Patents by Inventor Kari Timo Juhani Kostiainen

Kari Timo Juhani Kostiainen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11153081
    Abstract: A method and apparatus includes a determining unit configured to determine whether a device entering a network should be allowed access and an executing unit configured to execute a configuration protocol between the registrar and the device and to a shared unique configuration key between the registrar and the device. If the device provides a privileged service, the configuration protocol enables the device to advertise the privileged service or if the device is a control point, the configuration protocol enables the device to advertise that it is able to control certain privileged services. The registrar also includes a controlling unit configured to obtain a controller key, if the registrar is to become controller of the new device and a service unit configured to execute a credential service that allows devices providing privileged services to delegate issuing of access control credentials to the registrar, wherein other devices may use the credential service to obtain credentials for privileged services.
    Type: Grant
    Filed: March 26, 2020
    Date of Patent: October 19, 2021
    Assignee: Conversant Wireless Licensing S.a r.l.
    Inventors: Kari Timo Juhani Kostiainen, Seamus Peter Moloney, Olli Antero Rantapuska
  • Publication number: 20200328887
    Abstract: A method and apparatus includes a determining unit configured to determine whether a device entering a network should be allowed access and an executing unit configured to execute a configuration protocol between the registrar and the device and to a shared unique configuration key between the registrar and the device. If the device provides a privileged service, the configuration protocol enables the device to advertise the privileged service or if the device is a control point, the configuration protocol enables the device to advertise that it is able to control certain privileged services. The registrar also includes a controlling unit configured to obtain a controller key, if the registrar is to become controller of the new device and a service unit configured to execute a credential service that allows devices providing privileged services to delegate issuing of access control credentials to the registrar, wherein other devices may use the credential service to obtain credentials for privileged services.
    Type: Application
    Filed: March 26, 2020
    Publication date: October 15, 2020
    Inventors: Kari Timo Juhani Kostiainen, Seamus Peter Moloney, Olli Antero Rantapuska
  • Patent number: 10637661
    Abstract: A method and apparatus includes a determining unit configured to determine whether a device entering a network should be allowed access and an executing unit configured to execute a configuration protocol between the registrar and the device and to a shared unique configuration key between the registrar and the device. If the device provides a privileged service, the configuration protocol enables the device to advertise the privileged service or if the device is a control point, the configuration protocol enables the device to advertise that it is able to control certain privileged services. The registrar also includes a controlling unit configured to obtain a controller key, if the registrar is to become controller of the new device and a service unit configured to execute a credential service that allows devices providing privileged services to delegate issuing of access control credentials to the registrar, wherein other devices may use the credential service to obtain credentials for privileged services.
    Type: Grant
    Filed: June 4, 2018
    Date of Patent: April 28, 2020
    Assignee: Conversant Wireless Licensing S.a r.l.
    Inventors: Kari Timo Juhani Kostiainen, Seamus Peter Moloney, Olli Antero Rantapuska
  • Publication number: 20190020638
    Abstract: A method and apparatus includes a determining unit configured to determine whether a device entering a network should be allowed access and an executing unit configured to execute a configuration protocol between the registrar and the device and to a shared unique configuration key between the registrar and the device. If the device provides a privileged service, the configuration protocol enables the device to advertise the privileged service or if the device is a control point, the configuration protocol enables the device to advertise that it is able to control certain privileged services. The registrar also includes a controlling unit configured to obtain a controller key, if the registrar is to become controller of the new device and a service unit configured to execute a credential service that allows devices providing privileged services to delegate issuing of access control credentials to the registrar, wherein other devices may use the credential service to obtain credentials for privileged services.
    Type: Application
    Filed: June 4, 2018
    Publication date: January 17, 2019
    Inventors: Kari Timo Juhani Kostiainen, Seamus Peter Moloney, Olli Antero Rantapuska
  • Patent number: 10027638
    Abstract: A method and apparatus includes a determining unit configured to determine whether a device entering a network should be allowed access and an executing unit configured to execute a configuration protocol between the registrar and the device and to a shared unique configuration key between the registrar and the device. If the device provides a privileged service, the configuration protocol enables the device to advertise the privileged service or if the device is a control point, the configuration protocol enables the device to advertise that it is able to control certain privileged services. The registrar also includes a controlling unit configured to obtain a controller key, if the registrar is to become controller of the new device and a service unit configured to execute a credential service that allows devices providing privileged services to delegate issuing of access control credentials to the registrar, wherein other devices may use the credential service to obtain credentials for privileged services.
    Type: Grant
    Filed: February 16, 2015
    Date of Patent: July 17, 2018
    Assignee: Conversant Wireless Licensing S.a.r.l.
    Inventors: Kari Timo Juhani Kostiainen, Seamus Peter Moloney, Olli Antero Rantapuska
  • Publication number: 20150163208
    Abstract: A method and apparatus includes a determining unit configured to determine whether a device entering a network should be allowed access and an executing unit configured to execute a configuration protocol between the registrar and the device and to a shared unique configuration key between the registrar and the device. If the device provides a privileged service, the configuration protocol enables the device to advertise the privileged service or if the device is a control point, the configuration protocol enables the device to advertise that it is able to control certain privileged services. The registrar also includes a controlling unit configured to obtain a controller key, if the registrar is to become controller of the new device and a service unit configured to execute a credential service that allows devices providing privileged services to delegate issuing of access control credentials to the registrar, wherein other devices may use the credential service to obtain credentials for privileged services.
    Type: Application
    Filed: February 16, 2015
    Publication date: June 11, 2015
    Inventors: Kari Timo Juhani Kostiainen, Seamus Peter Moloney, Olli Antero Rantapuska
  • Patent number: 8352737
    Abstract: An apparatus for authentication of fragments using hash trees may include a processor. The processor may be configured to provide one or more data fragments and a hash tree representing the one or more fragments, send at least one first fragment accompanied by any nodes of the hash tree necessary to authenticate the one or more first sent fragments, and send one or more subsequent fragments accompanied by only some, but not all, of the nodes of the hash tree necessary to authenticate the one or more subsequent fragments with the other nodes that are not sent but are necessary for authentication having been previously sent in conjunction with a prior fragment.
    Type: Grant
    Filed: December 20, 2007
    Date of Patent: January 8, 2013
    Assignee: Nokia Corporation
    Inventors: John Solis, Kari Timo Juhani Kostiainen, Philip Ginzboorg, Nadarajah Asokan, Joerg Ott, Cheng Luo
  • Publication number: 20120324214
    Abstract: The exemplary embodiments or the invention provide at least a method, apparatus, and program of computer instructions to perform operations including receiving a challenge from a prover device, reading and saving an old value of a selected platform configuration register, obtaining at least one measurement or property and forming a new platform configuration register value, where the forming includes calculating a cryptographic hash over the old value of the platform configuration register and the obtained at least one measurement or property, triggering, with the trusted software, an attestation by sending a challenge to a trusted platform module/mobile platform module, and sending by the prover device a device certificate, attestation, at least one measurement or property, and old platform configuration register value to the verifier.
    Type: Application
    Filed: February 16, 2011
    Publication date: December 20, 2012
    Applicant: NOKIA CORPORATION
    Inventors: Nadarajah Asokan, Jan-Erik Ekberg, Kari Timo Juhani Kostiainen
  • Publication number: 20120239936
    Abstract: Methods and apparatus, including computer program products, are provided for credential transfer. In one aspect there is provided a method. The method may include receiving, at a first device, an authorization token; determining, at the first device, a delegation token, one or more credentials, and metadata; and providing, by the first device to a second device, the delegation token, the one or more credentials, and the metadata. Related apparatus, systems, methods, and articles are also described.
    Type: Application
    Filed: December 18, 2009
    Publication date: September 20, 2012
    Applicant: NOKIA CORPORATION
    Inventors: Silke Holtmanns, Nadarajah Asokan, Kari Timo Juhani Kostiainen
  • Patent number: 7913086
    Abstract: The invention relates to a method for remote attestation. In the method is created a first asymmetric key pair in a trusted platform module in an electronic device. A first public key and software platform state information are certified with an attestation identity key associated with the trusted platform module to produce a first certificate. A second asymmetric key pair is produced in an application within the electronic device. The second public key is certified with said first secret key to produce a second certificate. A message is signed with the second secret key to provide a message signature in the first electronic device. The message and the message signature, software platform state information, the first certificate and the second certificate are sent to a second electronic device.
    Type: Grant
    Filed: June 20, 2007
    Date of Patent: March 22, 2011
    Assignee: Nokia Corporation
    Inventors: Kari Timo Juhani Kostiainen, Nadarajah Asokan
  • Publication number: 20090164783
    Abstract: An apparatus for authentication of fragments using hash trees may include a processor. The processor may be configured to provide one or more data fragments and a hash tree representing the one or more fragments, send at least one first fragment accompanied by any nodes of the hash tree necessary to authenticate the one or more first sent fragments, and send one or more subsequent fragments accompanied by only some, but not all, of the nodes of the hash tree necessary to authenticate the one or more subsequent fragments with the other nodes that are not sent but are necessary for authentication having been previously sent in conjunction with a prior fragment.
    Type: Application
    Filed: December 20, 2007
    Publication date: June 25, 2009
    Inventors: John Solis, Kari Timo Juhani Kostiainen, Philip Ginzboorg, Nadarajah Asokan, Joerg Ott, Cheng Luo
  • Publication number: 20080320308
    Abstract: The invention relates to a method for remote attestation. In the method is created a first asymmetric key pair in a trusted platform module in an electronic device. A first public key and software platform state information are certified with an attestation identity key associated with the trusted platform module to produce a first certificate. A second asymmetric key pair is produced in an application within the electronic device. The second public key is certified with said first secret key to produce a second certificate. A message is signed with the second secret key to provide a message signature in the first electronic device. The message and the message signature, software platform state information, the first certificate and the second certificate are sent to a second electronic device.
    Type: Application
    Filed: June 20, 2007
    Publication date: December 25, 2008
    Inventors: Kari Timo Juhani Kostiainen, Nadarajah Asokan