Data exposure privacy protection method and device for 5g application, electronic equipment and medium
Patent Information
- Application Number
- CN202310437353.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-21
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-04-21
AI Technical Summary
从而解决相关技术中出现的,5G通信网络中用户的敏感隐私信息容易被泄露给应用程序功能的问题
[0030]根据本申请实施例的还一个方面,提供的一种计算机可读存储介质,用于存储计算机可读取的指令,所述指令被执行时执行上述任一所述5G应用的数据暴露隐私保护方法的操作。
Smart Images

Figure CN116847333B_ABST
Abstract
Description
Technical Field
[0001] This application relates to communication technologies, and in particular to a method, apparatus, electronic device, and medium for protecting data exposure privacy in 5G applications. Background Technology
[0002] With the development of the communication and information age, 5G technology has also developed rapidly. In 5G communication networks, applications frequently need to access user data. This can potentially lead to unauthorized access to user data or leaks of private information.
[0003] Therefore, how to design a 5G communication network that protects users' sensitive privacy information while allowing users to actively or passively consent to applications requesting access to their data has become a problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] This application provides a method, apparatus, electronic device, and medium for protecting the privacy of data exposure in 5G applications. This addresses the problem in related technologies where sensitive user privacy information is easily leaked to application functions in 5G communication networks.
[0005] According to one aspect of the embodiments of this application, a method for protecting the privacy of data exposure in 5G applications is provided, comprising:
[0006] After the network open function network element receives the data acquisition request sent by the target application function, it forwards the data acquisition request to the privacy purification function network element. The data acquisition request is used to acquire the target data of the target user terminal.
[0007] After the privacy purification function network element determines that the target data is privacy data, it performs purification processing on the acquired target data to obtain purified data;
[0008] After receiving the purification data sent by the privacy purification function network element, the network open function network element sends the purification data to the target application function.
[0009] Optionally, in another embodiment based on the method described above in this application, the network open function element forwards the data acquisition request to the privacy sanitization function element, including:
[0010] The network open function element authorizes and verifies the data acquisition request;
[0011] After verification is confirmed, the data acquisition request is forwarded to the privacy purification function network element.
[0012] Optionally, in another embodiment based on the method described above in this application, the privacy-cleaning function network element determines the target data as privacy data, including:
[0013] The privacy purification function network element extracts the data type and data purpose corresponding to the target data from the data acquisition request;
[0014] The privacy purification function network element matches the data type and data purpose with the pre-stored purification policy to detect whether the target data needs to be purified.
[0015] If necessary, the target data may be designated as private data.
[0016] Optionally, in another embodiment based on the method described above in this application, after the privacy-cleaning function network element determines that the target data is privacy data, it further includes:
[0017] The privacy-protection function network element collects the target data from the target user terminal; or,
[0018] The privacy purification function network element forwards the data acquisition request to the network data analysis function network element, so that after the network data analysis function network element collects the target data from the target user terminal, it sends the target data to the privacy purification function network element.
[0019] Optionally, in another embodiment based on the method described above in this application, the step of purifying the acquired target data to obtain purified data includes:
[0020] The target data is anonymized, desensitized, differentially private, or homomorphically encrypted to obtain the cleaned data.
[0021] Optionally, in another embodiment based on the method described above in this application, after forwarding the data acquisition request to the privacy sanitation function network element, the method further includes:
[0022] After the privacy purification function network element determines that the target data is not privacy data, it directly sends the target data to the network open function network element.
[0023] According to another aspect of the embodiments of this application, a data exposure privacy protection device for 5G applications is provided, comprising:
[0024] The receiving module is configured to forward the data acquisition request to the privacy purification function network element after the network open function network element receives the data acquisition request sent by the target application function. The data acquisition request is used to acquire the target data of the target user terminal.
[0025] The determination module is configured to perform purification processing on the acquired target data after the privacy purification function network element determines that the target data is privacy data, so as to obtain purified data;
[0026] The sending module is configured to send the purified data to the target application function after the network open function element receives the purified data sent by the privacy purification function element.
[0027] According to another aspect of the embodiments of this application, an electronic device is provided, comprising:
[0028] Memory, used to store executable instructions; and
[0029] A display for executing the executable instructions with the memory to perform the data exposure privacy protection method for any of the 5G applications described above.
[0030] According to another aspect of the embodiments of this application, a computer-readable storage medium is provided for storing computer-readable instructions, which, when executed, perform the operation of the data exposure privacy protection method of any of the above-described 5G applications.
[0031] In this application, after the network open function network element receives a data acquisition request from the target application function, it forwards the data acquisition request to the privacy purification function network element. The data acquisition request is used to acquire target data from the target user terminal. After the privacy purification function network element determines that the target data is privacy data, it performs purification processing on the acquired target data to obtain purified data. After the network open function network element receives the purified data sent by the privacy purification function network element, it sends the purified data to the target application function. By applying the technical solution of this application, before sending the target data of the user terminal to the application function, the privacy purification function network element in the 5G communication network can first determine whether it is privacy data, and if it is determined to be privacy data, it will perform purification processing on the data before sending it to the application function. This solves the problem in related technologies where sensitive privacy information of users in 5G communication networks is easily leaked to application functions.
[0032] The technical solution of this application will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0033] The accompanying drawings, which form part of this specification, illustrate embodiments of this application and, together with the description, serve to explain the principles of this application.
[0034] This application can be more clearly understood with reference to the accompanying drawings and the following detailed description, wherein:
[0035] Figure 1 This is a schematic diagram of a data exposure privacy protection method for 5G applications proposed in this application;
[0036] Figure 2 This is an overall flowchart of a data exposure privacy protection method for 5G applications proposed in this application;
[0037] Figure 3 This is an overall flowchart of another data exposure privacy protection method for 5G applications proposed in this application;
[0038] Figure 4 This is a schematic diagram of the electronic device proposed in this application;
[0039] Figure 5 This is a schematic diagram of the electronic device proposed in this application. Detailed Implementation
[0040] Various exemplary embodiments of the present application will now be described in detail with reference to the accompanying drawings. It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of the present application.
[0041] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.
[0042] The following description of at least one exemplary embodiment is merely illustrative and is not intended to limit the scope of this application or its application or use.
[0043] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, such techniques, methods, and equipment should be considered part of the specification.
[0044] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.
[0045] Furthermore, the technical solutions of the various embodiments of this application can be combined with each other, but only if they are based on the ability of those skilled in the art to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such combination of technical solutions does not exist and is not within the scope of protection claimed by this application.
[0046] It should be noted that all directional indicators (such as up, down, left, right, front, back, etc.) in the embodiments of this application are only used to explain the relative positional relationship and movement of each component in a certain specific posture (as shown in the figure). If the specific posture changes, the directional indicator will also change accordingly.
[0047] The following is combined with Figures 1-3 This application describes a method for protecting data exposure privacy in 5G applications according to exemplary embodiments thereof. It should be noted that the application scenarios described below are merely illustrative for understanding the spirit and principles of this application, and the embodiments of this application are not limited in any way. Rather, the embodiments of this application can be applied to any applicable scenario.
[0048] This application also proposes a method, apparatus, electronic device, and medium for protecting data exposure privacy in 5G applications.
[0049] Figure 1 A schematic flowchart illustrating a data exposure privacy protection method for a 5G application according to an embodiment of this application is shown. Figure 1 As shown, this method is applied in 5G communication networks and includes:
[0050] S101, after the network open function network element receives the data acquisition request sent by the target application function, it forwards the data acquisition request to the privacy purification function network element. The data acquisition request is used to acquire the target data of the target user terminal.
[0051] S102, after the privacy purification function network element determines that the target data is privacy data, it performs purification processing on the acquired target data to obtain purified data.
[0052] S103 After the network open function network element receives the purification data sent by the privacy purification function network element, it sends the purification data to the target application function.
[0053] In 5G communication networks, applications frequently need to access user data. Understandably, users must expose some or all of their user data to the application's functions in order to obtain the application's full services. This can potentially lead to unauthorized access to user data or leaks of private information.
[0054] Among them, 3GPP TR 33.898 studied how to provide security and privacy protection for AI / ML-based services and applications in 5G to avoid the leakage of UE privacy information. Specifically, it proposed that 5G communication networks should support the protection of privacy-sensitive user data from being exposed to AF (Application Function).
[0055] To address the aforementioned problems, this application proposes a method for protecting the privacy of data exposed in 5G applications. The core idea is to establish a method that performs pre-defined purification processing on the 5GC privacy data requested by the application function after successful AF authentication, thereby reducing the amount of sensitive privacy information leaked to the AF. This achieves a mechanism to mitigate the leakage of user privacy from data sources.
[0056] Understandably, the technical solution proposed in this application can protect user privacy and security, provided that the user actively or passively consents to the AF's data requests. As an example, even if the AF obtains the user's private data through legitimate procedures, the amount of sensitive private information leaked to the AF can be reduced.
[0057] Furthermore, this application incorporates herein... Figure 2 The plan will be explained in detail:
[0058] Step 1: The network open function element receives the data acquisition request sent by the target application function.
[0059] In one embodiment of this application, after the target application function AF determines to obtain the target data of the target user terminal, it can send a data acquisition request to the network exposure function (NEF) in the 5G communication network.
[0060] As an example, a data acquisition request can be for target data used in artificial intelligence (AI) / machine learning (ML) scenarios.
[0061] In one approach, a data acquisition request may include multiple data parameters, such as data type (i.e., the data type of the target data being requested), AF ID (i.e., the identifier of the application function), privacy data-related parameters, and the intended use of the target data being requested.
[0062] Step 2: The network open function network element authorizes and verifies the data acquisition request, and forwards the data acquisition request to the privacy purification function network element after confirming that the verification is successful.
[0063] In one approach, after the Network Open Function (NEF) element receives a data acquisition request, it first needs to perform an authorization verification to ensure its legitimacy. The authorization verification steps include:
[0064] First, the NEF can authorize service requests using the OAuth-based authorization mechanism specified in Clause 12.4 of 3GPP TS 33.501. That is, the NEF can determine whether it is necessary to check user consent based on the service request and the operator's local policies; for example, whether a data acquisition request involves processing the user's personal information, or whether it requires oversight, etc.
[0065] Furthermore, if the user terminal's consent parameters are not present in the NEF's UE context, the NEF can send a Nudm_SDM_Get request message to the UDM, including the UE ID and potentially the data processing purpose and data processor ID. After the UDM returns the requested user consent parameters, the NEF will again use the user consent framework defined in TS 33.501 to check whether the user terminal has consented. Understandably, based on the results of AI / ML and other service procedures, the NEF will subsequently respond to the AF indicating whether the verification was successful.
[0066] Step 3: The privacy purification function network element extracts the data type and purpose of the target data from the data acquisition request.
[0067] In one approach, the NEF forwards the data acquisition request sent by the AF to the privacy purifying function network element. This allows the privacy purifying function network element to search its locally stored purifying policies based on the data type and purpose carried in the data acquisition request, thereby determining whether the target data indicated by the data acquisition request requires privacy purifying processing.
[0068] Step 4: The privacy cleanup function matches the network data type and data purpose with the pre-stored cleanup policy to determine that the target data is privacy data. Then proceed to step 5a or step 5b.
[0069] Understandably, privacy-monitoring network elements can respond differently based on the matching results between the data type and purpose and the pre-stored monitoring policies. For example, if it is determined that target data requires privacy-monitoring, the data monitoring function network element will act as the execution network element to process it accordingly. However, if the matching result shows that the target data does not require additional processing, it can be sent directly to the AF after being obtained.
[0070] In one approach, if the privacy-cleaning function network element determines that the target data is privacy data, then it will choose whether to acquire the target data itself or the network data analysis function network element NWDAF, depending on whether it has the data acquisition capability (i.e., the ability to obtain the target data).
[0071] Step 5a: The privacy-cleaning network element collects target data from the target user terminal.
[0072] Step 5b: The privacy purification function network element forwards the data acquisition request to the network data analysis function network element, so that after the network data analysis function network element collects the target data from the target user terminal, it sends the target data to the privacy purification function network element.
[0073] Specifically, the privacy-filtering network element can forward the data acquisition request forwarded by NEF back to NWDAF, so that NWDAF can collect relevant target data in accordance with 3GPP TS23.288. After collection, the target data is sent to the privacy-filtering network element so that the privacy-filtering function network element can perform appropriate purification processing on it.
[0074] Step 6: The privacy purification function network element performs at least one of the following processing on the target data: anonymization, desensitization, differential privacy processing, and homomorphic encryption processing, to obtain purified data.
[0075] In one approach, the purification process may include anonymization, desensitization, differential privacy, homomorphic encryption, or specific processing mechanisms stipulated by the operator. This application does not impose any specific limitations on this.
[0076] Step 7: Send the cleaned data to the target application function.
[0077] In this application, after the network open function network element receives a data acquisition request sent by the target application function, it forwards the data acquisition request to the privacy purification function network element. The data acquisition request is used to acquire target data of the target user terminal. After the privacy purification function network element determines that the target data is privacy data, it performs purification processing on the acquired target data to obtain purified data. After the network open function network element receives the purified data sent by the privacy purification function network element, it sends the purified data to the target application function.
[0078] By applying the technical solution of this application, before sending target data from a user terminal to application functions, the privacy purification function network element in the 5G communication network can first determine whether the data is privacy data. If it is determined to be privacy data, the data is purified before being sent to application functions. This solves the problem in related technologies where sensitive user privacy information is easily leaked to application functions in 5G communication networks.
[0079] Optionally, in another embodiment based on the method described above in this application, the network open function element forwards the data acquisition request to the privacy sanitization function element, including:
[0080] The network open function element authorizes and verifies the data acquisition request;
[0081] After verification is confirmed, the data acquisition request is forwarded to the privacy purification function network element.
[0082] Optionally, in another embodiment based on the method described above in this application, the privacy-cleaning function network element determines the target data as privacy data, including:
[0083] The privacy purification function network element extracts the data type and data purpose corresponding to the target data from the data acquisition request;
[0084] The privacy purification function network element matches the data type and data purpose with the pre-stored purification policy to detect whether the target data needs to be purified.
[0085] If necessary, the target data may be designated as private data.
[0086] Optionally, in another embodiment based on the method described above in this application, after the privacy-cleaning function network element determines that the target data is privacy data, it further includes:
[0087] The privacy-protection function network element collects the target data from the target user terminal; or,
[0088] The privacy purification function network element forwards the data acquisition request to the network data analysis function network element, so that after the network data analysis function network element collects the target data from the target user terminal, it sends the target data to the privacy purification function network element.
[0089] Optionally, in another embodiment based on the method described above in this application, the step of purifying the acquired target data to obtain purified data includes:
[0090] The target data is anonymized, desensitized, differentially private, or homomorphically encrypted to obtain the cleaned data.
[0091] Optionally, in another embodiment based on the method described above in this application, after forwarding the data acquisition request to the privacy sanitation function network element, the method further includes:
[0092] After the privacy purification function network element determines that the target data is not privacy data, it directly sends the target data to the network open function network element.
[0093] In one approach, such as Figure 3 The diagram shown is an overall flowchart of a data exposure privacy protection method for 5G applications proposed in this application, which includes:
[0094] Step a: AF decides to request 5GC assistance information for AI / ML operations.
[0095] The AF sends a 5GC assistance information access request along with the required parameters to the NEF to request 5GC assistance information. The AF needs to provide the NEF with the following information: data type, AF ID, details of the 5GC assistance information, and optional additional information such as the purpose of the data.
[0096] Step b: NEF can verify the authorization of the AF's application. If the authorization is successful, the subsequent process will proceed; otherwise, the AF's application will be rejected.
[0097] Step c: NEF forwards the 5GC assistance information access request sent by AF to the privacy sanitation function network element. The privacy sanitation function network element can cooperate with NWDAF or be NWDAF itself.
[0098] Step d: The privacy purification function network element searches for local policies based on the data type and purpose of the data attached to the AF request to determine whether the AF request data needs privacy purification processing.
[0099] Step e: The privacy purification network element forwards the 5GC assistance information access request forwarded by NEF back to NWDAF.
[0100] Step f: NWDAF collects relevant privacy data in accordance with 3GPP TS23.288.
[0101] Step g: NWDAF will send a 5GC assistance information access response to the privacy purification network element, along with the data requested by AF.
[0102] In step h, the privacy-cleaning network element responds differently based on the local policy queried in S304. If the policy indicates that the data requested by the AF requires privacy-cleaning processing, the data cleanup function network element will act as the executing network element; if the policy indicates that the data requested by the AF does not require additional processing, step S308 will be skipped. Specific data cleanup mechanisms may include anonymization mechanisms, de-identification mechanisms, differential privacy, homomorphic encryption, etc., or specific mechanisms stipulated by the operator.
[0103] Step i: The privacy-cleaning network element sends a 5GC assistance information access response to the NEF, carrying either the cleaned AF request data or the original AF request data.
[0104] Step j: NEF forwards the 5GC assistance information access response to AF, carrying the sanitized / raw AF request data. If S302 authorization denial occurs, a rejection response is returned.
[0105] By applying the technical solution of this application, before sending target data from a user terminal to application functions, the privacy purification function network element in the 5G communication network can first determine whether the data is privacy data. If it is determined to be privacy data, the data is purified before being sent to application functions. This solves the problem in related technologies where sensitive user privacy information is easily leaked to application functions in 5G communication networks.
[0106] Optionally, in another embodiment of this application, such as Figure 4 As shown, this application also provides a data exposure privacy protection device for 5G applications. It includes:
[0107] The receiving module 201 is configured to forward the data acquisition request to the privacy purification function network element after the network open function network element receives the data acquisition request sent by the target application function. The data acquisition request is used to acquire the target data of the target user terminal.
[0108] The determination module 202 is configured to perform purification processing on the acquired target data after the privacy purification function network element determines that the target data is privacy data, so as to obtain purified data;
[0109] The sending module 203 is configured to send the purified data to the target application function after the network open function element receives the purified data sent by the privacy purification function element.
[0110] By applying the technical solution of this application, before sending target data from a user terminal to application functions, the privacy purification function network element in the 5G communication network can first determine whether the data is privacy data. If it is determined to be privacy data, the data is purified before being sent to application functions. This solves the problem in related technologies where sensitive user privacy information is easily leaked to application functions in 5G communication networks.
[0111] In another embodiment of this application, the determining module 202 is configured to:
[0112] The network open function element authorizes and verifies the data acquisition request;
[0113] After verification is confirmed, the data acquisition request is forwarded to the privacy purification function network element.
[0114] In another embodiment of this application, the determining module 202 is configured to:
[0115] The privacy purification function network element extracts the data type and data purpose corresponding to the target data from the data acquisition request;
[0116] The privacy purification function network element matches the data type and data purpose with the pre-stored purification policy to detect whether the target data needs to be purified.
[0117] If necessary, the target data may be designated as private data.
[0118] In another embodiment of this application, the determining module 202 is configured to:
[0119] The privacy-protection function network element collects the target data from the target user terminal; or,
[0120] The privacy purification function network element forwards the data acquisition request to the network data analysis function network element, so that after the network data analysis function network element collects the target data from the target user terminal, it sends the target data to the privacy purification function network element.
[0121] In another embodiment of this application, the determining module 202 is configured to:
[0122] The privacy purification function network element performs at least one of the following processes on the target data: anonymization, desensitization, differential privacy processing, and homomorphic encryption processing, to obtain the purified data.
[0123] In another embodiment of this application, the determining module 202 is configured to:
[0124] After the privacy purification function network element determines that the target data is not privacy data, it directly sends the target data to the network open function network element.
[0125] Figure 5 This is a logical structure block diagram of an electronic device according to an exemplary embodiment. For example, electronic device 300 may be an electronic device.
[0126] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory including instructions, which can be executed by an electronic device processor to complete the data exposure privacy protection method for the 5G application described above. The method includes: after a network open function element receives a data acquisition request sent by a target application function, forwarding the data acquisition request to a privacy purification function element, wherein the data acquisition request is used to acquire target data of a target user terminal; after the privacy purification function element determines that the target data is privacy data, purifying the acquired target data to obtain purified data; and after the network open function element receives the purified data sent by the privacy purification function element, sending the purified data to the target application function.
[0127] Optionally, the above instructions can also be executed by the processor of the electronic device to complete other steps involved in the exemplary embodiments described above. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0128] In an exemplary embodiment, an application / computer program product is also provided, including one or more instructions that can be executed by a processor of an electronic device to complete the above-described 5G application data exposure privacy protection method. The method includes: after a network open function element receives a data acquisition request sent by a target application function, forwarding the data acquisition request to a privacy purification function element, wherein the data acquisition request is used to acquire target data from a target user terminal; after the privacy purification function element determines that the target data is privacy data, purifying the acquired target data to obtain purified data; and after the network open function element receives the purified data sent by the privacy purification function element, sending the purified data to the target application function.
[0129] Alternatively, the above instructions may also be executed by the processor of the electronic device to complete other steps involved in the above exemplary embodiments.
[0130] Figure 5 This is an example diagram of an electronic device 300. Those skilled in the art will understand that it is illustrative. Figure 5 This is merely an example of electronic device 300 and does not constitute a limitation on electronic device 300. It may include more or fewer components than shown, or combine certain components, or different components. For example, electronic device 300 may also include input / output devices, network access devices, buses, etc.
[0131] The processor 302 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, or processor 302 can be any conventional processor. Processor 302 is the control center of electronic device 300, connecting all parts of electronic device 300 via various interfaces and lines.
[0132] The memory 301 can be used to store computer-readable instructions 303. The processor 302 implements various functions of the electronic device 300 by running or executing the computer-readable instructions or modules stored in the memory 301 and calling the data stored in the memory 301. The memory 301 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device 300, etc. In addition, the memory 301 may include a hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, read-only memory (ROM), random access memory (RAM), or other non-volatile / volatile storage devices.
[0133] If the modules integrated in the electronic device 300 are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by instructing related hardware through computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium, and when executed by a processor, they can implement the steps of the various method embodiments described above.
[0134] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0135] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for protecting the privacy of data exposure in 5G applications, characterized in that, Applied in 5G communication networks, including: After the network open function network element receives the data acquisition request sent by the target application function, it forwards the data acquisition request to the privacy purification function network element. The data acquisition request is used to acquire the target data of the target user terminal. After the privacy purification function network element determines that the target data is privacy data, it performs purification processing on the acquired target data to obtain purified data; After receiving the purification data sent by the privacy purification function network element, the network open function network element sends the purification data to the target application function. The privacy-cleaning function network element determines the target data as privacy data, including: The privacy purification function network element extracts the data type and data purpose corresponding to the target data from the data acquisition request; The privacy purification function network element matches the data type and data purpose with the pre-stored purification policy to detect whether the target data needs to be purified. If necessary, the target data may be classified as private data. After the privacy-cleaning function network element determines that the target data is privacy data, it also includes: The privacy-protection function network element collects the target data from the target user terminal; or, The privacy purification function network element forwards the data acquisition request to the network data analysis function network element, so that after the network data analysis function network element collects the target data from the target user terminal, it sends the target data to the privacy purification function network element.
2. The method as described in claim 1, characterized in that, The network open function element forwards the data acquisition request to the privacy purification function element, including: The network open function element authorizes and verifies the data acquisition request; After verification is confirmed, the data acquisition request is forwarded to the privacy purification function network element.
3. The method as described in claim 1, characterized in that, The privacy purification function network element purifies the acquired target data to obtain purified data, including: The privacy purification function network element performs at least one of the following processes on the target data: anonymization, desensitization, differential privacy processing, and homomorphic encryption processing, to obtain the purified data.
4. The method as described in claim 1, characterized in that, After forwarding the data acquisition request to the privacy purification function network element, the method further includes: After the privacy purification function network element determines that the target data is not privacy data, it directly sends the target data to the network open function network element.
5. A data exposure privacy protection device for 5G applications, characterized in that, Applied in 5G communication networks, including: The receiving module is configured to forward the data acquisition request to the privacy purification function network element after the network open function network element receives the data acquisition request sent by the target application function. The data acquisition request is used to acquire the target data of the target user terminal. The determination module is configured to perform purification processing on the acquired target data after the privacy purification function network element determines that the target data is privacy data, so as to obtain purified data; The sending module is configured to send the purified data to the target application function after the network open function element receives the purified data sent by the privacy purification function element. The determining module is further configured to execute the privacy-cleaning function network element to determine the target data as privacy data in the following manner: The privacy purification function network element extracts the data type and data purpose corresponding to the target data from the data acquisition request; The privacy purification function network element matches the data type and data purpose with the pre-stored purification policy to detect whether the target data needs to be purified. If necessary, the target data may be classified as private data. The device is also configured to: After the privacy-protection function network element determines that the target data is privacy data, the privacy-protection function network element collects the target data from the target user terminal; or, The privacy purification function network element forwards the data acquisition request to the network data analysis function network element, so that after the network data analysis function network element collects the target data from the target user terminal, it sends the target data to the privacy purification function network element.
6. An electronic device, characterized in that, include: Memory, used to store executable instructions; as well as, A processor, configured to execute the executable instructions with the memory to perform the operation of the data exposure privacy protection method for any of the 5G applications described in claims 1-4.
7. A computer-readable storage medium for storing computer-readable instructions, characterized in that, When the instruction is executed, it performs the operation of the data exposure privacy protection method for any of the 5G applications described in claims 1-4.
Citation Information
Patent Citations
A new method of data sanitization for the privacy protection of cloud data in cloud computing
AU2021102595A4
Finer granularity user plane security policy configuration
US20220303823A1