Patents by Inventor Harri Hakala
Harri Hakala has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260213999Abstract: A first network device (101) in a computer network (100), the first network device being connected to a second network device (102), the second network device possessing capabilities of a network manager function, and the first network device hosts a network function. The first network device operative to create an enclave; and determine, using the enclave, from an output of a twinned network function (105) based on a hosted network function (106), if the output exposes a vulnerability or if the output indicates that the twinned network function has ceased to operate according to operational criteria set for the hosted network function, Disclosed is also the second network device, a third network device, related methods, computer programs and computer program products.Type: ApplicationFiled: December 29, 2022Publication date: July 23, 2026Inventors: Harri Hakala, Anu Puhakainen, Joel Patrick Reijonen
-
Patent number: 12683951Abstract: A method, system and nodes are disclosed. According to one or more embodiments, a management node is provided. The management node includes processing circuitry configured to receive an origin certificate for a first service type where the received origin certificate includes a public key and a private key, receive a certificate request for a first instance of the first service type, generate a first proxy certificate based at least on the received origin certificate, and transmit the first proxy certificate and the public key of the received origin certificate to a first virtual network function component where the public key of the received origin certificate is for inclusion to a listing of trusted certificates at the first virtual network function component.Type: GrantFiled: June 9, 2021Date of Patent: July 14, 2026Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Makan Pourzandi, Bernard Smeets, Harri Hakala, Tommy Arngren, Yosr Jarraya
-
Patent number: 12670250Abstract: A method (200) for use in securing a computing system (416) against a recovery scenario from which the computing system would require recovery. The method comprises: i) obtaining (202) system recovery indicators for the computing system; and ii) predicting (204) a likelihood that the computing system will undergo the recovery scenario from the system recovery indicators using a model trained using a machine learning process that takes as input the system recovery indicators.Type: GrantFiled: September 22, 2021Date of Patent: June 30, 2026Assignee: Telefonaktiebolaget LM Ericsson (PUBL)Inventors: Anu Puhakainen, Harri Hakala, Joel Patrik Reijonen
-
Patent number: 12495294Abstract: A security management system including a first TEE and a common TEE is provided. The first TEE is a secured environment for data associated with a first entity. The common TEE is a secured environment for data associated with any one of a plurality of entities. First anonymization parameters are shared between the first TEE and the common TEE. The first anonymization parameters are based at least in part on at least one privacy requirement of the first entity and at least one utility requirement of the security management system. The security management system includes processing circuitry configured to: anonymize first data associated with the first entity based at least in part on the first anonymization parameters, analyze at least the anonymized first data for performing data investigation, and generate analysis results based at least in part on the analysis of at least the anonymized first data.Type: GrantFiled: January 14, 2020Date of Patent: December 9, 2025Assignee: Telefonaktiebolaget LM Ericsson (Publ)Inventors: Yosr Jarraya, Makan Pourzandi, Harri Hakala, Bernard Smeets, Tommy Arngren
-
Patent number: 12423438Abstract: A Security automation system (100; 400; 500) configured for security management of an Information Technology (IT) system (200), the security automation system using machine learning (ML). The system comprises a Threat engine (110), a Risk engine (120), a Policy engine (130) and a Security Adaptation engine (140). The Threat engine (110) comprises a threat catalog and detection rules for identifying threat events, wherein the detection rules are automatically adjusted and modified based on information collected from the managed IT system.Type: GrantFiled: February 4, 2021Date of Patent: September 23, 2025Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Harri Hakala, Anu Puhakainen
-
Publication number: 20250139236Abstract: Computer implemented systems and methods for use in monitoring a computing system (716) with respect to occurrence of a recovery scenario from which the computing system would require recovery. A method (200) comprises determining (202) a risk that the computing system will undergo the recovery scenario, and responsive to the determined risk, performing (204) one or more pre-emptive actions so as mitigate against occurrence of the recovery scenario. The pre-emptive actions comprise: a) adding a security control to compensate for the recovery scenario; b) creating an image of part of the computing system; c) storing artifacts of the computing system in a storage space that is separate from the computing system; d) encrypting or deleting data from the computing system; and/or e) disabling one or more components in the computing system.Type: ApplicationFiled: September 22, 2021Publication date: May 1, 2025Inventors: Anu Puhakainen, Harri Hakala, Joel Patrik Reijonen
-
Publication number: 20250048094Abstract: A method for authenticating a wireless communications device to a network slice of a communications network is provided. The wireless communications device has one or more attributes associated with it, at least one of the one or more attributes fulfilling an attribute-based access policy of the network slice. The method is performed by a slice manager of the communications network and comprises sending a secret key to the wireless communications device, sending an encrypted access key to the wireless communications device, the encrypted access key being encrypted using the access policy, such that a secret key generated based at least one attribute that fulfill the attribute-based access policy can decrypt the encrypted access key.Type: ApplicationFiled: December 16, 2021Publication date: February 6, 2025Inventors: Makan Pourzandi, Yosr Jarraya, Harri Hakala, Bernard Smeets, Tommy Arngren
-
Publication number: 20240394365Abstract: A method (200) for use in securing a computing system (416) against a recovery scenario from which the computing system would require recovery. The method comprises: i) obtaining (202) system recovery indicators for the computing system; and ii) predicting (204) a likelihood that the computing system will undergo the recovery scenario from the system recovery indicators using a model trained using a machine learning process that takes as input the system recovery indicators.Type: ApplicationFiled: September 22, 2021Publication date: November 28, 2024Inventors: Anu Puhakainen, Harri Hakala, Joel Patrik Reijonen
-
Publication number: 20240323103Abstract: A method is implemented by a security service orchestration function (SSOF) in a communication infrastructure, that includes a plurality of PLMNs and a plurality of enterprises, for orchestration of a security service level agreement (S-SLA). The method includes receiving, by a SSOF in a HPLMN, a S-SLA request from one or more of the enterprises. Each S-SLA request includes a plurality of requirements. The HPLMN corresponds to one of the plurality of PLMNs. The method also includes converting each S-SLA request into a consistent and unified S-SLA offerable to each enterprise. The consistent and unified S-SLA includes security attributes that the HPLMN is capable of providing. The method also includes offering the consistent and unified S-SLA to each enterprise that submitted the S-SLA request. The method further includes transforming each S-SLA request from the enterprises into security policies and controls to be enforced within the HPLMN.Type: ApplicationFiled: July 7, 2021Publication date: September 26, 2024Inventors: Harri HAKALA, Ari PIETIKÄINEN, Anu PUHAKAINEN
-
Publication number: 20240314171Abstract: A method implemented by a security service orchestration function (SSOF) in a communication infrastructure, that includes a plurality of communication service providers (CSPs), for orchestration of a security service level agreement (S-SLA) includes receiving a S-SLA request, by a CSP, from one or more other CSPs. Each S-SLA request includes a plurality of requirements. The method also includes converting each S-SLA request into a consistent and unified S-SLA offerable to each other CSP. The consistent and unified S-SLA includes security attributes that the CSP is capable of providing the other CSPs. The method also includes offering the consistent and unified S-SLA to each other CSP that submitted the S-SLA request. The method further includes receiving a response from each other CSP. The response from each other CSP includes an acknowledgement or a decline of the consistent and unified S-SLA including a non-repudiation signature of acknowledgement or declining.Type: ApplicationFiled: July 7, 2021Publication date: September 19, 2024Inventors: Anu PUHAKAINEN, Harri HAKALA, Ari PIETIKÄINEN
-
Publication number: 20240283713Abstract: A method implemented by a security service orchestration function (SSOF) in a communication infrastructure, that includes a communication service provider (CSP) and a plurality of enterprises, for orchestration of a security service level agreement (S-SLA). The method includes receiving a S-SLA request from one or more of the enterprises. Each S-SLA request includes a plurality of requirements. The method also includes converting each S-SLA request into a unique S-SLA corresponding to the plurality of requirements in the S-SLA request from an associated enterprise. Each unique S-SLA includes security attributes that the CSP is capable of providing. The method additionally includes offering the unique S-SLA to the associated enterprise for each enterprise that submitted the S-SLA request. The method further includes receiving a response from each enterprise.Type: ApplicationFiled: July 7, 2021Publication date: August 22, 2024Inventors: Harri HAKALA, Ari PIETIKÄINEN, Anu PUHAKAINEN
-
Publication number: 20240275775Abstract: A method, system and nodes are disclosed. According to one or more embodiments, a management node (16) is provided. The management node (16) includes processing circuitry (36) configured to receive an origin certificate for a first service type where the received origin certificate includes a public key and a private key, receive a certificate request for a first instance of the first service type, generate a first proxy certificate based at least on the received origin certificate, and transmit the first proxy certificate and the public key of the received origin certificate to a first virtual network function component where the public key of the received origin certificate is for inclusion to a listing of trusted certificates at the first virtual network function component.Type: ApplicationFiled: June 9, 2021Publication date: August 15, 2024Inventors: Makan POURZANDI, Bernard SMEETS, Harri HAKALA, Tommy ARNGREN, Yosr JARRAYA
-
Publication number: 20240015175Abstract: There is provided mechanisms for generating a security configuration profile for a network entity. A method is performed by a security configuration entity. The method comprises generating the security configuration profile for the network entity based on network entity information, deployment information, and feedback information for a previously generated security configuration profile. The method comprises determining, based on calculating a risk score for the generated security configuration profile, whether the security configuration profile is to be provided towards the network entity or not. The method comprises generating feedback information for the security configuration profile based on the risk score, the network entity information, and the deployment information.Type: ApplicationFiled: August 14, 2020Publication date: January 11, 2024Applicant: Telefonaktiebolaget LM Ericsson (publ)Inventors: Harri HAKALA, Anu PUHAKAINEN, Joel Patrik REIJONEN, Tomi POUTANEN
-
Publication number: 20230239687Abstract: According to some embodiments, a security management entity is provided. The security management entity includes processing circuitry configured to: generate a key having a plurality of key parts, anonymize at least a first data instance at least in part by using the key with threshold cryptography, transmit a respective key part to each one of the plurality of trusted entities, store at least one key part where the stored at least one key part is different from the transmitted respective key parts, receive a message from a first trusted entity of the plurality of trusted entities for investigating the anonymized first data instance where the message includes one of the transmitted respective key parts, and deanonymize the first data instance using the stored at least one key part and the one of the transmitted respective key parts associated with the first trusted entity.Type: ApplicationFiled: June 25, 2020Publication date: July 27, 2023Inventors: Bernard SMEETS, Harri HAKALA, Tommy ARNGREN, Yosr JARRAYA, Makan POURZANDI
-
Publication number: 20230071264Abstract: A Security automation system (100; 400; 500) configured for security management of an Information Technology (IT) system (200), the security automation system using machine learning (ML). The system comprises a Threat engine (110), a Risk engine (120), a Policy engine (130) and a Security Adaptation engine (140). The Threat engine (110) comprises a threat catalog and detection rules for identifying threat events, wherein the detection rules are automatically adjusted and modified based on information collected from the managed IT system.Type: ApplicationFiled: February 4, 2021Publication date: March 9, 2023Inventors: Harri HAKALA, Anu PUHAKAINEN
-
Publication number: 20230022539Abstract: A security management system including a first TEE and a common TEE is provided. The first TEE is a secured environment for data associated with a first entity. The common TEE is a seemed environment for data associated with any one of a plurality of entities. First anonymization parameters are shared between the first TEE and the common TEE The first anonymization parameters arc based at least in part on at least one privacy requirement of the first entity and at least one utility requirement of the security management system. The security management system includes processing circuitry configured to: anonymize first data associated with the first entity based at least in part on the first anonymization parameters, analyze at least the anonymized first data for performing data investigation, and generate analysis results based at least in part on the analysis of at least the anonymized first data.Type: ApplicationFiled: January 14, 2020Publication date: January 26, 2023Inventors: Yosr JARRAYA, Makan POURZANDI, Harri HAKALA, Bernard SMEETS, Tommy ARNGREN
-
Patent number: 11139957Abstract: An apparatus and method for creating a finite blockchain is provided. The blockchain comprises a genesis block that is the first block of the blockchain. The genesis block comprising a genesis expiry time. The method comprises the steps of creating a reincarnation block when a predefined condition is satisfied and appending it to the blockchain; determining whether the genesis expiry time has elapsed based on an expiry period; if the genesis expiry time has elapsed then identifying a first reincarnation block; if the first reincarnation block is identified then deleting all the blocks preceding the first reincarnation block including the genesis block in the block chain.Type: GrantFiled: December 8, 2016Date of Patent: October 5, 2021Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Hans Ahlbäck, Harri Hakala, Mikael Jaatinen, Leena Marjatta Mattila
-
Patent number: 10990428Abstract: A method of verifying the integrity of a virtual machine in a cloud computing deployment comprises: creating a virtual machine image derived from a trusted virtual machine, wherein the trusted virtual machine has a Keyless Signature Infrastructure signature stored in a signature store; and verifying that a computation resource can be trusted. If it is verified that a computation resource can be trusted, the method further comprises: submitting the virtual machine image to the trusted computation resource; checking a signature of the virtual machine image against the stored signature of the trusted virtual machine; launching the virtual machine image on the trusted computation resource, and creating a Keyless Signature Infrastructure signature of the virtual machine image; and storing the signature of the virtual machine image in a signature store.Type: GrantFiled: July 3, 2015Date of Patent: April 27, 2021Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Harri Hakala, Ari Pietikäinen, Ben Smeets
-
Publication number: 20200076576Abstract: An apparatus and method for creating a finite blockchain is provided. The blockchain comprises a genesis block that is the first block of the blockchain. The genesis block comprising a genesis expiry time. The method comprises the steps of creating a reincarnation block when a predefined condition is satisfied and appending it to the blockchain; determining whether the genesis expiry time has elapsed based on an expiry period; if the genesis expiry time has elapsed then identifying a first reincarnation block; if the first reincarnation block is identified then deleting all the blocks preceding the first reincarnation block including the genesis block in the block chain.Type: ApplicationFiled: December 8, 2016Publication date: March 5, 2020Inventors: Hans AHLBÄCK, Harri HAKALA, Mikael JAATINEN, Leena Marjatta MATTILA
-
Patent number: 10482078Abstract: The disclosure relates to a method (30) of handling a hash-tree based data signature. The method (30) is performed in a first device (13, 13a) and comprises: receiving (31), from a second device (12, 12a, 12b), a data signature generation request, the request comprising an indication on type of storage of a generated data signature; generating (32), in response to the data signature generation request, the data signature B using a hash-tree based data signing method; and providing (33), to the second device (12, 12a, 12b), a reference C to the generated data signature, wherein the generated data signature is obtainable by means of the reference C. The disclosure also relates to a method in a second device, corresponding devices, computer programs and computer program products.Type: GrantFiled: June 30, 2015Date of Patent: November 19, 2019Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Harri Hakala, Mikael Jaatinen, Hannu Lehtinen, Leena Marjatta Mattila