Local authorization for AI / ML model storage and sharing
By using network repository functions and authorization mechanisms in 5G communication networks, the security problems of AI/ML models in a multi-vendor environment are solved, and effective protection and management of the models are achieved.
Patent Information
- Application Number
- CN202380077418.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-07
- Filing Date
- 2023-11-02
- Publication Date
- 2025-06-27
AI Technical Summary
In 5G communication networks, prior art has difficulty effectively protecting and managing the security of artificial intelligence (AI)/machine learning (ML) models used to generate analysis, especially when sharing or storing these models in a multi-vendor environment.
By registering supplier identifiers and analytical identifiers in the Network Repository Function (NRF) of the communication network, the Consumer Network Function (NFc) can request the ML model from the Producer Network Function (NFp). NFp provides the URL of the ML model to NFc based on the authorization mechanism, ensuring that only authorized NFc can access and use these models.
Improves the confidentiality and security of AI/ML models, prevents unauthorized access and use, and promotes the security of deploying these models in multi-vendor 5G communication networks.
Smart Images

Figure CN120226311A_ABST
Abstract
Description
Technical Field
[0001] This application generally relates to the field of communication networks, and more specifically, to techniques for the security of artificial intelligence (AI) / machine learning (ML) models used to generate analytics in a communication network (e.g., a 5G core network). Background Art
[0002] Currently, the fifth-generation (5G) cellular system is being standardized within the Third Generation Partnership Project (3GPP). 5G is being developed to achieve maximum flexibility to support a variety of use cases, including enhanced mobile broadband (eMBB), machine type communication (MTC), ultra-reliable low-latency communication (URLLC), sidelink device-to-device (D2D), and several other use cases.
[0003] At a high level, the 5G system (5GS) consists of an access network (AN) and a core network (CN). The AN provides a connection from the UE to the CN, for example, via a base station (e.g., the gNB or ng-eNB described below). The CN includes various network functions (NFs) that provide a wide range of different functions (e.g., session management, connection management, charging, authentication, etc.).
[0004] Figure 1 A high-level view of an exemplary 5G network architecture is shown, which includes a Next Generation Radio Access Network (NG-RAN, 199) and a 5G Core Network (5GC, 198). The NG-RAN may include one or more gNodeBs (gNBs, e.g., 100, 150) connected to the 5GC via one or more NG interfaces (e.g., 102, 152). More specifically, a gNB may be connected to one or more Access and Mobility Management Functions (AMFs) in the 5GC via a corresponding NG-C interface, and to one or more User Plane Functions (UPFs) in the 5GC via a corresponding NG-U interface. Various other network functions (NFs) may be included in the 5GC, as described in more detail below.
[0005] In addition, gNBs may be connected to each other via one or more Xn interfaces (e.g., 140 between gNBs 100, 150). The radio technology of the NG-RAN is generally referred to as "New Radio" (NR). Regarding the NR interface to the UE, each gNB may support Frequency Division Duplexing (FDD), Time Division Duplexing (TDD), or a combination thereof. Each gNB may serve a geographical coverage area that includes one or more cells, and in some cases, may also use various directional beams to provide coverage in the corresponding cells.
[0006] Figure 1The NG-RAN logical nodes shown include a Centralized Unit (CU or gNB-CU) and one or more Distributed Units (DU or gNB-DU). The CU (e.g., 110) is a logical node that hosts higher layer protocols and performs various gNB functions (e.g., controls the operation of the DU). In contrast, the DU (e.g., 120, 130) is a decentralized logical node that hosts lower layer protocols and can include various subsets of gNB functions depending on the function split option. The CU is connected to one or more DUs via the corresponding F1 logical interface (e.g., Figure 1 the interfaces 122, 132 shown).
[0007] Another change in the 5G network (e.g., 5GC) is that traditional peer interfaces and protocols in previous generation networks are modified and / or replaced via a Service-Based Architecture (SBA), in which network functions (NFs) provide one or more services to one or more service consumers. For example, this can be achieved via Hypertext Transfer Protocol / Representational State Transfer (HTTP / REST) Application Programming Interfaces (APIs). Generally speaking, various services are self-contained functions that can be changed and modified in an isolated manner without affecting other services.
[0008] In addition, these services include various "service operations", which are more refined divisions of the overall service function. The interaction between service consumers and producers can be of the "request / response" or "subscribe / notify" type. In the 5G SBA, the Network Repository Function (NRF) allows each network function to discover the services provided by other network functions, and the Data Storage Function (DSF) allows each network function to store its context. The 5G SBA model is based on the principles of modularity, reusability, and self-containment of NFs, which can enable network deployment to leverage the latest virtualization and software technologies.
[0009] A 5GC NF of particular interest in this disclosure is the Network Data Analytics Function (NWDAF). This NF provides network analysis information (e.g., statistical information and / or prediction information of past events) to other NFs at the network slice instance level. The NWDAF can collect data from any 5GC NF. Note that a "network slice" is a logical partition of the 5G network that provides specific network capabilities and characteristics, e.g., supports a specific service. A network slice instance is a collection of NF instances and the required network resources (e.g., computing, storage, communication) that provide the capabilities and characteristics of the network slice.
[0010] Machine learning (ML) is a type of artificial intelligence (AI) that focuses on using data and algorithms to mimic the way humans learn, gradually improving accuracy as more data becomes available. ML algorithms build models based on sample (or "training") data, which are then used to make predictions or decisions. ML algorithms can be used in a variety of applications (such as medicine, email filtering, speech recognition, etc.) where it is difficult or infeasible to develop conventional algorithms to perform the required tasks. Subsets of ML are closely related to computational statistics.
[0011] The 5G system architecture allows any NF to obtain analytics from the NWDAF using the Data Collection Coordination Function (DCCF) and the associated Ndccf service. The NWDAF can also store and retrieve analytics information from the Analytics Data Repository Function (ADRF). 3GPP TS 23.288 (v17.2.0) specifies that the NWDAF is the primary NF for computing analytics reports and classifies the NWDAF into two sub-functions (or logical functions): the Analytics Logic Function (AnLF), which performs the analytics process; and the Model Training Logic Function (MTLF), which performs the training and re-training of the ML models used by the AnLF. Summary of the Invention
[0012] AI / ML models (or more simply, ML models) are regarded as important intellectual property of their owners (e.g., 5GC vendors), and thus their confidentiality and integrity must always be protected. 3GPP is studying the feasibility of sharing or storing ML models in network devices that may be provided by different vendors. Under this arrangement, access to and use of the ML model by a consumer NF provided by a vendor different from the ML model's vendor should be protected. However, there is currently no specified solution for this requirement.
[0013] The purpose of the embodiments of the present disclosure is to solve these and other problems, challenges, and / or difficulties related to the security of ML models, thereby facilitating other beneficial deployments of ML models for network analytics.
[0014] Some embodiments of the present disclosure include methods (e.g., processes) for a consumer NF (NFc) of a communication network (e.g., 5GC).
[0015] These exemplary methods include: registering the following information with a Network Repository Function (NRF) of a communication network: a vendor identifier (ID) associated with an NFc; and one or more analysis IDs associated with an ML model supported by the NFc, including a first analysis ID associated with a first ML model generated, owned, and / or maintained by a Producer NF (NFp) of the communication network. These exemplary methods further include: sending a request for the first ML model to the NFp. The request includes the first analysis ID and the vendor ID associated with the NFc. These exemplary methods further include: receiving a response from the NFp, the response including a URL associated with a second NF of the communication network, from which the ML model can be obtained.
[0016] In some embodiments, these exemplary methods further include: obtaining the ML model from the second NF using the URL. In some embodiments, the second NF associated with the URL is one of the following: the NFp, or an Analysis Data Repository Function (ADRF) of the communication network.
[0017] Other embodiments include exemplary methods (e.g., procedures) for an NFp of a communication network (e.g., 5GC).
[0018] These exemplary methods may include: receiving, from an NFc of a communication network, a request for an ML model generated, owned, and / or maintained by the NFp. The request includes a first analysis ID associated with the ML model and a vendor ID associated with the NFc. These exemplary methods further include: obtaining a profile associated with the NFc from the NRF of the communication network. These exemplary methods further include: authorizing access to the ML model by the NFc based on a match, correspondence, or relationship between the vendor ID included in the obtained NF profile and the vendor ID included in the request. These exemplary methods further include: based on authorizing the NFc, sending a response to the NFc, the response including a URL associated with a second NF of the communication network, from which the ML model can be obtained.
[0019] In some embodiments, the second NF associated with the URL is the NFp, and these exemplary methods further include: providing the ML model to the NFc using the URL associated with the NFp. In some of these embodiments, providing the ML model to the NFc is based on a match, correspondence, or relationship between an identifier associated with the NFc and a list of allowed NF instances associated with the ML model.
[0020] In other embodiments, the second NF associated with the URL is the ADRF of the communication network.
[0021] Other embodiments include methods (e.g., procedures) for an NRF of a communication network (e.g., 5GC).
[0022] These exemplary methods may include: registering the following information in a configuration file of an NFc in a communication network: a vendor ID associated with the NFc; and one or more analysis IDs associated with an ML model supported by the NFc, including a first analysis ID associated with a first ML model generated, owned, and / or maintained by an NFp of the communication network. These exemplary methods further include: receiving a request for the configuration file of the NFc from the NFp, and in response to the request, sending the configuration file of the NFc to the NFp.
[0023] In some embodiments, these exemplary methods further include: performing a discovery process with the NFc to identify the NFp based on the first analysis ID.
[0024] Other embodiments include methods (e.g., processes) for an ADRF of a communication network (e.g., 5GC).
[0025] These exemplary methods include: receiving a first request to store an ML model from an NFp of a communication network. The first request includes an association ID associated with the ML model, and a URL associated with the NFp from which the ML model can be obtained. These exemplary methods further include: obtaining the ML model from the NFp using the URL associated with the NFp, and storing the obtained ML model in association with the association ID. These exemplary methods further include: sending a first response to the NFp, the first response including a URL associated with the ADRF from which the ML model can be obtained.
[0026] In some embodiments, these exemplary methods further include: receiving an update request from the NFp, the update request including an association ID and a list of permitted NF instances; and storing the list of permitted NF instances in association with the ML model based on a match between the association ID included in the update request and the association ID stored in association with the ML model. Specifically, the list of permitted NF instances includes one or more identifiers associated with corresponding NFs of the communication network that are permitted to access the ML model.
[0027] In some of these embodiments, these exemplary methods further include: providing the ML model to an NFc of the communication network using the URL associated with the ADRF. In some of these embodiments, providing the ML model to the NFc is based on a match, correspondence, or relationship between an identifier associated with the NFc and an identifier included in the list of permitted NF instances stored in association with the ML model.
[0028] In the various embodiments summarized above, the NFc may be a NWDAF (AnLF), and / or the NFp may be a NWDAF (MTLF).
[0029] Other embodiments include NFc, NFp, NRF, and ADRF (or network devices configured to implement these NFs) configured to perform operations corresponding to any of the exemplary methods described herein. Other embodiments also include a non-transitory computer-readable medium storing computer-executable instructions that, when executed by a processing circuit, configure such an NF to perform operations corresponding to any of the exemplary methods described herein.
[0030] These and other disclosed embodiments may provide various benefits and / or advantages. By providing the ability to protect ML models during various transmission, storage, and acquisition scenarios for ML model owners / producers, the embodiments improve the security of confidential and / or sensitive ML models, thus facilitating the deployment of such models in multi-vendor communication networks (e.g., 5GC).
[0031] These and other objects, features, and advantages of the present disclosure will become apparent when reading the following detailed description in conjunction with the accompanying drawings described briefly below. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figures 1 to 2 Aspects of an exemplary 5G network architecture are shown.
[0033] Figure 3 A signaling diagram of a network process for authorizing and authenticating the transmission of an AI / ML model is shown.
[0034] Figure 4 A signaling diagram of a process involving NWDAF (AnLF), NRF, NWDAF (MTLF), and ADRF according to some embodiments of the present disclosure is shown.
[0035] Figure 5 An exemplary method (e.g., process) for a consumer NF of a communication network according to various embodiments of the present disclosure is shown.
[0036] Figure 6 An exemplary method (e.g., process) for a producer NF of a communication network according to various embodiments of the present disclosure is shown.
[0037] Figure 7 An exemplary method (e.g., process) for an NRF of a communication network according to various embodiments of the present disclosure is shown.
[0038] Figure 8 An exemplary method (e.g., process) for an ADRF of a communication network according to various embodiments of the present disclosure is shown.
[0039] Figure 9 A communication system according to various embodiments of the present disclosure is shown.
[0040] Figure 10 Shows a UE according to various embodiments of the present disclosure.
[0041] Figure 11 Shows a network node according to various embodiments of the present disclosure.
[0042] Figure 12 Shows a host computing system according to various embodiments of the present disclosure.
[0043] Figure 13 Is a block diagram of a virtualization environment in which functions implemented by some embodiments of the present disclosure can be virtualized.
[0044] Figure 14 Shows communication between a host computing system, a network node, and a UE via multiple connections according to various embodiments of the present disclosure. Detailed Description
[0045] The embodiments briefly outlined above will now be described more fully with reference to the accompanying drawings. These descriptions are provided by way of example to illustrate the subject matter to those skilled in the art and should not be construed as limiting the scope of the subject matter to the embodiments described herein. More specifically, examples of operations showing various embodiments according to the above advantages are provided below.
[0046] In general, unless explicitly given and / or implied from the context a different meaning, all terms used herein will be interpreted according to their ordinary meaning in the relevant technical field. All references to "an / a / element, device, component, apparatus, step, etc." shall be construed openly as referring to at least one instance of the element, device, component, apparatus, step, etc., unless otherwise explicitly stated. The operations of any method and / or process disclosed herein need not be performed in the exact order disclosed, unless it is explicitly described that one operation is after or before another operation and / or implicitly one operation must be after or before another operation. Where appropriate, any feature of any embodiment disclosed herein can be applied to any other disclosed embodiment. Similarly, where appropriate, any advantage of any embodiment described herein can be applied to any other disclosed embodiment.
[0047] Furthermore, the following terms are used throughout the description given below:
[0048] • Radio Access Node: As used herein, a "radio access node" (or equivalently, a "radio network node", "radio access network node", or "RAN node") can be any node in a radio access network (RAN) that operates to wirelessly transmit and / or receive signals. Some examples of radio access nodes include, but are not limited to, base stations (e.g., gNB in a 3GPP 5G / NR network or enhanced Node B or eNB in a 3GPP LTE network), base station distributed components (e.g., CU and DU), high-power or macro base stations, low-power base stations (e.g., micro, pico, femto, or home base stations, etc.), integrated access backhaul (IAB) nodes, transmission points (TP), transmission and reception points (TRP), remote radio units (RRU or RRH), and relay nodes.
[0049] • Core Network Node: As used herein, a "core network node" is any type of node in the core network. Some examples of core network nodes include, for example, a mobility management entity (MME), a serving gateway (SGW), a PDN gateway (P-GW), a policy and charging rules function (PCRF), an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), a charging function (CHF), a policy control function (PCF), an authentication server function (AUSF), a location management function (LMF), etc.
[0050] • Wireless Device: As used herein, a "wireless device" (or simply "WD") is any type of device that is capable of, configured to, arranged to, and / or operable to communicate wirelessly with network nodes and / or other wireless devices. Wireless communication can include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for transmitting information through the air. Unless otherwise specified, the term "wireless device" is used interchangeably herein with the term "user equipment" (abbreviated "UE"), and these two terms have different meanings from the term "network node".
[0051] • Radio Node: As used herein, a "radio node" can be a "radio access node" (or equivalent term) or a "wireless device".
[0052] • Network Node: As used herein, a "network node" is any node that is part of a radio access network (e.g., a radio access node or equivalent term) or a core network (e.g., the core network nodes discussed above) of a cellular communication network. Functionally, a network node is a device that is capable of, configured to, arranged to, and / or operable to communicate directly or indirectly with wireless devices and / or with other network nodes or devices in a cellular communication network to enable and / or provide radio access to wireless devices and / or to perform other functions (e.g., management) in a cellular communication network.
[0053] • Node: As used herein, the term "node" (without a prefix) can be any type of node that can be in a wireless network (including RAN and / or core network) or can be associated with a wireless network, including a radio access node (or equivalent terms), a core network node, or a wireless device. However, the term "node" can be limited to a specific type (e.g., a radio access node) based on its specific characteristics in any given context.
[0054] The above definitions are not meant to be exclusive. In other words, the various terms among the above terms can be interpreted and / or described using the same or similar terms elsewhere in the present disclosure. However, if other interpretations and / or descriptions conflict with the above definitions, the above definitions shall prevail.
[0055] Note that the description given herein focuses on 3GPP cellular communication systems and thus often uses 3GPP terms or terms similar to 3GPP terms. However, the concepts disclosed herein are not limited to 3GPP systems and can be applied to any system that can benefit from the concepts, principles, and / or embodiments described herein.
[0056] Figure 2 An exemplary non-roaming reference architecture of a 5GC (200) having service-based interfaces and various 3GPP-defined NFs within the control plane (CP) is shown. These NFs include the following:
[0057] • Application Function (AF, having an Naf interface), which interacts with the 5GC to provide information to the network operator and subscribe to specific events occurring in the operator's network. The AF provides an application that delivers services in a layer different from the layer in which the service has been requested (i.e., the signaling layer), namely the transport layer, and the control of flow resources is based on what has been negotiated with the network. The AF (via the N5 interface) conveys dynamic session information to the PCF, including a description of the media to be transported by the transport layer.
[0058] • Policy Control Function (PCF, having an Npcf interface), which provides PCC rules (e.g., regarding the handling of each service data flow under PCC control) to the SMF via the N7 reference point, supporting a unified policy framework to manage network behavior. The PCF provides policy control decisions and flow-based charging control to the SMF, including service data flow detection, gating, QoS, and flow-based charging (except for credit management). The PCF receives session and media-related information from the AF and notifies the AF of service (or user) plane events.
[0059] • User Plane Function (UPF) - Supports processing of user plane traffic based on rules received from the SMF, including packet inspection and different enforcement actions (e.g., event detection and reporting). The UPF communicates with the RAN (e.g., NG-RAN) via the N3 reference point, with the SMF (discussed below) via the N4 reference point, and with an external Packet Data Network (PDN) via the N6 reference point. The N9 reference point is used for communication between two UPFs.
[0060] • Session Management Function (SMF, with Nsmf interface), interacts with the decoupled bearer (or user) plane, including creating, updating, and deleting Protocol Data Unit (PDU) sessions and managing session context with the User Plane Function (UPF), e.g., for event reporting. For example, the SMF performs data flow detection (based on filter definitions included in PCC rules), online and offline charging interactions, and policy enforcement.
[0061] • Charging Function (CHF, with Nchf interface), responsible for convergent online charging and offline charging functions. The Charging Function provides quota management (for online charging), re-authorization triggers, rating conditions, etc., and is notified about usage reports from the SMF. Quota management involves specifying a certain quantity of units (e.g., bytes, seconds) for service allowance. The CHF also interacts with the billing system.
[0062] • Access and Mobility Management Function (AMF, with Namf interface), terminates the RAN CP interface and handles all mobility and connection management of the UE (similar to the MME in EPC). The AMF communicates with the UE via the N1 reference point and with the RAN (e.g., NG-RAN) via the N2 reference point.
[0063] • Network Exposure Function (NEF, with Nnef interface) - Serves as an entry point to the operator network by securely exposing network functions and events provided by 3GPP NFs to the AF and by providing a way for the AF to securely provide information to the 3GPP network. For example, the NEF provides services that allow the AF to pre-configure specific subscription data (e.g., expected UE behavior) for various UEs.
[0064] • Network Repository Function (NRF, 220, with Nnrf interface) - Provides service registration and discovery, enabling NFs to identify suitable services available from other NFs.
[0065] • Network Slice Selection Function (NSSF) with Nnssf interface - "Network slice" is a logical partition of the 5G network that provides specific network capabilities and characteristics, e.g., supporting specific services. A network slice instance is a collection of NF instances and the required network resources (e.g., computing, storage, communication) that provide the capabilities and characteristics of the network slice. NSSF enables other NFs (e.g., AMF) to identify the network slice instance suitable for the service desired by the UE.
[0066] • Authentication Server Function (AUSF) with Nausf interface - Based on the user's Home Public Land Mobile Network (HPLMN), it performs user authentication and calculates security key material for various purposes.
[0067] • Network Data Analytics Function (NWDAF, 210) with Nnwdaf interface, which is described in more detail above and below.
[0068] • Location Management Function (LMF) with Nlmf interface - Supports various functions related to the determination of the UE's location, including the determination of the UE's location and obtaining any of the following: DL location measurements or location estimates from the UE; UL location measurements from the NGRAN; and non-UE associated auxiliary data from the NG RAN.
[0069] The Unified Data Management (UDM) function supports the generation of 3GPP authentication credentials, user identity handling, access authorization based on subscription data, and other subscriber-related functions. To provide this function, UDM uses the subscription data (including authentication data) stored in the 5GC Unified Data Repository (UDR). UDR supports storing and obtaining policy data by the PCF and storing and obtaining application data by the NEF.
[0070] NRF allows each NF to discover the services provided by other NFs, and the Data Storage Function (DSF) allows each NF to store its context. In addition, NEF provides exposure of the capabilities and events of the 5GC to AFs both inside and outside the 5GC. For example, NEF provides a service that allows AFs to pre-configure specific subscription data (e.g., expected UE behavior) for various UEs.
[0071] The communication links between the UE and the 5G network (AN and CN) can be grouped into two different layers. The UE communicates with the CN through the Non-Access Stratum (NAS) and with the AN through the Access Stratum (AS). All NAS communications occur between the UE and the AMF via the NAS protocol ( Figure 2 the N1 interface in it). The security of the communications on these layers is provided by the NAS protocol (for NAS) and the PDCP protocol (for AS).
[0072] Release 17 of 3GPP enhances the SBA by adding a data management framework, which includes a Data Collection Coordination Function (DCCF) and a Messaging Framework Adapter Function (MFAF) as defined in detail in 3GPP TR 23.700-91 (v17.0.0). As described above, the data management framework is backward compatible with the Release 16 NWDAF function. For Release 17, the baseline of the services provided by the DCCF (e.g., to the NWDAF) is the Release 16 NF services for obtaining data. For example, the baseline of the DCCF service used by a NWDAF consumer to obtain UE mobility data is Namf_EventExposure.
[0073] 3GPP TS 23.288 (v17.2.0) specifies that the NWDAF is the main network function for calculating analytical reports. The 5G system architecture allows any NF to use the DCCF function and the associated Ndccf service to obtain analytics from the NWDAF. The NWDAF can also store and retrieve analytical information from the Analytical Data Repository Function (ADRF).
[0074] 3GPP TS 23.288 also classifies the NWDAF into two sub-functions (or logical functions): the NWDAF Analytical Logic Function (NWDAF AnLF), which performs the analytical process; and the NWDAF Model Training Logic Function (NWDAF MTLF), which performs the training and retraining of the ML models used by the NWDAF AnLF. Hereinafter, the terms "AnLF", "NWDAF AnLF", and "NWDAF (AnLF)" will be used interchangeably. Similarly, the terms "MTLF", "NWDAF MTLF", and "NWDAF (MTLF)" will be used interchangeably.
[0075] 3GPP TS 23.288 (v17.2.0) specifies the subscription / notification process for consumer NFs to obtain the ML models associated with one or more analytics IDs whenever a new ML model has been trained by the NWDAF MTLF and becomes available. This is referred to as ML model pre-configuration and is implemented by the Nnwdaf_MLModelProvision service.
[0076] 3GPP TR 33.738 (v0.2.0) describes the study of the security aspects of the enablers for network automation in 5G. One of the objectives of this study is the security of AI / ML model sharing and storage, which is identified as "Key Issue #3". The following text from 3GPP TR 33.378 describes the various aspects of this issue. In this document, from the perspective of the AI / ML of interest, "NFc" is the consumer NF and "NFp" is the producer NF.
[0077] ***Start of 3GPP text***
[0078] 5.3.1 Problem details
[0079] Share AI / ML models between NWDAF and / or NFs (i.e., NWDAF to NWDAF, ADRF to NWDAF...). In different scenarios, the NF producer of the AI / ML model can store the model in ADRF, NWDAF, or other entities.
[0080] ADRF (Analytics Data Repository Function) is being enhanced to store AI / ML models to facilitate the distribution and sharing of these models among NFs. Since AI / ML models and their algorithms are usually proprietary (i.e., protected by the intellectual property rights of the designers), it must be ensured that only NFs that have been duly authorized to access the AI / ML models can read and use these models. In addition, ADRF itself cannot be regarded as a fully trusted entity for storing sensitive AI / ML data models. These models are indeed exposed at rest in ADRF.
[0081] The current authorization scheme defined by 3GPP for SBA only applies to the service level or resource / operation level scope. This authorization granularity may not be sufficient in the AI / ML model sharing scenario because ADRF (Analytics Data Repository Function) or NWDAF, or any other network function that can store AI / ML models, cannot verify whether the NF consumer is authorized to obtain the AI / ML model.
[0082] 5.3.2 Security threats
[0083] An unauthorized NFc (which in principle has no right to obtain a specific model stored by NFp) may access the storage entity and obtain the model.
[0084] If there is no protection against accessing and reading the AI / ML models stored by NFp in ADRF, a compromised ADRF may expose the algorithms and sensitive data to unauthorized entities, which may easily abuse it and / or further distribute it to other entities, causing a greater data security vulnerability.
[0085] 5.3.3 Potential security requirements
[0086] AI / ML models should be protected between the entity that produces or stores the ML model in ADRF (e.g., NWDAF containing MTLF, NFp) and the entity that consumes the model (NFc).
[0087] The ADRF (Analytical Data Repository Function) or any other network function that can store AI / ML models should be able to authorize the NFc to obtain the AI / ML model.
[0088] The NF service consumer should be authorized to access the AI / ML models in the ADRF (or any other NF that can store ML models, such as NWDAF MTLF).
[0089] ***End of 3GPP text***
[0090] 3GPP TR 33.738 also describes a solution for authorizing and authenticating the transfer of AI / ML models, which is identified as "Solution #2". This security solution protects the AI / ML model between the first entity (e.g., NF) that produces the AI / ML model (or stores the AI / ML model in the ADRF) and the second entity (NFc) that consumes the model. In this solution, the ADRF uses an authorization token to verify that the NFc is allowed to access the ML model.
[0091] Figure 3 A signaling diagram showing this solution for authorizing and authenticating the transfer of AI / ML models is shown. As Figure 3 shown, the signaling is between NWDAF (AnLF) / NFc, the authorization server (e.g., NRF), NWDAF (MTLF), and the ADRF. Although Figure 3 the operations shown are given numerical labels, this is for ease of explanation and does not require or imply any particular order of operations, unless otherwise specified below.
[0092] In operation 1, the MTLF trains the ML model and sends the ML model to the ADRF by invoking the Nadrf_DataManagement_StorageRequest (ML model) service operation. In addition to the model metadata, this message may also include the ML model ID, analysis ID, vendor ID, MAC or SHA256 signature of the application binary, the environment required for ML model execution, the URL / link for obtaining the configuration, and the secret / signature key / certificate for generating authentication credentials. The MTLF may send the ML model encrypted with a symmetric key (e.g., AES key) before storage.
[0093] In operation 2, the ADRF stores the ML model and the response as specified in 3GPP TS 23.288 (v17.6.0), except that the storage is performed by the ADRF. In operation 3, the NFc (e.g., NWDAF AnLF) contacts the NRF and requests an access token using the existing procedure specified in 3GPP TS 33.501 (v17.7.0). In operation 4, the NRF uses the existing procedure specified in 3GPP TS 23.288 to send the access token and the MTLF ID.
[0094] In operation 5, the NWDAF (AnLF) uses the Nnwdaf_MLModelProvision service operation together with the access token to request the ML model ID from the NWDAF (MTLF), which obtains the ML model ID based on the ML analysis ID and / or the ADRF ID. The NWDAF (MTLF) also verifies the received access token. In operation 6, the NWDAF (MTLF) sends an Nnwdaf_MLModelProvision response, which includes an encryption key for encrypting the AI / ML model in operation 1. Additionally, the NWDAF (MTLF) may include a one-time credential for accessing the model from the ADRF, including any of the following items:
[0095] • A random number, which is shared as part of the metadata in operation 1;
[0096] • The MAC or hash value of a binary or random number shared as part of the data in operation 1;
[0097] • A signature key that is the private key of the MTLF, where the public part is shared in operation 1;
[0098] • A credential generated by the signature key of the MTLF, such as a JWT token or a certificate.
[0099] The one-time credential can be used to limit the number of accesses from the NFc. Even so, the "one-time" credential can be used as a regular authorization token for multiple accesses to the ML model, i.e., not just once (as the name suggests).
[0100] In operation 7, the NWDAF (AnLF) uses the ADRF service procedure to request the ML model, including the one-time credential received in operation 6. In operation 8, the ADRF verifies the one-time credential and, if the verification is successful, provides the stored AI / ML model to the NWDAF (AnLF).
[0101] As described above, AI / ML models are regarded as important intellectual property of their owners (e.g., 5GC vendors), and thus their confidentiality and integrity must always be protected. 3GPP is studying the feasibility of sharing or storing AI / ML models in network devices that may be provided by different vendors. Under this arrangement, the AI / ML models should be protected from access and use by consumer NFs provided by vendors different from the AI / ML models. However, there is currently no specified solution for this requirement. For example, Figure 3 the solution shown cannot provide the required security in a multi-vendor network environment.
[0102] Embodiments of the present disclosure solve these and other problems, challenges, and / or difficulties by providing secure AI / ML model sharing between NFp (e.g., NWDAF MTLF) and NFc (e.g., NWDAF AnLF) and AI / ML model storage in ADRF. For example, NFp (e.g., NWDAF MTLF) can authorize NFc to access the AI / ML models locally stored by NFp, and ADRF can authorize NFc to access the AI / ML models of NFp stored by NFp based on NFp instructions.
[0103] In various embodiments, NFp (e.g., NWDAF MTLF) can authorize the transmission of AI / ML models owned or controlled by it to ADRF, storage in the ADRF, and retrieval from the ADRF. In addition, in various embodiments, NFp can authorize the transmission of AI / ML models owned or controlled by it to NFc (e.g., NWDAF AnLF) that requests the AI / ML models. In addition, in various embodiments, NFp can encrypt and / or protect the integrity of the AI / ML models during any of these transmission scenarios to ensure security. Various techniques are described according to these embodiments.
[0104] Embodiments of the present disclosure can provide various benefits and / or advantages. By providing the ability for the owners / producers of AI / ML models to protect the AI / ML models during various transmission, storage, and retrieval scenarios, the embodiments can improve the security of confidential and / or sensitive AI / ML models, thus facilitating the deployment of such models in multi-vendor communication networks (e.g., 5GC).
[0105] In the following description of various embodiments, the terms NFp and NWDAF (MTLF) may be used interchangeably, and the terms NFc and NWDAF (AnLF) may be used interchangeably. Similarly, the terms "model", "ML model", and "AI / ML model" may be used interchangeably.
[0106] Figure 4A signaling diagram showing processes involving NWDAF (AnLF) 410, NRF 420, NWDAF (MTLF) 430, and ADRF 440 according to some embodiments of the present disclosure. Although Figure 4 the operations shown are given numerical labels, this is for ease of illustration only and does not require or imply any particular order of operations, unless otherwise specified below.
[0107] In operation 0a, NWDAF (AnLF) registers its associated vendor ID and the analysis IDs it supports in its NF profile in the NRF. In operation 0b, NWDAF (MTLF) trains an ML model and may encrypt and / or integrity protect it. The security algorithms and keys used for this operation can be vendor - specific and / or outside the scope of 3GPP specifications.
[0108] In operation 1, NWDAF (MTLF) determines that the ML model can / should be stored in the ADRF and discovers a specific ADRF instance to perform the model storage. NWDAF (MTLF) stores the identifier associated with the selected instance (referred to as the ADRF ID) for subsequent use (as described below). In some variants, NWDAF (MFLT) may also store the vendor ID and / or NFset associated with the selected instance for subsequent use.
[0109] In operation 2, NWDAF (MTLF) calls the Nadrf_DataManagement_StorageRequest service operation on the selected ADRF and includes the URL associated with the MTLF from which the ML model can be obtained. In some variants, the URL (MTLF) can be a one - time - use URL. NWDAF (MTLF) may also include an association ID associated with the ML model, which can also be referred to as the model ID.
[0110] In operation 3, the ADRF securely obtains the protected ML model from the NWDAF (MTLF) using the URL (MTLF) received in operation 2. During this process, the NWDAF (MTLF) verifies that the obtained ADRF instance is the ADRF instance selected in operation 1 based on a match or correspondence with the stored ADRF ID. In some variants, when there is no match or correspondence with the ADRF ID, but the NWDAF (MTLF) stores the NFset, NF type, or vendor ID associated with the selected ADRF instance, the NWDAF (MTLF) can verify that the obtained ADRF instance is within the same NFset, NF type, or vendor ID as the selected ADRF instance. Additionally, during the obtaining process, the NWDAF (MTLF) also verifies that the associated ID provided by the obtaining ADRF is associated with the ML model.
[0111] In operation 4, after storing the obtained ML model, the ADRF responds to the NWDAF (MTLF) by sending the URL associated with the ADRF, from which the NWDAF (MTLF) or other NF can obtain the ML model.
[0112] In operation 5, the NWDAF (AnLF) discovers the NWDAF (MTLF) via the NRF using the existing procedures specified in 3GPP TS 23.288. In operation 6, the NWDAF (AnLF) invokes the Nnwdaf_MLModelProvision_Subscribe (or Nnwdaf_MLModelInfo_Request) service operation to the NWDAF (MTLF) to obtain the ML model. The NWDAF (AnLF) includes its vendor ID and one of the analysis IDs it supports, both of which were previously registered in operation 0a.
[0113] In operation 7a, the NWDAF (MTLF) obtains the NF profile of the requesting NWDAF (AnLF) from the NRF. In operation 7b, the NWDAF (MTLF) obtains the vendor ID from the NF profile and verifies that it matches the vendor ID received in operation 6. In some embodiments, the NWDAF (MTLF) may maintain an interoperability indicator (or ID) that indicates which NWDAF vendors (e.g., a list) are allowed to obtain ML models from the NWDAF (MTLF). In this case, the NWDAF (MTLF) can also verify that the vendor ID received in operation 6 is among the vendors associated with the interoperability ID of the requested ML model. Alternatively, the NWDAF (MTLF) can verify the vendor ID received from the NWDAF (AnLF) based on an authentication process, such as using certificates, tokens, etc.
[0114] If the verification is successful, NWDAF (MTLF) authorizes NWDAF (AnLF) to access the ML model for the requested analysis ID. Additionally, NWDAF (MTLF) may store the identifier of NWDAF (AnLF) (referred to as NFc ID) in the list of allowed NF instances of the ML model. In some variants, NWDAF (MTLF) may store the NF type (e.g., AnLF), NFset, and / or vendor ID associated with the authorized NWDAF (AnLF) in the list of allowed NF instances.
[0115] If the ML model is stored in ADRF, in operation 8, NWDAF (MTLF) calls the Nadrf_ModelUpdate_Request service operation on ADRF and includes the association ID and the list of allowed NF instances (updated in operation 7b). After storing the list of allowed NF instances of the ML model associated with the association ID, ADRF responds to NWDAF (MTLF) indicating the completion of the request. In some variants, NWDAF (MTLF) may send the NF type (e.g., AnLF), NFset, and / or vendor ID associated with the authorized NWDAF (AnLF) in the list of allowed NF instances.
[0116] In operation 9, NWDAF (MTLF) responds to NWDAF (AnLF) with the Nnwdaf_MLModelProvision_Notify (or Nnwdaf_MLModelInfo_Request Response) service operation. If NWDAF (MTLF) stores the ML model locally, it includes the URL (MTLF) from which the ML model can be obtained (e.g., in a similar manner to ADRF in operation 3). If the ML model is stored in ADRF, NWDAF (MTLF) includes the URL (ADRF) it received in operation 4.
[0117] In operation 10, NWDAF (AnLF) uses the URL (MTLF) or URL (ADRF) received in operation 9 to obtain the ML model from NWDAF (MTLF) or ADRF, respectively. If the obtainment is from NWDAF (MTLF), the NF verifies that the obtained NWDAF (AnLF) is the same instance whose NFc ID was added to the list of permitted NF instances in operation 7b. If the obtainment is from ADRF, the NF verifies that the obtained NWDAF (AnLF) is part of the list of permitted NF instances received in operation 8. If the verification of NWDAF (MTLF) or ADRF is successful, the obtainment is authorized and proceeds. In some variants, when there is no match or correspondence with the NFc ID, but the receiving NF stores an NFset, NF type, or vendor ID associated with the authorized NWDAF (AnLF), the receiving NF may verify that the obtained NWDAF (AnLF) instance is in the same NFset, NF type, or vendor ID as the authorized NWDAF (AnLF).
[0118] In operation 11, NWDAF (AnLF) performs various security operations on the obtained ML model, such as decryption and integrity checks. These security operations may be based on the corresponding security operations performed by NWDAF (MTLF) in operation 0b. The security algorithms and keys used for this operation may be vendor - specific and / or outside the scope of 3GPP specifications.
[0119] Although the embodiments have been described above in the specific context of NWDAF and its logical functions MTLF and AnLF, those skilled in the art will understand that the basic principles of the above - described embodiments are equally applicable to other NFs, logical functions, nodes, etc. (e.g., having different names) that perform similar operations with these corresponding entities.
[0120] Reference may be made to Figures 5 to 8 for further illustration of these embodiments Figures 5 to 8 which depict exemplary methods (e.g., procedures) for a consumer NF, a producer NF, an NRF, and an ADRF, respectively. In other words, the various features of the operations described below correspond to the various embodiments described above. Figures 5 to 8 The exemplary methods shown may be used in concert (e.g., with each other and with other processes described herein) to provide the benefits, advantages, and / or solutions to problems described herein. Although these exemplary methods are shown by specific boxes in a particular order, the operations corresponding to the boxes may be performed in an order different from the shown order and may be combined and / or divided into boxes and / or operations having functions different from the shown functions. Optional boxes and / or operations are indicated by dashed lines. Figures 5 to 8
[0121] More specifically, Figure 5 An exemplary method (e.g., process) for a consumer NF (NFc) for a communication network (e.g., 5GC) according to various embodiments of the present disclosure is shown. Figure 5 The exemplary method shown may be performed by an NFc such as NWDAF (AnLF) or by a network device configured to implement NWDAF (AnLF) as described elsewhere herein.
[0122] The exemplary method includes an operation of block 510, wherein the NFc registers the following information with the NRF of the communication network: a vendor identifier (ID) associated with the NFc; and one or more analysis IDs associated with an ML model supported by the NFc, including a first analysis ID associated with a first ML model generated, owned, and / or maintained by an NFp of the communication network. The exemplary method includes an operation of block 530, wherein the NFc sends a request for the first ML model to the NFp. The request includes the first analysis ID and the vendor ID associated with the NFc. The exemplary method includes an operation of block 540, wherein the NFc receives a response from the NFp, the response including a URL associated with a second NF of the communication network, from which the ML model can be obtained.
[0123] In some embodiments, the NFc is NWDAF (AnLF) and / or the NFp is NWDAF (MTLF).
[0124] In some embodiments, the exemplary method further includes an operation of block 550, wherein the NFc obtains the ML model from the second NF using the URL. In some embodiments, the second NF associated with the URL is one of the following: the NFp, or an ADRF of the communication network.
[0125] In some embodiments, the exemplary method further includes an operation of block 560, wherein the NFc performs a second security operation on the ML model. The second security operation corresponds to a first security operation performed by the NFp on the ML model. In some of these embodiments, the first security operation includes encryption and / or integrity protection, and the second security operation includes decryption corresponding to the encryption and / or integrity check corresponding to the integrity protection.
[0126] In some embodiments, the response from the NFp is based on a match, correspondence, or relationship between the vendor ID registered with the NRF and the vendor ID included in the request. In some of these embodiments, the exemplary method further includes an operation of block 520, wherein the NFc performs a discovery process with the NRF to identify the NFp based on the first analysis ID. In this case, in response to the discovery process, the request is sent (e.g., in step 530).
[0127] In addition, Figure 6 exemplary methods (e.g., procedures) for an NFp for a communication network (e.g., 5GC) according to various embodiments of the present disclosure are shown. Figure 6 The exemplary methods shown may be performed by an NFp such as NWDAF (MTLF) or by a network device configured to implement NWDAF (MTLF) as described elsewhere herein.
[0128] The exemplary method includes an operation of block 650, wherein the NFp receives a request for an ML model generated, owned, and / or maintained by the NFp from an NFc of the communication network. The request includes a first analysis ID associated with the ML model and a vendor ID associated with the NFc. The exemplary method includes an operation of block 660, wherein the NFp obtains a profile associated with the NFc from the NRF of the communication network. The exemplary method includes an operation of block 670, wherein the NFp authorizes the NFc to access the ML model based on a match, correspondence, or relationship between the vendor ID included in the obtained NF profile and the vendor ID included in the request. The exemplary method includes an operation of block 680, wherein, based on authorizing the NFc, the NFp sends a response to the NFc, the response including a URL associated with a second NF of the communication network, from which the ML model can be obtained.
[0129] In some embodiments, the NFc is NWDAF (AnLF) and / or the NFp is NWDAF (MTLF).
[0130] In some embodiments, authorizing the NFC to access the ML model in block 670 is further based on a match, correspondence, or relationship between the vendor ID included in the request and an interoperability ID associated with the NFp and the ML model.
[0131] In some embodiments, the exemplary method further includes an operation of block 685, wherein, based on authorizing the NFc (e.g., in block 680), the NFp updates a list of permitted NF instances associated with the ML model to include an identifier (NFc ID) associated with the NFc. In some of these embodiments, the exemplary method further includes an operation of block 690, wherein the NFp sends an update request to the ADRF of the communication network, the update request including the updated list of permitted NF instances associated with the ML model and an association ID.
[0132] In some embodiments, the second NF associated with the URL is NFp, and the exemplary method further includes the operation of block 695, wherein NFp subsequently provides the ML model to NFc using the URL associated with NFp. For example, NFp can use the URL associated with NFp to facilitate NFc's acquisition of the ML model. In some of these embodiments, providing the ML model to NFc in block 695 is based on a match, correspondence, or relationship between an identifier associated with NFc and a list of permitted NF instances associated with the ML model (e.g., updated according to block 685).
[0133] In other embodiments, the second NF associated with the URL is the ADRF of the communication network, and the exemplary method further includes the following operations labeled with corresponding block numbers:
[0134] • (620) Send a first request to the ADRF to store the ML model, where the first request includes an association ID associated with the ML model and a URL associated with NFp from which the ML model can be obtained;
[0135] • (630) Provide the ML model to the ADRF using the URL associated with NFp; and
[0136] • (640) Receive a first response from the ADRF, the first response including a URL associated with the ADRF, and the URL is sent to NFc in this response.
[0137] In some of these embodiments, the exemplary method further includes the operation of block 615, wherein NFp selects an ADRF instance for storing the ML model, and the ADRF instance is associated with an ADRF ID. In this case, in block 620, the first request is sent to the ADRF instance, and providing the ML model to the ADRF in block 695 is based on a match, correspondence, or relationship between the ADRF ID and the ADRF to which the ML model is provided.
[0138] In some embodiments, the exemplary method further includes the operation of block 610, wherein NFp performs a first security operation on the ML model. The first security operation includes encryption and / or integrity protection.
[0139] Furthermore, Figure 7 An exemplary method (e.g., process) for an NRF of a communication network (e.g., 5GC) according to various embodiments of the present disclosure is shown. Figure 7 The exemplary method shown can be performed by the NRF or by a network device configured to implement the NRF as described elsewhere herein.
[0140] The exemplary method includes the operation of block 710, wherein the NRF registers the following information in the profile of a consumer NF (NFc) of a communication network: a supplier identifier (ID) associated with the NFc; and one or more analysis IDs associated with an ML model supported by the NFc, including a first analysis ID associated with a first ML model generated, owned, and / or maintained by an NFp of the communication network. The exemplary method further includes the operations of blocks 730 to 740, wherein the NFp receives a request for the profile of the NFc from the NFp and, in response to the request, sends the profile of the NFc to the NFp.
[0141] In some embodiments, the exemplary method further includes the operation of block 720, wherein the NRF performs a discovery process with the NFc to identify the NFp based on the first analysis ID.
[0142] In some embodiments, the NFc is a NWDAF (AnLF). In some embodiments, the NFp is a NWDAF (MTLF).
[0143] In addition, Figure 8 An exemplary method (e.g., process) for an ADRF for a communication network (e.g., 5GC) according to various embodiments of the present disclosure is shown. Figure 8 The exemplary method shown can be performed by the ADRF or by a network device configured to implement the ADRF as described elsewhere herein.
[0144] The exemplary method includes the operation of block 810, wherein the ADRF receives a first request for storing an ML model from an NFp of a communication network. The first request includes an association ID associated with the ML model and a URL associated with the NFp from which the ML model can be obtained. The exemplary method further includes the operation of block 820, wherein the ADRF obtains the ML model from the NFp using the URL associated with the NFp. In some embodiments, the obtained ML model may be encrypted and / or integrity protected. The exemplary method further includes the operations of blocks 830 to 840, wherein the ADRF stores the obtained ML model in association with the association ID and sends a first response to the NFp, the first response including a URL associated with the ADRF from which the ML model can be obtained.
[0145] In some embodiments, the exemplary method further includes the operation of block 850, wherein the ADRF receives an update request from the NFp, and the update request includes an association ID and a list of permitted NF instances. The exemplary method further includes the operation of block 860, wherein, based on a match between the association ID included in the update request and the association ID stored in association with the ML model, the ADRF stores the list of permitted NF instances in association with the ML model. Specifically, the list of permitted NF instances includes one or more identifiers associated with the corresponding NFs that are permitted (e.g., authorized) to access the communication network of the ML model.
[0146] In some of these embodiments, the exemplary method further includes the operation of block 870, wherein the ADRF provides the ML model to the NFc of the communication network using a URL associated with the ADRF. For example, the ADRF can use the URL associated with the ADRF to facilitate the NFc in obtaining the ML model. In some of these embodiments, providing the ML model to the NFc in block 870 is based on a match, correspondence, or relationship (e.g., in block 860) between an identifier associated with the NFc and an identifier included in the list of permitted NF instances stored in association with the ML model. In some of these embodiments, the NFc is the NWDAF (AnLF). In some of these embodiments, the NFp is the NWDAF (MTLF).
[0147] Although the various embodiments are described above in terms of methods, techniques, and / or processes, those of ordinary skill in the art will readily understand that such methods, techniques, and / or processes can be embodied by various combinations of hardware and software in various systems, communication devices, computing devices, control devices, apparatuses, non-transitory computer-readable media, computer program products, and the like.
[0148] Figure 9 An example of a communication system 900 according to some embodiments is shown. In this example, the communication system 900 includes a telecommunications network 902, and the telecommunications network 902 includes an access network 904 (e.g., RAN) and a core network 906, and the core network 906 includes one or more core network nodes 908. The access network 904 includes one or more access network nodes, such as network nodes 910a to 910b (one or more of which can generally be referred to as network node 910), or any other similar 3GP access node or non-3GPP access point. The network node 910 facilitates the direct or indirect connection of the UE, for example, connecting the UEs 912a to 912d (one or more of which can generally be referred to as UE 912) to the core network 906 through one or more wireless connections.
[0149] Example wireless communications via a wireless connection include sending and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without using wiring, cables, or other material conductors. Additionally, in various embodiments, communication system 900 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that can facilitate or participate in the communication of data and / or signals, whether via a wired connection or a wireless connection. Communication system 900 may include any type of communication, telecommunications, data, cellular, radio network, and / or other similar types of systems, and / or interface with any type of communication, telecommunications, data, cellular, radio network, and / or other similar types of systems.
[0150] UE 912 can be any of a variety of communication devices, including wireless devices arranged, configured, and / or operable to communicate wirelessly with network node 910 and other communication devices. Similarly, network node 910 is arranged, capable, configured, and / or operable to communicate directly or indirectly with UE 912 and / or with other network nodes or devices in telecommunications network 902 to enable and / or provide network access (such as wireless network access) and / or to perform other functions in telecommunications network 902 (such as management).
[0151] In the depicted example, core network 906 connects network node 910 to one or more hosts (such as host 916). These connections can be direct connections or indirect connections via one or more intermediate networks or devices. In other examples, the network node can be directly coupled to the host. Core network 906 includes one or more core network nodes (e.g., 908) consisting of hardware and software components. The characteristics of these components can be substantially similar to those described with respect to UEs, network nodes, and / or hosts, such that the description is generally applicable to the corresponding components of core network node 908. Example core network nodes include the functionality of one or more of the following: mobile switching center (MSC), mobility management entity (MME), home subscriber server (HSS), access and mobility management function (AMF), session management function (SMF), authentication server function (AUSF), subscription identifier concealment function (SIDF), unified data management (UDM), security edge protection proxy (SEPP), network exposure function (NEF), and / or user plane function (UPF).
[0152] The host 916 may be owned or under the control of a service provider other than the operator or provider of the access network 904 and / or the telecommunication network 902, and may be operated by or on behalf of the service provider. The host 916 may host multiple applications to provide one or more services. Examples of such applications include live and pre-recorded audio / video content, data collection services (e.g., obtaining and compiling data on various environmental conditions detected by multiple UEs), analytical functions, social media, functions for controlling or otherwise interacting with remote devices, functions for alarm and monitoring centers, or any other such functions performed by a server.
[0153] As a whole, Figure 9 the communication system 900 enables connections between UEs, network nodes, and hosts. In this sense, the communication system may be configured to operate according to predefined rules or procedures such as specific standards, which include but are not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long-Term Evolution (LTE) and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future-generation standards (e.g., 6G); Wireless Local Area Network (WLAN) standards such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard (WiFi); and / or any other suitable wireless communication standards such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC), ZigBee, LiFi, and / or any Low-Power Wide-Area Network (LPWAN) standards such as LoRa and Sigfox.
[0154] In some examples, the telecommunication network 902 is a cellular network implementing 3GPP standardized features. Thus, the telecommunication network 902 may support network slicing to provide different logical networks to different devices connected to the telecommunication network 902. For example, the telecommunication network 902 may provide ultra-reliable low-latency communication (URLLC) services to some UEs, while providing enhanced mobile broadband (eMBB) services to other UEs, and / or providing massive machine-type communication (mMTC) / massive IoT services to yet other UEs.
[0155] In some examples, the UE 912 is configured to send and / or receive information without direct human interaction. For example, the UE can be designed to send information to the access network 904 according to a predetermined schedule when triggered by an internal or external event or in response to a request from the access network 904. Additionally, the UE can be configured to operate in a single RAT mode, a multi-RAT mode, or a multi-standard mode. For example, the UE can operate using any one or combination of Wi-Fi, NR (New Radio), and LTE, i.e., be configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved UMTS Terrestrial Radio Access Network) New Radio - Dual Connectivity (EN-DC).
[0156] In this example, the hub 914 communicates with the access network 904 to facilitate indirect communication between one or more UEs (e.g., UEs 912c and / or 912d) and a network node (e.g., network node 910b). In some examples, the hub 914 can be a controller, a router, a content source and analyzer, or any other communication device described herein with respect to the UE. For example, the hub 914 can be a broadband router that enables the UE to access the core network 906. As another example, the hub 914 can be a controller that sends commands or instructions to one or more actuators in the UE. The commands or instructions can be received from the UE, the network node 910, or through executable code, scripts, procedures, or other instructions in the hub 914. As another example, the hub 914 can be a data collector that acts as a temporary storage device for UE data and, in some embodiments, can perform analysis or other processing of the data. As another example, the hub 914 can be a content source. For example, for a UE that is a VR headset, a display, a speaker, or other media delivery device, the hub 914 can obtain VR assets, videos, audio, or other media or data related to sensory information via the network node, and then the hub 914 can directly provide it to the UE after performing local processing and / or after adding additional local content. In yet another example, the hub 914 acts as a proxy server or coordinator for the UE, especially if one or more of the UEs are low-energy IoT devices.
[0157] The hub 914 may have a continuous / persistent or intermittent connection to the network node 910b. The hub 914 may also allow for different communication schemes and / or scheduling between the hub 914 and a UE (e.g., UE 912c and / or UE 912d) and between the hub 914 and the core network 906. In other examples, the hub 914 is connected to the core network 906 and / or one or more UEs via a wired connection. Additionally, the hub 914 may be configured to connect to an M2M service provider via the access network 904, and / or to connect to another UE via a direct connection. In some scenarios, a UE may establish a wireless connection with a network node 910 while still being connected via the hub 914 via a wired or wireless connection. In some embodiments, the hub 914 may be a dedicated hub - i.e., a hub whose main function is to route communications from the network node 910b to a UE or from a UE to the network node 910b. In other embodiments, the hub 914 may be a non-dedicated hub - i.e., a device that is capable of operating to route communications between a UE and the network node 910b but is additionally capable of operating as a communication origin and / or destination for certain data channels.
[0158] Figure 10 UE 1000 according to some embodiments is shown. Examples of UEs include, but are not limited to, smart phones, mobile phones, cellular phones, Internet Protocol voice (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, gaming consoles or devices, music storage devices, playback devices, wearable terminal devices, wireless endpoints, mobile stations, tablet computers, laptop computers, laptop embedded devices (LEEs), laptop mounted devices (LMEs), smart devices, wireless client premise equipment (CPE), vehicle-mounted or vehicle-embedded / integrated wireless devices, etc. Other examples include any UE identified by 3GPP, including narrowband Internet of Things (NB-IoT) UEs, machine type communication (MTC) UEs, and / or enhanced MTC (eMTC) UEs.
[0159] A UE may support device-to-device (D2D) communication, for example, by implementing 3GPP standards for sidelink communication, dedicated short range communication (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, a UE may not have a user in the sense of a human user who owns and / or operates the associated device. Instead, a UE may represent a device that is intended to be sold to or operated by a human user but may not or initially may not be associated with a particular human user (e.g., a smart sprinkler controller). Alternatively, a UE may represent a device that is not intended to be sold to or operated by an end user but may be associated with or operate in the interest of a user (e.g., a smart power meter).
[0160] UE 1000 includes processing circuitry 1002 that is operably coupled via a bus 1004 to an input / output interface 1006, a power supply 1008, a memory 1010, a communication interface 1012, and other components that may not be explicitly shown. Some UEs may utilize Figure 10 all or a subset of the components shown. The level of integration between components may vary with the UE. Additionally, some UEs may include multiple instances of components, such as multiple processors, memories, transceivers, transmitters, receivers, etc.
[0161] The processing circuitry 1002 is configured to process instructions and data and may be configured to implement any sequential state machine operable to execute instructions stored as a machine-readable computer program in the memory 1010. The processing circuitry 1002 may be implemented as: one or more hardware-implemented state machines (e.g., implemented in discrete logic, a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), etc.); programmable logic along with suitable firmware; one or more stored computer programs, a general-purpose processor (e.g., a microprocessor or a digital signal processor (DSP)) along with suitable software; or any combination of the foregoing. For example, the processing circuitry 1002 may include multiple central processing units (CPUs).
[0162] In this example, the input / output interface 1006 may be configured to provide one or more interfaces to an input device, an output device, or one or more input and / or output devices. Examples of output devices include speakers, sound cards, video cards, displays, monitors, printers, actuators, transmitters, smart cards, another output device, or any combination thereof. Input devices may allow a user to capture information into the UE 1000. Examples of input devices include a touch-sensitive or presence-sensitive display, a camera (e.g., a digital camera, a digital video camera, a webcam, etc.), a microphone, a sensor, a mouse, a trackball, a directional keypad, a touchpad, a roller, a smart card, etc. A presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. Sensors may be, for example, accelerometers, gyroscopes, tilt sensors, force sensors, magnetometers, optical sensors, proximity sensors, biometric sensors, etc., or any combination thereof. Output devices may use the same type of interface port as input devices. For example, a universal serial bus (USB) port may be used to provide input and output devices.
[0163] In some embodiments, power source 1008 is configured as a battery or battery pack. Other types of power sources can be used, such as an external power source (e.g., a power outlet), a photovoltaic device, or a battery cell. Power source 1008 can also include a power circuit for delivering power from power source 1008 itself and / or an external power source to various parts of UE 1000 via an input circuit or an interface such as a power cable. Delivering power can be used, for example, to charge power source 1008. The power circuit can perform any formatting, conversion, or other modification on the power from power source 1008 to make the power suitable for the various components of UE 1000 that it powers.
[0164] Memory 1010 can be or be configured to include memory such as random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, hard disks, removable magnetic tapes, flash drives, etc. In one example, memory 1010 includes one or more applications 1014 such as an operating system, a web browser application, widgets, a gadget engine, or other applications, as well as corresponding data 1016. Memory 1010 can store any one or combination of various operating systems used by UE 1000.
[0165] Memory 1010 can be configured to include multiple physical drive units such as redundant arrays of independent disks (RAID), flash memory, USB flash drives, external hard disk drives, thumb drives, pen drives, key drives, high density digital versatile disc (HD-DVD) disc drives, internal hard disk drives, Blu-ray disc drives, holographic digital data storage (HDDS) disc drives, external mini dual in-line memory modules (DIMMs), synchronous dynamic random access memory (SDRAM), external micro DIMM SDRAM, smart card memory (e.g., a tamper-resistant module in the form of a universal integrated circuit card (UICC) including one or more subscriber identity modules (SIMs) such as a USIM and / or an ISIM), other memory, or any combination thereof. The UICC can be, for example, an embedded UICC (eUICC), an integrated UICC (iUICC), or a removable UICC commonly referred to as a "SIM card". Memory 1010 can allow UE 1000 to access instructions, applications, etc. stored on a temporary or non-temporary storage medium to offload data or upload data. An article such as an article of manufacture of a communication system can be tangibly embodied as or in memory 1010, which can be or include a device-readable storage medium.
[0166] The processing circuit 1002 can be configured to communicate with an access network or other network using the communication interface 1012. The communication interface 1012 can include one or more communication subsystems and can include an antenna 1022 or be communicatively coupled to the antenna 1022. The communication interface 1012 can include one or more transceivers for communication (e.g., by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or a network node in the access network)). Each transceiver can include a transmitter 1018 and / or 1020 suitable for providing network communication (e.g., optical, electrical, frequency allocation, etc.). Additionally, the transmitter 1018 and / or receiver 1020 can be coupled to one or more antennas (e.g., 1022) and can share circuit components, software, or firmware, or alternatively be implemented separately.
[0167] In the illustrated embodiment, the communication functions of the communication interface 1012 can include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near-field communication, location-based communication (e.g., use of the Global Positioning System (GPS) for determining location), another type of communication function, or any combination thereof. The communication can be implemented according to one or more communication protocols and / or standards such as the following: IEEE802.11, Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), GSM, LTE, New Radio (NR), UMTS, WiMax, Ethernet, Transmission Control Protocol / Internet Protocol (TCP / IP), Synchronous Optical Network (SONET), Asynchronous Transfer Mode (ATM), QUIC, Hypertext Transfer Protocol (HTTP), etc.
[0168] Regardless of the type of sensor, the UE can provide an output of data captured by its sensors via its communication interface 1012 over a wireless connection to a network node. The data captured by the UE's sensors can be transmitted via another UE over a wireless connection to a network node. The output can be periodic (e.g., every 15 minutes if it reports the sensed temperature), random (e.g., to balance the load of reports from several sensors), in response to a triggering event (e.g., sending an alert when humidity is detected), in response to a request (e.g., a user-initiated request), or a continuous stream (e.g., a live video feed of a patient).
[0169] Figure 11 A network node 1100 is shown according to some embodiments. Examples of network nodes include, but are not limited to, access points (e.g., radio access points) and base stations (e.g., radio base stations, NodeB, eNB, gNB, etc.).
[0170] Base stations can be classified based on the amount of coverage they provide (or in other words, their transmit power levels), and thus, depending on the amount of coverage provided, a base station can be referred to as a femto base station, a pico base station, a micro base station, or a macro base station. A base station can be a relay node or a relay donor node that controls a relay. A network node can also include one or more (or all) parts of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU), sometimes referred to as a remote radio head (RRH). These remote radio units can be integrated with an antenna to form a radio with an integrated antenna, or they can not be integrated with an antenna to form a radio with an integrated antenna. The parts of a distributed radio base station can also be referred to as nodes in a distributed antenna system (DAS).
[0171] Other examples of network nodes include multi-transmission point (multi-TRP) 5G access points, multi-standard radio (MSR) devices (e.g., MSR BS), network controllers (e.g., radio network controller (RNC) or base station controller (BSC)), base transceiver stations (BTS), transmission points, transmission nodes, multi-cell / multicast coordination entities (MCE), operation and maintenance (O&M) nodes, operation support system (OSS) nodes, self-organizing network (SON) nodes, positioning nodes (e.g., evolved serving mobile location center (E-SMLC)), and / or minimized drive test (MDT).
[0172] As a more specific example, one or more network nodes 1100 can be configured to perform operations considered to be performed by various NFs in the descriptions of the various methods or processes herein. As a more specific example, one or more network nodes 1100 can be configured to perform operations considered to be performed by a consumer NF (e.g., NWDAF AnLF), a producer NF (e.g., NWDAF MTLF), NRF, and ADRF.
[0173] The network node 1100 includes a processing circuit 1102, a memory 1104, a communication interface 1106, and a power supply 1108. The network node 1100 may be composed of multiple physically separated components (e.g., Node B components and RNC components, or BTS components and BSC components, etc.), and these components may have their respective corresponding components. In some scenarios where the network node 1100 includes multiple separate components (e.g., BTS and BSC components), one or more of the separate components may be shared among multiple network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique "NodeB and RNC pair" may in some cases be considered a single separate network node. In some embodiments, the network node 1100 may be configured to support multiple radio access technologies (RATs). In such embodiments, some components may be replicated (e.g., there are separate memories 1104 for different RATs), and some components may be reused (e.g., the same antenna 1110 may be shared by different RATs). The network node 1100 may also include multiple sets of various components shown for different wireless technologies (e.g., GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, radio frequency identification (RFID), or Bluetooth wireless technologies) integrated into the network node 1100. These wireless technologies may be integrated into the same or different chips or chip sets and other components within the network node 1100.
[0174] The processing circuit 1102 may include a combination of one or more of the following: a microprocessor, a controller, a microcontroller, a central processing unit, a digital signal processor, an application specific integrated circuit, a field programmable gate array, or any other suitable computing device, resource, or a combination of hardware, software, and / or coded logic, which is operable to provide the network node 1100 functions either alone or in combination with other network node 1100 components (e.g., the memory 1104).
[0175] In some embodiments, the processing circuit 1102 includes a system on chip (SOC). In some embodiments, the processing circuit 1102 includes one or more of a radio frequency (RF) transceiver circuit 1112 and a baseband processing circuit 1114. In some embodiments, the RF transceiver circuit 1112 and the baseband processing circuit 1114 may be on separate chips (or chip sets), boards, or units (e.g., a radio unit and a digital unit). In alternative embodiments, some or all of the RF transceiver circuit 1112 and the baseband processing circuit 1114 may be on the same chip or chip set, board, or unit.
[0176] Memory 1104 may include any form of volatile or non-volatile computer-readable memory, including but not limited to permanent storage devices, solid-state memory, remotely installed memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disks), removable storage media (e.g., flash drives, compact discs (CDs) or digital video discs (DVDs)), and / or any other volatile memory or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data, and / or instructions that can be used by processing circuitry 1102. Memory 1104 may store any suitable instructions, data, or information, including computer programs, software, applications including one or more of logic, rules, code, tables, and / or other instructions capable of being executed by processing circuitry 1102 and used by network node 1100 (collectively referred to as computer program 1104a, which may be in the form of a computer program product). Storage device 1104 may be used to store any calculations made by processing circuitry 1102 and / or any data received via communication interface 1106. In some embodiments, processing circuitry 1102 and memory 1104 are integrated together.
[0177] Communication interface 1106 is used for wired or wireless communication of signaling and / or data between network nodes, access networks, and / or UEs. As shown, communication interface 1106 includes ports / terminals 1116 for sending data to and receiving data from a network, for example, via a wired connection. Communication interface 1106 also includes radio front-end circuitry 1118, which may be coupled to antenna 1110 or, in some embodiments, is part of antenna 1110. Radio front-end circuitry 1118 includes filter 1120 and amplifier 1122. Radio front-end circuitry 1118 may be connected to antenna 1110 and processing circuitry 1102. The radio front-end circuitry may be configured to condition signals transmitted between antenna 1110 and processing circuitry 1102. Radio front-end circuitry 1118 may receive digital data to be transmitted to other network nodes or UEs via a wireless connection. Radio front-end circuitry 1118 may convert the digital data into a radio signal having suitable channel and bandwidth parameters using a combination of filter 1120 and / or amplifier 1122. The radio signal may then be transmitted via antenna 1110. Similarly, when receiving data, antenna 1110 may collect radio signals, which are then converted into digital data by radio front-end circuitry 1118. The digital data may be passed to processing circuitry 1102. In other embodiments, the communication interface may include different components and / or different combinations of components.
[0178] In some alternative embodiments, the network node 1100 does not include a separate radio front-end circuit 1118. Instead, the processing circuit 1102 includes the radio front-end circuit and is connected to the antenna 1110. Similarly, in some embodiments, all or some of the RF transceiver circuits 1112 are part of the communication interface 1106. In yet another embodiment, the communication interface 1106 includes one or more ports or terminals 1116, a radio front-end circuit 1118, and RF transceiver circuits 1112 as part of a radio unit (not shown), and the communication interface 1106 communicates with a baseband processing circuit 1114, which is part of a digital unit (not shown).
[0179] The antenna 1110 may include one or more antennas or antenna arrays configured to transmit and / or receive wireless signals. The antenna 1110 may be coupled to the radio front-end circuit 1118 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In some embodiments, the antenna 1110 is separate from the network node 1100 and may be connected to the network node 1100 through an interface or port.
[0180] The antenna 1110, the communication interface 1106, and / or the processing circuit 1102 may be configured to perform any receiving operations and / or certain obtaining operations performed by the network node described herein. Any information, data, and / or signals may be received from a UE, another network node, and / or any other network device. Similarly, the antenna 1110, the communication interface 1106, and / or the processing circuit 1102 may be configured to perform any transmitting operations performed by the network node described herein. Any information, data, and / or signals may be transmitted to a UE, another network node, and / or any other network device.
[0181] The power supply 1108 supplies power to various components of the network node 1100 in a form suitable for the various components (e.g., at the voltage and current levels required by each respective component). The power supply 1108 may also include a power management circuit or be coupled to a power management circuit to supply power to the components of the network node 1100 for performing the functions described herein. For example, the network node 1100 may be connected to an external power supply (e.g., a power grid, a power outlet) via an input circuit or interface (e.g., a cable), and the external power supply supplies power to the power circuit of the power supply 1108. As another example, the power supply 1108 may include a power supply in the form of a battery or a battery pack, which is connected to or integrated in the power circuit. If the external power supply fails, the battery may provide backup power.
[0182] Embodiments of the network node 1100 may include beyond Figure 11An add-on to the component shown, for providing certain aspects of the functionality of a network node (including any functionality described herein and / or any functionality required to support the subject matter described herein). For example, network node 1100 may include a user interface device to allow information to be input into network node 1100 and to allow information to be output from network node 1100. This may allow a user to perform diagnostic, maintenance, repair, and other administrative functions for network node 1100.
[0183] Figure 12 is a block diagram of host 1200 in accordance with aspects described herein, and the host 1200 may be Figure 9 an embodiment of host 916. Host 1200 may be or include various combinations of hardware and / or software (including stand-alone servers, blade servers, cloud-implemented servers, distributed servers, virtual machines, containers, or processing resources in a server farm). Host 1200 may provide one or more services to one or more UEs.
[0184] Host 1200 includes processing circuitry 1202, which is operably coupled via bus 1204 to input / output interface 1206, network interface 1208, power supply 1210, and memory 1212. Other components may be included in other embodiments. The characteristics of these components may be substantially similar to those described for the devices of the previous figures (e.g., Figure 10 and Figure 11 ), such that the description thereof generally applies to the corresponding components of host 1200.
[0185] Memory 1212 may include one or more computer programs, which include data 1216 and one or more host applications 1214. The data 1216 may include user data, such as data generated by the UE for the host 1200 or data generated by the host 1200 for the UE. Embodiments of the host 1200 may utilize only a subset or all of the illustrated components. The host application 1214 may be implemented in a container-based architecture and may provide support for video codecs (e.g., Versatile Video Coding (VVC), High Efficiency Video Coding (HEVC), Advanced Video Coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAC, Advanced Audio Coding (AAC), MPEG, G.711), including transcoding for a variety of different categories, types, or implementations of UEs (e.g., mobile phones, desktop computers, wearable display systems, head-up display systems). The host application 1214 may also provide user authentication and license checking and may periodically report health status, routing, and content availability to a central node (such as a device in the core network or a device at the edge of the core network). Thus, the host 1200 may select and / or indicate different hosts for over-the-top services for the UE. The host application 1214 may support various protocols, such as the HTTP Live Streaming (HLS) protocol, the Real-Time Messaging Protocol (RTMP), the Real-Time Streaming Protocol (RTSP), the HTTP-based Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc.
[0186] Figure 13 FIG. is a block diagram showing a virtualized environment 1300 in which functions implemented by some embodiments may be virtualized. In this context, virtualization means creating a virtual version of a device or equipment that may include a virtualized hardware platform, storage devices, and network resources. As used herein, virtualization may be applied to any device or its components described herein and involves an implementation in which at least a portion of the functions are implemented as one or more virtual components. Some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines (VMs) that are implemented in one or more virtualized environments 1300 hosted by one or more of the hardware nodes (e.g., hardware computing devices operating as network nodes, UEs, core network nodes, or hosts). Additionally, in embodiments where the virtual node does not require a radio connection (e.g., core network nodes or hosts), the node may be fully virtualized.
[0187] The application 1302 (which may alternatively be referred to as a software instance, virtual application, network function, virtual node, virtual network function, etc.) runs in the virtualized environment 1300 to implement some of the features, functions, and / or benefits of some embodiments disclosed herein.
[0188] For example, various NFs (or portions thereof) described herein with respect to other figures may be implemented as virtual network functions 1302 in a virtualized environment 1300. As a more specific example, a consumer NF (e.g., NWDAF AnLF), a producer NF (e.g., NWDAF MTLF), an NRF, and / or an ADRF may be implemented as virtual network functions 1302 in a virtualized environment 1300.
[0189] The hardware 1304 includes processing circuitry, a memory storing software and / or instructions (collectively referred to as computer program 1304a, which may be in the form of a computer program product) executable by the hardware processing circuitry, and / or other hardware devices described herein (e.g., network interfaces, input / output interfaces, etc.). The software may be executed by the processing circuitry to instantiate one or more virtualization layers 1306 (also referred to as a hypervisor or virtual machine monitor (VMM)), provide VMs 1308a to 1308b (one or more of which may generally be referred to as VMs 1308), and / or perform any functions, features, and / or benefits described in connection with some embodiments herein. The virtualization layer 1306 may present a virtual operating platform to the VMs 1308 that appears like networked hardware.
[0190] The VMs 1308 include virtual processing, virtual memory, virtual network or interfaces, and virtual storage, and may be run by corresponding virtualization layers 1306. Different embodiments of instances of virtual devices 1302 may be implemented on one or more VMs 1308, and these implementations may be made in different ways. In some contexts, the virtualization of hardware is referred to as network function virtualization (NFV). NFV can be used to unify many network device types onto industry-standard high-capacity server hardware, physical switches, and physical storage that may be located in data centers and customer premise equipment (CPE).
[0191] In the context of NFV, each VM 1308 may be a software implementation of a physical machine that runs programs as if they were being executed on a physical, non-virtualized machine. Each VM 1308, along with the portion of the hardware 1304 that executes that VM (whether it is hardware dedicated to that VM and / or hardware shared by that VM with other VMs), forms a separate virtual network element. Still in the context of NFV, the virtual network function is responsible for handling a specific network function running in one or more VMs 1308 on top of the hardware 1304 and corresponds to the application 1302.
[0192] The hardware 1304 can be implemented in a stand-alone network node with general or specific components. Some functions of the hardware 1304 can be implemented via virtualization. Alternatively, the hardware 1304 can be part of a larger hardware cluster (e.g., in a data center or CPE), where many hardware nodes work together and are managed through management and coordination 1310, which particularly supervises the lifecycle management of the application 1302. In some embodiments, the hardware 1304 is coupled to one or more radio units, each radio unit including one or more transmitters and one or more receivers that can be coupled to one or more antennas. The radio units can communicate directly with other hardware nodes via one or more suitable network interfaces and can be used in combination with virtual components to provide virtual nodes with radio capabilities, such as radio access points or base stations. In some embodiments, some signaling can be provided by using the control system 1312, which can alternatively be used for communication between the hardware nodes and the radio units.
[0193] Figure 14 A communication diagram is shown in which a host 1402 communicates with a UE 1406 via a partial wireless connection through a network node 1404 according to some embodiments. Reference will now be made to Figure 14 describing example implementations according to various embodiments of the UE (e.g., Figure 9 UE 912a and / or Figure 10 UE 1000), network nodes (e.g., Figure 9 network node 910a and / or Figure 11 network node 1100), and hosts (e.g., Figure 9 host 916 and / or Figure 12 host 1200) discussed in the previous paragraphs.
[0194] Similar to the host 1200, embodiments of the host 1402 include hardware such as communication interfaces, processing circuitry, and memory. The host 1402 also includes software that is stored in or accessible by the host 1402 and can be executed by the processing circuitry. The software includes host applications that are operable to provide services to remote users, such as the UE 1406 connecting via an over-the-top (OTT) connection 1450 that extends between the UE 1406 and the host 1402. When providing services to remote users, the host applications can provide user data transmitted using the OTT connection 1450.
[0195] The network node 1404 includes hardware that enables it to communicate with the host 1402 and the UE 1406. The connection 1460 can be a direct connection or through a core network, such as Figure 9a connection to a core network 906) and / or one or more other intermediate networks (e.g., one or more public, private, or hosted networks). For example, the intermediate network can be a backbone network or the Internet.
[0196] UE 1406 includes hardware and software that is stored in or accessible by UE 1406 and executable by the processing circuitry of the UE. The software includes client applications (e.g., a web browser or a carrier-specific “app”) that are operable to provide services to a human or non-human user via UE 1406 with the support of host 1402. In host 1402, a running host application can communicate with a running client application via an OTT connection 1450 terminated at UE 1406 and host 1402. When providing services to a user, the client application of the UE can receive request data from the host application of the host and provide user data in response to the request data. The OTT connection 1450 can transmit both the request data and the user data. The client application of the UE can interact with the user to generate user data that is provided to the host application via the OTT connection 1450.
[0197] The OTT connection 1450 can extend via a connection 1460 between host 1402 and network node 1404 and via a wireless connection 1470 between network node 1404 and UE 1406 to provide a connection between host 1402 and UE 1406. The connection 1460 and the wireless connection 1470 through which the OTT connection 1450 can be provided have been abstractly drawn to illustrate communication between host 1402 and UE 1406 via network node 1404 without explicitly referring to any intermediate devices and the exact routing of messages through these devices.
[0198] As an example of sending data via the OTT connection 1450, in step 1408, the host 1402 provides user data, which can be performed by executing a host application. In some embodiments, the user data is associated with a specific human user who interacts with the UE 1406. In other embodiments, the user data is associated with the UE 1406, and the UE 1406 shares data with the host 1402 without explicit human interaction. In step 1410, the host 1402 initiates a transmission to the UE 1406 that carries the user data. The host 1402 can initiate the transmission in response to a request sent by the UE 1406. The request can be caused by a human interaction with the UE 1406 or by an operation of a client application executed on the UE 1406. According to the teachings of the embodiments described throughout the present disclosure, the transmission can be conveyed via the network node 1404. Thus, in step 1412, according to the teachings of the embodiments described throughout the present disclosure, the network node 1404 sends the user data carried in the transmission initiated by the host 1402 to the UE 1406. In step 1414, the UE 1406 receives the user data carried in the transmission, which can be performed by a client application executed on the UE 1406 that is associated with the host application executed by the host 1402.
[0199] In some examples, the UE 1406 executes a client application that provides user data to the host 1402. The user data can be provided in reaction or response to data received from the host 1402. Thus, in step 1416, the UE 1406 can provide user data, which can be performed by executing the client application. When providing the user data, the client application can also consider user input received from the user via the input / output interface of the UE 1406. Regardless of the specific manner of providing the user data, the UE 1406 initiates a transmission of the user data to the host 1402 via the network node 1404 in step 1418. In step 1420, according to the teachings of the embodiments described throughout the present disclosure, the network node 1404 receives the user data from the UE 1406 and initiates sending the received user data to the host 1402. In step 1422, the host 1402 receives the user data carried in the transmission initiated by the UE 1406.
[0200] One or more of the various embodiments improve the performance of OTT services provided to the UE 1406 using the OTT connection 1450, in which the wireless connection 1470 forms the final part. For example, by providing the ability to protect AI / ML models during various transmission, storage, and acquisition scenarios to AI / ML model owners / producers, the embodiments improve the security of confidential and / or sensitive AI / ML models, thus facilitating the deployment of such models in multi-vendor communication networks (e.g., 5GC). In this way, the embodiments facilitate improving network performance based on the deployed AI / ML models, thus increasing the value of OTT services delivered through the network improved in this manner.
[0201] In an example scenario, the host 1402 can collect and analyze factory status information. As another example, the host 1402 can process audio and video data that may have been obtained from the UE for creating a map. As another example, the host 1402 can collect and analyze real-time data to help control vehicle congestion (e.g., control traffic lights). As another example, the host 1402 can store the monitoring video uploaded by the UE. As another example, the host 1402 can store or control access to media content such as video, audio, VR, or AR that can be broadcast, multicast, or unicast to the UE. As other examples, the host 1402 can be used for energy pricing, remote control of non-time-critical electrical loads for balancing power generation demand, location services, rendering services (e.g., compiling charts, etc. based on data collected from remote devices), or any other function of collecting, obtaining, storing, analyzing, and / or sending data.
[0202] In some examples, a measurement process may be provided for monitoring data rate, latency, and other factors that are objects of improvement for one or more embodiments. There may also be optional network functions for reconfiguring the OTT connection 1450 between the host 1402 and the UE 1406 in response to changes in the measurement results. The measurement process and / or network function for reconfiguring the OTT connection may be implemented in the software and hardware of the host 1402 and / or the UE 1406. In some embodiments, sensors (not shown) may be deployed in or associated with other devices through which the OTT connection 1450 passes; the sensors may participate in the measurement process by providing values of the monitored quantities exemplified above or other physical quantities that software can use to calculate or estimate the monitored quantities. Reconfiguring the OTT connection 1450 may include message format, retransmission settings, preferred routing, etc.; the reconfiguration does not need to directly change the operation of the network node 1404. Such processes and functions may be known and practiced in the art. In some embodiments, the measurement may involve proprietary UE signaling that facilitates measurement by the host 1402 of throughput, propagation time, latency, etc. The measurement may be achieved by software causing messages (especially empty messages or "dummy" messages) to be sent using the OTT connection 1450 while monitoring propagation time, errors, etc.
[0203] The foregoing merely illustrates the principles of the present disclosure. In light of the teachings herein, various modifications and changes to the described embodiments will be apparent to those skilled in the art. Accordingly, it should be understood that those skilled in the art will be able to design many systems, arrangements, and processes that, although not explicitly shown or described herein, embody the principles of the present disclosure and are thus within the spirit and scope of the present disclosure. As will be understood by those of ordinary skill in the art, the various embodiments may be used together or interchangeably.
[0204] As used herein, the term unit may have its conventional meaning in the field of electronics, electrical devices, and / or electronic devices and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logic solid-state and / or discrete devices, computer programs or instructions for performing various tasks, processes, calculations, output, and / or display functions, etc., as exemplified herein.
[0205] Any suitable steps, methods, features, functions or benefits disclosed herein may be performed by one or more functional units or modules of one or more virtual devices. Each virtual device may include a plurality of these functional units. These functional units may be implemented by a processing circuit (which may include one or more microprocessors or microcontrollers), as well as other digital hardware (which may include a digital signal processor (DSP), dedicated digital logic, etc.). The processing circuit may be configured to execute program code stored in a memory, which may include one or several types of memories, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory devices, optical storage devices, etc. The program code stored in the memory includes program instructions for executing one or more telecommunication and / or data communication protocols and instructions for performing one or more of the techniques described herein. In some implementations, the processing circuit may be used to cause the corresponding functional unit to perform the corresponding function according to one or more embodiments of the present disclosure.
[0206] As described herein, a device and / or apparatus may be represented by a semiconductor chip, a chipset, or a (hardware) module including such a chip or chipset; however, this does not exclude the possibility that the function of the device or apparatus is not implemented by hardware but is implemented as a software module (e.g., a computer program or a computer program product including an executable software code portion for execution or running on a processor). In addition, the function of the device or apparatus may be implemented by any combination of hardware and software. A device or apparatus may also be regarded as a combination of multiple devices and / or apparatuses, whether they cooperate with each other functionally or are independent of each other. In addition, as long as the function of the device or apparatus is retained, the device and apparatus may be implemented in a distributed manner throughout the system. Such principles and similar principles are considered to be known to those skilled in the art.
[0207] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. It will also be understood that the terms used herein should be interpreted as being consistent with their meaning in the context of this specification and the relevant art, and not as being ideal or overly formal, unless expressly so defined herein.
[0208] In addition, certain terms used in this disclosure (including the specification and the drawings) may be used synonymously in certain instances (e.g., "data" and "information"). It should be understood that although these terms and / or their synonyms that may be synonymous with each other may be used synonymously herein, there may be instances where such words are not intended to be used synonymously.
[0209] Example embodiments of the techniques and devices described herein include, but are not limited to, the embodiments listed below:
[0210] A1. A method for a consumer network function (NFc) in a communication network, the method comprising:
[0211] Registering the following items with a network repository function (NRF) of the communication network:
[0212] A supplier identifier (ID) associated with the NFc, and
[0213] One or more analysis IDs associated with an ML model supported by the NFc, the one or more analysis IDs including a first analysis ID associated with an ML model generated, owned, and / or maintained by a producer NF (NFp) of the communication network;
[0214] Sending a request for the ML model to the NFp, wherein the request includes the first analysis ID and the supplier ID associated with the NFc; and
[0215] Receiving a response from the NFp, the response including a uniform resource locator (URL) associated with a second NF of the communication network, from which the ML model can be obtained.
[0216] A2. The method according to embodiment A1, further comprising: obtaining the ML model from the second NF using the URL.
[0217] A3. The method according to any one of embodiments A1 to A2, wherein the second NF associated with the URL is one of the following: the NFp, or an analysis data repository function (ADRF) of the communication network.
[0218] A4. The method according to any one of embodiments A1 to A3, further comprising: performing a second security operation on the ML model, wherein the second security operation corresponds to a first security operation performed by the NFp on the ML model.
[0219] A5. The method according to embodiment A4, wherein:
[0220] The first security operation includes encryption and / or integrity protection;
[0221] The second security operation includes decryption corresponding to the encryption and / or integrity check corresponding to the integrity protection.
[0222] A6. The method according to any one of embodiments A1 to A5, wherein the response from the NFp is based on a match, correspondence, or relationship between the supplier ID registered with the NRF and the supplier ID included in the request.
[0223] A7. The method according to any one of embodiments A1 to A6 further includes: performing a discovery process with the NRF to identify the NFp based on the first analysis ID, wherein the request is sent in response to the discovery process.
[0224] A8. The method according to any one of embodiments A1 to A7, wherein one or more of the following apply:
[0225] The NFc is an analysis logic function (AnLF) of a network data analytics function (NWDAF); and
[0226] The NFp is a model training logic function (MTLF) of a network data analytics function (NWDAF).
[0227] B1. A method for a producer (NFp) in a communication network, the method including:
[0228] Receiving, from a consumer NF (NFc) of the communication network, a request for a machine learning (ML) model produced, owned, and / or maintained by the NFp, wherein the request includes a first analysis identifier (ID) associated with the ML model and a vendor ID associated with the NFc;
[0229] Obtaining, from a network repository function (NRF) of the communication network, a configuration file associated with the NFc;
[0230] Authorizing the NFc to access the ML model based on a match, correspondence, or relationship between the vendor ID included in the obtained NF configuration file and the vendor ID included in the request; and
[0231] Sending, based on authorizing the NFc, a response to the NFc, the response including a uniform resource locator (URL) associated with a second NF of the communication network, from which the ML model can be obtained.
[0232] B2. The method according to embodiment B1, wherein authorizing the NFC to access the ML model is further based on a match, correspondence, or relationship between the vendor ID included in the request and an interoperability ID associated with the NFp and the ML model.
[0233] B3. The method according to any one of embodiments B1 to B2 further includes: updating, based on authorizing the NFc, a list of permitted NF instances associated with the ML model to include an identifier (NFc ID) associated with the NFc.
[0234] B4. The method according to embodiment B3 further includes: sending an update request to the Analytical Data Repository Function (ADRF) of the communication network, the update request including an updated list of permitted NF instances associated with the ML model and an association ID.
[0235] B5. The method according to any one of embodiments B1 to B4, wherein:
[0236] The second NF associated with the URL is the NFp; and
[0237] The method further includes: subsequently providing the ML model to the NFc using the URL associated with the NFp.
[0238] B5a. The method according to embodiment B5, wherein providing the ML model to the NFc is based on a match, correspondence, or relationship between an identifier associated with the NFc and a list of permitted NF instances associated with the ML model.
[0239] B6. The method according to any one of embodiments B1 to B4, wherein:
[0240] The second NF associated with the URL is the Analytical Data Repository Function (ADRF) of the communication network; and
[0241] The method further includes:
[0242] Sending a first request to the ADRF to store the ML model, wherein the first request includes an association ID associated with the ML model and a URL associated with the NFp from which the ML model can be obtained;
[0243] Providing the ML model to the ADRF using the URL associated with the NFp; and
[0244] Receiving a first response from the ADRF, the first response including a URL associated with the ADRF, the URL being sent to the NFc in the response.
[0245] B7. The method according to embodiment B6, wherein:
[0246] The method further includes selecting an ADRF instance for storing the ML model;
[0247] The ADRF instance is associated with an ADRF ID;
[0248] Sending the first request to the ADRF instance; and
[0249] Providing the ML model to the ADRF is based on a match, correspondence, or relationship between the ADRF ID and the ADRF to which the ML model is provided.
[0250] B8. The method according to any one of embodiments B1 to B7 further includes: performing a first security operation on the ML model, where the first security operation includes encryption and / or integrity protection.
[0251] B9. The method according to any one of embodiments B1 to B8, wherein one or more of the following apply:
[0252] The NFc is an analysis logic function (AnLF) of a network data analytics function (NWDAF); and
[0253] The NFp is a model training logic function (MTLF) of a network data analytics function (NWDAF).
[0254] C1. A method for a network repository function (NRF) of a communication network, the method including:
[0255] Registering the following information in a profile of a consumer NF (NFc) of the communication network:
[0256] A supplier identifier (ID) associated with the NFc, and
[0257] One or more analysis IDs associated with an ML model supported by the NFc, the one or more analysis IDs including a first analysis ID associated with a first ML model generated, owned, and / or maintained by a producer NF (NFp) of the communication network;
[0258] Receiving a request for the profile of the NFc from the NFp; and
[0259] In response to the request, sending the profile of the NFc to the NFp.
[0260] C2. The method according to embodiment C1 further includes: performing a discovery process with the NFc to identify the NFp based on the first analysis ID.
[0261] C3. The method according to any one of embodiments C1 to C2, wherein one or more of the following apply:
[0262] The NFc is an analysis logic function (AnLF) of a network data analytics function (NWDAF); and
[0263] The NFp is a model training logic function (MTLF) of a network data analytics function (NWDAF).
[0264] D1. A method for an analytics data repository function (ADRF) in a communication network, the method comprising:
[0265] Receiving, from a producer network function (NFp) of the communication network, a first request to store a machine learning (ML) model, wherein the first request includes an association identifier (ID) associated with the ML model and a uniform resource locator (URL) associated with the NFp, from which the ML model can be obtained;
[0266] Obtaining the ML model from the NFp using the URL associated with the NFp;
[0267] Storing the obtained ML model in association with the association ID; and
[0268] Sending a first response to the NFp, the first response including a URL associated with the ADRF, from which the ML model can be obtained.
[0269] D2. The method according to embodiment D1, further comprising:
[0270] Receiving, from the NFp, an update request including the association ID and a list of permitted NF instances; and
[0271] Storing the list of permitted NF instances in association with the ML model based on a match between the association ID included in the update request and the association ID stored in association with the ML model, wherein the list of permitted NF instances includes one or more identifiers associated with corresponding NFs of the communication network permitted to access the ML model.
[0272] D3. The method according to any one of embodiments D1 to D2, further comprising: providing the ML model to a consumer network function (NFc) of the communication network using the URL associated with the ADRF.
[0273] D4. The method according to embodiment D3, wherein providing the ML model to the NFc is based on a match, correspondence, or relationship between an identifier associated with the NFc and an identifier included in the list of permitted NF instances stored in association with the ML model.
[0274] D5. The method according to any one of embodiments D3 to D4, wherein one or more of the following apply:
[0275] The NFc is an analysis logic function (AnLF) of a network data analysis function (NWDAF); and
[0276] The NFp is a model training logic function (MTLF) of a network data analysis function (NWDAF).
[0277] D6. The method according to any one of embodiments D1 to D5, wherein the obtained ML model is encrypted and / or integrity protected.
[0278] E1. A consumer network function (NFc) of a communication network, wherein:
[0279] The NFc is implemented by an operatively coupled communication interface circuit and a processing circuit, and
[0280] The processing circuit and the interface circuit are configured to perform operations corresponding to any one of the methods according to embodiments A1 to A8.
[0281] E2. A consumer network function (NFc) of a communication network, the NFc being configured to perform operations corresponding to any one of the methods according to embodiments A1 to A8.
[0282] E3. A non-transitory computer-readable medium storing computer-executable instructions, which when executed by a processing circuit associated with a consumer network function (NFc) of a communication network, configure the NFc to perform operations corresponding to any one of the methods according to embodiments A1 to A8.
[0283] E4. A computer program product including computer-executable instructions, which when executed by a processing circuit associated with the consumer network function (NFc) of the communication network, configure the NFc to perform operations corresponding to any one of the methods according to embodiments A1 to A8.
[0284] F1. A producer network function (NFp) of a communication network, wherein:
[0285] The NFp is implemented by an operatively coupled communication interface circuit and a processing circuit; and
[0286] The processing circuit and the interface circuit are configured to perform operations corresponding to any one of the methods according to embodiments B1 to B9.
[0287] F2. A producer network function (NFp) of a communication network, the NFp being configured to perform operations corresponding to any one of the methods according to embodiments B1 to B9.
[0288] F3. A non - transitory computer - readable medium storing computer - executable instructions that, when executed by a processing circuit associated with a producer network function (NFp) of a communication network, configure the NFp to perform operations corresponding to any of the methods according to Embodiments B1 to B9.
[0289] F4. A computer program product comprising computer - executable instructions that, when executed by a processing circuit associated with a producer network function (NFp) of a communication network, configure the NFp to perform operations corresponding to any of the methods according to Embodiments B1 to B9.
[0290] G1. A network repository function (NRF) of a communication network, wherein:
[0291] the NRF is implemented by an operatively - coupled communication interface circuit and a processing circuit, and
[0292] the processing circuit and the interface circuit are configured to perform operations corresponding to any of the methods according to Embodiments C1 to C3.
[0293] G2. A network repository function (NRF) of a communication network, the NRF being configured to perform operations corresponding to any of the methods according to Embodiments C1 to C3.
[0294] G3. A non - transitory computer - readable medium storing computer - executable instructions that, when executed by a processing circuit associated with a network repository function (NRF) of a communication network, configure the NRF to perform operations corresponding to any of the methods according to Embodiments C1 to C3.
[0295] G4. A computer program product comprising computer - executable instructions that, when executed by a processing circuit associated with a network repository function (NRF) of a communication network, configure the NRF to perform operations corresponding to any of the methods according to Embodiments C1 to C3.
[0296] H1. An analysis data repository function (ADRF) of a communication network, wherein:
[0297] the ADRF is implemented by an operatively - coupled communication interface circuit and a processing circuit, and
[0298] the processing circuit and the interface circuit are configured to perform operations corresponding to any of the methods according to Embodiments D1 to D6.
[0299] H2. An Analytical Data Repository Function (ADRF) of a communication network, the ADRF being configured to perform operations corresponding to any of the methods according to Embodiments D1 to D6.
[0300] H3. A non-transitory computer-readable medium storing computer-executable instructions which, when executed by a processing circuit associated with an Analytical Data Repository Function (ADRF) of a communication network, configure the ADRF to perform operations corresponding to any of the methods according to Embodiments D1 to D6.
[0301] H4. A computer program product comprising computer-executable instructions which, when executed by a processing circuit associated with an Analytical Data Repository Function (ADRF) of a communication network, configure the ADRF to perform operations corresponding to any of the methods according to Embodiments D1 to D6.
Claims
1. A method for a consumer network function NFc in a communication network, the method comprising: Registering (510) with a network repository function NRF of the communication network the following items: A vendor identifier ID associated with the NFc, and One or more analysis IDs associated with an ML model supported by the NFc, the one or more analysis IDs including a first analysis ID associated with an ML model generated, owned, and / or maintained by a producer NF "NFp" of the communication network; Sending (530) a request for the ML model to the NFp, wherein the request includes the first analysis ID and the vendor ID associated with the NFc; and Receiving (540) a response from the NFp, the response including a uniform resource locator URL associated with a second NF of the communication network, from which the ML model can be obtained.
2. The method according to claim 1 further comprises: Obtaining (550) the ML model from the second NF using the URL.
3. The method according to any one of claims 1 to 2, wherein, The second NF associated with the URL is one of the following: the NFp, or an analysis data repository function ADRF of the communication network.
4. The method according to any one of claims 1 to 3 further comprises: Performing (560) a second security operation on the ML model, wherein the second security operation corresponds to a first security operation performed by the NFp on the ML model.
5. The method according to claim 4, wherein: The first security operation includes encryption and / or integrity protection; The second security operation includes decryption corresponding to the encryption and / or integrity check corresponding to the integrity protection.
6. The method according to any one of claims 1 to 5, wherein The response from the NFp is based on a match, correspondence, or relationship between the vendor ID registered with the NRF and the vendor ID included in the request.
7. The method according to any one of claims 1 to 6 further comprises: Performing (520) a discovery process with the NRF to identify the NFp based on the first analysis ID, wherein the request is sent in response to the discovery process.
8. The method according to any one of claims 1 to 7, wherein One or more of the following apply: The NFc is an analysis logic function AnLF of a network data analysis function NWDAF; and The NFp is a model training logic function MTLF of a network data analysis function NWDAF.
9. A method for a producer network function NFp in a communication network, the method comprising: Receiving (650) from a consumer NF "NFc" of the communication network a request for a machine learning ML model generated, owned, and / or maintained by the NFp, wherein the request includes a first analysis identifier ID associated with the ML model and a vendor ID associated with the NFc; Obtaining (660) a configuration file associated with the NFc from a network repository function NRF of the communication network; Authorizing (670) the NFc to access the ML model based on a match, correspondence, or relationship between the vendor ID included in the obtained NF configuration file and the vendor ID included in the request; Based on the authorization of the NFC (670), a response is sent (680) to the NFC, the response including a Uniform Resource Locator (URL) associated with a second NF of the communication network, from which the ML model can be obtained.
10. The method according to claim 9, wherein The authorization (670) of the NFC to access the ML model is further based on a match, correspondence, or relationship between the vendor ID included in the request and an interoperability ID associated with the NFp and the ML model.
11. The method according to any one of claims 9 to 10, further comprising: Based on the authorization of the NFC (670), the list of permitted NF instances associated with the ML model is updated (685) to include an identifier associated with the NFC.
12. The method according to claim 11 further comprises: An update request is sent (690) to the Analytical Data Repository Function (ADRF) of the communication network, the update request including the updated list of permitted NF instances associated with the ML model and an association ID.
13. The method according to any one of claims 9 to 12, wherein: The second NF associated with the URL is the NFp, and The method further includes: subsequently providing (695) the ML model to the NFC using the URL associated with the NFp.
14. The method according to claim 13, wherein The providing (695) of the ML model to the NFC is based on a match, correspondence, or relationship between the identifier associated with the NFC and the list of permitted NF instances associated with the ML model.
15. The method according to any one of claims 9 to 12, wherein: The second NF associated with the URL is the Analytical Data Repository Function (ADRF) of the communication network, and The method further includes: Sending (620) a first request to the ADRF to store the ML model, wherein the first request includes an association ID associated with the ML model and a URL associated with the NFp, from which the ML model can be obtained; Providing (630) the ML model to the ADRF using the URL associated with the NFp; and Receiving (640) a first response from the ADRF, the first response including a URL associated with the ADRF, which is sent to the NFC in the response.
16. The method according to claim 15, wherein: The method further includes: selecting (615) an ADRF instance for storing the ML model; The ADRF instance is associated with an ADRF ID; Sending the first request to the ADRF instance; and The providing (630) of the ML model to the ADRF is based on a match, correspondence, or relationship between the ADRF ID and the ADRF to which the ML model is provided.
17. The method according to any one of claims 9 to 16, further comprising: Performing (610) a first security operation on the ML model, wherein the first security operation includes encryption and / or integrity protection.
18. The method according to any one of claims 9 to 17, wherein, One or more of the following apply: The NFC is the Analytical Logic Function (AnLF) of the Network Data Analytics Function (NWDAF); and The NFp is the Model Training Logic Function (MTLF) of the Network Data Analytics Function (NWDAF).
19. A method for a Network Repository Function NRF of a communication network, the method comprising: Registering (710) the following information in a profile of a consumer NF "NFc" of the communication network: A vendor identifier ID associated with the NFc, and One or more analysis IDs associated with an ML model supported by the NFc, the one or more analysis IDs including a first analysis ID associated with a first ML model generated, owned, and / or maintained by a producer NF "NFp" of the communication network; Receiving (730) a request for the profile of the NFc from the NFp; And In response to the request, sending (740) the profile of the NFc to the NFp.
20. The method according to claim 19 further comprises: Performing (720) a discovery process with the NFc to identify the NFp based on the first analysis ID.
21. The method according to any one of claims 19 to 20, wherein One or more of the following apply: The NFc is an analysis logic function AnLF of a Network Data Analytics Function NWDAF; and The NFp is a model training logic function MTLF of a Network Data Analytics Function NWDAF.
22. A method for an Analysis Data Repository Function ADRF of a communication network, the method comprising: Receiving (810) a first request to store a machine learning ML model from a producer network function NFp of the communication network, wherein the first request includes an association identifier ID associated with the ML model and a Uniform Resource Locator URL associated with the NFp, from which the ML model can be obtained; Obtaining (820) the ML model from the NFp using the URL associated with the NFp; Storing (830) the obtained ML model in association with the association ID; and Sending (840) a first response to the NFp, the first response including a URL associated with the ADRF, from which the ML model can be obtained.
23. The method according to claim 22, further comprising: Receiving (850) an update request from the NFp, the update request including the association ID and a list of allowed NF instances; And Based on a match between the association ID included in the update request and the association ID stored in association with the ML model, storing (860) the list of allowed NF instances in association with the ML model, wherein the list of allowed NF instances includes one or more identifiers associated with corresponding NFs of the communication network allowed to access the ML model.
24. The method according to any one of claims 22 to 23, further comprising: Providing (870) the ML model to a consumer network function NFc of the communication network using the URL associated with the ADRF.
25. The method according to claim 24, wherein, Providing (870) the ML model to the NFc is based on a match, correspondence, or relationship between an identifier associated with the NFc and an identifier included in the list of allowed NF instances stored in association with the ML model.
26. The method according to any one of claims 24 to 25, wherein One or more of the following apply: The NFc is an analysis logic function AnLF of a Network Data Analytics Function NWDAF; and The NFp is a model training logic function (MTLF) of a network data analytics function (NWDAF).
27. The method according to any one of claims 22 to 26, wherein The obtained ML model is encrypted and / or integrity protected.
28. A network device (908, 1100, 1300) configured to implement a consumer network function NFc (410) of a communication network (198, 200, 902), wherein, The network device includes: Communication interface circuits (1106, 1304) configured to communicate with network devices of other network functions (NFs) implementing the communication network; and Processing circuits (1102, 1304) operably coupled to the communication interface circuits, wherein the processing circuits and the communication interface circuits are configured to: Register the following items with a network repository function (NRF) (420) of the communication network: A vendor identifier (ID) associated with the NFc, and One or more analysis IDs associated with an ML model supported by the NFc, the one or more analysis IDs including a first analysis ID associated with an ML model generated, owned, and / or maintained by a producer NF "NFp" (430) of the communication network; Send a request for the ML model to the NFp, wherein the request includes the first analysis ID and the vendor ID associated with the NFc; and Receive a response from the NFp, the response including a uniform resource locator (URL) associated with a second NF of the communication network, from which the ML model can be obtained.
29. The network device according to claim 28, wherein, The processing circuits and the communication interface circuits are further configured to perform operations corresponding to any of the methods according to claims 2 to 8.
30. A network device (908, 1100, 1300) configured to implement a consumer network function NFc (410) of a communication network (198, 200, 902), wherein, The network device is further configured to: Register the following items with a network repository function (NRF) (420) of the communication network: A vendor identifier (ID) associated with the NFc, and One or more analysis IDs associated with an ML model supported by the NFc, the one or more analysis IDs including a first analysis ID associated with an ML model generated, owned, and / or maintained by a producer NF "NFp" (430) of the communication network; Send a request for the ML model to the NFp, wherein the request includes the first analysis ID and the vendor ID associated with the NFc; and Receive a response from the NFp, the response including a uniform resource locator (URL) associated with a second NF of the communication network, from which the ML model can be obtained.
31. The network device according to claim 31 is further configured to perform operations corresponding to any of the methods according to claims 2 to 8.
32. A non-transitory computer-readable medium (1104, 1304) storing computer-executable instructions that, when executed by a processing circuit (1102, 1304) associated with a consumer network function (NFc) (410) of a communication network (198, 200, 902), configure the NFc to perform operations corresponding to any of the methods according to claims 1 to 8.
33. A computer program product (1104a, 1304a) comprising computer-executable instructions which, when executed by a processing circuit (1102, 1304) associated with a consumer network function NFc (410) of a communication network (198, 200, 902), configure the NFc to perform operations corresponding to any of the methods according to claims 1 to 8.
34. A network device (908, 1100, 1300) configured to implement a producer network function NFp (430) of a communication network (198, 200, 902), wherein, The network device comprises: a communication interface circuit (1106, 1304) configured to communicate with a network device implementing other network functions NF of the communication network; and a processing circuit (1102, 1304) operably coupled to the communication interface circuit, wherein the processing circuit and the communication interface circuit are configured to: receive, from a consumer NF "NFc" (410) of the communication network, a request for a machine learning ML model generated, owned, and / or maintained by the NFp, wherein the request includes a first analysis identifier ID associated with the ML model and a vendor ID associated with the NFc; obtain, from a network repository function NRF (420) of the communication network, a configuration file associated with the NFc; authorize access by the NFc to the ML model based on a match, correspondence, or relationship between the vendor ID included in the obtained NF configuration file and the vendor ID included in the request; and send, based on authorizing the NFc, a response to the NFc, the response including a uniform resource locator URL associated with a second NF (430, 440) of the communication network, from which the ML model can be obtained.
35. The network device according to claim 34, wherein, The processing circuit and the communication interface circuit are further configured to perform operations corresponding to any of the methods according to claims 10 to 18.
36. A network device (908, 1100, 1300) configured to implement a producer network function NFp (430) of a communication network (198, 200, 902), wherein, The network device is further configured to: receive, from a consumer NF "NFc" (410) of the communication network, a request for a machine learning ML model generated, owned, and / or maintained by the NFp, wherein the request includes a first analysis identifier ID associated with the ML model and a vendor ID associated with the NFc; obtain, from a network repository function NRF (420) of the communication network, a configuration file associated with the NFc; authorize access by the NFc to the ML model based on a match, correspondence, or relationship between the vendor ID included in the obtained NF configuration file and the vendor ID included in the request; and send, based on authorizing the NFc, a response to the NFc, the response including a uniform resource locator URL associated with a second NF (430, 440) of the communication network, from which the ML model can be obtained.
37. The network device according to claim F3, further configured to perform operations corresponding to any of the methods according to claims 10 to 18.
38. A non - transitory computer - readable medium (1104, 1304) storing computer - executable instructions, which, when executed by a processing circuit (1102, 1304) associated with a producer network function NFp (430) of a communication network (198, 200, 902), configure the NFp to perform operations corresponding to any of the methods according to claims 9 to 18.
39. A computer program product (1104a, 1304a) comprising computer - executable instructions, which, when executed by a processing circuit (1102, 1304) associated with a producer network function NFp (430) of a communication network (198, 200, 902), configure the NFc to perform operations corresponding to any of the methods according to claims 9 to 18.
40. A network device (908, 1100, 1300) configured to implement a network repository function NRF (420) of a communication network (198, 200, 902), wherein, The network device includes: A communication interface circuit (1106, 1304) configured to communicate with network devices of other network functions NF that implement the communication network; and A processing circuit (1102, 1304) operably coupled to the communication interface circuit, wherein the processing circuit and the communication interface circuit are configured to: Register the following information in a profile of a consumer NF "NFc" of the communication network: A supplier identifier ID associated with the NFc, and One or more analysis IDs associated with an ML model supported by the NFc, the one or more analysis IDs including a first analysis ID associated with a first ML model generated, owned, and / or maintained by a producer NF "NFp" (430) of the communication network; Receive a request for the profile of the NFc from the NFp; and In response to the request, send the profile of the NFc to the NFp.
41. The network device according to claim 40, wherein, The processing circuit and the communication interface circuit are further configured to perform operations corresponding to any of the methods according to claims 20 to 21.
42. A network device (908, 1100, 1300) configured to implement a network repository function NRF (420) of a communication network (198, 200, 902), wherein, The network device is further configured to: Register the following information in a profile of a consumer NF "NFc" of the communication network: A supplier identifier ID associated with the NFc, and One or more analysis IDs associated with an ML model supported by the NFc, the one or more analysis IDs including a first analysis ID associated with a first ML model generated, owned, and / or maintained by a producer NF "NFp" (430) of the communication network; Receive a request for the profile of the NFc from the NFp; And In response to the request, send the profile of the NFc to the NFp.
43. The network device according to claim 42, further configured to perform operations corresponding to any of the methods according to claims 20 to 21.
44. A non-transitory computer-readable medium (1104, 1304) storing computer-executable instructions which, when executed by a processing circuit (1102, 1304) associated with a network repository function NRF (420) of a communication network (198, 200, 902), configure the NRF to perform operations corresponding to any of the methods according to claims 19 to 21.
45. A computer program product (1104a, 1304a) comprising computer-executable instructions which, when executed by a processing circuit (1102, 1304) associated with a network repository function NRF (420) of a communication network (198, 200, 902), configure the NRF to perform operations corresponding to any of the methods according to claims 19 to 21.
46. A network device (908, 1100, 1300) configured to implement an analytical data repository function ADRF (440) of a communication network (198, 200, 902), wherein, The network device comprises: A communication interface circuit (1106, 1304) configured to communicate with a network device implementing other network functions NF of the communication network; and A processing circuit (1102, 1304) operably coupled to the communication interface circuit, wherein the processing circuit and the communication interface circuit are configured to: Receive, from a producer network function NFp of the communication network, a first request to store a machine learning ML model, wherein the first request includes an association identifier ID associated with the ML model and a uniform resource locator URL associated with the NFp, from which the ML model can be obtained; Obtain the ML model from the NFp using the URL associated with the NFp; Store the obtained ML model in association with the association ID; and Send a first response to the NFp, the first response including a URL associated with the ADRF, from which the ML model can be obtained.
47. The network device according to claim 46, wherein, The processing circuit and the communication interface circuit are configured to perform operations corresponding to any of the methods according to claims 23 to 27.
48. A network device (908, 1100, 1300) configured to implement an analytical data repository function ADRF (440) of a communication network (198, 200, 902), wherein, The network device is further configured to: Receive, from a producer network function NFp of the communication network, a first request to store a machine learning ML model, wherein the first request includes an association identifier ID associated with the ML model and a uniform resource locator URL associated with the NFp, from which the ML model can be obtained; Obtain the ML model from the NFp using the URL associated with the NFp; Store the obtained ML model in association with the association ID; and Send a first response to the NFp, the first response including a URL associated with the ADRF, from which the ML model can be obtained.
49. The network device according to claim 48, further configured to perform operations corresponding to any of the methods according to claims 23 to 27.
50. A non - transitory computer - readable medium (1104, 1304) storing computer - executable instructions which, when executed by a processing circuit (1102, 1304) associated with an analysis data repository function ADRF (440) of a communication network (198, 200, 902), configure the ADRF to perform operations corresponding to any of the methods according to claims 22 to 27.
51. A computer program product (1104a, 1304a) comprising computer - executable instructions which, when executed by a processing circuit (1102, 1304) associated with an analysis data repository function ADRF (440) of a communication network (198, 200, 902), configure the ADRF to perform operations corresponding to any of the methods according to claims 22 to 27.