) "scannable". Then, the mobile device 200, when in central mode, may send a scan request ("SCAN_REQ"), and the aerosol-generating device 100, acting as a peripheral device, may read and (using a scan response packet "SCAN_RSP") reply to the scan request to add additional information to the information contained in the initial advertisement. Thus, in the case where the payload required for the unlocking process is greater than the payload allowed by the advertisement packet, the aerosol-generating device 100 may indicate that it is "scannable" and use the scan response to transfer some or all of the above information to the mobile device 200. Conversely, and in the case where the encrypted OTC is greater than the advertisement packet size, the mobile device 200 may also use this "scannable" property to trigger a scan request from the aerosol-generating device 100 when sending the encrypted OTC to the aerosol-generating device 100, in order to send information to the aerosol-generating device 100 using the scan response.

[0248] In yet another variant, a predetermined code may be used to form a verification / unlocking code in place of the OTC of the above non-limiting examples. In this case, the fixed code may be exchanged in use between the device 100 and the server 300 using a process such as the above, or may be pre-known for both the device 100 and the server 300, for example, from the manufacturing process. The fixed code may include or be based on a pre-shared secret 144. In such an instance, additional context information may be used to supplement the fixed code to achieve additional security. For example, the verification / unlocking code may be based on such a fixed code in combination with time-varying information known or accessible to both parties, such as the current day time or the current numbered time slot.

[0249] Furthermore, it should be understood that the unlocking process does not necessarily need to be initiated by the device 100. In one such variant, the mobile device 200 and / or the server 300 may initiate the unlocking process, and the device 100 does not have to advertise its UID 142 or OTC 146. In such a variant, the device 100 may remain in central mode until it receives an unlocking authorization from the mobile device 200. The mobile device 200 may initiate the unlocking process by sending an unlocking request to the server 300 using the UID 142 of the device 100 and / or user identification data. If the user is authorized, the server 300 may then encrypt a predetermined code that has been stored in the database using the UID 142 and the pre-shared secret 144 as described above (optionally modified using the context information as described above) so that the device 100 performs decryption and / or code matching for verification purposes.

[0250] In a second non - limiting example of the unlocking process, the aerosol - generating device 100 utilizes mobile device MAC address grouping detection for YAP activation.

[0251] In this example, the aerosol - generating device 100 monitors or "sniffs" network traffic for at least one packet from a specific MAC address (e.g., the MAC address of the mobile device 200) in order to unlock the aerosol - generating device 100 to start a new experience. Thus, in this example, network sniffing (i.e., packet analysis) is used to implement connectionless communication. The detection of the MAC address indicates that the mobile device 200 is close enough to the aerosol - generating device 100 to confirm that the experience is being supervised by an authorized user. The MAC address is unique for each TCP / IP device and can be pre - stored on the aerosol - generating device 100 for this purpose. In this way, a packet including the MAC address of the mobile device 200 of the authorized user is regarded as an implied permission to unlock the aerosol - generating device 100, enabling the aerosol - generating device 100 to be unlocked as part of YAP activation. The detected MAC address serves as an unlock code for unlocking the aerosol - generating device 100, while the MAC address stored on the aerosol - generating device 100 serves as a verification code 146 for verifying the unlock code. The matching of the two codes indicates permission to unlock.

[0252] In this example, the aerosol - generating device 100 is configured to use WiFi communication, i.e., communication based on the IEEE 802.11 standard family. This communication typically involves a centralized access point (AP) that coordinates all communications, where a WiFi - enabled device needs to be associated with the AP to receive packets from it. In this example, the aerosol - generating device 100 is configured to receive unlock authorization using connectionless communication by operating its WiFi - enabled communication unit 150 in a monitoring mode, where the aerosol - generating device 100 receives all packets within a given frequency range. In the monitoring mode, the aerosol - generating device 100 can monitor the MAC addresses of devices currently communicating with the AP even when the aerosol - generating device 100 itself is not associated with the AP. Optionally, the aerosol - generating device 100 can perform a minimum signal strength (including signals with pre - stored MAC addresses) to ensure that the mobile device 200 of the authorized user is close enough. Since there may be multiple WiFi channels, the aerosol - generating device 100 can be configured to sequentially monitor them for a predetermined period (e.g., 100 ms) to detect the pre - registered MAC address.

[0253] In this way, the aerosol - generating device 100 can implement YAP using mobile device proximity detection without the need for user intervention or application installation.

[0254] It should be understood that the use of the MAC address is described only for illustrative purposes and any address or code that uniquely identifies and indicates the proximity of the mobile device 200 of the authorized user can be used to replace or supplement the MAC address, such as the device identifier used in Bluetooth.

[0255] Figure 3 An exemplary computing system 800 that can be used in accordance with the systems and methods disclosed herein is shown. The computing system 800 can form part of or include any desktop computer, laptop computer, server, or cloud-based computing system. The computing system 800 includes at least one processor 802 that executes instructions stored in a memory 804. The instructions can be, for example, instructions for implementing functions described as being performed by one or more components described herein or instructions for implementing one or more methods described herein. The processor 802 can access the memory 804 via a system bus 806. In addition to storing executable instructions, the memory 804 can also store session inputs, scores assigned to the session inputs, and the like.

[0256] The computing system 800 further includes a data storage device 808 that can be accessed by the processor 802 via the system bus 806. The data storage device 808 can include executable instructions, log data, and the like. The computing system 800 also includes an input interface 810 that allows external devices to communicate with the computing system 800. For example, the input interface 810 can be used to receive instructions from an external computer device, from a user, and the like. The computing system 800 also includes an output interface 812 that interfaces the computing system 800 with one or more external devices. For example, the computing system 800 can display text, images, and the like via the output interface 812.

[0257] It is contemplated that external devices that communicate with the computing system 800 via the input interface 810 and the output interface 812 can be included in an environment that provides substantially any type of user interface with which a user can interact. Examples of user interface types include graphical user interfaces, natural user interfaces, and the like. For example, a graphical user interface can accept input from a user employing (a) input device(s) such as a keyboard, a mouse, a remote control, and the like, and provide output on an output device such as a display. In addition, a natural user interface can enable a user to interact with the computing system 800 in a manner that is not constrained by input devices such as a keyboard, a mouse, a remote control, and the like. Instead, a natural user interface can rely on speech recognition, touch and touch recognition, gesture recognition on and near the screen, air gestures, head and eye tracking, speech and language, vision, touch, gesture, machine intelligence, and the like.

[0258] Additionally, although shown as a single system, it should be understood that computing system 800 can be a distributed system. Thus, for example, several devices can communicate via a network connection and can jointly perform tasks described as being performed by computing system 800.

[0259] The various functions described herein can be implemented in hardware, software, or any combination thereof. If implemented in software, the functions can be stored on a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. A computer-readable medium includes a computer-readable storage medium. A computer-readable storage medium can be any available storage medium accessible by a computer. By way of example and not limitation, such computer-readable storage media can include flash storage media, RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and that can be accessed by a computer. As used herein, disk and disc include CD, laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc (BD), where disk typically reproduces data magnetically and disc typically reproduces data optically with a laser. Additionally, propagated signals can be included within the scope of computer-readable storage media. A computer-readable medium also includes a communication medium, which includes any medium that facilitates transfer of a computer program from one place to another. For example, a connection can be a communication medium. For example, if software is transferred from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of communication medium. Combinations of the above should also be included within the scope of computer-readable media.

[0260] Alternatively or additionally, the functions described herein can be performed, at least in part, by one or more hardware logic components. By way of example, and not limitation, illustrative types of hardware logic components that can be used include field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), system on a chip (SOC), complex programmable logic devices (CPLD), etc.

[0261] The applicant hereby discloses independently each individual feature described herein and any combination of two or more such features, provided that these features or combinations can be implemented based on the present specification as a whole according to the common general knowledge of those skilled in the art, regardless of whether these features or combinations of features solve any of the problems disclosed herein, and are not limited to the scope of the claims. The applicant indicates that various aspects of the present invention may consist of any such individual feature or combination of features.

[0262] It must be noted that embodiments of the present invention are described with reference to different categories. Specifically, some examples are described with reference to methods, while other examples are described with reference to devices. However, those skilled in the art will understand from this specification that, unless otherwise notified, any combination between features related to different categories is also considered to be disclosed by this application, in addition to any combination of features belonging to one category. However, all features can be combined to provide more synergistic effects than a simple addition of the features.

[0263] Although the present invention has been shown and described in detail in the drawings and the foregoing description, such showings and descriptions are to be considered illustrative and not restrictive. The present invention is not limited to the disclosed embodiments. Those skilled in the art can understand and implement other variations of the disclosed embodiments through the study of the drawings, the present disclosure, and the appended claims.

[0264] The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used advantageously.

[0265] Any reference signs in the claims shall not be construed as limiting the scope.

Claims

1. An aerosol - generating system in a locked state that prevents the aerosol - generating system from generating an aerosol in the locked state, the aerosol - generating system being configured to: Receive an unlock authorization from an external computing device using connectionless communication, and After receiving the unlock authorization, transition the aerosol - generating system from the locked state to an unlocked state, in which the aerosol - generating system is allowed to generate an aerosol.

2. The aerosol - generating system according to claim 1, wherein the aerosol - generating system is configured to transmit an unlock request to the external computing device using connectionless communication.

3. The aerosol - generating system according to claim 2, wherein the unlock request includes a unique device identifier identifying the aerosol - generating system.

4. The aerosol - generating system according to claim 3, wherein the unlock authorization includes the unique device identifier and an unlock code.

5. The aerosol - generating system according to claim 4, wherein the unlock code is generated at, or derived by, a server.

6. The aerosol - generating system according to claim 4 or claim 5, the aerosol - generating system further being configured to verify the unlock code using a pre - shared secret unique to the aerosol - generating system after receiving the unlock authorization.

7. The aerosol - generating system according to any one of claims 4 - 6, the aerosol - generating system further being configured to transition the aerosol - generating system from the locked state to the unlocked state in response to successfully verifying the unlock code.

8. The aerosol - generating system according to any one of claims 4 - 7, the aerosol - generating system further being configured to obtain a verification code for comparison with the unlock code.

9. The aerosol - generating system according to claim 8, wherein the verification code is generated at the aerosol - generating system.

10. The aerosol - generating system according to any one of claims 4 - 9, the aerosol - generating system further being configured to verify the unlock code by comparing the unlock code with the verification code and, in response to the unlock code matching the verification code, transition the aerosol - generating system from the locked state to the unlocked state.

11. The aerosol - generating system according to any one of claims 4 - 10, the aerosol - generating system further being configured to generate a verification code, and the aerosol - generating system verifies the unlock code based on the verification code.

12. The aerosol - generating system according to any one of claims 4 - 11, the aerosol - generating system further being configured to include a verification code in the unlock request and, when verifying the unlock code, determine whether the unlock code included in the unlock authorization matches the verification code.

13. A server, the server being configured to: Determine whether an aerosol - generating system is associated with an authorized user; If the aerosol-generating system is associated with an authorized user, an unlocking authorization including an unlocking code is transmitted directly or indirectly to the aerosol-generating system, and the unlocking authorization enables the aerosol-generating system to transition from a locked state to an unlocked state, in which the aerosol-generating system is allowed to generate an aerosol.

14. A method performed by a computing device, the method comprising: Receiving an unlocking authorization from a server; And Transmitting the unlocking authorization to the aerosol-generating system using connectionless communication.

15. A computer program product comprising instructions that, when executed by a computing system, cause the computing system to perform the method according to claim 14.