Systems and methods for restricting access to a drug

The container system with multi-step authentication using challenge codes and one-time passwords securely stores and transports drugs, addressing unauthorized access issues and integrating with practice management systems to prevent misuse.

WO2026002863A1PCT designated stage Publication Date: 2026-01-02THE ROYAL VETERINARY COLLEGE
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/067518
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-24
Filing Date
2025-06-23
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

There is a need for improved systems to restrict unauthorized access to potentially dangerous drugs, particularly euthanasia drugs, to prevent misuse by medical professionals, ensuring secure transport and use while integrating with practice management systems and accommodating various treatment locations and conditions.

Method used

A container system with a locking mechanism and authentication process involving multiple challenge codes and one-time passwords, using cryptographic schemes, to securely store and access drugs based on user authentication, location, and time, thereby delaying and discouraging improper access.

Benefits of technology

The system effectively prevents unauthorized access by requiring multiple authentication steps, enhancing security and reducing the likelihood of drug misuse, while allowing secure transport and integration with practice management systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025067518_02012026_PF_FP_ABST
    Figure EP2025067518_02012026_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a system for restricting access to a drug, the system comprising: a container system comprising a container that is adjustable between an open state and a closed state and configured to contain the drug, a locking mechanism configured to lock the container in the closed state, and a processing unit configured to cause actuation of the locking mechanism; and a user device storing an authentication application, wherein the system is configured, when the container is locked in the closed state and contains the drug, to execute: at the user device running the authentication application, a main determination step of accessing data from a database and making a main determination of whether, based on identifying information and the data from the database, access to the drug should be granted; at the processing unit, a first container-side output step of causing generation of a first challenge code, causing the container system to output the first challenge code, and causing generation of a first container one-time password based on the first challenge code using a first cryptographic scheme; at the user device running the authentication application, a first device-side output step of, in response to receiving a first attempted challenge code, causing generation of a first device one-time password based on the first attempted challenge code using the first cryptographic scheme, and causing the user device to output the first device one-time password; at the processing unit, a first comparison step of, in response to receiving a first attempted one-time password, determining whether the first attempted one-time password is the same as the first container one-time password; at the processing unit, when the first attempted one- time password is determined to be the same as the first container one-time password, a second container-side output step of causing generation of a second challenge code, causing the container system to output the second challenge code, and causing generation of a second container one-time password based on the second challenge code using a second cryptographic scheme; at the user device running the authentication application, when the main determination has determined that access to the drug should be granted, a second device-side output step of, in response to receiving a second attempted challenge code, causing generation of a second device one-time password based on the second attempted challenge code using the second cryptographic scheme, and causing the user device to output the second device one-time password; at the processing unit, a second comparison step of, in response to receiving a second attempted one-time password, determining whether the second attempted one-time password is the same as the second container one-time password; and at the processing unit, when the second attempted one-time password is determined to be the same as the second container one-time password, an unlocking step of causing the locking mechanism to unlock the container.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEMS AND METHODS FOR RESTRICTING ACCESS TO A DRUG

[0002] Field of invention

[0003] The invention relates to a system for restricting access to a drug, a container system, a computer program, and a method of restricting access to a drug.

[0004] Background

[0005] Medical practitioners are often required to treat patients using drugs that are associated with a safety risk. Many countries categorize certain drugs as “scheduled” or “controlled” drugs and impose safe custody requirements upon such drugs by law. Unfortunately, even when such requirements are imposed by law, it may be difficult to prevent misuse of such drugs which can result in harm or even death of the receiver of the drug.

[0006] One example category of drugs that are prone to dangerous misuse is those that are used for euthanasia of animals by veterinarians. Animal euthanasia is a common procedure in veterinary practice. A part of the job of the veterinarian is safely and humanely to euthanise animals in the interests of their welfare or authorised destruction. This requires the use of controlled medicines that are harmful to both animals and humans. These drugs are often required to be used outside of the veterinary surgery in order to be administered to large animals. Tragically these same drugs are sometimes misused by veterinarians to commit suicide.

[0007] Psychological research has found that suicide is up to 2.4 times more likely in veterinary professionals than the general population. For example, one means of suicide that is known to have been used by veterinary professionals is poisoning using the euthanasia drug pentobarbital. The elevated rate of suicide seen in veterinary professionals has been attributed to fact that veterinary professionals have greater access to, and knowledge of, means of suicide than the general population does.

[0008] In the UK, for example, there is wide variation in how euthanasia drugs are stored, monitored and transported. The euthanasia drugs are often stored in a locked cupboard but with limited access control, with access to the key being easy for anyone in the practice. There is a requirement that records are kept of all prescriptions, and veterinary practices generally comply with this requirement by keeping a drug book with entries completed by veterinarians accessing the drugs. Drug book entries typically include, for example, the date, time, animal, drug, amount of drug prescribed, and owner. However, such recording systems are often vulnerable to misuse. Typically, there is no audit over volumes stored or used. Generally, the drug will be collected from the storage location when it is to be used and returned to the storage location afterwards. When in transport to the euthanasia appointment location, the drug will likely be stored in a locked medicines container in the transport vehicle. When attending call outs, the drug and other equipment might need to be carried for some distance by hand, particularly when attending an immobile horse or farm animal in a field. As such, the veterinary professional may have ample opportunities to access the euthanasia drug outside of a scheduled euthanasia appointment and misuse the euthanasia drug. Veterinary practices in many countries employ similar methods of managing euthanasia drugs which exhibit similar risks of misuse.

[0009] Accordingly, there exists a need for improved systems for restricting or preventing improper and / or unauthorised access to euthanasia drugs by veterinary professionals.

[0010] Animals are treated and assessed in a wide variety of locations and conditions. For instance, most small and companion animals are treated indoors in well-lit environments, while many larger animals are visited by a vet doing a call-out, with the treatment occurring either in facilities provided on-site (stables, farm buildings etc) or in a yard or in a field, possibly in the dark and / or in inclement weather. Treatment of large wild animals is likely to be carried out in the field and perhaps in austere conditions for example on moors, on the side of the highway or on a beach, and the work may well be completed at night and / or in bad weather. Drugs are often transported in road vehicles with storage space, but certain scenarios such as use on farms and equine practices might require drugs to be transported on quad bikes or similar small vehicles to provide quick transport to locations of animals off-road. Some locations might only be accessible on foot and in these cases the medication must be both protected and easily carried to the point of use. Accordingly, it is desirable for systems that restrict improper or unauthorised access to euthanasia drugs not to restrict possible means of transport for the drugs and, and for such systems to protect the drugs during transport from possible austere conditions.

[0011] Many veterinary practices use a Practice Management System (PMS) to deal with tasking, billing, inventory management, time tracking and other administrative tasks. Dispensing processes may be controlled in accordance with legislation along with locally developed policies and procedures, and the management of data is likely to be through the PMS or an integrated dispensing management package. Records of supply and administration by a veterinary surgeon, veterinarian, pharmacist or other suitably qualified person are usually kept, such as for 5 years, and this data is also likely to be captured and stored for audit purposes by the PMS. Accordingly, it is desirable for systems that restrict improper or unauthorised access to euthanasia drugs to integrate with PMS frameworks of veterinary practices and facilitate tracking and record-keeping in relation to the drugs.

[0012] Moreover, although animal euthanasia drugs are one prominent category of drugs prone to improper access and misuse by medical professionals, similar risks exist surrounding many scheduled or controlled drugs outside of this category. Many drugs intended for legitimate use on patients, but having associated safety risks, may be managed by medical practices in a way that enables improper access and misuse by medical professionals, resulting in harm to the medical professionals themselves or others. In general, there exists a need for improved systems for restricting or preventing improper and / or unauthorised access to potentially dangerous drugs by medical professionals.

[0013] Summary of Invention

[0014] The present disclosure relates to the development of systems and methods for the secure day-to-day transport and use of drugs, such as euthanasia drugs, for example by medical practitioners, such as veterinary practitioners, while also restricting possible harm from misuse.

[0015] A first aspect of the invention is a container system comprising a container that is adjustable between an open state and a closed state and configured to contain the drug, a locking mechanism configured to lock the container in the closed state, and a processing unit configured to cause actuation of the locking mechanism; and a user device storing an authentication application, wherein the system is configured, when the container is locked in the closed state and contains the drug, to execute: at the user device running the authentication application, a main determination step of accessing data from a database and making a main determination of whether, based on identifying information and the data from the database, access to the drug should be granted; at the processing unit, a first container-side output step of causing generation of a first challenge code, causing the container system to output the first challenge code, and causing generation of a first container one-time password based on the first challenge code using a first cryptographic scheme; at the user device running the authentication application, a first device-side output step of, in response to receiving a first attempted challenge code, causing generation of a first device one-time password based on the first attempted challenge code using the first cryptographic scheme, and causing the user device to output the first device one-time password; at the processing unit, a first comparison step of, in response to receiving a first attempted one-time password, determining whether the first attempted one-time password is the same as the first container one-time password; at the processing unit, when the first attempted one-time password is determined to be the same as the first container one-time password, a second container-side output step of causing generation of a second challenge code, causing the container system to output the second challenge code, and causing generation of a second container one-time password based on the second challenge code using a second cryptographic scheme; at the user device running the authentication application, when the main determination has determined that access to the drug should be granted, a second device-side output step of, in response to receiving a second attempted challenge code, causing generation of a second device one-time password based on the second attempted challenge code using the second cryptographic scheme, and causing the user device to output the second device one-time password; at the processing unit, a second comparison step of, in response to receiving a second attempted one-time password, determining whether the second attempted one-time password is the same as the second container one-time password; and at the processing unit, when the second attempted one-time password is determined to be the same as the second container onetime password, an unlocking step of causing the locking mechanism to unlock the container.

[0016] In the system according to this aspect, a drug (e.g. euthanasia drug) may be stored securely by being placed within the container and the container being locked in the closed state. Unlocking the container requires execution of various steps at the container system and at the user device running the authentication application. The requirement to execute the various steps introduces additional barriers between the user attempting to access the drug and the drug itself, thereby delaying the process of accessing the drug. This makes misuse of the drug less likely because the user may be discouraged from accessing the drug in a circumstance where it is not appropriate to do so. The various steps, particularly the main determination step, also provide heightened restriction on access such that improper or unusual attempts to access the drug may result in the container not opening.

[0017] In some embodiments, the user device running the authentication application is configured to make the main determination after the causing the user device to output the first device one-time password. In such cases, the main determination is an intermediate step between the provision of the first device one-time password and the provision (if the main determination is positive) of the second device one-time password. For example, the user device running the authentication application may be configured to receive all or some of the identifying information after the output of the first device one-time password.

[0018] In some embodiments the identifying information comprises at least one of: information identifying a user; information identifying the container system; information identifying a location of the user device and / or the container system; information identifying a recipient of the drug; information identifying a drug; information identifying a dose of the drug; information identifying a current time; information identifying an on-call status of the user. Preferably, the identifying information comprises at least one of: information identifying a location of the user device and / or the container system; information identifying a recipient of a drug; information identifying a drug; information identifying a dose of a drug.

[0019] In some embodiments, the identifying information comprises information identifying a location of the user device, and the main determination comprises determining whether the location of the user device is within a location range indicated by the data from the database. Accordingly, the main determination is made based on whether or not the user device is present in a location at which access to the drug is appropriate.

[0020] In some embodiments, the identifying information comprises information identifying a current time, and the main determination comprises determining whether the current time is within a time range indicated by the data from the database. Accordingly, the main determination is made based on whether or not the attempt to access the drug is at an appropriate time.

[0021] In some embodiments, the user device running the authentication application is configured, before the making the main determination, to execute steps of: determining a current time; accessing the data from the database and determining, based on the current time and the data from the database, whether the current time is within working hours of a user; and setting an amount of the identifying information required to be received before the main determination can be made, based on whether the current time is within the working hours of the user. Accordingly, an attempt to access the drug by a medical professional outside of their working hours, when misuse may be more likely, may require more justification than an attempt to access the drug by a medical professional within their working hours.

[0022] In some embodiments, the user device running the authentication application is configured, before the making the main determination, to execute steps of: determining a current time; accessing the data from the database and determining, based on the current time and the data from the database, a current on-call status of the user; and setting an amount of the identifying information required to be received before the main determination can be made, based on whether the on-call status of the user indicates that the user is on call. Accordingly, an attempt to access the drug by a medical professional who is on call, when misuse may be more likely, may require more justification than an attempt to access the drug by a medical professional who is not on call.

[0023] In some embodiments, the user device running the authentication application is configured to execute an auxiliary determination step of making an auxiliary determination of whether, based on wellbeing information, access to the drug should be granted, wherein the user device running the authentication application is configured to execute the second device-side output step when the auxiliary determination has determined that access to the drug should be granted. In such embodiments, the auxiliary determination step in addition to the main determination step further delays the opening process and further heightens security. The auxiliary determination is based on wellbeing information, which, like the identifying information, may be received from a user themselves, which may discourage the user from continuing an attempt to access the drug when it is not appropriate to do so.

[0024] In some embodiments, the user device running the authentication application is configured to make the auxiliary determination after the causing the user device to output the first device one- time password. Then, the auxiliary determination step is a barrier occurring between the first and second password outputs. For example, when the main determination is also made after the causing the user device to output the first device one-time password, the main determination and auxiliary determination may be made at the same time or in sequence. Where the user is required to input both identifying information and wellbeing information to enable the two determinations, the user device running the authentication application may invite the input of both sets of information together or in sequence, such as on a same display screen or sequential display screens.

[0025] In some embodiments, the auxiliary determination comprises calculating a wellbeing score of the user based on the received wellbeing information, and comparing the wellbeing score to a predetermined wellbeing score threshold, wherein if the calculated wellbeing score exceeds the predetermined wellbeing score threshold, the auxiliary determination determines that access to the drug should be granted.

[0026] In some embodiments, the calculating the wellbeing score is based on a machine learning model.

[0027] In some embodiments, the user device running the authentication application is configured to execute an additional determination step of accessing the data from the database and make an additional determination of whether, based on initial information and the data from the database, access to the drug should be granted, wherein the user device running the authentication application is configured to execute the second device-side output step when the additional determination has determined that access to the drug should be granted. In such embodiments, the additional determination step in addition to the main determination step further delays the opening process and further heightens security. The additional determination is based on initial information, which, like the identifying information, may be received from a user themselves, which may discourage the user from continuing an attempt to access the drug when it is not appropriate to do so.

[0028] In some embodiments, the user device running the authentication application is configured to make the additional determination when the user device has not been caused to output the first device one-time password. Then, the additional determination is a barrier occurring before the output of the first device one-time password. In such embodiments, a positive determination in the additional determination step may be required for output of the first device one-time password.

[0029] In some embodiments, the initial information comprises information identifying the container system, and the additional determination comprises locating, in the data from the database, a container record associated with the container system, determining whether the located container record comprises a container block flag, and if the located container record is determined to comprise a container block flag, determining that access to the drug should not be granted. Accordingly, specific containers that have been determined, such as by a medical practice overseeing a plurality of container systems, to be unsuitable for access by anyone may be blocked from being opened at all.

[0030] In some embodiments, the initial information comprises information identifying a user of the user device, and the additional determination comprises locating, in the data from the database, a user record associated with the user, determining whether the located user record comprises a user block flag, and if the located user record is determined to comprise a user block flag, determining that access to the drug should not be granted. Accordingly, specific users that have been determined, such as by a medical practice overseeing a plurality of users who are medical practitioners, to be unfit to access any drugs in containers, may be blocked from accessing the drug in any container system.

[0031] In some embodiments, the initial information comprises information identifying the container system and information identifying a user of the user device, and the additional determination comprises locating, in the data from the database, a container record associated with the container system and a user record associated with the user, determining whether the located container record and user record indicate that the user is a blocked user for the container system, and if the user is indicated to be a blocked user for the container system, determining that access to the drug should not be granted. Accordingly, specific users may be denied access to specific drugs.

[0032] In some embodiments, the database is remote from the user device and the container system, and the user device running the authentication application is configured to access the data from the database by accessing the database over a network. Accordingly, if connection to the network is available at the time when the data from the database is accessed (e.g. in the main determination step and / or the additional determination step), the accessing of the data from the database as part of the steps is formed by communication over the network with the remote database itself.

[0033] In some embodiments, the system is configured to execute a further step of causing the data from the database to be transferred from the database at a remote location to a memory of the user device over a network, wherein the user device running the authentication application is configured to access the data from the database from the memory of the user device. For example, the step of causing the data from the database to be transferred from the remote location to the memory of the user device over the network may have happened at an earlier time when network connection was available to the user device. Then, when access to the data from the database is required (e.g. as part of the main determination step and / or additional determination step), and where access to the database itself over a network is not possible, the data stored in the memory of the user device that has been previously obtained from the database may still be accessed. In some embodiments, the user device running the authentication application is configured, when the main determination has determined that access to the drug should not be granted, to receive new identifying information, and repeat the main determination step on the basis of newly- received identifying information and the data from the database. In such embodiments, a negative determination in the main determination step does not immediately result in failure of the attempt to open the container. Instead, new identifying information can be received, and the main determination step repeated on the basis of the newly received identifying information, effectively allowing a retry of the main determination step. Such a configuration may account for errors made in the supply of identifying information.

[0034] In some embodiments, the user device running the authentication application is configured, when the main determination has determined that access to the drug should not be granted, to end the running of the authentication application. In such embodiments, a negative determination in the main determination step results in an end to the opening procedure. That is, in response to a negative main determination, the box is prevented from being opened. In embodiments where the user device running the authentication application is configured to repeat the main determination step, there may be a predetermined number of repeated main determination steps allowed to be performed before the ending of running of the application occurs. Such a configuration may be implemented to prevent excessive retries of gaining access to the drug.

[0035] In some embodiments, the processing unit is configured, when the first attempted one-time password is determined not to be the same as the first container one-time password, to receive a further first attempted one-time password, and repeat the first comparison step on the basis of the further first attempted one-time password. Such embodiments can account for errors made when entering the first container one-time password in the container system.

[0036] In some embodiments, the processing unit is configured, when the first attempted one-time password is determined not to be the same as the first container one-time password, to cause the first challenge code and first container one-time password to be deleted from the container system. In such embodiments, an incorrect entry of the first container one-time password results in the first container one-time password no longer being valid, effectively ending the opening procedure. In cases where a repetition of the first attempted one-time password is allowed, the container system may be configured to allow a certain number of retries before deleting the first challenge code and first container one-time password from the container system. Such embodiments may prevent excessive retries of the first container one-time password.

[0037] In some embodiments, the processing unit is configured, when the second attempted onetime password is determined not to be the same as the second container one-time password, to receive a further second attempted one-time password, and repeat the second comparison step on the basis of the further second attempted one-time password. Such embodiments can account for errors made when entering the second container one-time password in the container system.

[0038] In some embodiments, the processing unit is configured, when the second attempted onetime password is determined not to be the same as the second container one-time password, to cause the second challenge code and second container one-time password to be deleted from the container system. Such embodiments may prevent excessive retries of the second container onetime password.

[0039] In some embodiments, the user device running the authentication application is configured, following a determination that access to the drug should not be granted, to cause a notification to be sent to a medical practice indicating that a failed attempt has been made to access the drug. The determination that access to the drug should not be granted may, for example, a result of the main determination step, the auxiliary determination step and / or the additional determination step. Accordingly, the medical practice may readily monitor failed access attempts for quick investigation.

[0040] In some embodiments, the user device running the authentication application is configured, following a determination that access to the drug should not be granted, to cause data indicating that a failed attempt has been made to access the drug to be stored in the database. Similarly, such embodiments may enhance record keeping, by automatically recording logs of failed attempts to access the drug.

[0041] In some embodiments, the user device running the authentication application is configured, after causing the user device to output the first device one-time password, to cause a notification to be sent to a medical practice indicating that the first device one-time password has been provided. In some embodiments, the user device running the authentication application is configured, after causing the user device to output the first device one-time password, to cause data indicating that the first device one-time password has been provided to be stored in the database.

[0042] In some embodiments, the user device running the authentication application is configured, after causing the user device to output the second device one-time password, to cause a notification to be sent to a medical practice indicating that access to the drug has been granted.

[0043] In some embodiments, the user device running the authentication application is configured, after causing the user device to output the second device one-time password, to cause data indicating that access to the drug has been granted to be stored in the database.

[0044] In some embodiments, the user device running the authentication application is configured, after causing the user device to output the second device one-time password, to receive supplementary information, and cause the supplementary information to be stored in the database. Storing supplementary information on the database following access to the drug being enabled may enhance record keeping of medical practices.

[0045] In some embodiments, the processing unit is configured to cause generation of the first challenge code in response to a start request received at the processing unit. Such embodiments may enable reduced power usage by the container system . In some embodiments, the user device running the authentication application is configured to receive a user login request, determine whether the user login request is valid, and if the user login request is valid, enable the main determination to be made. In such embodiments, before the main determination can be made (e.g. before the first attempted challenge code can be received in the user device running the authentication application), the user device running the authentication application may display a login user interface, enabling the input of login details. The user device running the authentication application may access data from a database (e.g. a different database to that accessed to make the main determination) to determine whether the login details of the user are valid and associated with a user having an account with the authentication application.

[0046] In some embodiments, the user device running the authentication application is configured to receive at least some of the identifying information from a user. In some embodiments, the user device running the authentication application is configured to receive at least some of the wellbeing information, initial information, and / or supplementary information from a user.

[0047] In some embodiments, the user device running the authentication application is configured to cause the user device to output at least one identifying information request.

[0048] In some embodiments, the outputting at least one identifying information request comprises displaying, on a display means of the user device, a user interface on which the at least one identifying information request is visible and into which a user is enabled to provide the identifying information.

[0049] In some embodiments, the container system comprises a container input device for receiving the first attempted one-time password and the second attempted one-time password. The container input device may be, for instance, a keypad with number keys, a touch screen, or any other such input device known in the art and capable of receiving passwords.

[0050] In some embodiments, the container system comprises a container display, wherein the processing unit is configured to cause the first challenge code to be displayed on the container display and to cause the second challenge code to be displayed on the container display.

[0051] In some embodiments, the container system comprises a handle for enabling a user to transport the container system. In such embodiments, transport of the container system may be facilitated, such as transport by foot when necessary. Thus, the container system is able to be transported in a variety of ways. In some embodiments, the container system is a unit dimensioned so as to fit inside a volume defined by orthogonal sides of length Im x 0.5m x 0.5m. In such embodiments, the container system is conveniently sized and may, for instance, fit within the storage compartment of a vehicle that may be used to transport the container and drug from an initial location to a location at or close to where the use of the drug is to take place.

[0052] In some embodiments, the container system comprises a memory, the memory configured to store temporarily the first container one-time password and the second container one-time password. Storage may be temporary in the sense that, after a successful attempt to open the container, a failed attempt to open the container, and / or a predetermined time period, stored onetime passwords may be deleted such that the opening procedure must be restarted.

[0053] In some embodiments, the memory stores instructions executable by the processing unit to cause the processing unit to generate the first challenge code and to apply the first cryptographic scheme based on the first challenge code, and / or the memory stores instructions executable by the processing unit to cause the processing unit to generate the second challenge code and to apply the second cryptographic scheme based on the second challenge code.

[0054] In some embodiments, the processing unit is configured, after determining that the first attempted one-time password is the same as the first container one-time password, to cause the first container one-time password to be deleted from the memory of the container system, and / or wherein the processing unit is configured, after determining that the second attempted one-time password is the same as the second container one-time password, to cause the second container one-time password to be deleted from the memory of the container system. In such embodiments, storage of unnecessary and / or outdated information is reduced.

[0055] In some embodiments, the processing unit is configured to cause the first challenge code to be randomly generated, and / or the processing unit is configured to cause the second challenge code to be randomly generated. For example, the first challenge code and / or second challenge code may be a random code of predefined length, such as six characters. The characters may include numbers and / or letters and / or symbols. Optionally, the first and second challenge code have the same predefined length.

[0056] In some embodiments, the first cryptographic scheme and / or the second cryptographic scheme corresponds to a HMAC-based one-time password (HOTP) algorithm.

[0057] In some embodiments, the first cryptographic scheme and / or the second cryptographic scheme corresponds to a HMAC-based one-time password (HOTP) algorithm in which the HMAC is computed by a secure hash algorithm (SHA).

[0058] In some embodiments, the first cryptographic scheme and the second cryptographic scheme are the same scheme. In some embodiments, the drug is a euthanasia drug. Such embodiments may be especially applicable in veterinary practices.

[0059] A second aspect of the invention is a container system comprising a container that is adjustable between an open state and a closed state and contains a drug; a locking mechanism configured to lock the container in the closed state; and a processing unit configured to cause actuation of the locking mechanism, wherein the processing unit is configured to execute steps of: when the container is locked in the closed state, causing generation of a first challenge code, causing the container system to output the first challenge code, and causing generation of a first container one-time password based on the first challenge code using a first cryptographic scheme; in response to receiving a first attempted one-time password, determining whether the first attempted one-time password is the same as the first container one-time password; when the first attempted one-time password is determined to be the same as the first container one-time password, causing generation of a second challenge code, causing the container system to output the second challenge code, and causing generation of a second container one-time password based on the second challenge code using a second cryptographic scheme; in response to receiving a second attempted one-time password, determining whether the second attempted one-time password is the same as the second container one-time password; and when the second attempted one-time password is determined to be the same as the second container one-time password, causing the locking mechanism to unlock the container.

[0060] The container system of this aspect may correspond to the container system of the system of the first aspect, and may incorporate any of the features described herein in relation to the container system of the system of the first aspect.

[0061] A third aspect of the invention is a computer program comprising instructions which, when the program is executed by a user device, cause the user device to execute steps of: accessing data from a database, and making a main determination of whether, based on identifying information and the data from the database, access to a drug should be granted; in response to receiving a first attempted challenge code, causing generation of a first device one-time password based on the first attempted challenge code using a first cryptographic scheme, and causing the user device to output the first device one-time password; and when the main determination has determined that access to the drug should be granted, in response to receiving a second attempted challenge code, causing generation of a second device one-time password based on the second attempted challenge code using a second cryptographic scheme, and causing the user device to output the second device onetime password.

[0062] The computer program may correspond to the authentication application that the user device of the system of the first aspect is configured to run. Thus, the computer program may incorporate any of the features described herein in relation to the authentication application program stored on the user device of the first aspect.

[0063] A fourth aspect of the invention is a method of restricting access to a drug, the method comprising: a step of providing a container system comprising a container that is adjustable between an open state and a closed state and configured to contain the drug, a locking mechanism configured to lock the container in the closed state, and a processing unit configured to cause actuation of the locking mechanism; at a user device running the authentication application, a main determination step of accessing data from a database and making a main determination of whether, based on identifying information and the data from the database, access to the drug should be granted; at the processing unit, when the container is locked in the closed state and contains the drug, a first container-side output step of causing generation of a first challenge code, causing the container system to output the first challenge code, and causing generation of a first container onetime password based on the first challenge code using a first cryptographic scheme; at the user device running the authentication application, a first device-side output step of, in response to receiving a first attempted challenge code, causing generation of a first device one-time password based on the first attempted challenge code using the first cryptographic scheme, and causing the user device to output the first device one-time password; at the processing unit, a first comparison step of, in response to receiving a first attempted one-time password, determining whether the first attempted one-time password is the same as the first container one-time password; at the processing unit, when the first attempted one-time password is determined to be the same as the first container one-time password, a second container-side output step of causing generation of a second challenge code, causing the container system to output the second challenge code, and causing generation of a second container one-time password based on the second challenge code using a second cryptographic scheme; at the user device running the authentication application, when the main determination has determined that access to the drug should be granted, a second device-side output step of, in response to receiving a second attempted challenge code, causing generation of a second device one-time password based on the second attempted challenge code using the second cryptographic scheme, and causing the user device to output the second device one-time password; at the processing unit, a second comparison step of, in response to receiving a second attempted one-time password, determining whether the second attempted one-time password is the same as the second container one-time password; and at the processing unit, when the second attempted one-time password is determined to be the same as the second container one-time password, an unlocking step of causing the locking mechanism to unlock the container.

[0064] The container system and user device running the authentication application may correspond to the container system and user device running the authentication application in the system of the first aspect. The method of the present aspect may incorporate steps corresponding to any of the features described herein in relation to the system of the first aspect.

[0065] In some embodiments, the method further comprises, before the generating the first challenge code, transporting the container system from a first location to a second location. That is, the container system is portable.

[0066] A fifth aspect of the invention is a container system comprising a container that is adjustable between an open state and a closed state and configured to contain the drug, a locking mechanism configured to lock the container in the closed state, and a processing unit configured to cause actuation of the locking mechanism; and a user device storing an authentication application, wherein the system is configured, when the container is locked in the closed state and contains the drug, to execute: at the user device running the authentication application, a main determination step of accessing data from a database and making a main determination of whether, based on identifying information and the data from the database, access to the drug should be granted; at the processing unit, a container-side output step of causing generation of a challenge code, causing the container system to output the challenge code, and causing generation of a container one-time password based on the challenge code using a cryptographic scheme; at the user device running the authentication application, when the main determination has determined that access to the drug should be granted, a device-side output step of, in response to receiving an attempted challenge code, causing generation of a device one-time password based on the attempted challenge code using the cryptographic scheme, and causing the user device to output the device one-time password; at the processing unit, a comparison step of, in response to receiving an attempted onetime password, determining whether the attempted one-time password is the same as the container one-time password; and at the processing unit, when the attempted one-time password is determined to be the same as the container one-time password, an unlocking step of causing the locking mechanism to unlock the container.

[0067] Brief Description of Drawings

[0068] The invention will now be described by way of example with reference to the accompanying drawings in which:

[0069] Figure 1 depicts a system for restricting access to a drug in accordance with an embodiment.

[0070] Figure 2 depicts a method of restricting access to a drug in accordance with an embodiment.

[0071] Figure 3 depicts additional steps implementable at the user device in the method of figure 2. Figure 4 depicts additional steps implementable at the container system in the method of figure 2.

[0072] Figure 5 depicts an exemplary form of a container system in accordance with an embodiment.

[0073] Figure 6 depicts another exemplary form of a container system comprising a plurality of containers, in accordance with an embodiment.

[0074] Figures 7A-7E depict exemplary user interfaces that may be displayed at a user device during the method of figure 2.

[0075] Detailed Description of Embodiments

[0076] Figure 1 illustrates a system 100 for restricting access to a drug according to an exemplary embodiment. Also depicted is a database 3. System 100 comprises a container system 1 and a user device 2. User device 2 is configured to access database 3, as depicted by a dashed line. For instance, database 3 may be remote from user device 2 and the user device may be configured to access database 3 for example over a wired connection or over a (optionally wireless) network.

[0077] User device 2 may be configured to download and store data from remote database 3, such as over a network or wired connection, such that data from database 3 may be accessed by user device 2 at times when the network or wired connection for access to database 3 itself is not available to user device 2. Accordingly, access to data from the database 3 can be made possible even at times when connection to a network (or remote access to the database 3 by other means) by the user device is not possible, such as when the user device 2 is being used in a location without mobile internet connectivity. User device 2 is a computing device, such as a smart phone or tablet, having processing means and communication means.

[0078] User device 2 stores an authentication application 21, which corresponds to a computer program configured to run on user device 2. Authentication application 21 may be stored on the user device by being downloaded from a network-based application “store”, and / or may be a web application run on a web server accessible by user device 2. Authentication application 21, when executed on user device 2 or on a web server accessed by user device 2, may cause a device display of user device 2 to display various user interfaces, enabling a user to input information in the user interfaces via input means of the user device (e.g. a touch screen).

[0079] Container system 1 comprises a container 11. Container 11 is configured to contain a drug, such as a euthanasia drug. Container 11 can exist in an open state in which the space internal to the container and any contents therein are accessible from the outside, and a closed state in which the space internal to the container and any contents therein are not accessible from the outside. This may be achieved by virtue of a closable door of the container, for example. Container 11 is lockable in the closed state by way of locking mechanism 12. Locking mechanism 12 may be a mechanical lock, a magnetic lock, or any other mechanism that is actuatable to prevent the container 11 from being adjusted from the closed state to the open state without physically damaging or breaking the container or locking mechanism. Such locking mechanisms (e.g. as used in lockable safes) are well-known.

[0080] Container system 1 also comprises a processing unit 13, which is coupled with locking mechanism 12 such that actuation of locking mechanism 12 to lock and unlock the container 11 may be controlled and caused by processing unit 13.

[0081] An example form of container system 1 is illustrated in figure 5. Container system 1 comprises container 11, depicted in an open state. In the depicted example, container 11 is openable and closable by way of a hinged lid 110 of the container 11, but other embodiments may comprise different means to open and close container 11. In this example, container system l is a unit comprising, in addition to container 11, a container input device 14, a container output device 15, a handle 16, a separate storage compartment 17, a cover 18, and a cover closing mechanism 19. Container locking mechanism 12 and processing unit 13 are not shown in figure 5 but are present within the same unit.

[0082] Container input device 14 is shown in figure 5 as a keypad comprising functional buttons operable by a user, including buttons corresponding to numerical characters, enabling a user to input numerical codes to the container system 1 using input device 14. In other embodiments the container system 1 may comprise different or additional input devices operable to receive inputs from a user, such as a keypad with alphabetical input characters, a touch screen, or voice recognition means configured to receive and compute spoken commands. Additionally or alternatively, input device 14 may be configured to receive information not from a user but from a communicating electronic device (such as user device 2), such as by near-field communication. Accordingly, container input device 14 may in some embodiments correspond to a communicative receiver. In general, input device 14 is operable to receive attempted one-time passwords that may then be processed by processing unit 13 of the container system as part of a procedure of opening the container.

[0083] Container output device 15 is shown as a display that is configured to display information visually such that a user may use the displayed information in a procedure for opening the container 11. For instance, display 15 is configured to display one or more challenge codes generated by (or as a result of) processing unit 13, for the user to read and input into user device 2 running the authentication application 21, as described below. In other embodiments the container system may comprise other forms of output device configured to output information in different ways. For instance, output device 15 may comprise a speaker system configured to output challenge codes in audio form, or may comprise a communicative transmitter configured to send challenge codes to a separate communicative device such as user device 2 (e.g. by near-field communication) without a user receiving and interpreting the codes.

[0084] Handle 16 may enable a user to transport the container system 1. That is, when container system 1 is a unit as shown, all components of the container system 1 (container 11, locking mechanism 12, processing unit 13) may be transported together by way of the handle 16. As such, container system 1 is not limited to being transported in a storage area of a vehicle, and is additionally be transportable by hand, which is useful in situations where the intended use of a drug contained in the container 11 is in a location only accessible by foot.

[0085] Separate storage compartment 17 may be present to provide a space for storage of additional items that may be useful or necessary to accompany the administration of the drug contained in container 11. For instance, separate storage compartment 17 may be configured to store medical items such as gloves, stethoscopes, hair clippers, etc.

[0086] Cover 18 may be configured to cover various components of container system 1 when not in use. Figure 5 illustrates cover 18 that is closable to cover container 11, input device 14, output device 15, and separate storage compartment 17 when not in use, such as during transport. In some embodiments, cover 18 is present and movable to cover and uncover at least the container input device 14. This may prevent unintentional inputs to the input device 14, such as due to movement of the container system in a vehicle compartment in transit. Thus, cover 18 may enhance the convenience of transport of container system 1. In some embodiments, including that shown in figure 5, cover 18 can be sealed in a closed position by way of cover closing mechanism 19.

[0087] The example container system shown in figure 5 comprises a single container 11. In other embodiments, container system 1 may comprise a plurality of containers each having a corresponding locking mechanism, such that a plurality of drugs (e.g. different drugs) may be stored securely within a single container system. In such embodiments, each individual container of the container system 1 may be openable by a separate opening procedure. Such embodiments may enable a medical professional to carry out several procedures using different drugs in succession, without needing to transport multiple container systems or to travel back and forth to a drug storage site to restock a single container. Such embodiments may advantageously enable secure day-to-day transport of several drugs in one container. For example, container system may comprise two, three or four containers or more, each container being individually configured to contain a drug.

[0088] An example form of a container system 1 in accordance with such embodiments is illustrated in figure 6. Figure 6 shows, similar to figure 5, container system 1 being a unit that includes a container input device 14 (shown as a keypad), container output device 15 (shown as a display), handle 16, cover 18 (shown as a hinged lid) and cover closing mechanism 19. In this arrangement, container input device 14 and container display 15 are located on cover 18.

[0089] Container system 1 includes four containers 1 la, 1 lb, 11c and 1 Id. Each container has a locking mechanism associated therewith. Processing unit 13 (not shown in figure 6) is coupled with the locking mechanisms of each of the separate containers, such that actuation of the locking mechanisms may be individually controlled by processing unit 13.

[0090] Container system 1 is not limited to the particular forms shown in figures 5 and 6 and may in general be a unit comprising container 11 (or a plurality thereof), locking mechanism 12 (or a corresponding plurality thereof) and processing unit 13 within a single physical housing or casing. Any or all of the additional components illustrated in figure 5 or figure 6 and described herein in relation to those figures may be present in container system 1, and part of the same unit, optionally transportable by way of handle 16. In such cases, container system 1 may be a unit dimensioned so as to fit inside a volume defined by orthogonal sides of length 1 m x 0.5 m x 0.5 m. Thus, container system 1 may be conveniently sized so as to fit within normal storage spaces of vehicles that are typically used to transport drugs, such as the boot space of a car.

[0091] Container system 1 may have an overall mass that is conducive the manual transport by a user (e.g. using handle 16). For example, the overall mass of container system 1 may be 20 kg or less, preferably 15 kg or less, more preferably 10 kg or less, or more preferably 5 kg or less. The overall mass of the container system 1 may exclude the mass of contents of the container system that are not themselves part of the container system (e.g. drugs).

[0092] Container system 1 may also comprise a memory coupled with processing unit 13 and configured to store pieces of information such as challenge codes and one-time passwords that have been generated by or as a result of processing unit 13, as part of processes described below. Processing unit 13 may be configured to cause information to be stored on and deleted from the memory of the container system. Processing unit 13 may be configured to cause information to be stored temporarily in the container memory, with deletion occurring after a certain time has passed since the beginning of the storage, or upon occurrence of a certain event.

[0093] The memory of the container system may also store instructions executable by processing unit 13 to cause the processing unit to perform operations such as generation of random codes and / or generation of one-time passwords using cryptographic schemes. Additionally or alternatively, processing unit 13 may be configured to cause such operations to be performed elsewhere, such as in a remote computing device in communication with processing unit 13, and receive information generated by such operations, and store the received information in the container system memory. Any storage of such one-time passwords by container system 1 is in secret, that is, one-time passwords generated using cryptographic schemes either by or as a result of processing unit 13 are not caused to be output from container system 1 to a user or to user device 2.

[0094] In general, container system 1 is configured such that when container 11 is initially locked in a closed state by locking mechanism 12, processing unit 13 will only cause locking mechanism 12 to unlock the container, thereby enabling container 11 to be adjusted to an open state and contents of the container to be accessed, upon receipt of (at least) two correct one-time passwords. The processing unit 13 is configured to generate, or otherwise cause generation of, one-time passwords (“container” one-time passwords) and also to receive one-time passwords (“attempted” one-time passwords). For example, the container system 1 may receive attempted one-time passwords from a user. An attempted one-time password is correct if it is the same as a corresponding container one-time password that processing unit 13 has caused to be generated. That is, processing unit 13 is capable of recalling generated container one-time passwords for comparison with received attempted one-time passwords to determine the correctness of attempted one-time passwords.

[0095] The use of one-time passwords rather than traditional static passwords reduces the likelihood of unauthorized entry to the container 11 by eliminating the possibility of unauthorized persons learning static passwords that would repeatedly enable access to the container 11. Accessing the drug in the container 11 without damaging or breaking the container system is possible through use of a second device (specifically, the user device 2 running authentication application 21), which may be inaccessible to unauthorized persons, to determine the one-time passwords that will cause the container 11 to open in any given instance. Moreover, the use of two one-time passwords rather than one delays the opening process and further heightens security.

[0096] Container one-time passwords are generated using cryptographic schemes that convert inputs to outputs, the outputs being the container one-time passwords. Herein, a cryptographic “scheme” may refer to implementation of a particular cryptographic technique or function. The inputs for such cryptographic schemes used by or as a result of processing unit 13 are challenge codes which are themselves generated, or otherwise caused to be generated, by processing unit 13. That is, processing unit 13 is configured to cause generation of a first challenge code and cause the first challenge code to be used to generate a first container one-time password by a first cryptographic scheme, and also to cause generation of a second challenge code and cause the second challenge code to be used to generate a second container one-time password by a second cryptographic scheme. In some embodiments, the processing unit 13 itself is configured to perform the generations of the challenge codes and container one-time passwords, rather than causing a separate device to perform the generations. The first and second cryptographic schemes that the processing unit 13 is configured to use may be the same or may be different. Preferably, the first cryptographic scheme is the same scheme as the second cryptographic scheme.

[0097] As described in more detail below, in a procedure for opening the container 11, processing unit 13 requires receipt of a correct first attempted one-time password (correct meaning the same as the first container one-time password) to move to the next step of causing generation of the second challenge code and second container one-time password. Processing unit 13 then requires receipt of a correct second attempted one-time password (correct meaning the same as the second container one-time password) in order to effect opening of the container 11. The processing unit 13 causes the generated challenge codes to be outputted from the container system (such as displayed on display 15 in the examples shown in figures 5 and 6), but does not cause the generated container one-time passwords to be outputted (i.e. the container one-time passwords are kept secret from any entity that is capable of inputting attempted one-time passwords to the container system 1, such as a user or user device 2). This means that, for an attempted one-time password received at the container system 1 to be correct, a separate one-time password generation using the same cryptographic scheme as used by (or as a result of) the processing unit 13 must have been performed based on the corresponding outputted challenge code (not accounting for the possibility of the attempted one-time password being randomly and correctly guessed). As described herein, user device 2 running authentication application 21 is configured to cause such separate generations, and thus is necessary to enable opening of the box (without random guessing of onetime passwords).

[0098] That is, user device 2, running authentication application 21, is configured to receive challenge codes (“attempted” challenge codes) and also to generate, or otherwise cause generation of, one-time passwords (“device” one-time passwords). The generation of device one-time passwords may be caused to be performed by processing means of the user device itself, or elsewhere such as on a network server. The generation of device one-time passwords uses the first and second cryptographic schemes, with the inputs being attempted challenge codes received at the user device 2 running the authentication application 21, and the outputs being device one-time passwords. That is, the first container one-time password and the first device one-time password are caused to be generated using the same cryptographic scheme (the first cryptographic scheme), and the second container one-time password and the second device one-time password are caused to be generated using the same cryptographic scheme (the second cryptographic scheme, which may also be the same as the first cryptographic scheme). Accordingly, if an attempted challenge code received at the user device 2 running the authentication application 21 matches the corresponding challenge code caused to be generated by the processing unit 13 of container system 1, then the device one-time password generated from that attempted challenge code will be the same as the corresponding container one-time password.

[0099] The user device 2 running the authentication application 21 is configured, upon generation of a device one-time password, to cause output of the device one-time password, such as to a user, or directly to container system 1 without requiring intervention of a user. For example, device onetime passwords may be caused to be displayed on display means of the user device 2, or may be transmitted directly to container system 1 by near-field communication. Thus, in a procedure for opening the container 11 as described in more detail below, the first and second challenge codes outputted by or as a result of container system 1 may be provided to user device 2 running authentication application 21 to cause generation and output of first and second device one-time passwords that match the first and second container one-time passwords, and can accordingly be provided to container system 1 as first and second attempted one-time passwords to effect successful opening of the container 11.

[0100] When two cryptographic schemes are referred to herein as being the “same”, it is meant that the two cryptographic schemes are an implementation of the same cryptographic function or technique, in the sense that if the two cryptographic schemes receive the same input they will generate the same output. It is not meant that, for instance, the cryptographic schemes must be coded in identical software. Although the first cryptographic scheme as caused to be used by the container system is the same as the first cryptographic scheme as caused to be used by the user device running the authentication application, this does not necessarily mean that the container system and user device running the authentication application cause execution of identical software programs to perform the first cryptographic scheme. The same applies regarding the second cryptographic scheme. For example, if the first cryptographic scheme caused to be used by the container system is an implementation of a SHA1-H0TP algorithm, then the first cryptographic scheme caused to be used by the user device running the authentication application is also a SHA1- HOTP algorithm, but the software language used to implement the SHA1-H0TP algorithm at the container system side and user device side might not be exactly the same.

[0101] As described in more detail below, an additional constraint on access to the drug in the container being granted is that the user device 2 running the authentication application 21 is configured only to provide both necessary device one-time passwords when it has been determined in a “main determination” step that access to the drug should be granted. That is, at least the second device one-time password will not be output unless or until the main determination step has occurred and resulted in a positive determination. In some embodiments, the first device one-time password will not be output unless or until the main determination step has occurred and resulted in a positive determination. That is, the system 100 is configurable such that the main determination step occurs at various points in the procedure for opening the container 11 and such that a negative main determination causes failure of the opening procedure at various points, as long as at least output of the second device one-time password does not occur until the main determination has determined that access to the drug should be granted to the user attempting the access.

[0102] The need for a positive main determination step in order for the container 11 to be unlocked further delays the opening process and further heightens security because it may enable improper or unusual access attempts to be prevented, as described in more detail below. As also described below, it is also possible to implement an auxiliary determination step and / or a main determination step at various points in the procedure for opening the container 11, so as to provide further delay and heightened security to the opening process.

[0103] Returning to figure 1, system 100 is configured such that opening of the container from a locked closed state to enable access to drugs inside the container may be effected by a container opening procedure, which is described hereinafter with reference to figures 2, 3 and 4.

[0104] Figure 2 illustrates a process by which successful unlocking of container 11 of the container system 1 may be achieved, in accordance with an exemplary embodiment. As shown, causing the container to open involves parallel sequences of steps performed at user device 2 and container system 1 of system 100. In such a process, various information (challenge codes and one-time passwords) is passed between user device 2 and container system 1, such as by a user, or by direct communication (e.g. near-field communication) between user device 2 and container system 1. Various information (e.g. “identifying information”, optionally “initial information” and “wellbeing information”) is received or otherwise accessed by user device 2 running authentication application 21. In figure 2, such transfers of information are represented by dashed arrows, and steps involving access to database 3 or data therefrom (e.g. remote access to database 3 over a network, or access to data downloaded previously on user device 2 from database 3) are represented by symbol “DB”.

[0105] The procedure at container system 1 may be initiated by receipt at the container system 1 of a start request (step Bl). For example, when container system 1 comprises a container input device 14, the start request may correspond to an input received at the container input device 14. When container input device 14 is a keypad as shown in figures 5 and 6, an exemplary start request is the pressing of a “*” button on the keypad. Other types of start request as known in the art may be employed. When such a step is included, receipt of the start request may “wake” the container system 1 and prompt the first container-side output step (step B2) to be initiated. Overall power usage of the container system 1 may be reduced by virtue of the configuration to wake in response to a start request. Container system 1 is configured to perform (for instance, in response to the receiving of a start request in step Bl) a first container-side output step (step B2). The first container-side output step includes processing unit 13 causing generation of a first challenge code (CC1). For example, processing unit 13 may generate CC1 or may cause CC1 to be generated by another processing device and receive CC1 from that device. CC1 may be generated by a random number generation technique, such as a technique resulting in generation of a random number with a predefined length (e.g. six characters). Processing unit 13 causes the container system 1 to output CC1, such that CC1 may be provided to user device 2 for step A3 (as described below), as indicated by the dashed arrow labelled “CC1” in figure 2. For example, when container system 1 comprises an output device 15 such as a display as shown in figures 5 and 6, processing unit 13 may cause CC1 to be represented (e.g. displayed) by output device such that the user may determine (e.g. read) CC1 from the output device and then input the determined information to the user device 2. In other embodiments, CC1 may be transmitted directly from container system 1 to user device 2 without intervention from the user.

[0106] Additionally, processing unit 13 causes generation of a first container one-time password (OTP1) based on CC1. As with the generation of CC1, generation of OTP1 may be performed by processing unit 13 itself or may be caused to be performed elsewhere. The generation of OTP1 based on CC1 uses a first cryptographic scheme. The first cryptographic scheme corresponds to an algorithm for converting an initial string of characters (here, CC1) into an encrypted code (here, OTP1). For this purpose, the generation of OTP1 may employ any known cryptographic scheme, such as a scheme corresponding to a HMAC-based one-time password (HOTP) algorithm. In such cases, the HMAC may be computed by a secure hash algorithm (SHA), such as SHA-1. Other secure hash algorithms usable in the first cryptographic scheme include SHA-0, SHA-2, SHA -3, SHA-256, SHA -384 and SHA -512. Following generation of OTP1, processing unit 13 is able to recall OTP1 (e.g. from a memory of the container system 1) for comparison with a later-received attempted first one-time password. As described below, derivation of OTP1 by the user and / or user device 2 (not accounting for random guessing) is enabled by step A3 being carried out at the user device 2.

[0107] The procedure at the user device may be initiated by receipt of a user login request (step Al). User login request may comprise, for example, a username and password known to the user. In some embodiments, user login request may be implemented at the user device 2 using biometric recognition, such as facial recognition. The details of the user login request may be verified by accessing data from a database (e.g. database 3, or a different database, accessed via a network or from within user device 2) holding login details of registered users of the authentication application. Upon verification that the login details correspond with a registered user, the authentication application 21 may begin running on the user device 2 and subsequent steps at the user device 2 may be enabled. If the details of the login request are determined not to correspond with a registered user, the user device 2 may be configured not to allow any further steps of the procedure at the user device 2 to be carried out, such as until a login request is received and verified.

[0108] Herein, the user device 2 being defined to be “running” the authentication application 21 means that login step Al, if included, has occurred and the user login details have been verified to correspond with a registered user. That is, the application “running” means that the user is already logged in if login is required.

[0109] When the user device 2 is a device including a display and input means, during this step a user interface may be displayed on the device display enabling the user to input login information using input means, such as a touch screen of the device. An example of a user interface that may be displayed on user device 2 during this step is shown in figure 7A.

[0110] At the user device 2 running the authentication application 21, an additional determination step may be executed (step A2). Figure 2 shows the additional determination step being executed before the first device-side output step (step A3), but the timing of the additional determination step (if included) is not so limited as long as the additional determination step (if included) occurs prior to completion of the second device-side output step (step A6, described below).

[0111] In the additional determination step, user device 2 running authentication application 21 accesses data from database 3, and makes an additional determination of whether, based on initial information and the data from database 3, access to the drug should be granted. The accessing of data from database 3 in this step may comprise accessing database 3 itself (optionally over a network) or may comprise accessing data that has previously been downloaded on user device 2 from database 3. That is, user device 2 running authentication application 21 receives or otherwise accesses initial information.

[0112] The initial information may include information inputted to the user device 2 by the user and / or information accessed from the user device 2 itself. Preferably, the initial information comprises information identifying the user attempting to access the drug, and / or information identifying the container system 1. For instance, if a prior step of receiving a user login request (step Al) has been executed, the information identifying the user may correspond to login details (e.g. a username) received in that step. Alternatively, the additional determination step may comprise receiving information identifying the user (such as a name inputted by the user, or by using biometric recognition) separately from any login step or when no login step is required to run the authentication application 21. An example of information identifying the container system is a serial number associated with the container system 1, which may be visible on the container system 1 such that the user may read the serial number from container system 1 and input it in the user device 2 running authentication application 21 as part of the additional determination step. Additionally or alternatively, the additional determination step may include utilising an imaging means of user device 2 to read a serial number visible on the container system, or another code readable by the user device running the authentication application such as a barcode or QR code, from which the identity of the container system 1 may be determined.

[0113] When additional determination step A2 is included, database 3 contains information indicative of whether access to the drug should be granted on the basis of the initial information.

[0114] In some embodiments, the initial information comprises information identifying the container system, and the additional determination comprises locating, in the data from database 3, a container record associated with the container system, determining whether the located container record comprises a container block flag, and if the located container record is determined to comprise a container block flag, determining that access to the drug should not be granted. In such embodiments, the container system 1 at which access is being attempted may be one of several container systems in a group of container systems, such as a set of container systems associated with a medical practice. Accordingly, the database 3 may include a container record associated with each container system of the group, such that the information identifying the container system may enable the container record in the database associated with the container system 1 at which access is being attempted to be located. Individual container records in the database 3 may be assignable (e.g. by a curator of the database 3, such as a medical practice associated with the set of container systems) with a container block flag to indicate that the contents of the container 11 of the container system 1 should not be accessed by any user. If the container record located in the database comprises a container block flag, in this embodiment, the additional determination is negative, preventing the container of the blocked container system from being opened.

[0115] In some embodiments, the initial information comprises information identifying a user of the user device, and the additional determination comprises locating, in the data from the database, a user record associated with the user, determining whether the located user record comprises a user block flag, and if the located user record is determined to comprise a user block flag, determining that access to the drug should not be granted. In these embodiments, the user may be one of several users in a group of users, such as a set of users associated with a medical practice. Accordingly, the database 3 may contain a user record associated with each user in the group, such that the information identifying the user may enable the record in the database 3 associated with the identified user to be located. Individual user records in the database may be assignable (e.g. by a curator of the database, such as a medical practice associated with the set of users) with a user block flag to indicate that the user should not be granted access to any drugs in container systems. If such a user block flag is determined to be present in the user record for the user attempting to access the drug, the additional determination is negative, preventing the container 11 from being opened by the blocked user.

[0116] In some embodiments, the initial information comprises both information identifying the container system and information identifying a user of the user device. The form of such information may be as discussed above. The database 3 may then comprise both container records and user records as described above, with particular user records being assignable with block flags for specific container records, to indicate specific users being blocked from accessing specific containers. In other words, in addition to the possibility of blocking certain users from accessing all containers and the possibility of blocking certain containers from being accessed by all users, specific users can be blocked from accessing specific containers. This may be desirable in cases where medical practices determine that a specific user should not be granted access to a specific drug. When such a flag is identified for the identified user and identified container system 1, the additional determination is negative and the container cannot be opened.

[0117] In the embodiment shown by figure 2, a determination that access to the drug should be granted (positive additional determination) is needed for first device-side output step (step A3) to be completed. A positive additional determination is represented by (Y) in figure 2.

[0118] At the user device 2 running the authentication application, a first device -side output step (step A3) is executed. As shown by the dashed arrow labelled “CC1” in figure 2, completion of the first device-side output step in a way that leads to opening of the container 11 involves CC1 being transmitted from container system 1 to user device 2, which transmission may be via a user or may be direct. In the first device-side output step, in response to receiving a first attempted challenge code, user device 2 running authentication application 21 causes generation of a first device onetime password based on the first attempted challenge code, and causes the user device to output the first device one-time password. The generation of the first device one-time password uses the first cryptographic scheme, that is, the same first cryptographic scheme used by container system 1 to generate OTP1. Accordingly, this step will only result in generation and output of a first device one-time password that is the same as OTP1 if the first attempted challenge code received at user device 2 is the same as CC1 generated at the container system in step B2.

[0119] The user device running the authentication application may be configured to: cause the user device to output at least one initial information request; and receive the initial information from a user in response to the at least one initial information request. For example, the user device may be caused to display (or otherwise provide) a user interface prompting the user to input the initial information via the user interface. Figure 7B shows an example user interface that may be caused to be displayed on a display of user device 2 during the first device-side output step and / or during receipt of initial information to enable an additional determination step (if included). As shown, the user may be enabled to input initial information in response to an initial information request (Box Serial No.) and also to input the first attempted challenge code (Key No 1), wherein subsequent selection of “GENERATE PIN No 1” may then trigger the generation of the first device one-time password and cause it to be displayed on the device display. In some embodiments, the first device one-time password is only displayed as such if the additional determination step has determined that access to the drug should be granted. In the example shown, the same user interface then allows entry of the second attempted challenge code (Key No 2) to enable the second device-side output step to be initiated (as described in more detail below).

[0120] At processing unit 13 of container system 1, a first comparison step (step B3) is executed. As shown by the dashed arrow labelled “OTP1” in figure 2, for successful completion of this step, the first device one-time password generated in step A3 is the same as OTP1 and is transmitted from the user device 2 to container system 1, such as via a user or directly. In the first comparison step, a received first attempted one-time password is compared with OTP1 as recalled by processing unit 13 (e.g. from a container system memory), to determine if the first attempted onetime password is the same as OTP1.

[0121] At processing unit 13 of container system 1, a second container-side output step (step B4) is executed if it has been determined in the first comparison step (step B3) that the first attempted one-time password is the same as OTP1. In this step, the processing unit 13 causes generation of a second challenge code (CC2), causes the container system 1 to output CC2, and causes generation of a second one-time password (OTP2) based on CC2 using a second cryptographic scheme. The form of the second container-side output step (step B4) is similar to that of the first container-side output step (step B2). Thus, the discussion herein regarding the generation and output of CC1, the generation of OTP 1 and the first cryptographic scheme may be regarded as applicable, mutatis mutandis, to the generation and output of CC2, the generation of OTP2 and the second cryptographic scheme. The second cryptographic scheme may be the same as the first cryptographic scheme, or may be different (such as being based on a different cryptographic algorithm). As described below, derivation of OTP2 by the user and / or user device 2 (not accounting for random guessing) is possible by virtue of step A6 being carried out at the user device 2.

[0122] If it has been determined in the first comparison step (step B3) that the first attempted onetime password is not the same as OTP1, the processing unit 13 is configured not to cause the container system to output CC2. For instance, the processing unit 13 may be configured in this circumstance to end the opening procedure or allow at least one retry of the first attempted onetime password, as described in more detail below.

[0123] At the user device, a main determination step is executed (step A4). Figure 2 shows the main determination step being executed after the first device-side output step (step A3), but the timing of the main determination step is not so limited, as long as the main determination step occurs prior to completion of the second device-side output step (step A6, described below). In the main determination step, user device 2 running authentication application 21 accesses data from database 3, and makes a main determination of whether, based on identifying information and the data from database 3, access to the drug should be granted. The accessing of data from database 3 in this step may comprise accessing database 3 itself (optionally over a network) or may comprise accessing data that has previously been downloaded on user device 2 from database 3. That is, user device 2 running authentication application 21 receives or otherwise accesses identifying information.

[0124] The identifying information may include information provided by the user in possession of the user device 2, and / or may include information available from the user device 2 itself and / or retrievable by network communication, such as time and location information. If the user is required to provide or enable access to the identifying information, this may discourage the user from continuing the attempt to access the drug when access is not appropriate. The identifying information is information that enables determination of whether the attempt to access the drug is legitimate and appropriate or not. For example, the identifying information may relate to the drug and the reason for accessing it, may relate to the time and location at which access is being attempted, may relate to the identity of the user attempting to access the drug, may relate to the identity of the container system, and so on.

[0125] The database 3 contains information indicative of whether access to the drug should be granted on the basis of the identifying information. For instance, the database 3 may be curated by a medical practice (such as a veterinary practice) associated with the container system 1 and / or user that holds information pertaining to authorised uses of drugs. That is, database 3 may hold records of planned appointments involving use of drugs stored in container systems, such that the identifying information may be used in the main determination to determine whether the intended use of the drug by the user corresponds with a planned appointment. Preferably, the identifying information includes information indicating a location of the user device 2 and / or a current time at which the attempt to access the drug in the container is occurring.

[0126] In some embodiments, the identifying information comprises information identifying a location of the user device 2, and the main determination comprises determining whether the location of the user device 2 is within a location range indicated by the data from the database 3. For example, database 3 may contain information indicating specific geographical areas in which access to drugs (e.g. a specific drug indicated in the identifying information) is authorised. This may correspond to a planned appointment location. The information identifying a location of the user device 2 could be received, for example, by input from the user themselves, and / or from global navigation satellite system (GNSS) information accessed by the user device 2.

[0127] In some embodiments, the identifying information comprises information identifying a current time, and the main determination comprises determining whether the current time is within a time range indicated by the data from the database 3. For example, database 3 may contain information indicating specific time ranges at which access to drugs (e.g. a specific drug indicated in the identifying information) is authorised. This may correspond to a planned appointment time. The information identifying the current time could be received, for example, by input from the user themselves, and / or may be accessed from a clock of the user device 2 or accessed over a network.

[0128] In some embodiments, the identifying information comprises information identifying a recipient of a euthanasia drug. That is, the user may be required to input information such as a species and / or a name of a subject to which the drug is intended to be administered. The main determination may then be based on whether or not an authorised use of drugs (e.g. a specific drug indicated in the identifying information) exists on database 3 corresponding to that identified species and / or name. Additionally or alternatively, the identifying information comprises information identifying a dose of a drug, in which case the main determination may be based on whether or not an authorised use of drugs (e.g. a specific drug indicated in the identifying information) exists on database 3 in which the dosage corresponds to that provided.

[0129] In some embodiments, the identifying information comprises information identifying a user (i.e. the user attempting access to the drug) and / or information identifying the container system 1. In such cases, database 3 may include user records and / or container records and the main determination step may involve identifying user and / or container block flags, as is described above in relation to the additional determination. Such embodiments may therefore be particularly advantageous where the additional determination step (step A2) is not included. This may also be seen as the additional determination step forming part of the main determination step rather than being a separate step.

[0130] The identifying information may include a combination of the various kinds of identifying information described herein, with the main determination being made based on a plurality of factors. For instance, the main determination may be positive if a sufficient proportion of the identifying information corresponds with data from database 3 associated with an authorised use of a drug. In some embodiments, the amount of identifying information to be received at the user device 2 for the main determination to be made may be set based on the particular circumstances. For instance, it has been found that misuse of drugs (particularly euthanasia drugs) may be more likely by a medical professional who is working out of their normal working hours or who is on call. Accordingly, database 3 may also store information indicative of normal working hours of users, and / or information indicative of on-call hours of users. Such information may be known to a medical practice who may curate database 3. In such cases, before the main determination is made, the user device 2 running authentication application 21 may be configured to determine a current time (such as from user input, or accessed directly from user device 2 or over a network), access the data from database 3, determine whether the user is out of working hours and / or on call, and set the amount of identifying information required accordingly (such as requiring a greater amount of identifying information if the current time is outside of the user’s working hours or in the user’s on- call hours).

[0131] Alternatively, the user may be required to indicate in the authentication application 21 whether or not the current time is out of the user’s working hours, and / or whether or not the user is currently on call, and this indication may be used to set the amount of identifying information required. The “amount” of identifying information may correspond, for instance, to a number of questions displayed or otherwise communicated to the user to enable the user’s response. That is, when the user is working out of hours or on call, the user device 2 running authentication application 21 may be configured to present a greater number of identifying information questions to the user than would be presented otherwise. Thus, the barriers between the user and the drug may be made greater in cases where misuse is deemed to be more likely.

[0132] The user device running the authentication application may be configured to: cause the user device to output at least one identifying information request; and receive the identifying information from a user in response to the at least one identifying information request. For example, the user device may be caused to display (or otherwise provide) a user interface prompting the user to input the identifying information via the user interface. In some embodiments, the identifying information request is outputted after the user device has outputted the first device one-time password.

[0133] A determination that access to the drug should be granted in the main determination step (positive main determination) must have occurred in order for second device-side output step (step A6) to be completed at the user device 2 running authentication application 21. A positive main determination is represented by (Y) in figure 2.

[0134] At the user device, an auxiliary determination step may also be executed (step A5). Figure

[0135] 2 shows the auxiliary determination being executed after the first device-side output step (step A3), but the timing of the auxiliary determination step (if included) is not so limited, as long as the auxiliary determination step (if included) occurs prior to completion of the second device-side output step (step A6, described below). In the auxiliary determination step, user device 2 running authentication application 21 makes an auxiliary determination of whether, based on wellbeing information, access to the drug should be granted. That is, user device 2 running authentication application 21 receives or otherwise accesses wellbeing information. The wellbeing information may include information provided by the user in possession of the user device 2. Where the user is required to provide the wellbeing information, this requirement may discourage the user from continuing the attempt to access the drug when access is not appropriate. The auxiliary determination step may also involve accessing data from database 3, like in the main determination step.

[0136] The wellbeing information is relevant to a wellbeing state of the user attempting to access the drug. The wellbeing information may be provided by the user to the user device 2 in response to a number of questions displayed or otherwise communicated to the user by the user device 2 running authentication application 21. For example, the wellbeing information may include information indicating a mood of the user as judged by the user themselves, information indicating whether or not the user is alone, and / or any other information that could be used in accordance with known techniques to estimate a wellbeing state of a user. The auxiliary determination may involve comparing the provided wellbeing information with pre -determined responses indicating certain wellbeing states, enabling the assignment of a particular wellbeing state to the user, wherein certain assigned wellbeing states lead to a positive auxiliary determination and certain assigned wellbeing states lead to a negative auxiliary determination.

[0137] In some embodiments, the auxiliary determination comprises calculating a wellbeing score of the user based on the received wellbeing information, and comparing the wellbeing score to a predetermined wellbeing score threshold, wherein if the calculated wellbeing score exceeds the predetermined wellbeing score threshold, the auxiliary determination determines that access to the drug should be granted. The mechanism of scoring and / or the setting of the score threshold may vary depending on use case, such as depending on the drug that is contained in the container. In some embodiments, the calculating the wellbeing score is based on a machine learning model. For example, a machine learning model may be applied which is capable of interpreting responses to wellbeing-related questions presented to the user, and assigning a score (e.g. a percentage score) to indicate the wellbeing of the user. The auxiliary determination may be positive if the wellbeing score is over a predetermined threshold of, for example, 75%. The auxiliary determination may involve presenting psychological questions to the user, prompting answers which can be used to estimate a mood state in accordance with any known technique. In the embodiment shown in figure 2, a determination that access to the drug should be granted in the auxiliary determination step (positive auxiliary determination) is needed for second device-side output step (step A6) to be completed at the user device 2 running authentication application 21. A positive auxiliary determination is represented by (Y) in figure 2.

[0138] The user device running the authentication application may be configured to: cause the user device to output at least one wellbeing information request; and receive the wellbeing information from a user in response to the at least one wellbeing information request. For example, the user device may be caused to display (or otherwise provide) a user interface prompting the user to input the wellbeing information via the user interface. In some embodiments, the wellbeing information request is outputted after the user device has outputted the first device one-time password.

[0139] Figure 7C shows an example user interface that may be caused to be displayed on a display of user device 2 during receipt of identifying information and / or wellbeing information to enable the main determination step and auxiliary determination step (if included). As shown, the user interface displays at least one identifying information request (“Animal Type”, “Reason for Euthanasia”, “Planned Drug and Dose”) and at least one wellbeing information request (“Is anyone else present?”), if included. That is, identifying information requests and wellbeing information requests may be displayed simultaneously on a same user interface.

[0140] At the user device 2 running authentication application 21, a second device-side output step (step A6) is executed. As shown by the dashed arrow labelled “CC2” in figure 2, completion of the second device-side step in a way that leads to opening of the container 11 involves CC2 being transmitted from container system 1 to user device 2, which transmission may be via a user or may be direct. In the second device-side output step, in response to receiving a second attempted challenge code, user device 2 running authentication application 21 causes generation of a second device one-time password based on the second attempted challenge code, and causes the user device to output the second device one-time password. The generation of the second device onetime password uses the second cryptographic scheme, that is, the same second cryptographic scheme used by container system 1 to generate OTP2. Accordingly, this step will only result in generation and output of a second device one-time password that is the same as OTP2 if the second attempted challenge code received at user device 2 is the same as CC2 generated at the container system in step B4. An example user interface that may be displayed on user device 2 during this step is shown in figure 7D. As shown, the user may be enabled to input the second attempted challenge code, wherein subsequent selection of “GENERATE PIN No 2” may then trigger the generation of the second device one-time password and cause it to be displayed on the device display. User device 2 running authentication application 21 is configured to execute the second device-side output step (step A6) when the main determination has determined that access to the drug should be granted. That is, the second device-side step can only be executed to completion (by the causing of output of the second device one-time password) when the main determination step (step A4) has occurred and resulted in a positive main determination. In some embodiments, the receiving of the second attempted challenge code and / or the causing generation of the second device one-time password at user device 2 running authentication application 21 may be executed at a time when the main determination step has not occurred or has occurred and resulted in a negative main determination, but the output of the second device one-time password still cannot be performed unless or until a positive main determination has been made. In other embodiments, no part of the second device-side output step may be executed unless or until a positive main determination has been made.

[0141] In general, when the main determination step has determined that access to the drug should not be granted (negative main determination), user device 2 running authentication application 21 is configured not to cause output of the second device one-time password. For example, user device 2 running authentication application 21 may in this circumstance be configured not to cause output of the second device one-time password at all (ending the procedure at the user device 2 without enabling unlocking of the container 11), or configured not to cause output of the second device one-time password until a positive main determination has been made (i.e. the main determination step may be repeated on the basis of new identifying information, as described in more detail below). In cases where the main determination step is repeated on the basis of new identifying information, the second device-side output step may only be executed to completion if the most recent main determination step has resulted in a positive main determination.

[0142] The same is true of the second device-side output step (step A6) with regard to the auxiliary determination step (step A5), if included. That is, when the auxiliary determination step is included, user device 2 running authentication application 21 is configured to execute the second device-side output step (step A6) when the auxiliary determination has determined that access to the drug should be granted. That is, in such embodiments, the second device-side step can only be executed to completion (by the causing of output of the second device one-time password) when the auxiliary determination step has occurred and resulted in a positive auxiliary determination. In such embodiments, when the auxiliary determination step has determined that access to the drug should not be granted (negative auxiliary determination), user device 2 running authentication application 21 is configured not to cause output of the second device one-time password (either at all or until a positive auxiliary determination has been made upon a retry), even if a positive main determination has been made. That is, when the auxiliary determination step is included, a combination of a positive main determination and a positive auxiliary determination enable the output of the second device one-time password.

[0143] The same is true of the second device-side output step (step A6) with regard to the additional determination step (step A2), if included. That is, when the additional determination step is included, user device 2 running authentication application 21 is configured to execute the second device-side output step (step A6) when the additional determination has determined that access to the drug should be granted. That is, in such embodiments, the second device-side step can only be executed to completion (by the causing of output of the second device one-time password) when the additional determination step has occurred and resulted in a positive additional determination. In such embodiments, when the additional determination step has determined that access to the drug should not be granted (negative additional determination), user device 2 running authentication application 21 is configured not to cause output of the second device one-time password (either at all or until a positive additional determination has been made upon a retry), even if a positive main and / or auxiliary determination has been made. That is, when the additional determination step is included, a combination of a positive main determination and a positive additional determination (and a positive auxiliary determination, if included) enable the output of the second device one-time password.

[0144] In the embodiment depicted in figure 2, the additional determination step occurs before the first device-side output step (step A3), in which case a negative additional determination may result in failure of the opening procedure at a stage earlier than the causing of output of the second device one-time password. For instance, in the depicted embodiment, when a negative additional determination has been made, the user device running authentication application 21 may also be configured not to cause output of the first device one-time password.

[0145] At processing unit 13 of container system 1, a second comparison step is executed (step B5). As shown by the dashed arrow labelled “OTP2” in figure 2, successful completion of this step means that the second device one-time password generated in step A6 is the same as OTP2 and is transmitted from the user device 2 to container system 1, such as via a user or directly. In the second comparison step, a received second attempted one-time password is compared with OTP2 as recalled by processing unit 13 (e.g. from a container system memory), to determine if the second attempted one-time password is the same as OTP2.

[0146] At processing unit 13 of container system 1, an unlocking step is executed (step B6) if it has been determined in the second comparison step (step B5) that the second attempted one-time password is the same as OTP2. The unlocking step comprises, at processing unit 13, causing locking mechanism 12 to unlock container 11. Accordingly, upon correct receipt of OTP2, the container 11 is caused to be unlocked and may be adjusted to the open state to allow access to contents internal to the container 11, including the drug. The user may then retrieve the drug and perform the intended procedure. The steps prior to the unlocking step in order to reach the unlocking step may have discouraged a user attempting an illegitimate access to the drug from continuing the attempt.

[0147] If it has been determined in the second comparison step (step B5) that the second attempted one-time password is not the same as OTP2, the processing unit 13 is configured to cause the locking mechanism to maintain the locked state. For instance, the processing unit 13 may be configured in this circumstance to end the opening procedure or allow at least one retry of the second attempted one-time password, as described in more detail below.

[0148] At user device 2 running authentication application 21, after output of the second device one-time password in step A6, supplementary information may be received (step A7) and caused to be stored in database 3. The supplementary information may be, for example, information pertaining to how the drug has been used after it has been accessed from the open container. For example, after causing the user device 2 to output the second device one-time password, user device 2 running authentication application 21 may display or otherwise communicate a request for the supplementary information to the user. This step may be useful for record-keeping purposes, particularly for medical practices where it is desirable to keep records of past uses of drugs. For example, the supplementary information may include a dose, confirmation that drugs have been returned to the container, confirmation that the container has been closed and locked, and any additional notes. An exemplary user interface that may be displayed on user device 2 during this step is shown in figure 7E. As shown, following input in the user interface of supplementary information, selection of “SAVE & LOG OUT” may cause the supplementary information to be stored in the database 3 and end running of the authentication application 21.

[0149] Generally, the main determination step (step A4) is not limited to being executed at the point in the container opening procedure at which it is shown in figure 2. The main determination step may be executed at a time when output of neither the first nor second device one-time password has been caused, or may be executed at a time when output of the first device one-time password has been caused but output of the second device one-time password has not been caused. For instance, the main determination may be executed prior to output of the first device one-time password, such that the user device 2 running authentication application 21 may then be configured not to cause output of the first device one-time password unless or until a positive main determination has been made. The same is true of the auxiliary determination step (if included) and additional determination step (if included). The auxiliary determination (if included) may occur alongside the main determination or at a different time in the opening procedure. The additional determination (if included) may occur alongside the main determination or at a different time in the opening procedure.

[0150] Likewise, the point in the opening procedure at which a positive main determination is needed for the procedure at user device 2 to continue is also not particularly limited. At the latest, the main determination being negative results only in the causing of the output of the second device one-time password not to be executed. In some embodiments, a negative main determination may halt the opening procedure earlier such that more than just the output of the second device one-time password requires a positive main determination to have occurred. For example, in some embodiments, user device 2 running authentication application 21 is configured to receive the second attempted challenge code only when the main determination step (e.g. most recent main determination step) has determined that access to the drug should be granted. In some embodiments, the user device 2 running authentication application 21 is configured to complete the first device-side output step (by causing output of the first device one-time password) only when the main determination step (e.g. most recent main determination step) has determined that access to the drug should be granted. In some embodiments, the first device-side output step and receipt of the second attempted challenge code may still be executed even when the main determination step has occurred and resulted in a negative main determination, as long as the second device onetime password is then not caused to be outputted (i.e. the second device-side output step is not executed to completion), either at all or until a positive main determination has been made. The same is true of the auxiliary determination step (if included) and the additional determination step (if included).

[0151] In some embodiments, user device 2 running authentication application 21 is configured to execute the first device-side output step (step A3) when (e.g. only when) either the main determination has determined that access to the euthanasia drug should be granted or the main determination has not been made. This means that, if the main determination step happens at a time when output of the first device one-time password has not been caused, user device 2 running authentication application 21 is configured not to output the first device one-time password (e.g. until a positive main determination has been made), whereas if the main determination step happens at a time when output of the first device one-time password has been caused, the output of the first device one-time password is not reliant on a positive main determination (because the main determination happens afterwards). In other embodiments, a negative main determination at a time when the output of the first device one-time password has not been caused does not prevent the causing of the output of the first device one-time password. The same is true, mutatis mutandis, with regard to the auxiliary determination step (if included) and additional determination step (if included). Likewise, the point in the opening procedure at which the identifying information is obtained by user device 2 running authentication application 21 is not particularly limited. Even if the main determination is made after the output of the first device one-time password, the receipt of the identifying information may have occurred prior to the output of the first device one-time password, for instance. For instance, when the identifying information is provided by a user through a user interface displayed on the user device 2, the user interface enabling input of the identifying information may be displayed to the user at any point prior to or during the making of the main determination. Preferably, the displaying of such a user interface to the user occurs after the output of the first device one-time password. The same is true of the wellbeing information (as used in the auxiliary determination, if included) and the initial information (as used in the additional determination, if included).

[0152] Figure 3 depicts steps that may occur following a negative determination (indicated by (N)) in either the main determination step, auxiliary determination step (if included) or additional determination step (if included). These steps are referred to collectively as “determination step”. The teachings of figure 3 may therefore apply to any one of, or all of, the main determination step, auxiliary determination step, and additional determination step. Figure 2 only depicts the results of positive determinations in these steps.

[0153] As shown in figure 3, a negative determination in a determination step (e.g. main determination step) may result in the user device 2 running authentication application 21 allowing a retry (step A8). In such a step, user device 2 running authentication application 21 is configured to receive new information (e.g. new identifying information) to replace the identifying information used in the previous determination step, and repeat the determination step on the basis of the newly-received information and data from the database 3. A positive determination in the repeated determination step may then allow the procedure as shown in figure 2 to continue, with the previous negative determination being disregarded in favour of the most recent positive determination. Such a configuration may allow for a certain degree of user error in providing the identifying information, and allow such errors to be corrected without requiring a full restart of the opening procedure. User device 2 running authentication application 21 may be configured to allow a certain number of retries of a determination step, before ending the opening procedure (step A9). For example, user device 2 running authentication application 21 may allow one repeat of the determination step, wherein if the repeated determination step is also negative, the running of the authentication application 21 is ended.

[0154] As also shown in figure 3, a negative determination in a determination step (e.g. main determination step) may result in the user device 2 running authentication application 21 ending the opening procedure (step A9). This means that the procedure at the user device 2 as shown in figure 2 does not progress to the step following the determination step that has resulted in the negative determination. For example, the running of the authentication application 21 on user device 2 may be caused to end, such as by logging out the user, or closing the application. The user device 2 running authentication application 21 may be configured only to initiate this step after a certain number of retry steps (step A8) have occurred in respect of the determination step. Such a configuration may be implemented to prevent excessive retries of gaining access to the drug.

[0155] As also shown in figure 3, a negative determination in a determination step (e.g. main determination step) may result in the user device 2 running authentication application 21 causing a notification to be sent to a medical practice (e.g. veterinary practice) indicating that a failed attempt has been made to access the drug (step A10). The notification may be sent, for example, over a network to a computing device associated with the medical practice. If the determination that access to the drug should not be granted is made at a time when communication over a network is not possible by the user device 2, the user device running the authentication application 21 may be configured to cause the notification to be sent when communication over the network becomes possible. Additionally or alternatively, the negative determination may result in the user device 2 running authentication application 21 causing data indicating that a failed attempt has been made to access the drug to be stored in database 3 (step Al 1). Such notifications and / or stored data may include the information that resulted in the negative determination (i.e. identifying information, wellbeing information and / or initial information). These steps may be useful and convenient for automated monitoring and record keeping purposes at the medical practice.

[0156] In some embodiments, notifications may be sent to a medical practice and / or data caused to be stored in database 3 in response to successful completions of steps, such as when the first device one-time password is caused to be outputted and / or when the second device one-time password is caused to be outputted. Such also steps may also be useful and convenient for monitoring and record keeping purposes.

[0157] Figure 4 depicts steps that may occur following a negative result (indicated by (N)) in either the first comparison step or second comparison step at the processing unit 13 of container system 1. These steps are referred to collectively as “comparison step”. The teachings of figure 4 may therefore apply to either or both of the first and second comparison step. Figure 2 only depicts the results of positive results in these steps (indicated by (Y) in figure 2).

[0158] As shown in figure 4, a negative result in a comparison step (e.g. at least one of the first comparison step and second comparison step) may result in the processing unit 13 allowing a retry (step B7). In such a step, processing unit 13 is configured to receive a further attempted one-time password (i.e. first or second attempted one-time password) to replace the one-time password used in the previous comparison step, and repeat the comparison step on the basis of the further atempted one-time password. A positive result in the repeated comparison step may then allow the procedure as shown in figure 2 to continue, with the previous negative result being disregarded in favour of the most recent positive result. Such a configuration can account for a degree of user error made when entering the container one-time password in the container system 11, and allow such errors to be corrected without requiring a full restart of the opening procedure. Processing unit 13 may be configured to allow a certain number of retries of a comparison step, before ending the opening procedure (step B8).

[0159] As also shown in figure 4, a negative result in a comparison step (e.g. at least one of the first comparison step and second comparison step) may result in the processing unit 13 ending the opening procedure (step B8). This means that the procedure at the processing unit 13 as shown in figure 2 does not progress to the step following the comparison step that has had the negative result. For example, the respective container one-time password that has to be recalled to make the comparison step may be deleted from the container system, such as from a container system memory, such that the recall is no longer possible and the opening procedure must be started again with newly generated one-time passwords. The respective challenge code from which the container one-time password has been generated may also be caused to be deleted, if it has been stored. The processing unit 13 may be configured only to initiate this step after a certain number of retry steps (step B7) have occurred in respect of the comparison step. Such embodiments may prevent excessive retries of atempted one-time passwords.

[0160] The system may be configured to execute various of the above-described steps without connection to the internet. In particular, the container system 1, which accommodates the drug, may be configured to execute all of its processes without internet connection. The container system 1 may be provided without internet connection capability. This eliminates the possibility of unauthorised access to the container contents via internet-based hacking methods. The system may therefore be capable of being operated when no connection to the internet is available. This may be beneficial when the system is used in remote geographical areas.

[0161] The capability for remote or digital communication of the container system 1 may be limited to near-field communication, such as with the user device in the proximity of the container system. Alternatively, the container system may be provided without any means for remote or digital communication with other devices at all (such that information is only provided to and outputed from the container system by direct (e.g. manual) input from a user).

[0162] The container system may be configured to be incapable of digitally transmiting the challenge codes directly to other devices (such as the user device). The container system may be configured to be incapable of receiving atempted one-time passwords directly from other devices (such as the user device) by digital transmission. That is, the container system may output challenge codes only by presenting them for a user (who is then able to input a corresponding challenge code into the user device), and may receive attempted one-time passwords only by input from a user directly into the container system (e.g. manual input using a keypad).

[0163] In some embodiments there is no bidirectional communication link (e.g. bidirectional radio link) between the user device and the container system. There may be no radio link at all between the user device and the container system.

[0164] The database 3 may be remote from the container system, remote from the user device, or remote from both the container system and the user device. The user device may access the remote database at a time when the user device is connected to the internet, and download data from the database. Then, when the main determination step is being carried out, the user device can access the data from the database that has been previously downloaded on the device (in which case the user device does not require internet connection at the time of the main determination). Alternatively, or additionally, the user device may access the remote database over the network at the time of the main determination, such that information is accessed directly from the remote database at the time of use of the system.

[0165] The database 3 may be remote from the container system. The container system may be isolated from the database, meaning that the container system is incapable of accessing the database (i.e. the database is inaccessible to the container system).

[0166] In the above-described processes for unlocking the container system 1, the exchange of information between the user device 2 and the container system 1 may generally be carried out via a user, through use of respective user interfaces at the user device and the container system.

[0167] That is, when the processing unit of the container system causes output of a challenge code, the challenge code may be displayed (or otherwise presented) to the user via information presenting means of the container system, such as output device 15. This may occur without direct electronic transmission of the challenge code to the user device. Then, the corresponding “attempted” challenge code received at the user device is a challenge code that has been inputted into the user device by the user, via a user interface of the user device, such as a touchscreen or audio input means. If the user’s attempt matches the challenge code that was presented by the container system, then the corresponding one-time password generated at the user device should match that generated at the container system. The user device may provide the user interface, enabling input of the attempted challenge code, at the start of the corresponding device-side output step as described herein.

[0168] Likewise, when the user device outputs a device one-time password, the device one-time password may be displayed (or otherwise presented) to the user via display means (or other information presenting means) of the user device. This may occur without direct electronic transmission of the device one-time password to the container system. Then, the corresponding “attempted” one-time password received at the processing unit of the container system is a onetime password that has been inputted into the container system by the user, via a user interface of the container system, such as input device 14. If the user’s attempt matches the device one-time password that was presented by the user device (and the corresponding attempted challenge code entered in the user device had matched the challenge code which was outputted from the container system), then the user’s attempt succeeds. The container system may provide the user interface, enabling input of the attempted one-time password, at the start of the corresponding comparison step as described herein.

[0169] The various determination steps described herein may be executed based on information inputted directly into the user device by the user, via a user interface of the user device.

[0170] The identifying information used in the above -de scribed main determination step may be information that the user has inputted via a user interface of the user device. For example, the user device may allow the user to input identifying information by typing the identifying information, selecting the identifying information from options presented on the user interface, dictating the identifying information, etc. As part of the step, the user device may display (or otherwise present) one or more user interfaces which prompt the user to input the identifying information. For example, the user device may display a question, a text insertion area and a keyboard, enabling the user to answer the question (thereby providing the identifying information) by typing in the text insertion area using the keyboard. By requiring the input of identifying information directly by the user, additional delay is introduced to the overall process, allowing for reflection and due process to be completed.

[0171] Additionally, or alternatively, the wellbeing information required for the above-described auxiliary determination step may be information that the user has inputted via a user interface of the user device. As part of the step, the user device may display (or otherwise present) one or more user interfaces which prompt the user to input the wellbeing information. The means of presentation and input described above in relation to the main determination step are applicable mutatis mutandis.

[0172] Additionally, or alternatively, the initial information required for the above-described additional determination step may be information that the user has inputted via a user interface of the user device. As part of the step, the user device may display (or otherwise present) one or more user interfaces which prompt the user to input the initial information. The means of presentation and input described above in relation to the main determination step are applicable mutatis mutandis. The system described herein may implement known suicide risk screening tools, such as the Columbia Protocol, as an additional authentication / authorisation factor. For example, the user device running the authentication application may be configured to verify that the user has an up- to-date authorisation from a central regulatory authority, such as a veterinary standards authority. The authorisation may include, for example, RCV S Practice Standards Medicine Module training, continuing professional development, or an up-to-date run-through the Columbia protocol. The verification may be made by looking up the user (whose identity has been provided to the user device, e.g. in the initial information or the identifying information) in a database which indicates persons that are and are not authorised. If an up-to-date authorisation is not found, the user device running the authentication application may be configured to present a user interface which runs the user through the Columbia protocol or another suicide risk assessment. Such risk screening tools may be implemented as the auxiliary determination (whereby the user’s responses to the risk assessment corresponds to wellbeing information).

[0173] As a further authentication / authorisation factor, the user device running the authorisation application may perform a scan (e.g. a Bluetooth or WiFi scan) to determine whether there are other user devices (and hence other people) in the vicinity of the user attempting to access the container. For example, the user device running the authentication application may scan local WiFi and Bluetooth traffic to create a measure of busyness or footfall, to determine if the user is alone or with others. The scan may correspond to a predefined radius around the user device. Based on the scan results, the user device may apply a lower security requirement if the area is busy, and a higher security requirement if the area is not busy. For example, the other authentication factors may be scaled according to the busyness of the area. That is, the amount of identifying information required for the main determination may be set based on the busyness of the area, with less identifying information being required if the area is busy, and vice versa. Similarly, the amount of wellbeing information required for the auxiliary determination (if used) may be set based on the busyness of the area, in a corresponding way.

[0174] As a further authentication / authorisation factor, the user device running the authentication application may require verification that the user device is in the proximity of the container system (e.g. within a predefined radius). For example, the container system may contain a Bluetooth radio (or similar) that transmits a Bluetooth “advert” when in use. A container system ID may be encrypted in the Bluetooth advert. The user device running the authentication application may scan for Bluetooth adverts, and thereby verify that the user and the container system are in the same location, before permitting access. For example, this step may be performed before the user device running the authentication application is enabled to receive a first attempted challenge code.

[0175] Additionally, or alternatively, this step may be performed as part of the main determination step. The user device running the authentication application may continuously or repeatedly perform the location verification (e.g. by continuously or repeatedly scanning for the Bluetooth advert during the authentication process), to verify that the user does not leave the vicinity of the container system during the authentication process. By verifying that the user and the container are in the same location as part of the opening process, access codes are prevented from being granted over the phone by a third party.

[0176] The container system may be configured to provide reports on various aspects of the status of the container system. For example, the container system may report on battery state, fill state, failed attempts to open the container previously, temperature data (e.g. instances of temperature within the box exceeding a threshold temperature for safe storage of the drug). Such information may be reported to the user device.

[0177] The container system may provide such reports to the user device by encrypting or “hiding” the relevant information within challenge codes (which are then provided to the user device, e.g. by a user). That is, a challenge code (e.g. the first challenge code or second challenge code, or both) generated by the container system may contain at least one status indication, that is recognisable by the user device running the authentication application when said challenge code is inputted into the user device. For example, the status indication may correspond to a value of a particular digit of the challenge code. For example, any of the “random” or pseudo-random challenge codes generated by the container system may contain one or more digits that are not random, and instead are set based on the status to be indicated (e.g. the first digit of the challenge code may represent the current battery level of the container system). Upon receipt of the challenge code, the user device running the authentication application may be configured to recognise the meaning of the non-random digit (e.g. recognise that the first digit corresponds to the battery level), and thus be informed of the status indication. The status indication may then be provided to the user, stored in a database, etc. Various types of status indication may be hidden within challenge codes, including fill state, number and timing of failed attempts to access the drug, instances of temperature falling outside safe levels for drug storage, etc. The receipt of the status indication by the user device running the authentication application may prompt a notification to the user. For example, if the container system has low battery, the user device may provide a battery charge notification.

[0178] The user device may be capable of providing information to the container system by “hiding” it in one-time passwords, in a corresponding way to that described above. That is, generally, data can be hidden in keys and responses in either direction to report battery state, fill state, failed attempts, temperature exceedances, etc. The container system may also transmit status indications in Bluetooth adverts. That is, the container system may send a Bluetooth advert (continuously, or at set intervals, or upon activation of the container system), containing information about the state of the container system (battery state, temperature data, failed attempts to open the box previously, etc). Transmission by Bluetooth may allow for detailed telemetry to be sent to the authentication application and beyond (e.g. to a veterinary practice) from the container system. For example, the container system electronics may wake at predetermined intervals (e.g. once per hour) to measure temperature inside the container, and temperature trends may be stored for transmission to a user device in such a Bluetooth advert. This information may be reported onwards, such as to a veterinary practice, to give an indication of whether drugs have been correctly stored.

[0179] In the above embodiments, the computational steps associated with initiation and running of authentication application 21 may be implemented in a wide variety of operating environments, which in some cases can include one or more user computers, computing devices, or processing devices which can be used to operate any of a number of applications. User devices can include any of a number of general-purpose personal computers, such as desktop or laptop computers running a standard operating system, as well as cellular, wireless, and handheld devices running mobile software and capable of supporting a number of networking and messaging protocols. Such a system also can include a number of workstations running any of a variety of commercially- available operating systems and other known applications for purposes such as development and datastore management.

[0180] Various computational aspects also can be implemented as part of at least one service or Web service, such as may be part of a service-oriented architecture. Services such as Web services can communicate using any appropriate type of messaging, such as by using messages in extensible markup language (XML) format and exchanged using an appropriate protocol such as SOAP (derived from the "Simple Object Access Protocol"). Processes provided or executed by such services can be written in any appropriate language, such as the Web Services Description Language (WSDL). Using a language such as WSDL allows for functionality such as the automated generation of client-side code in various SOAP frameworks. Alternatively, more modem technology stacks such as JSON messages and OpenAPI standards may be used to define the APIs used.

[0181] In embodiments utilising a Web server, the Web server can run any of a variety of server or mid-tier applications, including HTTP servers, FTP servers, CGI servers, data servers, Java in servers, and business application servers. The server(s) also may be capable of executing programs or scripts in response requests from user devices, such as by executing one or more Web applications that may be implemented as one or more scripts or programs written in any programming language, such as Java®, C, C# or C++, typescript, javascript or any other language, such as Node, Go, Perl, Python, or TCL, as well as combinations thereof. The server(s) may also include datastore servers, including without limitation open source datastores such as or MySQL or PostgresSQL or those commercially available e.g. from Oracle®, Microsoft®, Sybase®, and IBM®.

[0182] The operating environment can include a variety of data stores and other memory and storage media as discussed above. These can reside in a variety of locations, such as on a storage medium local to (and / or resident in) one or more of the computers or remote from any or all of the computers across the network, or on a third-party provided cloud platform such as Azure or AWS. In a particular set of embodiments, the information may reside in a storage-area network (“SAN”) familiar to those skilled in the art. Similarly, any necessary files for performing the functions attributed to the computers, servers, or other network devices may be stored locally and / or remotely, as appropriate. Where a system includes computerised devices, each such device can include hardware elements that may be electrically coupled via a bus, the elements including, for example, at least one central processing unit (CPU), at least one input device (e.g., a mouse, keyboard, controller, touch screen, or keypad), and at least one output device (e.g., a display device, printer, or speaker). Such a system may also include one or more storage devices, such as disk drives, optical storage devices, and solid-state storage devices such as random access memory (“RAM”) or read-only memory (“ROM”), as well as removable media devices, memory cards, flash cards, etc.

[0183] Such devices also can include a computer-readable storage media reader, a communications device (e.g., a modem, a network card (wireless or wired), an infrared communication device, etc.), and working memory as described above. The computer-readable storage media reader can be connected with, or configured to receive, a computer-readable storage medium, representing remote, local, fixed, and / or removable storage devices as well as storage media for temporarily and / or more permanently containing, storing, transmitting, and retrieving computer-readable information. The system and various devices also typically will include a number of software applications, modules, services, or other elements located within at least one working memory device, including an operating system and application programs. It should be appreciated that alternate embodiments may have numerous variations from that described above. For example, customized hardware might also be used and / or particular elements might be implemented in hardware, software (including portable software, such as applets), or both. Further, connection to other computing devices such as network input / output devices may be employed.

[0184] Storage media and other non-transitory computer readable media for containing code, or portions of code, can include any appropriate media known or used in the art, such as but not limited to volatile and non-volatile, removable and non-removable non-transitory media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules, or other data, including RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by the a system device. Based on the disclosure and teachings provided herein, a person of ordinary skill in the art will appreciate other ways and / or methods to implement the various embodiments. Computational tasks performed as part of the above description may be performed by more than one computing device serially or concurrently. If performed on a computer system comprising multiple computers, these computers may be co-located or distributed. The invention can be implemented wholly in a client computer, on a server computer, or a combination of client and server side processing. Having described the invention it will be appreciated that variations may be made on the above described embodiments, which are not intended to be limiting. The invention is defined in the appended claims and their equivalents.

Claims

Claims1. A system for restricting access to a drug, the system comprising: a container system comprising a container that is adjustable between an open state and a closed state and configured to contain the drug, a locking mechanism configured to lock the container in the closed state, and a processing unit configured to cause actuation of the locking mechanism; and a user device storing an authentication application, wherein the system is configured, when the container is locked in the closed state and contains the drug, to execute: at the user device running the authentication application, a main determination step of accessing data from a database and making a main determination of whether, based on identifying information and the data from the database, access to the drug should be granted; at the processing unit, a first container-side output step of causing generation of a first challenge code, causing the container system to output the first challenge code, and causing generation of a first container one-time password based on the first challenge code using a first cryptographic scheme; at the user device running the authentication application, a first device-side output step of, in response to receiving a first attempted challenge code, causing generation of a first device one-time password based on the first attempted challenge code using the first cryptographic scheme, and causing the user device to output the first device one-time password; at the processing unit, a first comparison step of, in response to receiving a first attempted one-time password, determining whether the first attempted one-time password is the same as the first container one-time password; at the processing unit, when the first attempted one-time password is determined to be the same as the first container one-time password, a second container-side output step of causing generation of a second challenge code, causing the container system to output the second challenge code, and causing generation of a second container one-time password based on the second challenge code using a second cryptographic scheme;at the user device running the authentication application, when the main determination has determined that access to the drug should be granted, a second deviceside output step of, in response to receiving a second attempted challenge code, causing generation of a second device one-time password based on the second attempted challenge code using the second cryptographic scheme, and causing the user device to output the second device one-time password; at the processing unit, a second comparison step of, in response to receiving a second attempted one-time password, determining whether the second attempted one-time password is the same as the second container one-time password; and at the processing unit, when the second attempted one-time password is determined to be the same as the second container one-time password, an unlocking step of causing the locking mechanism to unlock the container.

2. The system of claim 1, wherein the user device running the authentication application is configured to make the main determination after the causing the user device to output the first device one-time password.

3. The system of any preceding claim, wherein the identifying information comprises at least one of: information identifying a user; information identifying the container system; information identifying a location of the user device and / or the container system; information identifying a recipient of a drug; information identifying a drug; information identifying a dose of a drug; information identifying a current time; information identifying an on-call status of the user.

4. The system of any preceding claim, wherein the identifying information comprises information identifying a location of the user device, and the main determination comprises determining whether the location of the user device is within a location range indicated by the data from the database.

5. The system of any preceding claim, wherein the identifying information comprises information identifying a current time, and the main determination comprises determining whether the current time is within a time range indicated by the data from the database.

6. The system of any preceding claim, wherein the user device running the authentication application is configured to execute an auxiliary determination step of making an auxiliary determination of whether, based on wellbeing information, access to the drug should be granted,wherein the user device running the authentication application is configured to execute the second device-side output step when the auxiliary determination has determined that access to the drug should be granted.

7. The system of claim 6, wherein the auxiliary determination comprises calculating a wellbeing score of the user based on the received wellbeing information, and comparing the wellbeing score to a predetermined wellbeing score threshold, wherein if the calculated wellbeing score exceeds the predetermined wellbeing score threshold, the auxiliary determination determines that access to the drug should be granted, optionally wherein the calculating the wellbeing score is based on a machine learning model.

8. The system of any preceding claim, wherein the user device running the authentication application is configured to execute an additional determination step of accessing the data from the database and make an additional determination of whether, based on initial information and the data from the database, access to the drug should be granted, wherein the user device running the authentication application is configured to execute the second device-side output step when the additional determination has determined that access to the drug should be granted.

9. The system of claim 8, wherein: the initial information comprises information identifying the container system, and the additional determination comprises locating, in the data from the database, a container record associated with the container system, determining whether the located container record comprises a container block flag, and if the located container record is determined to comprise a container block flag, determining that access to the drug should not be granted; and / or the initial information comprises information identifying a user of the user device, and the additional determination comprises locating, in the data from the database, a user record associated with the user, determining whether the located user record comprises a user block flag, and if the located user record is determined to comprise a user block flag, determining that access to the drug should not be granted.

10. The system of any preceding claim, wherein the database is remote from the user device and the container system, and the user device running the authentication application is configured to access the data from the database by accessing the database over a network.

11. The system of any preceding claim, configured to execute a further step of causing the data from the database to be transferred from the database at a remote location to a memory of the user device over a network, wherein the user device running the authentication application is configured to access the data from the database from the memory of the user device.

12. The system of any preceding claim, wherein the user device running the authentication application is configured, when the main determination has determined that access to the drug should not be granted, to receive new identifying information, and repeat the main determination step on the basis of newly-received identifying information and the data from the database.

13. The system of any preceding claim, wherein: the processing unit is configured, when the first attempted one-time password is determined not to be the same as the first container one-time password, to receive a further first attempted one-time password, and repeat the first comparison step on the basis of the further first attempted one-time password; and / or the processing unit is configured, when the second attempted one-time password is determined not to be the same as the second container one-time password, to receive a further second attempted one-time password, and repeat the second comparison step on the basis of the further second attempted one-time password.

14. The system of any preceding claim, wherein the user device running the authentication application is configured, following a determination that access to the drug should not be granted, to cause a notification to be sent to a medical practice indicating that a failed attempt has been made to access the drug and / or to cause data indicating that a failed attempt has been made to access the drug to be stored in the database.

15. The system of any preceding claim, wherein the user device running the authentication application is configured, after causing the user device to output the second device one-time password, to cause a notification to be sent to a medical practice indicating that access to the drug has been granted and / or to cause data indicating that access to the drug has been granted to be stored in the database.

16. The system of any preceding claim, wherein the user device running the authentication application is configured, after causing the user device to output the second device one-time password, to receive supplementary information, and cause the supplementary information to be stored in the database.

17. The system of any preceding claim, wherein the user device running the authentication application is configured to receive a user login request, determine whether the user login request is valid, and if the user login request is valid, enable the main determination to be made.

18. The system of any preceding claim, wherein the user device running the authentication application is configured to receive at least some of the identifying information from a user.

19. The system of any preceding claim, wherein the container system comprises at least one of: a container input device for receiving the first attempted one-time password and the second attempted one-time password; a container display, wherein the processing unit is configured to cause the first challenge code to be displayed on the container display and to cause the second challenge code to be displayed on the container display; and a handle for enabling a user to transport the container system.

20. The system of any preceding claim, wherein the container system is a unit dimensioned so as to fit inside a volume defined by orthogonal sides of length Im x 0.5m x 0.5m.

21. The system of any preceding claim, wherein the processing unit is configured to cause the first challenge code to be randomly generated, and / or wherein the processing unit is configured to cause the second challenge code to be randomly generated.

22. The system of any preceding claim, wherein the first cryptographic scheme and / or the second cryptographic scheme corresponds to a HMAC-based one-time password (HOTP) algorithm, optionally in which the HMAC is computed by a secure hash algorithm (SHA).

23. The system of any preceding claim, wherein the user device running the authentication application is configured to: cause the user device to output at least one identifying information request; and receive the identifying information from a user in response to the at least one identifying information request.

24. The system of any preceding claim, wherein in the main determination step, the user device running the authentication application is configured to receive the identifying information from a user via a user interface provided at the user device.

25. The system of any preceding claim, wherein:in the first device-side output step, the user device running the authentication application is configured to receive the first attempted challenge code from a user via a user interface provided at the user device; and / or in the second device-side output step, the user device running the authentication application is configured to receive the second attempted challenge code from a user via a user interface provided at the user device.

26. The system of any preceding claim, wherein: in the first comparison step, the processing unit is configured to receive the first attempted one-time password from a user via input means provided at the container system; and / or in the second comparison step, the processing unit is configured to receive the second attempted one-time password from a user via input means provided at the container system.

27. A container system comprising: a container that is adjustable between an open state and a closed state and contains a drug; a locking mechanism configured to lock the container in the closed state; and a processing unit configured to cause actuation of the locking mechanism, wherein the processing unit is configured to execute steps of: when the container is locked in the closed state, causing generation of a first challenge code, causing the container system to output the first challenge code, and causing generation of a first container one-time password based on the first challenge code using a first cryptographic scheme; in response to receiving a first attempted one-time password, determining whether the first attempted one-time password is the same as the first container one-time password; when the first attempted one-time password is determined to be the same as the first container one-time password, causing generation of a second challenge code, causing the container system to output the second challenge code, and causing generation of a second container one-time password based on the second challenge code using a second cryptographic scheme;in response to receiving a second attempted one-time password, determining whether the second attempted one-time password is the same as the second container onetime password; and when the second attempted one-time password is determined to be the same as the second container one-time password, causing the locking mechanism to unlock the container.

28. A computer program comprising instructions which, when the program is executed by a user device, cause the user device to execute steps of: accessing data from a database, and making a main determination of whether, based on identifying information and the data from the database, access to a drug should be granted; in response to receiving a first attempted challenge code, causing generation of a first device one-time password based on the first attempted challenge code using a first cryptographic scheme, and causing the user device to output the first device one-time password; and when the main determination has determined that access to the drug should be granted, in response to receiving a second attempted challenge code, causing generation of a second device one-time password based on the second attempted challenge code using a second cryptographic scheme, and causing the user device to output the second device one-time password.

29. A method of restricting access to a drug, the method comprising: a step of providing a container system comprising a container that is adjustable between an open state and a closed state and configured to contain the drug, a locking mechanism configured to lock the container in the closed state, and a processing unit configured to cause actuation of the locking mechanism; at a user device running the authentication application, a main determination step of accessing data from a database and making a main determination of whether, based on identifying information and the data from the database, access to the drug should be granted; at the processing unit, when the container is locked in the closed state and contains the drug, a first container-side output step of causing generation of a first challenge code, causing the container system to output the first challenge code, and causing generation of a first container onetime password based on the first challenge code using a first cryptographic scheme;at the user device running the authentication application, a first device-side output step of, in response to receiving a first attempted challenge code, causing generation of a first device onetime password based on the first attempted challenge code using the first cryptographic scheme, and causing the user device to output the first device one-time password; at the processing unit, a first comparison step of, in response to receiving a first attempted one-time password, determining whether the first attempted one-time password is the same as the first container one-time password; at the processing unit, when the first attempted one-time password is determined to be the same as the first container one-time password, a second container-side output step of causing generation of a second challenge code, causing the container system to output the second challenge code, and causing generation of a second container one-time password based on the second challenge code using a second cryptographic scheme; at the user device running the authentication application, when the main determination has determined that access to the drug should be granted, a second device-side output step of, in response to receiving a second attempted challenge code, causing generation of a second device one-time password based on the second attempted challenge code using the second cryptographic scheme, and causing the user device to output the second device one-time password; at the processing unit, a second comparison step of, in response to receiving a second attempted one-time password, determining whether the second attempted one-time password is the same as the second container one-time password; and at the processing unit, when the second attempted one-time password is determined to be the same as the second container one-time password, an unlocking step of causing the locking mechanism to unlock the container.

Citation Information

Patent Citations

  • Identity verification

    EP2120175A2

  • Wireless key management for authentication

    US20160036594A1

  • Drug and device combination products with improved safety and efficacy profiles

    US20210319872A1