Patents by Inventor Jari Arkko
Jari Arkko has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260230460Abstract: The present disclosure relates to a method of a Manufacturer Usage Description (MUD) file server (13) enrolling a MUD device (12 ) and a MUD file server (13) performing the method, and a method of a MUD manager (12) verifying a MUD device (10) and a MUD manager MUD MUD (12) performing the method. The present disclosure further relates to computer programs (112, 212) and computer program products. In an aspect, a method of a MUD file server (13) enrolling a MUD device (10) is provided. The method comprises receiving (S101) authentication data from the MUD device (10), verifying (S102) the received authentication data, associating (S103) an identifier of the MUD device (10) with a MUD file assigned to the MUD device (10) and providing (S104) the MUD device (10) with a data destination to the assigned MUD file.Type: ApplicationFiled: December 27, 2022Publication date: August 6, 2026Inventors: Jaime Jiménez, Patrik Salmela, Jari Arkko
-
Publication number: 20260219357Abstract: The present disclosure provides methods and apparatus for setting up a collaborative sensing process. A method performed by a first UE (201a), for setting up a collaborative sensing process with an observer (200). The first UE (201a) receiving (103a) a first signal from the observer (200). The first signal comprising information about the identity of the observer (200). The first UE (201a) determining (104a) the identity of the observer (200) from the information about the identity of the observer (200) comprised in the received first signal. The first UE (201a) transmitting (105a) a second signal to the observer (200) for requesting the observer (200) to participate in the collaborative sensing process and setting up (106a) the collaborative sensing process upon agreement from the observer (200). Further, there is a method performed by the observer (200) for setting up a collaborative sensing process with the first UE 201a.Type: ApplicationFiled: January 19, 2023Publication date: July 30, 2026Inventors: Jari Arkko, Mikko Saarisalo, Ari Keränen
-
Patent number: 12683772Abstract: Mechanisms for establishing forward secrecy during digest access authentication are provided. A method is performed by a client device. The method includes performing digest access authentication with a server device. The digest access authentication includes sending a first request towards the server device for accessing a resource; and receiving a first response. The first response includes a challenge and a public component of an asymmetric key pair for a key exchange with the server device. The digest access authentication includes calculating, using a digest algorithm, a response parameter based at least on the challenge and the public component of the asymmetric key pair; and sending a second request towards the server device for accessing the resource. The second request includes the calculated response parameter. The digest access authentication includes receiving a second response from the server device that indicates successful digest access authentication with the server device.Type: GrantFiled: August 3, 2021Date of Patent: July 14, 2026Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Vesa Lehtovirta, Mohit Sethi, Jari Arkko, John Mattsson
-
Publication number: 20260156194Abstract: A computing device is disclosed. The computing device comprises processing circuitry that is configured to expose (110) a resource that is hosted at the computing device, wherein the resource comprises a digital interface for a physical entity to which the resource corresponds, and expose (120) information about a relation between a state of the resource and a state of the physical entity to which the resource corresponds. Also disclosed is a network node, the network node comprising processing circuitry that is configured to discover a resource that is hosted at the computing device, and to discover information about a relation between a state of the resource and a state of the physical entity to which the resource corresponds. The processing circuitry is further configured to prepare an action relating to the physical entity corresponding to the resource on the basis of a current state of the resource and the information, and to initiate execution of the prepared action.Type: ApplicationFiled: December 15, 2025Publication date: June 4, 2026Inventors: Ari Keränen, Jari Arkko
-
Patent number: 12621300Abstract: A method comprising a client device performing digest access authentication with a server device. The digest access authentication comprises sending a first request towards the server device for accessing a resource. The digest access authentication comprises receiving a first response from the server device. The first response comprises at least two challenges and indications of as many different digest algorithms, one digest algorithm is associated with each challenge. The digest access authentication comprises calculating a response to one of the challenges using the digest algorithm associated with said one of the challenges. The response to said one of the challenges is indicative of all of the different digest algorithms. The digest access authentication comprises sending a second request towards the server device for accessing the resource. The second request comprises the response to said one of the challenges.Type: GrantFiled: June 16, 2021Date of Patent: May 5, 2026Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Vesa Lehtovirta, Jari Arkko, Mohit Sethi, John Mattsson
-
Patent number: 12500960Abstract: A computing device is disclosed. The computing device comprises processing circuitry that is configured to expose (110) a resource that is hosted at the computing device, wherein the resource comprises a digital interface for a physical entity to which the resource corresponds, and expose (120) information about a relation between a state of the resource and a state of the physical entity to which the resource corresponds. Also disclosed is a network node, the network node comprising processing circuitry that is configured to discover a resource that is hosted at the computing device, and to discover information about a relation between a state of the resource and a state of the physical entity to which the resource corresponds. The processing circuitry is further configured to prepare an action relating to the physical entity corresponding to the resource on the basis of a current state of the resource and the information, and to initiate execution of the prepared action.Type: GrantFiled: July 29, 2020Date of Patent: December 16, 2025Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Ari Keränen, Jari Arkko
-
Patent number: 12500862Abstract: A technique for generating an internet protocol, IP, address according to IPv6, for access to one of a plurality of wireless devices connected or connectable to a wireless network from an application node in a communications network is provided. As to a method aspect of the technique, an IPv6 address for access from the application node in the communications network to a respective one of the wireless devices is generated based on a subnet identifier of the wireless network and a device identifier of the respective one of the wireless devices. The generated IPv6 address is provided for the access from the application node in the communications network.Type: GrantFiled: August 25, 2021Date of Patent: December 16, 2025Assignee: Telefonaktiebolaget LM Ericsson (Publ)Inventors: Jari Arkko, Ari Keränen, Jan Backman
-
Patent number: 12267672Abstract: A method (300) for registering with a serving network (104). The method is performed by a UE (102). The method includes the UE transmitting (s302) to the serving network (104) a message (212) indicating a UE capability that is relevant for a home network (106), wherein the 5 serving network (104) is configured to send to the home network (106) a message (216) indicating the UE capability.Type: GrantFiled: March 4, 2020Date of Patent: April 1, 2025Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Jari Arkko, Vesa Lehtovirta
-
Patent number: 12156109Abstract: A method of re-establishing a connection between a LWM2M client and an LWM2M server following a reconnection of the LWM2M client to the LWM2M server includes determining, at the LWM2M client, a state of the LWM2M client device prior to reconnection of the LWM2M client, transmitting, to the LWM2M server, an indication of the state of the LWM2M client prior to reconnection of the LWM2M client, and receiving a response from the LWM2M server indicating whether the indicated state of the LWM2M client is an expected state or an unexpected state of the LWM2M client.Type: GrantFiled: November 7, 2018Date of Patent: November 26, 2024Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Ari Keränen, Jari Arkko
-
Publication number: 20240356893Abstract: A technique for generating an internet protocol, IP, address according to IPv6, for access to one of a plurality of wireless devices connected or connectable to a wireless network from an application node in a communications network is provided. As to a method aspect of the technique, an IPv6 address for access from the application node in the communications network to a respective one of the wireless devices is generated based on a subnet identifier of the wireless network and a device identifier of the respective one of the wireless devices. The generated IPv6 address is provided for the access from the application node in the communications network.Type: ApplicationFiled: August 25, 2021Publication date: October 24, 2024Inventors: Jari ARKKO, Ari KERÄNEN, Jan BACKMAN
-
Publication number: 20240340164Abstract: Mechanisms for establishing forward secrecy during digest access authentication are provided. A method is performed by a client device. The method includes performing digest access authentication with a server device. The digest access authentication includes sending a first request towards the server device for accessing a resource; and receiving a first response. The first response includes a challenge and a public component of an asymmetric key pair for a key exchange with the server device. The digest access authentication includes calculating, using a digest algorithm, a response parameter based at least on the challenge and the public component of the asymmetric key pair; and sending a second request towards the server device for accessing the resource. The second request includes the calculated response parameter. The digest access authentication includes receiving a second response from the server device that indicates successful digest access authentication with the server device.Type: ApplicationFiled: August 3, 2021Publication date: October 10, 2024Inventors: Vesa LEHTOVIRTA, Mohit SETHI, Jari ARKKO, John MATTSSON
-
Publication number: 20240283794Abstract: A method comprising a client device performing digest access authentication with a server device. The digest access authentication comprises sending a first request towards the server device for accessing a resource. The digest access authentication comprises receiving a first response from the server device. The first response comprises at least two challenges and indications of as many different digest algorithms, one digest algorithm is associated with each challenge. The digest access authentication comprises calculating a response to one of the challenges using the digest algorithm associated with said one of the challenges. The response to said one of the challenges is indicative of all of the different digest algorithms. The digest access authentication comprises sending a second request towards the server device for accessing the resource. The second request comprises the response to said one of the challenges.Type: ApplicationFiled: June 16, 2021Publication date: August 22, 2024Inventors: Vesa Lehtovirta, Jari Arkko, Mohit Sethi, John Mattsson
-
Publication number: 20240276215Abstract: Security anchor equipment (20) relays Extensible Authentication Protocol, EAP, messages (12M) between a communication device (10) and an authentication server (30) that is operating as an EAP server for an EAP Authentication and Key Agreement, AKA, procedure (12) between the communication device (10) and the authentication server (30). The security anchor equipment (20) receives, from the communication device (10), a response (16) to a challenge (14). The security anchor equipment (20) checks whether the response (16) corresponds to an expected response (18) as part of an attempt by the security anchor equipment (20) to authenticate the communication device (10). In some embodiments, at least one of the response (16), the challenge (14), and the expected response (18) is, or is derived using, information used in the EAP AKA procedure (12) between the communication device (10) and the authentication server (30).Type: ApplicationFiled: June 1, 2022Publication date: August 15, 2024Inventors: Prajwol Kumar Nakarmi, Vesa Lehtovirta, Jari Arkko
-
Patent number: 11924634Abstract: Methods of operating a user equipment (UE) in a mobile communication network are disclosed. An authentication process start message may be transmitted from the UE to the mobile communication network, wherein the authentication process start message includes an identifier for the UE. After transmitting the authentication process start message from the UE, a request commit message may be received from the mobile communication network. Responsive to receiving the request commit message, a response commit message may be transmitted to the mobile communication network. After transmitting the response commit message, an authentication challenge message may be received corresponding to the authentication process start message. Related methods of operating network nodes are also discussed.Type: GrantFiled: January 13, 2020Date of Patent: March 5, 2024Assignee: Telefonaktiebolaget LM Ericsson (Publ)Inventors: Jari Arkko, Vesa Lehtovirta
-
Publication number: 20240054221Abstract: Embodiments include methods performed by a computing device to obtain trusted computing services (TCS) from service providers (SPs). Such methods include querying one or more remote service databases for one or more TCS required by a user of the computing device or by an application executing on the computing device. The query for each required TCS includes identification of software required to provide the required TCS, and one or more indicia of trust for any computing platform that provides the required TCS. Such methods include receiving, from the remote service databases, information related to one or more available TCS and corresponding SPs of the available TCS and, based on the received information, selecting one of the available TCS and establishing a connection with the SP corresponding to the selected TCS. Embodiments include complementary methods performed by SPs and remote service databases, as well as apparatus configured to perform such methods.Type: ApplicationFiled: November 12, 2021Publication date: February 15, 2024Inventors: Jari Arkko, Jimmy Kjällman
-
Publication number: 20230359498Abstract: A method performed by an orchestrator. The method comprises receiving signaling that requests the orchestrator to orchestrate a service and that indicates a trusted computing policy with which a resource must prove compliance in order for the service to be orchestrated with that resource. The method further comprises sending a response that indicates whether or not the orchestrator has orchestrated the service according to the received signaling.Type: ApplicationFiled: July 16, 2021Publication date: November 9, 2023Inventor: Jari Arkko
-
Patent number: 11784797Abstract: A method for a serving network to selectively employ perfect forward security (PFS) based on an indication from a home network is described. The method includes receiving, by the serving network, a PFS indicator from the home network; determining, by the serving network, whether the PFS indicator indicates that the home network has instructed the serving network to employ PFS for communications with a piece of user equipment; and performing, by the serving network, a PFS procedure with the piece of user equipment in response to determining that the PFS indicator indicates that the home network has instructed the serving network to employ PFS for communications with the piece of user equipment.Type: GrantFiled: October 19, 2018Date of Patent: October 10, 2023Assignee: Telefonaktiebolaget LM Ericsson (Publ)Inventors: Jari Arkko, Vesa Torvinen
-
Patent number: 11722473Abstract: A communication device of a communication network receives, via a network, a challenge, generates a first Diffie Hellman, DH, parameter, a first verification code for the first DH parameter, forwards the challenge or a derivative thereof to an identity module, receives at least one result parameter as response from the identity module, determines, based on the result parameter, whether the first DH parameter is authentic, and if the first DH parameter is authentic, generates and sends a second DH parameter to the network device for session key generation based on the first DH parameter and the second DH parameter.Type: GrantFiled: February 23, 2021Date of Patent: August 8, 2023Assignee: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)Inventors: Mats Näslund, Bengt Sahlin, Karl Norrman, Jari Arkko
-
Publication number: 20230231925Abstract: A computing device is disclosed. The computing device comprises processing circuitry that is configured to expose (110) a resource that is hosted at the computing device, wherein the resource comprises a digital interface for a physical entity to which the resource corresponds, and expose (120) information about a relation between a state of the resource and a state of the physical entity to which the resource corresponds. Also disclosed is a network node, the network node comprising processing circuitry that is configured to discover a resource that is hosted at the computing device, and to discover information about a relation between a state of the resource and a state of the physical entity to which the resource corresponds. The processing circuitry is further configured to prepare an action relating to the physical entity corresponding to the resource on the basis of a current state of the resource and the information, and to initiate execution of the prepared action.Type: ApplicationFiled: July 29, 2020Publication date: July 20, 2023Inventors: Ari Keränen, Jari Arkko
-
Patent number: 11689358Abstract: Methods may be provided to transmit encrypted data from a communication device to a remote storage system. A data value and information related to the data value may be provided, where the information related to the data value includes an identifier associated with the communication device and a time-value associated with the data value. A combination of the time-value and the identifier may be encrypted using a public key to provide a first encrypted value. The data value may be encrypted using the public key to provide a second encrypted value, and a hidden datum package may be generated including the time-value, the first encrypted value, and the second encrypted value. The hidden datum package including the time-value, the first encrypted value, and the second encrypted value may be transmitted to the remote storage system.Type: GrantFiled: December 29, 2017Date of Patent: June 27, 2023Assignee: Telefonaktiebolaget LM Ericsson (publ)Inventors: Jari Arkko, Ari Keränen