Patents by Inventor Dan Forsberg

Dan Forsberg has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9768961
    Abstract: A method and apparatus including units configured to send a request from a first network entity to a user equipment for an identifier and receive a message indicating that a public key is required from the user equipment by the first network entity. The method and apparatus also includes units configured to send, by the first network entity, the public key to the user equipment and receive an encrypted identifier by the first network entity, wherein upon authenticating the public key, the user equipment encrypts at least part of the identifier using the public key, thereby enabling further processing between the network entity and the user equipment.
    Type: Grant
    Filed: November 20, 2012
    Date of Patent: September 19, 2017
    Assignee: Nokia Technologies Oy
    Inventors: Silke Holtmanns, Dan Forsberg
  • Patent number: 9706395
    Abstract: A method and apparatus for intersystem mobility security context handling between different radio access networks which can include a receiver configured to receive a tracking area update message from a user terminal. The message can include a first key identifier configured to identify a mapped security context and a second key identifier configured to identify a cached security context. A verifier can be configured to verify the tracking area update message with a key identified by the first or second key identifier.
    Type: Grant
    Filed: April 28, 2008
    Date of Patent: July 11, 2017
    Assignee: Nokia Technologies Oy
    Inventors: Dan Forsberg, Valtteri Niemi
  • Patent number: 9344881
    Abstract: An identifier containing at least one encrypted part is received at a first network entity. A second network entity may then be determined based on the identifier. A request for assistance in decryption of the identifier from the second network entity may be sent from the first entity to the second network entity. The second network entity may then assist the first networks entity in an appropriate manner.
    Type: Grant
    Filed: September 13, 2012
    Date of Patent: May 17, 2016
    Assignee: Vringo Infrastrct Inc.
    Inventors: Dan Forsberg, Valtteri Niemi
  • Patent number: 9344411
    Abstract: In a method for key handling in mobile communication systems, first and second numbers are exchanged between entities of the mobile communication system. The first and second numbers are respectively used only once with respect to the respective system parameters of the communication system and therefore allowing greater security in the communication system.
    Type: Grant
    Filed: March 18, 2008
    Date of Patent: May 17, 2016
    Assignee: Nokia Solutions and Networks GmbH & Co. KG
    Inventors: Dan Forsberg, Guenther Horn, Ulrike Meyer
  • Patent number: 9204295
    Abstract: The user equipment (UE) and the Mobility Management Entity (MME) in an evolved 3GPP system generate authentication material that can be carried inside a packet switched network temporary mobile station identifier (P-TMSI) signature field of a Universal Mobile Telecommunications System (UMTS) signaling message from the UE to a UMTS/GPRS serving GPRS support node (SGSN) in a UMTS or GPRS Terrestrial Radio Access Network (UTRAN) or in a GSM/Edge Radio Access Network (GERAN), as well as from the SGSN to the MME of the evolved 3GPP system. The MME authenticates a context transfer request from the UTRAN/GERAN system based on the transferred authentication material and knowledge of how to create or to verify the authentication material. Additionally, the MME and the UE derive or verify authentication material, based on at least one user-specific key, for embedding in the P-TMSI signature field in legacy 3GPP signalling.
    Type: Grant
    Filed: October 28, 2008
    Date of Patent: December 1, 2015
    Assignee: Nokia Corporation
    Inventors: Marc Blommaert, Dan Forsberg, Frank Mademann, Valtteri Niemi
  • Publication number: 20140293857
    Abstract: In accordance with an example embodiment of the present invention, there is provided an apparatus comprising at least one memory configured to store an identity of a terminal, at least one processing core configured to use a terminal-specific inactivity timer value and to associate the terminal-specific inactivity timer value with the identity to provide terminal- or user-specific inactivity timers to manage state transitions in mobiles.
    Type: Application
    Filed: October 7, 2011
    Publication date: October 2, 2014
    Applicant: NOKIA CORPORATION
    Inventors: Lars Dalsgaard, Jussi-Pekka Koskinen, Ilkka Keskitalo, Jarkko Koskela, Jani Paavo Johannes Puttonen, Dan Forsberg, Timo Rantalainen
  • Patent number: 8838972
    Abstract: A communication network manages key material. A method generates and provides session keys from a security node to an access node for further propagation during handoff procedures, without requiring the security node to take part in the handoff procedures.
    Type: Grant
    Filed: September 13, 2012
    Date of Patent: September 16, 2014
    Assignee: Intellectual Ventures I LLC
    Inventors: Dan Forsberg, Lauri Tarkkala
  • Patent number: 8526953
    Abstract: An auxiliary handover message is sent from a target eNB to a UE being handed over from a source eNB. The auxiliary handover message includes a context identifier that is established between the source eNB and the UE, which the source eNB provides to the target eNB during context data exchange when preparing for the handover. The UE uses the context identifier to verify that the auxiliary handover message is valid. Various approaches are detailed for minimizing signaling overhead and minimizing the time the UE must monitor the separate channel for the auxiliary handover message in the event the UE does not properly receive the original handover message from the source eNB. The context identifier may be a random number, a C-RNTI, an eNB-ID, or a token. The auxiliary handover command sent from the target eNB may be the context identifier with or without a copy of the handover command.
    Type: Grant
    Filed: March 12, 2008
    Date of Patent: September 3, 2013
    Assignee: Nokia Corporation
    Inventors: Seppo M. Alanara, Leping Huang, Seppo Vesterinen, Lars Dalsgaard, Dan Forsberg
  • Publication number: 20130080779
    Abstract: A method and apparatus including units configured to send a request from a first network entity to a user equipment for an identifier and receive a message indicating that a public key is required from the user equipment by the first network entity. The method and apparatus also includes units configured to send, by the first network entity, the public key to the user equipment and receive an encrypted identifier by the first network entity, wherein upon authenticating the public key, the user equipment encrypts at least part of the identifier using the public key, thereby enabling further processing between the network entity and the user equipment.
    Type: Application
    Filed: November 20, 2012
    Publication date: March 28, 2013
    Inventors: Silke Holtmanns, Dan Forsberg
  • Publication number: 20130003971
    Abstract: An identifier containing at least one encrypted part is received at a first network entity. A second network entity may then be determined based on the identifier. A request for assistance in decryption of the identifier from the second network entity may be sent from the first entity to the second network entity. The second network entity may then assist the first networks entity in an appropriate manner.
    Type: Application
    Filed: September 13, 2012
    Publication date: January 3, 2013
    Applicant: Vringo Infrastructure, Inc.
    Inventors: Dan FORSBERG, Valtteri Niemi
  • Publication number: 20130007457
    Abstract: A communication network manages key material. A method generates and provides session keys from a security node to an access node for further propagation during handoff procedures, without requiring the security node to take part in the handoff procedures.
    Type: Application
    Filed: September 13, 2012
    Publication date: January 3, 2013
    Inventors: Dan Forsberg, Lauri Tarkkala
  • Patent number: 8347090
    Abstract: A method and apparatus including units configured to send a request from a first network entity to a user equipment for an identifier and receive a message indicating that a public key is required from the user equipment by the first network entity. The method and apparatus also includes units configured to send, by the first network entity, the public key to the user equipment and receive an encrypted identifier by the first network entity, wherein upon authenticating the public key, the user equipment encrypts at least part of the identifier using the public key, thereby enabling further processing between the network entity and the user equipment.
    Type: Grant
    Filed: September 21, 2007
    Date of Patent: January 1, 2013
    Assignee: Nokia Corporation
    Inventors: Silke Holtmanns, Dan Forsberg
  • Patent number: 8295488
    Abstract: A communication network manages key material. A method generates and provides session keys from a security node to an access node for further propagation during handoff procedures, without requiring the security node to take part in the handoff procedures.
    Type: Grant
    Filed: July 22, 2005
    Date of Patent: October 23, 2012
    Assignee: Intellectual Ventures I LLC
    Inventors: Dan Forsberg, Lauri Tarkkala
  • Patent number: 8284941
    Abstract: The invention allows changing a Radio Access Network security algorithm during handover in a manner that is efficient and secure. A security message is received at a mobile station previously using a first security algorithm in communication with a first access point, which message instructs to use a second security algorithm required by a second access point. In response, the mobile station is changed to use the second security algorithm.
    Type: Grant
    Filed: March 22, 2007
    Date of Patent: October 9, 2012
    Assignee: Nokia Corporation
    Inventor: Dan Forsberg
  • Patent number: 8117454
    Abstract: The present invention performs a Binding Update or a Location Update message authentication independently and terminal-specifically in a home SAE gateway. A key, which is derived in a home AAA server from an initially set long term key, is given to a visited network for encrypting the update messages in Proxy Mobile IP. In Client Mobile IP, the key is transmitted to a mobile node for update message encryption. When the update message is received in the home SAE gateway, the key can be derived independently in the home SAE gateway without any key requests between the gateway and the home AAA server. Thus, it is possible to authenticate the binding or location update messages by verifying the two signatures. The present invention can also be implemented on a lower hierarchy of the system. The invention can be implemented in 3GPP standard releases enhanced with LTE technology, for instance.
    Type: Grant
    Filed: April 27, 2007
    Date of Patent: February 14, 2012
    Assignee: Nokia Corporation
    Inventor: Dan Forsberg
  • Patent number: 8027304
    Abstract: Handoffs must be fast for wireless mobile nodes without sacrificing the security between a mobile node and wireless access points in an access network. A secure session keys context approach is shown having all the good features, like mobility and security optimization, of the currently existing proposals of key-request, pre-authentication, and pre-distribution but also providing improved scalability for the access network and for the mobile node. The new approach is compared to the existing proposals including memory requirements and especially how to reduce memory usage using a “just-in-time” transfer of security information between access points and a mobile node during a handover.
    Type: Grant
    Filed: July 6, 2006
    Date of Patent: September 27, 2011
    Assignee: Nokia Corporation
    Inventor: Dan Forsberg
  • Publication number: 20110191576
    Abstract: Cryptographic network separation functionality is provided on a user device. An option to store information about a type of database where a user is homed is provided in an indicator on a storage medium. An interface is provided between the user device and the storage medium for accessing the indicator. In case the information about the type of database cannot be obtained from the storage medium, it is determined not to enforce the cryptographic network separation functionality on the user device.
    Type: Application
    Filed: September 24, 2008
    Publication date: August 4, 2011
    Applicant: NOKIA CORPORATION
    Inventors: Dan Forsberg, Günther Horn, Marc Blommaert
  • Patent number: 7864731
    Abstract: Provided are apparatuses and methods for providing security measures for a handover execution procedure in a communication network. In one example, the handover procedure is initiated by more than one base station. In another example, a base station may not launch a Denial or Service (DoS) attack towards other base stations or towards a core network using handover signaling messages. For example, a user device may send at least one encryption parameter, such as a Nonce associated with the user device to a source base station. Handover of the user device from the source base station to a target base station may be accomplished based on the at least one encryption parameter to avoid the DoS attack.
    Type: Grant
    Filed: December 27, 2006
    Date of Patent: January 4, 2011
    Assignee: Nokia Corporation
    Inventor: Dan Forsberg
  • Patent number: 7813505
    Abstract: Sequence numbers for data packets to be transmitted using bearers having bearer identifiers in a communications system are generated, wherein the sequence numbers are generated independently for each of the bearers used for transmitting the data packets. Last generated sequence numbers for each of the bearers identifiers are stored and held in a memory. When a sequence number for a data packet to be transmitted using a bearer out of the bearers which has been used before is to be generated the memory is checked on a last generated sequence number for the bearer with a previously used bearer identifier and the sequence number is generated in accordance therewith.
    Type: Grant
    Filed: November 2, 2006
    Date of Patent: October 12, 2010
    Assignee: Nokia Corporation
    Inventors: Dan Forsberg, Timo M. Rantalainen, Haitao Tang
  • Publication number: 20100111308
    Abstract: In a method for key handling in mobile communication systems, first and second numbers are exchanged between entities of the mobile communication system. The first and second numbers are respectively used only once with respect to the respective system parameters of the communication system and therefore allowing greater security in the communication system.
    Type: Application
    Filed: March 18, 2008
    Publication date: May 6, 2010
    Applicant: NOKIA SIEMENS NETWORKS GMBH & CO. KG
    Inventors: Dan Forsberg, Guenther Horn, Ulrike Meyer