Aerosol Device Control Circuitry for Offline-Online Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing youth access prevention (YAP) methods for aerosol-generating devices face technical challenges, including connectivity issues and vulnerability to brute force attacks, which compromise the effectiveness of offline authentication processes.

Innovation Solution

Implementing control circuitry that transitions an aerosol-generating device from a locked to an unlocked state through an offline phase with limited authentication attempts, followed by an online phase if necessary, using a guided interactive input process with user-perceptible guidance signals and a secure online verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If offline YAP methods are used to prevent youth access, then device connectivity requirements are reduced, but the system becomes vulnerable to brute force attacks

Engineering Contradiction:
Improveconnectivity independenceVSAvoidsecurity against brute force attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication system dynamically transitions between offline and online modes based on the number of failed attempts. During the offline phase, the system allows a limited number of attempts (e.g., 5 attempts). When this threshold is exceeded, the system automatically transitions to the online phase requiring remote verification, thereby adapting the authentication mechanism to the current threat level and preventing brute force attacks while maintaining offline usability within reasonable limits.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If multiple authentication attempts are allowed during offline phase, then user convenience is improved, but the risk of brute force attacks increases

Engineering Contradiction:
Improveauthentication accessibilityVSAvoidbrute force attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements a feedback mechanism that monitors the number of failed authentication attempts and provides appropriate responses. When the threshold of failed attempts is reached, the system feeds back by transitioning to online authentication mode, effectively communicating the security risk to the attacker while maintaining user-friendly offline access within the defined attempt limits.

Inventive Principle:
Principle #23Feedback

3Reliability

If online authentication is required for all access, then security against unauthorized use is improved, but device connectivity and external applications are needed

Engineering Contradiction:
Improveauthentication securityVSAvoidconnectivity requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into two distinct phases: an offline phase for low-security scenarios requiring no external connectivity, and an online phase for high-security scenarios requiring remote verification. This segmentation allows the system to provide secure authentication without mandating constant connectivity, instead activating online verification only when necessary based on the authentication attempt history.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250261696A1Control circuitry for an aerosol-generating device
Publication Date: 2025.08.21 PHILIP MORRIS PRODUCTS SA
  • US20250261696A1 patent drawing
  • US20250261696A1 patent drawing
  • US20250261696A1 patent drawing

AI summary

An aerosol-generating system is provided, including: control circuitry; an aerosol-generating device and/or a companion device for the aerosol-generating device including a communications interface to provide device connectivity; and user interface components including: user interface components of the aerosol-generating device, of the companion device, or any combination of input and output elements of the aerosol-generating and/or companion devices, the aerosol-generating device having a locked state in which it is prohibited from delivering aerosol and an unlocked state in which it is permitted to deliver aerosol, and the circuitry being configured to perform an authentication process for authenticating the user.