Control circuit for aerosol generating device

The control circuit for aerosol generating devices employs an offline authentication process with guided interactive input to secure against brute force attacks, ensuring secure youth access prevention.

JP2025528907APending Publication Date: 2025-09-02PHILIP MORRIS PRODUCTS SA
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025511802
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-25
Filing Date
2023-08-17
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

Existing youth access prevention (YAP) methods for aerosol-generating devices are vulnerable to brute force attacks and require connectivity that is technically problematic.

Method used

A control circuit for aerosol generating devices implements an offline authentication process with a predetermined number of attempts, transitioning to an online phase if exceeded, and uses guided interactive input with user-perceptible guidance signals to prevent unauthorized access.

Benefits of technology

Effectively prevents unauthorized use by underage users through a secure offline authentication process, transitioning to an online phase if necessary, thereby enhancing security against brute force attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025528907000001_ABST
    Figure 2025528907000001_ABST
Patent Text Reader

Abstract

A control circuit for an aerosol generating device is provided, having a locked state in which the aerosol generating device is prohibited from delivering an aerosol, and an unlocked state in which the aerosol generating device is permitted to deliver an aerosol. The control circuit is configured to allow a user to make a first predetermined number of attempts to input valid authentication information using one or more user interface components during an offline phase of an authentication process, to determine to transition the aerosol generating device from the locked state to the unlocked state in response to receiving valid authentication information from the user before the first predetermined number of attempts is exceeded, and to proceed to the online phase of the authentication process in response to determining that the first predetermined number of attempts has been exceeded before the user enters valid authentication information. Corresponding methods are also provided.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a control circuit for an aerosol generating device, an aerosol generating device comprising the control circuit, an aerosol generating system comprising the aerosol generating device, and a method for authenticating the use of an aerosol generating device. [Background technology]

[0002] The aerosol-generating system may further include a companion device for storing the aerosol-generating device. The aerosol-generating device may be designed, for example, as a handheld device that can be used by a user to consume the aerosol generated by the aerosol-generating article in one or more use sessions. The aerosol-generating article may include an aerosol-forming substrate, such as a tobacco-containing substrate, often in the form of a stick. The stick may be configured in a shape and size to be at least partially inserted into the aerosol-generating device and may include a heating element for heating the aerosol-forming substrate. Another exemplary aerosol-generating article may include a cartridge containing a liquid that can be evaporated during aerosol consumption by a user. Such a cartridge may also be configured in a shape and size to be at least partially inserted into the aerosol-generating device. Alternatively, the cartridge may be fixedly attached to the aerosol-generating device and refilled by inserting a liquid into the cartridge. The aerosol-generating article may include an aerosol-generating substrate containing nicotine and / or other active ingredients.

[0003] To prevent underage users from accessing and using such aerosol-generating devices, it is desirable to implement a youth access prevention (YAP) method. Some online YAP methods require users to register and activate their devices by connecting them to a computing device, such as a smartphone or personal computer, running a registration application. The application may be provided as a USB application. Connection to the computing device may be achieved via Bluetooth Low Energy (BLE). However, the connection and application required for implementing online YAP methods in the above-described manner may be technically problematic. Therefore, offline YAP methods have been proposed to unlock devices without requiring such a connection or application. However, some offline YAP methods are vulnerable to brute force attacks.

[0004] It would be desirable to provide a YAP method that at least partially overcomes the above-mentioned technical problems. This problem is achieved by the subject matter of the independent claims. Optional features are provided by the dependent claims and the following description. Summary of the Invention

[0005] According to a first aspect, there is provided a control circuit for an aerosol generating device or an aerosol generating system including an aerosol generating device. The aerosol generating device has a locked state in which the aerosol generating device is prohibited from delivering an aerosol and an unlocked state in which the aerosol generating device is permitted to deliver an aerosol. The control circuit is configured to implement an authentication process for authenticating a user. The control circuit may be configured to allow a user to make a first predetermined number of attempts to enter valid authentication information using one or more user interface components during an offline phase of the authentication process. The control circuit may be further configured to determine to transition the aerosol generating device from the locked state to the unlocked state in response to receiving valid authentication information from the user before the first predetermined number of attempts is exceeded. The control circuit may be further configured to proceed to an online phase of the authentication process in response to determining that the user has exceeded the first predetermined number of attempts before entering valid authentication information.

[0006] Starting in the offline phase, an authentication process such as the YAP method can be completed without relying on any device connectivity and without the use of any external applications. Furthermore, the solution described herein prevents the use of brute force attacks to gain access to locked features of the aerosol generating device by transitioning to the online phase after an excessive number of forced attempts to unlock the aerosol generating device during the offline phase. Unauthorized users can be effectively and reliably prohibited from unlocking the aerosol generating device, thereby effectively and reliably prohibiting the use of the aerosol generating device for aerosol consumption by unauthorized users.

[0007] The control circuitry may be further configured to respond to unsuccessful user attempts to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, where the second predetermined number of attempts is less than the first predetermined number of attempts, and to delay the offline phase until the first time delay period has elapsed if the second predetermined number of attempts has been exceeded. The control circuitry may be configured to continue the offline phase without delay if the second predetermined number of attempts has not been exceeded.

[0008] The control circuitry may be further configured to respond to a user's unsuccessful attempts to enter valid authentication information during the offline phase by determining whether a third predetermined number of attempts has been exceeded, where the third predetermined number of attempts is less than the first predetermined number of attempts and greater than the second predetermined number of attempts, and to delay the offline phase until a second time delay period has elapsed if the third predetermined number of attempts has been exceeded. The control circuitry may be configured to continue the offline phase without delay if the third predetermined number of attempts has not been exceeded. The second time delay period may be longer than the first time delay period.

[0009] The first, second, and / or third predetermined number of trials may be defined in terms of consecutive and / or non-consecutive trials.

[0010] The control circuitry may be configured to delay the offline phase by prohibiting the user from entering further authentication information using one or more user interface components or by refraining from authenticating the user based on the user's entry of further authentication information.

[0011] The control circuitry may be further configured to receive user-input authentication information from one or more user interface components during each attempt of the offline phase and authenticate the user by determining the validity of the user-input authentication information.

[0012] The control circuitry may be further configured to guide the user in entering authentication information as part of the guided interactive input process and control a user interface component to output user-perceptible guidance signals, e.g., (i) prompting the user to take a predetermined action, (ii) providing feedback to the user regarding the progress of the guided interactive input process, or both (i) and (ii), in response to control signals from the control circuitry to guide the user through the guided interactive input process, e.g., by controlling the user interface component. Thus, the interactive input process is an example of a guided human-machine interaction process. The user-perceptible guidance signals may include any one or more of visual, audible, and tactile signals. To this end, the user interface component may include one or more output elements, including, for example, any combination of one or more of the following elements: a visual indicator (e.g., a light source such as an LED, incandescent lamp, compact fluorescent lamp, etc.), a tactile output element (e.g., a vibration actuator such as an eccentric rotating mass motor, a linear resonant actuator, a C2 tactor, a piezoelectric actuator, etc.), an audible output element such as a speaker, etc. The user interface component further includes one or more input elements, such as a button (e.g., a push button), a touch screen, a microphone, etc. In one implementation, the user interface component comprises a plurality of LEDs and a push button. In any of these ways, the user interface component facilitates implementation of an offline phase of the authentication process while conserving device area in what may be a small form factor aerosol generating device or companion device.

[0013] The control circuitry is configured to receive user-input authentication information during multiple time windows of a predetermined duration, each time window corresponding to a different digit in the series of numbers forming the authentication information, and to attribute user input received via one or more user interface components during the time window to the digit corresponding to the time window. The control circuitry may be configured to trigger a timeout in response to no user input being received by one or more user interface components within a predetermined time period beginning at the beginning of a respective one of the time windows. The control circuitry may be configured to initiate a first one of the time windows in response to a user interacting with one or more user interface components. The control circuitry may be configured to initiate a first one of the time windows in response to receiving a predetermined signal generated by a user interacting with one or more user interface components. One or more user interface components may include a push button, and the predetermined signal may be generated by a user pressing the push button a predetermined number of times. For example, a first time window may be initiated by a user pressing the push button a predetermined number of times (e.g., five times) within a predetermined time period (e.g., 30 seconds).

[0014] There may be preliminary time windows before and / or between one or more of the time windows (e.g., before and / or between the first time window). The control circuitry may be configured to determine that a user unsuccessfully attempted to enter valid authentication information if no user input authentication is received during the preliminary time window, store the received user input authentication (attributed to the corresponding digit), initiate the corresponding time window, and / or continue execution of the corresponding time window (allowing the corresponding digit to complete) if user input authentication is received during the preliminary time window.

[0015] The control circuitry may be configured to control the user interface component to output a user-perceptible guidance signal indicating at least the beginning of a respective time window. The control circuitry may be configured to control the user interface component to output a user-perceptible guidance signal indicating that the time window is running. The control circuitry may be configured to control the user interface component to output a user-perceptible guidance signal indicating a digit in the sequence at which the user is being guided to provide input. The aerosol generating device may be provided with output elements corresponding to the number of digits in the sequence. The control circuitry may be configured to use the position of the active output element relative to the inactive output element to indicate the position of the digit in the sequence at which input is expected.

[0016] The control circuitry may be further configured to interpret multiple signals resulting from repeated user actuation of the same user interface component during the time window as coded input signals defining a digit of the sequence to which the time window corresponds. The user interface component may be a power button for the aerosol generating device.

[0017] The sequence of digits forming the authentication information may include a personal ID number or code, e.g., a pin code. Thus, a separate time window is provided for entering each digit of the sequence or pin code, thereby providing certainty and security regarding which digit is currently being entered. "Attribution" means that the control circuit associates user input received during the time window with the digit corresponding to the time window, or uses user input received during the time window to determine or calculate the value of the digit corresponding to the time window. For enhanced security, the control circuit may be configured to trigger a timeout in response to no user input being received by one or more user interface components within a predetermined time period beginning from the beginning of each of the time windows. As a result, the control circuit may be further configured to determine not to transition the aerosol generating device to the unlocked state in response to the triggering of the timeout. "Timeout" means that a timer begins to run at the start and end of the predetermined period, generating an interrupt or trigger signal, thereby "triggering" the timeout if a predetermined action is not taken to cancel or reset the timer within the predetermined period.

[0018] During the offline phase, the control circuitry may be configured to respond by determining not to transition the aerosol generating device from the locked state to the unlocked state if the user unsuccessfully attempts to enter valid authentication information. The control circuitry may be further configured to compare the user-input authentication information with pre-stored reference authentication information and determine whether to transition the aerosol generating device from the locked state to the unlocked state based on the results of the comparison. The reference authentication information may be stored in data storage and / or memory of the aerosol generating device and / or companion device. For example, the reference authentication information may be obtained during and stored upon completion of an age verification process, as discussed further below. The control circuitry may be configured to determine the validity of the user-input authentication information using a key derivation mechanism.

[0019] The control circuitry may be configured to transition the aerosol generating device from a locked state to an unlocked state during the online phase of the authentication process by sending an unlock request to the server, the unlock request including unique device identification information that identifies the aerosol generating device and time-limited nonce information corresponding to an unlockable feature of the aerosol generating device, receive an unlock authorization from the server in response to the sent unlock request, and transition the aerosol generating device from the locked state to the unlocked state in response to receiving the unlock authorization. The unlock authorization may be at least partially encrypted. The unlock authorization may be decryptable using a public key stored on the aerosol generating device. The control circuitry may be configured to transition the aerosol generating device from the locked state to the unlocked state in response to receiving the unlock authorization: decrypting the unlock authorization; determining whether the decrypted unlock authorization includes the unique device identification information and the time-limited nonce information; and transitioning the aerosol generating device from the locked state to the unlocked state in response to determining that the decrypted unlock authorization includes the unique device identification information and the time-limited nonce information. The control circuitry may be configured to terminate unlocking of the unlockable feature if no unlock authorization is received after a validity period after the unlock request is sent to the server. The control circuitry may be configured to limit the number of unlock authorizations sent to the aerosol generating device. The unique device identification may include a serial number. Additionally or alternatively, the online phase may be performed using an external computing device or telephone, whereby the user contacts the authentication authority. In this manner, a comprehensive and secure procedure for determining a user's age can be implemented based on the user's personal data or information, such as the user's ID card, passport, credit card, driver's license, or social security number. Thus, the user's actual age can be reliably and unambiguously determined.

[0020] The authentication process may include a juvenile access prevention process. Performing the authentication process may include identifying the user, i.e., determining and / or verifying the user's identity, and / or determining whether the user is authorized to transition the aerosol generating device to an unlocked state and deliver and / or generate aerosol. Thus, a "successful authentication" of a user may include, for example, a successful attempt by the user to enter valid authentication information during an offline phase, or verifying the user's identity after receiving unlock authorization during an online phase, or more specifically, determining that the user is authorized to transition the aerosol generating device to an unlocked state. A "failed authentication" of a user may include a failure to verify the user's identity, or more specifically, determining that the user is not authorized to transition the aerosol generating device to an unlocked state. For example, the authentication process may include an age verification process to determine whether a user of the aerosol generating device has reached a minimum age indicated by an age threshold. The age threshold may include a predetermined minimum age for users of the aerosol generating device. In certain jurisdictions, for example, aerosol consumption may be permitted for citizens or individuals who have reached and / or are above a certain minimum age. Furthermore, in at least some jurisdictions, individuals who have reached this minimum age may be considered of legal age and / or adulthood. Thus, the term age threshold may indicate, represent, and / or describe the minimum age required for a user to use an aerosol generating device for aerosol consumption. Alternatively or additionally, the age threshold may indicate, represent, and / or describe the age of adulthood at which a user may be considered an adult. For example, the age threshold may range from 14 to 25 years old, such as 16, 18, or 21 years old. An age verification process may therefore be usable to determine whether a user of an aerosol generating system is of legal age, legal age, and / or adulthood. The age verification process may be associated with a registration or setup procedure prior to or at the time of the user's first use of the aerosol generating device.By determining that a user has reached an age threshold based on an age verification process, misuse or legally abusive use of the aerosol generating device for aerosol consumption by users who have not reached and / or are below the age threshold can be reliably and effectively prohibited, and in particular, use of the aerosol generating device for aerosol consumption by underage users can be reliably and effectively prohibited.

[0021] The control circuitry may be further configured to transition the aerosol generation device to an unlocked state in response to successful user authentication. The control circuitry may be further configured to transition the aerosol generation device to the unlocked state by one or more of: (i) changing the value of the authentication indicator stored in the data storage; (ii) adding the authentication indicator to the data storage; or (iii) removing the authentication indicator from the data storage. Additionally or alternatively, the control circuitry may be further configured to transition the aerosol generation device to the unlocked state by enabling one or more functions of the aerosol generation device that were previously disabled when the aerosol generation device was in the locked state. Additionally or alternatively, the control circuitry may be further configured to transition the aerosol generation device to the unlocked state by transmitting an unlock signal to a companion device for the aerosol generation device, the companion device configured to enable one or more functions of the aerosol generation device and the companion device that were previously disabled when the aerosol generation device was in the locked state in response to receiving the unlock signal. One or more functions enabled in the unlocked state may be essential for aerosol delivery by the aerosol generating device, and enabling may include enabling one or more of: (i) an electrical energy supply component (e.g., charging the aerosol generating device); (ii) a volatile liquid supply component; (iii) a heating component; (iv) an airflow enabling component; or (v) an actuation element for user actuation of one or more of the other components. For example, insertion of an aerosol-generating article into the aerosol generating device may be prohibited in the locked state, while insertion of an aerosol-generating article may be permitted in the unlocked state. Such functions that may be enabled or disabled may also be described herein with respect to lockable and unlockable functions. Additionally or alternatively, the control circuitry may be further configured to transition the aerosol generating device to the unlocked state by disabling one or more mechanical locking and / or flow path blocking components that are configured in the enabled state to prevent aerosol delivery and / or generation.However, any other means for permitting aerosol generation in the unlocked state and prohibiting aerosol generation in the locked state may be implemented. The control circuitry may be further configured to determine not to transition the aerosol generating device from the locked state based on a failure to authenticate the user. The control circuitry may be further configured to maintain the aerosol generating device in the locked state in response to determining not to transition the aerosol generating device from the locked state to the unlocked state.

[0022] The control circuitry may further control one or more functions of the aerosol generating device. The control circuitry may include one or more processors for data processing. Alternatively or additionally, the aerosol generating device may include data storage and / or memory for storing data, such as software instructions, computer programs, and / or other data.

[0023] According to a second aspect, there is provided an aerosol generating device including the control circuit of the first aspect.

[0024] An aerosol-generating device may be configured or designed, for example, as a handheld device that can be used by an authorized user to consume the aerosol-generating article during one or more use sessions (also referred to as an "experience" or "experience session"). For example, an aerosol-generating article that can be used with an aerosol-generating device may include an aerosol-forming substrate, such as a tobacco-containing substrate, in the form of a stick that can be at least partially inserted into the aerosol-generating device, optionally assembled with other elements or components. Alternatively or additionally, an aerosol-generating article that can be used with an aerosol-generating device may include at least one cartridge containing a liquid that can be evaporated during aerosol consumption by a user. Such a cartridge may be a refillable cartridge that is fixedly attached to the aerosol-generating device, or the cartridge may be at least partially inserted into the aerosol-generating device.

[0025] According to a third aspect, there is provided a companion device for an aerosol generating device, the companion device comprising the control circuit of the first aspect.

[0026] A companion device, also referred to as a receiving device, may generally refer to a support device for supporting and / or storing an aerosol generating device. A companion device may be a portable companion device. In the context of the present disclosure, a companion device may be configured to at least partially receive an aerosol generating device. For example, a companion device may be configured to be physically coupled to the aerosol generating device. Such physical coupling may include, for example, a mechanical coupling based on an attachment means, such as a hook mechanism, a latch mechanism, or a snap-fit ​​mechanism, by which the aerosol generating device may be mechanically coupled to the companion device and / or its housing. Alternatively or additionally, the aerosol generating device may be physically coupled to the companion device based on magnetic or electromagnetic coupling. Alternatively or additionally, the aerosol generating device may be at least partially inserted into the companion device, such as, for example, into an opening in the companion device. Furthermore, the aerosol generating device and the companion device may refer to physically separate components or elements of an aerosol generating system.

[0027] To communicate with each other and / or with external computing devices and / or to exchange data or signals, the aerosol generating device and / or companion device may include at least one communication interface. The communication interface may be configured for wireless communication, wired communication, or both. For example, the communication interface may be configured to communicatively couple via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection including BLE, a cellular network, a 3G / 4G / 5G connection, an edge connection, an LTE connection, a BUS connection, a wireless connection, a wired connection, a radio connection, a short-range connection, an IoT connection, or any other connection using any suitable communication protocol.

[0028] The aerosol generating device and / or companion device may include at least one energy storage unit for storing electrical energy and / or supplying electrical energy to the aerosol generating device. For example, the companion device may be configured to supply electrical energy to the aerosol generating device and charge the at least one energy storage unit of the aerosol generating device. In other words, the companion device may be configured to charge the aerosol generating device and / or its at least one energy storage unit. The at least one energy storage unit of the aerosol generating device may include, for example, at least one battery, at least one accumulator, at least one capacitor, or any other energy storage unit. The companion device may be configured to supply electrical energy to the energy storage unit of the aerosol generating device when the aerosol generating device is at least partially received by the companion device. The companion device may include one or more batteries for supplying electrical energy to the energy storage unit of the aerosol generating device. The companion device may be configured to wirelessly supply electrical energy to the energy storage unit of the aerosol generating device, for example, based on induction. Alternatively or additionally, the companion device may be configured to supply electrical energy to an energy storage unit of the aerosol generating device via one or more electrical connectors between the companion device and the aerosol generating device. For example, the aerosol generating device and the companion device may each include at least one electrical connector for electrically coupling the companion device with the aerosol generating device when the aerosol generating device is at least partially received by the companion device. As an example, the companion device may include an opening for at least partially receiving the aerosol generating device. By at least partially inserting the aerosol generating device into the opening, one or more electrical connectors may be established between the one or more electrical connectors of the aerosol generating device and the companion device.Alternatively or additionally, the aerosol generating device may be physically and / or mechanically coupled to the companion device, e.g., via the housing of the companion device, such that the aerosol generating device is at least partially received by the companion device and one or more electrical connections can be established between the aerosol generating device and the companion device. Optionally, a communicative coupling and / or connection between the companion device and the aerosol generating device may be established, e.g., for transmitting authentication signals, by establishing an electrical connection between the companion device and the aerosol generating device, e.g., via one or more electrical connectors of the aerosol generating device and the companion device. As an example, at least one electrical connector of the companion device may be combined with and / or include a communication interface of the companion device. In other words, at least one electrical connector of the companion device may be configured as a communication interface for communicatively coupling the companion device with the aerosol generating device. Alternatively or additionally, at least one electrical connector of the aerosol generating device may be combined with and / or include a communication interface of the aerosol generating device. In other words, at least one electrical connector of the aerosol generating device may be configured as a communication interface for communicatively coupling the aerosol generating device with the companion device. Thus, an authentication signal may be transmitted from the companion device to the aerosol generating device via one or more electrical connectors of the companion device and the aerosol generating device. However, it should be noted that the communication interface of one or both of the companion device and the aerosol generating device may be physically separate and independent from the at least one electrical connector of the companion device and / or the aerosol generating device. A charging cycle may refer to a period during which the aerosol generating device is continuously supplied with electrical energy by the companion device. During a charging cycle, the at least one energy storage unit may be partially or fully charged.

[0029] According to a fourth aspect, there is provided an aerosol generation system comprising the control circuit of the first aspect, optionally also an aerosol generation device, and optionally also a companion device. The control circuit may be entirely contained within only one of the aforementioned components of the system, or may be distributed among multiple components. For example, the control circuit may be distributed between the aerosol generation device and the companion device.

[0030] According to a fifth aspect, there is provided a server configured to perform at least an online phase of an authentication process in conjunction with an aerosol generating device. More specifically, there is provided a server for unlocking an unlockable feature of an aerosol generating device, the server comprising: a communications interface for transferring data to and from the aerosol generating device; and control circuitry operatively coupled to the communications interface, the control circuitry configured to receive an unlock request from the aerosol generating device to unlock the unlockable feature, the unlock request including unique device identification information identifying the aerosol generating device and time-limited nonce information corresponding to the unlockable feature, and to transmit an unlock authorization to the aerosol generating device and unlock the unlockable feature in response to the transmitted unlock request. It will be understood that references to an aerosol generating device in the context of operations performed by the server may be replaced or supplemented, as appropriate, by references to a companion device and / or an aerosol generating system and / or one or more external computing devices.

[0031] According to a sixth aspect, a method for implementing an authentication process to authenticate a user of an aerosol generating device is provided. The aerosol generating device has a locked state in which the aerosol generating device is prohibited from delivering aerosol and an unlocked state in which the aerosol generating device is permitted to deliver aerosol. The method may include allowing a user to make a first predetermined number of attempts to enter valid authentication information using one or more user interface components during an offline phase of the authentication process. The method may further include determining to transition the aerosol generating device from the locked state to the unlocked state in response to receiving valid authentication information from the user before exceeding the first predetermined number of attempts. The method may further include proceeding to an online phase of the authentication process in response to determining that the user has exceeded the first predetermined number of attempts before entering valid authentication information.

[0032] The method may further include responding if the user unsuccessfully attempts to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, the second predetermined number of attempts being less than the first predetermined number of attempts, and if the second predetermined number of attempts has been exceeded, delaying the offline phase until a first time delay period has elapsed. If the second predetermined number of attempts has not been exceeded, the method may include continuing the offline phase without delay.

[0033] The method may further include determining whether a third predetermined number of attempts has been exceeded and responding if the user unsuccessfully attempts to enter valid authentication information during the offline phase, the third predetermined number of attempts being less than the first predetermined number of attempts and greater than the second predetermined number of attempts, and delaying the offline phase until a second time delay period has elapsed if the third predetermined number of attempts has been exceeded. The method may further include continuing the offline phase without delay if the third predetermined number of attempts has not been exceeded. The second time delay period may be longer than the first time delay period.

[0034] The method may further include delaying the offline phase by prohibiting the user from entering further authentication information using one or more user interface components or by refraining from authenticating the user based on the user's entry of further authentication information.

[0035] The method may further include, during each attempt of the offline phase, receiving user-input authentication information from one or more user interface components and authenticating the user by determining validity of the user-input authentication information.

[0036] The method may further include receiving user-input authentication information during a plurality of time windows of a predetermined duration, each time window corresponding to a respective digit of a series of numbers forming the authentication information, and attributing user input received via one or more user interface components during the time window to the digit corresponding to the time window. The method may further include triggering a timeout within a predetermined period starting from the beginning of a respective one of the time windows in response to no user input being received by the one or more user interface components. The method may further include initiating a first one of the time windows in response to a user interacting with the one or more user interface components. The method may further include initiating a first one of the time windows in response to receiving a predetermined signal generated by a user interacting with the one or more user interface components. The one or more user interface components may include a push button. The predetermined signal may be generated by a user pressing the push button a predetermined number of times. There may be preliminary time windows before and / or between one or more of the time windows. The method may further include determining that the user has unsuccessfully attempted to enter valid authentication information if user input authentication is not received during the preliminary time window, storing the received user input authentication, and initiating a corresponding time window and / or continuing execution of the corresponding time window if user input authentication is received during the preliminary time window. The method may further include controlling a user interface component to output a user-perceptible guidance signal indicating at least the start of a respective time window. The method may further include controlling the user interface component to output a user-perceptible guidance signal indicating that the time window is running. The method may further include controlling the user interface component to output a user-perceptible guidance signal indicating a digit in the sequence for which the user is being guided to provide input. The aerosol generating device may be provided with output elements corresponding to the number of digits in the sequence.The method may further include using the position of the active output element relative to the inactive output element to indicate the position of a digit in the sequence for which input is expected. The method may further include interpreting multiple signals resulting from repeated user operation of the same aforementioned user interface component as coded input signals during the time window that define the digit of the sequence to which the time window corresponds. The user interface component may be a power button for the aerosol generating device.

[0037] The method may further include, during the online phase of the authentication process, transitioning the aerosol generating device from a locked state to an unlocked state by sending an unlock request to the server, the unlock request including unique device identification information that identifies the aerosol generating device and time-limited nonce information corresponding to an unlockable feature of the aerosol generating device; receiving an unlock authorization from the server in response to the sent unlock request; and transitioning the aerosol generating device from the locked state to the unlocked state in response to receiving the unlock authorization. The unlock authorization may be at least partially encrypted. The method may further include decrypting the unlock authorization using a public key stored on the aerosol generating device.

[0038] The method may further include, in response to receiving the unlock authorization, determining whether the decrypted unlock authorization includes the unique device identification information and the time-limited nonce information, and, in response to determining that the decrypted unlock authorization includes the unique device identification information and the time-limited nonce information, transitioning the aerosol generating device from the locked state to the unlocked state by unlocking the unlockable feature. The method may further include terminating the unlocking of the unlockable feature if the unlock authorization is not received after a validity period after the unlock request is sent to the server. The method may further include limiting the number of unlock authorizations sent to the aerosol generating device. The unique device identification may include a serial number.

[0039] The method may further include responding by deciding not to transition the aerosol generating device from a locked state to an unlocked state if the user unsuccessfully attempts to enter valid authentication information during the offline phase.

[0040] The method may further include determining the validity of the user-input credentials using a key derivation mechanism.

[0041] The method may be performed by an aerosol generating device, and / or by an aerosol generating system including the aerosol generating device, and / or by a companion device for the aerosol generating device. More specifically, the method may be performed by a control circuit of the aerosol generating device, by a control circuit of a companion device, or by a control circuit of a system including the aerosol generating device and a companion device. The method may also be performed in a distributed manner, such that different steps of the method are performed by different components of the system. The method of the fifth aspect may be computer-implemented.

[0042] According to a seventh aspect, there is provided a server-implemented method for conducting an online phase of an authentication process in conjunction with an aerosol generating device and / or a companion device and / or an aerosol generating system and / or one or more other computing devices. More specifically, there is provided a method for unlocking an unlockable feature of an aerosol generating device, the method comprising: receiving, by the server, an unlock request from the aerosol generating device to unlock the unlockable feature, the unlock request including unique device identification information that identifies the aerosol generating device and time-limited nonce information corresponding to the unlockable feature; and transmitting an unlock authorization to the aerosol generating device to unlock the unlockable feature in response to the transmitted unlock request.

[0043] According to an eighth aspect, there is provided a computing system configured to perform the method of the sixth and / or seventh aspects.

[0044] According to a ninth aspect, there is provided a computer program which, when executed by a computing system, is capable of, or comprises instructions to cause the computing system to perform, the method of the sixth aspect and / or the seventh aspect.

[0045] According to a tenth aspect, there is provided a computer-readable medium comprising instructions that, when executed by a computing system, can or causes the computing system to implement the sixth and / or seventh aspects. The computer-readable medium may be transitory or non-transitory, volatile or non-volatile.

[0046] As used herein, "offline" refers to a phase of an authentication process that is connectivity-free, connectivity-independent, or connectivity-independent, in the sense that the offline phase is performed while the aerosol generating device or the aerosol generating system that includes the aerosol generating device is disconnected or offline. In other words, "offline" refers to a phase of an authentication process in which an aerosol generating device transitioning from a locked state to an unlocked state does not depend on the control circuitry, aerosol generating system, or aerosol generating device receiving a signal from an external computing device. Additionally or alternatively, "offline" refers to a phase of an authentication process in which an aerosol generating device transitioning from a locked state to an unlocked state does not depend on the control circuitry, aerosol generating system, or aerosol generating device being connected (or "paired") with an external computing device.

[0047] Accordingly, the term "online phase" should be interpreted as a phase of the authentication process that uses a device connection for the purpose of conducting the authentication process while the aerosol generating device or an aerosol generating system comprising the aerosol generating device is in a connected or online state. The online and offline phases may alternatively be described in terms of online and offline modalities, respectively. In other words, "online" refers to a phase of the authentication process in which an aerosol generating device transitioning from a locked state to an unlocked state relies on the control circuitry, aerosol generating system, or aerosol generating device receiving a signal from an external computing device. Additionally or alternatively, "online" refers to a phase of the authentication process in which a device transitioning from a locked state to an unlocked state relies on the control circuitry, aerosol generating system, or aerosol generating device being connected (or paired) with an external computing device.

[0048] For example, the control circuitry may be further configured to perform an offline phase of the authentication process without the aerosol generating device (or any part of a system including the aerosol generating device) being connected (or requiring connection) to an external computing device (e.g., a mobile phone, personal computer, or tablet device). Additionally or alternatively, the control circuitry may be further configured to perform the offline phase without transmitting or receiving authentication-related data from an external computing device, where "authentication-related data" includes, for example, data used by the authentication process or necessary for authentication, even when the aerosol generating device is connected to an external computing device. The control circuitry may be further configured to perform the offline phase without being controlled by and / or controlling an external computing device. The control circuitry may be further configured to perform the offline phase without the aerosol generating device being connected to or forming part of a network including one or more external computing devices, such as the Internet. "Offline" may refer to any existing connection of the aerosol generating device that is not being used for authentication-related purposes or tasks, regardless of whether the aerosol generating device is connected / connectable to an external computing device. For example, "offline" may refer to a state or phase in which data is exchanged during the authentication process by any communication interface of the aerosol generating device, but that connectivity is not input to or output from the control circuitry, or more specifically, its threads or components that are performing authentication-related tasks. In other words, the aerosol generating device may include a communication interface for managing connections to external computing devices, and "offline" indicates that during the offline phase of the authentication process, the communication interface remains idle or performs only tasks unrelated to the authentication process.

[0049] It should be noted that the term "external computing device," when used in connection with the term "offline," does not include either the companion device or the aerosol generating device, where authentication is performed by other devices. Rather, in the context of the present disclosure, the term "external computing device" may refer to a computing device configured to communicate with the aerosol generating device and / or the companion device, for example, based on the exchange of data or information. Generally, an external computing device may be a handheld or portable device. Alternatively, an external computing device may be a standalone or fixedly attached device. Furthermore, an external computing device may be owned by or installed by a user or another entity or individual, such as a retail store. By way of example, an external computing device may refer to a handheld smartphone, personal computer ("PC"), tablet PC, laptop, or computer. An external computing device may include a user interface. An external computing device may include one or more processors for data processing, such as processing one or more user inputs received at a user interface. Alternatively or additionally, the external computing device may include data storage and / or memory for storing data such as, for example, software instructions, computer programs, and / or other data. Furthermore, the external computing device may include a communications interface, communications module, and / or communications circuitry for communicatively coupling the external computing device with the aerosol-generating device, for example, via a communications interface of the companion device. Thus, the external computing device may be configured for wireless and / or wired communications with the aerosol-generating device, the companion device, or both.For example, the external computing device may be configured to be communicatively coupled to the aerosol generating device and / or companion device via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection, a cellular network, a 3G / 4G / 5G connection, an edge connection, an LTE connection, a BUS connection, a wireless connection, a wired connection, a radio connection, a short-range connection, an IoT connection, or any other connection using any suitable communication protocol.

[0050] As used herein, the term "locked state" may refer to a locked configuration of an aerosol generation device, and the term "unlocked state" may refer to an unlocked configuration of an aerosol generation device. In a locked state or configuration, the aerosol generation device is prohibited from delivering and / or generating aerosol. This may mean that the aerosol generation device is locked from aerosol consumption by a user in the locked state and / or that the aerosol generation device is configured in the locked state such that aerosol is not delivered and / or generated. On the other hand, in an unlocked state or configuration, the aerosol generation device is permitted or allowed to deliver and / or generate aerosol. This may mean that the aerosol generation device is unlocked from aerosol consumption by a user in the unlocked state and / or that the aerosol generation device is configured in the unlocked state such that aerosol can be delivered and / or generated. Thus, when the aerosol generating device is in a locked state, the aerosol generating device may not be operable by the user to deliver and / or generate aerosol, and when the aerosol generating device is in an unlocked state, the aerosol generating device may be operable by the user to deliver and / or generate aerosol. In other words, when the aerosol generating device is in a locked state, the user may be prohibited from accessing one or more functions of the aerosol generating device, including aerosol delivery and / or generation, and when the aerosol generating device is in an unlocked state, the user may be permitted to access one or more functions of the aerosol generating device, including aerosol delivery and / or generation. Additionally or alternatively, the companion device may be configured to charge the energy storage of the aerosol generating device only upon successful authentication of the user. In this example, the locked state may be considered to mean that the energy storage of the aerosol generating device does not contain a sufficient charge to generate aerosol, and the unlocked state may be considered to mean that the energy storage contains a sufficient charge to generate aerosol. The authentication signal may then be considered to be the companion device providing a charge to the energy storage of the aerosol generating device.In the locked state, the control circuit may be configured to prohibit activation of the heating elements based on, for example, at least one of disabling the at least one heating element, disabling an energy supply source for supplying electrical energy to the at least one heating element, and disabling an input element for activating the at least one heating element by a user.

[0051] As used herein, the term "transition" may mean causing, configuring, and / or switching the aerosol generating device into a locked or unlocked state, and may mean or include operating and / or configuring the aerosol generating device so that the aerosol generating device is in a locked or unlocked state.

[0052] As used herein, the term "authentication" refers to the verification of a user's identity.

[0053] As used herein, the term "authorization" refers to determining a user's access rights, i.e., the user's right to transition the aerosol generating device from a locked state to an unlocked state. In the context of the YAP method, a user's identity is intrinsically tied to their access rights, and therefore the terms "authentication" and "authorization" can be used interchangeably in this disclosure.

[0054] As used herein, the term "authorized user" (also referred to as "verified user") may refer to or denote a user authorized to configure an aerosol generating device by another authorized user, such as the owner of the aerosol generating device, an adult, an adult individual, a user of full age, a user who has reached an age threshold, a user who has reached the age of majority, and / or the owner. Additionally, an unauthorized user may refer to or denote a minor user, a user under the age threshold, a child, or other user who is not authorized to configure the aerosol generating device, particularly a user who is not authorized to transition the aerosol generating device to an unlocked state for aerosol consumption.

[0055] As used herein, the term "circuitry" may include, for example, alone or in any combination, hardwired circuitry, programmable circuitry such as a computer processor including one or more individual instruction processing cores, state machine circuitry, and / or firmware that stores instructions performed by the programmable circuitry. Modules may be embodied as circuitry that collectively or individually form part of one or more devices or systems described herein.

[0056] As used herein, the term "acquiring" may include, for example, receiving from another system, device, or process; receiving through interaction with a user; loading or retrieving from a storage device or memory; and measuring or capturing using a sensor or other data acquisition device.

[0057] As used herein, the term "determining" encompasses a wide variety of operations and may include, for example, calculating, computing, processing, deriving, investigating, looking up (e.g., consulting a table, database, or another data structure), ascertaining, etc. "Determining" may also include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), etc. "Determining" may also include resolving, selecting, choosing, establishing, etc.

[0058] The indefinite articles "a" or "an" do not exclude a plurality. In addition, as used herein, the articles "a" and "an" should generally be construed to mean "one or more" unless otherwise specified or unless it is clear from the context that a singular reference is made.

[0059] Unless otherwise specified or clear from context, as used herein, the phrases "one or more of A, B, and C," "at least one of A, B, and C," and "A, B, and / or C" are intended to mean all possible permutations of one or more of the listed items. That is, the phrase "A and / or B" means (A), (B), or (A and B), while the phrase "A, B, and / or C" means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).

[0060] The term "comprising" does not exclude other elements or steps. Furthermore, terms such as "include", "comprise", "have" and the like may be used interchangeably herein. [Example]

[0061] The following provides a non-exhaustive list of non-limiting examples, any one or more of the features of these examples may be combined with any one or more features of any other example, embodiment, or aspect described herein.

[0062] Example 1 1. A control circuit for an aerosol generating device, or for an aerosol generating system comprising an aerosol generating device, the aerosol generating device having a locked state in which the aerosol generating device is prohibited from delivering an aerosol, and an unlocked state in which the aerosol generating device is permitted to deliver an aerosol, the control circuit being configured to implement an authentication process for authenticating a user, the control circuit comprising: During an offline phase of the authentication process, allowing the user to make a first predetermined number of attempts to enter valid authentication information using one or more user interface components; determining to transition the aerosol generating device from a locked state to an unlocked state in response to receiving valid authentication information from the user before a first predetermined number of attempts; The control circuit is configured to proceed to an online phase of the authentication process in response to determining that a first predetermined number of attempts has been exceeded before the user enters valid authentication information. Example 2. responding to a user's unsuccessful attempt to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, the second predetermined number of attempts being less than the first predetermined number of attempts; 2. The control circuit of example 1, configured to delay the offline phase until a first time delay period has elapsed if a second predetermined number of attempts has been exceeded. Example 3. 3. The control circuit of example 2, configured to continue the offline phase without delay if a second predetermined number of attempts is not exceeded. Example 4. responding to a user's unsuccessful attempt to enter valid authentication information during the offline phase by determining whether a third predetermined number of attempts has been exceeded, the third predetermined number of attempts being less than the first predetermined number of attempts and greater than the second predetermined number of attempts; 4. The control circuit of example 2 or 3, configured to delay the offline phase until a second time delay period has elapsed if a third predetermined number of attempts has been exceeded. Example 5. 5. The control circuit of example 4, configured to continue the offline phase without delay if a third predetermined number of attempts is not exceeded. Example 6 6. The control circuit of any one of examples 4 to 5, wherein the second time delay period is longer than the first time delay period. Example 7 A control circuit described in any of Examples 2 to 6, configured to delay the offline phase by prohibiting the user from entering further authentication information using one or more user interface components or by refraining from authenticating the user based on the user's entry of further authentication information. Example 8 A control circuit described in any of Examples 1 to 7, configured to receive user-input authentication information from one or more user interface components during each attempt of the offline phase and authenticate the user by determining validity of the user-input authentication information. Example 9. 9. The control circuit of example 8, configured to receive user-input authentication information during a plurality of time windows of a predetermined duration, each time window corresponding to a respective digit of a series of numbers forming the authentication information, and to attribute user input received via one or more user interface components during the time window to the digit corresponding to the time window. Example 10. The control circuit of example 9 is configured to trigger a timeout in response to no user input being received by one or more user interface components within a predetermined time period starting from the beginning of each of the time windows. Example 11 11. The control circuit of example 9 or 10, configured to initiate an initial one of the time windows in response to a user interacting with one or more user interface components. Example 12 12. The control circuit of example 11, configured to initiate a first one of the time windows in response to receiving a predetermined signal generated by a user interacting with one or more user interface components. Example 13 13. The control circuit of example 12, wherein the one or more user interface components comprise a push button, and a predetermined signal is generated when the user presses the push button a predetermined number of times. Example 14. A control circuit as described in any of Examples 9 to 13, wherein there are auxiliary time windows before and / or between one or more time windows, and the control circuit is configured to determine that a user has unsuccessfully attempted to enter valid authentication information if no user input authentication is received during the auxiliary time window, store the received user input authentication, start the corresponding time window, and / or continue execution of the corresponding time window if user input authentication is received during the auxiliary time window. Example 15. 15. The control circuit of any of Examples 9-14, configured to control a user interface component to output a user-perceptible guidance signal indicating at least the beginning of each time window. Example 16. 16. The control circuit of any of Examples 9-15, configured to control a user interface component to output a user-perceptible guidance signal indicating that the time window is running. Example 17. A control circuit described in any of Examples 9 to 16, configured to control a user interface component to output a user-perceivable guidance signal indicating a digit of the sequence to which the user is being guided to provide input. Example 18. 18. The control circuit of Example 17, wherein the aerosol generating device has output elements corresponding to digit numbers in the sequence, and the control circuit is configured such that the position of active output elements relative to inactive output elements is used to indicate the position of the digit number in the sequence for which input is desired. Example 19. A control circuit described in any of Examples 9 to 18, configured to interpret multiple signals resulting from repeated user operation of the same user interface component during the time window as coded input signals defining digits of a sequence to which the time window corresponds. Example 20. 20. The control circuit of Example 19, wherein the user interface component is a power button for the aerosol generating device. Example 21. During the online phase of the authentication process, sending an unlock request to the server to transition the aerosol generating device from a locked state to an unlocked state, optionally the unlock request including unique device identification information identifying the aerosol generating device and / or time-limited nonce information corresponding to unlockable features of the aerosol generating device; receiving an unlock authorization from the server in response to the sent unlock request; and 21. The control circuit of any one of Examples 1 to 20, configured to transition the aerosol generation device from a locked state to an unlocked state in response to receiving an unlocking authorization. Example 22. 22. The control circuit of example 21, wherein the unlockable feature comprises the ability to use a heating element of the aerosol generating device to heat an aerosol-generating article and generate an aerosol therefrom. Example 23. 23. The control circuit of example 21 or 22, wherein the unlocking authorization is at least partially encrypted. Example 24. 24. The control circuit of example 23, wherein the unlocking authorization is decryptable using a public key stored on the aerosol generating device. Example 25. A control circuit described in any of Examples 21 to 24, configured to: in response to receiving an unlocking authorization, decrypt the unlocking authorization; determine whether the decrypted unlocking authorization includes unique device identification information and time-limited nonce information; and in response to determining that the decrypted unlocking authorization includes unique device identification information and time-limited nonce information, transition the aerosol generating device from a locked state to an unlocked state by unlocking the unlockable function. Example 26. 26. The control circuit of any of Examples 21 to 25, configured to terminate unlocking of the unlockable feature if no unlock authorization is received after a validity period after the unlock request is sent to the server. Example 27. 27. The control circuit of any one of Examples 21 to 26, configured to limit the number of unlocking authorizations sent to the aerosol generating device. Example 28. 28. The control circuit of any one of Examples 21 to 27, wherein the unique device identification comprises a serial number. Example 29. 29. The control circuit according to any one of Examples 1 to 28, wherein the authentication process includes a juvenile access prevention process. Example 30. A control circuit described in any of Examples 1 to 29, configured to respond by determining not to transition the aerosol generating device from a locked state to an unlocked state when a user attempts to enter valid authentication information but fails during the offline phase. Example 31. 31. The control circuit of any of embodiments 1-30, configured to use a key derivation mechanism to determine the validity of user-input authentication information. Example 32. An aerosol generating device comprising the control circuit according to any one of Examples 1 to 31. Example 33. An aerosol generating system comprising the control circuit and the aerosol generating device according to any one of Examples 1 to 31. Example 34. A companion device for an aerosol generating device, the companion device comprising the control circuit described in any one of Examples 1 to 31. Example 35. The aerosol generating device has a locked state in which the aerosol generating device is prohibited from delivering an aerosol and an unlocked state in which the aerosol generating device is permitted to deliver an aerosol, and the method comprises: During an offline phase of the authentication process, allowing a user to make a first predetermined number of attempts to enter valid authentication information using one or more user interface components; determining to transition the aerosol generating device from a locked state to an unlocked state in response to receiving valid authentication information from the user before a first predetermined number of attempts; A method for performing an authentication process to authenticate a user of an aerosol generating device, comprising: proceeding to an online phase of the authentication process in response to determining that a first predetermined number of attempts has been exceeded before the user enters valid authentication information. Example 36. determining whether a second predetermined number of attempts has been exceeded and responding when the user unsuccessfully attempts to enter valid authentication information during the offline phase, the second predetermined number of attempts being less than the first predetermined number of attempts; 36. The method of example 35, comprising delaying the offline phase until a first time delay period has elapsed if a second predetermined number of attempts has been exceeded. Example 37. 37. The method of example 36, further comprising continuing the offline phase without delay if the second predetermined number of attempts is not exceeded. Example 38. determining whether a third predetermined number of attempts has been exceeded and responding when the user unsuccessfully attempts to enter valid authentication information during the offline phase, the third predetermined number of attempts being less than the first predetermined number of attempts and greater than the second predetermined number of attempts; 38. The method of example 36 or 37, comprising delaying the offline phase until a second time delay period has elapsed if a third predetermined number of attempts has been exceeded. Example 39. 39. The method of example 38, further comprising continuing the offline phase without delay if a third predetermined number of attempts is not exceeded. Example 40. 40. The method of example 38 or 39, wherein the second time delay period is longer than the first time delay period. Example 41. A method described in any of Examples 36 to 40, comprising delaying the offline phase by using one or more user interface components to prohibit the user from entering further authentication information or by refraining from authenticating the user based on the user's entry of further authentication information. Example 42. A method as described in any of Examples 35 to 41, comprising, during each attempt of the offline phase, receiving user-input authentication information from one or more user interface components, and authenticating the user by determining the validity of the user-input authentication information. Example 43. 43. The method of claim 42, comprising receiving user-input authentication information during a plurality of time windows of a predetermined period, each time window corresponding to a respective digit of a series of numbers forming the authentication information, and attributing user input received via one or more user interface components during the time windows to the digit corresponding to the time window. Example 44. 44. The method of claim 43, comprising triggering a timeout within a predetermined period starting from the beginning of each of the time windows in response to no user input being received by one or more user interface components. Example 45. 45. The method of example 43 or 44, comprising initiating an initial one of the time windows in response to a user interacting with one or more user interface components. Example 46. 46. ​​The method of example 45, comprising initiating a first one of the time windows in response to receiving a predetermined signal generated by a user interacting with one or more user interface components. Example 47. 47. The method of claim 46, wherein one or more user interface components comprise a push button, and a predetermined signal is generated when the user presses the push button a predetermined number of times. Example 48. 48. The method of any of Examples 43 to 47, wherein there is an auxiliary time window before and / or between one or more time windows, and the method further includes: determining that an attempt by the user to input valid authentication information has failed if no user input authentication is received during the auxiliary time window; storing the received user input authentication and starting the corresponding time window and / or continuing to execute the corresponding time window if a user input authentication is received during the auxiliary time window. Example 49. 49. The method of any of Examples 43-48, comprising controlling a user interface component to output a user-perceptible guidance signal indicating at least the beginning of each time window. Example 50. 50. The method of any of Examples 43-49, comprising controlling a user interface component to output a user-perceptible guidance signal indicating that the time window is running. Example 51. 51. The method of any of Examples 43-50, comprising controlling a user interface component to output a user-perceptible guidance signal indicating a digit of the sequence to which the user is being guided to provide input. Example 52. 52. The method of example 51, wherein the aerosol generating device is provided with output elements corresponding to digit numbers in the sequence, and the method includes using the position of active output elements relative to inactive output elements to indicate the position of the digit in the sequence for which input is required. Example 53. 53. The method of any of Examples 43-52, comprising interpreting a plurality of signals resulting from repeated user operation of the same user interface component during the time window as coded input signals defining a digit of the sequence to which the time window corresponds. Example 54. The method of Example 53, wherein the user interface component is a power button on the aerosol generating device. Example 55. During the online phase of the authentication process, sending an unlock request to the server to transition the aerosol generating device from a locked state to an unlocked state, the unlock request including unique device identification information that identifies the aerosol generating device and time-limited nonce information corresponding to unlockable features of the aerosol generating device; receiving an unlock authorization from the server in response to the transmitted unlock request; 55. The method of any of Examples 35-54, comprising transitioning the aerosol generating device from a locked state to an unlocked state in response to receiving the unlock authorization. Example 56. 56. The method of example 55, wherein the unlockable feature comprises the ability to use a heating element of the aerosol-generating device to heat the aerosol-generating article and generate an aerosol therefrom. Example 57. 57. The method of example 55 or 56, wherein the unlocking authorization is at least partially encrypted. Example 58. The method of Example 57, wherein the unlocking authorization includes decrypting using a public key stored on the aerosol generating device. Example 59. A method according to any of examples 55 to 58, comprising, in response to receiving an unlocking authorization, decrypting the unlocking authorization, determining whether the decrypted unlocking authorization includes unique device identification information and time-limited nonce information, and, in response to determining that the decrypted unlocking authorization includes unique device identification information and time-limited nonce information, transitioning the aerosol generating device from a locked state to an unlocked state by unlocking an unlockable function. Example 60. 60. The method of any of Examples 55 to 59, comprising terminating the unlocking of the unlockable feature if an unlock authorization is not received after a validity period after the unlock request is sent to the server. Example 61. 61. The method of any of Examples 55-60, comprising limiting the number of unlock authorizations sent to the aerosol generating device. Example 62. 62. The method of any of Examples 55-61, wherein the unique device identification is a serial number. Example 63. 63. The method of any one of Examples 35 to 62, wherein the authentication process includes a juvenile access prevention process. Example 64. A method described in any of Examples 35 to 63, comprising responding by deciding not to transition the aerosol generating device from a locked state to an unlocked state if a user unsuccessfully attempts to enter valid authentication information during the offline phase. Example 65. 65. The method of any of examples 35-64, comprising using a key derivation mechanism to determine the validity of user-input authentication information. Example 66. The method of any one of Examples 35 to 65, carried out by an aerosol generating device. Example 67. The method of any one of Examples 35 to 66, carried out by an aerosol generating system comprising an aerosol generating device. Example 68. The method of any of Examples 35 to 67, carried out by a companion device for an aerosol generating device. Example 69. A computer program comprising instructions that, when executed by a computing system, cause the computing system to perform the method described in any of Examples 35 to 68. Example 70. A computer-readable medium comprising instructions that, when executed by a computing system, cause the computing system to perform the method of any of Examples 35-68.

[0063] The present invention may include one or more aspects, embodiments, or features, whether specifically disclosed in that combination or separately, singly or in combination. Any optional feature or sub-aspect of one of the above-described aspects applies to any of the other aspects, as appropriate. [Brief explanation of the drawings]

[0064] The embodiments will now be further described with reference to the figures.

[0065] [Figure 1] FIG. 1 illustrates a schematic representation of an aerosol generation system comprising an aerosol generating device. [Figure 2] FIG. 2 illustrates a schematic representation of a portion of the companion device in the aerosol generating system of FIG. [Figure 3] FIG. 3 schematically illustrates an external computing device for use in conjunction with the aerosol generation system of FIG. [Figure 4] FIG. 4 is a flow chart illustrating an authentication process for authenticating a user of the aerosol generating device of FIG. [Figure 5] FIG. 5 is a flowchart illustrating a method for generating authentication information and transmitting it to a user. [Figure 6] FIG. 6 is a flow chart illustrating a method of device activation including steps from factory to user activation.

[0066] The figures are schematic and not to scale. DETAILED DESCRIPTION OF THE INVENTION

[0067] 1 shows an aerosol generation system 500 for generating an aerosol, for example for consumption by a user. The system 500 comprises an aerosol generation device 100 for generating the aerosol and a companion device 300 for at least partially receiving the aerosol generation device 100 and for charging the aerosol generation device 100.

[0068] The aerosol-generating device 100 includes an insertion opening 101 for at least partially inserting an aerosol-generating article (not shown). The aerosol-generating article includes an aerosol-forming substrate, such as a tobacco-containing substrate, and / or a cartridge containing a liquid. The aerosol-forming substrate may include nicotine.

[0069] The aerosol generating device 100 further includes a control circuit 102 having one or more processors 103. The control circuit 102 may be configured to control the activation, activation, and / or deactivation of at least one heating element 120.

[0070] The aerosol generating device 100 further includes a user interface component including an input element in the form of a push button 104. The push button 104 is operable by a user to input a pin code into the control circuit 102, as described further below. After successful completion of the authentication process, the push button 104 may further be used as a power button to activate or deactivate the heating element 120 for aerosol generation, thereby activating or deactivating the aerosol generating device 100. The push button 104 may also include an output element (e.g., one or more waveguides transmitting light from an LED) to indicate the status of the device 100 to the user. These options simplify the device 100. Upon activation of the aerosol generating device 100, the heating element 120 is activated, thereby applying heat to at least a portion of the aerosol-generating article, thereby generating aerosol for consumption by the user. Upon deactivation of the aerosol generating device 100, the heating element 120 is deactivated, thereby applying no or reduced heat to at least a portion of the aerosol-generating article, thereby generating no aerosol for consumption by the user. The user interface component further includes an output element in the form of an LED array 112 and a tactile output element (not shown) for providing a tactile pulse. The output element provides a user-perceptible guidance signal to the user. The LED array 112 may further be used to indicate the charge level of the at least one energy storage unit 122, for example, whether the at least one energy storage unit needs to be charged. The LED array 112 may also be used to indicate the configuration or status of the aerosol generation device 100, for example, whether the aerosol generation device is in a locked or unlocked state.

[0071] The aerosol generating device 100 further includes a communication device 106 having one or more communication interfaces 108 for communicatively linking the aerosol generating device 100 with the companion device 300, for example, via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection, a cellular network, a 3G / 4G / 5G connection, an edge connection, an LTE connection, a BUS connection, a wireless connection, a wired connection, a radio connection, a short-range connection, and / or an IoT connection.

[0072] The aerosol generating device 100 further includes a data storage 110 for storing information or data, such as, for example, at least one authentication indicator and / or other data.

[0073] The aerosol generating device 100 further includes at least one electrical connector 114 for coupling to at least one corresponding electrical connector 313 of the companion device 300. For example, when the aerosol generating device 100 is at least partially inserted into the opening 301 of the companion device 300, the one or more electrical connectors 114 of the aerosol generating device 100 may couple with the one or more electrical connectors 313 of the companion device 300 to charge at least one energy storage unit 122 of the aerosol generating device 100.

[0074] To generate aerosol during use or consumption of the aerosol-generating article, the aerosol-generating device 100 includes at least one heating element 120 or heat source 120 for heating at least a portion of the aerosol-generating article.

[0075] To power the at least one heating element 120, the aerosol generating device 100 further comprises at least one energy storage unit 122 or energy source 122 for storing electrical energy or power.

[0076] The aerosol generation device 100 has a locked state in which the aerosol generation device 100 is prohibited from delivering an aerosol, and an unlocked state in which the aerosol generation device 100 is permitted to deliver an aerosol.

[0077] In use, the control circuit 102 is configured to allow a user to make a first predetermined number of attempts to input valid authentication information using one or more user interface components during the offline phase of the authentication process, to determine to transition the aerosol generating device from a locked state to an unlocked state in response to receiving valid authentication information from the user before the first predetermined number of attempts is exceeded, and to proceed to the online phase of the authentication process in response to determining that the first predetermined number of attempts has been exceeded before the user enters valid authentication information.

[0078] One non-limiting example of an authentication process is now described. In this non-limiting example, the authentication process includes a YAP process that transitions from an offline phase to an online phase after a number of failed attempts. In this non-limiting example, the user uses pushbuttons 104 to enter a four-digit pin code (each digit ranging from 1 to 9). If the pin is entered incorrectly multiple times, the user must connect the aerosol generating device 100 to an external computing device, such as a smartphone via Bluetooth or a personal computer via USB. This allows the user to proceed to the online phase of the YAP process using a website provided for that purpose. Once the age verification process is successfully completed on the website, the aerosol generating device 100 is automatically unlocked.

[0079] To enter the offline phase of the YAP process, the user presses the push button 104 five times within three seconds. The aerosol generating device 100 responds to the one-second tactile pulse by causing the first LED (referred to herein as LED1) of the LED array 112 to begin flashing, indicating to the user that the first digit must be entered into the aerosol generating device 100. Thus, the first LED (LED1) corresponds to the first digit of the pin code. In this manner, the control circuit 102 controls the LED array 112 to indicate the digit of the pin code that the user is being guided to provide input for. Furthermore, the flashing of LED1 indicates to the user that a first time window is running, during which the first digit must be entered. The start of the flashing indicates the start of the time window. The control circuit 102 interprets multiple signals resulting from repeated user actuation of the push button 104 during the first time window as coded input signals defining the first digit of the pin code. In one illustrative example, if a user wishes to enter pin code 3521, they must press push button 104 three times while LED1 is flashing during the first time window. The three signals resulting from repeatedly pressing push button 104 during the first time window define a coded input signal that is interpreted by control circuit 102 as the digit "3." This digit received during the first time window is assigned by control circuit 102 to correspond to the first digit of the pin code.

[0080] A double timeout is implemented to allow sufficient time for the user to begin pressing the pushbutton 104. The first timeout is configured for 15 seconds to allow sufficient time for the user to understand the process. If the pushbutton 104 is not pressed within these first 15 seconds, the control circuitry determines not to transition the device 100 to the unlocked state. In one example, the device 100 turns off in response to the triggering of the first timeout. If the pushbutton 104 is pressed once (before the first timeout expires), a second timeout begins, and the user has an additional seven seconds to complete the first digit before the end of the first time window. The end of the first time window defines the point at which the control circuitry 102 no longer attributes the received user input to the first digit.

[0081] At the end of the first time window, LED1 turns off and LED2 begins flashing, indicating that the user is being prompted to enter the second digit during a second time window having a predetermined duration of 7 seconds. While LED2 is flashing during the second time window, the user must press push button 104 five times (for example pin code 3521) to generate a coded input signal defining the second digit of the pin code.

[0082] At the end of the second time window, LED2 turns off and LED3 begins flashing, prompting the user to enter the third digit. To continue with exemplary pin code 3521, the user must press push button 104 twice while LED3 is flashing during the third time window of 7 seconds.

[0083] At the end of the third time window, LED3 turns off and LED4 begins flashing, prompting the user to enter the fourth and final digit. Continuing the example above, the user only needs to press push button 104 once while LED4 is flashing. At the end of the fourth time window, LED4 turns off and all LEDs flash simultaneously for three seconds.

[0084] Thus, the control circuit 102 receives user input during multiple time windows of a predetermined duration. Each time window corresponds to a different digit of the pin code, with the first time window corresponding to the first digit, the second time window corresponding to the second digit, and so on. The control circuit 102 attributes user input received via the pushbuttons 104 during one of the time windows to the digit corresponding to that time window. User input received during the first time window is attributed to the first digit, user input received during the second time window is attributed to the second digit, and so on.

[0085] After the end of the final time window, the control circuit 102 compares the user-entered pin code with a pre-stored reference pin code and, based on the results of the comparison, determines whether to transition the aerosol generating device 100 from a locked state to an unlocked state. If the pin code is entered successfully, the device 100 is transitioned to the unlocked state and the device 100 is ready for use. If the pin is entered incorrectly, the control circuit 102 determines to transition the aerosol generating device 100 from a locked state to an unlocked state and allows further attempts according to the following protocol:

[0086] After five unsuccessful attempts, the user must wait five minutes.

[0087] After five or more failed attempts, the user must wait 20 minutes.

[0088] After five more failed attempts, the user must proceed to the online phase of the YAP process, thereby ending the offline phase of the YAP process, and the aerosol generating device 100 can only be unlocked during the online phase.

[0089] In one non-limiting example, the online phase of the YAP process includes the following steps: 1. The device 100 sends an unlock request to the server 1000 including unique device identification information such as its serial number and nonce information corresponding to the unlockable features of the aerosol generating device 100. 2. If the user is authenticated, the device 100 receives an at least partially encrypted unlock authorization from the server 1000. 3. The device 100 decrypts the unlock authorization using the public key stored on the aerosol generating device 100. 4. The device 100 determines whether the decrypted unlock permit contains the unique device identification information and nonce information. 5. If so, the device 100 transitions from the locked state to the unlocked state.

[0090] In this example, the nonce information is time-limited such that if an unlock grant is not received after the validity period after the unlock request is sent to the server, the process terminates and optionally restarts from step 1.

[0091] In a further non-limiting example, the online phase of the YAP process includes the following steps:

[0092] 1. The server 1000 (shown in FIG. 3) requests the current state of the feature that one wishes to lock or unlock. 2. The aerosol generating device 100 responds with a functional status. 3. If the server 1000 wishes to change the functional status, it requests unique information of the aerosol generating device 100, such as its serial number. 4. The aerosol generating device 100 transmits this to the server 1000. 5. The server 1000 then requests that the aerosol generating device 100 generate a unique value (nonce) associated with the functionality to be locked or unlocked. 6. The aerosol generating device 100 generates a nonce and sends it to the server 1000. 7. The aerosol generating device 100 starts a validity timer by which the unlocking process must be completed. If the procedure fails or is not completed within the validity period, the current process is invalidated and restarted from step 1. 8. The server 1000 creates a string (hereinafter referred to as a "message") consisting of the lock / unlock request, the aerosol generating device 100's unique information, a nonce, and some additional padding. 9. The server 1000 encrypts the message using the asymmetric private key and sends the result (the encrypted message) to the aerosol generating device 100. 10. The aerosol generating device 100 receives the encrypted message and decrypts it using the server's 1000 public key (stored on the aerosol generating device 100). 11. The aerosol generating device 100 verifies whether the decrypted message respects the predetermined format and contains the original nonce, the unique device information, and requests a change in the state of the function associated with the nonce.

[0093] If all of the above conditions are met and the validity timer has not expired, the aerosol generating device 100 changes its functional state, otherwise the process is invalid and must be restarted from step 1.

[0094] In any of the non-limiting examples described above, the pin code may be generated by a key derivation mechanism (not shown) on the aerosol generating device 100. The key derivation mechanism is symmetric, meaning that the server generates the same pin code as the aerosol generating device 100.

[0095] It will be understood that the operations described above as being performed under the control of the control circuitry 102 of the aerosol generating device 100 may be performed by the control circuitry 302 of the companion device 100 (as described below) or by the system 500 as a whole, with control being distributed between the control circuitry 102 of the aerosol generating device 100 and the control circuitry 302 of the companion device 300. Furthermore, the user interface components used to input and output information may include those of the aerosol generating device 100, those of the companion device 300 (described below), or any combination of input and output elements of the aerosol generating device 100 and the companion device 300. To further illustrate these possibilities, the companion device 300 will now be described.

[0096] The companion device 300 may be configured to physically couple to the aerosol generating device 100. To at least partially receive the aerosol generating device 100 and / or to physically couple the aerosol generating device 100 to the companion device 300, the companion device 300 includes an opening 301 or receiving opening 301 into which the aerosol generating device 100 can be at least partially inserted, e.g., to store and / or support the aerosol generating device 100. Optionally, the companion device 300 may include a cover for opening and closing the opening 301. Alternatively or additionally, the companion device 300 may be configured to at least partially receive the aerosol generating device 100 based on coupling the aerosol generating device 100 to a mechanical attachment or coupling mechanism of the companion device 300, e.g., a hook mechanism, a latch mechanism, a snap fit, etc. Alternatively or additionally, the companion device 300 may be configured to receive the aerosol generating device 100, at least in part, based on coupling the aerosol generating device 100 to the companion device 300 via magnetic or electromagnetic coupling. To this end, the companion device 300 includes a charging module 312 or charging circuit 312 coupled to an electrical connector 313. The charging module 312 may be coupled, for example, to a power grid for supplying electrical energy to the energy storage unit 122 of the aerosol generating device 100. Alternatively or additionally, the companion device 300 may include one or more batteries, accumulators, capacitors, etc. The companion device 300 includes a user interface component including a push button 304 and a visual indicator 314, such as, for example, one or more LEDs 314 and / or an LED array 314. The companion device 300 further includes data storage 306 for storing information or data, such as authentication indicators, reference authentication information, and / or other data. The control circuitry 302, data storage 306 and user interface components may be embodied in a single unit.In this way, a user can be authenticated without the authentication information ever leaving the single unit, thereby improving security. The companion device 300 further comprises a communication unit 308 having one or more communication interfaces 310 for communicatively coupling the aerosol generating device 100 and the companion device 300, for example, via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection, a cellular network, a 3G / 4G / 5G connection, an edge connection, an LTE connection, a BUS connection, a wireless connection, a wired connection, a radio connection, a short-range connection, and / or an IoT connection.

[0097] The companion device 300 further comprises a control circuit 302 including one or more processors 303. The control circuit 302 may be configured to control the charging module 312 and / or other components or functions of the companion device 300. It should also be noted that the charging circuit or module 312 may be combined with or included in the control circuit 302. The control circuit may be configured to perform the authentication process as described herein. Thus, the user is not required to interact with the aerosol generating device 100, but rather performs the offline phase of the authentication process by interacting with the companion device 300. The control circuit 302 may unlock or lock the aerosol generating device in a variety of different ways after successfully authenticating the user, for example, by sending an unlock signal to the aerosol generating device.

[0098] FIG. 2 is a block diagram illustrating companion device 300 in more detail. Specifically, FIG. 2 schematically illustrates at least part 305 of control circuitry 302, including at least one processor 303, coupled to push button 304 via multiplexer 307. Therein, part 305 may be coupled to or comprise charging circuitry 312 and / or other electrical components of companion device 300. For example, at least part 305 of example control circuitry 302 illustrated in FIG. 2 may refer to main controller 305 of companion device 300. Furthermore, a port 309, such as a one-wire MT communication port (referred to as an “MTRTX” port), may be used to couple control circuitry 302 to multiplexer 307. This one-wire communication may be converted to two-wire communication via multiplexer 307. For example, a signal can be sent from the multiplexer 307 to an input port 315 (e.g., an RX port) of the push button 304, and a signal can be sent from an output port 317 (e.g., a TX port) of the push button 304 to the multiplexer 307. Therein, the multiplexer 307 may be controlled by the control circuit 302 via a port 311. Furthermore, in the example shown in FIG. 2 , at least one communication interface 310 is combined with or integrated into the electrical connector 313 so that an electrical connection for charging the energy storage unit 122 of the aerosol generating device 100 and a communicative link between the aerosol generating device 100 and the companion device 300 can be established via the electrical connector 114 of the aerosol generating device 100 and the connector 313 of the companion device.

[0099] 3 shows an external computing device 700 that may or may not be used with the aerosol generation system 500. The external computing device 700 includes a control circuit 704 that includes a user interface 702, one or more processors 705 for data processing, a communication interface 706 for communicatively coupling the external computing device 700 to the server 1000 or one or more of the aerosol generation system 500, and data storage 708 for storing data or information.

[0100] FIG. 4 shows a flowchart illustrating a method for implementing an authentication process for authenticating a user of the aerosol generating device 100. Unless otherwise noted, the aerosol generating device 100 includes the same features, elements, and / or functionality as described elsewhere herein. Step 401 involves implementing an offline phase of the authentication process, during which the user is allowed a first predetermined number of attempts to enter valid authentication information. Step 402 involves determining whether authentication is successful during the offline phase—that is, whether valid authentication information is received from the user before the first predetermined number of attempts is exceeded. If so, the method proceeds to step 404, where a decision is made to transition the aerosol generating device 100 from a locked state to an unlocked state. Otherwise, the method proceeds to the online phase of the authentication process in step 403. After successful resolution of the online phase, the method again proceeds to step 404. Otherwise, the online phase may be repeated, as described above. The method illustrated in FIG. 4 may include numerous alternative or additional steps, as described elsewhere herein.

[0101] 5 shows a flowchart illustrating a method in which step 501 includes generating authentication information for the offline phase of the authentication process. Step 502 includes transmitting the authentication information to a user for input into control circuitry 102 and / or 302 as user-entered authentication information. Unless otherwise noted, the aerosol generating device 100 and control circuitry 102 and / or 302 include the same features, elements, and / or functionality as described elsewhere herein. The method illustrated in FIG. 5 may include numerous alternative or additional steps, as described elsewhere herein.

[0102] FIG. 6 is a flowchart illustrating a method for device activation, including steps from factory to user activation. Step 601 involves storing a pin code in the encrypted firmware of the aerosol generating device 100 at the factory. The user then acquires the device 100 and activates and uses it using one of the flows beginning with steps 602, 607, and 609, respectively. If the user is already registered, the method proceeds to step 602, where a hard age verification is performed if not already performed. Step 603 registers the device 100 to the user if not already performed. Step 604 involves the user entering or scanning an ID code (code) on a website to generate a pin code, as described elsewhere herein. Step 605 involves the user entering the pin code into the device 100 using pushbutton 104 in the manner described above. If the user is not yet registered, the method instead proceeds from step 601 to step 607, where hard-age verification is again performed on the website, which indicates that the user is a guest user and is valid only for one device and one session. Step 608 involves the user entering or scanning an identification code on the website to generate a pin code, as was done in step 604. The method then proceeds again to step 605. If the user cannot access the website, the user may call the call center, in which case the method proceeds from step 601 to step 609, where the user is authenticated as a registered user or guest. For guest users, the method proceeds to step 610, where hard-age verification is performed. Step 611 involves the user entering an ID code into a call center tool to generate a pin code before the method proceeds to step 605. For registered users, the method proceeds from step 609 to step 612, where hard-age verification is performed, if not already performed. Step 613 involves registering device 100 with the user, if not already performed. The method then proceeds to step 611.Following step 605, a determination is made at 614 as to whether the entered pin code is correct. If so, the method proceeds to step 606, where device 100 is unlocked for use after successful authentication, as described above. If the entered pin code is incorrect, the method proceeds to step 615, where the number of failed attempts is incremented by one, and then to step 616, where a determination is made as to whether the number of failed attempts exceeds a predetermined threshold. If the threshold is not exceeded, the method returns to step 605. Otherwise, the method proceeds to the online phase at step 617. Although not shown, the method may further include a time delay step as described herein between steps 616 and 605. In FIG. 6, the generation of the pin code corresponds to step 501 of FIG. 5, while the user obtains the pin code via a website or call center in a step corresponding to step 502. Hard age verification may also be referred to herein as an age verification process. Importantly, entering the pin code in step 605 does not require any connection between the aerosol generating device 100 (or companion device 300) and any external computing device (such as those mentioned above) or the use of any app for this purpose.

[0103] Applicant hereby separately discloses each individual feature and any combination of two or more such features described herein to the extent that such feature or combination of features can be implemented based on the specification as a whole in light of the general knowledge common to those skilled in the art, regardless of whether such feature or combination of features solves any problem disclosed herein, and without limiting the scope of the claims. Applicant indicates that aspects of the invention may consist of any such individual feature or combination of features.

[0104] It should be noted that embodiments of the present invention are described with reference to different categories. In particular, some examples are described with reference to methods, and other examples are described with reference to apparatuses. However, those skilled in the art will understand from the description that, unless otherwise indicated, any combination of features belonging to one category, as well as any combination between features relating to different categories, is considered to be disclosed by the present application. However, all features can be combined to provide a synergistic effect that exceeds the simple sum of the features.

[0105] While the invention has been illustrated and described in detail in the drawings and foregoing description, such illustration and description is given by way of example and not by way of limitation. The invention is not limited to the disclosed embodiments. Other variations to the disclosed embodiments can be understood and effected by those skilled in the art, from a study of the drawings, the disclosure, and the appended claims.

[0106] The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage. Any reference signs in the claims should not be construed as limiting the scope.

Claims

1. 1. A control circuit for an aerosol generating device or for an aerosol generating system comprising said aerosol generating device, said aerosol generating device having a locked state in which said aerosol generating device is prohibited from delivering an aerosol, and an unlocked state in which said aerosol generating device is permitted to deliver an aerosol, said control circuit being configured to implement an authentication process for authenticating the user, said control circuit comprising: during an offline phase of the authentication process, allowing the user to make a first predetermined number of attempts to enter valid authentication information using one or more user interface components; determining to transition the aerosol generating device from the locked state to the unlocked state in response to receiving valid authentication information from the user before the first predetermined number of attempts is exceeded; control circuitry configured to proceed to an online phase of the authentication process in response to determining that the first predetermined number of attempts has been exceeded before the user enters valid authentication information.

2. responding to unsuccessful attempts by the user to enter valid authentication information during the offline phase by determining whether a second predetermined number of attempts has been exceeded, the second predetermined number of attempts being less than the first predetermined number of attempts; The control circuit of claim 1 , configured to delay the offline phase until a first time delay period has elapsed if the second predetermined number of attempts has been exceeded.

3. The control circuit of claim 2 , configured to continue the offline phase without delay if the second predetermined number of attempts is not exceeded.

4. responding to unsuccessful attempts by the user to enter valid authentication information during the offline phase by determining whether a third predetermined number of attempts has been exceeded, the third predetermined number of attempts being less than the first predetermined number of attempts and greater than the second predetermined number of attempts; 4. The control circuit of claim 2 or 3, wherein if the third predetermined number of attempts is exceeded, the offline phase is delayed until a second time delay period has elapsed, and the control circuit is configured to continue the offline phase without delay if the third predetermined number of attempts is not exceeded.

5. 5. The control circuit of claim 4, wherein the second time delay period is longer than the first time delay period.

6. The control circuit of any of claims 2 to 5, configured to delay the offline phase by prohibiting the user from entering further authentication information using the one or more user interface components or by refraining from authenticating the user based on the user entering further authentication information.

7. The control circuit of any of claims 1 to 6, configured to receive user-input authentication information from the one or more user interface components during each attempt of the offline phase and authenticate the user by determining validity of the user-input authentication information.

8. 8. The control circuit of claim 7, configured to receive the user-input authentication information during a plurality of time windows of a predetermined duration, each time window corresponding to a respective digit of a series of numbers forming the authentication information, and to attribute user input received via the one or more user interface components during the time window to the digit corresponding to the time window.

9. During the online phase of the authentication process: sending an unlock request to a server to transition the aerosol generating device from the locked state to the unlocked state, the unlock request including unique device identification information identifying the aerosol generating device and time-limited nonce information corresponding to unlockable features of the aerosol generating device; receiving an unlock authorization from the server in response to the transmitted unlock request; and A control circuit according to any preceding claim, configured to transition the aerosol generating device from the locked state to the unlocked state in response to receiving the unlock permission.

10. 10. The control circuit of claim 9, configured to transition the aerosol generating device from the locked state to the unlocked state by: decrypting the unlocking authorization in response to receiving the unlocking authorization; determining whether the decrypted unlocking authorization includes the unique device identification information and the time-limited nonce information; and unlocking the unlockable function in response to a determination that the decrypted unlocking authorization includes the unique device identification information and the time-limited nonce information.

11. The control circuit of any preceding claim, configured to use a key derivation mechanism to determine the validity of user-entered authentication information.

12. During the online phase of the authentication process: sending an unlock request to a server to transition the aerosol generating device from the locked state to the unlocked state, optionally the unlock request including unique device identification information identifying the aerosol generating device and / or time-limited nonce information corresponding to an unlockable feature of the aerosol generating device; receiving an unlock authorization from the server in response to the transmitted unlock request; and A control circuit according to any preceding claim, configured to transition the aerosol generating device from the locked state to the unlocked state in response to receiving the unlock permission.

13. An aerosol generating device comprising the control circuit according to any one of claims 1 to 12.

14. An aerosol generating system comprising the control circuit according to any one of claims 1 to 12 and the aerosol generating device.

15. A companion device for an aerosol generating device, comprising a control circuit according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • Handwritten signature authentication method

    JP2007334467A

  • Inhalation device with user recognition based on inhalation behavior

    JP2017538408A

  • Vaporizer Control

    JP2021508457A

  • Smoking device with authentication means

    WO2021228678A1

  • Systems, devices, and methods for unlocking aerosol-generating devices

    WO2021260600A1