Method and apparatus for personal data protection
The method and apparatus enhance GDPR compliance in communication networks by implementing consent evaluation across network nodes, addressing the lack of unified consent management in 3GPP, enabling flexible and purpose-specific consent handling for diverse network APIs and types.
Patent Information
- Application Number
- PCT/EP2025/066810
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-28
- Filing Date
- 2025-06-17
- Publication Date
- 2026-01-02
AI Technical Summary
Existing communication networks, such as 3GPP, struggle to comply with GDPR regulations for personal data protection, particularly in handling consent validation for various network APIs and supporting multiple network types like EPC and 5GC, lacking a unified solution for consent management and purpose-specific consent handling.
A method and apparatus are introduced to extend network nodes with consent evaluation capabilities, enabling comprehensive consent management across different APIs and network types, allowing for purpose-specific consent handling and real-time revocation, through a consent management node that interacts with network exposure nodes.
This solution provides a generic and unified approach to protect user privacy by ensuring compliance with GDPR, supporting multiple network types, and enabling flexible consent management for various network APIs, enhancing privacy protection in communication networks.
Smart Images

Figure EP2025066810_02012026_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR PERSONAL DATA PROTECTIONTECHNICAL FIELD
[0001] The non-limiting and exemplary embodiments of the present disclosure generally relate to the technical field of communications, and specifically to methods and apparatuses for personal data protection.BACKGROUND
[0002] This section introduces aspects that may facilitate a better understanding of the disclosure. Accordingly, the statements of this section are to be read in this light and are not to be understood as admissions about what is in the prior art or what is not in the prior art.
[0003] In communication networks such as evolved packet system (EPS) and fifth generation system (5GS) as defined by 3rd Generation Partnership Project (3GPP), personal data protection schemes may be required to protect personal data, such as the processing of personal data, the movement of personal data, etc.SUMMARY
[0004] This summary is provided to introduce a selection of concepts in a simplified form that are further described below in the detailed description. This summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0005] To expose user equipment (UE) related Application Programming Interfaces (APIs) to an application function (AF), some countries may require Communication Service Providers (CSPs) to comply with some regulations such as Art. 6 General Data Protection Regulation (GDPR)-Lawfulness of processing-requirements. However, some communication networks such as 3GPP network can’t fully comply with the regulations such as GDPR requirement.
[0006] 3 GPP solution only supports the consent validation for a few network APIs (e.g. Non-Intemet protocol (IP) Data Delivery (NIDD), Device Triggering, etc.). The solution for different network API is quite different. There is no common solution for CSP to check consent from UE owner when AF invokes network APIs exposed by a network exposure node such as Network Exposure Function (NEF). It is huge effort for CSP to comply with regulations such as GDPR consent requirement for all network APIs exposed from the network exposure node, because CSP needs to wait for 3GPP to define consent validation solution for all APIs, and implement the 3GPP consent validation solution API by API.
[0007] According to GDPR, a subscriber can give the consent to AF for specific “purpose” only, but 3GPP solution doesn’t support this “purpose” concept.
[0008] GDPR allows the subscriber to give consent on the fly when AF requests to use the network API and revokes the consent whenever the subscriber disagrees to let AF use the network API, but 3GPP solution only allows consent to be provisioned into 3GPP system (e.g. Unified Data Repository (UDR)) in advanced. For example, when a subscriber downloads and first opens a gaming application in his / her device such as vehicle or UE, the subscriber can give the consent to the gaming application and let the gaming application’s backend server to use Quality of Service (QoS) API to enhance gaming experience and can also revoke the consent for this application at any time when the subscriber wants to uninstall the application from his / her device.
[0009] 3GPP solution can only be applicable for Fifth Generation Core network (5GC) use case, but CSP may require the consent solution applicable for other networks such as Evolved Packet Core (EPC).
[0010] The following typical use cases (such as from European Union (EU) and United States (US) are not supported by 3GPP solution.
[0011] QoS enhancement: before AF (e.g. mobile gaming provider) wants to use Nnef_AfsessionWithQoS (clause 5.2.6.9 of 3GPP TS 23.502 V18.5.0) to change the QoS of a specific UE traffic flow, the CSP should ensure the UE owner (e.g. subscriber) already gives consent to the AF to do so.
[0012] UE status query (Roaming and Reachability): before AF wants to use event exposure API to collect UE roaming or reachability information, the CSP should ensure the UE owner already gives consent to the AF to do so.
[0013] Change chargeable party for UE: before AF wants to use Chargeable Party API to change the charging rule for a UE, the CSP should ensure the UE owner already gives consent to AF to do so.
[0014] To overcome or mitigate at least one of above mentioned problems or other problems, the embodiments of the present disclosure propose an improved solution for personal data protection.
[0015] In a first aspect of the disclosure, there is provided a method performed by a first network node comprising a network exposure node. In the method, the first network node send to a third network node comprising a consent management node, a request for retrieving a consent result. The request may include second information indicating at least one data scope about an operation of personal data and / or invoking a specific Application Programming Interface (API) by a second network node. Here the second network node may comprise at least one of an application function, an application server, or a Services Capability Server (SCS). The firstnetwork node may further receive from the third network node, a response comprising a consent result for the at least one data scope.
[0016] In a second aspect of the disclosure, there is provided a method performed by a second network node. The second network node may comprise at least one of an application function, an application server, or a Services Capability Server (SCS). In the method, the second network node may send to a first network node comprising a network exposure node, a first message comprising second information indicating at least one data scope about an operation of personal data and / or invoking a specific API by the second network.
[0017] In a third aspect of the disclosure, there is provided a method performed by a third network node. The third network node may comprise a consent management node. In the method, the third network node may receive from a first network node comprising a network exposure node, a request for retrieving a consent result, wherein the request comprises second information indicating at least one data scope about an operation of personal data and / or invoking a specific API by a second network node. Here, the second network node may comprise at least one of an application function, an application server, or a Services Capability Server (SCS). In the method, the third network node may further send to the first network node a response comprising the consent result for the at least one data scope.
[0018] In a fourth aspect of the disclosure, there is provided a first network node. The first network node comprises a processor and a memory coupled to the processor. Said memory contains instructions executable by said processor. Said first network node is operative to execute the method according to the first aspect of the present disclosure.
[0019] In a fifth aspect of the disclosure, there is provided a second network node. The second network node comprises a processor and a memory coupled to the processor. Said memory contains instructions executable by said processor. Said second network node is operative to execute the method according the second aspect of the present disclosure.
[0020] In a sixth aspect of the disclosure, there is provided a third network node. The third network node comprises a processor and a memory coupled to the processor. Said memory contains instructions executable by said processor. Said third network node is operative to execute the method according to the third aspect of the present disclosure.
[0021] In a seventh aspect of the disclosure, there is provided a computer program product comprising instructions which when executed by at least one processor, cause the at least one processor to perform the method according to any one of the first or second or third aspect.
[0022] In an eighth aspect of the disclosure, there is provided a computer-readable storage medium storing instructions which when executed by at least one processor, cause the at least one processor to perform the method according to any one of the first or second or third aspect.
[0023] Embodiments herein may provide many advantages, of which a non-exhaustive list of examples follows. In some embodiments herein, it may extend the APIs of network node (such as NEF) with consent evaluation to protect end user’s privacy. In some embodiments herein, it may provide a generic solution that covers all APIs of network node (such as NEF) and different ways to collect consent data. In some embodiments herein, it may follow some regulations such as GPDR to protect end user’s privacy. In some embodiments herein, it may support consent for two or more networks (such as both EPC and 5GC (dual mode call)). The embodiments herein are not limited to the features and advantages mentioned above. A person skilled in the art will recognize additional features and advantages upon reading the following detailed description.BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The above and other aspects, features, and benefits of various embodiments of the present disclosure will become more fully apparent, by way of example, from the following detailed description with reference to the accompanying drawings, in which like reference numerals or letters are used to designate like or equivalent elements. The drawings are illustrated for facilitating better understanding of the embodiments of the disclosure and not necessarily drawn to scale, in which:
[0025] FIGs. la, lb, 1c, Id and 2 show exemplary system architecture according to embodiments of the present disclosure;
[0026] FIGs.3a-3f, 4a-4b, 5a-5b and 6a-6f show flowcharts of methods according to embodiments of the present disclosure;
[0027] FIG.7 is a block diagram showing an apparatus suitable for practicing some embodiments of the disclosure.DETAILED DESCRIPTION
[0028] The embodiments of the present disclosure are described in detail with reference to the accompanying drawings. It should be understood that these embodiments are discussed only for the purpose of enabling those skilled persons in the art to better understand and thus implement the present disclosure, rather than suggesting any limitations on the scope of the present disclosure. Reference throughout this specification to features, advantages, or similar language does not imply that all of the features and advantages that may be realized with the present disclosure should be or are in any single embodiment of the disclosure. Rather, language referring to the features and advantages is understood to mean that a specific feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the present disclosure. Furthermore, the described features, advantages, andcharacteristics of the disclosure may be combined in any suitable manner in one or more embodiments. One skilled in the relevant art will recognize that the disclosure may be practiced without one or more of the specific features or advantages of a particular embodiment. In other instances, additional features and advantages may be recognized in certain embodiments that may not be present in all embodiments of the disclosure.
[0029] As used herein, the term “network” refers to a network following any suitable communication standards such as new radio (NR), long term evolution (LTE), LTE-Advanced, wideband code division multiple access (WCDMA), high-speed packet access (HSPA), Code Division Multiple Access (CDMA), Time Division Multiple Address (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency -Division Multiple Access (OFDMA), Single carrier frequency division multiple access (SC-FDMA) and other wireless networks. A CDMA network may implement a radio technology such as Universal Terrestrial Radio Access (UTRA), etc. UTRA includes WCDMA and other variants of CDMA. A TDMA network may implement a radio technology such as Global System for Mobile Communications (GSM). An OFDMA network may implement a radio technology such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDMA, Ad-hoc network, wireless sensor network, etc. In the following description, the terms “network” and “system” can be used interchangeably. Furthermore, the communications between two devices in the network may be performed according to any suitable communication protocols, including, but not limited to, the communication protocols as defined by a standard organization such as 3GPP. For example, the communication protocols may comprise the first generation (1G), 2G, 3G, 4G, 4.5G, 5G, 6G communication protocols, and / or any other protocols either currently known or to be developed in the future.
[0030] The term “network device” or “network node” or “network function” refers to any suitable function which can be implemented in a network entity (physical or virtual) of a communication network. For example, the network function can be implemented either as a network element on a dedicated hardware, as a software instance running on a dedicated hardware, or as a virtualized function instantiated on an appropriate platform, e.g. on a cloud infrastructure. For example, the 5G system (5GS) may comprise a plurality of NFs such as Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Service Function (AUSF), Unified Data Management (UDM), Policy Control Function (PCF), Application Function (AF), Network Exposure Function (NEF), User plane Function (UPF) and Network Repository Function (NRF), radio access network (RAN), service communication proxy (SCP), network data analytics function (NWDAF), network slice Selection Function (NSSF), network slice-Specific Authentication and Authorization Function (NSSAAF), etc. In other embodiments, the network function may comprise different types ofNFs for example depending on a specific network. For example, the 4G system (such as Long Term Evolution (LTE)) may include Mobile Management Entity (MME), home subscriber server (HSS), PCRF (Policy and Charging Rules Function), PGW (Packet Data Network Gateway), PGW control plane (PGW-C), Serving gateway (SGW), SGW control plane (SGW-C), E-UTRAN Node B (eNB), etc. In other embodiments, the network function may comprise different types of NFs for example depending on a specific network.
[0031] Virtualizing means creating virtual versions of apparatuses or devices which may include virtualizing hardware platforms, storage devices and networking resources. As used herein, virtualization can be applied to a provider edge node and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components (e.g., via one or more applications, components, functions, virtual machines or containers executing on one or more physical processing nodes in one or more networks).
[0032] In some embodiments, some or all of the functions described herein may be implemented as virtual components executed by one or more virtual machines implemented in one or more virtual environments hosted by one or more of hardware nodes. Further, in embodiments in which the virtual node is not a radio access node or does not require radio connectivity (e.g., a core network node), then the provider edge node or PE may be entirely virtualized.
[0033] The functions may be implemented by one or more applications (which may alternatively be called software instances, virtual appliances, network functions, virtual nodes, virtual network functions, etc.) operative to implement some of the features, functions, and / or benefits of some of the embodiments disclosed herein. Applications are run in virtualization environment which provides hardware comprising processing circuitry and memory. Memory contains instructions executable by processing circuitry whereby application is operative to provide one or more of the features, benefits, and / or functions disclosed herein.
[0034] Virtualization environment, comprises general-purpose or special-purpose network hardware devices comprising a set of one or more processors or processing circuitry, which may be commercial off-the-shelf (COTS) processors, dedicated Application Specific Integrated Circuits (ASICs), or any other type of processing circuitry including digital or analog hardware components or special purpose processors. Each hardware device may comprise memory which may be non-persistent memory for temporarily storing instructions or software executed by processing circuitry. Each hardware device may comprise one or more network interface controllers (NICs), also known as network interface cards, which include physical network interface. Each hardware device may also include non-transitory, persistent, machine-readable storage media - having stored therein software and / or instructions executable by processing circuitry. Software may include any type of software including software for instantiating one ormore virtualization layers (also referred to as hypervisors), software to execute virtual machines as well as software allowing it to execute functions, features and / or benefits described in relation with some embodiments described herein.
[0035] Virtual machines, comprise virtual processing, virtual memory, virtual networking or interface and virtual storage, and may be run by a corresponding virtualization layer or hypervisor. Different embodiments of the instance of virtual appliance may be implemented on one or more of virtual machines, and the implementations may be made in different ways.
[0036] During operation, processing circuitry executes software to instantiate the hypervisor or virtualization layer, which may sometimes be referred to as a virtual machine monitor (VMM). Virtualization layer may present a virtual operating platform that appears like networking hardware to virtual machine.
[0037] The term “terminal device” refers to any end device that can access a communication network and receive services therefrom. By way of example and not limitation, the terminal device refers to a mobile terminal, user equipment (UE), or other suitable devices. The UE may be, for example, a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a portable computer, an image capture terminal device such as a digital camera, a gaming terminal device, a music storage and a playback appliance, a mobile phone, a cellular phone, a smart phone, a voice over IP (VoIP) phone, a wireless local loop phone, a tablet, a wearable device, a personal digital assistant (PDA), a portable computer, a desktop computer, a wearable terminal device, a vehicle-mounted wireless terminal device, a wireless endpoint, a mobile station, a laptop-embedded equipment (LEE), a laptop-mounted equipment (LME), a USB dongle, a smart device, a wireless customer-premises equipment (CPE) and the like. In the following description, the terms “terminal device”, “terminal”, “user equipment” and “UE” may be used interchangeably. As one example, a terminal device may represent a UE configured for communication in accordance with one or more communication standards promulgated by the 3GPP (3rd Generation Partnership Project), such as 3GPP LTE standard or NR standard. As used herein, a “user equipment” or “UE” may not necessarily have a “user” in the sense of a human user who owns and / or operates the relevant device. In some embodiments, a terminal device may be configured to transmit and / or receive information without direct human interaction. For instance, a terminal device may be designed to transmit information to a network on a predetermined schedule, when triggered by an internal or external event, or in response to requests from the communication network. Instead, a UE may represent a device that is intended for sale to, or operation by, a human user but that may not initially be associated with a specific human user.
[0038] As yet another example, in an Internet of Things (loT) scenario, a terminal device may represent a machine or other device that performs monitoring and / or measurements, and transmits the results of such monitoring and / or measurements to another terminal device and / or network equipment. The terminal device may in this case be a machine-to-machine (M2M) device, which may in a 3GPP context be referred to as a machine-type communication (MTC) device. As one particular example, the terminal device may be a UE implementing the 3GPP narrow band internet of things (NB-IoT) standard. Particular examples of such machines or devices are sensors, metering devices such as power meters, industrial machinery, or home or personal appliances, for example refrigerators, televisions, personal wearables such as watches etc. In other scenarios, a terminal device may represent a vehicle or other equipment that is capable of monitoring and / or reporting on its operational status or other functions associated with its operation.
[0039] References in the specification to “one embodiment,” “an embodiment,” “an example embodiment,” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0040] It shall be understood that although the terms “first” and “second” etc. may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed terms.
[0041] As used herein unless expressly stated to the contrary, the phrase “at least one of A and B” or “at least one of A or B” should be understood to mean any of the following “only A, only B, or both A and B.” The phrase “A and / or B” should be understood to mean any of the following “only A, only B, or both A and B”.
[0042] As used herein unless expressly stated to the contrary, the phrase “a plurality of’ followed by a conjunctive list of enumerated items (e.g, “A and B”, “A, B, and C”) is intended to mean “multiple items, with each item selected from the list consisting of’ the enumerated items. For example, “a plurality of A and B” is intended to mean any of the following: more than one A; more than one B; or at least one A and at least one B.
[0043] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0044] It is noted that these terms as used in this document are used only for ease of description and differentiation among nodes, devices or networks etc. With the development of the technology, other terms with the similar / same meanings may also be used.
[0045] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0046] Although the subject matter described herein may be implemented in any appropriate type of system using any suitable components, the embodiments disclosed herein are described in relation to a communication system complied with the exemplary system architecture illustrated in FIGs. la, lb, 1c, Id and 2. For simplicity, the system architecture of FIGs.la, lb, 1c, Id and 2 only depicts some exemplary elements. In practice, a communication system may further include any additional elements suitable to support communication between terminal devices or between a wireless device and another communication device, such as a landline telephone, a service provider, or any other network node or terminal device. The communication system may provide communication and various types of services to one or more terminal devices to facilitate the terminal devices’ access to and / or use of the services provided by, or via, the communication system.
[0047] FIG. la schematically shows a high level architecture in a 5G network according to an embodiment of the present disclosure. The architecture of FIG.la is same as Figure 4.2.3-1 of 3GPP TS 23.501 V18.5.0, the disclosure of which is incorporated by reference herein in its entirety. The system architecture of FIG.la may comprise a plurality of network functions (NFs) such as Access and Mobility Management Function (AMF), Session Management Function (SMF), Authentication Service Function (AUSF), Unified Data Management (UDM), Policy Control Function (PCF), Application Function (AF), Network Exposure Function (NEF), User plane Function (UPF) and Network Repository Function (NRF), (radio) access network ((R)AN), service communication proxy (SCP), network slice Selection Function (NSSF), network slice-Specific Authentication and Authorization Function (NSSAAF), Edge Application Server Discovery Function (EASDF), NSACF (network slice Admission Control Function), etc.
[0048] In accordance with an exemplary embodiment, the UE can establish a signaling connection with the AMF over the reference point Nl, as illustrated in FIG. la. This signaling connection may enable NAS (Non-access stratum) signaling exchange between the UE and the core network, comprising a signaling connection between the UE and the (R)AN and the N2 connection for this UE between the (R)AN and the AMF. The (R)AN can communicate with the UPF over the reference point N3. The UE can establish a protocol data unit (PDU) session to the DN (data network, e.g. an operator network or Internet) through the UPF over the reference point N6.
[0049] As further illustrated in FIG. la, the exemplary system architecture also contains the service-based interfaces such as Nnrf, Nnef, Nausf, Nudm, Npcf, Namf, Nnsacf, Neasdf and Nsmf exhibited by NFs such as the NRF, the NEF, the AUSF, the UDM, the PCF, the AMF, the NSACF, the EASDF and the SMF. In addition, FIG. la also shows some reference points such as Nl, N2, N3, N4, N6 and N9, which can support the interactions between NF services in the NFs. For example, these reference points may be realized through corresponding NF service-based interfaces and by specifying some NF service consumers and providers as well as their interactions in order to perform a particular system procedure.
[0050] Various NFs shown in FIG. la may be responsible for functions such as session management, mobility management, authentication, security, etc. The AUSF, AMF, DN, NEF, NRF, NSSF, PCF, SMF, UDM, UPF, AF, UE, (R)AN, SCP, NSACF, NSSAAF, EASDF may include the functionality for example as defined in clause 6.2 of 3GPP TS 23.501 V18.5.0.
[0051] FIG. lb schematically shows system architecture in a 4G network according to an embodiment of the present disclosure, which is the same as Figure 4.2-la of 3GPP TS 23.682 VI 8.0.0, the disclosure of which is incorporated by reference herein in its entirety. The system architecture of FIG. lb may comprise some exemplary elements such as Services Capability Server (SCS), Application Server (AS), SCEF (Service Capability Exposure Function), HSS, UE, RAN(Radio Access Network), SGSN (Serving GPRS(General Packet Radio Service) Support Node), MME, MSC(Mobile Switching Centre), S-GW(Serving Gateway), GGSN / P-GW(Gateway GPRS Support Node / PDN(Packet Data Network) Gateway), MTC-IWF(Machine Type Communications-InterWorking Function) CDF / CGF(Charging Data Function / Charging Gateway Function), MTC-AAA(Machine Type Communications-authentication, authorization and accounting), SMS-SC / GMSC / IWMSC(Short Message Service-Service Centre / Gateway MSC / InterWorking MSC) IP-SM-GW(Intemet protocol Short Message Gateway). The network elements and interfaces as shown in FIG. lb may be same as the corresponding network elements and interfaces as described in 3GPP TS 23.682 V18.0.0.
[0052] The system architecture shows the architecture for a UE used for MTC connecting to the 3GPP network (UTRAN (Universal Terrestrial Radio Access Network), E-UTRAN (Evolved UTRAN), GERAN (GSM EDGE (Enhanced Data rates for GSM Evolution) Radio Access Network), etc.) via the Um / Uu / LTE-Uu interfaces. The system architecture also shows the 3GPP network service capability exposure to SCS and AS.
[0053] As further illustrated in FIG. lb, the exemplary system architecture also contains various reference points which have been described in clause 4.3 of 3 GPP TS 23.682 VI 8.0.0.
[0054] FIG.lc shows non-roaming architecture for Network Exposure Function in reference point representation, which is same as Figure 4.2.3-5 of 3GPP TS23.501 V18.5.0. 3GPP Interface represents southbound interfaces between NEF and 5G core network (5GC) Network Functions e.g. N29 interface between NEF and SMF, N30 interface between NEF and PCF, etc. All southbound interfaces from NEF are not shown for the sake of simplicity. N33 is a reference point between NEF and AF.
[0055] FIG. Id shows non-roaming Service Exposure Architecture for EPC (Evolved Packet Core)-5GC Interworking, which is same as Figure 4.3.5.1-1 of 3GPP TS23.501 V18.5.0. If the UE is capable of mobility between EPS and 5GS, the network is expected to associate the UE with an SCEF+NEF (SCEF combined with NEF) node for Service Capability Exposure. Trust domain for SCEF+NEF is same as Trust domain for SCEF as defined in 3GPP TS 23.682 V18.0.0. EPC Interface represents southbound interfaces between SCEF and EPC nodes e.g. the S6t interface between SCEF and HSS, the T6a interface between SCEF and MME, etc. All southbound interfaces from SCEF are defined in 3GPP TS 23.682 V18.0.0 and are not shown for the sake of simplicity. 5GC Interface represents southbound interfaces between NEF and 5GC Network Functions e.g. N29 interface between NEF and SMF, N30 interface between NEF and PCF, etc. All southbound interfaces from NEF are not shown for the sake of simplicity. Interaction between the SCEF and NEF within the combined SCEF+NEF is required. For example, when the SCEF+NEF supports monitoring APIs, the SCEF and NEF need to share context and state information on a UE's configured monitoring events if the UE moves between from EPC and 5GC. The north-bound APIs which can be supported by an EPC or 5GC network are discovered by the SCEF+NEF node via the CAPIF (Common API Framework for 3GPP northbound APIs) function and / or via local configuration of the SCEF+NEF node. Different sets of APIs can be supported by the two network types.
[0056] NEF (see 3GPP TS 29.122 V18.5.0 & 3GPP TS 29.522 V18.5.0, the disclosure of which is incorporated by reference herein in its entirety) is the key exposure node to hide complexity of operator network, may base on local policy / configuration expose the needed parameters to the trusted AF or to the untrusted AF upon Service Level Agreement (SLA). NEF may provide a set of Network APIs to trusted or untrusted AF, which may allow AF to monitor(e.g. EventExposure), control (e.g. AsSessionWithQoS, ServiceParameter, Trafficlnflune), or communicate (e.g. NIDD, DeviceTriggering) with UE.
[0057] FIG.2 schematically shows system architecture according to an embodiment of the present disclosure.
[0058] The consent management system or node or function is a novel entity outside of 3GPP standard network function today, which may provide the consent management function. For example, it may provide the consent management function for network capability exposure complying with various personal data protection requirements such as GDPR requirement. For example, NEF may integrate with the consent management system to check consent during the NEF API invocation.
[0059] The consent data in consent management system may be obtained in various ways, such as from a provisioning system (for example, based on a contract signed with the subscribers) or from a consent capture system interacting with the individual subscribers.
[0060] There may be multiple ways to gather the consent information, which may depend on CSP and aggregator’s policy. For example, there may be three major ways to gather the consent information.
[0061] CSP may collect the consent information from subscriber and provision the consent information into consent management system via provisioning API.
[0062] CSP may provide Open Authorization (Oauth) server. Subscriber can use Authorization Code flow or Client Initiated Backchannel Authentication Grant (CIBA) flow to grant the consent on-demanded.
[0063] CSP may provide self-care portal to subscriber. Subscriber can give consent information via self-care portal.
[0064] As shown in FIG.2, the CSP Oauth Server or self-care portal can be Consent Capture system.
[0065] The architecture of FIG.2 is also applicable to other communication system such as EPC. For example, NEF could also be EPC equivalent SCEF. 5GC and 5GC NF could also be EPC and EPC function.
[0066] GDPR
[0067] The General Data Protection Regulation (Regulation (EU) 2016 / 679, abbreviated GDPR) is a European Union regulation on information privacy in the European Union (EU) and the European Economic Area (EEA). The GDPR is an important component of EU privacy law and human rights law. The GDPR's goals are to enhance individuals' control and rights over their personal information and to simplify the regulations for international business.
[0068] The regulation became a model for many other laws around the world, including in Turkey, Mauritius, Chile, Japan, Brazil, South Korea, South Africa, Argentina, Kenya, etc. Afterleaving the European Union the United Kingdom enacted its "UK GDPR", identical to the GDPR. The California Consumer Privacy Act (CCPA), adopted on 28 June 2018, has many similarities with the GDPR.
[0069] GDPR defines Consent requirement (https: / / gdpr-info.eu / issues / consent / and https: / / gdpr.eu / gdpr-consent-requirements / ): Processing personal data is generally prohibited, unless it is expressly allowed by law, or the data subject has consented to the processing. One easy way to avoid large GDPR fines is to always get permission from your users before using their personal data.
[0070] The “purpose” concept is defined in GDPR. Art. 6 GDPR - Lawfulness of processing - GDPR (gdpr-info.eu). To standardize a language for GDPR definition, World Wide Web Consortium (W3C) Data Privacy Vocabularies and Controls Community Group (DPVCG) was created to develop a taxonomy of privacy and data protection related terms. It provides taxonomy of personal data as well as a classification of purposes, see https: / / github.com / w3c / dpv / blob / bl2f27743bfl88dc7281619882cd9f87c9eca617 / documentation -generator / vocab_csv / Purpose.csv#L2.
[0071] FIGs.3a, 3b, 3c, 3d and 3e show flowcharts of methods according to embodiments of the present disclosure, which may be performed by an apparatus implemented in or at or as a first network node or communicatively coupled to the first network node. As such, the apparatus may provide means or modules or circuits for accomplishing various parts of the methods as well as means or modules or circuits for accomplishing other processes in conjunction with other components.
[0072] FIG.3a shows a flowchart of a method 300 according to an embodiment of the present disclosure.
[0073] At block 302, the first network node may receive, from a second network node, a first message comprising first information indicating at least one purpose describing one or more reasons of an operation of personal data and / or one or more reasons to invoke a specific API by the second network node.
[0074] The personal data may be any suitable personal data. For example, the personal data may comprise data sent from a UE, data sent to the UE, service data related to user / UE, or personal data stored in a network node, etc.
[0075] In an embodiment, the first message may further comprise second information indicating at least one data scope about the operation of personal data and / or invoking the specific API by the second network node.
[0076] In an embodiment, the purpose may describe the reason of an application using a specific API or access / operate / move the personal data such as user privacy data. For example, when an application requests consent from a subscriber to access / operate / move the subscriber’spersonal data, the application may / must provide the purpose of accessing / operating / moving the subscriber’s personal data to the subscriber. The subscriber may, based on the at least one purpose, to decide if the consent can be granted or not. After the consent is granted, when the application tries to access / operate / move the personal data, the application may / should provide the granted purpose in the message always.
[0077] The at least one purpose may comprise any suitable purpose and the present disclosure has no limit on it. For example, the at least one purpose may be any of the purposes as defined in https: / / github.com / w3c / dpv / blob / bl2f27743bfl88dc7281619882cd9f87c9eca617 / documentation -generator / vocab_csv / Purpose.csv#L2.
[0078] In an embodiment, the data scope may indicate the data categories which may be collected and processed. The data scope may comprise any suitable data scope (e.g. any personal data, any parameter related to an API message to influence personal data, etc.) and the present disclosure has no limit on it.
[0079] In an embodiment, the at least one data scope may comprise a parameter of service (e.g. related to a UE or user or subscriber), such as communication parameter, session QoS parameter, policy parameter, etc. For example, the at least one data scope may comprise a parameter of any suitable NF services provided by the NEF as described in clause 5.2.6 of 3GPP TS 23.502 V18.5.0.
[0080] In an embodiment, the at least one data scope may comprise at least one of identification data, address data, contact data, authorization related data, location data, device status data, a parameter to influence personal data, or traffic related data.
[0081] In an embodiment, the device status data may comprise at least one of a roaming status of device, a reachability status of device, a connectivity status of device, which slice is currently used by the device, etc.
[0082] In an embodiment, the identification data may comprise e.g. name, Mobile Subscriber Integrated Services Digital Network (ISDN) Number (MSISDN), Subscription Permanent Identifier (SUPI), International Mobile Subscriber Identity (IMSI), etc.
[0083] In an embodiment, the addresses and contact data may comprise e.g. postal addresses, e-mail addresses, phone numbers, organizational data such as company / organization, department, function, etc.
[0084] In an embodiment, the authorization related data may comprise e.g. authorizations and their use, e.g. IP addresses.
[0085] In an embodiment, the location data may comprise a location of user, e.g. civil address, the coordinate of latitude and longitude, etc.
[0086] In an embodiment, the traffic related data may comprise traffic categories and data, e.g. statistics of device traffic, QoS of device traffic, etc.
[0087] In an embodiment, the parameter to influence personal data may be any suitable parameter to influence personal data, such as any parameter of the first message (such as NEF API message).
[0088] In an embodiment, the at least one data scope may be mapped to at least one of a specific Application Programming Interface (API), a specific API operation, or a specific event type of API operation.
[0089] For example, the specific API may comprise any suitable NF services provided by the NEF as described in clause 5.2.6 of 3GPP TS 23.502 V18.5.0. The specific API operation may comprise any suitable API operation of any suitable NF services provided by the NEF as described in clause 5.2.6 of 3GPP TS 23.502 V18.5.0. The specific event type of API operation may comprise any suitable event type of any suitable API operation of any suitable NF services provided by the NEF as described in clause 5.2.6 of 3GPP TS 23.502 V18.5.0.
[0090] For example, the data scope can be mapped to at least one of a specific API, e.g. NEF AfSessionWithQoS API, a specific API operation, e.g. POST Operation of NEF UEID API, a specific event type of API operation, e.g. Location Event of NEF Event Exposure API.
[0091] In an embodiment, when an application requests consent from a subscriber to access / operate / move the subscriber’s personal data, the application may / must provide data scope to the subscriber. The subscriber may, based on the data scope, decide if the consent can be granted or not. After the consent is granted, when the application tries to access / operate / move the personal data, application may / should provide the granted data scope in the message always.
[0092] The first network node may be deployed in any suitable network. In an embodiment, the first network node may be deployed in EPS, a 5GS or a 6G system (6GS) as defined by 3GPP.
[0093] The first network node may be any suitable network device or network node or network function. For example, the first network node may implement network exposure function or service capability exposure function as described in various 3 GPP specifications such as 3 GPP TS 23.501 V18.5.0 or 3GPP TS 23.682 V18.0.0 or 3GPP 6G specification.
[0094] In an embodiment, the first network node may comprise at least one of Service Capability Exposure Function (SCEF), Network Exposure Function (NEF), or SCEF combined with NEF.
[0095] The second network node may be deployed in any suitable network. In an embodiment, the second network node may be deployed in EPS, a 5GS or a 6GS as defined by 3GPP.
[0096] The second network node may be any suitable network device or network node or network function. For example, the second network node may implement application function as described in various 3GPP specifications such as 3GPP TS 23.501 V18.5.0 or 3GPP TS 23.682 VI 8.0.0 or 3GPP 6G specification.
[0097] In an embodiment, the second network node may comprise at least one of an application function, an application server, or a Services Capability Server (SCS).
[0098] The first message may be a new message or a modified existing message. In an embodiment, the first message may comprise any suitable message of any suitable services provided by the NEF as described in clause 5.2.6 of 3GPP TS 23.502 V18.5.0 or any suitable message of any suitable services provided by the SCEF as described in 3GPP TS 23.682 V18.0.0.
[0099] The first information may be any suitable information which can indicate the at least one purpose, such as bit, flag, bitmap, indicator, etc. The second information may be any suitable information which can indicate the at least one data scope, such as bit, flag, bitmap, indicator, etc.
[0100] At block 304, optionally, the first network node may obtain a consent result, optionally for the at least one purpose.
[0101] In an embodiment, the consent result may be for the at least one data scope. For example, the first network node may obtain a consent result for the at least one data scope or for the at least one purpose and the at least one data scope.
[0102] The first network node may obtain the consent result in various ways. For example, if the consent result has been stored or cached in the first network node, the first network node may obtain it locally. Alternatively, the first network node may obtain the consent result from another network node or a user / subscriber.
[0103] As described in above, there may be multiple ways to gather the consent information, for example which may depend on CSP and aggregator’s policy. For example, for each purpose and / or data scope, the consent may be granted by a user or subscriber. Then the consent information may be gathered and provided to a network node such as consent management node. In an embodiment, the consent information may be stored in the user’s subscription data and the consent information may be obtained from the user’s subscription data.
[0104] The consent result may comprise any suitable information related to the consent. In an embodiment, the consent result may comprise information indicating whether a consent (from a user or subscriber) is granted or not. In an embodiment, the consent result may comprise at least one constraint associated with a consent.
[0105] The at least one constraint may comprise any suitable constraint. Examples of the constraints may comprise at least one of API invocation time, or a specific parameter in the API request shall be within a range, consent expiration time, consent effective time, etc.
[0106] At block 306, optionally, the first network node may send a second message to a fourth network node based on the consent result.
[0107] In an embodiment, the second message may be generated by the first network node based on the first message.
[0108] The fourth network node may be deployed in any suitable network. In an embodiment, the fourth network node may be deployed in EPS, a 5GS or a 6GS as defined by 3GPP.
[0109] The fourth network node may be any suitable network device or network node or network function. For example, the fourth network node may implement network function as described in various 3GPP specifications such as 3GPP TS 23.501 V18.5.0 or 3GPP TS 23.682 VI 8.0.0 or 3GPP 6G specification.
[0110] In an embodiment, the fourth network node may comprise at least one of Unified Data Management (UDM), Policy Control Function (PCF), Unified Data Repository (UDR), Access and Mobility Management Function (AMF), or network data analytics function (NWDAF).
[0111] The second message may be any suitable message for example as described in various 3GPP specifications such as 3GPP TS 23.501 V18.5.0 or 3GPP TS 23.682 V18.0.0 or 3GPP 6G specification, such as NEF message, SCEF message etc.
[0112] In an embodiment, if a consent (or all consent if there are two or more consent) is granted, the first network node may send the second message to the fourth network node. For example, if the first message is an NF service message provided by the NEF, the NEF may send a corresponding message to a corresponding NF.
[0113] In an embodiment, if a consent (or all consent if there are two or more consent) is granted and all constraints associated with the consent are fulfilled, the first network node may send the second message to the fourth network node. For example, if the first message is an NF service message provided by the NEF, the NEF may send a corresponding message to a corresponding NF.
[0114] FIG.3b shows a flowchart of a method 310 according to another embodiment of the present disclosure.
[0115] At block 312, the first network node may send, to a third network node, a request for retrieving the consent result.
[0116] The third network node may be deployed in any suitable network. In an embodiment, the third network node may be deployed in EPS, a 5GS or a 6GS as defined by 3GPP.
[0117] The third network node may be any suitable network device or network node or network function. For example, the third network node may implement consent management function.
[0118] In an embodiment, the third network node may comprise a consent management node.
[0119] As described in above, there may be multiple ways to gather the consent information, for example which may depend on CSP and aggregator’s policy. For example, for each purpose and / or data scope, the consent may be granted or denied by a user or subscriber. Then the consent information may be gathered and provided to the consent management node. In anembodiment, the consent information may be stored in the user’s subscription data and the consent information may be obtained from the user’s subscription data.
[0120] The request may comprise any suitable information which can be used for retrieving the consent result. In an embodiment, the request may comprise at least one of the at least one purpose, the at least one data scope, a group identifier (ID or Id), a user equipment identifier, a user identifier, or an identifier of the second network node.
[0121] In an embodiment, at least one of the at least one purpose, the at least one data scope and the identifier of the second network node may be mandatory.
[0122] In an embodiment, the group identifier, the user equipment identifier, the user identifier, or the identifier of the second network node may be an internal group identifier, an internal user equipment identifier, an internal user identifier, or an internal identifier of the second network node which can be used in the network such as EPS, 5GS, 6GS.
[0123] In an embodiment, the terms “user equipment identifier” and “user identifier” can be used interchangeably.
[0124] At block 314, the first network node may receive, from the third network node, a response comprising the consent result, optionally the consent result is for the at least one data scope and / or the at least one purpose.
[0125] FIG.3c shows a flowchart of a method 320 according to another embodiment of the present disclosure.
[0126] At block 322, optionally, the first network node may translate a first user equipment identifier in the first message to the user equipment identifier to be used in the request.
[0127] For example, the first user equipment identifier may be any suitable identifier which cannot be used directly in the network (such as EPS, 5GS, 6GS), such as an external identifier, UE IP address, UE name, UE’s Fully Qualified Domain Name(FQDN), Generic Public Subscription Identifier (GPSI) (External ID), etc. The user equipment identifier may be any suitable identifier which can be used in the network, such as an internal identifier, MSISDN, SUPI, IMSI, etc.
[0128] The first network node may translate the first user equipment identifier in the first message to the user equipment identifier to be used in the request in various ways. For example, the first network node may translate it by itself if the first network node has stored a mapping between the first user equipment identifier and the user equipment identifier. The first network node may send a request comprising the first user equipment identifier to another network node such as UDM and receive a response comprising the user equipment identifier from another network node such as UDM. For example, UDM may resolve GPSI to MSISDN / SUPI according to 3 GPP TS23.502. V18.5.0.
[0129] In an embodiment, block 322 may be performed before method 310.
[0130] At block 324, optionally, the first network node may translate a first group identifier in the first message to the group identifier to be used in the request.
[0131] For example, the first group identifier may be any suitable identifier which cannot be used directly in the network (such as EPS, 5GS, 6GS), such as an external group identifier. The group identifier may be any suitable identifier which can be used in the network, such as an internal group identifier.
[0132] The first network node may translate the first group identifier in the first message to the group identifier to be used in the request in various ways. For example, the first network node may translate it by itself if the first network node has stored a mapping between the first group identifier and the group identifier. The first network node may send a request comprising the first group identifier to another network node such as UDM and receive a response comprising the group identifier from another network node such as UDM. For example, UDM may resolve the external group identifier to internal group identifier according to 3GPP TS23.502. V18.5.0.
[0133] In an embodiment, block 324 may be performed before method 310.
[0134] At block 326, optionally, the first network node may obtain a list of user equipment identifiers to be used in the request based on the first group identifier in the first message.
[0135] For example, the first group identifier may be any suitable identifier which cannot be used directly in the network (such as EPS, 5GS, 6GS), such as an external group identifier. The list of user equipment identifiers may be any suitable identifier which can be used in the network, such as internal user equipment identifiers.
[0136] The first network node may obtain the list of user equipment identifiers in various ways. For example, the first network node may obtain it by itself if the first network node has stored a mapping between the first group identifier and the list of user equipment identifiers. The first network node may send a request comprising the first group identifier to another network node such as UDM and receive a response comprising the list of user equipment identifiers from another network node such as UDM. For example, UDM may resolve the first group identifier to the list of user equipment identifiers.
[0137] In an embodiment, block 326 may be performed before method 310. For example, for each user equipment identifier, the first network node may send, to the third network node, the request for retrieving the consent result.
[0138] FIG.3d shows a flowchart of a method 330 according to another embodiment of the present disclosure.
[0139] At block 332, the first network node may receive, from the second network node, an onboarding message comprising at least one of an identifier of the second network node, an API identifier of the first network node, an API operation of the first network node, a consent indicator indicating whether consent is required or not, a purpose, or a data scope.
[0140] In an embodiment, during the onboarding, CSP may decide what API can be used by the second network node, and if the consent evaluation is required for this the second network node (e.g. un-trusted application).
[0141] The information in the onboarding message may be stored in the first network node and can be used for various purposes.
[0142] FIG.3e shows a flowchart of a method 340 according to another embodiment of the present disclosure.
[0143] At block 342, optionally, the first network node may check if a consent evaluation is required for the first message based on the onboarding message.
[0144] For example, the first network node may, based on onboarding information, to check if consent evaluation is required for a request from the second network node. If so, block 304 may be executed. If not, the first network node may process the first message normally.
[0145] At block 344, optionally, if the first message does not comprise the at least one data scope, the first network node may derive the at least one data scope based on the onboarding message.
[0146] For example, if the second network node doesn’t provide the data scope in the first message, the first network node may derive the data scope based on the onboarding information.
[0147] In an embodiment, if the first message does not comprise the purpose, the first network node may derive the purpose based on the onboarding message.
[0148] FIG.3f shows a flowchart of a method 350 according to another embodiment of the present disclosure.
[0149] At block 352, optionally, if a consent is not granted, the first network node may send, to the second network node, a message comprising information indicating a consent issue. For example, if the first message is an NF service message provided by the NEF, the NEF may reject the NF service message and send, to the second network node, a message comprising information indicating a consent issue (e.g. consent is not granted).
[0150] At block 354, optionally, if a consent is granted and at least one constraint associated with the consent is not fulfilled, the first network node may send, to the second network node, a message comprising information indicating a consent issue. For example, if the first message is an NF service message provided by the NEF, the NEF may reject the NF service message and send, to the second network node, a message comprising information indicating a consent issue (e.g. consent is granted and at least one constraint associated with the consent is not fulfilled).
[0151] FIGs.4a and 4b show flowcharts of methods according to embodiments of the present disclosure, which may be performed by an apparatus implemented in or at or as a second network node or communicatively coupled to the second network node. As such, the apparatus may provide means or modules or circuits for accomplishing various parts of the methods as wellas means or modules or circuits for accomplishing other processes in conjunction with other components. For some parts which have been described in the above embodiments, the description thereof is omitted here for brevity.
[0152] FIG.4a shows a flowchart of a method 400 according to another embodiment of the present disclosure.
[0153] At block 402, the second network node may send, to a first network node, a first message comprising second information indicating at least one data scope about an operation of personal data and / or invoking a specific API by the second network node. Optionally, the first message may further comprise first information indicating at least one purpose describing one or more reasons of an operation of personal data and / or one or more reasons to invoke a specific API by the second network node.
[0154] In an embodiment, the first message may further comprise second information indicating at least one data scope about the operation of personal data and / or invoking a specific API by the second network node.
[0155] In an embodiment, the at least one data scope may comprise at least one of identification data, address data, contact data, authorization related data, location data, device status data, a parameter to influence personal data, or traffic related data.
[0156] In an embodiment, the at least one data scope may be mapped to at least one of a specific Application Programming Interface (API), a specific API operation, or a specific event type of API operation.
[0157] In an embodiment, the first network node may comprise at least one of Service Capability Exposure Function (SCEF), Network Exposure Function (NEF), or SCEF combined with NEF.
[0158] In an embodiment, the second network node may comprise at least one of an application function, an application server, or a Services Capability Server (SCS).
[0159] FIG.4b shows a flowchart of a method 410 according to another embodiment of the present disclosure.
[0160] At block 412, the second network node may send, to the first network node, an onboarding message comprising at least one of an identifier of the second network node, an API identifier of the first network node, an API operation of the first network node, a consent indicator indicating whether consent is required or not, a purpose, or a data scope.
[0161] FIGs.5a and 5b show flowcharts of methods according to embodiments of the present disclosure, which may be performed by an apparatus implemented in or at or as a third network node or communicatively coupled to the third network node. As such, the apparatus may provide means or modules or circuits for accomplishing various parts of the methods as well as means or modules or circuits for accomplishing other processes in conjunction with other components. Forsome parts which have been described in the above embodiments, the description thereof is omitted here for brevity.
[0162] FIG.5a shows a flowchart of a method 500 according to another embodiment of the present disclosure.
[0163] At block 502, the third network node may receive, from a first network node, a request for retrieving a consent result. Optionally, the request comprises second information indicating at least one data scope about an operation of personal data and / or invoking a specific Application Programming Interface (API) by a second network node, wherein the second network node comprises at least one of an application function, an application server, or a Services Capability Server (SCS). Optionally, the consent result may be further for at least one purpose describing one or more reasons of an operation of personal data and / or one or more reasons to invoke a specific API by the second network node.
[0164] In an embodiment, the consent result is further for at least one data scope about the operation of personal data and / or invoking the specific API by the second network node.
[0165] At block 504, the third network node may send, to a first network node, a response comprising the consent result for the at least data scope.
[0166] In an embodiment, the request may further comprise at least one of the at least one purpose describing one or more reasons of an operation of personal data and / or one or more reasons to invoke the specific API by the second network node, a group identifier, a user equipment identifier, a user identifier, or an identifier of the second network node.
[0167] In an embodiment, the at least one data scope may comprise at least one of identification data, address data, contact data, authorization related data, location data, device status data, a parameter to influence personal data, or traffic related data.
[0168] In an embodiment, the at least one data scope may be mapped to at least one of a specific Application Programming Interface (API), a specific API operation, or a specific event type of API operation.
[0169] In an embodiment, the consent result may comprise information indicating whether a consent is granted or not for the at least one data scope.
[0170] In an embodiment, the consent result may further comprise at least one constraint associated with a consent.
[0171] In an embodiment, the first network node may comprise at least one of Service Capability Exposure Function (SCEF), Network Exposure Function (NEF), or SCEF combined with NEF.
[0172] In an embodiment, the second network node may comprise at least one of an application function, an application server, or a Services Capability Server (SCS).
[0173] In an embodiment, the third network node may comprise a consent management node.
[0174] FIG.5b shows a flowchart of a method 510 according to another embodiment of the present disclosure.
[0175] At block 512, the third network node may obtain consent data.
[0176] As described above, the third network node may obtain the consent data in various ways. In an embodiment, the consent data may be obtained from a provisioning system or a consent capture system.
[0177] In an embodiment, the consent capture system may comprise Oauth server or Communication Service Provider selfcare portal.
[0178] Other embodiments
[0179] In an embodiment, the first network node such as NEF / SCEF may interact with the third network node such as consent management system (or node) to ensure first network node’s APIs process personal data with required consent to fulfil the corresponding regulation(s).
[0180] In an embodiment, the third network node such as consent management node may provide the provisioning solution to allow provisioning system or consent capture system to provision the consent data.
[0181] In an embodiment, the third network node such as consent management system may expose interface for the first network node such as NEF / SCEF to handle the consent evaluation based on purpose and / or data scope.
[0182] In an embodiment, the third network node such as consent management system may provide provisioning solution to collect consent data.
[0183] In an embodiment, the first network node such as NEF / SCEF may integrate with the third network node such as consent management system to check consent and constraints during the API invocation procedure.
[0184] In an embodiment, the first network node’s API request may be extended to carry the purpose of the second network node (such as AF) invokes the API request.
[0185] In an embodiment, the first network node such as NEF / SCEF may translate external identifier such as non-MSISDN UE ID to internal identifier such as MSISDN in order to do consent check.
[0186] In an embodiment, the first network node such as NEF / SCEF may retrieve the UE ID list by Group ID in order to do consent check.
[0187] In an embodiment, the first network node’s API response may be extended to include cause indication when consent(s) and / or constraint(s) are not fulfilled.
[0188] In an embodiment, to use the first network node’s API, the second network node such as AF should be onboarded in first network node first. During the onboarding, CSP may decide what API can be used by the second network node, and if the consent evaluation is required for this second network node (e.g. un-trusted application).
[0189] In an embodiment, at least one of below information may be provisioned during the second network node onboarding:
[0190] The second network node (such as AF) ID,
[0191] The first network node (such as NEF) API ID,
[0192] The first network node API operation(s),
[0193] New attribute: Consent Indicator (indicating if consent is required or not),
[0194] New attribute: Purpose, or
[0195] New attribute: Data Scope.
[0196] In an embodiment, it may introduce the above new additional attributes in the onboarding function / message.
[0197] In an embodiment, when the second network node calls the first network node’s API, at least one of below information may be provided in the request:
[0198] the second network node’s ID,
[0199] the first network node’s API operation (e.g. implicitly derive from the request),
[0200] New attribute: Purpose, or
[0201] New attribute: Data Scope (option).
[0202] In an embodiment, if the second network node such as AF communicates with the first network node such as NEF with Oauth enabled, the second network node’s ID (such as AF ID), purpose and / or data scope can be contained in Oauth access token to the first network node such as NEF.
[0203] FIG.6a shows a flowchart of a method according to another embodiment of the present disclosure.
[0204] This procedure describes the procedure that T8 API request includes a single UE ID and the consent evaluation is based on individual UE ID. T8 is a reference point used between the SCEF and the SCS / AS.
[0205] Step 1. AF sends T8 API request to NEF. The request may include at least one of AF ID, the target UE ID, purpose and data scope (optional) about the AF invokes the API.
[0206] Note: NEF may base on application onboarding information to check if consent evaluation is required for AF request. If so, steps 2-5 may be executed.
[0207] Step 2. If the UE ID in the request is not MSISDN, e.g., UE IP address, NEF may translate it to MSISDN leveraging the function provided by 5GC.
[0208] Step 3. NEF sends a request to consent management node to check consent. The request may include at least one of UE ID as MSISDN, AF ID, data scope of the API and the purpose.
[0209] Note: if AF doesn’t provide data scope in the request, NEF may derive the data scope based on the onboarding information.
[0210] Step 4. The consent management node returns the consent evaluation result to NEF.
[0211] Step 5. NEF checks the consent evaluation result. If consent is available, associated constraint(s) may be defined as well. NEF may further check if the constraint(s) is fulfilled. Examples of the constraints are as below:
[0212] API invocation time, or
[0213] A specific parameter in the API request shall be within a range.
[0214] Step 6. If consent is available and the constraint(s) is fulfilled, NEF may continue the API procedure.
[0215] Step 7. NEF returns a successful response to AF.
[0216] Step 8. Otherwise, NEF returns a failed API response to AF with cause indicator about consent issue.
[0217] FIG.6b shows a flowchart of a method according to another embodiment of the present disclosure.
[0218] This procedure describes the procedure that T8 API request includes a Group ID (indicating a group of UEs) and the consent evaluation is based on Group ID.
[0219] Step 1. AF sends T8 API request to NEF. The request may include at least one of AF ID, the target Group ID, and purpose and data scope (optional) about the AF invokes the API.
[0220] Step 2. NEF sends a request to consent management node to check consent. The request may include at least one of Group ID, AF ID, data scope of the API and the purpose.
[0221] Step 3. The consent management node returns the consent evaluation result to NEF.
[0222] Step 4. NEF checks the consent evaluation result. If consent associated with the Group ID is available, associated constraint(s) may be defined as well. NEF may further check if the constraint(s) is fulfilled. Examples of the constraints are as below:
[0223] API invocation time, or
[0224] A specific parameter in the API request shall be within a range.
[0225] Step 5. If consent is available and the constraint(s) is fulfilled, NEF may continue the API procedure.
[0226] Step 6. NEF returns a successful response to AF.
[0227] Step 7. Otherwise, NEF returns a failed API response to AF with cause indicator about consent issue.
[0228] FIG.6c shows a flowchart of a method according to another embodiment of the present disclosure.
[0229] This procedure describes the procedure that T8 API request includes a Group ID (indicating a group of UEs) and the consent evaluation is based on individual UE ID.
[0230] Step 1. AF sends T8 API request to NEF. The request may include at least one of AF ID, the target Group ID, and purpose and data scope (optional) about the AF invokes the API.
[0231] Step 2. NFE sends a request to UDM to retrieve the UE ID list by the Group ID.
[0232] Step 3. UDM returns the UE ID list to NEF.
[0233] Step 4. For each UE ID, NEF sends a request to consent management node to check consent. The request may include at least one of UE ID as MSISDN, AF ID, data scope of the API and the purpose.
[0234] Step 5. The consent management node returns the consent evaluation result to NEF.
[0235] Step 6. NEF checks the consent evaluation results for all UE ID in the list. If consent for a specific UE ID is available, associated constraint(s) may be defined as well. NEF may further check if the constraint(s) is fulfilled. Examples of the constraints are as below:
[0236] API invocation time, or
[0237] A specific parameter in the API request shall be within a range.
[0238] Step 7. If ALL consents are available and ALL constraints are fulfilled, NEF may continue the API procedure, otherwise NEF may stop process.
[0239] Step 8. NEF returns a successful response to AF.
[0240] Step 9. Otherwise, NEF returns a failed API response to AF with cause indicator about consent issue.
[0241] FIG.6d shows a flowchart of a method according to another embodiment of the present disclosure.
[0242] A concrete example about how T8 API AsSessionWithQos is extended with Consent Management support is illustrated in FIG.6d.
[0243] This procedure describes the procedure that AsSessionWithQos Subscription request includes a single UE ID (IP address) and the consent evaluation is based on individual UE ID (MSISDN).
[0244] Step 1. AF sends create AsSessionWithQos Subscription request (see clause 5.14.2.1.2 of 3GPP TS 29.122 V18.5.0) to NEF. The request may include at least one of AF ID, UE ID address, ipDomain, flowinfo, qosReference and purpose and data scope (optional) about the AF invokes the API.
[0245] Step 2. NEF sends a request to Binding Support Function (BSF) to get PCF binding in order to obtain the PCF address. The request may include UE IP address and ipDomain.
[0246] Step 3. BSF returns the PCF binding information.
[0247] Step 4. NEF exacts the MSISDN of the UE from the PCF binding information.
[0248] Step 5. NEF sends a request to consent management node to check consent. The request may include at least one of UE ID as MSISDN, AF ID, data scope of the AsSessionWithQos and the purpose.
[0249] Step 6. The consent management node returns the consent evaluation result to NEF.
[0250] Step 7. NEF checks the consent evaluation result. If consent is available, associated constraint(s) may be defined as well. NEF may further check if the constraint(s) is fulfilled. Examples of the constraints are as below:
[0251] API invocation time, or
[0252] The allowed values of qosReference.
[0253] Step 8. If consent is available and the constraint(s) is fulfilled, NEF may continue the Policy Authorization Creation procedure.
[0254] Step 9. NEF returns a Successful Create AsSessionWithQos Subscription response to AF.
[0255] Step 10. Otherwise, NEF returns a Failed Create AsSessionWithQos Subscription response with cause indicator about consent issue to AF.
[0256] FIG.6e shows a flowchart of a method according to another embodiment of the present disclosure.
[0257] This procedure describes the procedure that AsSessionWithQos Subscription request includes a Group ID (indicating a group of UEs) and the consent evaluation is based on Group ID.
[0258] Step 1. AF sends create AsSessionWithQos Subscription request to NEF. The request may include at least one of AF ID, Groupld, flowinfo, qosReference, and purpose and data scope (optional) about the AF invokes the API.
[0259] Step 2. NEF sends a request to consent management node to check consent. The request may include at least one of Group ID, AF ID, data scope of the AsSessionWithQos and the purpose.
[0260] Step 3. The consent management node returns the consent evaluation result to NEF.
[0261] Step 4. NEF checks the consent evaluation result. If consent is available, associated constraint(s) may be defined as well. NEF may further check if the constraint(s) is fulfilled. Examples of the constraints are as below:
[0262] API invocation time, or
[0263] The allowed values of qosReference.
[0264] Step 5. If consent is available and the constraint(s) is fulfilled, NEF may continue the Policy Authorization Creation for group procedure.
[0265] Step 6. NEF returns a Successful Create AsSessionWithQos Subscription response to AF.
[0266] Step 7. Otherwise, NEF returns a Failed Create AsSessionWithQos Subscription response with cause indicator about consent issue to AF.
[0267] FIG.6f shows a flowchart of a method according to another embodiment of the present disclosure.
[0268] This procedure describes the procedure that AsSessionWithQos Subscription request includes a Group ID (indicating a group of UEs) and the consent evaluation is based on individual UE ID (MSISDN).
[0269] Step 1. AF sends create AsSessionWithQos Subscription request to NEF. The request may include at least one of AF ID, Groupld, flowinfo, qosReference and purpose and data scope (optional) about the AF invokes the API.
[0270] Step 2. NEF sends a request to UDM to retrieve the UE ID list by the Group ID.
[0271] Step 3. UDM returns the UE ID list to NEF.
[0272] Step 4. For each UE ID, NEF sends a request to consent management node to check consent. The request may include UE ID as MSISDN, AF ID, data scope of the AsSessionWithQos and the purpose.
[0273] Step 5. The consent management node returns the consent evaluation result to NEF.
[0274] Step 6. NEF checks the consent evaluation results for all UE ID in the list. If consent for a specific UE ID is available, associated constraint(s) may be defined as well. NEF may further check if the constraint(s) is fulfilled. Examples of the constraints are as below:
[0275] API invocation time,
[0276] A specific parameter in the API request shall be within a range.
[0277] Step 7. If ALL consents are available and ALL constraints are fulfilled, NEF may continue the Policy Authorization Creation for group procedure, otherwise NEF may stop process.
[0278] Step 8. NEF returns a Successful Create AsSessionWithQos Subscription response to AF.
[0279] Step 9. Otherwise, NEF returns a Failed Create AsSessionWithQos Subscription response with cause indicator about consent issue to AF.
[0280] Some messages of FIGs.6a-6f may be similar to the corresponding messages as described in various 3GPP specifications such as 3GPP TS 23.502 V18.5.0, 3GPP TS 23.682 VI 8.0.0, 3GPP TS 29.122 V18.5.0, 3GPP TS 29.522 VI 8.5.0, etc. Some messages of FIGs.6a-6f may be enhanced according to various embodiments of the present disclosure. Some messages of FIGs.6a-6f are new messages according to various embodiments of the present disclosure.
[0281] Embodiments herein may provide many advantages, of which a non-exhaustive list of examples follows. In some embodiments herein, it may extend the APIs of network node (such as NEF) with consent evaluation to protect end user’s privacy. In some embodiments herein, it may provide a generic solution that covers all APIs of network node (such as NEF) and different ways to collect consent data. In some embodiments herein, it may follow some regulations such as GPDR to protect end user’s privacy. In some embodiments herein, it may support consent for two or more networks (such as both EPC and 5GC (dual mode call)). The embodiments hereinare not limited to the features and advantages mentioned above. A person skilled in the art will recognize additional features and advantages upon reading the following detailed description.
[0282] FIG.7 is a block diagram showing an apparatus suitable for practicing some embodiments of the disclosure. For example, the first network node, the second network node or the third network node described above may be implemented as or through the apparatus 700.
[0283] The apparatus 700 comprises at least one processor 721, such as a digital processor (DP), and at least one memory (MEM) 722 coupled to the processor 721. The apparatus 700 may further comprise a transmitter TX and receiver RX 723 coupled to the processor 721. The MEM 722 stores a program (PROG) 724. The PROG 724 may include instructions that, when executed on the associated processor 721, enable the apparatus 700 to operate in accordance with the embodiments of the present disclosure. A combination of the at least one processor 721 and the at least one MEM 722 may form processing means 725 adapted to implement various embodiments of the present disclosure.
[0284] Various embodiments of the present disclosure may be implemented by computer program executable by one or more of the processor 721, software, firmware, hardware or in a combination thereof.
[0285] The MEM 722 may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memories and removable memories, as non-limiting examples.
[0286] The processor 721 may be of any type suitable to the local technical environment, and may include one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples.
[0287] In an embodiment where the apparatus is implemented as or at the first network node, the memory 722 contains instructions executable by the processor 721, whereby the first network node operates according to any of the methods performed by the first network node as described above.
[0288] In an embodiment where the apparatus is implemented as or at the second network node, the memory 722 contains instructions executable by the processor 721, whereby the second network node operates according to any of the methods performed by the second network node as described above.
[0289] In an embodiment where the apparatus is implemented as or at the third network node, the memory 722 contains instructions executable by the processor 721, whereby the third network node operates according to any of the methods performed by the third network node as described above.
[0290] Further, the exemplary overall commutation system including the terminal device and the network node (such as the first network node, the second network node or the third network node) may be provided.
[0291] The term unit or module may have conventional meaning in the field of electronics, electrical devices and / or electronic devices and may include, for example, electrical and / or electronic circuitry, devices, modules, processors, memories, logic solid state and / or discrete devices, computer programs or instructions for carrying out respective tasks, procedures, computations, outputs, and / or displaying functions, and so on, as such as those that are described herein.
[0292] According to an aspect of the disclosure it is provided a computer program product being tangibly stored on a computer readable storage medium and including instructions which, when executed on at least one processor, cause the at least one processor to carry out any of the methods as described above.
[0293] According to an aspect of the disclosure it is provided a computer-readable storage medium storing instructions which when executed by at least one processor, cause the at least one processor to carry out any of the methods as described above.
[0294] In addition, the present disclosure may also provide a carrier containing the computer program as mentioned above, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium. The computer readable storage medium can be, for example, an optical compact disk or an electronic memory device like a RAM (random access memory), a ROM (read only memory), Flash memory, magnetic tape, CD-ROM, DVD, Blue-ray disc and the like.
[0295] The techniques described herein may be implemented by various means so that an apparatus implementing one or more functions of a corresponding apparatus described with an embodiment comprises not only prior art means, but also means for implementing the one or more functions of the corresponding apparatus described with the embodiment and it may comprise separate means for each separate function, or means that may be configured to perform two or more functions. For example, these techniques may be implemented in hardware (one or more apparatuses), firmware (one or more apparatuses), software (one or more modules), or combinations thereof. For a firmware or software, implementation may be made through modules (e.g., procedures, functions, and so on) that perform the functions described herein.
[0296] Exemplary embodiments herein have been described above with reference to block diagrams and flowchart illustrations of methods and apparatuses. It will be understood that each block of the block diagrams and flowchart illustrations, and combinations of blocks in the block diagrams and flowchart illustrations, respectively, can be implemented by various means including computer program instructions. These computer program instructions may be loadedonto a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions which execute on the computer or other programmable data processing apparatus create means for implementing the functions specified in the flowchart block or blocks.
[0297] Further, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the subject matter described herein, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.
[0298] While this specification contains many specific implementation details, these should not be construed as limitations on the scope of any implementation or of what may be claimed, but rather as descriptions of features that may be specific to particular embodiments of particular implementations. Certain features that are described in this specification in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination. Moreover, although features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be excised from the combination, and the claimed combination may be directed to a sub-combination or variation of a sub-combination.
[0299] It will be obvious to a person skilled in the art that, as the technology advances, the inventive concept can be implemented in various ways. The above described embodiments are given for describing rather than limiting the disclosure, and it is to be understood that modifications and variations may be resorted to without departing from the spirit and scope of the disclosure as those skilled in the art readily understand. Such modifications and variations are considered to be within the scope of the disclosure and the appended claims. The protection scope of the disclosure is defined by the accompanying claims.
Claims
WHAT IS CLAIMED IS:
1. A method (300) performed by a first network node comprising a network exposure node, comprising: sending (312), to a third network node comprising a consent management node, a request for retrieving a consent result, wherein the request comprises second information indicating at least one data scope about an operation of personal data and / or invoking a specific Application Programming Interface (API) by a second network node, wherein the second network node comprises at least one of an application function, an application server, or a Services Capability Server (SCS); and receiving (314), from the third network node, a response comprising a consent result for the at least one data scope.
2. The method according to claim 1, wherein the consent result comprises information indicating whether a consent is granted or not based on the at least one data scope.
3. The method according to claim 1 or 2, wherein the consent result further comprises at least one constraint associated with a consent.
4. The method according to any of claims 1 to 3, wherein the at least one data scope comprises at least one of: identification data, address data, contact data, authorization related data, location data, device status data, a parameter to influence personal data, or traffic related data.
5. The method according to any of claims 1-4, further comprising: receiving (302), from the second network node, a first message to invoke the specific API.
6. The method according to claim 5, wherein the at least one data scope is mapped to at least one of: a specific API, a specific API operation, or a specific event type of API operation.
7. The method according to claim 5 or 6, further comprising: sending (306) a second message to a fourth network node based on the consent result,wherein the second message is generated by the first network node based on the first message; wherein the fourth network node comprises at least one of: Unified Data Management (UDM), Policy Control Function (PCF), Unified Data Repository (UDR), Access and Mobility Management Function (AMF), or network data analytics function (NWDAF).
8. The method according to claim 7, wherein sending a second message to a fourth network node based on the consent result comprises at least one of: if a consent is granted, sending the second message to the fourth network node; or if a consent is granted and all constraints associated with the consent are fulfilled, sending the second message to the fourth network node.
9. The method according to any of claims 5 to 8, wherein the first message comprises first information indicating at least one purpose describing one or more reasons of an operation of personal data and / or one or more reasons to invoke the specific API.
10. The method according to any of claims 5-9, further comprising: if a consent is not granted, sending (352), to the second network node, a message comprising information indicating a consent issue; and / or if a consent is granted and at least one constraint associated with the consent is not fulfilled, sending (354), to the second network node, a message comprising information indicating a consent issue.
11. The method according to any of claims 5-10, further comprising: receiving (332), from the second network node, an onboarding message comprising at least one of an identifier of the second network node, an API identifier of the first network node, an API operation of the first network node, a consent indicator indicating whether consent is required or not, a purpose, or a data scope.
12. The method according to claim 11, further comprising: checking (342) if a consent evaluation is required for the first message based on the onboarding message; and / or if the first message does not comprise the at least one data scope, deriving (344) the at least one data scope based on the onboarding message.
13. The method according to any of claims 1 to 12, wherein the request further comprises at least one of: at least one purpose, a group identifier, a user equipment identifier, a user identifier, or an identifier of the second network node.
14. The method according to claim 13, further comprising: translating (322) a first user equipment identifier in the first message to the user equipment identifier to be used in the request; or translating (324) a first group identifier in the first message to the group identifier to be used in the request; or obtaining (326) a list of user equipment identifiers to be used in the request based on the first group identifier in the first message.
15. A method (400) performed by a second network node, wherein the second network node comprises at least one of an application function, an application server, or a Services Capability Server (SCS), comprising: sending (402), to a first network node comprising a network exposure node, a first message comprising second information indicating at least one data scope about an operation of personal data and / or invoking a specific Application Programming Interface (API) by the second network node.
16. The method according to claim 15, wherein the at least one data scope comprises at least one of: identification data, address data, contact data, authorization related data, location data, device status data, a parameter to influence personal data, or traffic related data.
17. The method according to claim 15 or 16, wherein the at least one data scope is mapped to at least one of: a specific API, a specific API operation, or a specific event type of API operation.
18. The method according to any of claims 15 to 17, further comprising: sending (410), to the first network node, an onboarding message comprising at least one of an identifier of the second network node, an API identifier of the first network node, an API operation of the first network node, a consent indicator indicating whether consent is required or not, a purpose, or a data scope.
19. The method according to any of claims 15 to 18, wherein the first message further comprises first information indicating at least one purpose describing one or more reasons of an operation of personal data and / or one or more reasons to invoke the specific API by the second network node.
20. A method (500) performed by a third network node comprising a consent management node, comprising: receiving (502), from a first network node comprising a network exposure node, a request for retrieving a consent result, wherein the request comprises second information indicating at least one data scope about an operation of personal data and / or invoking a specific Application Programming Interface (API) by a second network node, wherein the second network node comprises at least one of an application function, an application server, or a Services Capability Server (SCS); and sending (504), to the first network node, a response comprising the consent result for the at least one data scope.
21. The method according to claim 20, wherein the consent result is for at least one data scope about the operation of personal data and / or invoking the specific API by the second network node.
22. The method according to claim 20 or 21, wherein the at least one data scope comprises at least one of: identification data, address data, contact data, authorization related data, location data, device status data, a parameter to influence personal data, or traffic related data.
23. The method according to any of claims 20 to 22, wherein the at least one data scope is mapped to at least one of: a specific API, a specific API operation, or a specific event type of API operation.
24. The method according to any of claims 20 to 23, wherein the request further comprises at least one of:at least one purpose describing one or more reasons of an operation of personal data and / or one or more reasons to invoke the specific API by the second network node, a group identifier, a user equipment identifier, a user identifier, or an identifier of the second network node.
25. The method according to any of claims 20-24, further comprising: obtaining (512) consent data from a provisioning system or a consent capture system, wherein the consent capture system comprises Oauth server or Communication Service Provider selfcare portal.
26. The method according to any of claims 20-25, wherein the consent result comprises information indicating whether a consent is granted or not for the at least one data scope.
27. The method according to any of claims 20-26, wherein the consent result further comprises at least one constraint associated with a consent.
28. A first network node (700) comprising a network exposure node, comprising: a processor (721); and a memory (722) coupled to the processor (721), said memory (722) containing instructions executable by said processor (721), whereby said first network node (700) is operative to: send, to a third network node comprising a consent management node, a request for retrieving a consent result, wherein the request comprises second information indicating at least one data scope about an operation of personal data and / or invoking a specific Application Programming Interface (API) by a second network node, wherein the second network node comprises at least one of an application function, an application server, or a Services Capability Server (SCS); and receive, from the third network node, a response comprising a consent result for the at least one data scope.
29. The first network node according to claim 28, wherein the first network node is further operative to perform the method of any one of claims 2 to 14.
30. A second network node (700) comprising at least one of an application function, an application server, or a Services Capability Server (SCS), comprising: a processor (721); and a memory (722) coupled to the processor (721), said memory (722) containing instructions executable by said processor (721), whereby said second network node (700) is operative to:send, to a first network node comprising a network exposure node, a first message comprising second information indicating at least one data scope about an operation of personal data and / or invoking a specific Application Programming Interface (API) by the second network node.
31. The second network node according to claim 30, wherein the second network node is further operative to perform the method of any one of claims 16 to 19.
32. A third network node (700) comprising a consent management node, comprising: a processor (721); and a memory (722) coupled to the processor (721), said memory (722) containing instructions executable by said processor (721), whereby said third network node (700) is operative to: receive, from a first network node comprising a network exposure node, a request for retrieving a consent result, wherein the request comprises second information indicating at least one data scope about an operation of personal data and / or invoking a specific Application Programming Interface (API) by a second network node, wherein the second network node comprises at least one of an application function, an application server, or a Services Capability Server (SCS); and send, to the first network node, a response comprising the consent result for the at least one data scope.
33. The third network node according to claim 32, wherein the third network node is further operative to perform the method of any one of claims 21 to 27.
34. A computer-readable storage medium storing instructions which when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 27.
35. A computer program product comprising instructions which when executed by at least one processor, cause the at least one processor to perform the method according to any one of claims 1 to 27.
Citation Information
Patent Citations
Managing user consent for analytic and event monitoring operations in a core network
WO2024011254A1