Patents by Inventor Bernard Smeets
Bernard Smeets has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12712613Abstract: Various embodiments of the present disclosure provide for a method and apparatuses that perform spatial encoding in a multipath environment such that transmissions on different beams are separately encrypted with complex codes such that when the transmissions on the different beams are received at the receiver, the separate encryptions are cancelled out. The transmissions can also have time delay, gain, and phase modifications made to the transmissions such that the automatic self-decryption is performed within a predefined distance of where the receiver is determined to be. In this way, encryption/decryption keys do not have to be sent to the receiver, and unauthorized devices that intercept the beams at a location other than the receiver location will not be able to decrypt the communication.Type: GrantFiled: September 19, 2022Date of Patent: August 18, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Bernard Smeets, Raihan Rafique, Leif Wilhelmsson
-
Patent number: 12707240Abstract: There is provided mechanisms for profile handling of a communication device. A method is performed by a subscription server. The method comprises obtaining device type information of the communication device from a proxy server. The method comprises determining a profile handling action for the communication device according to at least one localization rule. According to which of the localization rule the profile handling action is determined depends on a mapping between the device type information and the localization rule. The method comprises notifying the proxy server of the profile handling action.Type: GrantFiled: July 1, 2020Date of Patent: August 11, 2026Assignee: Telefonaktiebolaget LM Ericsson (PUBL)Inventors: Per Ståhl, Qiang Li, Juha Sääskilahti, John Fornehed, Bernard Smeets
-
Patent number: 12706889Abstract: Embodiments of the present disclosure provide a method, a first computing device, a second computing device, and a computer program product for securing the information related to a tenant container. The method is performed by a first computing device. The method comprises receiving, from an endpoint agent resident on the first computing device, information collected from the tenant container during execution of the tenant container and encrypting at least some of the information related to the tenant container. Further, the method comprises transmitting the encrypted information to be decrypted at a second computing device in a secure environment for analysing the information at the second computing device. Corresponding first computing device, second computing device and computer program products are also disclosed.Type: GrantFiled: October 1, 2021Date of Patent: August 11, 2026Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Henrik Normann, Lina Pålsson, Bernard Smeets, Mikael Eriksson
-
Publication number: 20260222814Abstract: Embodiments include methods performed by a receiver network function (NF) arranged to receive notifications from notifier NFs of a communication network. Such methods include generating a first access token indicating that a notifier NF is authorized to send notifications to the receiver NF in accordance with a subscription and sending to a first NF of the communication network a first message related to a subscription for receiving notifications from the notifier NF. The first message includes the first access token. Such methods include receiving a notification from the notifier NF in accordance with the subscription. The notification includes or is received in association with a further access token. Such methods include, based on the further access token, verifying that the notifier NF is authorized to send the notification.Type: ApplicationFiled: February 2, 2024Publication date: July 30, 2026Inventors: Jesus Angel De Gregorio Rodriguez, Sune Gustafsson, Cheng Wang, Songmao Li, Christine Jost, Bernard Smeets
-
Patent number: 12683951Abstract: A method, system and nodes are disclosed. According to one or more embodiments, a management node is provided. The management node includes processing circuitry configured to receive an origin certificate for a first service type where the received origin certificate includes a public key and a private key, receive a certificate request for a first instance of the first service type, generate a first proxy certificate based at least on the received origin certificate, and transmit the first proxy certificate and the public key of the received origin certificate to a first virtual network function component where the public key of the received origin certificate is for inclusion to a listing of trusted certificates at the first virtual network function component.Type: GrantFiled: June 9, 2021Date of Patent: July 14, 2026Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Makan Pourzandi, Bernard Smeets, Harri Hakala, Tommy Arngren, Yosr Jarraya
-
Patent number: 12645812Abstract: A method at a first communication device for providing a second communication device access to content, the method comprising: providing an offer to the second communication device, offering the second communication device conditional access to the content, wherein access to the content at the second communication device is adaptable based on sensor data of at least one of the first and the second communication device; acquiring sensor data of at least one of the first and the second communication device; providing the second communication device full access to the content in case it is that the sensor data of at least one of the first and the second communication device indicates that the second communication device shall be grated full access to the content, or determining that access to the content is to be restricted at the second communication device, and providing the second communication device restricted access to the content, in case it is determined that sensor data of at least one of the first andType: GrantFiled: March 16, 2021Date of Patent: June 2, 2026Assignee: Telefonaktiebolaget LM Ericsson (PUBL)Inventors: Tommy Arngren, Bernard Smeets, Peter Ökvist
-
Patent number: 12634272Abstract: A user terminal emulation server establishes a secure channel connection with a first I/O user device using a session identifier and an identifier associated with the first I/O user device to determine a first I/O user device specific key generated from a master key, the first I/O user device specific key and the session identifier being used for secure communication of messages with the first I/O user device. An indication of an I/O user interface capability of the first I/O user device is received through the secure channel connection with the first I/O user device. The user terminal emulation server communicates with the first I/O user device to use the I/O user interface capability to provide at least part of the communication service for a user.Type: GrantFiled: April 28, 2022Date of Patent: May 19, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Tommy Arngren, Bernard Smeets, Peter Ökvist, Patrik Salmela
-
Patent number: 12598085Abstract: A method, network node and non-transitory computer readable media having stored thereon instructions for correlating a remote attestation quote with a virtualized network function (VNF) resource allocation event. The method comprises obtaining a set of VNF components (VNFCs) that require remote attestation. The method comprises obtaining an attestation quote for each VNFC of the set of VNFCs, the attestation quote ensuring that instances of each VNFC are used in a legitimate context. The method comprises correlating each attestation quote with the VNF resource allocation event.Type: GrantFiled: November 3, 2022Date of Patent: April 7, 2026Assignee: Telefonaktiebolaget L M Ericsson (publ)Inventors: Bernard Smeets, Cristina Badulescu, Daniel Migault, Stere Preda
-
Patent number: 12568354Abstract: There is provided mechanisms for downloading an operational subscription profile to a communication device. A method is performed by the communication device. The communication device has an EID and is provided with a provisioning subscription profile. The method comprises obtaining a temporary PSI for the provisioning subscription profile, wherein the temporary PSI is based on the EID. The method comprises providing, whilst using the provisioning subscription profile, the temporary PSI to a first MNO as part of performing network attachment with the first MNO. The first MNO is selected based on the temporary PSI. The method comprises obtaining, whilst using the provisioning subscription profile and as part of performing network access authentication for the network attachment, an operational PSI from an eSIM server via the first MNO.Type: GrantFiled: February 5, 2021Date of Patent: March 3, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Per Ståhl, Bernard Smeets
-
Publication number: 20260005740Abstract: Various embodiments of the present disclosure provide for a method and apparatuses that perform spatial encoding in a multipath environment such that transmissions on different beams are separately encrypted with complex codes such that when the transmissions on the different beams are received at the receiver, the separate encryptions are cancelled out. The transmissions can also have time delay, gain, and phase modifications made to the transmissions such that the automatic self-decryption is performed within a predefined distance of where the receiver is determined to be. In this way, encryption/decryption keys do not have to be sent to the receiver, and unauthorized devices that intercept the beams at a location other than the receiver location will not be able to decrypt the communication.Type: ApplicationFiled: September 19, 2022Publication date: January 1, 2026Inventors: Bernard Smeets, Raihan Rafique, Leif Wilhelmsson
-
Patent number: 12505202Abstract: A method for enabling attestation of a platform comprising a Trusted Execution Environment, TEE, and a Trusted Platform Module, TPM is disclosed. The method is performed by the TEE and comprises: receiving, from an Application of the platform, a request for generation of an attestation quote, the request comprising a nonce, information on which PCR(s) to be used and information about Attestation Keys; establishing a connection to the TPM and obtaining from it at least one PCR value; generating an attestation quote based on the received nonce and the at least one PCR value; signing the attestation, and rendering the attestation quote available for the Application.Type: GrantFiled: March 31, 2021Date of Patent: December 23, 2025Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Ilhan Gurel, Bernard Smeets
-
Patent number: 12495294Abstract: A security management system including a first TEE and a common TEE is provided. The first TEE is a secured environment for data associated with a first entity. The common TEE is a secured environment for data associated with any one of a plurality of entities. First anonymization parameters are shared between the first TEE and the common TEE. The first anonymization parameters are based at least in part on at least one privacy requirement of the first entity and at least one utility requirement of the security management system. The security management system includes processing circuitry configured to: anonymize first data associated with the first entity based at least in part on the first anonymization parameters, analyze at least the anonymized first data for performing data investigation, and generate analysis results based at least in part on the analysis of at least the anonymized first data.Type: GrantFiled: January 14, 2020Date of Patent: December 9, 2025Assignee: Telefonaktiebolaget LM Ericsson (Publ)Inventors: Yosr Jarraya, Makan Pourzandi, Harri Hakala, Bernard Smeets, Tommy Arngren
-
Patent number: 12483883Abstract: There is provided mechanisms for obtaining a HWAC for a baseband node. A method is performed by a network planner node. The method comprises performing mutual authentication between a TEE of the network planner node and a TEE of the baseband node. The method comprises providing, towards the TEE of the baseband node, a request for HWAC calculation data based on a network resource need. The method comprises obtaining, from the TEE of the baseband node, the requested HWAC calculation data. The method comprises obtaining the HWAC by inputting the obtained HWAC calculation data and a quantification of the network resource need to a HWAC calculation function on the TEE of the network planner node, where the HWAC is given as output from the HWAC calculation function. The method comprises providing, towards the TEE of the baseband node, the HWAC.Type: GrantFiled: November 22, 2018Date of Patent: November 25, 2025Assignee: TELEFONAKTIEBOLAGET LM ERICSSON, PLLCInventors: Patricia Togård, Tommy Arngren, Bernard Smeets
-
Patent number: 12464041Abstract: Techniques for enhancing performance in Industrial Internet-of-Things (IIoT) scenarios, including techniques for time-sensitive networking (TSN) and 5G wireless network integration. An example method, performed by a wireless device, comprises receiving system information (SI) from a radio base station (RBS) of a radio access network (RAN), the SI being indicative of support for TSN through the RBS, and establishing at least one TSN stream with an external data network, through the RBS. The example method further includes receiving a first timing signal from the wireless communications network, via the RBS, receiving a second timing signal from the external TSN data network to which the wireless device is connected, comparing the first timing signal to the second timing signal to determine an offset, and transmitting the offset to the wireless communications network.Type: GrantFiled: February 13, 2019Date of Patent: November 4, 2025Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Joachim Sachs, Abdulrahman Alabbasi, Mattias Andersson, Niklas Andgart, Ola Angelsmark, José Araújo, Muhammad Ikram Ashraf, Kumar Balachandran, Robert Baldemair, Rodrigo Berg, Yufei Blankenship, Fedor Chernogorov, John Walter Diachina, Torsten Dudda, Henrik Enbuske, Sorour Falahati, János Farkas, Jonas Fröberg Olsson, Majid Gerami, Harald Gustafsson, Kimmo Hiltunen, Andreas Höglund, Torgny Holmberg, Zsolt Kenesi, András Kern, Kittipong Kittichokechai, Anna Larmo, Johan Lundsjö, György Miklós, Hubertus Munz, Gabor Nemeth, Johannes Nygren, Johan Olsson, Alexandros Palaios, Dhruvin Patel, Joakim Persson, Per Persson, Jose Luis Pradas, Sándor Rácz, Pradeepa Ramachandra, Norbert Reider, Dinand Roeland, Stefano Ruffini, Patrik Salmela, Sara Sandberg, Magnus Sandgren, Paul Schliwa-Bertling, Alexey Shapin, Nianshan Shi, Bikramjit Singh, Per Skarin, Bernard Smeets, Ying Sun, Dennis Sundman, Fredrik Svensson, Malgorzata Svensson, Geza Szabo, Wolfgang Tonutti, Balázs Varga, Mårten Wahlström, Kun Wang, Yi-Pin Eric Wang, Osman Nuri Can Yilmaz, Zhenhua Zou, Miguel Lopez
-
Publication number: 20250258692Abstract: Embodiments include methods for a software integrity tool of a host computing system configured with a runtime environment arranged to execute containers that include applications. Such methods include, based on an identifier of a container instantiated in the runtime environment, obtaining a container locator tag associated with the container and performing measurements on a filesystem associated with the container. Such methods include sending, to an attestation verification system (AVS), a representation of the container locator tag and a result of the measurements. Other embodiments include complementary methods for the container and for the AVS, as well as host computing systems configured to perform such methods.Type: ApplicationFiled: October 28, 2022Publication date: August 14, 2025Inventors: Henrik Normann, Lina Pålsson, Mikael Eriksson, Bernard Smeets, Stere Preda, Daniel Migault
-
Publication number: 20250220012Abstract: Embodiments include methods for a certificate authority (CA) associated with a communication network, including first and/or second sets of operations. The first set includes receiving a first message about a network function (NF) lifecycle management (LCM) event performed by a first NF of the communication network. The first message includes an identifier of a second NF associated with the NF LCM event, and an event type associated with the NF LCM event. The first operations include performing a first certificate LCM event for certificate(s) associated with the second NF, based on the event type. The second set includes performing a second certificate LCM event for the certificate(s) associated with the second NF and sending the first NF a second message about the second certificate LCM event. The second message includes an identifier of the second NF and an event type associated with the certificate LCM event.Type: ApplicationFiled: April 24, 2023Publication date: July 3, 2025Inventors: Bernard Smeets, Pablo Martinez de la Cruz, Sune Gustafsson, Songmao Li, Mikael Eriksson, Christine Jost, Stere Preda, Ferhat Karakoc
-
Publication number: 20250220010Abstract: A user terminal emulation server establishes a secure channel connection with a first I/O user device using a session identifier and an identifier associated with the first I/O user device to determine a first I/O user device specific key generated from a master key, the first I/O user device specific key and the session identifier being used for secure communication of messages with the first I/O user device. An indication of an I/O user interface capability of the first I/O user device is received through the secure channel connection with the first I/O user device. The user terminal emulation server communicates with the first I/O user device to use the I/O user interface capability to provide at least part of the communication service for a user.Type: ApplicationFiled: April 28, 2022Publication date: July 3, 2025Inventors: Tommy ARNGREN, Bernard SMEETS, Peter ÖKVIST, Patrik SALMELA
-
Publication number: 20250209210Abstract: There is provided a method and a system to provide evidence of authorship of a digital document. The method includes obtaining the digital document. The method further includes acquiring first data and second data, wherein a combination of the first data and the second data provides information to identify an individual, and obtaining a digital timestamp associated to the digital document, the acquired first data and second data together.Type: ApplicationFiled: March 23, 2022Publication date: June 26, 2025Inventors: Dmitry KNYAGININ, Alexander HUNT, Bernard SMEETS, Tommy ARNGREN
-
Patent number: 12323538Abstract: There is provided mechanisms for attesting a first TEE residing on a first node. A method is performed by a second TEE also residing on the first node. The method comprises obtaining a request from the first TEE to be attested. The method comprises, in response thereto, obtaining a shared key from a third TEE residing on a second node. The method comprises performing local attestation of the first TEE, whereby the first TEE is provided with the shared key from the second TEE.Type: GrantFiled: April 1, 2019Date of Patent: June 3, 2025Assignee: Telefonaktiebolagget LM Ericsson (Publ)Inventors: Alexander Maximov, Bernard Smeets, Lina Pålsson
-
Publication number: 20250168150Abstract: Embodiments of the present disclosure provide a method, a first computing device, a second computing device, and a computer program product for securing the information related to a tenant container. The method is performed by a first computing device. The method comprises receiving, from an endpoint agent resident on the first computing device, information collected from the tenant container during execution of the tenant container and encrypting at least some of the information related to the tenant container. Further, the method comprises transmitting the encrypted information to be decrypted at a second computing device in a secure environment for analysing the information at the second computing device. Corresponding first computing device, second computing device and computer program products are also disclosed.Type: ApplicationFiled: October 1, 2021Publication date: May 22, 2025Applicant: Telefonaktiebolaget LM Ericsson (publ)Inventors: Henrik NORMANN, Lina PÅLSSON, Bernard SMEETS, Mikael ERIKSSON