-
公开(公告)号:US20240056301A1
公开(公告)日:2024-02-15
申请号:US18447374
申请日:2023-08-10
Applicant: Nokia Technologies Oy
Inventor: Markus Staufer , Peter Schneider , Ranganathan Mavureddi Dhanasekaran , Saurabh Khare
IPC: H04L9/32
CPC classification number: H04L9/32
Abstract: Method comprising:
monitoring whether a network receives an authorization request for establishing a session of an AF with a UE, wherein the authorization request comprises a permanent identifier of the AF, a received temporary identifier of the AF, and a temporary identifier of a UE;
if the authorization request is received:
forming a key identifier based on the temporary identifier of the UE;
retrieving, based on the key identifier, a stored key and a first permanent identifier of the UE;
calculating a calculated temporary identifier of the AF based on the permanent identifier of the AF and the stored key;
checking whether the calculated temporary identifier of the AF is identical with the received temporary identifier of the AF;
inhibiting authorizing the AF for the establishing the session with the UE if the calculated temporary identifier of the AF is not identical with the received temporary identifier of the AF.-
公开(公告)号:US11425636B1
公开(公告)日:2022-08-23
申请号:US17232640
申请日:2021-04-16
Applicant: Nokia Technologies Oy
Inventor: Chaitanya Aggarwal , Saurabh Khare , Anja Jerichow
Abstract: According to an example aspect, there is provided a method, comprising: receiving, from a first network function consumer, a subscribe request for a second network function consumer to subscribe to a service, wherein the subscribe request comprises a notification address and identifies the second network function consumer, transmitting, to a network repository function, an access token request, comprising the notification address and identifying the second network function consumer, receiving, from the network repository function, an access token response comprising an access token comprising the notification address verified by the network repository function, transmitting, to the second network function consumer, an authorization request for receiving data authorization and comprising the access token, receiving, from the second network function consumer, an authorization response indicative of authorization of the second network function consumer, and transmitting, on the basis of the authorization response, a notification to the second network function consumer.
-
公开(公告)号:US20210410071A1
公开(公告)日:2021-12-30
申请号:US17279438
申请日:2018-09-25
Applicant: Nokia Technologies Oy
Inventor: Saurabh Khare , Devaki Chandramouli
Abstract: A system and method for saving mobile battery and empowering user equipment for controlling incoming communication and paging are provided. Also provided are a system and method for determining whether a mobile a device is in an idle mode, and in response to receiving an incoming communication from a service, determining whether the service associated with the incoming communication is on a reject list of services or a preferred list of services. The system performs a first action specified by a determination that the service is on the reject list of services or the service is not on the preferred list of services, and performs a second action specified by a determination that the service is on the preferred list of services. The first action differs from the second action.
-
公开(公告)号:US12206671B2
公开(公告)日:2025-01-21
申请号:US17737576
申请日:2022-05-05
Applicant: Nokia Technologies Oy
Inventor: Gerald Kunzmann , Saurabh Khare , Chaitanya Aggarwal
IPC: H04L9/40
Abstract: Techniques for data management in a network entity to authorize data consumers in a communication network are disclosed. For example, a method comprises receiving, at a network entity of a communication network, data generated by a data producer in the communication network, and storing, at the network entity, the data generated by the data producer. The stored data has metadata, associated with the data producer, appended thereto.
-
公开(公告)号:US20250016559A1
公开(公告)日:2025-01-09
申请号:US18749970
申请日:2024-06-21
Applicant: Nokia Technologies Oy
Inventor: Aritra BANERJEE , German Peinado Gomez , K Tirumaleswar Reddy , Saurabh Khare
IPC: H04W12/0471
Abstract: Method comprising: informing a responding entity of two or more first key exchange schemes each comprising a respective key exchange supported by an initiating entity for a communication between the responding entity and the initiating entity; receiving, from the responding entity, an indication of a selected key exchange scheme in response to the informing the responding entity of the two or more first key exchange schemes; checking whether the selected key exchange scheme is a hybrid key exchange scheme; and, in response to checking that the selected key exchange scheme is not the hybrid key exchange scheme: rejecting the communication between the responding entity and the initiating entity; or performing the communication by exchanging a key according to the selected key exchange scheme and sending an alert indicating that the key exchange scheme different from the hybrid key exchange scheme is used for the communication.
-
公开(公告)号:US12041455B2
公开(公告)日:2024-07-16
申请号:US17514120
申请日:2021-10-29
Applicant: Nokia Technologies Oy
Inventor: Shubhranshu Singh , Chaitanya Aggarwal , Saurabh Khare , Konstantinos Samdanis , Gerald Kunzmann
IPC: H04W12/12 , H04W12/122 , H04W12/128
CPC classification number: H04W12/122 , H04W12/128
Abstract: According to an example aspect of the present invention, there is provided a method comprising, determining, by an apparatus configured to operate as a network function a cellular communication system, at least two disjoint network paths, wherein the at least two disjoint network paths are different paths, and comprise different physical resources, transmitting, by the apparatus, a subscription request to an analytics function of the cellular communication system, to request notifications about attacks or risks of attacks on at least one network function on at least one of the at least two disjoint network paths, receiving from the analytics function, by the apparatus, information about at least one compromised network entity and/or at least one network entity having a risk of being compromised on said at least one of the at least two disjoint network paths and performing, by the apparatus, attack mitigation based on said information.
-
公开(公告)号:US11777781B2
公开(公告)日:2023-10-03
申请号:US17394549
申请日:2021-08-05
Applicant: NOKIA TECHNOLOGIES OY
Inventor: Saurabh Khare , Colin Kahn
IPC: H04M3/42 , G06F15/173 , H04L41/0246 , H04W8/18 , H04W48/18 , H04W68/00
CPC classification number: H04L41/0246 , H04W8/18 , H04W48/18 , H04W68/005
Abstract: There is provided an apparatus, said apparatus comprising means for receiving, at a first network function from a second network function, a subscription request for notification of at least one event, wherein the subscription request comprises at least one condition to trigger notification of the at least one event, and providing a notification of the at least one event to the second network function accoriding to the at least one condition.
-
公开(公告)号:US20230155832A1
公开(公告)日:2023-05-18
申请号:US18047434
申请日:2022-10-18
Applicant: Nokia Technologies Oy
Inventor: Chaitanya AGGARWAL , Anja Jerichow , Saurabh Khare , Georgios Gkellas
CPC classification number: H04L9/3213 , H04L63/0884
Abstract: According to an example aspect of the present invention, there is provided an apparatus configured to process a request for an access token authorizing access for a network function consumer to a service provided by a network function producer, the request being received in the apparatus from a service communication proxy, wherein the processing comprises one or more of the following verification: verification that a credential data element comprised in the request, cryptographically signed by the network function consumer, identifies the request, the service or a type of the service, and verification with reference to a further node, or to a profile of the network function consumer, that the service communication proxy is authorized to act on behalf of the network function consumer, and transmit, responsive to at least one of the verifications being successful, the requested access token, the access token comprising an indication of the service communication proxy.
-
公开(公告)号:US20230136287A1
公开(公告)日:2023-05-04
申请号:US17514120
申请日:2021-10-29
Applicant: Nokia Technologies Oy
Inventor: Shubhranshu Singh , Chaitanya Aggarwal , Saurabh Khare , Konstantinos Samdanis , Gerald Kunzmann
IPC: H04W12/122 , H04W12/128
Abstract: According to an example aspect of the present invention, there is provided a method comprising, determining, by an apparatus configured to operate as a network function a cellular communication system, at least two disjoint network paths, wherein the at least two disjoint network paths are different paths, and comprise different physical resources, transmitting, by the apparatus, a subscription request to an analytics function of the cellular communication system, to request notifications about attacks or risks of attacks on at least one network function on at least one of the at least two disjoint network paths, receiving from the analytics function, by the apparatus, information about at least one compromised network entity and/or at least one network entity having a risk of being compromised on said at least one of the at least two disjoint network paths and performing, by the apparatus, attack mitigation based on said information.
-
公开(公告)号:US12184738B2
公开(公告)日:2024-12-31
申请号:US17389134
申请日:2021-07-29
Applicant: Nokia Technologies Oy
Inventor: Bruno Landais , Laurent Thiebaut , Saurabh Khare , Georgios Gkellas
IPC: H04L67/148 , H04L45/00
Abstract: There is provided an apparatus comprising means for receiving information about an identification of a network function set associated with at least one packet data network connection. The means is further configured for, in response to receiving an indication that a network function instance of the network function set supporting the at least one packet data network connection is no longer available, transferring the at least one packet data network connection from the network function instance to another network function instance comprised within the network function set.
-
-
-
-
-
-
-
-
-