Communication method, system and device
By employing a key management mechanism at the group or task level in vertical federated learning to verify network element permissions, the data security risks in vertical federated learning are resolved, and the security of data processing is improved.
Patent Information
- Application Number
- CN202410592812.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-11
- Publication Date
- 2025-11-11
AI Technical Summary
In the process of vertical federated learning, data security risks are relatively high, and how to improve the data processing security of vertical federated learning is an urgent problem to be solved.
By determining keys at the group or task granularity level, network data in the vertical federated learning group is encrypted and decrypted. Combined with the key management mechanism, network element permissions are verified to ensure that only legitimate network elements can obtain and use the keys, preventing malicious use.
This enhances the data processing security of vertical federated learning, prevents malicious consumers from unauthorized use of vertical federated learning services, and ensures the security of data transmission and processing.
Smart Images

Figure CN120934778A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly to communication methods, systems and apparatus. Background Technology
[0002] Federated learning (FL) is a machine learning method that allows multiple stakeholders to collaborate on data processing. Vertical federated learning (VFL) is suitable when the data samples from multiple stakeholders have a high degree of overlap, but the data features have a low degree of overlap.
[0003] To address the diversification of future communication scenarios and enhance service experience, the 3rd Generation Partnership Project (3GPP) supports the introduction of vertical federated learning for intelligent data analysis in mobile communication networks. However, data security risks still exist in the current vertical federated learning process, and improving the security of data processing in vertical federated learning is a technical issue worthy of research. Summary of the Invention
[0004] This application provides a communication method, system, and apparatus that are beneficial for improving the security of data processing in vertical federated learning.
[0005] In a first aspect, this application provides a communication method, which may include: a first network element determining a first key; the first key being used for data encryption of all or some network elements in a first vertical federated learning group; the first network element receiving a first request message from a second network element; the first request message being used to request the first key, and / or, the first request message being used to request the use of a decryption key corresponding to the first key to decrypt first encrypted data; the first network element sending the first key and / or first decrypted data to the second network element; the first decrypted data being obtained by decrypting the first encrypted data using the decryption key corresponding to the first key, and the second network element being one of all or some network elements in the first vertical federated learning group. The use of the first key for data encryption of all or some network elements in the first vertical federated learning group can be understood as all or some network elements in the first vertical federated learning group using the first key to encrypt data related to vertical federated learning (e.g., intermediate data generated during model training, gradients, losses, sample identifiers, etc.).
[0006] Based on this communication method, the first network element, acting as the key manager, can determine the key at the group (consortium) granularity level or the key at the task granularity level, so that network elements in a vertical federated learning group can use the same key, or network elements in a vertical federated learning group participating in the same vertical federated learning task can use the same key.
[0007] In conjunction with the first aspect, in one possible implementation, the first key is used for data encryption of all network elements in the first vertical federated learning group. The determination of the first key by the first network element may include: the first network element receiving a discovery request message from a third network element; the discovery request message requesting the discovery of network elements in the first vertical federated learning group that wish to participate in the vertical federated learning; the discovery request message including group information of the first vertical federated learning group; and the first network element determining the first key based on the group information of the first vertical federated learning group. Therefore, when the first key is a group (consortium) granularity key, the first network element can determine the first key based on the group information of the first vertical federated learning group carried in the discovery request message.
[0008] In conjunction with the first aspect, in one possible implementation, the group information of the first vertical federated learning group includes one or more of the following: the group identifier of the first vertical federated learning group, the analysis identifier corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group.
[0009] In conjunction with the first aspect, in one possible implementation, the group information of the first vertical federated learning group can specifically be the group identifier of the first vertical federated learning group, or the analysis identifier corresponding to the first vertical federated learning group, or the interoperability identifier corresponding to the first vertical federated learning group.
[0010] In conjunction with the first aspect, in one possible implementation, the first network element determines the first key based on the group information of the first vertical federated learning group. This can include: the first network element determining the first key based on the mapping relationship between the group information of the first vertical federated learning group and the first key; the mapping relationship between the group information of the first vertical federated learning group and the first key is pre-configured. That is, the first network element can be pre-configured with mapping relationships between different federated learning groups and different keys, thereby directly obtaining the key corresponding to a federated learning group, which helps improve the efficiency of the first network element in determining the first key.
[0011] In conjunction with the first aspect, in one possible implementation, the first network element can also dynamically generate the first key based on the group information of the first vertical federated learning group, which is beneficial to improving the flexibility of the first network element in determining the first key.
[0012] In conjunction with the first aspect, in one possible implementation, the above method may further include: a first network element receiving an authorization request message from a third network element; the authorization request message is used to request authorization to obtain the vertical federated learning service provided by the target network element; the authorization request message includes group information of a first vertical federated learning group; if the first network element determines, based on the group information of the first vertical federated learning group, that the target network element and / or the third network element are located in the first vertical federated learning group, the first network element sends an authorization response message to the third network element; the authorization response message includes an access token, the access token including one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
[0013] In this context, the third network element can be understood as either the initiator of vertical federated learning or the consumer of the vertical federated learning service; in other words, the third network element can be the network element requesting the vertical federated learning service. Correspondingly, the target network element can be the network element providing the vertical federated learning service. Before the third network element uses the vertical federated learning service provided by the target network element, the first network element can verify its permissions, specifically verifying whether the third network element and / or the target network element are located in the requested vertical federated learning group. This prevents malicious vertical federated learning consumers from exceeding their authorized access to the vertical federated learning service, thus improving the security of data processing in vertical federated learning.
[0014] In conjunction with the first aspect, in one possible implementation, the above method may further include: a first network element determining one or more network elements in the first vertical federated learning group based on the group information and configuration information of the first vertical federated learning group; sending a discovery response message to a third network element; the discovery response message including the identifiers of one or more network elements in the first vertical federated learning group and a first key. It is evident that the first key can be carried in the discovery response message. In some embodiments, the first key can also be carried in other messages, and this application does not limit this.
[0015] In conjunction with the first aspect, in one possible implementation, the first request message includes group information of the first vertical federated learning group. The method further includes: the first network element determining whether the second network element is located in the first vertical federated learning group based on the group information of the first vertical federated learning group and the identifier of the second network element; if the second network element is located in the first vertical federated learning group, the first network element sends a first response message to the second network element; the first response message includes a first key and / or first decryption data, wherein the first decryption data is obtained by decrypting the first encrypted data using the decryption key corresponding to the first key. That is, when the first key is a group (consortium) level key, the first network element can verify whether the second network element requesting the first key and / or the first decryption data is located in the first vertical federated learning group, or in other words, it can verify whether the second network element has the authority to obtain the first key and / or obtain the first decryption data.
[0016] In conjunction with the first aspect, in one possible implementation, the first key is used for data encryption of some network elements in the first vertical federated learning group, and these network elements participate in the first vertical federated learning task. The first network element determines the first key, which may include: the first network element receiving a first task registration request message from a third network element; the first task registration request message being used to request the registration of task information for the first vertical federated learning task; and the first network element determining the first key based on the task information of the first vertical federated learning task. The task information of the first vertical federated learning task includes one or more of the following: the task identifier of the first vertical federated learning task, the identifiers of the network elements participating in the first vertical federated learning task, and the role information of the network elements participating in the first vertical federated learning task. Therefore, when the first key is a task-level key, the first network element can determine the first key based on the task information of the first vertical federated learning task carried in the task registration request message.
[0017] In conjunction with the first aspect, in one possible implementation, the task information of the first vertical federated learning task may specifically be the task identifier of the first vertical federated learning task, or the identifier of the network element participating in the first vertical federated learning task, or the role information of the network element participating in the first vertical federated learning task.
[0018] In conjunction with the first aspect, in one possible implementation, the above method may further include: the first network element sending a first task registration response message to the third network element; the first task registration response message includes information indicating successful registration of task information for the first vertical federated learning task and / or a first key. It is evident that the first key can be carried in the task registration response message. In some embodiments, the first key may also be carried in other messages, which is not limited in this application.
[0019] In conjunction with the first aspect, in one possible implementation, the first request message includes a task identifier for the first vertical federated learning task. The method may further include: a first network element determining whether the network elements participating in the first vertical federated learning task include the second network element based on the task identifier of the first vertical federated learning task and the identifier of the second network element; if the network elements participating in the first vertical federated learning task include the second network element, the first network element sends a first response message to the second network element; the first response message includes a first key and / or first decryption data, where the first decryption data is obtained by decrypting the first encrypted data using the decryption key corresponding to the first key. That is, when the first key is a task-level key, the first network element can verify whether the second network element requesting the first key and / or the first decryption data is a network element participating in the first vertical federated learning task, or in other words, it can verify whether the second network element has the authority to obtain the first key and / or obtain the first decryption data.
[0020] Secondly, this application provides another communication method, which may include: a third network element obtaining a first key from a first network element; the first key being used for data encryption of all or some network elements in a first vertical federated learning group; the third network element sending first instruction information to a second network element; the second network element being located in the first vertical federated learning group; the first instruction information being used to indicate the network element that provides the first key; the first instruction information including or specifically being the identifier of the first network element.
[0021] Based on this communication method, after the third network element obtains the first key, it can inform the second network element of the provider of the first key, so that the second network element can obtain the first key more efficiently. The first key can be a group (consortium) level key or a task level key.
[0022] In conjunction with the second aspect, in one possible implementation, the first key is used for data encryption of all network elements in the first vertical federated learning group; the third network element obtains the first key from the first network element, which may include: the third network element sending a discovery request message to the first network element, the discovery request message being used to request the discovery of the first vertical federated learning group that wishes to participate in the vertical federated learning, the discovery request message including the group information of the first vertical federated learning group; the third network element receiving a discovery response message from the first network element; the discovery response message including the identifiers of one or more network elements in the first vertical federated learning group and the first key. It can be seen that when the first key is a group (consortium) granularity key, the first key can be carried in the discovery response message.
[0023] In conjunction with the second aspect, in one possible implementation, the above method may further include: a third network element sending an authorization request message to a first network element; the authorization request message is used to request authorization or authorization to obtain (request) the vertical federated learning service provided by the target network element; the authorization request message includes group information of the first vertical federated learning group; the third network element receives an authorization response message from the first network element; the authorization response message includes an access token, which includes one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element. That is, before using the vertical federated learning service provided by the target network element, the third network element can request authorization from the first network element. If the third network element and / or the target network element are located in the requested vertical federated learning group, then the third network element can be authorized to obtain the vertical federated learning service provided by the target network element. This can prevent malicious vertical federated learning consumers from exceeding their authority to use the vertical federated learning service, and is beneficial to improving the security of data processing in vertical federated learning.
[0024] In conjunction with the second aspect, in one possible implementation, the above method may further include: a third network element sending a task preparation request message to a second network element; the task preparation request message is used to request participation in the first vertical federated learning task in the target vertical federated learning group; the task preparation request message includes an access token and group information of the target vertical federated learning group; the group information of the target vertical federated learning group includes or specifically includes one or more of the following: the group identifier of the target vertical federated learning group, the analysis identifier corresponding to the target vertical federated learning group, and the interoperability identifier corresponding to the target vertical federated learning group; the third network element receiving a task preparation response message from the second network element; the task preparation response message is used to instruct the second network element to agree to participate in the first vertical federated learning task. It is evident that the second network element can verify whether the parameters carried in the task preparation request message match the parameters in the access token. For example, the task preparation request message may include the group information of the target vertical federated learning group, and the group information of the target vertical federated learning group may include the interoperability identifier corresponding to the target vertical federated learning group; the second network element can verify whether the interoperability identifier matches the interoperability identifier in the access token. Alternatively, the task preparation request message may also be other request messages, such as a vertical federated service request message, a vertical federated training request message, etc.
[0025] In conjunction with the second aspect, in one possible implementation, the first key is used for data encryption of some network elements in the first vertical federated learning group, and these network elements participate in the first vertical federated learning task. The third network element obtains the first key from the first network element, which may include: the third network element sending a first task registration request message to the first network element; the first task registration request message requesting the registration of task information for the first vertical federated learning task; the third network element receiving a first task registration response message from the first network element; the first task registration response message including information indicating successful registration of the task information for the first vertical federated learning task and / or the first key; wherein, the task information for the first vertical federated learning task includes one or more of the following: the task identifier of the first vertical federated learning task, the identifiers of the network elements participating in the first vertical federated learning task, and the role information of the network elements participating in the first vertical federated learning task. Therefore, when the first key is a task-level key, the first key can be carried in the task registration response message.
[0026] In conjunction with the second aspect, in one possible implementation, the above method may further include: If a third network element determines that a first-type network element exists among the network elements participating in the first vertical federated learning task, it sends a second task registration request message to a fourth network element. The second task registration request message includes task information of the first vertical federated learning task and / or the identifier of the first network element. The third network element communicates with the first-type network element through the fourth network element. The fourth network element may be, for example, a Network Open Function (NEF) network element or a Service Communication Proxy (SCP) network element. That is, if the third network element needs to communicate indirectly with the network elements participating in the first vertical federated learning task through the fourth network element, then the third network element can register the task information of the first vertical federated learning task with the fourth network element.
[0027] Thirdly, this application provides another communication method, which may include: a fourth network element receiving a second task registration request message from a third network element, the second task registration request message including information of a first vertical federated learning task and / or the identifier of the first network element; the first network element being a network element providing a first key; the first key being used by network elements participating in the first vertical federated learning task to encrypt data; the information of the first vertical federated learning task including one or more of the following: the task identifier of the first vertical federated learning task, the identifier of the network elements participating in the first vertical federated learning task, and the group information of the vertical federated learning group corresponding to the first vertical federated learning task; the fourth network element receiving a first request message from a second network element; the first request message being used to request the first key, and / or, the first request message being used to request the use of the decryption key corresponding to the first key to decrypt the first encrypted data.
[0028] Based on this communication method, the fourth network element can store the task information of the first vertical federated learning task, and the fourth network element can know the network element that provides the first key. Thus, when the fourth network element receives a key request and / or decryption request, it can decide whether to forward the request to the network element that provides the first key based on the stored task information of the first vertical federated learning task.
[0029] In conjunction with the third aspect, in one possible implementation, the first request message includes the task identifier of the first vertical federated learning task. The method may further include: if the fourth network element determines, based on the task identifier and information of the first vertical federated learning task, that the network elements participating in the first vertical federated learning task include the second network element, then the fourth network element forwards the first request message to the first network element. It is evident that, since the fourth network element stores information related to the first vertical federated learning task, upon receiving the first request message, the fourth network element can first verify its identity based on the relevant information related to the first vertical federated learning task. If the first key is at the task granularity level, and the second network element is a network element participating in the first vertical federated learning task, then the second network element passes the verification.
[0030] In conjunction with the third aspect, in one possible implementation, the first request message includes group information of the vertical federated learning group corresponding to the first vertical federated learning task. The method may further include: if the fourth network element determines, based on the group information of the vertical federated learning group corresponding to the first vertical federated learning task and the information of the first vertical federated learning task, that the second network element is located in the vertical federated learning group corresponding to the first vertical federated learning task, then the fourth network element forwards the first request message to the first network element. That is, if the first key is a group (consortium) level key, and the fourth network element determines that the second network element is a network element of that federated learning group based on the stored group information of the vertical federated learning group corresponding to the first vertical federated learning task, then the second network element passes the verification.
[0031] Fourthly, this application provides a communication method, which may include: a second network element obtaining a first key; the first key being used for data encryption of all or some network elements in a first vertical federated learning group; the second network element being located in the first vertical federated learning group; the second network element determining first encrypted data based on the first key; the second network element sending a decryption request message to the first network element; the decryption request message being used to request the use of the decryption key corresponding to the first key to decrypt the first encrypted data, and the decryption request message including the first encrypted data.
[0032] Based on this communication method, the second network element can obtain the first key and use it to encrypt data. It can also request the first network element, acting as the key manager, to decrypt the data using the decryption key corresponding to the first key. This improves the security of data processing in vertical federated learning.
[0033] In conjunction with the fourth aspect, in one possible implementation, the second network element obtaining the first key may include: the second network element obtaining the first key according to a predefined first key generation strategy; the first key generation strategy includes any of the following: the first key is the group identifier of the first vertical federated learning group, or the first key is the task identifier of the first vertical federated learning task. It is evident that in this approach, the second network element does not need to request the first key from the first network element, but can directly determine the first key based on the predefined key generation strategy. Optionally, when the first key is a group (consortium) granularity key, the group identifier of the vertical federated learning group can be used as the first key; when the first key is a task granularity key, the task identifier of the vertical federated learning task can be used as the first key.
[0034] In conjunction with the fourth aspect, in one possible implementation, the first key is used for data encryption of all network elements in the first vertical federated learning group. The second network element obtaining the first key may include: the second network element sending a first key request message to the first network element; the first key request message is used to request the first key; the first key request message includes group information of the first vertical federated learning group and the identifier of the second network element; the group information of the first vertical federated learning group and the identifier of the second network element are used to verify that the second network element is a network element in the first vertical federated learning group; the second network element receives a first key response message from the first network element; the first key response message includes the first key. Therefore, in this method, the second network element can request the first key from the first network element. When the first key is a group (consortium) level key, the first key request message sent by the second network element can carry the group information of the first vertical federated learning group, so that the first network element can verify the second network element based on the stored configuration information and the received group information of the first vertical federated learning group.
[0035] In conjunction with the fourth aspect, in one possible implementation, the first key is used for data encryption of some network elements in the first vertical federated learning group. These network elements participate in the first vertical federated learning task, and one of them includes the second network element. The second network element obtains the first key by: the second network element sending a second key request message to the first network element; the second key request message requesting the first key; the second key request message including the task identifier of the first vertical federated learning task and the identifier of the second network element; the task identifier of the first vertical federated learning task and the identifier of the second network element used to verify that the second network element is a network element participating in the first vertical federated learning task; the second network element receiving a second key response message from the first network element; the second key response message including the first key. Therefore, when the first key is a task-level key, the first key request message sent by the second network element can carry the task identifier of the first vertical federated learning task, so that the first network element can verify the second network element based on the stored task information of the first vertical federated learning task and the received task identifier of the first vertical federated learning task.
[0036] Fifthly, this application provides a communication method, which may include: a first network element receiving an authorization request message from a third network element; the authorization request message is used to request authorization or to authorize access to the vertical federated learning service provided by the target network element; the authorization request message includes group information of a first vertical federated learning group requesting participation in the vertical federated learning; the first network element determines whether to authorize the third network element to use the vertical federated learning service provided by the target network element based on the group information of the first vertical federated learning group.
[0037] Based on this communication method, when a third network element requests the use of the vertical federated learning service provided by the target network element from the first network element, the first network element can determine whether to authorize the third network element to use the vertical federated learning service provided by the target network element based on the group information of the first vertical federated learning group. This can prevent malicious vertical federated learning service consumers from exceeding their authority to use the vertical federated learning service, and is conducive to improving the security of data processing in vertical federated learning.
[0038] In conjunction with the fifth aspect, in one possible implementation, the first network element determines whether to authorize the third network element to use the vertical federated learning service provided by the target network element based on the group information of the first vertical federated learning group. This can include: the first network element determining whether the third network element and / or the target network element are located in the first vertical federated learning group based on the group information of the first vertical federated learning group; if the third network element and / or the target network element are located in the first vertical federated learning group, the first network element sends an authorization response message to the third network element; the authorization response message includes an access token, which includes one or more of the following: the group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element. In other words, the first network element can verify whether the third network element and / or the target network element are located in its claimed vertical federated learning group. If the third network element and / or the target network element are located in its claimed vertical federated learning group, then the first network element is authorized to use the vertical federated learning service provided by the target network element. This approach can prevent the third network element from forging information about the vertical federated learning group and / or the target network element, thereby improving the security of data processing in vertical federated learning.
[0039] In this embodiment of the application, the fact that the third network element and / or the target network element are located in the first vertical federated learning group can be understood as the member list of the first vertical federated learning group including the third network element and / or the target network element, or the third network element and / or the target network element supporting the first vertical federated learning group, or the third network element and / or the target network element having the right to use the vertical federated learning service in the first vertical federated learning group, or the third network element and / or the target network element having the right to participate in the vertical federated learning task in the first vertical federated learning group.
[0040] In conjunction with the fifth aspect, in one possible implementation, the group information of the first vertical federated learning group includes one or more of the following: the group identifier of the first vertical federated learning group, the analysis identifier corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group.
[0041] In conjunction with the fifth aspect, in one possible implementation, the group information of the first vertical federated learning group can specifically be the group identifier of the first vertical federated learning group, or the analysis identifier corresponding to the first vertical federated learning group, or the interoperability identifier corresponding to the first vertical federated learning group.
[0042] In conjunction with the fifth aspect, in one possible implementation, the first network element determines whether the third network element and / or the target network element is located in the first vertical federated learning group based on the group information of the first vertical federated learning group. This can include: the first network element determining whether the group information of the first vertical federated learning group is located in the group information of at least one vertical federated learning group supported by the third network element and / or the target network element; if the group information of the first vertical federated learning group is located in the group information of at least one vertical federated learning group supported by the third network element and / or the target network element, the first network element and / or the target network element is determined to be located in the first vertical federated learning group; wherein, the group information of the first vertical federated learning group includes one or more of the following: the group identifier of the first vertical federated learning group, the analysis identifier corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group. Alternatively, the group information of the first vertical federated learning group can consist of one or more of the group identifier of the first vertical federated learning group, the analysis identifier corresponding to the first vertical federated learning group, and the interoperability identifier corresponding to the first vertical federated learning group. The group information of at least one vertical federated learning group supported by the third network element and / or the target network element may consist of one or more of the following: the group identifier of the vertical federated learning group, the analysis identifier corresponding to the vertical federated learning group, and the interoperability identifier corresponding to the vertical federated learning group. Optionally, the group information of the first vertical federated learning group may be the same as or different from the group information of a vertical federated learning group supported by the third network element and / or the target network element.
[0043] In a sixth aspect, this application provides a communication system, which may include: a first network element, a second network element, and a third network element; the first network element is used to determine a first key and send the first key to the third network element; the first key is used for data encryption of all or some network elements in a first vertical federated learning group; the third network element is used to receive the first key from the first network element and send the identifier of the first network element to all or some network elements in the first vertical federated learning group; the identifier of the first network element is used by all or some network elements in the first vertical federated learning group to know the network element that provided the first key; the second network element is used to send a first request message to the first network element based on the identifier of the first network element; the first request message is used to request the first key, and / or, the first request message is used to request the decryption key corresponding to the first key to decrypt the first encrypted data.
[0044] In a seventh aspect, this application provides a communication device, which can be the first network element in the first aspect described above, or a device containing the first network element, or a device contained in the first network element, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the first aspect. These modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned functions.
[0045] In conjunction with the seventh aspect, in one possible implementation, the communication device includes: a processing module and a communication module. The processing module is used to determine a first key; the first key is used for data encryption of all or some network elements in a first vertical federated learning group; the communication module is used to receive a first request message from a second network element; the first request message is used to request the first key, and / or, the first request message is used to request data decryption of the first encrypted data using the decryption key corresponding to the first key.
[0046] In conjunction with the seventh aspect, in one possible implementation, the first key is used for data encryption of all network elements in the first vertical federated learning group, and the communication module is also used to receive a discovery request message from a third network element; the discovery request message is used to request the discovery of network elements in the first vertical federated learning group that wish to participate in vertical federated learning, and the discovery request message includes group information of the first vertical federated learning group; the processing module is also used to determine the first key based on the group information of the first vertical federated learning group.
[0047] In conjunction with the seventh aspect, in one possible implementation, the group information of the first vertical federated learning group includes one or more of the following: the group identifier of the first vertical federated learning group, the analysis identifier corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group.
[0048] In conjunction with the seventh aspect, in one possible implementation, the processing module is further configured to determine the first key based on the mapping relationship between the group information of the first vertical federated learning group and the first key; the mapping relationship between the group information of the first vertical federated learning group and the first key is pre-configured.
[0049] In conjunction with the seventh aspect, in one possible implementation, the communication module is further configured to receive an authorization request message from a third network element; the authorization request message is used to request authorization to obtain the vertical federated learning service provided by the target network element; the authorization request message includes group information of the first vertical federated learning group; the processing module is further configured to send an authorization response message to the third network element if, based on the group information of the first vertical federated learning group, it is determined that the target network element and / or the third network element are located in the first vertical federated learning group; the authorization response message includes an access token, which includes one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
[0050] In conjunction with the seventh aspect, in one possible implementation, the processing module is further configured to determine one or more network elements in the first vertical federated learning group based on the group information and configuration information of the first vertical federated learning group; the communication module is further configured to send a discovery response message to the third network element; the discovery response message includes the identifier of one or more network elements in the first vertical federated learning group and the first key.
[0051] In conjunction with the seventh aspect, in one possible implementation, the first request message includes group information of the first vertical federated learning group. The processing module is further configured to determine whether the second network element is located in the first vertical federated learning group based on the group information of the first vertical federated learning group and the identifier of the second network element. If the second network element is located in the first vertical federated learning group, the first network element sends a first response message to the second network element. The first response message includes a first key and / or first decryption data, wherein the first decryption data is obtained by decrypting the first encrypted data using the decryption key corresponding to the first key.
[0052] In conjunction with the seventh aspect, in one possible implementation, the first key is used for data encryption of some network elements in the first vertical federated learning group, and some network elements participate in the first vertical federated learning task; the communication module is also used to receive a first task registration request message from a third network element; the first task registration request message is used to request the registration of task information for the first vertical federated learning task; the processing module is also used to determine the first key based on the task information of the first vertical federated learning task.
[0053] In conjunction with the seventh aspect, in one possible implementation, the communication module is further configured to send a first task registration response message to the third network element; the first task registration response message includes information indicating successful registration of the task information for the first vertical federated learning task and a first key.
[0054] In conjunction with the seventh aspect, in one possible implementation, the first request message includes a task identifier for the first vertical federated learning task; the processing module is further configured to: determine whether the network elements participating in the first vertical federated learning task include the second network element based on the task identifier of the first vertical federated learning task and the identifier of the second network element; if the network elements participating in the first vertical federated learning task include the second network element, the first network element sends a first response message to the second network element; the first response message includes a first key and / or first decryption data, wherein the first decryption data is obtained by decrypting the first encrypted data using the decryption key corresponding to the first key.
[0055] Eighthly, this application provides another communication device, which can be the third network element in the second aspect described above, or a device containing the third network element, or a device contained in the third network element, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the second aspect. These modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions described above.
[0056] In conjunction with aspect eight, in one possible implementation, the communication device includes: a processing module and a communication module. The processing module is used to acquire a first key from a first network element; the first key is used for data encryption of all or some network elements in a first vertical federated learning group. The communication module is used to send first indication information to a second network element; the second network element is located in the first vertical federated learning group; the first indication information is used to indicate the network element that provided the first key; the first indication information includes an identifier of the first network element.
[0057] In conjunction with aspect eight, in one possible implementation, the first key is used for data encryption of all network elements in the first vertical federated learning group; the communication module is further used to send a discovery request message to the first network element, the discovery request message being used to request the discovery of the first vertical federated learning group that wishes to participate in the vertical federated learning, the discovery request message including group information of the first vertical federated learning group; and to receive a discovery response message from the first network element; the discovery response message including the identifiers of one or more network elements in the first vertical federated learning group and the first key.
[0058] In conjunction with aspect eight, in one possible implementation, the communication module is further configured to send an authorization request message to the first network element; the authorization request message is used to request the use of the vertical federated learning service provided by the target network element; the authorization request message includes group information of the first vertical federated learning group; and receive an authorization response message from the first network element; the authorization response message includes an access token, which includes one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
[0059] In conjunction with aspect eight, in one possible implementation, the communication module is further configured to send a task preparation request message to the second network element; the task preparation request message is used to request participation in the first vertical federated learning task in the target vertical federated learning group; the task preparation request message includes an access token and group information of the target vertical federated learning group; the group information of the target vertical federated learning group includes one or more of the following: the group identifier of the target vertical federated learning group, the analysis identifier corresponding to the target vertical federated learning group, and the interoperability identifier corresponding to the target vertical federated learning group; and receive a task preparation response message from the second network element; the task preparation response message is used to instruct the second network element to agree to participate in the first vertical federated learning task.
[0060] In conjunction with aspect eight, in one possible implementation, the first key is used for data encryption of some network elements in the first vertical federated learning group, and some network elements participate in the first vertical federated learning task; the communication module is further used to send a first task registration request message to the first network element; the first task registration request message is used to request the registration of task information for the first vertical federated learning task; and to receive a first task registration response message from the first network element; the first task registration response message includes information indicating successful registration of task information for the first vertical federated learning task and / or the first key; wherein, the task information for the first vertical federated learning task includes one or more of the following: the task identifier of the first vertical federated learning task, the identifier of the network element participating in the first vertical federated learning task, and the role information of the network element participating in the first vertical federated learning task.
[0061] In conjunction with the eighth aspect, in one possible implementation, the communication module is further configured to send a second task registration request message to the fourth network element when it is determined that there is a first type of network element among the network elements participating in the first vertical federated learning task; the second task registration request message includes task information of the first vertical federated learning task and / or the identifier of the first network element, and the third network element communicates with the first type of network element through the fourth network element.
[0062] Ninthly, this application provides yet another communication device, which can be the fourth network element in the third aspect described above, or a device containing the fourth network element, or a device contained in the fourth network element, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the third aspect. These modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned functions.
[0063] In conjunction with aspect nine, in one possible implementation, the communication device includes a processing module and a communication module. The communication module is configured to receive a second task registration request message from a third network element, the second task registration request message including information about a first vertical federated learning task and / or the identifier of the first network element; the first network element is a network element that provides a first key; the first key is used by the network elements participating in the first vertical federated learning task to encrypt data; the information about the first vertical federated learning task includes one or more of the following: the task identifier of the first vertical federated learning task, the identifiers of the network elements participating in the first vertical federated learning task, and the group information of the vertical federated learning group corresponding to the first vertical federated learning task; and to receive a first request message from a second network element; the first request message is used to request the first key, and / or, the first request message is used to request the use of the decryption key corresponding to the first key to decrypt the first encrypted data.
[0064] In conjunction with aspect nine, in one possible implementation, the first request message includes a task identifier for the first vertical federated learning task; the processing module is configured to forward the first request message to the first network element if, based on the task identifier and information of the first vertical federated learning task, it is determined that the network element participating in the first vertical federated learning task includes the second network element.
[0065] In conjunction with the ninth aspect, in one possible implementation, the first request message includes group information of the vertical federated learning group corresponding to the first vertical federated learning task; the processing module is used to forward the first request message to the first network element when it is determined, based on the group information of the vertical federated learning group corresponding to the first vertical federated learning task and the information of the first vertical federated learning task, that the second network element is located in the vertical federated learning group corresponding to the first vertical federated learning task.
[0066] In a tenth aspect, this application provides yet another communication device, which can be the second network element in the fourth aspect described above, or a device containing the second network element, or a device contained in the second network element, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the fourth aspect. These modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the aforementioned functions.
[0067] In conjunction with the tenth aspect, in one possible implementation, the communication device includes: a processing module and a communication module. The processing module is configured to acquire a first key; the first key is used for data encryption of all or some network elements in a first vertical federated learning group; and determine first encrypted data based on the first key. The communication module is configured to send a decryption request message to the first network element; the decryption request message requests the use of the decryption key corresponding to the first key to decrypt the first encrypted data, and the decryption request message includes the first encrypted data.
[0068] In conjunction with the tenth aspect, in one possible implementation, the processing module is further configured to obtain a first key according to a predefined first key generation strategy; the first key generation strategy includes any one of the following: the first key is a group identifier of a first vertical federated learning group, or the first key is a task identifier of a first vertical federated learning task.
[0069] In conjunction with aspect ten, in one possible implementation, the first key is used for data encryption of all network elements in the first vertical federated learning group; the communication module is further used to send a first key request message to the first network element; the first key request message is used to request the first key; the first key request message includes group information of the first vertical federated learning group and the identifier of the second network element; the group information of the first vertical federated learning group and the identifier of the second network element are used to verify that the second network element is a network element in the first vertical federated learning group; and a first key response message is received from the first network element; the first key response message includes the first key.
[0070] In conjunction with aspect ten, in one possible implementation, the first key is used for data encryption of some network elements in the first vertical federated learning group, some network elements participating in the first vertical federated learning task, and some network elements including the second network element; the communication module is further configured to send a second key request message to the first network element; the second key request message is used to request the first key; the second key request message includes the task identifier of the first vertical federated learning task and the identifier of the second network element; the task identifier of the first vertical federated learning task and the identifier of the second network element are used to verify that the second network element is a network element participating in the first vertical federated learning task; and the module receives a second key response message from the first network element; the second key response message includes the first key.
[0071] Eleventhly, this application provides yet another communication device, which can be the first network element in the fifth aspect above, or a device containing the first network element, or a device contained in the first network element, such as a chip. The communication device includes corresponding modules, units, or means for implementing the method described in the first aspect above. These modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions.
[0072] In conjunction with the eleventh aspect, in one possible implementation, the communication device includes a processing module and a communication module. The communication module is configured to receive an authorization request message from a third network element; the authorization request message requests the use of the vertical federated learning service provided by the target network element; the authorization request message includes group information of a first vertical federated learning group requesting participation in the vertical federated learning; the processing module is configured to determine, based on the group information of the first vertical federated learning group, whether to authorize the third network element to use the vertical federated learning service provided by the target network element.
[0073] In conjunction with the eleventh aspect, in one possible implementation, the processing module is further configured to determine whether the third network element and / or the target network element are located in the first vertical federated learning group based on the group information of the first vertical federated learning group; the communication module is further configured to send an authorization response message to the third network element when the third network element and / or the target network element are located in the first vertical federated learning group; the authorization response message includes an access token, which includes one or more of the following: the group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
[0074] In conjunction with the eleventh aspect, in one possible implementation, the group information of the first vertical federated learning group includes one or more of the following: the group identifier of the first vertical federated learning group, the analysis identifier corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group.
[0075] In a twelfth aspect, this application provides yet another communication device, which includes a processor and an interface circuit. The interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor, or to send signals from the processor to other communication devices outside the communication device. The processor is used through logic circuits or execution code instructions to implement the method as described in any of the possible implementations of the first to fifth aspects.
[0076] In a thirteenth aspect, this application provides a communication chip that stores instructions that, when the chip is operated on a communication device, cause the method described in any one of the first to fifth aspects to be implemented.
[0077] In a fourteenth aspect, this application provides a computer-readable storage medium storing a computer program or instructions that, when executed on a communication device, enable the communication device to perform the methods described in any one of the first to fifth aspects.
[0078] In a fifteenth aspect, this application provides a computer program product containing instructions, including computer program code, which, when run on a communication device, enables the communication device to perform the method described in any one of the first to fifth aspects. Attached Figure Description
[0079] Figure 1 This is a schematic diagram of a network architecture applicable to the embodiments of this application;
[0080] Figure 2 A schematic diagram illustrating the process of an NF service consumer registering with an NRF, provided as an embodiment of this application;
[0081] Figure 3 This application provides a schematic diagram of a process for an NF service consumer to discover NF services.
[0082] Figure 4 A schematic diagram illustrating the process of an NF service consumer obtaining an access token, provided as an embodiment of this application;
[0083] Figure 5 A schematic diagram of a federated learning process provided for an embodiment of this application;
[0084] Figure 6 This is a schematic diagram of the architecture of a communication system applied in an embodiment of this application;
[0085] Figure 7 A flowchart illustrating a communication method provided in an embodiment of this application;
[0086] Figure 8 A flowchart illustrating another communication method provided in an embodiment of this application;
[0087] Figure 9 A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0088] Figure 10 A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0089] Figure 11 A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0090] Figure 12 A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0091] Figure 13 A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0092] Figure 14A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0093] Figure 15 A flowchart illustrating yet another communication method provided in an embodiment of this application;
[0094] Figure 16 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application;
[0095] Figure 17 This is a schematic diagram of another communication device provided in an embodiment of this application. Detailed Implementation
[0096] To clearly describe the technical solution of this application, the terms "first" and "second" are used to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, nor do they necessarily imply that they are different. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0097] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0098] The technical solutions of this application can be applied to various communication systems, such as 5th generation (5G) systems (also known as New Radio (NR) systems); or 6th generation (6G) systems; or other future communication systems; or device-to-device (D2D) systems, machine-to-machine (M2M) systems, vehicle-to-everything (V2X) systems, etc. The term "system" can be used interchangeably with "network".
[0099] Please see Figure 1 , Figure 1 This is a schematic diagram of a network architecture applicable to embodiments of this application. For example... Figure 1As shown, this network architecture, taking a 5G system as an example, can be divided into three parts: terminal equipment, data network (DN), and operator network. The functions of the network elements in each part are briefly explained below.
[0100] The terminal equipment portion may include terminal equipment, which can also be referred to as user equipment (UE). The terminal equipment in this application is a device with wireless transceiver capabilities, capable of communicating with one or more core network (CN) devices via access network equipment (or access devices) in a radio access network (RAN). Terminal equipment may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, or user device, etc. Terminal equipment can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it can also be deployed on water (e.g., ships); and it can be deployed in the air (e.g., on airplanes, balloons, and satellites). Terminal equipment can be a cellular phone, cordless phone, session initiation protocol (SIP) phone, smartphone, mobile phone, wireless local loop (WLL) station, personal digital assistant (PDA), etc. Alternatively, the terminal device can also be a handheld device with wireless communication capabilities, a computing device or other device connected to a wireless modem, an in-vehicle device, a wearable device, a drone device, or a terminal in the Internet of Things (IoT), the Internet of Vehicles (IoV), a terminal in any form in 5G networks and future networks, a relay user equipment, or a terminal in a future evolved 6G network, etc. Among these, a relay user equipment can be, for example, a 5G residential gateway (RG). For example, the terminal device can be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. Here, "terminal device" refers to a 3GPP terminal. The embodiments of this application do not limit the specific technology or device form used in the terminal device.
[0101] A data network, also known as a packet data network (PDN), is typically a network located outside the carrier's network, such as a third-party network. However, in some implementations, the DN can also be deployed by the carrier, meaning the DN is part of the PLMN. A carrier's network can access multiple data networks (DNs), and various services can be deployed on these DNs, providing data and / or voice services to terminal devices. Terminal devices can also access data networks (DNs) through the carrier's network, using carrier services deployed on these DNs, and / or services provided by third parties.
[0102] The operator network portion includes, but is not limited to, the (radio)access network (RAN) portion and the core network (CN) portion.
[0103] (R)AN can be viewed as a sub-network of the operator's network, serving as the implementation system between service nodes and terminal devices within the operator's network. For a terminal device to access the operator's network, it first passes through the (R)AN, and then connects to the operator's network's service nodes via the (R)AN. The access network equipment (RAN equipment) in this application embodiment is a device that provides wireless communication functions for terminal devices; it can also be called a network device. RAN equipment includes, but is not limited to: next-generation node base stations (gNBs) in 5G systems, evolved node Bs (eNBs) in long-term evolution (LTE), radio network controllers (RNCs), node Bs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved node Bs, or home node Bs (HNBs)), base band units (BBUs), transmitting and receiving points (TRPs), transmitting points (TPs), small cell equipment (picos), mobile switching centers, or network equipment in future networks, etc. In systems employing different wireless access technologies, the names of devices with access network functionality may differ. The embodiments of this application do not limit the specific technology or form of the access network device.
[0104] The CN component includes, but is not limited to, the following Network Functions (NFs): User Plane Function (UPF), Authentication Server Function (AUSF), Access and Mobility Management Function (AMF), Session Management Function (SMF), Network Slice Selection Function (NSSF), Network Exposure Function (NEF), Network Repository Function (NRF), Policy Control Function (PCF), Unified Data Management (UDM), Unified Data Repository (UDR), Network Data Analytics Function (NWDAF), and Application Function (AF).
[0105] The following section introduces the NF functions included in CN.
[0106] 1. UPF: Primarily responsible for user data processing (forwarding, receiving, billing, etc.). For example, a UPF can receive user data from a DN and forward it to the terminal through access network equipment. A UPF can also receive user data from terminal equipment through access network equipment and forward it to the DN. In a Protocol Data Unit (PDU) session, the UPF directly connected to the DN via N6 is also called the Protocol Data Unit Session Anchor (PSA).
[0107] 2. AUSF: Primarily used for performing security authentication of terminal devices.
[0108] 3. AMF: Primarily used for mobility management in mobile networks. Examples include user location updates, user network registration, and user handover.
[0109] 4. SMF: Primarily used for session management in mobile networks. This includes session establishment, modification, and release. Specific functions include assigning Internet Protocol (IP) addresses to users and selecting a UPF (User-Defined Provider) to provide packet forwarding capabilities.
[0110] 5. NSSF: Primarily used to select network slices for terminal devices.
[0111] 6. NEF: Primarily used to support the opening of capabilities and events. For example, NEF can expose some capabilities of the 5G network to third-party applications through application programming interfaces (APIs). Third-party applications can obtain some capabilities of the 5G network by calling the APIs provided by NEF through AF, enabling them to control certain behaviors of the 5G network and terminal devices.
[0112] 7. NRF: Primarily used to provide network element discovery functionality. Based on requests from other network elements, it provides network element information corresponding to the network element type, and also provides network element management services, such as network element registration, update, deregistration, and authorization.
[0113] 8. PCF: Primarily supports providing a unified policy framework to control network behavior, delivering policy rules to control layer network functions, and acquiring user subscription information related to policy decisions. PCF can provide policies to AMF and SMF, such as Quality of Service (QoS) policies and slice selection policies.
[0114] 9. UDM: Primarily used to store user data, such as contract data, authentication / authorization data, etc.
[0115] 10. UDR: Primarily used to store structured data, including contract data, policy data, externally exposed structured data, and application-related data.
[0116] 11. NWDAF: Primarily used to collect relevant data from network elements, third-party service servers, terminal devices, or network management systems. Based on this data, it performs data analysis to obtain results, which are then provided to these network elements, third-party service servers, terminal devices, or network management systems. These results can assist the network in selecting service quality parameters, performing traffic routing, or selecting background data transmission strategies. Furthermore, NWDAF elements can also collect relevant data from network elements, third-party service servers, terminal devices, or network management systems, and use this data to train models to obtain artificial intelligence (AI) or machine learning (ML) models. These AI / ML models are then provided to other NWDAF elements to assist them in generating data analysis results based on the relevant data. 3GPP separates the training and inference functions of NWDAF; an NWDAF can support only model training, only data inference, or both. Among them, the NWDAF that supports model training can also be called the training NWDAF, or the NWDAF that supports the model training logical function (MTLF) (abbreviated as MTLF). The training NWDAF can train the model based on the acquired data to obtain the trained model. The NWDAF that supports data inference can also be called the inference NWDAF, or the NWDAF that supports the analytics logical function (AnLF) (abbreviated as AnLF). The inference NWDAF can input the input data into the trained model to obtain the analysis results or inference data. In the embodiments of this application, an NWDAF can be a separate network element or can be co-located with other network elements, such as setting the NWDAF in the PCF or AMF.
[0117] 11. Application Functions (AFs): Primarily used to provide application layer information. AFs can be divided into two categories: The first category is AFs deployed by the operator and considered trusted by the operator; this type of AF can directly interact with other network functions in the network. The second category is AFs that the operator does not allow to directly access network functions, such as third-party AFs; this type of AF can interact with other network functions in the NEF network. The AFs involved in the embodiments of this application refer to the second type of AF.
[0118] Figure 1Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Nausf, Namf, Nsmf, N1, N2, N3, N4, N6, and N9 are interface sequence numbers. For example, the meaning of the above interface sequence numbers can be found in the definitions in the 3GPP standard protocols; this application does not limit the meaning of the above interface sequence numbers.
[0119] It should be noted that, Figure 1 The interface names between the various network functions in this document are merely examples. In actual implementations, the interface names in this system architecture may be different, and this application does not limit them. Furthermore, the names of the messages (or signaling) transmitted between the aforementioned network elements are also merely examples and do not constitute any limitation on the function of the messages themselves. Figure 1 In the network architecture shown, network elements can communicate with each other via interfaces. These interfaces can be point-to-point or service-oriented; this application does not impose any restrictions.
[0120] It should be understood that the network architecture shown above is merely an illustrative example, and the network architecture applicable to the embodiments of this application is not limited thereto. Any network architecture capable of realizing the functions of the above-described network elements is applicable to the embodiments of this application.
[0121] It should also be understood that Figure 1 The AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM shown can be understood as network elements in the core network used to implement different functions, such as network slices that can be combined as needed. These core network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the above network elements.
[0122] It should also be understood that the above naming is defined solely for the purpose of distinguishing different functions and should not constitute any limitation on this application. This application does not preclude the possibility of using other naming conventions in 6G networks and other future networks. For example, in 6G networks, some or all of the above-mentioned network elements may use the terminology from 5G, or they may use other names, etc.
[0123] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0124] In the 5G service-oriented system architecture, the two parties communicating based on service interfaces are called the service consumer and the service producer, respectively. The party requesting the service is called the service consumer, and the party providing the service is called the service producer. The service consumer can also be referred to as a consumer, consuming network element, user, requester, or service consuming network element, etc. The service provider can also be referred to as a providing network element, service providing network element, producing network element, provider, producer, or responder, etc., and this application does not impose any limitations on these terms.
[0125] For service-oriented architectures, 3GPP defines the registration methods for NF service consumers with the NRF, the NF service discovery methods, and the authorization methods for NF service consumers before accessing services provided by NF service producers. The following section combines... Figures 2-4 This section provides a brief overview of how NF service consumers can register, discover NF services, and obtain authorization.
[0126] I. NF Service Registration
[0127] For example, please see Figure 2 , Figure 2 This is a schematic diagram illustrating the process of an NF service consumer registering with an NRF, as provided in an embodiment of this application.
[0128] like Figure 2 As shown, the steps may include, but are not limited to, the following:
[0129] S201, the NF service consumer sends a registration request message to the NRF. Correspondingly, the NRF receives the registration request message from the NF service consumer.
[0130] The registration request message may include the NF profile of the NF service consumer. Optionally, the NF profile may include the NF instance ID, NF type, names of services supported by the NF service consumer, and the Internet Protocol (IP) address of the NF service consumer.
[0131] For example, the registration request message can be an Nnrf_NFManagement_NRFRegister Request message.
[0132] S202, NRF stores the NF configuration information of NF consumers.
[0133] S203, the NRF sends a registration response message to the NF consumer. Correspondingly, the NF consumer receives the registration response message from the NRF.
[0134] The registration response message is a response to the registration request message. The registration response message can be used to indicate that the NF registration has been accepted.
[0135] For example, the registration response message can be an Nnrf_NFManagement_NRFRegister Response message.
[0136] pass Figure 2 As shown in the registration process, NF service consumers can provide NF configuration information to the NRF. Then, the NF service consumer can request the discovery of available NF services.
[0137] II. NF / NF Service Discovery
[0138] For example, please see Figure 3 , Figure 3 This is a schematic diagram illustrating a process for an NF service consumer to discover NF services, provided as an embodiment of this application. Figure 3 As shown, the steps may include, but are not limited to, the following:
[0139] S301, the NF service consumer sends a discovery request message to the NRF. Correspondingly, the NRF receives the discovery request message from the NF service consumer.
[0140] The discovery request message is used to request the discovery of available services in the network. Optionally, the discovery request message may include the desired NF service name, the desired NF type of the NF instance, and the NF type of the NF service consumer, etc.
[0141] For example, a discovery request message could be an Nnrf_NFDiscovery_Request message.
[0142] S302, NRF Authorized NF Service Discovery.
[0143] NRF can authorize NF service consumers to perform service discovery. For example, NRF can determine whether to authorize an NF service consumer to discover the desired NF instance based on the attributes of the NF / NF service the NF consumer expects and the type of the NF service consumer.
[0144] S303, the NRF sends a discovery response message to the NF service consumer. Correspondingly, the NF service consumer receives the discovery response message from the NRF.
[0145] When an NRF determines that an authorized NF service consumer should perform discovery services, it can send a discovery response message to the NF service consumer. This discovery response message may include NF configuration information for one or more candidate NFs.
[0146] For example, the discovery response message could be an Nnrf_NFDiscovery_Response message.
[0147] pass Figure 3 As shown in the discovery process, NF service consumers can discover information about available NF service producers. Then, based on the discovery results, NF service consumers can select NF service producers and send service request messages to NF service producers to request services.
[0148] III. NF Service Authorization
[0149] Before sending a service request message to an NF service producer, an NF service consumer can obtain authorization using OAuth. OAuth authorization is an open authorization mechanism based on authorization parameters such as tokens. The NF service consumer can request an access token from the NRF. After obtaining the access token, the NF service consumer can include it in its service request message to the NF service producer. Once the NF service producer successfully verifies the access token, it can provide the corresponding service to the NF service consumer.
[0150] For example, please see Figure 4 , Figure 4 This is a schematic diagram illustrating a process for an NF service consumer to obtain an access token, as provided in an embodiment of this application. Figure 4 As shown, the steps may include, but are not limited to, the following:
[0151] S401, the NF service consumer sends an authorization request message to the NRF. Correspondingly, the NRF receives the authorization request message from the NF service consumer.
[0152] In some embodiments, an NF service consumer may request services provided by an NF service producer of a specific NF type. In this case, the authorization request message may include the NF instance ID of the NF service consumer, the desired service name, the NF type of the NF service consumer, and the NF type of the NF service producer. Optionally, the authorization request message may also include additional scope (i.e., the requested resource and the requested operation on that resource), Single Network Slice Selection Assistance Information (S-NSSAI) or Network Slice Instance ID (NSI ID) of the desired NF service producer instance, the NF set ID of the desired NF service producer instance, and a list of S-NSSAIs for the NF service consumer, etc.
[0153] In some embodiments, an NF service consumer may request to use a service provided by a specific NF service producer. In this case, the authorization request message may include the NF instance ID(s) of the requesting NF service producer, the desired service name, and the NF instance ID of the NF service consumer. Optionally, the authorization request message may also include additional scope (i.e., the requested resource and the requested operation on the resource).
[0154] Additionally, if an NF service consumer wishes to authorize any NF in its NF set to use services provided by the NF service producer, the authorization request message may include an NF set ID, which can be used to identify the NF set to which the NF service consumer belongs.
[0155] For example, the authorization request message can be an Nnrf_AccessToken_Get Request message.
[0156] S402, NRF verification to determine whether an NF service consumer is authorized.
[0157] NRF can validate parameters in authorization request messages. For example, NRF can verify whether parameters carried in the authorization request message (such as NF type) match the corresponding parameters in the NF service consumer's public key certificate or NF profile. Additionally, NRF can verify whether the NF service consumer is authorized to access the requested service.
[0158] Upon successful verification, the NRF can generate an access token, which may include claims. These claims may include the NRF's NF instance ID, the NF instance ID of the NF service consumer, the NF type of the NF service producer, and the desired service name. Optionally, the claims may also include additional scope (allowed resources and requested operations on those resources), a list of desired NF service producers' S-NSSAI or NSI IDs, and the NF set ID of the desired NF service producer instance.
[0159] Additionally, if the authorization request message includes an NF set ID, the NRF can determine whether to authorize all NF service consumer instances in the NF set of the NF service consumer to use the services provided by the NF service producer. If the verification passes, the NRF can include the NF set ID of the NF service consumer in the claim.
[0160] S403, the NRF sends an authorization response message to the NF service consumer. Correspondingly, the NF service consumer receives the authorization response message from the NRF.
[0161] If all parameters in the authorization request message are verified and the NF service consumer is authorized to access the requested service, the NRF sends an authorization response message to the NF service consumer, which includes an access token generated by the NRF.
[0162] If the authorization verification in S402 fails, NRF can send an error response message or a rejection response message to the NF service consumer.
[0163] For example, the authorization response message could be an Nnrf_AccessToken_Get Response message.
[0164] pass Figure 4 As shown in the authorization process, NF service consumers can be authorized to use services provided by NF service producers, and can then send service request messages to NF service producers to request services.
[0165] Currently, 3GPP supports the introduction of NWDAFs for data analysis and supports federated learning among multiple NWDAFs. This involves a server-side NWDAF and multiple client-side NWDAFs collaboratively training machine learning (ML) models. For example, a client-side NWDAF can train a local ML model using its own data and share the trained local ML model with the server-side NWDAF. The server-side NWDAF can aggregate local ML models from different client-side NWDAFs into a global ML model and feed this global ML model back to the client-side NWDAFs.
[0166] In some embodiments, the federated learning (FL) process of multiple NWDAFs can be implemented based on the aforementioned NF service registration, discovery, and authorization mechanisms.
[0167] To facilitate understanding, before introducing the process of federated learning, we will first briefly introduce some basic terms related to federated learning.
[0168] 1. Federated Learning
[0169] Federated learning is a distributed machine learning method where multiple participants interact with model parameters through secure mechanisms without exchanging or sharing original training data, thereby achieving collaborative training effects. In other words, federated learning is an encrypted distributed machine learning technology. Federated learning fully utilizes the data and computing power of participating parties, enabling multiple parties to collaboratively build general and robust machine learning models without sharing data. Therefore, federated learning can effectively help multiple organizations use data and learn models while meeting the requirements of user privacy protection, data security, and government regulations. In short, federated learning aims to share knowledge and parameters without exchanging any of their own data.
[0170] Federated learning includes horizontal federated learning (HFL) and vertical federated learning (VFL). Horizontal federated learning combines multiple participants' training data with shared characteristics across multiple rows, meaning the participants' training data is horizontally partitioned. It is also called feature-aligned federated learning, where the participants' data features are aligned, increasing the total number of training samples. Vertical federated learning addresses model training and inference when participants are unwilling to share raw data. It is suitable when participants' training sample identifications (IDs) overlap significantly, but their data features overlap less. Vertical federated learning combines different data features from common samples of multiple participants, meaning the participants' training data is vertically partitioned. It is also called sample-aligned federated learning, where the participants' training samples are aligned, increasing the feature dimension of the training data.
[0171] 2. Analysis ID
[0172] An analysis identifier can be used to characterize the type of analysis business or service, or simply a service. This service is associated with a model; that is, the model can be used to execute the service. Alternatively, the analysis identifier is associated with a model; that is, the model is used to execute the service corresponding to the analysis identifier.
[0173] Alternatively, it can be understood that MTLF is associated with an analytics identifier, meaning that the model provided by the MTLF supports the execution of the service corresponding to that analytics identifier. For example, an MTLF can be associated with one or more analytics identifiers. This can be understood as the MTLF providing a model for the service corresponding to each of the one or more analytics identifiers. For instance, if MTLF1 is associated with analytics identifier 1 and analytics identifier 2, meaning MTLF1 corresponds to analytics identifier 1 and analytics identifier 2, then MTLF1 can provide a model for the service corresponding to analytics identifier 1, and a model for the service corresponding to analytics identifier 2.
[0174] 3. Interoperability indicator
[0175] Interoperability identifiers can correspond to MTLF, analysis identifiers, or analysis identifiers corresponding to MLTF. Alternatively, they can be described as interoperability identifiers being related to MTLF or analysis identifiers. Interoperability identifiers can also be called interoperability indicators, ML model interoperability identifiers, or ML model interoperability indicators.
[0176] An interoperability identifier includes a list of vendors, or can be described as a list of NWDAF providers (or vendors). Vendors in this list are permitted to retrieve or use models provided by MTLF. The interoperability identifier also indicates that MTLF supports vendors requesting models provided by MTLF for NWDAF from vendors in this list. The interoperability identifier also indicates that vendors in this list are permitted to obtain models from MTLF. Finally, the interoperability identifier also indicates that MTLF allows vendors in this list to obtain models from MTLF.
[0177] The interoperability identifier corresponding to a vertical federated learning group can be consistent with the interoperability identifier in an existing protocol, or it can extend the content of the interoperability identifier in an existing protocol. For example, the interoperability identifier corresponding to a vertical federated learning group can also include one or more of the following: Appname (application name), vendor identifier corresponding to the AF, and AF ID. Vendors in this vendor list are allowed to retrieve or use models provided by MTLF. The interoperability identifier indicates that the vertical federated entity supports providing vertical federated learning services to vendors, AFs, and Apps in this list. Or, vendors in the interoperability identifier are allowed or authorized to use vertical federated learning services. Optionally, the group identifier of the vertical federated learning group corresponds to the interoperability identifier. The group identifier of the vertical federated learning group is used to identify the interoperability identifier.
[0178] Interoperability identifiers are a list of MTLF providers. For example, an interoperability identifier may represent a vendor identifier, or an interoperability identifier may be associated with a vendor identifier. Interoperability identifiers can be associated with analytics identifiers, such as a one-to-one correspondence, indicating that the MTLF allows the corresponding vendor or an MTLF contained within a vendor to access the model corresponding to the analytics identifier, and / or that the MTLF is allowed to interoperate with the AnLF on the model corresponding to the analytics identifier. Optionally, an MTLF may have one or more interoperability identifiers. If it has multiple interoperability identifiers, then each of these interoperability identifiers corresponds to a different analytics identifier. For example, MTLF NF ID 1 corresponds to analytics identifier 1 and analytics identifier 2, where the MTLF to which MTLF NF ID 1 belongs has interoperability identifier 1 and interoperability identifier 2, with interoperability identifier 1 corresponding to analytics identifier 1 and interoperability identifier 2 corresponding to analytics identifier 2. Optionally, if the MTLF to which MTLF NF ID1 belongs and the MTLF to which MTLF NF ID2 belongs support interoperability, then the MTLF to which MTLF NF ID2 belongs can have interoperability identifier 1 and interoperability identifier 2, where interoperability identifier 1 corresponds to analysis identifier 1, and / or, interoperability identifier 2 corresponds to analysis identifier 2. That is, MTLFs from the same vendor can have the same interoperability identifier for the same analysis identifier. Furthermore, if the MTLF to which MTLF NF ID1 belongs and the MTLF to which MTLF NF ID2 belongs belong to different vendors, then the MTLF to which MTLF NF ID2 belongs can have interoperability identifier 3 and interoperability identifier 4, where interoperability identifier 3 corresponds to analysis identifier 1, and / or, interoperability identifier 4 corresponds to analysis identifier 2. That is, MTLFs from the same vendor can have different interoperability identifiers for the same analysis identifier.
[0179] For example, analysis identifier 1 is associated with model 1, meaning model 1 is used to execute the service corresponding to analysis identifier 1. Analysis identifier 1 is also associated with interoperability identifier 1, meaning model 1 is associated with interoperability identifier 1. Assuming interoperability identifier 1 includes the identifier of vendor 1 and the identifier of vendor 2, model 1 can be provided to both vendor 1 and vendor 2. Alternatively, it can be understood that if the vendor of the NWDAF is vendor 1 or vendor 2, then the NWDAF can use model 1.
[0180] For example, an MTLF may have one or more interoperability identifiers. If it has multiple interoperability identifiers, these multiple interoperability identifiers may correspond to different analytics identifiers. For example, MTLF1 corresponds to analytics identifier 1 and analytics identifier 2, where interoperability identifier 1 corresponds to analytics identifier 1 and interoperability identifier 2 corresponds to analytics identifier 2.
[0181] 4. Vendor ID
[0182] The vendor identifier can also be represented as network element information, identifying the vendor or manufacturer of the network element. For example, Vendor ID1 identifies the vendor of the NWDAF network element.
[0183] A vendor identifier can be used to identify a device vendor. A vendor identifier can correspond to one or more NWDAF device identifiers. For example, NWDAF NF ID 1 and NWDAF NF ID 2 can both correspond to vendor identifier 1, that is, the MTLF to which MTLF NF ID 1 belongs and the MTLF to which MTLF NF ID 2 belongs belong to the same vendor, and the vendor identifier of this vendor is vendor identifier 1.
[0184] The above provides a brief introduction to the relevant terminology of federated learning. The following section introduces the federated learning process implemented based on a 5G system.
[0185] For example, please see Figure 5 , Figure 5 This is a schematic diagram of a federated learning process provided for an embodiment of this application. Figure 5 As shown, the steps may include, but are not limited to, the following:
[0186] S501, the server NWDAF and client NWDAF (e.g., client NWDAF 1 to client NWDAF N) send registration request messages to the NRF. Correspondingly, the NRF receives the registration request messages from the server NWDAF and client NWDAF.
[0187] The server-side NWDAF can send a registration request message to the NRF to provide its NF configuration information; similarly, the client-side NWDAF can send a registration request message to the NRF to provide its NF configuration information. Optionally, the NF configuration information of the NWDAF (server-side or client-side) may include the NWDAF's NF type, analysis ID(s), address information, service area, FL capability type information (such as FL server and / or FL client), and the time interval for supporting FLs.
[0188] S502, NRF stores the configuration information for the NWDAF on the storage side and the NWDAF on the client side.
[0189] In step S503, the NRF sends a registration response message to both the server-side NWDAF and the client-side NWDAF. Correspondingly, the server-side NWDAF and the client-side NWDAF receive the registration response message from the NRF.
[0190] Steps S501-S503 above constitute the NWDAF registration process, which can be detailed in conjunction with... Figure 2 The registration process shown is for your understanding.
[0191] S504, the server-side NWDAF sends a discovery request message to the NRF. Correspondingly, the NRF receives the discovery request message from the server-side NWDAF.
[0192] The discovery request message is used to request the NRF to discover candidate client NWDAFs participating in FL. Optionally, the discovery request message may include the analysis ID(s) of the expected client NWDAF's ML model, the interoperability identifier of the ML model, the FL capability type (such as FL client), the service region, etc.
[0193] S505, NRF-authorized NF service discovery.
[0194] S506, the NRF sends a discovery response message to the server-side NWDAF. Correspondingly, the server-side NWDAF receives the discovery response message from the NRF.
[0195] With NRF authorization, a discovery response message can be sent to the NWDAF. The discovery response message can include NF configuration information for one or more candidate NWDAF client clients participating in the FL.
[0196] Steps S504-S506 above constitute the NWDAF detection process, which can be further explained in conjunction with... Figure 3 The discovery process is illustrated.
[0197] S507, the server-side NWDAF sends a FL preparation request message to the client-side NWDAF. Correspondingly, the client-side NWDAF receives the FL preparation request message from the server-side NWDAF.
[0198] For example, an FL preparation request message can be an FL preparation request message. For instance, a server-side NWDAF can use the Naf_MLModelTraining_Subscribe or Naf_MLModelTrainingInfo_Request service with the ML preparation flag to send an FL preparation request message to one or more client-side NWDAFs to check whether the client-side NWDAFs can meet ML model training requirements (e.g., analysis ID, ML model interoperability information), available data requirements (a list of event IDs for local data used for training; available data requirements may also include dataset statistics, time windows for data samples, and a minimum number of data samples), or availability time requirements (the time span required for the FL process), etc.
[0199] S508, the client-side NWDAF determines whether to join federated learning.
[0200] In this process, the client-side NWDAF can check whether it meets the training requirements of the ML model, and / or, if the FL preparation request message in step S507 provides model information, the client-side NWDAF also needs to check whether it can successfully download the model and decide whether to join the FL process. For example, the client-side NWDAF can decide whether to join the FL process based on its data availability and time availability, computing and communication capabilities, and ML model interoperability information.
[0201] S509, the client NWDAF sends a FL ready response message to the server NWDAF. Correspondingly, the server NWDAF receives the FL ready response message from the client.
[0202] For example, the FL preparation response message can be an FL preparation response message. For instance, the client NWDAF can invoke the Nnwdaf_MLModelTraining_Notify, Nnwdaf_MLModelTraining_Subscribe, or Nnwdaf_MLModelTrainingInfo_Request service operation to indicate whether it will join FL. If it cannot join FL, the FL preparation response message can include the reason for the inability to join.
[0203] S510, the server-side NWDAF selects the client-side NWDAF to participate in FL.
[0204] The server-side NWDAF can select the client-side NWDAF to participate in the FL process based on the information received in step S506 and / or step S509.
[0205] remove Figure 5 In addition to the federated learning process shown, before sending a service request message to the client NWDAF, the server-side NWDAF should also request an access token from the NRF. The server-side NWDAF can send an authorization request message to the NRF so that the NRF can check whether the server-side NWDAF is authorized to use the requested service. If the parameters in the authorization request message are validated by the NRF, an access token can be generated and sent to the server-side NWDAF along with the authorization response message. The process for the server-side NWDAF to obtain the access token is described above. Figure 4 The process for obtaining an access token is shown below.
[0206] As mentioned above, current federated learning processes do not consider how to improve data processing security in either horizontal or vertical federated learning scenarios. Therefore, this application provides a communication method that can be applied to vertical federated learning, helping to improve data processing security.
[0207] Please see Figure 6 , Figure 6 This is a schematic diagram of the architecture of a communication system applied in an embodiment of this application. As an example, such as... Figure 6 As shown, the communication system includes a first network element, a second network element, a third network element, and a fourth network element. The first network element and the second network element can communicate indirectly through the fourth network element, or they can communicate directly without going through the fourth network element.
[0208] In this embodiment, the first network element can be a key manager in vertical federated learning, possessing the ability to manage keys. This key can be used for encryption of various data during the vertical federated learning process (such as model parameters for training the ML model, intermediate data generated in vertical federation, sample IDs, features, etc.). Optionally, the first network element can be an NRF, NEF, or a third-party network element (such as a third-party server).
[0209] The second network element can be a participant in vertical federated learning, which can be understood as a network element participating in vertical federated learning. Optionally, the second network element can be an entity, device, or network element of type NF, such as NWDAF, or it can be an entity, device, or network element of type AF.
[0210] The third network element can be the initiator of vertical federated learning or the consumer of vertical federated learning services. It can be understood as a network element that requests vertical federated learning services or initiates vertical federated learning tasks. The third network element can be an entity, device, or network element of type NF, such as NWDAF, or it can be an entity, device, or network element of type AF.
[0211] The fourth network element can be a network element providing message forwarding services, or a network element or entity located between vertical federation entities, such as a NEF or a service communication proxy (SCP). The fourth network element can obtain vertical federation data transmitted between network elements or entities participating in vertical federation learning. It can be understood that the fourth network element can receive a first vertical federation service request message from a third network element and then send a second vertical federation service request message to the second network element. The content of the first and second vertical federation service request messages can be the same, i.e., the NEF only acts as a forwarder of the service request. Optionally, the content of the first and second vertical federation service request messages can also be different. After receiving the first vertical federation service request message from the third network element, the fourth network element can process the first vertical federation service request message to obtain the second vertical federation service request message, and then send the second vertical federation service request message to the third network element.
[0212] It should be understood that Figure 6 The number of network elements in the communication system shown is only an example; in actual applications, it may include different elements. Figure 6 The number of network elements shown may include, for example, two or more second network elements.
[0213] The following is combined with Figures 7-15 The communication method provided in the embodiments of this application will be described.
[0214] Please see Figure 7 , Figure 7 This is a flowchart illustrating a communication method provided in an embodiment of this application. Figure 7 As shown, the method may include, but is not limited to, the following steps:
[0215] S701, the first network element determines the first key.
[0216] In this embodiment, the first network element can be the network element responsible for key management in vertical federated learning, or it can be described as the first network element having key management capabilities. Specifically, the first key can be used for data encryption of all or some network elements in the first vertical federated learning group (also known as the first vertical federated learning consortium).
[0217] In this embodiment of the application, the use of the first key for data encryption of all or some network elements in the first vertical federated learning group can be understood as the ability of all or some network elements in the first vertical federated learning group to use the first key to encrypt data related to vertical federated learning (such as intermediate data, gradients, losses, sample identifiers, etc. generated during model training).
[0218] When the first key is used for data encryption of all network elements in the first vertical federated learning group, it means that all members of the first vertical federated learning group can use the first key for data encryption. When the first key is used for data encryption of some network elements in the first vertical federated learning group, it means that only some members of the first vertical federated learning group can use the first key for data encryption. These members may be, for example, those participating in the first vertical federated learning task. It should be understood that the first key can be a public key. When determining the first key, the first network element can also determine the corresponding decryption key, i.e., the private key corresponding to the public key. The first key can also be other types of keys.
[0219] In some embodiments, the first network element can be a network storage element with information storage capabilities, such as an NRF or NEF. The configuration information of the network elements in the first vertical federated learning group can be registered with the first network element. Correspondingly, the first network element can store the configuration information of the network elements in the first vertical federated learning group.
[0220] In one possible implementation, a third network element can send a discovery request message to a first network element, and the first network element receives the discovery request message from the third network element. The third network element can be understood as the network element initiating the vertical federated learning. The discovery request message can be used to request the discovery of network elements in the first vertical federated learning group participating in the vertical federated learning. The discovery request message can include group information of the first vertical federated learning group. For example, the discovery request message can be an Nnrf_NFDiscovery_Request message.
[0221] Based on the group information of the first vertical federated learning group included in the discovery request message, the first network element can determine a first key for data encryption of the network elements in the first vertical federated learning group. In this case, the determined first key can be used for data encryption of all or some network elements in the first vertical federated learning group.
[0222] Optionally, the group information of the first vertical federated learning group may include one or more of the following: the group identifier of the first vertical federated learning group, the analysis ID(s) corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group. The information of one or more network elements may include or specifically be the identifiers of one or more network elements, such as vendor ID(s), App name, NF ID(s), AF ID(s), and UE ID(s). Optionally, the group information of the first vertical federated learning group may specifically be the group identifier of the first vertical federated learning group, or the analysis ID(s) corresponding to the first vertical federated learning group, or the interoperability identifier corresponding to the first vertical federated learning group, or information of one or more network elements in the first vertical federated learning group. Optionally, the group identifier of the first vertical federated learning group may be used to identify the interoperability identifier corresponding to the first vertical federated learning group. The group identifier of the first vertical federated learning group corresponds to the interoperability identifier corresponding to the first vertical federated learning group.
[0223] Optionally, the first network element may determine the first key based on the group information of the first vertical federated learning group in one of the following two ways:
[0224] Method 1: Static Configuration
[0225] In this approach, there can be a correspondence or mapping relationship between the group information of the first vertical federated learning group and the first key, and this mapping relationship can be pre-configured. The first network element can determine the first key based on the mapping relationship between the group information of the first vertical federated learning group and the first key. Optionally, the mapping relationship between the group information of the first vertical federated learning group and the first key can be pre-configured by the management network element. The management network element can be any network element with management functions, such as an operation administration and maintenance (OAM) network element, or a terminal, base station, server, etc., and this application embodiment is not limited to this.
[0226] For example, the group information of the first vertical federated learning group may include the analysis ID corresponding to the first vertical federated learning group, and there may be a mapping relationship between the analysis ID and the first key. The first network element can determine the first key based on the mapping relationship between the analysis ID and the first key. In this case, it can be understood that the granularity of the first key is at the analysis ID level, that is, the same analysis ID can be used for the same vertical federated learning task. For example, assuming that the analysis ID corresponding to the first vertical federated learning group is analysis ID1, and analysis ID1 and key A may have a pre-configured mapping relationship, then the first network element can determine that the first key is key A based on the mapping relationship between analysis ID1 and key A.
[0227] For example, the group information of the first vertical federated learning group may include the group identifier of the first vertical federated learning group, and there may be a mapping relationship between the first vertical federated learning group identifier and the first key. The first network element can determine the first key based on the mapping relationship between the group identifier of the first vertical federated learning group and the first key. In this case, it can be understood that the granularity of the first key is at the group (consortium) granularity level, that is, the vertical federated learning tasks corresponding to the same vertical federated learning group can use the same key. For example, assuming that the group identifier corresponding to the first vertical federated learning group is group identifier 1, and there may be a pre-configured mapping relationship between group identifier 1 and key B, then the first network element can determine that the first key is key B based on the mapping relationship between group identifier 1 and key B.
[0228] For example, the group information of the first vertical federated learning group may include the group identifier of the first vertical federated learning group and the first analysis ID corresponding to the first vertical federated learning group. A mapping relationship may exist between the vertical federated learning task corresponding to one analysis ID of a vertical federated learning group and one key. The first network element can determine the first key based on the mapping relationship between the vertical federated learning task corresponding to the first analysis ID of the first vertical federated learning group and the first key. In this case, the granularity of the first key can be understood as the granularity level of the analysis ID of the group (consortium), that is, the vertical federated learning task corresponding to the same analysis ID in the same vertical federated learning group can use the same key. For example, assuming the group identifier of the first vertical federated learning group is group identifier 2, the analysis ID(s) corresponding to the first vertical federated learning group include: analysis ID 1 and analysis ID 2. Among them, a pre-configured mapping relationship may exist between group identifier 2, analysis ID 1, and key C, and a pre-configured mapping relationship may exist between group identifier 2, analysis ID 2, and key D. If the group information of the first vertical federated learning group includes group identifier 2 and analysis ID 1, then the first network element can determine the first key as key C based on the mapping relationship between group identifier 2, analysis ID 1, and key C. If the group information of the first vertical federated learning group includes group identifier 2 and analysis ID 2, then the first network element can determine the first key as key D based on the mapping relationship between group identifier 2, analysis ID 2, and key D.
[0229] It should be understood that the first key in this application may also be at other granularities, and this application does not limit this.
[0230] Method 2: Dynamic Generation
[0231] In this approach, the first network element can dynamically generate a first key for the first vertical federated learning group. Specifically, the first network element can generate the first key for the first vertical federated learning group during the registration phase of the network elements within the first vertical federated learning group.
[0232] For example, network element A in the first vertical federated learning group can send a registration request message to network element A, and correspondingly, network element A can receive the registration request message from network element A. This registration request message can include group information of the first vertical federated learning group that network element A has joined (such as analysis ID(s), group identifier, or interoperability identifier, etc.). Then, network element A can generate a first key based on the group information of the first vertical federated learning group. After generating the first key, network element A can store the mapping relationship between the first vertical federated learning group and the first key. Subsequently, if network element A receives a registration request message from another network element in the first vertical federated learning group (such as network element B), it can directly obtain the first key based on the mapping relationship between the first vertical federated learning group and the first key, without needing to generate a new key again.
[0233] In addition, the first network element can identify one or more network elements in the first vertical federated learning group based on the group information of the first vertical federated learning group in the discovery request message and the configuration information of the network elements in the first vertical federated learning group stored in the message.
[0234] Furthermore, the first network element can send a discovery response message to the third network element, and correspondingly, the third network element can receive the discovery response message from the first network element. For example, the discovery response message can be an Nnrf_NFDiscovery_Response message. The discovery response message may include the identifiers of one or more network elements in the first vertical federated learning group.
[0235] Optionally, the discovery response message may also include a first key. This first key can be used for data encryption of all network elements in the first vertical federated learning group.
[0236] In one possible implementation, after receiving the discovery response message, the third network element can further identify the network elements participating in the first vertical federated learning task within the first vertical federated learning group, and then send a first task registration request message to the first network element. Correspondingly, the first network element can receive the first task registration request message from the third network element. The first task registration request message may include task information for the first vertical federated learning task.
[0237] Based on the task information of the first vertical federated learning task included in the first task registration request message, the first network element can determine a first key for data encryption of network elements participating in the first vertical federated learning task within the first vertical federated learning group. In other words, the first key determined under this condition can be used for data encryption of some network elements within the first vertical federated learning group, and these "some network elements" are those participating in the first vertical federated learning task.
[0238] Optionally, the task information for the first vertical federated learning task may include one or more of the following: the task identifier of the first vertical federated learning task, the identifiers of the network elements participating in the first vertical federated learning task, the role information of the network elements participating in the first vertical federated learning task, and the group information of the first vertical federated learning group corresponding to the first vertical federated learning task. The role information of the network elements participating in the first vertical federated learning task can be used to indicate the role each network element plays when participating in the first vertical federated learning task (e.g., main participant, slave participant, or coordinator).
[0239] After storing the task information for the first vertical federated learning task, the first network element can send a first task registration response message to the third network element. Correspondingly, the third network element can receive the first task registration response message from the first network element. The first task registration response message may include information indicating that the task information for the first vertical federated learning task has been successfully registered.
[0240] Optionally, the first task registration response message may also include a first key, which can be used for data encryption of some network elements in the first vertical federated learning group, and some network elements are network elements participating in the first vertical federated learning task.
[0241] Optionally, the first network element can also send a first key to one or more network elements participating in the first vertical federated learning task. This first key can be used for data encryption of some network elements in the first vertical federated learning group, where some network elements are those participating in the first vertical federated learning task. It can be understood that the first network element can proactively send the first key to one or more network elements in the first vertical federated learning task. The first network element can also send the task identifier of the first vertical federated learning task and the group information of the first vertical federated learning group corresponding to the first vertical federated learning task.
[0242] In some embodiments, the first network element may also be a network element with task coordination capabilities. The third network element may send a task coordination request message to the first network element. Correspondingly, the first network element may receive a task coordination request message from the third network element. This task coordination request message can be used to request the first network element to participate in coordinating a vertical federated learning task. The task coordination message may include group information of the first vertical federated learning group and / or the task identifier of the first vertical federated learning task.
[0243] Optionally, the first network element can determine a first key for data encryption of all network elements in the first vertical federated learning group based on the group information of the first vertical federated learning group. Alternatively, the first network element can determine a first key for data encryption of network elements participating in the first vertical federated learning task in the first vertical federated learning group based on the task identifier of the first vertical federated learning task.
[0244] If the first network element agrees to participate in coordinating the first vertical federated learning task, it can send a task coordination response message to the third network element. This message may include information indicating agreement to participate in the first vertical federated learning task. Optionally, the task coordination response message may also include a first key. This first key can be used for data encryption of all network elements in the first vertical federated learning group, or it can be used for data encryption of network elements participating in the first vertical federated learning task within the first vertical federated learning group.
[0245] S702, the first network element sends the first key to the third network element. Correspondingly, the third network element receives the first key sent by the first network element.
[0246] In some embodiments, the first network element (such as an NRF) may carry the first key in the discovery response message corresponding to the discovery request message, that is, the first network element may send the first key to the third network element through the discovery response message. Alternatively, the first network element may also carry the first key in the first task registration response message corresponding to the first task registration request message, that is, the first network element may send the first key to the third network element through the first task registration response message.
[0247] In some embodiments, the first network element (such as NEF) may carry the first key in the task coordination response message corresponding to the task coordination request message, that is, the first network element may send the first key to the third network element through the task coordination response message.
[0248] In some embodiments, the first network element (such as NRF, NEF, or other independent network elements) can carry the first key in a separate message, meaning the first network element can send the first key to the third network element through a separate message. For example, the third network element can send a key request message to the first network element to request the first key. Correspondingly, the first network element can receive the key request message from the third network element. After determining the first key, the first network element can send a key response message carrying the first key to the third network element. Correspondingly, the third network element can receive the key response message from the first network element.
[0249] S703, the third network element sends the identifier of the first network element to the second network element. Correspondingly, the second network element receives the identifier of the first network element sent by the third network element.
[0250] The second network element can be understood as a network element in the first vertical federated learning group. Specifically, it can be a network element in the first vertical federated learning group that participates in the first vertical federated learning task, or it can be a network element in the first vertical federated learning group that does not participate in the first vertical federated learning task.
[0251] The third network element sends the identifier of the first network element to the second network element so that the second network element can know the provider of the first key.
[0252] In some embodiments, before sending the identifier of the first network element to the second network element, the third network element may first request the authorized access to the vertical federated learning service provided by the vertical federated learning producer.
[0253] A third network element can send an authorization request message to a first network element. Correspondingly, the first network element receives the authorization request message from the third network element. For example, the authorization request message could be an Nnrf_AccessToken_Get Request message. The authorization request message can be used to request authorization to obtain the vertical federated learning service provided by the target network element. Here, the target network element can be understood as the producer providing the vertical federated learning service. The authorization request message can include group information for the first vertical federated learning group requesting participation. Thus, based on the group information of the first vertical federated learning group and the configuration information of the network elements in the first vertical federated learning group registered with the first network element, the first network element can determine whether to authorize the third network element to use the vertical federated learning service provided by the target network element. For details on how the first network element determines authorization, please refer to the following... Figure 14 The relevant descriptions in the illustrated embodiments will not be repeated here. Wherein, when the first network element determines to authorize the third network element to use the vertical federated learning service provided by the target network element, it can send an authorization response message to the third network element. For example, the authorization response message can be an Nnrf_AccessToken_Get Response message. This authorization response message may include an access token. Optionally, the access token may include one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
[0254] In some embodiments, after a third network element is authorized to use the vertical federated learning service provided by the target network element, it can send a task preparation request message to a second network element in the first vertical federated learning group. Correspondingly, the second network element can receive a task preparation request message from the third network element. The task preparation request message can be used to request the second network element to participate in the first vertical federated learning task. The task preparation request message may include an access token.
[0255] Optionally, the task preparation request message may also include the identifier of the first network element, that is, the third network element can send the identifier of the first network element to the second network element through the task preparation request message.
[0256] In some embodiments, a second network element can determine whether a third network element is authorized to access the vertical federated learning services of the first vertical federated learning group by verifying an access token. Specifically, the second network element can verify whether the third network element supports the group information of the first vertical federated learning group in the access token, or in other words, determine whether the third network element is located in the first vertical federated learning group. For example, the access token may include the group information of the first vertical federated learning group, which may include, or specifically, the NF ID(s) of one or more network elements in the first federated learning group, assuming it includes {NFID 1, NF ID 2, NF ID 3}. The identifier of the third network element is assumed to be NF ID 2. Then, based on the group information of the first vertical federated learning group, the second network element can determine that the third network element is located in the first vertical federated learning group, and thus determine that the third network element is authorized to access the vertical federated learning services of the first vertical federated learning group.
[0257] In some embodiments, the task preparation request message may include an access token and group information of the target vertical federated learning group. The access token may include group information of the first vertical federated learning group. The second network element may verify whether the group information of the target vertical federated learning group in the task preparation request message matches the group information of the first vertical federated learning group in the access token, and determine whether the third network element is authorized to obtain the vertical federated learning service of the first vertical federated learning group. For example, the access token may include the group identifier of the first vertical federated learning group, and the group information of the target vertical federated learning group may include the group identifier of the first vertical federated learning group. The second network element may verify whether the group identifier of the first vertical federated learning group matches the group identifier of the target vertical federated learning group. If they match, then it can be determined that the third network element is authorized to obtain the vertical federated learning service of the first vertical federated learning group.
[0258] If the second network element determines that the third network element is authorized to obtain the vertical federated learning service of the first vertical federated learning group and agrees to participate in the first vertical federated learning task, it can send a task preparation response message to the first network element. Correspondingly, the first network element can receive the task preparation response message from the second network element. The task preparation response message may include information indicating that the second network element agrees to participate in the first vertical federated learning task. Furthermore, the first network element can send a task execution request message to the second network element. Correspondingly, the second network element receives the task execution request message from the first network element. The task execution request message is used to request the execution of the first vertical federated learning task.
[0259] Optionally, the task execution request message may include the identifier of the first network element, that is, the third network element may send the identifier of the first network element to the second network element through the task execution request message.
[0260] S704, the second network element sends a first request message to the first network element. Correspondingly, the first network element receives the first request message from the second network element.
[0261] After obtaining the identifier of the first network element, the second network element can send a first request message to the first network element based on the identifier. The first request message can be used to request a first key, and / or to request the decryption key corresponding to the first key to decrypt the first encrypted data. Here, the first encrypted data can be understood as the encrypted data received by the second network element.
[0262] Optionally, the first encrypted data may include data obtained by encrypting training samples in longitudinal federated learning using the first key, data obtained by encrypting model training results in longitudinal federated learning (such as intermediate results calculated by network element A based on the model and its own local data) using the first key, and data obtained by encrypting model training parameters in longitudinal federated learning (such as the loss function and gradient corresponding to the model) using the first key.
[0263] S705, the first network element verifies the second network element.
[0264] After receiving the first request message, the first network element can verify the second network element according to the first request message to determine whether the second network element has the authority to obtain the first key, and / or to determine whether the second network element has the authority to obtain the first decrypted data. The first decrypted data is obtained by decrypting the first encrypted data using the decryption key corresponding to the first key.
[0265] In some embodiments, the first request message may include group information of the first vertical federated learning group. The first network element can verify whether the second network element is located in the first vertical federated learning group based on the group information and the identifier of the second network element. If the second network element is located in the first vertical federated learning group, then the second network element has the authority to obtain the first key and / or the first decrypted data. Here, the first key can be understood as a key at the group (consortium) granularity level, that is, the first key can be used for data encryption of all network elements in the first vertical federated learning group.
[0266] In this embodiment of the application, the second network element being located in the first vertical federated learning group can be understood as: the second network element is included in the member list of the first vertical federated learning group, or the second network element supports the first vertical federated learning group, or the first network element has the permission to participate in the first vertical federated learning group, or the second network element has the permission to use the vertical federated learning service of the first vertical federated learning group. The second network element may be, for example, NWDAF or AF.
[0267] In one implementation, network elements in the first vertical federated learning group can register their configuration information (such as NF profile) with the first network element. Then, the first network element can verify whether the second network element is located in the first vertical federated learning group based on the stored configuration information, the group information of the first vertical federated learning group, and the identifier of the second network element. The process of network elements in the first vertical federated learning group registering their configuration information with the first network element can be found in the relevant descriptions in steps S501 to S503 above, and will not be repeated here.
[0268] For example, the configuration information for a second network element registering with a first network element may include group information for the vertical federated learning group to which the second network element joins. This group information may include one or more of the following: the group identifier of the vertical federated learning group, the analysis identifier corresponding to the vertical federated learning group, the interoperability identifier corresponding to the vertical federated learning group, and information about one or more network elements within the vertical federated learning group. The information about one or more network elements within the vertical federated learning group may include information about the second network element, such as its App name, AF ID, or vendor ID. The interoperability identifier corresponding to the vertical federated learning group can be understood as the interoperability identifier corresponding to the vertical federated learning supported by the second network element. For example, the group information of the vertical federated learning group to which the second network element joins includes the vendor list corresponding to the vertical federated learning group to which the second network element joins (e.g., the vendor list includes vendor A, vendor B, vendor C), and / or the group identifier of the vertical federated learning group to which the second network element joins. The first request message may include the group information of the first vertical federated learning group. The group information of the first vertical federated learning group may include, or specifically include, the group identifier of the first vertical federated learning group. Based on the configuration information of the second network element registered to the first network element, the group identifier of the first vertical federated learning group in the first request message, and the identifier of the second network element, the first network element can determine whether the second network element is located in the vertical federated learning group (i.e., the first vertical federated learning group) corresponding to the group identifier in the first request message.
[0269] For example, the configuration information of the second network element registered with the first network element may include a list of NF (or AF) IDs corresponding to the vertical federated learning group to which the second network element has joined (e.g., the NF IDs list includes NF ID1, NF ID2, and NF ID3), and / or the group identifier of the vertical federated learning group to which the second network element has joined (e.g., group 1). The first request message may include the group information of the first vertical federated learning group, which may include, or specifically include, the group identifier of the first vertical federated learning group. Based on the configuration information of the second network element registered with the first network element and the group identifier of the first vertical federated learning group in the first request message, the first network element can determine whether the second network element is located in the vertical federated learning group (i.e., the first vertical federated learning group) corresponding to the group identifier in the first request message. Optionally, the first request message may or may not include the identifier of the second network element.
[0270] For example, suppose the group identifier of the first vertical federated learning group in the first request message is group 1, and the identifier of the second network element is NF ID2. Based on the group identifier (i.e., group 1) and the configuration information registered to the first network element by the second network element, the first network element can determine the NF IDs list corresponding to group 1 (e.g., the NF IDs list includes NF ID1, NF ID2, and NF ID3). Then, based on the identifier of the second network element (i.e., NF ID2), the first network element can determine that the identifier of the second network element is located in the NF IDs list corresponding to group 1, thus confirming that the second network element is located in the first vertical federated learning group.
[0271] In some embodiments, the first request message may include a task identifier for the first vertical federated learning task. The first network element can verify whether the network elements participating in the first vertical federated learning task include the second network element based on the task identifier of the first vertical federated learning task and the identifier of the second network element. If the network elements participating in the first vertical federated learning task include the second network element, then the second network element has the authority to obtain the first key and / or the first decrypted data. Here, the first key can be understood as a task-level key, that is, the first key can be used by the network elements participating in the first vertical federated learning task in the first vertical federated learning group to encrypt data.
[0272] In this embodiment of the application, the network element participating in the first vertical federated learning task including the second network element can be understood as: the second network element is located in the member list of the first vertical federated learning task, or the second network element has the ability to participate in the first vertical federated learning task, or the second network element supports the first vertical federated learning task.
[0273] In one implementation, after the third network element determines the network elements participating in the first vertical federated learning task in the first vertical federated learning group, it can register the task information of the first vertical federated learning task with the first network element. Then, the first network element can verify whether the network elements participating in the first vertical federated learning task include the second network element based on the task information of the first vertical federated learning task, the task identifier of the first vertical federated learning task, and the identifier of the second network element.
[0274] For example, the task information of the first vertical federated learning task may include the task identifier of the first vertical federated learning task and the identifier of the network element participating in the first vertical federated learning task. In this way, the first network element can verify whether the network element participating in the first vertical federated learning task includes the second network element based on the task information of the first vertical federated learning task, the task identifier of the first vertical federated learning task, and the identifier of the second network element.
[0275] S706, the first network element sends a first response message to the second network element. Correspondingly, the second network element receives the first response message from the first network element.
[0276] If the first network element determines that the second network element has the authority to obtain the first key, and / or determines that the second network element has the authority to obtain the first decrypted data, the first network element may send a first response message to the second network element. The first response message may include the first key and / or the first decrypted data.
[0277] In some embodiments, when the first key is used for data encryption of all network elements in the first vertical federated learning group, if the first network element determines that the second network element is a network element in the first vertical federated learning group, then it can send a first response message to the second network element. In this case, for example, the first request message can carry a group identifier 1, then the first network element can find the key A corresponding to the group identifier 1 based on the group identifier 1 carried in the first request message, and then send a first response message carrying the key A to the second network element.
[0278] In some embodiments, when the first key is used for data encryption by network elements participating in the first vertical federated learning task within the first vertical federated learning group, if the first network element determines that the network elements participating in the first vertical federated learning task include the second network element, it can send a first response message to the second network element. In this case, for example, the first request message may carry group identifier 1 and task identifier 2. The first network element can then find the key B corresponding to task identifier 2 under group identifier 1 based on the group identifier 1 and task identifier 2 carried in the first request message, and then send a first response message carrying the key B to the second network element. As another example, the first request message may carry task identifier 2. The first network element can then find the key C corresponding to task identifier 2 based on the task identifier 2 carried in the first request message, and then send a first response message carrying the key C to the second network element.
[0279] Figure 7 In the illustrated embodiment, the first network element, acting as the key manager, can not only determine the first key but also verify the identity of the second network element. Only after the second network element's authentication is successful will the first key and / or the first decryption data be sent to it. This enhances the security of data processing in vertical federated learning.
[0280] The following section combines 5G systems to... Figure 7 The communication method shown will be explained.
[0281] Please see Figure 8 , Figure 8 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 8 Taking the first network element as NRF, the second network element as client NWDAF, and the third network element as server NWDAF as an example, the client NWDAF can include client NWDAF 1 to client NWDAF N. For example... Figure 8 As shown, this communication method may include, but is not limited to, the following steps:
[0282] S801, the server-side NWDAF and client-side NWDAF (including client-side NWDAF 1 to client-side NWDAF N) are registered with the NRF.
[0283] Both the server-side NWDAF and the client-side NWDAF can register their respective NF configuration information with the NRF. Optionally, the NF configuration information may include the analysis ID, the vertical federated learning group joined (such as NF ID, Vendor ID, or UEID), and supported role attributes (such as participant (whether they can provide labels and / or training data), coordinator, etc.). For details, please refer to the relevant descriptions in steps S501 to S503 above, which will not be repeated here.
[0284] S802, the server-side NWDAF sends a discovery request message to the NRF. Correspondingly, the NRF receives the discovery request message from the server-side NWDAF.
[0285] The discovery request message can be used to request the discovery of network elements in the first vertical federated learning group that wish to participate in the vertical federated learning. The discovery request message may include group information of the first vertical federated learning group.
[0286] Optionally, the group information of the first vertical federated learning group may include one or more of the following: the group identifier of the first vertical federated learning group, the analysis ID corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group. The information of one or more network elements may include, or specifically be, the identifiers of one or more network elements, such as vendor ID(s), App name, NF ID(s), AF ID(s), and UE ID(s). Optionally, the group information of the first vertical federated learning group may specifically be the group identifier of the first vertical federated learning group, or it may be the analysis ID(s) corresponding to the first vertical federated learning group, or it may be the interoperability identifier corresponding to the first vertical federated learning group, or it may be information of one or more network elements in the first vertical federated learning group.
[0287] Optionally, S803, NRF determines the first key based on the group information of the first longitudinal federated learning group.
[0288] The first key can be a group (consortium) level key. In this case, NRF can determine the first key based on the group information of the first vertical federated learning group.
[0289] Optionally, the NRF can determine the first key based on the group information of the first vertical federated learning group in either a static configuration or a dynamic generation method. For details, please refer to the two methods (method one and method two) for the first network element to determine the first key in step S701 above, which will not be elaborated here.
[0290] In step S804, the NRF sends a discovery response message to the server-side NWDAF. Correspondingly, the server-side NWDAF receives the discovery response message from the NRF.
[0291] Based on the group information of the first vertical federated learning group and the NF configuration information registered with the NRF in step S801, the NRF can identify one or more client NWDAFs in the first vertical federated learning group. The NRF can then send a discovery response message to the server NWDAF. This discovery response message may include the identifiers (such as NFIDs) of one or more client NWDAFs.
[0292] Optionally, the discovery response message may also include the first key determined in step S803.
[0293] S805, the server-side NWDAF sends a task preparation request message to the client-side NWDAF. Correspondingly, the client-side NWDAF receives the task preparation request message from the server-side NWDAF.
[0294] The task preparation request message can be used to request the client NWDAF to participate in the first vertical federated learning task in the target vertical federated learning group. The task preparation request message may include an access token.
[0295] Optionally, the task preparation request message may also include NRFID, the task identifier of the first longitudinal federated learning task, and the group information of the target longitudinal federated learning group.
[0296] The client-side NWDAF can verify whether the information of the target vertical federated learning group carried in the task preparation request message matches the information in the access token. If they match, the client-side NWDAF can agree to participate in the first vertical federated learning task, or in other words, the client-side NWDAF can agree to provide vertical federated learning services to the server-side NWDAF. For details on how the client-side NWDAF verifies the match between the information of the target vertical federated learning group carried in the task preparation request message and the information in the access token, please refer to the above. Figure 7 Or the following Figure 15 The relevant descriptions in the illustrated embodiments will not be repeated here.
[0297] S806, the client NWDAF sends a task preparation response message to the server NWDAF. Correspondingly, the server NWDAF receives the task preparation response message from the client NWDAF.
[0298] If the client NWDAF agrees to participate in the first vertical federated learning task, it can send a task preparation response message to the server NWDAF.
[0299] S807, the server-side NWDAF identifies the members participating in the first vertical federated learning task.
[0300] Specifically, the server-side NWDAF can determine one or more client-side NWDAFs participating in the first vertical federated learning task based on the task preparation response message received from one or more client-side NWDAFs in step S806.
[0301] S808, the server-side NWDAF sends a first task registration request message to the NRF. Correspondingly, the NRF receives the first task registration request message from the server-side NWDAF.
[0302] After the server-side NWDAF determines the members participating in the first vertical federated learning task, it can send a first task registration request message to the NRF to register the task information of the first vertical federated learning task with the NRF. The first task registration request message can include the task information of the first vertical federated learning task.
[0303] Optionally, the task information of the first vertical federated learning task may include one or more of the following: the task identifier of the first vertical federated learning task, the identifier of the network element participating in the first vertical federated learning task, and the role information of the network element participating in the first vertical federated learning task.
[0304] Optionally, in S809, NRF determines the first key based on the task information of the first longitudinal federated learning task.
[0305] The first key can be a task-level key. In this case, NRF can determine the first key based on the task information of the first vertical federated learning task.
[0306] S810, the NRF sends a first task registration response message to the server NWDAF. Correspondingly, the server NWDAF receives the first task registration response message from the NRF.
[0307] The first task registration response message can be used to indicate that the task information of the first vertical federated learning task has been successfully registered with the NRF.
[0308] Optionally, the first task registration response message may include the first key determined in step S809.
[0309] S811, the server-side NWDAF sends a task execution request message to the client-side NWDAF. Correspondingly, the client-side NWDAF receives the task execution request message from the server-side NWDAF.
[0310] The task execution request message can be used to request the client NWDAF to execute the first vertical federated learning task. The task execution request message may include an access token.
[0311] Optionally, the task execution request message may also include NRFID.
[0312] S812, the client NWDAF sends a task execution response message to the server NWDAF. Correspondingly, the server NWDAF receives the task execution response message from the client NWDAF.
[0313] The task execution response message can be used to instruct the server-side NWDAF to confirm the execution of the first vertical federated learning task.
[0314] S813, the client NWDAF sends a first request message to the NRF. Correspondingly, the NRF receives the first request message from the client NWDAF.
[0315] The first request message can be used to request a first key, and / or, the first request message can be used to request the decryption key corresponding to the first key to decrypt the first encrypted data. For example, the first request message can be a vertical federated learning service request message.
[0316] Optionally, the client NWDAF can send a first request message to the NRF based on the NRFID included in the task preparation request message in step S805 above. Alternatively, the client NWDAF can send a first request message to the NRF based on the NRFID included in the task execution request message in step S811 above. This NRFID can be used to indicate the provider of the first key.
[0317] S814, NRF verifies the client's NWDAF.
[0318] The NRF can verify the identity of the client NWDAF. The specific implementation process of step S814 can be found in the relevant description in step S705 above. The NRF corresponds to the first network element mentioned above, and the client NWDAF corresponds to the second network element mentioned above. It will not be repeated here.
[0319] S815, the NRF sends a first response message to the client NWDAF. Correspondingly, the client NWDAF receives the first response message from the NRF.
[0320] Once the client NWDAF is successfully authenticated, the NRF can send a first response message to the client NWDAF. This first response message may include a first key and / or first decrypted data. For example, the first response message could be a vertical federated learning service response message.
[0321] Figure 8In the illustrated embodiment, the NRF can act as a key manager, not only determining the first key but also verifying the identity of the client NWDAF. Only after the client NWDAF's authentication is successful will the first key and / or the first decryption data be sent to the client NWDAF. This enhances the security of data processing in vertical federated learning.
[0322] Please see Figure 9 , Figure 9 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 9 Taking NEF as the first network element, AF as the second network element, and NWDAF as the third network element as the server network element as the third network element, the client network element can include client network element 1 to client network element N. The client network element can communicate with the server network element NWDAF through NEF. Figure 9 As shown, this communication method may include, but is not limited to, the following steps:
[0323] S901, the server-side NWDAF and client-side AFs (including client-side AF 1 to client-side AF N) are registered with the NRF.
[0324] The process of registering the server-side NWDAF and the client-side AF to the NRF is similar to the registration process described in steps S501 to S503 or step S801 above, and will not be repeated here.
[0325] S902, the server-side NWDAF sends a discovery request message to the NRF. Correspondingly, the NRF receives the discovery request message from the server-side NWDAF.
[0326] The discovery request message can be used to request the discovery of network elements in the first vertical federated learning group that wish to participate in the vertical federated learning. The discovery request message may include group information of the first vertical federated learning group.
[0327] S903, the NRF sends a discovery response message to the server-side NWDAF. Correspondingly, the server-side NWDAF receives the discovery response message from the NRF.
[0328] Based on the group information of the first vertical federated learning group and the configuration information registered with the NRF in step S901, the NRF can identify one or more client AFs in the first vertical federated learning group. The NRF can then send a discovery response message to the server NWDAF. This discovery response message may include the identifiers (such as AF IDs) of one or more client AFs.
[0329] S904, the server-side NWDAF sends a task coordination request message to the NEF. Correspondingly, the NEF receives the task coordination request message from the server-side NWDAF.
[0330] Among them, the task coordination request message can be used to request NEF to participate in coordinating vertical federated learning tasks.
[0331] Optionally, the task coordination request message may include group information for the first vertical federated learning group and / or the task identifier for the first vertical federated learning task.
[0332] S905, NEF determines the first key.
[0333] In some embodiments, NEF can determine a first key based on the group information of the first vertical federated learning group. In this case, the first key can be used for data encryption of all network elements (such as client AF1 to client AFN) in the first vertical federated learning group.
[0334] In other embodiments, NEF can determine the first key based on the task identifier of the first vertical federated learning task. In this case, the first key can be used for data encryption by network elements (such as clients AF1 to AF5) participating in the first vertical federated learning task in the first vertical federated learning group.
[0335] S906, NEF sends a task coordination response message to the server NWDAF. Correspondingly, the server NWDAF receives the task coordination response message from NEF.
[0336] Among them, the task coordination response message can be used to instruct NEF to agree to participate in coordinating the first vertical federated learning task.
[0337] Optionally, the task coordination response message may include the first key.
[0338] S907, the server-side NWDAF sends a task preparation request message to the client-side AF. Correspondingly, the client-side AF receives the task preparation request message from the server-side NWDAF.
[0339] The task preparation request message can be used to request the client AF to participate in the first vertical federated learning task in the target vertical federated learning group. The task preparation request message may include an access token.
[0340] Optionally, the task preparation request message may also include the NEF ID, the task identifier of the first vertical federated learning task, and the group information of the target vertical federated learning group.
[0341] The client-side federated learning (AF) can verify whether the information of the target vertical federated learning group carried in the task preparation request message matches the information in the access token. If they match, the client-side AF can agree to participate in the first vertical federated learning task, or in other words, the client-side AF can agree to provide vertical federated learning services to the server-side NWDAF.
[0342] S908, the client AF sends a task preparation response message to the server NWDAF. Correspondingly, the server NWDAF receives the task preparation response message from the client AF.
[0343] S909, the server-side NWDAF identifies the members participating in the first vertical federated learning task.
[0344] In this process, the server-side NWDAF can determine one or more client AFs participating in the first vertical federated learning task based on the task preparation response message sent by one or more client AFs received in step S908.
[0345] S910, the server-side NWDAF sends a second task registration request message to the NEF. Correspondingly, the NEF receives the second task registration request message from the server-side NWDAF.
[0346] After the server-side NWDAF determines the members participating in the first vertical federated learning task, it can send a second task registration request message to NEF to register the task information of the first vertical federated learning task with NEF. The second task registration request message can include the task information of the first vertical federated learning task.
[0347] S911, NEF sends a second task registration response message to the server NWDAF. Correspondingly, the server NWDAF receives the second task registration response message from NEF.
[0348] The second task registration response message can be used to indicate that the task information of the first vertical federated learning task has been successfully registered with NEF.
[0349] S912, the server-side NWDAF sends a task execution request message to the client-side AF. Correspondingly, the client-side AF receives the task execution request message from the server-side NWDAF.
[0350] The task execution request message can be used to request the client AF to execute the first vertical federated learning task. The task execution request message may include an access token.
[0351] Optionally, the task execution request message may also include a NEF ID.
[0352] S913, the client AF sends a task execution response message to the server NWDAF. Correspondingly, the server NWDAF receives the task execution response message from the client AF.
[0353] The task execution response message can be used to instruct the server-side AF to confirm the execution of the first vertical federated learning task.
[0354] S914, the client AF sends a first request message to the NEF. Correspondingly, the NEF receives the first request message from the client AF.
[0355] The first request message can be used to request a first key, and / or the first request message can be used to request the decryption key corresponding to the first key to decrypt the first encrypted data.
[0356] Optionally, the client AF can send a first request message to the NEF based on the NEF ID included in the task preparation request message in step S907 above. Alternatively, the client AF can send a first request message to the NEF based on the NEF ID included in the task execution request message in step S912 above.
[0357] S915, NEF verifies the client AF.
[0358] The NEF can verify the identity of the client AF. The specific implementation process of step S915 can be found in the relevant description in step S705 above. The NEF corresponds to the first network element mentioned above, and the client AF corresponds to the second network element mentioned above. It will not be repeated here.
[0359] S916, the NRF sends a first response message to the client NWDAF. Correspondingly, the client NWDAF receives the first response message from the NRF.
[0360] If the client AF is successfully authenticated, NEF can send a first response message to the client AF. This first response message may include a first key and / or first decrypted data.
[0361] Figure 9 In the illustrated embodiment, the client AF can communicate with the server NWDAF via the NEF, which acts as a key manager. The NEF can not only determine the first key but also verify the identity of the client AF. Only after the client AF's authentication is successful will the first key and / or the first decryption data be sent to the client AF. This improves the security of data processing in vertical federated learning.
[0362] The above Figures 7-9 This paper describes how a network element acting as a key manager (or a network element capable of determining the first key) determines the first key and how it verifies the identity of a network element requesting to obtain the first key. In addition, embodiments of this application provide a communication method in which a network element other than the key manager can first verify the identity of the network element requesting the first key.
[0363] Please see Figure 10 , Figure 10This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 7 As shown, the method may include, but is not limited to, the following steps:
[0364] S1001, the first network element determines the first key.
[0365] S1002, the first network element sends the first key to the third network element. Correspondingly, the third network element receives the first key sent by the first network element.
[0366] The specific implementation process of steps S1001 and S1002 can be found in the relevant descriptions of steps S701 and S702 above, and will not be repeated here.
[0367] S1003, the third network element sends the identifier of the first network element to the fourth network element. Correspondingly, the fourth network element receives the identifier of the first network element sent by the third network element.
[0368] The third network element can communicate with the second network element through the fourth network element. The third network element can send the identifier of the first network element to the fourth network element so that the fourth network element can know the provider of the first key.
[0369] In some embodiments, after the third network element determines the network elements participating in the first vertical federated learning task within the first vertical federated learning group, it can send a second task registration request message to the fourth network element to register the task information of the first vertical federated learning task with the fourth network element. The second task registration request message may include the task information of the first vertical federated learning task.
[0370] Optionally, the task information of the first vertical federated learning task may include one or more of the following: the task identifier of the first vertical federated learning task, the identifier of the network element participating in the first vertical federated learning task, and the role information of the network element participating in the first vertical federated learning task.
[0371] Optionally, the second task registration request message may also include group information of the first vertical federated learning group, so as to register the group information of the first vertical federated learning group to the fourth network element.
[0372] Optionally, the second task registration request message may also include the identifier of the first network element. That is, the third network element can send the identifier of the first network element to the fourth network element through the second task registration request message.
[0373] S1004, the second network element sends a first request message to the fourth network element. Correspondingly, the fourth network element receives the first request message from the second network element.
[0374] The first request message can be used to request a first key, and / or the first request message can be used to request the decryption key corresponding to the first key to decrypt the first encrypted data.
[0375] Optionally, the first request message may include the identifier of the first network element.
[0376] S1005, the fourth network element verifies the second network element.
[0377] Since the third network element provides the identifier of the first network element to the fourth network element in step S1003 above, the fourth network element can know the network element that provided the first key. Here, before forwarding the first request message sent by the second network element to the first network element, the fourth network element can first verify the identity of the second network element, or in other words, first verify the permissions of the second network element.
[0378] In some embodiments, the first key can be a group (consortium) level key, meaning the first key can be used for data encryption of all network elements in the first vertical federated learning group. In this case, the third network element can pre-register the group information of the first vertical federated learning group with the fourth network element, and the first request message can include the group identifier of the first vertical federated learning group and the identifier of the second network element. Then, the fourth network element can verify the second network element based on the group information of the first vertical federated learning group, the group identifier of the first vertical federated learning group, and the identifier of the second network element, for example, verifying whether the second network element is located in the first vertical federated learning group. If the second network element is located in the first vertical federated learning group, then the second network element passes the verification, indicating that the second network element has the permission to obtain the first key, and / or, the second network element has the permission to obtain the first decrypted data.
[0379] In some embodiments, the first key can be a task-level key, meaning it can be used for data encryption of network elements participating in the first vertical federated learning task within the first vertical federated learning group. In this case, the third network element can pre-register the task information of the first vertical federated learning task with the fourth network element. The first request message can include the task identifier of the first vertical federated learning task and the identifier of the second network element. Then, the fourth network element can verify the second network element based on the task information of the first vertical federated learning task, the task identifier of the first vertical federated learning task, and the identifier of the second network element. For example, it can verify whether the network elements participating in the first vertical federated learning task include the second network element. If the network elements participating in the first vertical federated learning task include the second network element, then the second network element passes the verification.
[0380] S1006, the fourth network element sends a first request message to the first network element. Correspondingly, the first network element receives the first request message from the fourth network element.
[0381] If the fourth network element determines that the second network element has the authority to obtain the first key, and / or determines that the second network element has the authority to obtain the first decrypted data, the fourth network element may forward the first request message sent by the second network element to the first network element.
[0382] Figure 10 In the illustrated embodiment, the first network element, acting as the key manager, can determine the first key. The fourth network element, responsible for forwarding messages from the second network element, can verify the identity of the second network element before forwarding the message from the second network element requesting the first key and / or the first decryption data. Only if the second network element's authentication is successful will the message from the second network element requesting the first key and / or the first decryption data be forwarded to the first network element. This improves the security of data processing in vertical federated learning.
[0383] The following section combines 5G systems to... Figure 10 The communication method shown will be explained.
[0384] Please see Figure 11 , Figure 11 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 11 Taking the first network element as NRF, the second network element as client AF, the third network element as server NWDAF, and the fourth network element as NEF as an example, the client AF can include client AF 1 to client AF N. Figure 11 As shown, this communication method may include, but is not limited to, the following steps:
[0385] S1101, the server-side NWDAF and client-side AFs (including client-side AF 1 to client-side AF N) are registered with the NRF.
[0386] S1102, the server-side NWDAF sends a discovery request message to the NRF. Correspondingly, the NRF receives the discovery request message from the server-side NWDAF.
[0387] Optionally, in S1103, the NRF determines the first key based on the group information of the first longitudinal federated learning group.
[0388] S1104, the NRF sends a discovery response message to the server NWDAF. Correspondingly, the server NWDAF receives the discovery response message from the NRF.
[0389] S1105, the server-side NWDAF sends a task preparation request message to the client-side AF. Correspondingly, the client-side AF receives the task preparation request message from the server-side NWDAF.
[0390] S1106, the client AF sends a task preparation response message to the server NWDAF. Correspondingly, the server NWDAF receives the task preparation response message from the client AF.
[0391] The specific implementation process of steps S1101 to S1106 can be found in the relevant descriptions of steps S801 to S806 above, and will not be repeated here.
[0392] S1107, the server-side NWDAF identifies the members participating in the first vertical federated learning task.
[0393] Specifically, the server-side NWDAF can determine whether the members participating in the first vertical federated learning task include client-side AFs that need to communicate through NEF. If the members participating in the first vertical federated learning task include client-side AFs that need to communicate through NEF, then the server-side NWDAF can register the information related to the first vertical federated learning task with NEF.
[0394] S1108, the server-side NWDAF sends a first task registration request message to the NRF. Correspondingly, the NRF receives the first task registration request message from the server-side NWDAF.
[0395] Optionally, in S1109, the NRF determines the first key based on the task information of the first longitudinal federated learning task.
[0396] S1110, the NRF sends a first task registration response message to the server NWDAF. Correspondingly, the server NWDAF receives the first task registration response message from the NRF.
[0397] The specific implementation process of steps S1108 to S1110 can be found in the relevant descriptions of steps S808 to S810 above, and will not be repeated here.
[0398] S1111, the server NWDAF sends a second task registration request message to NEF. Correspondingly, NEF receives the second task registration request message from the server NWDAF.
[0399] Specifically, the server-side NWDAF can register information related to the first vertical federated learning task with NEF via a second task registration request message. NEF can store this information. The second task registration request message may include task information for the first vertical federated learning task.
[0400] Optionally, the second task registration request message may also include group information for the first vertical federated learning group.
[0401] Optionally, the second task registration request message may also include NRFID so that NEF can identify network elements with key management capabilities.
[0402] S1112, NEF sends a second task registration response message to the server NWDAF. Correspondingly, the server NWDAF receives the second task registration response message from NEF.
[0403] The second task registration response message is a response message to the second task registration request message.
[0404] S1113, the client AF sends a first request message to the NEF. Correspondingly, the NEF receives the first request message from the client AF.
[0405] S1114, NEF verifies the client AF.
[0406] S1115, NEF sends a first request message to NRF. Correspondingly, NRF receives the first request message from NEF.
[0407] The specific implementation process of steps S1113 to S1115 can be found in the relevant descriptions of steps S1004 to S1006 above, and will not be repeated here.
[0408] Figure 11 In the illustrated embodiment, the NRF, acting as the key manager, can determine the first key. The NEF, as the network element responsible for forwarding messages from the client AF, can verify the identity of the client AF before forwarding the message from the client AF requesting the first key and / or the first decryption data. Only if the client AF's authentication is successful will the message requesting the first key and / or the first decryption data sent by the client AF be forwarded to the NRF. This improves the security of data processing in vertical federated learning.
[0409] The above Figure 10 and Figure 11 This describes how network elements other than the key manager can first verify the identity of the network element requesting the first key. Furthermore, embodiments of this application also provide a communication method that allows network elements participating in vertical federated learning to obtain the first key based on a predefined key generation strategy, without needing to request the first key from the key manager.
[0410] Please see Figure 12 , Figure 12 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 12 As shown, the method may include, but is not limited to, the following steps:
[0411] S1201, the second network element obtains the first key.
[0412] The first key can be used for data encryption of all network elements in the first vertical federated learning group, or the first key can be used for data encryption of network elements in the first vertical federated learning group that participate in the first vertical federated learning task. The second network element is the network element in the first vertical federated learning group that participates in the first vertical federated learning task.
[0413] In some embodiments, the second network element may obtain the first key according to a predefined first key generation strategy. The first key generation strategy may include any of the following: the first key is the group identifier of the first vertical federated learning group, or the first key is the task identifier of the first vertical federated learning task. That is, when the first key can be used for data encryption of all network elements in the first vertical federated learning group, the group identifier of the first vertical federated learning group can be directly used as the first key for data encryption; when the first key can be used for data encryption of network elements participating in the first vertical federated learning task in the first vertical federated learning group, the task identifier of the first vertical federated learning task can be directly used as the first key for data encryption.
[0414] S1202, the second network element determines the first encrypted data based on the first key.
[0415] After obtaining the first key, the second network element can determine the first encrypted data based on the first key. The first encrypted data can be obtained by the second network element encrypting target data using the first key. The target data can be obtained by the second network element based on local data and data shared by other network elements during the first vertical federated learning task. It should be understood that the data shared by other network elements here is also data encrypted using the first key.
[0416] S1203, the second network element sends a decryption request message to the first network element. Correspondingly, the first network element receives the decryption request message from the second network element.
[0417] The decryption request message may include the first encrypted data. The first network element may be a network element with key management capabilities, such as an NRF, NEF, or a third-party network element. The first network element may store the first key and the corresponding decryption key.
[0418] S1204, the first network element verifies the second network element.
[0419] After receiving a decryption request message from the second network element, the first network element can verify the identity of the second network element. The first network element may store group information for the first vertical federated learning group and / or task information for the first vertical federated learning task.
[0420] Optionally, if the first key is the group identifier of the first vertical federated learning group, the decryption request message may include the group identifier of the first vertical federated learning group and the identifier of the second network element. The first network element can verify whether the second network element is located in the first vertical federated learning group based on the stored group information of the first vertical federated learning group, the group identifier of the first vertical federated learning group included in the decryption request message, and the identifier of the second network element. If the second network element is located in the first vertical federated learning group, then the second network element passes the verification.
[0421] Optionally, if the first key is the task identifier of the first vertical federated learning task, the decryption request message may include the task identifier of the first vertical federated learning task and the identifier of the second network element. The first network element can verify whether the network elements participating in the first vertical federated learning task include the second network element based on the stored task information of the first vertical federated learning task, the task identifier of the first vertical federated learning task, and the identifier of the second network element included in the decryption request message. If the network elements participating in the first vertical federated learning task include the second network element, then the second network element passes the verification.
[0422] S1205, the first network element sends a decryption response message to the second network element. Correspondingly, the second network element receives the decryption response message from the first network element.
[0423] If the second network element passes verification, the first network element can use the decryption key corresponding to the first key to decrypt the first encrypted data, obtaining the first decrypted data, and then send a decryption response message to the second network element. The decryption response message includes the first decrypted data.
[0424] Figure 12 In the illustrated embodiment, network elements participating in vertical federated learning can obtain the first key according to a predefined key generation strategy, thus eliminating the need to explicitly transmit the first key.
[0425] The following section combines 5G systems to... Figure 12 The communication method shown will be explained.
[0426] Please see Figure 13 , Figure 13 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 13 Taking the first network element as a third-party network element and the second network element as a client AF as an example, the client AF can include client AF 1 to client AF N. For example... Figure 13 As shown, this communication method may include, but is not limited to, the following steps:
[0427] S1301, the server-side NWDAF and client-side NWDAF (including client-side NWDAF 1 to client-side NWDAF N) are registered with the NRF.
[0428] S1302, the server-side NWDAF sends a discovery request message to the NRF. Correspondingly, the NRF receives the discovery request message from the server-side NWDAF.
[0429] S1303, the NRF sends a discovery response message to the server NWDAF. Correspondingly, the server NWDAF receives the discovery response message from the NRF.
[0430] The specific implementation process of steps S1302 to S1303 can be found in the relevant descriptions of steps S901 to S903 above, and will not be repeated here.
[0431] S1304, the server-side NWDAF sends a task coordination request message to the third-party network element. Correspondingly, the third-party network element receives the task coordination request message from the server-side NWDAF.
[0432] Among them, the task coordination request message can be used to request third-party network elements to participate in coordinating vertical federated learning tasks.
[0433] Optionally, the task coordination request message may include group information for the first vertical federated learning group and / or the task identifier for the first vertical federated learning task.
[0434] S1305, the third-party network element determines the decryption key corresponding to the first key.
[0435] The third-party network element can be a network element with key management capabilities. The first key can be obtained based on a predefined first key generation strategy, so the third-party network element does not need to generate the first key, but only needs to determine the decryption key corresponding to the first key.
[0436] Optionally, the group identifier of the first vertical federated learning group can be used as the first key, and the third-party network element can determine the decryption key corresponding to the first key based on the group identifier of the first vertical federated learning group.
[0437] Optionally, the task identifier of the first vertical federated learning task can be used as the first key, and the third-party network element can determine the decryption key corresponding to the first key based on the task identifier of the first vertical federated learning task.
[0438] Optionally, the identifier of a third-party network element can be used as the first key, and the third-party network element can determine the decryption key corresponding to the first key based on its identifier.
[0439] S1306, the third-party network element sends a task coordination response message to the server-side NWDAF. Correspondingly, the server-side NWDAF receives the task coordination response message from the third-party network element.
[0440] Among them, the task coordination response message can be used to instruct a third-party network element to agree to participate in coordinating the first vertical federated learning task.
[0441] S1307, the server-side NWDAF sends a task preparation request message to the client-side AF. Correspondingly, the client-side AF receives the task preparation request message from the server-side NWDAF.
[0442] S1308, the client AF sends a task preparation response message to the server NWDAF. Correspondingly, the server NWDAF receives the task preparation response message from the client AF.
[0443] S1309, the server-side NWDAF identifies the members participating in the first vertical federated learning task.
[0444] S1310, the server-side NWDAF sends a task registration request message to the third-party network element. Correspondingly, the third-party network element receives a second task registration request message from the server-side NWDAF.
[0445] S1311, the third-party network element sends a task registration response message to the server-side NWDAF. Correspondingly, the server-side NWDAF receives the task registration response message from the third-party network element.
[0446] The specific implementation process of steps S1307 to S1311 is similar to that of steps S907 to S911 above. Please refer to the relevant descriptions in steps S907 to S911 above. They will not be repeated here.
[0447] S1312, Client AF obtains the first key.
[0448] S1313, the client AF determines the first encrypted data based on the first key.
[0449] S1314, Client AF sends a decryption request message to a third-party network element. Correspondingly, the third-party network element receives the decryption request message from Client AF1.
[0450] S1315, a third-party network element verifies the client AF.
[0451] S1316, the third-party network element sends a decryption response message to the client AF. Correspondingly, the client AF receives the decryption response message from the third-party network element.
[0452] The specific implementation process of steps S1312 to S1316 can be found in the relevant descriptions of steps S1201 to S1205 above, and will not be repeated here.
[0453] The above embodiments primarily describe how to improve the security of data processing in vertical federated learning from the perspective of key management. In some embodiments, the security of data processing in vertical federated learning can also be improved from the perspective of service authorization. The service authorization process can be executed after the service discovery process.
[0454] Please see Figure 14 , Figure 14 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 14 As shown, the method may include, but is not limited to, the following steps:
[0455] S1401, the third network element sends an authorization request message to the first network element. Correspondingly, the first network element receives the authorization request message from the third network element.
[0456] The authorization request message can be used to request vertical federated learning services provided by the target network element. The authorization request message may include group information for the first vertical federated learning group. The third network element can be understood as a consumer of the vertical federated learning service, and the target network element can be understood as a producer of the vertical federated learning service. The first network element can be a network storage network element with information storage capabilities, and the configuration information of the network elements in the first vertical federated learning group can be stored in the first network element.
[0457] Optionally, the group information of the first vertical federated learning group may include one or more of the following: the group identifier of the first vertical federated learning group, the analysis ID corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group. The information of one or more network elements may include, or specifically be, the identifiers of one or more network elements, such as vendor ID(s), App name, NF ID(s), AF ID(s), and UE ID(s). Optionally, the group information of the first vertical federated learning group may specifically be the group identifier of the first vertical federated learning group, or it may be the analysis ID(s) corresponding to the first vertical federated learning group, or it may be the interoperability identifier corresponding to the first vertical federated learning group, or it may be information of one or more network elements in the first vertical federated learning group.
[0458] S1402, the first network element determines whether to authorize the third network element to use the vertical federated learning service provided by the target network element based on the group information of the first vertical federated learning group.
[0459] After receiving the authorization request message, the first network element can verify the information carried in the authorization request message to determine whether to authorize the third network element to obtain the vertical federated learning service provided by the target network element. Specifically, the first network element can determine the group information of at least one vertical federated learning group supported by the third network element and / or the target network element based on the stored configuration information. Then, based on the group information of at least one vertical federated learning group supported by the third network element and / or the target network element, and the group information of the first vertical federated learning group included in the authorization request message, the first network element can determine whether the third network element and / or the target network element is located in the first vertical federated learning group.
[0460] Optionally, the group information of the first vertical federated learning group may include the group identifier of the first vertical federated learning group, and the group information of at least one vertical federated learning group supported by the third network element and / or the target network element may include the group identifier of at least one vertical federated learning group supported by the third network element and / or the target network element. The first network element can determine whether the third network element and / or the target network element is located in the first vertical federated learning group based on the group identifier of at least one vertical federated learning group supported by the third network element and / or the target network element, and the group identifier of the first vertical federated learning group. If the group identifier of at least one vertical federated learning group supported by the third network element and / or the target network element includes the group identifier of the first vertical federated learning group, then it can be determined that the third network element and / or the target network element is located in the first vertical federated learning group.
[0461] For example, assuming the authorization request message includes group identifier 1 of the first vertical federated learning group, the first network element determines, based on the stored configuration information, that the group identifier of at least one vertical federated learning group supported by the third network element and / or the target network element includes {group identifier 1, group identifier 2, group identifier 3}. Thus, the first network element can know that the group identifier of at least one vertical federated learning group supported by the third network element and / or the target network element (i.e., {group identifier 1, group identifier 2, group identifier 3}) includes the group identifier of the first vertical federated learning group (i.e., group identifier 1), and can thus determine that the third network element and / or the target network element is located in the first vertical federated learning group.
[0462] For example, suppose the authorization request message includes information about one or more network elements in the first vertical federated learning group, such as the Vendor ID, App Name, or AF ID of the third network element. The first network element determines, based on stored configuration information, that the interoperability identifiers of at least one vertical federated learning group supported by the third network element and / or the target network element include {Vendor ID(s), App Name(s), AF ID(s)}. Therefore, the first network element can determine that the Vendor ID, App Name, or AF ID of the third network element is located within the interoperability identifiers of at least one vertical federated learning group supported by the third network element and / or the target network element, i.e., the third network element and / or the target network element are located in the first vertical federated learning group.
[0463] If the first network element determines that the third network element and / or the target network element are located in the first vertical federated learning group, it can authorize the third network element to obtain the federated learning services provided by the target network element. The first network element can then send an authorization response message to the third network element, which may include an access token.
[0464] Optionally, the authorization response message may include one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
[0465] Figure 14 In the illustrated embodiment, the first network element can verify whether the third network element and / or the target network element are located in its claimed vertical federated learning group. If the third network element and / or the target network element are located in its claimed vertical federated learning group, then the third network element is authorized to use the vertical federated learning service provided by the target network element. In this way, the third network element can be prevented from forging information about the vertical federated learning group and / or the target network element, thereby improving the security of data processing in vertical federated learning.
[0466] The following section combines 5G systems to... Figure 14 The communication method shown will be explained.
[0467] Please see Figure 15 , Figure 15 This is a flowchart illustrating another communication method provided in an embodiment of this application. Figure 15 Taking the first network element as NRF and the third network element as the server-side NWDAF as an example. Figure 15 As shown, this communication method may include, but is not limited to, the following steps:
[0468] S1501, the server-side NWDAF and client-side NWDAF (such as client-side NWDAF 1 to client-side NWDAF N) are registered with the NRF.
[0469] S1502, the server-side NWDAF sends a discovery request message to the NRF. Correspondingly, the NRF receives the discovery request message from the server-side NWDAF.
[0470] S1503, the NRF sends a discovery response message to the server NWDAF. Correspondingly, the server NWDAF receives the discovery response message from the NRF.
[0471] The specific implementation process of steps S1501 to S1503 can be found in the relevant descriptions of steps S901 to S903 above, and will not be repeated here.
[0472] S1504, the server-side NWDAF sends an authorization request message to the NRF. Correspondingly, the NRF receives the authorization request message from the server-side NWDAF.
[0473] S1505, NRF determines whether to authorize based on the group information of the first longitudinal federated learning group.
[0474] The specific implementation process of steps S1504 and S1505 can be found in the relevant descriptions of steps S1401 and S1402 above, and will not be repeated here.
[0475] S1506, the NRF sends an authorization response message to the server NWDAF. Correspondingly, the server NWDAF receives the authorization response message from the NRF.
[0476] If the NRF determines authorization, it can send an authorization response message to the server-side NWDAF. This authorization response message may include an access token.
[0477] Optionally, the authorization response message may also include one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element (such as the client NWDAF 2 that provides the vertical federated learning service), and the identifier of the server NWDAF.
[0478] S1507, the server-side NWDAF sends a task preparation request message to the client-side NWDAF. Correspondingly, the client-side NWDAF receives the task preparation request message from the server-side NWDAF.
[0479] The task preparation request message may include the access token from step S1506.
[0480] Optionally, the task preparation request message may also include group information for the target vertical federated learning group.
[0481] S1508, Client NWDAF verifies access token.
[0482] In this process, the client-side NWDAF can determine whether the server-side NWDAF is authorized to obtain the vertical federated learning services of the first vertical federated learning group by verifying the access token.
[0483] Optionally, the access token may include group information of the first vertical federated learning group. Specifically, the client NWDAF can verify whether the server NWDAF supports the group information of the first vertical federated learning group in the access token, or determine whether the server NWDAF is located in the first vertical federated learning group.
[0484] Optionally, the client-side NWDAF can also verify whether the parameters carried in the task preparation request message match the parameters in the access token. For example, the task preparation request message may include group information of the target vertical federated learning group, which may include the group identifier of the target vertical federated learning group, and the access token may include the group identifier of the first vertical federated learning group. The client-side NWDAF can verify whether the group identifier of the target vertical federated learning group matches the group identifier of the first vertical federated learning group in the access token.
[0485] S1509, the client NWDAF sends a task preparation response message to the server NWDAF. Correspondingly, the server NWDAF receives the task preparation response message from the client NWDAF.
[0486] If the client-side NWDAF successfully verifies the access token, it can send a task preparation response message to the server-side NWDAF.
[0487] Figure 15 In the illustrated embodiment, during the process of the server NWDAF requesting to use the vertical federated learning service provided by the client NWDAF, the NRF can verify whether the requesting server NWDAF and client NWDAF are located in the vertical federated learning group they claim to be in, thereby preventing malicious vertical federated learning service consumers from using the vertical federated learning service without authorization.
[0488] It should be understood that the names of messages, information, etc. shown in the embodiments of this application may also be other names, and the embodiments of this application do not limit them.
[0489] The foregoing mainly describes the solution provided in this application. Accordingly, this application also provides a communication device that can be used to implement the functions of the first network element, second network element, third network element, or fourth network element described above. This communication device can be the first network element, second network element, third network element, or fourth network element, or it can be a device containing the first network element, second network element, third network element, or fourth network element, or it can be a component usable by the first network element, second network element, third network element, or fourth network element, such as a chip or chip system. This communication device includes modules corresponding one-to-one to the methods / operations / steps / actions performed by the first network element, second network element, third network element, or fourth network element in the above method embodiments. These modules can be hardware circuits, software, or a combination of hardware circuits and software implementation.
[0490] This application embodiment can divide the communication device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0491] Please see Figure 16 , Figure 16 A schematic diagram of a communication device 1600 according to an embodiment of this application is shown. The communication device 1600 may include a processing module 1601 and a communication module 1602. Specifically, the processing module 1601 is used to execute the processing functions of the first network element, or the second network element, or the third network element, or the fourth network element in the above method embodiment. The communication module 1602 is used to execute the communication functions of the first network element, or the second network element, or the third network element, or the fourth network element in the above method embodiment.
[0492] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0493] In one possible implementation, in this embodiment of the application, the communication module 1602 may include a receiving module and a transmitting module. Figure 16 (Not shown in the diagram). The transmitting module and the receiving module are used to implement the transmitting and receiving functions of the communication device 1600, respectively.
[0494] In one possible implementation, the communication device 1600 may further include a storage module. Figure 16 (Not shown in the image), this storage module stores programs or instructions. When the processing module 1601 executes the program or instructions, it enables the communication device 1600 to perform... Figures 7-15 The functions of the first network element, the second network element, the third network element, or the fourth network element in any of the methods shown.
[0495] In some embodiments, the processing module 1601 involved in the communication device 1600 may be implemented by a processor or processor-related circuit components, and may be a processor or processing unit; the communication module 1602 may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or transceiver unit.
[0496] For example, Figure 17 This is a schematic diagram of another communication device provided in an embodiment of this application. The communication device can be the first or second device in the above method embodiments, or it can be a chip (system) or other component or assembly that can be disposed in the first or second device. Figure 17 As shown, the communication device 1700 may include a processor 1701, a bus 1702, a communication interface 1703, and a memory 1704. The processor 1701, memory 1704, and communication interface 1703 communicate via the bus 1702. The communication device 1700 may be the first network element, the second network element, the third network element, or the fourth network element described above. It should be understood that this application does not limit the number of processors and memories in the communication device 1700.
[0497] The 1702 bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 17 The bus 1702 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 1702 may include a path for transmitting information between various components of the communication device 1700 (e.g., memory 1704, processor 1701, communication interface 1703).
[0498] Processor 1701 may include any one or more processors such as CPU, graphics processing unit (GPU), microprocessor (MP), or digital signal processor (DSP).
[0499] The memory 1704 may include volatile memory, such as random access memory (RAM). The processor 1701 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0500] The communication interface 1703 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the communication device 1700 and other devices or communication networks.
[0501] The memory 1704 stores executable program code, and the processor 1701 executes the executable program code to implement the functions of the first device or the second device in the aforementioned method embodiments, respectively. That is, the memory 1704 stores instructions for executing the aforementioned communication method.
[0502] This application also provides a computer program product containing instructions, including computer program code, which, when run on a communication device, enables the communication device to execute the methods described in any of the above embodiments.
[0503] This application also provides a computer-readable storage medium. This computer-readable storage medium stores a computer program or instructions that, when executed on a communication device, enable the communication device to perform the methods described in any of the above embodiments.
[0504] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs).
[0505] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0506] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units, i.e., they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0507] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or an access network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.
[0508] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, the disclosure, and the appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.
[0509] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.
Claims
1. A communication method, characterized in that, The method includes: The first network element determines the first key; the first key is used for data encryption of all or some network elements in the first vertical federated learning group; The first network element receives a first request message from the second network element; the first request message is used to request the first key, and / or, the first request message is used to request the decryption key corresponding to the first key to decrypt the first encrypted data; The first network element sends the first key and / or the first decryption data to the second network element; the first decryption data is obtained by decrypting the first encrypted data using the decryption key corresponding to the first key, and the second network element belongs to all or some of the network elements in the first vertical federated learning group.
2. The method as described in claim 1, characterized in that, The first key is used for data encryption of all network elements in the first vertical federated learning group; the first network element determines the first key, including: The first network element receives a discovery request message from the third network element; the discovery request message is used to request the discovery of network elements that wish to participate in the first vertical federated learning group, and the discovery request message includes the group information of the first vertical federated learning group; The first network element determines the first key based on the group information of the first vertical federated learning group.
3. The method as described in claim 2, characterized in that, The group information of the first vertical federated learning group includes one or more of the following: the group identifier of the first vertical federated learning group, the analysis identifier corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group.
4. The method as described in claim 3, characterized in that, The first network element determines the first key based on the group information of the first vertical federated learning group, including: The first network element determines the first key based on the mapping relationship between the group information of the first vertical federated learning group and the first key; the mapping relationship between the group information of the first vertical federated learning group and the first key is pre-configured.
5. The method as described in claim 2 or 4, characterized in that, The method further includes: The first network element receives an authorization request message from the third network element; the authorization request message is used to request authorization to obtain the vertical federated learning service provided by the target network element; the authorization request message includes group information of the first vertical federated learning group; When the first network element determines that the target network element and / or the third network element are located in the first vertical federated learning group based on the group information of the first vertical federated learning group, the first network element sends an authorization response message to the third network element; the authorization response message includes an access token, which includes one or more of the following: the group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
6. The method as described in claim 2 or 4, characterized in that, The method further includes: The first network element determines one or more network elements in the first vertical federated learning group based on the group information and configuration information of the first vertical federated learning group; A discovery response message is sent to the third network element; the discovery response message includes the identifiers of one or more network elements in the first vertical federated learning group and the first key.
7. The method according to any one of claims 3-6, characterized in that, The first request message includes group information of the first vertical federated learning group; the first network element sends the first key and / or first decryption data to the second network element, including: The first network element determines whether the second network element is located in the first vertical federated learning group based on the group information of the first vertical federated learning group and the identifier of the second network element; When the second network element is located in the first vertical federated learning group, the first network element sends a first response message to the second network element; the first response message includes the first key and / or the first decryption data.
8. The method as described in claim 1, characterized in that, The first key is used for data encryption of some network elements in the first vertical federated learning group, and the network elements participate in the first vertical federated learning task. The first network element determines the first key, including: The first network element receives a first task registration request message from the third network element; the first task registration request message is used to request the registration of task information for the first vertical federated learning task; The first network element determines the first key based on the task information of the first vertical federated learning task; The task information of the first vertical federated learning task includes one or more of the following: the task identifier of the first vertical federated learning task, the identifier of the network element participating in the first vertical federated learning task, and the role information of the network element participating in the first vertical federated learning task.
9. The method as described in claim 8, characterized in that, The method further includes: The first network element sends a first task registration response message to the third network element; the first task registration response message includes information indicating that the task information of the first vertical federated learning task has been successfully registered and / or the first key.
10. The method as described in claim 9, characterized in that, The first request message includes the task identifier of the first vertical federated learning task; The first network element sends the first key and / or the first decryption data to the second network element, including: The first network element determines whether the network elements participating in the first vertical federated learning task include the second network element based on the task identifier of the first vertical federated learning task and the identifier of the second network element. If the network element participating in the first vertical federated learning task includes the second network element, the first network element sends a first response message to the second network element; the first response message includes the first key and / or the first decryption data.
11. A communication method, characterized in that, The method includes: The third network element obtains the first key from the first network element; the first key is used for data encryption of all or some network elements in the first vertical federated learning group; The third network element sends a first indication message to the second network element; the second network element is located in the first vertical federated learning group; the first indication message is used to indicate the network element that provides the first key; the first indication message includes or is the identifier of the first network element.
12. The method as described in claim 11, characterized in that, The first key is used for data encryption of all network elements in the first vertical federated learning group; the third network element obtains the first key from the first network element, including: The third network element sends a discovery request message to the first network element. The discovery request message is used to request the discovery of the first vertical federated learning group that wishes to participate in the vertical federated learning. The discovery request message includes the group information of the first vertical federated learning group. The third network element receives a discovery response message from the first network element; the discovery response message includes the identifiers of one or more network elements in the first vertical federated learning group and the first key.
13. The method as described in claim 12, characterized in that, The method further includes: The third network element sends an authorization request message to the first network element; the authorization request message is used to request the use of the vertical federated learning service provided by the target network element; the authorization request message includes the group information of the first vertical federated learning group. The third network element receives an authorization response message from the first network element; the authorization response message includes an access token, which includes one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
14. The method as described in claim 13, characterized in that, The method further includes: The third network element sends a task preparation request message to the second network element; the task preparation request message is used to request participation in the first vertical federated learning task in the target vertical federated learning group; the task preparation request message includes the access token and the group information of the target vertical federated learning group; the group information of the target vertical federated learning group includes one or more of the following: the group identifier of the target vertical federated learning group, the analysis identifier corresponding to the target vertical federated learning group, and the interoperability identifier corresponding to the target vertical federated learning group; The third network element receives a task preparation response message from the second network element; the task preparation response message is used to indicate that the second network element agrees to participate in the first vertical federated learning task.
15. The method as described in claim 11, characterized in that, The first key is used for data encryption of some network elements in the first vertical federated learning group, and the network elements participate in the first vertical federated learning task. The third network element obtains the first key from the first network element, including: The third network element sends a first task registration request message to the first network element; the first task registration request message is used to request the registration of task information for the first vertical federated learning task. The third network element receives a first task registration response message from the first network element; the first task registration response message includes information indicating that the task information registration of the first vertical federated learning task was successful and / or the first key. The task information of the first vertical federated learning task includes one or more of the following: the task identifier of the first vertical federated learning task, the identifier of the network element participating in the first vertical federated learning task, and the role information of the network element participating in the first vertical federated learning task.
16. The method as described in claim 15, characterized in that, The method further includes: If the third network element determines that there is a first type of network element among the network elements participating in the first vertical federated learning task, it sends a second task registration request message to the fourth network element. The second task registration request message includes the task information of the first vertical federated learning task and / or the identifier of the first network element. The third network element communicates with the first type of network element through the fourth network element.
17. A communication method, characterized in that, The method includes: The fourth network element receives a second task registration request message from the third network element. The second task registration request message includes information about the first vertical federated learning task and / or the identifier of the first network element. The first network element is the network element that provides the first key. The first key is used by the network elements participating in the first vertical federated learning task to encrypt data. The information about the first vertical federated learning task includes one or more of the following: the task identifier of the first vertical federated learning task, the identifier of the network element participating in the first vertical federated learning task, and the group information of the vertical federated learning group corresponding to the first vertical federated learning task. The fourth network element receives a first request message from the second network element; the first request message is used to request the first key, and / or, the first request message is used to request the decryption key corresponding to the first key to decrypt the first encrypted data.
18. The method as described in claim 17, characterized in that, The first request message includes the task identifier of the first vertical federated learning task; the method further includes: When the fourth network element determines, based on the task identifier and information of the first vertical federated learning task, that the network element participating in the first vertical federated learning task includes the second network element, it forwards the first request message to the first network element.
19. The method as described in claim 17, characterized in that, The first request message includes group information of the vertical federated learning group corresponding to the first vertical federated learning task; the method further includes: When the fourth network element determines that the second network element is located in the vertical federated learning group corresponding to the first vertical federated learning task based on the group information of the vertical federated learning group corresponding to the first vertical federated learning task and the information of the first vertical federated learning task, the fourth network element forwards the first request message to the first network element.
20. A communication method, characterized in that, The method includes: The second network element acquires the first key; the first key is used for data encryption of all or some network elements in the first vertical federated learning group; the second network element is located in the first vertical federated learning group; The second network element determines the first encrypted data based on the first key; The second network element sends a decryption request message to the first network element; the decryption request message is used to request the decryption key corresponding to the first key to decrypt the first encrypted data, and the decryption request message includes the first encrypted data.
21. The method as described in claim 20, characterized in that, The second network element obtains the first key, including: The second network element obtains the first key according to a predefined first key generation strategy; the first key generation strategy includes any one of the following: the first key is the group identifier of the first vertical federated learning group, or the first key is the task identifier of the first vertical federated learning task.
22. The method as described in claim 20, characterized in that, The first key is used for data encryption of all network elements in the first vertical federated learning group; The second network element obtains the first key, including: The second network element sends a first key request message to the first network element; the first key request message is used to request the first key; the first key request message includes the group information of the first vertical federated learning group and the identifier of the second network element; the group information of the first vertical federated learning group and the identifier of the second network element are used to verify that the second network element is a network element in the first vertical federated learning group; The second network element receives a first key response message from the first network element; the first key response message includes the first key.
23. The method as described in claim 20, characterized in that, The first key is used for data encryption of some network elements in the first vertical federated learning group, and the network elements participating in the first vertical federated learning task include the second network element. The second network element obtains the first key, including: The second network element sends a second key request message to the first network element; the second key request message is used to request the first key; the second key request message includes the task identifier of the first vertical federated learning task and the identifier of the second network element; the task identifier of the first vertical federated learning task and the identifier of the second network element are used to verify that the second network element is a network element participating in the first vertical federated learning task; The second network element receives a second key response message from the first network element; the second key response message includes the first key.
24. A communication method, characterized in that, The method includes: The first network element receives an authorization request message from the third network element; the authorization request message is used to request the use of the vertical federated learning service provided by the target network element; the authorization request message includes group information of the first vertical federated learning group requesting to participate in the vertical federated learning. The first network element determines whether to authorize the third network element to use the vertical federated learning service provided by the target network element based on the group information of the first vertical federated learning group.
25. The method as described in claim 24, characterized in that, The first network element determines, based on the group information of the first vertical federated learning group, whether to authorize the third network element to use the vertical federated learning service provided by the target network element, including: The first network element determines whether the third network element and / or the target network element are located in the first vertical federated learning group based on the group information of the first vertical federated learning group; If the third network element and / or the target network element are located in the first vertical federated learning group, the first network element sends an authorization response message to the third network element; the authorization response message includes an access token, which includes one or more of the following: group information of the first vertical federated learning group, the identifier of the target network element, and the identifier of the third network element.
26. The method as described in claim 24 or 25, characterized in that, The first network element determines whether the third network element and / or the target network element is located in the first vertical federated learning group based on the group information of the first vertical federated learning group, including: The first network element determines whether the group information of the first vertical federated learning group is located in the group information of at least one vertical federated learning group supported by the third network element and / or the target network element; If the group information of the first vertical federated learning group is located in the group information of a vertical federated learning group that the third network element and / or the target network element supports at least one, then the third network element and / or the target network element is determined to be located in the first vertical federated learning group. The group information of the first vertical federated learning group includes one or more of the following: the group identifier of the first vertical federated learning group, the analysis identifier corresponding to the first vertical federated learning group, the interoperability identifier corresponding to the first vertical federated learning group, and information of one or more network elements in the first vertical federated learning group.
27. A communication system, characterized in that, The communication system includes: a first network element, a second network element, and a third network element; The first network element is used to determine the first key and send the first key to the third network element; the first key is used for data encryption of all or some network elements in the first vertical federated learning group. The third network element is used to receive the first key from the first network element and send the identifier of the first network element to all or some network elements in the first vertical federated learning group; the identifier of the first network element is used by all or some network elements in the first vertical federated learning group to know the network element that provided the first key. The second network element is used to send a first request message to the first network element based on the identifier of the first network element; the first request message is used to request the first key, and / or, the first request message is used to request the decryption key corresponding to the first key to decrypt the first encrypted data.
28. A communication device, characterized in that, It includes at least one module for performing the method as described in any one of claims 1-26.
29. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions, which, when executed by a communication device, implement the method as described in any one of claims 1-26.
30. A computer program product, characterized in that, It includes computer program code, which, when run on a communication device, implements the method as described in any one of claims 1-26.