Aerosol generator with encrypted data management
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- PHILIP MORRIS PRODUCTS SA
- Filing Date
- 2023-05-22
- Publication Date
- 2026-05-29
AI Technical Summary
Existing aerosol generating devices face challenges in protecting usage data confidentiality and integrity due to complex and insecure encryption algorithms, which increase manufacturing costs and complexity, and expose manufacturers to data contamination and privacy breaches.
Each aerosol generating device is equipped with a unique identifier and a secret value to derive an encryption key, encrypting usage data locally, and transmitting it with the identifier to a server that can decrypt it using a stored secret value, ensuring secure data exchange without complex key exchange protocols.
This approach enhances data security by using simpler encryption methods, reducing complexity and costs, while preventing data manipulation and ensuring interoperability among devices, thus protecting user privacy and manufacturer data integrity.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an aerosol generating device, and in particular, to an aerosol generating device that creates, stores, and transmits usage data, as well as a system including the aerosol generating device and a server, a method for operating the aerosol generating device, a method for transmitting data from the aerosol generating device to the server, and a method for manufacturing the aerosol generating device.
Background Art
[0002] In aerosol generating devices such as electronic cigarettes, or risk-reduced devices that generate inhalable aerosols by heating a liquid or solid precursor material, usage data is created and stored during operation. The usage data can relate to both the functional operation and state of the device, as well as the consumer use of the device. Examples include aerosol generation, temperature, battery level, events, and errors. Some of this data may be communicated to a manufacturer server.
[0003] There are several reasons why it is desirable to protect the usage data thus created. First, data protection regulations may prescribe measures for protecting the privacy of customers. Furthermore, by ensuring the confidentiality of functional information, the manufacturer is protected from providing competitors with insights into how the device functions or is functioning. It also becomes possible to avoid opening the manufacturer's ecosystem to malicious or low-quality third-party services that degrade the customer experience. Additionally, ensuring the integrity and authenticity of the data collected on the manufacturer's servers protects these servers from being contaminated with false or corrupted information that has been uploaded maliciously or by mistake.
[0004] Therefore, it is necessary to protect the data stored in the aerosol generating device and ensure the confidentiality of data records both when transmitting inside and outside the device. Furthermore, it is necessary to protect the server that collects data from the aerosol generating device from being contaminated with false or corrupted information.
[0005] For data encryption, decryption, and authentication, there are numerous encryption algorithms known in the art. Many of these algorithms are computationally complex and are at least one of unsuitable or insecure for implementation in embedded systems.
Summary of the Invention
[0006] An object of the present invention is to provide an aerosol generating device having the ability to protect its usage data without unduly increasing complexity and manufacturing costs and without limiting its usefulness, as well as a corresponding method and system.
[0007] This is achieved by the features of the independent claims. Preferred embodiments are the subject matter of the dependent claims.
[0008] A specific approach of the present invention is to provide each aerosol generating device with a unique identifier and a secret value stored in the device. At least the secret value is used by the device to derive an encryption key for encrypting its usage data. The encrypted usage data and the unique identifier may be transmitted to the manufacturer server. The manufacturer server has access to a database that stores the secret value associated with the unique identifier. Therefore, the manufacturer server can obtain the secret value from the database and derive an encryption key for decrypting the encrypted usage data transmitted from the device.
[0009] According to a first aspect of the present invention, an aerosol generating device is provided that includes a storage unit having a secret value and a unique identification value therein. The aerosol generating device may further include a communication unit and a controller. The controller creates usage data indicating the use of the aerosol generating device, derives an encryption key from at least the stored secret value and optionally the unique identification value, encrypts the created usage data with the derived encryption key, stores the encrypted usage data in the storage unit, and is configured to transmit the encrypted usage data and the unique identification value to an external device via the communication unit.
[0010] According to a second aspect of the present invention, a method for operating an aerosol generating device is provided. The method includes storing a secret value and a unique identification value in a storage unit of the aerosol generating device, creating usage data indicating the use of the aerosol generating device, deriving an encryption key from at least the stored secret value, optionally encrypting the unique identification value and the created usage data with the derived encryption key, storing the encrypted usage data in the storage unit, and transmitting the encrypted usage data and the unique identification value to an external device via the communication unit.
[0011] By deriving the encryption key from the secret value stored in the aerosol generating device, there is no need to implement a complex protocol for key exchange between the aerosol generating device and an external device such as a manufacturer's server. By storing a unique identification value in the aerosol generating device and transmitting it together with the encrypted usage data to the external device, the external device can derive the appropriate encryption key even when different aerosol generating devices use different encryption keys to encrypt the usage data. Using different encryption keys for different aerosol generating devices ensures the security of the encrypted usage data of the aerosol generating device even if another aerosol generating device breaks or its secret value leaks.
[0012] In this specification, the term "derivation" is used to refer to obtaining or determining "A" (e.g., an encryption key) from "B" (e.g., a secret value). In one example, "A" is directly derived from "B" such that, for example, "A" is equal to "B" or "A" is at least part of "B". In another embodiment, "A" is indirectly derived from "B" by, for example, performing an operation on "B" to obtain "A".
[0013] The controller and / or method is preferably further adapted to derive an authentication key from at least a secret value and optionally a unique identification value to authenticate usage data stored with the derived authentication key.
[0014] Providing an (encrypted) authentication code to the usage data enables authentication of the usage data and detection of intentional or accidental modification. By deriving an authentication key from a secret value stored in the aerosol generator, no additional protocol is required to provide a dedicated authentication key for each aerosol generator.
[0015] The unique identification value preferably includes at least one of a product identifier, a platform identifier, a unique device identifier, and a manufacturing site identifier.
[0016] By providing product-related information instead of or in combination with a unique device identifier such as a serial number as the unique identification value, an external device can easily understand the type of aerosol generator it is communicating with.
[0017] The secret value is preferably a random value generated during the manufacturing stage of the aerosol generator.
[0018] Using a random number as a secret value has the advantage that the secret value of an aerosol generator cannot be derived from the (leaked) secret value of another aerosol generator, thus further strengthening the system against possible cryptographic attacks. Generating the secret value during the manufacturing stage of the aerosol generator enables taking appropriate precautions to secure a part of this confidential information.
[0019] The aerosol generator preferably further comprises a sensor for detecting the operating state of the aerosol generator. Accordingly, the controller and / or method may be adapted to create usage data based on the detected operating state. Various types of sensors may be used, in particular sensors configured to detect user interaction with the aerosol generator, sensors configured to detect smoking performed by the user of the aerosol generator, sensors configured to detect voltage, current, resistance, charge, energy or temperature related to the aerosol generating unit of the aerosol generator, sensors for detecting voltage, current, resistance, charge, energy or temperature related to the power supply of the aerosol generator, sensors for detecting voltage, current, resistance, charge, energy or temperature related to a charging device connected to the aerosol generator, and / or sensors for detecting the type or amount of consumable material used by the aerosol generating unit.
[0020] Accordingly, different types of sensors can detect different kinds of usage information that may be relevant to the user and / or the manufacturer. For example, the usage data may include at least one of the following displays.
[0021] Start time, duration, end time, or type of user interaction, Start time, duration, or end time of a single smoking or multiple smokings performed by the user of the aerosol generator, By connecting the aerosol generating device to the charging device, the start time, duration, or end time of the charging operation performed by the user, or the number of charging operations, and At the start, during, or end of smoking performed by the user of the aerosol generating device, the voltage, current, resistance, charge, energy, or temperature related to the aerosol generating unit of the aerosol generating device, At the start, during, or end of smoking performed by the user of the aerosol generating device, the voltage, current, resistance, charge, energy, or temperature related to the power supply of the aerosol generating device, At the start, during, or end of the charging operation, the voltage, current, resistance, charge, energy, or temperature related to the power supply of the aerosol generating device, The type or amount of consumable material used by the aerosol generating unit.
[0022] The controller and / or method is preferably adapted to store the encrypted usage data in the payload section of the data record. Each data record may include a header, a payload section, and an authentication section. Further, each header may include a first data field indicating the format of the data record and a second data field indicating the length of the data record.
[0023] By using a predetermined data format to store and / or transmit the usage data, it becomes possible to define the software interface between the aerosol generating device and the external device so that the software on the side of the aerosol generating device and the external device can be developed and maintained independently of each other. Further, different types of aerosol generating devices may use the same data format, thus improving the interoperability of different devices.
[0024] Preferably, each data record may also be associated with a recording index. Thus, the recording index may be used to manage a plurality of different data records stored within the aerosol generating device. The recording index may also be used (as part of) as a unique identifier (recording unique ID, RUID) for each data record transmitted from the aerosol generating device to an external device.
[0025] Each header preferably further includes a third data field indicating the number of times the recording index has rolled over. In this way, even when the recording index is only used internally by the aerosol generating device to manage data records, and even when part of the older data records have already been overwritten by more recent data records, each data record is uniquely identified.
[0026] The controller and / or method is preferably adapted to employ a symmetric key algorithm for encrypting the created usage data. AES is preferably used as the symmetric key algorithm.
[0027] The symmetric key algorithm is significantly less complex with respect to both key generation / distribution and encryption / decryption than algorithms based on asymmetric keys. Among conventional symmetric key algorithms, AES is a well-established algorithm particularly suitable for implementation in embedded systems.
[0028] The controller and / or method is preferably adapted to encrypt the created usage data by deriving an initialization vector from a secret value and / or a unique identification value and applying a block cipher in counter mode using the encryption key and the initialization vector.
[0029] Applying a block cipher in counter mode is a secure way to apply the block cipher to variable-length data blocks and enables a less complex implementation on both the encryption and decryption sides. By deriving the initialization vector of the counter mode from a secret value and / or a unique identifier value, there is no need to store and / or transmit additional information.
[0030] The controller and / or method is preferably adapted to use a hash-based key derivation function HKDF to derive the initialization vector from a secret value and / or a unique identifier value. Specifically, the controller and / or method preferably uses a salt containing at least one of at least a part of a predetermined value, the value of the record index associated with the data record containing the created usage data, the type of the data record, and the message authentication code MAC calculated for the created usage data to derive the initialization vector from the secret value and / or the unique identifier value.
[0031] HKDF provides a secure means for deriving a primary material of any length from a limited-length input primary material. Security is further improved by using a salt containing a predetermined value, in particular by using a salt containing at least one of at least a part of the value of the record index associated with the data record containing the created usage data, the type of the data record, and the message authentication code MAC calculated for the created usage data. In this way, different initialization vectors are used for different data records, thus further strengthening the system against decryption by dramatically reducing the amount of ciphertext encrypted with the same key. Ensuring that the initialization vector is derived or constructed from the characteristics of the payload protects against generating repeated initialization vectors in the case of an attack that may succeed in forcing a repeated record index or unique record identifier (RUID).
[0032] The controller and / or method is preferably adapted to authenticate the created usage data by calculating a message authentication code MAC for the created usage data. Specifically, the controller and / or method may be configured to calculate the MAC of the created usage data from the created usage data and from a first authentication key.
[0033] Calculating the MAC for the created usage data, i.e., the plain text usage data, enables the use of the MAC as an additional input to a key derivation function, thus ensuring that different keys and / or initialization vectors are used for different items of the usage data.
[0034] The controller and / or method is preferably adapted to authenticate the encrypted usage data by calculating a MAC for the encrypted usage data. Specifically, the controller and / or method may be adapted to calculate the MAC for the encrypted usage data from the encrypted usage data and a second authentication key. The controller and / or method may also be adapted to calculate the MAC for the encrypted usage data from the encrypted usage data, from the MAC of the created usage data, and from a second authentication key.
[0035] Calculating the MAC for the encrypted usage data further strengthens the system against decryption, since it can already detect data records that have been tampered with before decryption, instead of or in addition to the MAC for the plain text usage data. In this way, cryptographic attacks based on the manipulated ciphertext can be thwarted. By calculating the MAC for the encrypted usage data not only from the encrypted usage data and the second authentication key, but also from the MAC of the created usage data, the MAC of the created usage data can also be authenticated, further improving security against spoofing attacks.
[0036] The controller and / or method is preferably adapted to derive a first authentication key and / or a second authentication key from a secret value and / or a unique identification value.
[0037] By deriving the authentication key from the secret value stored in the aerosol generator, no additional protocol is required to provide an authentication key dedicated to each aerosol generator.
[0038] The controller and / or method is preferably adapted to use a hash function to calculate a MAC for the created usage data and / or a MAC for the encrypted usage data. Further, the controller and / or method may be further adapted to calculate a MAC for the created usage data and / or a MAC for the encrypted usage data by truncating the output of the hash function to a predetermined number of bytes. Further, the controller and / or method may be further adapted to store the MAC for the created usage data and / or the MAC for the encrypted usage data in the storage unit together with the encrypted usage data.
[0039] Using a limited number of bytes truncated from the output of the hash function, particularly 2 bytes, 3 bytes, or 4 bytes, as the MAC for the created usage data and / or the MAC for the encrypted usage data provides an optimal compromise between the amount of extra storage capacity required to store the MAC and the level of security that can be achieved to prevent unauthorized opening of the usage data.
[0040] The controller and / or method is preferably adapted to employ a hash-based key derivation function (HKDF) to derive at least one of an encryption key for encrypting usage data created from a secret value and / or a unique identification value, an initialization vector for encrypting usage data created with a block cipher in counter mode, and an authentication key for authenticating the usage data. Specifically, at least a portion of the secret value and / or the unique identification value can be used as input key material for the key derivation function.
[0041] The hash-based key derivation function is a particularly efficient means for cryptographically deriving a secure key from a limited amount of input key material. Involving at least a portion of the secret value and / or the unique identification value in the process for deriving the encryption key, the initialization vector, or the authentication key ensures that each aerosol generating device uses a different key for encrypting and / or authenticating its user data. Thus, the overall security of a system comprising a plurality of aerosol generating devices is significantly improved by reducing the amount of ciphertext that is coded and / or authenticated with the same key.
[0042] A salt is preferably used together with at least a portion of the secret value and / or the unique identification value as input key material for the key derivation function. Additionally, a fixed salt may be used for deriving the encryption key and / or the authentication key.
[0043] Using a salt, i.e., random data used as additional input to the hash function, further improves the cryptographic security, particularly by strengthening the system against attacks based on pre-computed hash chains.
[0044] A predetermined subset of the bit representation of the secret value, together with a unique identification value and a salt, may preferably be used as input key material for a key derivation function. Further, a predetermined subset of the bit representation of the secret value used as input key material for deriving an encryption key and / or an authentication key is preferably different from a predetermined subset of the bit representation of the secret value used as input key material for deriving an initialization vector.
[0045] Deriving the encryption key and the authentication key from different subsets of the bit representation of the secret value can further strengthen the system against decryption.
[0046] At least a part of the message authentication code MAC calculated from the created usage data is preferably used as a salt for deriving the initialization vector.
[0047] In this way, different salts are used to derive initialization vectors for different usage data items, thus effectively resulting in different keys for encrypting these usage data items.
[0048] A first part of the output key material generated by the key derivation function is preferably used as the encryption key, and a second part of the output key material different from the first part is preferably used as the authentication key.
[0049] In this way, a single call to the key derivation function is sufficient to generate both the encryption key and the authentication key.
[0050] The controller and / or method is preferably adapted to transmit the encrypted usage data together with an authentication code of the encrypted usage data via a communication unit to an external device.
[0051] In this way, the external device can verify the authentication code of the encrypted data to authenticate the transmitted usage data.
[0052] In the context of the present disclosure, the external device may be any device that can be communicatively coupled to the aerosol generating device, such as a charging station, a docking station, a mobile terminal, a personal computer, a host computer, and a server. Further, the data communication between the aerosol generating device and the external device may be based on any suitable communication protocol and / or medium, including but not limited to a data cable, short-range wireless communication, Bluetooth, BLE, and WiFi.
[0053] According to a third aspect of the present invention, there is provided an aerosol generation system comprising an aerosol generating device according to a first aspect of the present invention, a database configured to store a unique identification value for each of a plurality of aerosol generating devices in relation to a secret value of the aerosol generating device, and a server. The server is configured to receive encrypted usage data and a unique identification value of the aerosol generating device from the aerosol generating device, use the unique identification value to obtain a secret value associated with the unique identification value from the database, and use the obtained secret value to decrypt the encrypted usage data.
[0054] By providing a database that stores the unique identification value of each of the plurality of aerosol generating devices in relation to its respective secret value, the server can use the unique identification value received from the aerosol generating device to obtain the corresponding secret value. Once the server has the secret value, it can decrypt the encrypted data received from the aerosol generating device. In this way, a secure exchange can be established between the aerosol generating device and the server without including the secret value in any of the messages exchanged between the server and the aerosol generating device, without implementing a complex algorithm for secure key exchange, and without establishing an encrypted secure channel.
[0055] According to a fourth aspect of the present invention, there is provided a method of manufacturing an aerosol generating device according to the first aspect of the present invention. The method includes generating a secret value and a unique identification value, writing the secret value and the unique identification value into a storage unit of the aerosol generating device, and storing, for each of a plurality of aerosol generating devices, the secret value associated with the unique identification value in a database.
[0056] By providing the secret value and the unique identification value to each aerosol generating device, the aerosol generating device can encrypt its usage data with a device-specific key. At the same time, the aerosol generating device can identify itself in a communication session with the server by the unique identification value. By storing the unique identification value of each of the plurality of aerosol generating devices in association with each secret value in the database, the server can use the unique identification value received from the aerosol generating device to obtain the corresponding secret value and use the obtained secret value to decrypt the usage data. In this way, a secure exchange can be carried out between the server and the aerosol generating device without establishing an encrypted secure channel, without including the secret value in any of the messages exchanged between the server and the aerosol generating device, and without implementing a complex algorithm for secure key exchange.
[0057] The unique identification value preferably includes at least one of a product identifier, a platform identifier, a unique device identifier, and a manufacturing site identifier.
[0058] By providing product-related information instead of or in combination with a unique device identifier such as a serial number as the unique identification value, the server can easily understand the type of the aerosol generating device being communicated with.
[0059] The secret value is preferably a random number generated by the aerosol generating device during the manufacturing stage.
[0060] Using a random number as a secret value has the advantage that the secret value of an aerosol generator cannot be derived from the (leaked) secret value of another aerosol generator, and thus further strengthens the system against possible cryptographic attacks. Generating the secret value during the manufacturing stage of the aerosol generator enables appropriate precautions to be taken to secure part of this confidential information.
[0061] The method may also include the step of transmitting the generated random number from the aerosol generator to the host computer, preferably in encrypted form. The host computer may then take care to store the secret value in association with a unique identification value in the database.
[0062] According to a fifth aspect of the present invention, a method for transmitting usage data from an aerosol generator to a host is provided. The aerosol generator has stored therein a secret value and a unique identification value. The method includes the steps of receiving, at the host, the unique identification value from the aerosol generator, and obtaining the secret value of the aerosol generator from a database storing the respective secret values of a plurality of aerosol generators in association with their respective unique identification values. The method also includes the step of deriving, at the host, an encryption key from at least the obtained secret value and optionally the received unique identification value. The method further includes the steps of receiving, at the host, the encrypted usage data from the aerosol generator, and decrypting the received encrypted usage data with the encryption key.
[0063] By transmitting only the unique identification value from the aerosol generator to the host and obtaining the secret value of the aerosol generator from the database, secure data exchange can be implemented between the aerosol generator and the host without establishing an encrypted secure channel, and without including the secret value in any of the messages exchanged between the host and the aerosol generator, and without implementing a complex algorithm for secure key exchange.
[0064] The method preferably further includes, at the host, deriving an authentication key from at least the obtained secret value and optionally from a unique identification value, receiving, at the host, a first message authentication code MAC together with encrypted usage data from an aerosol generator, calculating a second MAC from the decrypted usage data and the derived authentication key, and comparing the first MAC with the second MAC.
[0065] By computing, at the host, a second MAC from the decrypted usage data and comparing this MAC with the first MAC received together with the encrypted usage data, the host can authenticate the received usage data, detect inadvertent modification to the received usage data, and prevent spoofing attacks by malicious devices.
[0066] The method preferably further includes deriving an initialization vector, and the received encrypted usage data is preferably decrypted by applying a block cipher in counter mode using an encryption key and the initialization vector. Further, the initialization vector can preferably be derived from the unique identification value, the secret value, and the first MAC.
[0067] In this way, the encrypted usage data can be decrypted even when a block cipher is applied in counter mode, which is a secure way for the aerosol generator to apply the block cipher to variable-length data blocks and enables a less complex implementation on both the encoder side and the decoder side.
[0068] The encrypted usage data is preferably included in a payload section of a data record having a unique record identifier. In this case, the initialization vector can preferably be derived from the unique identification value, the secret value, the first MAC, and the unique record identifier.
[0069] In this way, the unique record identifier can be used to further improve data security by requesting specific usage information from the aerosol generator and / or by effectively using different keys for different data records.
[0070] According to a sixth aspect of the invention, there is provided a host computer having a processing unit and a memory storing computer-readable instructions adapted to perform all steps of the method according to the fifth aspect of the invention when executed by the processing unit.
[0071] The present invention is defined in the claims. However, a non-exhaustive list of non-limiting examples is provided below. Any one or more of the features of these examples may be combined with any one or more of the features of any other example, embodiment, or aspect described herein.
[0072] Example 1: An aerosol generator comprising a storage unit storing a secret value and a unique identification value therein, a communication unit, and a controller configured to create usage data indicating the use of the aerosol generator, derive an encryption key from at least the stored secret value and optionally the unique identification value, encrypt the created usage data with the derived encryption key, store the encrypted usage data in the storage unit, and transmit the encrypted usage data and optionally the unique identification value to an external device via the communication unit.
[0073] Example 2: The aerosol generator according to Example 1, wherein the controller is further configured to derive an authentication key from at least the secret value and optionally the unique identification value and authenticate the stored usage data with the derived authentication key.
[0074] Example 3: The aerosol generator according to any one of Examples 1 to 2, wherein the unique identification value includes at least one of a product identifier, a platform identifier, a unique device identifier, and a manufacturing site identifier.
[0075] Example 4: The aerosol generator according to any one of Examples 1 to 3, wherein the secret value is a random value generated during the manufacturing stage of the aerosol generator.
[0076] Example 5: The aerosol generator according to any one of Examples 1 to 4, further comprising a sensor for detecting an operating state of the aerosol generator.
[0077] Example 6: The aerosol generator according to any one of Examples 1 to 5, wherein the controller is configured to create usage data based on the detected operating state.
[0078] Example 7: The aerosol generator according to any one of Examples 1 to 6, wherein the sensor is one of a sensor configured to detect user interaction with the aerosol generator, a sensor configured to detect smoking performed by a user of the aerosol generator, a sensor configured to detect voltage, current, resistance, charge, energy or temperature related to the aerosol generating unit of the aerosol generator, a sensor for detecting voltage, current, resistance, charge, energy or temperature related to the power supply of the aerosol generator, a sensor for detecting voltage, current, resistance, charge, energy or temperature related to a charging device connected to the aerosol generator, and a sensor for detecting the type or amount of consumable material used by the aerosol generating unit.
[0079] Example 8: A display in which the usage data includes at least one of a start time, a duration, an end time, or a type of user interaction, and the start time, duration, or end time of a single smoking or multiple smokings performed by a user of the aerosol generating device, and the start time, duration, or end time, or the number of charging operations, of a charging operation performed by the user by connecting the aerosol generating device to a charging device, and the voltage, current, resistance, charge, energy, or temperature related to the aerosol generating unit of the aerosol generating device at the start, during, or end of a smoking performed by the user of the aerosol generating device, and the voltage, current, resistance, charge, energy, or temperature related to the power supply of the aerosol generating device at the start, during, or end of a smoking performed by the user of the aerosol generating device, and the voltage, current, resistance, charge, energy, or temperature related to the power supply of the aerosol generating device at the start, during, or end of a charging operation, and the type or amount of consumable material used by the aerosol generating unit. The aerosol generating device according to any one of Examples 1 to 7.
[0080] Example 9: The aerosol generating device according to any one of Examples 1 to 8, wherein the controller is configured to store the encrypted usage data in the payload section of the data record.
[0081] Example 10: The aerosol generating device according to any one of Examples 1 to 9, wherein each data record includes a header, a payload section, and an authentication section.
[0082] Example 11: The aerosol generating device according to any one of Examples 1 to 10, wherein each header includes a first data field indicating the format of the data record and a second data field indicating the length of the data record.
[0083] Example 12: The aerosol generating device according to Example 11, wherein each data record is associated with a recording index.
[0084] Example 13: The aerosol generator according to any one of Examples 1 to 12, wherein each header further includes a third data field indicating the number of times the recording index has rolled over.
[0085] Example 14: The aerosol generator according to any one of Examples 1 to 13, wherein the controller is configured to employ a symmetric key algorithm for encrypting the generated usage data.
[0086] Example 15: The aerosol generator according to any one of Examples 1 to 14, wherein AES is employed as the symmetric key algorithm.
[0087] Example 16: The aerosol generator according to any one of Examples 1 to 15, wherein the controller is further configured to encrypt the created usage data by deriving an initialization vector from a secret value and / or a unique identification value and applying a block cipher in counter mode using the encryption key and the initialization vector.
[0088] Example 17: The aerosol generator according to any one of Examples 1 to 16, wherein the controller is configured to employ a hash-based key derivation function HKDF to derive the initialization vector from a secret value and / or a unique identification value.
[0089] Example 18: The aerosol generator according to any one of Examples 1 to 17, wherein the controller is configured to derive the initialization vector from a secret value and / or a unique identification value using a sort that includes at least one of at least a part of a predetermined value, the value of the recording index associated with the data record including the created usage data, the type of the data record, and a message authentication code MAC calculated from the created usage data.
[0090] Example 19: The aerosol generator according to any one of Examples 1 to 18, wherein the controller is further configured to authenticate the created usage data by calculating a message authentication code MAC for the generated usage data.
[0091] Example 20: The aerosol generator according to any one of Examples 1 to 19, wherein the controller is further configured to calculate a MAC for the created usage data from the created usage data and from the first authentication key.
[0092] Example 21: The aerosol generator according to any one of Examples 1 to 20, wherein the controller is further configured to authenticate the encrypted usage data by calculating a MAC for the encrypted usage data.
[0093] Example 22: The aerosol generator according to any one of Examples 1 to 21, wherein the controller is further configured to calculate a MAC for the encrypted usage data from the encrypted usage data and the second authentication key.
[0094] Example 23: The aerosol generator according to any one of Examples 1 to 22, wherein the controller is further configured to calculate a MAC for the encrypted usage data from the encrypted usage data, from the MAC of the created usage data, and from the second authentication key.
[0095] Example 24: The aerosol generator according to any one of Examples 20 to 23, wherein the controller is further configured to derive the first authentication key and / or the second authentication key from a secret value and / or a unique identification value.
[0096] Example 25: The aerosol generator according to any one of Examples 19 to 24, wherein the controller is further configured to employ a hash function for calculating a MAC for the created usage data and / or a MAC for the encrypted usage data.
[0097] Example 26: The aerosol generator according to any one of Examples 1 to 25, wherein the controller is further configured to calculate a MAC for the created usage data and / or a MAC for the encrypted usage data by truncating the output of the hash function to a predefined number of bytes.
[0098] Example 27: The aerosol generator according to any one of Examples 19 to 26, wherein the controller is further configured to store the MAC for the created usage data and / or the MAC for the encrypted usage data in the storage unit together with the encrypted usage data.
[0099] Example 28: The aerosol generator according to any one of Examples 1 to 27, wherein the controller is further configured to employ a hash-based key derivation function (HKDF) to derive at least one of an encryption key for encrypting the created usage data, an initialization vector for encrypting the created usage data with a block cipher in counter mode, and an authentication key for authenticating the usage data from a secret value and / or a unique identification value.
[0100] Example 29: The aerosol generator according to any one of Examples 1 to 28, wherein at least a part of the secret value and / or the unique identification value is used as input key material for the key derivation function.
[0101] Example 30: The aerosol generator according to any one of Examples 1 to 29, wherein a salt is used together with at least a part of the secret value and / or the unique identification value as input key material for the key derivation function.
[0102] Example 31: The aerosol generator according to Examples 28 to 30, wherein a predetermined subset of the bit representation of the secret value is used together with the unique identification value and the salt as input key material for the key derivation function.
[0103] Example 32: An aerosol generator according to any one of Examples 1 to 31, wherein a predetermined subset of the bit representation of the secret value used as the input key material for deriving the encryption key and / or the authentication key is different from the predetermined subset of the bit representation of the secret value used as the input key material for deriving the initialization vector.
[0104] Example 33: An aerosol generator according to any one of Examples 28 to 32, wherein a fixed salt is used for deriving the encryption key and / or the authentication key.
[0105] Example 34: An aerosol generator according to any one of Examples 28 to 33, wherein at least a part of the message authentication code MAC calculated from the generated usage data is used as a salt for deriving the initialization vector.
[0106] Example 35: An aerosol generator according to any one of Examples 28 to 34, wherein the first part of the output key material generated by the key derivation function is used as the encryption key, and the second part of the output key material different from the first part is used as the authentication key.
[0107] Example 36: An aerosol generator according to any one of Examples 1 to 35, wherein the controller is further configured to transmit the encrypted usage data together with the authentication code of the encrypted usage data via the communication unit.
[0108] Example 37: An aerosol generator according to any one of Examples 1 to 36, wherein the external device is any one of a charging station, a docking station, a mobile terminal, a personal computer, a host computer, and a server.
[0109] Example 38: An aerosol generator according to any one of Examples 1 to 37, wherein the encrypted usage data is transmitted via any one of a data cable, short-range wireless communication, Bluetooth, BLE, and WiFi.
[0110] Example 39: An aerosol generation system, comprising: an aerosol generator according to any one of Examples 1 to 38; a database configured to store unique identification values for each of a plurality of aerosol generators in relation to the secret value of the aerosol generator; and a server configured to receive, from the aerosol generator, the encrypted usage data and the unique identification value of the aerosol generator, obtain, using the unique identification value, the secret value associated with the unique identification value from the database, and decrypt the encrypted usage data using the obtained secret value.
[0111] Example 40: A method of operating an aerosol generator, the method comprising: storing a secret value and a unique identification value in a storage unit of the aerosol generator; generating usage data indicating the use of the aerosol generator; deriving an encryption key from at least the stored secret value; encrypting the generated usage data with the derived encryption key; storing the encrypted usage data in the storage unit; and transmitting the encrypted usage data and the unique identification value to an external device via a communication unit.
[0112] Example 41: The method according to Example 40, further comprising: deriving an authentication key from at least the secret value and optionally the unique identification value; and authenticating the stored usage data with the derived authentication key.
[0113] Example 42: The method according to any one of Examples 1 to 41, wherein the unique identification value includes at least one of a product identifier, a platform identifier, a unique device identifier, and a manufacturing site identifier.
[0114] Example 43: The method according to any one of Examples 1 to 43, further comprising generating a random value as the secret value during the manufacturing stage of the aerosol generator.
[0115] Example 44: The method according to any one of Examples 1 to 43, including the step of detecting the operating state of the aerosol generator.
[0116] Example 45: The aerosol generator according to any one of Examples 1 to 44, wherein usage data is created based on the detected operating state.
[0117] Example 46: Detecting the operating state includes at least one of detecting user interaction with the aerosol generator, detecting smoking performed by the user of the aerosol generator, detecting voltage, current, resistance, charge, energy or temperature related to the aerosol generating unit of the aerosol generator, detecting voltage, current, resistance, charge, energy or temperature related to the power supply of the aerosol generator, detecting voltage, current, resistance, charge, energy or temperature related to a charging device connected to the aerosol generator, and detecting the type or amount of consumable material used by the aerosol generating unit. The method according to any one of Examples 1 to 45.
[0118] Example 47: A method according to any one of Examples 1 to 46, wherein the usage data includes a display including at least one of a start time, a duration, an end time, or a type of user interaction, and the start time, duration, or end time of one or multiple smoking sessions performed by a user of the aerosol generating device, and the start time, duration, or end time of a charging operation performed by the user by connecting the aerosol generating device to a charging device, or the number of charging operations, and the voltage, current, resistance, charge, energy, or temperature associated with the aerosol generating unit of the aerosol generating device at the start, during, or end of a smoking session performed by a user of the aerosol generating device, and the voltage, current, resistance, charge, energy, or temperature associated with the power supply of the aerosol generating device at the start, during, or end of a smoking session performed by a user of the aerosol generating device, and the voltage, current, resistance, charge, energy, or temperature associated with the power supply of the aerosol generating device at the start, during, or end of a charging operation, and the type or amount of consumable material used by the aerosol generating unit.
[0119] Example 48: A method according to any one of Examples 1 to 47, wherein the encrypted usage data is stored in the payload section of the data record.
[0120] Example 49: A method according to any one of Examples 1 to 48, wherein each data record includes a header, a payload section, and an authentication section.
[0121] Example 50: A method according to any one of Examples 1 to 49, wherein each header includes a first data field indicating the format of the data record and a second data field indicating the length of the data record.
[0122] Example 51: A method according to any one of Examples 1 to 50, wherein each data record is associated with a record index.
[0123] Example 52: The method according to any one of Examples 1 to 51, wherein each header further includes a third data field indicating the number of times the recording index has rolled over.
[0124] Example 53: The method according to any one of Examples 1 to 52, wherein a symmetric key algorithm is used to encrypt the generated usage data.
[0125] Example 54: The method according to any one of Examples 1 to 53, wherein AES is used as the symmetric key algorithm.
[0126] Example 55: The method according to any one of Examples 1 to 54, further comprising the steps of deriving an initialization vector from a secret value and / or a unique identification value, and encrypting the created usage data by applying a block cipher in counter mode using an encryption key and the initialization vector.
[0127] Example 56: The method according to any one of Examples 1 to 55, wherein the hash-based key derivation function HKDF is used to derive the initialization vector from a secret value and / or a unique identification value.
[0128] Example 57: The method according to any one of Examples 1 to 56, wherein the initialization vector is derived from a secret value and / or a unique identification value having a sort including at least one of at least a part of a predefined value, a value of a recording index associated with a data record including the created usage data, a type of the data record, and a message authentication code MAC calculated from the created usage data.
[0129] Example 58: The method according to any one of Examples 1 to 57, further comprising the step of authenticating the created usage data by calculating a message authentication code MAC for the generated usage data.
[0130] Example 59: The method according to any one of Examples 1 to 58, wherein the MAC for the created usage data is calculated from the created usage data and from the first authentication key.
[0131] Example 60: The method according to any one of Examples 1 to 59, further comprising the step of authenticating the encrypted usage data by calculating a MAC for the encrypted usage data.
[0132] Example 61: The method according to any one of Examples 1 to 60, wherein the MAC for the encrypted usage data is calculated from the encrypted usage data and the second authentication key.
[0133] Example 62: The method according to any one of Examples 1 to 61, further comprising the step of calculating the MAC of the encrypted usage data from the encrypted usage data, from the MAC of the created usage data, and from the second authentication key.
[0134] Example 63: The method according to any one of Examples 59 to 62, further comprising the step of deriving the first authentication key and / or the second authentication key from a secret value and / or a unique identification value.
[0135] Example 64: The method according to any one of Examples 58 to 63, wherein a hash function is used to calculate the MAC for the created usage data and / or the MAC for the encrypted usage data.
[0136] Example 65: The method according to any one of Examples 1 to 64, wherein the MAC for the created usage data and / or the MAC for the encrypted usage data is calculated by truncating the output of the hash function to a predetermined number of bytes.
[0137] Example 66: The method according to any one of Examples 58 to 65, further comprising the step of storing the MAC for the created usage data and / or the MAC for the encrypted usage data together with the encrypted usage data.
[0138] Example 67: The method according to any one of Examples 1 to 66, further comprising the step of employing a hash-based key derivation function HKDF for deriving at least one of an encryption key for encrypting usage data created from a secret value and / or a unique identification value, an initialization vector for encrypting usage data created with a block cipher in counter mode, and an authentication key for authenticating the usage data.
[0139] Example 68: The method according to any one of Examples 1 to 67, wherein at least a part of the secret value and / or the unique identification value is used as input key material for the key derivation function.
[0140] Example 69: The method according to any one of Examples 1 to 68, wherein a salt is used together with at least a part of the secret value and / or the unique identification value as input key material for the key derivation function.
[0141] Example 70: The method according to Example 67, wherein a predetermined subset of the bit representation of the secret value is used as input key material for the key derivation function together with the unique identification value and the salt.
[0142] Example 71: The method according to any one of Examples 1 to 70, wherein a predetermined subset of the bit representation of the secret value used as input key material for deriving the encryption key and / or the authentication key is different from a predetermined subset of the bit representation of the secret value used as input key material for deriving the initialization vector.
[0143] Example 72: The method according to any one of Examples 67 to 71, wherein a fixed salt is used for deriving the encryption key and / or the authentication key.
[0144] Example 73: The method according to any one of Examples 67 to 72, wherein at least a part of the message authentication code MAC calculated from the generated usage data is used as a salt for deriving the initialization vector.
[0145] Example 74: The method according to any one of Examples 67 to 73, wherein a first portion of the output key material generated by the key derivation function is used as the encryption key, and a second portion of the output key material different from the first portion is used as the authentication key.
[0146] Example 75: The method according to any one of Examples 1 to 74, wherein the encrypted usage data is transmitted together with an authentication code of the encrypted usage data.
[0147] Example 76: The method according to any one of Examples 1 to 75, wherein the external device is any one of a charging station, a docking station, a mobile terminal, a personal computer, a host computer, and a server.
[0148] Example 77: The method according to any one of Examples 1 to 76, wherein the encrypted usage data is transmitted via any one of a data cable, short-range wireless communication, Bluetooth, BLE, and WiFi.
[0149] Example 78: The method for manufacturing an aerosol generator according to any one of Examples 1 to 77, the method including generating a secret value and a unique identification value, writing the secret value and the unique identification value into a storage unit of the aerosol generator, and storing, in a database, the secret value associated with the unique identification value for each of a plurality of aerosol generators.
[0150] Example 79: The method according to any one of Examples 1 to 78, wherein the unique identification value includes at least one of a product identifier, a platform identifier, a unique device identifier, and a manufacturing site identifier.
[0151] Example 80: The method according to Example 78 or 79, wherein the secret value is a random number generated by the aerosol generator during the manufacturing stage.
[0152] Example 81: The method according to any one of Examples 1 to 80, further comprising transmitting the generated random number from the aerosol generator to the host computer.
[0153] Example 82: The method according to any one of Examples 1 to 82, wherein the generated random number is transmitted from the aerosol generator to the host computer in an encrypted form.
[0154] Example 83: A method for transmitting usage data from an aerosol generator to a host, wherein the aerosol generator stores a secret value and a unique identification value therein, the method comprising: receiving, at the host, the unique identification value from the aerosol generator; obtaining, from a database stored therein, the secret value of each of a plurality of aerosol generators in association with each respective unique identification value; deriving, at the host, an encryption key from at least the obtained secret value and optionally the received unique identification value; receiving, at the host, the encrypted usage data from the aerosol generator; and decrypting the received encrypted usage data with the encryption key.
[0155] Example 84: The method according to any one of Examples 1 to 83, further comprising: deriving, at the host, an authentication key from at least the obtained secret value and optionally the unique identification value; receiving, at the host, a first message authentication code MAC together with the encrypted usage data from the aerosol generator; calculating, at the host, a second MAC from the decrypted usage data and the derived authentication key; and comparing the first MAC and the second MAC.
[0156] Example 85: The method according to any one of Examples 1 to 84, further comprising deriving an initialization vector, wherein the received encrypted usage data is decrypted by applying a block cipher in counter mode using the encryption key and the initialization vector.
[0157] Example 86: The method according to any one of Examples 1 to 85, wherein the initialization vector is derived from a unique identification value, a secret value, and a first MAC.
[0158] Example 87: The method according to any one of Examples 1 to 86, wherein the encrypted usage data is included in the payload section of a data record having a unique record identifier.
[0159] Example 88: The method according to any one of Examples 1 to 87, wherein the initialization vector is derived from a unique identification value, a secret value, a first MAC, and a unique record identifier.
[0160] Example 89: A host computer having a processing unit and a memory storing computer-readable instructions thereon adapted to perform all steps of the method according to any one of Examples 83 to 88 when executed by the processing unit.
[0161] Hereinafter, the examples will be further described with reference to the drawings.
Brief Description of the Drawings
[0162]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
DETAILED DESCRIPTION OF THE INVENTION
[0163] FIG. 1 shows a block diagram of an aerosol generating device (100) according to an embodiment of the present invention. The aerosol generating device (100) may include an aerosol generating unit (110), a sensor (120), a communication unit sensor (130), a storage unit (140), a communication unit (150), and a power source (160).
[0164] The aerosol generating unit (110) is a unit for generating an aerosol for inhalation by a user of the aerosol generating device from a precursor material (consumable material). As an example, the aerosol generating unit (110) may include an atomizer or a heating element. The precursor material may be provided in a liquid or solid form. The aerosol generating unit (110) is powered by electrical energy provided by the power source (160) and is controlled by the controller (130).
[0165] The sensor (120) delivers data that can be used to control the operation of the aerosol generating device. For example, the sensor may be configured to detect user interactions with the aerosol generating device, such as pressing a button, opening and closing a receptacle for a precursor material, or performing a gesture by moving the device in a particular manner. The sensor may also be configured to detect smoking performed by a user of the aerosol generating device. In another embodiment, the sensor may be configured to detect a voltage, current, resistance, charge, energy, or temperature associated with the operation of the aerosol generating unit (110). The sensor may also be configured to detect a voltage, current, resistance, charge, energy, or temperature associated with the power supply (160) of the aerosol generating device and / or a charging device connected to the aerosol generating device. In a further embodiment, the sensor may be configured to detect the type or amount of consumable material used by the aerosol generating unit (110).
[0166] The controller (130) is responsible for controlling the overall operation of the aerosol generating device, in particular, operating the aerosol generating unit (110) based on data delivered by the sensor (120), creating, encrypting, and storing usage data in the storage unit (140), receiving and transmitting data via the communication unit (150), monitoring and / or controlling the charging of the power supply (160), and the like. The controller (130) may be a microprocessor, a microcontroller, or a combination of multiple microprocessors and / or microcontrollers. The controller (130) may also be provided with storage for storing computer program instructions and / or memory for storing data related to the execution of a computer program.
[0167] The memory unit (140) is connected to the controller (130) and stores therein a unique identifier (142) and a secret value (144), which may be used by the controller for encrypting usage data. The memory unit (140) is further adapted to store the encrypted usage data created by the controller (130). The memory unit may be volatile or non-volatile. As an example, a flash memory is provided as the memory unit. The memory unit may be an integral part of a microcontroller or a component external to the controller. The memory unit may comprise a plurality of physically or logically separated storage sections or components for storing different data items. The unique identifier (142), the secret value (144), and the encrypted usage data (144) may be stored, for example, in different sections or components of the memory unit (140). The secret value may be stored in a section or component that is particularly protected against unauthorized access.
[0168] The unique identifier (142) is part of data unique to each aerosol generator device, for example, a unique device identity. For example, each aerosol generator device may be provided with a unique serial number stored as a unique identifier within the memory unit (140). The unique identifier may also include, in addition to or instead of the serial number, information indicating at least one of a product identifier, a platform identifier, and a manufacturing site. The unique identifier may also be provided as a unique manufacturing information block (or manufacturing facility ID), as a MIB, that is, a data block containing information regarding the manufacturing process such as a product ID, a platform ID, a unique ID (or serialized device unit ID), and a manufacturing site.
[0169] The secret value (144) is a value used by the controller to derive an encryption key for encrypting usage data. The secret value is secret in the sense that it is generally not known to the user or any other unauthorized person, and is also secret in the sense that it cannot be (easily) derived from the aerosol generator or the transmitted data. The secret value is also not included in any data transmissions during normal operation. The secret value may be stored in a particularly secure part of the memory unit (140) that is not accessible to any external device.
[0170] The secret value is also stored in a database accessible by the manufacturer's server, in association with each unique identifier. In this way, the server may use the unique identifier in a lookup operation to obtain the secret value of a particular aerosol generator in order to derive the encryption key used to encrypt the usage data of the device. The server can then decrypt the encrypted usage data transmitted from this particular device using the thus-derived encryption key.
[0171] The secret value may be large enough to prevent a brute-force attack on the encrypted data. For example, the secret value may contain 8, 16, 32, 64, 128, or 256 bytes of data. Other sizes of secret values, which are powers of two or which contain sizes different from powers of two, may also be used.
[0172] As an example, a random or pseudo-random number generated during the manufacturing process may be used as the secret value. The secret value is generated by the aerosol generator during the manufacturing process and may be transmitted, preferably in encrypted form, to a host computer that stores the secret value in association with a unique identifier in a database for later reference by the manufacturer's server. The secret value may also be generated by the host computer and transmitted or written directly to the memory unit (140) during a stage of the manufacturing process.
[0173] The encrypted usage data (146) is usage data created by the controller and stored in the storage unit (140) in encrypted form. The usage data indicates the use of the aerosol generating device and may be data generated by the device in response to a specific event. Examples include data generated by device errors, aerosol generation, or battery recharging. For example, the usage data may include a display of at least one of a start time, a duration, an end time, and the type of interaction the user has with the aerosol generating device, such as pressing a button, opening and closing a receptacle for a precursor material, performing a gesture by moving the device in a specific manner, etc. The usage data may also include a display of at least one of the start time, duration, and end time of a single smoking or multiple smokings performed by the user of the aerosol generating device. The usage data may also include a display of at least one of the start time, duration, and end time of a charging operation, or the number of charging operations performed by the user by connecting the aerosol generating device to a charging device.
[0174] The usage data may also be related to the operating state or health state of the aerosol generating device (100). For example, the usage data may also include a display of at least one of the voltage, current, resistance, charge, energy, and temperature related to the aerosol generating unit (110) of the aerosol generating device. The usage data may also include a display of at least one of the voltage, current, resistance, charge, energy, or temperature related to the power supply (160) of the aerosol generating device. Each of these displays may be adjusted for a specific event such as the start of smoking, during smoking, or the end of smoking performed by the user of the aerosol generating device. At least some of these displays may also be adjusted for the start, duration, or end of a heating operation performed by the aerosol generating unit (110), and / or the start, during charging, or end of a charging operation. The usage data may also indicate the type or amount of consumable material used by the aerosol generating unit.
[0175] The communication unit (150) is configured to transmit usage data (146), particularly encrypted, to the manufacturer server in order to establish a communication link to an external device. The communication link may be based on any wired or wireless communication technology, including but not limited to serial communication link, Universal Serial Bus (USB), optical communication port, Near Field Communication (NFC), Bluetooth, Bluetooth Low Energy (BLE), wireless communication, WiFi according to the IEEE 802.11x standard, mobile communication, etc. The communication with the manufacturer server may be direct or indirect, for example, via an intermediate device such as a mobile phone, a holder, or a docking station. The communication with the manufacturer server may also involve multiple communication protocols, for example, a Bluetooth connection between the aerosol generating device and a mobile phone, and a mobile communication between the mobile phone and an Internet access point.
[0176] The power supply (160) supplies power to all components of the aerosol generating device. The power source may be a rechargeable battery such as a lithium-ion battery or a lithium polymer battery. Other power sources may also be used.
[0177] Figure 2 shows a block diagram of a system comprising an aerosol generating device (100) and a server (200) according to an embodiment of the present invention. The aerosol generating device (100) and the server (200) are connected by a communication link for transmitting encrypted usage data. The server (200) has access to a database (300) that stores the secret values of each of a plurality of aerosol generating devices associated with respective unique identifiers. The aerosol generating device may also be connected to a holder (190) or a docking station that operates as a charging device (190) for charging the power supply (160). The communication link between the aerosol generating device (100) and the server (200) may also be indirectly formed via a mobile phone that operates as a holder (190) or an intermediate part (not shown).
[0178] Figure 3 shows a schematic diagram of a data structure according to an embodiment of the present invention. Usage data may be stored and transmitted in the form of data records, and each data record is related to specific events such as user interactions, charging operations, temperature, battery level, error messages, etc. Each data record may include a header, a payload section, and an authentication section (message authentication code, MAC). The header may specify the format of the data record, the length of the data record, and an index. The format may indicate at which positions within the payload section which data is provided. Different formats may be predefined for different events. The length may indicate the total length of the data record or the length of the payload section.
[0179] The index, or indices, together with other elements of the header, particularly the length, data type, and data format, may form a unique identifier (record unique ID, RUID) of the corresponding data record. The record index may be unique based on either an increment value, or a combination of a small increment value that can be repeated and a "rollover" value indicating the number of times the smaller number has overflowed. The index does not necessarily need to be stored and / or transmitted together with the payload and may be implicitly known either from a request for a particular data record or from the position of the data record within an array or list of data records. Thus, instead of the index value, a rollover value indicating how many times the index has rolled over above a predetermined maximum index value may be stored and / or transmitted.
[0180] The payload may include the actual usage data, i.e., information regarding each event, as described above in relation to FIG. 1. The payload may be encrypted. The MAC may be an encrypted signature or authentication code used for authentication purposes. The processes of data encryption, authentication, and key derivation will be described below.
[0181] According to the present invention, a symmetric key algorithm is used to encrypt the usage data stored in the payload of each data record. Since the payload length can vary and generally exceeds the block size of conventional block cipher algorithms, the counter mode is applied to convert a conventional block cipher into a stream cipher. The counter mode generates a key stream by encrypting consecutive values of a counter, as is generally known in the art. Next, the ciphertext is obtained by XORing the plaintext with the key stream. To ensure that different key streams are used for each data record, the counter is concatenated with a different nonce or initialization vector for each data record. Encryption is then performed by XORing the ciphertext again with the same key stream.
[0182] In a preferred embodiment, the Advanced Encryption Standard (AES) is used in counter mode (AES-CTR) to encrypt the usage data. The data flow for encrypting the usage data according to this embodiment is shown in FIG. 4.
[0183] The AES-CTR algorithm receives the usage data as input and delivers the encrypted usage data as output. The encryption process may further require a counter and an initialization vector for the counter mode, separate from the encryption key (AES key).
[0184] According to a further aspect of the present invention, the authenticity of each usage data record is guaranteed by an authentication code (digital signature) or a "summary". This signature is provided in the form of a message authentication code (MAC) calculated from the header and / or payload of the data record. Any modification to the data record will (with overwhelming probability) result in a MAC different from the MAC of the original data record, and as a result, the tampered data can be easily detected (integrity check). Furthermore, the calculation of the MAC is based on a secret key (authentication key or MAC key), and as a result, an attacker cannot predict the "correct" MAC for a given data. In this way, the system is strengthened against spoofing attacks that attempt to contaminate the manufacturer server with false or corrupted information (authenticity check).
[0185] In a preferred embodiment, a hash-based MAC (HMAC), i.e., a MAC calculated by applying a cryptographic hash algorithm, preferably Secure Hash Algorithm 1 (SHA-1), to the data to be authenticated, is used. The algorithm for calculating the MAC based on SHA-1 is generally referred to as HMAC-SHA1. Other algorithms, including HMAC-SHA256, may also be used.
[0186] Figure 5 is a diagram illustrating the data flow in a method for calculating a MAC according to an embodiment of the present invention. The HMAC-SHA1 algorithm receives the header and payload of the data record together with the MAC key as input and delivers the MAC as output.
[0187] Generally, the strength of an authentication code, i.e., a "summary", depends on its length. The HMAC-SHA1 algorithm delivers a MAC, for example, 160 bits (20 bytes) in length. However, in an aerosol generator, it is necessary to authenticate a large number of short data records of only a few bytes per record. Therefore, attaching a 20-byte MAC to each record is not feasible, especially from the perspective of the limited storage capacity available in an aerosol generator.
[0188] To reduce the overhead of storing and transmitting authenticated data records and increase the maximum number of data records that can be stored within an aerosol generator, the MAC delivered by the HMAC algorithm can be truncated to a few bytes, for example, 2, 3, or 4 bytes. The use of such truncated authentication codes increases the number of collisions for maliciously encrypted records. However, in such cases, attempts to contaminate the manufacturer's server with false data should be detected due to either impossible data or multiple data logs with false authentication codes.
[0189] Both the encryption key (AES key) and the message authentication key (MAC key) are derived from secret values and unique IDs stored in the aerosol generator. Thus, different aerosol generators use different keys to encrypt and authenticate data records. Thus, even if a particular device is compromised such that the AE key and / or MAC key becomes known, other devices are not affected.
[0190] A key derivation function based on the HMAC algorithm (HKDF) is used to derive both the AES key and the MAC key. A key derivation function (KDF) is a cryptographic algorithm that derives one or more secret keys from a secret value and can be used to expand a key into a longer key or obtain a key of the required format. The HKDF algorithm uses an HMAC hash function (e.g., HMAC-SHA256) over an arbitrary salt (acting as the key for the HMAC function) and a potentially weak input key material (IKM) (acting as data) to extract a pseudorandom key (PRK). The PRK is then repeatedly used to generate keyed hash blocks, which are then appended to the output key material and finally truncated to the desired length to generate an output key material (OKM) of the same cryptographically strong length as desired.
[0191] The data flow of this process is shown in Figure 6. The HKDF algorithm receives a secret value (a subset of bits) as input key material, receives a unique identifier (UID) as context and a constant value as salt, and delivers an output key material (OKM). A mask (AES mask) is used to select (multiplex) a subset of bits from the secret value as IKM. Different masks (IV masks) are used to select different subsets of bits from the secret value as IKM for deriving the initialization vector as described below in conjunction with Figure 7. Both the AES key and the MAC key are obtained from the OKM by selecting the required number of consecutive bits (AES length, MAC length) from different positions (AES offset, MAC offset) within the OKM.
[0192] The initialization vector for encrypting the data used in AES-CTR is also derived from the secret value and the UID by a key derivation function similar to the one used for deriving the AES key and the MAC key. To further strengthen this method against decryption, the initialization vector is also made to depend on the MAC of the data used (not encrypted) stored in the current data record, particularly in the payload section of the data record, and / or the index or sequence number, and / or other characteristics of the payload to be encrypted, i.e., a unique identifier (RUID) of the data record. In this way, different initialization vectors can be used for each data record and / or each transmission without further increasing the size of the data record.
[0193] The data flow of this process is shown in Figure 7. The HKDF algorithm receives a secret value as the input key material (IKM) (a subset of bits), and receives, as context, a unique identifier (UID), and a combination of (truncated) MAC, a record identifier, and a constant value as a salt (a subset of bits), and delivers the output key material (OKM). The combination of (truncated) MAC, record identifier, and constant value can be obtained, for example, by concatenating the respective bit strings to a multiplexer (MUX). A mask (IV mask) is used to select (demultiplex) a subset of bits from the secret value as the IKM. The initialization vector is obtained at a specific position (IV offset) having the required length (IV length) from the OKM.
[0194] All input information to the key derivation function illustrated in Figure 7, including MAC and the unique identifier, is also available at the manufacturer server when the encrypted data record is transmitted from the aerosol generator. Thus, the server can derive the same initialization vector and decrypt the received data record.
[0195] It is generally acceptable that it should be calculated for the encrypted message so that the MAC can check authenticity (encrypt-then-MAC) before starting decryption. However, in this situation, the advantage of being able to use the MAC as additional input to the KDF for deriving the initialization vector may outweigh the risk of applying the decryption algorithm to potentially tampered data. Thus, it is preferable that it is calculated for the unencrypted data so that the MAC is available for the encryption process (MAC-then-encrypt).
[0196] In a further embodiment of the present invention, the MAC may also be calculated for encrypted usage data (encrypt-then-MAC) in addition to, or instead of, the MAC for unencrypted data (MAC-then-encrypt). For this purpose, a second authentication key may be derived from unique device information in a manner similar to that for deriving the (first) authentication key for calculating the MAC for unencrypted data. Next, the second authentication key may be used to calculate the MAC for the encrypted usage data by applying the HMAC algorithm to the encrypted usage data, or to the encrypted usage data and the MAC for the unencrypted data. Next, the MAC for the encrypted usage data is transmitted together with the encrypted message.
[0197] On the server side, the integrity of the encrypted message can be checked by deriving the second authentication key in the same way as for the aerosol generator, calculating the server-side MAC from the encrypted message, and comparing the server-side MAC with the MAC attached to the encrypted message. The decryption process is then only started if the two MACs are identical.
[0198] FIG. 8 shows a flowchart of a method for encrypting usage data according to an embodiment of the present invention.
[0199] In step S110, the encryption key K ENC and the message authentication key K MACis derived from unique device information having a key derivation process, as will be described in conjunction with FIG. 6. In step 120, the operating state of the aerosol generator is detected by, for example, an appropriate sensor. Based on the detection result, usage data is created in step S130. Depending on the type of the created usage data, a unique record ID is generated in step S140. The unique record ID may include information indicating the type, format, length, and index of the data record. In step S150, the message authentication code MAC is calculated for the unique record ID and the usage data using the message authentication key K MAC as described in conjunction with FIG. 5. In step S160, a unique initialization vector IV is derived from the unique device information, the unique record ID, and the MAC having a process as described in conjunction with FIG. 7. In step S170, the data record is encrypted using the encryption key K ENC and the initialization vector IV in a process as described in conjunction with FIG. 4. Next, the encrypted data record is stored in the aerosol generator together with the MAC in step 180. Thereafter, the process returns to step S120.
[0200] FIG. 9 shows a flowchart of a method for transmitting usage data from an aerosol generator to a host and decrypting the received data at the host according to an embodiment of the present invention.
[0201] The process may be started by a host (which may be a manufacturer server) by sending a request to the aerosol generator (S210). The aerosol generator may respond to this request by sending its unique device ID such as a manufacturing information block MIB (S215). On the other hand, the confidential information is not part of this transmission nor any other transmission between the aerosol generator and the host in the context of this process. Upon receiving the unique device ID, the host obtains the corresponding secret value S DEV from the database in step S220. The secret value may be stored in the database in an encrypted form, and the host decrypts the encrypted secret value E(SDEV ) may be decrypted. At this point, the host has the entire unique device information, that is, the unique device ID and the secret value, and thus is in a position to derive the encryption and message authentication keys used by the aerosol generator to encrypt and authenticate the usage data. Specifically, in step S230, the host, the encryption key K ENC and the message authentication key K MAC are derived from the unique device information having the same key derivation process as that performed by the aerosol generator and described in conjunction with FIG. 6.
[0202] In step S235, the host may request data from the aerosol generator. The request may include an indication of one or more data records transmitted by the aerosol generator, such as at least a part of the unique record ID or the range of index values. The aerosol generator may respond to this request by transmitting the requested data record in an encrypted form together with the corresponding MAC data (S240). The response may also include the unique record ID of each data record transmitted.
[0203] In step S245, the host derives a unique initialization vector IV from the unique device information, the unique record ID, and the MAC DATA in the same process as that performed by the aerosol generator and described in conjunction with FIG. 7. The initialization vector IV is then used in step S250 together with the encryption key K ENC to decrypt the received data record and recover the data DATA host contained therein.
[0204] In step S255, the host calculates a message authentication code MAC host from the unique record ID and the recovered data DATA host . The message authentication code MAC host thus calculated is, in step S260, compared with the message authentication code MAC data received together with the encrypted data record.If it is found to be the same, the record is considered valid. Otherwise, the data record is invalid.
[0205] FIG. 10 shows a flowchart of a method for manufacturing an aerosol generating device according to an embodiment of the present invention. The steps of this method may be performed at a specific stage of the assembly process of the aerosol generating device or during the final test of the assembled aerosol generating device, for example, when the controller 130 is first powered on.
[0206] In step S330, the aerosol generating device generates a unique secret value S, for example, by a random number generator. DEV The thus generated secret value S DEV is then stored in the storage unit 140 of the aerosol generating device as part of the unique device information (S340), encrypted (S350), and transmitted to the host computer for storage in a database for future reference (S360).
[0207] FIG. 11 shows a flowchart of a method for manufacturing an aerosol generating device according to an embodiment of the present invention. The steps of this method may be performed at a specific stage of the assembly process of the aerosol generating device or during the final test of the assembled aerosol generating device, for example, when the controller 130 is first powered on.
[0208] The process according to FIG. 11 differs from that of FIG. 10 by additional steps S310 and S320. In step S310, the host generates a unique device ID and transmits it to the aerosol generating device. The unique device ID may include a unique manufacturing information block, MIB, that is, a data block containing information related to the manufacturing process such as product ID, platform ID, unique ID, and manufacturing site, as described above.
[0209] In step S320, the aerosol generating device stores the received unique device ID in the storage unit 140. In step S330, the aerosol generating device generates a unique secret value S, for example, by a random number generator.DEV is generated. The thus generated secret value S DEV is then stored in the storage unit 140 of the aerosol generator, together with a unique device ID (S340). In step S530, the secret value S DEV is encrypted and transmitted to the host computer (S360) so as to be stored in the database in association with a unique device ID for later retrieval.
[0210] Accordingly, embodiments of the present invention provide a technique for protecting usage data stored within an aerosol generator when transmitting it to an external device such as inside the device and a manufacturer server. Further, the manufacturer server that collects data from the aerosol generator is protected from being contaminated with false or corrupted information. Embodiments of the present invention can protect the storage and transmission of usage data in an aerosol generator without requiring a public key infrastructure or an overly complex algorithm for secure key exchange. Embodiments of the present invention further provide a high level of data security even in a system having a large number of aerosol generators and a large number of individual data records. Embodiments of the present invention are also particularly adapted to the limited computing and storage capabilities of an aerosol generator.
Claims
1. Aerosol generator, Among them is a memory unit that stores secret values and unique identification values generated during the manufacturing stage of the aerosol generator, Communication unit and Equipped with a controller, The aforementioned controller To create usage data showing the use of the aerosol generator, At least the stored secret value and optionally the unique identification value from which the encryption key is derived. The generated usage data is encrypted using the derived encryption key. The encrypted usage data is stored in the storage unit, and An aerosol generator configured to transmit the encrypted usage data and the unique identifier to an external device via the communication unit, wherein the unique identifier identifies the secret value used to derive the encryption key.
2. The aerosol generator according to claim 1, wherein the controller is further configured to derive an authentication key from at least the secret value and optionally the unique identification value, and to authenticate the stored usage data with the derived authentication key.
3. The aerosol generator according to claim 1, wherein the controller is configured to employ a symmetric key algorithm for encrypting the generated usage data.
4. The aerosol generator according to claim 1, wherein the controller is further configured to encrypt the generated usage data by deriving an initialization vector from the secret value and / or the unique identification value, and by applying a block cipher in counter mode using the encryption key and the initialization vector.
5. The aerosol generator according to claim 1, wherein the controller is further configured to authenticate the created usage data by calculating a message authentication code MAC for the created usage data.
6. The aerosol generator according to claim 1, wherein the controller is further configured to authenticate the encrypted usage data by calculating the MAC for the encrypted usage data.
7. The aerosol generator according to claim 5, wherein the controller is further configured to calculate the MAC for the created usage data and / or the MAC for the encrypted usage data by truncating the output of the hash function to a predetermined number of bytes.
8. The aerosol generator according to claim 5, wherein the controller is further configured to store the MAC for the created usage data and / or the MAC for the encrypted usage data together with the encrypted usage data in the storage unit.
9. The aerosol generator according to claim 1, further configured to employ a hash-based key derivation function HKDF for deriving from the secret value and / or the unique identification value at least one of the following: an encryption key for encrypting the created usage data, an initialization vector for encrypting the created usage data with a block cipher in counter mode, and an authentication key for authenticating the usage data.
10. The aerosol generator according to claim 9, wherein at least a portion of the message authentication code MAC calculated on the generated usage data is used as a salt for deriving the initialization vector.
11. an aerosol generation system, an aerosol generator according to any one of claims 1 to 10, A database configured to store a unique identification value for each of a plurality of aerosol generators in relation to the secret value of the aerosol generator, It is a server, The aerosol generator receives encrypted usage data and a unique identifier from the aerosol generator. Using the unique identifier, retrieve the secret value associated with the unique identifier from the database, and An aerosol generating system further includes a server configured to decrypt the encrypted usage data using the secret value obtained.
12. A method for operating an aerosol generator, wherein the method is A step of storing the secret value and unique identification value generated during the manufacturing stage of the aerosol generator in the memory unit of the aerosol generator, A step of generating usage data indicating the use of the aerosol generator, The process includes deriving an encryption key from at least the stored secret value and, optionally, the unique identification value, The process involves encrypting the created usage data with the derived encryption key, The steps include storing the encrypted usage data in the storage unit, A method comprising the steps of transmitting the encrypted usage data and the unique identifier to an external device via a communication unit, wherein the unique identifier identifies the secret value used to derive the encryption key.
13. A method for transmitting usage data from an aerosol generator to a host, wherein the aerosol generator stores a secret value and a unique identification value therein, and the method The process of receiving the unique identification value from the aerosol generator at the host, The steps include obtaining the secret value of each of the multiple aerosol generators from a database stored therein, in relation to the respective unique identification values of the aerosol generators, The host comprises the steps of deriving an encryption key from at least the acquired secret value and optionally the received unique identification value, The process of receiving encrypted usage data from the aerosol generator on the host, A method comprising the step of decrypting the received encrypted usage data with the encryption key.
14. On the host, the authentication key is derived from at least the acquired secret value and optionally the unique identification value. The host receives a first message authentication code (MAC) from the aerosol generator along with the encrypted usage data, Calculating a second MAC from the decrypted usage data and the derived authentication key, The method according to claim 13, further comprising comparing the first MAC with the second MAC.
15. This further includes deriving the initialization vector, The method according to claim 14, wherein the received encrypted usage data is decrypted by applying a block cipher in counter mode using the encryption key and the initialization vector.