Patents by Inventor Bernard Smeets
Bernard Smeets has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12683951Abstract: A method, system and nodes are disclosed. According to one or more embodiments, a management node is provided. The management node includes processing circuitry configured to receive an origin certificate for a first service type where the received origin certificate includes a public key and a private key, receive a certificate request for a first instance of the first service type, generate a first proxy certificate based at least on the received origin certificate, and transmit the first proxy certificate and the public key of the received origin certificate to a first virtual network function component where the public key of the received origin certificate is for inclusion to a listing of trusted certificates at the first virtual network function component.Type: GrantFiled: June 9, 2021Date of Patent: July 14, 2026Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Makan Pourzandi, Bernard Smeets, Harri Hakala, Tommy Arngren, Yosr Jarraya
-
Patent number: 12645812Abstract: A method at a first communication device for providing a second communication device access to content, the method comprising: providing an offer to the second communication device, offering the second communication device conditional access to the content, wherein access to the content at the second communication device is adaptable based on sensor data of at least one of the first and the second communication device; acquiring sensor data of at least one of the first and the second communication device; providing the second communication device full access to the content in case it is that the sensor data of at least one of the first and the second communication device indicates that the second communication device shall be grated full access to the content, or determining that access to the content is to be restricted at the second communication device, and providing the second communication device restricted access to the content, in case it is determined that sensor data of at least one of the first andType: GrantFiled: March 16, 2021Date of Patent: June 2, 2026Assignee: Telefonaktiebolaget LM Ericsson (PUBL)Inventors: Tommy Arngren, Bernard Smeets, Peter Ökvist
-
Patent number: 12634272Abstract: A user terminal emulation server establishes a secure channel connection with a first I/O user device using a session identifier and an identifier associated with the first I/O user device to determine a first I/O user device specific key generated from a master key, the first I/O user device specific key and the session identifier being used for secure communication of messages with the first I/O user device. An indication of an I/O user interface capability of the first I/O user device is received through the secure channel connection with the first I/O user device. The user terminal emulation server communicates with the first I/O user device to use the I/O user interface capability to provide at least part of the communication service for a user.Type: GrantFiled: April 28, 2022Date of Patent: May 19, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Tommy Arngren, Bernard Smeets, Peter Ökvist, Patrik Salmela
-
Patent number: 12598085Abstract: A method, network node and non-transitory computer readable media having stored thereon instructions for correlating a remote attestation quote with a virtualized network function (VNF) resource allocation event. The method comprises obtaining a set of VNF components (VNFCs) that require remote attestation. The method comprises obtaining an attestation quote for each VNFC of the set of VNFCs, the attestation quote ensuring that instances of each VNFC are used in a legitimate context. The method comprises correlating each attestation quote with the VNF resource allocation event.Type: GrantFiled: November 3, 2022Date of Patent: April 7, 2026Assignee: Telefonaktiebolaget L M Ericsson (publ)Inventors: Bernard Smeets, Cristina Badulescu, Daniel Migault, Stere Preda
-
Patent number: 12568354Abstract: There is provided mechanisms for downloading an operational subscription profile to a communication device. A method is performed by the communication device. The communication device has an EID and is provided with a provisioning subscription profile. The method comprises obtaining a temporary PSI for the provisioning subscription profile, wherein the temporary PSI is based on the EID. The method comprises providing, whilst using the provisioning subscription profile, the temporary PSI to a first MNO as part of performing network attachment with the first MNO. The first MNO is selected based on the temporary PSI. The method comprises obtaining, whilst using the provisioning subscription profile and as part of performing network access authentication for the network attachment, an operational PSI from an eSIM server via the first MNO.Type: GrantFiled: February 5, 2021Date of Patent: March 3, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Per Ståhl, Bernard Smeets
-
Publication number: 20260005740Abstract: Various embodiments of the present disclosure provide for a method and apparatuses that perform spatial encoding in a multipath environment such that transmissions on different beams are separately encrypted with complex codes such that when the transmissions on the different beams are received at the receiver, the separate encryptions are cancelled out. The transmissions can also have time delay, gain, and phase modifications made to the transmissions such that the automatic self-decryption is performed within a predefined distance of where the receiver is determined to be. In this way, encryption/decryption keys do not have to be sent to the receiver, and unauthorized devices that intercept the beams at a location other than the receiver location will not be able to decrypt the communication.Type: ApplicationFiled: September 19, 2022Publication date: January 1, 2026Inventors: Bernard Smeets, Raihan Rafique, Leif Wilhelmsson
-
Patent number: 12505202Abstract: A method for enabling attestation of a platform comprising a Trusted Execution Environment, TEE, and a Trusted Platform Module, TPM is disclosed. The method is performed by the TEE and comprises: receiving, from an Application of the platform, a request for generation of an attestation quote, the request comprising a nonce, information on which PCR(s) to be used and information about Attestation Keys; establishing a connection to the TPM and obtaining from it at least one PCR value; generating an attestation quote based on the received nonce and the at least one PCR value; signing the attestation, and rendering the attestation quote available for the Application.Type: GrantFiled: March 31, 2021Date of Patent: December 23, 2025Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Ilhan Gurel, Bernard Smeets
-
Patent number: 12495294Abstract: A security management system including a first TEE and a common TEE is provided. The first TEE is a secured environment for data associated with a first entity. The common TEE is a secured environment for data associated with any one of a plurality of entities. First anonymization parameters are shared between the first TEE and the common TEE. The first anonymization parameters are based at least in part on at least one privacy requirement of the first entity and at least one utility requirement of the security management system. The security management system includes processing circuitry configured to: anonymize first data associated with the first entity based at least in part on the first anonymization parameters, analyze at least the anonymized first data for performing data investigation, and generate analysis results based at least in part on the analysis of at least the anonymized first data.Type: GrantFiled: January 14, 2020Date of Patent: December 9, 2025Assignee: Telefonaktiebolaget LM Ericsson (Publ)Inventors: Yosr Jarraya, Makan Pourzandi, Harri Hakala, Bernard Smeets, Tommy Arngren
-
Patent number: 12483883Abstract: There is provided mechanisms for obtaining a HWAC for a baseband node. A method is performed by a network planner node. The method comprises performing mutual authentication between a TEE of the network planner node and a TEE of the baseband node. The method comprises providing, towards the TEE of the baseband node, a request for HWAC calculation data based on a network resource need. The method comprises obtaining, from the TEE of the baseband node, the requested HWAC calculation data. The method comprises obtaining the HWAC by inputting the obtained HWAC calculation data and a quantification of the network resource need to a HWAC calculation function on the TEE of the network planner node, where the HWAC is given as output from the HWAC calculation function. The method comprises providing, towards the TEE of the baseband node, the HWAC.Type: GrantFiled: November 22, 2018Date of Patent: November 25, 2025Assignee: TELEFONAKTIEBOLAGET LM ERICSSON, PLLCInventors: Patricia Togård, Tommy Arngren, Bernard Smeets
-
Patent number: 12464041Abstract: Techniques for enhancing performance in Industrial Internet-of-Things (IIoT) scenarios, including techniques for time-sensitive networking (TSN) and 5G wireless network integration. An example method, performed by a wireless device, comprises receiving system information (SI) from a radio base station (RBS) of a radio access network (RAN), the SI being indicative of support for TSN through the RBS, and establishing at least one TSN stream with an external data network, through the RBS. The example method further includes receiving a first timing signal from the wireless communications network, via the RBS, receiving a second timing signal from the external TSN data network to which the wireless device is connected, comparing the first timing signal to the second timing signal to determine an offset, and transmitting the offset to the wireless communications network.Type: GrantFiled: February 13, 2019Date of Patent: November 4, 2025Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Joachim Sachs, Abdulrahman Alabbasi, Mattias Andersson, Niklas Andgart, Ola Angelsmark, José Araújo, Muhammad Ikram Ashraf, Kumar Balachandran, Robert Baldemair, Rodrigo Berg, Yufei Blankenship, Fedor Chernogorov, John Walter Diachina, Torsten Dudda, Henrik Enbuske, Sorour Falahati, János Farkas, Jonas Fröberg Olsson, Majid Gerami, Harald Gustafsson, Kimmo Hiltunen, Andreas Höglund, Torgny Holmberg, Zsolt Kenesi, András Kern, Kittipong Kittichokechai, Anna Larmo, Johan Lundsjö, György Miklós, Hubertus Munz, Gabor Nemeth, Johannes Nygren, Johan Olsson, Alexandros Palaios, Dhruvin Patel, Joakim Persson, Per Persson, Jose Luis Pradas, Sándor Rácz, Pradeepa Ramachandra, Norbert Reider, Dinand Roeland, Stefano Ruffini, Patrik Salmela, Sara Sandberg, Magnus Sandgren, Paul Schliwa-Bertling, Alexey Shapin, Nianshan Shi, Bikramjit Singh, Per Skarin, Bernard Smeets, Ying Sun, Dennis Sundman, Fredrik Svensson, Malgorzata Svensson, Geza Szabo, Wolfgang Tonutti, Balázs Varga, Mårten Wahlström, Kun Wang, Yi-Pin Eric Wang, Osman Nuri Can Yilmaz, Zhenhua Zou, Miguel Lopez
-
Publication number: 20250258692Abstract: Embodiments include methods for a software integrity tool of a host computing system configured with a runtime environment arranged to execute containers that include applications. Such methods include, based on an identifier of a container instantiated in the runtime environment, obtaining a container locator tag associated with the container and performing measurements on a filesystem associated with the container. Such methods include sending, to an attestation verification system (AVS), a representation of the container locator tag and a result of the measurements. Other embodiments include complementary methods for the container and for the AVS, as well as host computing systems configured to perform such methods.Type: ApplicationFiled: October 28, 2022Publication date: August 14, 2025Inventors: Henrik Normann, Lina Pålsson, Mikael Eriksson, Bernard Smeets, Stere Preda, Daniel Migault
-
Publication number: 20250220012Abstract: Embodiments include methods for a certificate authority (CA) associated with a communication network, including first and/or second sets of operations. The first set includes receiving a first message about a network function (NF) lifecycle management (LCM) event performed by a first NF of the communication network. The first message includes an identifier of a second NF associated with the NF LCM event, and an event type associated with the NF LCM event. The first operations include performing a first certificate LCM event for certificate(s) associated with the second NF, based on the event type. The second set includes performing a second certificate LCM event for the certificate(s) associated with the second NF and sending the first NF a second message about the second certificate LCM event. The second message includes an identifier of the second NF and an event type associated with the certificate LCM event.Type: ApplicationFiled: April 24, 2023Publication date: July 3, 2025Inventors: Bernard Smeets, Pablo Martinez de la Cruz, Sune Gustafsson, Songmao Li, Mikael Eriksson, Christine Jost, Stere Preda, Ferhat Karakoc
-
Publication number: 20250220010Abstract: A user terminal emulation server establishes a secure channel connection with a first I/O user device using a session identifier and an identifier associated with the first I/O user device to determine a first I/O user device specific key generated from a master key, the first I/O user device specific key and the session identifier being used for secure communication of messages with the first I/O user device. An indication of an I/O user interface capability of the first I/O user device is received through the secure channel connection with the first I/O user device. The user terminal emulation server communicates with the first I/O user device to use the I/O user interface capability to provide at least part of the communication service for a user.Type: ApplicationFiled: April 28, 2022Publication date: July 3, 2025Inventors: Tommy ARNGREN, Bernard SMEETS, Peter ÖKVIST, Patrik SALMELA
-
Publication number: 20250209210Abstract: There is provided a method and a system to provide evidence of authorship of a digital document. The method includes obtaining the digital document. The method further includes acquiring first data and second data, wherein a combination of the first data and the second data provides information to identify an individual, and obtaining a digital timestamp associated to the digital document, the acquired first data and second data together.Type: ApplicationFiled: March 23, 2022Publication date: June 26, 2025Inventors: Dmitry KNYAGININ, Alexander HUNT, Bernard SMEETS, Tommy ARNGREN
-
Patent number: 12323538Abstract: There is provided mechanisms for attesting a first TEE residing on a first node. A method is performed by a second TEE also residing on the first node. The method comprises obtaining a request from the first TEE to be attested. The method comprises, in response thereto, obtaining a shared key from a third TEE residing on a second node. The method comprises performing local attestation of the first TEE, whereby the first TEE is provided with the shared key from the second TEE.Type: GrantFiled: April 1, 2019Date of Patent: June 3, 2025Assignee: Telefonaktiebolagget LM Ericsson (Publ)Inventors: Alexander Maximov, Bernard Smeets, Lina Pålsson
-
Publication number: 20250168150Abstract: Embodiments of the present disclosure provide a method, a first computing device, a second computing device, and a computer program product for securing the information related to a tenant container. The method is performed by a first computing device. The method comprises receiving, from an endpoint agent resident on the first computing device, information collected from the tenant container during execution of the tenant container and encrypting at least some of the information related to the tenant container. Further, the method comprises transmitting the encrypted information to be decrypted at a second computing device in a secure environment for analysing the information at the second computing device. Corresponding first computing device, second computing device and computer program products are also disclosed.Type: ApplicationFiled: October 1, 2021Publication date: May 22, 2025Applicant: Telefonaktiebolaget LM Ericsson (publ)Inventors: Henrik NORMANN, Lina PÅLSSON, Bernard SMEETS, Mikael ERIKSSON
-
Publication number: 20250141680Abstract: There is provided techniques for key replacement in a communication device (100). A method is performed by the communication device (100). The method comprises receiving (S104) a trigger for the communication device (100) to perform the key replacement. The method comprises providing (106) a request to a DI wallet entity (200) for a verifiable presentation for the communication device (100) to perform the key replacement. The method comprises receiving (S108) the verifiable presentation from the DI wallet entity (200). The verifiable presentation comprises attributes of one or more verifiable credentials. The method comprises obtaining (S110) a new key pair, and replacing an existing key pair with the new key pair upon the communication device (100) having successfully verified the verifiable presentation. The method comprises communicating (S116) with an SP entity (300). The new key pair is used as part of the communication device (100) communicating with the SP entity (300).Type: ApplicationFiled: September 21, 2023Publication date: May 1, 2025Inventors: Per Ståhl, Bo Fjelkner, Bernard Smeets
-
Publication number: 20250048094Abstract: A method for authenticating a wireless communications device to a network slice of a communications network is provided. The wireless communications device has one or more attributes associated with it, at least one of the one or more attributes fulfilling an attribute-based access policy of the network slice. The method is performed by a slice manager of the communications network and comprises sending a secret key to the wireless communications device, sending an encrypted access key to the wireless communications device, the encrypted access key being encrypted using the access policy, such that a secret key generated based at least one attribute that fulfill the attribute-based access policy can decrypt the encrypted access key.Type: ApplicationFiled: December 16, 2021Publication date: February 6, 2025Inventors: Makan Pourzandi, Yosr Jarraya, Harri Hakala, Bernard Smeets, Tommy Arngren
-
Publication number: 20250039001Abstract: A method, network node and non-transitory computer readable media having stored thereon instructions for correlating a remote attestation quote with a virtualized network function (VNF) resource allocation event. The method comprises obtaining a set of VNF components (VNFCs) that require remote attestation. The method comprises obtaining an attestation quote for each VNFC of the set of VNFCs, the attestation quote ensuring that instances of each VNFC are used in a legitimate context. The method comprises correlating each attestation quote with the VNF resource allocation event.Type: ApplicationFiled: November 3, 2022Publication date: January 30, 2025Inventors: Bernard Smeets, Cristina Badulescu, Daniel Migault, Stere Preda
-
Publication number: 20250007957Abstract: Embodiments of the present disclosure provide a method, a computing device and a computer program product for achieving transparency of information collected from a tenant container. The method is performed by the computing device. The method includes identifying collection of information from the tenant container by an endpoint agent resident on the computing device during execution of the tenant container and extracting a summary of collected information. Further, the method includes signing the extracted information using a signing key. The signing key is not accessible to one or more processes that are being executed on the computing device. Corresponding computing device and computer program products are also disclosed.Type: ApplicationFiled: October 1, 2021Publication date: January 2, 2025Inventors: Henrik NORMANN, Lina PÅLSSON, Bernard SMEETS, Mikael ERIKSSON