Patents by Inventor Vesa Lehtovirta

Vesa Lehtovirta has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11381387
    Abstract: Methods, network nodes, computer programs, carrier and user equipment, wherein a proof-of-presence in communications between private land mobile networks (PLMNs) is presented. In an example method performed by a network node in a home public land mobile network (HPLMN) of a user equipment (UE), the network node obtains, from a visited public land mobile network (VPLMN), a proof-of-presence indicator that represents the UE as being present in the VPLMN. The network node verifies whether or not the UE is present in the VPLMN by determining whether or not the proof-of-presence indicator was generated by the UE using a secret shared between the UE and at least the HPLMN. Upon verification of the presence of the UE in the VPLMN, sensitive information can be communicated by the HPLMN to the VPLMN.
    Type: Grant
    Filed: July 25, 2017
    Date of Patent: July 5, 2022
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Prajwol Kumar Nakarmi, Noamen Ben Henda, Christine Jost, Vesa Lehtovirta, Vesa Torvinen
  • Patent number: 11374941
    Abstract: Integrity protection is activated for user plane data transferred between a network node and a terminal device of the cellular communications network. The activation can be initiated by the terminal device sending a request message to a second network node. Thus, a UE, such as a Cellular IoT UE, and a network node such as a SGSN are able to use LLC layer integrity protection for both control plane and user plane data.
    Type: Grant
    Filed: November 2, 2016
    Date of Patent: June 28, 2022
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Vesa Torvinen, Noamen Ben Henda, Vesa Lehtovirta, Katharina Pfeffer, Monica Wifvesson
  • Publication number: 20220201479
    Abstract: There is provided mechanisms for authenticating a first radio communication device with a network. A method is performed by the first radio communication device. The method comprises obtaining credentials for a network subscription to the network. The method comprises obtaining an upper part of a radio protocol stack, according to which radio protocol stack the first radio communication device is configured to communicate with the network. The method comprises authenticating with the network. The method comprises providing, to a second radio communication device, at least one key, as derived from the credentials during the authenticating, for use by the second radio communication device when executing the remaining part of the radio protocol stack for communication between the second radio communication device and the network.
    Type: Application
    Filed: March 15, 2019
    Publication date: June 23, 2022
    Inventors: Patrik Salmela, Per STÅHL, Kristian Slavov, Vesa Lehtovirta
  • Publication number: 20220167167
    Abstract: A method performed by a core network node (300) of a wireless communication system includes receiving a (902) registration request to register a fixed network residential gateway, FN-RG, to the core network, obtaining (904) an identifier associated with the FN-RG, and determining (906), based on the identifier of the FN-RG, that authentication of the FN-RG by the core network is not required.
    Type: Application
    Filed: February 24, 2020
    Publication date: May 26, 2022
    Inventors: Christine Jost, Helena Vahidi Mazinani, Noamen Ben Henda, Vesa Lehtovirta
  • Publication number: 20220159457
    Abstract: A method (300) for registering with a serving network (104). The method is performed by a UE (102). The method includes the UE transmitting (s302) to the serving network (104) a message (212) indicating a UE capability that is relevant for a home network (106), wherein the 5 serving network (104) is configured to send to the home network (106) a message (216) indicating the UE capability.
    Type: Application
    Filed: March 4, 2020
    Publication date: May 19, 2022
    Applicant: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Jari ARKKO, Vesa LEHTOVIRTA
  • Publication number: 20220159460
    Abstract: A method by a core network node of a core network of a wireless communication system for authenticating a user equipment, UE, to the core network includes receiving a first authentication request to authenticate the UE to the core network, determining that the UE should be authenticated by an external authentication entity that is external to the wireless communication system, transmitting a second authentication request to the external authentication entity, the second authentication request identifying the UE, receiving an authentication response from the external authentication entity verifying authenticity of the UE, the authentication response including a master key, and deriving a first key for securing communications with the UE from the master key.
    Type: Application
    Filed: February 24, 2020
    Publication date: May 19, 2022
    Inventors: Noamen Ben Henda, Monica Wifvesson, David Castellanos ZAMORA, Vesa Lehtovirta, Peter Hedman
  • Publication number: 20220150694
    Abstract: A method for key derivation for non-3GPP access. The method includes determining a particular non-3GPP access type, wherein the particular non-3GPP access type is one of N different particular non-3GPP access types (N>1), and each one of the N particular non-3GPP access types is associated with a unique access type distinguisher value. The method also includes generating (s604) a first access network key using a key derivation function and the unique access type distinguisher value with which the determined particular non-3GPP access type is associated, thereby generating a first access network key for the particular non-3GPP access type.
    Type: Application
    Filed: February 13, 2020
    Publication date: May 12, 2022
    Inventors: Vesa Lehtovirta, Christine Jost, Helena Vahidi Mazinani
  • Patent number: 11296890
    Abstract: A message authentication code, for a message transmitted and received over a communications network, is formed by applying inputs to an integrity algorithm acting on the message. The inputs comprise: an integrity key; a value indicating a transfer direction; and a frame-dependent integrity input, wherein the frame-dependent integrity input is a frame-dependent modulo count value that also depends on a random value and on a frame-specific sequence number.
    Type: Grant
    Filed: November 24, 2016
    Date of Patent: April 5, 2022
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Vesa Torvinen, Noamen Ben Henda, Qian Chen, Vesa Lehtovirta, Mats Näslund, Karl Norrman, Gang Ren, Mikael Wass, Monica Wifvesson
  • Publication number: 20220095104
    Abstract: A method performed by an Authentication and Key Management for Applications security anchor function (AAnF) includes determining that an anchor key associated with a user equipment (UE) is no longer valid and sending, to at least one Authentication and Key Management for Applications application function (AKMA AF) a message that revokes the anchor key.
    Type: Application
    Filed: January 20, 2020
    Publication date: March 24, 2022
    Inventors: Noamen BEN HENDA, Henrik NORMANN, Vesa LEHTOVIRTA, Helena VAHIDI MAZINANI
  • Patent number: 11233817
    Abstract: A method performed by a proximity service server. The method comprises generating a ProSe query code and a ProSe response code, sending at least the ProSe response code together with a first and a second discovery key to a first end device, and sending at least the first discovery key and the ProSe query code to a second end device, so that the second end device can securely discover the first end device over an air interface.
    Type: Grant
    Filed: February 19, 2020
    Date of Patent: January 25, 2022
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Vesa Lehtovirta, Katharina Pfeffer, Vesa Torvinen, Monica Wifvesson
  • Publication number: 20220014914
    Abstract: A method for re-establishing a Radio Resource Control (RRC) connection between a UE and a target eNB. The method is performed by the UE. The method includes the UE receiving an RRC Connection Reestablishment message from the target eNB, the RRC Connection Reestablishment message including a DL authentication token which has been generated by an MME and has had a Non Access Stratum integrity key as input. The method also includes the UE authenticating the received DL authentication token.
    Type: Application
    Filed: September 28, 2021
    Publication date: January 13, 2022
    Applicant: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Vesa LEHTOVIRTA, Prajwol Kumar NAKARMI, Monica WIFVESSON
  • Publication number: 20210400475
    Abstract: A method is performed by a communications device. The method may comprise receiving, via a control plane of a serving network of the communications device, a message in anauthentication procedure for authentication of the communications device with a home network of the communications device. The message in some embodiments indicates that the authentication is for the purpose of establishing a shared security key between the communications device and an application server.
    Type: Application
    Filed: November 1, 2019
    Publication date: December 23, 2021
    Inventors: Vesa Lehtovirta, Vesa Torvinen, Noamen Ben Henda
  • Publication number: 20210367951
    Abstract: A method for improving data transmission security at a user equipment comprises receiving, from a source network node, a connection release message including instructions for computing a hash value for data to be included in a connection request message; computing the hash value based on the instructions included in the connection release message; calculating a token based on the hash value, and sending, to a target network node, the connection request message including the token. The method may further forward the data from the target network node directly to a gateway after the token has been verified. The method may reduce a signaling overhead by having a fixed-size hash value for data. Furthermore, the method may improve a transmission security by including the token in an RRC message, in which the token is calculated based on the hash value representing the data.
    Type: Application
    Filed: February 14, 2019
    Publication date: November 25, 2021
    Inventors: Magnus STATTIN, Vesa LEHTOVIRTA, Prajwol Kumar NAKARMI, Dung PHAM VAN
  • Patent number: 11146951
    Abstract: A method for re-establishing a Radio Resource Control, RRC, connection between a User Equipment (1), UE, and a target evolved NodeB (3), target eNB, the method being performed by the UE (1) and comprising: receiving (S100) an RRC Connection Reestablishment message from the target eNB (3), the RRC Connection Reestablishment message including a downlink, DL, authentication token which has been generated by a Mobility Management Entity (4) and has had a Non Access Stratum integrity key as input; and authenticating (S110) the received DL authentication token. Discloses are also UEs, target eNBs, source eNBs and Mobility Management Entities as well as methods, computer programs and computer program product related thereto.
    Type: Grant
    Filed: January 29, 2018
    Date of Patent: October 12, 2021
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Vesa Lehtovirta, Prajwol Kumar Nakarmi, Monica Wifvesson
  • Publication number: 20210297400
    Abstract: Secure, authenticated communication is enabled between an initiator (12) (e.g., a user equipment) and a responder (14) (e.g., an authentication server function, AUSF, or a subscription de-concealing function, SIDF). The initiator (12) transmits a message (20) to the responder (14) over a secure communication channel (16). The message (20) may include information indicating a third party (18) whose signing of data (e.g., bound to the secure communication channel (16)) will authenticate the responder (14) to the initiator (12). The responder (14) correspondingly retrieves from the third party (18) data that is signed by the third party (18) and transmits a response (24) to the initiator (12) that includes the retrieved data. The initiator (12) receives this response (24) and determines whether or not the responder (14) is authenticated by determining whether or not the response (24) includes data that is signed by the third party (18).
    Type: Application
    Filed: August 2, 2018
    Publication date: September 23, 2021
    Inventors: Vesa Lehtovirta, Mohit Sethi
  • Publication number: 20210297855
    Abstract: A method by an AUSF of a home PLMN configured to communicate through an interface with electronic devices is provided. A first authentication request is received from a first PLMN that is authenticating an electronic device. A first security key used for integrity protection of messages delivered from the home PLMN to the electronic device is obtained. A second authentication request is received from a second PLMN that is authenticating the electronic device. A second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device is obtained. A message protection request is received. Which of the first security key and the second security key is a latest security key is determined. The latest security key is used to protect a message associated with the message protection request.
    Type: Application
    Filed: June 2, 2021
    Publication date: September 23, 2021
    Inventors: Noamen Ben Henda, David Castellanos ZAMORA, Monica Wifvesson, Vesa Lehtovirta
  • Patent number: 11122419
    Abstract: There is provided mechanisms for obtaining initial cellular network connectivity. A method is performed by a terminal device. The method comprises obtaining an activation code for a network subscription and MNO specific information. The method comprises identifying at least one MNO from the MNO specific information. The method comprises wirelessly authenticating with an MNO node of one of the at least one identified MNO by using the MNO specific information to obtain the initial cellular network connectivity.
    Type: Grant
    Filed: May 10, 2017
    Date of Patent: September 14, 2021
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Kazi Wali Ullah, Vesa Lehtovirta, Patrik Salmela
  • Patent number: 11082844
    Abstract: A method performed by a network server is provided for authentication and key management for a terminal device in a wireless communication network. The method includes authenticating the terminal device during a primary authentication session for the terminal device. The method further includes responsive to a successful authentication of the terminal device, obtaining a first key. The method further includes generating bootstrapping security parameters. The parameters include a second key derived from the first key and a temporary identifier. The temporary identifier identifies the terminal device and the bootstrapping security parameters.
    Type: Grant
    Filed: January 26, 2021
    Date of Patent: August 3, 2021
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Noamen Ben Henda, Helena Vahidi Mazinani, Vesa Lehtovirta
  • Patent number: 11070631
    Abstract: A terminal device, for example a 3GPP Proximity Services (ProSe)-enabled user equipment, obtains imprecise location information relating to a location of the terminal device, and transmits a proximity service discovery message, wherein the discovery message includes the imprecise location information. A second terminal device, again for example a 3GPP Proximity Services (ProSe)-enabled user equipment, receives a proximity service discovery message containing location information. The second terminal device obtains location information relating to its location, and calculates a distance from the location indicated by the location information in the received discovery message to its location. The second terminal device acts on the received discovery message only if the calculated distance is less than a predetermined distance.
    Type: Grant
    Filed: November 24, 2016
    Date of Patent: July 20, 2021
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Monica Wifvesson, Noamen Ben Henda, Vesa Lehtovirta, Katharina Pfeffer, Shabnam Sultana, Vesa Torvinen
  • Patent number: 11039312
    Abstract: A method by an AUSF of a home PLMN configured to communicate through an interface with electronic devices is provided. A first authentication request is received from a first PLMN that is authenticating an electronic device. A first security key used for integrity protection of messages delivered from the home PLMN to the electronic device is obtained. A second authentication request is received from a second PLMN that is authenticating the electronic device. A second security key used for integrity protection of the messages delivered from the home PLMN to the electronic device is obtained. A message protection request is received. Which of the first security key and the second security key is a latest security key is determined. The latest security key is used to protect a message associated with the message protection request.
    Type: Grant
    Filed: January 20, 2021
    Date of Patent: June 15, 2021
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Vesa Lehtovirta, Noamen Ben Henda, David Castellanos Zamora, Monica Wifvesson