Patents by Inventor Pekka Laitinen

Pekka Laitinen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20120110637
    Abstract: Systems, methods, and apparatuses are provided for facilitating authorization of a roaming mobile terminal. A method may include receiving a request for security key related policy information for a user equipment device. The request may be sent by a service providing node on a visited network. The method may further include causing a service authorization information request including a user security settings package to be sent to a policy decisioning server. The method may also include receiving, in response to the service authorization information request, a service authorization information answer including a modified user security settings package including the authorization policy information for the user equipment device. The method may additionally include causing the requested security key related policy information to be sent to the service providing node. Corresponding systems and apparatuses are also provided.
    Type: Application
    Filed: April 29, 2010
    Publication date: May 3, 2012
    Applicant: NOKIA CORPORATION
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Patent number: 8107623
    Abstract: A method for verifying a first identity and a second identity of an entity, said method comprising: receiving first identity information at a checking entity; sending second identity information from the entity to said checking entity; verifying that the first and second identities both belong to said entity; and generating a key using one of said first and second identity information.
    Type: Grant
    Filed: June 21, 2004
    Date of Patent: January 31, 2012
    Assignee: Nokia Corporation
    Inventor: Pekka Laitinen
  • Publication number: 20120011574
    Abstract: A method and apparatus provide generic mechanism for a network application server. A receiver receives a request from a user equipment to provide authentication information to a network application function. A determining unit determines a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings. A providing unit provides the authentication information to the network application function.
    Type: Application
    Filed: September 21, 2011
    Publication date: January 12, 2012
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Patent number: 8046824
    Abstract: A method and apparatus provide generic mechanism for a network application server. A receiver receives a request from a user equipment to provide authentication information to a network application function. A determining unit determines a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings. A providing unit provides the authentication information to the network application function.
    Type: Grant
    Filed: July 20, 2005
    Date of Patent: October 25, 2011
    Assignee: Nokia Corporation
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Patent number: 8037522
    Abstract: Security level establishment for an application in a terminal equipment under a generic bootstrapping architecture offering a plurality of different bootstrapping mechanisms, the terminal equipment comprising a credential establishment entity and an application entity, comprising a request for a credential for the application from the application entity to the credential establishment entity and a response from the credential establishment entity to the application entity, wherein the response comprises the requested credential and credential quality information.
    Type: Grant
    Filed: March 23, 2007
    Date of Patent: October 11, 2011
    Assignee: Nokia Corporation
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Patent number: 7877787
    Abstract: An apparatus and method for sharing data in a communications system include a bootstrapping server function (BSF) configured to transmit a first message. The first message includes a timestamp parameter corresponding to a generic bootstrapping architecture user security settings (GUSS) stored in the BSF. A home subscriber server (HSS) is configured to receive the first message, to compare the timestamp parameter corresponding to the GUSS stored in the BSF with a timestamp parameter corresponding to a GUSS stored in the HSS, and to transmit a second message back to the BSF excluding the GUSS when the timestamp parameters of the GUSS of the BSF and the HSS are equal.
    Type: Grant
    Filed: December 16, 2005
    Date of Patent: January 25, 2011
    Assignee: Nokia Corporation
    Inventors: Pekka Laitinen, Philip Ginzboorg
  • Publication number: 20100332834
    Abstract: An approach is provided for building a scalable service platform by initiating transmission of encrypted data from a public network cache. An access control server platform determines a first authorization key for a user and a second authorization key for a resource, and then encrypts the resource with the second authorization key, and encrypts the second authorization key with the first authorization key. The access control server platform initiates distribution of the encrypted second authorization key with the encrypted resource over a network. The access control server platform further initiates caching the encrypted second authorization key with the encrypted resource that meets a predefined threshold value (e.g., a data size, an access frequency, a modification frequency, or an auditing requirement) in a cache in the network, and initiates transmission of the cached and encrypted second authorization key with the cached and encrypted resource from the cache to at least one authorized entity.
    Type: Application
    Filed: June 30, 2009
    Publication date: December 30, 2010
    Applicant: Nokia Corporation
    Inventors: Yan Fu, Ari M. Vepsalainen, Ari Antero Aarnio, Markku Kalevi Vimpari, Pekka Laitinen
  • Publication number: 20100325427
    Abstract: An approach is provided for authenticating a mobile device. A mobile device initiates transmission of a request to an authentication platform for generating a public-key certificate to access a service from the mobile device. The mobile device receives an identity challenge and responds by initiating transmission of a tag specific to the mobile device to the authentication platform. The authentication platform uses the tag to generate a public-key certificate.
    Type: Application
    Filed: June 22, 2009
    Publication date: December 23, 2010
    Applicant: Nokia Corporation
    Inventors: Jan-Erik Ekberg, Kari Kostiainen, Pekka Laitinen, Ville Aarni, Miikka Sainio, Niklas Von Knorring, Dmitry Kolesnikov, Atte Lahtiranta
  • Patent number: 7788493
    Abstract: A method of authenticating a user seeking access to a service from a service provider in a communication network, the method comprising: allocating to a user a plurality of service-specific identities for accessing respective services; issuing a request from the user, the request identifying the service to be accessed and including a public key of the user; at a certification authority, authenticating the request and issuing a public key certificate for binding the service-specific identity with the public key in the request, and returning the public key certificate to the user.
    Type: Grant
    Filed: February 17, 2005
    Date of Patent: August 31, 2010
    Assignee: Nokia Corporation
    Inventors: Risto Mononen, Nadarajah Asokan, Pekka Laitinen
  • Patent number: 7628322
    Abstract: Methods of creating a secure channel over which credit card personalization data can be transmitted over the air (OTA) are provided. In particular, Generic Authentication Architecture (GAA) may be used to establish a secure communication channel between the user equipment (UE) and a personalization application server or bureau acting as a network application function (NAF) server. An user equipment, personalization application service (e.g., a NAF server), a system embodying a personalization application server and an user equipment, and a computer program product are also provided for creating a secure channel, such as via GAA, over which credit card personalization data can be transmitted OTA.
    Type: Grant
    Filed: September 28, 2005
    Date of Patent: December 8, 2009
    Assignee: Nokia Corporation
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Publication number: 20090232310
    Abstract: An apparatus for providing key management for a mobile authentication architecture may include a processor. The processor may be configured to provide a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function, and cancel key information associated with the request for key revocation.
    Type: Application
    Filed: October 5, 2007
    Publication date: September 17, 2009
    Inventors: Silke Holtmanns, Pekka Laitinen, Hannu Tuominen
  • Publication number: 20080294560
    Abstract: A method comprising receiving at a user equipment encrypted content. The content is stored in said user equipment in an encrypted form. At least one key for decryption of said stored encrypted content is stored in the user equipment.
    Type: Application
    Filed: May 22, 2007
    Publication date: November 27, 2008
    Inventors: Silke Holtmanns, Pekka Laitinen, Tao Haukka
  • Publication number: 20080016230
    Abstract: A user equipment in a communications system, the user equipment comprising: a memory arranged to store at least one identifier associated with the user equipment; a transceiver arranged to communicate with a node in the communication system, wherein the transceiver is arranged to receive the at least one identifier from the node in the communications system, wherein the at least one identifier is used by the user equipment to authenticate the user equipment to at least one further node in the communications system.
    Type: Application
    Filed: June 28, 2007
    Publication date: January 17, 2008
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Publication number: 20070240205
    Abstract: Security level establishment for an application in a terminal equipment under a generic bootstrapping architecture offering a plurality of different bootstrapping mechanisms, the terminal equipment comprising a credential establishment entity and an application entity, comprising a request for a credential for the application from the application entity to the credential establishment entity and a response from the credential establishment entity to the application entity, wherein the response comprises the requested credential and credential quality information.
    Type: Application
    Filed: March 23, 2007
    Publication date: October 11, 2007
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Publication number: 20070234041
    Abstract: One aspect of the invention discloses a method of authenticating an application. The method comprising performing, with a server application, bootstrapping procedures between the server application and a bootstrapping server function; deriving a shared key based on at least a key received from the bootstrapping server function server during the bootstrapping procedures and a network application function identifier; providing an application with a bootstrapping transaction identifier, the bootstrapping transaction identifier being received from the bootstrapping server function server during the bootstrapping procedures; receiving a response from the application; and authenticating the application by validating the response with the shared key.
    Type: Application
    Filed: October 18, 2006
    Publication date: October 4, 2007
    Inventors: Shreekanth Lakshmeshwar, Philip Ginzboorg, Pekka Laitinen, Silke Holtmanns
  • Publication number: 20070223703
    Abstract: An approach is provided for providing service keys in multiple broadcast networks. A message including a group of keys is generated for providing secure communication over a first broadcast network and a second broadcast network. A message is transmitted to a terminal within the first broadcast network and a terminal within the second broadcast network. An encrypted service key is broadcast to the terminals, wherein the encrypted service key is decrypted using a portion of the group of keys.
    Type: Application
    Filed: October 10, 2006
    Publication date: September 27, 2007
    Inventors: Sanjeev Verma, Silke Holtmanns, Pekka Laitinen
  • Publication number: 20070192838
    Abstract: A method and arrangements for managing user security data stored in a database of a communications system. In the method a user equipment transmits a request to manage the user security data, the user equipment is authenticated, after which an application entity can manage user security data in the database that associates with the user by communicating data between the application entity and the database connected to the communications system.
    Type: Application
    Filed: January 30, 2007
    Publication date: August 16, 2007
    Inventors: Pekka Laitinen, Silke Holtmanns
  • Patent number: 7251733
    Abstract: A method in a system for transferring accounting information, a system for transferring accounting information, a method in a terminal, a terminal, a method in an Extensible Authentication Protocol (EAP) service authorization server, an EAP service authorization server, a computer program, an Extensible Authentication Protocol response (EAP-response) packet, wherein the method: meters data related to a service used by at least one terminal, provides the metered data as accounting information to at least one Extensible Authentication Protocol (EAP) service authorization server, sends, by means of an Extensible Authentication Protocol request (EAP-request), a service authorization request from the at least one EAP service authorization server to the at least one terminal, digitally signs accounting information, in the at least one terminal, includes, at the at least one terminal, the digitally signed accounting information in an Extensible Authentication Protocol response (EAP-response), and sends the digitally
    Type: Grant
    Filed: June 20, 2003
    Date of Patent: July 31, 2007
    Assignee: Nokia Corporation
    Inventors: Henry Haverinen, Pekka Laitinen, Nadarajah Asokan
  • Publication number: 20070124587
    Abstract: An apparatus for re-keying a mobile terminal in a foreign network includes a processor. The processor is configured to receive, at the apparatus which is physically located in the foreign network, a request for re-keying from the mobile terminal in the foreign network. The processor is also configured to translate the request for transmission to a home network of the mobile terminal and to transmit the translated request to a bootstrapping server function of the home network.
    Type: Application
    Filed: September 21, 2006
    Publication date: May 31, 2007
    Inventors: Govindarajan Krishnamurthi, Tat Chan, Pekka Laitinen
  • Publication number: 20070050365
    Abstract: A method and arrangements for managing user data stored in a database of a communications system where the database is managed by a main controller is disclosed. In the method a user is first authenticated, where after an application entity can manage user data in the database that associates with the user and an application by communicating data between the application entity and a second entity connected to the communications system.
    Type: Application
    Filed: October 13, 2005
    Publication date: March 1, 2007
    Inventors: Pekka Laitinen, Silke Holtmanns