Age and identification confirmation system

The computing device and RRD system addresses the challenge of varying age requirements by locking the RRD until successful identity verification, ensuring legal access and use.

JP2025170295APending Publication Date: 2025-11-18ALTRIA CLIENT SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025134825
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-05-07
Filing Date
2025-08-13
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Various jurisdictions have different minimum age requirements for the purchase, sale, and consumption of tobacco-related and nicotine-related products, necessitating effective age and identity verification systems for retailers to ensure compliance.

Method used

A computing device and risk-reduced device (RRD) system that includes identity verification through a unique ID, cryptographic keys, and control circuitry to ensure the RRD operates only after successful adult verification, initially locking the device until verified.

Benefits of technology

Ensures compliance with age and identity verification requirements by enabling or disabling the RRD based on successful verification, preventing unauthorized access and use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025170295000001_ABST
    Figure 2025170295000001_ABST
Patent Text Reader

Abstract

To provide a computing device for confirming the identification of an adult consumer.SOLUTION: An age and / or identification confirmation system for a reduced risk device (RRD) includes an RRD which is initially in an inoperable state, an identification confirmation server configured to perform identification confirmation related to an adult consumer, and a personal computing device. The personal computing device receives adult consumer identification information corresponding to an adult consumer from the adult consumer, receives a UID of the RRD, transmits the adult consumer identification information and the UID of the RRD to the identification confirmation server, executes the identification confirmation of the adult consumer, receives a result of the executed identification confirmation from the identification confirmation server, receives an encryption key corresponding to the RRD on the basis of the result of the executed identification confirmation for the adult consumer, and transmits the encryption key to the RRD. The RRD changes a state of the RRD to an operable state on the basis of the encryption key.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to systems, devices, methods, and / or non-transitory computer-readable media related to age and / or identity verification of reduced-risk or reduced-harm devices, such as thermal non-combustible aerosol generating devices, non-heated inhalable aerosol generating devices, electronic vaping devices (e.g., e-vaping devices), and the like. [Background technology]

[0002] In various countries and elsewhere, the purchase, sale, possession, and / or operation of tobacco-related, nicotine-related products, and / or non-nicotine-related products, such as reduced-risk or reduced-harm products, are restricted based on the consumer's age. Examples of reduced-risk products (e.g., reduced-harm products) include nicotine or non-nicotine, heated non-combustion aerosol generators, heated non-inhalable aerosol generators, and / or electronic vaping devices (e.g., e-vaping devices). For example, under U.S. federal law, only individuals 21 years of age or older are legally permitted to purchase, possess, and / or consume, or attempt to purchase, possess, and / or consume, tobacco-related and / or nicotine-related products. Summary of the Invention [Problem to be solved by the invention]

[0003] However, various states, cities, countries, and other jurisdictions may have different minimum age requirements for the purchase, sale, possession, and / or consumption of tobacco-related products. Furthermore, retailers and other businesses that sell tobacco-related products to individuals are legally required to verify that purchasers of tobacco-related products comply with the relevant minimum age provisions before selling tobacco-related products to individuals. [Means for solving the problem]

[0004] At least one embodiment relates to a computing device for verifying the identity of an adult consumer. In an exemplary embodiment, the computing device may include a memory having computer-readable instructions stored thereon and at least one processor configured to execute the computer-readable instructions. The at least one processor may receive adult consumer identity information corresponding to the adult consumer from the adult consumer, receive a unique ID (UID) of a risk-reduced device (RRD), transmit the adult consumer identity information to an identity verification server to perform identity verification of the adult consumer, receive results of the performed identity verification from the identity verification server, generate a cryptographic key corresponding to the RRD based on the results of the performed identity verification of the adult consumer and the UID of the RRD, transmit the cryptographic key to the RRD, and cause the cryptographic key to change the state of the RRD based on the cryptographic key.

[0005] At least one embodiment relates to a Risk Reduction Device (RRD) for use in an identity verification service, where the RRD is initially in an inoperable state. In an exemplary embodiment, the RRD may include at least one transceiver configured to communicate with at least one computing device, a memory configured to store a private key corresponding to the RRD, and control circuitry configured to receive, from a computing device associated with an adult consumer, a cryptographic key corresponding to the RRD, the cryptographic key being generated based on a unique ID (UID) corresponding to the RRD and a result of an identity verification performed on the adult consumer by an identity verification server, decrypt the cryptographic key using the private key, determine whether the adult consumer's identity has been successfully verified based on the decryption key, and change the state of the RRD to an operable state based on the result of determining whether the adult consumer's identity has been successfully verified.

[0006] At least one embodiment relates to an identity verification system. In an exemplary embodiment, the identity verification system may include a risk-reduced device (RRD), the RRD including a unique ID (UID) of the RRD and at least one transceiver, the RRD being initially in an inoperable state; an identity verification server configured to perform identity verification associated with an adult consumer; and a computing device. The computing device may be configured to receive adult consumer identity information corresponding to the adult consumer from the adult consumer, receive the UID of the RRD, transmit the adult consumer identity information and the UID of the RRD to the identity verification server, perform identity verification of the adult consumer, receive a result of the performed identity verification from the identity verification server, receive a cryptographic key corresponding to the RRD based on the result of the performed identity verification of the adult consumer, the cryptographic key being generated based on the UID of the RRD, and transmit the cryptographic key to the RRD. The RRD may be further configured to change the state of the RRD to an operational state based on the cryptographic key. [Brief explanation of the drawings]

[0007] Various features and advantages of the non-limiting exemplary embodiments herein will become more apparent from a consideration of the detailed description in conjunction with the accompanying drawings, which are provided for illustrative purposes only and should not be construed to limit the scope of the claims. The accompanying drawings should not be considered to be drawn to scale unless explicitly stated. Various dimensions of the drawings may be exaggerated for clarity.

[0008] [Figure 1] FIG. 1 is a schematic diagram of an exemplary thermal non-combustion aerosol generating device according to at least one exemplary embodiment.

[0009] [Figure 2] FIG. 2 is a cross-sectional view of an exemplary e-vape device according to at least one exemplary embodiment.

[0010] [Figure 3]FIG. 3 is a block diagram illustrating various components of an identification system including a risk-reduced device, a personal computing device, and an identification server in accordance with at least one exemplary embodiment.

[0011] [Figure 4A] FIG. 4A is a block diagram illustrating various components of a personal computing device for an identity verification system in accordance with at least one exemplary embodiment.

[0012] [Figure 4B] FIG. 4B is a block diagram illustrating various components of a risk-reduced device for an identity verification system in accordance with at least one exemplary embodiment.

[0013] [Figure 4C] FIG. 4C is a block diagram illustrating various components of an identity verification server for an identity verification system in accordance with at least one exemplary embodiment.

[0014] [Figure 5] FIG. 5 is a flowchart illustrating a method of operating a risk-reduced device in accordance with at least one exemplary embodiment.

[0015] [Figure 6] FIG. 6 is a flowchart illustrating a method for verifying the age and / or identity of an adult consumer associated with a risk-reduced device in accordance with at least one exemplary embodiment.

[0016] [Figure 7] FIG. 7 is a flowchart illustrating a method for unlocking a risk-reduced device that has been locked based on the outcome of an age and / or identity challenge, according to at least one exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0017] It should be noted that these figures are intended to illustrate general characteristics of methods and / or structures utilized in certain exemplary embodiments and to supplement the description of the specification provided below. However, these figures are not to scale, may not precisely reflect the exact structure or performance characteristics of any exemplary embodiment, and should not be construed to define or limit the range of values ​​or characteristics encompassed by the exemplary embodiments. Although several detailed exemplary embodiments are disclosed herein, the specific structural and functional details disclosed herein are merely representative for purposes of describing the exemplary embodiments, however, the exemplary embodiments may be embodied in many alternative forms and should not be construed as being limited to only the exemplary embodiments set forth herein.

[0018] Thus, while example embodiments are susceptible to various modifications and alternative forms, example embodiments thereof have been shown by way of example in the drawings and will be described in detail herein. It is to be understood, however, that there is no intention to limit the example embodiments to the particular forms disclosed, but on the contrary, the example embodiments encompass all modifications, equivalents, and alternatives falling within the scope of the example embodiments. Like numbers refer to like elements throughout the description of the figures.

[0019] Various exemplary embodiments relate to systems, devices, methods, and / or non-transitory computer-readable media related to age and / or identity verification of reduced-risk devices (e.g., harm-reduced devices, etc.). Reduced-risk devices may include heated non-combustion aerosol generating devices, non-heated inhalable aerosol generating devices, e-vaping devices (e.g., e-vaping devices), etc. While a description of two exemplary embodiments of reduced-risk devices is provided in connection with FIGS. 1-2, exemplary embodiments of reduced-risk devices are not limited thereto and may also include non-heated inhalable aerosol generating devices, etc.

[0020] FIG. 1 is a schematic diagram of an exemplary thermal non-combustion aerosol generating device according to at least one exemplary embodiment. Referring to FIG. 1 , the thermal non-combustion aerosol generating device 1000 may include, but is not limited to, a mouthpiece 1015 and a device body 1025. A power source 1035 and a control circuit 1045 may be disposed within the device body 1025 of the thermal non-combustion aerosol generating device 1000. According to at least one exemplary embodiment, the thermal non-combustion aerosol generating device 1000 may include an I / O interface (not shown) and / or a network interface (not shown). The I / O interface may be a USB interface (e.g., a USB mini-cable interface), a power cable, or the like. The network interface may be a Bluetooth transmitter (e.g., Bluetooth and / or Bluetooth Low Energy (LE), etc.), an NFC transmitter, a ZigBee transmitter, a WiFi transmitter, a cellular network transmitter, etc. Furthermore, the thermal non-combustion aerosol generating device 1000 may include a puff sensor (not shown) for detecting a puff, for example, by detecting the application of negative air pressure to the mouthpiece 1015. In response to the detection of a puff by the puff sensor and / or the application of negative air pressure, the control circuit 1045 may be configured to control, for example, the supply of current to one or more heaters of the thermal non-combustion aerosol generating device 1000.

[0021] The thermal non-combustion aerosol generating device 1000 is configured to receive a capsule 1080. The capsule 1080 is removable. According to at least some exemplary embodiments, the capsule 1080 may include an aerosol-forming substrate (e.g., a pre-dispersed formulation, etc.) sandwiched between first and second heaters. According to at least some exemplary embodiments, the first and second heaters may be planar and formed of a material that heats when an electric current is applied. The thermal non-combustion aerosol generating device 1000 may also include, but is not limited to, a first electrode 1055a, a second electrode 1055b, a third electrode 1055c, and a fourth electrode 1055d configured to be in electrical contact with the capsule 1080. According to at least some exemplary embodiments, the first electrode 1055a and the third electrode 1055c may be in electrical contact with a first heater, and the second electrode 1055b and the fourth electrode 1055d may be in electrical contact with a second heater. However, it should be understood that in non-limiting embodiments including a capsule having only one heater, the first electrode 1055a and the third electrode 1055c (or the second electrode 1055b and the fourth electrode 1055d) may be omitted.

[0022] As used herein, the term "aerosol-forming substrate" refers to a material (or combination of materials) capable of producing an aerosol. As referred to herein, "aerosol" refers to any substance generated or output from any thermal non-combustion aerosol-generating device according to any of the exemplary embodiments disclosed herein. The material is in solid form and is a significant source of a compound (e.g., nicotine, cannabinoids, etc.), and when the material is heated, an aerosol containing the compound is generated. The heating may be below combustion temperatures to generate the aerosol without substantial thermal decomposition of the aerosol-forming substrate or substantial production of combustion by-products (if any). Thus, according to at least some exemplary embodiments, thermal decomposition does not occur during heating and the resulting production of the aerosol. In other examples, thermal decomposition and combustion by-products may exist, but the extent may be relatively small and / or may be considered merely incidental. For example, when a thermal non-combustion aerosol-generating device heats the aerosol-forming substrate to an aerosolization temperature, the aerosol-forming substrate may produce an aerosol. As used herein, the "aerosolization temperature" of an aerosol-forming substrate is the temperature at which the aerosol-forming substrate produces an aerosol, and is up to the combustion temperature of the aerosol-forming substrate.

[0023] The aerosol-forming substrate may be a fibrous material. For example, the fibrous material may be a plant material. The fibrous material is configured to release a compound when heated. The compound may be a naturally occurring component of the fibrous material. For example, the fibrous material may be a plant material such as tobacco, and the released compound may be nicotine. The term "tobacco" includes tobacco leaves, tobacco plugs, reconstituted tobacco, compressed tobacco, formed tobacco, or powdered tobacco, and combinations thereof, derived from one or more tobacco plants, such as Nicotiana rustica and Nicotiana tabacum.

[0024] FIG. 2 is a cross-sectional view of an exemplary e-vape device according to at least one exemplary embodiment.

[0025] 2, the e-vaping device 2000 may include a replaceable cartridge (or first portion) 2070 and a reusable battery portion (or second portion) 2072, which may be coupled to one another with a threaded connector 2205. The first portion 2070 (e.g., a dispersed product, cartridge, pod assembly, pod, capsule, etc.) may include a housing 2006, and the second portion 2072 may include a second housing 2006′. The e-vaping device 2000 includes a mouth-end insert 2008. The first portion 2070 may include a reservoir 2345 configured to contain an aerosol-forming substrate (e.g., a pre-dispersed formulation, etc.), such as a pre-vaporized formulation, dried herbs, essential oils, etc., and at least one heater 2014 that may draw from the reservoir 2345 by a wick 2028 to vaporize the aerosol-forming substrate.

[0026] In at least one exemplary embodiment, the pre-vaporization formulation is a material or combination of materials that can be converted into vapor. For example, the pre-vaporization formulation may be a liquid, solid, and / or gel formulation, including, but not limited to, water, beads, solvents, active ingredients, ethanol, plant extracts, natural or artificial flavors, and / or vapor-forming agents such as glycerin and propylene glycol. The pre-vaporization formulation may include a nicotine compound or a non-nicotine compound.

[0027] In some exemplary embodiments, the active ingredient may be a nicotine compound or a non-nicotine compound. The nicotine compound may include tobacco or may be a compound derived from tobacco. Meanwhile, the non-nicotine compound is not a non-nicotine compound that does not include tobacco or is derived from tobacco. In at least one exemplary embodiment, the non-nicotine compound is cannabis or includes at least one cannabis-derived component. In at least one exemplary embodiment, the cannabis-derived component includes at least one of a cannabis-derived cannabinoid (e.g., a phytocannabinoid, or a cannabinoid synthesized by the cannabis plant), at least one cannabis-derived terpene, at least one cannabis-derived flavonoid, or a combination thereof.

[0028] In at least one exemplary embodiment, the pre-vaporized formulation (either nicotine or non-nicotine type) includes at least one flavoring. In at least one exemplary embodiment, the at least one flavoring may be at least one of a natural flavoring, an artificial flavoring, or a combination of a natural flavoring and an artificial flavoring. For example, the at least one flavoring may include menthol, wintergreen, peppermint, cinnamon, clove, combinations thereof, and / or extracts thereof. In addition, flavorings may be included to provide herbal flavors, fruit flavors, nut flavors, liquor flavors, roasted flavors, mint flavors, savory flavors, combinations thereof, and any other desired flavors.

[0029] In at least one exemplary embodiment, the non-nicotine pre-vaporized formulation in at least one flavoring comprises volatile cannabis flavor compounds (flavonoids). In at least one exemplary embodiment, the at least one flavoring of the non-nicotine pre-vaporized formulation comprises flavor compounds instead of or in addition to cannabis flavor compounds.

[0030] In at least one exemplary embodiment, the non-nicotine compound may be a naturally occurring component of a medicinal plant or a plant with medically acceptable therapeutic effects. The medicinal plant may be the cannabis plant, and the component may be at least one cannabis-derived component. Cannabinoids (phytocannabinoids) are an example of a cannabis-derived component. Cannabinoids interact with receptors in the body to exert various effects. As a result, cannabinoids are used for a variety of medicinal purposes. The cannabis-derived material may include leaves and / or flower material from one or more cannabis plants, or extracts from one or more cannabis plants. In at least one exemplary embodiment, the one or more cannabis plants include Cannabis sativa, Cannabis indica, and Cannabis ruderalis. In some exemplary embodiments, the non-nicotine pre-vaporized formulation is 60-80% (e.g., 70%) Cannabis sativa and 20-40% (e.g., 30%) Cannabis indica, or includes a mixture of cannabis and / or cannabis-derived components therefrom.

[0031] Cannabinoids derived from cannabis include tetrahydrocannabinolic acid (THCA), tetrahydrocannabinol (THC), cannabidiol acid (CBDA), cannabidiol (CBD), cannabinol (CBN), cannabicyclol (CBL), cannabichromene (CBC), cannabigerol (CBG), etc. Tetrahydrocannabinolic acid (THCA) is the precursor of tetrahydrocannabinol (THC), while cannabidiol acid (CBDA) is the precursor of cannabidiol (CBD). Tetrahydrocannabinolic acid (THCA) and cannabidiol acid (CBDA) can be converted to tetrahydrocannabinol (THC) and cannabidiol (CBD), respectively, by heating. In at least one exemplary embodiment, the heat from heater 60 causes decarboxylation, converting tetrahydrocannabinolic acid (THCA) in the non-nicotine pre-vaporized formulation to tetrahydrocannabinol (THC) and / or cannabidiolic acid (CBDA) in the non-nicotine pre-vaporized formulation to cannabidiol (CBD).

[0032] In instances where both tetrahydrocannabinolic acid (THCA) and tetrahydrocannabinol (THC) are present in a non-nicotine pre-vaporized formulation, decarboxylation and the resulting conversion will result in a decrease in tetrahydrocannabinolic acid (THCA) and an increase in tetrahydrocannabinol (THC). At least 50% (e.g., at least 87%) of the tetrahydrocannabinolic acid (THCA) may be converted to tetrahydrocannabinol (THC) via a decarboxylation process during heating of the non-nicotine pre-vaporized formulation for vaporization. Similarly, in instances where both cannabidiolic acid (CBDA) and cannabidiol (CBD) are present in a non-nicotine pre-vaporized formulation, decarboxylation and the resulting conversion will result in a decrease in cannabidiolic acid (CBDA) and an increase in cannabidiol (CBD). At least 50% (e.g., at least 87%) of the cannabidiolic acid (CBDA) may be converted to cannabidiol (CBD) via a decarboxylation process during heating of the non-nicotine pre-vaporized formulation for vaporization.

[0033] 2, during vaping, a pre-vaporized formulation, etc., may be transported from the reservoir 2345 to the vicinity of the heater 2014 via capillary action in the wick 2028. The wick 2028 may include at least a first end and a second end, which may extend on opposite sides of the reservoir 2345. The heater 2014 may at least partially surround a central portion of the wick 2028 such that, when the heater 2014 is activated, the pre-vaporized formulation, etc., in the central portion of the wick 2028 may be vaporized by the heater 2014 to form a vapor.

[0034] In at least one exemplary embodiment, the heater 2014 may include a wire coil that at least partially surrounds the wick 2028. The wire may be a metal wire, and / or the heater coil may extend completely or partially along the length of the wick 2028. The heater coil may also extend completely or partially around the periphery of the wick 2028. In some exemplary embodiments, the heater coil 2014 may or may not be in contact with the wick 2028.

[0035] In at least one exemplary embodiment, the heater 2014 may heat the pre-vaporized formulation (or the like) in the wick 2028 by thermal conduction. Alternatively, heat from the heater 2014 may be conducted to the pre-vaporized formulation (or the like) by a thermal conduction element, or the heater 2014 may transfer heat to the incoming ambient air drawn through the e-vape device 2000 during vaping, resulting in heating of the pre-vaporized formulation (or the like) by convection.

[0036] It should be understood that instead of using a wick 2028, the heater 2014 may include a porous material incorporating a resistive heater formed of a material having an electrical resistance capable of generating heat quickly.

[0037] 2, the second portion 2072 of the e-vape device 2000 may include a puff sensor 2016 (e.g., a pressure sensor, a flow sensor, etc.) that is responsive to air drawn into the second portion 2072 through an air inlet port 2044a adjacent the free or tip end of the e-vape device 2000. The second portion 2072 may also include a power source 2001.

[0038] Additionally, the second portion 2072 of the e-vape device 2000 may include a control circuit 2045 and a battery monitoring unit (BMU) (not shown). In some exemplary embodiments, the second portion 2072 may also include an external device input / output interface (not shown) and / or a network interface (not shown). The input / output interface may be a USB interface (e.g., a USB mini-cable interface), a power cable, etc. The network interface may be a Bluetooth transmitter (e.g., Bluetooth and / or Bluetooth Low Energy (LE), etc.), an NFC transmitter, a ZigBee transmitter, a WiFi transmitter, a cellular network transmitter, etc.

[0039] The control circuitry 2045 may include a microprocessor, a non-transitory computer-readable storage medium, heater control circuitry, and / or charge control circuitry, etc., and may be connected to the puff sensor 2016 .

[0040] The control circuit 2045 performs the functions of the second section 2072 as well as the functions of the entire e-vape device 2000, such as controlling the heater, interfacing with an external charger, and monitoring the pressure within the e-vape device 2000 to determine if negative air pressure has been applied. Additionally, the control circuit 2045 may determine if positive pressure has been applied for a threshold time. In such an example, the control circuit 2045 may disable and / or place the e-vape device 2000 in a hibernation mode (reducing power consumption and / or preventing operation).

[0041] Control circuitry 2045 may be processing and / or control circuitry, hardware executing software, or any combination thereof. If control circuitry 2045 is hardware, such existing hardware may include one or more central processing units (CPUs), one or more microcontrollers, one or more arithmetic logic units (ALUs), digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), one or more systems on a chip (SoCs), one or more programmable logic units (PLUs), one or more microprocessors, computers, or any other device capable of responding to and executing instructions in a defined manner configured as a special purpose machine that performs the functions of control circuitry 2045.

[0042] When the control circuitry 2045 is at least one processor that executes software (e.g., computer-readable instructions), the control circuitry 2045 is configured as a special-purpose machine that executes software stored on a non-transitory computer-readable storage medium to perform the functions of the control circuitry 2045.

[0043] Upon completing the connection between the first portion 2070 and the second portion 2072, the power source 2001 may be electrically connectable to the heater 2014 in the first portion 2070 upon activation of the puff sensor 2016. Air is drawn into the first portion 2070 through one or more air inlets 2044, which may be located primarily along the housing or in the connector 2205.

[0044] Power source 2001 may include a battery disposed in e-vape device 2000. Power source 2001 may be a lithium-ion battery or variants thereof, such as a lithium-ion polymer battery. Alternatively, power source 2001 may be a nickel-metal hydride battery, a nickel-cadmium battery, a lithium-manganese battery, a lithium-cobalt battery, or a fuel cell, etc.

[0045] In at least one exemplary embodiment, the power source 2001 may be rechargeable and may include circuitry configured to allow the battery to be rechargeable by an external charging device. To recharge the e-vape device 2000, a USB mini charger or other suitable charger assembly may be used in conjunction with a charging interface (not shown).

[0046] In at least one exemplary embodiment, the first portion 2070 may be replaceable. In other words, once the cartridge's pre-vaporized formulation or other contents are depleted, only the first portion 2070 may be replaced. Alternative arrangements may include exemplary embodiments in which the entire e-vape device 2000 may be discarded once the reservoir 2345 is depleted. Furthermore, according to at least one exemplary embodiment, the first portion 2070 may be configured to be refillable with the contents of the cartridge.

[0047] While FIGS. 1-2 depict exemplary embodiments of a reduced-risk or reduced-harm device, the exemplary embodiments are not limited thereto and may include additional and / or alternative reduced-risk or reduced-harm devices, such as non-heated inhalable devices or non-nicotine versions of reduced-risk or reduced-harm devices. Furthermore, the hardware configuration of the reduced-risk device is not limited to any single embodiment, and other hardware configurations that may be suitable for the demonstrated purpose may likewise be used. For example, a reduced-risk device may include multiple additional or alternative components and / or additional or alternative functions, such as the additional components and / or functions discussed in connection with FIGS. 3-4B , etc., as well as additional or alternative heating elements, reservoirs, batteries, etc. Furthermore, while FIGS. 1-2 depict exemplary embodiments of a reduced-risk device as embodied in two separate housing elements, additional exemplary embodiments may be directed to reduced-risk devices disposed in a single housing and / or more than two housing elements.

[0048] For example, a non-nicotine type of reduced-risk or reduced-harm device may generate a dispersion (e.g., an aerosol, vapor, etc.) from a non-nicotine pre-dispersed formulation (e.g., an aerosol-generating substrate, a pre-vaporized formulation, etc.) that includes a non-nicotine compound. In an exemplary embodiment, the non-nicotine pre-dispersed formulation does not include or is not derived from tobacco. The non-nicotine compound of the non-nicotine pre-vaporized formulation may be part of or contained in a liquid or partial liquid, including an extract, oil, alcohol, tincture, suspension, dispersion, colloid, general non-neutral (weakly acidic or weakly basic) solution, or a combination thereof. During preparation of the non-nicotine pre-dispersed formulation, the non-nicotine compound may be injected, mixed, or otherwise combined with other ingredients of the non-nicotine pre-dispersed formulation.

[0049] FIG. 3 is a block diagram illustrating various components of an identification system including a risk-reduced (and / or harm-reduced) device, a personal computing device, and an identification server in accordance with at least one exemplary embodiment.

[0050] Referring to FIG. 3 , according to at least one exemplary embodiment, an identity verification system may include at least one reduced-risk device 310 (e.g., a heated non-combustion aerosol generating device, a non-heated inhalable device, an e-vape device, etc.), at least one personal computing device 320 associated with one or more adult consumers, and / or an identity verification server 330, etc. However, exemplary embodiments are not limited in this respect, and a greater or lesser number of separate components within the system and / or other additional components may be included in identity verification systems according to other exemplary embodiments. According to some exemplary embodiments, reduced-risk device 310 may be a reduced-nicotine risk device or a non-nicotine reduced-risk device, etc. Furthermore, in some exemplary embodiments, the identity verification system may include a third-party identity verification service 340 and / or a point-of-sale (POS) terminal 350, a wireless beacon transmitter 360, etc.

[0051] According to some exemplary embodiments, personal computing device 320 may be, but is not limited to, a smartphone, a mobile phone, a tablet, a laptop, a personal computer (PC), a personal digital assistant (PDA), a wearable device, a virtual reality (VR) and / or augmented reality (AR) device, an Internet of Things (IoT) device, a voice assistant device, etc. Personal computing device 320 may be associated with an adult consumer who intends to operate reduced-risk device 310 and / or operate reduced-risk device 310 with new and / or replacement components (not shown) for reduced-risk device 310. New and / or replacement components may include new and / or replacement distribution products (e.g., cartridges, capsules, heat sticks, etc.) for reduced-risk device 310, a power supply for reduced-risk device 310, etc.

[0052] Personal computing device 320 may operate an identity verification software application (e.g., an identity verification app, a risk-reduced device application, etc.) to receive information related to risk-reduced device 310 and / or components of the risk-reduced device, input identity verification information related to the adult consumer's identity, receive identity verification results from identity verification server 330, and / or transmit cryptographic keys to risk-reduced device 310 to enable operation of risk-reduced device 310 and / or separate components of the risk-reduced device, although example embodiments are not limited thereto. According to some example embodiments, personal computing device 320 may manually and / or automatically lock and unlock risk-reduced device 310 based on input received from the adult consumer through an identity verification software application (e.g., an app) installed on personal computing device 320 and / or based on the termination of a communication session between risk-reduced device 310 and personal computing device 320.

[0053] Additionally, personal computing device 320 may be a device operated by a retailer and / or business to facilitate verification of an adult consumer during the purchase of a reduced-risk device and / or components of a reduced-risk device. For example, a retailer and / or business may use point-of-sale terminal 350, an age / identification verification kiosk (e.g., a standalone kiosk), and / or other dedicated devices to verify the identity of an adult consumer and / or enable operation of reduced-risk device 310 and / or components of a reduced-risk device.

[0054] The risk-reduced device 310 and / or components of the risk-reduced device 310 may initially be in a "locked" state (e.g., an age / identity lock state may be activated, a disabled state, etc.) that renders the risk-reduced device 310 and / or components of the risk-reduced device inoperable until the risk-reduced device 310 and / or components of the risk-reduced device enter an "unlocked" state (e.g., an age / identity lock state may be deactivated, an enabled state, etc.). For example, prior to legal sale of the risk-reduced device 310 from a retailer and / or business, the risk-reduced device 310 may be in an initial locked or disabled state, and the control circuitry (e.g., controller, processor, etc.) of the risk-reduced device 310 may disable vapor generation using the risk-reduced device 310 and / or disable operation of the power source of the risk-reduced device 310, etc., by setting a lock state flag (e.g., locked, age / identity locked, disabled, etc.) in the lock control routine 523 of the memory 520.

[0055] The risk-reduced device 310 and / or components of the risk-reduced device may be placed in a locked or disabled state at the time of manufacture (e.g., when an age / identity lock flag is set in memory), although example embodiments are not limited thereto. For example, the risk-reduced device 310 may be temporarily unlocked or enabled through successful age and / or identity verification of an adult consumer, and after a desired period of time (or other criteria) has occurred, the risk-reduced device 310 may re-enter the locked or disabled state (e.g., by setting an age / identity lock flag).

[0056] Additionally, when negative air pressure (e.g., a puff) is detected at the mouthpiece of the risk-reduced device 310 by the puff sensor 595, the control circuitry 510 of the risk-reduced device 310 may, in response to the detected negative air pressure, determine whether the risk-reduced device 310 is in a "locked" state (e.g., whether an age / identity lock status flag, setting, etc. is set) to determine whether to enable operation of the heater 540. If the risk-reduced device is in a locked state (e.g., the lock flag is set), the control circuitry 510 does not allow (e.g., prevents, inhibits, disables, etc.) the power source 530 to energize the heater 540. If the lock flag is not set, the control circuitry 510 allows (e.g., enables, allows, etc.) the power source 530 to energize the heater 540.

[0057] The risk-reduced device 310 and / or components of the risk-reduced device may include a unique identifier (UID) for the risk-reduced device 310 and / or separate components of the risk-reduced device that uniquely identifies the item. For example, the UID of the risk-reduced device 310 may be used during the identity verification process for separate purchases of the risk-reduced device 310, and the UID may also be used to associate the risk-reduced device 310 with an individual's account on a database for verification purposes, such as the verification history of a particular risk-reduced device and / or component of the risk-reduced device (collectively referred to hereinafter as the risk-reduced device). An individual UID corresponding to an adult consumer may also be associated with an individual's account.

[0058] The personal computing device 320 may be used to acquire and / or receive the UID of the risk-reduced device 310 and / or the UIDs of separate components of the risk-reduced device. For example, a camera included in the personal computing device 320 may be used to acquire an image of the UID of the risk-reduced device 310, a sensor included in the personal computing device 320 (e.g., an RFID sensor, an NFC sensor, an IR reader, etc.) may be used to sense / detect / read the UID of the risk-reduced device 310, and / or a separate operation of the personal computing device 320 may manually enter the UID of the risk-reduced device 310 into verification software operating on the personal computing device 320. Furthermore, according to some exemplary embodiments, the personal computing device 320 may establish a wired and / or wireless communication connection (e.g., communication via a USB connection, a WiFi connection, a Bluetooth connection, an NFC connection, etc.) with the risk-reduced device 310 and may receive the UID of the risk-reduced device 310 and / or the UIDs of the components of the risk-reduced device via the communication connection, etc.

[0059] Additionally, when a connection is established between the personal computing device 320 and the risk-reduced device 310, the personal computing device 320 may store location information associated with the personal computing device 320 and / or the risk-reduced device 310 upon connection establishment and / or disconnection. The location information may be obtained from a GPS sensor 590 (and / or other location sensors) included in the risk-reduced device 310, a GPS sensor 460 (and / or other location sensors) included in the personal computing device 320, and / or may be determined based on other information associated with the risk-reduced device 310 and / or the personal computing device 320, such as a location lookup based on the IP address of the personal computing device 320, a WiFi fingerprint analysis of WiFi signals detected by the personal computing device 320, cellular triangulation of the personal computing device 320, etc. Once the location information is obtained, it may be stored in the RRD profile information 425 in the memory 420 of the personal computing device 320. Additionally, the location information for risk-reduced device 310 and / or personal computing device 320 may be periodically refreshed while risk-reduced device 310 is connected to personal computing device 320, such as using GPS sensor 590, GPS sensor 460, etc. Additionally, according to some exemplary embodiments, the location information may be transmitted to identity verification server 330 and stored in association with the adult consumer's profile in verification information database 623. The location information may be used to determine the last known location of risk-reduced device 310, such as in the event that the adult consumer loses and / or misplaces risk-reduced device 310.

[0060] Additionally, the adult consumer may use the risk-reduced device software to enable a "find-my-device" type feature, and the adult consumer may use the risk-reduced device software to determine the last known location of the risk-reduced device. According to at least one exemplary embodiment, the adult consumer may interact with the risk-reduced device software (e.g., pressing a GUI button to initiate the "find-my-device" feature) to send a device find command (e.g., a message, a display, etc.) to the risk-reduced device 310 via a wireless connection (e.g., a Bluetooth connection, an NFC connection, a WiFi connection, etc.) and / or a wired connection. If the risk-reduced device 310 is connected to the personal computing device 320 via a wireless connection and / or a wired connection, the risk-reduced device 310 may receive the sent device find command. Additionally, the risk-reduced device 310 may transmit a confirmation message in response to the transmitted device discovery command, which may cause the personal computing device 320 to start a timer, countdown, etc. and / or display a timer, countdown, etc. on the risk-reduced device software GUI to indicate the length of time the device discovery operation was valid (and / or the time remaining in the desired time window for the device discovery operation). If the timer expires before the adult consumer finds the risk-reduced device 310, the adult consumer may use the risk-reduced device software GUI to re-initiate the device discovery operation.

[0061] Upon receiving the device discovery command, if the risk-reduced device 310 is in a low power mode (and / or sleep mode, off state, etc.), the risk-reduced device 310 enters a normal power mode (and / or on mode, performance mode, wake state, etc.) in response to the received device discovery command. If the risk-reduced device 310 is already in a normal power mode or if the risk-reduced device 310 enters a normal power mode in response to the received device discovery command, the risk-reduced device 310 displays and / or emits at least one responsive indication in response to the received device discovery command. For example, the responsive indication may be flashing an LED light on the risk-reduced device 310, displaying a message on the risk-reduced device 310, emitting a sound from a speaker of the risk-reduced device 310, haptic feedback (e.g., vibration, etc.) generated by the risk-reduced device 310, etc. to draw the adult consumer's attention to the current location of the risk-reduced device 310. However, example embodiments are not so limited, and the response instructions may be any equivalent instructions executable by risk-reduced device 310 .

[0062] According to some exemplary embodiments, the responsive prompts may be generated at a level that increases the likelihood that an adult consumer will discover the risk-reduced device 310, such as by displaying an LED light at maximum brightness, emitting a sound through a speaker at maximum volume, and / or generating haptic feedback at maximum vibration level. Furthermore, the responsive prompts may be a combination of prompts (e.g., a flashing LED light and an emitted sound, etc.) and / or may be generated based on a desired pattern (e.g., a light pattern, a sound pattern, and / or a haptic feedback pattern, etc.), and the responsive prompts may be repeated in a desired number of sequences and / or for a desired period of time, etc. The risk-reduced device 310 may generate the responsive prompts for a desired period of time (e.g., 750 ms, etc.) before returning to a previous state (e.g., the state the risk-reduced device 310 was in before receiving the prompt from the personal computing device 320).

[0063] Once the adult consumer discovers the reduced-risk device 310, the adult consumer may cancel the generation of the response prompt on the reduced-risk device 310 by interacting with the reduced-risk device 310, for example, by interacting with an I / O device on the reduced-risk device 310, by interacting with a UI button on the reduced-risk device 310, by interacting with a puff sensor on the reduced-risk device 310, etc. The cancellation of the response prompt on the reduced-risk device 310 may initiate the transmission of a cancellation message over the connection to the personal computing device 320 indicating that the adult consumer has located the reduced-risk device 310 and / or canceled the device discovery operation. The personal computing device 320 may display a status indication on the GUI of the reduced-risk device software based on the received cancellation message.

[0064] Additionally, the adult consumer may cancel the "discover device" operation using the personal computing device 320 via the reduced risk device software GUI. For example, the reduced risk device software GUI may display a UI element that causes the personal computing device 320 to initiate cancellation of the "discover device" operation by sending a cancel instruction to the reduced risk device 310. Upon receiving the cancel instruction, the reduced risk device 310 may cancel (e.g., stop) generating response instructions and return the reduced risk device to its previous state.

[0065] According to at least one exemplary embodiment, when the risk-reduced device 310 is not connected to the personal computing device 320, the personal computing device 320 may display stored location information (e.g., last known location information) on the risk-reduced device software GUI corresponding to the last location at which the risk-reduced device 310 connected to the personal computing device 320 and / or the last location at which the connection between the risk-reduced device 310 and the personal computing device 320 was terminated, thereby indicating the last known location of the risk-reduced device 310. Additionally, according to some exemplary embodiments, the risk-reduced device software GUI may display a map with a location indication (e.g., a marker, an avatar associated with the risk-reduced device, etc.) corresponding to the last known location of the risk-reduced device 310, as well as the stored location information. Additionally, the risk-reduced device software GUI may display additional information associated with the location information that is useful to adult consumers, such as a mailing address associated with the location information, a business name associated with the location information, a phone number associated with the location information, a photo associated with the location information, etc. Additionally, the GUI of the risk-reduced device software may display the last known location information, a map view corresponding to the last known location information, and / or additional information associated with the location information, even if the risk-reduced device 310 and the personal computing device 320 have an established connection as described above.

[0066] According to some exemplary embodiments, the adult consumer may use the risk-reduced device software to initiate an identification request to unlock the risk-reduced device 310 from the personal computing device 320 and may enter the adult consumer's identification information into the personal computing device 320 via the risk-reduced device software GUI. The personal computing device 320 may transmit the identification information to the identification server 330 to verify the adult consumer's age and / or identity, as well as other information related to the identification request, such as location information corresponding to the location of the personal computing device 320 and / or the risk-reduced device 310, etc., date information corresponding to the date of the identification request, time information corresponding to the time of the identification request, etc. The personal computing device 320 may communicate with the identification server via wired and / or wireless networks, such as the Internet, an intranet, a wide area network, a local area network, a personal area network, a cellular data network, etc., although exemplary embodiments are not limited thereto.

[0067] The identifying information may be, but is not limited to, personal information related to the adult consumer's identity, such as the adult consumer's name, date of birth, current address, past addresses, telephone number, place of birth, Social Security number, names of relatives, etc.; account information related to the adult consumer, such as a username and password; biometric information of the adult consumer, such as the adult consumer's fingerprint information, retinal information, voice information, facial feature information, heart rate information, etc.; social networking service (SNS) information; instant messaging service account information; etc. The identifying information may also include other information that can specifically identify the adult consumer, such as an individual's employment history, educational history, banking history, places where the individual has lived, names of relatives, etc. However, the exemplary embodiments are not limited to this, and other identifying information unique to the adult consumer may be used.

[0068] Additionally, according to some exemplary embodiments, the identity verification server may transmit identity verification challenge questions to the personal computing device 320 that require the adult consumer to successfully answer questions specific to verifying the adult consumer. For example, the identity verification challenge questions may include questions related to the adult consumer's mother's maiden name, place of birth, the individual's work history, educational history, banking history, where the individual has lived, names of relatives, etc. The identity verification challenge questions may be questions to which the adult consumer has previously created and / or submitted answers, or may be questions and answers collected by a third-party and / or external identity verification service 340 based on available public records regarding the adult consumer. Additionally, the identity verification challenge questions may be a request for the adult consumer to provide biometric information (e.g., fingerprint, facial scan, retinal scan, voice identification, etc.) that matches the adult consumer's previously provided biometric information. However, exemplary embodiments are not limited in this regard, and the identity verification challenge questions may take other equivalent forms that provide accurate verification of a person's identity.

[0069] According to some exemplary embodiments, the identity verification server 330 may optionally connect over a network to a third-party identity verification service 340, request identity challenge questions and / or answers corresponding to the adult consumer from the third-party identity verification service 340, and transmit the identity challenge questions to the adult consumer's personal computing device 320. Once the adult consumer provides answers to the identity challenge questions, the personal computing device 320 may transmit the answers to the identity verification server 330, which may determine whether the answers entered by the adult consumer are correct based on the answers received from the third-party identity verification service 340 and / or transmit the answers entered by the adult consumer to the third-party identity verification service 340 for verification.

[0070] Once the response is verified by the identity verification server 330 and / or the third-party identity verification service 340, a verification result is sent by the identity verification server 330 to the personal computing device 320. The personal computing device 320 may determine whether the verification result indicates that the adult consumer's identity has been properly verified by the identity verification server 330 (and / or the third-party identity verification service 340) and that the adult consumer is legally authorized to operate the risk-reduced device 310. Based on the verification result, the personal computing device 320 may generate a cryptographic key to unlock the risk-reduced device 310 (and / or any locked components of the risk-reduced device). For example, the cryptographic key may be generated based on a public key (of a public-private key pair) stored on the personal computing device 320 (e.g., a public cryptographic key associated with the risk-reduced device 310, a public key associated with the adult consumer, and / or other public keys), the UID of the risk-reduced device 310, the adult consumer's personal UID, and / or the verification result, etc. However, the exemplary embodiment is not so limited, and the encryption key may be generated based on other information as well.

[0071] According to some exemplary embodiments, the identity verification server 330 may generate an encryption key for unlocking the risk-reduced device 310 based on the verification results. The identity verification server 330 may generate the encryption key based on public keys stored on the identity verification server 330 (such as the public key associated with the risk-reduced device 310, the public key associated with the adult consumer, and / or other public keys), the UID of the risk-reduced device 310, the adult consumer's personal UID, and / or the verification results. However, exemplary embodiments are not limited in this respect, and the encryption key may similarly be generated based on other information. For example, the public key may be the UID of the risk-reduced device 310, etc. The identity verification server 330 may then transmit the encryption key to the personal computing device 320.

[0072] Once the personal computing device 320 generates and / or receives the encryption key, the personal computing device 320 may transmit the encryption key to the risk-reduced device 310. The risk-reduced device 310 may decrypt the encryption key using a private key corresponding to the public key used to encrypt the encryption key. For example, the private key may be a key stored on the risk-reduced device 310 corresponding to the UID of the risk-reduced device 310, etc. The risk-reduced device 310 may then determine, based on the verification result included in the encryption key, whether the adult consumer has been properly verified and / or is legally authorized to operate the locked risk-reduced device 310 and / or locked components of the risk-reduced device. If the verification result indicates that the adult consumer has been properly verified, the risk-reduced device 310 may unlock the risk-reduced device 310 and / or locked components of the risk-reduced device 310 (e.g., enabling operation of the risk-reduced device 310, the distributed product, the risk-reduced device's power source, etc.). A locked risk-reduced device 310 and / or locked components of a risk-reduced device may be unlocked for an indeterminate period of time (e.g., permanently unlocked), may be unlocked for a desired period of time (e.g., temporarily unlocked for 15 minutes, 30 minutes, etc.), and / or may be unlocked while a desired unlocking condition is met.

[0073] For example, the unlocked state of the risk-reduced device 310 may be further conditioned based on whether the risk-reduced device 310 is within a desired distance of the personal computing device 320. The risk-reduced device 310 may determine whether the risk-reduced device 310 is within a desired distance of the personal computing device 320 based on a wireless connection established with the personal computing device 320 and / or wireless messages transmitted between the risk-reduced device 310 and the personal computing device 320, and if the wireless connection and / or wireless messages are disconnected, discontinued, stopped, etc., the risk-reduced device 310 may relock itself (e.g., block operation of the risk-reduced device) and / or relock previously locked components of the risk-reduced device. As another example, the risk-reduced device 310 and / or components of the risk-reduced device may remain unlocked until a condition associated with the risk-reduced device itself expires, such as the expiration of a full power charge for the risk-reduced device, or until a distributed product item (e.g., cartridge, capsule, heat stick, etc.) installed in the risk-reduced device is emptied and / or replaced. However, the example embodiments are not so limited.

[0074] According to some exemplary embodiments, risk-reduced device 310 may be unlocked using a POS terminal 350 (e.g., a kiosk, etc.) located at the location (e.g., a store, etc.) where risk-reduced device 310 and / or components of the risk-reduced device are purchased. For example, POS terminal 350 may be a cash register, computer, tablet, computing terminal, and / or dedicated standalone kiosk, etc., configured to allow an adult consumer to undergo an identity verification process with identity verification server 330 and unlock risk-reduced device 310 without using personal computing device 320. For example, the adult consumer may input personal information into POS terminal 350 (e.g., via a touchscreen, keyboard and mouse, microphone, paper scanner, etc.), and once identity verification server 330 verifies the adult consumer's identity and / or legal ability to purchase and operate risk-reduced device 310, identity verification server 330 transmits the verification results and / or a cryptographic key to POS terminal 350. POS terminal 350 may transmit the encryption key to risk-reduced equipment 310 via wireless and / or wired communication channels when risk-reduced device 310 is removed from its packaging.

[0075] Alternatively, the POS terminal 350 may unlock the risk-reduced device 310 by emitting a pressurized burst of air at a desired air pressure and / or frequency to a puff sensor in the risk-reduced device 310, which, when received by the risk-reduced device 310, unlocks the risk-reduced device 310. Additionally, the POS terminal 350 may emit a code tone via a speaker, which is received by the microphone in the risk-reduced device 310 and causes the risk-reduced device 310 to unlock.

[0076] Additionally, when puff sensor 595 detects negative air pressure (e.g., a puff) at the mouthpiece of risk-reduced device 310, control circuitry 510 of risk-reduced device 310 may determine whether a manual lock flag is set to determine whether to enable operation of heater 540. If the manual lock flag is set (e.g., when risk-reduced device 310 is in a locked state), control circuitry 510 does not allow (e.g., prohibit, disable, etc.) power source 530 to energize heater 540. If the manual lock flag is not set, control circuitry 510 allows (e.g., enable, allow, etc.) power source 530 to energize heater 540.

[0077] The adult consumer also operates software installed on personal computing device 320, such as risk-reduced device software and / or apps corresponding to the risk-reduced device, which allows the adult consumer to input manual lock commands (e.g., tapping, dragging, gesturing, other touchscreen operations, typing, etc.) into a graphical user interface (GUI) of the risk-reduced device software. In response to the adult consumer inputting the manual lock command into the risk-reduced device software GUI, personal computing device 320 transmits a manual lock indication to risk-reduced device 310. When risk-reduced device 310 receives a manual lock command (e.g., a disable command, etc.) from personal computing device 320, risk-reduced device 310 sets a manual lock flag (e.g., a lock flag, a disable flag, a manual disable setting, etc.) in lock control routine 523 of memory 520. When puff sensor 595 detects negative air pressure (e.g., a puff) at the mouthpiece of risk-reduced device 310, control circuitry 510 of risk-reduced device 310 may determine whether a manual lock flag is set to determine whether to enable operation of heater 540. If the manual lock flag is set (e.g., when risk-reduced device 310 is in a locked state), control circuitry 510 does not allow (e.g., prohibit, disable, etc.) power source 530 to energize heater 540. If the manual lock flag is not set, control circuitry 510 allows (e.g., enable, allow, etc.) power source 530 to energize heater 540.

[0078] Additionally, the manual lock command sent by the personal computing device 320 may include a unique serial number associated with the personal computing device 320 and / or the risk-reduced device software installed on the personal computing device 320, an IP address and / or a MAC address associated with the personal computing device 320, a UID corresponding to the personal computing device 320, such as a UID associated with the adult consumer, a UID associated with the risk-reduced device software installed on the personal computing device, etc., and / or a connection session ID corresponding to a communication session established between the personal computing device 320 and the risk-reduced device 310, which may be stored in the lock control routine 523. The UID corresponding to the personal computing device 320 may be used to determine whether the manual lock should be toggled off (e.g., change the locked state of the risk-reduced device to an unlocked state) based on receipt of a second manual lock command (and / or a manual unlock command, etc.) from the personal computing device 320. For example, as a security feature, the personal computing device UID included in a first manual locking instruction (e.g., a locking instruction) may be compared to the personal computing device UID included in a second manual locking instruction (e.g., an unlocking instruction) to determine whether the personal computing device UIDs for the first and second manual locking instructions match before unlocking the risk-reduced device 310 based on the second manual locking instruction (e.g., an unlocking instruction). By verifying that the personal computing device UIDs for the first and second manual locking instructions match before unlocking a previously manually locked risk-reduced device, the security of the risk-reduced device may be increased by reducing and / or preventing the ability of a non-adult consumer to use the second personal computing device to unlock a manually locked risk-reduced device.

[0079] Additionally, the risk-reduced device 310 may include a “proximity lock” feature (e.g., a personal computing device proximity lock feature), where a risk-reduced device 310 in an unlocked state may be automatically placed in a locked state in response to the risk-reduced device 310 being disconnected from its paired personal computing device 320. For example, when an adult consumer enables a proximity lock setting in the risk-reduced device software installed on the personal computing device 320 (e.g., enters a proximity lock command into the risk-reduced device software GUI), and the personal computing device 320 is paired with the risk-reduced device 310 via a wireless and / or wired connection, such as a Bluetooth connection, a near field communication (NFC) connection, a WiFi connection, a USB connection, etc., the risk-reduced device software sends a proximity lock command (e.g., a command, a message, a flag, a configuration file, etc.) to the risk-reduced device 310 to transition it to the proximity lock state. The proximity lock command may include a UID corresponding to personal computing device 320, such as a unique serial number associated with personal computing device 320 and / or risk-reduced device software installed on personal computing device 320, an IP address and / or MAC address associated with personal computing device 320, a UID associated with the adult consumer, a UID associated with the risk-reduced device software installed on the personal computing device, a connection session ID associated with a communication session established between personal computing device 320 and risk-reduced device 310, etc. When risk-reduced device 310 receives the proximity lock command, risk-reduced device 310 enters a "proximity lock" state (e.g., a proximity lock flag is set in lock control routine 523 of memory 520). Now, risk-reduced device 310 may be operated by the adult consumer only if risk-reduced device 310 connection with personal computing device 320 is maintained.

[0080] Thus, similar to a manual lock setting, when puff sensor 595 detects negative air pressure (e.g., a puff) at the mouthpiece of risk-reduced device 310, control circuitry 510 of risk-reduced device 310 may determine whether a proximity lock flag is set to determine whether operation of heater 540 may be enabled in response to the detected negative air pressure. If the proximity lock flag is set (e.g., risk-reduced device 310 is in a locked state), control circuitry 510 determines whether risk-reduced device 310 is connected to the same personal computing device that set the proximity lock (e.g., personal computing device 320 that sent the initial proximity lock command) based on the personal computing device UID included in the initial proximity lock command and the subsequent proximity lock command. In response to a mismatch in the personal computing device UIDs, control circuitry 510 does not allow power source 530 to energize heater 540 (e.g., inhibits, disables, etc.). In response to a matching personal computing device UID, control circuitry 510 allows (eg, enables, authorizes, etc.) power supply 530 to energize heater 540 .

[0081] According to some exemplary embodiments, the identity verification system may include a "beacon proximity lock" feature, whereby an unlocked risk-reduced device 310 may be automatically placed in a locked state in response to the risk-reduced device 310 receiving a wireless lock signal from a wireless beacon transmitter 360. The wireless beacon transmitter 360 may be a Bluetooth beacon transmitter, a WiFi beacon transmitter, an NFC transmitter, or the like, but exemplary embodiments are not limited thereto. The wireless beacon transmitter 360 may be installed in locations and / or vehicles that prohibit and / or restrict the operation of risk-reduced devices, such as schools, places of worship, youth facilities, government facilities, designated non-smoking areas, airports, airplanes, trains, mass transit vehicles, and the like, and may transmit a wireless lock signal to risk-reduced devices in the vicinity of the restricted location. When the risk-reduced device 310 receives the wireless lock signal, the control circuitry 510 of the risk-reduced device 310 places the risk-reduced device 310 in a "beacon proximity lock" state (e.g., a beacon proximity lock flag is set in the lock control routine 523 of the memory 520). The risk-reduced device 310 then does not allow operation of the risk-reduced device 310 until the risk-reduced device 310 is out of range of the wireless beacon transmitter 360 (e.g., until the risk-reduced device 310 no longer receives a wireless lock signal from the wireless beacon transmitter 360). The wireless beacon transmitter 360 may periodically transmit a wireless lock signal, where the wireless lock signal includes information indicating the amount of time the risk-reduced device 310 should remain in the locked state before determining whether an additional wireless lock signal has been received from the wireless beacon transmitter 360. In other words, when the risk-reduced device 310 receives a wireless lock signal from the wireless beacon transmitter 360, the risk-reduced device 310 may extract a lockdown period (e.g., 30 seconds, 5 minutes, 15 minutes, etc.) from the wireless lock signal and begin a countdown from the time the wireless lock signal is received before the adult consumer attempts to unlock the risk-reduced device 310. If another wireless lock signal is received by the risk-reduced device 310 before the lockdown period expires, the lockdown period is reset and the countdown begins again.

[0082] Additionally, according to at least one exemplary embodiment, the identification service may evaluate the identification request to determine whether the identification request is suspicious and / or potentially fraudulent based on location information included in the identification request and information stored in the adult consumer's profile. For example, previously stored location information of the risk-reduced device 310 and / or personal computing device 320 may be included in the identification request to identify suspicious identification activity and / or prohibited risk-reduced device operation based on geographic location. Referring back to the identification method, location information of the risk-reduced device 310 and / or personal computing device 320 may be associated with each identification request and transmitted to the identification server 330 to determine the adult consumer's location at the time of the identification request. one or more consecutive failed identification attempts; a total number of failed identification attempts in a given time period that exceeds a predetermined threshold; an identification attempt that is determined to deviate from the characteristics of an adult consumer based on the temporal and / or spatial characteristics of the identification attempt (e.g., if the identification attempt occurs in a geographic location not associated with adult consumers; if the identification attempt occurs at a time that deviates from the characteristics of an adult consumer; if the identification attempt occurs in a location previously identified as being suspicious, prohibited, and / or associated with a high probability of false identification attempts, such as a location likely to contain only minors (e.g., a school), or a retail store suspected of illegally selling reduced-risk devices to minors). If suspicious identification activity is detected, such as an identification attempt occurring using a personal computing device not associated with the adult consumer (e.g., a previously unregistered personal computing device), each identification request may be analyzed for suspicious activity by comparing characteristics of the identification request (e.g., information such as time, date, location, success / failure of the request, etc.) with data stored in the identification server 330 related to the adult consumer's previous identification requests (e.g., historical identification data) to determine whether the identification request is suspicious and / or should be flagged as suspicious.Additionally, characteristics of each identification request may be compared to general identification data, such as known and / or suspicious store locations that sell reduced-risk devices to minors, known locations of schools and juvenile facilities, known locations where reduced-risk device activity is prohibited, etc., to determine whether the identification request is suspicious and / or should be flagged as suspicious. However, example embodiments are not limited in this regard, and other characteristics may be analyzed to detect suspicious identification activity.

[0083] If an identification request is determined to be suspicious, a suspicious identification activity notification may be sent to known contacts previously registered by the adult consumer with the identification service, such as the adult consumer's phone number, email address, mailing address, social networking service (SNS) account, instant messaging service account, risk-reduced device software installed on the personal computing device 320 associated with the adult consumer, etc., corresponding to the suspicious identification request (e.g., the identity entered in the identification request). For example, the adult consumer's contact information may be stored in profile information associated with the adult consumer in the identification information database 623 of the identification server 330. The suspicious identification notification may include the adult consumer's name entered in the identification request and / or details regarding the identity, such as the date, time, location, etc. of the request.

[0084] The suspicious identification notification may include a request from the adult consumer to confirm that the adult consumer initiated the suspicious identification request. For example, the suspicious identification notification may include a URL link where the adult consumer engages to confirm / deny the suspicious identification request, may include a phone number where the adult consumer can call and / or send an SMS message to confirm the suspicious identification request, may include an instant messaging account for sending a response regarding the suspicious identification request, and / or the adult consumer can respond to the suspicious identification request using messaging functionality of the risk-reduced device software, etc., example embodiments are not limited thereto.

[0085] If the adult consumer responds to the suspicious identification notification, indicating that the adult consumer initiated the identification request (e.g., the identification request is not fraudulent), the identification server 330 may redesignate the corresponding identification request as not suspicious in the verification information database 623, and the identification server 330 may transmit the identification result to the risk mitigation device 310 as described above. If the adult consumer responds to the suspicious identification notification and confirms that the suspicious identification request is fraudulent (and / or the adult consumer does not respond to the suspicious identification notification within a predetermined period of time), the identification server 330 may transmit the identification request result indicating that the identification request has been confirmed as suspicious and / or fraudulent to the personal computing device 320, and the personal computing device 320 may treat the confirmed suspicious and / or fraudulent result as the equivalent of a failed identification attempt. The identity verification server 330 may also include a permanent lock indication in the identity verification results based on the number of failed and / or confirmed suspicious identity verification requests received from the adult consumer and / or personal computing device 320, and the risk-reduced device software of the personal computing device 320 may place the risk-reduced device 310 and / or components of the risk-reduced device in a permanent lock state (e.g., permanent age / identity lock state), where the risk-reduced device 310 and / or components of the risk-reduced device 310 may not need to be unlocked using the identity verification system.

[0086] Additionally, if the identity verification server 330 determines that the number of failed and / or confirmed suspicious identity verification requests has reached a predetermined threshold, the notification may transmit relevant information regarding the failed and / or confirmed suspicious identity verification requests to law enforcement agencies, such as information related to the adult consumer identity used in the identity verification request, the location of the identity verification request, the date / time of the identity verification request, etc., to enable law enforcement agencies associated with the location of the failed and / or confirmed suspicious identity verification requests to investigate the failed and / or confirmed suspicious identity verification requests, such as investigating retail stores to determine whether the retail stores are illegally selling risk-reduced devices to minors, etc. Additionally, if the adult consumer indicates that a particular suspicious identity verification request is suspicious and / or fraudulent, the adult consumer may select in the GUI of the risk-reduced device software to similarly forward relevant information regarding the confirmed suspicious identity verification requests to law enforcement agencies.

[0087] FIG. 4A is a block diagram illustrating various components of a personal computing device for an identity verification system in accordance with at least one exemplary embodiment.

[0088] According to at least one example embodiment, a personal computing device, such as personal computing device 320 of Figure 3, may include at least one processor 410, a communication bus 415, and / or memory 420. Memory 420 may include computer-readable instructions (and / or software code, etc.) corresponding to an operating system (OS) 421 for operating the personal computing device, as well as dedicated computer-readable instructions related to risk-reduced device locking / unlocking and / or identity verification processes, such as risk-reduced device (RRD) software 422, identity / age verification routines 423, cryptographic key generator 424, risk-reduced device (RRD) profile 425, and / or adult consumer profile 426, etc. However, exemplary embodiments are not limited thereto, and according to some exemplary embodiments, one or more of the operating system (OS) 421, risk reduced device (RRD) software 422, identity / age verification routine 423, encryption key generator 424, risk reduced device (RRD) profile 425, and / or adult consumer profile 426 may be combined into one or more of the routines, for example, RRD software 422 may include identity / age verification routine 423, encryption key generator 424, risk reduced device (RRD) profile 425, and / or adult consumer profile 426, etc.

[0089] In at least one exemplary embodiment, processor 410 may be at least one processor (and / or processor core, distributed processor, networked processor, etc.) that may be configured to control one or more components of personal computing device 320. Processor 410 is configured to execute the control and functionality of personal computing device 320 by retrieving and processing program code (e.g., computer-readable instructions) and data from memory 420. When program instructions are loaded into processor 410, processor 410 executes the program instructions, transforming processor 410 into a special-purpose processor. For example, when processor 410 loads special purpose instructions associated with risk reduced device (RRD) software 422, identity / age verification routine 423, cryptographic key generator 424, RRD profile 425, and / or adult consumer profile 426, processor 410 is transformed into a special purpose processor that executes routines of RRD software 422, identity / age verification routine 423, cryptographic key generator 424, risk reduced device RRD profile 425, and / or adult consumer profile 426, etc.

[0090] In at least one exemplary embodiment, memory 420 may be a non-transitory computer-readable storage medium and may include random access memory (RAM), read-only memory (ROM), and / or permanent mass storage such as a disk drive, solid-state storage drive, etc. Memory 420 stores computer-readable instructions (e.g., program code) for risk-reduced device (RRD) software 422, identity / age verification routine 423, cryptographic key generator 424, risk-reduced device (RRD) profile 425, and / or adult consumer profile 426, etc. Additionally, memory 420 may store additional data (not shown) for use with the stored program code, such as sensor information, program configuration data, risk-reduced device data, etc. Such software components may be loaded from a non-transitory computer-readable storage medium separate from memory 420 using a drive mechanism (not shown) connected to personal computing device 320 via network interface 430. The network interface 430 may include a wired communication interface for a wired communication protocol such as Ethernet, USB, FireWire, eSATA, ExpressCard, Thunderbolt, etc., and / or a wireless communication interface for a wireless communication protocol such as WiFi, Bluetooth, Near Field Communication (NFC), 3G, 4G LTE, 5G, Zigbee, etc. For example, the network interface may include a Bluetooth transceiver 431, a WiFi transceiver 432, an IR sensor 481, an NFC sensor 482, an RFID sensor 483, a magnetic sensor 484, etc.

[0091] Additionally, network interface 430 may enable processor 410 to communicate with and / or transfer data to / from risk reduced device 310, identity verification server 330, third-party identity verification service 340, POS terminal 350, and / or other computing devices (not shown), such as servers, personal computers (PCs), laptops, smartphones, tablets, gaming devices, etc. Data transferred between processor 410 and risk reduced device 310 may include identity verification results, cryptographic keys, profile data regarding one or more adult consumers, software updates to risk reduced device (RRD) software 422, identity / age verification routines 423, cryptographic key generator 424, risk reduced device (RRD) profile 425, and / or adult consumer profile 426, etc.

[0092] In at least one exemplary embodiment, communication bus 415 may enable communication and data transfer between components of personal computing device 320. Bus 415 may be implemented using a high-speed serial bus, a parallel bus, and / or any other suitable communication technology.

[0093] The personal computing device 320 may include at least one input / output (I / O) interface 440 for connecting to one or more I / O devices such as a keyboard (not shown), a mouse (not shown), a microphone (not shown), a speaker (not shown), sensors (e.g., a gyroscope (not shown), an accelerometer (not shown), a GPS sensor 460, other position and location sensors (not shown), a pressure sensor (not shown), etc.), a camera 450, etc. The I / O devices may be integrated into the personal computing device 320 or may be external to the personal computing device 320 and connected to the personal computing device 320 via wired and / or wireless connections, etc. Further, the personal computing device 320 may include at least one display (not shown), such as a monitor, television, touchscreen panel, and / or projector, etc.

[0094] Additionally, according to some exemplary embodiments, USB dongle 470 may be connected to personal computing device 320, such as a personal computer (PC), laptop, tablet, etc. USB dongle 470 may be a "plug-in" type device that allows a personal computing device that includes one or more of Bluetooth transceiver 431, WiFi transceiver 432, IR sensor 481, NFC sensor 482, RFID sensor 483, magnetic sensor 484, etc., to communicate with risk-reduced device 310, especially if the personal computing device does not already include one or more of these sensors.

[0095] Additionally, according to some exemplary embodiments, personal computing device 320 may be a point-of-sale terminal and / or special-purpose device located at a retail location, store, point-of-purchase, etc., so that an adult consumer and / or retail employee, merchant, etc. may unlock risk-reduced device 310 after purchase. According to these exemplary embodiments, personal computing device 320 may include an air puff mechanism 490 and / or speaker 492 that emits a special code to unlock risk-reduced device 310 after an adult consumer has verified their age and / or identity via special-purpose personal computing device 320 located at the retail location. After the adult consumer has undergone the age and / or identity verification process using personal computing device 320, personal computing device 320 receives a verification result and / or an encryption key from identity verification server 330. If personal computing device 320 receives a verification result from identity verification server 330, personal computing device 320 generates an encryption key based on the verification result. Additionally, personal computing device 320 may use air puff mechanism 490 and / or speaker 492 to specially encrypt the encryption key and transmit the encryption key to risk-reduced device 310. For example, if personal computing device 320 uses air puff mechanism 490, the encryption key is converted (e.g., translated, converted, etc.) into a special air puff "pattern" to be generated by air puff mechanism 490, which, when detected by a puff sensor in risk-reduced device 310, is converted into data by risk-reduced device 310, etc. When personal computing device 320 uses speaker 492 to transmit the encryption key to risk-reduced device 310, the encryption key is converted into coded sound waves that are detected by a microphone in risk-reduced device 310, and risk-reduced device 310 converts the coded sound into data, etc.

[0096] FIG. 4B is a block diagram illustrating various components of a risk-reduced device for an identity verification system in accordance with at least one exemplary embodiment.

[0097] According to at least one exemplary embodiment, a risk-reduced device, such as risk-reduced device 310, may include control circuitry 510, memory 520, bus 515, power supply 530, heater 540, distributed product items 550, power supply charging interface 560, input / output (I / O) interface 570, network interface 580, GPS sensor 590, puff sensor 595, and / or biometric sensor 596. However, exemplary embodiments are not limited in this respect, and the risk-reduced device may include a greater or lesser number of components.

[0098] Additionally, the risk-reduced device may also include one or more risk-reduced device UID tags, such as RFID tag 581, WiFi tag 582, infrared (IR) tag 583, NFC tag 584, Bluetooth tag 585, barcode 586, QR code 587, magnetic tag 588, etc. According to at least one exemplary embodiment, the risk-reduced device UID tag may include (e.g., store, program, embed, and / or have printed thereon, etc.) unique identifying information (e.g., UID, etc.) corresponding to the risk-reduced device itself and / or individual components of the risk-reduced device, such as power supply 530, heater 540, distributed product item 550, charging interface 560, I / O interface 570, network interface 580, GPS sensor 590, and / or puff sensor 595, etc. The UID information included in the risk-reduced device UID tag may be read by a corresponding reader and / or sensor of a personal computing device and / or POS terminal, such as personal computing appliance 320, POS terminal 350, etc., respectively, and / or a stand-alone reader and / or sensor. For example, if the risk-reduced device UID tag is an RFID tag 581, the UID information may be read using a corresponding RFID scanner, etc. If the risk-reduced device UID tag is a barcode 586 or QR code 587, the UID information may be read using a camera, barcode scanner, etc. Additionally, the risk-reduced device UID tag may be a serial number printed or etched on the risk-reduced device and entered into personal computing device 320, POS terminal 350, etc., that can be read by an adult consumer and / or store clerk, etc. According to at least one exemplary embodiment, the risk-reduced device UID tag may be located on the risk-reduced device 310, a component of the risk-reduced device 310 (e.g., distributed product item 550, power source 530, etc.), and / or on packaging for the risk-reduced device 310 or a component of the risk-reduced device, etc.

[0099] In at least one exemplary embodiment, memory 520 may be a non-transitory computer-readable storage medium and may include random access memory (RAM), read-only memory (ROM), and / or permanent mass storage such as a solid-state drive, etc. Memory 520 stores program code (i.e., computer-readable instructions) for overall risk-reduced device 310 functionality, such as decoding control routines 522, heater control routines 523, and / or profile information 524 (e.g., risk-reduced device profile information, distributed product profile information, adult consumer profile information, etc.), as well as data such as private key 521, biometric information captured using biometric sensor 596, etc., and / or functionality related to locking / unlocking the risk-reduced device and / or components of the risk-reduced device. Such software components may be loaded from a non-transitory computer-readable storage medium separate from memory 520 via wired communication protocols such as Ethernet, USB, FireWire, eSATA, ExpressCard, Thunderbolt, etc., and / or wireless communication protocols such as Wi-Fi, Bluetooth, Near Field Communication (NFC), Infrared (IR) communication, RFID communication, 3G, 4G LTE, 5G, etc. Furthermore, some or all of the functionality and / or data stored in memory 520 may be stored in an encrypted state, such as private keys 521, profile information, etc.

[0100] In at least one exemplary embodiment, bus 515 may enable communication and data transfer to occur between components of risk-reduced device 310. Bus 515 may be implemented using a high-speed serial bus, a parallel bus, and / or any other suitable communication technology.

[0101] According to at least one exemplary embodiment, control circuitry 510 may be at least one controller, processor, processing device, field programmable gate array (FPGA), system-on-chip (SoC), and / or hardwired circuitry, etc., that may be configured to control one or more components of risk-reduced device 310. Control circuitry 510 may also recover and process program code (e.g., computer-readable instructions), such as decryption control routines 522, heater control routines 523, and / or profile information 524 (e.g., risk-reduced device profile information, distributed product profile information, etc.), and data from memory 520 (e.g., private key 521, etc.), to control overall risk-reduced device 310 functionality and / or functionality related to locking / unlocking the risk-reduced device and / or components of the risk-reduced device. Once program code is loaded into control circuitry 510, control circuitry 510 executes special-purpose program instructions, transforming control circuitry 510 into a special-purpose controller and / or processor, etc. Further, according to some exemplary embodiments, the control circuitry 510 may be two or more controllers, processors, processing devices, field programmable gate arrays (FPGAs), systems on chips (SoCs), and / or hardwired circuits, etc., with a first controller focused on controlling and performing functions of the risk-reduced device, and a second controller focused on functions related to locking / unlocking the risk-reduced device and / or components of the risk-reduced device, etc.

[0102] In at least one exemplary embodiment, control circuitry 510 may control network interface 580 to receive an encryption key from personal computing device 320, POS terminal 350, etc. Control circuitry 510 may decrypt the received encryption key using decryption control routine 522 and private key 521 and, based on the identity verification result and the risk-reduced device UID (and / or risk-reduced device component UID) included in the encryption key, determine whether to unlock risk-reduced device 310 and / or unlock corresponding components of the risk-reduced device, such as distributed product item 550, power supply 530, heater 540, charging interface 560, etc. Additionally, according to some exemplary embodiments, control circuitry 510 may control biometric sensor 596 to capture biometric information (e.g., fingerprint scan, retinal scan, voice scan, face scan, heart rate scan, etc.) of the adult consumer and transmit the biometric information to personal computing device 320 for verifying the adult consumer's identity, etc.

[0103] According to at least one exemplary embodiment, puff sensor 595 may receive a pressurized burst of air from, for example, POS terminal 350 and / or an air puff device (e.g., an air puff generator) installed in the retail store. If the received pressurized burst of air is at a desired air pressure and / or frequency, control circuitry 510 may decide to unlock risk-reduced device 310 and / or components of the risk-reduced device. Additionally, risk-reduced device 310 may receive an encrypted sound emitted through, for example, a speaker of POS terminal 350, which is received by a microphone (not shown) of risk-reduced device 310. If the received encrypted sound matches the desired encrypted sound, control circuitry 510 may decide to unlock risk-reduced device 310 and / or components of the risk-reduced device. The pressurized burst of air and / or the encrypted sound may be encoded using a desired air pressure-based or sound-based data format known to control circuitry 510, such that the air burst and sound can be converted into digital data by control circuitry 510. The translated digital data may correspond to the identity and UID of reduced risk device 310 and / or components of the reduced risk device that the adult consumer is attempting to unlock.

[0104] In at least one exemplary embodiment, control circuitry 510 may execute lock control routine 523 to unlock risk-reduced device 310 and / or individual components of risk-reduced device 310 based on the results of the determination of whether to unlock risk-reduced device 310. If control circuitry 510 determines that risk-reduced device 310 should be unlocked, control circuitry 510 may enable power source 530 to send power to heater 540 of risk-reduced device 310. Furthermore, if control circuitry 510 determines that individual components of risk-reduced device 310 and / or multiple components of risk-reduced device 310 should be unlocked, control circuitry 510 may enable operation of those components by operating electrical and / or physical switches connected to those components, such as dispersed product item 550, puff sensor 595, etc. Risk-reduced device 310 and / or components of risk-reduced device 310 may be permanently or temporarily unlocked based on the settings of risk-reduced device 310 and / or lock condition settings contained in the cryptographic key.

[0105] Additionally, control circuitry 510 may execute lock control routine 523 to lock risk-reduced device 310 and / or individual components of risk-reduced device 310 based on at least one lock / unlock condition, such as expiration of an unlock period, proximity of risk-reduced device 310 to personal computing device 320, proximity of risk-reduced device 310 to a location where operation of risk-reduced device 310 is prohibited, receipt of a lock signal, etc. For example, control circuitry 510 may relock risk-reduced device 310 and / or individual components of risk-reduced device 310 after expiration of a set period included in a lock condition setting of an encryption key and / or programmed into risk-reduced device 310. Additionally, control circuitry 510 may relock risk-reduced device 310 if risk-reduced device 310 moves out of a desired proximity range (e.g., a desired distance range) from personal computing device 320. The desired proximity range may be based on the connection range of a wireless protocol, such as Bluetooth, NFC, WiFi, etc., used to wirelessly connect the network interface 580 of the risk-reduced device 310 with the network interface 430 of the personal computing device 320.

[0106] The control circuitry 510 may also relock the risk-reduced device 310 based on location information corresponding to the current location of the risk-reduced device 310. For example, the risk-reduced device 310 may include a location sensor, such as a GPS sensor 590, a GLONASS sensor (not shown), etc., that determines the current location information of the risk-reduced device 310, which may be determined based on location information of a personal computing device 320, if connected to the risk-reduced device 310. The control circuitry 510 may compare the location information associated with the risk-reduced device 310 with location information of locations where operation of the risk-reduced device 310 may be prohibited and / or restricted, such as educational facilities, places of worship, public venues, medical facilities, etc., or locations entered by the adult consumer, such as location information corresponding to the adult consumer's home, office, etc. The location information of the restricted locations may be stored in the memory 520 of the risk-reduced device 310 and / or transmitted from the personal computing device 320, etc., to the risk-reduced device 310, without limitation.

[0107] Control circuitry 510 may also relock risk-reduced device 310 based on receiving a wireless locking signal emitted from wireless beacon transmitter 360, such as a Bluetooth beacon transmitter, a WiFi beacon transmitter, etc. Wireless beacon transmitter 360 may be installed in locations where operation of risk-reduced devices is prohibited and / or restricted, such as schools, places of worship, etc., and may emit a wireless locking signal to risk-reduced devices in the vicinity of the restricted location. If control circuitry 510 detects that network interface 580 has received a wireless locking signal from wireless beacon transmitter 360, control circuitry 510 may disable the power supply from transmitting power to heater 540, etc.

[0108] 4B illustrates an exemplary embodiment of a risk-reduced device, the risk-reduced device is not limited thereto and may include additional and / or alternative structures that may be suitable for the demonstrated purpose. For example, the risk-reduced device may include multiple additional or alternative components, such as additional processing units, interfaces, and memory.

[0109] 4C is a block diagram illustrating components of an identity verification server according to at least one example embodiment. Components of the identity verification server that are identical to components described in connection with FIG. 4A may be partially or completely omitted, and the identical components may be assumed to have the same and / or similar characteristics and / or operation as the components described in connection with FIG. 4A. Differences between the personal computing device and the identity verification server are described below.

[0110] According to at least one example embodiment, an identity verification server, such as identity verification server 330 of Figure 3, may include at least one processor 610, a communication bus 615, a memory 620, a network interface 630, and / or an I / O interface 640, etc. Memory 620 may include computer-readable instructions (and / or software code, etc.) corresponding to an operating system (OS) 621 for operating the identity verification server, as well as special-purpose computer-readable instructions related to the identity verification process, such as an age / identity verification routine 622, a verification information database 623 for storing age and / or identity verification information associated with a plurality of adult consumers, a cryptographic key generator 624, etc., although example embodiments are not limited thereto.

[0111] In at least one exemplary embodiment, processor 610 may be at least one processor (and / or processor core, distributed processor, networked processor, etc.) that may be configured to control one or more components of identity verification server 330. Processor 610 is configured to retrieve and process program code (e.g., computer-readable instructions) and data from memory 620 to perform the control and functions of identity verification server 330. When program instructions are loaded into processor 610, processor 610 executes the program instructions, converting processor 610 into a special-purpose processor. For example, when processor 610 loads special-purpose instructions related to age / identity verification routine 622, verification information database 623, encryption key generator 624, etc., processor 610 is converted into a special-purpose processor for executing routines such as age / identity verification routine 622, verification information database 623, encryption key generator 624, etc.

[0112] Additionally, according to at least one example embodiment, processor 610 may execute age / identity verification routine 622 to perform age and / or identity verification of the adult consumer based on information received from personal computing device 320 and / or POS terminal 350, etc., using network interface 630. The information received from personal computing device 320 and / or POS terminal 350 may include a request for age and / or identity verification, the UID of the risk-reduced device and / or UIDs of components of the risk-reduced device, and information regarding the identity of the adult consumer requesting age / identity verification (e.g., a personal UID corresponding to the adult consumer, the name of the adult consumer, etc.). Processor 610 may then generate age / identity challenge questions based on the adult consumer's identity information and verified identity information stored in verification information database 623 and corresponding to the received age / identity request, such as questions regarding the adult consumer's personal information, questions regarding the adult consumer's family, public financial information regarding the adult consumer, business information regarding the adult consumer, biometric information regarding the adult consumer, etc., which are stored in verification information database 623 and have previously been verified as accurate information regarding the adult consumer. The identity challenge questions may be questions that the adult consumer has previously created and / or submitted answers to, or questions and answers collected by a third party and / or external identity verification service 340 based on available information about the adult consumer, such as public records, financial data, information the adult consumer has provided to identity verification server 330, information provided to an identity verification software application, the adult consumer's biometric data, etc. Once processor 610 has generated the age and / or identity challenge questions, processor 610 may transmit the challenge questions to personal computing device 320 and / or POS terminal 350 using network interface 630.

[0113] Alternatively, according to at least one example embodiment, processor 610 may contact a third party server, such as third party identity verification service 340, a third party credit reporting / information service, a government database, etc., to generate a verification challenge question for the adult consumer based on information corresponding to the adult consumer stored on the third party server. Once processor 610 receives the verification challenge question from the third party server, processor 610 may transmit the verification challenge question to personal computing device 320 and / or POS terminal 350, etc., using network interface 630.

[0114] Processor 610 may receive responses to the identity challenge questions from personal computing device 320 and / or POS terminal 350, etc., using network interface 630, and processor 610 may verify the responses based on identifying information corresponding to the adult consumer stored in identifying information database 623 of identifying server 330. According to some exemplary embodiments, identifying information database 623 may be provided by a third party server, such as a third party identity verification service, a third party credit report / information service, a government database, etc., which may be accessed to verify information included in responses to the identity challenge questions received from personal computing device 320 and / or POS terminal 350, etc. Additionally, once the identity of an adult consumer requesting the unlocking of a locked risk-reduced device 310 and / or a locked component of the risk-reduced device has been verified, processor 610 may determine whether the adult consumer is of legal age (e.g., of legal age) to purchase and / or operate reduced-risk device 310 by, for example, matching the stored age of the verified identity against the minimum legal age for purchasing and / or operating reduced-risk devices and / or components of the reduced-risk device (e.g., reduced-risk device distribution product 550) in the appropriate jurisdiction. For example, geographic information related to the location of reduced-risk device 310, the location of personal computing device 320, and / or the location of POS terminal 350 may be transmitted to identity verification server 330. The geographic information may be determined using GPS sensors and / or other location determining sensors / devices of the risk-reduced device 310, personal computing device 320, and / or POS terminal 350, may be a location relative to the store where the risk-reduced device 310 is purchased, may be a predetermined address relative to the adult consumer's mailing address, etc.

[0115] Based on the verification result of the response to the identity challenge question, processor 610 generates an encryption key using encryption key generator 624. Processor 610 may generate the encryption key based on the verification result (e.g., indicating that the information included in the response received from the adult consumer was successfully verified using the information stored in verification information database 623, or that the information included in the response did not match the information stored in verification information database 623), the UID of risk-reduced device 310 and / or the UID of the component of risk-reduced device 310 that the adult consumer requests to unlock, etc. For example, processor 610 may generate an encryption key based on public keys stored in identity verification server 330 that correspond to risk-reduced device 310 and / or the component of risk-reduced device 310, the UID of the risk-reduced device and / or the component of risk-reduced device, the verification result, etc., and transmit the encryption key to personal computing device 320 and / or POS terminal 350. However, exemplary embodiments are not limited thereto, and the encryption key may be generated based on other data.

[0116] According to some exemplary embodiments, the UID of risk-reduced device 310 and / or a component of the risk-reduced device may be the public key itself, although exemplary embodiments are not limited thereto. Additionally, according to other exemplary embodiments, processor 610 may omit generating the encryption key and instead transmit the verification result to personal computing device 320 and / or POS terminal 350, which may generate the encryption key in a similar manner. Additionally, according to yet other exemplary embodiments, processor 610 may transmit the generated encryption key or the verification result directly to risk-reduced device 310 itself, or the like.

[0117] Additionally, according to some exemplary embodiments, processor 610 may record the verification attempts in verification information database 623. For example, processor 610 may record all verification attempts or may record failed verification attempts in verification information database 623. Data included in the verification attempt record may include, but is not limited to, the date, time, the adult consumer identity used in the verification attempt, the result of the verification attempt, the UID of the risk-reduced device and / or component of the risk-reduced device corresponding to the verification attempt, the IP address and / or MAC address of the personal computing device and / or POS terminal associated with the verification attempt, location information of the personal computing device and / or POS terminal associated with the verification attempt (e.g., GPS information, latitude / longitude, address associated with the POS terminal, etc.), store / retailer employee information associated with the point of sale of the risk-reduced device, etc. Additionally, information related to the failed verification attempts may be forwarded to relevant authorities, such as government agencies (e.g., law enforcement, public health authorities, state regulatory agencies, etc.), school authorities, employers, etc., so that possible illegal activity related to the sale or consumption of reduced-risk devices to minors, etc. may be monitored and / or remedied. Additionally, information related to the failed verification attempts may also be forwarded to an address (e.g., mailing address, email address, telephone number, etc.) associated with the identity of the adult consumer for whom the request was attempted. This may allow a legitimate adult consumer, using the adult consumer's identity, to be notified of a failed attempt to pass age / identity verification to unlock the reduced-risk device.

[0118] 4C illustrates an exemplary embodiment of an identity verification server, the identity verification server is not limited thereto and may include additional and / or alternative structures that may be suitable for the purposes demonstrated. For example, identity verification server 330 may include multiple additional or alternative components, such as additional processing units, interfaces, routines, memory, etc.

[0119] FIG. 5 is a flowchart illustrating a method of operating a risk-reduced device in accordance with at least one exemplary embodiment.

[0120] 5, a method of operating a risk-reduced device according to at least one exemplary embodiment is illustrated, but exemplary embodiments are not limited thereto. In operation S510, the risk-reduced device may detect the initiation of operation of the risk-reduced device based on, for example, using a puff sensor, negative air pressure applied to a mouthpiece of the risk-reduced device, activation of a power button (e.g., an on / off button, etc.), a request sent from software on the risk-reduced device (e.g., a wireless pairing request (e.g., a Bluetooth pairing request, an NFC pairing request, a WiFi pairing request, etc.), an age / identification request, etc.), etc.

[0121] In operation S520, the risk-reduced device may determine whether an age / identity lock has been activated on the risk-reduced device (e.g., first lock, the risk-reduced device is in a locked state, and / or the age / identity lock flag is set, etc.) based on settings stored in the risk-reduced device's memory (e.g., lock control routine 523 in the memory). In response to the risk-reduced device determining that the age / identity lock has been activated, the risk-reduced device may perform an age / identity verification method according to some example embodiments, such as, but not limited to, the operations beginning with operation S630 of FIG. 6. The age / identity verification method is described in further detail in FIG. 6.

[0122] In response to the risk-reduced device determining that the age / identity lock is not activated, in operation S530, the risk-reduced device may determine whether a manual lock (e.g., a second lock, etc.) is activated based on settings stored in the memory of the risk-reduced device (e.g., memory lock control routine 523).

[0123] In response to the risk-reduced device determining that the manual lock is engaged, the risk-reduced device proceeds to operation S570. In response to the risk-reduced device determining that the manual lock is not engaged and / or disengaged (e.g., a second manual lock command is received from the personal computing device that sent the first manual lock command that placed the risk-reduced device in a manual lock state), in operation S540 the risk-reduced device may determine whether a proximity lock (e.g., a third lock, etc.) is engaged based on settings stored in memory of the risk-reduced device (e.g., lock control routine 523 in memory).

[0124] In response to the risk reduced device determining that the proximity lock is not activated, the risk reduced device proceeds to operation S550. In response to the risk-reduced device determining that the proximity lock has been activated, the risk-reduced device determines whether it is connected to the same personal computing device (e.g., the personal computing device that sent the initial proximity lock command, the personal computing device that initiated the proximity lock, etc.) that originally set the proximity lock and is stored in the memory of the risk-reduced device (e.g., stored in the lock control routine 523 of the memory) based on the personal computing device UID included in the initial proximity lock command (e.g., a unique serial number associated with the personal computing device and / or risk-reduced device software installed on the personal computing device, an IP address and / or MAC address associated with the personal computing device, a UID associated with the adult consumer, a UID associated with the risk-reduced device software installed on the personal computing device, a connection session ID corresponding to a communication session established between the personal computing device and the risk-reduced device, etc.) and the personal computing device UID received from the personal computing device connected (e.g., paired) to the risk-reduced device (e.g., received in the second proximity lock command, received upon wireless pairing of the personal computing device and the risk-reduced device, etc.). In response to the personal computing device UIDs not matching (and / or the personal computing device not being paired with the risk-reduced device), the risk-reduced device maintains the proximity lock state, operation of the risk-reduced device remains prohibited, and the risk-reduced device proceeds to operation S470. However, in response to the personal computing device UID of the initial proximity lock command and the current pair of personal computing devices matching, the risk-reduced device changes the proximity lock state to an unlocked state and proceeds to operation S550.

[0125] In operation S550, the risk-reduced device may determine whether a beacon proximity lock (e.g., a fourth lock, etc.) has been activated based on settings stored in the risk-reduced device's memory (e.g., memory lock control routine 523). In response to the risk-reduced device determining that a beacon proximity lock has been activated (e.g., receiving a beacon proximity lock indication from a wireless beacon transmitter), the risk-reduced device proceeds to operation S550A and starts a countdown timer of a predetermined length of time. If the countdown timer expires and no additional beacon proximity lock indications have been received from the wireless beacon transmitter and / or the risk-reduced device is no longer within range of the wireless beacon transmitter, the risk-reduced device releases the beacon proximity lock (e.g., sets the beacon proximity state to an unlocked state, etc.) and repeats operation S550. If the risk-reduced device receives another beacon proximity lock indication while the countdown timer is running, the beacon proximity lock state remains locked, and the countdown timer is reset and restarted. Furthermore, if the risk-reduced device receives a beacon proximity lock indication while the beacon proximity lock is in an unlocked state, the risk-reduced device immediately changes the beacon proximity lock state to a locked state, disables operation of the risk-reduced device (if the risk-reduced device is being operated at that time), and starts a countdown timer.

[0126] In response to the beacon proximity lock being released, the risk-reduced device proceeds to operation S560, where the risk-reduced device allows operation of the risk-reduced device by an adult consumer, for example, by allowing a power source in the risk-reduced device to provide power to a heating coil in the risk-reduced device.

[0127] Additionally, in response to the risk-reduced device determining that one or more of the age / identity lock, manual lock, proximity lock, and / or beacon proximity lock have been activated, the risk-reduced device may perform operation S570 and display a "locked" status message to the adult consumer via the risk-reduced device user interface and / or via the GUI of the risk-reduced device software on the personal computing device. For example, the "locked" status message may also include a message indicating which locks have been activated so that the adult consumer may unlock the appropriate locks to enable operation of the risk-reduced device, although example embodiments are not limited in this regard.

[0128] Additionally, example embodiments are not limited to the above, for example, the risk-reduced device may include more or fewer locks than those discussed herein. Additionally, example embodiments are not limited to the order of operations described above, and the order of operations may be changed as desired by one of ordinary skill in the art.

[0129] FIG. 6 is a flowchart illustrating a method for verifying the age and / or identity of an adult consumer associated with a risk-reduced device in accordance with at least one exemplary embodiment.

[0130] 6, a method for verifying the age and / or identity of an adult consumer associated with a risk-reduced device is illustrated in accordance with at least one exemplary embodiment, but not limited to, an exemplary embodiment. In operation S610, the adult consumer may install a risk-reduced device software application (e.g., an app, etc.) on a personal computing device (e.g., a smartphone, tablet, laptop, personal computer, smartwatch, VR device, AR device, etc.). Additionally, the adult consumer may create an adult consumer profile using a website associated with the risk-reduced device software and / or an identity verification server and / or a third-party identity verification service. The adult consumer profile may include, but is not limited to, information such as the adult consumer's legal name, the adult consumer's date of birth, the adult consumer's address information (e.g., street address, mailing address, work address, etc.), a government-issued identification number associated with the adult consumer, such as the adult consumer's Social Security number, the adult consumer's driver's license number, the adult consumer's passport number, etc., the adult consumer's contact information (e.g., phone number, email address, social media information, instant messaging information, etc.), the adult consumer's biometric information (e.g., the adult consumer's fingerprint, the adult consumer's voice signature, the adult consumer's facial recognition signature, the adult consumer's retinal signature, the adult consumer's heart rate signature, etc.). Additionally, the adult consumer profile information may include an adult consumer-created password, PIN information, etc., for protecting the adult consumer profile, and / or adult consumer-created identity challenge questions and adult consumer-provided answers to the adult consumer-created identity challenge questions for future authentication of the adult consumer's age / identity. Additionally, according to some exemplary embodiments, the adult consumer profile information may be stored on the personal computing device and / or on a website in encrypted form.

[0131] At act S620, the adult consumer profile (e.g., adult consumer profile information) stored on the personal computing device and / or website may be transmitted to an identity verification server. The identity verification server may store the adult consumer profile in encrypted form in its memory and may associate the adult consumer profile with publicly available identity verification information corresponding to the adult consumer's identity. For example, the identity verification server may associate the adult consumer profile with information obtained from third-party identity verification services, government databases, credit agencies, etc., including information such as past addresses associated with the adult consumer's identity, past phone numbers associated with the adult consumer's identity, family information associated with the adult consumer's identity, biographical information related to the adult consumer's identity (e.g., information related to the place of birth, the hospital where the adult consumer was born, foreign countries visited, the adult consumer's spouse, partner, children, parents, other relatives, etc.), educational information associated with the adult consumer's identity (e.g., schools attended by the adult consumer, graduation dates associated with the adult consumer, awards received while attending school, etc.), the adult consumer's banking / financial history, the adult consumer's employment history, etc., but example embodiments are not limited thereto. Additionally, the identity verification server may assign a UID associated with the adult consumer profile.

[0132] In operation S630, the adult consumer may operate a personal computing device (and / or POS terminal, etc.) to capture the UID of the reduced risk device and / or UIDs of components of the reduced risk device, such as dispersed products, using a camera and / or sensors on the personal computing device or POS terminal. Alternatively, the adult consumer may manually enter the UIDs using a GUI in the reduced risk device software.

[0133] In operation S640, the adult consumer may enter their identity information (e.g., name, etc.) into the risk-reduced device software, and the personal computing device or POS terminal may send an identity verification request to the identity verification server, the request including the identity of the adult consumer that needs to be unlocked and the UID of the risk-reduced device and / or components of the risk-reduced device. Additionally, other information may be included in the identity verification request, such as location information associated with the personal computing or POS terminal sending the identity verification request, the IP address and / or MAC address of the personal computing device and / or POS terminal associated with the verification request, and, if a POS terminal sends the identity verification request, retailer information associated with the POS terminal (e.g., store number, store location information, identity of the retail employee assisting the adult consumer with the purchase of the risk-reduced device, etc.).

[0134] At operation S650, the identity verification server may receive an identity verification request from the personal computing device or POS terminal and may generate at least one identity verification challenge question and corresponding answer to verify the identity and / or age of the adult consumer based on information included in the identity verification request, adult consumer profile information stored on the identity verification server, and / or information received from a third-party identity verification service. For example, the identity verification server may generate identity verification challenge questions related to the adult consumer's mother's maiden name, place of birth, employment history, education history, banking / financial history, locations where the individual has lived, names of relatives, etc. The identity verification challenge questions may be questions the adult consumer has previously created, such as entering a previously created password or PIN, adult consumer-created identity challenge questions, etc., and / or submitted answers stored in the adult consumer's profile. Additionally, according to some exemplary embodiments, the identity verification server may request identity verification questions and corresponding answers generated by a third-party verification service (e.g., an external identity verification service, a government identity verification service, etc.) based on available public records related to the adult consumer. The identity verification server may also generate an identity challenge question that requests the adult consumer to provide biometric information (e.g., a fingerprint, facial scan, retinal scan, voice identification, etc.) that matches the adult consumer's previously provided biometric information stored in the adult consumer's profile. However, exemplary embodiments are not limited in this regard, and the identity challenge question may take other equivalent forms that provide accurate confirmation of a person's identity. Once the identity challenge question is generated, the identity verification server may transmit the question to the personal computing device or POS terminal that originally sent the identity request.

[0135] In act S660, the personal computing device or POS terminal receives the generated identity challenge question from the identity verification server, presents the question to the adult consumer (e.g., displays the question, speaks the question, etc.), and receives an answer to the question from the adult consumer. For example, the adult consumer may type their answer into the personal computing device or POS terminal, speak their answer, provide their biometric information, etc. The personal computing device or POS terminal may then transmit the answer to the identity verification server.

[0136] In operation S670, the identity verification server may verify the received identity challenge response based on information corresponding to the adult consumer previously stored in an adult consumer profile and / or provided by a third-party identity verification service, etc., and determine whether the received identity challenge response matches an answer to an identity challenge question generated by (and / or stored in) the identity verification server. Additionally, assuming the identity verification attempt is successful, the identity verification server may determine the adult consumer's age based on the information stored in the adult consumer profile, and whether the adult consumer is legally permitted to purchase, possess, and operate the risk-reduced device and / or components of the risk-reduced device based on the location information included in the identity verification request, the address information associated with the adult consumer in the adult consumer profile, retail store location information, etc., and the relevant laws of the jurisdiction corresponding to the location information. If the adult consumer successfully verifies their identity based on the identity challenge question, and it is determined that the age associated with the adult consumer meets all legal requirements related to risk-reduced devices, the identity verification server determines that the identity and / or age verification request is successful. However, if it is determined that the adult consumer successfully verifies their identity based on the identity challenge questions but not the age requirement and / or that the adult consumer has failed to verify their identity, the identity verification server determines that the identity and / or age verification request was unsuccessful.

[0137] In operation S680, the identity verification server transmits the results of the identity and / or age verification to the personal computing device or the POS terminal. According to some exemplary embodiments, the identity verification server may generate a cryptographic key for unlocking the risk-reduced device and / or components of the risk-reduced device based on the verification results and public keys stored on the identity verification server (e.g., a public key associated with the risk-reduced device, a public key associated with the adult consumer, and / or other public keys, etc.), the UID of the risk-reduced device, and / or the adult consumer's personal UID, etc., although exemplary embodiments are not limited in this respect and the cryptographic key may be generated based on other information as well. For example, the public key may be the UID of the risk-reduced device 310, etc. The identity verification server may then transmit the cryptographic key to the personal computing device or the POS terminal instead of transmitting the verification results.

[0138] Additionally, according to some exemplary embodiments, the identity verification server may record the verification attempts in a database, such as verification information database 623. For example, the identity verification server may record all verification attempts or only failed verification attempts. Data included in the verification attempt record may include, but is not limited to, the date, time, the identity of the adult consumer used in the verification attempt, the result of the verification attempt, the UID of the risk-reduced device and / or component of the risk-reduced device corresponding to the verification attempt, the IP address and / or MAC address of the personal computing device and / or POS terminal associated with the identity verification request, location information associated with the personal computing device and / or POS terminal associated with the verification attempt (e.g., GPS information, latitude / longitude, address associated with the POS terminal, etc.), store / retailer employee information associated with the point of sale of the risk-reduced device, etc. Additionally, if the number of failed verification attempts exceeds a predetermined threshold (e.g., the predetermined threshold may be any number greater than or equal to one), information related to the failed verification attempts may be forwarded to relevant authorities, such as government agencies (e.g., law enforcement, public health authorities, state regulatory agencies, etc.), school authorities, employers, etc., to monitor and / or remediate possible illegal activities, etc. related to the sale or consumption of reduced-risk devices to minors. Additionally, information related to the failed verification attempts may also be forwarded to an address (e.g., mailing address, email address, telephone number, etc.) associated with the identity of the adult consumer that the request attempted to verify, so that the legitimate adult consumer may be notified of the failed attempt to pass the age / identity check to unlock the reduced-risk device using the adult consumer's identity. Additionally, if the number of failed verification attempts exceeds a predetermined threshold, the adult consumer may be permanently blocked from using the identity verification service (e.g., subsequent attempts to use the adult consumer's identity using the identity verification service may be automatically rejected by the identity verification server), and / or the identity verification server may send a permanent lock instruction to the risk-reduced device software installed on the personal computing device and / or the risk-reduced device itself.

[0139] FIG. 7 is a flowchart illustrating a method for unlocking a risk-reduced device that has been locked based on the outcome of an age and / or identity challenge in accordance with at least one exemplary embodiment.

[0140] At operation S710, the personal computing device (or POS terminal) that initiated the age and / or identity verification request receives from the identity verification server the results of the identity verification performed by the identity verification server. At operation S720, the personal computing device (or POS terminal) may generate a cryptographic key for unlocking the locked risk-reduced device (and / or components of the locked risk-reduced device) based on the verification results. For example, the cryptographic key may be generated based on public keys stored on the personal computing device (e.g., a public key associated with the risk-reduced device, a public key associated with the adult consumer, and / or other public keys), the UID of the risk-reduced device, the adult consumer's personal UID, and / or the verification results, although example embodiments are not limited thereto and the cryptographic key may be generated based on other information as well. Alternatively, according to some example embodiments, the personal computing device (or POS terminal) may receive the identity verification results from the identity verification server, which may include the cryptographic key generated by the identity verification server.

[0141] Additionally, the personal computing device may transmit the encryption key to the risk-reduced device.

[0142] Alternatively, according to some exemplary embodiments, the POS terminal may transmit the encryption key to the risk-reduced device via a wireless and / or wired communication channel when the risk-reduced device is removed from its packaging. The POS terminal may then unlock the risk-reduced device by issuing a pressurized burst of a predetermined air pressure and / or frequency corresponding to the encryption key to a puff sensor on the risk-reduced device. The POS terminal may also issue a encryption sound corresponding to the encryption key via a speaker, which is received by a microphone on the risk-reduced device.

[0143] At operation S730, the risk-reduced device may decrypt the encryption key using a private key stored on the risk-reduced device's memory. The risk-reduced device may decrypt the encryption key using a private key that corresponds to the public key used to encrypt the encryption key. For example, the private key may be a key stored on the risk-reduced device that corresponds to the risk-reduced device's UID, etc. Furthermore, if the risk-reduced device is unable to decrypt the encryption key using the private key, such as when an attempt to circumvent identity verification is performed using an encryption key copied from a previously successful identity verification attempt, the risk-reduced device may record the unsuccessful decryption attempt and / or transmit the results of the unsuccessful decryption attempt to the personal computing device (or POS terminal) and / or the identity verification server for further recording.

[0144] In act S740, the risk-reduced device may determine, based on the verification result included in the decrypted key, whether the adult consumer has been properly verified and / or whether they are legally permitted to operate the locked risk-reduced device and / or components of the locked risk-reduced device. If the verification result indicates that the adult consumer has been properly verified, the risk-reduced device may unlock the risk-reduced device and / or components of the locked risk-reduced device (e.g., enable operation of the risk-reduced device, distributed product, power source for the risk-reduced device, etc.). The locked risk-reduced device and / or components of the locked risk-reduced device may be unlocked for an indeterminate period of time (e.g., permanently unlocked), may be unlocked for a predetermined period of time (e.g., temporarily unlocked for 15 minutes, 30 minutes, etc.), and / or may be unlocked while predetermined unlocking conditions are met.

[0145] In operation S750, in response to the risk-reduced device being changed to an operable state, the control circuitry of the risk-reduced device enables operation of the risk-reduced device, such as allowing current to flow from a battery in the risk-reduced device to a heating element in the risk-reduced device, enabling operation of a dispersed product article, and / or other operations.

[0146] According to one or more exemplary embodiments, an identity verification system, device, method, and non-transitory computer-readable medium are provided that improve the process of verifying the age at time of sale of purchasers of tobacco-related, nicotine-related, and / or non-nicotine-related products, such as nicotine and / or non-nicotine types of reduced-risk or reduced-harm devices, e.g., heated non-combustion aerosol generating devices, non-heated inhalable aerosol generating devices, and / or e-vape devices. Furthermore, one or more exemplary embodiments provide an identity verification service when an individual attempts to operate a reduced-risk device (and / or reduced-harm device), and do not allow operation of the reduced-risk device if the individual's age and / or identity are not verified. One or more exemplary embodiments also allow adult consumers to manually lock the reduced-risk device to reduce and / or eliminate the possibility of unauthorized individuals operating the reduced-risk device. One or more exemplary embodiments also allow adult consumers to locate a lost reduced-risk device based on the location where the reduced-risk device was last operated, which reduces and / or eliminates the possibility of unauthorized individuals operating the reduced-risk device.

[0147] When a component or layer is referred to as being "on," "connected," "coupled," or "covered" another component or layer, it is understood that it may be directly connected, coupled, or covered by the other component or layer, or that intervening components or layers may be present. In contrast, when a component is referred to as being "directly," "directly connected," or "directly coupled" on another component or layer, there are no intervening components or layers. Like numbers refer to like components throughout this specification. As used herein, the term "and / or" includes any and all combinations of one or more associated listed items.

[0148] Although terms such as first, second, and third may be used herein to describe various components, modules, regions, layers, and / or sections, it should be understood that these components, modules, regions, layers, and / or sections are not limited by these terms. These terms are used only to distinguish one component, module, region, layer, or section from another region, layer, or section. Thus, a first component, module, region, layer, or section described below could be referred to as a second component, module, region, layer, or section without departing from the teachings of the exemplary embodiments.

[0149] Spatially relative terms (e.g., "below," "lower," "lower side," "upper," "upper," etc.) may be used herein for ease of description to describe the relationship of one component or feature to other components or features, as shown in the figures. It should be understood that the spatially relative terms are intended to encompass different orientations of the device during use or operation in addition to the orientation depicted in the figures. For example, if the device in the figures were inverted, components described as "below" or "below" other components or features would then be oriented "above" the other components or features. Thus, the term "below" can encompass both an orientation of above and below. The device may be otherwise oriented (rotated 90 degrees or at other orientations), and the spatially relative descriptions used herein would be interpreted accordingly.

[0150] The terminology used herein is for the purpose of describing various exemplary embodiments only and is not intended to be limiting of the exemplary embodiments. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly dictates otherwise. It will be further understood that as used herein, the terms "including," "having," "comprising," and / or "comprising" specify the presence of stated features, integers, steps, operations, components, and / or modules, but do not preclude the presence or addition of one or more other features, integers, steps, operations, components, modules, and groups thereof.

[0151] Example embodiments are described herein with reference to cross-section illustrations that are schematic illustrations of idealized embodiments (and intermediate structures) of example embodiments. As such, variations from the shapes of the illustrations are to be expected as a result, for example, of manufacturing techniques and / or tolerances. Thus, example embodiments should not be construed as limited to the shapes of regions illustrated herein but are to include deviations in shapes that result from manufacturing, for example.

[0152] Unless otherwise specified, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the exemplary embodiments belong. Terms, including those defined in commonly used dictionaries, should be interpreted as having a meaning consistent with the meaning in the context of the relevant art, and will be further understood not to be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0153] While exemplary embodiments are disclosed herein, it should be understood that other variations are possible. Such variations are not to be considered a departure from the spirit and scope of the present disclosure, and all such modifications that are obvious to those skilled in the art are intended to be included within the scope of the following claims.

Claims

1. 1. A computing device for verifying the identity of an adult consumer, comprising: a memory having computer readable instructions stored thereon; at least one processor; the at least one processor executes the computer-readable instructions; receiving, from the adult consumer, adult consumer identification information corresponding to the adult consumer; receiving a unique ID (UID) of a Risk Reduced Device (RRD); transmitting the adult consumer identity information to an identity verification server to perform identity verification of the adult consumer; receiving from the identity verification server a result of the performed identity verification; generating a cryptographic key corresponding to the RRD based on the results of the performed identity verification of the adult consumer and the UID of the RRD; A computing device configured to transmit the encryption key to the RRD, the encryption key causing the RRD to change a state of the RRD based on the encryption key.

2. 10. The computing device of claim 1, The computing device is at least one of a smartphone, a tablet, a laptop, a personal computer, a point-of-sale terminal, an air puff generating device, or a combination thereof.

3. 10. The computing device of claim 1, the adult consumer verification information includes at least the adult consumer's date of birth; The at least one processor further comprises: transmitting the adult consumer's name, the adult consumer's date of birth, and the adult consumer's mailing address via an encrypted communication channel to an identity verification server; a computing device configured to receive the results of the identity verification of the adult consumer via the encrypted channel.

4. 10. The computing device of claim 1, the UID of the RRD is a public key corresponding to the RRD; The computing device, wherein the UID of the RRD is embodied in at least one of a barcode, a QR code, an NFC tag, a Bluetooth tag, an RFID tag, a magnetic tag, a printed serial number, or a combination thereof.

5. 10. The computing device of claim 1, The at least one processor further comprises: receiving a unique ID (UID) of a dispersion product for the RRD, the dispersion product being configured to include a pre-dispersed formulation; generating a cryptographic key corresponding to the distributed product based on the result of the performed identity verification of the adult consumer and the UID of the distributed product; configured to transmit the encryption key corresponding to the distributed product to the RRD; The cryptographic key allows the RRD to operate the distributed product.

6. A Risk Reduced Device (RRD) for use with an identity verification service, said RRD being initially in an inoperable state; at least one transceiver configured to communicate with at least one computing device; a memory configured to store a private key corresponding to the RRD; a control circuit; the control circuitry receives an encryption key corresponding to the RRD from a computing device associated with the adult consumer, the encryption key being generated based on a unique ID (UID) corresponding to the RRD and the results of an identity verification performed on the adult consumer by an identity verification server; decrypting the encryption key using the private key; determining whether the adult consumer's identity was successfully verified based on the decrypted key; The RRD configured to change the state of the RRD to an operable state based on the result of a determination of whether the identity of the adult consumer has been successfully verified.

7. 7. The RRD according to claim 6, the UID of the RRD is a public key corresponding to the RRD; the UID of the RRD is embodied in at least one of a barcode, a QR code, an NFC tag, a Bluetooth tag, an RFID tag, a magnetic tag, a printed serial number, or a combination thereof; The control circuitry is further configured to change the state of the RRD to the operable state in response to a determination result indicating that the adult consumer meets the legal age requirement to operate the RRD.

8. 7. The RRD according to claim 6, The control circuit further comprises: In response to the RRD being in the inoperable state, cutting off current flowing from a power supply included in the RRD to a heater included in the RRD; The RRD is configured to allow current to flow from the power source to the heater in response to the RRD being in the operable state.

9. 7. The RRD according to claim 6, In response to the RRD being in the operable state, the control circuitry further determining whether the RRD is within a predetermined distance range of the computing device based on signals received from the computing device by the transceiver; An RRD configured to change the state of the RRD to the inoperable state based on determining whether the RRD is within the predetermined distance range of the computing device.

10. 7. The RRD according to claim 6, In response to the RRD being in the operable state, the control circuitry further Calculating the length of time the RRD is in the operational state; An RRD configured to change the state of the RRD to the inoperable state in response to a length of time exceeding a predetermined threshold operation time.

11. 7. The RRD according to claim 6, The control circuit further comprises: an RRD that changes the state of the RRD to the inoperable state in response to a radio blocking signal received by the at least one transceiver;

12. 1. An identification system comprising: a Risk Reduced Device (RRD) having a unique ID (UID) of the RRD and at least one transceiver, the RRD being initially in an inoperable state; an identity verification server configured to perform identity verification associated with the adult consumer; a computing device; the computing device receives, from the adult consumer, adult consumer identity information corresponding to the adult consumer; receiving the UID of the RRD; transmitting the adult consumer identity and the UID of the RRD to the identity verification server to perform identity verification of the adult consumer; receiving from the identity verification server a result of the performed identity verification; receiving a cryptographic key corresponding to the RRD based on the result of the performed identity verification of the adult consumer, the cryptographic key being generated based on the UID of the RRD; configured to transmit the encryption key to the RRD; The RRD is further configured to change the state of the RRD to an operational state based on the encryption key.

13. 13. The system of claim 12, the adult consumer verification information includes at least the adult consumer's date of birth; The identity verification server further receiving the adult consumer identity information from the computing device over an encrypted channel; performing said verification of the identity of said adult consumer by verifying said identity and said age of said adult consumer based on said adult consumer identity information; A system configured to transmit results of the identity verification of the adult consumer to the computing device over the encrypted channel.

14. 13. The system of claim 12, the UID of the RRD is a public key corresponding to the RRD; the RRD, a memory configured to store a private key associated with the RRD; The RRD further comprises: decrypting the encryption key using the stored private key; determining whether the identity of the adult consumer was successfully verified based on the decrypted key; A system configured to change the state of the RRD to the operational state based on the result of the determination.

15. 15. The system of claim 14, The RRD is further configured to change the state of the RRD to the operable state in response to a result of the determination indicating that the adult consumer meets the legal age requirement to operate the RRD.

16. 13. The system of claim 12, the RRD includes a control circuit, a heater, and a power source; The control circuit In response to the state of the RRD being in the inoperable state, preventing current from flowing from the power source to the heater; A system configured to allow current to flow from the power source to the heater in response to the state of the RRD being in the operational state.

17. 13. The system of claim 12, In response to the state of the RRD being the operable state, the control circuitry of the RRD further determining whether the RRD is within a predetermined distance range of the computing device based on signals received by the transceiver; A system configured to change the state of the RRD to the inoperable state based on a result of determining whether the RRD is within a predetermined distance range of the computing device.

18. 13. The system of claim 12, In response to the state of the RRD being the operational state, the RRD further: Calculating the length of time the RRD is in the operational state; A system configured to change the state of the RRD to the inoperable state in response to a length of time of operation exceeding a predetermined threshold.

19. 13. The system of claim 12, The RRD further comprises: Receives a radio disconnect signal; A system configured to change the state of the RRD to the inoperable state in response to the received wireless disconnect signal.

20. 13. The system of claim 12, The system, wherein the UID of the RRD is embodied in at least one of a barcode, a QR code, an NFC tag, a Bluetooth tag, an RFID tag, a magnetic tag, a printed serial number, or a combination thereof.