Patents by Inventor Jari T. Malinen
Jari T. Malinen has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 11564074Abstract: In a second group of embodiments, an electronic device that provides a virtual Bluetooth gateway is described. During operation, the electronic device may receive a first packet associated with a second electronic device and that has an Internet Protocol (IP)-compatible format (such as a JavaScript Object Notation or JSON format). Then, the electronic device may de-encapsulate a second packet from the first packet, where the second packet is compatible with a Bluetooth communication protocol. Next, the electronic may provide the second packet. Note that the electronic device may not include a physical Bluetooth radio, such as dedicated hardware for a physical Bluetooth radio. Instead, the electronic device may include a virtual Bluetooth device that communicates with the second electronic device via the virtual Bluetooth gateway. This virtual Bluetooth device may have the capabilities of a physical Bluetooth radio (without the dedicated hardware).Type: GrantFiled: September 30, 2020Date of Patent: January 24, 2023Assignee: ARRIS Enterprises LLCInventors: Brajesh Kumar, Jari T. Malinen, Dinesh Raman
-
Patent number: 11546150Abstract: An electronic device (such as an IoT controller) that distributes a link key is described. During operation, while an administrator is logged in, the electronic device may receive the link key using a secure widget, where the link key may facilitate secure communication via a link. Then, the electronic device may generate an access key, and may generate an encrypted version of the link key based at least in part on the access key and the link key, where the access key enables access to the link key based at least in part on the encrypted version of the link key. Next, the electronic device may store the link key, the access key and/or the encrypted version of the link key in a trusted envelope or partition in the memory with encryption. Moreover, when the administrator logs out, the electronic device may disable access to the trusted envelope.Type: GrantFiled: September 24, 2020Date of Patent: January 3, 2023Assignee: ARRIS ENTERPRISES, LLCInventors: Siby Mathew Tarigopla Pancras, Jari T. Malinen
-
Patent number: 11277351Abstract: An electronic device (such as an access point or an eNodeB) that selectively provides prioritized communication is described. During operation, the electronic device may receive one or more packets or frames from a second electronic device using a communication protocol. Then, the electronic device may determine device-specific information based at least in part on a device profile associated with the communication protocol and/or a communication history of the second electronic device. Next, based on the determined device-specific information, the electronic device may assign additional data traffic associated with the second electronic device to a queue in a set of queues, where queues in the set of queues have different priorities, and where the queue provides a predefined latency of communication with the second electronic device corresponding to a priority of the queue.Type: GrantFiled: October 10, 2019Date of Patent: March 15, 2022Assignee: ARRIS Enterprises LLCInventors: Siby Mathew Tarigopla Pancras, Karthik Ranganathan, Dinesh Raman, Jari T. Malinen
-
Publication number: 20210409923Abstract: In a second group of embodiments, an electronic device that provides a virtual Bluetooth gateway is described. During operation, the electronic device may receive a first packet associated with a second electronic device and that has an Internet Protocol (IP)-compatible format (such as a JavaScript Object Notation or JSON format). Then, the electronic device may de-encapsulate a second packet from the first packet, where the second packet is compatible with a Bluetooth communication protocol. Next, the electronic may provide the second packet. Note that the electronic device may not include a physical Bluetooth radio, such as dedicated hardware for a physical Bluetooth radio. Instead, the electronic device may include a virtual Bluetooth device that communicates with the second electronic device via the virtual Bluetooth gateway. This virtual Bluetooth device may have the capabilities of a physical Bluetooth radio (without the dedicated hardware).Type: ApplicationFiled: September 30, 2020Publication date: December 30, 2021Applicant: ARRIS Enterprises LLCInventors: Brajesh Kumar, Jari T. Malinen, Dinesh Raman
-
Publication number: 20210091941Abstract: An electronic device (such as an IoT controller) that distributes a link key is described. During operation, while an administrator is logged in, the electronic device may receive the link key using a secure widget, where the link key may facilitate secure communication via a link. Then, the electronic device may generate an access key, and may generate an encrypted version of the link key based at least in part on the access key and the link key, where the access key enables access to the link key based at least in part on the encrypted version of the link key. Next, the electronic device may store the link key, the access key and/or the encrypted version of the link key in a trusted envelope or partition in the memory with encryption. Moreover, when the administrator logs out, the electronic device may disable access to the trusted envelope.Type: ApplicationFiled: September 24, 2020Publication date: March 25, 2021Applicant: ARRIS Enterprises LLCInventors: Siby Mathew Tarigopla Pancras, Jari T. Malinen
-
Publication number: 20200177517Abstract: An electronic device (such as an access point or an eNodeB) that selectively provides prioritized communication is described. During operation, the electronic device may receive one or more packets or frames from a second electronic device using a communication protocol. Then, the electronic device may determine device-specific information based at least in part on a device profile associated with the communication protocol and/or a communication history of the second electronic device. Next, based on the determined device-specific information, the electronic device may assign additional data traffic associated with the second electronic device to a queue in a set of queues, where queues in the set of queues have different priorities, and where the queue provides a predefined latency of communication with the second electronic device corresponding to a priority of the queue.Type: ApplicationFiled: October 10, 2019Publication date: June 4, 2020Inventors: Siby Mathew Tarigopla Pancras, Karthik Ranganathan, Dinesh Raman, Jari T. Malinen
-
Patent number: 9445272Abstract: The invention proposes a system for authenticating and authorizing network services comprising: a mobile device being adapted to, upon receipt of an information message indicating at least one network access type, determine the network access type, to create a start message containing at least a user identity, and to encapsulate the start message in an authentication message compatible with the access network identified in the information message, and an access controller for reading the encapsulated message from the mobile and forwarding the encapsulated message to an authentication server identified in the encapsulated message. The invention also proposes a corresponding method for authenticating and authorizing network services, and an access control device, a subscriber device and a router device.Type: GrantFiled: September 29, 2014Date of Patent: September 13, 2016Assignee: Nokia Technologies OyInventors: Jari T. Malinen, Timothy J. Kniveton, Meghana Sahasrabudhe
-
Publication number: 20150016609Abstract: The invention proposes a system for authenticating and authorizing network services comprising: a mobile device being adapted to, upon receipt of an information message indicating at least one network access type, determine the network access type, to create a start message containing at least a user identity, and to encapsulate the start message in an authentication message compatible with the access network identified in the information message, and an access controller for reading the encapsulated message from the mobile and forwarding the encapsulated message to an authentication server identified in the encapsulated message. The invention also proposes a corresponding method for authenticating and authorizing network services, and an access control device, a subscriber device and a router device.Type: ApplicationFiled: September 29, 2014Publication date: January 15, 2015Inventors: Jari T. Malinen, Timothy J. Kniveton, Meghana Sahasrabudhe
-
Patent number: 8869242Abstract: The invention proposes a system for authenticating and authorizing network services comprising: a mobile device being adapted to, upon receipt of an information message indicating at least one network access type, determine the network access type, to create a start message containing at least a user identity, and to encapsulate the start message in an authentication message compatible with the access network identified in the information message, and an access controller for reading the encapsulated message from the mobile and forwarding the encapsulated message to an authentication server identified in the encapsulated message. The invention also proposes a corresponding method for authenticating and authorizing network services, and an access control device, a subscriber device and a router device.Type: GrantFiled: November 16, 2012Date of Patent: October 21, 2014Assignee: Nokia CorporationInventors: Jari T. Malinen, Timothy J. Kniveton, Meghana Sahasrabudhe
-
Patent number: 8705522Abstract: A method and system for supporting mobile routers in Internet Protocol version 6 (IPv6) is provided. A mobile router obtains a care-of-address associated with an address configuration. The mobile router registers the care-of-address with a home agent. A bi-directional tunnel is established between the mobile router and the home agent. Packets are then forwarded via the bi-directional tunnel.Type: GrantFiled: October 9, 2007Date of Patent: April 22, 2014Assignee: Nokia CorporationInventors: Outi Elisa Markki, Timothy J. Kniveton, Jari T. Malinen, Vijay Devarapalli, Charles E. Perkins
-
Publication number: 20130074161Abstract: The invention proposes a system for authenticating and authorizing network services comprising: a mobile device being adapted to, upon receipt of an information message indicating at least one network access type, determine the network access type, to create a start message containing at least a user identity, and to encapsulate the start message in an authentication message compatible with the access network identified in the information message, and an access controller for reading the encapsulated message from the mobile and forwarding the encapsulated message to an authentication server identified in the encapsulated message. The invention also proposes a corresponding method for authenticating and authorizing network services, and an access control device, a subscriber device and a router device.Type: ApplicationFiled: November 16, 2012Publication date: March 21, 2013Inventors: Jari T. Malinen, Timothy J. Kniveton, Meghana Sahasrabudhe
-
Patent number: 8341700Abstract: The invention proposes a system for authenticating and authorizing network services comprising: a mobile device being adapted to, upon receipt of an information message indicating at least one network access type, determine the network access type, to create a start message containing at least a user identity, and to encapsulate the start message in an authentication message compatible with the access network identified in the information message, and an access controller for reading the encapsulated message from the mobile and forwarding the encapsulated message to an authentication server identified in the encapsulated message. The invention also proposes a corresponding method for authenticating and authorizing network services, and an access control device, a subscriber device and a router device.Type: GrantFiled: October 8, 2004Date of Patent: December 25, 2012Assignee: Nokia CorporationInventors: Jari T. Malinen, Timothy J. Kniveton, Meghana Sahasrabudhe
-
Patent number: 7900242Abstract: A system and method for three-party authentication and authorization. The system includes an authorizer that authorizes requestors, a client that makes a request, and a local attendant that provides a conduit through which messages between the client and the authorizer pass. The authorizer, the client, and a peer on which the requested resource may be accessed are each in separate domains. A domain is defined as a set of one or more entities such that if the set includes more than one entity, a connection between any two of the entities in the set can be secured by static credentials that are known by each of the two entities. A subscriber identity module (SIM) may be used to generate a copy of a key for the client to be used in accessing a requested resource.Type: GrantFiled: July 9, 2002Date of Patent: March 1, 2011Assignee: Nokia CorporationInventors: Jari T. Malinen, Timothy J. Kniveton, Henry Haverinen
-
Patent number: 7444513Abstract: A client 110 may be authenticated by transmitting or beaming a telecommunication network subscriber's authentication to the client from a device 120, over a wireless link. For example, a GSM telephone 120 may authenticate an electronic book 110 to a content providing service within the Internet. The service verifies the authentication using the subscriber's GSM network operator's Authentication Center 161 to generate an authenticator and the client correspondingly generates a local copy of the authenticator using a GSM SIM over the wireless local link. The authentication is then determined by checking that these authenticators match and thereafter the authenticator can be used as a session key to encrypt data in the service.Type: GrantFiled: May 29, 2001Date of Patent: October 28, 2008Assignee: Nokia CorporiationInventors: Kai Nyman, Mikko Olkkonen, Jari T. Malinen
-
Publication number: 20080256605Abstract: The invention provides a method for bootstrapping a local authorizer of a non-public access network. The local authorizer is arranged for granting access for a client device to the non-public access network. Therefore, the local authorizer includes a credentials database, which is used in authentication and authorization of the client device during access to services or resources of the non-public network. A secret knowledge of the client device is used for generating at least one set of credentials. The bootstrapping method includes the step of uploading the at least one set of credentials to the credentials database of the local authorizer. This upload is performed by the client device at least at first access of the client device to the non-public network. Then the credentials in the credentials database are used for authentication and authorization of the client device during access to the non-public access network.Type: ApplicationFiled: August 14, 2003Publication date: October 16, 2008Inventor: Jari T. Malinen
-
Patent number: 7298743Abstract: A method and system for supporting mobile routers in Internet Protocol version 6 (IPv6) is provided. A mobile router obtains a care-of-address associated with an address configuration. The mobile router registers the care-of-address with a home agent. A bi-directional tunnel is established between the mobile router and the home agent. Packets are then forwarded via the bi-directional tunnel.Type: GrantFiled: November 14, 2002Date of Patent: November 20, 2007Assignee: Nokia CorporationInventors: Outi Elisa Markki, Timothy J. Kniveton, Jari T. Malinen, Vijay Devarapalli, Charles E. Perkins
-
Patent number: 7263087Abstract: The invention is directed to enabling an serving node and a gateway node to be informed of a new route for a new node or sub-network that has become active behind a Mobile Terminal that can also act as a router. When IP level route injection occurs at the Mobile Terminal, a Modify session profile message causes insertion of a new IP address or prefix at a gateway node related to the new route. Also, the gateway node will update the serving node and the Mobile Terminal with information related to the new route or a proposed new route. The Mobile Terminal and the gateway node can share routing information over a dynamic routing protocol. Additionally, the Mobile Terminal and the gateway node can configure static routing information on routes towards each other. The new route can be added with 24.008 and/or GTP messages when initiated on the Mobile Terminal side for either the dynamic or static case.Type: GrantFiled: January 24, 2003Date of Patent: August 28, 2007Assignee: Nokia CorporationInventors: Jonne Soininen, Jari T. Malinen
-
Patent number: 7142520Abstract: A mobile internet protocol regional paging network 10 includes a paging foreign agent for handling a regional registration of a mobile node visiting a paging area, which includes internet protocol subnetworks. In operation, the mobile node periodically can provide an idle mode request to the paging foreign agent to enter an idle mode so as to deactivate one or more components for energy-saving purposes and reduce active communication with the mobile internet protocol regional paging network. The invention provides a small and link-layer independent extension to Mobile Internet Protocol with Regional Registrations to support power-constrained operation in the mobile nodes and to reduce routing state information in the visited domain. The extension allows a Mobile Node to enter a power saving Idle Mode during which its location is known with the coarse accuracy defined by a Paging Area. The mobile node and the visited domain may optionally agree on time slots used for Agent Advertisements and paging.Type: GrantFiled: June 16, 2000Date of Patent: November 28, 2006Assignee: Nokia Mobile Phones Ltd.Inventors: Henry Haverinen, Jari T. Malinen
-
Patent number: 7085808Abstract: The invention relates to a method for distinguishing clients in a communication system comprising at least one wireless access network and at least one wired access network. The wireless access network comprise means for connecting wireless clients in communication to the wireless access network. Wired access network comprise means for connecting wired clients in communication to the wired access network. Communication system comprise means for communicating between the access network and the wired access network. In the method a resolution request message is transmitted to the communication system indicating a client to be examined, the message is received in at least one other node. A decision whether a resolution reply message is to be transmitted to the communication system is performed on the basis of a resolution reply message.Type: GrantFiled: June 7, 2001Date of Patent: August 1, 2006Assignee: Nokia CorporationInventors: Henry Haverinen, Jari T. Malinen
-
Patent number: 7035940Abstract: A system and method is directed to updating information in a mobile network. A dynamic signaling routing protocol is extended over bi-directional tunneling between a mobile router and its home agent such that information associated with the home agent of the mobile router reflects roaming of the mobile router as it travels from its home network. The information is determined as a function of a characteristic associated with each link of the tunnel between the mobile router and its home agent. In one embodiment, the information includes a cost metric associated with the cost of the tunnel. The information is advertised to another router. The other router employs the information associated with the tunnel to determine a path for communication.Type: GrantFiled: November 7, 2002Date of Patent: April 25, 2006Assignee: Nokia CorporationInventors: Meghana Sahasrabudhe, Jari T. Malinen