Method and device for unlocking an aerosol delivery system, non-transitory computer-readable storage medium, and aerosol delivery system
A separate age verification service with cryptographic authentication secures the unlocking process for non-flammable aerosol delivery systems, addressing the challenge of user age verification in systems with limited processing power and preventing unauthorized access.
Patent Information
- Application Number
- JP2023555589
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-12
- Filing Date
- 2022-03-10
- Publication Date
- 2025-10-22
- Estimated Expiration
- 2042-03-10
AI Technical Summary
Existing non-flammable aerosol delivery systems face challenges in verifying the age of users due to their small size and limited processing power, making it impractical to implement age verification within the system itself.
A separate age verification service is used to verify the user's age, and cryptography is employed to securely communicate the successful completion of this process, ensuring the system remains locked until verification is confirmed, using public and private key pairs to authenticate unlock messages.
This approach effectively prevents unauthorized access by underage users and reduces the risk of replay attacks, ensuring secure and reliable age verification for non-flammable aerosol delivery systems.
Smart Images

Figure 0007758749000001 
Figure 0007758749000002 
Figure 0007758749000003
Abstract
Description
Field and Background
[0001]
[0001] The present disclosure relates to the field of aerosol delivery system security. In particular, but not exclusively, the present disclosure relates to locking and unlocking non-flammable aerosol delivery systems.
[0002]
[0002] A "non-flammable" aerosol delivery system is one in which the aerosol-generating material (or components thereof) that constitute the aerosol delivery system is not burned or is not combusted to facilitate delivery of at least one substance to a user.
[0003]
[0003] The non-combustible aerosol delivery system may be an electronic cigarette, also known as a vaping device or an electronic nicotine delivery system (END), although it should be noted that the presence of nicotine in the aerosol-generating material is not a requirement.
[0004]
[0004] A non-combustion aerosol delivery system may be an aerosol-generating material heating system, also known as a non-combustion heating system. One example of such a system is a tobacco heating system.
[0005]
[0005] A non-combustible aerosol delivery system may be a hybrid system that generates aerosol using a combination of aerosol-forming materials, one or more of which may be adapted to be heated. Each aerosol-forming material may be, for example, in solid, liquid, or gel form, and may or may not contain nicotine. A hybrid system may include a liquid or gel aerosol-forming material and a solid aerosol-forming material. The solid aerosol-forming material may include, for example, tobacco or a non-tobacco product.
[0006]
[0006] Generally, a non-flammable aerosol delivery system may include a non-flammable aerosol delivery device and a consumable item for use with the non-flammable aerosol delivery device.
[0007] The non-combustible aerosol delivery system (e.g., the non-combustible aerosol delivery device) may include a power source and a controller. The power source may be, for example, an electrical power source or a heat-generating power source. The heat-generating power source may include a carbon substrate that can be energized to provide power in the form of heat to an aerosol-generating material or a heat transfer material in proximity to the heat-generating power source.
[0008] The non-flammable aerosol delivery system may include a consumable receiving area, an aerosol generator, an aerosol generating area, a housing, a mouthpiece, a filter, and / or an aerosol modifying agent.
[0009] Consumables for use with non-flammable aerosol delivery devices may include aerosol-generating materials, aerosol-generating material storage areas, aerosol-generating material transfer components, aerosol generators, aerosol-generating areas, housings, wrappers, filters, mouthpieces, and / or aerosol modifiers.
[0010]
[0010] According to a first aspect, a method for unlocking a non-flammable aerosol delivery system is provided, comprising the steps of receiving an indication from an age verification service that the age verification process has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to the unlock service; receiving a signed unlock message from the unlock service that is cryptographically signed using a private key associated with the corresponding public key of the non-flammable aerosol delivery system; and forwarding the signed unlock message to the non-flammable aerosol delivery system and authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system.
[0011]
[0011] Therefore, because verifying a user's age within the aerosol delivery system itself is considered impractical due to the system's small size and potentially limited processing power, a separate age verification service is used to verify the user's age. To this end, the non-flammable aerosol delivery system may be configured to maintain a locked state that prevents the system from generating and delivering aerosol until the system can confirm that the age verification process has been successfully performed. The use of cryptography provides a mathematically secure means for communicating successful execution of age verification, thereby reducing the likelihood that an inappropriate user (e.g., someone attempting to unlock a device without validly completing age verification) will generate a message that inappropriately triggers the system to unlock.
[0012] Various optional features that may be implemented in combination with the first aspect described above may add protection against replay attacks in which a validly generated signed unlock message is used at a later time than intended on an unintended aerosol delivery system or outside the scope in which the message was generated by the unlocking service. Optional features may also be implemented to reduce the impact of compromise of one non-flammable aerosol delivery system on other aerosol delivery systems, and / or to reduce the likelihood of a user inappropriately triggering an unlock without age verification.
[0013]
[0013] According to a second aspect, there is provided a device for unlocking a non-flammable aerosol delivery system, the device comprising processing circuitry configured to receive an indication from an age verification service that the age verification process has been successfully completed, send a request to unlock the non-flammable aerosol delivery system to the unlock service, receive from the unlock service a signed unlock message cryptographically signed using a private key associated with the corresponding public key of the non-flammable aerosol delivery system, and forward the signed unlock message to the non-flammable aerosol delivery system and authenticate the signed unlock message using the public key of the non-flammable aerosol delivery system.
[0014] According to a third aspect, there is provided a computer readable medium corresponding to the methods and devices of the first and second aspects.
[0015]
[0015] According to a fourth aspect, there is provided a method for unlocking a non-flammable aerosol delivery system, the method comprising: receiving a signed unlock message at the non-flammable aerosol delivery system from a user device, the signed unlock message being cryptographically signed using a private key; authenticating the signed unlock message at the non-flammable aerosol delivery system using the public key of the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key of the non-flammable aerosol delivery system; and unlocking the non-flammable aerosol delivery system in response to successful authentication of the signed unlock message.
[0016]
[0016] According to a fifth aspect, there is provided a non-flammable aerosol delivery system comprising processing circuitry configured to receive from a user device a signed unlock message cryptographically signed using a private key, authenticate the signed unlock message using a public key stored in the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key, and unlock the non-flammable aerosol delivery system in response to successful authentication of the signed unlock message.
[0017] According to a sixth aspect, there is provided a computer readable medium corresponding to the method and non-flammable aerosol delivery system of the fourth and fifth aspects.
[0018]
[0018] According to a seventh aspect, there is provided a method for unlocking a non-flammable aerosol delivery system, the method comprising the steps of: receiving, by a user device, an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; sending, by the user device, a request to unlock the non-flammable aerosol delivery system to the unlock service; generating, by the unlock service, a signed unlock message cryptographically signed using a private key associated with the corresponding public key of the non-flammable aerosol delivery system; sending, by the unlock service, the signed unlock message to a remote device; forwarding, by the user device, the signed unlock message to the non-flammable aerosol delivery system; authenticating the signed unlock message at the non-flammable aerosol delivery system using the public key of the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key of the non-flammable aerosol delivery system; and unlocking the non-flammable aerosol delivery system in response to successful authentication of the signed unlock message.
[0019]
[0019] According to an eighth aspect, there is provided a system comprising a non-flammable aerosol delivery system, a remote device, and an unlocking service, wherein the remote device is configured to receive an indication from an age verification service that the age verification process for the non-flammable aerosol delivery system has been successfully completed and to send a request to unlock the non-flammable aerosol delivery system to the unlocking service, the unlocking service is configured to generate a signed unlocking message cryptographically signed using a private key associated with the corresponding public key of the non-flammable aerosol delivery system and send the signed unlocking message to the remote device, the remote device is further configured to forward the signed unlocking message to the non-flammable aerosol delivery system, and the non-flammable aerosol delivery system is configured to authenticate the signed unlocking message using the public key of the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlocking message corresponds to the public key, and unlock the non-flammable aerosol delivery system in response to successful authentication of the signed unlocking message.
[0020] According to a ninth aspect, there is provided a computer readable medium corresponding to the methods and systems of the seventh and eighth aspects.
[0021]
[0021] According to a tenth aspect, there is provided a method for setting an encryption key in a non-flammable aerosol delivery system, the method comprising the steps of receiving a device identifier of the non-flammable aerosol delivery system, obtaining a specific encryption key to be set in the non-flammable aerosol delivery system based on one or more encryption keys provided by a key generation service, storing the device identifier in association with the specific encryption key, and writing the specific encryption key to the non-flammable aerosol delivery system.
[0022]
[0022] Thus, a secure means is provided for generating a unique key and providing it to a computing device for configuration into the aerosol delivery system. According to various optional features that may be implemented in combination with the tenth aspect above, the key may be configurable by an offline computing device that operates without a data connection.
[0023]
[0023] According to an eleventh aspect, there is provided a system for setting an encryption key in a non-flammable aerosol delivery system, the system comprising: a non-flammable aerosol delivery system; and a computer device configured to receive a device identifier of the non-flammable aerosol delivery system, obtain a specific encryption key to be set in the non-flammable aerosol delivery system based on one or more encryption keys provided by a key generation service, store the device identifier in association with the specific encryption key, and write the specific encryption key to the non-flammable aerosol delivery system.
[0024] According to a twelfth aspect, there is provided a computer readable medium corresponding to the method and computer of the tenth and eleventh aspects. [Brief explanation of the drawings]
[0025]
[0025] Embodiments and examples of the present approach will now be described, by way of example only, with reference to the accompanying drawings, in which:
[0026] [Figure 1] FIG. 1 is a schematic diagram illustrating an example of an implementation of asymmetric key cryptography to unlock a non-flammable aerosol delivery system.
[0027] [Figure 2A] FIG. 2A is a flow diagram illustrating a method for unlocking a non-flammable aerosol delivery system using asymmetric key cryptography. [Figure 2B]FIG. 2B is a flow diagram illustrating a method for unlocking a non-flammable aerosol delivery system using asymmetric key cryptography.
[0028] [Figure 3] FIG. 3 is a schematic diagram illustrating an example of an implementation of symmetric key cryptography to unlock a non-flammable aerosol delivery system.
[0029] [Figure 4A] FIG. 4A is a flow diagram illustrating a method for unlocking a non-flammable aerosol delivery system using symmetric key cryptography. [Figure 4B] FIG. 4B is a flow diagram illustrating a method for unlocking a non-flammable aerosol delivery system using symmetric key cryptography.
[0030] [Figure 5] FIG. 5 is a schematic diagram illustrating an example in which a computing device in communication with a key provision service can establish a cryptographic key for a non-flammable aerosol delivery system.
[0031] [Figure 6] FIG. 6 is a schematic diagram illustrating an example in which a computing device without a data connection to a key provisioning service can set a cryptographic key to a non-flammable aerosol delivery system.
[0032] [Figure 7] FIG. 7 is a flow diagram illustrating a method for establishing a cryptographic key for a non-flammable aerosol delivery system using a computing device in communication with a key provision service.
[0033] [Figure 8] FIG. 8 is a flow diagram illustrating a method for establishing a cryptographic key for a non-flammable aerosol delivery system using a computing device that does not have a data connection to a key provision service.
[0034] [Figure 9] FIG. 9 is a schematic diagram showing an example of a non-flammable aerosol supply system.
[0035] [Figure 10] FIG. 10 is a schematic diagram showing an example of a user device.
[0036] While the techniques described herein are susceptible to various modifications and alternative forms, specific embodiments are shown by way of example in the drawings and are herein described in detail. It is to be understood, however, that the drawings and detailed description are not intended to limit the scope to the particular forms disclosed, but rather that the scope is to cover all modifications, equivalents, and alternatives falling within the spirit and scope as defined by the appended claims. DETAILED DESCRIPTION
[0037] In the context of a non-flammable aerosol delivery system, it may be appropriate to limit its use to people above a certain age. Because verifying a user's age within the non-flammable aerosol delivery system itself is considered impractical due to the small size and potentially limited processing power of systems according to the technology described herein, a separate user device that interacts with an age verification service verifies the user's age. The non-flammable aerosol delivery system is configured to maintain a locked state that prevents the system from generating and delivering aerosol until the system can confirm that the age verification process has been successfully performed.
[0038] The age verification process itself can take any suitable form, but in some examples involves the presentation of a user's identification showing a user's photograph and age that can be checked to verify the user is of the required age before unlocking the non-flammable aerosol delivery system. Other age verification techniques are possible, and any age verification process that can be implemented using an age verification service can be used in conjunction with the techniques disclosed herein. The age verification service that performs the age verification process can be implemented by the manufacturer and / or supplier of the non-flammable aerosol delivery system, or by a third-party age verification service provider.
[0039]
[0039] Such age verification services are provided from a location remote from the non-flammable aerosol delivery system. Accordingly, the following teachings describe techniques for securely determining whether a given age verification result applies to the intended non-flammable aerosol delivery system. Accordingly, the techniques may unlock a particular non-flammable aerosol delivery system in response to successful age verification of the user / owner of that system, while preventing the same age verification from being applied to non-flammable aerosol delivery systems of different users / owners. Thus, these techniques may be useful in preventing unauthorized access to the system, for example, by underage users.
[0040]
[0040] In this example, cryptography is used to securely indicate to the non-flammable aerosol delivery system that the age verification process has been successfully completed and that the system should be unlocked. In response to notification that the age verification process is complete, the system allows the user to use the system to generate aerosol. By using cryptography, this example reduces the opportunity for an unverified user to generate a message that inappropriately triggers the system to unlock by providing a mathematically secure means for communicating that age verification has been successfully performed.
[0041]
[0041] Techniques of the present teachings utilize public key cryptography (also known as asymmetric cryptography) and symmetric cryptography (also known as private key cryptography), respectively. A generic technique that applies regardless of the cryptographic technique employed may unlock a non-flammable aerosol delivery system using a method that includes receiving, from an age verification service, an indication that an age verification process has been successfully completed for a user of the non-flammable aerosol delivery system, sending a request to unlock the non-flammable aerosol delivery system to an unlock service, receiving, from the unlock service, an unlock message that is cryptographically associated with a cryptographic key stored in the non-flammable aerosol delivery system, and forwarding the unlock message to the non-flammable aerosol delivery system and authenticating the unlock message using the cryptographic key stored in the non-flammable aerosol delivery system.
[0042]
[0042] As used herein, the term "user" is used to refer to a person who is verified by the age verification service to unlock a non-flammable aerosol delivery system. It is understood that a user may or may not be the owner of the non-flammable aerosol delivery system, but is instead a person associated with a user device used for local communication with the non-flammable aerosol delivery system for which unlocking is requested. The user may also be registered with or associated with the non-flammable aerosol delivery system in some form of manufacturer or supplier record with which the user device can communicate.
[0043] The non-flammable aerosol delivery system being requested to be unlocked is already in a locked state. This locked state may be a default state set when the device is sold and / or a state adopted when the device is disconnected from a user device for which age verification was previously performed. Such disconnection may be related to association with a different user device and / or the passage of a threshold duration since connection to the user device was established. Thus, not only is age verification for unlocking required after purchase and before use of the non-flammable aerosol delivery system (as described below), but successful age verification for unlocking is also required periodically after a period of disconnection from the associated user device or upon association with a different user device.
[0044]
[0044] The following description provides details of how the two cryptographic techniques are implemented, with the understanding that the general approach described above links both techniques, and it will be appreciated that optional features and techniques that apply with respect to the first technique may also apply with respect to the second technique, and vice versa.
[0045] As mentioned above, the above technique for unlocking a non-combustible aerosol delivery system uses a user device. The user device (which may be referred to as a remote device, meaning that it is remote from the non-combustible aerosol delivery system, or as an intermediate device, meaning that it is intermediate between the non-combustible aerosol delivery system and the unlocking / age verification service) is configured to establish a local communication channel with the non-combustible aerosol delivery system. The local communication channel may take many forms, as described below. The user device is also configured to establish communication channels with one or both of the age verification service and the unlocking service to send and receive messages that enable unlocking of the non-combustible aerosol delivery system. The user device may be, for example, the user's mobile phone or tablet device. By using the user device to facilitate communication between the aerosol delivery system and the unlocking service in this manner, the method reduces the processing requirements of the aerosol delivery system, enabling secure locking and unlocking of aerosol delivery systems with limited connectivity and processing capabilities.
[0046] 1, 2A, and 2B, a first set of examples for unlocking a non-flammable aerosol delivery system using an asymmetric key cryptography implementation is shown. A schematic infrastructure for these examples is shown in FIG. 1. As shown in this figure, a non-flammable aerosol delivery system 10 includes a random number generator 12 and a public key 14, which are used to generate messages for the unlocking process, as described in more detail below.
[0047] Also shown, non-flammable aerosol delivery system 10 is connected to a user device 18 by a local communication channel 16. The local communication channel may be non-permanent or transient in the sense that it is established for the duration needed to perform a particular function and may be disconnected when not needed.
[0048] In this example, local communication channel 16 is a wireless channel provided using a connection technology such as a personal area network protocol. Exemplary personal area network protocols include Bluetooth™, Bluetooth Low Energy (BLE)™, Zigbee™, Wireless USB, and Near Field Communication (NFC). Exemplary personal area network protocols also include protocols that utilize optical communication and data over sound, such as Infrared Data Association (IrDA). The remainder of this discussion will use BLE examples and terminology, but it will be understood that corresponding or equivalent features of other personal area network technologies may be substituted. Other wireless technologies, such as Wi-Fi™ technology, may also be used if the non-flammable aerosol delivery system has suitable capabilities. In another example, local communication channel 16 may be a wired communication channel established between a physical port on non-flammable aerosol delivery system 10 and user device 18. Such wired communication channels may utilize physical connection technologies such as USB™, serial port, FireWire™, or other point-to-point wired connections.
[0049] Using local communication channel 16, user device 18 and non-flammable aerosol delivery system 10 can exchange messages related to the use of non-flammable aerosol delivery system 10. This message exchange may include many different functions, and this disclosure will focus on functions related to unlocking non-flammable aerosol delivery system 10 for use after successful age verification.
[0050] To provide functionality to user device 18, the present approach uses a software application (often simply referred to as an "app") to perform unlocking functions. Of course, the app may also include other functions related to the use of non-flammable aerosol delivery system 10. These may include tasks such as providing a mechanism for a user to confirm details of use of non-flammable aerosol delivery system 10. This disclosure focuses on functions related to unlocking non-flammable aerosol delivery system 10 for use after successful age verification.
[0051] Also shown, user device 18 can be connected to age verification service 22 via network connection 20. Age verification service 22 may be a commercially available age verification service that uses known techniques for determining whether a person being verified exceeds a certain age threshold. In this context, age verification service 22 may respond to a request for age verification that suitably identifies a user by providing an age verification result (or an output that can be used to represent an age verification result, such as an actual age that can be tested against an age threshold). The nature of this suitable form varies from age verification service to age verification service and may include one or more of the following: a username, a user identification number, a user photo, a user identification document, or other personally identifying information for the user. Interaction between user device 18 and age verification service 22 may utilize a public interface of the age verification service, such as an application programming interface. One example of a commercially available age verification service is Jumio™, which provides an API for use in submitting verification requests.
[0052] The connection between the user device 18 and the age verification service 22 is represented as a network connection 20 that facilitates the use of commercial age verification services in conjunction with an internet-accessible interface. Thus, the network connection 20 may include one or more of a local area network, a wide area network, and an internet connection, which may be provided via wireless and / or wired network infrastructure. The connection may be intermittent or non-persistent, in that a connection may be established to perform certain functions, but not necessarily maintained otherwise. The network connection 20 may be protected by techniques such as SSL, tunneling, encryption, signed message exchange, etc., so that a given age verification request and response are exchanged securely without opportunity for tampering by a malicious party.
[0053] Also shown, the user device 18 is connectable to an unlocking service 26 via the network connection 24. The unlocking service 26 has a key store 30 that stores a private key 32. The private key 32, as stored in the unlocking service's key store, and the public key 14, as stored in the non-flammable aerosol delivery system, are a corresponding public / private key pair. The key store 30 may be local to the unlocking service 26 or may be internal to the unlocking service 26. Alternatively, the key store 26 may be external to the unlocking service 26 but securely connected to it. The unlocking service 26 may receive an unlock request generated using the public key 14 of the non-flammable aerosol delivery system 10, test the unlock request against the private key 32, and in response, generate an unlock message using the private key 32, which may then be tested against the corresponding public key 14, thereby facilitating unlocking.
[0054] Additionally, unlocking service 26 can use the age verification result of the user of non-flammable aerosol delivery system 10 to trigger the provision of a responsively generated unlocking message. In this example, the age verification result is provided directly from age verification service 22 to unlocking service 26 via network connection 30. In other examples, the age verification result may be provided from age verification service 22 to unlocking service 26 via user device 18 (and thus network connections 20 and 24).
[0055]
[0055] For this reason, the unlocking service 26 in this example stores the relationship between the non-flammable aerosol delivery system 10 and the private key 32. The unlocking service 26 may also store the received age verification result in association with the non-flammable aerosol delivery system 10 and the private key 32. Additionally or alternatively, the unlocking service 26 may store an identifier corresponding to the user and / or the user device (or an instance of an app on the user device) in association with the private key 32.
[0056] Interactions between the user device 18 and the unlock service 26 (and any interactions between the unlock service 26 and the age verification service 22) may utilize public interfaces of the unlock service 26, such as an application programming interface. An application programming interface is a programmatic interface that allows requests and messages to be provided using predetermined formats or rules that facilitate the secure and correct operation of the service.
[0057] The connection between the user device 18 and the unlock service 26 (and any interaction between the unlock service 26 and the age verification service 22) is represented as a network connection 24 (and 28) that facilitates the unlock service being provided to the user device at a remote location through the use of a remotely accessible interface (which may be an API interface as described above). Thus, the network connection 26 (and 28) may include one or more of a local area network, a wide area network, and an Internet connection, which may be provided via wireless and / or wired network infrastructure. The connection may be intermittent or non-persistent, in that a connection may be established to perform certain functions but not necessarily maintained otherwise. The network connection 24 (and 28) may be protected by techniques such as SSL, tunneling, encryption, signed message exchange, etc., so that a given unlock request and unlock message (and age verification result) are exchanged securely without opportunity for unauthorized intervention by a malicious party.
[0058]
[0058] The foregoing provides an overview of an infrastructure that allows a locked non-flammable aerosol delivery system to be securely unlocked upon request and upon the outcome of an age verification test of the user of the non-flammable aerosol delivery system.
[0059]
[0059] A method for unlocking a non-flammable aerosol delivery system using asymmetric key cryptography performed by the infrastructure shown with reference to Figure 1 will now be discussed with reference to Figures 2A and 2B. In this example, all steps shown in Figures 2A and 2B are employed, although dashed boxes in Figures 2A and 2B indicate some steps that may be omitted from the method in other examples.
[0060] In this example, the process may be triggered in one of many ways. A consistent aspect of the trigger is that a user wishes to unlock the non-flammable aerosol delivery system for use, and age verification is required to achieve the unlock. In one example, the user submits a request to unlock the aerosol delivery system on the user device, which then directs the user to an age verification service to verify their age before the aerosol delivery system can be unlocked. In another example, the user may attempt to activate a locked non-flammable aerosol delivery system, and signaling to the user device may notify the user of the initiation of the age verification and unlock process. In another example, the user may interact directly with the age verification service, which may later notify the user device (directly or via the unlock service) that the user's age has been successfully verified.
[0061] Regardless of how the age verification process is triggered, upon successful completion of the age verification process, as shown in step S2-1, the age verification service 22 sends an indication to the user device 18 via connection 20 that the age verification process has been successfully completed. As previously mentioned, this indication of successful completion may be a simple pass result (as opposed to fail) or may be an indication that the user device may test against a locally stored threshold (e.g., an actual age result).
[0062] Thus, in step S2-3, the user device 18 receives an indication from the age verification service that the process has been successfully completed. This indication alerts or notifies the user device 18 that the unlocking process can begin. As previously mentioned, the user device 18 may be running an app (or any other suitable form of software) that allows the user to control the aerosol delivery system, and the instructions may be received by the app. Additionally or alternatively, as previously mentioned, the instructions may be pursuant to an API that governs the form and content of the interaction between the user device 18 (or its app) and the age verification service 22. However, in some examples, the instructions from the age verification service may be in the form of an email or text message sent to the user device, or may be provided via the user themselves (e.g., the age verification service provides the user with a code indicating that age verification has been completed).
[0063] In response to an indication that age verification is complete, the user device then generates or obtains an unlock request to send to the unlock service. As shown, the unlock request in this example is obtained by the user device sending the unlock request to non-flammable aerosol delivery system 10 (step S2-5). The unlock request (sometimes referred to as a challenge request) is then received by non-flammable aerosol delivery system 10 in step S2-7.
[0064] In response to the unlock request, the non-flammable aerosol delivery system 0 generates a challenge in step S2-11. The challenge can take many forms. As described below, the various techniques for generating the challenge provide protection against so-called replay attacks. In some examples, the challenge may be a cryptographic nonce (i.e., a one-time use number).
[0065] In general, more complex challenges may be used to reduce the likelihood that the challenge will be unique to the non-flammable aerosol delivery device generating the message, the time at which the aerosol delivery device generates the message, or both, thereby reducing the likelihood that the challenge, and therefore the response unlock message, will be accidentally or intentionally reused for multiple different unlock requests to multiple non-flammable aerosol delivery systems.
[0066]
[0066] On the other hand, by providing a challenge response message that can be easily generated by the non-flammable aerosol delivery system, the non-flammable aerosol delivery system may be able to generate challenges more quickly without requiring more complex processing circuitry.
[0067] In this example, the challenge is created by generating a random number using random number generator 12 of non-flammable aerosol delivery system 10. As used herein, the term random number refers to both truly random and pseudo-random numbers. In addition to providing challenges with low predictability, this approach increases the chances that different challenges will be generated at different times by the same non-flammable aerosol delivery system 10.
[0068]
[0068] In this example, the random number is then hashed to generate a hash digest of the random number. Using a hashing method allows the challenge to benefit from the uniqueness of a long random number without making the exchange message equally long, and, as will become apparent below, minimizes the length of data required for any cryptographic operations performed by the non-flammable aerosol delivery system. The hash may be calculated using any suitable hash algorithm, such as the Secure Hash Algorithm. In this example, the SHA-2 algorithm is used to provide an appropriate balance between security and the processing power required by the non-flammable aerosol delivery system, although other algorithms may be used. In a specific illustrative example, the SHA256 variant of SHA-2 is used to generate the hash digest, which is expressed in Base64 for ease of copying.
[0069]
[0069] In the above examples, the random number itself is used to generate the challenge response message, but in some examples, the random number is used to select one of a number of predetermined challenge contents to be used as the challenge content.
[0070]
[0070] In the above example, a hash of a random number is used to generate the challenge, but in some examples the random number itself (or a portion of it) may be used as the challenge.
[0071]
[0071] In a simpler example that avoids the need for numeric generation in the non-flammable aerosol delivery system, the challenge includes the device identifier or serial number of the device. In this way, the challenge response message can be easily generated without requiring complex processing circuitry. Furthermore, since the device identifier is likely to be unique to the aerosol delivery system, it is known that the challenge response message will not be the same as a challenge response message generated by another aerosol delivery device. Furthermore, such a device identifier or serial number may be used in combination with the random number method described above.
[0072] Additionally, in some examples, the challenge may include a timestamp that ties the challenge to the time of generation, which may be to provide a challenge that is likely to be unique in the sense that a particular aerosol delivery system and other aerosol delivery systems will not generate the same challenge containing the same timestamp.
[0073] Once the challenge is generated in step S2-11, the challenge is transmitted from the non-flammable aerosol delivery system 10 to the user device 18 as a challenge response message in step S2-13, which may also be referred to as notifying the challenge. The user device 18 then incorporates the challenge response message into an unlock request that it sends to the unlock service 26 (in step S2-15), which may also be referred to as posting the challenge. The unlock request message in this example includes information identifying at least one of the non-flammable aerosol delivery system 10, the user, and / or the user device 18. As described above, the unlock request message is sent from the user device 18 to the unlock service 26 via connection 24 in accordance with communication or interaction rules defined for communication, such as an API. The unlock request message is then received by the unlock service 26 in step S2-17.
[0074] As noted above, the unlocking service can take many forms. In this example, the unlocking service is implemented as a remote service accessible to user devices via the internet. In some examples, the unlocking service is provided by a cloud, which may be a public cloud or a private cloud maintained, for example, by the manufacturer of the aerosol delivery device.
[0075]
[0075] Receipt of the unlock request by the unlock service triggers the unlock service to generate a signed unlock message that can be used to unlock the aerosol delivery system. As previously mentioned, the technique of this example uses public key cryptography (also known as asymmetric cryptography) to ensure that only the unlock service can unlock the aerosol delivery system. Public key cryptography uses a pair of keys, including a public key and a private key. One of the public / private keys is used to perform a cryptographic operation on some data to encrypt the data, thereby obscuring the data itself. The other of the public / private keys can then be used to reverse the cryptographic operation to decrypt the encrypted data. In the example using asymmetric cryptography, the public key 14 resides in the non-flammable aerosol delivery system, and the private key resides in the key store 30 of the unlock service 26.
[0076] In this example, the challenge in the unlock request message (provided to the unlock service 26), which is itself based on the challenge response message, is signed with the private key 32 to generate a signed unlock message (sometimes referred to as a signed challenge response). As previously mentioned, this example also involves providing the age verification result directly from the age verification service 22 to the unlock service 26.
[0077]
[0077] Therefore, prior to generating the signed unlock message, the unlock service 26 verifies the age verification result with the age verification service 22. In this example, in step S2-19, the unlock service uses connection 28 to send a verification request to the age verification service 22 seeking confirmation that the age verification process for the non-flammable aerosol delivery system 10 has been successfully completed. To facilitate this verification request, the unlock service 26 uses information about the non-flammable aerosol delivery system 10, the user, and / or the user device 18 from the unlock request message to identify the age verification result that is being asked to be confirmed by the age verification service 22.
[0078]
[0078] Thus, as shown in step S2-21, age verification service 22 receives a request to verify that the age verification process for non-flammable aerosol delivery system 10 has been successfully completed and checks whether this is the case. If the age verification process has not been successfully completed ("No" output of S2-21), the unlock service is notified of this fact, and the unlock process terminates in step S2-23. At this point, unlock service 22 can notify user device 18 that the unlock process has terminated, which can prompt the user to, for example, retry age verification. Of course, termination of the unlock process at this point in the process prevents unlocking of non-flammable aerosol delivery system 10, since no unlock command is sent to either user device 18 or non-flammable aerosol delivery system 10. On the other hand, if the age verification process is in fact completed successfully (YES output of S2-21), the unlocking service is informed of this fact and the unlocking process continues at step S2-27.
[0079]
[0079] As an alternative or improvement, in the above example where the age verification service provides the results directly to the user via a code provided directly to the user, the unlock request message can also include this code, which the unlock service can use as unique proof of successful age verification or as part of a request to the age verification service to confirm that age verification has been completed.
[0080] In other examples, the age verification result may have already been provided to the unlock service 26 by the age verification service 22 at the same time that the age verification result was provided to the user or user device during the age verification process. In such examples, the age verification result may include some indication of the non-combustible aerosol delivery device, the user, or the user device regarding the provided age verification, such that the unlock service 26 may later match the age verification result against an unlock request message received from the user device 18 for the non-combustible aerosol delivery system 10. In such examples, the step of matching the age verification result against the unlock request message may occur between step S2-17 and step S2-27 (or step S2-23 if no such match is found).
[0081] In another example, if the age verification result is not provided directly to the unlock service 26 by the age verification service 22, the unlock request message may include a representation that the age verification was successfully completed. Such a result may then be used by the unlock service 26 to proceed directly from steps S2-17 to S2-27. In such an example, the representation that the age verification was successfully completed (included in the unlock request message) is itself securely indicated as authentic, preventing a malicious actor from unlocking the non-flammable aerosol delivery system 10, for example, by unauthorized access to the user device 18 or by issuing a false age verification result to the user device in the unlock request message. For example, the representation that the age verification was successfully completed may be signed using the private key of the age verification service 22, and the signature may then be verified by the unlock service 26 using the corresponding public key of the age verification service.
[0082] These techniques for testing, checking, or confirming age verification results reduce the likelihood that a user will inappropriately trigger an unlock request without first performing age verification that would result in the age verification service sending an indication that the user's age has been sufficiently verified. In this manner, performing an independent verification with the age verification service can prevent even an erroneously generated unlock request from initiating the unlock of the non-flammable aerosol delivery system.
[0083]
[0083] The method therefore continues with step S2-27, in which the unlocking service 26 generates a signed unlocking message signed using the private key 32.
[0084]
[0084] In this example, this signed unlock message is generated by the unlock service 26 signing the challenge as it was originally generated by the non-flammable aerosol delivery system 10 and then forwarded to the unlock service in the challenge response message and unlock request message. As noted above, the challenge in this example was created by generating a hash of a random number generated by the non-flammable aerosol delivery system 10. The signed unlock message is then generated by signing this hash digest with the private key 32. Of course, such a signature can then be verified by the non-flammable aerosol delivery system 10 using the public key 14. As explained in more detail below, this allows the signature to be tested against the original challenge, verifying that the unlock process has not been tampered with "in flight" either on its way to or from the unlock service 26.
[0085]
[0085] In a specific example where the hash digest is represented as Base64 before being sent in the challenge response message, the unlock service 26 may sign the hash digest after decrypting it from the Base64 encoding and then re-encode the signed hash digest as Base64.
[0086] In some alternative examples, the unlocking service 26 generates a signed unlocking message by first generating an unsigned unlocking message and then performing a cryptographic operation on a hash of the unsigned unlocking message using a private key to construct a signature. In such examples, the signed unlocking message includes both the signed unlocking message and the signature. The signed unlocking message can then be verified by the non-flammable aerosol delivery system 10 as having been generated by the owner of the private key (i.e., the unlocking service) by using the public key to revoke the cryptographic operation of the signature and comparing it to the hash of the unsigned unlocking message. A match provides strong indication that the signed unlocking message was generated by the unlocking service and has not been tampered with “in-flight” between the unlocking service and the aerosol delivery system.
[0087]
[0087] Another approach to generating a signed unlocking message is to perform a cryptographic operation using the private key directly on the unsigned unlocking message to encrypt the unsigned unlocking message and generate the signed unlocking message. In such a case, the signed unlocking message can be authenticated by the aerosol delivery system (or indeed by anyone with the public key) by using the public key to undo the cryptographic operation and reveal the unsigned unlocking message. If the unsigned unlocking message is still an unlocking message that conforms to the agreed-upon format, the aerosol delivery system may determine that the unlocking message is valid.
[0088] After generating the signed unlock message in step S2-27, the unlock service 26, in step S2-29, sends the signed unlock message to the user device 18. Next, in step S2-31, the user device 18 receives the signed unlock message and forwards the signed unlock message to the non-flammable aerosol delivery system 10.
[0089]
[0089] In response to receiving the signed unlock message forwarded by the user device 18 (step S2-33), the aerosol delivery system, in step S2-35, determines whether the private key 32 used to sign the unlock message corresponds to the public key 14 of the non-flammable aerosol delivery system by authenticating the signed unlock message using a public key stored in the aerosol delivery system.
[0090] As noted above, this authentication may be performed by hashing an unsigned copy of the unlock message contained in the signed unlock, undoing the cryptographic operations performed on the signature using public key 14, and comparing the results. Alternatively, this authentication may involve decrypting the signed unlock message using public key 14 and determining whether the resulting message is a valid unlock message.
[0091]
[0091] As described above, in this example, the signed unlock message uses a signed copy of the hash digest generated as the challenge and transmitted in the challenge response message. Therefore, in this example, verifying the signed unlock message in non-flammable aerosol delivery device 10 involves verifying that the signature applied to the hash digest could only have been generated by private key 32 paired with public key 14, and that the signature was applied to the hash digest that constitutes the challenge. In a specific example in which the signed unlock message is transmitted converted to Base64, this authentication involves reversing the Base64 encoding prior to verification using public key 14.
[0092]
[0092] Thus, successful authentication by the non-flammable aerosol delivery system 10 provides strong indication both that the signed unlock message was generated by the unlocking service 26 (since the non-flammable aerosol delivery system 10 can identify that the signed unlock message was generated using the private key 32) and, because the value of the signed / encrypted form of the message is bound to the content of the message itself, that the signed unlock message has not been tampered with "in-flight" between the unlocking service 26 and the non-flammable aerosol delivery system 10. If the signed unlock message includes a signed hash digest, there is further end-to-end assurance that the challenge message has not been tampered with "in-flight" between the non-flammable aerosol delivery system 10 and the unlocking service 26.
[0093]
[0093] In particular, this approach makes it extremely difficult for a user to unlock the aerosol delivery system without successfully completing an age verification process in which instructions are received that enable generation of a signed unlock message at unlock service 26. Thus, this approach effectively reduces the opportunities for someone wishing to circumvent the age verification process to successfully gain access to the aerosol delivery system.
[0094] In response to successful authentication of the signed unlock message ("Yes" output of step S2-37), in step S2-41, the non-flammable aerosol delivery system 10 is unlocked. Unlocking the system may include allowing a user to use the system to generate aerosol. For example, the processing circuitry of the non-flammable aerosol delivery system may prevent operation of the system's aerosol generator while the aerosol delivery system is in the locked state.
[0095] Conversely, the non-flammable aerosol delivery system may prevent unlocking of the aerosol delivery system (step S2-39) in response to a failure to authenticate the signed unlock message ("No" output of step S2-37). For example, if the aerosol delivery system detects that the signed unlock message has been tampered with or not generated by the unlock service 26, the aerosol delivery system may keep the non-flammable aerosol delivery system 10 in a locked state to prevent access by users who have not successfully verified their age.
[0096] In some examples, the non-flammable aerosol delivery system 10 notifies the user device 18 after unlocking. Similarly, the non-flammable aerosol delivery system 10 may notify the user device 18 in the event of authentication failure (step S2-43). Accordingly, the user device 18 may receive a notification indicating whether authentication was successful and, for example, display corresponding instructions to the user on the user device.
[0097]
[0097] It will be appreciated that there are a variety of possibilities for cryptographic operations and the configuration of private and public keys that can be used in accordance with the techniques described herein. For example, the unlocking service and aerosol delivery system may utilize the Digital Signature Algorithm (DSA) or Rivest-Shamir-Adleman (RSA) cryptosystems to generate and authenticate signed unlocking messages. In one example, the Elliptic Curve Digital Signature Algorithm (ECDSA) is used, and the cryptographic operations performed and the cryptographic keys used follow the techniques specified in ECDSA.
[0098]
[0098] Thus, a method for maintaining a non-flammable aerosol delivery system in a locked state that is released (and the unlocked state adopted) only upon request and upon the outcome of an age verification test of a user of the non-flammable aerosol delivery system has been described. This method is secured through the use of asymmetric key cryptography such that only devices associated with users who have successfully completed age verification can transition from the locked state to the unlocked state.
[0099] 1 and 2, the unlocking service stores a private key paired with the non-flammable aerosol delivery system, which stores a public key. Because the public key can be made public without compromising cryptographic security, the non-flammable aerosol delivery system does not store secrets, reducing the risk of unauthorized access to the aerosol delivery system. This may also facilitate the manufacture of aerosol delivery devices and the establishment of cryptographic keys, since there is no need to provide tamper-proof storage for securely storing the private key.
[0100]
[0100] As noted above, in this example, the signed unlock message is cryptographically associated with the challenge response message, allowing the non-flammable aerosol delivery system to authenticate that the signed unlock message corresponds to a challenge response message previously generated by the non-flammable aerosol delivery system. Such an approach can be useful in protecting against replay attacks in which a validly generated signed unlock message is used at a later time than intended on an unintended non-flammable aerosol delivery system, or outside the scope in which the message was generated by the unlocking service. By associating the signed unlock message with the challenge response message, the non-flammable aerosol delivery device in this example can detect when a validly signed unlock message is used outside the intended scope, thereby preventing the non-flammable aerosol delivery system from being unlocked.
[0101]
[0101] As described above, the use of the challenge response message allows the non-flammable aerosol delivery system, when later verifying the signed unlock message, to verify not only that the signed unlock message originating from the unlocking service was not tampered with when transmitted to the aerosol delivery system, but also that the signed unlock message corresponds to a challenge response message generated by the system. Thus, even if a user attempts to unlock the aerosol delivery system using a signed unlock message validly generated by the unlocking service for a different aerosol delivery system that issued a different challenge response message, the aerosol delivery system will not be able to successfully authenticate the signed unlock message, preventing the non-flammable aerosol delivery system from being unlocked.
[0102]
[0102] As an alternative to the above example, the unlocking service may combine (e.g., concatenate or interleave) the unsigned unlocking message and the challenge response message, hash the combination, and perform a cryptographic operation on the hash of both messages using a private key to generate a cryptographic signature to include in the signed unlocking message. This association could then be authenticated by performing a similar process at the non-combustible aerosol delivery system, combining a challenge response message previously generated at the non-combustible aerosol delivery system with the unsigned unlocking message included in the signed unlocking message, hashing the result, reversing the cryptographic operation performed on the signature with the public key, and comparing the hash. If the comparison finds a match, the cryptographic association between the signed unlocking message and its challenge response message is considered valid.
[0103] While the above description relates to unlocking a single non-flammable aerosol delivery system, the same techniques and infrastructure can be used to control the lock status of multiple different non-flammable aerosol delivery systems. In some such examples, the same key pair is used for multiple (or all) aerosol delivery systems managed by the unlocking service. This can simplify the aerosol delivery system manufacturing process by eliminating the need to provide different cryptographic keys for different non-flammable aerosol delivery systems. However, to prevent a valid signed unlock message for one non-flammable aerosol delivery system from being used for another non-flammable aerosol delivery system (e.g., if two non-flammable aerosol delivery systems happen to issue the same challenge), and to limit the impact of compromise of one non-flammable aerosol delivery system on other non-flammable aerosol delivery systems, the unlocking service may have access to multiple private keys corresponding to different aerosol delivery systems. Techniques for establishing keys for non-flammable aerosol delivery systems are described below with reference to Figures 5-8.
[0104] In such a case, the user device 18 includes the device identifier (e.g., serial number) of the non-flammable aerosol delivery system 10 in the unlock request so that the unlocking service 26 can identify the private key 32 to use in generating a signed unlock message for the particular non-flammable aerosol delivery system 10. The unlocking service 26 can then generate a signed unlock message using the private key 32 of the non-flammable aerosol delivery system by selecting a private key 32 from multiple private keys in the key store 28 (or multiple such key stores) accessible to the unlocking service. The unlocking service 26 then generates a signed unlock message using the selected private key 32. Because the private key 32 selected by the unlocking service 26 corresponds to the public key 14 stored in the non-flammable aerosol delivery system 10 with that device identifier, use of the correct private key 32 will result in successful authentication with the aerosol delivery system, but unlocking will not occur because the non-flammable aerosol delivery system can detect the use of a private key with a different non-flammable aerosol delivery system. Thus, a signed unlock message validly generated for one non-flammable aerosol delivery system cannot be reused to unlock a different aerosol delivery system.
[0105]
[0105] With respect to message exchange between the user device 18 and the non-flammable aerosol delivery system, as previously mentioned, the local communication channel 16 can be a suitable personal area network connection for transmission. The local communication channel 16 can further improve communication efficiency by generating an improved profile corresponding to the use of age verification techniques. Thus, message exchange can be achieved with low overhead over the local communication channel, as message headers / wrappers can be minimized if the profile itself carries the relevant information.
[0106]
[0106] In this example where the BLE protocol is used for the local communication channel, the above communication efficiency can also be achieved by using the following profile definitions: ●For sending an unlock request message from the user device 18 to the non-flammable aerosol supply system 10 (step S2-5), the profile may describe a message coding (e.g., App Write Request Challenge) indicating that the app (user device) is writing a request for a challenge, which may be coded, for example, as [0x00]. ●For sending a challenge response from the non-flammable aerosol delivery system 10 to the user device 18 (step S2-13), the profile may describe a message coding (e.g., Device Notify Challenge) indicating that the non-flammable aerosol delivery system is notifying the user device of a challenge, which may be coded, for example, as [0x01][Challenge]. ●For sending a signed unlock message from the user device 18 to the non-flammable aerosol delivery system 10 (step S2-31), the profile may describe a message (e.g., App Write Request Signed) indicating that the app (user device) is writing a signed request, which may be coded, for example, as [0x02][Signed Data]. ●For sending a notification of unlock success or failure from the non-flammable aerosol delivery system 10 to the user device 18 (step S2-43), the profile may describe a message (e.g., Device Notify Unlock Success) indicating that the non-flammable aerosol delivery system is writing an unlock success status, which may be coded, for example, as [0x03][0x00 True||0x01 False]. In the example where the challenge and signed unlock message are base64 encoded, this is the format used for the [Challenge] and [Signed Data] payloads shown above.
[0107]
[0107] Having described a first approach to unlocking a non-flammable aerosol delivery system using public key cryptography, we now describe a second approach to unlocking a non-flammable aerosol delivery system using symmetric cryptography.
[0108]
[0108] To this end, with reference to Figures 3, 4A, and 4B, a second set of examples are provided for implementing symmetric key cryptography to unlock a non-flammable aerosol delivery system. A schematic infrastructure for these examples is shown in Figure 3.
[0109]
[0109] The infrastructure shown in Figure 3 is similar to that described above with reference to Figure 1, and so like reference numerals are used to denote like elements, and a description of like features will not be repeated.
[0110]
[0110] As noted above, in this example, symmetric cryptography is used to protect communications between the unlock service 26 and the non-flammable aerosol delivery system 10. To facilitate this, the non-flammable aerosol delivery system 10 in this example stores a device key 40, and the key store 30 stores a matching pass key 42. Thus, the device key 40 and the pass key 42 represent shared secrets that can be applied on both sides of a communication path to protect the transmission of messages between them.
[0111]
[0111] Thus, in accordance with the technology described herein, symmetric cryptography (also known as secret-key cryptography) is used to ensure that only the unlocking service can unlock the aerosol delivery system. In symmetric cryptography, a shared secret in the form of a cryptographic key that is known to both parties but secret to others is used to protect the transmission of information. To this end, the unlocking service uses the private key to perform a cryptographic operation on some data, encrypting that data in a way that cannot be easily reversed without knowledge of the private key. The cryptographic operation can then be reversed by the non-flammable aerosol delivery system, which stores a copy of the private key. Also, as will become apparent below, the cryptographic operation need not be performed using a shared secret; rather, each can be used as input for a calculation at the unlocking service that is sent to the non-flammable aerosol delivery system and then generated as a message that can be verified by repeated calculations at the non-flammable aerosol delivery system.
[0112] In this approach, the unlocking service stores a copy of the private key, referred to as the PassKey, and the aerosol delivery system stores a copy of the private key, referred to as the DeviceKey. Thus, the non-flammable aerosol delivery system may include secure storage configured to securely store the DeviceKey such that even an owner of the aerosol delivery system has difficulty accessing the DeviceKey. The secure storage may include tamper-resistant hardware, such as a Trusted Platform Module (TPM).
[0113]
[0113] Thus, the unlocking service 26 in this example stores the relationship between the non-flammable aerosol delivery system 10 and the passkey 42. The unlocking service 26 may also store the received age verification result in association with the non-flammable aerosol delivery system 10 and the passkey 42. Additionally or alternatively, the unlocking service 26 may store an identifier corresponding to the user and / or the user device (or an instance of an app on the user device) in association with the passkey 42.
[0114]
[0114] The foregoing provides an overview of an infrastructure that allows a locked non-flammable aerosol delivery system to be securely unlocked upon request and upon the outcome of an age verification test for the user of the non-flammable aerosol delivery system.
[0115]
[0115] A method for unlocking a non-flammable aerosol delivery system using asymmetric key cryptography performed by the infrastructure shown with reference to Figure 3 will now be discussed with reference to Figures 4A and 4B. In this example, all steps shown in Figures 4A and 4B are employed, although dashed boxes in Figures 4A and 4B indicate some steps that may be omitted from the method in other examples.
[0116]
[0116] Similar to the approach described above with reference to Figures 2A and 2B, the process may be triggered in one of many ways, and therefore reference is made to the examples given above.
[0117]
[0117] Regardless of how the age verification process is triggered, once the age verification process is successfully completed, as shown in step S4-1, the age verification service 22 sends an indication that the age verification process has been successfully completed in substantially the same manner as described above with respect to step S2-1.
[0118]
[0118] Thus, at step S4-3, the remote user device 18 receives an indication from the age verification service that the process has been successfully completed, in substantially the same manner as described above with respect to step S2-3.
[0119] In response to an indication that age verification is complete, the user device then generates or obtains an unlock request to send to the unlock service. In this example, the unlock request is generated directly on the user device by the user device using the serial number or other specific identifier of the non-flammable aerosol delivery system 10. Generally, in the present teachings, any reference to the serial number of the non-flammable aerosol delivery system includes the actual serial number, a portion of the serial number, a combination of the product number and serial number, or any other specific or unique identifier of the non-flammable aerosol delivery system. Such an identification number may also be referred to as a device identifier. In this manner, the unlock request can be easily generated on the user device without requiring complex processing circuitry or burden on the non-flammable aerosol delivery system. Furthermore, because the device identifier is likely to be unique to the aerosol delivery system, it is known that the challenge response message is unlikely to be the same as a challenge response message generated by another aerosol delivery device.
[0120]
[0120] As shown, the unlock request in this technique may optionally be generated by steps S4-5, S4-7, S4-11, and S4-13 in substantially the same manner as steps S2-7, S2-9, S2-11, and S2-13 described above. Reference is therefore again made to the technique described above and how such a technique may provide complementary protection against replay attacks.
[0121]
[0121] In some examples, for purposes of an age-verification unlocking technique based on symmetric encryption, the serial number of the non-flammable aerosol delivery system 10 or an optional challenge may be considered a cryptographic nonce (i.e., a disposable number).
[0122]
[0122] Regardless of how the unlock request is determined, the unlock request is then sent by the user device 18 to the unlock service 26 in step S4-15. The unlock request message is then received by the unlock service 26 in step S4-17.
[0123] 2A, the unlock service then verifies that age verification has been successfully completed for the user for whom the non-flammable aerosol delivery system 10 is the subject of the unlock request. As above, this may include querying the age verification service (as shown in steps S4-19, S4-21, and S4-23), checking against verification results previously received from the age verification service, and / or using an assertion (received in or associated with the unlock request) that age verification has been completed.
[0124]
[0124] Once age verification is determined to be successfully completed, the method continues to step S4-27, where an unlock password is generated. This unlock password is based on passkey 42.
[0125]
[0125] In this example, if the unlock request includes the serial number of the non-flammable aerosol delivery system 10, the unlock password is generated by applying the passkey 42 to the serial number of the non-flammable aerosol delivery system 10. While it is possible to generate the password by directly signing and / or encrypting using the serial number of the non-flammable aerosol delivery system 10, this example uses a method that aims to both minimize the size of the transmitted data and minimize the cryptographic operations performed by the non-flammable aerosol delivery system 10.
[0126]
[0126] Thus, in this example, a password is generated by generating a string combination of the passkey and the serial number of the non-flammable aerosol delivery system 10. This may be a simple concatenation, or the two data may be interleaved in some manner. Once the string combination is generated, a hash digest is generated by hashing the string combination. The hash may be calculated using any suitable hash algorithm, such as the Secure Hash Algorithm. In this example, the SHA-2 algorithm is used to provide an appropriate balance between security and the processing power required for the non-flammable aerosol delivery system, although other algorithms may be used. In one illustrative example, the SHA256 variant of SHA-2 is used to generate the hash digest.
[0127] To further minimize the amount of data required to transmit a message exchange, the technique applies a string selection rule to output the unlock password. In some examples, the digest may be re-represented in Base64 to facilitate copying, either before or after applying the string selection rule. The string selection rule (which is optional; in some examples, a hash digest may be used as the unlock password) selects a subset of values from the hash digest using predetermined rules known to both the unlock service 26 and the non-flammable aerosol delivery system. In one illustrative example, the unlock passcode includes values obtained from positions in the hash digest that correspond to the first eight digits of the Fibonacci sequence. In other examples, different string selection rules may be used.
[0128]
[0128] In examples where the unlock request includes a challenge generated by the non-flammable aerosol delivery system 10, the combination of the string is based on a combination (such as a concatenation or interleaving) of the Passkey 42 and the challenge response (and optionally the serial number of the non-flammable aerosol delivery system 10). In other examples where the unlock request includes a challenge generated by the non-flammable aerosol delivery system 10, the unlock password is generated by signing and / or encrypting the challenge with the Passkey 42. In examples where a Passkey is used to generate the unlock password by signing data directly, additional techniques may be used to protect the Passkey.
[0129]
[0129] After generating the signed unlock message in step S4-27, the unlock service 26, in step S4-29, sends the unlock password to the user device 18. The user device 18 then receives the unlock password and forwards it to the non-flammable aerosol delivery system 10 in step S4-31.
[0130] In response to receiving the unlock password transmitted by the user device 18 (step S4-33), the aerosol delivery system generates a test password in step S2-35. The test password is generated using the same technique as generating the unlock password, but the input is the device key 40, which in this example is the serial number of the non-flammable aerosol delivery system 10, which is already known to the non-flammable aerosol delivery system 10. In other examples where the non-flammable aerosol delivery system 10 has generated a challenge, the challenge is used as input for generating the test key.
[0131]
[0131] It is therefore understood that if the test password is generated using the same inputs as the unlock password, then they will be identical. Thus, as long as device key 40 and passkey 42 are identical, as well as the other inputs (i.e., in this example, the serial number of non-flammable aerosol delivery system 10, and in other examples, optionally including or being a challenge), the passwords will match, indicating that unlocking should be permitted.
[0132]
[0132] Thus, in step S4-37, the unlock password and the test password are compared to determine whether they match. A match indicates that the unlock password is valid, and strongly indicates that the unlock password was generated by the unlock service 26 in response to an unlock request from the user device 18. Thus, an unlock password validly generated for one aerosol delivery system cannot be reused to unlock a different aerosol delivery system.
[0133]
[0133] Thus, successful verification by the non-flammable aerosol delivery system 10 provides strong indication both that the unlock password was generated by the unlock service 26 (since the non-flammable aerosol delivery system 10 can identify that the unlock password was generated using Passkey 42) and, since the password does not match the test password if it has been altered, that the unlock password has not been tampered with "in-flight" between the unlock service 26 and the non-flammable aerosol delivery system 10. Additionally, if the unlock password and test password are based on a challenge, there is further end-to-end assurance that the challenge message has not been tampered with "in-flight" between the non-flammable aerosol delivery system 10 and the unlock service 26.
[0134]
[0134] In particular, this approach makes it very difficult for a user to unlock the aerosol delivery system without successfully completing an age verification process in which instructions are received that enable generation of an unlock password at unlock service 26. Thus, this approach effectively reduces the opportunities for someone wishing to circumvent the age verification process to successfully gain access to the aerosol delivery system.
[0135] In response to successful authentication of the signed unlock message ("Yes" output of step S4-37), in step S4-41, the non-flammable aerosol delivery system 10 is unlocked. Unlocking the system may include allowing a user to use the system to generate aerosol. For example, the processing circuitry of the non-flammable aerosol delivery system may prevent operation of the system's aerosol generator while the aerosol delivery system is in the locked state.
[0136] Conversely, the non-flammable aerosol delivery system may respond to a failure to authenticate the signed unlock message ("No" output of step S4-37) by preventing unlocking of the aerosol delivery system (step S4-39). For example, if the aerosol delivery system detects that the signed unlock message has been tampered with or not generated by the unlock service 26, the aerosol delivery system may maintain the non-flammable aerosol delivery system 10 in a locked state to prevent access by users who have not successfully verified their age.
[0137] In some examples, the non-flammable aerosol delivery system 10 notifies the user device 18 after unlocking. Similarly, the non-flammable aerosol delivery system 10 may notify the user device 18 in the event of authentication failure (step S4-43). Accordingly, the user device 18 may receive a notification indicating whether authentication was successful and, for example, display corresponding instructions to the user on the user device.
[0138]
[0138] The techniques involved in generating and authenticating unlock passwords are typically less computationally expensive than corresponding techniques in public key cryptography. Therefore, the use of symmetric cryptography in this manner can speed up the secure unlocking of non-flammable aerosol delivery systems and may enable non-flammable aerosol delivery systems with limited processing power to perform the operations required to authenticate the unlock password.
[0139] Of course, there are many possibilities for the form of cryptographic operations and cryptographic keys that can be used in accordance with the techniques described herein. For example, the unlocking service and aerosol delivery system may utilize the Advanced Encryption Standard (AES) or ChaCha encryption to generate and authenticate unlock passwords.
[0140] In some examples, the same secret key is used for multiple (or all) aerosol delivery systems managed by the unlocking service. This can simplify the manufacturing process of the aerosol delivery systems by eliminating the need to provide different device keys for different non-flammable aerosol delivery systems. However, to prevent a valid unlock password for one aerosol delivery system from being used for another aerosol delivery system and to limit the impact of unauthorized access to one aerosol delivery system on other aerosol delivery systems, each non-flammable aerosol delivery system may be provided with a different device, and the unlocking service may have access to multiple pass keys for the aerosol delivery systems. In this example, because key store 32 stores pass keys for many aerosol delivery systems, pass key 64 for the particular aerosol delivery system to be unlocked is selected based on the device identifier for aerosol delivery system 10 received from user device 18 in the unlock request.
[0141]
[0141] In an example where a challenge from a non-flammable aerosol delivery device is utilized in an unlock request, additional protection can be provided against a replay attack where a validly generated unlock password-signed unlock message is used at a later time than intended on an unintended aerosol delivery system or outside the scope for which the message was generated by the unlocking service. By associating the unlock password-signed unlock message with the challenge response message, such an example aerosol delivery device can detect when a valid unlock password-signed unlock message is used outside the intended scope and consequently prevent the aerosol delivery system from being unlocked.
[0142]
[0142] In this way, when using a challenge-based approach, the non-flammable aerosol delivery system can verify not only that the unlock password from the unlocking service was tampered with when sent to the aerosol delivery system, but also that the unlock password corresponds to a challenge response message generated by the system. Thus, even if a user attempts to unlock the aerosol delivery system using an unlock password validly generated by the unlocking service for a different aerosol delivery system that issued a different challenge response message, the aerosol delivery system will not be able to successfully authenticate the unlock password, preventing the non-flammable aerosol delivery system from being unlocked.
[0143]
[0143] When a challenge technique is used for an unlock request, typically a more complex challenge response message may be used to increase the likelihood that the challenge response message will be unique to the non-combustible aerosol delivery device generating the message, the time at which the aerosol delivery device generates the message, or both, thereby reducing the likelihood that another given unlock password will be associated with the matching challenge response message, such that in the case of reuse, the aerosol delivery device will erroneously authenticate the signed unlock message.
[0144]
[0144] On the other hand, by providing a challenge-response message that can be easily generated by a non-flammable aerosol delivery system, the aerosol delivery system may be able to generate challenge-response messages more quickly without requiring more complex processing circuitry, such as dedicated hardware for generating random numbers or maintaining clock synchronization.
[0145]
[0145] The foregoing describes a method for maintaining a non-flammable aerosol delivery system in a locked state that is released (and the unlocked state adopted) only upon request and upon the outcome of an age verification test of a user of the non-flammable aerosol delivery system. This method is secured through the use of symmetric key cryptography (or other shared secret) schemes, such that only devices associated with users who have successfully completed age verification can transition from the locked state to the unlocked state.
[0146]
[0146] With respect to message exchange between the user device 18 and the non-flammable aerosol delivery system, as previously mentioned, the local communication channel 16 can be a suitable personal area network connection for transmission. The local communication channel 16 can further improve communication efficiency by generating an improved profile corresponding to the use of age verification techniques. Thus, message exchange can be achieved with low overhead over the local communication channel, as message headers / wrappers can be minimized if the profile itself carries the relevant information.
[0147]
[0147] In this example where the BLE protocol is used for the local communication channel, the above communication efficiency can also be achieved by using the following profile definitions: ●For sending the unlock password from the user device 18 to the non-flammable aerosol supply system 10 (step S4-31), the profile may describe a message coding (e.g., App Write Passkey) indicating that the app (user device) is writing the password, which may be coded, for example, as [0x00][Passkey]. ●For sending a notification of unlock success or failure from the non-flammable aerosol delivery system 10 to the user device 18 (step S4-43), the profile may describe a message (e.g., Device Notify Unlock Success) indicating that the non-flammable aerosol delivery system is writing an unlock success status, which may be coded, for example, as [0x03][0x00 True||0x01 False]. In instances where a challenge is used, a profile message exchange corresponding to that shown for the asymmetric encryption method above may be used. In instances where the challenge and signed unlock message are base64 encoded, this is the format used for the [Passkey] payload shown above.
[0148]
[0148] Whether asymmetric or symmetric cryptography is used, as described above, the non-flammable aerosol delivery system is unlocked using a cryptographic key stored in the non-flammable aerosol delivery system. Whether all non-flammable aerosol delivery systems are given the same key (e.g., each non-flammable aerosol delivery system has a unique key), this key may be provided during the manufacturing process of the non-flammable aerosol delivery system or in a configuration step after manufacture but before sale. In the context of an example in which each non-flammable aerosol delivery system is configured with a different key, the following example is discussed.
[0149] 5 is a schematic diagram illustrating a first example key establishment technique in which a computing device 50, in communication with a key providing service 54 via connection 56, can establish an encryption key to a non-flammable aerosol delivery system 10 via connection 52. In this example, the non-flammable aerosol delivery system 10 has been provided with the encryption key by a computing device 50, which is in communication with a key providing service 54 via connection 56. In some examples, this includes writing the encryption key to tamper-resistant storage in the non-flammable aerosol delivery system, such as tamper-resistant storage in a trusted platform module (TPM).
[0150]
[0150] As further shown in Figure 5, the key providing service 54 is also in communication with a key storage service 58 via connection 60. Of course, in this example and the examples of Figures 6 to 8, the cryptographic key set in the non-flammable aerosol delivery system 10 may be the public key of an asymmetric key pair, or it may be a private key used in a symmetric cryptography scheme.
[0151] Because the non-flammable aerosol delivery system 10 may have limited connectivity capabilities, the connection 52 in this example is a wireless channel provided using a connectivity technology such as a personal area network protocol. Exemplary personal area network protocols include Bluetooth™, Bluetooth Low Energy (BLE)™, ZigBee™, Wireless USB, and Near Field Communication (NFC). Exemplary personal area network protocols also include protocols that utilize optical communications and data over sound, such as Infrared Data Association (IrDA). The remainder of this discussion will use BLE examples and terminology, but it will be understood that corresponding or equivalent features of other personal area network technologies may be substituted. Other wireless technologies, such as Wi-Fi™ technology, may also be used if the non-flammable aerosol delivery system has suitable capabilities. In other examples, the connection 52 may be a wired communication channel provided between the physical ports of the non-flammable aerosol delivery system 10 and the user device 18. Such wired communication channels may utilize physical connection technologies such as USB™, serial port, Firewire™, or other point-to-point wired connections.
[0152] In this example, the connections 56 and 60 interconnecting the computing device 50, the key providing service 54, and the key storage service 60 are all network connections. As such, each of these connections may include one or more of a local area network, a wide area network, and an Internet connection, which may be provided via wireless and / or wired network infrastructure. The network connections may be protected by techniques such as SSL, tunneling, encryption, signed message exchange, etc., so that keys and other associated data are securely exchanged without opportunity for unauthorized intervention by malicious parties. In other examples, one or both of these connections may be directly wired, such as a serial (e.g., USB™, Firewire™, serial port) or parallel connection. Indeed, in some examples, any two or more of the computing device 50, the key providing service 54, and the key storage service 60 may be separate functions of a single computing system.
[0153]
[0153] Connections 52, 56 and 60 may be non-permanent or transient in the sense that they may be established for the period required to perform a particular function and disconnected when not required.
[0154]
[0154] By allowing the computing device 50 to communicate with the key providing service 54 when keys are written to the non-flammable aerosol delivery system 10, the computing device 50 can receive encryption keys to use as needed. This reduces the need for the computing device 50 to generate its own encryption keys or store a set of pre-generated keys. Also, by providing the key storage service 58 in real time (or near real time) the relationship between the key being written to any given non-flammable aerosol delivery system 10 and its identifier (e.g., device identifier), the need for local storage of relationship information on the computing device 50 is reduced.
[0155] FIG. 6 is a schematic diagram illustrating a second exemplary manner in which a computing device can set cryptographic keys for a non-combustible aerosol delivery system. This manner is similar to that shown in FIG. 5, except that computing device 50 operates “offline” with respect to the key provision service and key storage service (as indicated by outline 66). Thus, in this example, computing device 50 operates without a data connection to key provision service 54. This ensures the security of the cryptographic keys, since the confidentiality of these keys is fundamental to the integrity of communications with non-combustible aerosol delivery system 10. Thus, computing device 50 sets cryptographic keys for the non-combustible aerosol delivery system using keys already available to the computing device. In some examples, this includes writing the cryptographic keys to tamper-resistant storage in the non-combustible aerosol delivery system, such as tamper-resistant storage in a Trusted Platform Module (TPM).
[0156]
[0156] In this example, via connection 54, computing device 60 can access storage 64, which stores pre-generated keys previously generated by key providing service 54, and which may also store an association between an assigned encryption key and a device identifier of the non-flammable aerosol delivery system to which the encryption key is assigned. Storage 60 may be physically removed and securely moved to and from computing device 50 to transfer unassigned keys to computing device 50 and to transfer the association between keys and device identifiers assigned between computing devices 50 to key storage service 58. Thus, connection 64 in this example is a secure direct connection between computing device 50 and storage 62. This secure direct connection may include directly connecting the storage to a data bus of computing device 50 (e.g., via an eSATA™ port), directly connecting the storage to a data port of computing device 50 (e.g., via a USB™ or Firewire™ port), or connecting the storage to a local area network of computing devices (e.g., in the form of a NAS or SAN volume) and securing connectivity via the local area network. Other connection techniques (such as wireless data connections) may also be employed as deemed suitably secure in any particular implementation.
[0157] In another example, the connection between computing device 50 and key provisioning service 54 may be activated intermittently to allow for the placement of more keys in storage 62 and / or the batch or burst recording of key / device ID relationships from storage 62. This approach may be used, for example, to enhance security by avoiding long periods of open connection 56 and / or to facilitate the provision of keys to and receipt of associated information for computing device 50 while computing device 50 is physically removed from the configuration or location of the non-flammable aerosol delivery device and moved to a location considered more secure for data connectivity. Thus, the computing system may be “referenced” to the key provisioning service for key / relationship transfer before or after use in placing keys in the non-flammable aerosol delivery device.
[0158] 5 and 6, when computing device 50 establishes a cryptographic key for a non-flammable aerosol delivery system, it receives a device identifier for the non-flammable aerosol delivery system to which the key is to be assigned. The device identifier (e.g., a serial number or other suitable identifier) may be received from the non-flammable aerosol delivery system itself, or from another device involved in the manufacturing process (e.g., a second computing device that assigns and stores the device identifier).
[0159]
[0159] The computing device that configures the cryptographic key for the aerosol delivery system obtains the specific cryptographic key for the non-flammable aerosol delivery system based on one or more cryptographic keys provided by a key providing service. The key providing service itself provides a secure means for generating and providing a unique key to the computing device for configuration into the aerosol delivery system. The cryptographic key provided by the key providing service may be generated, for example, according to standard techniques for generating unique keys. The cryptographic key received from the key providing service may be a device key in the form of a private key for use in a symmetric cryptography system or a public key of a public-private key pair for use in a public key cryptography system. As noted with respect to the discussion of Figures 5 and 6 above, provisioning of the key to the computing device may occur via a live connection to the key providing service or via an offline configuration that allows for key storage (caching) on the computing system.
[0160]
[0160] The computing device stores the device identifier and the particular encryption key in association with each other so that the encryption key for the aerosol delivery system can later be determined from the device identifier (e.g., for use in unlocking the non-flammable aerosol delivery system). By referencing the stored association between the device identifier and the particular encryption key, the particular encryption key to be used can be later determined based on the device identifier. As noted above with respect to the discussion of Figures 5 and 6, the association can be provided to the key storage service via a live connection between the key provision service and the computing device, or via an offline setting that allows for the association to be stored (cached) in the computing system.
[0161]
[0161] The above describes an exemplary infrastructure for both offline and online setting of cryptographic keys for non-combustible aerosol delivery devices, which allows the non-combustible aerosol delivery device to later use the cryptographic key to more secure the age verification process for unlocking the non-combustible aerosol delivery device.
[0162]
[0162] In the following, with reference to Figures 7 and 8, exemplary methods for establishing keys according to the two exemplary architectures will be described.
[0163]
[0163] Figure 7 is a flow diagram illustrating a method for establishing a cryptographic key for a non-flammable aerosol delivery system 10 using a computing device 50 in communication with a key provision service 54.
[0164] In step S7-1, computing device 50 receives a device identifier for non-flammable aerosol delivery system 10. In this example, the device identifier is received from non-flammable aerosol delivery system 10 itself, but in other examples, the device identifier may be received from another computing device involved in the process of creating non-flammable aerosol delivery system 10.
[0165]
[0165] In response to receiving the device identifier, computing device 50, at step S7-3, sends a request for a new encryption key to key provision service 54. The request indicates the device identifier of the non-flammable aerosol delivery system 10 for which the key is to be established.
[0166]
[0166] The key providing service 54 receives this request in step S7-5. In response to the request, the key providing service 54 provides the computing device 50 with an encryption key to be assigned to the non-flammable aerosol delivery system 10 (step S7-7). The encryption key may have been generated by the key providing service 54 by any suitable means, or the key providing service 54 may itself have received the encryption key from a separate key generation service or may have retrieved a pre-generated key from a key storage service.
[0167] In response to receiving the encryption key from key providing service 54 at step S7-9, computing device 50 writes the encryption key to non-flammable aerosol delivery system 10 at step S7-11. The encryption key may be written to tamper-proof storage of non-flammable aerosol delivery system, for example, so that it cannot be modified once written. In this manner, non-flammable aerosol delivery system 10 is permanently assigned the encryption key.
[0168]
[0168] Also, in step S7-13, the key providing service 54 stores the device identifier of the non-flammable aerosol delivery system in association with the encryption key in the key storage service 58. In this manner, by sending a request by the computing device 50, the device identifier is stored in association with the encryption key.
[0169]
[0169] The above describes an optional exemplary method for online setting of a cryptographic key for a non-combustible aerosol delivery device, which allows the non-combustible aerosol delivery device to later use the cryptographic key to more secure the age verification process for unlocking the non-combustible aerosol delivery device.
[0170]
[0170] Figure 8 is a flow diagram illustrating a method for establishing a cryptographic key in a non-flammable aerosol delivery system 10 using an offline computing device 50 that operates without a data connection to a key providing service 54.
[0171]
[0171] As shown in step S8-1, multiple encryption keys may initially be set in secure storage 62 accessible to computing device 50 from key providing service 54. However, after the keys are transferred, when the keys are set in the non-flammable aerosol delivery device, offline computing device 50 and key providing service 54 are not connected.
[0172]
[0172] Thus, to set an encryption key in non-flammable aerosol delivery system 10, computing device 50 first receives, in step S8-3, the device identifier for non-flammable aerosol delivery system 110, whereupon the computing device selects (in step S8-5) an encryption key from among the unassigned encryption keys stored in storage 62. This key can then be written to the non-flammable aerosol delivery system in step S8-7 by any suitable technique, including by writing the key in a manner that makes it unmodifiable once written to the device.
[0173]
[0173] Then, in step S8-9, computing device 50 stores the encryption key written to non-flammable aerosol delivery system 10 in association with the device identifier of non-flammable aerosol delivery system 10. Thus, in this example, computing device 50 stores the association between the encryption key and the device identifier in secure storage 62, thereby storing the association.
[0174]
[0174] Steps S8-3 through S8-9 may be repeated multiple times using the multiple encryption keys provided in step S8-1, without requiring communication between the computing device 50 and the key providing service 54. When all of the encryption keys provided to the computing device 50 have been assigned, or if it is desired to move the stored keys and device identifiers to the key storage service 54, a data transfer may be performed as described above. In this example, the storage 62 is removed from the computing device 50 and physically moved to the key storage service 54. In other examples, the computing device may be physically removed and moved to a key / relationship transfer location, and / or a data connection may be temporarily established between the computing device and the key providing service.
[0175]
[0175] In this way, by securely providing the encryption key to the non-flammable aerosol delivery system 10, the risk of the key being subject to unauthorized access during the key writing process can be reduced.
[0176]
[0176] The above describes an optional exemplary method for offline setting of a cryptographic key for a non-combustible aerosol delivery device, which allows the non-combustible aerosol delivery device to later use the cryptographic key to more secure the age verification process for unlocking the non-combustible aerosol delivery device.
[0177]
[0177] Keys stored in the key storage service 58 by any of the methods discussed with reference to Figures 7 and 8 may then be made available to the unlocking service 26 described above for various techniques to perform unlocking using the age verification and cryptographic certainty described with reference to Figures 1-4 above. In some examples, the key storage service 58 may be the same as the key store 30, and in other examples, the key storage service 58 may generate keys and relationships available for retention in the key store 30.
[0178] In some instances, a new cryptographic key may be written into the non-combustible aerosol delivery system 10, either to replace or complement a previously written key. To accomplish this, the same methodology as described with respect to FIG. 7 or FIG. 8 may be used, but this may occur after use rather than during manufacture / pre-sale. Such a method may be performed to re-establish the cryptographic security employed in the age verification method if one or more specific keys (e.g., a symmetric key or the private key of an asymmetric key pair) are compromised. Alternatively, a transition from a symmetric to an asymmetric encryption method (or vice versa) may be required for the non-combustible aerosol delivery device. In such instances, a software or firmware update for the non-combustible aerosol delivery system may reflect the revised method to secure the age verification method.
[0179]
[0179] In instances where the same key is configured for multiple non-flammable aerosol delivery systems, the techniques of the above teachings are still applicable, but the number of devices to which each key is configured increases and the key relationships are updated accordingly. If all non-flammable aerosol delivery systems are provided with the same key, storing key relationship data is optional.
[0180]
[0180] It will be appreciated that this approach involves transmitting and receiving data to and from the non-flammable aerosol delivery system, and processing of stored and / or received data by the non-flammable aerosol delivery system. Portions of this approach also require that the user device be able to communicate with the non-flammable aerosol delivery system and other services or systems. Accordingly, to illustrate suitable devices for providing such functionality, an exemplary non-flammable aerosol delivery system 10 and an exemplary user device 16 are shown in Figures 9 and 10, respectively.
[0181]
[0181] FIG. 9 schematically illustrates an example of a non-flammable aerosol delivery system 10. As illustrated, the aerosol delivery device 10 includes elements related to aerosol generation, such as an aerosol medium container or cartridge 70 (in the case of an END device, the aerosol medium container or cartridge 70 will contain nicotine or a nicotine-containing formulation), an aerosol generation chamber 71, and an outlet 72 through which the generated aerosol can be released. A battery 73 may be provided to power a heat-generating element (such as a heating coil 74) within the aerosol generation chamber 71. The battery 73 may also power a processor / controller 75, which may serve device usage purposes, such as activating the device to generate aerosol in response to an activation trigger, as well as communication and functional control purposes. The processor / controller 75 may have access to memory 76, in which cryptographic keys may be stored. Thus, the memory 76 may be or include secure storage, such as a trusted platform module. The memory 76 may be internal to the processor / controller or may be provided as a separate, additional physical element. To perform the transmission and reception of data and / or messages, the processor / controller is provided with a transmit / receive element 77, which in this example is a BLE interface element including a radio antenna for wireless communication, although in other examples this may be an interface element for alternative personal area network technologies and / or a wired connection interface, as previously mentioned.
[0182] In one example, the processor / controller 75 may be an STM32 microcontroller provided by ST Microelectronics and based on the ARM™ Cortex™-M processor. In other examples, alternative microcontrollers or processors may be used, such as those based on the ARM™ and Atom™ architectures or other low-power processor technologies. In one example, alternatively or additionally, the transceiver element 77 may include an nRF BLE chip that cooperates with the processor / controller to provide BLE connectivity to the non-flammable aerosol delivery system. In other examples, other communication interface chips or modules may be deployed to provide connectivity services.
[0183] As shown, processor 75 may be connected, for example, to aerosol medium container or cartridge 70, aerosol generation chamber 71, and battery 73. This connection may be to an interface connection or to an output of one of the components and / or to a sensor located on or within one of the components. These connections may allow the processor access to the characteristics of each component. For example, the battery connection may be used to control whether the non-flammable aerosol delivery system can be activated for aerosol generation according to a lock / unlock status stored in processor 75 or memory 77.
[0184] Processor / controller 75 may also generate random numbers using a random number generator in the non-flammable aerosol delivery system, a random number generator of the processor / controller, and / or software / firmware routines for random number generation. Processor / controller 75 may also generate a challenge (such as corresponding to steps S2-11 or S4-11) in response to receiving a challenge request via transceiver element 77. Such a challenge may include a random number and / or a data string stored in memory 77 or may be provided in response to receiving a challenge request.
[0185] Processor / controller 75 may also perform cryptographic or other calculations corresponding to confirming age verification (such as by authenticating a signed unlock message corresponding to step S2-35 or generating a test password corresponding to step S4-35). Processor / controller 75 may also control non-flammable aerosol delivery system 10 to be in one of a locked state (in which activation of aerosol generation is not permitted) and an unlocked state (in which activation of aerosol generation is permitted). Such control between the locked and unlocked states may depend on the outcome of an age verification process such as that described above with reference to FIGS. 2 and 4.
[0186]
[0186] The processor / controller 75 and / or memory 77 can also accept the writing of encryption keys, which may be provided by the key establishment method as described above with reference to Figures 7 and 8.
[0187]
[0187] The various functions of the processor / controller 75 described above may be provided by software stored in memory 77 and / or firmware instructions written into the processor / controller 75.
[0188]
[0188] Thus, the non-flammable aerosol delivery system 10 of the present example is operable in accordance with any and all infrastructure and / or methods described above with reference to any of Figures 1-8.
[0189] 10 is a schematic diagram of an example of a user device 18. As previously mentioned, the user device may be a device such as a mobile phone or a tablet. The user device may also be a device such as a portable computer, a laptop computer, or a netbook. As shown, the user device 18 includes a transmitting / receiving element 80 for communicating with the non-flammable aerosol delivery system 10. To this end, the transmitting / receiving element 80 is configured to use the same connections, protocols, etc. as the non-flammable aerosol delivery system with which it will interact in any given embodiment.
[0190] The transmitting / receiving element 80 is connected to a processor or controller 81 that may receive and process data or messages from the non-flammable aerosol delivery system. The processor or controller 81 has access to a memory 82 that may be used to store program information and / or data. The user device 18 may also include a separate data transmission interface 83. This interface may provide one or more interface functions for a wired connection, such as a wired local area network, and / or a wireless connection, such as a wireless local area network and / or a cellular data service. This interface may be used to transmit and receive messages to, for example, the unlock service 22 and / or the unlock service 26. The user device 18 may also include user interface elements, such as an output device 84 (which may include one or more of a display, an audio output, and a tactile output) and / or an input device 85 (which may include one or more of buttons, keys, a touch-sensitive display element, or a mouse / trackpad).
[0191]
[0191] The user device 18 may be pre-programmed or configured to provide the functionality discussed with reference to the infrastructure shown in Figures 1 and 3 and / or the methods shown in Figures 2 and 4. Additionally or alternatively, the user device may store software (e.g., in memory 82) such as an app that, when executed, causes the processor or controller 81 to perform these functions. Thus, the user device may be a multi-purpose device that has the functionality described above when the app is executed.
[0192]
[0192] Also, as noted above, the techniques described herein may be embodied in or encoded on a computer-readable medium containing instructions, such as a computer-readable storage medium. The instructions embedded or encoded on the computer-readable medium, when executed, may cause a programmable processor or other processor to perform the methods described above. Computer-readable media may include non-transitory computer-readable storage media and transient communication media, such as carrier signals and transmission media. Computer-readable storage media may include random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, hard disk, CD-ROM, floppy disk, cassette, magnetic medium, optical medium, or other computer-readable storage medium. The term "computer-readable storage medium" refers to a physical storage medium. A transitory communication medium may exist between components of a single computer system (e.g., on an internal link or bus between memory and a processor) or between separate computer systems (e.g., via a network or other connection between computer devices), and may include transmission signals, carrier waves, etc.
[0193]
[0193] In this application, the word "configured to..." is used to mean that elements of a device have a configuration that can perform a specified operation. In this context, "configuration" refers to the arrangement or manner of interconnection of hardware or software. For example, the device may have dedicated hardware that provides the specified operation, or a processor or other processing device may be programmed to perform this function. "Configured to" does not imply that device elements must be arbitrarily modified to provide the specified operation.
[0194]
[0194] The various embodiments described herein are presented solely as an aid in understanding and teaching the features of the claims. These embodiments are provided as a representative sample of embodiments and are not intended to be exhaustive and / or exclusive. The advantages, embodiments, examples, functions, features, structures, and / or other aspects described herein should not be construed as limitations on the scope of the invention as defined by the claims or limitations on the equivalents of the claims, and it is understood that other embodiments may be utilized and improved without departing from the scope of the claimed invention. The various embodiments of the present invention may suitably include, consist of, or essentially consist of any suitable combination of the disclosed elements, components, features, parts, steps, means, etc., other than those specifically described herein. The present disclosure may also include other inventions not currently claimed but which may be claimed in the future. [Provisions] [Article 1] 1. A method for unlocking a non-flammable aerosol delivery system, comprising: receiving an indication from an age verification service that the age verification process for the non-flammable aerosol delivery system has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving from the unlock service an unlock password based on a passkey accessible to the unlock service; transmitting and authenticating the unlock password to the non-flammable aerosol delivery system to determine whether the passkey matches a device key of the non-flammable aerosol delivery system; A method comprising: [Clause 2] the unlock request includes a device identifier for the non-flammable aerosol delivery system; 2. The method of claim 1, wherein the passkey is a specific passkey for the non-flammable aerosol delivery system selected from a plurality of passkeys accessible to the unlocking service based on the device identifier. [Article 3] In response to receiving the instruction from an age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; further comprising the step of sending the unlock request to the unlock service includes sending an unlock request including the challenge response message; The method of any one of clauses 1 to 2, wherein the unlock password received from the unlock service provides a cryptographic relationship between the passkey and the challenge response message that can be authenticated by the non-flammable aerosol delivery system. [Article 4] 4. The method of clause 3, wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system. [Article 5] 5. The method of any one of clauses 1 to 4, wherein the unlock password received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed. [Article 6] The method of any one of clauses 1 to 5, wherein the step of unlocking the non-flammable aerosol delivery system includes allowing use of the non-flammable aerosol delivery system for generating aerosol to be delivered to a user. [Article 7] 7. The method according to any one of clauses 1 to 6, wherein the user device executing the method communicates with the unlocking service via a program interface. [Article 8] The method according to any one of clauses 1 to 7, wherein the unlocking service is configured on a remote server. [Article 9] 1. A device for unlocking a non-flammable aerosol delivery system, comprising: receiving an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving from the unlock service an unlock password based on a passkey accessible to the unlock service; transmitting the unlock password to the non-flammable aerosol delivery system and authenticating the unlock password to determine whether the passkey matches a device key of the non-flammable aerosol delivery system; A device comprising: a processing circuit configured to perform [Article 10] the unlock request includes a device identifier for the non-flammable aerosol delivery system; The device described in clause 9, wherein the passkey is a specific passkey for the non-flammable aerosol delivery system selected from a plurality of passkeys accessible to the unlocking service based on the device identifier. [Article 11] In response to receiving the instruction from an age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; further configured to: the device is configured to send an unlock request including the challenge response message to send the unlock request to the unlock service; A device as described in clause 9 or 10, wherein the unlock password received from the unlock service provides a cryptographic relationship between the passkey and the challenge response message that can be authenticated by the non-flammable aerosol delivery system. [Article 12] 12. The device described in clause 11, wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system. [Article 13] 13. The device of any one of clauses 9 to 12, wherein the unlock password received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed. [Article 14] 14. The device of any one of clauses 9 to 13, wherein unlocking the non-flammable aerosol delivery system includes permitting use of the non-flammable aerosol delivery system for generating an aerosol to be delivered to a user. [Article 15] A device according to any one of clauses 9 to 14, configured to communicate with the unlocking service via a program interface. [Article 16] The device according to any one of clauses 9 to 15, wherein the unlocking service is configured on a remote server. [Article 17] When executed by a computing device, receiving an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving from the unlock service an unlock password based on a passkey accessible to the unlock service; transmitting the unlock password to the non-flammable aerosol delivery system and authenticating the unlock password to determine whether the passkey matches a device key of the non-flammable aerosol delivery system; A computer-readable medium containing instructions that cause the computing device to perform the steps of: [Article 18] the unlock request includes a device identifier for the non-flammable aerosol delivery system; 18. The computer-readable medium of clause 17, wherein the passkey is a specific passkey for the non-flammable aerosol delivery system selected from a plurality of passkeys accessible to the unlocking service based on the device identifier. [Article 19] The instructions, when executed by the computing device, In response to receiving the instruction from an age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; and further causing the computing device to perform transmitting the unlock request to the unlock service, the computer device transmitting the unlock request including the challenge response message; The computer-readable medium of clause 17 or 18, wherein the unlock password received from the unlock service provides a cryptographic relationship between the passkey and the challenge response message that can be authenticated by the non-flammable aerosol delivery system. [Article 20] 20. The computer-readable medium of clause 19, wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system. [Article 21] 21. The computer-readable medium of any one of clauses 17-20, wherein the unlock password received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed. [Article 22] 22. The computer-readable medium of any one of clauses 17-21, wherein unlocking the non-flammable aerosol delivery system includes permitting use of the non-flammable aerosol delivery system for generating aerosol to be delivered to a user. [Article 23] 23. The computer-readable medium of any one of clauses 17 to 22, wherein the device is configured to communicate with the unlocking service via a program interface. [Article 24] 24. The computer-readable medium of any one of clauses 17 to 23, wherein the unlocking service is configured on a remote server. [Article 25] 1. A method for unlocking a non-flammable aerosol delivery system, comprising: receiving, from a user device, an unlock password based on a passkey at the non-flammable aerosol delivery system; generating a test password based on a device key stored in the non-flammable aerosol delivery system; comparing the test password and the unlock password to determine whether the device key matches the passkey on which the unlock password is based; unlocking the non-flammable aerosol delivery system in response to detecting a match in the comparison; A method comprising: [Article 26] generating the test password, combining at least a portion of the device key with at least a portion of a device identifier of the non-flammable aerosol delivery system to generate a test string; hashing the test string; 26. The method of claim 25, comprising: [Article 27] 27. The method of clause 26, wherein generating the test password includes generating the test password by extracting a predetermined set of bits from the test string. [Article 28] receiving a challenge request message from the user device; generating a challenge response message; sending the challenge response message to the user device; further comprising the unlock password provides a cryptographic association between a given challenge response message and the passkey; generating the test password includes generating the test password based on the challenge response message; The method of any one of clauses 25 to 27, wherein the step of comparing the test password and the unlock password further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Article 29] 29. The method of clause 28, wherein the step of generating a challenge response message includes selecting a random number and generating the challenge response message in response to the selected random number. [Article 30] 1. A non-flammable aerosol delivery system comprising: receiving an unlock password from the user device based on the passkey; generating a test password based on a device key stored in the non-flammable aerosol delivery system; comparing the test password and the unlock password to determine whether the device key matches the passkey on which the unlock password is based; unlocking the non-flammable aerosol delivery system in response to detecting a match of the comparison; A non-flammable aerosol delivery system comprising a processing circuit configured to: [Article 31] To generate the test password, the processing circuitry: combining at least a portion of the device key with at least a portion of a device identifier of the non-flammable aerosol delivery system to generate a test string; hashing the test string; 31. The non-flammable aerosol delivery system of claim 30, configured to: [Article 32] 32. The non-flammable aerosol delivery system of claim 31, wherein the processing circuitry is further configured to generate the test password by extracting a predetermined set of bits from the test string. [Article 33] the processing circuitry receiving a challenge request message from the user device; generating a challenge response message; sending the challenge response message to the user device; further configured to: the unlock password provides a cryptographic association between a given challenge response message and the passkey; to generate the test password, the processing circuitry is configured to generate the test password based on the challenge response message; A non-flammable aerosol delivery system as described in any one of clauses 30 to 32, wherein comparing the test password and the unlock password further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Article 34] Clause 34. The non-flammable aerosol delivery system of clause 33, wherein the processing circuit is configured to select a random number and generate the challenge response message in accordance with the selected random number to generate the challenge response message. [Article 35] When implemented by a processing circuit of a non-flammable aerosol delivery system, receiving an unlock password from the user device based on the passkey; generating a test password based on a device key stored in the non-flammable aerosol delivery system; comparing the test password and the unlock password to determine whether the device key matches the passkey on which the unlock password is based; unlocking the non-flammable aerosol delivery system in response to detecting a match of the comparison; a computer-readable medium comprising instructions for causing the non-flammable aerosol delivery system to: [Article 36] To generate the test password, the non-flammable aerosol delivery system: combining at least a portion of the device key with at least a portion of a device identifier of the non-flammable aerosol delivery system to generate a test string; hashing the test string; 36. The computer-readable medium of claim 35, [Article 37] 37. The computer-readable medium of clause 36, wherein the non-flammable aerosol delivery system generates the test password by extracting a predetermined set of bits from the test string to generate the test password. [Article 38] The instructions, when executed by the processing circuitry, receiving a challenge request message from the user device; generating a challenge response message; sending the challenge response message to the user device; to the non-flammable aerosol delivery system, the unlock password provides a cryptographic association between a given challenge response message and the passkey; generating the test password based on the challenge-response message; A computer-readable medium as described in any one of clauses 35 to 37, wherein comparing the test password and the unlock password further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Article 39] 39. The computer-readable medium of clause 38, wherein to generate the challenge response message, the processing circuitry is configured to select a random number and generate the challenge response message in response to the selected random number. [Article 40] 1. A method for unlocking a non-flammable aerosol delivery system, comprising: receiving, by a user device, an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; sending, by the user device, a request to unlock the non-flammable aerosol delivery system to an unlock service; generating, by the unlocking service, an unlocking password based on a passkey accessible to the unlocking service; transmitting, by the unlock service, the unlock password to the user device; transmitting, by the user device, the unlock password to the non-flammable aerosol delivery system; generating, by the non-flammable aerosol dispensing system, a test password based on a device key stored in the non-flammable aerosol dispensing system; comparing the test password and the unlock password to determine whether the device key matches the passkey on which the unlock password is based; unlocking the non-flammable aerosol delivery system in response to detecting a match in the comparison; A method comprising: [Article 41] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; The method of claim 40, wherein the step of generating the unlock password by the unlock service includes selecting a specific passkey for the non-flammable aerosol delivery system selected from a plurality of passkeys accessible to the unlock service based on the device identifier. [Article 42] transmitting, by the user device, a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from an age verification service; generating a challenge-response message by the non-flammable aerosol delivery system; transmitting the challenge response message to the user device by the non-flammable aerosol delivery system; further comprising the step of sending the unlock request to the unlock service includes sending an unlock request including the challenge response message; generating the unlock password by the unlock service includes providing a cryptographic association between the passkey and a given challenge response message; generating the test password by the non-flammable aerosol delivery system includes generating the test password based on the challenge response message; The method of any one of clauses 40 to 41, wherein the step of comparing the test password and the unlock password further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Article 43] and verifying, by the unlocking service in response to the unlocking request, that the age verification process of the non-flammable aerosol delivery system has been successfully completed; 43. The method of any one of clauses 40 to 42, wherein the step of generating the unlock password by the unlock service is in response to successful verification that the age verification process has been successfully completed. [Article 44] generating the unlock password by the unlock service includes combining at least a portion of the passkey with at least a portion of the device identifier to generate a passstring; and hashing the passstring; The method of clause 41, wherein the step of generating the test password by the non-flammable aerosol delivery system includes combining at least a portion of the device key with at least a portion of the device identifier of the non-flammable aerosol delivery system to generate a test string, and hashing the test string. [Article 45] the step of generating the unlock password further comprises generating the unlock password by extracting a predetermined set of bits from the pass-string; Clause 45. The method of clause 44, wherein generating the test password includes generating the test password by extracting the predetermined set of bits from the test string. [Article 46] a non-flammable aerosol delivery system; a remote device; Unlocking service and A system comprising: the remote device is configured to receive an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed, and to send a request to unlock the non-flammable aerosol delivery system to the unlock service; the unlock service is configured to generate an unlock password based on a passkey accessible to the unlock service and transmit the unlock password to the remote device; the remote device is further configured to transmit the unlock password to the non-flammable aerosol delivery system; The non-flammable aerosol delivery system is configured to generate a test password based on a device key stored in the non-flammable aerosol delivery system, compare the test password and the unlock password to determine whether the device key matches the pass key on which the unlock password is based, and unlock the non-flammable aerosol delivery system in response to detecting a match in the comparison. [Article 47] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; The system described in clause 46, wherein to generate the unlock password, the unlock service is configured to select a specific passkey for the non-flammable aerosol delivery system from a plurality of passkeys accessible to the unlock service based on the device identifier. [Article 48] the user device is configured to send a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from an age verification service; the non-flammable aerosol delivery system is configured to generate a challenge-response message; the non-flammable aerosol delivery system configured to transmit the challenge response message to the user device; the user device is configured to send an unlock request including the challenge response message to the unlock service; the unlocking service is configured to provide a cryptographic association between the passkey and a given challenge response message to generate the unlocking password; to generate the test password, the non-flammable aerosol delivery system is configured to generate the test password based on the challenge-response message; The system described in clause 46 or 47, wherein comparing the test password and the unlock password further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Article 49] the unlocking service is configured to, in response to the unlocking request, verify with the age verification process that the age verification process of the non-flammable aerosol delivery system has been successfully completed; 49. The system of any one of clauses 46 to 48, wherein the unlock service generates the unlock password in response to successful verification that the age verification process has been successfully completed. [Article 50] to generate the unlock password, the unlock service is configured to combine at least a portion of the passkey with at least a portion of the device identifier to generate a passstring, and hash the passstring; The system described in Clause 41, wherein to generate the test password, the non-flammable aerosol delivery system is configured to combine at least a portion of the device key with at least a portion of the device identifier of the non-flammable aerosol delivery system to generate a test string, and hash the test string. [Article 51] to generate the unlock password, the unlock service is configured to generate the unlock password by extracting a predetermined set of bits from the pass string; The system described in clause 50, wherein to generate the test password, the non-flammable aerosol delivery system is configured to generate the test password by extracting the predetermined set of bits from the test string. [Article 52] When implemented by the processing circuitry of the non-flammable aerosol delivery system, the user device, and the unlock service, receiving, by the user device, an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; transmitting, by the user device, a request to unlock the non-flammable aerosol delivery system to an unlock service; generating, by the unlock service, an unlock password based on a passkey accessible to the unlock service; transmitting, by the unlock service, the unlock password to the user device; transmitting, by the user device, the unlock password to the non-flammable aerosol delivery system; generating, by the non-flammable aerosol dispensing system, a test password based on a device key stored in the non-flammable aerosol dispensing system; comparing the test password and the unlock password to determine whether the device key matches the passkey on which the unlock password is based; unlocking the non-flammable aerosol delivery system in response to detecting a match of the comparison; A computer-readable medium containing instructions that cause the processing circuit to perform the steps of: [Article 53] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; The computer-readable medium of clause 52, wherein to generate the unlock password, the unlock service selects a specific passkey for the non-flammable aerosol delivery system from a plurality of passkeys accessible to the unlock service based on the device identifier. [Article 54] The instruction: transmitting, by the user device, a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from an age verification service; generating a challenge response message from the non-flammable aerosol delivery system; the non-flammable aerosol delivery system transmitting the challenge response message to the user device; Further, the user device sending an unlock request including the challenge response message to send the unlock request to the unlock service; the unlocking service providing a cryptographic relationship between the passkey and a given challenge response message to generate the unlocking password; generating the test password based on the challenge-response message; The computer-readable medium of clause 52 or 53, wherein comparing the test password and the unlock password further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Article 55] The instruction: the unlocking service, in response to the unlocking request, verifying through an age verification process that the age verification process of the non-flammable aerosol delivery system has been successfully completed; generating, by the unlock service, the unlock password in response to successful verification that the age verification process has been successfully completed; 55. The computer-readable medium of any one of clauses 52 to 54, further comprising: [Article 56] to generate the unlock password, the unlock service combines at least a portion of the passkey with at least a portion of the device identifier to generate a passstring, and hashes the passstring; The computer-readable medium of clause 41, wherein to generate the test password, the non-flammable aerosol delivery system combines at least a portion of the device key with at least a portion of the device identifier of the non-flammable aerosol delivery system to generate a test string, and hashes the test string. [Article 57] to generate the unlock password, the unlock service extracts a predetermined set of bits from the pass string to generate the unlock password; 57. The computer-readable medium of clause 56, wherein the non-flammable aerosol delivery system generates the test password by extracting the predetermined set of bits from the test string to generate the test password. [Article 58] 1. A method for establishing a cryptographic key in a non-flammable aerosol delivery system, comprising: receiving a device identifier for the non-flammable aerosol delivery system; Obtaining a specific encryption key for the non-flammable aerosol delivery system based on one or more encryption keys provided by a key generation service; storing the device identifier in association with the particular encryption key; writing the unique encryption key to the non-flammable aerosol delivery system; A method comprising: [Article 59] The step of obtaining the specific encryption key to be set in the non-flammable aerosol delivery system includes: sending a request to the key generation service including the device identifier; receiving the particular key from the key providing service; Including, 59. The method of clause 58, wherein the device identifier is stored in association with the particular encryption key by the key providing service by sending the request to the key generation service. [Article 60] obtaining the specific encryption key to be set in the non-flammable aerosol delivery system includes selecting the specific encryption key from a plurality of encryption keys provided by the key providing service and stored on an offline device; 59. The method of clause 58, wherein storing the device identifier in association with the particular cryptographic key comprises storing the particular key in association with the device identifier for subsequent transfer to a key storage service. [Article 61] 61. The method of clause 60, wherein the method is performed by a device operating without a data connection to the key provision service. [Article 62] 62. The method of any one of clauses 58 to 61, wherein the particular cryptographic key is a key for a symmetric encryption algorithm. [Article 63] 63. The method of clause 62, further comprising providing the key to an unlocking service and storing it in association with the device identifier. [Article 64] 64. The method of any one of clauses 62 and 63, wherein the step of writing the specific cryptographic key to the non-flammable aerosol delivery system includes securely storing the key in the non-flammable aerosol delivery system. [Article 65] 1. A system for establishing a cryptographic key for a non-flammable aerosol delivery system, comprising: the non-flammable aerosol delivery system; receiving a device identifier for the non-flammable aerosol delivery system; Obtaining a specific encryption key for the non-flammable aerosol delivery system based on one or more encryption keys provided by a key generation service; storing the device identifier in association with the particular encryption key; writing the specific encryption key to the non-flammable aerosol delivery system; a computing device configured to perform A system comprising: [Article 66] the computing device: sending a request to the key generation service including the device identifier; receiving the particular key from the key providing service; The specific encryption key to be set in the non-flammable aerosol delivery system is obtained by 66. The system of clause 65, wherein the key providing service stores the device identifier in association with the particular encryption key by sending the request to the key generation service. [Article 67] the computing device: obtaining the specific encryption key to be set in the non-flammable aerosol delivery system by selecting the specific encryption key from a plurality of encryption keys provided by the key providing service and stored in an offline device; storing the device identifier in association with the particular encryption key by storing the particular key in association with the device identifier for subsequent transfer to a key storage service; 66. The system of claim 65, configured to: [Article 68] 68. The system of clause 67, wherein the computing device is configured to operate without a data connection to the key provision service. [Article 69] 69. The system of any one of clauses 65 to 68, wherein the particular cryptographic key is a key for a symmetric encryption algorithm. [Article 70] 70. The system of clause 69, wherein the computing device is further configured to provide the key to an unlocking service and store it in association with the device identifier. [Article 71] 71. The system of claim 69 or 70, wherein writing the specific encryption key to the non-flammable aerosol delivery system includes securely storing the key in the non-flammable aerosol delivery system. [Article 72] When executed by the processing circuitry of a computing device, receiving a device identifier for the non-flammable aerosol delivery system; Obtaining a specific encryption key for the non-flammable aerosol delivery system based on one or more encryption keys provided by a key generation service; storing the device identifier in association with the particular encryption key; writing the specific encryption key to the non-flammable aerosol delivery system; A computer-readable medium containing instructions that cause the computing device to perform the steps of: [Article 73] The instructions, when executed by the processing circuitry, sending a request to the key generation service including the device identifier; receiving the particular encryption key from the key providing service; causing the computer device to obtain the specific encryption key to be set in the non-flammable aerosol delivery system by 73. The computer-readable medium of clause 72, wherein the device identifier is stored in association with the particular encryption key by the key-providing service by sending the request to the key-generation service. [Article 74] The instructions, when executed by the processing circuitry, obtaining the specific encryption key to be set in the non-flammable aerosol delivery system by selecting the specific encryption key from a plurality of encryption keys provided by the key providing service and stored in an offline device; storing the device identifier in association with the particular encryption key by storing the particular encryption key in association with the device identifier for subsequent transfer to a key storage service; 73. The computer-readable medium of claim 72, causing the computer device to: [Article 75] 75. The computer-readable medium of clause 74, wherein the computing device is configured to operate without a data connection to the key provision service. [Article 76] 76. The computer-readable medium of any one of clauses 72 to 75, wherein the particular cryptographic key is a key for a symmetric encryption algorithm. [Article 77] 77. The computer-readable medium of clause 76, wherein the instructions, when executed, further cause the computing device to provide the key to an unlocking service and store it in association with the device identifier. [Article 78] 78. The computer-readable medium of clause 76 or 77, wherein writing the particular cryptographic key to the non-flammable aerosol delivery system includes securely storing the key in the non-flammable aerosol delivery system. [Item of invention] [Item 1] 1. A method for unlocking a non-flammable aerosol delivery system, comprising: receiving an indication from the age verification service that the age verification process has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving, from the unlocking service, a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system; forwarding the signed unlock message to the non-flammable aerosol delivery system and authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system; A method comprising: [Item 2] In response to receiving the instruction from the age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; further comprising the step of sending the unlock request to the unlock service includes sending an unlock request including the challenge response message; 2. The method of claim 1, wherein the signed unlock message received from the unlock service provides a cryptographic relationship between the private key and the challenge response message that can be authenticated by the non-flammable aerosol delivery system using the public key. [Item 3] 3. The method of claim 2, wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system. [Item 4] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; The method of any one of items 1 to 3, wherein the signed unlock message received from the unlock service is signed using a private key of the non-flammable aerosol delivery system selected from a plurality of private keys accessible to a remote server based on the device identifier. [Item 5] 5. The method of any one of items 1 to 4, wherein the signed unlock request received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed. [Item 6] 6. The method of any one of items 1 to 5, wherein unlocking the non-flammable aerosol delivery system includes permitting use of the non-flammable aerosol delivery system for generating aerosol for delivery to a user. [Item 7] 7. The method according to any one of items 1 to 6, wherein the user device executing the method communicates with the unlocking service via a program interface. [Item 8] 8. The method according to any one of items 1 to 7, wherein the unlocking service is set on a remote server. [Item 9] 1. A device for unlocking a non-flammable aerosol delivery system, comprising: receiving an indication from the age verification service that the age verification process has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving, from the unlocking service, a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system; forwarding the signed unlock message to the non-flammable aerosol delivery system and authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system; A device comprising: a processing circuit configured to perform [Item 10] the processing circuitry In response to receiving the instruction from the age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; further configured to: the processing circuitry is configured to transmit an unlock request including the challenge response message to transmit the unlock request to the unlock service; 10. The device of item 9, wherein the signed unlock message received from the unlock service provides a cryptographic relationship between the private key and the challenge response message that can be authenticated by the non-flammable aerosol delivery system using the public key. [Item 11] Item 11. The device of item 10, wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system. [Item 12] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; A device described in any one of items 9 to 11, wherein the signed unlock message received from the unlock service is signed using a private key of the non-flammable aerosol delivery system selected from a plurality of private keys accessible to a remote server based on the device identifier. [Item 13] 13. The device of any one of items 9 to 12, wherein the signed unlock request received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed. [Item 14] 14. The device of any one of items 9 to 13, wherein unlocking the non-flammable aerosol delivery system comprises permitting use of the non-flammable aerosol delivery system for generation of an aerosol for delivery to a user. [Item 15] 15. A device according to any one of items 9 to 14, configured to communicate with the unlocking service via a program interface. [Item 16] 16. The device according to any one of items 9 to 15, wherein the unlocking service is set on a remote server. [Item 17] When executed by a computing device, receiving an indication from the age verification service that the age verification process has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving, from the unlocking service, a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system; forwarding the signed unlock message to the non-flammable aerosol delivery system and authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system; A computer-readable medium containing instructions that cause the computing device to perform the steps of: [Item 18] The instructions, when executed by the computing device, In response to receiving the instruction from the age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; and further causing the computing device to perform transmitting the unlock request to the unlock service, the computer device transmitting the unlock request including the challenge response message; Item 18. The computer-readable medium of item 17, wherein the signed unlock message received from the unlock service provides a cryptographic relationship between the private key and the challenge response message that can be authenticated by the non-flammable aerosol delivery system using the public key. [Item 19] Item 19. The computer-readable medium of item 18, wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system. [Item 20] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; 20. The computer-readable medium of any one of items 17 to 19, wherein the signed unlock message received from the unlock service is signed using a private key of the non-flammable aerosol delivery system selected from a plurality of private keys accessible to a remote server based on the device identifier. [Item 21] 21. The computer-readable medium of any one of items 17-20, wherein the signed unlock request received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed. [Item 22] 22. The computer-readable medium of any one of items 17-21, wherein unlocking the non-flammable aerosol delivery system includes permitting use of the non-flammable aerosol delivery system for generating an aerosol to be delivered to a user. [Item 23] 23. The computer-readable medium of any one of items 17 to 22, wherein the computer device communicates with the unlocking service via a program interface. [Item 24] 24. The computer-readable medium of any one of items 17 to 23, wherein the unlocking service is configured on a remote server. [Item 25] 1. A method for unlocking a non-flammable aerosol delivery system, comprising: receiving, from a user device, a signed unlock message at the non-flammable aerosol delivery system, the signed unlock message being cryptographically signed using a private key; authenticating the signed unlock message at the non-flammable aerosol delivery system using the non-flammable aerosol delivery system's public key to determine whether the private key used to sign the signed unlock message corresponds to the public key of the non-flammable aerosol delivery system; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; A method comprising: [Item 26] receiving a challenge request message from the user device; generating a challenge response message; sending the challenge response message to the user device; further comprising the signed unlock message provides a cryptographic association between a given challenge response message and the private key; 26. The method of claim 25, wherein authenticating the signed unlock message further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Item 27] Item 27. The method of item 26, wherein the step of generating the challenge response message includes selecting a random number and generating the challenge response message according to the selected random number. [Item 28] 1. A non-flammable aerosol delivery system comprising: receiving a signed unlock message from the user device, the signed unlock message being cryptographically signed using the private key; authenticating the signed unlock message using a public key stored in the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; A non-flammable aerosol delivery system comprising a processing circuit configured to: [Item 29] the processing circuitry receiving a challenge request message from the user device; generating a challenge response message; sending the challenge response message to the user device; further configured to: the signed unlock message provides a cryptographic association between a given challenge response message and the private key; Item 29. The non-flammable aerosol delivery system of item 28, wherein the processing circuit is further configured to determine whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message to authenticate the signed unlock message. [Item 30] 30. The non-flammable aerosol delivery system of item 29, wherein the processing circuit is configured to select a random number and generate the challenge response message in accordance with the selected random number to generate the challenge response message. [Item 31] When implemented by a processing circuit of a non-flammable aerosol delivery system, receiving a signed unlock message from the user device, the signed unlock message being cryptographically signed using the private key; authenticating the signed unlock message using a public key stored in the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; a computer-readable medium comprising instructions for causing the non-flammable aerosol delivery system to: [Item 32] The instructions, when executed by the processing circuitry, receiving a challenge request message from the user device; generating a challenge response message; sending the challenge response message to the user device; to the non-flammable aerosol delivery system, the signed unlock message provides a cryptographic association between a given challenge response message and the private key; Item 32. The computer-readable medium of item 31, wherein, to authenticate the signed unlock message, the non-flammable aerosol delivery system further determines whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Item 33] Item 33. The computer-readable medium of item 32, wherein to generate the challenge response message, the non-flammable aerosol delivery system selects a random number and generates the challenge response message according to the selected random number. [Item 34] 1. A method for unlocking a non-flammable aerosol delivery system, comprising: receiving, by a user device, an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; sending, by the user device, a request to unlock the non-flammable aerosol delivery system to an unlock service; generating, by the unlocking service, a signed unlocking message cryptographically signed using a private key associated with the corresponding public key of the non-flammable aerosol delivery system; sending, by the unlock service, the signed unlock message to the remote device; transmitting, by the user device, the signed unlock message to the non-flammable aerosol delivery system; authenticating the signed unlock message at the non-flammable aerosol delivery system using the public key of the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key of the non-flammable aerosol delivery system; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; A method comprising: [Item 35] transmitting, by the user device, a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from the age verification service; generating a challenge-response message by the non-flammable aerosol delivery system; transmitting the challenge response message to the user device by the non-flammable aerosol delivery system; further comprising the step of sending the unlock request to the unlock service includes sending an unlock request including the challenge response message; generating the signed unlock message by the unlock service includes providing a cryptographic association between the private key and a given challenge response message; Item 35. The method of item 34, wherein the step of authenticating the signed unlock message by the non-flammable aerosol delivery system further includes determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Item 36] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; Item 36. The method of item 34 or 35, wherein the step of generating the signed unlock message by the unlock service includes selecting the private key from a plurality of private keys accessible to the unlock service based on the device identifier, and signing the signed unlock message using the selected private key. [Item 37] and verifying, by the unlocking service in response to the unlocking request, that the age verification process of the non-flammable aerosol delivery system has been successfully completed; 37. The method of any one of items 34 to 36, wherein the step of generating the signed unlock request by the unlock service is in response to successful verification that the age verification process has been successfully completed. [Item 38] a non-flammable aerosol delivery system; a remote device; Unlocking service and A system comprising: the remote device is configured to receive an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed, and to send a request to unlock the non-flammable aerosol delivery system to the unlock service; the unlocking service is configured to generate a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system, and transmit the signed unlocking message to the remote device; the remote device is further configured to transmit the signed unlock message to the non-flammable aerosol delivery system; The non-flammable aerosol delivery system is configured to determine whether the private key used to sign the signed unlock message corresponds to the public key by authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system, and to unlock the non-flammable aerosol delivery system in response to successful authentication of the signed unlock message. [Item 39] the user device is configured to send a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from the age verification service; the non-flammable aerosol delivery system is configured to generate a challenge-response message; the non-flammable aerosol delivery system configured to transmit the challenge response message to the user device; the user device is configured to send an unlock request including the challenge response message to the unlock service; the unlocking service is configured to provide a cryptographic association between the private key and a given challenge response message to generate the signed unlocking message; Item 39. The system of item 38, wherein authenticating the signed unlock message by the non-flammable aerosol delivery system further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Item 40] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; 40. The system of claim 38 or 39, wherein to generate the signed unlock message, the unlock service is configured to select the private key from a plurality of private keys accessible to the unlock service based on the device identifier, and to sign the signed unlock message using the selected private key. [Item 41] the unlocking service is configured to, in response to the unlocking request, verify with the age verification process that the age verification process of the non-flammable aerosol delivery system has been successfully completed; 41. The system of any one of items 38 to 40, wherein the unlock service generates the signed unlock request in response to successful verification that the age verification process has been successfully completed. [Item 42] When implemented by the processing circuitry of the non-flammable aerosol delivery system, the user device, and the unlock service, receiving, by the user device, an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; transmitting, by the user device, a request to unlock the non-flammable aerosol delivery system to an unlock service; generating, by the unlocking service, a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system; sending, by the unlock service, the signed unlock message to the user device; transmitting, by the user device, the signed unlock message to the non-flammable aerosol delivery system; authenticating the signed unlock message at the non-flammable aerosol delivery system using the public key of the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key of the non-flammable aerosol delivery system; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; A computer-readable medium containing instructions that cause the processing circuit to perform the steps of: [Item 43] The instruction: transmitting, by the user device, a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from the age verification service; generating a challenge response message from the non-flammable aerosol delivery system; the non-flammable aerosol delivery system transmitting the challenge response message to the user device; Further, the user device sending an unlock request including the challenge response message to send the unlock request to the unlock service; the unlocking service providing a cryptographic association between the private key and a given challenge response message to generate the signed unlocking message; Item 43. The computer-readable medium of item 42, wherein authenticating the signed unlock message by the non-flammable aerosol delivery system further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message. [Item 44] the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; Item 44. The computer-readable medium of item 42 or 43, wherein to generate the signed unlock message, the unlock service selects the private key from a plurality of private keys accessible to the unlock service based on the device identifier, and signs the signed unlock message using the selected private key. [Item 45] The instruction: the unlocking service, in response to the unlocking request, verifying through an age verification process that the age verification process of the non-flammable aerosol delivery system has been successfully completed; generating, by the unlock service, the signed unlock request in response to successful verification that the age verification process has been successfully completed; 45. The system according to any one of items 42 to 44, further comprising: [Item 46] 1. A method for establishing a cryptographic key in a non-flammable aerosol delivery system, comprising: receiving a device identifier for the non-flammable aerosol delivery system; Obtaining a specific encryption key for the non-flammable aerosol delivery system based on one or more encryption keys provided by a key generation service; storing the device identifier in association with the particular encryption key; writing the unique encryption key to the non-flammable aerosol delivery system; A method comprising: [Item 47] The step of obtaining the specific encryption key to be set in the non-flammable aerosol delivery system includes: sending a request to the key generation service including the device identifier; receiving the particular encryption key from the key providing service; Including, Item 47. The method of item 46, wherein the key providing service stores the device identifier in association with the particular encryption key by sending the request to the key generation service. [Item 48] obtaining the specific encryption key to be set in the non-flammable aerosol delivery system includes selecting the specific encryption key from a plurality of encryption keys provided by the key providing service and stored on an offline device; 47. The method of claim 46, wherein storing the device identifier in association with the particular encryption key comprises storing the particular encryption key in association with the device identifier for subsequent transfer to a key storage service. [Item 49] Item 49. The method of item 48, performed by a device operating without a data connection to the key provision service. [Item 50] 50. The method according to any one of items 46 to 49, wherein the particular encryption key is a private key of an asymmetric key pair. [Item 51] 51. The method of claim 50, further comprising providing the public key of the asymmetric key pair to an unlocking service and storing it in association with the device identifier. [Item 52] 1. A system for establishing a cryptographic key for a non-flammable aerosol delivery system, comprising: the non-flammable aerosol delivery system; receiving a device identifier for the non-flammable aerosol delivery system; Obtaining a specific encryption key for the non-flammable aerosol delivery system based on one or more encryption keys provided by a key generation service; storing the device identifier in association with the particular encryption key; writing the specific encryption key to the non-flammable aerosol delivery system; a computing device configured to perform A system comprising: [Item 53] the computing device: sending a request to the key generation service including the device identifier; receiving the particular key from the key providing service; The specific encryption key to be set in the non-flammable aerosol delivery system is obtained by Item 53. The system of item 52, wherein the key providing service stores the device identifier in association with the particular encryption key by sending the request to the key generation service. [Item 54] the computing device: obtaining the specific encryption key to be set in the non-flammable aerosol delivery system by selecting the specific encryption key from a plurality of encryption keys provided by the key providing service and stored in an offline device; storing the device identifier in association with the particular encryption key by storing the particular key in association with the device identifier for subsequent transfer to a key storage service; Item 53. The system of item 52, configured to: [Item 55] Item 55. The system of item 54, wherein the computing device is configured to operate without a data connection to the key provision service. [Item 56] 56. The system according to any one of items 52 to 55, wherein the particular encryption key is a private key of an asymmetric key pair. [Item 57] Item 57. The system of item 56, wherein the computing device is further configured to provide the public key of the asymmetric key pair to an unlocking service and store it in association with the device identifier. [Item 58] When executed by the processing circuitry of a computing device, receiving a device identifier for the non-flammable aerosol delivery system; Obtaining a specific encryption key for the non-flammable aerosol delivery system based on one or more encryption keys provided by a key generation service; storing the device identifier in association with the particular encryption key; writing the specific encryption key to the non-flammable aerosol delivery system; A computer-readable medium containing instructions that cause the computing device to perform the steps of: [Item 59] The instructions, when executed by the processing circuitry, sending a request to the key generation service including the device identifier; receiving the particular key from the key providing service; causing the computer device to obtain the specific encryption key to be set in the non-flammable aerosol delivery system by Item 59. The computer-readable medium of item 58, wherein the key providing service stores the device identifier in association with the particular encryption key by sending the request to the key generation service. [Item 60] The instructions, when executed by the processing circuitry, obtaining the specific encryption key to be set in the non-flammable aerosol delivery system by selecting the specific encryption key from a plurality of encryption keys provided by the key providing service and stored in an offline device; storing the device identifier in association with the particular encryption key by storing the particular key in association with the device identifier for subsequent transfer to a key storage service; Item 59. The computer-readable medium of item 58, which causes the computer device to perform the following: [Item 61] Item 61. The computer-readable medium of item 60, wherein the computing device is configured to operate without a data connection to the key provision service. [Item 62] 62. The computer-readable medium of any one of items 58 to 61, wherein the particular cryptographic key is a private key of an asymmetric key pair. [Item 63] Item 63. The computer-readable medium of item 62, wherein the instructions, when executed, further cause the computing device to provide the public key of the asymmetric key pair to an unlock service and store it in association with the device identifier.
Claims
1. 1. A method for unlocking a non-flammable aerosol delivery system, the method being executable by a user device having processing circuitry, the method comprising: receiving an indication from the age verification service that the age verification process has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving, from the unlocking service, a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system; forwarding the signed unlock message to the non-flammable aerosol delivery system and authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system; Including, The method comprises: In response to receiving the instruction from the age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; further comprising the step of sending the unlock request to the unlock service includes sending an unlock request including the challenge response message; The method, wherein the signed unlock message received from the unlock service provides a cryptographic relationship between the private key and the challenge response message that can be authenticated by the non-flammable aerosol delivery system using the public key.
2. The method of claim 1 , wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system.
3. the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; The method of claim 1 or 2, wherein the signed unlock message received from the unlock service is signed using a private key of the non-flammable aerosol delivery system selected from a plurality of private keys accessible to a remote server based on the device identifier.
4. 4. The method of claim 1, wherein the signed unlock message received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed.
5. 5. The method of claim 1, wherein unlocking the non-flammable aerosol delivery system comprises permitting use of the non-flammable aerosol delivery system for generating an aerosol for delivery to a user.
6. The method according to any one of claims 1 to 5, wherein the user device executing the method communicates with the unlocking service via a program interface.
7. The method according to any one of claims 1 to 6, wherein the unlocking service is configured on a remote server.
8. 1. A device for unlocking a non-flammable aerosol delivery system, comprising: receiving an indication from the age verification service that the age verification process has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving, from the unlocking service, a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system; forwarding the signed unlock message to the non-flammable aerosol delivery system and authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system; a processing circuit configured to perform the processing circuitry In response to receiving the instruction from the age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; further configured to: the processing circuitry is configured to transmit an unlock request including the challenge response message to transmit the unlock request to the unlock service; A device that provides a cryptographic relationship between the private key and the challenge response message such that the signed unlock message received from the unlock service can be authenticated by the non-flammable aerosol delivery system using the public key.
9. The device of claim 8 , wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system.
10. the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; The device of claim 8 or 9, wherein the signed unlock message received from the unlock service is signed using a private key of the non-flammable aerosol delivery system selected from a plurality of private keys accessible to a remote server based on the device identifier.
11. 11. The device of claim 8, wherein the signed unlock message received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed.
12. 12. The device of claim 8, wherein unlocking the non-flammable aerosol delivery system comprises permitting use of the non-flammable aerosol delivery system for generating an aerosol for delivery to a user.
13. A device according to any one of claims 8 to 12, adapted to communicate with said unlocking service via a program interface.
14. The device according to any one of claims 8 to 13, wherein the unlocking service is configured on a remote server.
15. A non-transitory computer-readable storage medium containing instructions, The instructions, when executed by a computing device, receiving an indication from the age verification service that the age verification process has been successfully completed; sending a request to unlock the non-flammable aerosol delivery system to an unlock service; receiving, from the unlocking service, a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system; forwarding the signed unlock message to the non-flammable aerosol delivery system and authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system; causing the computing device to perform The instructions, when executed by the computing device, In response to receiving the instruction from the age verification service, transmitting a challenge request message to the non-flammable aerosol delivery system; receiving a challenge response message from the non-flammable aerosol delivery system; and further causing the computing device to perform transmitting the unlock request to the unlock service, the computer device transmitting the unlock request including the challenge response message; A non-transitory computer-readable storage medium that provides a cryptographic relationship between the private key and the challenge response message such that the signed unlock message received from the unlock service can be authenticated by the non-flammable aerosol delivery system using the public key.
16. 16. The non-transitory computer-readable storage medium of claim 15, wherein the challenge response message is based on a random number selected by the non-flammable aerosol delivery system.
17. the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; A non-transitory computer-readable storage medium as described in claim 15 or 16, wherein the signed unlock message received from the unlock service is signed using a private key of the non-flammable aerosol delivery system selected from a plurality of private keys accessible to a remote server based on the device identifier.
18. 18. The non-transitory computer-readable storage medium of claim 15, wherein the signed unlock message received from the unlock service indicates that the unlock service has received an indication that the age verification process has been successfully completed.
19. 19. The non-transitory computer-readable storage medium of any one of claims 15 to 18, wherein unlocking the non-combustible aerosol delivery system comprises permitting use of the non-combustible aerosol delivery system for generating an aerosol for delivery to a user.
20. The non-transitory computer-readable storage medium of any one of claims 15 to 19, wherein the computing device communicates with the unlocking service via a program interface.
21. The non-transitory computer-readable storage medium according to any one of claims 15 to 20, wherein the unlocking service is configured on a remote server.
22. 1. A method for unlocking a non-flammable aerosol delivery system, comprising: receiving, at the non-flammable aerosol delivery system, from a user device, a signed unlock message cryptographically signed using a private key; at the non-flammable aerosol delivery system, authenticating the signed unlock message using a public key of the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key of the non-flammable aerosol delivery system; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message at the non-flammable aerosol delivery system; Including, The method comprises: receiving a challenge request message from the user device at the non-flammable aerosol delivery system; generating a challenge-response message in the non-flammable aerosol delivery system; transmitting the challenge response message from the non-flammable aerosol delivery system to the user device; further comprising the signed unlock message provides a cryptographic association between a given challenge response message and the private key; The method, wherein the step of authenticating the signed unlock message further includes determining, at the non-flammable aerosol delivery system, whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message.
23. 23. The method of claim 22, wherein generating the challenge response message comprises selecting a random number and generating the challenge response message in response to the selected random number.
24. 1. A non-flammable aerosol delivery system comprising: receiving a signed unlock message from the user device, the signed unlock message being cryptographically signed using the private key; authenticating the signed unlock message using a public key stored in the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; processing circuitry configured to: the processing circuitry receiving a challenge request message from the user device; generating a challenge response message; sending the challenge response message to the user device; further configured to: the signed unlock message provides a cryptographic association between a given challenge response message and the private key; A non-flammable aerosol delivery system, wherein the processing circuit is further configured to determine whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message to authenticate the signed unlock message.
25. 25. The non-flammable aerosol delivery system of claim 24, wherein to generate the challenge response message, the processing circuitry is configured to select a random number and generate the challenge response message in response to the selected random number.
26. A non-transitory computer-readable storage medium containing instructions, the instructions, when executed by a processing circuit of a non-flammable aerosol delivery system, receiving a signed unlock message from the user device, the signed unlock message being cryptographically signed using the private key; authenticating the signed unlock message using a public key stored in the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; to the non-flammable aerosol delivery system; The instructions, when executed by the processing circuitry, receiving a challenge request message from the user device; generating a challenge response message; sending the challenge response message to the user device; to the non-flammable aerosol delivery system, the signed unlock message provides a cryptographic association between a given challenge response message and the private key; A non-transitory computer-readable storage medium, further comprising the non-flammable aerosol delivery system determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message to authenticate the signed unlock message.
27. 27. The non-transitory computer-readable storage medium of claim 26, wherein to generate the challenge response message, the non-flammable aerosol delivery system selects a random number and generates the challenge response message according to the selected random number.
28. 1. A method for unlocking a non-flammable aerosol delivery system, comprising: receiving, by a user device, an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; sending, by the user device, a request to unlock the non-flammable aerosol delivery system to an unlock service; generating, by the unlocking service, a signed unlocking message cryptographically signed using a private key associated with the corresponding public key of the non-flammable aerosol delivery system; sending, by the unlock service, the signed unlock message to the user device; transmitting, by the user device, the signed unlock message to the non-flammable aerosol delivery system; at the non-flammable aerosol delivery system, authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key of the non-flammable aerosol delivery system; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; Including, The method comprises: transmitting, by the user device, a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from the age verification service; generating a challenge-response message by the non-flammable aerosol delivery system; transmitting the challenge response message to the user device by the non-flammable aerosol delivery system; further comprising the step of sending the unlock request to the unlock service includes sending an unlock request including the challenge response message; generating the signed unlock message by the unlock service includes providing a cryptographic association between the private key and a given challenge response message; The method, wherein the step of authenticating the signed unlock message by the non-flammable aerosol delivery system further includes determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message.
29. the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; 29. The method of claim 28, wherein generating the signed unlock message by the unlock service comprises selecting the private key from a plurality of private keys accessible to the unlock service based on the device identifier, and signing the signed unlock message using the selected private key.
30. and verifying, by the unlocking service in response to the unlocking request, that the age verification process of the non-flammable aerosol delivery system has been successfully completed; 30. The method of claim 28 or 29, wherein the step of generating the signed unlock message by the unlock service is in response to successful verification that the age verification process has been successfully completed.
31. a non-flammable aerosol delivery system; a remote device; Unlocking service and A system comprising: the remote device is configured to receive an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed, and to send a request to unlock the non-flammable aerosol delivery system to the unlock service; the unlocking service is configured to generate a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system, and transmit the signed unlocking message to the remote device; the remote device is further configured to transmit the signed unlock message to the non-flammable aerosol delivery system; the non-flammable aerosol delivery system is configured to determine whether the private key used to sign the signed unlock message corresponds to the public key by authenticating the signed unlock message using the public key of the non-flammable aerosol delivery system, and unlock the non-flammable aerosol delivery system in response to successful authentication of the signed unlock message; the remote device is a user device, and the user device is configured to send a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from the age verification service; the non-flammable aerosol delivery system is configured to generate a challenge-response message; the non-flammable aerosol delivery system configured to transmit the challenge response message to the user device; the user device is configured to send an unlock request including the challenge response message to the unlock service; the unlocking service is configured to provide a cryptographic association between the private key and a given challenge response message to generate the signed unlocking message; The system further comprises: authenticating the signed unlock message by the non-flammable aerosol delivery system by determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message.
32. the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; 32. The system of claim 31 , wherein to generate the signed unlock message, the unlock service is configured to select a private key from a plurality of private keys accessible to the unlock service based on the device identifier, and to sign the signed unlock message using the selected private key.
33. the unlocking service is configured to, in response to the unlocking request, verify with the age verification process that the age verification process of the non-flammable aerosol delivery system has been successfully completed; 33. The system of claim 31 or 32, wherein the unlocking service generates the signed unlocking message in response to successful verification that the age verification process has been successfully completed.
34. A non-transitory computer-readable storage medium containing instructions, The instructions, when executed by processing circuitry of the non-flammable aerosol delivery system, the user device, and the unlock service, receiving, by the user device, an indication from an age verification service that an age verification process for the non-flammable aerosol delivery system has been successfully completed; transmitting, by the user device, a request to unlock the non-flammable aerosol delivery system to an unlock service; generating, by the unlocking service, a signed unlocking message cryptographically signed using a private key associated with a corresponding public key of the non-flammable aerosol delivery system; sending, by the unlock service, the signed unlock message to the user device; transmitting, by the user device, the signed unlock message to the non-flammable aerosol delivery system; authenticating the signed unlock message at the non-flammable aerosol delivery system using the public key of the non-flammable aerosol delivery system to determine whether the private key used to sign the signed unlock message corresponds to the public key of the non-flammable aerosol delivery system; unlocking the non-flammable aerosol delivery system in response to successfully authenticating the signed unlock message; causing the processing circuit to perform The instruction: transmitting, by the user device, a challenge request message to the non-flammable aerosol delivery system in response to receiving the instruction from the age verification service; generating a challenge response message from the non-flammable aerosol delivery system; the non-flammable aerosol delivery system transmitting the challenge response message to the user device; Further, the user device sending an unlock request including the challenge response message to send the unlock request to the unlock service; the unlocking service providing a cryptographic association between the private key and a given challenge response message to generate the signed unlocking message; A non-transitory computer-readable storage medium, wherein authenticating the signed unlock message by the non-flammable aerosol delivery system further comprises determining whether the challenge response message generated by the non-flammable aerosol delivery system matches the given challenge response message.
35. the unlock request sent to the unlock service includes a device identifier of the non-flammable aerosol delivery system; 35. The non-transitory computer-readable storage medium of claim 34, wherein to generate the signed unlock message, the unlock service selects the private key from a plurality of private keys accessible to the unlock service based on the device identifier, and signs the signed unlock message using the selected private key.
36. The instruction: the unlocking service, in response to the unlocking request, verifying through an age verification process that the age verification process of the non-flammable aerosol delivery system has been successfully completed; generating, by the unlocking service, the signed unlocking message in response to successful verification that the age verification process has been successfully completed; 36. The non-transitory computer-readable storage medium of claim 34 or 35, further comprising:
Citation Information
Patent Citations
Device, method, and system for controlling access to age-restricted electronic products
EP3772001A1
Method, apparatus, and computer program product for enabling operation of an aerosol generating device
JP2022542638A
Electronic cigarette and electronic cigarette activation system
WO2019114597A1