Patents by Inventor Anja Jerichow
Anja Jerichow has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12676841Abstract: According to an example aspect of the present invention, there is provided an apparatus configured to receive a service request for a service provided by the apparatus, determine whether to provide the service based at least partly on an authentication based on a first identifier, comprised in an access token in the service request, and on a second identifier, comprised in a credential data element in the service request, wherein the authentication is successful when the first identifier and the second identifier identify a same network function instance or same network function instance set, and provide the service responsive to a result of the determination indicating the service is to be provided.Type: GrantFiled: January 4, 2022Date of Patent: July 7, 2026Assignee: Nokia Technologies OyInventors: Saurabh Khare, Chaitanya Aggarwal, Anja Jerichow
-
Patent number: 12671977Abstract: Techniques for enhancing subscription authorization in a communications network are provided. For example, a method in a source network function service producer or an apparatus for a source network function service provider is disclosed. The method comprises: receiving a subscription request including access authorization information from a network function service consumer for a subscription to receive a notification upon occurrence of a specific event; verifying that the network function service consumer is authorized to create the subscription to the source network function service producer; storing subscription context and access authorization information granted for the subscription if the subscription request is authorized.Type: GrantFiled: July 14, 2023Date of Patent: June 30, 2026Assignee: Nokia Technologies OyInventors: Saurabh Khare, Bruno Landais, Anja Jerichow
-
Publication number: 20260058956Abstract: Example embodiments of the disclosure relate to methods, devices, apparatuses and computer readable storage medium for resource owner(s) authorization for an Application Programming Interface (API) invoker in Communication API Framework (CAPIF) Resource owner-aware Northbound API Access (RNAA) context. In a method, a first apparatus transmits, to a second apparatus, an access token request for authorization from one or more resource owners. The access token request comprises first information for accessing resources of the one or more resource owners, each of the one or more resource owners being different from a further resource owner associated with the first apparatus; and receive. Then, the first apparatus receives, from the second apparatus, an access token response comprising second information indicating a result of the authorization for accessing the resources of the one or more resource owners.Type: ApplicationFiled: August 14, 2025Publication date: February 26, 2026Inventors: Sireesha BOMMISETTY, Topuri BRAHMAIAH, Mallikarjunudu MAKHAM, Anja JERICHOW, Niranth AMOGH, Saurabh KHARE, Edoardo GIORDANO
-
Patent number: 12563391Abstract: Techniques are disclosed for security management for authentication failure notification in a communication system. For example, a method comprises receiving, at user equipment from a network entity in a communication system, a message comprising an indication of at least one specific cause for a failure in an authentication procedure between the communication system and the user equipment, wherein the at least one specific cause comprises an occurrence of an authentication credential expiration. The user equipment may apply a policy and/or take one or more actions in response to receipt of the message.Type: GrantFiled: February 10, 2023Date of Patent: February 24, 2026Assignee: Nokia Technologies OyInventor: Anja Jerichow
-
Publication number: 20260039650Abstract: Example embodiments of the present disclosure relate to access token verification. In example embodiments, a method is provided.Type: ApplicationFiled: July 21, 2022Publication date: February 5, 2026Inventors: Xin WANG, Bruno LANDAIS, Anja JERICHOW, Jani Petteri EKMAN, Xin Xin WANG, Han Xiao DU, Horst Thomas BELLING
-
Patent number: 12535965Abstract: The disclosure relates to an apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to: receive one or more rules for storing data or analytics in a storage; determine a storage approach based on the one or more rules for storing data or analytics in the storage; and track data or analytics in the storage and determine whether to store, update or remove all or a portion of the data or analytics in the storage based on the storage approach.Type: GrantFiled: September 7, 2022Date of Patent: January 27, 2026Assignee: NOKIA TECHNOLOGIES OYInventors: Colin Kahn, Gerald Kunzmann, Saurabh Khare, Anja Jerichow, Yannick Lair
-
Patent number: 12519709Abstract: There is disclosed a network apparatus that is caused to receive analytics data from a first network apparatus, determine that said analytics data is usable by a second network apparatus, and send said analytics data to the second network apparatus in dependence on said determining.Type: GrantFiled: August 11, 2020Date of Patent: January 6, 2026Assignee: NOKIA TECHNOLOGIES OYInventors: Shubhranshu Singh, Yannick Lair, Laurent Thiebaut, Saurabh Khare, Anja Jerichow
-
Patent number: 12513523Abstract: According to an example aspect of the present invention, there is provided an apparatus comprising means for determining a data privacy filter of a user equipment, wherein the data privacy filter is configured to be used in a visited network by the user equipment to determine whether a request, from a network function in the visited network, to collect data from the user equipment is acceptable and whether the user equipment should transmit said data to the network function and means for transmitting, to the user equipment located in the visited network, the data privacy filter of the user equipment.Type: GrantFiled: February 15, 2022Date of Patent: December 30, 2025Assignee: NOKIA TECHNOLOGIES OYInventors: Saurabh Khare, Chaitanya Aggarwal, Anja Jerichow
-
Publication number: 20250358622Abstract: A user equipment in a communication system, a unified subscription identifier data structure is constructed. The unified subscription identifier data structure includes a plurality of fields that specify information for a selected one of two or more subscription identifier types and selectable parameters associated with the selected subscription identifier type, and wherein the information in the unified subscription identifier data structure is useable by the user equipment to access one or more networks associated with the communication system based on an authentication scenario corresponding to the selected subscription identifier type. For example, during different authentication scenarios, the user equipment utilizes the unified subscription identifier data structure to provide the appropriate subscription identifier (e.g., SUPI, SUCI or IMSI) and associated parameters for a given authentication scenario.Type: ApplicationFiled: July 28, 2025Publication date: November 20, 2025Inventors: Suresh NAIR, Anja JERICHOW, Nagendra S BYKAMPADI, Dimitrios SCHOINIANAKIS
-
Publication number: 20250338203Abstract: The disclosure relates to a first apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to: send (500), to a second apparatus, a request comprising information indicating a list of public land mobile network identifiers identifying a first public land mobile network supported by the first apparatus, and information to derive a second public land mobile network supported by the second apparatus; and receive (502), from the second apparatus, a response comprising information indicating a list of public land mobile network identifiers identifying the second public land mobile network supported by the second apparatus.Type: ApplicationFiled: April 30, 2025Publication date: October 30, 2025Inventors: Saurabh KHARE, Bruno LANDAIS, Anja JERICHOW
-
Patent number: 12452063Abstract: According to an example aspect of the present invention, there is provided an apparatus configured to function as a network function repository, and transmit to a network function consumer an access token authorizing access to a service provided by a network function producer, the access token comprising an at least one of: indication of a fully qualified domain name of the network function consumer, an indication of a domain from which access to the network function producer is allowed and an indication of a stand-alone non-public network from which access to the network function producer is allowed.Type: GrantFiled: July 28, 2022Date of Patent: October 21, 2025Assignee: Nokia Technologies OyInventors: Saurabh Khare, Chaitanya Aggarwal, Anja Jerichow, Georgios Gkellas
-
Patent number: 12425857Abstract: In one example, a method initiates establishment of a secure tunnel by a security proxy element (e.g., SEPP) in a first communication network (e.g., VPLMN) with an internetwork exchange element (e.g., IPX node) which is operatively coupled between the first communication network and a second communication network (e.g., HPLMN). Upon establishment of the secure tunnel, the method sends a message from the security proxy element to the internetwork exchange element over the secure tunnel. The secure tunnel can be a VPN tunnel and can be established using TLS or IPsec. In one example, the internetwork exchange node functions as an HTTP proxy, and in another embodiment as an interception (e.g., MITM) proxy. In another example, HTTPS is used to establish a separate TLS connection for each HTTP message. In yet another example, the security proxy element is configured to select (and change as needed) the secure communication mechanism.Type: GrantFiled: September 20, 2019Date of Patent: September 23, 2025Assignee: Nokia Technologies OyInventors: Nagendra S Bykampadi, Anja Jerichow, Suresh Nair
-
Patent number: 12425480Abstract: It is provided a method comprising at least one of a) and b): a) monitoring whether a service request to produce a producer service is received and producing the producer service if the service request is received, wherein the producer service is a service produced by the access network; and b) consuming a producer service from a core network or an access network, wherein the producer service is consumed by an access network.Type: GrantFiled: December 18, 2020Date of Patent: September 23, 2025Assignee: Nokia Technologies OyInventors: Ă–mer Bulakci, Bruno Landais, Laurent Thiebaut, Thomas Belling, Anja Jerichow, Hannu Flinck, Jens Gebert, Christian Mannweiler, Subramanya Chandrashekar, Philippe Godin
-
Patent number: 12418569Abstract: The apparatus includes a memory configured to store security information, and at least one processing core, configured to generate the security information by defining a security policy concerning user plane transfer of precision time protocol messages, and to instruct at least one network node to implement the security policy by transmitting the security information to the at least one network node.Type: GrantFiled: October 15, 2020Date of Patent: September 16, 2025Assignee: Nokia Technologies OyInventors: Anja Jerichow, Genevieve Mange
-
Patent number: 12413982Abstract: A user equipment in a communication system, a unified subscription identifier data structure is constructed. The unified subscription identifier data structure includes a plurality of fields that specify information for a selected one of two or more subscription identifier types and selectable parameters associated with the selected subscription identifier type, and wherein the information in the unified subscription identifier data structure is useable by the user equipment to access one or more networks associated with the communication system based on an authentication scenario corresponding to the selected subscription identifier type. For example, during different authentication scenarios, the user equipment utilizes the unified subscription identifier data structure to provide the appropriate subscription identifier (e.g., SUPI, SUCI or IMSI) and associated parameters for a given authentication scenario.Type: GrantFiled: January 5, 2024Date of Patent: September 9, 2025Assignee: NOKIA TECHNOLOGIES OYInventors: Suresh Nair, Anja Jerichow, Nagendra S Bykampadi, Dimitrios Schoinianakis
-
Patent number: 12413591Abstract: There is provided a method, apparatus and computer program product for causing a network repository function to perform: receiving, from a network function service consumer, an access request for an access authorization token, the request comprising a first identification of the network function service consumer and a first identification of at least one network slice on which access is requested; generating an access token in response to the request, the access token comprising at least one network slice identifier for the at least one network slice identified by the first identification; and providing the generated access token to the network function in response to the request for an access authorization token.Type: GrantFiled: May 4, 2022Date of Patent: September 9, 2025Assignee: Nokia Technologies OyInventors: Chaitanya Aggarwal, Suresh Nair, Saurabh Khare, Anja Jerichow, Laurent Thiebaut
-
Patent number: 12401690Abstract: Example embodiments of the present disclosure relate to dynamic authorization. According to embodiments of the present disclosure, a solution for dynamic access control to data is proposed. On receiving data registration from a data source, a first device checks the data types to be produced by the data source and adds policies for the data or updates existing policies for the data according to its property. It also serves as access control decision point to determine consumers' access rights based on centrally managed policies. Authorization for data access is granted/denied according to local attributes/policies. In this way, it achieves a dynamic, context-aware and risk-intelligent access control to different kind of data from various data sources (i.e., service producers).Type: GrantFiled: October 9, 2020Date of Patent: August 26, 2025Assignee: NOKIA TECHNOLOGIES OYInventors: Iris Adam, Jing Ping, Konstantinos Samdanis, Chaitanya Aggarwal, Anja Jerichow
-
Patent number: 12335851Abstract: The disclosure relates to a first apparatus comprising at least one processor and at least one memory including computer code for one or more programs, the at least one memory and the computer code configured, with the at least one processor, to cause the apparatus at least to: send (500), to a second apparatus, a request comprising information indicating a list of public land mobile network identifiers identifying a first public land mobile network supported by the first apparatus, and information to derive a second public land mobile network supported by the second apparatus; and receive (502), from the second apparatus, a response comprising information indicating a list of public land mobile network identifiers identifying the second public land mobile network supported by the second apparatus.Type: GrantFiled: August 4, 2022Date of Patent: June 17, 2025Assignee: Nokia Technologies OyInventors: Saurabh Khare, Bruno Landais, Anja Jerichow
-
Patent number: 12328395Abstract: According to an example aspect of the present invention, there is provided an apparatus configured to process a request for an access token authorizing access for a network function consumer to a service provided by a network function producer, the request being received in the apparatus from a service communication proxy, wherein the processing comprises one or more of the following verification: verification that a credential data element comprised in the request, cryptographically signed by the network function consumer, identifies the request, the service or a type of the service, and verification with reference to a further node, or to a profile of the network function consumer, that the service communication proxy is authorized to act on behalf of the network function consumer, and transmit, responsive to at least one of the verifications being successful, the requested access token, the access token comprising an indication of the service communication proxy.Type: GrantFiled: October 18, 2022Date of Patent: June 10, 2025Assignee: NOKIA TECHNOLOGIES OYInventors: Chaitanya Aggarwal, Anja Jerichow, Saurabh Khare, Georgios Gkellas
-
Publication number: 20250126466Abstract: There are provided measures for error message generation and processing. Such measures exemplarily comprise, at a first network entity associated with a first network roaming interconnected with a second network, receiving a message indicative of a roaming service related error, wherein said message includes first error cause information related to said roaming service related error and addressed to said first network entity, and deciding on further handling of said message based on said first error cause information.Type: ApplicationFiled: August 27, 2024Publication date: April 17, 2025Inventors: Anja JERICHOW, Horst Thomas Belling, Bruno Landais