Patents by Inventor Henry Haverinen

Henry Haverinen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20050195780
    Abstract: The present invention relates to arranging data transmission for a mobile node in a telecommunications system comprising a secure network and an insecure network. A connection to a secure network for a mobile node may be arranged by a home agent if the mobile node is accessing the secure network directly or via a third network other than the insecure network, or a connection to the secure network may be arranged by a VPN node if the mobile node is accessing the secure network via the insecure network. According to a first aspect of the invention, the VPN node and the home agent are configured to allocate the same IP address as an internal IP address and as a home address.
    Type: Application
    Filed: February 25, 2005
    Publication date: September 8, 2005
    Inventors: Henry Haverinen, Heikki Riittinen, Pasi Eronen
  • Publication number: 20050176407
    Abstract: The invention relates to a method and system for authenticating a user of a data transfer device (such as a terminal in a wireless local area network, i.e. WLAN). The method comprises: setting up a data transfer connection from the data transfer device to a service access point. Next, identification data of the mobile subscriber (for example an MSISDN) are inputted to the service access point. This is followed by checking from the mobile communications system whether the mobile subscriber identification data contains an access right to the service access point. If a valid access right exists, a password is generated, then transmitted to a subscriber terminal (for example a GSM mobile phone) corresponding to the mobile subscriber identification data, and login from the data transfer device to the service access point takes place with the password transmitted to the subscriber terminal.
    Type: Application
    Filed: December 17, 2002
    Publication date: August 11, 2005
    Inventors: Jukka Tuomi, Henry Haverinen, Niklas Lyback, Sami Pienimaki
  • Publication number: 20050149734
    Abstract: A method for use by a telecommunication terminal (10) in checking whether a candidate RAND in an EAP/SIM RAND challenge is likely a replay, based on using a Bloom filter including a vector data structure (21) for determining (admittedly sometimes erroneously) whether the candidate RAND is in a set of previously used RAND values. The components of the vector data structure (21) are set to one or left at zero depending on whether pointers corresponding to the previously used RAND values point to them. The pointers can be hash functions or can be constructed from the previously used RAND values. To provide for smooth filter performance at points in time when the Bloom filter is full and cannot hold information for any new previously used RAND values, the vector data structure (21) is partitioned into more than one part, and only one part is reset and re-initialized at a time.
    Type: Application
    Filed: January 2, 2004
    Publication date: July 7, 2005
    Applicant: Nokia Corporation
    Inventors: Pasi Eronen, Henry Haverinen, Kaisa Nyberg
  • Publication number: 20050143071
    Abstract: The invention relates to applying a handover algorithm in a mobile terminal. In the method, the state of a user interface component of the terminal is checked, and the handover algorithm is applied on the basis of the current state of the user interface component. The handover algorithm is applied only if the current state of the user interface component is active.
    Type: Application
    Filed: December 30, 2003
    Publication date: June 30, 2005
    Inventors: Mikko Jaakkola, Jukka-Juhana Latva, Henry Haverinen
  • Publication number: 20040264427
    Abstract: The invention relates to selecting connection settings in a telecommunication system. In accordance with the method, history data is maintained, in which at least one network address is defined and also one connection setting, which has been used for establishing a connection to the network address. In response to the fact that there is a need to arrange a connection to the desired network address, the history data is checked and the selection of the connection settings to be used is arranged by means of the history data.
    Type: Application
    Filed: June 24, 2004
    Publication date: December 30, 2004
    Applicant: Nokia Corporation
    Inventors: Mikko Jaakkola, Henry Haverinen, Anne Huotari
  • Publication number: 20040266436
    Abstract: The invention relates to a method for arranging handover in a wireless telecommunications system. Connection settings are stored in a terminal, wherein at least one network identifier is associated with alternative connection settings, the network identifier identifying a target network reachable by a connection from the terminal. The network identifier associated with the currently applied connection settings is compared with the network identifiers associated with the other available connection settings. The connection settings associated with the same network identifier as the one associated with the currently applied connection settings are then selected. The handover may then be carried out by using the selected connection settings.
    Type: Application
    Filed: December 30, 2003
    Publication date: December 30, 2004
    Applicant: Nokia Corporation
    Inventors: Mikko Jaakkola, Henry Haverinen, Anne Huotari, Jukka-Juhana Latva
  • Publication number: 20040255033
    Abstract: The present invention provides an access point device arranged to receive data packets from one or more client devices and transmit them along an area network characterised wherein the access point device comprises security means arranged to configure the client data packets such that they are directed only to one or more permitted area network device(s).
    Type: Application
    Filed: December 3, 2003
    Publication date: December 16, 2004
    Inventors: Jonathan Edney, Henry Haverinen
  • Publication number: 20040236964
    Abstract: The invention relates to a method for authenticating the user of a terminal (5), in which terminal a device (15) for verifying the rights to use is applied for running an authentication protocol. The device (15) for verifying the rights to use is connected to the terminal (5). In the device (15) for verifying the rights to use, an extendable authentication protocol interface is applied, via which at least some of the authentication functions are carried out.
    Type: Application
    Filed: March 26, 2004
    Publication date: November 25, 2004
    Inventor: Henry Haverinen
  • Publication number: 20040208151
    Abstract: A method and device for routing data packets of a wireless terminal device in a communication network. When Open system Authentication is used, the system operates similarly as the current Nokia Operator Wireless LAN system, in which the terminal device and the access controller are the parties involved in the authentication. The access controller relays information relating to the authentication between the terminal device and an authenticating server, and it is capable of updating independently the list of users it maintains. When authentication according IEEE 802.1X authentication, the access point operates according to the IEEE 802.1X standard, serving as the authenticating party and relaying information relating to the authentication between the terminal device and the authentication server. In addition, the list maintained by the access controller is updated after a successful authentication, for example by the access point or the authenticating server.
    Type: Application
    Filed: January 21, 2003
    Publication date: October 21, 2004
    Inventors: Henry Haverinen, Anton Bush, Jyri Rinnemaa, Mike P. Smith, Timo Takamaki, Jukka Tuomi, Hannu Tuominen
  • Publication number: 20040192284
    Abstract: The present invention relates to Wireless Local Area Networks and Access Points in such networks, in particular it relates to the control and use of varying beacon intervals in such networks. According to the present invention, the beacon frames in the Wireless Local Area Network are provided with an adaptive beacon interval. The interval is adapted in dependence on a current network load such that the length of the beacon interval is decreased when the network load is decreased and increased when network load is increased. The invention is applicable in existing as well as future IEEE 802.11 standards.
    Type: Application
    Filed: March 25, 2003
    Publication date: September 30, 2004
    Inventors: Ari Vaisanen, Pekka Orava, Henry Haverinen
  • Publication number: 20040187030
    Abstract: The invention provides an access point device arranged to receive data packets from one or more client devices and transmit them along a public area network characterised wherein the access point device comprises security means arranged to consider the source/destination of data packets and control the forwarding/discarding of a data packet according to whether the data packet originates from a client device and is destined for a client device.
    Type: Application
    Filed: May 5, 2004
    Publication date: September 23, 2004
    Inventors: Jonathan Edney, Henry Haverinen
  • Publication number: 20040153555
    Abstract: A method (and corresponding equipment) for use in reauthentication—after a first, full authentication by a first authentication server (23a)—of a communication session involving the exchange of information between a terminal (21) and a server (24), the method including: a step (11) in which the first authentication server (23a) and other authentication servers (23b) are each assigned a respective unique realm name; and a step (13) in which during authentication between the terminal and the first authentication server (23a), the first authentication server (23a) transmits to the terminal (21) a reauthentication identity including the unique realm name assigned to the first authentication server. Then, later, during reauthentication, to make possible that the reauthentication is performed by the same authentication server (23a) as performed the full authentication—i.e. by the first authentication server (23a)—the reauthentication identity is included in a request for reauthentication.
    Type: Application
    Filed: September 10, 2003
    Publication date: August 5, 2004
    Inventors: Henry Haverinen, Kalle Ahmavaara
  • Publication number: 20040148374
    Abstract: A method and device for ensuring address information of a wireless terminal device in a wireless local area network, the network comprising; an access point for setting up a communication connection to the terminal device, the method comprising establishing a communication connection between the terminal device and the access point (101), and relaying data packets from the terminal device to the network and from the network to the terminal device (105). The method further comprising the steps at the access point: detecting an IP address of the terminal device in response to the established communication connection (103), associating the detected IP address of the terminal device to the MAC address of the terminal device (104), and comparing that the address information of the terminal device on the relayed data packets are corresponding to the associated address information (111, 112).
    Type: Application
    Filed: May 1, 2003
    Publication date: July 29, 2004
    Applicant: Nokia Corporation
    Inventors: Anton Bush, Henry Haverinen, Jyri Rinnemaa, Mike Smith, Timo Takamaki, Jukka Tuomi, Hannu Tuominen
  • Publication number: 20040078571
    Abstract: Method of authenticating a client comprising the steps of sending a subscriber identity to an authentication server; obtaining at least one challenge and at least one first secret to the authentication server based on a client's secret specific to the client; forming first credentials; forming a first authentication key using the at least one first secret; encrypting the first credentials using the first authentication key; sending the at least one challenge and the encrypted first credentials to the client; forming an own version of the first authentication key at the client; decrypting the encrypted first credentials using the own version of the first authentication key. In the method, the encrypted credentials are sent together with the at least one challenge to the client so that the client can proceed authentication only if it can derive the first secret from the at least one challenge.
    Type: Application
    Filed: November 3, 2003
    Publication date: April 22, 2004
    Inventor: Henry Haverinen
  • Patent number: 6721291
    Abstract: This is a method and system to efficiently do handovers for mobile IP. The mobile node registers itself with several foreign agents using a new registration type. Only one of the foreign agents is selected to forward the data packets of a data message to the mobile node. The selection algorithm may be one based on randomness, dynamic learning, message traffic congestion, or statistical information collected at the mobile node.
    Type: Grant
    Filed: October 19, 1999
    Date of Patent: April 13, 2004
    Assignee: Nokia IP
    Inventors: Martin Bergenwall, Henry Haverinen, Jukka Seppälä, Tom Soderlund
  • Publication number: 20040066756
    Abstract: A method for user equipment (UE) resident in a wireless access network (WLAN) to obtain access to at least one other network is disclosed. The method includes storing the identification (SSID) of the at least one other network (visited PLMNs 1-3 and home PLMNs 4 and 5) in the user equipment; transmitting from the user equipment a request for connection to one of the at least one other network, which includes an identification of at least one of the at least one other network, to the wireless access network; and in response to the wireless access network receiving the identification, the user equipment is connected to the identified at least one other network through the wireless access network.
    Type: Application
    Filed: March 10, 2003
    Publication date: April 8, 2004
    Inventors: Kalle Ahmavaara, Henry Haverinen
  • Publication number: 20040064741
    Abstract: A method in a system for transferring accounting information, a system for transferring accounting information, a method in a terminal, a terminal, a method in an Extensible Authentication Protocol (EAP) service authorization server, an EAP service authorization server, a computer program, an Extensible Authentication Protocol response (EAP-response) packet, wherein the method:
    Type: Application
    Filed: June 20, 2003
    Publication date: April 1, 2004
    Applicant: Nokia Corporation
    Inventors: Henry Haverinen, Pekka Laitinen, Nadarajah Asokan
  • Publication number: 20040029580
    Abstract: A method in a system, a system, a method in a terminal and a terminal for service selection in a data network. The method sends, from a Wireless Local Area Network (WLAN) terminal, a Network Access Identifier (NAI) including a service selection indicator via a WLAN access point; receives, at an authentication server, the NAI including a service selection indicator, and provides the WLAN terminal with a connection to the service indicated by said selection indicator. The system comprises at least one WLAN access point and terminal comprising means for including a service selection indicator in a NAI and means for sending said NAI including said service selection indicator via the WLAN access point, at least one authentication server comprising means for receiving said NAI, means for extracting said service selection indicator from said NAI and means for initiating connection to a service indicated by said service selection indicator.
    Type: Application
    Filed: April 17, 2003
    Publication date: February 12, 2004
    Applicant: Nokia Corporation
    Inventors: Henry Haverinen, Jouni Mikkonen
  • Patent number: 6681259
    Abstract: The invention relates to a terminal (A), which comprises at least one network interface card (NIC1, NIC2, NIC3) for setting up a data transmission connection to a communication network (NW1, NW2, NW3, MNW) for packet switched data transmission, and means (PD) for forming packets of the information to be transmitted and for unpacking information from the received packets. The terminal (A) is allocated at least one first address identifying the terminal (A), and at least one data network-specific second address.
    Type: Grant
    Filed: May 10, 1999
    Date of Patent: January 20, 2004
    Assignee: Nokia Mobile Phones Ltd
    Inventors: Jussi Lemiläinen, Henry Haverinen
  • Publication number: 20030177267
    Abstract: The invention relates to a method of transferring required messages for acquiring a temporary MAC address in a wireless local area network. In a first device in the local area network, a first identifier is determined to identify the first device. A message comprising the first identifier is transmitted from the first device to a second device to arrange a temporary MAC address. A response message relating to the acquisition of the MAC address and comprising the first identifier is transmitted from the second device to the first device. The first device identifies on the basis of the first identifier that the response message is intended for it.
    Type: Application
    Filed: December 5, 2002
    Publication date: September 18, 2003
    Applicant: Nokia Corporation
    Inventors: Pekko Orava, Jukka-Pekka Honkanen, Henry Haverinen, Jouni Mikkonen, Markku T. Niemi