Patents by Inventor Bernard Smeets

Bernard Smeets has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12683951
    Abstract: A method, system and nodes are disclosed. According to one or more embodiments, a management node is provided. The management node includes processing circuitry configured to receive an origin certificate for a first service type where the received origin certificate includes a public key and a private key, receive a certificate request for a first instance of the first service type, generate a first proxy certificate based at least on the received origin certificate, and transmit the first proxy certificate and the public key of the received origin certificate to a first virtual network function component where the public key of the received origin certificate is for inclusion to a listing of trusted certificates at the first virtual network function component.
    Type: Grant
    Filed: June 9, 2021
    Date of Patent: July 14, 2026
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Makan Pourzandi, Bernard Smeets, Harri Hakala, Tommy Arngren, Yosr Jarraya
  • Patent number: 12645812
    Abstract: A method at a first communication device for providing a second communication device access to content, the method comprising: providing an offer to the second communication device, offering the second communication device conditional access to the content, wherein access to the content at the second communication device is adaptable based on sensor data of at least one of the first and the second communication device; acquiring sensor data of at least one of the first and the second communication device; providing the second communication device full access to the content in case it is that the sensor data of at least one of the first and the second communication device indicates that the second communication device shall be grated full access to the content, or determining that access to the content is to be restricted at the second communication device, and providing the second communication device restricted access to the content, in case it is determined that sensor data of at least one of the first and
    Type: Grant
    Filed: March 16, 2021
    Date of Patent: June 2, 2026
    Assignee: Telefonaktiebolaget LM Ericsson (PUBL)
    Inventors: Tommy Arngren, Bernard Smeets, Peter Ökvist
  • Patent number: 12634272
    Abstract: A user terminal emulation server establishes a secure channel connection with a first I/O user device using a session identifier and an identifier associated with the first I/O user device to determine a first I/O user device specific key generated from a master key, the first I/O user device specific key and the session identifier being used for secure communication of messages with the first I/O user device. An indication of an I/O user interface capability of the first I/O user device is received through the secure channel connection with the first I/O user device. The user terminal emulation server communicates with the first I/O user device to use the I/O user interface capability to provide at least part of the communication service for a user.
    Type: Grant
    Filed: April 28, 2022
    Date of Patent: May 19, 2026
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Tommy Arngren, Bernard Smeets, Peter Ökvist, Patrik Salmela
  • Patent number: 12598085
    Abstract: A method, network node and non-transitory computer readable media having stored thereon instructions for correlating a remote attestation quote with a virtualized network function (VNF) resource allocation event. The method comprises obtaining a set of VNF components (VNFCs) that require remote attestation. The method comprises obtaining an attestation quote for each VNFC of the set of VNFCs, the attestation quote ensuring that instances of each VNFC are used in a legitimate context. The method comprises correlating each attestation quote with the VNF resource allocation event.
    Type: Grant
    Filed: November 3, 2022
    Date of Patent: April 7, 2026
    Assignee: Telefonaktiebolaget L M Ericsson (publ)
    Inventors: Bernard Smeets, Cristina Badulescu, Daniel Migault, Stere Preda
  • Patent number: 12568354
    Abstract: There is provided mechanisms for downloading an operational subscription profile to a communication device. A method is performed by the communication device. The communication device has an EID and is provided with a provisioning subscription profile. The method comprises obtaining a temporary PSI for the provisioning subscription profile, wherein the temporary PSI is based on the EID. The method comprises providing, whilst using the provisioning subscription profile, the temporary PSI to a first MNO as part of performing network attachment with the first MNO. The first MNO is selected based on the temporary PSI. The method comprises obtaining, whilst using the provisioning subscription profile and as part of performing network access authentication for the network attachment, an operational PSI from an eSIM server via the first MNO.
    Type: Grant
    Filed: February 5, 2021
    Date of Patent: March 3, 2026
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Per Ståhl, Bernard Smeets
  • Publication number: 20260005740
    Abstract: Various embodiments of the present disclosure provide for a method and apparatuses that perform spatial encoding in a multipath environment such that transmissions on different beams are separately encrypted with complex codes such that when the transmissions on the different beams are received at the receiver, the separate encryptions are cancelled out. The transmissions can also have time delay, gain, and phase modifications made to the transmissions such that the automatic self-decryption is performed within a predefined distance of where the receiver is determined to be. In this way, encryption/decryption keys do not have to be sent to the receiver, and unauthorized devices that intercept the beams at a location other than the receiver location will not be able to decrypt the communication.
    Type: Application
    Filed: September 19, 2022
    Publication date: January 1, 2026
    Inventors: Bernard Smeets, Raihan Rafique, Leif Wilhelmsson
  • Patent number: 12505202
    Abstract: A method for enabling attestation of a platform comprising a Trusted Execution Environment, TEE, and a Trusted Platform Module, TPM is disclosed. The method is performed by the TEE and comprises: receiving, from an Application of the platform, a request for generation of an attestation quote, the request comprising a nonce, information on which PCR(s) to be used and information about Attestation Keys; establishing a connection to the TPM and obtaining from it at least one PCR value; generating an attestation quote based on the received nonce and the at least one PCR value; signing the attestation, and rendering the attestation quote available for the Application.
    Type: Grant
    Filed: March 31, 2021
    Date of Patent: December 23, 2025
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Ilhan Gurel, Bernard Smeets
  • Patent number: 12495294
    Abstract: A security management system including a first TEE and a common TEE is provided. The first TEE is a secured environment for data associated with a first entity. The common TEE is a secured environment for data associated with any one of a plurality of entities. First anonymization parameters are shared between the first TEE and the common TEE. The first anonymization parameters are based at least in part on at least one privacy requirement of the first entity and at least one utility requirement of the security management system. The security management system includes processing circuitry configured to: anonymize first data associated with the first entity based at least in part on the first anonymization parameters, analyze at least the anonymized first data for performing data investigation, and generate analysis results based at least in part on the analysis of at least the anonymized first data.
    Type: Grant
    Filed: January 14, 2020
    Date of Patent: December 9, 2025
    Assignee: Telefonaktiebolaget LM Ericsson (Publ)
    Inventors: Yosr Jarraya, Makan Pourzandi, Harri Hakala, Bernard Smeets, Tommy Arngren
  • Patent number: 12483883
    Abstract: There is provided mechanisms for obtaining a HWAC for a baseband node. A method is performed by a network planner node. The method comprises performing mutual authentication between a TEE of the network planner node and a TEE of the baseband node. The method comprises providing, towards the TEE of the baseband node, a request for HWAC calculation data based on a network resource need. The method comprises obtaining, from the TEE of the baseband node, the requested HWAC calculation data. The method comprises obtaining the HWAC by inputting the obtained HWAC calculation data and a quantification of the network resource need to a HWAC calculation function on the TEE of the network planner node, where the HWAC is given as output from the HWAC calculation function. The method comprises providing, towards the TEE of the baseband node, the HWAC.
    Type: Grant
    Filed: November 22, 2018
    Date of Patent: November 25, 2025
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON, PLLC
    Inventors: Patricia Togård, Tommy Arngren, Bernard Smeets
  • Patent number: 12464041
    Abstract: Techniques for enhancing performance in Industrial Internet-of-Things (IIoT) scenarios, including techniques for time-sensitive networking (TSN) and 5G wireless network integration. An example method, performed by a wireless device, comprises receiving system information (SI) from a radio base station (RBS) of a radio access network (RAN), the SI being indicative of support for TSN through the RBS, and establishing at least one TSN stream with an external data network, through the RBS. The example method further includes receiving a first timing signal from the wireless communications network, via the RBS, receiving a second timing signal from the external TSN data network to which the wireless device is connected, comparing the first timing signal to the second timing signal to determine an offset, and transmitting the offset to the wireless communications network.
    Type: Grant
    Filed: February 13, 2019
    Date of Patent: November 4, 2025
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Joachim Sachs, Abdulrahman Alabbasi, Mattias Andersson, Niklas Andgart, Ola Angelsmark, José Araújo, Muhammad Ikram Ashraf, Kumar Balachandran, Robert Baldemair, Rodrigo Berg, Yufei Blankenship, Fedor Chernogorov, John Walter Diachina, Torsten Dudda, Henrik Enbuske, Sorour Falahati, János Farkas, Jonas Fröberg Olsson, Majid Gerami, Harald Gustafsson, Kimmo Hiltunen, Andreas Höglund, Torgny Holmberg, Zsolt Kenesi, András Kern, Kittipong Kittichokechai, Anna Larmo, Johan Lundsjö, György Miklós, Hubertus Munz, Gabor Nemeth, Johannes Nygren, Johan Olsson, Alexandros Palaios, Dhruvin Patel, Joakim Persson, Per Persson, Jose Luis Pradas, Sándor Rácz, Pradeepa Ramachandra, Norbert Reider, Dinand Roeland, Stefano Ruffini, Patrik Salmela, Sara Sandberg, Magnus Sandgren, Paul Schliwa-Bertling, Alexey Shapin, Nianshan Shi, Bikramjit Singh, Per Skarin, Bernard Smeets, Ying Sun, Dennis Sundman, Fredrik Svensson, Malgorzata Svensson, Geza Szabo, Wolfgang Tonutti, Balázs Varga, Mårten Wahlström, Kun Wang, Yi-Pin Eric Wang, Osman Nuri Can Yilmaz, Zhenhua Zou, Miguel Lopez
  • Publication number: 20250258692
    Abstract: Embodiments include methods for a software integrity tool of a host computing system configured with a runtime environment arranged to execute containers that include applications. Such methods include, based on an identifier of a container instantiated in the runtime environment, obtaining a container locator tag associated with the container and performing measurements on a filesystem associated with the container. Such methods include sending, to an attestation verification system (AVS), a representation of the container locator tag and a result of the measurements. Other embodiments include complementary methods for the container and for the AVS, as well as host computing systems configured to perform such methods.
    Type: Application
    Filed: October 28, 2022
    Publication date: August 14, 2025
    Inventors: Henrik Normann, Lina Pålsson, Mikael Eriksson, Bernard Smeets, Stere Preda, Daniel Migault
  • Publication number: 20250220012
    Abstract: Embodiments include methods for a certificate authority (CA) associated with a communication network, including first and/or second sets of operations. The first set includes receiving a first message about a network function (NF) lifecycle management (LCM) event performed by a first NF of the communication network. The first message includes an identifier of a second NF associated with the NF LCM event, and an event type associated with the NF LCM event. The first operations include performing a first certificate LCM event for certificate(s) associated with the second NF, based on the event type. The second set includes performing a second certificate LCM event for the certificate(s) associated with the second NF and sending the first NF a second message about the second certificate LCM event. The second message includes an identifier of the second NF and an event type associated with the certificate LCM event.
    Type: Application
    Filed: April 24, 2023
    Publication date: July 3, 2025
    Inventors: Bernard Smeets, Pablo Martinez de la Cruz, Sune Gustafsson, Songmao Li, Mikael Eriksson, Christine Jost, Stere Preda, Ferhat Karakoc
  • Publication number: 20250220010
    Abstract: A user terminal emulation server establishes a secure channel connection with a first I/O user device using a session identifier and an identifier associated with the first I/O user device to determine a first I/O user device specific key generated from a master key, the first I/O user device specific key and the session identifier being used for secure communication of messages with the first I/O user device. An indication of an I/O user interface capability of the first I/O user device is received through the secure channel connection with the first I/O user device. The user terminal emulation server communicates with the first I/O user device to use the I/O user interface capability to provide at least part of the communication service for a user.
    Type: Application
    Filed: April 28, 2022
    Publication date: July 3, 2025
    Inventors: Tommy ARNGREN, Bernard SMEETS, Peter ÖKVIST, Patrik SALMELA
  • Publication number: 20250209210
    Abstract: There is provided a method and a system to provide evidence of authorship of a digital document. The method includes obtaining the digital document. The method further includes acquiring first data and second data, wherein a combination of the first data and the second data provides information to identify an individual, and obtaining a digital timestamp associated to the digital document, the acquired first data and second data together.
    Type: Application
    Filed: March 23, 2022
    Publication date: June 26, 2025
    Inventors: Dmitry KNYAGININ, Alexander HUNT, Bernard SMEETS, Tommy ARNGREN
  • Patent number: 12323538
    Abstract: There is provided mechanisms for attesting a first TEE residing on a first node. A method is performed by a second TEE also residing on the first node. The method comprises obtaining a request from the first TEE to be attested. The method comprises, in response thereto, obtaining a shared key from a third TEE residing on a second node. The method comprises performing local attestation of the first TEE, whereby the first TEE is provided with the shared key from the second TEE.
    Type: Grant
    Filed: April 1, 2019
    Date of Patent: June 3, 2025
    Assignee: Telefonaktiebolagget LM Ericsson (Publ)
    Inventors: Alexander Maximov, Bernard Smeets, Lina Pålsson
  • Publication number: 20250168150
    Abstract: Embodiments of the present disclosure provide a method, a first computing device, a second computing device, and a computer program product for securing the information related to a tenant container. The method is performed by a first computing device. The method comprises receiving, from an endpoint agent resident on the first computing device, information collected from the tenant container during execution of the tenant container and encrypting at least some of the information related to the tenant container. Further, the method comprises transmitting the encrypted information to be decrypted at a second computing device in a secure environment for analysing the information at the second computing device. Corresponding first computing device, second computing device and computer program products are also disclosed.
    Type: Application
    Filed: October 1, 2021
    Publication date: May 22, 2025
    Applicant: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Henrik NORMANN, Lina PÅLSSON, Bernard SMEETS, Mikael ERIKSSON
  • Publication number: 20250141680
    Abstract: There is provided techniques for key replacement in a communication device (100). A method is performed by the communication device (100). The method comprises receiving (S104) a trigger for the communication device (100) to perform the key replacement. The method comprises providing (106) a request to a DI wallet entity (200) for a verifiable presentation for the communication device (100) to perform the key replacement. The method comprises receiving (S108) the verifiable presentation from the DI wallet entity (200). The verifiable presentation comprises attributes of one or more verifiable credentials. The method comprises obtaining (S110) a new key pair, and replacing an existing key pair with the new key pair upon the communication device (100) having successfully verified the verifiable presentation. The method comprises communicating (S116) with an SP entity (300). The new key pair is used as part of the communication device (100) communicating with the SP entity (300).
    Type: Application
    Filed: September 21, 2023
    Publication date: May 1, 2025
    Inventors: Per Ståhl, Bo Fjelkner, Bernard Smeets
  • Publication number: 20250048094
    Abstract: A method for authenticating a wireless communications device to a network slice of a communications network is provided. The wireless communications device has one or more attributes associated with it, at least one of the one or more attributes fulfilling an attribute-based access policy of the network slice. The method is performed by a slice manager of the communications network and comprises sending a secret key to the wireless communications device, sending an encrypted access key to the wireless communications device, the encrypted access key being encrypted using the access policy, such that a secret key generated based at least one attribute that fulfill the attribute-based access policy can decrypt the encrypted access key.
    Type: Application
    Filed: December 16, 2021
    Publication date: February 6, 2025
    Inventors: Makan Pourzandi, Yosr Jarraya, Harri Hakala, Bernard Smeets, Tommy Arngren
  • Publication number: 20250039001
    Abstract: A method, network node and non-transitory computer readable media having stored thereon instructions for correlating a remote attestation quote with a virtualized network function (VNF) resource allocation event. The method comprises obtaining a set of VNF components (VNFCs) that require remote attestation. The method comprises obtaining an attestation quote for each VNFC of the set of VNFCs, the attestation quote ensuring that instances of each VNFC are used in a legitimate context. The method comprises correlating each attestation quote with the VNF resource allocation event.
    Type: Application
    Filed: November 3, 2022
    Publication date: January 30, 2025
    Inventors: Bernard Smeets, Cristina Badulescu, Daniel Migault, Stere Preda
  • Publication number: 20250007957
    Abstract: Embodiments of the present disclosure provide a method, a computing device and a computer program product for achieving transparency of information collected from a tenant container. The method is performed by the computing device. The method includes identifying collection of information from the tenant container by an endpoint agent resident on the computing device during execution of the tenant container and extracting a summary of collected information. Further, the method includes signing the extracted information using a signing key. The signing key is not accessible to one or more processes that are being executed on the computing device. Corresponding computing device and computer program products are also disclosed.
    Type: Application
    Filed: October 1, 2021
    Publication date: January 2, 2025
    Inventors: Henrik NORMANN, Lina PÅLSSON, Bernard SMEETS, Mikael ERIKSSON