Charging privacy budgets in networks and schedulers that help enhance privacy

By introducing a privacy budget mechanism in 5G networks, user devices and core network functions work together to solve the problem of privacy leakage during federated learning, achieving more efficient privacy protection and security management.

CN122375009APending Publication Date: 2026-07-10NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NOKIA TECHNOLOGIES OY
Filing Date
2024-11-13
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

In 5G networks, how can we effectively manage and protect the privacy of user devices during the training of jointly learned models, especially to prevent privacy leaks during data exchange?

Method used

By implementing a privacy budget mechanism between user equipment and core network functions, user equipment sends a privacy budget to control the privacy costs of data processing, and core network functions select and schedule user equipment based on the privacy budget, ensuring that data processing complies with privacy guarantees.

Benefits of technology

It enables effective management of user device privacy in 5G networks, reduces the risk of privacy leaks during data processing, and improves network security and user privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122375009A_ABST
    Figure CN122375009A_ABST
Patent Text Reader

Abstract

An apparatus for a user equipment that implements privacy guarantees regarding service requests for providing data from a communication network, the apparatus comprising components for: sending a privacy budget to a core network function, wherein the privacy budget at least partially enables the core network function to select a user equipment capable of processing the service request and maintaining guaranteed privacy; receiving a service request from the network function, wherein processing the service request is associated with a privacy cost; obtaining the privacy cost associated with processing the service request; determining whether the privacy cost associated with processing the service request is greater than the privacy budget; and processing the service request based on whether the privacy cost associated with processing the service request is greater than or less than the privacy budget.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to methods, apparatus, systems, and computer programs for performing billing privacy budgets in a network, and in particular, but not excluded, for performing billing privacy budgets in a network during the training of a model using joint learning. Background Technology

[0002] A communication system can be viewed as a facility that enables communication between two or more entities (such as terminals and / or other nodes), or provides connectivity services for entities. A communication system may include a communication network and one or more compatible terminals (also called communication devices). For example, communication may carry voice, video, email, SMS, multimedia data, and / or content data. Non-limiting examples of connectivity services provided by a communication system may include enhanced mobile broadband, ultra-reliable low-latency communication, mission-critical communication, large-scale Internet of Things (IoT), and multimedia services.

[0003] In a communication system, at least a portion of the communication between at least two entities occurs over a wireless link. Examples of networks in a communication system are public terrestrial mobile networks (PLMNs), radio access networks (such as terrestrial radio access networks or non-terrestrial radio access networks (e.g., satellite networks)), and various wireless local area networks (e.g., wireless local area networks (WLANs)). Radio access networks can include cells and are therefore often referred to as cellular networks.

[0004] A terminal can be referred to as user equipment (UE) or user device. A terminal is equipped with appropriate signal receiving and transmitting devices for communication, such as accessing a communication network or communicating directly with other terminals. A terminal can access a carrier provided by a base station, such as a base station in a radio access network, and transmit and / or receive communications on that carrier.

[0005] Communication systems and associated compatible terminals typically operate according to a given standard or specification that defines what the various network entities of the communication system are allowed to do and how they should be implemented. Communication protocols and / or parameters used for communication are also usually defined.

[0006] Fourth-generation (4G) wireless mobile communication technology (also known as Long Term Evolution (LTE) technology) is designed to provide high-capacity mobile multimedia with high data rates, particularly for human-machine interaction. Next-generation or fifth-generation (5G) technology is designed not only for human-machine interaction but also for machine-type communication in so-called Internet of Things (IoT) networks.

[0007] While 5G networks are designed to enable large-scale IoT services (e.g., a large number of devices with limited capacity) and mission-critical IoT services (e.g., requiring high reliability), they also support improvements to traditional mobile communication services in the form of enhanced mobile broadband (eMBB) services, providing improved wireless internet access for mobile devices.

[0008] In the example communication system, user equipment (5G UE in a 5G network, or more broadly, UE) (such as a mobile terminal (subscriber)) communicates via an air interface with a base station or access point of an access network in the 5G network, referred to as a 5G AN. An access point (e.g., a gNB) is, exemplarily, part of the access network of the communication system.

[0009] For example, in 5G networks, the access network referred to as 5G AN is described in 5G Technical Specification (TS) 23.501 entitled "Technical Specification Group Services and Systems Aspects; System Architecture for 5G Systems" and TS 23.502 entitled "Technical Specification Group Services and Systems Aspects; Procedures for 5G Systems (5GS)," the entire contents of which are incorporated herein by reference. Typically, an access point (e.g., gNB) provides the UE with access to the core network (CN or 5GC), and the core network then provides the UE with access to other UEs and / or data networks (such as packet data networks (e.g., the Internet)).

[0010] TS 23.501 further defines a 5G Service-Based Architecture (SBA) that models services as network functions (NFs) that communicate with each other using a representative state transition application programming interface (Restful API).

[0011] In addition, TS33.501, entitled “Technical Specification Group Services and Systems Aspects; Security Architecture and Processes for 5G Systems,” describes security management details associated with 5G networks, the entire contents of which are incorporated herein by reference.

[0012] Security management is a critical consideration in any communications network environment. However, as efforts continue to improve the architecture and protocols associated with 5G networks to enhance network efficiency and / or subscriber convenience, the security management of data exchanged within these environments can present significant challenges. For example, implementing data privacy algorithms in communications network environments is a technical challenge. Summary of the Invention

[0013] According to one aspect, an apparatus for a user equipment is provided that implements privacy guarantees regarding service requests from a communication network for providing data. The apparatus includes components for: sending a privacy budget to a core network function, wherein the privacy budget at least partially enables the core network function to select a user equipment capable of processing the service request and maintaining guaranteed privacy; receiving a service request from the network function, wherein processing the service request is associated with a privacy cost; obtaining the privacy cost associated with processing the service request; determining whether the privacy cost associated with processing the service request is greater than the privacy budget; and processing the service request based on whether the privacy cost associated with processing the service request is greater than or less than the privacy budget.

[0014] The component for processing a service request based on determining whether the privacy cost associated with processing the service request is greater than the privacy budget can be used to: request an increase in the privacy budget tolerance for the requested network function when the privacy cost associated with processing the service request is greater than the privacy budget; obtain the increased privacy budget; and further determine whether the privacy cost associated with processing the service request is greater than the increased privacy budget; and process the service request based on whether the privacy cost associated with processing the service request is greater than or less than the increased privacy budget.

[0015] The component for processing a service request based on whether the privacy cost associated with processing the service request is greater than the privacy budget or an increased privacy budget can be used to: when the privacy cost associated with processing the service request is less than the privacy budget or an increased privacy budget: execute the service request to generate data; send the generated data to network functions; and send an updated privacy budget to core network functions based on the privacy cost.

[0016] The core network function can be unified data management (UDM).

[0017] The network function can be one of the following: core network model training function; or radio access network model training function.

[0018] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0019] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0020] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0021] The device may include or may be included in a user device.

[0022] According to a second aspect, an apparatus is provided for controlling a core network function for privacy in a communication network, the apparatus comprising components for: receiving a privacy budget from at least one user equipment, wherein the privacy budget is a parameter defining the amount of data that the at least one user equipment considers acceptable for transmission; receiving a discovery request from at least one network function, the discovery request being associated with a service request for data from the at least one user equipment; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with processing the service request is greater than or less than the privacy budget received from the at least one user equipment; and sending a list of user equipment, including user equipment for processing the service request, to the at least one network function.

[0023] This component can also be used to send privacy budget information associated with user devices on a list of user devices to at least one network function.

[0024] This component can also be used to receive at least one updated privacy budget associated with at least one user device after at least one user device has made a service request.

[0025] The device may include core network functions, or may be included in core network functions.

[0026] The core network function can be unified data management (UDM).

[0027] The network function can be one of the following: core network model training function; or radio access network model training function.

[0028] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0029] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0030] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0031] According to a third aspect, an apparatus is provided for a network function that generates a service request for data from at least one user equipment within a communication network. The network function includes components for: sending a discovery request to a core network function associated with the service request for data from the at least one user equipment; receiving from the core network function a list of user equipments including user equipments for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipments; and sending the service request for data to the at least one user equipment selected and / or scheduled from the list of user equipments.

[0032] This component can also be used to receive privacy budget information associated with user devices on a list of user devices from core network functions.

[0033] This component can also be used to: receive a privacy budget tolerance increase request from at least one user device; and send an increased privacy budget to at least one user device, or a response to reject the increased privacy budget.

[0034] The component for selecting and / or scheduling at least one user device from a list of user devices can be used for at least one of the following: randomly selecting and / or scheduling at least one user device from a list of user devices to reduce the privacy costs or budget associated with processing a service request; selecting and / or scheduling at least one user device from a list of user devices based on at least one other subsample of user devices from the list of user devices to reduce the privacy costs or budget associated with processing a service request; or selecting and / or scheduling at least one user device from a list of user devices based at least on the associated privacy budget of the user device.

[0035] The core network function can be unified data management (UDM).

[0036] The device may include network functionality or may be included in network functionality.

[0037] The network function can be one of the following: core network model training function; or radio access network model training function.

[0038] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0039] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0040] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0041] According to a fourth aspect, a method is provided for a user equipment that implements privacy guarantees regarding service requests from a communication network for providing data. The method includes: sending a privacy budget to a core network function, wherein the privacy budget at least partially enables the core network function to select a user equipment capable of processing the service request and maintaining guaranteed privacy; receiving a service request from the network function, wherein processing the service request is associated with a privacy cost; obtaining the privacy cost associated with processing the service request; determining whether the privacy cost associated with processing the service request is greater than the privacy budget; and processing the service request based on whether the privacy cost associated with processing the service request is greater than or less than the privacy budget.

[0042] Processing a service request based on determining whether the privacy cost associated with processing the service request is greater than the privacy budget may include: when the privacy cost associated with processing the service request is greater than the privacy budget: requesting an increase in the privacy budget tolerance for the requested network function; obtaining the increased privacy budget; and further determining whether the privacy cost associated with processing the service request is greater than the increased privacy budget; and processing the service request based on whether the privacy cost associated with processing the service request is greater than or less than the increased privacy budget.

[0043] Processing a service request based on whether the privacy cost associated with processing the service request is greater than the privacy budget or an increased privacy budget may include: when the privacy cost associated with processing the service request is less than the privacy budget or an increased privacy budget: executing the service request to generate data; sending the generated data to network functions; and sending an updated privacy budget to core network functions based on the privacy cost.

[0044] The core network function can be unified data management (UDM).

[0045] The network function can be one of the following: core network model training function; or radio access network model training function.

[0046] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0047] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0048] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0049] The device may include or may be included in a user device.

[0050] According to a fifth aspect, a method is provided for an apparatus for controlling a core network function of privacy in a communication network, the method comprising: receiving a privacy budget from at least one user equipment, wherein the privacy budget is a parameter defining the amount of data that the at least one user equipment considers acceptable for transmission; receiving a discovery request from at least one network function, the discovery being associated with a service request for data from the at least one user equipment; estimating a privacy budget or cost associated with processing the service request; determining whether the estimated privacy budget cost associated with processing the service request is greater than or less than the privacy budget received from the at least one user equipment; and sending a list of user equipment, including user equipment for processing the service request, to the at least one network function.

[0051] The method may also include sending privacy budget information associated with user devices on a list of user devices to at least one network function.

[0052] The method may also include receiving at least one updated privacy budget associated with at least one user device after at least one user device has made a service request.

[0053] This method can be included in core network functions.

[0054] The core network function can be unified data management (UDM).

[0055] The network function can be one of the following: core network model training function; or radio access network model training function.

[0056] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0057] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0058] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0059] According to a sixth aspect, a method is provided for an apparatus for a network function that generates a service request for data from at least one user equipment within a communication network, the method comprising: sending a discovery request to a core network function associated with the service request for data from at least one user equipment; receiving from the core network function a list of user equipments including user equipments for processing the service request; selecting and / or scheduling at least one user equipment from the list of user equipments; and sending the service request for data to the at least one user equipment selected and / or scheduled from the list of user equipments.

[0060] The method may also include receiving privacy budget information associated with user devices on a list of user devices from core network functions.

[0061] The method may further include: receiving a privacy budget tolerance increase request from at least one user device; and sending an increased privacy budget to at least one user device, or a response for rejecting the increased privacy budget.

[0062] Selecting and / or scheduling at least one user device from a list of user devices may include at least one of the following: randomly selecting and / or scheduling at least one user device from a list of user devices to reduce privacy costs or budget associated with processing a service request; selecting and / or scheduling at least one user device from a list of user devices based on at least one other subsample of user devices from the list of user devices to reduce privacy costs or budget associated with processing a service request; or selecting and / or scheduling at least one user device from a list of user devices based at least on the privacy budget associated with the user device.

[0063] The core network function can be unified data management (UDM).

[0064] This method can be included in network functionality.

[0065] The network function can be one of the following: core network model training function; or radio access network model training function.

[0066] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0067] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0068] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0069] According to a seventh aspect, an apparatus for a user equipment is provided, the user equipment implementing privacy guarantees regarding service requests from a communication network for providing data, the apparatus comprising: at least one processor and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least: send a privacy budget to a core network function, wherein the privacy budget at least partially causes the core network function to select a user equipment capable of processing the service request and maintaining guaranteed privacy; receive a service request from the network function, wherein processing of the service request is associated with a privacy cost; obtain the privacy cost associated with processing the service request; determine whether the privacy cost associated with processing the service request is greater than the privacy budget; and process the service request based on whether the privacy cost associated with processing the service request is greater than or less than the privacy budget.

[0070] An apparatus that is configured to process a service request based on whether the privacy cost associated with processing the service request is greater than the privacy budget can be configured to: when the privacy cost associated with processing the service request is greater than the privacy budget: request an increase in the privacy budget tolerance for the requested network function; obtain the increased privacy budget; and further determine whether the privacy cost associated with processing the service request is greater than the increased privacy budget; and process the service request based on whether the privacy cost associated with processing the service request is greater than or less than the increased privacy budget.

[0071] An apparatus that is made to process a service request based on whether the privacy cost associated with processing the service request is greater than the privacy budget or an increased privacy budget can be made to: execute the service request to generate data; send the generated data to a network function; and send an updated privacy budget to a core network function based on the privacy cost when the privacy cost associated with processing the service request is less than the privacy budget or an increased privacy budget.

[0072] The core network function can be unified data management (UDM).

[0073] The network function can be one of the following: core network model training function; or radio access network model training function.

[0074] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0075] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0076] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0077] The device may include or may be included in a user device.

[0078] According to an eighth aspect, an apparatus for a core network function configured to control privacy in a communications network is provided. The apparatus includes: at least one processor and at least one memory storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: receive a privacy budget from at least one user equipment, wherein the privacy budget is a parameter defining the amount of data that the at least one user equipment considers acceptable for transmission; receive a discovery request from at least one network function associated with a service request for data from the at least one user equipment; estimate a privacy budget or cost associated with processing the service request; determine whether the estimated privacy budget cost associated with processing the service request is greater than or less than the privacy budget received from the at least one user equipment; and send a list of user equipment, including user equipment for processing the service request, to the at least one network function.

[0079] The device can also be configured to send privacy budget information associated with user devices on a list of user devices to at least one network function.

[0080] The device can also be configured to receive at least one updated privacy budget associated with at least one user device after at least one user device has made a service request.

[0081] The device may include core network functions, or may be included in core network functions.

[0082] The core network function can be unified data management (UDM).

[0083] The network function can be one of the following: core network model training function; or radio access network model training function.

[0084] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0085] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0086] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0087] According to a ninth aspect, an apparatus for a network function is provided, the network function being configured to generate a service request for data from at least one user equipment within a communication network, the apparatus comprising: at least one processor and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least: send a discovery request to a core network function, the discovery request being associated with a service request for data from at least one user equipment; receive from the core network function a list of user equipments including user equipments for processing the service request; select and / or schedule at least one user equipment from the list of user equipments; and send the service request for data to the at least one user equipment selected and / or scheduled from the list of user equipments.

[0088] The device can also be enabled to receive privacy budget information associated with user devices on a list of user devices from core network functions.

[0089] The device can also be configured to: receive a request to increase the privacy budget tolerance from at least one user equipment; and send an increased privacy budget to at least one user equipment, or a response to reject the increased privacy budget.

[0090] The device may also be configured to select and / or schedule at least one user device from a list of user devices that are configured to perform at least one of the following: randomly select and / or schedule at least one user device from the list of user devices to reduce the privacy costs or budget associated with the processing of service requests; select and / or schedule at least one user device from the list of user devices based on at least one other subsample of user devices from the list of user devices to reduce the privacy costs or budget associated with the processing of service requests; or select and / or schedule at least one user device from the list of user devices based at least on the associated privacy budget of the user device.

[0091] The core network function can be unified data management (UDM).

[0092] The device may include network functionality or be included in network functionality.

[0093] The network function can be one of the following: core network model training function; or radio access network model training function.

[0094] The core network model training function can be the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0095] Service requests may include one of the following: a joint learning model request; a training data request; or a collaborative training request.

[0096] A privacy budget may include one of the following: a privacy budget associated with all data types; or at least two privacy budgets, each associated with a data type.

[0097] According to some other aspects, a computer-readable medium including program instructions is provided for causing a device to perform at least the methods disclosed above.

[0098] According to some additional aspects, a system is provided that includes components for the following:

[0099] Receive privacy budget, where the privacy budget is a parameter that defines the amount of data that can be accepted to be sent;

[0100] Send a discovery request, which is associated with a service request for the data;

[0101] Receive a discovery request, which is associated with a service request for data;

[0102] Estimate the privacy budget or costs associated with processing service requests;

[0103] Determine whether the estimated privacy budget cost associated with processing the service request is greater than or less than the privacy budget;

[0104] Send a list of user devices to handle service requests;

[0105] Receive a list of user devices used to process service requests;

[0106] Select and / or schedule at least one user device from the list of user devices; and

[0107] A service request to send data to at least one user equipment selected and / or scheduled from a list of user equipment.

[0108] A system includes: at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, cause the system to at least:

[0109] Receive privacy budget, where the privacy budget is a parameter that defines the amount of data that can be accepted to be sent;

[0110] Send a discovery request, which is associated with a service request for the data;

[0111] Receive a discovery request, which is associated with a service request for data;

[0112] Estimate the privacy budget or costs associated with processing service requests;

[0113] Determine whether the estimated privacy budget cost associated with processing the service request is greater than or less than the privacy budget;

[0114] Send a list of user devices to handle service requests;

[0115] Receive a list of user devices used to process service requests;

[0116] Select and / or schedule at least one user device from the list of user devices; and

[0117] A service request to send data to at least one user equipment selected and / or scheduled from a list of user equipment.

[0118] An apparatus comprising components for performing actions of the methods described above.

[0119] An apparatus configured to perform the actions of the methods described above.

[0120] A computer program comprising program instructions for causing a computer to perform the methods described above.

[0121] A computer program product stored on a medium can cause a device to perform the methods described herein.

[0122] According to one aspect, a non-transitory or transient computer-readable medium is provided, comprising program instructions for causing a device to perform a method according to at least any of the foregoing aspects.

[0123] Many different embodiments have been described above. It should be understood that other embodiments may be provided by combination of any two or more of the embodiments described above. Attached Figure Description

[0124] The embodiments will now be described by way of example only, with reference to the accompanying drawings, in which:

[0125] Figure 1 Representations of a network system according to some example embodiments are shown;

[0126] Figure 2 A representation of a control device according to some example embodiments is shown;

[0127] Figure 3 A representation of an apparatus according to some example embodiments is shown;

[0128] Figures 4a to 4c The signaling framework is shown, illustrating the overall privacy budget for network transmission and management of the UE; and

[0129] Figure 5 and Figure 6A diagram illustrating example scheduling improvements in privacy budget control is shown;

[0130] Figure 7 A schematic diagram of an example gNB including a scheduler and a DP is shown according to some embodiments;

[0131] Figure 8 As shown Figure 7 The diagram shows an example DP; and

[0132] Figures 9 to 11 Examples of some embodiments are shown. Figure 7 The diagram shows an example scheduler. Detailed Implementation

[0133] In the following explanation, certain embodiments are described with reference to a device capable of communicating with a communication system serving such a device. Before explaining the exemplary embodiments in detail, refer to... Figure 1 , Figure 2 and Figure 3 A brief explanation of some general principles of communication systems (e.g., 5G communication systems) including access networks (ANs) and core networks, and devices (e.g., terminals served by the communication system) to aid in understanding the technology on which the examples are based.

[0134] Figure 1 A schematic diagram of a 5G wireless communication system (5GS) is shown. 5GS can consist of a radio access network (RAN) (e.g., a 5G radio access network or a next-generation radio access network), a 5G core network (5GC), one or more application functions (AFs), and one or more data networks (DNs). In some embodiments, an AF is a customer of the 5GC and is connected to the 5GC's user plane function (UPF) via the DN and to the 5GC's network function (NF) via the 5GC's network exposure function (NEF). In some embodiments, an AF is a trusted application function, and therefore the trusted AF is implemented in the 5GC and directly connected to other NFs of the 5GC. AFs may include functions for performing training using federated learning and for selecting terminals (such as UEs) to connect to participating FLs of the 5GC, as described in further detail below. It can be understood that, although... Figure 1 The diagram shows only one UPF, but 5GS can consist of a series of UPFs, including UPF anchors connected to the DN. The connection between the AF and the NEF and UPF (or the AF and NF of 5GC) is achieved via interfaces defined in the 3GPP standard.

[0135] 5GC may include, for example, the following network functions (NFs) (also known as network entities): Network Slice Selection Function (NSSF); Network Exposure Function (NEF); Network Repository Function (NRF); Network Data Analysis Function (NWDAF); Policy Control Function (PCF); Unified Data Management (UDM); Authentication Server Function (AUSF); Access and Mobility Management Function (AMF); and Session Management Function (SMF). 5GC NFs may have a service-based architecture as described in 3GPP standard TR 23.501. In 3GPP standards, particularly TR 23.501 and 23.502, the NF services that 5GC NFs can provide and the service-based interfaces of 5GC NFs are described.

[0136] Terminal access to 5GC typically occurs via an access network, such as a 5G Radio Access Network (5G-RAN). A 5G-RAN may include one or more base stations (e.g., gNodeBs (gNBs)). A gNB in ​​a 5G-RAN may include a gNB distributed unit connected to the gNB central unit and a remote radio head unit connected to the gNB distributed unit. In some embodiments, one or more base stations in the 5G-RAN may be evolved NodeBs (eNBs). In some embodiments, the 5G-RAN may be a 3GPP radio access network (e.g., a RAN operating using NR or LTE radio access technologies as defined in 3GPP standards). Although Figure 1 The diagram illustrates 5G-RAN, but those skilled in the art will understand that access to the 5GC can be made via any wireless or wired access network, such as non-3GPP access networks (e.g., an untrusted WLAN accessing the 5GC via a non-3GPP Interoperability Function (N3IWF), a trusted WLAN accessing the 5GC via a trusted non-3GPP Gateway Function (TNGF), or a wired network accessing the 5G via a wired Access Network Gateway Function (W-AGF)). Non-3GPP access networks are access networks not configured to communicate directly with a core network having the architecture and operation defined in the 3GPP standard.

[0137] Figure 2 The diagram illustrates what can be implemented. Figure 1The illustrated device 200 is an example of one or more NFs of 5GC. Device 200 may include at least one random access memory (RAM) 211a, at least one read-only memory (ROM) 211b, at least one processor 212, 213, and a network interface 214. At least one processor 212, 213 may be coupled to RAM 211a and ROM 211b. At least one processor 212, 213 may be configured to execute software code 215. Software code 215 may, for example, include instructions for performing actions or operations of one or more NFs of 5GC. In some embodiments, software code 215 may include instructions for performing one or more actions or operations related to federated learning (FL) or privacy budget control according to aspects of this disclosure. Software code 215 may be stored in ROM 211b. Device 200 may implement one or more NFs of 5GC and may interconnect with another device 200 implementing one or more other NFs of 5GC. In such embodiments, device 200 may be part of a distributed computing system. In some embodiments, each NF of 5GC may be implemented on a single device 200. In such an embodiment, device 200 may be a cloud computing system.

[0138] Figure 3 The diagram shows... Figure 1 The illustrated device 300 is an example. Device 300 can be any wireless communication device capable of transmitting and receiving radio signals. Non-limiting examples of device 300 include terminals, wireless communication devices, user equipment, mobile stations (MS) or mobile devices (such as mobile phones or so-called 'smartphones'), computers equipped with wireless interface cards or other wireless interface facilities (e.g., USB dongles), personal data assistants (PDAs) or tablets equipped with wireless communication capabilities, machine-type communication (MTC) devices, Internet of Things (IoT) type communication devices, or any combination of these devices. Device 300 can be configured to communicate via a 5G-RAN base station with base stations in access networks such as 5G-RAN and 5GC (e.g., NG eNB or gNB) using non-access stratum (NAS) signaling, for example, to perform data communication. Communication may include or carry one or more of voice, email, text messages, multimedia, data, machine data, etc.

[0139] Device 300 can receive wireless signals (e.g., radio or cellular signals) via an air or radio interface 307 (typically referred to as a Uu interface) through a suitable means 306 for receiving wireless signals, and can transmit wireless signals (e.g., wireless or cellular signals) via a suitable means for transmitting wireless signals. Figure 3In this embodiment, device 306 includes one or more antennas (or an antenna array including multiple antennas) and a transceiver, and is schematically designated by block 306. Device 306 may be provided, for example, by means of radio components and associated antenna arrangements including one or more antennas. The antenna arrangements may be arranged inside or outside the mobile device.

[0140] The device 300 may include at least one processor 301, at least one memory ROM 302a, at least one RAM 302b, and other possible components 303 for software and hardware-assisted execution of tasks it is designed to perform, including controlling access to and communication with access networks such as 5G-RAN and other devices 300. At least one processor 301 is coupled to RAM 311a and ROM 311b. At least one processor 301 may be configured to execute appropriate software code 308. The software code 308 may include, for example, instructions that, when executed by at least one processor 301, perform one or more actions or operations of this aspect. The software code 308 may be stored in ROM 311b.

[0141] At least one processor 301, storage device, and other related control devices may be disposed on a suitable circuit board and / or chipset. This feature is indicated by reference numeral 304. Terminal 300 may optionally have a user interface, such as a keypad 305, a touch-sensitive display or touch-sensitive tablet, or a combination thereof. Depending on the type of device, one or more of a display, speaker, and microphone may optionally be provided.

[0142] The control or configuration of such communication systems is traditionally implemented through control mechanisms that operate based on defined rules. To improve network performance (i.e., the performance of networks in communication systems such as 5GS), control mechanisms have been proposed for implementing machine learning (ML) models. In these models, network and / or administrative data from numerous network entities within the communication system can be processed by the ML model to generate appropriate control outputs for such systems. Training of the ML model is centralized. Network and / or administrative data is collected by network entities (often referred to as distributed nodes) and provided to a single network entity (often referred to as a central node) to train the ML model using the received data.

[0143] To minimize the amount of data exchanged between distributed nodes and the central node (typically model training occurs at the central node (hereinafter referred to as model training)) and to reduce the loss of privacy for each node's data, the model can be trained using Joint Learning (FL). In FL, instead of training the model at the central node using centralized data, the central node provides a global model, including parameters or data, to the distributed nodes, and each distributed node performs local training on its local model during FL iterations using a dataset that includes the distributed node's data (hereinafter referred to as local model training). In other words, each distributed node has a dataset (hereinafter referred to as the local dataset) and trains its local model using its own local dataset (i.e., performs local model training). In the following disclosure, the terms local training and local model training are used interchangeably. For each iteration of FL, each distributed node then sends its local training results (e.g., the 'learned' parameters of its local model) to the central node.

[0144] During each iteration of FL, the central node receives the local training results of the local model from the distributed nodes, and combines or aggregates the local training results to obtain new global model parameters or data (global training results of the global model).

[0145] Local training results can include values ​​of parameters used for the local model, while global training results can include aggregated values ​​of parameters used for the global model.

[0146] Then, in further iterations of FL, new global model parameters or data (e.g., aggregated received local training parameter values) can be sent to the distributed nodes, and the distributed nodes use these “new” global model parameters as parameters for their local models and perform further local training of the local models to learn the new local model parameters. This process can be repeated until the values ​​of the global model parameters are optimized. The process of training local models at different distributed nodes is known to those skilled in the art and therefore will not be described in further detail. For example, federated learning and local and global models are further described in “Federated Optimization: Distributed Optimization Beyond the Datacenter” by Konecný, Jakub, HB McMahan, and Daniel Ramage (ArXiv abs / 1511.03575 (2015)).

[0147] As mentioned above, one problem that has been raised but not fully resolved is ensuring privacy regarding information provided by the device or UE (e.g., information in the form of a local model provided by the UE). One approach to attempting to measure and control privacy and privacy breaches (where, over time, the UE provides sufficient information for a third party to identify the UE or determine information that the UE's users consider private) is differential privacy.

[0148] Differential privacy (DP), as discussed in "Calibrating noise tosensitivity in private data analysis" (Theory of Cryptography conference 2006) by Dwork, C., McSherry, F., Nissim, K., and Smith, A., was initially proposed to provide formal privacy guarantees when common anonymization techniques, such as k-anonymity and l-divergence, are insufficient or unavailable. DP is a statistical technique that, when used with algorithms or data, guarantees the privacy of individuals within a dataset, regardless of how the output of the algorithm or data is further processed.

[0149] The initial motivation for proposing this robust definition of privacy stemmed from the observation that combining data from different sources could compromise privacy.

[0150] DP guarantees provide a mathematical upper bound on the risk of disclosing information about individual data sources. DP guarantees allow for the precise quantification of the acceptable level of individual risk. DP is described using probability theory, and mathematically, it can be defined as follows.

[0151] If a data entry can be obtained by replacing another data entry, then the two datasets... X and Y They are neighbors. (Assuming...) ε >0 and δ ∈[0,1]( ε and δ (These are DP parameters). Random function. M ( X ): yes( ε , δ)-DP, or for each pair of adjacent datasets X and Y and each result ,exist: .

[0152] parameter δ This can be interpreted as the probability of a total data breach. ε The smaller the value, the more likely the output is from... X stillY The less likely it is, the less likely it is to happen. In other words, ε and δ The smaller the value, the less likely it is to notice the existence of any individual, and the better the mechanism protects privacy.

[0153] when δ When =0, the DP mechanism is specified as ε -DP. For example, consider a random response: if the data output is a yes / no answer with a probability of 0.5, then the following can be calculated: ε =log3 satisfies the above definition. If the probability p of lying increases, then privacy increases, and ε To become smaller (specifically, In some cases, we must allow non-zero δ (e.g., when adding Gaussian noise).

[0154] In the discrete output randomization function, the data is described by integers 1, ..., n, and... Private mechanism M Data i As input and random output j This makes the data j Output probability p ij So, what is the mechanism? M yes ε -DP, .

[0155] This formula can be interpreted as, for all outputs j , e ε It provides the source i 1 and i The upper limit of the output probability ratio of 2. If the ratio is close to 1 (i.e., if...), ε If the input is close to 0, then any input pair i 1 and i 2. Even an eavesdropping adversary cannot discern the source of the output. In other words, this provides a very robust definition of privacy (this is the worst-case scenario where the adversary is extremely powerful). Furthermore, the DP mechanism maintains the same statistical protection for all post-processing of randomization, meaning that regardless of how the output is processed, an adversary cannot compare the parameters. ε The more specific regional output described originates from i 1 or i 2.

[0156] The following example illustrates how DP can be used to help protect user privacy while allowing UEs to expose datasets containing privacy-sensitive information (e.g., by providing a dataset with added random noise to a machine learning (ML) solution such as federated learning (FL)).

[0157] In the following examples, a privacy budget is considered for each device or UE. Each UE's privacy budget includes the total amount of information that can be disclosed for one or more types of datasets.

[0158] In some examples, the amount of noise to be added can be determined based on differential privacy (DP), specifically based on ( ,δ)-DP, where the smaller The value corresponds to a smaller privacy loss when the DP-protected dataset is publicly disclosed, and a smaller δ value corresponds to a smaller probability of drastic privacy loss, such as being able to discover the entire original dataset. Compared to the original data, The smaller the δ value, the lower the statistical precision of the published data.

[0159] It is generally accepted that low single-digit ε values ​​(i.e., 0 < ε < 5) represent a conservative choice and provide strong privacy protection. Furthermore, larger ε values ​​(i.e., 5 < ε < 20) can also provide strong privacy protection in a variety of settings, and in some cases, even higher ε values ​​(i.e., ε > 20) can still provide meaningful privacy protection.

[0160] In the examples discussed in this paper, a network function (NF) / application function (AF) (e.g., NWDAF) is configured to collect data from a UE or other entity in the network that generates or possesses privacy-sensitive data. The collected data is processed, and the results of this processing are shared with third parties, other UEs, or the general public. Because the processed data (e.g., AI / ML models) may reveal information, privacy enhancement techniques (PET) based on differential privacy (DP) monitoring can be employed for each data release or the function of the data. This monitoring can be achieved through (…). , δ)-DP is used to measure privacy breaches. The smaller the value of δ, the less data is leaked. For example, if the UE participates in the FL training of a centralized model, the total privacy leakage will be with ( The aggregation of all data publishing instances of δ)-DP. The monitoring and control discussed in this paper can be referred to as a privacy budget.

[0161] In these examples, the privacy budget is a parameter configured by the UE (or any entity involved in UDM data collection for any NF / AF purpose) to communicate with the network. In some embodiments, the privacy budget may define the total amount of privacy data leakage (or privacy breach) that the user deems acceptable. In some embodiments, current privacy breaches are monitored, and any further breaches are identified to check whether any further privacy breach would cause the current or total breach (for data types) to exceed the budget, and to determine whether the data can be published.

[0162] Therefore, for example, the following examples or embodiments describe a signaling framework that enables each UE to transmit its total privacy budget to core network functions via AMF, MTLF, and NWDAF.

[0163] This privacy budget information can be used in network functions (NF) as a criterion for selecting whether a UE can be used for a specific service (e.g., for AI / ML training).

[0164] Additionally, in some embodiments, both the UE and the network are able to transmit their estimated remaining privacy budget during the implementation of the service or training process so as not to exceed the privacy budget.

[0165] In some embodiments, a privacy budget may be used, for example, to control the operation of the scheduler in the gNB, to select the UE for implementing the service.

[0166] In other words, the scheduler within the gNB can use the enhancements as subsampling for privacy enhancement techniques (PET), or it can consider the UE's remaining budget at a given time in addition to the traditional standards used for scheduling.

[0167] A privacy budget differs from a privacy target value or privacy loss / leakage. When a function is computed multiple times on the same dataset, some privacy information is leaked at each given time. This leakage is mathematically limited through privacy enhancement techniques such as differential privacy. However, over a period of time or process (e.g., a joint learning training cycle), too much data can be leaked. Therefore, it is necessary to define not only the amount of leakage for the UE and network each time, but also the total amount of information leaked—in other words, to specify a privacy budget that is in the interests of both the UE and the network.

[0168] about Figure 4a The example illustrates the first part of a signaling diagram, where (in this embodiment) the UE is configured to initiate a privacy budget definition operation. Additionally, the example illustrates signaling between core network functions or nodes (and between access network functions and core network functions or nodes) that enables the allocation of services to UEs with a privacy budget available for implementing that service.

[0169] Therefore, for example, as shown in 401, UE 300 is configured to perform an initial registration operation with 5G core network function 406. This registration includes UE privacy budget information defining a privacy budget. In some embodiments, 5G core network function 406 may be a UDM. The privacy budget information may be generic in some embodiments and applicable to all data types, or may include separate or different categories or data types of data budgets. For example, the privacy budget information may include separate privacy budget parameters or elements for a data type called “advertising,” or privacy budget parameters or elements for other third-party services, such as localization, while defining additional or different privacy budget parameters or elements for the “network optimization” data type.

[0170] In some embodiments, the network (or 5G core network function 406) is configured to respond with an 'ok confirmation' message, as shown in 403. The ok confirmation is an acknowledgment of acceptance of the privacy budget information.

[0171] At a certain point in time, core network functions (e.g., 5G core model training functions such as NWDAF 404) or RAN node functions (e.g., RAN node model training function 404) are configured to generate discovery requests to establish which UEs are capable of serving the request.

[0172] For example, as shown in 405, the model training function in the core (5G core model training function 404) sends a service discovery request from the UE. In some embodiments, this request may be FL model training, training data, or collaborative training.

[0173] Additionally, as shown in 407, the model training function in the RAN (RAN node model training function 400) sends a service discovery request from the UE. As described above, this request can be FL model training, training data, or collaborative training.

[0174] Discovery requests can be received by a 5G core NF 406 (such as a UDM or any other core NF), which has access to the received UE privacy budget and can determine the approximate privacy expenditure for each received request. In other words, as shown in 409, the 5G core NF 406 is configured to determine the approximate privacy budget / cost required to serve the received request, and then further identify any or which UE(s) can serve the request based on the privacy budget it previously signaled.

[0175] It is understood that privacy budgets can vary depending on actual or specific requirements. For example, the privacy budget / cost will be highest when requesting actual training data, followed by requests for collaborative training, and then lastly for FL and local training of ML models done at the UE.

[0176] Once determined, as shown in 409, NF 406 can be configured to respond to the requesting node (core ML training function, RAN node, or AF) with a list of UEs (in some embodiments, the corresponding privacy budget associated with the identified UE corresponds to the required service / model training category). Thus, for example, in response to the request shown in 405, 5G core NF 406 is configured to generate a response to the 5G core node (5G core model training function 404), as shown in 411, which has a list of UEs and optionally the corresponding privacy budgets for the UEs on the list. Furthermore, in response to the request shown in 407, 5G core NF 406 is configured to generate a response to the RAN node (RAN node model training function 400), as shown in 413, which has a list of UEs and optionally the corresponding privacy budgets for the UEs on the list.

[0177] A model training node that has received a list of UEs (and optionally the corresponding privacy budgets of the UEs) is configured to schedule or select one or more UEs from the list. The model training node can then send a request to the UE containing information for implementing the service. For example, this information may include the exact ML model to be trained, or the FL operations or training data required to perform training at the network. For instance, a 5G core node (5G core model training function 404) as shown on 515 is configured to send a request to a UE selected or scheduled from the list, including information for performing the requested service. Additionally, 517 shows a RAN node (RAN model training function 400) sending a request to a UE selected or scheduled from the list, including information for performing the requested service.

[0178] about Figure 4b This illustrates the signaling and operations following the receipt of signaling from the UE with information for performing the requested service.

[0179] For example, based on the received request, UE 300 calculates or determines the privacy budget or privacy cost required to serve the request, as shown in 421. The privacy budget may be modified in some embodiments based on the exact data required for training, the type of training service (e.g., complete training data or FL process), and the ML training category (e.g., advertising or network optimization).

[0180] As shown in 422, the UE can then determine whether the service request can be completed within the available privacy budget (in other words, whether the calculated service privacy budget / cost is less than or greater than the remaining privacy budget).

[0181] As shown in 423a, the UE executes the request after it has been determined or calculated that the service request can be completed within the available privacy budget (privacy budget / cost of the service < remaining privacy budget).

[0182] After the service has been performed, the UE can be configured to send a response including the results to the requesting source (5G Core Model Training Function 404 in this example), as shown in 425a.

[0183] Additionally, the UE can be configured to update the remaining privacy budget, as shown in 427a, and send the updated privacy budget to 5G core network function 406 (e.g., UDM) after the service request is completed.

[0184] This could cause 5G core network function 406 (as shown in 429a) to update the UE's stored privacy budget information.

[0185] about Figure 4c The diagram illustrates further signaling and operations following a determination, as shown in 422, of whether a service request can be completed within the available privacy budget (in other words, whether the calculated privacy budget / service cost is less than or greater than the remaining privacy budget). In this example, it is determined that the service request cannot be completed within the available privacy budget.

[0186] The subsequent operation, as shown in 423b, is that if the service request cannot be completed within the available privacy budget (or the calculated privacy budget / cost > the remaining privacy budget), the UE generates a privacy budget tolerance increase request.

[0187] Then, a privacy budget tolerance increase request can be sent to a source or request, as shown in 431b, in this example, the source or request is the 5G core model training function 404.

[0188] The model training function (in this example, the 5G core model training function 404) can then process requests to increase the privacy budget tolerance, as shown in 433b. This processing can be either acceptance, where the privacy tolerance level (budget) can be increased (e.g., from medium to high); or rejection, where the current privacy tolerance level is maintained.

[0189] Then, as shown in 435b, the model training function (in this example, the 5G core model training function 404) is configured to respond to a request. For example, the response may include an increase in privacy requirements (optionally a new, increased privacy budget level) or a response indicating a rejection of the request. This response is then sent back to the UE 300.

[0190] UE 300 is configured to handle this response. For example, as shown in 437b, if the response is an increase in privacy requirements, the UE increases the privacy level, and if the new increased privacy budget allows the service request to be executed, the original request is served.

[0191] Once the original service request is executed, operations 425a and 427a can be performed, the UE sends a response including the result to the source of the request (5G core model training function 404 in this example), updates the remaining privacy budget, and sends the updated privacy budget to 5G core network function 406 (e.g., UDM) after the service request is completed.

[0192] Although not shown in these figures, in some embodiments, the UE may also, after determining whether a service request can be completed within the available privacy budget, generate a response to the original request indicating that the request cannot be served if the service request cannot be completed within the available privacy budget (calculated privacy budget / cost > remaining privacy budget).

[0193] In this way, such as Figures 4a to 4c As shown, the communication system can help the UE maintain privacy by implementing the indicated 'privacy budget' implementation.

[0194] Additionally, in some embodiments, the 'privacy budget' implementation can be extended to the scheduling or selection of the UE by network functions (e.g., access network nodes or gNB / BS) to provide further privacy amplification.

[0195] In some embodiments, an enhanced scheduler may be employed to improve privacy. For example, in the following example, the gNB / BS is a semi-trusted entity (in other words, a "friendly but strange" entity) where the results of FL or UE data shared with the AF / NF are shared to the public via the gNB (NWDAF, NF, AF...). Additionally, in the following example, the UE privatizes its own data before uploading using the current local DP.

[0196] The following two schedulers are shown: the Round Robin (RR) scheduler and the simplified semi-persistent scheduler (Random Channel Scheduler RCS).

[0197] Additionally, two example embodiments of privacy amplification using these schedulers are shown. The first example embodiment is an implementation of an RR scheduler with so-called shuffle amplification, and the second example embodiment is an RCS scheduler with so-called subsampling amplification.

[0198] Regarding the use of the RR scheduler for data collection, privacy amplification can be obtained from shuffling noisy messages.

[0199] As previously indicated, the training function (e.g., the RAN node model training function) can receive a response with a list of UEs from the 5G core NF (wherein the response may optionally include a corresponding privacy budget for each UE on the list). The RR scheduler can then be configured to select or schedule UEs from this list. Requests (e.g., measurement requests to be served by the UEs) can then be generated for these selected and scheduled UEs.

[0200] In these embodiments, the RR scheduler is configured to schedule all devices (or UEs) in a single round but in a random order. This can be done one by one, or in batches and / or blocks.

[0201] For example, available UE IDs are mapped to 0 through 15: [0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15]

[0202] The example RR scheduler can then be configured to schedule all devices (or UEs) in a random order within a single round.

[0203] [4, 5, 14, 1, 0, 6, 9, 3, 8, 12, 7, 13, 15, 2, 11, 10]

[0204] If all device identifiers are removed from the results, the random order introduces additional randomness / indistinguishability. Local noise in the UE or device provides some indistinguishability to the observation of the effect of changing a single UE message, and this indistinguishability is amplified by random permutations.

[0205] The additional randomness introduced by the random order can be mathematically analyzed to obtain formal dynamic programming guarantees. This analysis is equivalent to analyzing a so-called shuffler.

[0206] For example, Figure 5The graph shows two levels of local noise based on non-randomized 501 and randomized 503 scheduling, resulting in local ε of ~4.6 and 2.2 respectively, and an example of how privacy guarantee ε decreases as the number of devices increases (noisy messages are 'lost' more in congestion). ε is calculated using mathematical techniques expressed in Feldman, Vitaly, Audra McMillan, and Kunal Talwar's "Hiding among the clones: A simple and nearly optimal analysis of privacy amplification by shuffling" (2021 IEEE 62nd Annual Symposium on Foundations of Computer Science (FOCS). IEEE, 2022) and Feldman, V., McMillan, A., and Talwar, K.'s (2023) "Stronger privacy amplification by shuffling for Rényi and approximate differential privacy" (In Proceedings of the 2023 Annual ACM-SIAMS Symposium on Discrete Algorithms (SODA), pages 4966–4981. SIAM). The ε value on the y-axis depicts the worst-case privacy risk of observing the impact of a single UE in the scheduler's output. Unlike summation, all individual messages can be seen in the output (without any identifiers), which also helps to remove malicious messages.

[0207] Additionally, the scheduler can be deployed on a round-by-round basis. For example, early scenes with UE IDs mapped to 0 through 15: [0, 1, 2, 3, , 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15] can be mapped based on the following selections from round 1 to round 4.

[0208] In some embodiments, a scheduler may be employed that is configured to randomize the channel conditions for each UE (at least relative to the scheduler’s observer output).

[0209] In these embodiments, the scheduler selects or schedules the UE based on channel conditions (which can therefore be considered random). If the scheduler (appearing random) selects from... nSelect from individual devices or UEs m If a device is used, the subsampling amplification result can be used to calculate or determine the privacy guarantee of the final result.

[0210] Therefore, when all device identifiers are removed, random subsampling introduces additional randomness / indistinguishability. In other words, the device's local noise provides some indistinguishability to the observation of changes in individual messages, and this indistinguishability is amplified by random subsampling.

[0211] This can be done Figure 6 As shown in the figure, where with Figure 5 The example shown is the same, with two levels of local noise resulting in local ε of ~2.2 (as shown in curve 503) and 4.6 (as shown in curve 501). From n Within the total number of devices, there can be 1% random sampling. For this 1% random subset, we reduce any identifiers and thus show the random permutation of messages. This shows how curves 505 and 507 indicate where the privacy guarantee ε decreases as the number of devices increases (compared to curves 501 and 503, respectively). In such an embodiment, through the combination of subsampling and shuffling amplification, individual noisy messages are 'lost' more in the crowd.

[0212] In some embodiments, these results may be reflected in a semi-persistent scheduler implementation.

[0213] about Figure 7 A schematic diagram of an example gNB or suitable RAN node or function for implementing RAN is shown.

[0214] For example, Figure 7 The gNB 711 is shown, which is configured to receive local DP appendage 701 and further output to the network core or application functions or network functions.

[0215] gNB 711 is shown to include a scheduler 713, which is configured to implement the scheduling functions described above and later herein for selecting and scheduling a UE or device to fulfill a service request.

[0216] gNB 711 may also include components configured to be used with respect to... Figure 8 The described method applies additional or supplementary DP modules 715.

[0217] For example, Figure 8 An additional DP module 715 is shown. In some embodiments, the additional DP module 715 includes a total DP measurer / determiner 801 configured to measure the total DP from the scheduler and any additional local DP.

[0218] The determined total DP can be passed to the total DP controller 803, which is configured to determine whether the total DP is sufficient. If the total DP is sufficient, the scheduler output is implemented. However, if the total DP is determined to be insufficient, the additional DP controller 805 is configured to control the scheduler to perform additional subsampling or implement any other DP enhancement mechanism.

[0219] Additional subsamples of the results from the scheduler can be billed based on Rényi DP (RDP).

[0220] Definition 1. Let ε>0 and δ ∈[0,1]. We say that mechanism M is (ε, δ)-DP , If for all adjacent datasets X and Y, and for each measurable set We all have : .

[0221] We will also use Rényi Differential Privacy (RDP) (Mironov, 2017), which is defined as follows. Two distributions P and Q The Rényi divergence of order 1 between λ>1 is defined as (1.1)

[0222] Definition 2. We say that mechanism M is (λ, ε)-RDP , If for all neighboring datasets X and Y, the output distribution M(X) is... M(Y) has a Rényi divergence of at most ε order λ, i.e. , .

[0223] For example, we can use the following formula to convert Rényi DP to an approximate DP:

[0224] Lemma 3 (Canonne et al., 2020). Assume mechanism M is (λ, ε')-RDP . Then, for any ε≥0 Furthermore, M is also (ε, δ(ε))-DP, where (1.2)

[0225] Suppose M is a (λ, ε)-RDP mechanism for adding / removing neighborhood relations. Consider a subsampling mechanism. .if M If it is (λ, ε(λ))-RDP, then It is (λ, ε'(λ))-RDP (λ≥2 is an integer), where

[0226] As an example, suppose the channel is performing random subsampling, caused by conditions that appear random to the scheduler's observer output. It can be assumed that each UE is sampled with a fixed probability γ in each scheduling round.

[0227] Using RDP amplification, privacy amplification of this random subsampling can be achieved, specifically by obtaining the RDP parameters for the output, assuming each UE is sampled with a fixed probability γ. These RDP parameters can be converted using the formula described above. (ε, δ)-DP ensure.

[0228] Therefore, if necessary, further subsampling can be performed from the results of this subsampling if the additional DP module determines that the total DP is not strong enough. In other words, the result obtained through subsampling with a fixed probability γ1 is first calculated. ε' ( λ The value. Then use the obtained ε' ( λ ) value replacement ε ( j The value of ) is calculated, and the expression is calculated using the sampling probability γ2.

[0229] Therefore, the final ( ) can be controlled via γ2. ε, δ How low is the DP guarantee? Therefore, if the sampling randomness with probability γ1 comes from random channel conditions (which cannot be directly affected), the final ( ) can be adjusted by adjusting γ2 of the second sampling. ε, δ -DP guarantee.

[0230] In some embodiments, the scheduler is configured to perform scheduling based on the type of potential requests to be served and the UE's privacy budget. Therefore, in some embodiments, scheduling is configured to utilize the UE's privacy budget information in the gNB while simultaneously performing joint learning of NF / AF in the network.

[0231] In the wireless scheduler 713, the function of scheduling UEs for resource allocation depends on factors such as the UE's instantaneous channel, the UE's data rate budget, and some fairness factors. However, considering privacy budgets, budget data used for scheduling can be used to implement more efficient scheduling.

[0232] For example, Figure 9 A schematic view of an example scheduler 713 is shown. Scheduler 713 is configured to receive the privacy budget of UE 911, UE channel state information 913, target BLER / delay 915, and the number of times (N) the UE has been scheduled before 917.

[0233] Scheduler 713 may also include an FL training determiner / scheduler controller 900 configured to determine whether the scheduler is currently scheduling for a joint learning FL application or another application.

[0234] In some embodiments, the FL training determiner / scheduler controller 900 is configured to control a conventional scheduler 901 to schedule the selection of UEs in non-FL applications and to control a privacy-aware scheduler 903 to schedule the selection of UEs in FL applications.

[0235] Therefore, for example, joint learning can be implemented, where the gNB is collecting data / models / gradients from multiple UEs to train a neural network (NN). Problems arise when some UEs can perform updates with greater latency. Typically, these updates can be safely ignored and included in the next round or the round after that of backpropagation. However, this may not be feasible when considering the privacy budget of the UEs.

[0236] While the above examples allow for better privacy protection and enhancement when the number of UEs (Unique Data Points) is large, the privacy-aware scheduler 903 is configured to schedule UEs with very low privacy budgets when the number of active UEs in the FL training update is large. Conversely, in some embodiments, UEs with higher remaining privacy budgets can be scheduled when no low-budget UEs are available or when the number of participating UEs is small.

[0237] For example, Figure 10 The prioritization order of the conventional scheduler 901 and the privacy-aware scheduler 903 based on channel data information ChU, delay f, the number of times it has been scheduled before N, and the privacy budget of the UE PbU is shown.

[0238] Furthermore, in some embodiments, the conventional scheduler 901 can be modified to implement a privacy-aware scheduler, such as... Figure 11 As shown. In this example, the scheduler includes a UE filter 1101. The UE filter 1101 is configured to remove UEs with very small privacy budgets from the scheduler. This can be implemented, for example, by checking the privacy budget of each scheduler. If the budget is insufficient to complete a full round or a whole round of backpropagation to complete the gradient update, the identified UE is removed from the scheduler list.

[0239] For example, the pseudocode for implementing a filter can be as follows:

[0240] If in FL_mode:

[0241] For each j in PbU, perform:

[0242] If j>=T_fl:

[0243] UE_Schedule_list=UE_schedul_list+j

[0244] PbU is a list of UE privacy budgets directly provided by the 5G core and / or UE.

[0245] FL_mode is the mode in which FL training is performed.

[0246] T_fl is a threshold indicating the privacy budget required for that particular FL.

[0247] UE_schedul_list is a list of eligible UEs for participating in a specific FL.

[0248] It should be understood that these devices may include or be coupled to other units or modules, such as radio sections or radio heads for transmitting and / or receiving. Although these devices have been described as a single entity, different modules and memories may be implemented as one or more physical or logical entities.

[0249] It should be noted that while some embodiments have been described for 5G systems, similar principles can be applied to other networks and communication systems. Therefore, although certain embodiments have been described by way of example with reference to certain example architectures, radio access technologies, and standards of radio access and core networks, these embodiments can be applied to any other suitable form of communication system implementing other radio access technologies besides those illustrated and described herein.

[0250] It should also be noted in this document that although embodiments have been described above, various changes and modifications can be made to the disclosed solutions without departing from the scope of the invention.

[0251] Typically, in various embodiments, the FL aggregator can be implemented as hardware or a dedicated circuit system, software, logic, or any combination thereof. Some aspects of this disclosure can be implemented in hardware, while others can be implemented in firmware or software, which can be executed by a controller, microprocessor, or other computing device, although this disclosure is not limited thereto. While various aspects of this disclosure may be illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it is well understood that, by way of non-limiting example, the blocks, apparatuses, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or a controller or other computing device, or some combination thereof.

[0252] As used in this application, the term "circuit system" may refer to one or more or all of the following: (a) Hardware circuit-only implementations (such as implementations using only analog and / or digital circuit systems), and (b) A combination of hardware circuitry and software, such as (if applicable): (i) A combination of (multiple) analog and / or digital hardware circuit systems with software / firmware; and (ii) Any part of a hardware processor (including multiple digital signal processors), software, and memory (multiple processors) that works together to enable a device (such as a mobile phone or server) to perform various functions, and (c) (Multiple) hardware circuits and / or (multiple) processors, such as (multiple) microprocessors or a portion thereof, which require software (e.g., firmware) to operate, but may be absent when operation is not required.

[0253] This definition of circuit system applies to all uses of the term in this application, including in any claim. As another example, as used herein, the term circuit system also covers implementations of only hardware circuitry or processors (or processors) or a portion thereof, and their accompanying software and / or firmware. For example, and if applicable to a particular claim element, the term circuit system also covers baseband integrated circuits or processor integrated circuits for mobile devices, or similar integrated circuits in servers, cellular network devices, or other computing or network devices.

[0254] Embodiments of this disclosure may be implemented by computer software executable by the data processor of a mobile device (such as in a processor entity), by hardware, or by a combination of software and hardware. Computer software or programs (also referred to as program products, including software routines, applets, and / or macros) may be stored in any device-readable data storage medium, and they include program instructions for performing a specific task. A computer program product may include one or more computer-executable components that, when the program is run, are configured to perform the embodiment. The one or more computer-executable components may be at least one piece of software code or a portion thereof.

[0255] Furthermore, it should be noted in this regard that any block of the logic flow shown in the figure can represent a program step, or an interconnected logic circuit, block and function, or a combination of program steps and logic circuits, blocks and functions. Software can be stored on physical media (such as memory chips or memory blocks implemented within a processor), magnetic media (such as hard disks or floppy disks), and optical media (such as DVDs and their data variants, CDs). Physical media are non-transitory media.

[0256] The memory can be of any type suitable for the local technical environment and can be implemented using any suitable data storage technology, such as semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory. The data processor can be of any type suitable for the local technical environment and, by way of non-limiting example, can include one or more of the following: general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), FPGAs, gate-level circuits, and processors based on multi-core processor architectures.

[0257] The embodiments of this disclosure can be practiced in a variety of components, such as integrated circuit modules. The design of integrated circuits is largely a highly automated process. Complex and powerful software tools can be used to translate logic-level designs into semiconductor circuit designs for etching and formation on semiconductor substrates.

[0258] The independent claims define the scope of protection sought by the various embodiments of this disclosure. Embodiments and features described in this specification that are not within the scope of the independent claims, and if any, are to be interpreted as examples that aid in understanding the various embodiments of this disclosure.

[0259] The foregoing description provides a complete and informative description of exemplary embodiments of the present disclosure by way of non-limiting examples. However, various modifications and adaptations may become apparent to those skilled in the art when read in conjunction with the accompanying drawings and appended claims, given the foregoing description. Nevertheless, all such and similar modifications to the teachings of this disclosure will still fall within the scope of the invention as defined in the appended claims. Indeed, there is also an embodiment that includes a combination of one or more embodiments with any other embodiments previously discussed.

[0260] As used herein, “at least one of the following: ” and “at least one of ” and similar wording (where the list of two or more elements is connected by “and” or “or”) means at least any one of these elements, or at least any two or more of these elements, or at least all of these elements.

[0261] Example Terms

[0262] Example embodiments may be considered in accordance with the following terms.

[0263] Clause 1. An apparatus for a user equipment that implements privacy guarantees regarding service requests for providing data from a communication network, the apparatus comprising components for:

[0264] Send a privacy budget to the core network function, wherein the privacy budget at least partially enables the core network function to select the user equipment that is capable of processing service requests and maintaining guaranteed privacy;

[0265] Receive service requests from network functions, wherein the processing of such service requests is associated with privacy costs;

[0266] Obtain the privacy cost associated with the processing of the service request;

[0267] Determine whether the privacy cost associated with processing the service request exceeds the privacy budget; and

[0268] The service request is processed based on whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget.

[0269] Clause 2. The apparatus according to Clause 1, wherein the component for processing the service request based on determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget is used to:

[0270] When the privacy cost associated with processing the service request exceeds the privacy budget:

[0271] Request an increase in the privacy budget tolerance for the aforementioned network function;

[0272] Obtain the increased privacy budget; and also determine whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and

[0273] The service request is processed based on whether the privacy cost associated with processing the service request is greater than or less than the increased privacy budget.

[0274] Clause 3. The apparatus according to Clause 1 or 2, wherein the component for processing the service request based on determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget or the increased privacy budget is used to:

[0275] When the privacy cost associated with processing the service request is less than the privacy budget or the increased privacy budget:

[0276] The service request is executed to generate data; the generated data is sent to the network function; and an updated privacy budget is sent to the core network function based on the privacy cost.

[0277] Clause 4. The apparatus according to any one of Clauses 1 to 3, wherein the core network function is Unified Data Management (UDM).

[0278] Clause 5. The apparatus according to any one of Clauses 1 to 4, wherein said network function is one of the following:

[0279] Core network model training functionality; or

[0280] Radio access network model training function.

[0281] Clause 6. The apparatus according to Clause 5, wherein the core network model training function includes the model training logic function (MTLF) included in the network data analysis function (NWDAF).

[0282] Clause 7. The device pursuant to any one of Clauses 1 to 6, wherein the service request includes one of the following:

[0283] Joint learning model request;

[0284] Training data request; or

[0285] Collaborative training request.

[0286] Clause 8. The device pursuant to any one of Clauses 1 to 7, wherein the privacy budget includes one of the following:

[0287] Privacy budget associated with all data types; or

[0288] There are at least two privacy budgets, each associated with a data type.

[0289] Clause 9. An apparatus according to any one of Clauses 1 to 8, wherein the apparatus includes or may be included in the user equipment.

[0290] Clause 10. An apparatus for controlling core network functions related to privacy in a communication network, the apparatus comprising components for:

[0291] A privacy budget is received from at least one user device, wherein the privacy budget is a parameter defining the amount of data that the at least one user device considers acceptable for transmission;

[0292] Receive a discovery request from at least one network function, the discovery request being associated with a service request for data from at least one user device;

[0293] Estimate the privacy budget or cost associated with processing the service request;

[0294] Determine whether the estimated privacy budget cost associated with processing the service request is greater than or less than the privacy budget received from the at least one user equipment; send a list of user equipment, including user equipment for processing the service request, to the at least one network function.

[0295] Clause 11. The apparatus according to Clause 10, wherein said component is further configured to: send privacy budget information associated with user devices on the list of user devices to said at least one network function.

[0296] Clause 12. The apparatus according to any one of Clauses 10 or 11, wherein the component is further configured to: receive at least one updated privacy budget associated with at least one user equipment after the at least one user equipment has performed the service request.

[0297] Clause 13. An apparatus according to any one of Clauses 10 to 12, wherein the apparatus includes or is included in the core network function.

[0298] Clause 14. The apparatus according to any one of Clauses 10 to 13, wherein the core network function is Unified Data Management (UDM).

[0299] Clause 15. The apparatus according to any one of Clauses 10 to 14, wherein said network function is one of the following:

[0300] Core network model training functionality; or

[0301] Radio access network model training function.

[0302] Clause 16. The apparatus according to any one of Clauses 10 to 15, wherein the core network model training function is a model training logic function (MTLF) included in the network data analysis function (NWDAF).

[0303] Clause 17. The device pursuant to any one of Clauses 10 to 16, wherein said service request includes one of the following:

[0304] Joint learning model request;

[0305] Training data request; or

[0306] Collaborative training request.

[0307] Clause 18. The apparatus described in Clauses 10 to 17, wherein the privacy budget includes one of the following:

[0308] Privacy budgets associated with all data types;

[0309] There are at least two privacy budgets, each associated with a data type.

[0310] Clause 19. An apparatus for a network function, the network function being used to generate a service request for data from at least one user equipment within a communication network, the network function comprising components for:

[0311] Send a discovery request to the core network function, which is associated with a service request for data from at least one user equipment;

[0312] Receive from the core network function a list of user devices including user devices for processing the service request;

[0313] Select and / or schedule at least one user equipment from the list of user equipment; and

[0314] The service request to send data to at least one user equipment selected and / or scheduled from the list of user equipment.

[0315] Clause 20. The apparatus according to Clause 19, wherein said component is further configured to: receive privacy budget information associated with user equipment on the list of user equipment from said core network function.

[0316] Clause 21. The apparatus according to Clause 19 or 20, wherein said component is further used for:

[0317] Receive a privacy budget tolerance increase request from at least one user device; and

[0318] Send an increased privacy budget to the at least one user device, or a response to reject the increased privacy budget.

[0319] Clause 22. The apparatus according to any one of Clauses 19 to 21, wherein the component for selecting and / or scheduling at least one user equipment from the list of user equipment is used for at least one of the following:

[0320] Randomly select and / or schedule the at least one user device from the list of user devices to reduce the privacy costs or budget associated with processing the service request;

[0321] Based on at least one further subsample of the user devices from the list of user devices, select and / or schedule the at least one user device from the list of user devices to reduce the privacy costs or budget associated with processing the service request; or

[0322] The at least one user device is selected and / or scheduled from the list of user devices, based at least on the associated privacy budget of the user device.

[0323] Clause 23. The apparatus according to any one of Clauses 19 to 22, wherein the core network function may be Unified Data Management (UDM).

[0324] Clause 24. The apparatus according to any one of Clauses 19 to 23, wherein the apparatus includes or is included in the network functionality.

[0325] Clause 25. The apparatus according to any one of Clauses 19 to 24, wherein said network function is one of the following:

[0326] Core network model training functionality; or

[0327] Radio access network model training function.

[0328] Clause 26. The apparatus according to any one of Clauses 19 to 25, wherein the core network model training function is a model training logic function (MTLF) included in the network data analysis function (NWDAF).

[0329] Clause 27. The device pursuant to any one of Clauses 19 to 26, wherein the service request includes one of the following:

[0330] Joint learning model request;

[0331] Training data request; or

[0332] Collaborative training request.

[0333] Clause 28. The apparatus pursuant to any one of Clauses 19 to 27, wherein the privacy budget includes one of the following:

[0334] Privacy budget associated with all data types; or

[0335] There are at least two privacy budgets, each associated with a data type.

[0336] Clause 29. A method for a user equipment, the user equipment implementing privacy guarantees regarding service requests from a communication network for providing data, the method comprising:

[0337] Send a privacy budget to the core network function, wherein the privacy budget at least partially enables the core network function to select the user equipment that is capable of processing service requests and maintaining guaranteed privacy;

[0338] Receive service requests from network functions, wherein the processing of such service requests is associated with privacy costs;

[0339] Obtain the privacy cost associated with the processing of the service request;

[0340] Determine whether the privacy cost associated with processing the service request exceeds the privacy budget; and

[0341] The service request is processed based on whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget.

[0342] Clause 30. The method according to Clause 29, wherein processing the service request based on determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget includes:

[0343] When the privacy cost associated with processing the service request exceeds the privacy budget:

[0344] Request an increase in the privacy budget tolerance for the aforementioned network function;

[0345] Obtain the increased privacy budget; and also determine whether the privacy cost associated with the processing of the service request is greater than the increased privacy budget; and

[0346] The service request is processed based on whether the privacy cost associated with processing the service request is greater than or less than the increased privacy budget.

[0347] Clause 31. The method according to any one of Clauses 29 or 30, wherein processing the service request based on determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget or the increased privacy budget includes:

[0348] When the privacy cost associated with processing the service request is less than the privacy budget or the increased privacy budget:

[0349] Execute the service request to generate data;

[0350] Send the generated data to the network function; and

[0351] The updated privacy budget is sent to the core network functions based on the privacy cost.

[0352] Clause 32. The method according to any one of Clauses 29 to 31, wherein the core network function is Unified Data Management (UDM).

[0353] Clause 33. The method according to any one of Clauses 29 to 32, wherein said network function is one of the following:

[0354] Core network model training functionality; or

[0355] Radio access network model training function.

[0356] Clause 34. The method according to any one of Clauses 29 to 33, wherein the core network model training function is the model training logic function (MTLF) included in the network data analysis function (NWDAF).

[0357] Clause 35. The method pursuant to any one of Clauses 29 to 34, wherein the service request includes one of the following:

[0358] Joint learning model request;

[0359] Training data request; or

[0360] Collaborative training request.

[0361] Clause 36. The method according to any one of Clauses 29 to 35, wherein the privacy budget includes one of the following:

[0362] Privacy budget associated with all data types; or

[0363] There are at least two privacy budgets, each associated with a data type.

[0364] Clause 37. The method according to any one of Clauses 29 to 36, wherein the apparatus includes or is included in the user equipment.

[0365] Clause 38. A method for controlling core network functions related to privacy in a communication network, the method comprising:

[0366] A privacy budget is received from at least one user device, wherein the privacy budget is a parameter defining the amount of data that the at least one user device considers acceptable for transmission;

[0367] Receive a discovery request from at least one network function, the discovery request being associated with a service request for data from at least one user device; estimate the privacy budget or cost associated with processing the service request;

[0368] Determine whether the estimated privacy budget cost associated with processing the service request is greater than or less than the privacy budget received from the at least one user device;

[0369] Send a list of user devices, including user devices for processing the service request, to the at least one network function.

[0370] Clause 39. The method according to Clause 38 further includes sending privacy budget information associated with user devices on the list of user devices to the at least one network function.

[0371] Clause 40. The method according to any one of Clauses 38 or 39 further includes receiving at least one updated privacy budget associated with the at least one user device after the at least one user device performs the service request.

[0372] Clause 41. The method pursuant to any one of Clauses 38 to 40 is included in the core network function.

[0373] Clause 42. The method according to any one of Clauses 38 to 41, wherein the core network function is Unified Data Management (UDM).

[0374] Clause 43. The method according to any one of Clauses 38 to 42, wherein said network function is one of the following:

[0375] Core network model training functionality; or

[0376] Radio access network model training function.

[0377] Clause 44. The method according to any one of Clauses 38 to 43, wherein the core network model training function is the model training logic function (MTLF) included in the network data analysis function (NWDAF).

[0378] Clause 45. The method pursuant to any one of Clauses 38 to 44, wherein the service request includes one of the following:

[0379] Joint learning model request;

[0380] Training data request; or

[0381] Collaborative training request.

[0382] Clause 46. The method according to any one of Clauses 38 to 45, wherein the privacy budget includes one of the following:

[0383] Privacy budgets associated with all data types;

[0384] There are at least two privacy budgets, each associated with a data type.

[0385] Clause 47. A method for an apparatus for a network function, the network function being used to generate a service request for data from at least one user equipment within a communication network, the method comprising:

[0386] Send a discovery request to the core network function, which is associated with a service request for data from at least one user equipment;

[0387] Receive from the core network function a list of user devices including user devices for processing the service request;

[0388] The service request includes selecting and / or scheduling at least one user device from the list of user devices; and sending data to at least one user device selected and / or scheduled from the list of user devices.

[0389] Clause 48. The method described in Clause 47 further includes receiving privacy budget information associated with user equipment on the list of user equipment from the core network function.

[0390] Clause 49. The methods described pursuant to Clause 47 or Clause 48 further include:

[0391] Receive a privacy budget tolerance increase request from at least one user device; and

[0392] Send an increased privacy budget to the at least one user device, or a response to reject the increased privacy budget.

[0393] Clause 50. The method according to any one of Clauses 47 to 49, wherein selecting and / or scheduling at least one user equipment from the list of user equipment comprises at least one of the following:

[0394] Randomly select and / or schedule the at least one user device from the list of user devices to reduce the privacy costs or budget associated with processing the service request;

[0395] Based on at least one further subsample of the user devices from the list of user devices, select and / or schedule the at least one user device from the list of user devices to reduce the privacy costs or budget associated with processing the service request; or

[0396] The at least one user device is selected and / or scheduled from the list of user devices, based at least on the associated privacy budget of the user device.

[0397] Clause 51. The method according to any one of Clauses 47 to 50, wherein the core network function is Unified Data Management (UDM).

[0398] Clause 52. The method pursuant to any one of Clauses 47 to 51 is included in the network function.

[0399] Clause 53. The method according to any one of Clauses 47 to 52, wherein said network function is one of the following:

[0400] Core network model training functionality; or

[0401] Radio access network model training function.

[0402] Clause 54. The method according to any one of Clauses 47 to 53, wherein the core network model training function is the Model Training Logic Function (MTLF) included in the Network Data Analysis Function (NWDAF).

[0403] Clause 55. The method pursuant to any one of Clauses 47 to 53, wherein the service request includes one of the following:

[0404] Joint learning model request;

[0405] Training data request; or

[0406] Collaborative training request.

[0407] Clause 56. The method according to any one of Clauses 47 to 54, wherein the privacy budget includes one of the following:

[0408] Privacy budget associated with all data types; or

[0409] There are at least two privacy budgets, each associated with a data type.

[0410] Clause 57. An apparatus for a user equipment, the user equipment implementing privacy guarantees regarding service requests for providing data from a communication network, the apparatus comprising: at least one processor and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least:

[0411] Send a privacy budget to the core network function, wherein the privacy budget at least partially enables the core network function to select the user equipment that is capable of processing service requests and maintaining guaranteed privacy;

[0412] Receive a service request from a network function, wherein processing of the service request is associated with privacy costs; obtain the privacy costs associated with the processing of the service request;

[0413] Determine whether the privacy cost associated with processing the service request exceeds the privacy budget; and

[0414] The service request is processed based on whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget.

[0415] Clause 58. The apparatus according to Clause 57 is configured to process the service request based on determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget, thereby enabling:

[0416] When the privacy cost associated with processing the service request exceeds the privacy budget:

[0417] Request an increase in the privacy budget tolerance for the aforementioned network function;

[0418] Obtain an increased privacy budget; and

[0419] It also determines whether the privacy cost associated with the processing of the service request exceeds the increased privacy budget; and

[0420] The service request is processed based on whether the privacy cost associated with processing the service request is greater than or less than the increased privacy budget.

[0421] Clause 59. The apparatus pursuant to any one of Clauses 57 or 58 is configured to process the service request based on determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget or the increased privacy budget, such that:

[0422] When the privacy cost associated with processing the service request is less than the privacy budget or the increased privacy budget:

[0423] Execute the service request to generate data;

[0424] Send the generated data to the network function; and

[0425] The updated privacy budget is sent to the core network functions based on the privacy cost.

[0426] Clause 60. The apparatus pursuant to any one of Clauses 57 to 59, wherein the core network function is Unified Data Management (UDM).

[0427] Clause 61. The apparatus according to any one of Clauses 57 to 60, wherein said network function is one of the following:

[0428] Core network model training functionality; or

[0429] Radio access network model training function.

[0430] Clause 62. The apparatus according to any one of Clauses 57 to 61, wherein the core network model training function is a model training logic function (MTLF) included in the network data analysis function (NWDAF).

[0431] Clause 63. The device pursuant to any one of Clauses 57 to 62, wherein the service request includes one of the following:

[0432] Joint learning model request;

[0433] Training data request; or

[0434] Collaborative training request.

[0435] Clause 64. The apparatus pursuant to any one of Clauses 57 to 63, wherein the privacy budget includes one of the following:

[0436] Privacy budget associated with all data types; or

[0437] There are at least two privacy budgets, each associated with a data type.

[0438] Clause 65. An apparatus pursuant to any one of Clauses 57 to 64 includes or is included in the user equipment.

[0439] Clause 66. An apparatus for a core network function configured to control privacy in a communications network, the apparatus comprising: at least one processor and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least:

[0440] A privacy budget is received from at least one user device, wherein the privacy budget is a parameter defining the amount of data that the at least one user device considers acceptable for transmission;

[0441] Receive a discovery request from at least one network function, the discovery request being associated with a service request for data from at least one user device;

[0442] Estimate the privacy budget or cost associated with processing the service request;

[0443] Determine whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user device;

[0444] Send a list of user devices, including user devices for processing the service request, to the at least one network function.

[0445] Clause 67. The apparatus according to Clause 66 is also configured to send privacy budget information associated with user devices on the list of user devices to the at least one network function.

[0446] Clause 68. The apparatus pursuant to any one of Clauses 66 or 57 is also configured to receive at least one updated privacy budget associated with the at least one user device after the at least one user device has made the service request.

[0447] Clause 69. An apparatus pursuant to any one of Clauses 66 to 68 includes, or is included in, the core network function.

[0448] Clause 70. The apparatus pursuant to any one of Clauses 66 to 69, wherein the core network function is Unified Data Management (UDM).

[0449] Clause 71. The apparatus according to any one of Clauses 66 to 70, wherein said network function is one of the following:

[0450] Core network model training functionality; or

[0451] Radio access network model training function.

[0452] Clause 72. The apparatus according to any one of Clauses 66 to 71, wherein the core network model training function is a model training logic function (MTLF) included in the network data analysis function (NWDAF).

[0453] Clause 73. The device pursuant to any one of Clauses 66 to 72, wherein the service request includes one of the following:

[0454] Joint learning model request;

[0455] Training data request; or

[0456] Collaborative training request.

[0457] Clause 74. The apparatus pursuant to any one of Clauses 66 to 73, wherein the privacy budget includes one of the following:

[0458] Privacy budgets associated with all data types;

[0459] There are at least two privacy budgets, each associated with a data type.

[0460] Clause 75. An apparatus for a network function configured to generate a service request for data from at least one user equipment within a communication network, the apparatus comprising: at least one processor and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least: send a discovery request to a core network function associated with the service request for data from at least one user equipment; receive from the core network function a list of user equipments including user equipments for processing the service request; select and / or schedule at least one user equipment from the list of user equipments; and send the service request for data to the at least one user equipment selected and / or scheduled from the list of user equipments.

[0461] Clause 76. The apparatus described in Clause 75 is also configured to receive privacy budget information associated with user equipment on the list of user equipment from the core network function.

[0462] Clause 77. The apparatus described in Clause 75 or Clause 76 is also made to:

[0463] Receive a privacy budget tolerance increase request from at least one user device; and

[0464] Send an increased privacy budget to the at least one user device, or a response to reject the increased privacy budget.

[0465] Clause 78. The apparatus pursuant to any one of Clauses 75 to 77, which is caused to select and / or schedule at least one user equipment from the list of user equipment, is caused to perform at least one of the following:

[0466] Randomly select and / or schedule the at least one user device from the list of user devices to reduce the privacy costs or budget associated with processing the service request;

[0467] Based on at least one further subsample of the user devices from the list of user devices, select and / or schedule the at least one user device from the list of user devices to reduce the privacy costs or budget associated with processing the service request; or

[0468] The at least one user device is selected and / or scheduled from the list of user devices, based at least on the associated privacy budget of the user device.

[0469] Clause 79. The apparatus according to any one of Clauses 75 to 78, wherein the core network function may be Unified Data Management (UDM).

[0470] Clause 80. An apparatus according to any one of Clauses 75 to 79, wherein the apparatus includes or is included in the network functionality.

[0471] Clause 81. The apparatus according to any one of Clauses 75 to 80, wherein said network function is one of the following:

[0472] Core network model training functionality; or

[0473] Radio access network model training function.

[0474] Clause 82. The apparatus according to any one of Clauses 75 to 81, wherein the core network model training function is a model training logic function (MTLF) included in the network data analysis function (NWDAF).

[0475] Clause 83. The device pursuant to any one of Clauses 75 to 82, wherein the service request includes one of the following:

[0476] Joint learning model request;

[0477] Training data request; or

[0478] Collaborative training request.

[0479] Clause 84. The apparatus pursuant to any one of Clauses 75 to 83, wherein the privacy budget includes one of the following:

[0480] Privacy budget associated with all data types; or

[0481] There are at least two privacy budgets, each associated with a data type.

[0482] Clause 85. A computer-readable medium comprising program instructions for causing an apparatus to perform at least any one of Clauses 29 to 37, 38 to 46, or 47 to 56.

[0483] Clause 86. A system comprising components for:

[0484] Receive privacy budget, where the privacy budget is a parameter that defines the amount of data that can be accepted to be sent;

[0485] Send a discovery request, which is associated with a service request for the data;

[0486] Receive a discovery request, which is associated with a service request for data;

[0487] Estimate the privacy budget or cost associated with processing the service request;

[0488] Determine whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget;

[0489] Send a list of user devices for processing the service request;

[0490] Receive a list of user devices for processing the service request;

[0491] Select and / or schedule at least one user equipment from the list of user equipment; and

[0492] The service request to send data to at least one user equipment selected and / or scheduled from the list of user equipment.

[0493] Clause 87. A system comprising: at least one processor; and at least one memory storing instructions, said instructions, when executed by said at least one processor, causing the system to at least:

[0494] Receive privacy budget, where the privacy budget is a parameter that defines the amount of data that can be accepted to be sent;

[0495] Send a discovery request, which is associated with a service request for the data;

[0496] Receive a discovery request, which is associated with a service request for data;

[0497] Estimate the privacy budget or cost associated with processing the service request;

[0498] Determine whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget;

[0499] Send a list of user devices for processing the service request;

[0500] Receive a list of user devices for processing the service request;

[0501] Select and / or schedule at least one user equipment from the list of user equipment; and

[0502] The service request to send data to at least one user equipment selected and / or scheduled from the list of user equipment.

Claims

1. An apparatus for a user equipment, the user equipment implementing privacy guarantees regarding data service requests from a communication network, the apparatus comprising components for: Send a privacy budget to the core network function, wherein the privacy budget at least partially enables the core network function to select the user equipment that is capable of processing service requests and maintaining guaranteed privacy; Receive service requests from network functions, wherein the processing of such service requests is associated with privacy costs; Obtain the privacy cost associated with the processing of the service request; Determine whether the privacy cost associated with processing the service request exceeds the privacy budget; as well as The service request is processed based on whether the privacy cost associated with the processing of the service request is greater than or less than the privacy budget.

2. The apparatus of claim 1, wherein the component for processing the service request based on determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget is used to: When the privacy cost associated with processing the service request exceeds the privacy budget: Request an increase in the privacy budget tolerance for the aforementioned network function; Obtain an increased privacy budget; and It also determines whether the privacy cost associated with the processing of the service request exceeds the increased privacy budget; and The service request is processed based on whether the privacy cost associated with processing the service request is greater than or less than the increased privacy budget.

3. The apparatus of any one of claims 1 or 2, wherein the component for processing the service request based on determining whether the privacy cost associated with the processing of the service request is greater than the privacy budget or the increased privacy budget is used to: When the privacy cost associated with processing the service request is less than the privacy budget or the increased privacy budget: Execute the service request to generate data; Send the generated data to the network function; and The updated privacy budget is sent to the core network functions based on the privacy cost.

4. The apparatus according to any one of claims 1 to 3, wherein the core network function is Unified Data Management (UDM).

5. The apparatus according to any one of claims 1 to 4, wherein the network function is one of the following: Core network model training functionality; or Radio access network model training function.

6. The apparatus of claim 5, wherein the core network model training function is a model training logic function (MTLF) included in the network data analysis function (NWDAF).

7. The apparatus according to any one of claims 1 to 6, wherein the service request includes one of the following: Joint learning model request; Training data request; or Collaborative training request.

8. An apparatus for controlling core network functions related to privacy in a communication network, the apparatus comprising components for: A privacy budget is received from at least one user device, wherein the privacy budget is a parameter defining the amount of data that the at least one user device considers acceptable for transmission; Receive a discovery request from at least one network function, the discovery request being associated with a service request for data from at least one user device; Estimate the privacy budget or cost associated with processing the service request; Determine whether the estimated privacy budget cost associated with the processing of the service request is greater than or less than the privacy budget received from the at least one user device; Send a list of user devices, including user devices for processing the service request, to the at least one network function.

9. The apparatus of claim 8, wherein the component is further configured to: send privacy budget information associated with user devices on the list of user devices to the at least one network function.

10. The apparatus according to any one of claims 8 or 9, wherein the component is further configured to: receive at least one updated privacy budget associated with the at least one user equipment after the at least one user equipment implements the service request.

11. The apparatus according to any one of claims 8 or 10, wherein the apparatus includes, or is included in, the core network function.

12. The apparatus according to any one of claims 8 to 11, wherein the core network function is Unified Data Management (UDM).

13. The apparatus according to any one of claims 8 to 12, wherein the network function is one of the following: Core network model training functionality; or Radio access network model training function.

14. The apparatus of claim 13, wherein the core network model training function is a model training logic function (MTLF) included in the network data analysis function (NWDAF).

15. An apparatus for a network function, the network function being configured to generate a service request for data from at least one user equipment within a communication network, the network function comprising components for: Send a discovery request to the core network function, the discovery request being associated with a service request for data from at least one user equipment; Receive from the core network function a list of user devices including user devices for processing the service request; Select and / or schedule at least one user equipment from the list of user equipment; as well as Send the service request for data to at least one user equipment selected and / or scheduled from the list of user equipment.

16. The apparatus of claim 15, wherein the component is further configured to: receive privacy budget information associated with user devices on the list of user devices from the core network function.

17. The apparatus according to any one of claims 15 or 16, wherein the component is further configured to: Receive a privacy budget tolerance increase request from at least one user device; and Send a response to the at least one user device indicating whether to increase the privacy budget or refuse to increase the privacy budget.

18. The apparatus according to any one of claims 15 to 17, wherein the component for selecting and / or scheduling at least one user equipment from the list of user equipment is used for at least one of the following: Randomly select and / or schedule the at least one user device from the list of user devices to reduce the privacy costs or budget associated with processing the service request; Based on at least one further subsample of the user devices from the list of user devices, select and / or schedule the at least one user device from the list of user devices to reduce the privacy costs or budget associated with processing the service request; or The at least one user device is selected and / or scheduled from the list of user devices, based at least on the associated privacy budget of the user device.

19. The apparatus according to any one of claims 15 to 18, wherein the core network function is Unified Data Management (UDM).

20. The apparatus according to any one of claims 15 to 19, wherein the apparatus includes or is included in the network function.