Data anonymization for minimization of drive tests
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ALCATEL LUCENT SHANGHAI BELL CO LTD
- Filing Date
- 2020-11-07
- Publication Date
- 2026-08-07
AI Technical Summary
即使无线电接入网的网络设备(例如,gNB)或核心网的接入和移动性管理功能(AMF)在处理时空轨迹时不向TCE转发任何UE身份或TAC信息,例如,在电信网络环境中所收集的数据的情况下,身份信息也存在暴露于MDT期间收集的敏感和非敏感测量的风险
Smart Images

Figure CN116746194B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this disclosure generally relate to the telecommunications field, and more particularly to methods, apparatus, devices, and computer-readable storage media for minimizing data anonymization in drive tests (MDT). Background Technology
[0002] MDT (Drive Testing) allows management systems (MnS) to collect UE (User Equipment) measurements, including but not limited to data volume, throughput and loss rate, location, and sensor information. Network operators can leverage these UE measurements to more easily monitor their networks and optimize network coverage and capacity. Furthermore, MDT can replace expensive drive tests performed manually by operators.
[0003] From a network signaling perspective, there are two types of MDTs: signaling-based MDTs targeting specific terminal devices (e.g., UEs) and management-based MDTs targeting a group of terminal devices located within a specific area. From the perspective of the terminal device (e.g., UE), MDT measurements typically involve privacy data associated with the UE user, such as user identity and International Mobile Equipment Identity Tracking Area Code (IMEI-TAC). Currently, the anonymization of user privacy data is divided into two levels. If the user does not wish to expose their identity, no user identity will be sent to the Tracking Collection Entity (TCE) of the communication network during the MDT. Otherwise, at least some identity information (e.g., the UE's IMEI-TAC) will be sent to the TCE. Even if the network equipment of the radio access network (e.g., gNB) or the access and mobility management function (AMF) of the core network does not forward any UE identity or TAC information to the TCE when processing spatiotemporal trajectories, for example, in the case of data collected in a telecommunications network environment, identity information is still at risk of being exposed to sensitive and non-sensitive measurements collected during the MDT. Summary of the Invention
[0004] Generally speaking, the exemplary embodiments of this disclosure provide a solution for data anonymization in MDT.
[0005] In a first aspect, a first device is provided. The first device includes: at least one processor; and at least one memory, including computer program code; the at least one memory and the computer program code are configured, together with the at least one processor, to cause the first device to: generate first anonymization information related to Minimize Drive Test (MDT), the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; and send the first anonymization information to a second device.
[0006] In a second aspect, a second device is provided. The second device includes: at least one processor; and at least one memory, including computer program code, wherein the at least one memory and the computer program code are configured, together with the at least one processor, to cause the second device to: receive first anonymization information related to Minimize Drive Testing (MDT) from a first device, the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; receive MDT measurements from at least one terminal device; and cause a set of anonymization processes to be performed on data associated with the MDT, the data including the MDT measurements.
[0007] In a third aspect, a third device is provided. The third device includes: at least one processor; and at least one memory, including computer program code, wherein the at least one memory and the computer program code are configured, together with the at least one processor, to enable the third device to: acquire data associated with Minimum Drive Testing (MDT), the data including at least MDT measurements; determine at least one anonymization process to be performed on the data associated with MDT; and cause at least one anonymization process to be performed on the data.
[0008] In a fourth aspect, a method is provided. The method includes: generating first anonymization information related to Minimum Drive Test (MDT) at a first device, the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; and sending the first anonymization information to a second device.
[0009] In a fifth aspect, a method is provided. The method includes: receiving, at a second device, first anonymization information related to Minimize Drive Testing (MDT) from a first device, the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; receiving MDT measurements from at least one terminal device; and inducing a set of anonymization processes to be performed on data associated with the MDT, the data including the MDT measurements.
[0010] In a sixth aspect, a method is provided. The method includes: acquiring data associated with Minimum Drive Testing (MDT) at a third device, the data including at least MDT measurements; determining at least one anonymization process to be performed on the data associated with the MDT; and inducing the at least one anonymization process to be performed on the data.
[0011] In a seventh aspect, a first apparatus is provided. The first apparatus includes: components for generating first anonymization information related to Minimize Drive Test (MDT), the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; and components for transmitting the first anonymization information to a second apparatus.
[0012] In an eighth aspect, a second apparatus is provided. The second apparatus includes: means for receiving first anonymization information related to Minimize Drive Testing (MDT) from a first device, the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; means for receiving MDT measurements from at least one terminal device; and means for inducing a set of anonymization processes to be performed on data associated with the MDT, the data including the MDT measurements.
[0013] In a ninth aspect, a third apparatus is provided. The third apparatus includes: components for acquiring data associated with Minimum Drive Testing (MDT), the data including at least MDT measurements; components for determining at least one anonymization process to be performed on the data associated with MDT; and components for inducing at least one anonymization process to be performed on the data.
[0014] In a tenth aspect, a non-transient computer-readable medium is provided, comprising program instructions for causing a device to execute at least the method according to the fourth aspect above.
[0015] In an eleventh aspect, a non-transient computer-readable medium is provided, comprising program instructions for causing a device to at least execute the method according to the fifth aspect above.
[0016] In a twelfth aspect, a non-transient computer-readable medium is provided, comprising program instructions for causing a device to at least execute the method according to the sixth aspect above.
[0017] It should be understood that the summary portion is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0018] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which:
[0019] Figure 1 The illustration shows an exemplary communication environment in which example embodiments of this disclosure can be implemented;
[0020] Figure 2 The diagram illustrates a signaling flowchart for data anonymization in MDT according to some example embodiments of the present disclosure;
[0021] Figure 3 The illustration shows a flowchart of a data anonymization method for MDT according to some example embodiments of the present disclosure;
[0022] Figure 4 The illustration shows a flowchart of a data anonymization method for MDT according to some example embodiments of the present disclosure;
[0023] Figure 5 The illustration shows a flowchart of a data anonymization method for MDT according to some example embodiments of the present disclosure;
[0024] Figure 6 A simplified block diagram of an apparatus suitable for implementing embodiments of the present disclosure is illustrated; and
[0025] Figure 7 A block diagram of an example computer-readable medium according to some embodiments of the present disclosure is illustrated.
[0026] Throughout the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation
[0027] The principles of this disclosure will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described merely for illustration and to help those skilled in the art understand and implement this disclosure, and do not imply any limitation on the scope of this disclosure. The disclosure described herein can be implemented in various ways other than those described below.
[0028] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.
[0029] In this disclosure, references to "an embodiment," "embodiment," and "example embodiment," etc., indicate that the described embodiment may include a specific feature, structure, or characteristic, but not every embodiment must include that specific feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Moreover, when a specific feature, structure, or characteristic is described in conjunction with an example embodiment, it is considered that, whether explicitly described or not, any influence of that feature, structure, or characteristic on other embodiments is within the knowledge scope of those skilled in the art.
[0030] It should be understood that although the terms “first” and “second”, etc., may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish different elements. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the exemplary embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0031] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. The singular forms “a,” “an,” and “the” used herein also include the plural forms unless the context clearly indicates otherwise. Further understanding is that the terms “comprising,” “including,” “having,” “having,” “covering,” and / or “containing,” when used herein, specify the presence of the stated features, elements, and / or components, but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.
[0032] As used in this application, the term "circuit system" may refer to one or more or all of the following:
[0033] (a) Pure hardware circuit implementation (such as implementation using only analog and / or digital circuit systems), and
[0034] (b) A combination of hardware circuitry and software, such as (if applicable):
[0035] (i) A combination of (multiple) analog and / or digital hardware circuits and software / firmware, and
[0036] (ii) Any part of a hardware processor(s) having software, including (multiple) digital signal processors(s), software, and (multiple) memories(s), which work together to cause a device (such as a mobile phone or server) to perform various functions, and
[0037] (c) Multiple hardware circuits and / or multiple processors, such as multiple microprocessors or a portion thereof, that require software (e.g., firmware).
[0038] The software can be used to perform operations, but it may not exist when no operation is needed.
[0039] The definition of "circuit system" applies to all uses of the term in this application, including in any claim. As another example, as used in this application, the term "circuit system" also covers only hardware circuitry or a processor (or processors) or a portion of hardware circuitry or a processor and its accompanying software and / or firmware. For example, if applicable to a particular claim element, the term "circuit system" also covers baseband integrated circuits or processor integrated circuits for mobile devices, or similar integrated circuits in servers, cellular network devices, or other computing or network devices.
[0040] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as fifth-generation (5G) systems, Long Term Evolution (LTE), LTE-A Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. Furthermore, communication between terminal devices and network devices in a communication network can be performed according to any appropriate generation of communication protocol, including but not limited to first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, future fifth-generation (5G) New Radio (NR) communication protocols, and / or any other currently known or to be developed in the future. Embodiments of this disclosure can be applied to various communication systems. Given the rapid development of communications, there will naturally be future types of communication technologies and systems that can embody this disclosure. The scope of this disclosure should not be limited to the systems described above.
[0041] As used herein, the term "network device" refers to a node in a communication network through which terminal devices access the network and receive services. Network devices can refer to base stations (BS) or access points (APs), such as Node B (NodeB or NB), evolved Node B (eNodeB or eNB), NR next-generation Node B (gNB), remote radio unit (RRU), radio header (RH), remote radio headend (RRH), repeater, low-power nodes (such as femtoseconds, picoseconds), non-terrestrial network (NTN) or terrestrial network equipment such as satellite network equipment, low Earth orbit (LEO) satellites and geostationary orbit (GEO) satellites, aircraft network equipment, etc., depending on the terminology and technology applied.
[0042] The term "terminal device" refers to any terminal device capable of wireless communication. By way of example and not limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smartphones, VoIP phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop in-vehicle devices (LME), USB dongles, smart devices, wireless customer premises equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronics devices, devices operating on commercial and / or industrial wireless networks, etc. Terminal equipment can also correspond to the mobile terminal (MT) portion of an integrated access and backhaul (IAB) node (also known as a relay node). In the following description, the terms "terminal equipment," "communication equipment," "terminal," "user equipment," and "UE" are used interchangeably.
[0043] As mentioned earlier, telecommunications network management systems can collect user equipment measurements through the MDT (Multi-Level Marketing) process. Due to privacy and legal obligations, the MDT process can only be conducted with the user's consent. Telecommunications network operators can collect user consent for specific measurements, such as International Mobile Subscriber Identity (IMSI), IMEI, and Subscriber Permanent Identifier (SUPI), through customer care processes. User consent availability information is considered part of the subscription data and is configured in the Unified Data Management (UDM) database.
[0044] Typically, user consent is represented as a static attribute (e.g., a one-bit indicator) indicating whether MDT measurements are permitted. Before activating MDT functionality, the UDM checks user consent availability. If a given user has not provided user consent to the network where the TCE resides, the UDM will not initiate a tracking session for that user. Therefore, traditional user consent does not allow for specifying multi-level consent, consent for each measurement type (e.g., data volume, throughput, location and sensor information, packet delay, loss rate, etc.), consent for each service / application (i.e., per slice), etc. Consequently, the effectiveness and flexibility of the MDT process are very limited.
[0045] In the case of managed MDT, when a terminal device (e.g., UE) accesses the network, the UDM forwards user consent information to the corresponding AME. The AMF can store the received user consent information in a user database. The AMF can also check the roaming status of candidate terminal devices. If the candidate terminal device is within the HPLMN and the user has already given user consent, the AMF sends a managed MDT allow IE and user consent information to the base station (e.g., gNB) during the UE context setting procedure, with the user consent information as part of the managed MDT allow IE. Otherwise, the managed MDT allow IE will not be sent to the base station.
[0046] As part of the UE context, the base station stores the received managed MDT allow IEs. Upon receiving a managed MDT activation, the base station checks the availability of the managed MDT allow IE. If the managed MDT allow IE is unavailable, the base station will not select a terminal device from the candidate terminal devices for MDT measurement. However, if the managed MDT allow IE is available, but the registered PLMN (RPLMN) of the candidate terminal device does not match the PLMN where the TCE resides (i.e., the tracking reference PLMN portion), the base station will not select the candidate terminal device as the terminal device for MDT measurement. Then, during Xn-based handover, the base station forwards the managed MDT allow IE to the target node.
[0047] For the radio access network (RAN) of the fifth-generation new radio, also known as 5GNR, the gNB does not send cell traffic trace messages to the AMF. If the anonymization indication requires IMEI-TAC, the gNB sends the cell traffic trace message to the AMF and populates the privacy indicator IE with the following information based on the job type. Common anonymization techniques adopted by data collectors and data owners include pseudonymization, which involves replacing the personal identifiers of the terminal device (e.g., name, phone number, IMSI associated with the terminal device) with pseudo-random identifiers (i.e., random or irreversible hash values). However, pseudonymization may not be effective when processing spatiotemporal trajectory data, and it has been shown that user identities can be discovered from pseudonymous spatiotemporal trajectories. Therefore, more robust anonymization techniques are needed to process spatiotemporal trajectories.
[0048] To address the aforementioned and other potential problems, exemplary embodiments of this disclosure provide a data anonymization mechanism for MDT processes. According to this data anonymization mechanism, multi-level user consent is configured to indicate multi-level anonymization of MDT measurements by extending the Tracejob attribute tjMDTAnonymizationOfData of the data. Furthermore, anonymization of MDT measurements can be achieved through various anonymization functions deployed on TCE or other network elements.
[0049] Figure 1 An exemplary communication environment 100 is illustrated, which can implement exemplary embodiments of the present disclosure. Environment 100 may be part of a communication network, including a first device 110, a second device 120, a third device 130, an AMF 140, and a terminal device 150. It should also be understood that... Figure 1 The number of network devices shown, including various network components, network administrators, and terminal devices, is given for illustrative purposes and does not indicate any limitation.
[0050] In the following description, the first device 110 will be described as a configuration device of a telecommunications management system, such as a configuration MnS consumer. To activate a tracking session, the first device 110 sends a tracking session activation request to the second device 120, the session activation request including first anonymization information related to the MDT and other configuration parameters. In an example embodiment, the first anonymization information also indicates anonymization processing to be performed by the third device 130. This will be described in detail below.
[0051] AMF 140 collects user consent information, which indicates multi-level consent given by the user of terminal device 150 through a customer care process, and stores it in the database of AMF 140. AMF 140 may provide user consent information to second device 120 for MDT processing, which will be described in detail below.
[0052] The second device 120 may include a base station, a provisioning MnS provider, a tracking report MnS provider, etc. Hereinafter, for discussion purposes, the second device 120 will be described as a base station, such as a gNB, serving at least one terminal device including terminal device 150. The second device 120 may select a set of terminal devices (including terminal device 150) for collecting MDT measurements based on user consent information and first anonymization information. The second device 120 then activates the MDT process of terminal device 150. As a result, the second device 120 receives a tracking report including MDT measurements from terminal device 150 and performs at least partial anonymization processing on the MDT measurements based on the first anonymization information. The second device 120 then sends the anonymized MDT measurements and a first anonymization indicator to the third device 130, the first anonymization indicator indicating the required level of anonymization for the MDT measurements.
[0053] The third device 130 will be described as a tracking device in a telecommunications management system. Depending on the type of tracking report, the third device 130 may be a TCE or a tracking report device. For example, if the tracking report is a file-based tracking report, the second device 120 may send MDT measurements and a first anonymization indicator to the TCE. If the tracking report is a stream-based tracking report, the second device 120 may send MDT measurements and a first anonymization indicator to the tracking report MnS consumer.
[0054] Communication in communication environment 100 can be implemented according to any suitable communication protocol(s), including but not limited to cellular communication protocols such as first-generation (1G), second-generation (2G), third-generation (3G), fourth-generation (4G), and fifth-generation (5G), wireless local area network communication protocols such as IEEE 802.11, and / or any other currently known or to be developed in the future. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiplexing (OFDM), Discrete Fourier Transform Extended Orthogonal Frequency Division Multiplexing (DFT-s-OFDM), and / or any other currently known or to be developed in the future.
[0055] The following will refer to Figures 2 to 5 The principles and embodiments of this disclosure are described in detail. To implement advanced MDT processes based on multi-level consent, embodiments of this disclosure provide data anonymization for MDT processes, the mechanisms of which include... Figure 2 The advanced flowchart 200 is shown. For discussion purposes, reference will be made to... Figure 1Describe process 200. Process 200 may involve first device 110, second device 120, third device 130, AMF 140 and terminal device 150.
[0056] First device 110 generates 205 first anonymization information related to MDT. As described above, the first anonymization information indicates the anonymization conditions required for the data associated with the MDT. These anonymization conditions correspond to a set of anonymization processes that may be enabled, for example, by second device 120, third device 130, or a combination thereof. The data associated with the MDT may include, but is not limited to, MDT measurements, TAC, Tracking Record Session Reference (TRSR), Tracking Reference (TR), Serving Cell CGI, User Identity, etc.
[0057] In some example embodiments, the first anonymization information may also indicate configuration parameters associated with the MDT obtained from the MaS, and indicate, for example, the region where the candidate terminal device used to collect MDT measurements is located.
[0058] In some example embodiments, the first device 110 may generate first anonymization information based on one or more user consent information and / or operator policies. The user consent information may be obtained from a core network device (e.g., AMF 140). Additionally, or alternatively, the user consent information may be obtained from a Basic Service Set (BSS) system. The user consent information may indicate the level of anonymization associated with a user of at least one terminal device (such as terminal device 150).
[0059] In some example embodiments, the first anonymization information may be sent in a tracking session activation request, which also includes other configuration parameters. The tracking session activation request enables the second device 120 to collect MDT measurements from the terminal device 150. For this purpose, the tracking session activation request may include an extended tjMDTAnonymizationOfData, indicating the required anonymization conditions for the data associated with the user identifier.
[0060] First device 110 sends first anonymization information 210 to second device 120. Upon receiving the first anonymization information, second device 120 may trigger MDT, which will be discussed below. In some example embodiments, first device 110 may also send first anonymization information 215 to third device 130 so that at least a subset of the anonymization processing set will be enabled by third device 130. Alternatively, first device 110 may generate second anonymization information related to MDT and send the second anonymization information to third device 130. The second anonymization information may indicate a second subset of the anonymization processing set to be enabled by third device 130.
[0061] Based on the receipt of the first anonymization information, the second device 120 establishes a tracking session. During the establishment of the tracking session, the second device 120 can select at least one terminal device from candidate terminal devices, such as terminal device 150 for collecting MDT measurements. In some example embodiments, the selection of the terminal device may be based on configuration parameters associated with MDT and user consent information. The user consent information is obtained from AMF 140 as part of an MDT-permitted IE (e.g., a managed MDT-permitted IE). According to example embodiments of this disclosure, the user consent information indicates the level of anonymization associated with the user of terminal device 150, rather than simply indicating whether MDT is permitted.
[0062] After selecting terminal device 150, second device 120 can send a 230MDT indication to terminal device 150 to activate the MDT function. Upon receiving the MDT activation indication, terminal device 150 can initiate the MDT function and, for example, send an MDT measurement to second device 120 via a Radio Resource Control (RRC) signaling trace report.
[0063] The second device 120 receives 235 MDT measurements and can store the MDT measurements in an MDT record. Based on the first anonymization information, the second device 120 generates 240 first anonymization indicators. In some example embodiments, the second device 120 can determine that none of the anonymization processing sets will be performed by itself. In this case, the second device 120 can generate a first anonymization indicator indicating the anonymization processing set. Furthermore, the second device 120 can send a cell service tracing message containing TRSR, TR, serving cell CGI, and the first anonymization indicator. In response to this message, AMF 140 sends tracing data about the terminal device 150, such as IMEI-TAC, TRSR, TR, etc., to the third device 130. Furthermore, the third device 130 can further obtain other tracing data from the RAN. Therefore, the third device 130 can obtain data including at least MDT measurements and tracing data.
[0064] In some other embodiments, the second device 120 may determine that a first subset of the anonymization processing set will be performed by itself. In this case, the second device 120 may perform the first subset of anonymization processing on the MDT measurements and generate a first anonymization indicator indicating the first subset of anonymization processing already performed on the MDT measurements. Alternatively, the second device 120 may generate a first anonymization indicator indicating a second subset of the anonymization processing set to be performed, i.e., anonymization processing other than the first subset of anonymization processing in the set. The first anonymization indicator may also indicate the anonymization conditions and anonymization functions required for the data associated with the MDT. The second device 120 then sends the MDT measurements and the first anonymization indicator to the third device 130.
[0065] After obtaining the MDT measurement and the first anonymization indicator, the third device 130 determines at least one anonymization process to be performed on the data associated with the MDT. As described above, the third device 130 may combine the MDT measurement with data obtained from the core network, including but not limited to tracking data (if applicable). The at least one anonymization process to be performed may refer to a second subset of the anonymization process set. Therefore, the third device 130 causes at least one anonymization process to be performed on the data.
[0066] In some example embodiments, the third device 130 may perform at least one anonymization process on the data itself. In some other example embodiments, the third device 130 may have the data anonymized by a fourth device. In such an embodiment, the third device 130 may generate a second anonymization indicator indicating at least one anonymization process and send the data associated with the MDT and the second anonymization indicator to the fourth device. As a result, the fourth device may perform at least one anonymization process on the data based on the second anonymization indicator and then send the anonymized data to the third device 130.
[0067] Then, the third device 130 can send an MDT measurement to the data consumer, which is anonymized based on the anonymization level associated with the user of the terminal device 150. The data consumer can be a third party. In the above embodiments, the third device 130 can be a tracking device of a telecommunications management system. Specifically, in the case of file-based tracking reports, the third device 130 can be a TCE. In the case of stream-based tracking reports, the third device 130 can be a tracking report MnS consumer.
[0068] To obtain anonymized data, in some example embodiments, the third device 130 may enable at least one anonymization process by using one or more suitable anonymization functions. For example, the anonymization function may be k-anonymization. For instance, if a group of terminal devices requires k-anonymization, but the number of terminal devices in the group is insufficient (e.g., less than k) to apply the required anonymization algorithm, the third device 130 may integrate MDT measurements with data associated with terminal devices that do not require anonymization. The third device 130 then enables anonymization of both the MDT measurements and the data by using the anonymization function. In cases where such data is unavailable, the third device 130 may delay the anonymization of the MDT measurements to await data from other terminal devices, or alternatively, discard the MDT measurements.
[0069] According to an example embodiment of this disclosure, a data anonymization mechanism for the MDT process is provided by using multi-level user consent and anonymization options / levels defined by tjMDTAnonymizationOfData. Therefore, the operation and maintenance system of the communication network can anonymize measurements based on multi-level user consent by applying appropriate anonymization functions before forwarding any specific UE measurement to the data consumer.
[0070] Figure 3 The illustration shows a flowchart of a method 300 for data anonymization for MDT according to some example embodiments of the present disclosure. Method 300 can be implemented at a configuration device of a telecommunications management system, for example, as shown in reference... Figure 1 The first device 110 is described. Method 300 may also involve a second device 120, a third device 130, and an AMF 140. It should be understood that method 300 may include additional actions not shown and / or some actions shown may be omitted, and the scope of this disclosure is not limited thereto. Furthermore, it should be understood that although this document primarily presents it as sequentially performed, at least a portion of the actions of process 300 may be performed simultaneously or in different sequences. Figure 3 The execution order presented in the text.
[0071] At step 310, the first device 110 generates first anonymization information related to the MDT. The first anonymization information indicates the anonymization conditions required for the data associated with the MDT. The anonymization conditions correspond to a set of anonymization processes.
[0072] In some example embodiments, the first device 110 may generate first anonymization information based on the anonymization level associated with a user of at least one terminal device, including terminal device 150. For example, user consent information obtained from a core network device (e.g., AMF 140) may be configured to indicate the appropriate anonymization level for the user.
[0073] At step 320, the first device 110 sends first anonymization information to the second device 120. Upon receiving the first anonymization information, the second device 120 may trigger an MDT. In some example embodiments, the first anonymization information may be sent in a tracking session activation request. The tracking session activation request allows the second device 120 to collect MDT measurements from the terminal device 150.
[0074] In some example embodiments, the first device 110 may also send first anonymization information to the third device 130. In such embodiments, at least a subset of the anonymization processing set is to be performed or enabled by the third device 130.
[0075] In some example embodiments, the first device 110 generates second anonymization information related to the MDT. The second anonymization information indicates a second subset of the anonymization processing set to be enabled by the third device 130. In these embodiments, the first device 110 may send the second anonymization information to the third device 130, causing the second subset of the anonymization processing set to be executed.
[0076] Figure 4 The illustration shows a flowchart of a method 400 for data anonymization for MDT according to some example embodiments of the present disclosure. Method 400 can be implemented at a network device of a telecommunications management system, for example, as shown in reference... Figure 1 The second device 120 is described. Method 400 may also involve the first device 110, the third device 130, the AMF 140, and the terminal device 150. It should be understood that method 500 may include additional actions not shown and / or some actions shown may be omitted, and the scope of this disclosure is not limited thereto. Furthermore, it should be understood that although this document primarily presents it as sequentially executed, at least a portion of the actions of process 500 may be performed simultaneously or in different ways. Figure 4 The execution order presented in the text.
[0077] At step 410, the second device 120 receives first anonymization information related to the MDT from the first device 110. The first anonymization information indicates the anonymization conditions required for the data associated with the MDT, and the anonymization conditions correspond to a set of anonymization processes to be performed on the data. In some example embodiments, the first anonymization information may be received in a tracking session activation request from the first device 110.
[0078] At step 420, the second device 120 receives MDT measurements from at least one terminal device (i.e., terminal device 150). In some example embodiments, the second device 120 may select at least one terminal device based at least in part on anonymization conditions and an anonymization level associated with a user of at least one terminal device including terminal device 150. User consent information obtained from core network equipment (e.g., AMF 140) may be configured to indicate the anonymization level. The second device 120 may then send an MDT indication to terminal device 150 for activating the MDT. As a result, the second device 120 may receive MDT measurements from terminal device 150.
[0079] At step 430, the second device 120 initiates a set of anonymization processes to be performed on the data associated with the MDT. In this case, the data may include at least MDT measurements. The data may also include tracking data obtained from the core network and / or the RAN.
[0080] In some example embodiments, the second device 120 may determine that no set of anonymization processing is performed on the MDT measurement. In these embodiments, the second device 120 generates a first anonymization indicator indicating the set of anonymization processing. The second device 120 then sends the first anonymization indicator and the MDT measurement to the third device 130, which causes the set of anonymization processing to be performed, for example, by the third device 130, a fourth device separate from the third device 130, or a combination thereof.
[0081] In some example embodiments, the second device 120 may perform a first subset of anonymization processing on the MDT measurements based on the first anonymization information. In these embodiments, the second device 120 generates a first anonymization indicator based on the first subset of the anonymization processing. The second device 120 sends the anonymized MDT measurements and the first anonymization indicator to the third device 130, which causes the second subset of anonymization processing to be performed, for example, by the third device 130, a fourth device separate from the third device 130, or a combination thereof.
[0082] In some example embodiments, the first anonymization indicator may indicate a first subset of the set of anonymization processes to be performed by the second device 120. In these embodiments, the second device 120 may also send first anonymization information to the third device 130. Therefore, the third device 130 may determine a second subset of the anonymization processes to be performed based on the first anonymization information and the first anonymization indicator. In some other example embodiments, the first anonymization indicator may explicitly indicate a second subset of the set of anonymization processes.
[0083] Figure 5The illustration shows a flowchart of a method 500 for data anonymization for MDT according to some example embodiments of the present disclosure. Method 500 can be implemented at a tracking device in a telecommunications management system, for example, referring to... Figure 1 The third device 130 is described. Method 500 may also involve the first device 110, the second device 120, and a data consumer device that may be from a third party. It should be understood that method 500 may include additional actions not shown and / or some actions shown may be omitted, and the scope of this disclosure is not limited thereto. Furthermore, it should be understood that although this document primarily presents it as sequentially executed, at least some actions of process 500 may be performed simultaneously or in different ways. Figure 5 The execution order presented in the text.
[0084] At step 510, the third device 130 obtains data associated with the MDT. The data may include at least MDT measurements collected from at least one terminal device (e.g., terminal device 150).
[0085] As described above, the third device 130 can receive MDT measurements from the second device 120 and obtain tracking data about the terminal device 150 from the AMF 140 and / or RAN. The MDT-related data includes at least MDT measurement and tracking data.
[0086] At step 520, the third device 130 determines at least one anonymization process to be performed on the data associated with the MDT. In some example embodiments, the third device 130 may receive a first anonymization indicator from the second device 120 indicating the at least one anonymization process to be performed.
[0087] In some other example embodiments, the third device 130 may receive second anonymization information related to the MDT from the first device 110. In these embodiments, the second anonymization information may indicate at least one anonymization process.
[0088] In some other example embodiments, the third device 130 may receive first anonymization information related to the MDT from the first device 110. The first anonymization information indicates the anonymization conditions required for the data associated with the MDT, and the anonymization conditions correspond to a set of anonymization processes required for the data. In these embodiments, the third device 130 then receives a first anonymization indicator from the second device 120. Figure 4 The first anonymization indicator can indicate a first subset of the set of anonymization processes already performed by the second device 120. Therefore, the third device 130 can determine a second subset of the set of anonymization processes to be performed based on the first anonymization information and the first anonymization indicator.
[0089] At step 530, the third device 130 causes at least one anonymization process to be performed on the data. In some example embodiments, the anonymization of the MDT measurement can be implemented at the third device 130. In these embodiments, the third device 130 can perform at least one anonymization process on the data associated with the MDT measurement, for example by applying an appropriate anonymization function indicated in the second anonymization information.
[0090] In some other example embodiments, anonymization of the MDT measurement can be performed at a fourth device separate from the third device 130. In these embodiments, the third device 130 can generate a second anonymization indicator indicating at least one anonymization process to be performed. The third device 130 can send the data associated with the MDT received from the second device 120 and the second anonymization indicator to the fourth device. The second anonymization indicator is configured to cause the fourth device to perform at least one anonymization process on the data. Therefore, the third device 130 can receive data anonymized by at least one anonymization process from the fourth device.
[0091] In some example embodiments, the third device 130 may also be configured to send data anonymized by at least one anonymization process to the data consumer device, such as data from a third-party data consumer.
[0092] In some example embodiments, the first means capable of performing method 300 may include components for performing the corresponding steps of method 300. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit system or a software module.
[0093] In some example embodiments, the first device includes: components for generating first anonymization information at the first device in relation to Minimize Drive Test (MDT), the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; and components for sending the first anonymization information to a second device.
[0094] In some example embodiments, the component for generating the first anonymization information includes: a component for generating the first anonymization information based at least in part on an anonymization level associated with a user of at least one terminal device.
[0095] In some example embodiments, the first anonymization information is sent in the tracking session activation request, and the tracking session activation request causes the second device to collect MDT measurements from at least one terminal device.
[0096] In some example embodiments, the first anonymization information also indicates another part of the anonymization process to be enabled by a third device different from the second device.
[0097] In some example embodiments, the first device further includes components for sending the first anonymization information to a third device, which is different from the second device, such that at least one subset of the anonymization processing set is to be performed.
[0098] In some example embodiments, the first device further includes: components for generating second anonymization information related to the MDT, the second anonymization information indicating at least another portion of anonymization processing to be enabled by a third device different from the second device; and components for sending the second anonymization information to the third device.
[0099] In some example embodiments, the first device is a telecommunications management system device, the second device is an access network device, and the third device is a telecommunications management system tracking device.
[0100] In some example embodiments, the second means capable of performing method 400 may include components for performing the corresponding steps of method 400. These components may be implemented in any suitable form. For example, the components may be implemented in a circuit system or a software module.
[0101] In some example embodiments, the second device includes: components for receiving, at the second device and from the first device, first anonymization information related to Minimize Drive Testing (MDT), the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; components for receiving MDT measurements from at least one terminal device; and components for inducing a set of anonymization processes to be performed on data associated with the MDT, the data including the MDT measurements.
[0102] In some example embodiments, first anonymization information is received in a tracking session activation request from a first device.
[0103] In some example embodiments, the components for receiving MDT measurements include: components for selecting at least one terminal device based on anonymization conditions and an anonymization level associated with a user of at least one terminal device; components for sending an MDT indication to at least one terminal device for activating MDT at at least one terminal device; and components for receiving MDT measurements from at least one terminal device.
[0104] In some example embodiments, the second apparatus further includes: a component for generating a first anonymization indicator indicating a set of anonymization processes; and a component for sending the first anonymization indicator and the set of anonymization processes to be performed caused by MDT measurements to a third apparatus.
[0105] In some example embodiments, the components for inducing a set of anonymization processes to be performed include: components for performing a first subset of the anonymization processes on the MDT measurements based on first anonymization information; components for generating a first anonymization indicator based on the first subset of the anonymization processes; and components for sending the anonymized MDT measurements and the first anonymization indicator to a third device to induce a second subset of the anonymization processes to be performed.
[0106] In some example embodiments, the first anonymization indicator indicates a first subset of the set of anonymization processes performed by the second device, and the second device further includes a component for sending the first anonymization information to the third device.
[0107] In some example embodiments, the first anonymization indicator indicates a second subset of the anonymization processing set.
[0108] In some example embodiments, the first device is a telecommunications management system device, the second device is an access network device, and the third device is a telecommunications management system tracking device.
[0109] In some example embodiments, the third means capable of performing method 500 may include a component for performing the corresponding steps of method 500. This component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module.
[0110] In some example embodiments, the third means includes: components for obtaining data associated with Minimum Drive Testing (MDT) at the third means, the data including at least MDT measurements; components for determining at least one anonymization process to be performed on the data associated with MDT; and components for inducing at least one anonymization process to be performed on the data.
[0111] In some example embodiments, the components for obtaining data associated with the MDT include: components for receiving MDT measurements collected from at least one terminal device from a second device; components for obtaining tracking data about at least one terminal device; and components for obtaining data associated with the MDT based on the MDT measurements and tracking data.
[0112] In some example embodiments, the component for determining at least one anonymization process includes: a component for receiving from a second device a first anonymization indicator indicating at least one anonymization process.
[0113] In some example embodiments, the component for determining at least one anonymization process includes: a component for receiving second anonymization information associated with the MDT from a first device, the second anonymization information indicating at least one anonymization process.
[0114] In some example embodiments, the components for determining at least one anonymization process include: components for receiving first anonymization information associated with the MDT from a first device, the first anonymization information indicating anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; components for receiving from a second device a first anonymization indicator indicating a first subset of the set of anonymization processes to be performed by the second device; and components for determining a second subset of the set of anonymization processes to be performed based on the first anonymization information and the first anonymization indicator.
[0115] In some example embodiments, the component for inducing at least one anonymization process to be performed includes: a component for performing at least one anonymization process on the data.
[0116] In some example embodiments, the components for inducing at least one anonymization process to be performed include: components for generating a second anonymization indicator indicating at least one anonymization process; components for sending data associated with the MDT to a fourth device and the second anonymization indicator for causing the fourth device to perform at least one anonymization process on the data; and components for receiving data anonymized by at least one anonymization process from the fourth device.
[0117] In some example embodiments, the first device is a network device of the telecommunications management system, the second device is an access network device, and the third device is a tracking device of the telecommunications management system.
[0118] Figure 6 This is a simplified block diagram of a device 600 suitable for implementing embodiments of the present disclosure. The device 600 can be provided to implement a communication device, for example, as... Figure 1 The first device 110, the second device 120, and the third device 130 are shown. As shown, device 600 includes one or more processors 610, one or more memories 620 coupled to processor 610, and one or more communication modules 640 coupled to processor 610.
[0119] Communication module 640 is used for bidirectional communication. Communication module 640 has at least one antenna to facilitate communication. The communication interface can represent any interface necessary for communication with other network elements.
[0120] Processor 610 can be any type suitable for a local technology network, and by way of non-limiting example, can include one or more of the following: general-purpose computer, special-purpose computer, microprocessor, digital signal processor (DSP), and processor based on a multi-core processor architecture. Device 600 can have multiple processors, such as application-specific integrated circuit chips that are time-subordinate to a clock synchronized with the main processor.
[0121] Memory 620 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 624, electrically programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disk (DVD), and other magnetic and / or optical storage. Examples of volatile memories include, but are not limited to, random access memory (RAM) 622 and other volatile memories that do not persist during power outages.
[0122] Computer program 630 includes computer-executable instructions that are executed by the associated processor 610. Program 630 may be stored in ROM 620. Processor 610 can perform any suitable actions and processes by loading program 630 into RAM 620.
[0123] Embodiments of this disclosure can be implemented using program 630, enabling device 600 to execute reference... Figures 3 to 5 Any process discussed in this disclosure. Embodiments of this disclosure may also be implemented by hardware or by a combination of software and hardware.
[0124] In some embodiments, program 630 may be tangibly contained in a computer-readable medium, which may be included in device 600 (such as memory 620) or other storage device accessible to device 600. Device 600 may load program 630 from the computer-readable medium into RAM 622 for execution. The computer-readable medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. Figure 7 An example of a computer-readable medium 700 in the form of a CD or DVD is shown. A program 630 is stored on the computer-readable medium.
[0125] Generally, the various embodiments of this disclosure can be implemented using hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented using hardware, while others can be implemented using firmware or software that can be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of this disclosure are illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that, as non-limiting examples, the blocks, apparatuses, systems, techniques, or methods described herein can be implemented using hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.
[0126] This disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in a program module, which execute in a device on a target real or virtual processor to perform the above-referenced... Figures 3 to 5 Methods 300, 400, or 500 are described. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc., that perform specific tasks or implement specific abstract data types. In various embodiments, the functionality of a program module can be combined or split among program modules as needed. The machine-executable instructions of a program module can execute on a local or distributed device. In a distributed device, a program module can reside on both local and remote storage media.
[0127] Program code used to perform the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a stand-alone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0128] In the context of this disclosure, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.
[0129] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any suitable combination thereof. More specific examples of computer-readable storage media will include electrical connections having one or more wires, portable computer floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0130] Furthermore, although operations are described in a specific order, this should not be construed as requiring the operations to be performed in the specific order shown or sequentially, or to perform all of the shown operations to obtain the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features described in the context of a single embodiment may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0131] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that this disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms of implementing the claims.
Claims
1. A first device for communication, comprising: At least one processor; as well as At least one memory, including computer program code; The at least one memory and the computer program code are configured, together with the at least one processor, to cause the first device to at least: Generate first anonymization information related to minimizing the drive test MDT, the first anonymization information indicating the anonymization conditions required for data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes, wherein the first anonymization information is generated based on the anonymization level associated with a user of at least one terminal device; as well as The first anonymization information is sent to a second device, wherein the first anonymization information is sent in a tracking session activation request, the tracking session activation request causing the second device to collect MDT measurements from the at least one terminal device. The first device is further configured to: Generate second anonymization information associated with the MDT, the second anonymization information indicating a second subset of the anonymization processing set; as well as Sending the second anonymization information to a third device causes the second subset of the set of anonymization processes to be performed.
2. The first device according to claim 1, wherein the first device is further configured to send the first anonymization information to a third device different from the second device, the third device causing at least one subset of the set of anonymization processes to be performed.
3. The first device according to claim 1 or 2, wherein the first device is a device of a telecommunications management system, the second device is a network device of an access network, and the third device is a tracking device of the telecommunications management system.
4. A second device for communication, comprising: At least one processor; as well as At least one memory, including computer program code; The at least one memory and the computer program code are configured, together with the at least one processor, to cause the second device to at least: First anonymization information related to minimizing the drive test MDT is received from a first device. The first anonymization information indicates the anonymization conditions required for data associated with the MDT, and the anonymization conditions correspond to a set of anonymization processes. The first anonymization information is received in a tracking session activation request from the first device. Receive MDT measurements from at least one terminal device; as well as The set of anonymization processes that cause to be performed on data associated with the MDT, the data including at least the MDT measurements. The second device is configured to cause the set of anonymization processes to be performed by: Based on the first anonymization information, a first subset of the anonymization processing set is performed on the MDT measurements; Based on the first subset of the anonymization processing set, a first anonymization indicator is generated; as well as Sending the anonymized MDT measurement and the first anonymization indicator to the third device causes a second subset of the anonymization process to be performed.
5. The second device according to claim 4, wherein the second device is configured to receive the MDT measurement by: The at least one terminal device is selected based at least in part on the anonymization conditions and the anonymization level associated with the user of the at least one terminal device; Send an MDT instruction to the at least one terminal device for activating the MDT at the at least one terminal device; as well as The MDT measurement is received from the at least one terminal device.
6. The second device of claim 4, wherein the second device is configured to cause the set of anonymization processes to be performed by: Generate a first anonymization indicator, the first anonymization indicator indicating the anonymization processing set; and Sending the first anonymization indicator and the MDT measurement to the third device causes the set of anonymization processes to be performed.
7. The second device of claim 4, wherein the first anonymization indicator indicates the first subset of the set of anonymization processes performed by the second device, and the second device is further configured such that: The first anonymization information is sent to the third device.
8. The second device of claim 4, wherein the first anonymization indicator indicates the second subset of the anonymization processing set.
9. The second device according to any one of claims 4 to 8, wherein the first device is a device of a telecommunications management system, the second device is a network device of an access network, and the third device is a tracking device of the telecommunications management system.
10. A third device for communication, comprising: At least one processor; as well as At least one memory, including computer program code; The at least one memory and the computer program code are configured, together with the at least one processor, to cause the third device to at least: Obtain data associated with minimizing the road test MDT, the data including at least MDT measurements, wherein the third device is configured to obtain the data associated with the MDT by: Receive the MDT measurements collected from at least one terminal device from the second device; Obtain tracking data regarding the at least one terminal device; as well as Based on the MDT measurements and the tracking data, the data associated with the MDT is obtained; Determine at least one anonymization process to be performed on the data associated with the MDT; as well as This triggers the at least one anonymization process to be performed on the data. The third device is configured to determine the at least one anonymization process by: Receive first anonymization information related to the MDT from a first device, the first anonymization information indicating the anonymization conditions required for the data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; Receive a first anonymization indicator from the second device, the first anonymization indicator indicating a first subset of the set of anonymization processes performed by the second device; as well as Based on the first anonymization information and the first anonymization indicator, a second subset of the set of anonymization processes to be performed is determined.
11. The third device of claim 10, wherein the third device is configured to determine the at least one anonymization process by: Receive a first anonymization indicator from the second device, the first anonymization indicator indicating the at least one anonymization process.
12. The third device of claim 10, wherein the third device is configured to determine the at least one anonymization process by: Receive second anonymization information related to MDT from the first device, the second anonymization information indicating the at least one anonymization process.
13. The third device according to claim 10, wherein the third device is configured to cause the at least one anonymization process to be performed by: Perform the at least one anonymization process on the data.
14. The third device of claim 10, wherein the third device is configured to cause the at least one anonymization process to be performed by: Generate a second anonymization indicator, the second anonymization indicator indicating the at least one anonymization process; Send the data associated with the MDT and the second anonymization indicator to the fourth device to cause the fourth device to perform the at least one anonymization process on the data; as well as The data anonymized by the at least one anonymization process is received from the fourth device.
15. The third device according to claim 14, wherein the third device is further configured to: The data anonymized by the at least one anonymization process is sent to the data consumer device.
16. The third device according to any one of claims 10 to 15, wherein the first device is a device of a telecommunications management system, the second device is a network device of an access network, and the third device is a tracking device of the telecommunications management system.
17. A method of communication, comprising: At a first device, first anonymization information related to minimizing the drive test MDT is generated. The first anonymization information indicates the anonymization conditions required for data associated with the MDT, and the anonymization conditions correspond to a set of anonymization processes. The first anonymization information is generated based on the anonymization level associated with a user of at least one terminal device. as well as The first anonymization information is sent to a second device, wherein the first anonymization information is sent in a tracking session activation request, the tracking session activation request causing the second device to collect MDT measurements from the at least one terminal device. The method further includes: Generate second anonymization information associated with the MDT, the second anonymization information indicating a second subset of the anonymization processing set; as well as Sending the second anonymization information to a third device causes the second subset of the set of anonymization processes to be performed.
18. A method of communication, comprising: At the second device, first anonymization information related to minimizing the drive test MDT is received from the first device. The first anonymization information indicates the anonymization conditions required for the data associated with the MDT, and the anonymization conditions correspond to a set of anonymization processes. The first anonymization information is received in a tracking session activation request from the first device. Receive MDT measurements from at least one terminal device; as well as The set of anonymization processes that cause to be performed on data associated with the MDT, the data including at least the MDT measurements. The second device triggers the set of anonymization processes to be performed through the following: Based on the first anonymization information, a first subset of the anonymization processing set is performed on the MDT measurements; Based on the first subset of the anonymization processing set, a first anonymization indicator is generated; as well as Sending the anonymized MDT measurement and the first anonymization indicator to the third device causes a second subset of the anonymization process to be performed.
19. A method of communication, comprising: Data associated with minimizing the road test MDT is obtained at a third device, the data including at least MDT measurements, wherein the third device is configured to obtain the data associated with the MDT via: Receive the MDT measurements collected from at least one terminal device from the second device; Obtain tracking data regarding the at least one terminal device; as well as Based on the MDT measurements and the tracking data, the data associated with the MDT is obtained; Determine at least one anonymization process to be performed on the data associated with the MDT; as well as This triggers the at least one anonymization process to be performed on the data. The third device determines the at least one anonymization process by: Receive first anonymization information related to the MDT from a first device, the first anonymization information indicating the anonymization conditions required for the data associated with the MDT, the anonymization conditions corresponding to a set of anonymization processes; Receive a first anonymization indicator from the second device, the first anonymization indicator indicating a first subset of the set of anonymization processes performed by the second device; as well as Based on the first anonymization information and the first anonymization indicator, a second subset of the set of anonymization processes to be performed is determined.
20. A non-transient computer-readable medium comprising program instructions for causing a device to perform at least the method of claim 17.
21. A non-transient computer-readable medium comprising program instructions for causing a device to perform at least the method of claim 18.
22. A non-transient computer-readable medium comprising program instructions for causing a device to perform at least the method according to claim 19.
Citation Information
Patent Citations
User equipment (ue) data anonymization
GB202014388D0