Method and apparatus for secure connection between artificial intelligence server and base station node

By establishing an IPSec tunnel between the base station and the AI ​​server and using encryption keys, the security issue of data transmission between the base station and the AI ​​server is solved, enabling secure and reliable data transmission and improving the stability and efficiency of the communication network.

CN114747246BActive Publication Date: 2026-01-02ZTE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080082860.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-05-29
Publication Date
2026-01-02
Estimated Expiration
2040-05-29

AI Technical Summary

Technical Problem

In existing technologies, data transmission between base stations and artificial intelligence servers lacks security, resulting in unreliable and insecure transmission of important information such as configuration commands, measurement, and training data.

Method used

The Internet Key Exchange (IKE) protocol is used to establish a data transmission tunnel based on the Internet Protocol Security (IPSec) network protocol between the base station and the artificial intelligence server. The user plane data is encrypted using encryption keys, and user and control plane data are transmitted through the IPSec tunnel.

Benefits of technology

Secure data transmission between base stations and artificial intelligence servers has been achieved, ensuring the security and reliability of configuration commands, measurement and training data, and improving the operational stability and efficiency of communication networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114747246B_ABST
    Figure CN114747246B_ABST
Patent Text Reader

Abstract

Disclosed herein are methods and systems for securely sending user plane data from a base station to an artificial intelligence (AI) server via a mobile telecommunication network. In one embodiment, a method performed by a base station located in a radio access network (RAN) includes sending an interface setup request to an (AI) server, receiving an interface setup response from the AI server, establishing an Internet Protocol Security (IPSec) network protocol based data transfer tunnel between the base station and the AI server by exchanging encryption keys using an Internet Key Exchange (IKE) protocol, and sending user plane data from the base station to the AI server for training an artificial intelligence based model.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates generally to communication systems, and more particularly to a system for securing user plane and control plane data transmission between a base station and an artificial intelligence (AI) server. BACKGROUND

[0002] Wireless communication systems are widely deployed to provide various telecommunication services such as telephony, video, data, messaging, and broadcasts. Typical wireless communication systems can employ multiple-access technologies capable of supporting communication with multiple users by sharing available system resources (e.g., time, frequency, power, etc.). Examples of such multiple-access technologies include code-division multiple access (CDMA) systems, time-division multiple access (TDMA) systems, frequency-division multiple access (FDMA) systems, orthogonal frequency-division multiple access (OFDMA) systems, single-carrier frequency-division multiple access (SC-FDMA) systems, time division synchronous code division multiple access (TD-SCDMA) systems, Long Term Evolution (LTE) and 5G networks.

[0003] A wireless communication network can include a number of base stations (BSs) that can support communication for a number of user equipment (UEs). A BS can also be referred to as an evolved node B (eNB or eNode B), a g-nodeB (gNB), an access point (AP), a radio head, a transmit receive point (TRP), a new radio (NR) BS, a 5G node B, a radio access network (RAN) node, and / or the like, as the skilled man will appreciate.

[0004] In a wireless communication network, a BS provides user plane (UP) and control plane (CP) signaling between the BS and a UE. As known to those skilled in the art, the UP carries network user traffic and the CP carries routing configuration data. In addition, the UP and CP signaling protocols can also be used to establish communication between the BS and any other interface.

[0005] In the above-described wireless communication system, a large amount of data is generated during the operation of the communication network, including transport layer data (channels, spectrum, and customer links), network layer data (signaling and management data), and various types of application layer data. This large amount of data can be used to create and train artificial intelligence models for adaptive network policy decisions, prediction of user and network demands, resource orchestration and scheduling, and other network automation solutions. Therefore, the above-described UP and CP signaling protocols are used to establish communication between the BS and an artificial intelligence (AI) server. In addition, the BS uses the CP signaling protocol to send configuration commands to the AI server to set AI model parameters and uses the UP signaling protocol to send measurement and training data to the AI server. Since the configuration commands, measurement and training data, and AI model outputs are indispensable for the operation of the communication network, a secure data transmission protocol needs to be established between the BS and the AI server. SUMMARY

[0006] The example embodiments disclosed herein are directed to addressing the problems identified above, and to providing additional features that will become apparent upon reading the following detailed description in conjunction with the drawings. In accordance with various embodiments, example systems, methods, devices, and computer program products are disclosed herein. It should be understood, however, that these embodiments are presented by way of example and not limitation, and that various modifications can be made while remaining within the scope of the disclosure as will become apparent to those of ordinary skill upon reading the following detailed description.

[0007] In one embodiment, a method for securely sending user plane data from a base station to an artificial intelligence (AI) server via a mobile telecommunication network includes, at a base station located in a radio access network (RAN): sending an interface request to the AI server, receiving an interface response from the AI server, establishing an Internet Protocol Security (IPSec) network protocol based data transfer tunnel between the base station and the AI server by exchanging encryption keys using an Internet Key Exchange (IKE) protocol, and sending user plane data from the base station to the AI server for training an artificial intelligence based model.

[0008] In a further embodiment, securely sending user plane data from a base station to an artificial intelligence (AI) server further includes encrypting the user plane data using the encryption keys. And encapsulating a payload having the user plane data into an Internet Protocol (IP) packet.

[0009] In another embodiment, a method for securely exchanging first control plane data and second control plane data between a base station and an artificial intelligence (AI) server via a mobile telecommunication network includes, at a base station located in a radio access network (RAN): sending an interface setup request to the (AI) server, wherein the interface setup request includes a first list of Internet Protocol Security (IPSec) control plane addresses of the base station, receiving an interface setup response from the AI server, wherein the interface setup request includes a second list of Internet Protocol Security (IPSec) control plane addresses of the AI server, establishing an Internet Protocol Security (IPSec) network protocol based data transfer tunnel between the base station and the AI server by exchanging encryption keys using an Internet Key Exchange (IKE) protocol, sending first control plane data from the base station to the AI server for configuring an artificial intelligence based model, receiving second control plane data from the AI server for configuring the base station.

[0010] In a further embodiment, the disclosure provides an apparatus configured to perform any of the methods disclosed herein.

[0011] In further embodiments, the present disclosure provides a non-transitory computer- readable storage medium storing computer-executable instructions that, when executed, perform any of the methods disclosed herein.

[0012] In further embodiments, a wireless communication node includes a memory storing computer-executable instructions that, when executed, perform any of the methods disclosed herein; and at least one processor coupled to the memory and configured to execute the computer-executable instructions. BRIEF DESCRIPTION OF DRAWINGS

[0013] Various exemplary embodiments of the present disclosure are described in detail below. The accompanying drawings are provided solely for illustration of the exemplary embodiments of the present disclosure and are not intended to limit the scope of the disclosure. It will be apparent to one of ordinary skill in the art that the drawings presented are not necessarily drawn to scale and that, unless otherwise specified, the drawings are merely intended to conceptually illustrate the structures and procedures described herein. In the drawings:

[0014] Figure 1 is a schematic configuration diagram of a radio communication network connected to an AI server according to some embodiments of the present disclosure.

[0015] Figure 2 is an operation sequence diagram illustrating an operational flow with respect to establishing a secure IPSec tunnel between a RAN node and an AI server according to various embodiments of the present disclosure.

[0016] Figure 3 is an operation sequence diagram illustrating an operational flow with respect to establishing a secure IPSec tunnel between a RAN node and an AI server for transmission of control plane data according to some embodiments of the present disclosure.

[0017] Figure 4 is an operation sequence diagram illustrating an operational flow with respect to establishing a secure IPSec tunnel between a RAN node and an AI server for exchange of operational and maintenance (O&M) configuration according to various embodiments of the present disclosure.

[0018] Figures 5A to 5C illustrates examples of various structures of interface request messages according to some embodiments of the present disclosure.

[0019] Figure 6 is a block diagram of a flowchart of a method for establishing a secure IPSec tunnel between a RAN node and an AI server according to various embodiments of the present disclosure.

[0020] Figure 7A block diagram illustrating a wireless communication system including network nodes and user equipment according to various embodiments of the present disclosure is shown.

[0021] Figure 8 An example of an AI server configured to perform the methods disclosed herein according to various embodiments of the present disclosure is shown. DETAILED DESCRIPTION

[0022] Various exemplary embodiments of the present disclosure are described below with reference to the accompanying drawings, so that a person of ordinary skill in the art can make and use the present disclosure. Various changes or modifications can be made to the examples described herein without departing from the scope of the present disclosure, which will be apparent to those of ordinary skill in the art upon reading the present disclosure. Therefore, the present disclosure is not limited to the exemplary embodiments and applications described and illustrated herein. Furthermore, the specific order and / or hierarchy of steps in the methods disclosed herein are merely exemplary methods. Based upon design preferences, the specific order or hierarchy of steps of the disclosed methods or processes can be re-arranged, while remaining within the scope of the present disclosure. Therefore, a person of ordinary skill in the art will understand that the methods and techniques disclosed herein present various steps or acts in an exemplary order and that the present disclosure is not limited to the specific order or hierarchy presented unless specifically stated otherwise.

[0023] As discussed herein, a“wireless communication node” can include or be implemented as a Next Generation Node B (gNB), an E-UTRAN Node B (eNB), a transmission reception point (TRP), an access point (AP), a donor node (DN), a relay node, a core network (CN) node, a RAN node, a master node, a secondary node, a distributed unit (DU), a centralized unit (CU), etc., in accordance with the understanding of those of skill in the art. Furthermore, as discussed herein, a“wireless communication device” can include or be implemented as a station (STA), a mobile terminal (MT), a mobile station (MS), etc., in accordance with the understanding of those of skill in the art. In the description of the following exemplary embodiments, the“wireless communication node” is referred to as a base station“BS” and the“wireless communication device” is referred to as a user equipment“UE.” However, it should be understood that the scope of the present disclosure is not limited to these exemplary embodiments.

[0024] Figure 1is a schematic configuration diagram of a wireless communication network 101 connected to an AI server 111 according to various embodiments of the disclosure. In some embodiments, the wireless communication network 101 can be an LTE network or some other wireless network, such as a 5G NR network. The wireless communication network 101 can include a plurality of BSs 107 and a plurality of UEs 103. In some embodiments, the BSs 107 can perform one or more of the following functions: transmission of user data, radio channel encryption and decryption, integrity protection, header compression, mobility control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection setup and release, load balancing, distribution of Non-Access Stratum (NAS) messages, NAS node selection, synchronization, Radio Access Network (RAN) sharing, Multimedia Broadcast Multicast Service (MBMS), subscriber and equipment tracking, RAN Information Management (RIM), paging, positioning, and warning message transfer.

[0025] Furthermore, each BS 107 can provide communication coverage for a particular geographic area. In some embodiments, the geographic area that is covered by a BS and / or the BS subsystem that serves the geographic area can be referred to as a "cell." In other embodiments, each BS 107 can interconnect with one or more other BSs and / or with one or more other BSs through various types of backhaul links or through an X2 interface. The backhaul links can be wired or wireless. Furthermore, each BS 107 in the wireless communication network 101 can be connected by an IP network 109 to an AI server 111. In some embodiments, the BSs 107 can be connected to the AI server 111 through an S1 interface.

[0026] The UEs 103 can be dispersed throughout the wireless network 101, and each UE can be stationary or mobile. A UE can be a cellular phone (e.g., a smart phone), a personal digital assistant (PDA), a wireless modem, a wireless communication device, a handheld device, a laptop computer, a cordless phone, a wireless local loop (WLL) station, a tablet, a camera, a gaming device, a netbook, a smartbook, an ultrabook, a medical device or equipment, a biometric sensor / device, a wearable device (smart watches, smart clothing, smart glasses, smart wrist bands, smart jewelry (e.g., smart ring, smart bracelet)), an entertainment device (e.g., music or video device, or satellite radio), a vehicular component or sensor, a smart meter / sensor, industrial manufacturing equipment, a global positioning system device, or any other suitable device that is configured to communicate via a wireless or wired medium.

[0027] In some embodiments, the AI server 111 can be configured to use statistical regression techniques (e.g., bagged trees, boosted trees, support vector machines (SVM), linear regressors, etc.) to predict performance that the UEs 103 can experience in the future based on collected radio performance measurements, such as path loss and throughput for specific frequency and bandwidth settings received from the BSs 107. In particular, the AI server 111 can provide a learning-based dynamic frequency and bandwidth allocation (DFBA) prediction model that yields significant performance gains. As another example, the AI server 111 can be configured to use a multi-layer perceptron (MLP) model to predict coverage for short or long distance communications under various environmental conditions.

[0028] Figure 2 is an operational sequence diagram illustrating an operational flow with respect to establishing a secure IPSec tunnel between the RAN node 201 and the AI server 203 in accordance with various embodiments of the disclosure. The interface between the RAN node 201 and the AI server 203 established as a result of the operations described herein can be referred to as the “A interface.” In some embodiments, the “A interface” can be used to transmit user control plane signaling to the AI server 203 and transmit results of machine learning models implemented on the AI server 203 to the RAN node 201. In various embodiments, the secure IPSec tunnel can use the IPSec protocol to transmit user plane data described in the ITU RFC 7619 standard.

[0029] In further embodiments, the control plane signaling can include network policy configurations and measurement request parameters. In some embodiments, the user plane data includes measurement data collected at the RAN node 201 and training data. Further, the control plane signaling can be exchanged between the RAN node 201 and the AI server 203 using stream control transmission protocol (SCTP) or transmission control protocol (TCP). Further, the user plane signaling can be exchanged between the RAN node 201 and the AI server 203 using, for example, user datagram protocol (UDP), general packet radio service (GPRS) tunneling protocol (GTP) tunnels, or hypertext transfer protocol (HTTP).

[0030] In some embodiments, the RAN node 201 can send an interface setup request message 205 to the AI server 203 to establish a control plane connection with the AI server 203. This request message can be referred to as an “interface setup request.” In various embodiments, the interface setup request message 205 can include a list of user plane IPSec addresses used by the RAN node 201 to provide a secure link for the transport of user plane data between the RAN node 201 and the AI server 203. In some embodiments, if the user plane signaling between the RAN node 201 and the AI server 203 uses the GTP protocol to transport user plane data, each IPSec address in the list of user plane IPSec addresses is associated with a list of GTP addresses having GTP addresses. In further embodiments, the established GTP tunnel using the GTP protocol to transport user plane can use only the associated IPSec address, otherwise the GTP tunnel can be denied access to user plane or control plane data. In some embodiments, if other user plane data transport protocols are used (such as File Transfer Protocol (FTP), HTTP, or HTTPS) between the RAN node 201 and the AI server 203 to transport user plane and control plane data, address information (e.g., FTP addresses or URLs for HTTP or HTTPS protocols) or protocol port numbers used by these data transport protocols can be associated with each IPSec address in the list of user plane IPSec addresses.

[0031] Upon receiving the interface setup request message 205 initiated by the RAN node 201, the AI server 203 can send an interface response message 207. In some embodiments, the AI server 203 saves the content or payload of the interface setup request message 205 prior to sending the interface response message 207. In some embodiments, the interface response message 207 can carry a list of user plane IPSec addresses of the AI server 203. In addition, the interface response message 207 can also carry addresses of GTP tunnels associated with each IPSec address in the list of user plane IPSec addresses. In further embodiments, multiple user plane IPSec addresses can be used to isolate, for example, measurement and training data belonging to different network slices. In this regard, the isolation of different user planes can provide more secure data transport.

[0032] In some embodiments, the RAN node 201 and the AI server 203 can exchange IPSec tunnel configuration settings for setting up a secure link between the RAN node 201 and the AI server 203. In various embodiments, after receiving the response message 207 from the AI server 203, the RAN node can establish an IPSec tunnel between the RAN node 201 and the AI server 203 by exchanging IPSec tunnel configuration parameters 209 such as encryption keys through the Internet Key Exchange (IKE) protocol. In some embodiments, the RAN node 201 and the AI server 203 can establish multiple IPSec tunnels between the RAN node 201 and the AI server 203 for transporting user plane data.

[0033] In further embodiments, after the RAN node 201 and the AI server 203 establish the IPSec tunnel, at step 211, the RAN node 201 can send user plane data through the IPSec tunnel. Also, at step 211, the AI server 203 can also send its user plane data 211 through the same IPSec tunnel. In various embodiments, before sending the user plane data such as measurement data or training data, the payload including the user plane data can be encrypted and encapsulated according to the requirements of the IPSec protocol described in the ITU RFC7619 standard.

[0034] Figure 3 is an operational sequence diagram illustrating an operational flow regarding establishing a secure IPSec tunnel between the RAN node 301 and the AI server 303 for transporting control plane data according to some embodiments of the present disclosure. In some embodiments, the RAN node 301 and the AI server 303 exchange control plane data including initial parameters for configuring an IPSec tunnel between the RAN node 301 and the AI server 303. More specifically, after the initial parameter exchange, the RAN node 301 and the AI server 303 can modify or delete the initial control plane connection. In some embodiments, if a new control plane secure connection is needed, the RAN node 301 can initiate a new “A-interface” setup procedure to transport control plane data using the existing IPSec tunnel.

[0035] The above described operations of establishing a secure link by the RAN node 301 and the AI server 303 for control plane data transmission are described in detail below. As Figure 3As shown, the RAN node 301 can send an interface request message 305 to the AI server 303 to establish a control plane connection with the AI server 303. In some embodiments, the interface request message 305 can carry a list of control plane IPSec addresses or Datagram Transport Layer Security (DTLS) addresses that can be used by the RAN node 301 to establish a secure link for exchanging control plane data between the RAN node 301 and the AI server 303.

[0036] In some embodiments, if the control plane signaling between the RAN node 301 and the AI server 303 uses a Stream Control Transmission Protocol (SCTP) protocol to transport control plane data, each IPSec or DTLS address in the list of control plane IPSec addresses is associated with a list of SCTP addresses having SCTP addresses. In further embodiments, the established SCTP connection that transports control plane data using the SCTP protocol can only use the associated IPSec or DTLS addresses, otherwise the SCTP connection can be denied access to control plane data. In some embodiments, if other user plane data transport protocols such as File Transfer Protocol (FTP), HTTP, or HTTPS are used to transport user plane and control plane data between the RAN node 301 and the AI server 303, address information (e.g., FTP addresses or URLs for HTTP or HTTPS protocols) or protocol port numbers used by these data transport protocols can be associated with each IPSec or DTLS address in the list of control plane IPSec or DTLS addresses.

[0037] In some embodiments, when the AI server 303 receives the interface request message 305 initiated by the RAN node 301, the AI server 303 sends an interface control plane response message 307. In various embodiments, the AI server 303 can save the contents or payload of the interface request message 305 prior to sending the interface control plane response message 307. In some embodiments, the interface response message 307 can carry a list of control plane IPSec or DTLS addresses of the AI server 303. In addition, the interface response message 307 can additionally carry addresses of the SCTP connections associated with each IPSec or DTLS address in the list of control plane IPSec or DTLS addresses. In further embodiments, multiple control plane IPSec or DTLS addresses can be used to isolate, for example, measurement and training data belonging to different network slices. In this regard, the isolation of different control planes can provide more secure data transmission.

[0038] In some embodiments, the RAN node 301 and the AI server 303 can exchange IPSec tunnel or DTLS connection configuration settings for setting up a secure link for transferring control plane data between the RAN node 301 and the AI server 303. In various embodiments, after receiving the response message 307 from the AI server 203, the RAN node can establish an IPSec tunnel DTLS connection between the RAN node 301 and the AI server 303 by exchanging IPSec tunnel configuration parameters 309 such as encryption keys through the Internet Key Exchange (IKE) protocol. In some embodiments, the RAN node 301 and the AI server 303 can establish multiple IPSec tunnels or DTLS connections between the RAN node 301 and the AI server 303 for transferring control plane data.

[0039] In further embodiments, the RAN node 301 can use the established IPSec tunnel to reestablish a secure control plane connection between the RAN node 301 and the AI server 303. For example, as shown in FIG. 3, the RAN node 301 can send a new interface request message 311 and the AI server can send a new interface response message 313 to establish a new secure control plane connection. Figure 3

[0040] Figure 4 is an operational sequence diagram illustrating an operational flow for establishing a secure IPSec tunnel for exchanging operational and maintenance (O&M) configuration between the RAN node 401 and the AI server 405, in accordance with various embodiments of the present disclosure. In some embodiments, the RAN operational and maintenance (O&M) system 401 can be used to determine optimal settings for the RAN node 403. In other embodiments, the AI server operational and maintenance (O&M) system 407 can be used to determine optimal settings for the AI server 407. In some embodiments, the O&M systems 401 and 407 can be implemented as software (i.e., computer-executable instructions) stored in a non-transitory computer readable medium that, when executed by a processor, allows a network operator to configure the BS 107 or the AI server 111. Thus, the O&M systems 401 and 407 can provide O&M settings 409 and 413 for configuring various operational parameters of the RAN node 403 and the AI server 405.

[0041] ​In various embodiments, the O&M settings 409 can include settings for tuning the RAN node 403 for optimal coverage, capacity, or performance. In some embodiments, the O&M settings 409 can include adjustments to the uplink / downlink gain of signals transmitted by the RAN node 403 to compensate for noise detected within the RAN node 403. In other embodiments, the O&M settings 409 can include reallocating power levels of downlink signals transmitted by the RAN node 403 to address changing traffic conditions. In some embodiments, the O&M settings 413 can include a list of machine learning models and their related parameters. In further embodiments, the O&M settings 409 and 413 can include necessary settings for configuring a secure communication link between the RAN node 403 and the AI server 405. Additionally, the O&M system can also provide keys, authentication, or attestation IDs to the AI server 405 or the RAN node 403.

[0042] In further embodiments, the RAN node O&M system 401 can provide a list of IPSec addresses of the AI server 405 and a list of General Packet Radio Service (GPRS) Tunneling Protocol addresses associated with the IPSec addresses of the AI server 405. Similarly, the AI server O&M system 407 can provide the AI server 405 with all necessary configurations for establishing a secure communication link with the RAN node 403. For example, the AI server O&M system 407 can provide the AI server 405 with a list of IPSec addresses of the RAN node 403 and a list of General Packet Radio Service (GPRS) Tunneling Protocol addresses associated with the IPSec addresses of the RAN node 403.

[0043] The RAN node 403 and the AI server 405 can perform similar sequences of operations to establish a secure communication link as described in Figure 1 Further, after establishing a secure IPSec tunnel through the exchange of IPSec tunnel setting configuration parameters 411, the RAN node 403 and the AI server 405 can establish a secure control plane connection over the existing IPSec tunnel. In some embodiments, to establish a secure control plane connection over the existing IPSec tunnel, the RAN node 403 can send an interface request message 415 to the AI server. In various embodiments, the interface request message 415 can include similar information as in the interface request message 500C described in further detail below. Next, the AI server 405 can send an interface response to the RAN node 403 in response to receiving the interface request message 415. Subsequently, at step 419, after the RAN node 403 and the AI server 405 establish a secure IPSec tunnel, the RAN node 403 and the AI server 405 can transmit user plane as well as control plane data.

[0044] Figures 5A to 5C Examples of various structures of interface request messages 205, 305, and 415 shown in Figure 2 , Figure 3 and Figure 4 respectively, are shown in accordance with some embodiments of the present disclosure.

[0045] Referring to Figure 5A , in some embodiments, the structure 500A of the interface request messages 205, 305, and 415 can include a message type 501 indicating the type of request being made. For example, the message type 501 can carry various attributes describing the type of interface being requested. In addition, the interface request messages 205, 305, and 415 can also include a global RAN node ID 503. In some embodiments, the global RAN node ID 503 is a unique identifier of the RAN node 201 Figure 2 ). In addition, in some embodiments, the interface request can include a list of user plane addresses 505 provided by the RAN node 201 to the AI server 203. In various embodiments, the list of user plane addresses 505 can include a plurality of IPSec user plane transport addresses 507. In other embodiments, the list 505 can include user plane addresses to be modified or deleted. In addition, each IPSec user plane transport address can include an associated list of GTP transport addresses 509 including GTP transport addresses 511. In addition, the list of user plane addresses 505 can also include GTP transport address information 513 for each GTP transport address. In some embodiments, the length of the list of user plane addresses 505 can be preset to a first maximum number of user plane addresses. The length of the associated list of GTP transport addresses 509 can be preset to a second first maximum number of GTP addresses.

[0046] In some embodiments, the list of user plane addresses 505 can include a plurality of DTLS transport addresses for establishing a secure link between the RAN node and the AI server, as shown in structure 500B of Figure 5B , Figure 5B illustrates an interface request message.

[0047] In further embodiments, the interface request message can include a list of control plane addresses 506 for establishing a secure control plane connection link between the RAN node and the AI server, as shown in structure 500C of Figure 5C , Figure 5C illustrates an interface request message. As Figure 5CAs shown, the control plane address list 506 can include a plurality of IPSec or DTLS control plane transport addresses 515. Further, each IPSec or DTLS control plane transport address can include an associated list of SCTP transport addresses 517, which includes SCTP transport addresses 519. Further, the control plane address list 506 can also include SCTP transport address information 521 for each SCTP transport address. In some embodiments, the control plane address list 506 can be preconfigured with a first maximum number of user plane addresses. The associated list of SCTP transport addresses 517 can be preconfigured with a second first maximum number of SCTP addresses.

[0048] Figure 6 is a block diagram of a flowchart of a method for establishing a secure IPSec tunnel between a RAN node and an AI server in accordance with various embodiments of the disclosure. In some embodiments, Figure 6 The flowchart shown can be executed, for example, by the AI server 111.

[0049] In block 601, the BS 107 can send an interface setup request to the AI server 111. In block 603, the BS 107 can receive an interface setup response from the AI server 111. In some embodiments, the AI server 111 sends the interface setup response in response to receiving the interface setup request from the BS 107. In block 605, the BS 107 and the AI server 111 can establish an Internet Protocol Security (IPSec) network protocol based data transfer tunnel between the BS 107 and the AI server 111. In block 607, the BS 107 and the AI server 111 can send user plane data from the BS 107 to the AI server 111 for training an artificial intelligence based model. In some embodiments, the BS 107 can encrypt the user plane data using an encryption key. In further embodiments, the BS 107 can encapsulate a payload carrying the user plane data into Internet Protocol (IP) packets.

[0050] Figure 7 A block diagram of a wireless communication system including a network node (NN) 700 and a user equipment 710 is shown in accordance with various embodiments of the disclosure. The NN 700 is an example of a wireless communication node that can be configured to implement the various methods described herein. In some embodiments, the NN 700 can be a wireless communication node, such as a radio access network node (RAN node), as described herein. In other embodiments, the NN 700 can be a wireless communication device, such as a base station (BS), as described herein. As Figure 7As shown, the NN 700 includes a housing 720 that houses a system clock 721, a processor 722, a memory 723, a transceiver 710 including a transmitter 726 and a receiver 727, and a network controller 724.

[0051] In this embodiment, the system clock 721 provides timing signals to the processor 722 to control the timing of all operations of the NN 700. The processor 722 controls the general operation of the NN 700 and can include one or more processing circuits or modules, such as a central processing unit (CPU), and / or any combination of a general-purpose microprocessor, a microcontroller, a digital signal processor (DSP), a field-programmable gate array (FPGA), a programmable logic device (PLD), a controller, a state machine, gated logic, discrete hardware components, a dedicated hardware finite state machine, or any other suitable circuit, device, and / or structure that can execute calculations or other manipulations of data.

[0052] The memory 723, which can include both read-only memory (ROM) and random access memory (RAM), can provide instructions and data to the processor 722. A portion of the memory 723 can also include non-volatile random access memory (NVRAM). The processor 722 typically performs arithmetic and logical operations based on program instructions stored in the memory 723. The instructions (also referred to as software) stored in the memory 723 can be executed by the processor 722 to perform the methods described herein. The processor 722 and the memory 723 together form a processing system that stores and executes software. As used herein, “software” means any type of instructions, whether referred to as software, firmware, middleware, microcode, or the like, that can configure a machine or device to perform one or more desired functions or processes. The instructions can include code (e.g., in source code format, binary code format, executable code format, or any other suitable format of code). The instructions, when executed by one or more processors, cause the processing system to perform a variety of functions described herein.

[0053] The transceiver 710, including the transmitter 726 and the receiver 727, allows the NN 700 to transmit data to and receive data from external network nodes (e.g., BSs, UEs, or AI servers). The antenna 728 is typically attached to the housing 720 and electrically coupled to the transceiver 710. In various embodiments, the NN 700 includes (not shown) multiple transmitters, multiple receivers, and multiple transceivers. In some embodiments, the antenna 728 includes a multiple antenna array that can form multiple beams each pointing in a different direction according to MIMO beamforming techniques.

[0054] As Figure 7As further shown, the user equipment (UE) 710 includes a processor 711, a memory 717, and an RF unit 713. In some embodiments, layers of the radio interface protocol can be implemented by the processor 711. The memory 717 can be connected to the processor 711 and configured to store a program for controlling the processor 711 and data. The RF unit 713 can be connected to the processor 711 and configured to transmit and / or receive uplink (UL) downlink (DL) signals. Furthermore, the UE 710 can have a single antenna or multiple antennas 715.

[0055] The network controller 724 can be implemented as part of the processor 722 programmed to perform the functions outlined herein or can be a separate module implemented in hardware, firmware, software, or combinations thereof. According to various embodiments, the network controller 724 is configured to transmit and receive data to and from external devices such as the AI server 111 Figure 1 ), etc. In some embodiments, the network controller 724 can be implemented as software (i.e., computer-executable instructions) stored in a non-transitory computer readable medium that, when executed by the processor 722, transforms the processor 722 into a specific purpose computer to perform the secure data transmission operations described herein.

[0056] The various components and modules within the housing 720 described above are coupled together by a bus system 725. The bus system 725 can include a data bus, and in addition, can include, for example, a power bus, a control signal bus, and / or a status signal bus. It will be appreciated that the modules of the NN 700 can be operatively coupled to each other using any suitable techniques and media. It will also be appreciated that additional modules (not shown) can be included in the NN 700 without departing from the scope of the present disclosure.

[0057] Figure 8 An example of an AI server 800 configured to perform the methods disclosed herein according to various embodiments of the present disclosure is shown. In some embodiments, the AI server 800 can include a communication unit 801, a memory 807, a learning processor 805, and a processor 803. The communication unit 801 can transmit and receive data to and from external devices such as the BS 107 Figure 1 ), etc. In addition, in various embodiments, the memory 807 can include a model storage unit 809 configured to store model parameters of one or more machine learning models 811. More specifically, the model storage unit 809 can store one or more models 811 that are being trained or have been trained by the learning processor 805.

[0058] In some embodiments, the learning processor 805 can use training data received from the BS 107 to train an artificial neural network model or a reinforcement learning model. In other embodiments, the learning processor 805 can be used to train other machine learning models, such as supervised and unsupervised learning models and deep learning models. The one or more learning models 811 can be implemented as hardware, software, or a combination of hardware and software. Further, the processor 803 can be configured to compute a result value for new input data using the one or more learning models 811 and can generate a response or control command based on the determined result value. For example, the processor 803 can be used to compute network demand and dynamically allocate an amount of network resources, topology settings, and bit rates based on a supervised classifier model trained by the learning processor 805 using bandwidth, delay, and jitter measurement data received from the BS 107. Figure 1 ) can be configured to perform distributed learning processing.

[0059] While various embodiments of the present disclosure have been described above, it should be understood that they have been presented by way of example only, and not in limitation. As such, the various diagrams can depict example architectures or configurations, which can be employed, as appropriate, to embody one or more of the exemplary features described herein. Those skilled in the art will recognize that the example architectures or configurations depicted are illustrative only and can be modified on the basis of varying implementations. Additionally, unless otherwise stated, the functions or features described can be implemented in either hardware or software, or a combination of both. Likewise, plural instances can be presented in a single implementation, and vice versa. Furthermore, functions can be added or removed from various embodiments, and the scope of the present disclosure should not be limited to the features described herein, but can be modified on the basis of varying implementations.

[0060] It also should be appreciated that any reference to elements in the singular is not intended to mean "one and only one" unless specifically so stated, but rather "one or more." In other words, unless specified otherwise, the various embodiments can include one or more elements, and any references to singular elements should be understood to include the possibility of including one or more elements.

[0061] Furthermore, those skilled in the art will appreciate that the information and signals can be represented using any of a variety of different methods and techniques. For example, data, instructions, commands, information, signals, bits, and symbols, which can be referenced throughout the above description, can be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0062] Those of ordinary skill in the art will further appreciate that any of the various illustrative logical blocks, modules, processors, devices, circuits, methods and functions described in connection with the aspects disclosed herein can be implemented by electronic hardware (e.g., a digital implementation, an analog implementation, or a combination of the two), firmware, various forms of program or design code incorporating instructions (which can be referred to herein, for convenience, as "software" or a "software module"), or any combination of these techniques.

[0063] To clearly illustrate this interchangeability of hardware, firmware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware, firmware or software, or any combination thereof, depends upon the particular application and design constraints imposed on the overall system. Skilled artisans can implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure. In accordance with various embodiments, a processor, device, component, circuit, structure, machine, module, or the like can be configured to perform one or more of the functions described herein. As used herein, the terms "configured to," "configured for" or "adapted to" with reference to a specified operation or function means that the processor, device, component, circuit, structure, machine, module, signal, etc. is physically constructed, programmed, arranged and / or formatted to perform the specified operation or function.

[0064] In addition, those of ordinary skill in the art will appreciate that the various illustrative logical blocks, modules, devices, components and circuits described herein can be implemented within or performed by an integrated circuit (IC), which can include a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, or a combination of these. The logical blocks, modules, and circuits can further include antennas and / or transceivers to communicate with various components within a network or within a device. A processor programmed to perform the functions described herein will become a special purpose processor and can be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, a plurality of microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration for performing the functions described herein.

[0065] If implemented in software, the functions can be stored on or transmitted over as one or more instructions or code on a computer-readable medium. Therefore, the steps of a method or algorithm disclosed herein can be implemented as software stored on a computer-readable medium. Computer-readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program or code from one place to another. Storage media can be any available media that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer. Disk and disc, as used herein, includes compact discs and laser discs.

[0066] In this document, the term "module" as used herein, refers to software, firmware, hardware, and any combination of these elements that is used to implement the relevant functionality described herein. Furthermore, various modules can be described as discrete modules; however, as will be understood by those of ordinary skill, two or more modules can be combined to form a single module that performs the associated functions of the combined modules.

[0067] Various modifications to the implementations described in this disclosure will be readily apparent to those skilled in the art, and the generic principles defined herein can be applied to other implementations without departing from the scope of this disclosure. Thus, the disclosure is not intended to be limited to the implementations shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein and made apparent to others skilled in the art by the teachings herein.

Claims

1. An apparatus for securely transmitting user plane data to an artificial intelligence (AI) server via a mobile telecommunications network, comprising: The transmitter is configured to transmit interface requests to the AI ​​server and transmit the user plane data from the device to the AI ​​server for training an artificial intelligence-based model. The receiver is configured to receive an interface response from the AI ​​server; as well as The processor is configured to, in response to determining that an interface response has been received from the AI ​​server, establish a data transmission tunnel between the base station and the AI ​​server based on the Internet Protocol Security (IPSec) network protocol by exchanging encryption keys using the Internet Key Exchange (IKE) protocol.

2. The apparatus of claim 1, wherein the processor is further configured to encrypt the user plane data using the encryption key and to encapsulate a payload having the user plane data into Internet Protocol (IP) packets.

3. The apparatus of claim 1, wherein the interface response includes a list of Internet Protocol (IP) addresses associated with the user plane.

4. The apparatus of claim 1, wherein the interface response includes General Packet Radio Service (GPRS) Tunneling Protocol (GTP) tunneling information.

5. The apparatus of claim 4, wherein the GTP tunnel information includes the Internet Protocol IP address of the GTP tunnel and a unique tunnel endpoint identifier (TEID).

6. The apparatus of claim 1, wherein the interface request includes a first list of IPSec addresses associated with the user plane, and wherein the IPSec addresses are used by the apparatus to transmit the user plane data.

7. The apparatus of claim 6, wherein the interface request further includes a preset parameter that determines the maximum number of IPSec addresses in the first list.

8. The apparatus of claim 6, wherein the interface request includes a second list of General Packet Radio Service GPRS Tunneling Protocol GTP addresses associated with the IPSec addresses in the first list.

9. The apparatus of claim 1, wherein the interface request includes a list of IPSec addresses to be modified or deleted.

10. The apparatus of claim 1, wherein the transmitter is further configured to transmit the control plane to the AI ​​server via a control plane data transmission tunnel.

11. A method for securely transmitting user plane data from a base station to an artificial intelligence (AI) server via a mobile telecommunications network, the method comprising: At the base station located in the radio access network (RAN): Send an interface request to the AI ​​server; Receive interface response from the AI ​​server; In response to determining that the interface response has been received from the AI ​​server, an encryption key is exchanged using the Internet Key Exchange (IKE) protocol, and a data transmission tunnel based on the Internet Protocol Security (IPSec) network protocol is established between the base station and the AI ​​server. as well as The user plane data is sent from the base station to the AI ​​server for training an artificial intelligence-based model.

12. The method of claim 11, further comprising: The user plane data is encrypted using the encryption key. as well as The payload containing the user plane data is encapsulated into Internet Protocol (IP) packets.

13. The method of claim 11, wherein the interface response includes a list of Internet Protocol (IP) addresses associated with the user plane.

14. The method of claim 11, wherein the interface response includes General Packet Radio Service (GPRS) Tunneling Protocol (GTP) tunneling information.

15. The method of claim 14, wherein the GTP tunnel information includes the Internet Protocol IP address of the GTP tunnel and a unique tunnel endpoint identifier (TEID).

16. The method of claim 11, wherein the interface request includes a first list of IPSec addresses associated with the user plane, and wherein the IPSec addresses are used by the base station to transmit the user plane data.

17. The method of claim 16, wherein the interface request further includes a preset parameter that determines the maximum number of IPSec addresses in the first list.

18. The method of claim 16, wherein the interface request includes a second list of General Packet Radio Service GPRS Tunneling Protocol (GTP) addresses associated with the IPSec addresses in the first list.

19. The method of claim 11, wherein the interface request includes a list of IPSec addresses to be modified or deleted.

20. The method of claim 11, further comprising: Control plane data is transmitted to the AI ​​server via a control plane data transmission tunnel.

21. A method for securely transmitting user plane data from an artificial intelligence (AI) server to a base station located in a radio access network (RAN) via a mobile telecommunications network, the method comprising: At the AI ​​server: Receive interface requests from the RAN; Send an interface response to the RAN; In response to determining to send the interface response to the RAN, an encryption key is exchanged using the Internet Key Exchange (IKE) protocol, and a data transmission tunnel based on the Internet Protocol Security (IPSec) network protocol is established between the base station and the AI ​​server. as well as The user plane data is received from the base station for training an artificial intelligence-based model.

22. The method of claim 21, further comprising: The encryption key is used to decrypt the user plane data received from the base station.

23. The method of claim 21, wherein the interface response includes a list of Internet Protocol (IP) addresses associated with the user plane.

24. The method of claim 21, wherein the interface response includes General Packet Radio Service (GPRS) Tunneling Protocol (GTP) tunneling information.

25. The method of claim 24, wherein the GTP tunnel information includes the Internet Protocol IP address of the GTP tunnel and a unique tunnel endpoint identifier (TEID).

26. The method of claim 21, wherein the interface request includes a first list of IPSec addresses associated with the user plane, and wherein the IPSec addresses are used by the base station to transmit the user plane data.

27. The method of claim 26, wherein the interface request further includes a preset parameter that determines the maximum number of IPSec addresses in the first list.

28. The method of claim 26, wherein the interface request includes a second list of General Packet Radio Service GPRS Tunneling Protocol GTP addresses associated with the IPSec addresses in the first list.

29. The method of claim 21, wherein the interface request includes a list of IPSec addresses to be modified or deleted.

30. The method of claim 21, further comprising: Control plane data is received from the base station through a control plane data transmission tunnel.

31. An apparatus for securely receiving user plane data transmitted from a base station via a mobile telecommunications network at an artificial intelligence (AI) server, comprising: The receiver is configured to receive interface requests from the base station and to receive user plane data from the base station for training an artificial intelligence-based model. The transmitter is configured to transmit an interface response to the base station; as well as The processor is configured to, in response to determining that an interface response has been received from the AI ​​server, establish a data transmission tunnel between the base station and the device based on the Internet Protocol Security (IPSec) network protocol by exchanging encryption keys using the Internet Key Exchange (IKE) protocol.

32. The apparatus of claim 31, wherein the processor is further configured to decrypt the user plane data using the encryption key.

33. The apparatus of claim 31, wherein the interface response includes a list of Internet Protocol (IP) addresses associated with the user plane.

34. The apparatus of claim 31, wherein the interface response includes General Packet Radio Service (GPRS) Tunneling Protocol (GTP) tunneling information.

35. The apparatus of claim 34, wherein the GTP tunnel information includes the Internet Protocol IP address of the GTP tunnel and a unique tunnel endpoint identifier (TEID).

36. The apparatus of claim 31, wherein the interface request includes a first list of IPSec addresses associated with the user plane, and wherein the IPSec addresses are used by the apparatus to transmit the user plane data.

37. The apparatus of claim 36, wherein the interface request further includes a preset parameter that determines the maximum number of IPSec addresses in the first list.

38. The apparatus of claim 36, wherein the interface request includes a second list of General Packet Radio Service GPRS Tunneling Protocol (GTP) addresses associated with the IPSec addresses in the first list.

39. The apparatus of claim 31, wherein the interface request includes a list of IPSec addresses to be modified or deleted.

40. The apparatus of claim 31, wherein the receiver is further configured to receive control plane data from the base station via a control plane data transmission tunnel.

Citation Information

Patent Citations

  • Method, server, base station and communication system for configuring security parameters

    CN106797560A

  • Networking method and apparatus of fog wireless access network based on artificial intelligence

    CN109688597A