Security for AI / ML model storage and sharing

By registering authorization information associated with the joint learning group in the network repository function of the 5G system, the security problem of machine learning model in the 5G system is solved, ensuring that only authorized NFs can join the joint learning group, achieving higher security and protection effects.

CN119999145APending Publication Date: 2025-05-13TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380071380.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-10
Filing Date
2023-10-10
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art cannot effectively solve the security problems of machine learning models in 5G systems, especially in a federated learning environment. It is difficult to prevent unauthorized network functions (NFs) from joining the federated learning group as clients, resulting in the exposure of confidential models.

Method used

Ensure that only authorized NFs can join the joint learning group by registering information associated with the joint learning group, including authorized information, in the Network Repository Function (NRF). The method includes receiving an access token and an authorization token for verifying and authorizing the joining of the NF.

Benefits of technology

Effectively prevent unauthorized NFs from joining the joint learning group, protecting confidential models from being exposed, and improving the security of joint learning in 5G systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119999145A_ABST
    Figure CN119999145A_ABST
Patent Text Reader

Abstract

A method for a first Network Function (NF) configured to operate as a server of a Joint Learning (FL) group in a communication network. Such a method includes registering information associated with a group of FLs in a network repository function (NRF) of a communication network. The FL group includes a first NF and one or more further NFs configured to operate as clients in the FL group. The registered information includes authorization information for the additional NF to join the FL group as the client. Such a method includes receiving an indication of a second NF as a candidate client of the FL group in the communication network and obtaining an indication that the second NF is authorized to join the FL group as a client. The indication is based on registered authorization information. Such a method includes updating the FL group to include the second NF as the client based on the indication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates generally to the field of communication networks, and more specifically to techniques for protecting artificial intelligence / machine learning (AI / ML) models used to generate analytics in communication networks (e.g., 5G core networks). Background Art

[0002] Currently, the fifth generation (5G) cellular system, also known as New Radio (NR), is being standardized within the 3rd Generation Partnership Project (3GPP). NR is developed for maximum flexibility to support multiple, substantially different use cases. These use cases include enhanced mobile broadband (eMBB), machine type communications (MTC), ultra-reliable low latency communications (URLLC), sidelink device-to-device (D2D), and several other use cases.

[0003] At a high level, the 5G system (5GS) consists of an access network (AN) and a core network (CN). The AN provides connectivity to the CN for UEs, for example via base stations (such as gNB or ng-eNB described below). The CN includes various network functions (NFs) that provide a wide range of different functionalities, such as session management, connection management, billing, authentication, etc.

[0004] Figure 1 A high-level view of an exemplary 5G network architecture is shown, which consists of a next-generation radio access network (NG-RAN) 199 and a 5G core (5GC) 198. The NG-RAN 199 may include one or more gNodeBs (gNBs) connected to the 5GC via one or more NG interfaces, such as gNBs 100, 150 connected via interfaces (NG) 102, 152, respectively. More specifically, the gNBs 100, 150 may be connected to one or more access and mobility management functions (AMFs) in the 5GC 198 via respective NG-C interfaces. Similarly, the gNBs 100, 150 may be connected to one or more user plane functions (UPFs) in the 5GC 198 via respective NG-U interfaces. Various other network functions (NFs) may be included in the 5GC 198, as described in more detail below.

[0005] In addition, the gNBs may be connected to each other via one or more Xn interfaces, such as Xn interface 140 between gNBs 100 and 150. The radio technology of NG-RAN is generally referred to as "new radio" (NR). With respect to the NR interface to the UE, each gNB may support frequency division duplex (FDD), time division duplex (TDD), or a combination thereof. Each gNB may serve a geographic coverage area including one or more cells, and in some cases, may also use various directional beams to provide coverage in the corresponding cells.

[0006] NG-RAN 199 is layered into Radio Network Layer (RNL) and Transport Network Layer (TNL). The NG-RAN architecture (i.e., NG-RAN logical nodes and the interfaces between them) is defined as part of the RNL. For each NG-RAN interface (NG, Xn, F1), the relevant TNL protocols and functionality are specified. TNL provides services for user plane transport and signaling transport.

[0007] Figure 1 The NG RAN logical nodes shown in FIG. 1 include a central unit (CU or gNB-CU) and one or more distributed units (DU or gNB-DU). For example, gNB 100 includes gNB-CU 110 and gNB-DUs 120 and 130. CU (e.g., gNB-CU 110) is a logical node that hosts higher layer protocols and performs various gNB functions (such as controlling the operation of DU). DU (e.g., gNB-DU 120, 130) is a decentralized logical node that hosts lower layer protocols and may include various subsets of gNB functions according to functional partitioning options.

[0008] gNB-CU through the corresponding F1 logical interface (such as, Figure 1 The F1 interface is connected to one or more gNB-DUs (see interfaces 122 and 132 shown in FIG. 1 ). However, a gNB-DU can only be connected to a single gNB-CU. The gNB-CU and the connected gNB-DU(s) are visible only to other gNBs and the 5GC as a gNB. In other words, the F1 interface is not visible outside the gNB-CU.

[0009] Another change in 5G networks (e.g., in 5GC) is that the traditional peer-to-peer interfaces and protocols seen in earlier generations of networks are modified and / or replaced by a service-based architecture (SBA), where a network function (NF) provides one or more services to one or more service consumers. For example, this can be done through a hypertext transfer protocol / representational state transfer (HTTP / REST) ​​application programming interface (API). In general, various services are self-contained functionalities that can be changed and modified in an isolated manner without affecting other services.

[0010] In addition, services are composed of various "service operations", which are finer-grained segmentations of the overall service functionality. The interaction between service consumers and producers can be of "request / response" or "subscription / notification" type. In 5G SBA, the Network Repository Function (NRF) allows each network function to discover the services provided by other network functions, and the Data Storage Function (DSF) allows each network function to store its context. This 5G SBA model is based on the principles of modularity, reusability, and self-containment of NFs, which enables network deployments to take advantage of the latest virtualization and software technologies.

[0011] A 5GC NF of particular interest in this disclosure is the Network Data Analysis Function (NWDAF). This NF provides network analysis information (e.g., statistics of past events and / or prediction information) to other NFs at the network slice instance level. The NWDAF can collect data from any 5GC NF. Note that a "network slice" is a logical partition of a 5G network that provides specific network capabilities and features, e.g., to support a specific service. A network slice instance is a set of NF instances and the required network resources (e.g., compute, storage, communication) that provide the capabilities and features of a network slice.

[0012] Machine learning (ML) is a type of artificial intelligence (AI) that focuses on using data and algorithms to mimic the way humans learn, gradually improving accuracy as more data becomes available. ML algorithms build models based on sample (or "training") data, which are then used to make predictions or decisions. ML algorithms can be used in a wide variety of applications (e.g., medicine, email filtering, speech recognition, etc.) where it is difficult or infeasible to develop conventional algorithms to perform the desired tasks. A subset of ML is closely related to computational statistics.

[0013] Traditionally, AI models reside on cloud-based servers that also store training data. In contrast, federated learning (FL, also known as collaborative learning) trains ML models across multiple distributed edge devices that hold local data samples without exchanging training data between devices. Edge devices (e.g., clients) train their respective model copies using their own local data, and then send parameters / weights from their locally trained models to a master device (e.g., a server), which aggregates the parameters and updates the global ML model.

[0014] The 5G system architecture allows any NF to obtain analysis from the NWDAF using the Data Collection Coordination Function (DCCF) and the associated Ndccf services. The NWDAF can also store analysis information and retrieve analysis information from the Analysis Data Repository Function (ADRF). 3GPP TS23.288 (v17.2.0) specifies that the NWDAF is the main NF for ML model-based computational analysis and classifies the NWDAF into two sub-functions (or logical functions): the Analysis Logic Function (AnLF), which performs the analysis process; and the Model Training Logic Function (MTLF), which performs the training and retraining of the ML model used by the AnLF.

[0015] 3GPP TR 23.700-81 (v1.0.0) states that supporting FL in 5GC is a key topic for further study in 3GPP. This document states that ML model security is an important requirement for supporting FL in 5GC, especially between the corresponding NWDAF (MTLF) that will operate as FL client and server. In particular, the temporary ML model trained by the FL client and the final ML model derived by the FL server are important intellectual property rights of their owners and should be treated as such in 5GC.

[0016] Therefore, it is very important to authorize the NWDAF to participate in its corresponding FL role. However, the current authorization capabilities in the 3GPP SBA framework are not granular enough to provide this required level of security. Summary of the invention

[0017] Embodiments of the present disclosure address these and other problems, issues, and / or difficulties, thereby facilitating otherwise advantageous deployments of federated learning for network analytics.

[0018] Some embodiments of the present disclosure include a method (e.g., process) for configuring a first NF to operate as a server of an FL group in a communication network (e.g., 5GC).

[0019] These exemplary methods may include registering information associated with a FL group in a network repository function (NRF) of a communication network, the FL group including a first NF and one or more additional NFs configured to operate as clients in the FL group. The registered information includes authorization information for the additional NF to join the FL group as a client. These exemplary methods may also include receiving a first response including a first access token from the first NF. These exemplary methods may also include receiving an indication of a second NF of the communication network, the second NF being a candidate client of the FL group. These exemplary methods may also include obtaining an indication that the second NF is authorized to join the FL group as a client. The indication is based on the registered authorization information. These exemplary methods may also include updating the FL group to include the second NF as a client based on the indication.

[0020] In some embodiments, the registered authorization information includes one or more of the following: The identifier of the FL group owner; One or more identifiers associated with the target ML model for which the FL group performed training; and ●Indication of the scope of authorization of the FL group.

[0021] In some embodiments, the identifier of the FL group owner is an identifier associated with the first NF (i.e., the first NF is the owner of the FL group). In addition, the one or more identifiers associated with the target ML model include one or more of the following: interoperability ID, vendor ID, analysis ID, model filter, model URL, and model ID.

[0022] In some of these embodiments, the indication of the authorization scope of the FL group includes an indication or identifier of one or more of: ● one or more allowed requester and / or provider NF types; ● one or more allowed requester and / or provider NF IDs; ● One or more allowed requestor and / or provider NF providers; ● one or more allowed interoperability IDs; and ● Allowed FL capabilities.

[0023] In some embodiments, the first NF is a NWDAF and / or the second NF is a NWDAF.

[0024] Other embodiments include exemplary methods (eg, processes) for configuring a second NF to operate as a client of an FL group in a communication network (eg, 5GC).

[0025] In different embodiments, these exemplary methods may include a first set of operations or a second set of operations. Specifically, the first set of operations may include registering information about the FL capability of the second NF in an NRF of the communication network; and receiving a FL preparation request from the first NF configured to operate as a server of the FL group, the request including the following: ● interoperability information, indicating the capabilities required by the NF to participate in the FL group as a client, and - A second authorization token indicating that the first NF is an authorized server for the FL group. The first set of operations also includes sending a FL prepare response to the first NF, the FL prepare response indicating that the second NF accepts the FL prepare request.

[0026] In some of these embodiments, the first set of operations further comprises determining whether to join the FL group as a client based on: the second authorization token, and a comparison of the interoperability information with corresponding FL capabilities of the second NF. In such cases, the FL preparation response indicating that the second NF accepted the FL preparation request is based on the determination.

[0027] In other embodiments, the exemplary method may include a second set of operations including discovering the FL group and the first NF as a server of the FL group via the NRF; sending the FL join request to the first NF; and receiving an indication from the first NF that the first NF accepted the FL join request.

[0028] Other embodiments include methods (e.g., processes) for NRF of a communication network (e.g., 5GC).

[0029] These exemplary methods may include registering information associated with a FL group in a communication network. The FL group includes a first NF configured to operate as a server and one or more additional NFs configured to operate as clients. The registered information includes authorization information for the additional NF to join the FL group as a client.

[0030] In various embodiments, the registered authorization information may include any corresponding content and / or features outlined above in relation to the first NF embodiment. In some embodiments, the registered information associated with the FL group also includes an analysis identifier and an identifier of the FL group and / or an identifier of a FL process performed by the FL group.

[0031] In different embodiments, the exemplary method may further include a first set of operations or a second set of operations. The first set of operations includes registering information about FL capabilities of a second NF of the communication network, and sending an indication to the first NF that the second NF is a candidate client of the FL group.

[0032] In other embodiments, the second set of operations includes: during discovery by the second NF, notifying the second NF of the FL group and the first NF as a server of the FL group. In some of these embodiments, the second set may also include: receiving a request for an authorization token from the second NF, the authorization token indicating that the second NF is authorized to join the FL group as a client; and sending the requested authorization token to the second NF. In some variants, the authorization token includes at least a portion of the registered authorization information.

[0033] Other embodiments include NFs (e.g., NWDAFs, NRFs) or network nodes hosting these NFs, which are configured to perform operations corresponding to any of the exemplary methods described herein. Other embodiments also include non-transitory computer-readable media storing computer-executable instructions that, when executed by a processing circuit, configure such NFs or network nodes to perform operations corresponding to any of the exemplary methods described herein.

[0034] These and other disclosed embodiments may prevent unauthorized NFs (e.g., NWDAFs) from joining a FL group as a client and / or prevent NFs from joining a group as a client to perform fraudulent and / or inauthentic FL operations. In this way, embodiments may prevent confidential and / or sensitive ML models from being exposed to unauthorized parties during FL, and may prevent security risks to NFs that may participate in FL. By improving security, embodiments facilitate deployment of FL in multi-vendor communication networks such as 5GC.

[0035] These and other objects, features and advantages of the present disclosure will become apparent after reading the following "Detailed Description" in view of the accompanying drawings which are briefly described below. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1-2 Various aspects of an exemplary 5G network architecture are shown.

[0037] Figure 3 A high-level diagram showing the client NWDAF selection process during the FL preparation phase.

[0038] Figure 4 A high-level diagram showing the client NWDAF monitoring and reselection process during the FL execution phase.

[0039] Figure 5-6 A high-level diagram showing the two processes of dynamically discovering and adding new NWDAF(s) in the FL execution phase.

[0040] Figure 7 A signaling diagram illustrating processes involving a server NWDAF, an NRF, and various client NWDAFs according to various embodiments of the present disclosure.

[0041] Figure 8 An exemplary method (eg, process) for a first NF of a communication network according to various embodiments of the present disclosure is illustrated.

[0042] Fig. 9 An exemplary method (eg, process) for a second NF of a communication network according to various embodiments of the present disclosure is illustrated.

[0043] Fig.10An exemplary method (eg, process) for an NRF of a communication network according to various embodiments of the present disclosure is shown.

[0044] Fig.11 A communication system according to various embodiments of the present disclosure is shown.

[0045] Fig.12 A UE according to various embodiments of the present disclosure is shown.

[0046] Fig.13 A network node according to various embodiments of the present disclosure is shown.

[0047] Fig.14 A host computing system according to various embodiments of the present disclosure is shown.

[0048] Fig.15 is a block diagram of a virtualization environment in which the functionality implemented by some embodiments of the present disclosure may be virtualized.

[0049] Fig.16 Communications between a host computing system, a network node, and a UE via multiple connections are shown according to various embodiments of the present disclosure. DETAILED DESCRIPTION

[0050] The embodiments briefly summarized above will now be described more fully with reference to the accompanying drawings. These descriptions are provided by way of example to explain the subject matter to those skilled in the art and should not be construed as limiting the scope of the subject matter to only the embodiments described herein. More specifically, examples are provided below that illustrate the operation of various embodiments in accordance with the advantages discussed above.

[0051] In general, all terms used herein should be interpreted according to their ordinary meanings in the relevant technical field, unless different meanings are clearly given and / or different meanings are implied from the context in which it is used. All references to a (a / an) / the element, device, assembly, part, step, etc. should be exposed and interpreted as referring to at least one instance of the element, device, assembly, part, step, etc., unless otherwise clearly stated. The steps of any method and / or process disclosed herein do not have to be performed in the exact order disclosed, unless a certain step is clearly described as following or being followed by another step and / or implying that a certain step must be followed by or being followed by another step. Any feature of any embodiment disclosed herein can be applied to any other embodiment where appropriate. Similarly, any advantage of any embodiment can be applied to any other embodiment, and vice versa. Other purposes, features and advantages of the disclosed embodiments will be understood from the following description.

[0052] In addition, the following terms are used throughout the specification as given below: ● Radio access node: As used herein, a "radio access node" (or equivalently, a "radio network node", "radio access network node" or "RAN node") may be any node in a radio access network (RAN) of a cellular communication network that operates to transmit and / or receive signals wirelessly. Some examples of radio access nodes include, but are not limited to, base stations (e.g., new radio (NR) base stations (gNBs) in 3GPP fifth generation (5G) NR networks or enhanced or evolved Node Bs (eNBs) in 3GPP LTE networks), base station distributed components (e.g., CUs and DUs), high power or macro base stations, low power base stations (e.g., micro base stations, pico base stations, femto base stations or home base stations or the like), integrated access backhaul (IAB) nodes (or components thereof, such as MTs or DUs), transmission points, remote radio units (RRUs or RRHs), and relay nodes. ● Core network node: As used herein, a "core network node" is any type of node in a core network. Some examples of core network nodes include, for example, a mobility management entity (MME), a serving gateway (SGW), a packet data network gateway (P-GW), etc. A core network node may also be a node that implements a specific core network function (NF), such as an access and mobility management function (AMF), a session management function (AMF), a user plane function (UPF), a service capability exposure function (SCEF), or the like. ● Wireless device: As used herein, a "wireless device" (or "WD" for short) is any type of device capable of, configured to, arranged to, and / or operable to wirelessly communicate with a network node and / or other wireless devices. Wireless communication may involve the use of electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information through the air to transmit and / or receive wireless signals. Unless otherwise specified, the term "wireless device" may be used interchangeably herein with the term "user equipment" (or "UE" for short), both of which have different meanings from the term "network node". • Radio node: As used herein, a "radio node" may be a "radio access node" (or equivalent terms) or a "wireless device". ● Network node: As used herein, a "network node" is any node that is part of a radio access network (e.g., a radio access node or equivalent term) or a core network (e.g., the core network node described above) of a cellular communication network. Functionally, a network node is a device capable of, configured to, arranged to, and / or operable to communicate directly or indirectly with a wireless device and / or with other network nodes or devices in a cellular communication network for enabling and / or providing wireless access to a wireless device, and / or performing other functions (e.g., management) in a cellular communication network. ●Node: As used herein, the term “node” (without any prefix) may be any type of node capable of operating in or with a wireless network (including the RAN and / or the core network), including a radio access node (or equivalent terms), a core network node, or a wireless device.

[0053] Note that the description given herein focuses on 3GPP cellular communication systems, and therefore, 3GPP terminology or terms similar to 3GPP terminology are generally used. However, the concepts disclosed herein are not limited to 3GPP systems. Other wireless systems (including but not limited to Wideband Code Division Multiple Access (WCDMA), Worldwide Interoperability for Microwave Access (WiMax), Ultra Mobile Broadband (UMB), and Global System for Mobile Communications (GSM)) may also benefit from the concepts, principles, and / or embodiments described herein.

[0054] In addition, the functions and / or operations performed by a wireless device or network node described herein may be distributed across multiple wireless devices and / or network nodes. In addition, although the term "cell" is used herein, it should be understood (particularly for 5GNR) that a beam may be used instead of a cell, and therefore, the concepts described herein are equally applicable to cells and beams.

[0055] Figure 2 An exemplary non-roaming reference architecture of 5GC 200 is shown, which has a service-based interface and various 3GPP-defined NFs within the control plane (CP). These NFs include the following NFs: The Application Function (AF, with the Naf interface) interacts with the 5GC to provision information to the network operator and to subscribe to certain events occurring in the operator's network. The AF supplies control of flow resources for applications targeted for delivery of services in a layer different from the layer where the requested service is located (i.e., the transport layer) (based on what has been negotiated with the network). The AF passes dynamic session information to the PCF (via the N5 interface), including a description of the media to be delivered by the transport layer. ● Policy Control Function (PCF, with Npcf interface) supports a unified policy framework to govern network behavior (by providing PCC rules (e.g., regarding the handling of each service data flow under PCC control) to the SMF via the N7 reference point). The PCF provides policy control decisions and flow-based charging control to the SMF, including service data flow detection, gating, QoS, and flow-based charging (except credit management). The PCF receives session and media-related information from the AF and notifies the AF of service (or user) plane events. ● User Plane Function (UPF) - supports handling of user plane traffic based on rules received from the SMF, including packet inspection and different enforcement actions (e.g., event detection and reporting). The UPF communicates with the RAN (e.g., NG-RNA) via the N3 reference point, with the SMF (described below) via the N4 reference point, and with external packet data networks (PDNs) via the N6 reference point. The N9 reference point is used for communication between two UPFs. ●Session Management Function (SMF, with Nsmf interface) interacts with the decoupled service (or user) plane, including creating, updating and removing protocol data unit (PDU) sessions and managing session context for the user plane function (UPF), such as for event reporting. For example, SMF performs data flow detection (based on filter definitions contained in PCC rules), online and offline charging interactions, and policy enforcement. The Charging Function (CHF, with Nchf interface) is responsible for merging online and offline charging functionality. It provides quota management (for online charging), re-authorization triggers, ranking conditions, etc., and receives notifications about usage reports from the SMF. Quota management involves granting a specific number of units (e.g. bytes, seconds) for a service. The CHF also interacts with the charging system. ● Access and Mobility Management Function (AMF, with Namf interface) terminates the RAN CP interface and handles all mobility and connection management of the UE (similar to the MME in EPC). The AMF communicates with the UE via the N1 reference point and with the RAN (e.g., NG-RAN) via the N2 reference point. ● Network Exposure Function (NEF) with Nnef interface - acts as an entry point into the operator network (by securely exposing network capabilities and events provided by 3GPP NFs to the AF, and by providing a way for the AF to securely provide information to the 3GPP network). For example, the NEF provides services that allow the AF to pre-configure specific subscription data (e.g., expected UE behavior) for various UEs. • Network Repository Function (NRF, 220) with Nnrf interface - provides service registration and discovery, enabling NFs to identify appropriate services available from other NFs. ● Network Slice Selection Function (NSSF) with Nnssf interface - A "network slice" is a logical partition of a 5G network that provides specific network capabilities and features, e.g. to support a specific service. A network slice instance is a set of NF instances and required network resources (e.g. compute, storage, communication) that provide the capabilities and features of a network slice. NSSF enables other NFs (e.g. AMF) to identify a network slice instance that is suitable for a UE's desired service. ●Authentication Server Function (AUSF) with Nausf interface - located in the user's home network (HPLMN), it performs user authentication and calculates security key material for various purposes. - Network Data Analysis Function (NWDAF, 210) with Nnwdaf interface - described in more detail above and below. ● Location Management Function (LMF) with Nlmf interface - supports various functions related to determining the UE location, including UE location determination and obtaining any of the following: DL location measurement or location estimate from the UE; UL location measurement from the NGRAN; and non-UE associated assistance data from the NGRAN.

[0056] The Unified Data Management (UDM) function supports the generation of 3GPP authentication credentials, user identity handling, access authorization based on subscription data, and other subscription-related functions. To provide this functionality, UDM uses subscription data (including authentication data) stored in the 5GC Unified Data Repository (UDR). In addition to UDM, UDR also supports the storage and retrieval of policy data by PCF and the storage and retrieval of application data by NEF.

[0057] NRF allows each NF to discover services provided by other NFs, and the Data Storage Function (DSF) allows each NF to store its context. In addition, NEF also provides exposure of 5GC capabilities and events to AFs inside and outside the 5GC. For example, NEF provides services that allow AFs to preconfigure specific subscription data (e.g., expected UE behavior) for various UEs.

[0058] The communication link between the UE and the 5G network (AN and CN) can be grouped into two different layers. The UE communicates with the CN via the non-access stratum (NAS) and with the AN via the access stratum (AS). All NAS communications are carried out via the NAS protocol ( Figure 2 The N1 interface in the UE is between the UE and the AMF. The communication security at these levels is provided by the NAS protocol (for NAS) and the PDCP protocol (for AS).

[0059] 3GPP Rel-17 enhances SBA by adding a data management framework, which includes a data collection coordination function (DCCF) and a messaging framework adapter function (MFAF), which are defined in detail in 3GPP TR 23.700-91 (v17.0.0). The data management framework is backward compatible with the Rel-16 NWDAF functions described above. For Rel-17, the baseline for the services provided by the DCCF (e.g., to the NWDAF) is the Rel-16 NF services for obtaining data. For example, the baseline for the DCCF service used by the NWDAF consumer to obtain UE mobility data is Namf_EventExposure.

[0060] As briefly mentioned above, machine learning (ML) is a type of artificial intelligence (AI) that focuses on using data and algorithms to mimic the way humans learn, gradually improving accuracy as more data becomes available. ML algorithms build models based on sample (or "training") data, which are then used to make predictions or decisions. ML algorithms can be used in a wide variety of applications (e.g., medicine, email filtering, speech recognition, etc.) where it is difficult or infeasible to develop conventional algorithms to perform the required tasks.

[0061] 3GPP TS23.288 (v17.2.0) specifies that NWDAF is the main NF for ML model-based computational analysis, and classifies NWDAF into two sub-functions (or logical functions): an analysis logic function (AnLF), which performs the analysis process; and a model training logic function (MTLF), which performs training and retraining of the ML model used by AnLF. In the following, the terms "AnLF", "NWDAF AnLF" and "NWDAF (AnLF)" will be used interchangeably. Similarly, the terms "MTLF", "NWDAFMTLF" and "NWDAF (MTLF)" will also be used interchangeably.

[0062] 3GPP TS23.288 (v17.2.0) specifies a subscription / notification procedure for a consumer NF to retrieve the ML model(s) associated with one or more analysis IDs whenever a new ML model has been trained by the NWDAF MTLF and becomes available. This is called ML model provisioning and is implemented by the Nnwdaf_MLModelProvision service.

[0063] Traditionally, ML models are trained on cloud-based servers that also store training data. In contrast, federated learning (FL, also known as collaborative learning) trains ML models across multiple distributed edge devices that hold local data samples without exchanging training data between devices. Edge devices (e.g., clients) train their respective model copies using their own local data, and then send parameters / weights from their locally trained models to a master device (e.g., a server), which aggregates the parameters and updates the global ML model.

[0064] 3GPP TR 23.700-81(v1.0.0) states that supporting FL in 5GC is a key topic for further study in 3GPP. This document states that ML model security is an important requirement for supporting FL in 5GC, especially between the corresponding NWDAF (MTLF) that will operate as FL client and server. The following text from 3GPP TR 23.700-81(v1.0.0) describes various aspects of this key topic that needs to be studied. *** Start 3GPP text *** 5.8.1 Description This contribution is related to WT#4.1. NWDAF still faces some major challenges as a current enabler of network automation architecture: ●User data privacy and security (protected by, for example, GDPR) has become a global issue, and it is difficult for NWDAF to collect UE-level network data. ● With the introduction of MTLF in Rel-17, various data from a wide area are needed to train ML models for NWDAF containing MTLF. However, it is difficult for NWDAF containing MTLF to collect all raw data from distributed data sources in different areas. To address these challenges, 3GPP attempts to adopt federated learning (also known as federated machine learning) technology in NWDAFs containing MTLF to train ML models, where original data transmission (e.g., centralized to NWDAF) is not required, but only cooperation between multiple NWDAFs (MTLFs), that is, sharing ML models and learning results between multiple NWDAFs (MTLFs). However, in Rel-17, cooperation between multiple NWDAFs containing MTLFs is explicitly prohibited, and only NWDAFs containing AnLF are allowed to subscribe or request ML models from configured NWDAFs containing MTLFs. This key topic aims to study architectural enhancements to support federated learning, which allows multiple NWDAFs including MTLF to cooperate to train ML models in 3GPP networks, with the following aspects: ●Identify use cases in 5GC that require federated learning; ● Research on the registration and discovery of NWDAFs that support federated learning; ● Research how to determine whether federated learning is required for existing or new analysis IDs; ● Study how to coordinate multiple NWDAFs, including the selection of participant NWDAF instances in a joint learning group, e.g., assistance information for performing said selection (if any), and role decisions of participant NWDAFs; ● Study whether and how to perform performance (e.g., network performance and model performance) monitoring on NWDAF federated learning operations. NOTE 1: Performance monitoring of federated learning operations should be consistent with the mechanisms for improving analysis correctness defined in WT#1.2 NOTE 2: Collaboration with SA3 is required for improvements in user data privacy and security. Note 3: For this key issue, the impact on UE and RAN should be avoided. NOTE 4: The solution requiring model distribution of FL should be consistent with the model sharing mechanism defined in WT#3.2 NOTE 5: The server NWDAF is connected to one layer of the client NWDAF, and any client NWDAF cannot cascade more sub-layers. NOTE 6: All NWDAFs participating in the joint learning should belong to the same PLMN. ***END OF 3GPP TEXT***

[0065] Some candidate solutions for participant NWDAF discovery and selection are described in 3GPP TR 23.700-81 (v1.0.0). One of these solutions ("Solution #51") is described in the following text in 3GPP TR 23.700-81 (v1.0.0): ***BEGIN 3GPP TEXT*** 6.51.1 Description This solution is proposed to address key issue #8: Supporting federated learning in 5GC. The key research points of this key issue include: - Study how to coordinate multiple NWDAFs, including the selection of participant NWDAF instances in a joint learning group, e.g., assistance information for performing said selection (if any) and role decisions of participant NWDAFs. - Study whether and how to perform performance (e.g., network performance and model performance) monitoring on NWDAF federated learning operations. To address the challenges in the above points of supporting federated learning in 5GC, the solution focuses on (one or more) NWDAF selection in the federated learning preparation phase, (one or more) NWDAF monitoring and maintenance in the federated learning execution phase. In the federated learning preparation phase, many factors affect the selection of (one or more) client NWDAFs, such as the capabilities of (one or more) NWDAFs, the interoperability and availability of (one or more) client NWDAFs to join the federated learning. In the joint learning execution phase, due to the dynamic changes of the joint network, the current (one or more) client NWDAF may leave or join, and the dynamic joining and leaving of (one or more) client NWDAFs in the joint learning multi-round learning / training process in 5GC should be considered. In addition, a method can be applied so that the server NWDAF monitors the state changes (e.g., changes in capabilities and availability) of (one or more) client NWDAFs. ***END OF 3GPP TEXT***

[0066] In the FL preparation phase, servers and (potential) client NWDAFs are discovered via NRFs, and client NWDAF(s) are selected by means of a handshake mode. The selection of client NWDAF(s) is based on availability, capabilities, etc. Figure 3 A high-level diagram of the client NWDAF selection process during the FL preparation phase is shown. Figure 3 The operations in are given numerical labels, but this is intended to facilitate the following description and is not intended to require or imply any particular order of operations unless explicitly stated otherwise.

[0067] In operation 0 (which can be considered as preparation), the NWDAF registers with the NRF with FL capability. The server NWDAF discovers the client NWDAF based on, for example, FL capability, analysis ID, etc.

[0068] In operation 1, the server NWDAF sends a FL preparation request to the (one or more) client NWDAFs by calling the Nnwdaf_MLPreparation_Request service operation with interoperability information. The preparation request may include a role indication of the (one or more) NWDAFs, i.e., as (one or more) client NWDAFs. Note that the interoperability information indicates what capabilities (e.g., ability to run certain models) are required for the client NWDAF to support this FL process, for example, whether the server NWDAF and the client NWDAF can share models and how to share models. The interoperability information is determined between different vendors and its content is not specified by 3GPP.

[0069] In operation 2, the client NWDAF(s) determine whether to join the FL process based on their respective availability, capabilities and interoperability information. In operation 3, one or more client NWDAFs respond to the server NWDAF indicating that they want to join the FL process.

[0070] In operation 4, the server NWDAF may send a test task to the (one or more) client NWDAFs that want to join the FL process. The (one or more) client NWDAFs run the test task and send the results to the server NWDAF. Note that the test task may be a micro-computation or training task, so that the requirements for completing the micro-task are the same or similar to those for the main task. For example, the test task may be a small task that lets the client NWDAF collect local data and send local model weights back to the server; or a test to ensure that the server and client NWDAF can communicate when they use the same FL framework or library. How to retrieve and run the test task is beyond the scope of the 3GPP specification.

[0071] In operation 5 , the server NWDAF selects (one or more) client NWDAFs for the FL (as needed and / or desired taking into account the results of the test task).

[0072] In the FL execution phase, the server NWDAF monitors the status changes of (one or more) client NWDAFs. (One or more) client NWDAFs may be reselected for FL tasks based on the updated status, availability and / or capabilities of (one or more) client NWDAFs. Figure 4 A high-level diagram for the NWDAF monitoring and reselection process during the FL execution phase is shown. Figure 4 The operations in are given numerical labels, but this is intended to facilitate the following description and is not intended to require or imply any particular order of operations unless explicitly stated otherwise.

[0073] In operation 1, when monitoring the status of (one or more) client NWDAFs during FL execution, the server NWDAF receives the updated status of (one or more) client NWDAFs. The server NWDAF may perform monitoring and obtain (e.g., receive) the updated status of (one or more) client NWDAFs directly and / or via the NRF. For example, the status of the client NWDAF may be NF load, NF availability, capability change (e.g., no longer supporting FL), etc.

[0074] In operation 2, the server NWDAF checks the status of the client NWDAF(s) based on the received information and determines whether it is necessary to reselect the client NWDAF(s) for the next round(s) of FL. The determination is based on the updated status of the client NWDAF(s), including availability, capability, etc. If it is determined that reselection is required, in operation 3, the server NWDAF selects the client NWDAF(s) based on the received information. Figure 3 To reselect (one or more) client NWDAFs, perform steps 1-5 in the following. Figure 5The process for discovering (one or more) new clients NWDAF in the FL execution phase is described below.

[0075] In operation 4, if the client NWDAF(s) receive a termination request from the server NWDAF, the client NWDAF(s) terminate the operation for the FL.

[0076] For the server NWDAF, there are two possible ways to obtain information about the new client NWDAF(s): directly from the new client, or indirectly via the NRF.

[0077] Figure 5 A high-level diagram of the process for dynamically discovering and joining new NWDAF(s) when a new client directly notifies the server NWDAF during the FL execution phase is shown. Figure 5 The operations in are given numerical labels, but this is intended to facilitate the following description and is not intended to require or imply any particular order of operations unless explicitly stated otherwise.

[0078] As a prerequisite, the server NWDAF selects the client NWDAF 1-N to participate in the current round of FL. New clients NWDAF N+(1-X) are available and / or capable of joining the subsequent round of FL. These new clients NWDAF know information about the server NWDAF. In operation 0, the server NWDAF registers the FL process with the NRF with the following parameters: ● FL association ID, which is used to identify a specific FL process. For example, a server NWDAF or a client NWDAF can be part of multiple FL processes at the same time, so when they receive messages or data from other NWDAFs, they must know the FL process associated with the message or data. ●Analysis ID.

[0079] When the server NWDAF starts the FL process, it registers the FL process in the NRF with the FL association ID and analysis ID. When the client NWDAF later wants to dynamically join the FL (for example, it wants to update its local model with global information), it will query the NRF if there is an ongoing FL for the analysis ID. The NRF will then provide the server NWDAFID and the FL association ID to the client NWDAF, and the client NWDAF can then contact the server NWDAF to join the FL process. With the FL association ID, the server NWDAF knows which FL process the client NWDAF wants to join and which model it should provide to the client.

[0080] In operation 1, if the information about the server NWDAF and the corresponding FL process is known via the NRF, the new client NWDAF N+(1-X) informs the server NWDAF by calling the Nnwdaf_MLPreparation_Request service operation indicating its interoperability and availability information.

[0081] In operation 2, before starting the next round of training, the server NWDAF selects (one or more) client NWDAFs from NWDAF 1-(N+X) based on the updated information of (one or more) client NWDAFs. Figure 3 Perform the process by following steps 1-5 in the procedure.

[0082] Figure 6 A high-level diagram shows the process for dynamically discovering and joining new NWDAF(s) in the FL execution phase when the server NWDAF obtains information about the NWDAFs from the NRF. Figure 6 The operations in are given numerical labels, but this is intended to facilitate the following description and is not intended to require or imply any particular order of operations unless explicitly stated otherwise.

[0083] As a prerequisite, the client NWDAF 1-N has been selected by the server NWDAF to participate in the current round of FL. New clients NWDAF N+(1-X) are available and / or capable of joining the subsequent round of FL. Operation 0 and Figure 5 The same as operation 0 of . In operation 1, the server NWDAF dynamically obtains information about (one or more) new client NWDAFs via the NRF, i.e., by subscribing to events of new client NWDAFs registering with the NRF, or discovering new client NWDAFs via the NRF when it needs to perform reselection of client NWDAFs. Operation 2 is the same as Figure 5 The operation is the same as 2.

[0084] The temporary ML model trained by the FL client and the final ML model derived by the FL server are important intellectual property rights of their owners and should be treated as such in 5GC. Therefore, it is very important to authorize NWDAF to participate in its corresponding FL role. For example, if a client NWDAF instance joins an unauthorized FL group, the following security threats and / or issues may result: ●The resources of the client NWDAF (MTLF) may be exhausted by being included in many unauthorized FL groups. ●Sensitive data can be used to train ML models by unauthorized FL groups. • An unauthorized FL group can exploit the local model received from the client NWDAF (MTLF) to infer sensitive training data details.

[0085] Similarly, if the client NWDAF joins the FL group without authorization by the server NWDAF, it may lead to the following security threats and / or issues: ● Unauthorized client NWDAF can negatively impact ML model generation by the FL group. ●Sensitive training data and ML models of the FL group can be exposed to unauthorized clients NWDAF.

[0086] Therefore, it is necessary to selectively authorize the participant NWDAF instances in the FL group. Specifically, the client NWDAF should be able to authorize the server NWDAF whether it can be included in the FL group, and the server NWDAF should be able to authorize the client NWDAF whether it can join the FL group. However, the current authorization capabilities in the 3GPP SBA framework only support authorization at the SBA service, resource or operation level, which is not fine enough to ensure that the server and client NWDAF are authorized to participate in the FL process, and / or the FL process provided is authentic and / or does not pose a security threat to potential participants.

[0087] Embodiments of the present disclosure solve these and other problems, issues and / or difficulties through the following techniques: The server NWDAF provides an authorization profile for a specific FL group, which enables the issuance of a token for the authorization profile, wherein the token authorizes the client NWDAF to join the FL group. In addition, based on a request from the client NWDAF to join the FL group, the server NWDAF retrieves the NF profile of the client NWDAF from the NRF, based on which the server NWDAF authorizes the client NWDAF to join the FL group.

[0088] More specifically, it is expected that authorization of a participant NWDAF may occur at the time of initial creation of a FL group, or when a participant NWDAF joins an existing FL group and an ongoing training process. For embodiments related to initial creation of a FL group, it is expected that a server NWDAF creates a FL group by discovering and selecting a client NWDAF via an NRF. Based on the trust between the server NWDAF and the NRF, discovery of the client NWDAF via the NRF provides an implicit indication to the server NWDAF that the discovered client NWDAF is authorized to participate in the FL process. Similarly, the server NWDAF obtains an SBA OAuth token to invoke a FL service request to the discovered client NWDAF, and the discovered client NWDAF authorizes the server NWDAF based on receiving the token with the FL service request.

[0089] For embodiments related to a new client NWDAF joining an existing / ongoing FL group, there are two variants. In one variant, the server NWDAF becomes aware of the new client NWDAF via NRF discovery or notification and invites the new client NWDAF to join the FL group. The authorization method for server / client participants is the same as the initial process.

[0090] In another variant, the client NWDAF detects an ongoing FL group and an associated server NWDAF (e.g., via an NRF) and proactively sends a join request to the server NWDAF. The client NWDAF obtains the SBA Oauth token for joining the FL group from the NRF and includes the token in the join request. The NRF issues a token to the client NWDAF based on the authorization of the FL group, and the client NWDAF has been registered in the NRF by the server NWDAF when the FL group was created. Based on the token received with the join request, the server NWDAF authorizes the client NWDAF to join the FL group. Alternatively, the server NWDAF retrieves the NF profile of the client NWDAF from the NRF and performs authorization based on this information.

[0091] The client NWDAF may authorize the server NWDAF in various ways. In some variants, the client NWDAF may implicitly authorize the server NWDAF based on receiving a join response and FL group related information from the server NWDAF. In other variants, the client NWDAF may include a token in the join request, which is used by the server NWDAF in subsequent messages inviting the client NWDAF to join the FL group. These variants may be similar to embodiments related to the initial creation of the FL group.

[0092] Embodiments of the present disclosure may provide various benefits and / or advantages. For example, embodiments may prevent unauthorized NFs (e.g., NWDAFs) from joining a FL group as a client and / or prevent NFs from joining a group as a client to perform fraudulent and / or unauthentic FL operations. In this way, embodiments may prevent confidential and / or sensitive ML models from being exposed to unauthorized parties during FL, and may prevent security risks to NFs that are able to participate in FL. Therefore, embodiments improve the security of FL in a multi-vendor communication network (such as 5GC), and thereby facilitate the deployment of the FL.

[0093] Figure 7 1 shows a signaling diagram of a process involving a server NWDAF 710, an NRF 720, client NWDAFs 1-N (collectively referred to as 730), and a client NWDAF X 740 according to various embodiments of the present disclosure. Figure 7The operations shown in the drawings are given numerical labels, but this is intended to facilitate explanation and does not require or imply any particular order of operations unless otherwise specified below.

[0094] In operations 0a-b, the server NWDAF and the client NWDAF 1-N register their respective NF profiles in the NRF, including FL capabilities, interoperability IDs, (one or more) analysis IDs, etc. In operation 1, the server NWDAF discovers the client NWDAF 1-N via the NRF based on the FL selection criteria. For example, the client NWDAF FL capabilities, interoperability IDs, (one or more) analysis IDs, etc. match the corresponding values ​​of the server NWDAF. In addition, the server NWDAF requests a token for each discovered client NWDAF from the NRF, and the NRF grants the token based on the information in the corresponding client NWDAF NF profile.

[0095] In operation 2, the server NWDAF sends a FL preparation request to the client NWDAFs 1-N by calling the Nnwdaf_MLPreparation_Request service operation (with interoperability information and corresponding token). The FL preparation request may include a role indication of the (one or more) NWDAFs, i.e., as (one or more) client NWDAFs. Note that the interoperability information indicates what capabilities are required for the client NWDAFs (e.g., to run certain models) to support this FL process, such as whether the server NWDAF and the client NWDAF can share models and how to share models.

[0096] In operation 3, the client NWDAFs 1-N verify that the server NWDAF is authorized to form a FL group based on the token, and determine whether to join the FL group based on their respective availability, capabilities, and interoperability information. In operation 4, the client NWDAFs 1-N respond to the server NWDAF, indicating that they want to join the FL group. In operation 5, the server NWDAF selects one or more of the client NWDAFs based on a local policy to form a FL group.

[0097] In operation 6, the server NWDAF registers or updates its registration in the NRF to contain information about the formed FL group, including the following: ●FL association ID or FL group ID, as described above Figure 5 as described; ●Analysis ID; or ● Authorization information for joining the FL group, including one or more of the following items: o FL Group Owner ID (eg, server NWDAF). ○ One or more identifiers associated with the target model, such as an interoperability ID, vendor ID, analysis ID, ML model filter, model URL, model ID, etc., or ○ The scope of authorization shall include one or more of the following: ■ the allowed requester and / or provider NF type(s), ■ allowed requester and / or provider NF ID(s), ■ allowed requester(s) and / or provider NF providers, ■ the allowed interoperability ID(s), or ■ Allowed FL capability(s). In some embodiments, the NRF may verify that the authorization information that the server NWDAF is registering is authentic, for example, the FL group owner ID is correct and the same as the ID of the registration server NWDAF.

[0098] Subsequently, the new client NWDAF X joins the FL group according to different embodiments described below. In some embodiments, in operation 7a, the new client NWDAF X registers with the NRF in a similar manner to the existing clients NWDAF 1-N in operation 0b. In operation 8a, the server NWDAF obtains information about the new client NWDAF X via the NRF, for example, by subscribing to a registration event of the new client NWDAF, or by discovering the new client NWDAF via the NRF when the server NWDAF determines that one or more client NWDAFs need to be reselected. In operation 9a, the server NWDAF repeats the above operations 2-4 to include the new client NWDAF into the FL group.

[0099] In other embodiments, in operation 7b, the new client NWDAF discovers the FL group and the corresponding server NWDAF via the NRF. In operation 8b, the client NWDAF requests a token from the NRF to join the discovered FL group and the server NWDAF, the token including the requesting client information corresponding to the authorization information of the FL group registered by the server NWDAF in operation 6. The NRF grants the token request based on the correspondence between the client information and the authorization information of the FL group registered by the server NWDAF. The NRF generates a token ("token1"), which may include the same or similar information as the registered authorization information, such as: ●FL association ID or FL group ID, as described above Figure 5 as described; ●Analysis ID; and / or • Authorization information to join the FL group, such as listed above.

[0100] In operation 9b, the client NWDAF X sends a FL join request to the server NWDAF, including the obtained token 1. In operation 10b, the server NWDAF determines whether the client NWDAF is authorized to join the ongoing FL group based on the received token 1. Based on the positive determination in operation 10b, the server NWDAF responds to the new client NWDAF X in operation 11b, indicating that it accepts the FL join request from the client NWDAF.

[0101] In a variation of operations 8b-10b, the client NWDAF sends a FL join request without a token. The server NWDAF retrieves the NF profile of the client NWDAF from the NRF and determines whether the client NWDAF is authorized to join the ongoing FL group based on the retrieved NF profile.

[0102] Although the embodiments have been described above in the specific context of an NWDAF arranged as a client or server, the skilled person will understand that the basic principles of the above embodiments are equally applicable to other NFs, logical functions, nodes, etc. (e.g., with different names) that perform similar operations as these corresponding entities.

[0103] The above embodiments can be referred to Figure 8-10 It is further shown that Figure 8-10 Exemplary methods (eg, processes) for the first NF, the second NF, and the NRF are depicted, respectively. In other words, various features of the operations described below correspond to the various embodiments described above. Figure 8-10 The exemplary methods described in the examples can be used in conjunction (e.g., with each other and with other processes described herein) to provide benefits, advantages, and / or solutions to the problems described herein. Figure 8-10 Although the exemplary method is shown in a specific order of specific blocks in the figure, the operations corresponding to these blocks can be performed in a different order than shown, and can be combined and / or divided into blocks and / or operations with different functionality than shown. Optional blocks and / or operations are indicated by dashed lines.

[0104] More specifically, Figure 8 An exemplary method (e.g., process) for configuring a first NF to operate as a server of an FL group in a communication network (e.g., 5GC) according to various embodiments of the present disclosure is shown. Figure 8 The exemplary method shown in may be performed by a FL server such as an NWDAF (or a logical function thereof, such as an MTLF) or a network node hosting an NWDAF (such as described elsewhere herein).

[0105] The exemplary method may include an operation of block 820, wherein the first NF may register information associated with a FL group in an NRF of a communication network, the FL group including the first NF and one or more additional NFs configured to operate as clients in the FL group. The registered information includes authorization information for the additional NF to join the FL group as a client. The exemplary method may also include an operation of block 830, wherein the first NF may receive an indication of a second NF of the communication network, the second NF being a candidate client of the FL group. The exemplary method may also include an operation of block 840, wherein the first NF may obtain an indication that the second NF is authorized to join the FL group as a client. The indication is based on the registered authorization information. The exemplary method may also include an operation of block 890, wherein, based on the indication, the first NF may update the FL group to include the second NF as a client.

[0106] In some embodiments, the registered authorization information includes one or more of the following: The identifier of the FL group owner; One or more identifiers associated with the target ML model for which the FL group performed training; and ●Indication of the scope of authorization of the FL group.

[0107] In some of these embodiments, the identifier of the FL group owner is an identifier associated with the first NF (i.e., the first NF is the FL group owner). In addition, the one or more identifiers associated with the target ML model include one or more of the following: an interoperability ID, a vendor ID, an analysis ID, a model filter, a model URL, or a model ID.

[0108] In some of these embodiments, the indication of the authorization scope of the FL group includes an indication or identifier of one or more of: ● one or more allowed requester and / or provider NF types; ● one or more allowed requester and / or provider NF IDs; ● One or more allowed requestor and / or provider NF providers; ● one or more allowed interoperability IDs; or ● Allowed FL capabilities.

[0109] In some embodiments, the indication that the second NF is a candidate client of the FL group is a notification received from the NRF, the notification being based on the subscription of the first NF to a registration event of a candidate client of the FL group. In addition, the indication that the second NF is authorized to join the FL group as a client is one of: implicit based on receiving the notification from the NRF; or an explicit authorization token received with the notification.

[0110] In some of these embodiments, based on the indication that the second NF is authorized to join the FL group, the exemplary method may further include operations of blocks 850-855. In block 850, the first NF may send a FL preparation request to the second NF, the request including the following: ● interoperability information indicating the capabilities required by the NF to participate in the FL group as a client; and - A second authorization token indicating that the first NF is an authorized server for the FL group. In block 855, the first NF may receive a FL prepare response from the second NF, the FL prepare response indicating that the additional NF has accepted the FL prepare request. Updating the FL group to include the second NF as a client in block 890 is based on the FL prepare response.

[0111] In other embodiments, the indication that the second NF is a candidate client of the FL group is a FL join request from the second NF, and the indication that the second NF is authorized to join the FL group as a client is an authorization token. In such embodiments, the exemplary method may also include the operation of block 880, wherein, based on the authorization token, the first NF may send an indication to the second NF that the FL join request has been accepted by the first NF. In some embodiments, the authorization token includes at least a portion of the registered authorization information.

[0112] In some of these embodiments, an authorization token is received from the second NF together with the FL join request. In other of these embodiments, in response to the FL join request, the exemplary method may further include operations of blocks 860-870, wherein the first NF may send a request for an authorization token to the NRF, the authorization token indicating that the second NF is authorized to join the FL group as a client; and receive the requested authorization token from the NRF. In such cases, the received authorization token may be used in the operations of block 880.

[0113] In some embodiments, the exemplary method may also include operations of blocks 810-815, wherein the first NF may register information about the FL capabilities of the first NF in the NRF, and discover the one or more additional NFs of the FL group via the NRF based on the information about the corresponding FL capabilities of the one or more additional NFs registered in the NRF.

[0114] In some embodiments, the registered information associated with the FL group also includes: an identifier of the FL group and / or an identifier of a FL process performed by the FL group; and an analysis identifier.

[0115] In some embodiments, the first NF is a NWDAF and / or the second NF is a NWDAF.

[0116] also, Fig. 9An exemplary method (e.g., process) for configuring a second NF to operate as a client of an FL group in a communication network (e.g., 5GC) according to various embodiments of the present disclosure is shown. Fig. 9 The exemplary method shown in may be performed by a FL client such as an NWDAF (or a logical function thereof, such as an MTLF) or a network node hosting an NWDAF, such as described elsewhere herein.

[0117] In different embodiments, the exemplary method may include a first set of operations or a second set of operations.

[0118] Specifically, the first set of operations may include operations of blocks 910-930. In block 910, the second NF may register information about the FL capability of the second NF in an NRF of the communication network. In block 920, the second NF may receive a FL preparation request from a first NF configured to operate as a server of the FL group, the request including the following: ● interoperability information, indicating the capabilities required by the NF to participate in the FL group as a client, and - A second authorization token indicating that the first NF is an authorized server for the FL group. In block 930 , the second NF may send a FL prepare response to the first NF, the FL prepare response indicating that the second NF accepts the FL prepare request.

[0119] In some embodiments, the first set of operations also includes the operation of block 925, wherein the second NF may determine whether to join the FL group as a client based on the second authorization token and a comparison of the interoperability information with the corresponding FL capabilities of the second NF. In such a case, the FL preparation response indicating that the second NF accepts the FL preparation request is based on the determination.

[0120] In other embodiments, the exemplary method may include a second set of operations of blocks 940, 970, and 980. In block 940, the second NF may discover the FL group and the first NF as a server of the FL group via the NRF. In blocks 970-980, the second NF may send a FL join request to the first NF and receive an indication from the first NF that the first NF accepted the FL join request.

[0121] In some of these embodiments, the discovery of the FL group and the first NF in block 940 is based on one or more of the following items that the first NF has registered in the NRF: information associated with the FL group; or information about the FL capabilities of the first NF. In some of these embodiments, the registered information associated with the FL group includes the following: ● Authorization information for the additional NF to join the FL group as a client; An identifier of the FL group and / or an identifier of a FL process performed by the FL group; and ●Analyze identifiers.

[0122] In some embodiments, the second set of operations also includes operations of blocks 950-960, wherein the second NF may send a request for an authorization token to the NRF, the authorization token indicating that the second NF is authorized to join the FL group as a client; and receive the requested authorization token from the NRF. The authorization token may then be included in the FL join request sent in block 970.

[0123] In some of these embodiments, the authorization token is based on the authorization information associated with the FL group that the first NF has registered in the NRF. Specifically, the registered authorization information includes one or more of the following items: The identifier of the FL group owner; One or more identifiers associated with the target ML model for which the FL group performed training; and ●Indication of the authorization scope of the FL group.

[0124] In some variants, the identifier of the FL group owner is an identifier associated with the first NF, and the one or more identifiers associated with the target ML model include one or more of the following: an interoperability ID, a vendor ID, an analysis ID, a model filter, a model URL, or a model ID. In some variants, the indication of the scope of authorization of the FL group includes an indication or identifier of one or more of the following: ● one or more allowed requester and / or provider NF types; ● one or more allowed requester and / or provider NF IDs; ● One or more allowed requestor and / or provider NF providers; ● one or more allowed interoperability IDs; or ● Allowed FL capabilities.

[0125] In some embodiments, the first NF is a NWDAF and / or the second NF is a NWDAF.

[0126] also, Fig.10 An exemplary method (e.g., process) for NRF of a communication network (e.g., 5GC) according to various embodiments of the present disclosure is shown. Fig.10 The exemplary methods shown in may be performed by an NRF or a network node hosting an NRF, such as described elsewhere herein.

[0127] The exemplary method may include the operation of block 1020, wherein the NRF may register information associated with a federated learning (FL) group in the communication network. The FL group includes a first NF configured to operate as a server and one or more additional NFs configured to operate as clients. The registered information includes authorization information for the additional NF to join the FL group as a client.

[0128] In various embodiments, the registered authorization information may include any corresponding content and / or features described above in relation to the first NF embodiment. In some embodiments, the registered information associated with the FL group also includes an analysis identifier and an identifier of the FL group and / or an identifier of a FL process performed by the FL group.

[0129] In various embodiments, the exemplary method may also include the first set of operations or the second set of operations.

[0130] The first set of operations includes operations of blocks 1030-1040, where the NRF may register information about the FL capability of the second NF of the communication network and send an indication to the first NF that the second NF is a candidate client of the FL group.

[0131] In some of these embodiments, the indication that the second NF is a candidate client of the FL group is based on notification of the first NF's subscription to: a registration event of a candidate client of the FL group. In some variants, the notification is an implicit indication that the second NF is authorized to join the FL group as a client. In other variants, an explicit authorization token indicating that the second NF is authorized to join the FL group as a client is included with the notification.

[0132] In other embodiments, the second set of operations includes the operation of block 1050, wherein during discovery by the second NF, the NRF may inform the second NF about the FL group and the first NF as a server of the FL group. In some of these embodiments, the second set may also include the operations of blocks 1060-1070, wherein the NRF may receive a request for an authorization token from the second NF, the authorization token indicating that the second NF is authorized to join the FL group as a client; and send the requested authorization token to the second NF. In some variants, the authorization token includes at least a portion of the registered authorization information.

[0133] In some embodiments, the exemplary method may also include operations of blocks 1010-1015, wherein the NRF may register information about the FL capabilities of the first NF, and during discovery by the first NF, notify the first NF of the one or more additional NFs of the FL group based on information about the corresponding FL capabilities of the one or more additional NFs registered in the NRF.

[0134] In some embodiments, the first NF is a NWDAF and / or the second NF is a NWDAF.

[0135] Although various embodiments are described above in terms of methods, techniques and / or processes, a person of ordinary skill will readily appreciate that these methods, techniques and / or processes may be implemented through various combinations of hardware and software in various systems, communication devices, computing devices, control devices, equipment, non-transitory computer-readable media, computer program products, etc.

[0136] Fig.11 An example of a communication system 1100 according to some embodiments is shown. In this example, the communication system 1100 includes a telecommunications network 1102, which includes an access network 1104 such as a RAN and a core network 1106, which includes one or more core network nodes 1108. The access network 1104 includes one or more access network nodes, such as network nodes 1110a and 1110b (one or more of which may be collectively referred to as network nodes 1110), or any other similar 3GPP access nodes or non-3GPP access points. The network nodes 1110 facilitate direct or indirect connection of UEs, such as by connecting UEs 1112a-d (one or more of which may be collectively referred to as UEs 1112) to the core network 1106 through one or more wireless connections.

[0137] Example wireless communications via wireless connections include transmitting and / or receiving wireless signals using electromagnetic waves, radio waves, infrared waves, and / or other types of signals suitable for conveying information without the use of wires, cables, or other material conductors. Additionally, in various embodiments, the communication system 1100 may include any number of wired or wireless networks, network nodes, UEs, and / or any other components or systems that may facilitate or participate in the transfer of data and / or signals, whether via a wired or wireless connection. The communication system 1100 may include and / or interface with any type of communication, telecommunication, data, cellular, radio network, and / or other similar types of systems.

[0138] UE 1112 may be any of a variety of communication devices, including wireless devices arranged, configured and / or operable to communicate wirelessly with network node 1110 and other communication devices. Similarly, network node 1110 is arranged, capable, configured and / or operable to communicate directly or indirectly with UE 1112 and / or with other network nodes or devices in telecommunication network 1102 to enable and / or provide network access, such as wireless network access, and / or perform other functions, such as management in telecommunication network 1102.

[0139] In the depicted example, the core network 1106 connects the network node 1110 to one or more hosts, such as the host 1116. These connections may be direct, or indirect via one or more intermediate networks or devices. In other examples, the network node may be directly coupled to the host. The core network 1106 includes one or more core network nodes (e.g., core network node 1108) constructed using hardware and software components. The features of these components may be substantially similar to those described with respect to the UE, network nodes, and / or hosts, so that their descriptions are generally applicable to the corresponding components of the core network node 1108. The example core network node includes a mobile switching center (MSC), a mobility management entity (MME), a home subscriber server (HSS), an access and mobility management function (AMF), a session management function (SMF), an authentication server function (AUSF), a subscription identifier de-hiding function (SIDF), a unified data management (UDM), a security edge protection agent (SEPP), a network exposure function (NEF), and / or a user plane function (UPF) One or more functions.

[0140] The host 1116 may be owned or controlled by a service provider other than the operator or provider of the access network 1104 and / or the telecommunications network 1102, and may be operated by or on behalf of the service provider. The host 1116 may host various applications to provide one or more services. Examples of such applications include live and pre-recorded audio / video content, data collection services (such as retrieving and compiling data about various environmental conditions detected by multiple UEs), analysis functionality, social media, functions for controlling or otherwise interacting with remote devices, functions for alarm and monitoring centers, or any other such functions performed by a server.

[0141] As a whole, Fig.11 The communication system 1100 enables connectivity between UEs, network nodes, and hosts. In that sense, the communication system 1100 can be configured to operate according to predefined rules or procedures, such as specific standards, including but not limited to: Global System for Mobile Communications (GSM); Universal Mobile Telecommunications System (UMTS); Long Term Evolution (LTE) and / or other suitable 2G, 3G, 4G, 5G standards, or any applicable future generation standards (e.g., 6G); Wireless Local Area Network (WLAN) standards, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard (WiFi); and / or any other suitable wireless communication standards, such as Worldwide Interoperability for Microwave Access (WiMax), Bluetooth, Z-Wave, Near Field Communication (NFC) ZigBee, LiFi, and / or any Low Power Wide Area Network (LPWAN) standards, such as LoRa and Sigfox.

[0142] In some examples, telecommunication network 1102 is a cellular network implementing 3GPP standardized features. Thus, telecommunication network 1102 may support network slicing to provide different logical networks to different devices connected to telecommunication network 1102. For example, telecommunication network 1102 may provide ultra-reliable low-latency communication (URLLC) services to some UEs, while providing enhanced mobile broadband (eMBB) services to other UEs, and / or providing massive machine type communication (mMTC) / massive IoT services to yet other UEs.

[0143] In some examples, UE 1112 is configured to transmit to and / or receive information without direct human interaction. For example, the UE may be designed to transmit information to access network 1104 on a predetermined schedule when triggered by an internal or external event, or in response to a request from access network 1104. In addition, the UE may be configured to operate in a single RAT or multi-RAT or multi-standard mode. For example, the UE may operate with any one or a combination of Wi-Fi, NR (new air interface), and LTE, i.e., be configured for multi-radio dual connectivity (MR-DC), such as E-UTRAN (Evolved UMTS Terrestrial Radio Access Network) new air interface dual connectivity (EN-DC).

[0144] In an example, the hub 1114 communicates with the access network 1104 to facilitate indirect communication between one or more UEs (e.g., UE 1112c and / or 1112d) and a network node (e.g., network node 1110b). In some examples, the hub 1114 can be a controller, a router, a content source, and an analysis device, or any of the other communication devices described herein with respect to the UE. For example, the hub 1114 can be a broadband router that enables the UE to access the core network 1106. As another example, the hub 1114 can be a controller that sends commands or instructions to one or more actuators in the UE. The command or instruction can be received from the UE, the network node 1110, or through an executable code, script, process, or other instruction in the hub 1114. As another example, the hub 1114 can be a data collector that acts as a temporary storage device for UE data, and in some embodiments, analysis or other processing of the data can be performed. As another example, the hub 1114 can be a content source. For example, for a UE that is a VR headset, display, speaker, or other media delivery device, the hub 1114 can retrieve VR assets, video, audio, or other media or data related to sensory information via a network node, and then the hub 1114 provides it to the UE either directly, after performing local processing, and / or after adding additional local content. In yet another example, the hub 1114 acts as a proxy server or orchestrator for the UE, particularly when one or more of the UEs are low-energy IoT devices.

[0145] Hub 1114 may have a continuous / persistent or intermittent connection to network node 1110b. Hub 1114 may also allow different communication schemes and / or scheduling between hub 1114 and UE (e.g., UE 1112c and / or 1112d) and between hub 1114 and core network 1106. In other examples, hub 1114 is connected to core network 1106 and / or one or more UEs via a wired connection. In addition, hub 1114 may be configured to connect to an M2M service provider through access network 1104 and / or to another UE via a direct connection. In some scenarios, a UE may establish a wireless connection with network node 1110 while still being connected via hub 1114 via a wired or wireless connection. In some embodiments, hub 1114 may be a dedicated hub, that is, a hub whose primary function is to route communications from network node 1110b to UE / from UE to network node 1110b. In other embodiments, hub 1114 may be a non-dedicated hub, that is, a device operable to route communications between UEs and network node 1110b, but additionally operable as a communications origin and / or endpoint for a particular data channel.

[0146] Fig.12 A UE 1200 according to some embodiments is shown. Examples of UEs include, but are not limited to, smartphones, mobile phones, cellular phones, voice over IP (VoIP) phones, wireless local loop phones, desktop computers, personal digital assistants (PDAs), wireless cameras, game consoles or devices, music storage devices, playback devices, wearable terminal devices, wireless endpoints, mobile stations, tablet computers, laptops, laptop embedded equipment (LEE), laptop mounted equipment (LME), smart devices, wireless customer premises equipment (CPE), vehicle-mounted or vehicle-embedded / integrated wireless devices, etc. Other examples include any UE identified by the Third Generation Partnership Project (3GPP), including narrowband Internet of Things (NB-IoT) UEs, machine type communication (MTC) UEs, and / or enhanced MTC (eMTC) UEs.

[0147] The UE may support device-to-device (D2D) communications, such as by implementing 3GPP standards for sidelink communications, dedicated short-range communications (DSRC), vehicle-to-vehicle (V2V), vehicle-to-infrastructure (V2I), or vehicle-to-everything (V2X). In other examples, the UE may not necessarily have a user in the sense of a human user owning and / or operating an associated device. Instead, the UE may represent a device that is intended for sale to or operation by a human user but may not be associated with a specific human user or may not initially be associated with a specific human user (e.g., a smart sprinkler controller). Alternatively, the UE may represent a device that is not intended for sale to or operation by an end user but may be associated with or operated for the benefit of a user (e.g., a smart meter).

[0148] UE 1200 includes processing circuitry 1202 operatively coupled to input / output interface 1206, power supply 1208, memory 1210, communication interface 1212, and / or any other components or any combination thereof via bus 1204. A particular UE may utilize Fig.12 All or a subset of the components shown in . The level of integration between components may vary from one UE to another UE. In addition, a particular UE may contain multiple instances of a component, such as multiple processors, memories, transceivers, transmitters, receivers, etc.

[0149] The processing circuit 1202 is configured to process instructions and data, and may be configured to implement any sequential state machine that operates to execute instructions stored in the memory 1210 as a machine-readable computer program. The processing circuit 1202 may be implemented as one or more hardware-implemented state machines (e.g., in discrete logic, field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), etc.); programmable logic and appropriate firmware; one or more stored computer programs, general-purpose processors, such as microprocessors or digital signal processors (DSPs), and appropriate software; or any combination of the above. For example, the processing circuit 1202 may include multiple central processing units (CPUs).

[0150] In an example, the input / output interface 1206 may be configured to provide one or more interfaces to an input device, an output device, or one or more input and / or output devices. Examples of output devices include speakers, sound cards, video cards, displays, monitors, printers, actuators, transmitters, smart cards, another output device, or any combination thereof. An input device may allow a user to capture information into the UE 1200. Examples of input devices include touch-sensitive or presence-sensitive displays, cameras (e.g., digital cameras, digital video cameras, web cameras, etc.), microphones, sensors, mice, trackballs, directional pads, trackpads, rollers, smart cards, and the like. A presence-sensitive display may include a capacitive or resistive touch sensor to sense input from a user. The sensor may be, for example, an accelerometer, a gyroscope, a tilt sensor, a force sensor, a magnetometer, an optical sensor, a proximity sensor, a biometric sensor, or the like, or any combination thereof. An output device may use an interface port of the same type as an input device. For example, a universal serial bus (USB) port may be used to provide an input device and an output device.

[0151] In some embodiments, the power supply 1208 is configured as a battery or a battery pack. Other types of power supplies may be used, such as an external power supply (e.g., a power outlet), a photovoltaic device, or a battery. The power supply 1208 may further include a power circuit for delivering power from the power supply 1208 itself and / or an external power supply to various parts of the UE 1200 via an input circuit or an interface such as a power cable. The delivered power may be used, for example, for charging the power supply 1208. The power circuit may perform any formatting, conversion, or other modification on the power from the power supply 1208 to make the power suitable for the corresponding components of the UE 1200 to which the power is supplied.

[0152] The memory 1210 may be or be configured to include a memory such as a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic disk, an optical disk, a hard disk, a removable cartridge, a flash drive, etc. In one example, the memory 1210 includes one or more application programs 1214, such as an operating system, a web browser application, a gadget, a widget engine, or other application, and corresponding data 1216. The memory 1210 may store any of a variety of operating systems or combinations of operating systems for use by the UE 1200.

[0153] The memory 1210 may be configured to include a plurality of physical drive units, such as a redundant array of independent disks (RAID), a flash memory, a USB flash drive, an external hard drive, a thumb drive, a pen drive, a key drive, a high-density digital versatile disk (HD-DVD) optical drive, an internal hard drive, a Blu-ray optical drive, a holographic digital data storage (HDDS) optical drive, an external mini dual in-line memory module (DIMM), a synchronous dynamic random access memory (SDRAM), an external micro DIMM SDRAM, a smart card memory (such as a tamper-proof module in the form of a universal integrated circuit card (UICC), including one or more subscriber identity modules (SIMs), such as USIM and / or ISIM), other memories, or any combination thereof. For example, the UICC may be an embedded UICC (eUICC), an integrated UICC (iUICC), or a removable UICC commonly referred to as a “SIM card”. The memory 1210 may allow the UE 1200 to access instructions, applications, etc. stored on a temporary or non-temporary storage medium to offload data or upload data. An article of manufacture, such as one utilizing a communication system, may be tangibly embodied as or in memory 1210, which may be or include a device-readable storage medium.

[0154] The processing circuit 1202 may be configured to communicate with an access network or other network using a communication interface 1212. The communication interface 1212 may include one or more communication subsystems and may include or be communicatively coupled to an antenna 1222. The communication interface 1212 may include one or more transceivers for communication, such as by communicating with one or more remote transceivers of another device capable of wireless communication (e.g., another UE or network node in the access network). Each transceiver may include a transmitter 1218 and / or a receiver 1220 suitable for providing network communications (e.g., optical, electrical, frequency allocation, etc.). In addition, the transmitter 1218 and the receiver 1220 may be coupled to one or more antennas (e.g., antenna 1222) and may share circuit components, software, or firmware, or alternatively be implemented separately.

[0155] In the illustrated embodiment, the communication functionality of the communication interface 1212 may include cellular communication, Wi-Fi communication, LPWAN communication, data communication, voice communication, multimedia communication, short-range communication such as Bluetooth, near field communication, location-based communication such as using a global positioning system (GPS) to determine location, another similar communication functionality, or any combination thereof. Communication may be implemented according to one or more communication protocols and / or standards, such as IEEE 802.11, code division multiple access (CDMA), wideband code division multiple access (WCDMA), GSM, LTE, new radio (NR), UMTS, WiMax, Ethernet, transmission control protocol / Internet protocol (TCP / IP), synchronous optical networking (SONET), asynchronous transfer mode (ATM), QUIC, hypertext transfer protocol (HTTP), etc.

[0156] Regardless of the type of sensor, the UE may provide an output of the data captured by its sensor via a wireless connection to a network node through its communication interface 1212. The data captured by the UE's sensor may be delivered to the network node via another UE over a wireless connection. The output may be periodic (e.g., every 15 minutes if it reports the sensed temperature), random (e.g., to even out the load from reports from several sensors), in response to a trigger event (e.g., sending an alarm when moisture is detected), in response to a request (e.g., a user-initiated request), or a continuous stream (e.g., a live video feed of a patient).

[0157] As another example, the UE includes an actuator, motor, or switch associated with a communication interface configured to receive wireless input from a network node via a wireless connection. In response to the received wireless input, the state of the actuator, motor, or switch can change. For example, the UE can include a motor that adjusts a control surface or rotor of a drone in flight based on the received input, or adjusts a robotic arm performing a medical procedure based on the received input.

[0158] When in the form of an Internet of Things (IoT) device, a UE may be a device for use in one or more application areas including, but not limited to, urban wearable technology, extended industrial applications, and healthcare. Non-limiting examples of such IoT devices are or are embedded in: a connected refrigerator or freezer, a television, a connected lighting device, an electric meter, a robotic vacuum cleaner, a voice-activated smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electronic door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for augmented reality (AR) or virtual reality (VR), a wearable device for tactile enhancement or sensory enhancement, a sprinkler, an animal or item tracking device, a sensor for monitoring plants or animals, an industrial robot, an unmanned aerial vehicle (UAV), and any kind of medical device, similar to a heart rate monitor or a teleoperated surgical robot. In addition to the above, the UE may be used to monitor the environment, such as a connected refrigerator or freezer, a television, a connected lighting device, an electric meter, a robotic vacuum cleaner, a voice-activated smart speaker, a home security camera, a motion detector, a thermostat, a smoke detector, a door / window sensor, a flood / moisture sensor, an electronic door lock, a connected doorbell, an air conditioning system like a heat pump, an autonomous vehicle, a surveillance system, a weather monitoring device, a vehicle parking monitoring device, an electric vehicle charging station, a smart watch, a fitness tracker, a head-mounted display for augmented reality (AR) or virtual reality (VR), a wearable device for tactile enhancement or sensory enhancement, a sprinkler, an animal or item tracking device, a sensor for monitoring plants or animals, an industrial robot, an unmanned aerial vehicle (UAV), and any kind of medical device, such as a heart rate monitor or a teleoperated surgical robot. Fig.12 In addition to the other components described for the UE 1200 shown in FIG. 1 , a UE in the form of an IoT device includes circuitry and / or software depending on the intended application of the IoT device.

[0159] As yet another specific example, in an IoT scenario, a UE may represent a machine or other device that performs monitoring and / or measurement and transmits the results of such monitoring and / or measurement to another UE and / or a network node. In such a case, the UE may be an M2M device, which may be referred to as an MTC device in the 3GPP context. As a specific example, a UE may implement the 3GPP NB-IoT standard. In other scenarios, a UE may represent a vehicle, such as a car, bus, truck, ship, and airplane, or other equipment capable of monitoring and / or reporting its operating status or other functions associated with its operation.

[0160] In fact, any number of UEs may be used together with respect to a single use case. For example, a first UE may be a drone or integrated in a drone and provide the drone's speed information (obtained via a speed sensor) to a second UE that is a remote controller operating the drone. When the user makes changes from the remote controller, the first UE may adjust the throttle on the drone (e.g., by controlling an actuator) to increase or decrease the drone's speed. The first and / or second UE may also include more than one of the functionalities described above. For example, a UE may include a sensor and an actuator and handle the transfer of data from both the speed sensor and the actuator.

[0161] Fig.13 A network node 1300 according to some embodiments is shown. As used herein, a network node refers to a device capable of, configured to, arranged to, and / or operable to communicate directly or indirectly with a UE and / or other network nodes or devices in a telecommunications network. Examples of network nodes include, but are not limited to, access points (APs) (e.g., radio access points), base stations (BSs) (e.g., radio base stations, Node Bs, evolved Node Bs (eNBs), and NR Node Bs (gNBs)).

[0162] Base stations may be classified based on the amount of coverage they provide (or in other words, their transmit power level), and therefore, depending on the amount of coverage provided, may be referred to as femto base stations, pico base stations, micro base stations, or macro base stations. A base station may be a relay node or a relay donor node that controls a relay. A network node may also include one or more (or all) parts of a distributed radio base station, such as a centralized digital unit and / or a remote radio unit (RRU), which is sometimes referred to as a remote radio head (RRH). Such a remote radio unit may or may not be integrated with an antenna as an antenna-integrated radio device. Portions of a distributed radio base station may also be referred to as nodes in a distributed antenna system (DAS).

[0163] Other examples of network nodes include multi-transmission point (multi-TRP) 5G access nodes, multi-standard radio (MSR) equipment such as an MSR BS, a network controller such as a radio network controller (RNC) or a base station controller (BSC), a base transceiver station (BTS), a transmission point, a transport node, a multi-cell / multicast coordination entity (MCE), an operation and maintenance (O&M) node, an operation support system (OSS) node, a self-organizing network (SON) node, a positioning node (e.g., an evolved serving mobile location center (E-SMLC)), and / or minimization of drive tests (MDT).

[0164] For example, in the description of various methods or processes herein, one or more network nodes 1300 may be configured to perform operations performed by a FL server NF (eg, server NWDAF), a FL client NF (eg, client NWDAF), or an NRF.

[0165] The network node 1300 includes a processing circuit 1302, a memory 1304, a communication interface 1306, and a power supply 1308. The network node 1300 may be composed of multiple physically separated components (e.g., a NodeB component and an RNC component, or a BTS component and a BSC component, etc.), each of which may have its own corresponding components. In a specific scenario in which the network node 1300 includes multiple separate components (e.g., a BTS and a BSC component), one or more of the separate components may be shared between several network nodes. For example, a single RNC may control multiple NodeBs. In such a scenario, each unique NodeB and RNC pair may be considered as a single separate network node in a specific instance. In some embodiments, the network node 1300 may be configured to support multiple radio access technologies (RATs). In such an embodiment, some components may be copied (e.g., separate memories 1304 for different RATs), and some components may be reused (e.g., the same antenna 1310 may be shared by different RATs). The network node 1300 may also include multiple sets of various illustrated components for different wireless technologies, such as GSM, WCDMA, LTE, NR, WiFi, Zigbee, Z-wave, LoRaWAN, RFID, or Bluetooth wireless technologies, integrated into the network node 1300. These wireless technologies may be integrated into the same or different chips or chipsets and other components within the network node 1300.

[0166] The processing circuit 1302 may include: a microprocessor, a controller, a microcontroller, a central processing unit, a digital signal processor, an application specific integrated circuit, a field programmable gate array, or any other suitable computing device, a combination of one or more of the resources, or a combination of hardware, software and / or encoded logic that can be operated to provide the functionality of the network node 1300 either alone or in combination with other network node 1300 components such as memory 1304.

[0167] In some embodiments, processing circuitry 1302 includes a system on a chip (SOC). In some embodiments, processing circuitry 1302 includes one or more of radio frequency (RF) transceiver circuitry 1312 and baseband processing circuitry 1314. In some embodiments, radio frequency (RF) transceiver circuitry 1312 and baseband processing circuitry 1314 may be on separate chips (or chipsets), circuit boards, or units, such as a radio unit and a digital unit. In alternative embodiments, some or all of RF transceiver circuitry 1312 and baseband processing circuitry 1314 may be on the same chip or chipset, circuit board, or unit.

[0168] The memory 1304 may include any form of volatile or non-volatile computer-readable memory, including, but not limited to, permanent storage, solid-state memory, remotely mounted memory, magnetic media, optical media, random access memory (RAM), read-only memory (ROM), mass storage media (e.g., hard disk), removable storage media (e.g., flash drive, compact disk (CD) or digital video disk (DVD)), and / or any other volatile or non-volatile, non-transitory device-readable and / or computer-executable memory device that stores information, data and / or instructions that can be used by the processing circuit 1302. The memory 1304 may store any suitable instructions, data or information, including computer programs, software, applications including one or more logic, rules, codes, tables and / or other instructions that can be executed by the processing circuit 1302 and utilized by the network node 1300 (collectively referred to as computer program product 1304a). The memory 1304 may be used to store any calculations performed by the processing circuit 1302 and / or any data received via the communication interface 1306. In some embodiments, processing circuit 1302 and memory 1304 are integrated.

[0169] The communication interface 1306 is used for wired or wireless transmission of signaling and / or data between network nodes, access networks and / or UEs. As illustrated, the communication interface 1306 includes (one or more) ports / (one or more) terminals 1316 for sending data to and receiving data from the network, for example, via a wired connection. The communication interface 1306 also includes a radio front-end circuit 1318, which can be coupled to the antenna 1310, or is a part of the antenna 1310 in a specific embodiment. The radio front-end circuit 1318 includes a filter 1320 and an amplifier 1322. The radio front-end circuit 1318 can be connected to the antenna 1310 and the processing circuit 1302. The radio front-end circuit can be configured to adjust the signal transmitted between the antenna 1310 and the processing circuit 1302. The radio front-end circuit 1318 can receive digital data to be sent outward to other network nodes or UEs via a wireless connection. The radio front-end circuit 1318 can use a combination of a filter 1320 and / or an amplifier 1322 to convert the digital data into a radio signal with appropriate channel and bandwidth parameters. The radio signal may then be transmitted via antenna 1310. Similarly, when receiving data, antenna 1310 may collect the radio signal, which may then be converted into digital data by radio front end circuit 1318. The digital data may be passed to processing circuit 1302. In other embodiments, the communication interface may include different components and / or different combinations of components.

[0170] In certain alternative embodiments, the network node 1300 does not include a separate radio front end circuit 1318, instead the processing circuit 1302 includes the radio front end circuit and is connected to the antenna 1310. Similarly, in some embodiments, all or some of the RF transceiver circuit 1312 is part of the communication interface 1306. In still other embodiments, the communication interface 1306 includes one or more ports or terminals 1316, the radio front end circuit 1318, and the RF transceiver circuit 1312 as part of a radio unit (not shown), and the communication interface 1306 communicates with the baseband processing circuit 1314, which is part of the digital unit (not shown).

[0171] Antenna 1310 may include one or more antennas or antenna arrays configured to send and / or receive wireless signals. Antenna 1310 may be coupled to radio front end circuit 1318 and may be any type of antenna capable of wirelessly transmitting and receiving data and / or signals. In a particular embodiment, antenna 1310 is separate from network node 1300 and may be connected to network node 1300 via an interface or port.

[0172] Antenna 1310, communication interface 1306 and / or processing circuit 1302 can be configured to perform any receiving operation and / or specific obtaining operation described herein as being performed by a network node. Any information, data and / or signal can be received from a UE, another network node and / or any other network device. Similarly, antenna 1310, communication interface 1306 and / or processing circuit 1302 can be configured to perform any transmitting operation described herein as being performed by a network node. Any information, data and / or signal can be transmitted to a UE, another network node and / or any other network device.

[0173] The power supply 1308 provides power to the respective components of the network node 1300 in a form suitable for the respective components (e.g., at the voltage and current levels required by each respective component). The power supply 1308 may further include or be coupled to a power management circuit to supply power to the components of the network node 1300 for performing the functionality described herein. For example, the network node 1300 may be connected to an external power source (e.g., a power grid, a power outlet) via an input circuit or interface such as a cable, whereby the external power source supplies power to the power circuit of the power supply 1308. As another example, the power supply 1308 may include a power source in the form of a battery or battery pack that is connected to or integrated in the power circuit. If the external power source fails, the battery may provide backup power.

[0174] Embodiments of the network node 1300 may include, in addition to Fig.13 Additional components beyond those shown in the figure are used to provide specific aspects of the functionality of the network node, including any of the functionality described herein and / or any functionality necessary to support the subject matter described herein. For example, the network node 1300 may include a user interface device to allow information to be input into the network node 1300 and to allow information to be output from the network node 1300. This may allow a user to perform diagnostics, maintenance, repair, and other management functions on the network node 1300.

[0175] Fig.14 is a block diagram of a host 1400 according to various aspects described herein, the host 1400 may be Fig.11 1400. As used herein, host 1400 may be or include various combinations of hardware and / or software, including processing resources in a standalone server, blade server, cloud-implemented server, distributed server, virtual machine, container, or server farm. Host 1400 may provide one or more services to one or more UEs.

[0176] Host 1400 includes processing circuitry 1402, which is operatively coupled to input / output interface 1406, network interface 1408, power supply 1410, and memory 1412 via bus 1404. Other components may be included in other embodiments. The features of these components may be substantially similar to those described with respect to previous figures (such as Fig.12 and Fig.13 ) so that its description is generally applicable to the corresponding components of the host 1400.

[0177] The memory 1412 may include one or more computer programs, including one or more host applications 1414 and data 1416, which may include user data, such as data generated by the UE for the host 1400 or data generated by the host 1400 for the UE. An embodiment of the host 1400 may utilize only a subset or all of the components shown. The host application 1414 may be implemented in a container-based architecture and may provide support for video codecs (e.g., generic video coding (VVC), high efficiency video coding (HEVC), advanced video coding (AVC), MPEG, VP9) and audio codecs (e.g., FLAC, advanced audio coding (AAC), MPEG, G.711), including transcoding for multiple different categories, types, or implementations of UEs (e.g., mobile phones, desktop computers, wearable display systems, head-up display systems). The host application 1414 may also provide user authentication and permission checks, and may periodically report health, routing, and content availability to a central node (such as a device in a core network or on the edge). Accordingly, the host 1400 can select and / or indicate different hosts for the UE for over-the-top services. The host application 1414 can support various protocols, such as HTTP Live Streaming (HLS) protocol, Real-time Messaging Protocol (RTMP), Real-time Streaming Protocol (RTSP), Dynamic Adaptive Streaming over HTTP (MPEG-DASH), etc.

[0178] Fig.151500 is a block diagram illustrating a virtualized environment, in which the functions implemented by some embodiments can be virtualized. In this context, virtualization means creating a virtual version of a device or equipment, which can include a virtualized hardware platform, a storage device, and a networking resource. As used herein, virtualization can be applied to any device or component thereof described herein, and relates to an implementation in which at least a portion of the functionality is implemented as one or more virtual components. Some or all of the functions described herein can be implemented as virtual components executed by one or more virtual machines (VMs) implemented in one or more virtual environments 1500, which are hosted by one or more hardware nodes (such as hardware computing devices operating as network nodes, UEs, core network nodes, or hosts). In addition, in embodiments in which a virtual node does not require radio connectivity (e.g., a core network node or host), then the node can be fully virtualized.

[0179] Application 1502 (which may alternatively be referred to as a software instance, a virtual appliance, a network function, a virtual node, a virtual network function, etc.) runs in a virtualized environment Q400 to implement some of the features, functions and / or benefits of some of the embodiments disclosed herein.

[0180] For example, various NFs (or parts thereof) described herein in conjunction with other figures may be implemented as virtual network functions 1502 in the virtualization environment 1500. As a more specific example, a FL server NF (e.g., NWDAF), a FL client NF (e.g., NWDAF), and / or an NRF may be implemented as a virtual network function 1502 in the virtualization environment 1500.

[0181] The hardware 1504 includes a processing circuit, a memory storing software and / or instructions (collectively referred to as a computer program product 1504a) executable by the hardware processing circuit, and / or other hardware devices as described herein, such as a network interface, an input / output interface, etc. The software can be executed by the processing circuit to instantiate one or more virtualization layers 1506 (also referred to as a hypervisor or virtual machine monitor (VMM)), provide VMs 1508a and 1508b (one or more of which may be collectively referred to as VMs 1508), and / or perform any of the functions, features, and / or benefits described with respect to some embodiments described herein. The virtualization layer 1506 can present a virtual operating platform to the VM 1508 that appears similar to the networked hardware.

[0182] VM 1508 includes virtual processing, virtual memory, virtual networking or interfaces, and virtual storage, and may be run by a corresponding virtualization layer 1506. Different embodiments of instances of virtual devices 1502 may be implemented on one or more of VM 1508, and the implementation may be performed in different ways. Virtualization of hardware is referred to as network function virtualization (NFV) in a particular context. NFV may be used to integrate many network device types onto industry-standard high-volume server hardware, physical switches, and physical storage that may be located in data centers and customer premises equipment.

[0183] In the context of NFV, VMs 1508 can be software implementations of physical machines that run programs as if they were executing on a physical, non-virtualized machine. Each of VMs 1508 and that portion of hardware 1504 on which the VM executes, whether hardware dedicated to the VM and / or hardware shared by the VM with other VMs in the VM, form a separate virtual network element. Still in the context of NFV, a virtual network function is responsible for handling a specific network function running in one or more VMs 1508 on top of hardware 1504, and corresponds to an application 1502.

[0184] Hardware 1504 can be implemented in a standalone network node with general or specific components. Hardware 1504 can implement some functions via virtualization. Alternatively, hardware 1504 can be part of a larger hardware cluster (e.g., such as in a data center or CPE), where many hardware nodes work together and are managed via management and orchestration 1510, which also oversees the lifecycle management of application 1502. In some embodiments, hardware 1504 is coupled to one or more radio units, each of which includes one or more transmitters and one or more receivers that can be coupled to one or more antennas. The radio unit can communicate directly with other hardware nodes via one or more appropriate network interfaces, and can be used in conjunction with virtual components to provide radio capabilities to virtual nodes, such as radio access nodes or base stations. In some embodiments, a control system 1512 can be used to provide some signaling, which can alternatively be used for communication between hardware nodes and radio units.

[0185] Fig.16 A communication diagram is shown in which a host 1602 communicates with a UE 1606 via a network node 1604 over a partially wireless connection according to some embodiments. Fig.16 Describes the UE discussed in the previous paragraphs according to various embodiments (such as Fig.11 UE 1112a and / or Fig.12 UE 1200), network nodes (such as Fig.11 The network node 1110a and / or Fig.13 network nodes 1300) and hosts (such as Fig.11 Host 1116 and / or Fig.14 An example implementation of host 1400).

[0186] Like the host 1400, embodiments of the host 1602 include hardware, such as a communication interface, a processing circuit, and a memory. The host 1602 also includes software stored in or accessible by the host 1602 and executable by the processing circuit. The software includes a host application, which may be operable to provide services to a remote user, such as a UE 1606 connected via an over-the-top (OTT) connection 1650 extending between the UE 1606 and the host 1602. In providing services to the remote user, the host application may provide user data transmitted using the OTT connection 1650.

[0187] The network node 1604 includes hardware that enables it to communicate with the host 1602 and the UE 1606. The connection 1660 can be direct or through a core network (such as Fig.11 The core network 1106 of the present invention) and / or one or more other intermediate networks, such as one or more public, private or managed networks. For example, the intermediate network can be a backbone network or the Internet.

[0188] UE 1606 includes hardware and software stored in or accessible by UE 1606 and executable by the processing circuit of UE. The software includes a client application, such as a web browser or an operator-specific "application", which may be operable to provide services to human or non-human users via UE 1606 with the support of host 1602. In host 1602, the executing host application can communicate with the executing client application via an OTT connection 1650 terminated at UE 1606 and host 1602. When providing services to the user, the client application of the UE can receive request data from the host application of the host and provide user data in response to the request data. The OTT connection 1650 can transmit both request data and user data. The client application of the UE can interact with the user to generate user data, which it provides to the host application via the OTT connection 1650.

[0189] The OTT connection 1650 may extend via a connection 1660 between the host 1602 and the network node 1604 and via a wireless connection 1670 between the network node 1604 and the UE 1606 to provide connectivity between the host 1602 and the UE 1606. The connection 1660 and the wireless connection 1670 through which the OTT connection 1650 may be provided have been drawn abstractly to illustrate communications between the host 1602 and the UE 1606 via the network node 1604 without explicit reference to any intermediate devices and the precise routing of messages via those devices.

[0190] As an example of transmitting data via the OTT connection 1650, in step 1608, the host 1602 provides user data, which can be performed by executing a host application. In some embodiments, the user data is associated with a specific human user interacting with the UE 1606. In other embodiments, the user data is associated with the UE 1606, which shares data with the host 1602 without explicit human interaction. In step 1610, the host 1602 initiates a transmission carrying the user data toward the UE 1606. The host 1602 may initiate the transmission in response to a request transmitted by the UE 1606. The request may be caused by human interaction with the UE 1606 or by the operation of a client application executed on the UE 1606. According to the teachings of the embodiments described throughout the present disclosure, the transmission may be via the network node 1604. Therefore, in step 1612, according to the teachings of the embodiments described throughout the present disclosure, the network node 1604 transmits the user data carried in the transmission initiated by the host 1602 to the UE 1606. In step 1614 , UE 1606 receives the user data carried in the transmission, which may be performed by a client application executing on UE 1606 in association with a host application executed by host 1602 .

[0191] In some examples, UE 1606 executes a client application that provides user data to host 1602. The user data may be provided as a reaction or response to data received from host 1602. Thus, in step 1616, UE 1606 may provide the user data, which may be performed by executing the client application. In providing the user data, the client application may further consider user input received from a user via an input / output interface of UE 1606. Regardless of the specific manner in which the user data is provided, in step 1618, UE 1606 initiates transmission of the user data toward host 1602 via network node 1604. In step 1620, in accordance with the teachings of the embodiments described throughout the present disclosure, network node 1604 receives user data from UE 1606 and initiates transmission of the received user data toward host 1602. In step 1622, host 1602 receives the user data carried in the transmission initiated by UE 1606.

[0192] One or more of the various embodiments improves the performance of OTT services provided to UE 1606 using OTT connection 1650, wherein wireless connection 1670 forms the last leg. More precisely, embodiments may prevent unauthorized NFs (e.g., NWDAFs) from joining FL groups as clients and / or prevent NFs from joining groups as clients to perform fraudulent and / or unauthentic FL operations. In this way, embodiments may prevent confidential and / or sensitive ML models from being exposed to unauthorized parties during FL, and may mitigate security risks to NFs participating in FL. By improving security, embodiments facilitate the deployment of FL in multi-vendor communication networks (e.g., 5GC), which may improve ML models for network performance analysis in such networks. This may result in improved network performance, which increases the value of OTT services delivered to end users and service providers over such improved networks.

[0193] In an example scenario, plant status information may be collected and analyzed by host 1602. As another example, host 1602 may process audio and video data that may have been acquired from a UE for use in creating a map. As another example, host 1602 may collect and analyze real-time data to help control traffic congestion (e.g., control traffic lights). As another example, host 1602 may store surveillance videos uploaded by a UE. As another example, host 1602 may store or control access to media content that it may broadcast, multicast, or unicast to a UE, such as video, audio, VR, or AR. As other examples, host 1602 may be used for energy pricing, remote control of non-time-critical power loads to balance power generation demand, positioning services, presentation services (such as compiling charts from data collected from remote devices, etc.), or any other function for collecting, retrieving, storing, analyzing, and / or transmitting data.

[0194] In some examples, a measurement process may be provided for the purpose of monitoring data rates, delays, and other factors that are improved by one or more embodiments. In response to changes in the measurement results, there may be further optional network functionality for reconfiguring the OTT connection 1650 between the host 1602 and the UE 1606. The measurement process and / or the network functionality for reconfiguring the OTT connection may be implemented with software and hardware of the host 1602 and / or the UE 1606. In some embodiments, sensors (not shown) may be deployed in other devices through which the OTT connection 1650 passes or may be associated with other devices through which the OTT connection 1650 passes; the sensors may participate in the measurement process by supplying the values ​​of the monitored quantities illustrated above or supplying the values ​​of other physical quantities by which the software can calculate or estimate the monitored quantities. The reconfiguration of the OTT connection 1650 may include message formats, retransmission settings, preferred routing selections, etc.; the reconfiguration does not require direct changes to the operation of the network node 1604. Such processes and functionality may be known and implemented in the art. In a particular embodiment, the measurement may involve proprietary UE signaling that facilitates the measurement of the host 1602 of throughput, propagation time, delay, etc. Measurement can be achieved because the software uses the OTT connection 1650 to cause messages to be transmitted, particularly empty messages or "fake" messages to be transmitted, while the software monitors propagation times, errors, etc.

[0195] The foregoing merely illustrates the principles of the present disclosure. In view of the teachings herein, various modifications and changes to the described embodiments will be apparent to those skilled in the art. Therefore, it will be appreciated that those skilled in the art will be able to design many systems, arrangements, and processes that, although not explicitly shown or described herein, implement the principles of the present disclosure and are therefore within the spirit and scope of the present disclosure. The various embodiments may be used together with each other, and may be used interchangeably therewith, as will be understood by those of ordinary skill in the art.

[0196] The term "unit" used herein may have the conventional meaning in the field of electronics, electrical devices and / or electronic devices, and may include, for example, electrical and / or electronic circuits, devices, modules, processors, memories, logical solid-state and / or discrete devices, computer programs or instructions for performing corresponding tasks, processes, calculations, output and / or display functions, etc., such as those described herein.

[0197] Any appropriate steps, methods, features, functions or benefits disclosed herein may be performed by a module or one or more functional units of one or more virtual devices. Each virtual device may include a plurality of these functional units. These functional units may be implemented via processing circuits and other digital hardware, and the processing circuits may include one or more microprocessors or microcontrollers, and other digital hardware may include digital signal processors (DSPs), dedicated digital logic, and the like. The processing circuit may be configured to execute program codes stored in a memory, and the memory may include one or more types of memory, such as read-only memory (ROM), random access memory (RAM), cache memory, flash memory device, optical storage device, etc. The program code stored in the memory includes program instructions for executing one or more telecommunications and / or data communication protocols and instructions for executing one or more technologies described herein. In some implementations, the processing circuit may be used to cause the corresponding functional unit to perform corresponding functions according to one or more embodiments of the present disclosure.

[0198] As described herein, a device and / or equipment may be represented by a semiconductor chip, a chipset, or a (hardware) module including such a chip or chipset; however, this does not exclude the possibility that the functionality of the device or equipment is not implemented by hardware, but as a software module (such as a computer program or a computer program product including an executable software code portion, which is used to execute on a processor or is running on a processor). In addition, the functionality of the device or equipment may be implemented by any combination of hardware and software. A device or equipment may also be viewed as an assembly of multiple devices and / or equipment, whether they are functionally cooperative or independent of each other. In addition, as long as the functionality of the device or equipment is retained, the device and equipment can be implemented in a distributed manner throughout the system. Such principles and similar principles are considered to be known to technicians.

[0199] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as those commonly understood by those of ordinary skill in the art to which the present disclosure belongs. It should also be understood that the terms used herein should be interpreted as having a meaning consistent with the meaning in the context of this specification and the relevant art, and will not be interpreted in an idealized or overly formal sense unless explicitly defined as such herein.

[0200] In addition, certain terms used in this disclosure (including the specification and drawings) may be used synonymously in some cases (e.g., "data" and "information"). It should be understood that although these terms (and / or other terms that may be synonymous with each other) may be used synonymously herein, there may be certain situations where these words may not be intended to be used synonymously.

[0201] Example embodiments of the devices and techniques described herein include, but are not limited to, the claims recited below.

Claims

1. A method for a first network function NF (710), the first network function NF (710) being configured to operate as a server (710) of a federated learning FL group in a communication network, the method comprising: registering (820) information associated with the FL group in a network repository function NRF (720) of the communication network, wherein: The FL group includes the first NF (710) and one or more additional NFs (730, 740) configured to operate as clients (730, 740) in the FL group, and The registered information includes authorization information for the additional NF (730, 740) to join the FL group as a client (730, 740); receiving (830) an indication of a second NF (730, 740) of the communication network, the second NF being a candidate client (730, 740) of the FL group; obtaining (840) an indication that the second NF (730, 740) is authorized to join the FL group as a client (730, 740), wherein the indication is based on the registered authorization information; and Based on the indication, the FL group is updated (890) to include the second NF (730, 740) as a client (730, 740).

2. The method of claim 1, wherein: The registered authorization information includes one or more of the following items: Identifier of the FL group owner; One or more identifiers associated with a target machine learning (ML) model for which the FL group performs training; or An indication of the authorization scope of the FL group.

3. The method of claim 2, wherein: The identifier of the FL group owner is an identifier associated with the first NF (710); and The one or more identifiers associated with the target ML model include one or more of: an interoperability ID, a vendor ID, an analysis ID, a model filter, a model URL, or a model ID.

4. The method according to any one of claims 2 to 3, wherein: The indication of the authorized scope of the FL group includes an indication or identifier of one or more of the following: One or more allowed requester and / or provider NF types; One or more allowed requester and / or provider NF IDs; One or more allowed requester and / or provider NF providers; One or more allowed interoperability IDs; or FL capabilities allowed.

5. The method according to any one of claims 1 to 4, wherein: The indication of the second NF (730, 740) being a candidate client (730, 740) of the FL group is a notification received from the NRF (720) based on the subscription of the first NF to the registration event of the candidate client (730, 740) of the FL group; and The indication that the second NF (730, 740) is authorized to join the FL group as the client (730, 740) is one of the following: Implicitly based on receiving said notification from said NRF (720); or The explicit authorization token received with the notification.

6. The method of claim 5, further comprising: Based on the indication that the second NF (730, 740) is authorized to join the FL group: Sending a FL preparation request to the second NF (730, 740), wherein the FL preparation request includes the following contents: interoperability information indicating capabilities required for the NF (730, 740) to participate in the FL group as a client (730, 740); as well as a second authorization token indicating that the first NF (710) is an authorized server (710) of the FL group; as well as receiving a FL preparation response from the second NF (730, 740), the FL preparation response indicating that the other NF (730, 740) has accepted the FL preparation request, Wherein, updating the FL group to include the second NF (730, 740) as a client (730, 740) is based on the FL preparation response.

7. The method of any one of claims 1 to 4, wherein: The indication of the second NF (730, 740) being a candidate client (730, 740) of the FL group is a FL join request from the second NF (730, 740); The indication that the second NF (730, 740) is authorized to join the FL group as a client (730, 740) is an authorization token; as well as The method further includes sending an indication to the second NF (730, 740) that the FL join request has been accepted by the first NF (710) based on the authorization token.

8. The method of claim 7, wherein: The authorization token is received from the second NF (730, 740) together with the FL join request.

9. The method of claim 7, further comprising, in response to the FL join request: sending a request for an authorization token to the NRF (720), the authorization token indicating that the second NF (730, 740) is authorized to join the FL group as a client (730, 740); and The requested authorization token is received from the NRF (720).

10. The method according to any one of claims 7 to 9, wherein: The authorization token includes at least a portion of the registered authorization information.

11. The method according to any one of claims 1 to 10, further comprising: registering information about the FL capability of the first NF (710) in the NRF (720); as well as The one or more additional NFs (730, 740) of the FL group are discovered via the NRF (720) based on the information about the corresponding FL capabilities of the one or more additional NFs (730, 740) of the FL group registered in the NRF (720).

12. The method according to any one of claims 1 to 11, wherein: The registered information associated with the FL group also includes the following: an identifier of the FL group and / or an identifier of a FL process performed by the FL group; and Parse the identifier.

13. The method according to any one of claims 1 to 12, wherein: One or more of the following apply: the first NF (710) is a network data analysis function NWDAF, and the second NF (730, 740) is a NWDAF.

14. A method for a second network function NF (730, 740), the second NF being configured to operate as a client (730, 740) of a federated learning FL group in a communication network, the method comprising: Performing a first set of operations or a second set of operations, where The first set includes: registering (910) information about the FL capability of the second NF (730, 740) in a network repository function NRF (720) of the communication network; A FL preparation request is received (920) from a first NF (710) configured to operate as a server (710) of the FL group, the FL preparation request including the following: interoperability information indicating the capabilities required for the NF (730, 740) to participate in the FL group as a client (730, 740), and a second authorization token indicating that the first NF (710) is an authorized server (710) of the FL group; sending (930) a FL preparation response to the first NF (710), the FL preparation response indicating that the second NF (730, 740) has accepted the FL preparation request; The second set includes: discovering (940) the FL group and the first NF (710) as a server (710) of the FL group via the NRF (720); sending (970) a FL join request to the first NF (710); and An indication is received (980) from the first NF (710) that the first NF (710) has accepted the FL join request.

15. The method of claim 14, wherein: The FL group and the first NF (710) are found based on one or more of the following items registered by the first NF (710) in the NRF (720): information associated with the FL group; and Information about the FL capability of the first NF (710).

16. The method of claim 15, wherein: The registered information associated with the FL group includes the following: Authorization information for an additional NF (730, 740) to join the FL group as a client (730, 740); an identifier of the FL group and / or an identifier of a FL process performed by the FL group; and Parse the identifier.

17. The method according to any one of claims 14 to 15, wherein: The second set also includes the following operations: sending (950) a request for an authorization token to the NRF (720), the request indicating that the second NF (730, 740) is authorized to join the FL group as a client (730, 740); as well as receiving (960) the requested authorization token from the NRF (720), The received authorization token is included with the FL joining request.

18. The method of claim 17, wherein: The authorization token is based on the authorization information associated with the FL group registered by the first NF (710) in the NRF (720); and The registered authorization information includes one or more of the following items: Identifier of the FL group owner; One or more identifiers associated with a target machine learning (ML) model for which the FL group performs training; and An indication of the authorization scope of the FL group.

19. The method of claim 18, wherein: The identifier of the FL group owner is an identifier associated with the first NF (710); and The one or more identifiers associated with the target ML model include one or more of: an interoperability ID, a vendor ID, an analysis ID, a model filter, a model URL, and a model ID.

20. The method according to any one of claims 18 to 19, wherein: The indication of the authorized scope of the FL group includes an indication or identifier of one or more of the following: One or more allowed requester and / or provider NF types; One or more allowed requester and / or provider NF IDs; One or more allowed requester and / or provider NF providers; One or more allowed interoperability IDs; or FL capabilities allowed.

21. The method of claim 14, wherein: The first set also includes determining whether to join the FL group as a client (730, 740) based on the following information: the second authorization token, and comparison of the interoperability information with a corresponding FL capability of the second NF (730, 740); And the FL preparation response indicating that the second NF (730, 740) accepted the FL preparation request is based on the determination.

22. The method of any one of claims 14 to 21, wherein: One or more of the following apply: the first NF (710) is a network data analysis function NWDAF, and the second NF (730, 740) is a NWDAF.

23. A method for a network repository function (NRF) of a communication network, the method comprising: Information associated with the federated learning FL group is registered (1020) in the communication network, wherein: The FL group includes a first NF (710) configured to operate as a server (710) and one or more additional NFs (730, 740) configured to operate as clients (730, 740); and The registered information includes authorization information for the additional NF (730, 740) to join the FL group as a client (730, 740); Performing a first set of operations or a second set of operations, where The first set includes: registering (1030) information about the FL capability of the second NF (730, 740) of the communication network; and sending (1040) to the first NF (710) an indication that the second NF (730, 740) is a candidate client (730, 740) of the FL group; The second set includes: During discovery by the second NF (730, 740), the second NF (730, 740) is notified (1050) of the FL group and the first NF (710) being a server (710) of the FL group.

24. The method of claim 23, wherein: The registered authorization information includes one or more of the following items: Identifier of the FL group owner; One or more identifiers associated with a target machine learning (ML) model for which the FL group performs training; and An indication of the authorization scope of the FL group.

25. The method of claim 24, wherein: The identifier of the FL group owner is an identifier associated with the first NF (710); and The one or more identifiers associated with the target ML model include one or more of: an interoperability ID, a vendor ID, an analysis ID, a model filter, a model URL, and a model ID.

26. The method of any one of claims 24-25, wherein: The indication of the authorized scope of the FL group includes an indication or identifier of one or more of the following: One or more allowed requester and / or provider NF types; One or more allowed requester and / or provider NF IDs; One or more allowed requester and / or provider NF providers; One or more allowed interoperability IDs; or FL capabilities allowed.

27. The method of any one of claims 23 to 26, wherein: The indication that the second NF (730, 740) is a candidate client (730, 740) of the FL group is based on notification of a subscription by the first NF to a registration event of the candidate client (730, 740) of the FL group.

28. The method of claim 27, wherein: One of the following applies: The notification is an implicit indication that the second NF (730, 740) is authorized to join the FL group as a client (730, 740); or An explicit authorization token indicating that the second NF (730, 740) is authorized to join the FL group as a client (730, 740) is included with the notification.

29. The method of any one of claims 23 to 26, wherein: The second set also includes: receiving (1060) a request for an authorization token from the second NF (730, 740), the authorization token indicating that the second NF (730, 740) is authorized to join the FL group as a client (730, 740); and The requested authorization token is sent (1070) to the second NF (730, 740).

30. The method of claim 29, wherein: The authorization token includes at least a portion of the registered authorization information.

31. The method of any one of claims 23 to 30, further comprising: registering (1010) information about the FL capability of the first NF (710); as well as During discovery by the first NF (710), the first NF (710) is notified (1015) of the one or more additional NFs (730, 740) of the FL group based on information about the corresponding FL capabilities of the one or more additional NFs (730, 740) registered in the NRF (720).

32. The method of any one of claims 23 to 31, wherein: The registered information associated with the FL group also includes the following: an identifier of the FL group and / or an identifier of a FL process performed by the FL group; and Parse the identifier.

33. The method of any one of claims 23 to 32, wherein: One or more of the following apply: the first NF (710) is a network data analysis function NWDAF, and the second NF (730, 740) is a NWDAF.

34. A first network function NF (710) configured to operate as a server (710) of a federated learning FL group in a communication network, wherein: The first NF (710) is implemented by a communication interface circuit and a processing circuit that are operably coupled; and The processing circuit and the interface circuit are configured to perform operations corresponding to any of the methods of claims 1-13.

35. A first network function NF (710) configured to operate as a server (710) of a federated learning FL group in a communication network, the first NF (710) being further configured to perform operations corresponding to any of the methods of claims 1-13.

36. A non-transitory computer-readable medium storing computer-executable instructions which, when executed by a processing circuit associated with a first network function NF (710) configured to operate as a server (710) of a federated learning FL group in a communication network, configure the first NF (710) to perform operations corresponding to any of the methods of claims 1-13.

37. A computer program product comprising computer executable instructions which, when executed by a processing circuit associated with a first network function NF (710) configured to operate as a server (710) of a federated learning FL group in a communication network, configure the first NF (710) to perform operations corresponding to any of the methods of claims 1-13.

38. A second network function NF (730, 740) configured to operate as a client (730, 740) of a federated learning FL group in a communication network, wherein: The second NF (730, 740) is implemented by a communication interface circuit and a processing circuit that are operably coupled; and The processing circuit and the interface circuit are configured to perform operations corresponding to any of the methods of claims 14-22.

39. A second network function NF (710) configured to operate as a client (730, 740) of a federated learning FL group in a communication network, the second NF (730, 740) being further configured to perform operations corresponding to any of the methods of claims 14-22.

40. A non-transitory computer-readable medium storing computer-executable instructions which, when executed by a processing circuit associated with a second network function NF (730, 740) configured to operate as a client (730, 740) of a federated learning FL group in a communication network, configure the second NF (730, 740) to perform operations corresponding to any of the methods of claims 14-22.

41. A computer program product comprising computer executable instructions which, when executed by a processing circuit associated with a second network function NF (730, 740) configured to operate as a client (730, 740) of a federated learning FL group in a communication network, configure the second NF (730, 740) to perform operations corresponding to any of the methods of claims 14-22.

42. A network repository function (NRF) (720) of a communication network, wherein: The NRF (720) is implemented by operatively coupled communication interface circuitry and processing circuitry; and The processing circuit and the interface circuit are configured to perform operations corresponding to any of the methods of claims 23-33.

43. A network repository function (NRF) (720) of a communication network, the NRF (720) being configured to perform operations corresponding to any of the methods of claims 23-33.

44. A non-transitory computer readable medium storing computer executable instructions which, when executed by processing circuitry associated with a network repository function (NRF) (720) of a communication network, configures the NRF (720) to perform operations corresponding to any of the methods of claims 23-33.

45. A computer program product comprising computer executable instructions which, when executed by processing circuitry associated with a network repository function (NRF) (720) of a communication network, configure the NRF (720) to perform operations corresponding to any of the methods of claims 23-33.