Network user data delivery

By utilizing the collaborative work of the virtual network function layer and service orchestration layer during user data transmission, the problem of user privacy protection in user data delivery is solved, achieving security and privacy protection for data transmission without user identification.

CN115733852BActive Publication Date: 2026-07-24INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INTERNATIONAL BUSINESS MACHINE CORPORATION
Filing Date
2022-08-22
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively protect user privacy during data delivery, especially in the transmission of medical and health data, where there is a risk of leakage of user identification data.

Method used

Logical channels are allocated to user equipment through the Virtual Network Function (VNF) layer, and user health data is inspected and processed by the service orchestration layer. Access to user identification data is restricted, and communication is conducted only through proxy identifiers.

Benefits of technology

It enables the protection of user privacy during user data transmission, ensuring that medical and health data does not contain any user identification data, thereby improving the security and privacy protection of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115733852B_ABST
    Figure CN115733852B_ABST
Patent Text Reader

Abstract

Methods, computer program products, and systems are introduced. The methods, computer program products, and systems can include, for example: obtaining, by a virtual network function (VNF) layer, user medical health data from a respective one of a plurality of UE devices, the VNF layer having assigned a logical channel to the respective one of the UE devices for wireless transmission of user data, wherein the VNF layer maintains user-to-logical channel association data that associates user identification data to the logical channel assigned to a user identified by the user identification data; checking, by a service orchestration layer running on top of the VNF layer, medical health data of the user health data, wherein the service orchestration layer is configured such that access by the service orchestration layer to the user identification data of the user-to-logical channel association data is restricted; and performing processing in accordance with the checking.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments described herein generally relate to computer networks, and more particularly to the delivery of network user data. Background Technology

[0002] Network services may include applications running at or above the network application layer, providing data storage, manipulation, representation, communication, or other functions, typically implemented using a client-server architecture based on application-layer network protocols. Each network service is typically provided by a server component running on one or more computers and accessed over the network by client components running on other devices. However, client and server components may run on the same machine. Furthermore, a dedicated server computer can provide multiple network services simultaneously.

[0003] Location-based services (LBS) are software services that use location data to control the functions of a computer system. LBS messaging services have many uses, such as in social networking, entertainment, security, and many other applications. LBS services use location services to locate mobile computer systems. Location services can combine various different location service technologies, such as the Global Positioning System (GPS), cellular network positioning technology, and Wi-Fi-based positioning technology, among others. An example of LBS is a location-based messaging service, where notifications and other messages sent to users can depend on the user's individual location.

[0004] Data structures have been used to improve the operation of computer systems. A data structure refers to the organization of data within a computer environment to improve the operation of computer systems. Types of data structures include containers, lists, stacks, queues, tables, and graphs. Data structures have been used to improve the operation of computer systems in areas such as algorithm efficiency, memory usage efficiency, maintainability, and reliability.

[0005] Artificial intelligence (AI) refers to the intelligence exhibited by machines. AI research includes search and mathematical optimization, neural networks, and probability. AI solutions involve features derived from research across a variety of scientific and technological disciplines, including computer science, mathematics, psychology, linguistics, statistics, and neuroscience. Machine learning is described as a field of research that endows computers with the ability to learn without explicit programming. Summary of the Invention

[0006] On the one hand, a method is provided to overcome the shortcomings of the prior art and provide additional advantages. This method may include, for example,: obtaining user health data from a corresponding UE device among a plurality of UE devices by a Virtual Network Function (VNF) layer, the VNF layer having assigned logical channels to the corresponding UE devices for wireless transmission of user data, wherein the VNF layer maintains user-to-logical channel association data that associates user identification data with logical channels assigned to the user identified by the user identification data; examining the user health data by a service orchestration layer operating above the VNF layer, wherein the service orchestration layer is configured such that its access to the user identification data of the user-to-logical channel association data is restricted; and performing processing based on the examination.

[0007] On the other hand, a computer program product can be provided. The computer program product may include a computer-readable storage medium readable by one or more processing circuits, the computer-readable storage medium storing instructions for performing a method executed by one or more processors. The method may, for example, include: obtaining user health data from a corresponding UE device among a plurality of UE devices by a Virtual Network Function (VNF) layer, the VNF layer having assigned logical channels to the corresponding UE devices for wireless transmission of user data, wherein the VNF layer maintains user-to-logical channel association data that associates user identification data with logical channels assigned to the user identified by the user identification data; examining the user health data by a service orchestration layer operating above the VNF layer, wherein the service orchestration layer is configured such that its access to the user identification data of the user-to-logical channel association data is restricted; and performing processing based on the examination.

[0008] On the other hand, a system can be provided. The system may include, for example, a memory. Furthermore, the system may include one or more processors communicating with the memory. Additionally, the system may include program instructions executable by one or more processors via the memory to perform a method. The method may include, for example,: obtaining user health data from a corresponding UE among a plurality of UE devices by a Virtual Network Function (VNF) layer, the VNF layer having assigned logical channels to the corresponding UE devices for wireless transmission of user data, wherein the VNF layer maintains user-to-logical channel association data that associates user identification data with logical channels assigned to the user identified by the user identification data; examining the user health data by a service orchestration layer operating above the VNF layer, wherein the service orchestration layer is configured such that access to the user identification data of the user-to-logical channel association data is restricted; and performing processing based on the examination.

[0009] Other features are implemented using the techniques described herein. This document describes in detail other embodiments and aspects, including but not limited to methods, computer program products, and systems, and considers them part of the claimed invention. Attached Figure Description

[0010] One or more aspects of the invention are specifically pointed out and explicitly claimed by way of example in the claims at the end of the specification. The foregoing and other objects, features, and advantages of the invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings, in which:

[0011] Figure 1 This illustrates a computing environment according to one embodiment;

[0012] Figure 2 This illustrates a computing environment according to one embodiment;

[0013] Figure 3 This illustrates a computing environment according to one embodiment;

[0014] Figure 4 This illustrates a computing environment according to one embodiment;

[0015] Figure 5 This is an execution flowchart of the interaction between the orchestrator and other components according to one embodiment;

[0016] Figure 6 A predictive model trained by machine learning is shown according to one embodiment;

[0017] Figure 7 A heatmap is shown according to one embodiment;

[0018] Figure 8 A heatmap is shown according to one embodiment;

[0019] Figure 9 A heatmap is shown according to one embodiment;

[0020] Figure 10 A computing node is shown according to one embodiment;

[0021] Figure 11 This illustrates a cloud computing environment according to one embodiment;

[0022] Figure 12 An abstract model layer is shown according to one embodiment. Detailed Implementation

[0023] Figure 1A computing environment 100 for secure collection and delivery of user data is illustrated. The computing environment 100 may include multiple UE devices 110A-110Z, multiple base stations 120A-120Z, and one or more orchestrators 130. In one embodiment, the UE devices 110A-110Z may be new radio devices and are compatible UE devices. The UE devices 110A-110Z can communicate wirelessly with the base stations 120A-120Z, and the base stations 120A-120Z can communicate wiredly with the orchestrator 130. In one embodiment, the orchestrator 130 may be defined by computing nodes in a core network, which may be part of an edge enterprise entity network.

[0024] The computing environment 100 can be configured to provide secure collection and delivery of user data. The computing environment 100 can be configured to collect and process secure user data, such as secure user healthcare data.

[0025] Referring to computing environment 100, each UE device 110A-110Z may include an orchestration process 110R running on VNF process 110V. Each base station 120A-120Z may include an orchestration process 120R running on VNF process 120V. Orchestrator 130 may include orchestration process 130R. In each instance of orchestration process 110R, orchestration process 110R may define an orchestration layer running on a VNF layer jointly defined by the instances of VNF process 120V and VNF process 110V. UE devices 110A-110Z, base stations 120A-120Z, and orchestrator 130 may include corresponding data repositories 210, 220, and 230.

[0026] According to one embodiment, each base station 120A-120Z can be an eNodeB base station compliant with the fifth-generation (5G) New Radio (NR) standard. According to one embodiment, each base station 120A-120Z and each UE device 110A-110Z can define a wireless network that facilitates communication according to the New Radio (NR) standard.

[0027] Figure 2 Is it like this? Figure 1 The partial Open Systems Interconnection (OSI) model shown represents computing environment 100. Computing environment 100 may include environments running at the physical layer (further reference). Figure 3 The Virtual Network Function (VNF) layer 1000 and the Service Orchestration Layer 2000 running on the Virtual Network Function (VNF) layer 1000 are described. According to one aspect, the VNF layer 1000 may be responsible for allocating logical channels through which the UE device can communicate with the base station.

[0028] According to one embodiment, this document describes a process by which a Virtual Network Function (VNF) layer obtains user data from a corresponding UE device among a plurality of UE devices—the VNF layer having allocated logical channels to the corresponding UE devices for wireless transmission of the user data; examines the data of the user data; and performs processing based on the examination.

[0029] According to the NR standard in 5G, logical channels are referred to as NR Dedicated Traffic Channels (DTCH). On one hand, the VNF layer 1000 can, for example, maintain user-to-logical channel association data in a table that associates UE device identifiers with the logical channels (e.g., DTCH channels) to which they are assigned. In one embodiment, user-to-logical channel association data can be provided as described in Table A.

[0030] Table A

[0031]

[0032]

[0033] VNF layer 1000 can distribute relevant portions of user-to-logical channel associated data to the corresponding base stations 120A-120Z and UE devices 110A-110Z to facilitate communication between UE devices 120A-110Z and base stations 120A-120Z. A one-to-one correspondence can exist between DTCH channels and UE devices, identified by a UE device identifier, which serves as the user's identifier. Through these characteristics, data collection process 110 can facilitate connections between UE devices associated with corresponding users and base stations, and can allocate DTCH channels to the corresponding UE devices and users.

[0034] In one aspect, the computing environment 100 can be configured to restrict the service orchestration layer 2000's access to user identification data associated with the user-to-logical channel data. This functionality allows the service orchestration layer 2000 to process user data specific to individual users without the risk of accessing any user identification data associated with a single user. When the service orchestration layer 2000 processes user-specific data, it can use the allocated corresponding logical (e.g., DTCH) channel as a proxy identifier for the general user, which does not contain any identifier that actually identifies any user or contains any user identification data. The 5G NR standard facilitates communications where the DTCH identifier can be used as a proxy identifier for a user without accessing any underlying actual user identification information.

[0035] refer to Figure 2The service orchestration layer 2000 of the computing environment 100 may include 5G device and subscription management platform process 2010, infection and suspicion finder process 2020 and medical logistics management process 2030.

[0036] The 5G Device and Subscription Management Platform Process 2010 can be responsible for maintaining the registered user list of the computing environment 100. The 5G Device and Subscription Management Platform Process 2010 can be configured to maintain the registered user list, which can be used to record whether various UE devices of various users have installed the installation package for the UE device to participate in the computing environment 100. However, the subscription list data generated and maintained by the 5G Device and Subscription Management Platform Process 2010 may not contain any collected user data, such as collected sensitive medical user data. Instead, the computing environment 100 can be configured such that sensitive user medical health data can be associated with allocated logical channels (e.g., 5G DTCH channels) without referencing any user identification data.

[0037] The Suspicion Finder Process 2020 is responsible for maintaining a list of logical channels, which includes user location data that changes over time, as well as sensitive medical and health data of users associated with logical channels, but does not include user identification data.

[0038] The Medical Logistics Management Service Process 2030 can be responsible for, for example, aggregating geospatial mapping data from multiple base stations and generating mapping data that aggregates mapping data from multiple base stations. Figure 3 An OSI diagram of computing environment 100 is shown, illustrating the physical layer characteristics and additional details of virtual network functional layer 1000, including the user-to-logical channel association data provided by the "eNodeB-DTCH orchestration table" within data collection process 1010. (See reference...) Figure 3 UE devices 110A-120Z are generally indicated by indicator UE device 110, and base stations 120A-120Z are generally indicated by indicator base station 120.

[0039] Regarding the physical network functional characteristics of the computing environment 100, the physical network layer functions of the computing environment 100 can be executed through the physical layer functions of the computing node 10, which can be configured by the respective UE device 110 and base station 120. The physical network layer functions of the computing node 10 may include, for example, spectrum management functions, radio estimator functions, data collection functions, and storage functions.

[0040] Further reference Figure 3The service orchestration layer 2000 can iteratively communicate data with the collection process 1010 to initiate data collection requests. In response to the receipt of a data collection request, the data collection process 110 can use the aforementioned user-to-logical channel associated data to request user data.

[0041] In response, Physical Network Function Layer 01 can send user health data with location data to the data collection process 110 of VNF Layer 1000 via its allocated DTCH logical channel. The data collection process 110 of VNF Layer 1000 can push the received health data with location data to Service Orchestration Layer 2000. When pushing the generated user health data to Service Orchestration Layer 2000, access to any user identification data can be restricted so that the user health data pushed to Service Orchestration Layer 2000 may include DTCH data that does not represent agent user identification data, does not include any UE device identification data, or other user identification data. In some embodiments, the data collection process 1010 of VNF Layer 1000 can be defined to provide geospatial map locations specifying various users. For such functionality, VNF Layer 1000 can interface with, for example, Google... (GOOGLE The system communicates with the geospatial mapping service (a registered trademark of Google). When the VNF layer 1000 provides geospatial mapping data, it can push this data, along with user health data and location data, to the service orchestration layer 2000. Users are generally represented by their respective associated logical channels, and the pushed data does not contain any user identification data. In another embodiment, the geospatial mapping function can be performed entirely by the service orchestration layer 2000.

[0042] VNF layer 1000 may include a data collection process 110. Data collection process 110 may reference the user-to-logical channel associated data to obtain user health data. User health data may include multiple data tags as summarized in Table B.

[0043] Table B

[0044]

[0045] In one embodiment, UE devices 110A-110Z can send user health datasets, as shown in Table A, to their respective base stations 120A-120Z. Data tags, as shown in Table B, may include, for example, UE device UUID, logical channel identifier, timestamp, location coordinates, and infection status. The embodiments described herein recognize that the location of UE devices can be determined with high accuracy using various 5G technologies. UE devices 110A-110Z and RAN 500N can comply with fifth-generation (5G) technologies, including the New Radio (NR) standard, 3GPP TS 28.530 V15.1.0 Release 15 document published by the 3GPP Third Generation Partnership Project (3GPP), and the 3GPP Release 16 technical report (3GPP Release 16 report). Densely deployed access nodes (ANs) can increase the line-of-sight (LoS) probability between user nodes (UNs) and ANs, thereby enabling high-accuracy time-of-arrival (ToA) estimation. Access nodes in 5G networks will be used in conjunction with smart antenna solutions, such as antenna arrays, which can also enable accurate direction-of-arrival (DoA) estimation. Generally, all the aforementioned measurements can be efficiently estimated from uplink (UL) pilot signals in a network-centric manner, thus not necessarily requiring additional positioning-specific signals. Due to their large antenna arrays and wide bandwidth, 5G networks provide a convenient environment for positioning, which in turn enables high-precision DoA and ToA estimation, including under Loss of Position (LoS) conditions. Next-generation positioning maps can be supported by 5G network AN positioning using 5G-enabled UE devices, enabling them to communicate with other devices and transmit their current location, including latitude and longitude coordinates and device altitude calculated using altitude. Therefore, efficient positioning and location identification services can be provided within the 5G orchestration plane. Precise positioning based on the Global Navigation Satellite System (GNSS) is increasingly important for commercial use cases across various sectors. GNSS positioning relies on information from signals and positions of multiple satellites, typically supplemented by mobile device information provided by cellular network operators. Real-Time Kinematic (RTK) technology has significantly improved GNSS positioning accuracy, reducing it from meters to just centimeters. The embodiments described herein may use GNSS-RTK auxiliary data signaling supported by new radio (NR) equipment provided by the technical reports of 3GPP Release 15 and 3GPP Release 16 (3GPP Release 16 report).

[0046] Upon receiving the dataset as shown in Table B, the corresponding base station can pass the dataset to the service orchestration layer 2000 through VNF procedure 120V of VNF layer 1000, removing the UE device UUID that identifies the user, so that service orchestration layer 2000 receives the dataset without the UE device UUID as shown in Table B. Service orchestration layer 2000 can store the data of Table B, minus the user identification data, in a data repository, such as data repository 230. Service orchestration layer 2000 can identify suspected infected individuals, for example, through its procedures running on base station and / or orchestrator 130, to provide an adapted dataset with the suspected infected status field as shown in Table C.

[0047] Table C

[0048]

[0049] For users whose current infection status is uninfected, the service orchestration layer 2000 can determine a suspected infection status. Determining a suspected infection status may include assigning an infection probability to users whose current infection status is uninfected. Embodiments described herein can operate in 5G service orchestration combined with virtual network functions and 5G user location systems to detect individuals suspected of having infectious diseases. As previously described, 5G has a highly efficient geolocation tracking system that works in conjunction with AN-based location systems. Embodiments described herein can use geolocation tracking systems and geofencing as backbone interfaces, and our invention operates on top of these precise location services provided by 5G virtual network functions. Embodiments operating in the service orchestration plane described herein can connect to medical services in the plane, which provide backtracking computation triggers for specific users or sets of users. Medical services may include integration with platforms capable of authentication to prevent abuse of user location tracking. User consent may allow medical information to be sent through a logical channel that does not contain any user identification data. Once medical service authentication is performed, medical records at predefined time intervals can be pushed to a service with a 5G_UUID number. In some embodiments, the VNF function can request user information from the 5GUUID. User information may include International Mobile Equipment Identity (IMEI) or International Mobile Subscriber Identity (IMSI). The collected IMSI can be transmitted to VNF layer 1000 via timeline input to track the user's location over the past few days. The service can then examine the location of the infected individual from the user's records.

[0050] In one embodiment, the service orchestration layer 2000, used to assign infection probabilities to users with a currently uninfected status, can determine, for example, the number of historical crossings within a threshold time period of the current time. For instance, if the first and second users are within a threshold distance from each other (e.g., 6 feet or 2 meters), a crossing can be determined. Based on the historical crossing data, the service orchestration layer 2000 can assign infection probabilities.

[0051] To allocate infection probabilities based on historical crossover counts, Service Orchestration Layer 2000 can query, for example... Figure 6 The illustration shows a specific predictive model 6002 trained using machine learning. Predictive model 6002 can be trained using a training dataset containing (a) the number of crossovers between a specific uninfected user and an infected user, and (b) the subsequent infection status of an uninfected user. Once trained, predictive model 6002 can respond to query data. Query data may include the number of crossovers detected in the past. Output data in response to the query data may include a value specifying the probability of infection.

[0052] In one embodiment, the service orchestration layer 2000, used to assign infection probabilities to users, can predict subsequent crossovers between uninfected users and then assign infection probabilities based on the predicted crossovers by querying a specific prediction model 6002 trained with a training dataset that includes (a) the number of crossovers between a particular uninfected user and an infected user and (b) the subsequent infection status of an uninfected user. To predict subsequent crossovers, the service orchestration layer 2000 may include historical travel data of the detected users for whom it collects user data.

[0053] The Service Orchestration Layer 2000 can determine the current direction of a corresponding user using recent historical location data. This current direction can be viewed as a trajectory. The Service Orchestration Layer 2000 can then use this determined current direction to predict the user's subsequent path (position changing over time). To predict the subsequent path, the Service Orchestration Layer 2000 can apply the assumption that the user will continue traveling along their current direction for the next N time intervals. The Service Orchestration Layer 2000 can determine predictions of future intersections by examining the corresponding predicted paths of the corresponding users based on the detected current paths and identifying intersections between users traveling along their respective paths.

[0054] Once the predicted subsequent crossovers are determined, the service orchestration layer 2000 can query the prediction model 6002 to determine the infection probability based on the predicted crossover count for the corresponding user. The service orchestration layer 2000 can use the predicted crossover count determined using the historical path data of the corresponding user as described in this document to query the prediction model 6002.

[0055] The network diagram of computing environment 100 is as follows: Figure 4 As shown. Figure 4 The computing environment 100 is described in further detail. The computing environment 100 may include UE devices 110A-110Z that communicate with a data network 2000N via multiple edge enterprise entity networks 100N (one of which is shown). Each edge enterprise entity network may include edge infrastructure owned, operated, and / or controlled by a different edge entity. An edge enterprise entity may own, operate, and / or control an edge network infrastructure comprising a wireless network 1100N, a fronthaul / backhaul network 1200N, and a core network 1300N. The different edge enterprises may be telecommunications network providers, sometimes also referred to as communication service providers (edge ​​enterprise entities CSPs). According to one embodiment, the wireless network 1100N may include base stations 120A-120Z, which may be provided by eNodeB base stations.

[0056] In the Figure 4 In one embodiment, the combination of wireless network 1100N and fronthaul network 1200N defines an edge network 500N provided by radio access network (RAN) 500N. The edge network 500N defines edge infrastructure. The RAN 500N shown provides access from UE devices 110A-110Z to various core networks 1300N. In an alternative embodiment, one or more of the edge networks 500N may be provided by a content delivery network (CDN). UE devices 110A-110Z and RAN 500N may comply with the New Radio (NR) standard, the 3GPP TS 28.530 V15.1.0 Release 15 document published by the 3GPP Project (3GPP), and the 3GPP Release 16 technical report (3GPP Release 16 report).

[0057] Each of the different UE devices 110A-110Z can be associated with a different user. In one embodiment, the UE devices in UE devices 110A-110Z can be computing node devices provided by client computers (e.g., mobile devices, such as smartphones or tablets, laptops, smartwatches, or PCs), which run one or more programs that facilitate access to services provided by one or more service providers. Alternatively, the UE devices in UE devices 110A-110Z can be provided by, for example, Internet of Things (IoT) sensing devices.

[0058] The embodiments described herein recognize that hosting service functions on one or more compute nodes within an edge enterprise entity network 1000N can provide various advantages, including latency advantages in speed of service delivery to end users at UE devices 110A-110Z. The service functions hosted by the edge enterprise entity can be hosted, for example, within an edge network 500N or an edge enterprise entity network 1000N.

[0059] Data Network 2000N may include, for example, an IP Multimedia Subsystem (IMS) and / or the “Internet” as a network of networks. The Internet may consist of private, public, academic, commercial, and government networks ranging from local to global, interconnected by a wide range of electronic, wireless, and optical networking technologies. Data Network 2000N may include, for example, multiple non-edge data centers. Such data centers may include private enterprise data centers as well as multi-tenant data centers provided by IT companies that offer hosting services developed by multiple different business entities.

[0060] Some edge entities that own, operate, and / or control edge infrastructure (such as that provided by Edge Network 500N) can provide multi-tenant hosting services that allow enterprises outside of the edge enterprise to host their applications on one or more edge nodes within the Edge Enterprise Entity Network 1000N.

[0061] According to one embodiment, orchestrator 130 can be deployed on compute nodes of core network 1300N. According to another embodiment, orchestrator 130 can be deployed on one or more compute nodes of data network 2000N. According to one embodiment, orchestrator 130 can be distributed between compute nodes of core network 1300N and data network 2000N. According to one embodiment, orchestrator 130 can be located on compute nodes of core network 1300N and data network 2000N. In one embodiment, the management and orchestration (MANO) computing environment may conform to the 3GPP TS 28.530V15.1.0 Release 15 document and the 3GPP Release 16 technical report (3GPP Release 16 report) published by the 3GPP Third Generation Partnership Project (3GPP).

[0062] Various available tools, libraries, and / or services can be used to implement predictive model 6002. For example, machine learning services can provide access to libraries and executable code to support machine learning functionalities. Machine learning services can provide access to a set of REST APIs that can be called from any programming language and allow predictive analytics to be integrated into any application. Enabled REST APIs can provide, for example, retrieving metadata for a given predictive model, deploying and managing deployed models, online deployment, scoring, batch deployment, stream deployment, monitoring, and retraining deployed models. According to one possible implementation, The provided machine learning services are accessible. and The library ( and It is a registered trademark of IBM. and It is a registered trademark of the APACHE Software Foundation. The provided machine learning services offer access to a collection of REST APIs that can be invoked from any programming language and allow predictive analytics to be integrated into any application. The enabled REST APIs provide, for example, the ability to retrieve metadata for a given predictive model, deploy and manage deployed models, online deployment, scoring, batch deployment, streaming deployment, monitoring, and retraining deployed models. The configuration of predictive model 6002 can include the use of, for example, support vector machines (SVMs), Bayesian networks, neural networks, and / or other machine learning techniques.

[0063] refer to Figure 5 The flowchart illustrates the execution method for the orchestrator 130 to interact with base stations 120A-120Z and UE devices 110A-110Z. In block 1301, the orchestrator 130 may send an installation package to a base station owned, operated, and / or controlled by an edge enterprise entity that owns, operates, and / or controls the orchestrator 130. In block 1201, upon receiving the installation package, the base station 120A-120Z may install the received installation package.

[0064] The installation package sent in block 1301 may include, for example, libraries and executable code for providing functionality for VNF procedure 120V and orchestration procedure 120R running on each of the base stations 120A-120Z, which define VNF layer 1000 and service orchestration layer 2000, respectively. In block 1101, UE devices 110A-110Z may send registration data to orchestrator 130. The registration data may be entered into a web-based user interface displayed on the UE device's screen. The registration data may be sent to orchestrator 130 via a network including base stations 120A-120Z or another network.

[0065] Upon receiving registration data, the orchestrator 130 can establish a user subscription for storage, such as... Figure 1 In the data repository 230 shown, and upon receiving registration data, the orchestrator 130 can send an installation package to the UE devices 110A-110Z. In response to receiving the installation package sent at block 1302, the UE devices 110A-110Z can install the installation package at block 1102. The installation package installed at block 1102 may include, for example, features defining... Figure 1 The library and executable code shown represent the VNF procedure 110V and orchestration procedure 110R running on their respective UE devices 110b-110Z. These procedures are defined as shown in the reference. Figure 2 and 3 The VNF layer 1000 and service orchestration layer 2000 are described above. The installation packages installed at blocks 1201 and 1102 can also be defined as shown in the reference. Figure 3 The functions of the physical network functional layer 01.

[0066] In response to sending the installation packet at block 1302, orchestrator 130 can proceed to block 1303. At block 1303, orchestrator 140 can update base stations 120A-120Z by sending updated data for the new UE device identifier mapped to the registered user of computing environment 100. Therefore, when base stations 120A-120Z receive an join request from a recently registered new UE device, base stations 120A-120Z will be able to recognize such a new UE device. At block 1103, UE devices in UE devices 110A-110Z can send join requests for reception by base stations 120A-120Z. As previously described, base stations 120A-120Z can recognize previously registered UE devices and therefore can respond appropriately according to the characteristics of computing environment 100.

[0067] In response to receiving a join request, the base station in base stations 120A-120Z that receives the strongest signal strength from UE devices in UE devices 110A-110Z can respond at block 1202 by transmitting channel data indicating an allocated DTCH channel for further communication between a specific UE device (e.g., UE device 110A) and a specific base station (e.g., base station 120A). In blocks 1104 and 1203, join communication can be performed, enabling the specific UE device (e.g., UE device 110A) to connect to the specific base station 120A.

[0068] As indicated by the return arrow, UE devices 110A-110Z can iteratively execute the loops in blocks 1103 and 1104 to iteratively send join requests to new base stations and iteratively receive join communications to communicate on a new logical DTCH channel when it is allocated. Since UE devices can change the logical channel they communicate with different base stations, base stations 120A-120Z in VNF layer 1000 can maintain the user-to-logical channel association data or related portions thereof, allowing base stations 120A-120Z to maintain communication with the corresponding UE devices joining them. However, the user identification data of the user-to-logical channel association data is not shared with service orchestration layer 2000; therefore, applications running in service orchestration layer 2000 cannot recover UE device and UE information from data transmissions in service orchestration layer 2000.

[0069] Further reference Figure 5 In the flowchart, at block 1305, orchestrator 130 may send data collection request data to initiate data collection. The data collection request data sent at block 1305 may be sent to base stations 120A-120Z owned, operated, and / or controlled by the edge enterprise entity operating orchestrator 130. At transmission block 1205, in response, base stations 120b-120Z that receive the data collection request data sent at block 1305 may send data collection request data to UE devices 110A-110Z currently joined and connected to base stations 120A-120Z.

[0070] In block 1105, in response to receiving data collection request data transmitted at block 1205, the respective UE devices 110A-110Z can transmit user health data to the corresponding base station in their currently joined and connected base station 120A-120Z via VNF procedure 110V. The user health data transmitted at block 1105 may include sensitive user health data transmitted on the allocated, specifically isolated logical channels associated with the respective UE devices in UE devices 110A-110Z.

[0071] In block 1206, in response to receiving user healthcare data transmitted at block 1105, base stations 120Z-120Z can generate geospatial mapping data specifying the geospatial map location of each user via VNF procedure 120V. The geospatial map can specify infrastructure elements such as roads and buildings. For this functionality, VNF layer 1000 can interface with, for example, Google... (GOOGLE It communicates with a geospatial mapping service (a registered trademark of Google).

[0072] In response to the generation of geospatial mapping data, in block 1207, base stations 120A-120Z can send geospatial mapping data to orchestration process 130R of orchestrator 130 via VNF process 120V. When sending geospatial mapping information at block 1207, base stations 120A-120Z can associate user health data with allocated logical channels, but the user health data may not contain any specific user identification data. To send geospatial mapping data at block 1207, VNF layer 1000 can push the received health data along with location data all the way to service orchestration layer 2000. When pushing the generated user health data all the way to service orchestration layer 2000, data collection process 110 can be restricted from accessing any user identification data, so that the user health data pushed to service orchestration layer 2000 may include DTCH data that does not represent proxy user identification data and does not contain any UE device identification data or other user identification data. When the VNFS layer 1000 provides geospatial mapping data, it can push this data along with user health data and location data to the service orchestration layer 2000. Users are typically represented by their respective associated logical channels, and the pushed data does not contain any user identification data. In another embodiment, the geospatial mapping function can be performed entirely by the service orchestration layer 2000.

[0073] Utilizing the features described herein, each user can be represented by an assigned logical data channel, but without actual user identification data, such as device UUID information associated with the assigned logical channel. In aggregation block 1306, in response to receiving transmitted geospatial mapping data at block 1207, orchestrator 130 can aggregate mapping data associated with multiple different base stations via service orchestration layer 200. In aggregation block 1306, orchestrator 130 can also identify suspected infected users via service orchestration layer 2000. When identifying suspected infected users, orchestrator 130 can assign infection probabilities to users currently in an uninfected state by defining orchestrator procedure 130R of service orchestration layer 2000.

[0074] In one embodiment, the service orchestration layer 2000, used to assign infection probabilities to users with a currently uninfected status, can determine, for example, the number of historical crossovers within a threshold time period of the current time. For instance, a crossover can be determined when the first and second users are within a threshold distance (e.g., 6 feet or 2 meters) of each other. Based on this historical crossover data, the service orchestration layer 2000 can assign infection probabilities.

[0075] To allocate infection probabilities based on historical crossover counts, Service Orchestration Layer 2000 can query, for example... Figure 6 The illustration shows a specific predictive model 6002 trained using machine learning. Predictive model 6002 may have been trained with a training dataset containing (a) the number of crossovers between a specific uninfected user and an infected user, and (b) the subsequent infection status of that uninfected user. Once trained, predictive model 6002 is able to respond to query data. The query data includes the number of crossovers detected in the past. Output data in response to the query data may include a value specifying the probability of infection.

[0076] In one embodiment, a service orchestration layer 2000 for assigning infection probabilities to users can predict subsequent crossovers between uninfected users and then assign infection probabilities based on the predicted crossovers by querying a specific prediction model trained with a training dataset containing (a) the number of crossovers between a particular uninfected user and an infected user and (b) the subsequent infection status of uninfected users. To predict subsequent crossovers, the service orchestration layer 2000 may include historical travel data of the detected users for whom it collects user data.

[0077] The Service Orchestration Layer 2000 can determine the current direction of a corresponding user using recent historical location data. This current direction can be viewed as a trajectory. The Service Orchestration Layer 2000 can then use this determined current direction to predict the user's subsequent path (position changing over time). To predict the subsequent path, the Service Orchestration Layer 2000 can apply the assumption that the user will continue traveling along their current direction for the next N time intervals. The Service Orchestration Layer 2000 can determine predictions of future intersections by examining the corresponding predicted paths of the corresponding users based on the detected current paths and identifying intersections between users as they travel along their respective paths.

[0078] Once the predicted subsequent crossovers are determined, the service orchestration layer 2000 can query the prediction model 6002 to determine the infection probability based on the predicted crossover count for the corresponding user. The service orchestration layer 2000 can use the predicted crossover count determined using the historical path data of the corresponding user as described in this document to query the prediction model 6002.

[0079] Using the predicted infection level data (the probability of infection data allocation), the orchestrator 130 of the business orchestration layer 2000 can generate, for example, Figures 7 to 9 The heatmap shown is illustrated below. In the heatmap, the darkest areas indicate the highest infection intensity, while the brightest areas indicate areas with lower infection intensity. The determined infection intensity can be a function of the recorded user infection status and the assigned infection probability. An area may have a small number of infected users, but in the heatmap, it can be recorded as a high-infection-intensity area based on identified suspected infected individuals with a substantial assigned infection probability.

[0080] At configuration box 1307, orchestrator 130 can allocate resources for suppressing and resolving infections in areas via service orchestration layer 2000, for example, allocating vaccine doses or other infection treatment resources based on the infection intensity level determined by service orchestration layer 2000 and indicated by heatmap mapping data. According to one embodiment, service orchestration layer 2000 can allocate resources proportionally to the detected infection intensity level, with areas having higher determined infection intensity levels receiving proportionally more medical resources. Figure 9 In the diagram, the circled area is the region with the highest infection intensity, as determined by the service orchestration layer 2000. Therefore, the service orchestration layer 2000 can allocate the maximum number of medical resources. In output box 1308, orchestrator 130 can initiate the automated delivery of medical resources by autonomous vehicles. In response to the completion of box 1308, orchestrator 130 can proceed to box 1309. In box 1309, orchestrator 1300 can return to box 1305, and the loop from box 1305 to 1309 can be executed iteratively during the deployment of orchestrator 130. Orchestrator 130 can also iteratively execute the loops of boxes 1302 and 1303 during the deployment of orchestrator 130.

[0081] Providing medical resources to a medical institution through appropriate configuration of output box 1308 may include, for example, automatically placing a delivery order to a vehicle delivery service owned by the enterprise or externally through output box 1308, or automatically activating a robotic medical resource reserve, such as an autonomous vehicle, through output box 1308, and activating a route for an autonomous vehicle to a destination (e.g., a medical institution) through output box 1308.

[0082] According to one embodiment, this document describes the acquisition of user health data by a Virtual Network Function (VNF) layer from a corresponding UE device among multiple UE devices, wherein the VNF layer has assigned logical channels to the corresponding UE devices for wireless transmission of user data, wherein the VNF layer maintains user-to-logical channel association data that associates user identification data with the logical channel assigned to the user identified by the user identification data; the user health data is examined by a service orchestration layer running above the VNF layer, wherein the service orchestration layer is configured such that access to the user identification data of the user-to-logical channel association data is restricted; and processing is performed based on the examination. Processing based on the examination may include, for example, the processing performed at blocks 1306, 1307, and / or 1308.

[0083] Medical resources in this document may include: medicines, such as vaccines; medical equipment, such as syringes, bandages, tables, user health monitoring devices, etc.; and personnel, such as doctors, nurses, and technicians. Service orchestration layer 2000 can allocate resources based on the severity level of a disease (e.g., infection) in a region. The severity level of a disease, as described herein, can be a function of the number of users with an infected status and the probability of infection allocated to other users. Autonomous robot picking and packaging technologies (e.g., available from Kion Group AG) can be used. Automated autonomous vehicle stocking is performed using robotics technology within the product line. This is achieved using TRIMBLEAUTOMOTIVE POSITIONING technology provided by TRIMBLE Inc. and provided by NVIDIA Autonomous vehicle software, hardware, and infrastructure kits can provide route planning for autonomous vehicles.

[0084] According to one embodiment, the service orchestration layer 2000 may be equipped with the medical resources described in Tables D and E.

[0085] Table D

[0086]

[0087] Table E

[0088]

[0089] Referring to Tables D and E, it can be seen that, depending on a scenario, Service Orchestration Layer 2000 can be configured with a second geographical region to include increased resources compared to the first region, even if fewer infected users are identified. The rationale is that Service Orchestration Layer 2000 may determine that there are more suspected infected users in this second region, which is determined by assigning infection probability values ​​to uninfected users. Upon determining the presence of suspected infected users, Service Orchestration Layer 2000 can assign infection probabilities to users currently in an uninfected state.

[0090] This document provides a method, system, and apparatus for operating in the 5G service orchestration layer, communicating with existing services for infected users and suspected infected individuals via a DTCH logical channel established through user-consented eNodeB login using 5G physical network functions. The embodiments of this document can provide an eNodeB radio access map for selected infected and suspected UE devices, locate the device's operating area, and proactively trigger medical logistics calculations for infectious diseases.

[0091] The embodiments described herein can calculate disease-related drug demand based on exposure probabilities derived using a multi-level hierarchical DTCH_LIST, and can predict medical logistics demand based on the number of exposed individuals and disease exposure levels within a region. Medical logistics data is pushed to respective subscribers to optimize logistics based on suspected cases in the region and maintain proactive inventory in real-time at required locations. This facilitates access to medication locally when exposed individuals test positive and further aids in isolating these areas, as people do not need to cross these areas to obtain medical resources such as vaccines and other medications.

[0092] The embodiments in this paper recognize that artificial intelligence simplifies the lives of patients, doctors, and hospital administrators by performing tasks typically done by humans, but in less time and at a lower cost. As AI advances in the medical field, deep learning models are designed to gather information from patients, analyze user histories, and predict the causes of diseases and drug treatments. There are chatbots available to collect AI-based symptom data, and treatment checkers that use algorithms to diagnose and treat diseases. These virtual agents collect user information and, accordingly, suggest therapies to overcome illnesses.

[0093] New deep learning-based medical tools are simplifying various diagnoses based on deployment domains. Several deep learning platforms analyze unstructured medical data (radiological images, blood tests, electrocardiograms, patient histories) to help doctors better understand patients' real-time needs. With the empowerment of next-generation artificial intelligence technologies, the cognitive medicine field is expanding into AI-based medical logistics and healthcare supply chains.

[0094] The embodiments described in this paper recognize that 5G technology can act as a rich enabler, pushing dependent technologies to a higher level through the convergence of 1 Gbps mobile bandwidth and IoT device access. One of the key characteristics of 5G is that the network itself is intelligent and cognitive.

[0095] The embodiments described herein recognize that 5G New Radio (NR) can improve performance by providing large bandwidth for precise timing, new millimeter wave bands, massive MIMO for accurate angle-of-arrival estimation, and new architectural options that particularly support positioning. Enhanced 5G device positioning can provide precise user location, offering advantages for location-specific application development and location-driven analytics. One emerging component of location-driven analytics could be healthcare logistics as described in the embodiments herein.

[0096] The embodiments described herein recognize that infectious diseases are caused by microorganisms such as bacteria, viruses, parasites, and fungi that can be transmitted directly or indirectly from one person to another. Some microorganisms are transmitted through insect bites, while others are transmitted through contact with an infected person. These viruses typically spread from person to person based on their transmissible nature. Infectious diseases like COVID-19 are transmitted through contact, so the best approach is to isolate suspected cases and maintain social distancing. In some infectious diseases, such as COVID-19, the spread of infection exceeds expectations, leading to crises such as the COVID-19 pandemic. In such outbreaks, enhanced healthcare support plays a crucial role in protecting and treating patients and controlling the transmission to others.

[0097] The embodiments described herein recognize that existing methods are not yet able to use information about the number of infected and suspected cases to plan healthcare logistics and accordingly allocate medical resources and equipment to the relevant areas. In a pandemic situation, there are mechanisms that can maintain records of infected individuals by region, but this is primary evidence and can only be implemented during a pandemic.

[0098] The embodiments described herein recognize that it is currently impossible to allocate medical resources, such as medicines, equipment, and other resources, based on dynamically identified suspected individuals in a region. The embodiments described herein also recognize that existing methods cannot collect information from users indicating the status of an infectious disease (such as infection or suspected infection) and allocate logistics accordingly. A user's medical records can be used based on the user's consent agreement, but this data cannot currently be used to infer the allocation of medical resources, such as medicines and other medical equipment. For example, if five people are infected in one part of a city, and more than 1,000 other people have been in contact with these infected individuals in the past few days due to the contagious nature of the disease, they are suspected cases of contact infection. However, there are also five positive cases and 200 suspected cases in other parts of the region. A 5G healthcare service invention discloses generating information about suspected individuals upon user consent. The embodiments described herein recognize that the uneven distribution of infected users and suspected cases means that current medical logistics services cannot obtain this information and proactively allocate medical resources to the corresponding affected areas.

[0099] The embodiments described herein recognize that in the event of large-scale infections and emergencies, there is a shortage of medicines and medical capacity (including equipment), thus creating a greater need for intelligent supply mechanisms based on the prediction of demand per unit within a region.

[0100] Embodiments herein provide a method, system, and apparatus that communicate with other services in a multi-domain programmable framework within the service orchestration layer of a 5G telecommunications network to collect information from various sources to obtain a DTCH list of infected and suspected individuals, and accordingly trigger a medical facility logistics management system to allocate medical resources to the corresponding areas.

[0101] An embodiment of this invention, operating at the service orchestration layer of a 5G network, initiates and collects information from a medical service in the 5G multi-domain layer, and communicates with that service to obtain a DTCH_ list of infected and suspected individuals. The infection and trajectory management medical service has information about the UUIDs of infected user devices and other devices that have had contact with the infected individuals.

[0102] Service instances in a 5G network use a multi-level hierarchical lookup table in the network plane to initiate handshakes with these services and perform inter-service authentication to obtain the necessary information. Once the service is authenticated and the user's consent is verified, the service receives the DTCH_ID of the infected person and their contacts. This DTCH_list can be provided by a list of 5G logical channels created between the UE device and the eNodeB. The DTCH_list can be provided as a Virtual Network Function (VNF) of the 5G network. These logical channels can be created by the UE device and / or base station to send and receive information over radio bearers (NR), and the VNF can track these DTCHs assigned to various devices.

[0103] Once the DTCH_ list is received, a map-based classifier is invoked to obtain the geographic latitude, longitude, and altitude information of each DTCH. A 5G virtual network function is invoked, which has built-in capabilities to locate the DTCHs based on GPS and other 5G-based precise positioning algorithms. The DTCH locations can be tracked to obtain their operational areas. These operational areas for all DTCHs in the DTCH_ list can be collected and saved to a 5G metadata mapper object, which can then be used to calculate healthcare resource needs. Once the locations and operational areas have been collected using the map-based classifier, the information aggregator can determine the number of people requiring healthcare resources (such as medical assistance, medications, and other medical resources) to address disease transmission issues.

[0104] A list of infection and suspected severity levels can be calculated based on the suspected DTCH_IDs in the received DTCH_ list. Based on the severity of the disease and the probability of transmission (expressed as a set of suspected DTCH individuals), the availability of medical resources, such as medical equipment and other facilities, will be determined by tracking a disease-related medical database. For example, if a COVID-19 infected person requires 14 tablets... (antiviral drugs-) If the number of suspected cases in a region is 1000, then 1000 tablets (14 tablets per 1000 tablets) could be provided to that region. This information can be generated by categorizing a disease medical database, which includes disease maps and medical resources allocated to address the disease.

[0105] Once this information is known, a notification can be generated for healthcare service providers within the region, along with the corresponding medical resource requirements to address the illness. This notification will be consumed by subscribed healthcare services within the 5G plane, which can be further extended to notifying service providers to meet medical needs. The notification can be extended to subscribed service providers.

[0106] Because the service orchestration layer 2000 proactively allocates appropriate medical resources to healthcare facilities within a region, infected users can obtain the necessary medications and / or other medical resources without leaving the region. This, in turn, helps establish isolation, as infected users do not need to travel across regions. Medications and other resources are proactively provided before people are actually infected. Resource allocation is based on infected users and suspected users with an assigned probability of infection; therefore, they can easily obtain medications or other medical resources when needed.

[0107] The embodiments described herein utilize 5G technology that includes providing logical channels in a wireless network. Virtual Network Functions (VNFs) can abstract usernames and / or device IDs in user-to-logical channel association data (e.g., tables) using logical channel IDs created with the user. By restricting service orchestration layer 2000's access to user information in the user-to-logical channel association data, services in the orchestration plane cannot trace back to obtain the user's personal information, such as IMSI and TMSI numbers, because these are abstracted in the VNF functions.

[0108] Therefore, the embodiments in this paper use 5G to prevent unauthorized access to information. Furthermore, transparent processing of user identity can be achieved due to the DTCH-to-UE conversion provided at the VNF for the user-to-logical channel associated data. Additionally, the VNF and PNF of the 5G telecommunications network include location-based classification capabilities and user connection establishment mechanisms that the computing environment 100 can utilize. One of the main methods of the computing environment 100 is the use of DTCH, which is a logical slice of the physical bearer, for sending dedicated traffic between entities, DTCH tracking in eNodeB login mode, and area display that is not possible in 4G or compatible platforms.

[0109] Embodiments herein may include services operating in the 5G service orchestration plane that communicate with other location-based services in the multi-domain cognitive orchestration layer, and may include collecting information about dedicated logical channels in the 5G network. User health data may be transmitted using allocated logical channels and may include various types of health data, including health data indicating whether a user is infected or data indicating whether a user has been exposed to an infection (e.g., path data).

[0110] Embodiments of this document may also include a user-consent-driven location tracking system in a 5G virtual network function (VNF), wherein the VNF tracks the location of DTCHs based on 5G positioning technology or Global Positioning System (GPS) and latitude and longitude coordinates of each DTCH. Embodiments of this document may also include utilizing existing map-based services in a 5G-VNF using inbound or outbound protocols. Embodiments of this document may also include invoking a 5G-based infection tracking system to obtain an assigned list of DTCHs, which may include healthcare information such as medical health data indicating whether a user has been infected with or exposed to a disease. Embodiments of this document may provide a user access policy-driven authentication mechanism that allows for user location tracking and metadata mapping records at the 5G VNF layer. Embodiments of this document may provide a multi-level hierarchical list of infected and suspected UE devices during authentication using a medical mapper. Embodiments of this document include a collection of DTCH lists, extracting the DTCH_list, and branching the list based on primary, secondary, and subsequent infection exposure levels. Embodiments of this document may include updating the metadata mapper for the collected DTCH_list and using these mapper objects for next-level insight representations. Embodiments of this document may provide methods to trigger DTCH location monitoring of selected DTCHs in a DTCH_ list. Embodiments of this document may include VNF-level monitoring of DTCH_IDs and identification of eNodeB areas of access locations. Embodiments of this document may include aggregation of eNodeB radio resource maps (access reservations at eNodeBs) for all DTCHs in the aggregated list to obtain the area of ​​a user's DTCH. Embodiments of this document may include applying map-based classification to an eNodeB access pattern map and generating user operation area information. Embodiments of this document may calculate the total number of elements in a predefined area map and count the number of multi-level infected individuals and contacts within that area. Embodiments of this document may invoke a medical classifier to provide infection information and drug treatment details, and collect drug policy needs to address patient issues. Embodiments of this document may further notify healthcare institutions of information regarding their allocated medical resources, including relevant drug needs, and notify other healthcare institutions of their allocated resources based on their area. Providing healthcare resources to medical institutions may include, for example, automatically placing delivery orders with enterprise-owned or external vehicle delivery services, or automatically allocating resources to healthcare institutions by activating automated robotic medical resource reserves, such as autonomous vehicles, and initiating routes for autonomous vehicles to their destinations (e.g., healthcare institutions). Embodiments herein may include issuing demand notifications to subscribed healthcare service providers. Embodiments herein may include generating user notifications regarding healthcare institution service departments to manage logistics. Embodiments herein may identify suspected cases in a region and calculate their medication and other medical resource needs, and accordingly execute proactive notifications to effectively handle emergencies.The embodiments described herein can proactively identify the need for medical resources to address infectious diseases during a pandemic and update relevant personnel accordingly to fill gaps. The embodiments described herein can provide critical functionality during pandemics where the availability of medicines and other medical resources for treating diseases is limited. The embodiments described herein can improve the responsiveness of medical institutions when the equitable allocation of medical resources to different institutions during medical emergencies such as COVID-19 cannot address the needs of different institutions. The embodiments described herein provide a mechanism for predicting the use of medicines and other medical resources, as well as the use of other related facilities, which facilitates proactive medical resource reservation. The embodiments described herein provide a list of suspected users and correspondingly indicate medical requirements, which helps to provide appropriate treatment for infected users and suspected users who have been assigned a probability of infection. The service provided by the embodiments described herein does not specify a list of infected persons or any other user information because it pushes information directly on the medical channel using VNF. Therefore, there is no threat to personal information. The embodiments described herein provide parameters of the time spent by infected users with other users and accordingly select the distribution of allocated medical resources. The embodiments described herein can provide logistical advice to relevant subscribers to provide medical resources in a timely manner to address illness.

[0111] The embodiments described herein can utilize 5G infrastructure in the autonomous vehicle domain. The embodiments described herein are applicable to dynamically changing user-based 5G-DTCH VNF requirements based on relevant expectations in medical history and mobility. The embodiments described herein enable IaaS / PaaS service providers to use 5G service orchestration to deliver more accurate and optimal real-time data placement, and to provide the ability to push data based on real-time conditions through self-regulating monitoring levels such as real-time information utilization.

[0112] According to one example, embodiments of this document may include (1) the service orchestration layer of the 5G network initiating and invoking the MEDICA_SERVICE interconnect API on a 5G in-band protocol frame; (2) a data collector daemon may be invoked to receive streams from medical services and other interrelated 5G multi-domain services; (3) the DTCH_COLLECTOR sends asynchronous (ASYNC) communication to a multi-level hierarchical infection detection service to collect a DTCH_ list of infected and suspected cases; (4) information may be processed at peer services in the domain and a trajectory management service may be invoked to collect a list of IDs; (5) the service collects the allowed UUIDs of infected user devices and other devices that have been in contact with contacts and infected individuals; (6) a handshake communication. (7) The COMM is troubled by the multi-level hierarchical suspected finder of these services in the plane; (8) Trigger inter-service UUID and DTCH authentication using the 5G programmable framework and user plane (UP) authentication service; (9) Call the stream receiver and metadata mapper that receive the DTCH_ID of infected personnel and contact personnel UEs (DTCH_list is a list of 5G logical channels created between UE→eNodeB→virtual network function→radio bearer (NR)); (10) Once the DTCH_list is received, call the map-based classifier to obtain the geographic latitude and longitude information of the DTCH; (11) Inject the VNF instance of the DTCH locator, which tracks the device and returns the corresponding eNodeB; (22) Perform frequency-based eNodeB filtering on each eNodeB in the received DTCH-LIST to obtain the area Location; (12) Once the location and operational area are collected using a map-based classifier, the information aggregator will provide the number of people who may need medical assistance and infectious disease medication; (13) DTCH_lists will be used to enhance intensity calculations; (14) The intensity and probability of disease transmission (expressed in the form of a DTCH set of suspected cases), the number of medical devices and other facilities will be determined by tracking a disease medical database (this information can be generated by classifying a disease medical database containing a disease-drug mapper); (15) In-band messages on PLMQ will be sent to the notification manager via <region, medical logistics demand> tuples; (16) This notification can be selectively consumed by a subscription medical service in the 5G plane, which can further extend the notification to the service; (17) Optionally, notifications can be published to subscribers via the 5G built-in VNF-DTCH conversion logic.

[0113] Some embodiments described herein offer various computational advantages, including computational advantages in solving problems arising in the fields of computer networks and computer systems. Embodiments described herein can provide, for example, secure delivery of user data, such as sensitive user healthcare data. To deliver user healthcare data, a Virtual Network Function (VNF) layer can be configured to include user-to-logical channel association data that facilitates the participation of UE devices within a wireless network. In the wireless network, the VNF layer can assign logical channels, such as 5G New Radio (NR) DHTC channels, to corresponding UE devices associated with various users. Upon receiving user data, the VNF layer can pass the user data to a service orchestration layer for further processing. At the service orchestration layer, user data can be associated with logical channels, which serve as general references to users. However, access to user identification data in the user-to-logical channel association data can be restricted at the service orchestration layer. At the service orchestration layer, a probability of infection can be assigned to users currently in an uninfected state. Historical location data of users can be used to assign infection probabilities to various users. Medical resources allocated for infection can be allocated based on the assigned infection probabilities. Various decision data structures can be used to drive artificial intelligence (AI) decision-making, such as decision data structures that cognitively map social media interactions related to published content based on parameters for better allocation, which may include the allocation of digital rights. Decision data structures as described herein can be updated via machine learning to iteratively improve accuracy and reliability over time without requiring resource-intensive, rule-intensive processing. Machine learning processes can be performed to improve accuracy and reduce reliance on rule-based standards, thereby reducing computational overhead. To improve computational accuracy, embodiments may have computing platforms, such as AI platforms and machine learning platforms, that exist only in the realm of computer networks. Embodiments herein may employ data structuring processes, for example, processes for transforming unstructured data into a form optimized for computerized processing. Embodiments herein may examine data from diverse data sources, such as data from data sources that process radio signals to determine user location. Embodiments herein may include AI processing platforms with improved processes for transforming unstructured data into a structured form, thereby allowing computer-based analysis and decision-making. Embodiments herein may include specific arrangements for collecting rich data into data repositories, and additional specific arrangements for updating such data and using it to drive AI decision-making. Some implementations can be achieved using various types of cloud platforms / data centers, including Software as a Service (SaaS), Platform as a Service (PaaS), Database as a Service (DBaaS), and subscription-based combinations thereof.

[0114] Figure 10-12This document illustrates various aspects of computing, including computer systems and cloud computing, according to one or more aspects described herein.

[0115] It should be understood in advance that although this disclosure includes a detailed description of cloud computing, the implementation of the teachings given herein is not limited to a cloud computing environment. Rather, embodiments of the invention can be implemented in conjunction with any other type of computing environment now known or developed hereafter.

[0116] Cloud computing is a service delivery model that enables convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services), which can be rapidly provisioned and released with minimal management effort or interaction with the service provider. This cloud model may include at least five features, at least three service models, and at least four deployment models.

[0117] The features are as follows:

[0118] On-demand self-service: Cloud consumers can unilaterally and automatically provide computing power, such as server time and network storage, as needed, without requiring human interaction with the service provider.

[0119] Extensive network access: Capabilities are available through networks and accessed via standard mechanisms that facilitate the use of heterogeneous thin client or thick client platforms (e.g., mobile phones, laptops, and PDAs).

[0120] Resource pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, where different physical and virtual resources are dynamically assigned and reassigned as needed. There is a sense of location independence because consumers typically do not have control or knowledge of the exact location of the resources provided, but may be able to specify the location at a higher level of abstraction (e.g., country, state, or data center).

[0121] Rapid flexibility: The ability to provide capacity quickly and flexibly, automatically scaling down and up rapidly in some situations to scale up rapidly. For consumers, the available supply capacity often appears unlimited and can be purchased in any quantity at any time.

[0122] Measuring services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at a level of abstraction appropriate to the service type (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both service providers and consumers.

[0123] The service model is as follows:

[0124] Software as a Service (SaaS): This provides consumers with the ability to use the provider's applications running on cloud infrastructure. Applications can be accessed from different client devices via thin client interfaces such as web browsers (e.g., web-based email). Consumers do not manage or control the underlying cloud infrastructure, including the network, servers, operating system, storage, or even individual application capabilities, with possible exceptions such as limited user-specific application configuration settings.

[0125] Platform as a Service (PaaS): This provides consumers with the ability to deploy applications created or acquired by the consumer using programming languages ​​and tools supported by the provider onto cloud infrastructure. Consumers do not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but they have control over the deployed applications and the configuration of any application hosting environment.

[0126] Infrastructure as a Service (IaaS): The capabilities offered to consumers are processing, storage, networking, and other basic computing resources that enable consumers to deploy and run arbitrary software, which may include operating systems and applications. Consumers do not manage or control the underlying cloud infrastructure, but rather have control over the operating system, storage, deployed applications, and potentially limited control over selected networking components (e.g., host firewalls).

[0127] The deployment model is as follows:

[0128] Private cloud: A cloud infrastructure that operates solely for an organization. It can be managed by the organization or a third party and can exist on-site or off-site.

[0129] Community cloud: A cloud infrastructure shared by several organizations and supporting a specific community with shared concerns (e.g., tasks, security requirements, policies, and compliance considerations). It can be managed by an organization or a third party and can exist on-site or off-site.

[0130] Public cloud: Makes cloud infrastructure available to the public or large industry groups and is owned by an organization that sells cloud services.

[0131] Hybrid cloud: A cloud infrastructure is a combination of two or more clouds (private, community, or public) that remain a single entity but are bound together by standardized or proprietary technologies that enable data and applications to be ported (e.g., cloud bursting for load balancing between clouds).

[0132] Cloud computing environments are service-oriented, focusing on statelessness, loose coupling, modularity, and semantic interoperability. At the heart of cloud computing is the infrastructure comprising a network of interconnected nodes.

[0133] See now Figure 10The diagram illustrates an example of a computing node. Computing node 10 is merely one instance of a computing node suitable for use as a cloud computing node and is not intended to impose any limitation on the scope or functionality of the embodiments of the invention described herein. In any case, computing node 10 is capable of implementing and / or performing any of the functions set forth above. Computing node 10 can be implemented as a cloud computing node in a cloud computing environment, or it can be implemented as a computing node in a computing environment other than a cloud computing environment.

[0134] Computing node 10 contains computer system 12, which operates in conjunction with many other general-purpose or special-purpose computing system environments or configurations. Examples of well-known computing systems, environments, and / or configurations that may be applicable to computer system 12 include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments that include any of the above systems or devices.

[0135] Computer system 12 can be described in the general context of computer system executable instructions (such as program procedures) executed by the computer system. Generally, program procedures may include routines, programs, objects, components, logic, data structures, etc., that perform a specific task or implement a specific abstract data type. Computer system 12 can be implemented in a distributed cloud computing environment, where tasks are performed by remote processing devices linked via a communication network. In a distributed cloud computing environment, program procedures may reside in local and remote computer system storage media, including memory storage devices.

[0136] like Figure 10 As shown, the computer system 12 in compute node 10 is illustrated as a computing device. Components of the computer system 12 may include, but are not limited to, one or more processors 16, system memory 28, and a bus 18 coupling various system components, including the system memory 28, to the processors 16. In one embodiment, compute node 10 is a compute node in a non-cloud computing environment. In another embodiment, compute node 10 is as described herein in conjunction with... Figure 11-12 The computing nodes of the cloud computing environment described.

[0137] Bus 18 represents any one or more of several types of bus architectures, including memory buses or memory controllers, peripheral buses, accelerated graphics ports, and processor or local buses using any of the various bus architectures. By way of example and not limitation, such architectures include the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MCA) bus, the Enhanced ISA (EISA) bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0138] Computer system 12 typically includes various computer system readable media. Such media can be any available media accessible by computer system 12, and includes volatile and non-volatile media, removable and non-removable media.

[0139] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Computer system 12 may also include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be provided for reading from and writing to a non-removable non-volatile magnetic medium (not shown, and generally referred to as a "hard disk drive"). Although not shown, disk drives for reading from or writing to removable non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable non-volatile optical disks (e.g., CD-ROMs, DVD-ROMs, or other optical media) may be provided. In such cases, each may be connected to bus 18 via one or more data media interfaces. As will be further described and illustrated below, memory 28 may include at least one program product having at least one set of program processes configured to perform embodiments of the invention.

[0140] One or more programs 40 having a set (at least one) of program processes 42, along with an operating system, one or more applications, other program processes, and program data, may be stored in memory 28 by way of example and not limitation. One or more programs 40 including program processes 42 can generally perform the functions set forth herein. In one embodiment, UE devices 110A-110Z may include one or more computing nodes 10 and may include one or more programs 40 for performing the functions described with reference to UE devices 110A-110Z. In one embodiment, base stations 120A-120Z may include one or more computing nodes 10 and may include one or more programs 40 for performing the functions described with reference to base stations 120A-120Z. In one embodiment, orchestrator 130 may include one or more computing nodes 10 and may include one or more programs 40 for performing the functions described with reference to orchestrator 130. In one embodiment, vNF layer 1000 may be executed using one or more computing nodes 10 and may be defined by one or more programs 40 for performing the functions described with reference to vNF layer 1000. In one embodiment, vNF layer 2000 may be executed using one or more compute nodes 10 and may be defined by one or more programs 40 for performing the functions described with reference to vNF layer 2000.

[0141] Computer system 12 can also communicate with one or more external devices 14, such as a keyboard, pointing device, and display 24; with one or more devices that enable a user to interact with computer system 12; and / or with any device (e.g., a network interface card, modem, etc.) that enables computer system 12 to communicate with one or more other computing devices. This communication may be via input / output (I / O) interface 22. Furthermore, computer system 12 can communicate with one or more networks, such as a local area network (LAN), a general wide area network (WAN), and / or a public network (e.g., the Internet), via network adapter 20. As shown, network adapter 20 communicates with other components of computer system 12 via bus 18. It should be understood that, although not shown, other hardware and / or software components may be used in conjunction with computer system 12. Examples include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archiving storage systems. In addition to or instead of having external devices 14 and display 24 that can be configured to provide user interface functionality, in one embodiment, computing node 10 may include a display 25 connected to bus 18. In one embodiment, the display 25 may be configured as a touchscreen display and may be configured to provide user interface functionality, such as facilitating virtual keyboard functionality and input of general data. In one embodiment, the computer system 12 may also include one or more sensor devices 27 connected to the bus 18. The one or more sensor devices 27 may alternatively be connected via I / O interface 22. In one embodiment, the one or more sensor devices 27 may include a Global Positioning Sensor (GPS) device and may be configured to provide the location of the computing node 10. In one embodiment, the one or more sensor devices 27 may alternatively or additionally include one or more of, for example, a camera, gyroscope, temperature sensor, humidity sensor, pulse sensor, blood pressure (bp) sensor, or audio input device. The computer system 12 may include one or more network adapters 20. Figure 11 In the text, compute node 10 is described as being implemented in a cloud computing environment, and correspondingly in Figure 11 In the context of cloud computing nodes, they are referred to as cloud computing nodes.

[0142] See now Figure 11This describes an illustrative cloud computing environment 50. As shown, the cloud computing environment 50 includes one or more cloud computing nodes 10 to which local computing devices used by cloud consumers can communicate. These local computing devices include, for example, personal digital assistants (PDAs) or cellular phones 54A, desktop computers 54B, laptop computers 54C, and / or automotive computer systems 54N. The nodes 10 can communicate with each other. They can be physically or virtually grouped (not shown) in one or more networks, such as private clouds, community clouds, public clouds, or hybrid clouds, or combinations thereof, as described above. This allows the cloud computing environment 50 to provide infrastructure, platforms, and / or software as services that cloud consumers do not need to maintain on their local computing devices. It should be understood that... Figure 11 The types of computing devices 54A-N shown are intended to be illustrative only, and computing node 10 and cloud computing environment 50 can communicate with any type of computerized device via any type of network and / or network-addressable connection (e.g., using a web browser).

[0143] See now Figure 12 This demonstrates a cloud computing environment of 50 ( Figure 11 This provides a set of functional abstractions. It should be understood beforehand. Figure 12 The components, layers, and functions shown are intended to be illustrative only, and embodiments of the invention are not limited thereto. As shown, the following layers and corresponding functions are provided:

[0144] The hardware and software layer 60 includes hardware and software components. Examples of hardware components include: a mainframe 61; a RISC (Reduced Instruction Set Computer) based server 62; a server 63; a blade server 64; a storage device 65; and network and networking components 66. In some embodiments, software components include network application server software 67 and database software 68.

[0145] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual server 71; virtual storage 72; virtual network 73, including virtual private network; virtual application and operating system 74; and virtual client 75.

[0146] In one example, management layer 80 may provide the following functionalities: Resource Provisioning 81 provides dynamic procurement of computing resources and other resources used to perform tasks within the cloud computing environment. Metering and Pricing 82 provides cost tracking as resources are utilized within the cloud computing environment and bills or invoices for the consumption of these resources. In one example, these resources may include application software licenses. Security provides authentication for cloud consumers and tasks, as well as protection for data and other resources. User Portal 83 provides access to the cloud computing environment for consumers and system administrators. Service Level Management 84 provides cloud resource allocation and management to ensure that required service levels are met. Service Level Agreement (SLA) Planning and Fulfillment 85 provides pre-scheduling and procurement of cloud resources based on anticipated future needs according to the SLA.

[0147] Workload layer 90 provides examples of functionalities that can leverage a cloud computing environment. Examples of workloads and functionalities that can be provided from this layer include: mapping and navigation 91; software development and lifecycle management 92; virtual classroom instruction delivery 93; data analytics and processing 94; transaction processing 95; and processing components 96 for user data delivery as described herein. Processing component 96 is available... Figure 10 This is achieved through one or more procedures described herein.

[0148] This invention can be a system, method, and / or computer program product at any possible level of technical detail integration. The computer program product may include a computer-readable storage medium having computer-readable program instructions thereon for causing a processor to execute aspects of the invention.

[0149] Computer-readable storage media can be tangible devices capable of retaining and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example, but not limited to, electronic storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital universal disk (DVD), memory sticks, floppy disks, mechanical encoding devices such as punch cards or protrusions in slots having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses passing through fiber optic cables), or electrical signals transmitted through wires.

[0150] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device, or downloaded to an external computer or external storage device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network). The network may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the corresponding computing / processing device.

[0151] Computer-readable program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​(such as Java, Smalltalk, C++, etc.) and conventional procedural programming languages ​​(such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on a user's computer, partially on a user's computer, as a standalone software package, partially on a user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)) or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) may be personalized to execute computer-readable program instructions by utilizing state information from the computer-readable program instructions in order to perform aspects of this invention.

[0152] This document describes various aspects of the invention with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0153] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / actions specified in one or more blocks of a flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that causes a computer, programmable data processing apparatus, and / or other device to operate in a particular manner, such that the computer-readable storage medium storing the instructions includes an article of manufacture containing instructions that implement aspects of the functions / actions specified in the blocks of the flowchart and / or block diagram.

[0154] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce computer-implemented processing, such that the instructions executed on the computer, other programmable apparatus, or other device perform the functions / actions specified in one or more blocks of a flowchart and / or block diagram.

[0155] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. Each block in a flowchart or block diagram may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than indicated in the figures. For example, depending on the functions involved, two consecutively shown blocks may actually be executed substantially simultaneously, or these blocks may sometimes be executed in reverse order. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action or executes a combination of dedicated hardware and computer instructions.

[0156] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used herein, unless the context clearly indicates otherwise, the singular forms “a,” “an,” and “the” are intended to also include the plural forms. It should be further understood that the terms “comprising,” “having,” “including,” and “containing” are open-ended connecting verbs. Thus, a method or apparatus that “comprising,” “having,” “including,” or “containing” one or more steps or elements possesses, but is not limited to, possessing only those one or more steps or elements. Similarly, the elements of a method or apparatus that “comprising,” “having,” “including,” or “containing” one or more features possess, but are not limited to, possessing only those one or more features. Various forms of the term “based on” herein cover relationships in which elements are partially based as well as relationships in which elements are entirely based. A method, product, or system described as having a certain number of elements can be practiced with fewer or more than that number of elements. Furthermore, an apparatus or structure configured in a certain way is at least configured in that way, but may also be configured in ways not listed.

[0157] The expected numerical values, as well as other values ​​listed herein, are modified by the term “about,” whether explicitly stated or inherently derived from the discussion of this disclosure. As used herein, the term “about” defines the numerical boundaries of the modified value to include, but is not limited to, tolerances and values ​​up to and including the numerical values ​​so modified. That is, numerical values ​​may include explicitly stated actual values, as well as other values ​​that are, or may be, decimals, fractions, or other multiples of the actual values ​​indicated and / or described in this disclosure.

[0158] All means or steps plus functional elements (if any) in the following claims are intended to include any structure, material, action, and equivalent for performing the function in combination with other claimed elements as specifically claimed. The description set forth herein has been presented for purposes of illustration and description, but is not intended to be exhaustive or limited to the forms disclosed. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of this disclosure. Embodiments were chosen and described in order to best explain the principles and practical application of one or more aspects set forth herein, and to enable others skilled in the art to understand one or more aspects as described herein with respect to different embodiments having various modifications suitable for the particular intended use.

Claims

1. A computer-implemented method, comprising: The Virtual Network Function (VNF) layer obtains user medical and health data from the corresponding UE devices among multiple UE devices. The VNF layer has allocated logical channels to the corresponding UE devices among the UE devices for wireless transmission of user data. The VNF layer maintains user-to-logical channel association data that associates user identification data with the logical channel assigned to the user identified by the user identification data. The service orchestration layer, operating above the VNF layer, examines the user's healthcare data, wherein the service orchestration layer is configured to restrict its access to the user's identifier data related to logical channel association data; and Processing is carried out based on this inspection.

2. The computer implementation method according to claim 1, wherein, The logical channel is a 5G-compatible DTCH channel.

3. The computer-implemented method according to claim 1, wherein, The method includes receiving permission from a specific user associated with a user's health data to process user data of that specific user by a VNF layer, wherein the permission does not include permission to allow a service orchestration layer to access the user's user identification data.

4. The computer-implemented method according to claim 1, wherein, The medical health data examined by the service orchestration layer running above the VNF layer includes the infection status of a specified group of users and the trajectory of that group of users over time. The method includes allocating medical resources to a geographic area to respond to the infection based on the infection status of the group of users and the location of the group of users over time.

5. The computer-implemented method according to claim 1, wherein, The medical health data examined by the service orchestration layer running above the VNF layer includes the infection status of a specified group of users and the trajectory of that group of users over time. The method includes allocating medical resources to a geographic area to respond to the infection based on the infection status of the group of users and the location of the group of users over time. The method also includes determining the historical user crossover of the group of users based on the location of the group of users over time and identifying suspected infected users based on the determination.

6. The computer-implemented method according to claim 1, wherein, The medical health data examined by the service orchestration layer running above the VNF layer includes the infection status of a specified group of users and the trajectory of that group of users over time. The method includes allocating medical resources to a geographic area to respond to the infection based on the infection status of the group of users and their location over time. The method also includes predicting user crossover of the group of users based on their location over time and identifying suspected infected users based on the prediction.

7. The computer-implemented method according to claim 1, wherein, The medical health data examined by the service orchestration layer running above the VNF layer includes the infection status of a specified group of users and the trajectory of that group of users over time. The method includes allocating medical resources to a geographic area to address the infection based on the infection status of the group of users and their location over time. The method also includes predicting user crossovers based on the location of the group of users over time and identifying suspected infected users based on the prediction. The allocation is performed such that a first area with a first number of infected users is equipped with a first medical resource, and a second area with a second number of infected users is equipped with a second medical resource, where the second number is less than the first number and the second medical resource is greater than the first medical resource.

8. A computer program product comprising computer program instructions executable by one or more processors for performing the method according to any one of claims 1 to 7.

9. A network user data delivery system, comprising: Memory; At least one processor that communicates with memory; and One or more processors may execute program instructions from memory to perform the method according to any one of claims 1 to 7.