Patents by Inventor Luis Barriga

Luis Barriga has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20100049980
    Abstract: Methods, systems and communication nodes for bootstrapping key establishment to exchange encryption keys between a terminal-based client and an application server using Session Initiation Protocol (SIP) signaling are described.
    Type: Application
    Filed: August 17, 2009
    Publication date: February 25, 2010
    Inventors: Luis Barriga, David Castellanos Zamora
  • Publication number: 20090205028
    Abstract: Methods and systems taught herein allow communication device manufacturers to preconfigure communication devices to use preliminary access credentials to gain temporary network access for downloading subscription credentials, and particularly allow the network operator issuing the subscription credentials to verify that individual devices requesting credentials are trusted. In one or more embodiments, a credentialing server is owned or controlled by the network operator, and is used by the network operator to verify that subscription credentials are issued only to trusted communication devices, even though such devices may be referred to the credentialing server by an external registration server and may be provisioned by an external provisioning server. Particularly, the credentialing server interrogates requesting devices for their device certificates and submits these device certificates to an external authorization server, e.g., an independent OCSP server, for verification.
    Type: Application
    Filed: October 23, 2008
    Publication date: August 13, 2009
    Inventors: Bernard Smeets, Luis Barriga, Mattias Johansson, Vesa Petteri Lehtovirta, Krister Sallberg
  • Publication number: 20090199001
    Abstract: A method and arrangement is disclosed for providing a user, not previously having an individual subscription with a network operator, with credentials for secure access to network services. The arrangement includes a gateway, associated with a subscription for network services, having means for generating and exporting to a user entity personalized user security data derived from security data related to the subscription. In particular, the derivation of credentials is based on a function that is shared between network and gateway and further conveniently makes use of bootstrapping on keying material from the subscription authentication. Pre-registered user identities are assigned trusted users who, thereafter, can download credentials and authenticate for service access. The invention may be implemented at a public place for providing temporary visitors network access whereby trust may exemplary be established by presenting a credit card.
    Type: Application
    Filed: June 9, 2006
    Publication date: August 6, 2009
    Inventors: Luis Barriga, Rolf Blom, Mats Naslund
  • Publication number: 20080215888
    Abstract: The present invention improves privacy protection and authentication over prior art GAA/GBA system specifying a Bootstrap Server Function (BSF) that creates an Authentication Voucher asserting to a network application function NAF authentication of a. BSF generates keys Ks and Ks NAF with corresponding key identifiers B_TID and B_TID_NAF. In order to prevent tracking of user by collusion between several NAF entities B_TID_NAF and the Voucher can be unique for each NAF. The interface Ua is further protected by encryption using key Ks and the Ub interface is further protected against man-in-the-middle attacks by using signatures with key Ks and provision of freshness.
    Type: Application
    Filed: July 7, 2005
    Publication date: September 4, 2008
    Applicant: Telefonaktiebolaget LM Ericsson
    Inventors: Luis Barriga, David Castellanos-Zarnora
  • Publication number: 20080009265
    Abstract: The present invention is related to an authentication method and arrangements in a communication system including a Subscriber (50) with a terminal (51), an Operator Node (52) and a Service Provider Node (53), which authentication method is based on an SLA agreement between the Operator (OP) and the Service Provider (SP). The method includes that the Subscriber (50) with terminal (51) performs (5) strong authentication with the Operator Node (52) acting as Registration Authority OP(RA). After the strong authentication is performed by the Operator Node (52) a Mobile Strong Authentication Assertion MSAA is generated (6) and transmitted to the Service Provider Node (53) for validation. By this method the authentication is being delegated from the Service Provider to the Mobile Operator.
    Type: Application
    Filed: December 22, 2006
    Publication date: January 10, 2008
    Inventors: Susana Fernandez-Alonso, Luis Barriga
  • Patent number: 7296290
    Abstract: An apparatus and method for providing Single Sign-On services to a user when accessing a selected Service Provider from a plurality of Service Providers. An Authentication Provider authenticates the user at with a user-identity, provides the user with a token as proof of the authentication, and assigns a temporary alias-identity to the user for use when the user accesses the selected Service Provider. The Authentication Provider and the selected Service Provider link the assigned alias-identity and the user-identity to identify the user at respective sites. The user accesses the selected Service Provider by presenting the token along with a local user-identity valid for the selected Service Provider. When the user attempts a subsequent access at the selected Service Provider, the user is identified by the shared alias-identity, if the user allowed permanent linking. If the user did not allow permanent linking, the process is repeated for each subsequent access.
    Type: Grant
    Filed: February 28, 2003
    Date of Patent: November 13, 2007
    Assignee: Telefonaktiebolget LM Ericsson (publ)
    Inventors: Luis Barriga, Avelina Pardo-Blazquez, John Michael Walker, Jesus-Angel de Gregorio
  • Publication number: 20070184819
    Abstract: The advent of new and sophisticated web services provided by Service Providers to users, services that individually require authentication of user and authorization of access, brings the needs for a new service to facilitate such authentication and access, a service referred to as Single Sign-On (SSO). The basic principle behind SSO is that users are authenticated once at a particular level, and then access all their subscribed services accepting that level of authentication. The present invention provides a system, method and apparatus wherein a cellular Federation of mobile network operators becomes an SSO authentication authority for subscribers of this Federation accessing Service Providers having such agreement with a mobile network operator of the Federation.
    Type: Application
    Filed: April 19, 2007
    Publication date: August 9, 2007
    Inventors: Luis Barriga-Caceres, Jesus Angel de Gregorio-Rodriguez, Avelina Pardo-Blazquez, John Michael Walker-Pina
  • Patent number: 7221935
    Abstract: The advent of new and sophisticated web services provided by Service Providers to users, services that individually require authentication of user and authorization of access, brings the needs for a new service to facilitate such authentication and access, a service referred to as Single Sign-On (SSO). The basic principle behind SSO is that users are authenticated once at a particular level, and then access all their subscribed services accepting that level of authentication. The present invention provides a system, method and apparatus wherein a cellular Federation of mobile network operators becomes an SSO authentication authority for subscribers of this Federation accessing Service Providers having such agreement with a mobile network operator of the Federation.
    Type: Grant
    Filed: June 19, 2002
    Date of Patent: May 22, 2007
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Luis Barriga-Caceres, Jesus Angel de Gregorio-Rodriguez, Avelina Pardo-Blazquez, John Michael Walker-Pina
  • Publication number: 20050154913
    Abstract: An apparatus and method for providing Single Sign-On services to a user when accessing a selected Service Provider from a plurality of Service Providers. An Authentication Provider authenticates the user at with a user-identity, provides the user with a token as proof of the authentication, and assigns a temporary alias-identity to the user for use when the user accesses the selected Service Provider. The Authentication Provider and the selected Service Provider link the assigned alias-identity and the user-identity to identify the user at respective sites. The user accesses the selected Service Provider by presenting the token along with a local user-identity valid for the selected Service Provider. When the user attempts a subsequent access at the selected Service Provider, the user is identified by the shared alias-identity, if the user allowed permanent linking. If the user did not allow permanent linking, the process is repeated for each subsequent access.
    Type: Application
    Filed: February 28, 2003
    Publication date: July 14, 2005
    Inventors: Luis Barriga, Avelina Pardo-Blazquez, John Walker, Jesus-Angel de Gregorio
  • Publication number: 20040249892
    Abstract: A multicontent e-mail has a body part comprising separately encrypted content parts and a header part comprising a clear text part and an encrypted part. The encrypted header part includes a descriptor section and a link section. The link section specifics relationships between content parts. The descriptor section provides information related to each body content part such as information format. The descriptor section, further, provides information for access to any content part such as requirement for authorization. The access information can include executable code exemplary for establishing a negotiation process for access to linked information at a remote information server. Further disclosed is an arrangement for download and decryption of the e-mail header part and analysis of the descriptor section. A user can select any body content part for downloading according to requirements determined from the descriptor section.
    Type: Application
    Filed: July 9, 2004
    Publication date: December 9, 2004
    Inventors: Luis Barriga, Jan-Erik Mangs
  • Patent number: 6779111
    Abstract: A system and method for encrypting data communications between a client and server utilizes an untrusted proxy server to perform computationally expensive encryption calculations which would otherwise be performed by the client. Prior to transmitting the data message to the proxy server, the client masks the data message such that the data message is indecipherable to the untrusted proxy. The untrusted proxy performs the computationally expensive encryption calculations prior to transmitting the data message to the intended receiver.
    Type: Grant
    Filed: May 10, 1999
    Date of Patent: August 17, 2004
    Assignee: Telefonaktiebolaget LM Ericsson (publ)
    Inventors: Christian Gehrmann, Luis Barriga
  • Publication number: 20030163733
    Abstract: The advent of new and sophisticated web services provided by Service Providers to users, services that individually require authentication of user and authorization of access, brings the needs for a new service to facilitate such authentication and access, a service referred to as Single Sign-On (SSO). The basic principle behind SSO is that users are authenticated once at a particular level, and then access all their subscribed services accepting that level of authentication.
    Type: Application
    Filed: June 19, 2002
    Publication date: August 28, 2003
    Inventors: Luis Barriga-Caceres, Jesus Angel de Gregorio-Rodriguez, Avelina Pardo-Blazquez, John Michael Walker-Pina