Unlocking the aerosol generating system for use

Connectionless communication with BLE or WiFi packet analysis and secure unlock codes in aerosol generating systems address BLE pairing incompatibilities, enhancing YAP success rates and reducing firmware updates, ensuring secure and efficient underage access prevention.

JP2025539058APending Publication Date: 2025-12-03PHILIP MORRIS PRODUCTS SA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025526787
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-11-10
Filing Date
2023-11-02
Publication Date
2025-12-03

AI Technical Summary

Technical Problem

Existing aerosol generating systems face challenges with Bluetooth Low Energy (BLE) pairing incompatibilities with various external computing devices, leading to time-consuming and costly firmware updates to resolve issues, and low unlock success rates for youth access prevention methods.

Method used

Implementing connectionless communication using BLE or WiFi packet analysis to exchange unlock requests and permissions, utilizing pre-shared secrets and one-time random values for secure unlock codes, and verifying user authorization through devices known to be associated with authorized users.

Benefits of technology

Enhances compatibility and increases the youth access prevention (YAP) unlock success rate from 70-80% to 100%, reduces the need for firmware updates, and ensures robust underage access prevention with secure, efficient, and adaptable unlocking processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025539058000001_ABST
    Figure 2025539058000001_ABST
Patent Text Reader

Abstract

An aerosol generation system is provided that is in a locked state, preventing the aerosol generation system from generating aerosol. The aerosol generation system is configured to receive an unlock authorization from an external computing device using connectionless communication, and, after receiving the unlock authorization, transition the aerosol generation system from the locked state to an unlocked state, allowing the aerosol generation system to generate aerosol. Also provided is a server configured to determine whether the aerosol generation system is associated with an authorized user, and, if so, to send the unlock authorization to the aerosol generation system. Further provided is a computing device configured to receive the unlock authorization from the server and send the unlock authorization to the aerosol generation device.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an aerosol generation system having a locked state in which the aerosol generation system is prevented from generating an aerosol, and a method for unlocking the aerosol generation system for use. [Background technology]

[0002] An aerosol generating system may include an aerosol generating device and, optionally, a companion device for storing and / or charging the aerosol generating device. The aerosol generating device may be designed, for example, as a handheld device that can be used by a user to consume the aerosol generated by the aerosol generating article in one or more use sessions. The aerosol generating article may include an aerosol-forming substrate, such as a tobacco-containing substrate, often in the form of a stick. The stick may be configured in a shape and size to be at least partially inserted into the aerosol generating device and may include a heating element for heating the aerosol-forming substrate. Another exemplary aerosol-generating article may include a cartridge containing a liquid that can be evaporated during aerosol consumption by a user. Such a cartridge may also be configured in a shape and size to be at least partially inserted into the aerosol generating device. Alternatively, the cartridge may be fixedly attached to the aerosol generating device and refilled by inserting liquid into the cartridge.

[0003] To prevent underage users from accessing and using such aerosol generating devices, it is desirable to implement a youth access prevention (YAP) method. Existing YAP methods generally require a Bluetooth Low Energy (BLE) connection to unlock the aerosol generating system for use. The aerosol generating system must be properly paired with an external computing device, such as a smartphone or PC, which exchanges information with a server to obtain unlock permission to unlock the aerosol generating system. The inventors have recognized that some aerosol generating systems, particularly Android-based external computing devices, have difficulty successfully completing the BLE pairing process. Prior to the commercial release of an aerosol generating system, thorough testing is conducted to identify and resolve BLE incompatibilities. However, new external computing devices are released throughout the life of the aerosol generating system, and previously compatible devices may become incompatible after a firmware update. Taking action to resolve these incompatibilities is time-consuming and expensive, typically requiring firmware revisions to the aerosol generating system. Affected systems cannot be unlocked using BLE until new firmware is released. Even after updated firmware is released, affected systems may not be able to be updated using BLE due to pairing issues.

[0004] It would therefore be desirable to provide an apparatus and method for unlocking an aerosol generating system that mitigates or overcomes problems caused by incompatibility of BLE pairing with various external computing devices, or other types of connection difficulties, or the need to install and use a dedicated unlocking app.

[0005] Thus, according to a first aspect, there is provided an aerosol generation system in a locked state in which the aerosol generation system is prevented from generating aerosol. The aerosol generation system may be configured to send an unlock request to an external computing device using connectionless communication. The aerosol generation system may be further configured to receive an unlock authorization from the external computing device using connectionless communication, and, after receiving the unlock authorization, transition the aerosol generation system from the locked state to an unlocked state in which the aerosol generation system is able to generate aerosol. Summary of the Invention

[0006] In some embodiments described herein, the unlock permission is issued by an entity capable of determining whether a user is authorized. The server described herein is one such entity. In other embodiments, the unlock permission provides implicit permission to unlock the aerosol generating system, for example, based on the detected proximity of a device known to be associated with an authorized user. In this case, it can be reasonably assumed that use of the aerosol generating system will occur under the supervision of an authorized user.

[0007] According to a second aspect, a server is provided. The server may be configured to receive an unlock request identifying an aerosol generating system in a locked state. The server may be further configured to determine whether the aerosol generating system is associated with an authorized user, and if the aerosol generating system is associated with the authorized user, to send, directly or indirectly, an unlock authorization including an unlock code to the aerosol generating system, the unlock authorization enabling the aerosol generating system to transition from the locked state to an unlocked state in which the aerosol generating system is capable of generating aerosol.

[0008] According to a third aspect, there is provided a computing device, the computing device may be configured to receive an unlock request from an aerosol generating system using connectionless communication, the computing device may be further configured to send the unlock request to a server, receive an unlock grant from the server, and send the unlock grant to the aerosol generating device using connectionless communication.

[0009] According to a fourth aspect, there is provided a system comprising the aerosol generation system of the first aspect and the computing device of the third aspect. The system of the fourth aspect may further comprise the server of the second aspect.

[0010] By using connectionless communication to exchange unlock requests and / or unlock permissions, connection difficulties, such as those caused by BLE pairing incompatibility with various external computing devices, are alleviated while providing a higher success rate for the YAP (Young Adult Access Prevention) method. In particular, information can be exchanged between the server and the aerosol-generating device without requiring BLE pairing or association with a WiFi access point. In this way, the online YAP method can be implemented on all mobile devices via BLE or WiFi packet analysis, even if the aerosol-generating device cannot pair with or establish a connection to those devices, increasing the YAP unlock success rate from the current low level of 70-80% to 100%.

[0011] Using connectionless communication as described herein, including the basic features of BLE or WiFi packet analysis, may provide improved compatibility between the aerosol generating device and an external computing device, such as a mobile device, and / or may reduce the need for firmware updates to the aerosol generating device or a dedicated unlocking application, which may reduce user frustration.

[0012] By using a pre-shared secret and a one-time random value to generate a device-unique and session-unique unlock code, the unlock code cannot be sniffed and used against other devices. The unlock code cannot be easily guessed because it is based on the device secret and changes at the start of each unlock process. Furthermore, using a pre-shared secret significantly reduces online YAP execution time (due to fewer bytes and a lighter cryptographic algorithm) without compromising security.

[0013] Robust underage access prevention can be provided by verifying that the aerosol generating device user is a Legal Age User / Legal Age Smoker (LAU / LAS) using the mobile device (app) and server, using secure data and account verification processes (e.g., mandatory two-factor authentication to start the app, credit card ID, GPS data provided by the mobile device, and reconciliation of legal age to country laws, etc.).

[0014] The unlocking process can be easily adapted to older versions of BLE and only requires that the mobile device be able to alternate between different Generic Access Profile (GAP) roles (Central and Peripheral), which have been common since around 2015.

[0015] Additionally, using BLE's non-connectable advertisement mode (“ADV_NONCONN_IND”) to transmit advertising data (versus “connectable mode”) may be more power efficient.

[0016] The unlock request may include a unique device identifier that identifies the aerosol generating system. The aerosol generating system may be configured to include the unique device identifier in the unlock request before sending the unlock request. The server may be further configured to determine whether the unique device identifier included in the received unlock request is associated with an authorized user. More specifically, the server may be configured to use the unique device identifier (UID) to obtain a device unique serial number (DUSN) that can be linked to only one user account, and to authorize unlocking of the aerosol generating system only when the DUSN is linked to the user account of the authorized user. The unlock authorization sent by the server and received by the aerosol generating system may also include the unique device identifier. The aerosol generating system may be further configured to verify the unlock code only if the unique device identifier included in the unlock authorization matches that of the aerosol generating system.

[0017] The unlock authorization may further include an unlock code. The server may be further configured to generate the unlock code and include the unlock code in the unlock authorization. The unlock code may be based at least in part on a pre-shared secret unique to the aerosol generating system. The unlock code may be generated by the server or derived by the server. The unlock code may be based at least in part on a verification code provided by the aerosol generating system as part of the unlock request. The server may be further configured to generate the unlock code based at least in part on the verification code included in the unlock request. After receiving the unlock authorization, the aerosol generating system may be further configured to verify the unlock code using the pre-shared secret unique to the aerosol generating system. In response to successfully verifying the unlock code, the aerosol generating system may be further configured to transition the aerosol generating system from a locked state to an unlocked state. The unlock code may be unique to the current unlock session. This may be implemented by the unlock code being based at least in part on or including a one-time code (OTC). An OTC may alternatively be referred to as a one-time password (OTP) or a one-time authentication code (OTAC). The unlock code may include or constitute a message authentication code. More specifically, the unlock code may include a hash-based message authentication code.

[0018] The aerosol generating system may be further configured to obtain a verification code for comparison with the unlock code. The verification code may be generated by the aerosol generating system. In other words, the aerosol generating system may be further configured to generate the verification code based on the aerosol generating system verifying the unlock code. The aerosol generating system may be further configured to include the verification code in the unlock request and, when verifying the unlock code, determine whether the unlock code included in the unlock authorization matches the verification code. In other words, the aerosol generating system may be further configured to verify the unlock code by comparing the unlock code included in the unlock authorization with the verification code, and, in response to the unlock code matching the verification code, transition the aerosol generating system from a locked state to an unlocked state.

[0019] The unlock code included in the unlock authorization may be encrypted. The server may be further configured to encrypt the unlock code before sending the unlock authorization. Similarly, the aerosol generating system may be further configured to decrypt the encrypted unlock code. More specifically, the server may be further configured to encrypt the unlock code using a symmetric key algorithm, while the aerosol generating system may also be configured to decrypt the encrypted unlock code using the symmetric key algorithm. The server may be further configured to encrypt the unlock code using a key, while the aerosol generating system may also be further configured to decrypt the encrypted unlock code using the key. The key used to encrypt and / or decrypt the unlock code may be derived at least in part from a pre-shared secret unique to the aerosol generating system. Additionally or alternatively, the key used to encrypt and / or decrypt the unlock code may be derived at least in part from a unique device identifier. Additionally or alternatively, the key used to encrypt and / or decrypt the unlock code may be derived at least in part from a one-time code. The aerosol generating system may be configured to verify the unlock code only if the encrypted unlock code can be decrypted using the key.

[0020] The unlock authorization may further include a challenge. The challenge may include a server challenge. The server may be further configured to generate the challenge for inclusion in the unlock authorization. The aerosol generating system may be configured to verify the unlock code based at least in part on the challenge. More specifically, the aerosol generating system may be configured to verify the unlock code only when the aerosol generating system provides a valid response to the challenge.

[0021] As used herein, the term "connectionless communication" specifically refers to communication that occurs without device pairing and without association with an access point. Connectionless communication may occur between two endpoints, where messages are sent from one endpoint to another without prior arrangement, i.e., without first ensuring that the recipient is available and ready to receive data. The term "connectionless communication" is used herein in contrast to communication that uses a pre-arranged, fixed data channel, as in connection-oriented communication, also referred to herein as "connectable" mode. Connectionless communication may include multicast and / or broadcast operation, in which the same data is sent to several recipients in a single transmission. For example, connectionless communication may include communication that uses at least one broadcast / advertising beacon and / or at least one broadcast / advertising packet, as in Bluetooth or Bluetooth Low Energy, and thus may be referred to in terms of communication that uses an advertising mode. To enable both sending and receiving data using connectionless communication, the aerosol generating system may be configured to switch between peripheral and central mode operation. The aerosol generating system may be configured to send an unlock request when operating in a peripheral mode and to receive an unlock authorization when operating in a central mode. Similarly, the computing device may be further configured to switch between operating in a central mode and a peripheral mode. The computing device may be further configured to receive an unlock request when operating in a central mode and to send an unlock authorization when operating in a peripheral mode.Connectionless communication may alternatively include monitoring network traffic using network sniffing or packet analysis without any association between the aerosol generating system and the access point.

[0022] As used herein, the term "peripheral mode" refers to a mode or role in which a device advertises its presence and waits for devices operating in central mode to connect to it, and the term "central mode" refers to a mode or role in which a device scans for other devices. The terms "central mode" and "peripheral mode" may refer to pre-connection modes or roles. After connection, a device operating in central mode may operate as a master, and a device operating in peripheral mode may operate as a slave.

[0023] The aerosol generating system may include an aerosol generating device. The aerosol generating device may be configured or designed, for example, as a handheld device that can be used by an authorized user to consume the aerosol-generating article during one or more use sessions (also referred to as an "experience" or "experience session"). For example, an aerosol-generating article that can be used with an aerosol generating device may include an aerosol-forming substrate, such as a tobacco-containing substrate, in the form of a stick that can be at least partially inserted into the aerosol generating device, optionally assembled with other elements or components. Alternatively or additionally, an aerosol-generating article that can be used with an aerosol generating device may include at least one cartridge containing a liquid that can be evaporated during aerosol consumption by a user. Such a cartridge may be a refillable cartridge that is fixedly attached to the aerosol generating device, or the cartridge may be at least partially inserted into the aerosol generating device. Alternatively, the aerosol generating device may be referred to as a risk reduction device (RRD).

[0024] The aerosol generating system may further include a companion device. The companion device may include a charging case. The companion device, which may also be described as an auxiliary device, a receiving device, or a support device, may be configured to support and / or store the aerosol generating device. The companion device may be portable. The companion device may be configured to at least partially receive the aerosol generating device. For example, the companion device may be configured to be physically coupled to the aerosol generating device. Such physical coupling may include, for example, a mechanical coupling based on an attachment means such as a hook mechanism, a latch mechanism, a snap-fit ​​mechanism, or the like, by which the aerosol generating device may be mechanically coupled to the companion device and / or its housing. Alternatively or additionally, the aerosol generating device may be physically coupled to the companion device based on magnetic or electromagnetic coupling. Alternatively or additionally, the aerosol generating device may be at least partially inserted into the companion device, for example, into an opening in the companion device.

[0025] To communicate with each other and / or with external computing devices and / or to exchange data or signals, the aerosol generating device and / or companion device may include at least one communication interface. The communication interface may be configured for wireless communication, wired communication, or both. For example, the communication interface may be configured to communicatively couple via an Internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection including BLE, a cellular network, a 3G / 4G / 5G connection, an edge connection, an LTE connection, a BUS connection, a wireless connection, a wired connection, a radio connection, a short-range connection, an IoT connection, or any other connection using any suitable communication protocol.

[0026] The aerosol generating device and / or companion device may include at least one energy storage unit for storing electrical energy and / or supplying electrical energy to the aerosol generating device. For example, the companion device may be configured to supply electrical energy to the aerosol generating device and charge the at least one energy storage unit of the aerosol generating device. In other words, the companion device may be configured to charge the aerosol generating device and / or its at least one energy storage unit. The at least one energy storage unit of the aerosol generating device may include, for example, at least one battery, at least one accumulator, at least one capacitor, or any other energy storage unit. The companion device may be configured to supply electrical energy to the energy storage unit of the aerosol generating device when the aerosol generating device is at least partially received by the companion device. The companion device may include one or more batteries for supplying electrical energy to the energy storage unit of the aerosol generating device. The companion device may be configured to wirelessly supply electrical energy to the energy storage unit of the aerosol generating device, for example, based on induction. Alternatively or additionally, the companion device may be configured to supply electrical energy to an energy storage unit of the aerosol generating device via one or more electrical connectors between the companion device and the aerosol generating device. For example, the aerosol generating device and the companion device may each include at least one electrical connector for electrically coupling the companion device with the aerosol generating device when the aerosol generating device is at least partially received by the companion device. As an example, the companion device may include an opening for at least partially receiving the aerosol generating device. By at least partially inserting the aerosol generating device into the opening, one or more electrical connectors may be established between the one or more electrical connectors of the aerosol generating device and the companion device.Alternatively or additionally, the aerosol generating device may be physically and / or mechanically coupled to the companion device, e.g., via the housing of the companion device, such that the aerosol generating device is at least partially received by the companion device and one or more electrical connections can be established between the aerosol generating device and the companion device. Optionally, a communicative coupling and / or connection between the companion device and the aerosol generating device may be established, e.g., for transmitting authentication signals, by establishing an electrical connection between the companion device and the aerosol generating device, e.g., via one or more electrical connectors of the aerosol generating device and the companion device. As an example, at least one electrical connector of the companion device may be combined with and / or include a communication interface of the companion device. In other words, at least one electrical connector of the companion device may be configured as a communication interface for communicatively coupling the companion device with the aerosol generating device. Alternatively or additionally, at least one electrical connector of the aerosol generating device may be combined with and / or include a communication interface of the aerosol generating device. In other words, at least one electrical connector of the aerosol generating device may be configured as a communication interface for communicatively coupling the aerosol generating device with the companion device. Thus, an authentication signal may be transmitted from the companion device to the aerosol generating device via one or more electrical connectors of the companion device and the aerosol generating device. However, it should be noted that the communication interface of one or both of the companion device and the aerosol generating device may be physically separate and independent from the at least one electrical connector of the companion device and / or the aerosol generating device. A charging cycle may refer to a period during which the aerosol generating device is continuously supplied with electrical energy by the companion device. During a charging cycle, the at least one energy storage unit may be partially or fully charged.

[0027] The external computing device may be configured to communicate with the aerosol generating device and / or the companion device, for example, based on the exchange of data or information. Generally, the external computing device may be a handheld or portable device. Alternatively, the external computing device may be a standalone or fixedly attached device. Furthermore, the external computing device may be owned by or installed by a user or another entity or individual, such as a retail store. By way of example, the external computing device may refer to a handheld smartphone, personal computer ("PC"), tablet PC, laptop, or computer. The external computing device may include a user interface. The external computing device may include one or more processors for data processing, such as processing one or more user inputs received at the user interface. Alternatively or additionally, the external computing device may include data storage and / or memory for storing data, such as software instructions, computer programs, and / or other data. Furthermore, the external computing device may include a communication interface, a communication module, and / or communication circuitry for communicatively coupling the external computing device with the aerosol generating device, for example, via a communication interface of the companion device. Thus, the external computing device may be configured for wireless and / or wired communication with the aerosol-generating device, the companion device, or both. For example, the external computing device may be configured to be communicatively coupled to the aerosol-generating device and / or the companion device via an internet connection, a wireless LAN connection, a WiFi connection, a Bluetooth connection, a cellular network, a 3G / 4G / 5G connection, etc., an edge connection, an LTE connection, a BUS connection, a wireless connection, a wired connection, a radio connection, a short-range connection, an IoT connection, or any other connection using any suitable communication protocol.

[0028] The unlock code may include a MAC address detected in network traffic by the aerosol generating system, the MAC address being associated with a computing device (e.g., a mobile device) of a known authorized user, such that packets containing that MAC address indicating the proximity of the authorized user constitute implicit permission to unlock the aerosol generating system. To that end, the aerosol generating system may be configured to detect the MAC address in the network traffic using packet analysis, for example, when operating in a monitoring mode to monitor network traffic using packet analysis. The aerosol generating system may further be configured to transition from a locked state to an unlocked state in response to successfully verifying the unlock code including the MAC address. The verification code may include, for example, a MAC address of the authorized user's computing device pre-stored in the aerosol generating system for comparison with the unlock code in the form of a MAC address detected by the aerosol generating system in network traffic. Thus, a match between the pre-stored MAC address, which serves as the verification code, and the detected MAC address, which serves as the unlock code, may transition the aerosol generating system from a locked state to an unlocked state. Thus, the aerosol generating system may be further configured to verify the unlock code by comparing the detected MAC address with the MAC address of the authorized user's computing device, and transition from a locked state to an unlocked state in response to the detected MAC address matching the MAC address of the authorized user's computing device.

[0029] According to a fifth aspect, there is provided a method implemented by an aerosol generating system in a locked state in which the aerosol generating system is prevented from generating aerosol. The method may include sending an unlock request to an external computing device using connectionless communication. The method may further include receiving an unlock authorization from the external computing device using connectionless communication, and transitioning the aerosol generating system from the locked state to an unlocked state in which the aerosol generating system is able to generate aerosol after receiving the unlock authorization.

[0030] The method of the fifth aspect may further include, after receiving the unlock authorization, verifying the unlock code using a pre-shared secret unique to the aerosol generating system. The method may further include transitioning the aerosol generating system from a locked state to an unlocked state in response to successfully verifying the unlock code. The method may further include obtaining a verification code for comparison with the unlock code. The method may further include generating the verification code at the aerosol generating system. The method may further include verifying the unlock code by comparing the unlock code with the verification code, and transitioning the aerosol generating system from a locked state to an unlocked state in response to the unlock code matching the verification code. The method may further include generating a verification code based on which the aerosol generating system verifies the unlock code. The method may further include including the verification code in the unlock request, and, when verifying the unlock code, determining whether the unlock code included in the unlock authorization matches the verification code. If the unlock code included in the unlock authorization is encrypted, the method may further include decrypting the encrypted unlock code. The method may further include decrypting the encrypted unlock code using a symmetric key algorithm. The method may further include decrypting the encrypted unlock code using a key. The key may be derived at least in part from a pre-shared secret, and / or at least in part from a unique device identifier, and / or at least in part from a one-time code. The method may further include verifying the unlock code only if the encrypted unlock code can be decrypted using the key. The method may further include verifying the unlock code only if a unique device identifier included in the unlock authorization matches an identifier of the aerosol generating system. If the unlock authorization further includes a challenge, the method may further include verifying the unlock code based, at least in part, on the challenge. The method may further include switching between operating in a peripheral mode and a central mode.The method may further include sending an unlock request when operating in the peripheral mode and receiving an unlock grant when operating in the central mode.

[0031] The unlock code may include a MAC address detected in the network traffic. The method may include detecting the MAC address in the network traffic, for example, using packet analysis, when operating in a monitoring mode to monitor the network traffic using packet analysis. The verification code may include a MAC address of the authorized user's computing device. The method may include comparing the detected MAC address with a MAC address of the authorized user's computing device stored in the aerosol generating system, and transitioning the aerosol generating system from a locked state to an unlocked state in response to the detected MAC address matching the stored MAC address.

[0032] According to a sixth aspect, there is provided a method implemented by a server. The method may include receiving an unlock request identifying an aerosol generating system in a locked state. The method may further include determining whether the aerosol generating system is associated with an authorized user, and if the aerosol generating system is associated with the authorized user, sending, directly or indirectly, an unlock authorization including an unlock code to the aerosol generating system, the unlock authorization enabling the aerosol generating system to transition from the locked state to an unlocked state in which the aerosol generating system is capable of generating aerosol.

[0033] If the unlock request includes a unique device identifier that identifies the aerosol generating system, the method of the sixth aspect may further include determining whether the unique device identifier is associated with an authorized user. The method may further include generating an unlock code and including the unlock code in the unlock authorization. The method may further include generating the unlock code based at least in part on a verification code included in the unlock request. The method may further include encrypting the unlock code before sending the unlock authorization. The method may further include encrypting the unlock code using a symmetric key algorithm. The method may further include encrypting the unlock code using a key described herein. The method may further include generating a challenge for inclusion in the unlock authorization.

[0034] According to a seventh aspect, there is provided a method implemented by a computing device. The method may include receiving an unlock request from an aerosol generating system using connectionless communication. The method may further include sending the unlock request to a server, receiving an unlock authorization from the server, and sending the unlock authorization to the aerosol generating device using connectionless communication.

[0035] The method of the seventh aspect may further include switching between operating in a peripheral mode and operating in a central mode. The method may further include receiving an unlock request when operating in the central mode and sending an unlock grant when operating in the peripheral mode.

[0036] The methods of the fifth to seventh aspects may be computer-implemented.

[0037] According to an eighth aspect, there is provided a computing system configured to perform the methods of the fifth to seventh aspects.

[0038] According to a ninth aspect, there is provided a computer program (product) which, when executed by a computing system, is capable of causing or includes instructions to cause the computing system to perform the method of any of the fifth to seventh aspects.

[0039] According to a tenth aspect, there is provided a computer-readable (storage) medium comprising instructions that, when executed by a computing system, can cause or cause the computing system to implement any of the fifth to seventh aspects. The computer-readable medium may be transitory or non-transitory, volatile or non-volatile.

[0040] As used herein, the term "locked state" may refer to a locked configuration of an aerosol generation device, and the term "unlocked state" may refer to an unlocked configuration of an aerosol generation device. In a locked state or configuration, the aerosol generation device is prohibited from delivering and / or generating aerosol. This may mean that the aerosol generation device is locked from aerosol consumption by a user in the locked state and / or that the aerosol generation device is configured in the locked state such that aerosol is not delivered and / or generated. On the other hand, in an unlocked state or configuration, the aerosol generation device is permitted or allowed to deliver and / or generate aerosol. This may mean that the aerosol generation device is unlocked from aerosol consumption by a user in the unlocked state and / or that the aerosol generation device is configured in the unlocked state such that aerosol can be delivered and / or generated. Thus, when the aerosol generating device is in a locked state, the aerosol generating device may not be operable by the user to deliver and / or generate aerosol, and when the aerosol generating device is in an unlocked state, the aerosol generating device may be operable by the user to deliver and / or generate aerosol. In other words, when the aerosol generating device is in a locked state, the user may be prohibited from accessing one or more functions of the aerosol generating device, including aerosol delivery and / or generation, and when the aerosol generating device is in an unlocked state, the user may be permitted to access one or more functions of the aerosol generating device, including aerosol delivery and / or generation. Additionally or alternatively, the companion device may be configured to charge the energy storage of the aerosol generating device only upon successful authentication of the user. In this example, the locked state may be considered to mean that the energy storage of the aerosol generating device does not contain a sufficient charge to generate aerosol, and the unlocked state may be considered to mean that the energy storage contains a sufficient charge to generate aerosol. The authentication signal may then be considered to be the companion device providing a charge to the energy storage of the aerosol generating device.In the locked state, the control circuit may be configured to prohibit activation of the heating elements based on, for example, at least one of disabling the at least one heating element, disabling an energy supply source for supplying electrical energy to the at least one heating element, and disabling an input element for activating the at least one heating element by a user.

[0041] As used herein, the term "transition" may mean causing, configuring, and / or switching the aerosol generating device into a locked or unlocked state, and may mean or include operating and / or configuring the aerosol generating device so that the aerosol generating device is in a locked or unlocked state.

[0042] As used herein, the term "authentication" refers to the verification of a user's identity.

[0043] As used herein, the term "authorization" refers to determining a user's access rights, i.e., the user's right to transition the aerosol generating device from a locked state to an unlocked state. In the context of the YAP method, a user's identity is intrinsically tied to their access rights, and therefore the terms "authentication" and "authorization" can be used interchangeably in this disclosure.

[0044] As used herein, the term "authorized user" (also referred to as "verified user") may refer to or denote a user authorized to configure an aerosol generating device by another authorized user, such as the owner of the aerosol generating device, an adult, an adult individual, a user of full age, a user who has reached an age threshold, a user who has reached the age of majority, and / or the owner. Additionally, an unauthorized user may refer to or denote a minor user, a user under the age threshold, a child, or other user who is not authorized to configure the aerosol generating device, particularly a user who is not authorized to transition the aerosol generating device to an unlocked state for aerosol consumption.

[0045] As used herein, the term "circuitry" may include, for example, alone or in any combination, hardwired circuitry, programmable circuitry such as a computer processor including one or more individual instruction processing cores, state machine circuitry, and / or firmware that stores instructions performed by the programmable circuitry. Modules may be embodied as circuitry that collectively or individually form part of one or more devices or systems described herein.

[0046] As used herein, the term "acquiring" may include, for example, receiving from another system, device, or process; receiving through interaction with a user; loading or retrieving from a storage device or memory; and measuring or capturing using a sensor or other data acquisition device.

[0047] As used herein, the term "determining" encompasses a wide variety of operations and may include, for example, calculating, computing, processing, deriving, investigating, looking up (e.g., consulting a table, database, or another data structure), ascertaining, etc. "Determining" may also include receiving (e.g., receiving information), accessing (e.g., accessing data in a memory), etc. "Determining" may also include resolving, selecting, choosing, establishing, etc.

[0048] The indefinite articles "a" or "an" do not exclude a plurality. In addition, as used herein, the articles "a" and "an" should generally be construed to mean "one or more" unless otherwise specified or unless it is clear from the context that a singular reference is made.

[0049] Unless otherwise specified or clear from context, as used herein, the phrases "one or more of A, B, and C," "at least one of A, B, and C," and "A, B, and / or C" are intended to mean all possible permutations of one or more of the listed items. That is, the phrase "A and / or B" means (A), (B), or (A and B), while the phrase "A, B, and / or C" means (A), (B), (C), (A and B), (A and C), (B and C), or (A, B, and C).

[0050] The term "comprising" does not exclude other elements or steps. Furthermore, terms such as "include", "comprise", "have" and the like may be used interchangeably herein. [Example]

[0051] The following provides a non-exhaustive list of non-limiting examples, any one or more of the features of these examples may be combined with any one or more features of any other example, embodiment, or aspect described herein.

[0052] Example 1 1. An aerosol generation system in a locked state in which the aerosol generation system is prevented from generating an aerosol, the aerosol generation system comprising: receiving an unlock authorization from the external computing device using connectionless communication; The aerosol generation system is configured to transition the aerosol generation system from a locked state to an unlocked state in which the aerosol generation system is capable of generating aerosol after receiving the unlock authorization. Example 1A. 2. The aerosol generation system of example 1, further configured to send the unlock request to an external computing device using connectionless communication. Example 2. The aerosol generation system of Example 1A, wherein the unlock request includes a unique device identifier that identifies the aerosol generation system. Example 3 3. The aerosol generation system of example 2, wherein the unlock authorization comprises a unique device identifier and an unlock code. Example 4. The aerosol generating system described in Example 3, wherein the unlock code is generated in or derived by another external computing device (e.g., a server) or an external computing device (as described herein). Example 5. 5. The aerosol generation system of any one of Examples 3 to 4, further configured to, after receiving the unlock authorization, verify the unlock code using a pre-shared secret unique to the aerosol generation system. Example 6 An aerosol generation system described in any one of Examples 3 to 5, further configured to transition the aerosol generation system from a locked state to an unlocked state in response to successfully verifying the unlock code. Example 7 An aerosol generating system as described in any of Examples 3 to 6, further configured to obtain a verification code for comparison with the unlock code. Example 8 8. The aerosol generation system of example 7, wherein the verification code is generated by the aerosol generation system. Example 9. An aerosol generating system as described in any of Examples 3 to 8, further configured to verify the unlock code by comparing the unlock code with a verification code, and transition the aerosol generating system from a locked state to an unlocked state in response to the unlock code matching the verification code. Example 10. 10. The aerosol generating system of any of Examples 3 to 9, wherein the aerosol generating system is further configured to generate a verification code based on verifying the unlock code. Example 11 An aerosol generating system described in any of Examples 3 to 10, further configured to include a verification code in the unlock request and, when verifying the unlock code, determine whether the unlock code included in the unlock authorization matches the verification code. Example 12 An aerosol generating system described in any of Examples 3 to 11, wherein the unlock code included in the unlock permission is encrypted and the aerosol generating system is configured to decrypt the encrypted unlock code. Example 13 An aerosol generating system described in any of Examples 3 to 12, wherein the unlock code included in the unlock permission is encrypted, and the aerosol generating system is configured to decrypt the encrypted unlock code using a symmetric key algorithm. Example 14. An aerosol generating system described in any of Examples 3 to 13, wherein the unlock code included in the unlock authorization is encrypted, and the aerosol generating system is configured to decrypt the encrypted unlock code using a key derived, at least in part, from a pre-shared secret. Example 15. An aerosol generation system described in any of Examples 3 to 14, wherein the unlock code included in the unlock authorization is encrypted, and the aerosol generation system is configured to decrypt the encrypted unlock code using a key derived, at least in part, from the unique device identifier. Example 16. An aerosol generating system described in any of Examples 3 to 15, wherein the unlock code included in the unlock authorization is encrypted, and the aerosol generating system is configured to decrypt the encrypted unlock code using a key derived, at least in part, from the one-time code. Example 17. An aerosol generating system described in any of Examples 14 to 16, wherein the unlock code included in the unlock permission is encrypted, and the aerosol generating system is configured to verify the unlock code only when the encrypted unlock code can be decrypted using a key. Example 18. An aerosol generating system described in any of Examples 3 to 17, wherein the unlock code is unique to the current unlock session. Example 19. 19. The aerosol generating system of any of Examples 3-18, wherein the unlock code is based at least in part on a one-time code. Example 20. 20. The aerosol generating system of any one of Examples 3 to 19, wherein the unlock code comprises a message authentication code. Example 21. An aerosol generating system described in any of Examples 3 to 20, wherein the unlock code comprises a hash-based message authentication code. Example 22. An aerosol generation system described in any of Examples 3 to 21, further configured to verify the unlock code only if the unique device identifier included in the unlock authorization matches that of the aerosol generation system. Example 23. An aerosol generating system described in any of Examples 3 to 22, wherein the unlock permission further includes a challenge, and the aerosol generating system is configured to verify the unlock code based, at least in part, on the challenge. Example 24. 24. The aerosol generation system of any of Examples 1 to 23, wherein the aerosol generation system is configured to switch between operating in a peripheral mode and operating in a central mode. Example 25. An aerosol generation system described in any of Examples 1A to 24, wherein the aerosol generation system is configured to send an unlock request when operating in peripheral mode and to receive an unlock permission when operating in central mode. Example 26. An aerosol generating system described in any of Examples 1 to 25, wherein the connectionless communication includes communication using at least one advertising packet. Example 27. An aerosol generating system described in any of Examples 1 to 26, wherein the connectionless communication includes communication using at least one broadcast beacon. Example 28. 28. An aerosol generation system according to any one of Examples 1 to 27, wherein the system comprises an aerosol generation device, or an aerosol generation device and an auxiliary device. Example 29. An aerosol generation system as described in Example 28, wherein the auxiliary device is a charging case. Example 30. a server, determining whether the aerosol generating system is associated with an authorized user; and if the aerosol generating system is associated with an authorized user, transmitting, directly or indirectly, an unlock authorization including an unlock code to the aerosol generating system, the unlock authorization enabling the aerosol generating system to transition from a locked state to an unlocked state in which the aerosol generating system is capable of generating aerosol. Example 30A. A server as described in Example 30, further configured to receive an unlock request identifying an aerosol generation system in a locked state. Example 31. A server as described in Example 30A, wherein the unlock request includes a unique device identifier that identifies the aerosol generating system, and the server is further configured to determine whether the unique device identifier is associated with an authorized user. Example 32. 32. The server of any one of Examples 30 to 31, further configured to generate an unlock code and include the unlock code in the unlock authorization. Example 33. The server of Example 32, wherein the unlock code is based at least in part on a pre-shared secret unique to the aerosol generating system. Example 34. The server of example 32 or 33 when dependent on example 30A, further configured to generate an unlock code based, at least in part, on a verification code included in the unlock request. Example 35. 35. The server of any of Examples 32 to 34, further configured to encrypt the unlock code before sending the unlock authorization. Example 36. 36. The server of example embodiment 35, further configured to encrypt the unlock code using a symmetric key algorithm. Example 37. 37. The server of any one of Examples 35 to 36, further configured to encrypt the unlock code using a key derived at least in part from the pre-shared secret. Example 38. A server described in any of Examples 35 to 37, further configured to encrypt the unlock code using a key derived at least in part from a unique device identifier that identifies the aerosol generating system. Example 39. 39. The server of any of Examples 35-38, further configured to encrypt the unlock code at least in part using a key derived from the one-time code.

[0053] Example 40. 40. The server of any one of embodiments 32 to 39, wherein the unlock code is unique to the current unlock session. Example 41. 41. A server according to any one of embodiments 32 to 40, wherein the unlock code is based at least in part on a one-time code. Example 42. 42. The server according to any one of embodiments 32 to 41, wherein the unlock code includes a message authentication code. Example 43. 43. The server of any one of embodiments 32 to 42, wherein the unlock code includes a hash-based message authentication code. Example 44. 44. The server of any of Examples 30 to 43, further configured to generate a challenge for inclusion in the unlock authorization. Example 45. 1. A computing device comprising: receiving an unlock authorization from the server; The computing device is further configured to: send the unlock authorization to the aerosol generation system using connectionless communication. Example 45A. The computing device of Example 45, further configured to receive an unlock request from the aerosol generating system using connectionless communication and to send the unlock request to the server. Example 46. A computing device as described in Example 45A, wherein the unlock request includes a unique device identifier that identifies the aerosol generating system. Example 47. 47. The computing device of Example 46, wherein the unlock permission includes a unique device identifier and an unlock code. Example 48. 48. The computing device of Example 47, wherein the unlock code is unique to the current unlock session. Example 49. 49. The computing device of example 47 or 48, wherein the unlock code is based at least in part on a one-time code. Example 50. 50. A computing device as described in any one of Examples 47 to 49, wherein the unlock code comprises a message authentication code. Example 51. 51. A computing device described in any of Examples 47 to 50, wherein the unlock code comprises a hash-based message authentication code. Example 52. A computing device described in any of Examples 47 to 51, wherein the unlock code is encrypted and a key used to encrypt and / or decrypt the unlock code is derived at least in part from a pre-shared secret unique to the aerosol generating system. Example 53. A computing device described in any of Examples 47 to 52, wherein the unlock code is encrypted and a key used to encrypt and / or decrypt the unlock code is derived at least in part from a unique device identifier. Example 54. A computing device described in any of Examples 47 to 53, wherein the unlock code is encrypted and a key used to encrypt and / or decrypt the unlock code is derived at least in part from the one-time code. Example 55. A computing device described in any of Examples 47 to 54, wherein the unlock code is based, at least in part, on a verification code provided by the aerosol generating system as part of the unlock request. Example 56. 56. A computing device described in any of Examples 45 to 55, further configured to switch between operation in peripheral mode and operation in central mode. Example 57. A computing device described in any of Examples 45A to 56, further configured to receive an unlock request when operating in a central mode and to send an unlock grant when operating in a peripheral mode. Example 58. A computing device described in any of Examples 45 to 57, wherein the connectionless communication includes communication using at least one advertising packet. Example 59. A computing device described in any of embodiments 45 to 58, wherein the connectionless communication includes communication using at least one broadcast beacon. Example 60. A system comprising: an aerosol generating system according to any one of Examples 1 to 29; and a computing device according to any one of Examples 45 to 59. Example 61. The system described in Example 60, further comprising the server described in any one of Examples 30 to 44. Example 62. 1. A method performed with an aerosol generation system in a locked state in which the aerosol generation system is prevented from generating an aerosol, the method comprising: receiving an unlock authorization from the external computing device using connectionless communication; and after receiving the unlock authorization, transitioning the aerosol generation system from a locked state to an unlocked state in which the aerosol generation system is capable of generating aerosol. Example 62A. 63. The method of embodiment 62, further comprising sending the unlock request to the external computing device using connectionless communication. Example 63. The method of Example 62A, wherein the unlock request includes a unique device identifier that identifies the aerosol generating system. Example 64. 64. The method of embodiment 63, wherein the unlock permission includes a unique device identifier and an unlock code. Example 65. The method of Example 64, wherein the unlock code is generated in or derived by another external computing device (e.g., a server) or an external computing device (as described herein). Example 66. The method of example 64 or 65, further comprising, after receiving the unlock authorization, verifying the unlock code using a pre-shared secret unique to the aerosol generating system. Example 67. 67. The method of any of Examples 64-66, further comprising transitioning the aerosol generation system from a locked state to an unlocked state in response to successfully verifying the unlock code. Example 68. 68. The method of any one of Examples 64-67, further comprising obtaining a verification code for comparison with the unlock code. Example 69. The method of example 68, further comprising generating a verification code with the aerosol generating system. Example 70. A method described in any of Examples 64 to 69, further comprising verifying the unlock code by comparing the unlock code with a verification code, and transitioning the aerosol generation system from a locked state to an unlocked state in response to the unlock code matching the verification code. Example 71. The method of any of Examples 64-70, further comprising generating a verification code based on the aerosol generating system verifying the unlock code. Example 72. 72. The method of any of Examples 64 to 71, further comprising including a verification code in the unlock request, and determining, when verifying the unlock code, whether the unlock code included in the unlock authorization matches the verification code. Example 73. 73. The method according to any of examples 64-72, wherein the unlock code included in the unlock authorization is encrypted, and the method further comprises decrypting the encrypted unlock code. Example 74. 75. The method of any of embodiments 64 to 74, wherein the unlock code included in the unlock authorization is encrypted, and the method further includes decrypting the encrypted unlock code using a symmetric key algorithm. Example 75. 75. The method of any of examples 64-74, wherein the unlock code included in the unlock authorization is encrypted, and the method further includes decrypting the encrypted unlock code using a key derived at least in part from the pre-shared secret. Example 76. 76. The method of any of examples 64-75, wherein the unlock code included in the unlock authorization is encrypted, and the method further includes decrypting the encrypted unlock code using a key derived at least in part from the unique device identifier. Example 77. 77. The method of any of examples 64-76, wherein the unlock code included in the unlock authorization is encrypted, and the method further includes decrypting the encrypted unlock code using a key derived, at least in part, from the one-time code. Example 78. 78. The method of any of Examples 75 to 77, wherein the unlock code included in the unlock authorization is encrypted, and the method further includes verifying the unlock code only if the encrypted unlock code can be decrypted using the key. Example 79. 79. The method of any one of examples 64 to 78, wherein the unlock code is unique to the current unlock session.

[0054] Example 80. 80. The method of any one of examples 64-79, wherein the unlock code is based at least in part on a one-time code. Example 81. 81. The method of any one of Examples 64 to 80, wherein the unlock code comprises a message authentication code. Example 82. 82. The method of any one of embodiments 64-81, wherein the unlock code comprises a hash-based message authentication code. Example 83. The method of any of Examples 64 to 82, further comprising verifying the unlock code only if the unique device identifier included in the unlock authorization matches that of the aerosol generation system. Example 84. 84. The method of any of examples 64-83, wherein the unlock permission further includes a challenge, and the method further includes verifying the unlock code based at least in part on the challenge. Example 85. 85. The method of any of Examples 62-84, further comprising switching between operation in a peripheral mode and operation in a central mode. Example 86. A method described in any of Examples 62 to 85 when dependent on Example 62A, further comprising sending an unlock request when operating in peripheral mode and receiving an unlock grant when operating in central mode. Example 87. 87. A method according to any one of embodiments 62 to 86, wherein the connectionless communication includes communication using at least one advertising packet. Example 88. 88. A method according to any one of embodiments 62 to 87, wherein the connectionless communication includes communication using at least one broadcast beacon. Example 89. 1. A server-implemented method, the method comprising: determining whether the aerosol generating system is associated with an authorized user; If the aerosol generating system is associated with an authorized user, transmitting, directly or indirectly, an unlock authorization including an unlock code to the aerosol generating system, the unlock authorization enabling the aerosol generating system to transition from a locked state to an unlocked state in which the aerosol generating system is capable of generating aerosol. Example 89A. The method of example 89, further comprising receiving an unlock request identifying an aerosol generation system in a locked state. Example 90. The method of Example 89A, wherein the unlock request includes a unique device identifier that identifies the aerosol generation system, and the method further includes determining whether the unique device identifier is associated with an authorized user. Example 91. 91. The method of any one of examples 89-90, further comprising generating an unlock code and including the unlock code in the unlock authorization. Example 92. The method of Example 91, wherein the unlock code is based at least in part on a pre-shared secret unique to the aerosol generating system. Example 93. The method of example 91 or 92 when dependent on example 89A, further comprising generating an unlock code based at least in part on the verification code included in the unlock request. Example 94. 94. The method of any one of Examples 91-93, further comprising encrypting the unlock code before sending the unlock authorization. Example 95. 95. The method of example 94, further comprising encrypting the unlock code using a symmetric key algorithm. Example 96. 96. The method of example 94 or 95, further comprising encrypting the unlock code using a key derived at least in part from the pre-shared secret. Example 97. The method of any of Examples 94 to 96, further comprising encrypting the unlock code using a key derived at least in part from a unique device identifier that identifies the aerosol generation system. Example 98. 98. The method of any of examples 94-97, further comprising encrypting the unlock code at least in part using a key derived from the one-time code. Example 99. 99. The method of any one of examples 91 to 98, wherein the unlock code is unique to the current unlock session. Example 100. 99. The method of any one of examples 91 to 99, wherein the unlock code is based at least in part on a one-time code. Example 101. 101. A method according to any one of embodiments 91 to 100, wherein the unlock code comprises a message authentication code. Example 102. 102. The method of any one of embodiments 91-101, wherein the unlock code comprises a hash-based message authentication code. Example 103. 103. The method of any of examples 89-102, further comprising generating a challenge for inclusion in the unlock authorization. Example 104. 1. A method implemented by a computing device, the method comprising: receiving an unlock authorization from the server; and transmitting an unlock authorization to the aerosol generating system using connectionless communication. Example 104A. The method of example 104, further comprising receiving an unlock request from the aerosol generating system using connectionless communication and sending the unlock request to a server. Example 105. The method described in example 104A, wherein the unlock request includes a unique device identifier that identifies the aerosol generation system. Example 106. 106. The method of embodiment 105, wherein the unlock permission includes a unique device identifier and an unlock code. Example 107. 107. The method of embodiment 106, wherein the unlock code is unique to the current unlock session. Example 108. 108. The method of example 106 or 107, wherein the unlock code is based at least in part on a one-time code. Example 109. 109. The method of any one of Examples 106 to 108, wherein the unlock code comprises a message authentication code. Example 110. 109. A method according to any one of embodiments 106 to 109, wherein the unlock code comprises a hash-based message authentication code. Example 111. A method described in any of Examples 106-110, wherein the unlock code is encrypted and a key used to encrypt and / or decrypt the unlock code is derived, at least in part, from a pre-shared secret unique to the aerosol generating system. Example 112. 112. A method according to any of embodiments 106 to 111, wherein the unlock code is encrypted and a key used to encrypt and / or decrypt the unlock code is derived at least in part from the unique device identifier. Example 113. 113. The method according to any of embodiments 106 to 112, wherein the unlock code is encrypted and a key used to encrypt and / or decrypt the unlock code is derived at least in part from the one-time code. Example 114. A method according to any of Examples 106 to 113, wherein the unlock code is based, at least in part, on a verification code provided by the aerosol generating system as part of the unlock request. Example 115. 115. The method of any of examples 104-114, further comprising switching between operation in a peripheral mode and operation in a central mode. Example 116. A method according to any one of embodiments 104A to 115, further comprising receiving an unlock request when operating in a central mode and sending an unlock grant when operating in a peripheral mode. Example 117. 117. A method according to any one of embodiments 104 to 116, wherein the connectionless communication includes communication using at least one advertising packet. Example 118. 118. A method according to any one of embodiments 104 to 117, wherein the connectionless communication includes communication using at least one broadcast beacon. Example 119. A computer program (product) comprising instructions that, when executed by a computing system, cause the computing system to perform the method described in any of Examples 62-118.

[0055] Example 120. A computer-readable (storage) medium (transient or non-transient, volatile or non-volatile) containing instructions that, when executed by a computing system, enable or cause the computing system to perform the method described in any of Examples 62 to 118. Example 121. An aerosol generating system described in any of Examples 1 to 29, wherein the unlock code includes a MAC address detected in network traffic. Example 122. An aerosol generation system as described in Example 121, configured to detect MAC addresses in network traffic. Example 123. An aerosol generation system as described in Example 122, configured to detect MAC addresses in network traffic using packet analysis. Example 124. An aerosol generation system as described in Example 123, configured to operate in a monitoring mode to monitor network traffic using packet analysis. Example 125. An aerosol generating system described in any of Examples 121 to 124, wherein the verification code includes the MAC address of the authorized user's computing device. Example 126. An aerosol generating system as described in Example 125, further configured to verify the unlock code by comparing the detected MAC address with the MAC address of the authorized user's computing device, and transition from a locked state to an unlocked state in response to the detected MAC address matching the MAC address of the authorized user's computing device. Example 127. An aerosol generation system described in any of Examples 121 to 126, wherein the connectionless communication includes monitoring network traffic using packet analysis. Example 128. 89. The method of any one of embodiments 62-88, wherein the unlock code includes a MAC address detected in network traffic. Example 129. 129. The method of example 128, comprising detecting a MAC address in network traffic. Example 130. 130. The method of example 129, comprising using packet analysis to detect MAC addresses in network traffic. Example 131. The method of example 130, comprising operating in a monitoring mode to monitor network traffic using packet analysis. Example 132. 132. A method according to any one of embodiments 128 to 131, wherein the verification code includes a MAC address of the authorized user's computing device. Example 133. The method described in Example 132, further comprising verifying the unlock code by comparing the detected MAC address with the MAC address of the authorized user's computing device, and transitioning the aerosol generation system from a locked state to an unlocked state in response to the detected MAC address matching the MAC address of the authorized user's computing device. Example 134. A method described in any of embodiments 128 to 133, wherein the connectionless communication includes monitoring network traffic using packet analysis.

[0056] The present invention may include one or more aspects, embodiments, or features, whether specifically disclosed in that combination or separately, singly or in combination. Any optional feature or sub-aspect of one of the above-described aspects applies to any of the other aspects, as appropriate.

[0057] The detailed description, by way of example only, refers to the accompanying drawings, in which: [Brief explanation of the drawings]

[0058] [Figure 1] FIG. 1 shows an aerosol generating device. [Figure 2] FIG. 2 shows a system including the aerosol generating device of FIG. 1, a mobile device, and a server. [Figure 3] FIG. 3 illustrates a computing system that may be used in accordance with the systems and methods disclosed herein. DETAILED DESCRIPTION OF THE INVENTION

[0059] 1 shows a block diagram of an aerosol generating device 100. The aerosol generating device 100 may include an aerosol generating unit 110, a sensor 120, a controller 130, a storage unit 140, a communication unit 150, and a power source 160.

[0060] The aerosol generation unit 110 is a unit for generating an aerosol from precursor materials (consumable materials) for inhalation by a user of the aerosol generating device 100. As an example, the aerosol generation unit 110 may include a vaporizer or a heating element. The precursor materials may be provided in liquid or solid form. The aerosol generation unit 110 is powered by electrical energy provided by a power supply 160 and controlled by a controller 130.

[0061] The sensor 120 delivers data that can be used to control the operation of the aerosol generating device 100. For example, the sensor may be configured to detect user interactions with the aerosol generating device 100, such as pressing a button, opening or closing a precursor receptacle, or performing a gesture by moving the device 100 in a particular manner. The sensor 120 may also be configured to detect puffs taken by a user of the aerosol generating device 100. In another example, the sensor 120 may be configured to detect voltage, current, resistance, charge, energy, or temperature associated with the operation of the aerosol generating unit 110. The sensor 120 may also be configured to detect voltage, current, resistance, charge, energy, or temperature associated with the power supply 160 of the aerosol generating device 100 and / or a charging device connected to the aerosol generating device 100. In a further example, the sensor 120 may be configured to detect the type or amount of consumable material used by the aerosol generating unit 110.

[0062] The controller 130 is responsible for controlling the overall operation of the aerosol generating device 100, in particular operating the aerosol generation unit 110 based on data delivered by the sensor 120, creating, encrypting, and storing data in the memory unit 140, receiving and transmitting data via the communication unit 150, monitoring and / or controlling the charging of the power source 160, etc. The controller 130 may include a computing device such as those described herein, or a microcontroller. The controller 130 may also be further provided with storage for storing computer programs and / or memory for storing data related to the execution of the computer programs.

[0063] The storage unit 140 is connected to the controller 130 and configured to store therein data related to the unlocking process, such as the unique device identifier 142, the pre-shared secret 144, and / or the verification code 146. The storage unit 140 may be volatile or non-volatile. As an example, a flash memory is provided as the storage unit 140. The storage unit 140 may be an integral part of the controller 130 or a component external to the controller 130. The storage unit 140 may include multiple physically or logically separated storage sections or components for storing different data items. The unique device identifier 142, the pre-shared secret 144, and the verification code 146 may be stored, for example, in different sections or components of the storage unit 140. The pre-shared secret 144 may be stored in a section or component that is particularly protected against unauthorized access.

[0064] The unique device identifier 142 is a piece of data unique to the aerosol generating device 100, such as a unique device identification (UID) assigned to the device 100 during manufacturing. For example, each aerosol generating device 100 may be provided with a unique serial number stored in the storage unit 140 as a unique identifier. The unique device identifier 142 may also include information indicative of at least one of a product identifier, a platform identifier, and a manufacturing site, in addition to or instead of the serial number. The unique device identifier 142 may also be provided as a unique manufacturing information block (or manufacturing facility ID), MIB, i.e., as a data block containing information about the manufacturing process, such as a product ID, a platform ID, a unique ID (or serialized device unit ID), and a manufacturing site. In one embodiment, the unique device identifier 142 is a "codetify" value, i.e., a unique multi-digit alphanumeric code provided during manufacturing that encrypts unique manufacturing / time data.

[0065] The pre-shared secret 144 is a value that can be used to derive an encryption key for encrypting data. The pre-shared secret 144 is secret in the sense that it is generally not known to the user or any other unauthorized person and is not (easily) derivable from data transmitted to or from the aerosol generating device 100. The pre-shared secret 144 is not included in any data transmission during normal operation. The pre-shared secret 144 may be stored in a particularly secure portion of the storage unit (140) that is not accessible to any external device. The pre-shared secret 144 is also stored in association with each unique device identifier 142 in a database accessible to the manufacturer's server. In this way, the server may use the unique device identifier 142 in a lookup operation to obtain the pre-shared secret 144 for a particular aerosol generating device 100 in order to derive an encryption key for encrypting and / or decrypting data. Using the derived key, the server may decrypt encrypted data received from the aerosol generating device 100 and / or encrypt data transmitted to the aerosol generating device 100. The pre-shared secret 144 may be a multi-byte value large enough to prevent brute-force attacks on the encrypted data. For example, the pre-shared secret 144 may contain 8, 16, 32, 64, 128, or 256 bytes of data. Other sizes for the pre-shared secret 144 may also be used, including sizes that are or are not powers of two. As an example, a random or pseudo-random number generated during the manufacturing process may be used as the pre-shared secret 144. The pre-shared secret 144 may be generated by the aerosol generating device 100 during the manufacturing process, preferably in encrypted form, and transmitted, for example, using a public key cryptosystem such as RSA, to a host computer that stores the pre-shared secret 144 in association with the unique device identifier 142 in a database for later reference by the manufacturer server. For example, the device 100 may encrypt the pre-shared secret 144 and the unique device identifier 14 using the server public key before sending them to the server, which decrypts them using its private key.The pre-shared secret 144 may also be generated by a host computer and transmitted or written directly to the storage unit 140 during a stage in the manufacturing process.

[0066] The verification code 146 may include any suitable information by which the aerosol generating device 100 verifies the unlock code included in the unlock authorization, e.g., the unlock authorization received from the server. The verification code 146 may be generated by the aerosol generating device 100 or may be generated by a party authorized to know the pre-shared secret 144 contained within the aerosol generating device 100, e.g., the device manufacturer. The verification code 146 may be created and used for verification in many ways. One example involves calculating the verification code at the aerosol generating device 100 and the unlock code at the server in parallel, where the aerosol generating device then compares the unlock code received from the server with its own calculated verification code. In this example, the verification code and unlock code may be calculated based on common information, such as the pre-shared secret, and / or a known point in time or time slot. In another embodiment, the verification process involves receiving, decrypting, and encrypting a verification code that serves as a device challenge (and optional server challenge) by the server to generate an unlock code that is compared with the verification code (and optional server challenge) at the aerosol generating device 100. In yet another embodiment, the verification code includes the MAC address of a mobile device belonging to an authorized user, as further described below.

[0067] The communication unit 150 functions as a communication interface for establishing a communication link to an external device, particularly an external computing device such as a mobile device and / or a manufacturer server. The communication link may be based on any wired or wireless communication technology, including, but not limited to, a serial communication link, a Universal Serial Bus (USB), an optical communication port, Near Field Communication (NFC), Bluetooth, Bluetooth Low Energy (BLE), wireless communication, WiFi according to any of the IEEE 802.11x standards, mobile communication, etc. Communication with the manufacturer server may be direct or indirect, for example, via an intermediate device such as a mobile device, a holder, or a docking station. Communication with the manufacturer server may also involve multiple communication protocols, for example, a Bluetooth connection between the aerosol generating device 100 and the mobile device, and mobile communication between the mobile device and an Internet access point.

[0068] The power supply 160 acts as an energy storage unit that provides power to all components of the aerosol generating device 100. The power source 160 may be a rechargeable battery, such as a lithium ion battery or a lithium polymer battery.

[0069] FIG. 2 shows a block diagram of a system including an aerosol generating device 100, a user's external computing device, which in this example includes a mobile device 200, and a manufacturer server 300. The aerosol generating device 100 and the mobile device 200 are connected by a communication link for transmitting data. In one non-limiting example described herein, the communication link between the aerosol generating device 100 and the mobile device 200 is implemented using Bluetooth Low Energy (BLE). The mobile device 200 may include a smartphone, tablet, or PC running dedicated software such as an application (app) or a web browser. The mobile device 200 and the server 300 are also connected by a communication link. Thus, the communication link is formed indirectly between the aerosol generating device 100 and the server 300, with the mobile device 200 acting as an intermediate device. The server 300 has access to a database (not shown) that stores, among other things, the pre-shared secret 144 for the aerosol generating device 100 in association with its unique device identifier 142.

[0070] This disclosure relates to a process for unlocking an aerosol generating device 100 that uses BLE but does not complete the full BLE pairing sequence. The unlocking process can be performed to verify that the user of the aerosol generating device 100 is a legal age user / legal age smoker (LAU / LAS). In this way, it is possible to prevent underage access to the nicotine-containing aerosol generated by the aerosol generating device 100 during normal use. However, the unlocking process can be used to unlock any device function for any reason. The unlocking process uses the open nature of BLE (advertising or beaconing) to exchange information between the aerosol generating device 100 and the mobile device 200, thereby exchanging information with the server 300, which can be used to unlock the aerosol generating device 100. To this end, the aerosol generating device 100 and the mobile device 200 (particularly, the app) each have the capability to support BLE in both central and peripheral Generic Access Profile (GAP) roles. A device operating in a peripheral role can transmit data (in the form of "advertisements") containing the device's identity as well as other information. A device operating in a central role can scan for such incoming data. Such connectionless communication is typically used before pairing two BLE devices, one of which advertises its presence and the other of which reads the advertisement and optionally initiates the pairing process to form a connection for subsequent connection-oriented communication.

[0071] FIG. 2 also illustrates a first non-limiting example of an unlocking process.

[0072] In an optional preliminary step of the unlocking process, at step 10 the user enters user identification data into the mobile device 200 .

[0073] When the user is ready to begin the unlocking process, the user launches the dedicated app (or a generic app) on the mobile device in step 12. Optionally, the app itself then verifies that the user is a LAU / LAS before the unlocking process is initiated. This step may involve uploading information, such as identification, via the mobile device 12 so that the mobile device and / or server can verify whether the user is above an age threshold. If the user is a LAU / LAS, the app prompts the user to initiate the unlocking process, for example, by pressing a button on the aerosol generating device 100, which is now in a locked state, to provide a signal to the sensor 120. If multiple locked aerosol generating devices 100 are present, the user is prompted by the app to select the correct device. This indication may be provided by the app solely by reading advertisements sent by the devices, without requiring pairing.

[0074] In step 14, after the app starts, the mobile device 200 is placed in a central role ready to detect BLE advertisements coming from the aerosol-generating device 100.

[0075] In step 16, the user presses a button on the aerosol generating device 100 as instructed by the app to initiate the unlocking process.

[0076] In step 18, the aerosol generating device 100 generates a verification code 146. In this non-limiting example, the verification code 146 comprises a random one-time code (OTC) that changes with each unlocking process initiated.

[0077] In step 20, the aerosol generating device 100 is placed on a peripheral roll.

[0078] In step 22, the aerosol generating device 100 starts BLE advertising an unlock request including the unique device identifier 142 (UID) and the OTC 146.

[0079] In step 24, the mobile device 200 (and ultimately the app) receives an unlock request from the aerosol generating device 100.

[0080] In step 26, the mobile device 200 sends an unlock request including the UID 142, the OTC 146, and optionally the user identification data (entered in step 10) to the server 300. Any suitable communication means may be used in this step.

[0081] In step 28, the server 300 determines whether unlocking is permitted for the received UID. For example, the UID 142 is used to obtain a device unique serial number (DUSN), which can be linked to only one user account. Device unlocking is permitted only if the DUSN is linked to the user account corresponding to the user identification data and if the user is an LAU / LAS. If device unlocking is not permitted, the unlocking process may be aborted.

[0082] At step 30 , if device unlocking is allowed, the server 300 encrypts the OTC 146 using the UID 142 and the pre-shared secret 144 .

[0083] In step 32, the server 300 sends an unlocking authorization to the mobile device 200, including the UID 142 and the encrypted OTC 146. The unlocking authorization may also optionally include a random value generated by the server 300 as a server challenge.

[0084] In step 34, the mobile device 200 enters peripheral mode.

[0085] At step 36, the mobile device 200 advertises the unlock authorization, including the UID 142, the encrypted OTC 146, and, if used, the server challenge.

[0086] In step 38, after its advertisement of the unlock request in step 22, the aerosol generating device 100 alternates between peripheral mode and central mode.

[0087] In step 40, the aerosol generating device, in the central role, receives a BLE advertisement containing an unlock permission.

[0088] In step 42, the aerosol generating device 100 checks the UID 142 to ensure that the unlock authorization is intended for that particular aerosol generating device 100. If not, the aerosol generating device 100 ignores the unlock authorization. In that case, the aerosol generating device 100 decrypts the encrypted OTC 146 using the UID 142 and the pre-shared secret 144 to obtain the decrypted OTC, which serves as the unlock code.

[0089] In step 44, the aerosol generating device 100 verifies the received unlock code (i.e., the decoded OTC) by comparing it with the OTC stored in the aerosol generating device 100, i.e., the OTC included in the unlock request. If the OTCs match, the aerosol generating device 100 transitions to an unlocked state, for example, by unlocking lockable features.

[0090] After the unlocking process is completed or aborted, the aerosol generating device 100 may return to the peripheral role and continue advertising its UID 142 and, optionally, its locked state. The UID 142 and locked state may then be restored by the mobile device 200 in the central role, which may optionally communicate the locked state to the server 300. The locked state may be used by the server 300 in further instances of the unlocking process to determine whether to send an unlock authorization to the aerosol generating device 100. Additionally or alternatively, once the device 100 is in an unlocked state, based on such further advertisements by the device 100 and / or which may be confirmed manually within the app, the device 100 may resume in a BLE "connectable" mode, allowing pairing of the aerosol generating device 100 with the mobile device 200.

[0091] In this non-limiting example, encryption and decryption are performed using a symmetric key algorithm, e.g., AES 128 in CTR mode. The symmetric key algorithm uses a primary key and an initial value (IV) for encryption. The primary key and IV may be generated by a key derivation function (KDF) using the UID 142, pre-shared secret 144, and OTC 146. The KDF derives one or more encryption keys from the key provided as input material and parameters known as "salt" and "context." The KDF may include a hash-based key derivation function (HKDF) with HMAC-SHA1 as the hash function. In this example, the HKDF uses the pre-shared secret 144 as the input key material and the UID 142 and OTC 146 for the other parameters (salt and context). By using the OTC 146 to create the IV, the IV changes during each encryption process, making the encryption highly secure.

[0092] The table below shows the server-side encryption process for encrypting the OTC based on the UID 142 and OTC 146 received in the unlock request. [Table 1]

[0093] The table below shows the device-side decryption process for decrypting the encrypted OTC received from the server 300 in the unlock authorization. [Table 2]

[0094] In one variation on the above non-limiting example, the server 300 hashes the encrypted OTC before returning it, while the aerosol generating device 100 encrypts the initial OTC using AES, then hashes it, compares the two hashes, and determines that the user is an LAU in response to the two hashes matching.

[0095] In a further variation, the aerosol generating device 100 and the mobile device 200 may use a BLE scan request to exchange information. In this case, when in peripheral mode, the aerosol generating device 100 may indicate that it has certain characteristics, including being a connectable device (or not) or being “scannable” (or not). The mobile device 200 in central mode may then send a scan request (“SCAN_REQ”), and the aerosol generating device 100 as a peripheral may read and respond (using a scan response packet “SCAN_RSP”), adding additional information to that included in the initial advertisement. Thus, if the payload required by the unlocking process is larger than the payload allowed in an advertisement packet, the aerosol generating device 100 may indicate that it is “scannable” and use the scan response to pass some or all of the above information to the mobile device 200. Conversely, if the encrypted OTC is larger than the advertisement packet size, when sending the encrypted OTC to the aerosol generating device 100, the mobile device 200 may also use such "scannable" characteristics to trigger a scan request from the aerosol generating device 100 and send information to the aerosol generating device 100 using the scan response.

[0096] In still further variations, a predetermined code may be used to form the verification / unlock code in place of the OTC of the non-limiting example described above. In this case, the fixed code may be exchanged between the device 100 and the server 300 at the time of use using a process such as that described above, or may be known in advance to both the device 100 and the server 300, for example, from a manufacturing process. The fixed code may include or be based on the pre-shared secret 144. In such examples, additional context information may be used to complement the fixed code for additional security. For example, the verification / unlock code may be based on such a fixed code in conjunction with time-varying information known or accessible to both parties, such as the current time or the current numbered time slot.

[0097] Further, it should be appreciated that the unlocking process does not necessarily have to be initiated by device 100. In one such variation, mobile device 200 and / or server 300 may initiate the unlocking process without device 100 having to advertise its UID 142 or OTC 146. In such a variation, device 100 may remain in central mode until it receives unlock authorization from mobile device 200. Mobile device 200 may initiate the unlocking process by sending an unlock request to server 300 using device 100's UID 142 and / or user identification data. If the user is authorized, server 300 may then encrypt a pre-defined code already stored in a database (optionally modified using context information, as described above) using UID 142 and pre-shared secret 144, as described above, for device 100 to perform decryption and / or code matching for verification purposes.

[0098] In a second non-limiting example of the unlocking process, the aerosol generating device 100 utilizes mobile device MAC address packet detection for YAP activation.

[0099] In this embodiment, the aerosol generating device 100 monitors or "sniffs" network traffic for at least one packet from a specific MAC address, e.g., the MAC address of the mobile device 200, to unlock the aerosol generating device 100 for initiating a new experience. Thus, in this embodiment, connectionless communication is implemented using network sniffing, i.e., packet analysis. Detecting a MAC address indicates that the mobile device 200 is in sufficient proximity to the aerosol generating device 100 to verify that the experience is under the control of an authorized user. A MAC address, which is unique for each TCP / IP device, may be pre-stored in the aerosol generating device 100 for this purpose. In this manner, packaging containing the MAC address of an authorized user's mobile device 200 is considered implicit permission to unlock the aerosol generating device 100, allowing the aerosol generating device 100 to be unlocked as part of YAP activation. The detected MAC address serves as an unlock code to unlock the aerosol generating device 100, and the MAC address stored in the aerosol generating device 100 serves as a verification code 146 to verify the unlock code. A match between the two codes indicates that unlocking is permitted.

[0100] In this embodiment, the aerosol-generating device 100 is configured to use WiFi communication, i.e., communication based on the IEEE 802.11 family of standards. Such communication typically involves a centralized access point (AP) that coordinates all communication, and WiFi-enabled devices must associate with the AP to receive packets from it. In this embodiment, the aerosol-generating device 100 is configured to receive the unlock grant using connectionless communication by operating its WiFi-enabled communication unit 150 in monitor mode, where the aerosol-generating device 100 receives all packets within a given frequency range. In monitor mode, the aerosol-generating device 100 can monitor the MAC addresses of devices currently communicating with the AP, even when the aerosol-generating device 100 itself is not associated with the AP. Optionally, the aerosol-generating device 100 may enforce a minimum signal strength (for signals containing pre-stored MAC addresses) to ensure that authorized users' mobile devices 200 are sufficiently close. Since there may be multiple WiFi channels, the aerosol generating device 100 may be configured to monitor them sequentially for a predetermined period of time (e.g., 100 ms) to detect pre-registered MAC addresses.

[0101] In this way, the aerosol generating device 100 can implement YAP using mobile device proximity detection without requiring user intervention or app installation.

[0102] It will be appreciated that the use of a MAC address is described for illustrative purposes only, and that any address or code that uniquely identifies an authorized user's mobile device 200 and indicates proximity may be used instead of or in addition to a MAC address, such as, for example, a device identifier used in Bluetooth.

[0103] 3 illustrates an exemplary computing system 800 that can be used in accordance with the systems and methods disclosed herein. The computing system 800 may form part of or include any desktop, laptop, server, or cloud-based computing system. The computing system 800 includes at least one processor 802 that executes instructions stored in memory 804. The instructions may be, for example, instructions for implementing functions described as being performed by one or more components described herein or instructions for implementing one or more of the methods described herein. The processor 802 may access the memory 804 via a system bus 806. In addition to storing executable instructions, the memory 804 may also store conversational inputs, scores assigned to the conversational inputs, etc.

[0104] Computing system 800 further includes a data storage unit 808 accessible by processor 802 via system bus 806. Data storage unit 808 may include executable instructions, log data, etc. Computing system 800 also includes an input interface 810 that allows external devices to communicate with computing system 800. For example, input interface 810 may be used to receive instructions from an external computer device, a user, etc. Computing system 800 also includes an output interface 812 that connects computing system 800 to one or more external devices. For example, computing system 800 may display text, images, etc. via output interface 812.

[0105] It is contemplated that external devices communicating with computing system 800 via input interface 810 and output interface 812 may be included in the environment to provide virtually any type of user interface with which a user can interact. Examples of user interface types include graphical user interfaces, natural user interfaces, etc. For example, a graphical user interface may accept input from a user using an input device such as a keyboard, mouse, remote control, etc., and provide output to an output device such as a display. Furthermore, a natural user interface may allow a user to interact with computing system 800 in a manner unconstrained by input devices such as a keyboard, mouse, remote control, etc. Rather, a natural user interface may rely on speech recognition, touch and stylus recognition, on-screen and adjacent-screen gesture recognition, air gestures, head and eye tracking, voice and speech, vision, touch, gestures, machine intelligence, etc.

[0106] Additionally, although illustrated as a single system, it should be understood that computing system 800 may be a distributed system. Thus, for example, several devices may be in communication over network connections and may collectively perform the tasks described as being performed by computing system 800.

[0107] The various functions described herein may be implemented in hardware, software, or any combination thereof. If implemented in software, the functions may be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Computer-readable media includes computer-readable storage media. A computer-readable storage medium may be any available storage medium that can be accessed by a computer. By way of example, and not limitation, such computer-readable storage media may include FLASH storage media, RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. As used herein, disk and disc include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs (BDs), where disks typically reproduce data magnetically and discs typically reproduce data optically with lasers. Additionally, propagated signals may be included within the scope of computer-readable storage media. Computer-readable media also includes communication media, which includes any medium that facilitates transfer of a computer program from one place to another. A connection, for example, may be a communications medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included within the definition of communications media. Combinations of the above should also be included within the scope of computer-readable media.

[0108] Alternatively, or in addition, functionality described herein may be implemented, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that may be used include, but are not limited to, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), etc.

[0109] Applicant hereby separately discloses each individual feature and any combination of two or more such features described herein to the extent that such feature or combination of features can be implemented based on the specification as a whole in light of the general knowledge common to those skilled in the art, regardless of whether such feature or combination of features solves any problem disclosed herein, and without limiting the scope of the claims. Applicant indicates that aspects of the invention may consist of any such individual feature or combination of features.

[0110] It should be noted that embodiments of the present invention are described with reference to different categories. In particular, some examples are described with reference to methods, and other examples are described with reference to apparatuses. However, those skilled in the art will understand from the description that, unless otherwise indicated, any combination of features belonging to one category, as well as any combination between features relating to different categories, is considered to be disclosed by the present application. However, all features can be combined to provide a synergistic effect that exceeds the simple sum of the features.

[0111] While the invention has been illustrated and described in detail in the drawings and foregoing description, such illustration and description is given by way of example and not by way of limitation. The invention is not limited to the disclosed embodiments. Other variations to the disclosed embodiments can be understood and effected by those skilled in the art, from a study of the drawings, the disclosure, and the appended claims.

[0112] The mere fact that certain measures are recited in mutually different dependent claims does not indicate that a combination of these measures cannot be used to advantage.

[0113] Any reference signs in the claims should not be construed as limiting the scope.

Claims

1. 1. An aerosol generation system in a locked state in which the aerosol generation system is prevented from generating an aerosol, the aerosol generation system comprising: receiving an unlock authorization from the external computing device using connectionless communication; The aerosol generation system is configured to transition the aerosol generation system from the locked state to an unlocked state in which the aerosol generation system can generate aerosol after receiving the unlock authorization.

2. The aerosol generating system of claim 1 , wherein the aerosol generating system is configured to send an unlock request to the external computing device using connectionless communication.

3. The aerosol generating system of claim 2 , wherein the unlock request includes a unique device identifier that identifies the aerosol generating system.

4. The aerosol generating system of claim 3 , wherein the unlocking authorization includes the unique device identifier and an unlock code.

5. 5. The aerosol generating system of claim 4, wherein the unlock code is generated on or derived by a server.

6. 6. The aerosol generating system of claim 4 or claim 5, further configured to, after receiving the unlocking authorization, verify the unlocking code using a pre-shared secret unique to the aerosol generating system.

7. 7. The aerosol generating system of claim 4, further configured to transition the aerosol generating system from the locked state to the unlocked state in response to successfully verifying the unlock code.

8. 8. The aerosol generating system of claim 4, further configured to obtain a verification code for comparison with the unlock code.

9. The aerosol generation system of claim 8 , wherein the verification code is generated at the aerosol generation system.

10. An aerosol generation system as described in any one of claims 4 to 9, further configured to verify the unlock code by comparing the unlock code with a verification code, and transition the aerosol generation system from the locked state to the unlocked state in response to the unlock code matching the verification code.

11. The aerosol generating system of any of claims 4 to 10, further configured to generate a verification code based on the aerosol generating system verifying the unlock code.

12. An aerosol generating system as described in any one of claims 4 to 11, further configured to include a verification code in the unlock request and, when verifying the unlock code, determine whether the unlock code included in the unlock authorization matches the verification code.

13. a server, determining whether the aerosol generating system is associated with an authorized user; A server configured to: if the aerosol generating system is associated with an authorized user, send, directly or indirectly, an unlock authorization including the unlock code to the aerosol generating system, the unlock authorization enabling the aerosol generating system to transition from the locked state to an unlocked state in which the aerosol generating system can generate aerosol.

14. 1. A method implemented by a computing device, the method comprising: receiving an unlock authorization from the server; and transmitting the unlocking authorization to the aerosol generating system using connectionless communication.

15. 15. A computer program product comprising instructions that, when executed by a computing system, cause the computing system to perform the method of claim 14.

Citation Information

Patent Citations

  • Vaporizer Control

    JP2021508457A

  • Electronic vaping device

    US20150181945A1

  • An aerosol generating device with a wireless communication interface

    WO2021228775A1

  • Systems, devices, and methods for unlocking aerosol-generating devices

    WO2021260600A1