Patents by Inventor Harri Hakala

Harri Hakala has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260213999
    Abstract: A first network device (101) in a computer network (100), the first network device being connected to a second network device (102), the second network device possessing capabilities of a network manager function, and the first network device hosts a network function. The first network device operative to create an enclave; and determine, using the enclave, from an output of a twinned network function (105) based on a hosted network function (106), if the output exposes a vulnerability or if the output indicates that the twinned network function has ceased to operate according to operational criteria set for the hosted network function, Disclosed is also the second network device, a third network device, related methods, computer programs and computer program products.
    Type: Application
    Filed: December 29, 2022
    Publication date: July 23, 2026
    Inventors: Harri Hakala, Anu Puhakainen, Joel Patrick Reijonen
  • Patent number: 12683951
    Abstract: A method, system and nodes are disclosed. According to one or more embodiments, a management node is provided. The management node includes processing circuitry configured to receive an origin certificate for a first service type where the received origin certificate includes a public key and a private key, receive a certificate request for a first instance of the first service type, generate a first proxy certificate based at least on the received origin certificate, and transmit the first proxy certificate and the public key of the received origin certificate to a first virtual network function component where the public key of the received origin certificate is for inclusion to a listing of trusted certificates at the first virtual network function component.
    Type: Grant
    Filed: June 9, 2021
    Date of Patent: July 14, 2026
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Makan Pourzandi, Bernard Smeets, Harri Hakala, Tommy Arngren, Yosr Jarraya
  • Patent number: 12670250
    Abstract: A method (200) for use in securing a computing system (416) against a recovery scenario from which the computing system would require recovery. The method comprises: i) obtaining (202) system recovery indicators for the computing system; and ii) predicting (204) a likelihood that the computing system will undergo the recovery scenario from the system recovery indicators using a model trained using a machine learning process that takes as input the system recovery indicators.
    Type: Grant
    Filed: September 22, 2021
    Date of Patent: June 30, 2026
    Assignee: Telefonaktiebolaget LM Ericsson (PUBL)
    Inventors: Anu Puhakainen, Harri Hakala, Joel Patrik Reijonen
  • Patent number: 12495294
    Abstract: A security management system including a first TEE and a common TEE is provided. The first TEE is a secured environment for data associated with a first entity. The common TEE is a secured environment for data associated with any one of a plurality of entities. First anonymization parameters are shared between the first TEE and the common TEE. The first anonymization parameters are based at least in part on at least one privacy requirement of the first entity and at least one utility requirement of the security management system. The security management system includes processing circuitry configured to: anonymize first data associated with the first entity based at least in part on the first anonymization parameters, analyze at least the anonymized first data for performing data investigation, and generate analysis results based at least in part on the analysis of at least the anonymized first data.
    Type: Grant
    Filed: January 14, 2020
    Date of Patent: December 9, 2025
    Assignee: Telefonaktiebolaget LM Ericsson (Publ)
    Inventors: Yosr Jarraya, Makan Pourzandi, Harri Hakala, Bernard Smeets, Tommy Arngren
  • Patent number: 12423438
    Abstract: A Security automation system (100; 400; 500) configured for security management of an Information Technology (IT) system (200), the security automation system using machine learning (ML). The system comprises a Threat engine (110), a Risk engine (120), a Policy engine (130) and a Security Adaptation engine (140). The Threat engine (110) comprises a threat catalog and detection rules for identifying threat events, wherein the detection rules are automatically adjusted and modified based on information collected from the managed IT system.
    Type: Grant
    Filed: February 4, 2021
    Date of Patent: September 23, 2025
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Harri Hakala, Anu Puhakainen
  • Publication number: 20250139236
    Abstract: Computer implemented systems and methods for use in monitoring a computing system (716) with respect to occurrence of a recovery scenario from which the computing system would require recovery. A method (200) comprises determining (202) a risk that the computing system will undergo the recovery scenario, and responsive to the determined risk, performing (204) one or more pre-emptive actions so as mitigate against occurrence of the recovery scenario. The pre-emptive actions comprise: a) adding a security control to compensate for the recovery scenario; b) creating an image of part of the computing system; c) storing artifacts of the computing system in a storage space that is separate from the computing system; d) encrypting or deleting data from the computing system; and/or e) disabling one or more components in the computing system.
    Type: Application
    Filed: September 22, 2021
    Publication date: May 1, 2025
    Inventors: Anu Puhakainen, Harri Hakala, Joel Patrik Reijonen
  • Publication number: 20250048094
    Abstract: A method for authenticating a wireless communications device to a network slice of a communications network is provided. The wireless communications device has one or more attributes associated with it, at least one of the one or more attributes fulfilling an attribute-based access policy of the network slice. The method is performed by a slice manager of the communications network and comprises sending a secret key to the wireless communications device, sending an encrypted access key to the wireless communications device, the encrypted access key being encrypted using the access policy, such that a secret key generated based at least one attribute that fulfill the attribute-based access policy can decrypt the encrypted access key.
    Type: Application
    Filed: December 16, 2021
    Publication date: February 6, 2025
    Inventors: Makan Pourzandi, Yosr Jarraya, Harri Hakala, Bernard Smeets, Tommy Arngren
  • Publication number: 20240394365
    Abstract: A method (200) for use in securing a computing system (416) against a recovery scenario from which the computing system would require recovery. The method comprises: i) obtaining (202) system recovery indicators for the computing system; and ii) predicting (204) a likelihood that the computing system will undergo the recovery scenario from the system recovery indicators using a model trained using a machine learning process that takes as input the system recovery indicators.
    Type: Application
    Filed: September 22, 2021
    Publication date: November 28, 2024
    Inventors: Anu Puhakainen, Harri Hakala, Joel Patrik Reijonen
  • Publication number: 20240323103
    Abstract: A method is implemented by a security service orchestration function (SSOF) in a communication infrastructure, that includes a plurality of PLMNs and a plurality of enterprises, for orchestration of a security service level agreement (S-SLA). The method includes receiving, by a SSOF in a HPLMN, a S-SLA request from one or more of the enterprises. Each S-SLA request includes a plurality of requirements. The HPLMN corresponds to one of the plurality of PLMNs. The method also includes converting each S-SLA request into a consistent and unified S-SLA offerable to each enterprise. The consistent and unified S-SLA includes security attributes that the HPLMN is capable of providing. The method also includes offering the consistent and unified S-SLA to each enterprise that submitted the S-SLA request. The method further includes transforming each S-SLA request from the enterprises into security policies and controls to be enforced within the HPLMN.
    Type: Application
    Filed: July 7, 2021
    Publication date: September 26, 2024
    Inventors: Harri HAKALA, Ari PIETIKÄINEN, Anu PUHAKAINEN
  • Publication number: 20240314171
    Abstract: A method implemented by a security service orchestration function (SSOF) in a communication infrastructure, that includes a plurality of communication service providers (CSPs), for orchestration of a security service level agreement (S-SLA) includes receiving a S-SLA request, by a CSP, from one or more other CSPs. Each S-SLA request includes a plurality of requirements. The method also includes converting each S-SLA request into a consistent and unified S-SLA offerable to each other CSP. The consistent and unified S-SLA includes security attributes that the CSP is capable of providing the other CSPs. The method also includes offering the consistent and unified S-SLA to each other CSP that submitted the S-SLA request. The method further includes receiving a response from each other CSP. The response from each other CSP includes an acknowledgement or a decline of the consistent and unified S-SLA including a non-repudiation signature of acknowledgement or declining.
    Type: Application
    Filed: July 7, 2021
    Publication date: September 19, 2024
    Inventors: Anu PUHAKAINEN, Harri HAKALA, Ari PIETIKÄINEN
  • Publication number: 20240283713
    Abstract: A method implemented by a security service orchestration function (SSOF) in a communication infrastructure, that includes a communication service provider (CSP) and a plurality of enterprises, for orchestration of a security service level agreement (S-SLA). The method includes receiving a S-SLA request from one or more of the enterprises. Each S-SLA request includes a plurality of requirements. The method also includes converting each S-SLA request into a unique S-SLA corresponding to the plurality of requirements in the S-SLA request from an associated enterprise. Each unique S-SLA includes security attributes that the CSP is capable of providing. The method additionally includes offering the unique S-SLA to the associated enterprise for each enterprise that submitted the S-SLA request. The method further includes receiving a response from each enterprise.
    Type: Application
    Filed: July 7, 2021
    Publication date: August 22, 2024
    Inventors: Harri HAKALA, Ari PIETIKÄINEN, Anu PUHAKAINEN
  • Publication number: 20240275775
    Abstract: A method, system and nodes are disclosed. According to one or more embodiments, a management node (16) is provided. The management node (16) includes processing circuitry (36) configured to receive an origin certificate for a first service type where the received origin certificate includes a public key and a private key, receive a certificate request for a first instance of the first service type, generate a first proxy certificate based at least on the received origin certificate, and transmit the first proxy certificate and the public key of the received origin certificate to a first virtual network function component where the public key of the received origin certificate is for inclusion to a listing of trusted certificates at the first virtual network function component.
    Type: Application
    Filed: June 9, 2021
    Publication date: August 15, 2024
    Inventors: Makan POURZANDI, Bernard SMEETS, Harri HAKALA, Tommy ARNGREN, Yosr JARRAYA
  • Publication number: 20240015175
    Abstract: There is provided mechanisms for generating a security configuration profile for a network entity. A method is performed by a security configuration entity. The method comprises generating the security configuration profile for the network entity based on network entity information, deployment information, and feedback information for a previously generated security configuration profile. The method comprises determining, based on calculating a risk score for the generated security configuration profile, whether the security configuration profile is to be provided towards the network entity or not. The method comprises generating feedback information for the security configuration profile based on the risk score, the network entity information, and the deployment information.
    Type: Application
    Filed: August 14, 2020
    Publication date: January 11, 2024
    Applicant: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Harri HAKALA, Anu PUHAKAINEN, Joel Patrik REIJONEN, Tomi POUTANEN
  • Publication number: 20230239687
    Abstract: According to some embodiments, a security management entity is provided. The security management entity includes processing circuitry configured to: generate a key having a plurality of key parts, anonymize at least a first data instance at least in part by using the key with threshold cryptography, transmit a respective key part to each one of the plurality of trusted entities, store at least one key part where the stored at least one key part is different from the transmitted respective key parts, receive a message from a first trusted entity of the plurality of trusted entities for investigating the anonymized first data instance where the message includes one of the transmitted respective key parts, and deanonymize the first data instance using the stored at least one key part and the one of the transmitted respective key parts associated with the first trusted entity.
    Type: Application
    Filed: June 25, 2020
    Publication date: July 27, 2023
    Inventors: Bernard SMEETS, Harri HAKALA, Tommy ARNGREN, Yosr JARRAYA, Makan POURZANDI
  • Publication number: 20230071264
    Abstract: A Security automation system (100; 400; 500) configured for security management of an Information Technology (IT) system (200), the security automation system using machine learning (ML). The system comprises a Threat engine (110), a Risk engine (120), a Policy engine (130) and a Security Adaptation engine (140). The Threat engine (110) comprises a threat catalog and detection rules for identifying threat events, wherein the detection rules are automatically adjusted and modified based on information collected from the managed IT system.
    Type: Application
    Filed: February 4, 2021
    Publication date: March 9, 2023
    Inventors: Harri HAKALA, Anu PUHAKAINEN
  • Publication number: 20230022539
    Abstract: A security management system including a first TEE and a common TEE is provided. The first TEE is a secured environment for data associated with a first entity. The common TEE is a seemed environment for data associated with any one of a plurality of entities. First anonymization parameters are shared between the first TEE and the common TEE The first anonymization parameters arc based at least in part on at least one privacy requirement of the first entity and at least one utility requirement of the security management system. The security management system includes processing circuitry configured to: anonymize first data associated with the first entity based at least in part on the first anonymization parameters, analyze at least the anonymized first data for performing data investigation, and generate analysis results based at least in part on the analysis of at least the anonymized first data.
    Type: Application
    Filed: January 14, 2020
    Publication date: January 26, 2023
    Inventors: Yosr JARRAYA, Makan POURZANDI, Harri HAKALA, Bernard SMEETS, Tommy ARNGREN
  • Patent number: 11139957
    Abstract: An apparatus and method for creating a finite blockchain is provided. The blockchain comprises a genesis block that is the first block of the blockchain. The genesis block comprising a genesis expiry time. The method comprises the steps of creating a reincarnation block when a predefined condition is satisfied and appending it to the blockchain; determining whether the genesis expiry time has elapsed based on an expiry period; if the genesis expiry time has elapsed then identifying a first reincarnation block; if the first reincarnation block is identified then deleting all the blocks preceding the first reincarnation block including the genesis block in the block chain.
    Type: Grant
    Filed: December 8, 2016
    Date of Patent: October 5, 2021
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Hans Ahlbäck, Harri Hakala, Mikael Jaatinen, Leena Marjatta Mattila
  • Patent number: 10990428
    Abstract: A method of verifying the integrity of a virtual machine in a cloud computing deployment comprises: creating a virtual machine image derived from a trusted virtual machine, wherein the trusted virtual machine has a Keyless Signature Infrastructure signature stored in a signature store; and verifying that a computation resource can be trusted. If it is verified that a computation resource can be trusted, the method further comprises: submitting the virtual machine image to the trusted computation resource; checking a signature of the virtual machine image against the stored signature of the trusted virtual machine; launching the virtual machine image on the trusted computation resource, and creating a Keyless Signature Infrastructure signature of the virtual machine image; and storing the signature of the virtual machine image in a signature store.
    Type: Grant
    Filed: July 3, 2015
    Date of Patent: April 27, 2021
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Harri Hakala, Ari Pietikäinen, Ben Smeets
  • Publication number: 20200076576
    Abstract: An apparatus and method for creating a finite blockchain is provided. The blockchain comprises a genesis block that is the first block of the blockchain. The genesis block comprising a genesis expiry time. The method comprises the steps of creating a reincarnation block when a predefined condition is satisfied and appending it to the blockchain; determining whether the genesis expiry time has elapsed based on an expiry period; if the genesis expiry time has elapsed then identifying a first reincarnation block; if the first reincarnation block is identified then deleting all the blocks preceding the first reincarnation block including the genesis block in the block chain.
    Type: Application
    Filed: December 8, 2016
    Publication date: March 5, 2020
    Inventors: Hans AHLBÄCK, Harri HAKALA, Mikael JAATINEN, Leena Marjatta MATTILA
  • Patent number: 10482078
    Abstract: The disclosure relates to a method (30) of handling a hash-tree based data signature. The method (30) is performed in a first device (13, 13a) and comprises: receiving (31), from a second device (12, 12a, 12b), a data signature generation request, the request comprising an indication on type of storage of a generated data signature; generating (32), in response to the data signature generation request, the data signature B using a hash-tree based data signing method; and providing (33), to the second device (12, 12a, 12b), a reference C to the generated data signature, wherein the generated data signature is obtainable by means of the reference C. The disclosure also relates to a method in a second device, corresponding devices, computer programs and computer program products.
    Type: Grant
    Filed: June 30, 2015
    Date of Patent: November 19, 2019
    Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
    Inventors: Harri Hakala, Mikael Jaatinen, Hannu Lehtinen, Leena Marjatta Mattila