Patents by Inventor Pekka Laitinen

Pekka Laitinen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20060271785
    Abstract: This invention relates to security procedures in a communication system, specifically to production of key material. The invention provides a method for producing key material in a highly secure way for use in communication with a local network of a company. The method uses authentication information obtained from the communication system and information exchanged locally between a mobile station and the authentication systems of the company to produce a communication key for use in authentication procedures or e.g. for signing and/or encrypting data.
    Type: Application
    Filed: September 16, 2005
    Publication date: November 30, 2006
    Inventors: Silke Holtmanns, Pekka Laitinen, Philip Ginzboorg, Kari Miettinen, Jaakko Rajaniemi
  • Publication number: 20060230436
    Abstract: A method and apparatus provide generic mechanism for a network application server. A receiver receives a request from a user equipment to provide authentication information to a network application function. A determining unit determines a key of a generic authentication architecture to integrate additional network application servers by extending an existing standard for user security settings. A providing unit provides the authentication information to the network application function.
    Type: Application
    Filed: July 20, 2005
    Publication date: October 12, 2006
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Publication number: 20060218396
    Abstract: A method and apparatus for authenticating to a third party service provider from a personal computer. The method includes authenticating, with a mobile terminal, to the service provider with a universal subscriber identity module associated with the mobile terminal to obtain credentials specific to the service provider, transferring the credentials specific to the service provider from the mobile terminal to the personal computer, and accessing the service provider with the personal computer using the credentials transferred from the mobile terminal. The apparatus includes a mobile terminal, a computing device, a bootstrapping security module, and a network application function that cooperatively work to allow the computing device to access the network application function using a security credential from the mobile terminal.
    Type: Application
    Filed: January 10, 2006
    Publication date: September 28, 2006
    Inventors: Pekka Laitinen, Shreekanth Lakshmeshwar
  • Publication number: 20060196931
    Abstract: Methods of creating a secure channel over which credit card personalization data can be transmitted over the air (OTA) are provided. In particular, Generic Authentication Architecture (GAA) may be used to establish a secure communication channel between the user equipment (UE) and a personalization application server or bureau acting as a network application function (NAF) server. An user equipment, personalization application service (e.g., a NAF server), a system embodying a personalization application server and an user equipment, and a computer program product are also provided for creating a secure channel, such as via GAA, over which credit card personalization data can be transmitted OTA.
    Type: Application
    Filed: September 28, 2005
    Publication date: September 7, 2006
    Applicant: Nokia Corporation
    Inventors: Silke Holtmanns, Pekka Laitinen
  • Publication number: 20060182280
    Abstract: An approach is provided for performing authentication in a communication system. In one embodiment, a key is established with a terminal in a communication network according to a key agreement protocol. The agreed key is tied to an authentication procedure to provide a security association that supports reuse of the key. A master key is generated based on the agreed key. In another embodiment, digest authentication is combined with key exchange parameters (e.g., Diffie-Hellman parameters) in the payload of the digest message, in which a key (e.g., SMEKEY or MN-AAA) is utilized as a password. In yet another embodiment, an authentication algorithm (e.g., Cellular Authentication and Voice Encryption (CAVE)) is employed with a key agreement protocol with conversion functions to support bootstrapping.
    Type: Application
    Filed: February 10, 2006
    Publication date: August 17, 2006
    Inventors: Pekka Laitinen, Philip Ginzboorg, Nadarajah Asokan, Garbor Bajko
  • Publication number: 20060185003
    Abstract: An apparatus and method for sharing data in a communications system include a bootstrapping server function (BSF) configured to transmit a first message. The first message includes a timestamp parameter corresponding to a generic bootstrapping architecture user security settings (GUSS) stored in the BSF. A home subscriber server (HSS) is configured to receive the first message, to compare the timestamp parameter corresponding to the GUSS stored in the BSF with a timestamp parameter corresponding to a GUSS stored in the HSS, and to transmit a second message back to the BSF excluding the GUSS when the timestamp parameters of the GUSS of the BSF and the HSS are equal.
    Type: Application
    Filed: December 16, 2005
    Publication date: August 17, 2006
    Inventors: Pekka Laitinen, Philip Ginzboorg
  • Publication number: 20060174117
    Abstract: Methods, a client entity, network entities, a system, and a computer program product perform authentication between a client entity and a network. The network includes at least a bootstrapping server function entity and a network application function entity. The client entity is not able to communicate with both of the network entities in a bidirectional manner. The 3GPP standard Ub reference point between the client entity and the bootstrapping server function entity is not utilized for authentication purposes, such as authentication using GAA functionality for unidirectional network connections.
    Type: Application
    Filed: April 19, 2005
    Publication date: August 3, 2006
    Inventor: Pekka Laitinen
  • Publication number: 20060101270
    Abstract: Methods, user equipment, a bootstrapping server function and computer programs determine a key derivation function to be used by user equipment. The user equipment sends an authentication request to a bootstrapping server function. The bootstrapping server function sends a key derivation function identifier along with a bootstrapping transaction identifier to the user equipment. Based on the key derivation function identifier, the user equipment is able to determine which key derivation function to use.
    Type: Application
    Filed: October 14, 2005
    Publication date: May 11, 2006
    Inventor: Pekka Laitinen
  • Publication number: 20060075222
    Abstract: A method and corresponding equipment, for enabling a subscriber device (14) to engage a service provided by a server (12) to give a friend device (15) access to the service, including a step (21) in which the subscriber device (14) engages the server (12) to provide the service and obtains a subscriber certificate corresponding to the service; and a step (24) in which the subscriber device (14) issues to the friend device (15) a friend certificate based on the subscriber certificate, the friend certificate being such that it is recognized by the server as entitling the friend device to the service.
    Type: Application
    Filed: October 6, 2004
    Publication date: April 6, 2006
    Inventors: Seamus Moloney, Pekka Laitinen, Sampo Sovio
  • Publication number: 20060020791
    Abstract: An entity uses generic authentication architecture and Liberty architecture. The entity provides both a Liberty enabled proxy function and a network application function.
    Type: Application
    Filed: July 22, 2004
    Publication date: January 26, 2006
    Inventor: Pekka Laitinen
  • Publication number: 20050287990
    Abstract: A method of authenticating a user seeking access to a service from a service provider in a communication network, the method comprising: allocating to a user a plurality of service-specific identities for accessing respective services; issuing a request from the user, the request identifying the service to be accessed and including a public key of the user; at a certification authority, authenticating the request and issuing a public key certificate for binding the service-specific identity with the public key in the request, and returning the public key certificate to the user.
    Type: Application
    Filed: February 17, 2005
    Publication date: December 29, 2005
    Inventors: Risto Mononen, Nadarajah Asokan, Pekka Laitinen
  • Publication number: 20050278420
    Abstract: There is disclosed a method for verifying a first identity and a second identity of an entity, said method comprising: receiving a first and second identity of said entity at a checking entity; sending information relating to at least one of the first and second identities to a home subscriber entity; and verifying that said first and second identities both belong to the entity from which said first and second identities have been received.
    Type: Application
    Filed: April 26, 2005
    Publication date: December 15, 2005
    Inventors: Auvo Hartikainen, Kalle Tammi, Toni Miettinen, Lauri Laitinen, Philip Ginzboorg, Pekka Laitinen
  • Publication number: 20050246548
    Abstract: A method for verifying a first identity and a second identity of an entity, said method comprising: receiving first identity information at a checking entity; sending second identity information from the entity to said checking entity; verifying that the first and second identities both belong to said entity; and generating a key using one of said first and second identity information.
    Type: Application
    Filed: June 21, 2004
    Publication date: November 3, 2005
    Inventor: Pekka Laitinen
  • Publication number: 20050216740
    Abstract: Method and apparatus for dealing with digital certificate requests in a mobile telecommunications network. A request for a digital certificate is sent from a subscriber to a network element via the network, the request including a first part and a second part. The first part is sent via an authenticated communication channel of the network and the second part is sent via an unprotected communication channel of the network.
    Type: Application
    Filed: February 22, 2002
    Publication date: September 29, 2005
    Inventors: Pekka Laitinen, Nadarajah Asokan, Risto Kuusela
  • Publication number: 20050102501
    Abstract: A communication system including at least one user equipment and at least one network application functional entity is disclosed. The system further includes a bootstrapping functional entity. The user equipment includes means to transmit a request to push authentication information to at least one network application function. The bootstrapping functional entity includes receiving means for receiving the request from the user equipment, and transmitting means for transmitting the authentication information to the at least one network application function entity. The at least one network application function includes means adapted to receive unsolicited bootstrapping information from the bootstrapping functional entity.
    Type: Application
    Filed: January 21, 2004
    Publication date: May 12, 2005
    Inventors: Tao Haukka, Pekka Laitinen, Nadarajah Asokan
  • Publication number: 20050002382
    Abstract: A communication system comprising a data communication network, a service provider and a communication terminal is described. The communication terminal includes a user interaction device, a processor, a memory and a character stored in the memory and capable of running on the processor and of providing a presence on the user interaction device. The communication system also comprises an agent residing in the data communication network being configurable to collect data from the service provider, of providing a continuous follow-up of occurrences in the network and of providing the data to the character. The character is configurable to approach the agent and to receive the data from the agent over a wireless link supported by the communication terminal and to present the data to the user by means of the user interaction device. Furthermore, a method for data transfer from a service provider to a communication terminal over a data communication network is described.
    Type: Application
    Filed: June 29, 2004
    Publication date: January 6, 2005
    Inventors: Jyri Salomaa, Pekka Lahtinen, Pekka Laitinen, Olli Rantapuska, Juha Saarnio, Jaakko Teinila
  • Publication number: 20040064741
    Abstract: A method in a system for transferring accounting information, a system for transferring accounting information, a method in a terminal, a terminal, a method in an Extensible Authentication Protocol (EAP) service authorization server, an EAP service authorization server, a computer program, an Extensible Authentication Protocol response (EAP-response) packet, wherein the method:
    Type: Application
    Filed: June 20, 2003
    Publication date: April 1, 2004
    Applicant: Nokia Corporation
    Inventors: Henry Haverinen, Pekka Laitinen, Nadarajah Asokan