Patents by Inventor Luis Barriga

Luis Barriga has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8516133
    Abstract: Methods and systems taught herein allow communication device manufacturers to preconfigure communication devices to use preliminary access credentials to gain temporary network access for downloading subscription credentials, and particularly allow the network operator issuing the subscription credentials to verify that individual devices requesting credentials are trusted. In one or more embodiments, a credentialing server is owned or controlled by the network operator, and is used by the network operator to verify that subscription credentials are issued only to trusted communication devices, even though such devices may be referred to the credentialing server by an external registration server and may be provisioned by an external provisioning server. Particularly, the credentialing server interrogates requesting devices for their device certificates and submits these device certificates to an external authorization server, e.g., an independent OCSP server, for verification.
    Type: Grant
    Filed: October 23, 2008
    Date of Patent: August 20, 2013
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Bernard Smeets, Luis Barriga, Mattias Eld, Vesa Petteri Lehtovirta, Krister Sällberg
  • Publication number: 20130148585
    Abstract: An IMS (IP Multimedia Subsystem) network contains at least one of (A) a discovery function (2) for providing ISIM (IP Multimedia Subscriber Identity Module) discovery information to the mobile device (1) and (B) a provisioning function (2, 5, 6) for providing, in response to a request from a mobile device, an ISIM to the mobile device (1). Where the IMS network contains the discovery function, the discovery function is adapted to provide ISIM discovery information to the mobile device, and where the IMS network contains the provisioning function, the provisioning function is adapted to provide an ISIM to the mobile device (1).
    Type: Application
    Filed: August 31, 2010
    Publication date: June 13, 2013
    Applicant: Telefonaktiebolaget L M Ericsson (publ)
    Inventors: Oscar Ohlsson, Luis Barriga, Fredrik Lindholm
  • Patent number: 8429737
    Abstract: An IMS system includes an IMS initiator user entity. The system includes an IMS responder user entity that is called by the initiator user entity. The system includes a calling side S-CSCF in communication with the caller entity which receives an INVITE having a first protection offer and parameters for key establishment from the caller entity, removes the first protection offer from the INVITE and forwards the INVITE without the first protection offer. The system includes a receiving end S-CSCF in communication with the responder user entity and the calling side S-CSCF which receives the INVITE without the first protection offer and checks that the responder user entity supports the protection, inserts a second protection offer into the INVITE and forwards the INVITE to the responder user entity, wherein the responder user entity accepts the INVITE including the second protection offer and answers with an acknowledgment having a first protection accept.
    Type: Grant
    Filed: December 1, 2008
    Date of Patent: April 23, 2013
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Luis Barriga, Rolf Blom, Yi Cheng, Fredrik Lindholm, Mats Naslund, Karl Norrman
  • Patent number: 8417952
    Abstract: The present invention relates to a method and an operator network node for enabling a user-defined DRM domain of *SIMs hosted by *SIM-enabled devices. The operator network node is connectable to a *SIM based device and to a content provider node, and comprises means for establishing a secure channel between a *SIM-based device and an operator network node, means for creating a DRM domain defined by at least one user of *SIM-based devices, means for receiving at the operator network node a registration request from the *SIM-based device to register the *SIM of the *SIM-based device into the created user-defined DRM domain, means for registering at the operator network node the *SIM of the *SIM-based device into the registered user-defined DRM domain, and means for making the registered information associated with the user-defined DRM domain available to the content provider.
    Type: Grant
    Filed: December 19, 2007
    Date of Patent: April 9, 2013
    Assignee: Telefonaktiebolaget L M Ericsson (publ)
    Inventors: Yi Cheng, Luis Barriga, Karl Norrman
  • Patent number: 8386767
    Abstract: Methods, systems and communication nodes for bootstrapping key establishment to exchange encryption keys between a terminal-based client and an application server using Session Initiation Protocol (SIP) signaling are described.
    Type: Grant
    Filed: August 17, 2009
    Date of Patent: February 26, 2013
    Assignee: Telefonaktiebolaget L M Ericsson (Publ)
    Inventors: Luis Barriga, David Castellanos Zamora
  • Patent number: 8261078
    Abstract: A method and arrangement is disclosed for providing a user, not previously having an individual subscription with a network operator, with credentials for secure access to network services. The arrangement includes a gateway, associated with a subscription for network services, having means for generating and exporting to a user entity personalized user security data derived from security data related to the subscription. In particular, the derivation of credentials is based on a function that is shared between network and gateway and further conveniently makes use of bootstrapping on keying material from the subscription authentication. Pre-registered user identities are assigned trusted users who, thereafter, can download credentials and authenticate for service access. The invention may be implemented at a public place for providing temporary visitors network access whereby trust may exemplary be established by presenting a credit card.
    Type: Grant
    Filed: June 9, 2006
    Date of Patent: September 4, 2012
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Luis Barriga, Rolf Blom, Mats Näslund
  • Publication number: 20120159632
    Abstract: Method and arrangement in a mediating function (204) for supporting detection of fraud in a network, when a network security function (200) is employed for analysing activities in the network in view of predefined alert criteria, and a fraud detection function (202) is employed for analysing e.g. charging information of users. When a first alert is received from a first one of the network security function and the fraud detection function, indicating that the predefined alert criteria of said first function have been satisfied, the alert criteria of the second one of said network security function and fraud detection function are modified based on the received first alert. Thereby, the network security and fraud detection functions can be correlated and made more efficient regarding accuracy and/or speed in detecting fraud.
    Type: Application
    Filed: August 25, 2009
    Publication date: June 21, 2012
    Applicant: TELEFONAKTIEBOLAGET L M ERICSSON (PUBL)
    Inventors: Luis Barriga, Michael Liljenstam, Alessandro Mordacci
  • Patent number: 8184623
    Abstract: A method and apparatus for sharing an application profile for plural public IMS identities across different IMS subscriptions. A home application profile for a first public IMS identity (IMPUx) of a first IMS subscription, is stored in its entirety at a first HSS storage. A profile reference is stored as an abbreviated foreign application profile for a second public IMS identity (IMPUy) of a second IMS subscription at a second HSS storage. The profile reference points to the home application profile in the first HSS storage. An authorizing identifier for the second public IMS identity that authorizes access to the home application profile, is also stored at the first HSS storage.
    Type: Grant
    Filed: April 19, 2007
    Date of Patent: May 22, 2012
    Assignee: Telefonaktiebolaget L M Ericsson (Publ)
    Inventors: Luis Barriga, David Castellanos Zamora, Nuria Esteban Vares
  • Publication number: 20120059897
    Abstract: The invention relates to a method, party challenging device (18) and computer program products for providing a challenge to a first terminal (10) intending to communicate with a second terminal (24) via two networks (N1, N2). The party challenging device receives a first electronic message (1M) concerning a transfer of media from the first terminal to the second terminal sent from the first terminal (10) and addressed to the second terminal (24), obtains communication contextual data associated with the first party or the first terminal, provides an electronic challenge message (CHM) including a challenge (CHl1) based on the obtained data and sends the challenge message to the first terminal in order to enable a decision to be made how to process the invitation message for the second terminal based on the correctness of a response (RM) including a response to the challenge.
    Type: Application
    Filed: May 20, 2009
    Publication date: March 8, 2012
    Applicant: Telefonaktiebolaget L M Ericsson (PUBL)
    Inventors: Luis Barriga, Michael Liljenstam, Mats Naslund, Per-Olof Nerbrant
  • Publication number: 20110302627
    Abstract: A method of authenticating access to a service comprises: a) receiving at a mobile terminal, over a bi-directional near-field communication channel between the mobile terminal and a browser, at least part of the identifier of a service; b) comparing, at the mobile terminal, at least part of the identifier received at the mobile terminal with a set of identifiers stored in the mobile device; and c) authenticating access to the service on the basis of whether at least part of the identifier received at the mobile terminal matches an identifier in the set. The mobile terminal may stored a set of URLs, and may compare a received URL (or part URL) with the set of stored URLs. It may generate an alert to the user if at least part of the URL received at the mobile terminal does not match a stored URL. User names and keys are not required to be stored on the web-browser, so the web-browser does not need to maintain a password database.
    Type: Application
    Filed: February 18, 2009
    Publication date: December 8, 2011
    Applicant: Telefonaktiebolaget L M Ericsson (publ)
    Inventors: Rolf Blom, Luis Barriga, Karl Norrman
  • Publication number: 20110296181
    Abstract: The embodiments of the present invention relate to apparatuses in the form of a first network unit and a device, and also relates to a method for enabling protection of a bootstrap message in a device management network system. The method comprises: receiving at the first network unit, a request to bootstrap the device; transmit a request for a bootstrap key, to a second network unit; receiving a message comprising the bootstrap key and further comprises trigger information and transmitting the trigger information to the device to trigger generation of the bootstrap key internally in the device. Thereafter a protected bootstrap message can be transmitted to the device from the first network unit, and when the device verifies and/or decrypts the bootstrap message, device management (DM) sessions can start between the device and the first network unit.
    Type: Application
    Filed: October 1, 2009
    Publication date: December 1, 2011
    Inventors: Luis Barriga, Per-Anders Dysenius, Magnus Lindström
  • Publication number: 20110131414
    Abstract: Methods, systems and communication nodes for protecting Session Initiation Protocol (SIP) message payloads are described. Different protection techniques can be used to protect SIP payloads depending upon, for example, whether a recipient client application resides in a user equipment or an application server and/or whether a recipient client application resides in a same SIP/IP domain as the target SIP application server which is sending the SIP payloads.
    Type: Application
    Filed: November 30, 2009
    Publication date: June 2, 2011
    Inventors: Yi Cheng, Åke Busin, Luis Barriga
  • Publication number: 20110055565
    Abstract: An IMS User Equipment (UE) is provided. The IMS UE comprises: searching means for searching, based on UPnP technology, a UPnP network for a host device that has IMS subscription information, establishing means for establishing a session with the host device discovered by the searching means, subscription retrieving means for retrieving, from the host device via the session, the IMS subscription information, registering means for registering with the IMS network using the IMS subscription information, key retrieving means for retrieving, from the host device via the session, a first encryption key shared with an IMS application server (AS) in an IMS network by sending identity of the IMS AS to the host device via the session, and communicating means for performing encrypted communication with the IMS AS using the first encryption key.
    Type: Application
    Filed: May 23, 2008
    Publication date: March 3, 2011
    Inventors: Shingo Murakami, Toshikane Oda, Luis Barriga
  • Publication number: 20110010768
    Abstract: An IMS system includes an IMS initiator user entity. The system includes an IMS responder user entity that is called by the initiator user entity. The system includes a calling side S-CSCF in communication with the caller entity which receives an INVITE having a first protection offer and parameters for key establishment from the caller entity, removes the first protection offer from the INVITE and forwards the INVITE without the first protection offer. The system includes a receiving end S-CSCF in communication with the responder user entity and the calling side S-CSCF which receives the INVITE without the first protection offer and checks that the responder user entity supports the protection, inserts a second protection offer into the INVITE and forwards the INVITE to the responder user entity, wherein the responder user entity accepts the INVITE including the second protection offer and answers with an acknowledgment having a first protection accept.
    Type: Application
    Filed: December 1, 2008
    Publication date: January 13, 2011
    Applicant: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Luis Barriga, Rolf Blom, Yi Cheng, Fredrik Lindholm, Mats Naslund, Karl Norrman
  • Patent number: 7865173
    Abstract: The present invention is related to an authentication method and arrangements in a communication system including a Subscriber (50) with a terminal (51), an Operator Node (52) and a Service Provider Node (53), which authentication method is based on an SLA agreement between the Operator (OP) and the Service Provider (SP). The method includes that the Subscriber (50) with terminal (51) performs (5) strong authentication with the Operator Node (52) acting as Registration Authority OP(RA). After the strong authentication is performed by the Operator Node (52) a Mobile Strong Authentication Assertion MSAA is generated (6) and transmitted to the Service Provider Node (53) for validation. By this method the authentication is being delegated from the Service Provider to the Mobile Operator.
    Type: Grant
    Filed: December 22, 2006
    Date of Patent: January 4, 2011
    Assignee: Telefonaktiebolaget L M Ericsson (Publ)
    Inventors: Susana Fernandez-Alonso, Luis Barriga
  • Publication number: 20100333173
    Abstract: Methods and systems taught herein provide for authentication information for authenticating a user terminal to be shared between a network entity that supports IMS-AKA authentication of the user terminal and a network entity that supports GBA-AKA authentication of the user terminal. Sharing authentication information between these entities allows all or part of the authentication information generated for IMS-AKA authentication of the user terminal to be used subsequently for GBA-AKA authentication of the user terminal, or vice versa.
    Type: Application
    Filed: February 15, 2008
    Publication date: December 30, 2010
    Applicant: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Luis Barriga, David Castellanos Zamora
  • Publication number: 20100281262
    Abstract: The present invention relates to a method and an operator network node for enabling a user-defined DRM domain of *SIMs hosted by *SIM-enabled devices. The operator network node is connectable to a *SIM based device and to a content provider node, and comprises means for establishing a secure channel between a *SIM-based device and an operator network node, means for creating a DRM domain defined by at least one user of *SIM-based devices, means for receiving at the operator network node a registration request from the *SIM-based device to register the *SIM of the *SIM-based device into the created user-defined DRM domain, means for registering at the operator network node the *SIM of the *SIM-based device into the registered user-defined DRM domain, and means for making the registered information associated with the user-defined DRM domain available to the content provider.
    Type: Application
    Filed: December 19, 2007
    Publication date: November 4, 2010
    Applicant: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Yi Cheng, Luis Barriga, Karl Norrman
  • Publication number: 20100223339
    Abstract: A method and arrangement in a multimedia gateway connected to a multimedia service network, for providing access to multimedia services for communication devices connected to a private network. In the multimedia gateway, a communication unit receives a request from a device in the private network for a public identity associated with the multimedia gateway. An identity manager then selects and allocates an associated public identity from a pool of public identities associated with the multimedia gateway which have been predefined as valid in the multimedia service network. The communication unit then registers the device by activating the allocated associated public identity in the multimedia service network. Thereby, the multimedia gateway can establish a multimedia session on behalf of the device, using the allocated associated public identity.
    Type: Application
    Filed: December 13, 2005
    Publication date: September 2, 2010
    Inventors: Yi Cheng, Luis Barriga
  • Publication number: 20100177769
    Abstract: A method and apparatus for sharing an application profile for plural public IMS identities across different IMS subscriptions. A home application profile for a first public IMS identity (IMPUx) of a first IMS subscription, is stored in its entirety at a first HSS storage. A profile reference is stored as an abbreviated foreign application profile for a second public IMS identity (IMPUy) of a second IMS subscription at a second HSS storage. The profile reference points to the home application profile in the first HSS storage. An authorizing identifier for the second public IMS identity that authorizes access to the home application profile, is also stored at the first HSS storage.
    Type: Application
    Filed: April 19, 2007
    Publication date: July 15, 2010
    Inventors: Luis Barriga, David Castellanos Zamora, Nuria Esteban Vares
  • Publication number: 20100115598
    Abstract: A method is disclosed that provides efficient integration of infrastructure for federated single sign on, e.g. Liberty ID-FP framework, and generic bootstrapping architecture, e.g. 3GPP GAA/GBA architecture. An integrated proxy server (IAP) is inserted in the path between a user and a service provider (SP). The proxy server differentiates type of access and determines corresponding operative state to act as a liberty enabled server or as a GAA/GBA network application function. A Bootstrapping, Identity, Authentication and Session Management arrangement (BIAS) leverages on 3GPP GAA/GBA infrastructure to provide an integrated system for handling Liberty Federated SSO and 3GPP GAA/GBA bootstrapping procedures at the same time. The method and arrangement provides improved use of infrastructure elements and performance for authenticated service access.
    Type: Application
    Filed: December 28, 2006
    Publication date: May 6, 2010
    Inventors: Luis Barriga, David Castellanos Zamora