Method and device for user agreement and computer readable storage medium

By managing user consent information in terminal devices, the problem of privacy leakage in user data sharing is solved, and privacy protection is achieved in the data sharing process.

CN120604531APending Publication Date: 2025-09-05HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380092760.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-02-06
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In future data-driven networks, the collection and processing of user data will need to comply with privacy protection policies and regulations, but the management of user consent in existing technologies is not strict enough, resulting in an increased risk of privacy leaks.

Method used

By storing user consent information in the terminal device and utilizing functional components such as the TruA ​​module, privacy enabler module, and flow point module, the user data provision permissions are determined and managed to ensure that data is shared only with the user's consent.

Benefits of technology

It effectively avoids unauthorized disclosure of user privacy, ensures privacy protection during data sharing, and complies with regulatory requirements agreed to by users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120604531A_ABST
    Figure CN120604531A_ABST
Patent Text Reader

Abstract

Exemplary embodiments relate to a method and device for communication, and a computer readable storage medium. In an exemplary method, a terminal device receives an agreement request from a first network device, the agreement request for a user to agree to provide user data of the user stored in the first network device to a second network device. And the terminal device determines whether the user is allowed to provide the user data to the second network device based on user agreement information stored in the terminal device. And based on determining that the user allows the user data to be provided to the second network device, the terminal device sends an agreement response to the first network device. Therefore, when the second network equipment requests the data from the first network equipment, the second network equipment can obtain the agreement of the user from the terminal equipment, so that the privacy leakage of the user is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Exemplary embodiments of the present invention generally relate to the field of telecommunications, and more particularly, to methods, apparatus, and computer-readable storage media for user consent. Background Art

[0002] The future network will be data-driven and service-oriented. Some applications in the future network will require the collection and processing of user data to provide related services. The use of personal data must comply with standards and policies and regulations established by government agencies to ensure that the privacy of users or data subjects is protected.

[0003] User consent is provided by the user, allowing or denying the collection and processing of their personal data for a specific task or application. Different services require different personal data, so user consent must be handled on a case-by-case basis. If an attacker modifies the user's consent, the service could be granted access to the user's data, or the user could be denied access to a specific service. In the former case, the user's data could be shared with a third party without their knowledge. Summary of the Invention

[0004] In general, exemplary embodiments of the present invention provide a solution for protecting privacy through user consent.

[0005] In a first aspect, a method performed by a terminal device is provided. The method includes: receiving a consent request from a first network device, the consent request being for user consent to provide user data of the user stored in the first network device to a second network device; determining whether the user allows the user data to be provided to the second network device based on user consent information stored in the terminal device; and sending a consent response to the first network device based on determining that the user allows the user data to be provided to the second network device, the consent response including an indication of the user's consent. In this way, when the second network device requests data from the first network device, the terminal device can provide the user's consent to the second network device to avoid leakage of the user's privacy. In some embodiments of the present invention, the terminal device includes a functional component module, the functional component module being configured to store the user consent information and protect the privacy of the user data. In this way, the terminal device can retain the user's consent to avoid leakage of the user's privacy.

[0006] In some embodiments of the present invention, in order to determine whether the user allows the user data to be provided to the second network device, based on receiving the consent request, the terminal device can enable the Trustworthiness Association (TruA) module in the functional component module to request authorization from the user. The terminal device can enable the TruA ​​module to map the consent request to the privacy enabler module in the functional component module based on receiving the authorization from the user. The terminal device can enable the TruA ​​module to send a first consent request to call the privacy enabler module to the flow point module in the functional component module. The terminal device can enable the TruA ​​module to receive a first consent response from the flow point module, and the first consent response includes the indication of the user's consent. In this way, the TruA ​​module can send a consent request message and a consent response message to avoid user privacy leakage.

[0007] In some embodiments of the present invention, in order to send the consent response to the first network device, the terminal device may enable the TruA ​​module to send the consent response to the first network device. In this way, the TruA ​​module can send the consent response message to avoid user privacy leakage.

[0008] In some embodiments of the present invention, in order to determine whether the user allows the user data to be provided to the second network device, the terminal device can enable the flow point module to receive a first consent request from the TruA ​​module to call the privacy enabler module. The terminal device can enable the flow point module to send a second consent request for the user's consent to the privacy enabler module. The terminal device can enable the flow point module to receive a second consent response from the privacy enabler module, the second consent response including the indication of the user's consent. The terminal device can enable the flow point module to send a first consent response to the TruA ​​module, the first consent response including the indication of the user's consent. In this way, the flow point module can send a consent request message and a consent response message to avoid user privacy leakage.

[0009] In some embodiments of the present invention, to determine whether the user permits provision of the user data to the second network device, the terminal device may cause the privacy enabler module to receive the second consent request from the stream point module. The terminal device may cause the privacy enabler module to determine, based on the user consent information, that the user permits provision of the user data to the second network device. The terminal device may cause the privacy enabler module to send the second consent response to the stream point module. In this way, the privacy enabler module may send consent request messages and consent response messages to prevent user privacy leaks.

[0010] In some embodiments of the present invention, the first network device comprises a network function (NF) in a public land mobile network (PLMN), and the second network device comprises a network data analytics function (NWDAF) in the PLMN. In this way, the NWDAF can obtain data from the NF in the PLMN with the user's consent, thereby preventing user privacy leakage.

[0011] In some embodiments of the present invention, the first network device comprises a NWDAF in a PLMN, and the second network device comprises a third-party service provider relative to the PLMN. In this way, the third-party service provider can obtain data from the NWDAF in the PLMN network with the user's consent, thereby preventing user privacy leakage.

[0012] In a second aspect, a method performed by a first network device is provided. The method includes: receiving a data request for user data of a user stored in the first network device from a second network device; sending a consent request to a terminal device storing user consent information of the user, the consent request being for the user to consent to providing the user data to the second network device; and, based on receiving a consent response from the terminal device, the consent response including an indication of the user's consent, sending a data response to the second network device, the data response including the user data and the indication of the user's consent. In this way, the first network device can send a consent request to the terminal device when the second network device requests data from the first network device, thereby preventing user privacy from being leaked.

[0013] In some embodiments of the present invention, to send the consent request to the terminal device, the first network device determines whether the second network device is authorized to access the user data; and based on determining that the second network device is authorized to access the user data, sends the consent request to the terminal device. In this way, the first network device can send the consent request to the terminal device when it determines that the second network device is authorized, thereby preventing user privacy leakage.

[0014] In some embodiments of the present invention, to send the consent request to the terminal device, the first network device determines whether the user's consent is required to provide the user data; and based on determining that the user's consent is required to provide the user data, sends the consent request to the terminal device. In this way, the first network device can send the consent request to the terminal device when it determines that the user's consent is required, thereby preventing user privacy leakage.

[0015] In some embodiments of the present invention, the first network device comprises a network function (NF) in a public land mobile network (PLMN), and the second network device comprises a network data analytics function (NWDAF) in the PLMN. In this way, the NWDAF can obtain data from the NF in the PLMN with the user's consent, thereby preventing user privacy leakage.

[0016] In some embodiments of the present invention, the first network device comprises a NWDAF in a PLMN, and the second network device comprises a third-party service provider relative to the PLMN. In this way, the third-party service provider can obtain data from the NWDAF in the PLMN network with the user's consent, thereby preventing user privacy leakage.

[0017] In a third aspect, a method performed by a second network device is provided. The method comprises: sending a data request to a first network device for user data of a user stored on the first network device; and, if the user permits provision of the user data to the second network device, receiving a data response from the first network device, the data response including the user data and an indication of the user's consent to provision of the user data to the second network device. In this manner, when the second network device requests data from the first network device, the second network device can obtain the user's consent from the terminal device, thereby preventing leakage of user privacy.

[0018] In some embodiments of the present invention, the first network device comprises a network function (NF) in a public land mobile network (PLMN), and the second network device comprises a network data analytics function (NWDAF) in the PLMN. In this way, the NWDAF can obtain data from the NF in the PLMN with the user's consent, thereby preventing user privacy leakage.

[0019] In some embodiments of the present invention, the first network device comprises a NWDAF in a PLMN, and the second network device comprises a third-party service provider relative to the PLMN. In this way, the third-party service provider can obtain data from the NWDAF in the PLMN network with the user's consent, thereby preventing user privacy leakage.

[0020] In a fourth aspect, a method performed by a terminal device is provided. The method includes: determining that user consent information of a user stored in the terminal device has been updated by the user; and sending a consent update message to a network device, the consent update message indicating the update of the user consent information. In this manner, when the user consent information is updated, a consent update message is sent to the network device to prevent user privacy leakage.

[0021] In some embodiments of the present invention, the terminal device includes a functional component module, which is used to store the user consent information and protect the privacy of the user data. In this way, the terminal device can retain the user's consent to avoid leakage of the user's privacy.

[0022] In some embodiments of the present invention, the consent update message is a first consent update message. Upon determining that the user consent information has been updated, the terminal device may cause the privacy enabler module in the functional component module to send a second consent update message to the flow point in the functional component module, where the second consent update message indicates the user's consent to the update. In this way, the privacy model can send the consent update message to prevent the user's privacy from being leaked.

[0023] In some embodiments of the present invention, the terminal device may cause the flow point module to receive the second consent update message from the privacy enabler module; and cause the flow point module to send a third consent update message to a trustworthiness association (TruA) module in the functional component module, wherein the third consent update message indicates the update consented by the user. In this way, the flow point module may forward the consent update message to prevent user privacy leakage.

[0024] In some embodiments of the present invention, to send the consent update message to the network device, the terminal device may cause the TruA ​​module to send the first consent update message to the network device based on the third consent update message received from the flow point module. In this way, the TruA ​​module can forward the consent update message to prevent user privacy leakage.

[0025] In some embodiments of the present invention, the network device includes a network function (NF) in a public land mobile network (PLMN) or a third-party service provider relative to the PLMN. In this way, a consent update message can be sent from the terminal device to the NF or the third-party service provider relative to the PLMN to prevent user privacy leakage.

[0026] In a fifth aspect, a method performed by a network device is provided. The method includes: receiving a consent update message from a terminal device storing user consent information of a user, the consent update message indicating an update to the user consent information; and updating privacy settings associated with user data of the user stored in the network device based on the update to the user consent information. In this manner, when the user consent information is updated in the terminal device, the network device receives the consent update message from the terminal device to prevent leakage of user privacy.

[0027] In some embodiments of the present invention, before updating the privacy setting, the network device performs identity authentication on the user. In this way, by performing identity authentication on the user, leakage of user privacy can be avoided.

[0028] In some embodiments of the present invention, the network device includes a network function (NF) in a public land mobile network (PLMN) or a third-party service provider relative to the PLMN. In this way, a consent update message can be sent from the terminal device to the NF or the third-party service provider relative to the PLMN to prevent user privacy leakage.

[0029] In a sixth aspect, a terminal device is provided. The terminal device includes: a communication interface; at least one processor coupled to the communication interface; a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: receive a consent request from a first network device via the communication interface, the consent request being for user consent to provide user data of the user stored in the first network device to a second network device; determine, based on user consent information stored in the terminal device, whether the user allows the user data to be provided to the second network device; and, based on determining that the user allows the user data to be provided to the second network device, send a consent response to the first network device via the communication interface, the consent response including an indication of the user's consent. In this way, when the second network device requests data from the first network device, the terminal device can provide the user's consent to the second network device to avoid leakage of the user's privacy.

[0030] In a seventh aspect, a first network device is provided. The first network device includes: a communication interface; at least one processor coupled to the communication interface; a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: receive a data request for user data of a user stored in the first network device from a second network device via the communication interface; send a consent request to a terminal device storing user consent information of the user via the communication interface, the consent request being used for the user to agree to provide the user data to the second network device; based on receiving a consent response from the terminal device via the communication interface, the consent response including an indication of the user's consent, send a data response to the second network device via the communication interface, the data response including the user data and the indication of the user's consent. In this way, the first network device can send a consent request to the terminal device when the second network device requests data from the first network device, so as to avoid leakage of user privacy.

[0031] In an eighth aspect, a second network device is provided. The second network device includes: a communication interface; at least one processor coupled to the communication interface; a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, wherein the program instructions instruct the at least one processor to: send a data request for user data of a user stored in the first network device to the first network device via the communication interface; and if the user allows the user data to be provided to the second network device, receive a data response from the first network device via the communication interface, wherein the data response includes the user data and an indication that the user agrees to provide the user data to the second network device. In this way, when the second network device requests data from the first network device, the second network device can obtain the user's consent from the terminal device to avoid leakage of user privacy.

[0032] In a ninth aspect, a terminal device is provided. The terminal device includes: a communication interface; at least one processor coupled to the communication interface; and a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: determine whether user consent information of a user stored in the terminal device has been updated by the user; and send a consent update message to a network device via the communication interface, the consent update message indicating the update of the user consent information. In this way, when the user consent information is updated, a consent update message is sent to the network device to prevent user privacy leakage.

[0033] In a tenth aspect, a network device is provided. The network device includes: a communication interface; at least one processor coupled to the communication interface; and a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: receive a consent update message from a terminal device storing user consent information of a user via the communication interface, the consent update message indicating an update to the user consent information; and update privacy settings based on the update to the user consent information, the privacy settings being associated with the user data of the user stored in the network device. In this way, when the user consent information is updated in the terminal device, the network device receives a consent update message from the terminal device to prevent leakage of user privacy.

[0034] In the eleventh aspect, a terminal device is provided. The terminal device includes a sending unit, a receiving unit, and a determining unit. The receiving unit receives a consent request from a first network device, and the consent request is for the user to agree to provide the user data of the user stored in the first network device to a second network device. The determining unit determines whether the user allows the user data to be provided to the second network device based on the user consent information stored in the terminal device. Based on determining that the user allows the user data to be provided to the second network device, the sending unit sends a consent response to the first network device, and the consent response includes an indication of the user's consent. In this way, when the second network device requests data from the first network device, the terminal device can provide the user's consent to the second network device to avoid leakage of the user's privacy.

[0035] In the twelfth aspect, a first network device is provided. The first network device includes a sending unit and a receiving unit. The receiving unit receives a data request for user data of a user stored in the first network device from a second network device. The sending unit sends a consent request to a terminal device storing user consent information of the user, and the consent request is used for the user to agree to provide the user data to the second network device. Based on the receiving unit receiving a consent response from the terminal device, the consent response includes the user's consent indication, and the sending unit sends a data response to the second network device, and the data response includes the user data and the user's consent indication. In this way, the first network device can send a consent request to the terminal device when the second network device requests data from the first network device to avoid leakage of user privacy.

[0036] In a thirteenth aspect, a second network device is provided. The second network device includes a sending unit and a receiving unit. The sending unit sends a data request for user data of a user stored in the first network device to a first network device. If the user allows the user data to be provided to the second network device, the receiving unit receives a data response from the first network device, the data response including the user data and an indication that the user agrees to provide the user data to the second network device. In this way, when the second network device requests data from the first network device, the second network device can obtain the user's consent from the terminal device to prevent the leakage of user privacy.

[0037] In a fourteenth aspect, a terminal device is provided. The terminal device includes a sending unit and a determining unit. The determining unit determines that user consent information of a user stored in the terminal device has been updated by the user. The sending unit sends a consent update message to a network device, the consent update message indicating the update of the user consent information. In this way, when the user consent information is updated, the consent update message is sent to the network device to prevent user privacy leakage.

[0038] In a fifteenth aspect, a network device is provided. The network device includes a receiving unit and a determining unit. The receiving unit receives a consent update message from a terminal device storing user consent information of a user, the consent update message indicating an update to the user consent information. The determining unit updates privacy settings based on the update to the user consent information, the privacy settings being associated with user data of the user stored in the network device. In this manner, when the user consent information is updated in the terminal device, the network device receives the consent update message from the terminal device to prevent leakage of user privacy.

[0039] In the sixteenth aspect, a communication system is provided. The communication system includes a first network device, a second network device and a terminal device. The terminal device includes at least one processor, and the at least one processor is coupled to a memory storing program instructions. The program instructions instruct the at least one processor to process the method in the first aspect. The first network device includes at least one processor, and the at least one processor is coupled to a memory storing program instructions. The program instructions instruct the at least one processor to process the method in the second aspect. The second network device includes at least one processor, and the at least one processor is coupled to a memory storing program instructions. The program instructions instruct the at least one processor to process the method in the third aspect. In this way, when the second network device requests data from the first network device, the terminal device can provide the user's consent to the second network device to avoid leakage of the user's privacy.

[0040] In the seventeenth aspect, a communication system is provided. The communication system includes a network device and a terminal device. The terminal device includes at least one processor, and the at least one processor is coupled to a memory storing program instructions. The program instructions instruct the at least one processor to process the method in the fourth aspect. The network device includes at least one processor, and the at least one processor is coupled to a memory storing program instructions. The program instructions instruct the at least one processor to process the method in the fifth aspect. In this way, when user consent information is updated in the terminal device, the network device receives a consent update message from the terminal device to avoid user privacy leakage.

[0041] In the eighteenth aspect, a chip having one or more execution units is provided, which, when instructions are executed by the one or more execution units of the chip, enables the chip to execute at least the methods in the first aspect, the second aspect, the third aspect, the fourth aspect and the fifth aspect.

[0042] In the nineteenth aspect, a computer-readable storage medium storing instructions is provided, which, when executed by one or more processors of a computing device, causes the computing device to perform at least the methods of the first, second, third, fourth and fifth aspects.

[0043] It should be understood that the summary of the invention is not intended to identify the key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which:

[0045] Figure 1A An example of a communication system in which some exemplary embodiments of the present invention may be implemented is shown;

[0046] Figure 1B An example of another communication system in which some exemplary embodiments of the present invention may be implemented is shown;

[0047] Figure 1C shows an example of a network environment in which some exemplary embodiments of the present invention may be implemented;

[0048] Figure 1D An example of a block diagram illustrating functional components in a terminal device in which some exemplary embodiments of the present invention may be implemented;

[0049] Figure 2A An example of a processing flow of a second network device requesting data from a first network device provided by some exemplary embodiments of the present invention is shown;

[0050] Figure 2B An example of a process for a terminal device to update user consent information to a network device provided by some exemplary embodiments of the present invention is shown;

[0051] Figure 3 An example of a process flow in which an NWDAF requests data from other NFs provided by some exemplary embodiments of the present invention is shown;

[0052] Figure 4 An example of a process flow in which a third-party service provider requests data from an NWDAF is shown in some exemplary embodiments of the present invention;

[0053] Figure 5 An example of a process flow for performing a privacy update consented by a user provided by some exemplary embodiments of the present invention is shown;

[0054] Figure 6 An example of a method implemented at a terminal device provided by some exemplary embodiments of the present invention is shown;

[0055] Figure 7 An example of a method implemented at a first network device provided by some exemplary embodiments of the present invention is shown;

[0056] Figure 8 An example of a method implemented at a second network device provided by some exemplary embodiments of the present invention is shown;

[0057] Figure 9 An example of a method implemented at a terminal device provided by some exemplary embodiments of the present invention is shown;

[0058] Figure 10 An example of a method implemented at a network device provided by some exemplary embodiments of the present invention is shown;

[0059] Figure 11 shows a simplified block diagram of a communication device suitable for implementing some exemplary embodiments of the present invention;

[0060] Figure 12 shows another simplified block diagram of a terminal device suitable for implementing some exemplary embodiments of the present invention;

[0061] Figure 13 shows a simplified block diagram of a first network device suitable for implementing some exemplary embodiments of the present invention;

[0062] Figure 14 shows another simplified block diagram of a terminal device suitable for implementing some exemplary embodiments of the present invention;

[0063] Figure 15 A simplified block diagram of a network device suitable for implementing some exemplary embodiments of the present invention is shown.

[0064] Throughout the drawings, the same or similar reference numerals refer to the same or similar elements. DETAILED DESCRIPTION

[0065] The principle of the present invention will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described merely to illustrate and help those skilled in the art understand and implement the present invention, without limiting the scope of the present invention. The disclosure described herein can be implemented in a variety of ways except for the manner described below.

[0066] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art.

[0067] References to "one embodiment," "an exemplary embodiment," etc., in this disclosure indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment must include the particular feature, structure, or characteristic. Furthermore, these phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in conjunction with an embodiment, it is understood that it is within the knowledge of those skilled in the art to affect such feature, structure, or characteristic in conjunction with other embodiments, whether or not explicitly described.

[0068] It should be understood that although terms such as "first" and "second" may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, a first element can be referred to as a second element, and similarly, a second element can be referred to as a first element without departing from the scope of the exemplary embodiments. The term "and / or" as used herein includes any and all combinations of one or more of the listed items.

[0069] The terms used herein are intended only to describe specific embodiments and are not intended to limit exemplary embodiments. Unless the context clearly indicates otherwise, the singular forms "a," "an," and "the" used herein are intended to include the plural forms. It should also be understood that the terms "comprising," "having," and / or "including," when used herein, specify the presence of the features, elements, and / or components, but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0070] The term "communication network" as used herein refers to a network that complies with any suitable communication standard, such as long term evolution (LTE), LTE-Advanced (LTE-A), wideband code division multiple access (WCDMA), high-speed packet access (HSPA), narrowband internet of things (NB-IoT), etc. In addition, the communication between the terminal equipment and the network equipment in the communication network can be performed according to any suitable generation of communication protocol, including but not limited to the fourth generation (4G), 4.5G, the future fifth generation (5G) communication protocol and / or any other protocol currently known or to be developed in the future. The embodiments of the present invention can be applied to various communication systems. In view of the rapid development of communications, there will certainly be future types of communication technologies and systems that can be combined with the present invention. It should not be considered that the scope of the present invention is limited to the aforementioned system.

[0071] The term "network function" (NF) used in this document refers to functions in the 5G core network, including at least one of the following: network slice selection function (NSSF), network exposure function (NEF), network repository function (NRF), policy control function (PCF), unified data management (UDM), unified data repository (UDR), application function (AF), network data analytics function (NWDAF), trusted non-3GPP gateway function (TNGF), authentication server function (AUSF), access and mobility management function (AMF), session management function (SMF) and user plane function (UPF).

[0072] The term "terminal device" refers to any terminal device capable of wireless communication. By way of example and not limitation, a terminal device may also be referred to as a communication device, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices may include, but are not limited to, mobile phones, cellular phones, smartphones, voice over IP (VoIP) phones, wireless local loop phones, tablet computers, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image capture terminal devices (such as digital cameras), game terminal devices, music storage and playback devices, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMD), vehicles, drones, medical devices and applications (such as remote surgery), industrial devices and applications (such as robots and / or other wireless devices operating in the context of industrial and / or automated process chains), consumer electronic devices, devices operating in commercial and / or industrial wireless networks, etc. In the following description, the terms "terminal device", "communication device" and "terminal" may be used interchangeably.

[0073] As mentioned above, future networks will be data-driven and service-oriented. Some applications in future networks will require the collection and processing of user data in order to provide related services. The use of personal data must comply with standards, policies, and regulations established by government agencies to ensure the privacy of users or data subjects is protected. According to Article 4 of the General Data Protection Regulation (GDPR), personal data is defined as "any information relating to an identified or identifiable natural person ('data subject')." Third Generation Partnership Project (3GPP) TR33.849 mentions user consent as a potential privacy requirement. Services that collect personal information should require this requirement. User consent is provided by the user, in which the user allows or denies the collection and processing of their personal data for a specific task or application. Different services require different personal data, so user consent must be handled on a case-by-case basis.

[0074] In the 5G architecture, UDR utilizes services provided by UDM to store user consent for user data. This consent is received from the mobile network operator (MNO) as part of the user's subscription information. If any attacker modifies the user's consent, the service may be granted access to the user's data, or the user may be denied access to specific services. In the former case, the user's data will be shared with a third party without their knowledge.

[0075] Whenever an application uses user data to provide a service, user consent may be required. NFs in cellular networks may need to obtain user consent before sharing user information with third-party service providers, otherwise privacy may be compromised. Whenever a user updates their consent to decline the use of personal data, the third-party service provider or NF must delete the user data accordingly, otherwise privacy may be compromised.

[0076] In view of the above, several communication solutions for privacy protection are proposed. Some embodiments of the present invention propose to store the user's consent in the terminal device, for example, in a functional component module that takes privacy as one of the enabler functions.

[0077] Some embodiments of the present invention provide a protocol for obtaining user consent in a terminal device when a network device (e.g., NWDAF) requests data from another network device (e.g., other NF) in the same public land mobile network (PLMN). 5G network functions (NFs) collect user data, such as location, profile, and the network to which the user is currently subscribed. NWDAF collects user data from other NFs to provide behavioral analysis, mobility analysis, etc. When sharing data with NWDAF, user consent is required to ensure privacy protection in the NF and avoid privacy leakage without the user's permission.

[0078] Some embodiments of the present invention provide a protocol for obtaining user consent in a terminal device when a third-party service provider requests data from a network device (e.g., NWDAF). NWDAF analysis information is shared with the third-party service provider to provide services. When the third-party service provider requests analysis information from NWDAF, user consent is required to ensure privacy protection in NWDAF and prevent privacy disclosure without user permission.

[0079] Some embodiments of the present invention also provide a protocol in the terminal device when the user updates their consent. When a user updates their consent for a specific service, the third party or the NF may need to update the user data privacy policy accordingly. For example, if a user unsubscribes from a service that provides mobility analytics and does not want the NF or third-party service provider to collect their mobility data, the NF or third-party service provider will need to delete the mobility-related user data. Under some data protection regulations, users have a "right to be forgotten."

[0080] Figure 1A An example of a communication system 100 in which some exemplary embodiments of the present invention may be implemented is shown. Communication system 100 includes a first network device 101, a second network device 103, and a terminal device 105. In some embodiments, first network device 101 and second network device 103 can communicate with each other, and first network device 101 and terminal device 105 can communicate with each other. In some embodiments, second network device 103 requests data from first network device 101, which requires the consent of the user of terminal device 105.

[0081] Figure 1B FIG1 shows an example of a communication system 110 in which some exemplary embodiments of the present invention may be implemented. In the communication system 110, the terminal device 105 may communicate with the network device 107. In some embodiments, when a user updates user consent in the terminal device 105, the terminal device 105 may need to send consent update information to the network device 107.

[0082] Figure 1C An example of a network environment 120 in which some exemplary embodiments of the present invention may be implemented is shown. In the network environment 120, there are a base station 121, a terminal device (TD) 125, a first core network function 123, a third-party service provider 127, and a second core network function 129. Figure 1C The terminal device 125 is Figure 1A or Figure 1B In some embodiments, Figure 1C The first core network function 123 is Figure 1A In the example of the first network device 101, Figure 1C The second core network function 129 is Figure 1A Optionally, in some other embodiments, Figure 1C The third-party service provider 127 is Figure 1A An example of the second network device 103 in .

[0083] If the second core network function 129 is an example of the second network device 103, the first core network function 123 may be an NF, and the second core network function 129 may be an NWDAF. The NWDAF requests data from the NF and needs to obtain the user consent of the terminal device 125. If the third-party service provider 127 is an example of the second network device 103, the first core network function 123 may be an NWDAF. The third-party service provider 127 requests data from the NWDAF and needs to obtain the user consent of the terminal device 125. In some embodiments, the first core network function 123 may be Figure 1B In some other embodiments, the third party service provider 127 may be Figure 1B An example of a network device 107 in FIG.

[0084] Figure 1DAn example block diagram of a functional component 130 in a terminal device 105 that can implement some exemplary embodiments of the present invention is shown. In some embodiments of the present invention, a functional component 130 (also referred to as a trusted functional component 130) is defined for security functions. Within the trusted functional component 130 are several modules: a trusted alliance (TruA) module 131, an encryption module 135, an authorization module 137, a flow point functional component (FPoint_G) module 133, an attestation module 139, a privacy enabler module 141, a blockchain module 145, a management functional component (Mana_G) module 149, and a root of trust module 147. The privacy enabler module 141 maintains user consent 143. The TruA ​​module 131 serves as an interface between modules within the functional component 130 and functions outside of the functional component 130. The TruA ​​module 131 also includes certain communication protocols. The flow point module 133 serves as an information bridge for communication between other modules within the functional component 130 (e.g., the encryption module 135, the authorization module 137, the attestation module 139, etc.).

[0085] The encryption module 135 implements functions such as signature, symmetric encryption, asymmetric encryption, etc. The authorization module 137 implements static authorization and token-based authorization. The certification module 139 implements verification, challenge generation, evidence generation, and reference value generation. The trusted root module 147 includes a key, a standard value, and a certificate. The management function component module 149 includes or has a function component profile, an update management function, and a monitoring function. Some embodiments of the present invention can be used in cellular networks, such as 5G, 6G, Wi-Fi networks, Bluetooth networks, and proprietary wireless networks, which collect the user's personal data and require the user's consent before collecting the data. It will be appreciated by those skilled in the art that the trusted function component 130 may also be located in other devices other than the terminal device, such as in a base station, or in a core network function.

[0086] Figure 2AAn example of a processing flow 200 in which the second network device 103 requests data from the first network device 101, provided by some exemplary embodiments of the present invention, is shown. In the processing flow 200, the second network device 103 sends (208) a data request 210 to the first network device 101. The data request 210 is used to request user data of a user stored in the first network device 101. The first network device 101 receives (212) the data request 210 from the second network device 103. Then, the first network device 101 sends (213) a consent request 215 to the terminal device 105 storing the user consent information of the user. The consent request 215 is used to request the user's consent to provide the user data stored in the first network device 101 to the second network device 103. The terminal device 105 receives (217) the consent request 215 from the first network device 101.

[0087] Then, the terminal device 105 determines (220) whether the user allows the user data to be provided to the second network device 103 based on the user consent information stored in the terminal device 105. Based on determining that the user allows the user data to be provided to the second network device 103, the terminal device 105 sends (223) a consent response 225 to the first network device 101. The consent response 225 includes an indication of the user's consent. Based on receiving (227) the consent response 225 including an indication of the user's consent from the terminal device 105, the first network device 101 sends (228) a data response 230 to the second network device 103. The data response 230 includes the user data and an indication of the user's consent. Therefore, the second network device 102 can receive (232) the user data and the indication of the user's consent from the first network device 101. In this way, when the second network device 103 requests data from the first network device 101, it can obtain the user's consent from the terminal device 105 to avoid leakage of the user's privacy.

[0088] like Figure 1D As shown, in some embodiments of the present invention, the terminal device 105 includes a functional component module 130. The functional component module 130 can be used to store user consent information and maintain the privacy of user data to prevent user privacy leakage. As described above, the functional component module 130 in the terminal device 105 includes several modules, such as a trustworthiness association (TruA) module 131, a flow point module 133, and a privacy enabler module 141 including a user consent module 143.

[0089] In some embodiments of the present invention, after receiving the consent request 215, the terminal device 105 causes the Trustworthiness Association (TruA) module 131 to request authorization from the user. After receiving the authorization from the user, the terminal device 105 causes the TruA ​​module 131 to map the consent request to the privacy enabler module 141. The terminal device 105 causes the TruA ​​module 131 to send a first consent request to the flow point module 133 to invoke the privacy enabler module 141. The terminal device 105 causes the TruA ​​module 131 to receive a first consent response from the flow point module 133, the first consent response including an indication of the user's consent.

[0090] The terminal device 105 causes the TruA ​​module 131 to send a consent response to the first network device 101. The terminal device 105 causes the stream point module 133 to receive a first consent request from the TruA ​​module 131, which invokes the privacy enabler module 141. The terminal device 105 causes the stream point module 133 to send a second consent request to the privacy enabler module 141 for the user's consent. The terminal device 105 causes the stream point module 133 to receive a second consent response from the privacy enabler module 141. The second consent response includes an indication of the user's consent. The terminal device 105 causes the stream point module 133 to send the first consent response to the TruA ​​module 131. The first consent response includes an indication of the user's consent. The terminal device 105 causes the privacy enabler module 141 to receive the second consent request from the stream point module 133. Based on the user consent information, the terminal device 105 causes the privacy enabler module 141 to determine whether the user has permitted the user data to be provided to the second network device 103.

[0091] Terminal device 105 causes privacy enabler module 141 to send a second consent response to stream point module 133. Thus, the consent request is sent from TruA ​​module 131 to stream point module 133, and finally to privacy enabler module 141. Based on user consent 143, terminal device 105 causes privacy enabler module 141 to determine that the user permits the user data to be provided to second network device 103. The consent response is sent from privacy enabler module 141 to stream point module 133, and finally to TruA ​​module 131 and first network device 101. In this way, when second network device 103 requests data from first network device 101, it can obtain user consent from terminal device 105, thereby preventing the user's privacy from being leaked.

[0092] In some embodiments of the present invention, first network device 101 comprises a network function (NF) in a public land mobile network (PLMN); second network device 103 comprises a network data analytics function (NWDAF) in the PLMN. In some embodiments of the present invention, first network device 101 comprises an NWDAF in the PLMN; second network device 103 comprises a third-party service provider for the PLMN. This allows the NWDAF to obtain user consent from the terminal device 105 when requesting data from the NF, or the third-party service provider to obtain user consent from the terminal device 105 when requesting data from the NWDAF, thereby preventing privacy leaks.

[0093] In some embodiments of the present invention, first network device 101 determines whether second network device 103 is authorized to access user data. After determining that second network device 103 is authorized to access user data, first network device 101 sends a consent request to terminal device 105. In some embodiments of the present invention, first network device 101 determines whether providing user data requires user consent. After determining that providing user data requires user consent, first network device 101 sends a consent request to terminal device 105. This allows first network device 101 to authenticate and confirm consent before sending the consent request to terminal device 105, thereby preventing user privacy leaks.

[0094] Figure 2B An example of a processing flow 240 for updating user consent information from a terminal device 105 to a network device 107 provided by some exemplary embodiments of the present invention is shown. In the processing flow 240, the terminal device 105 determines (250) that the user consent information of a user stored in the terminal device has been updated by the user. Then, the terminal device 105 sends (253) a consent update message 255 to the network device 107, wherein the consent update message 255 indicates the update of the user consent information. The network device 107 receives (257) the consent update message from the terminal device 105 storing the user consent information of the user. The consent update message 255 indicates the update of the user consent information. Then, after updating the user consent information, the network device 107 updates (260) the privacy settings associated with the user data of the user stored in the network device. In this way, when the user updates the consent information, a consent update message can be sent from the terminal device 105 to the network device 107, causing the network device 107 to update the privacy settings accordingly. This can prevent the user's privacy from being leaked.

[0095] In some embodiments of the present invention, Figure 1DAs shown, the functional component module 130 in the terminal device 105 includes several modules: a trustworthiness association (TruA) module 131, a flow point module 133, a privacy enabler module 141 including a user consent module 143, etc. After determining that the user consent information has been updated, the terminal device 105 causes the privacy enabler module 141 to send a second consent update message to the flow point module 133. The second consent update message indicates the update of the user consent. The terminal device 105 causes the flow point module 133 to receive the second consent update message from the privacy enabler module 141. The terminal device 105 causes the flow point module 133 to send a third consent update message to the TruA ​​module 131. The third consent update message indicates the update of the user consent. After receiving the third consent update message from the flow point module 133, the terminal device 105 causes the TruA ​​module 131 to send a first consent update message to the network device 107. In this way, the consent update message can be gradually sent from the privacy module 141 to the flow point module 133, then to the TruA ​​module 131, and finally to the network device 107. This allows the network device to update the privacy settings accordingly to avoid the user's privacy leakage.

[0096] In some embodiments of the present invention, network device 107 comprises a network function (NF) in a public land mobile network (PLMN) or a third-party service provider associated with the PLMN. In some embodiments of the present invention, network device 107 authenticates the user before updating privacy settings. This allows different network functions to update privacy settings based on user consent, making privacy settings updates more flexible and preventing privacy leaks.

[0097] In some embodiments of the present invention, three scenarios are proposed: (i) NWDAF requests data from other NFs in the same PLMN, (ii) a third-party service provider requests data from NWDAF, and (iii) a user performs a privacy update with user consent. The following table provides a description of the attributes used in the protocol in each scenario.

[0098]

[0099] Figure 3 FIG. 3 shows an example of a process flow 300 in which NWDAF 301 requests data from another NF 303 provided by some exemplary embodiments of the present invention. It should be understood that the process flow 300 is as follows: Figure 2AA more specific example of the process flow 200 is shown. NWDAF 301 is an example of the second network device 103 , NF 303 is an example of the first network device 101 , and functional component 130 is a module of the terminal device 105 .

[0100] like Figure 3 As shown, NWDAF 301 requests data from other NFs 303 within the same PLMN. 5G network functions (NFs) 303 collect user data, such as location and profile, and the user's current network subscription. NWDAF 301 collects user data from NFs 303 to provide behavioral and mobility analytics. User consent is required when sharing data with NWDAF 301. This scenario may pose a privacy threat, and NWDAF 301 must obtain user consent before collecting data; otherwise, privacy breaches may occur.

[0101] NWDAF 301 sends (308) a data request 310 for analysis purposes to other NF 303 via Request_for_data(user ID, PLMN ID, analysis ID, data). After receiving (312) the data request 310, NF 303 authenticates NF 303 in 315 and checks whether NWDAF 301 is authorized to access the data and whether the request comes from a legitimate network function. NF 303 has a whitelist of entities that can access the data maintained by the blockchain module. NF 303 also checks whether user consent is required to perform the analysis. In this way, NF 303 can prevent NWDAF 301 from accessing the data without authorization, thereby preventing illegal data access.

[0102] NF 303 further sends (318) a request message 320 NTruGear_Request_for_data (user ID, PLMN ID, analysis ID, Consent_Request, data) to the functional component module 130. In this way, the request from NWDAF 301 can be forwarded to the functional component module 130 to be confirmed in the user consent 143 in the functional component module 130 to protect privacy and avoid leakage of private information.

[0103] The TruA ​​module 131 in the functional component module 130 is the first interaction point in the functional component module 130 that communicates with the external interface (external to the functional component module). Once the functional component module 130 receives the request 320, the TruA ​​module 131 requests authorization (340) from the user through the Nuser (GUI) interface, and after receiving the agreement, maps the consent request to the privacy enabler module 141. The TruA ​​module 131 sends (343) GFlowPoint_Request (enabler ID, analysis ID, consent_request, data) 345 to the flow point module 133 and requests the flow point module 133 to call the privacy enabler module 141. The flow point module 306 then sends (348) GPrivacy_UserConsent_Request (analysis ID, consent_request, data) 350 to the privacy enabler module 141, requesting the privacy enabler module 141 to consent.

[0104] After receiving (352) GPrivacy_UserConsent_Request(analysis ID, Consent_Request, data) 350, the privacy enabler module 141 checks (355) for user consent 143. The privacy enabler module (141) sends (358) a response 360 ​​to the flow point module 133 via GPrivacy_UserConsent_Response(analysis ID, Consent_Response, data). The flow point module 133 sends (363) the response 365 to the TruA ​​module 131 along with the enabler identifier and the analytic identifier in GFlowPoint_Response(enabler ID, analytic ID, Consent_Response, data). The enabler identifier corresponds to the ID of the privacy enabler module 141, indicating that the response 365 is from the privacy enabler module. In this way, through several requests and responses within the functional component module 130 in TD 105, the data request from NWDAF 301 to NF 303 for analysis purposes can be authorized by the user consent 143 in the functional component module 130 in TD 105 to avoid leakage of private information in data analysis.

[0105] The TruA ​​module 131 then converts (325) the response message 365 to the external interface and sends (328) a response message 330 to the NF 303 via Response_for_data(User ID, PLMN ID, Analysis ID, Consent_Response, Data). The user ID and PLMN ID are indicated in the message 330 along with the consent response and other parameters. The NF 303 finally sends (333) a response message 335 to the NWDAF 301 via Response_for_data(User ID, PLMN ID, Analysis ID, Consent_Response, Data). In this way, the NWDAF 301 can obtain a response message with the user ID and PLMN ID. The response message indicates the analysis permission from the user consent 143 to prevent the leakage of privacy information during data analysis.

[0106] Figure 4 FIG4 shows an example of a processing flow 400 in which a third-party service provider 401 requests data from an NWDAF 403 provided by some exemplary embodiments of the present invention. It should be understood that the processing flow 400 is as follows: Figure 2A A more specific example of the process flow 200 is shown. The third-party service provider 401 is an example of the second network device 103 , the NWDAF 403 is an example of the first network device 101 , and the functional component 130 is a module of the terminal device 105 .

[0107] In some embodiments of the present invention, a third-party service provider 401 requests data from NWDAF 301. NWDAF analysis information is shared with the third-party service provider 401 to provide services. When the third-party service provider 401 requests analysis information from NWDAF 301, user consent is required. In this scenario, the privacy threat is that the NF must obtain user consent before sharing user information with the third-party service provider 401; otherwise, privacy will be compromised.

[0108] like Figure 4As shown, the third-party service provider 401 sends (408) a data request 410 to the NWDAF 301 via the message NTruGear_Request_for_data(userID, PLMNID, SerPovID, SerID, data). The NWDAF 301 authenticates the third-party service provider 401 (315) and checks whether the third-party service provider 401 is authorized to access the data and whether the request comes from a legitimate network function. The NWDAF 301 has a whitelist of entities that can access the data maintained by the blockchain module. The NWDAF 301 also checks whether user consent is required. The NWDAF 301 also sends (418) a request 420 to the functional component module 130 and the user consent 143 via the message NTruGear_Request_for_data(userID, PLMNID, SerPovID, SerID, Consent_Request, data). In this way, the request from the third-party service provider 401 can be forwarded to the functional component module 130 to be confirmed in the user consent 143 in the functional component module 130 to protect privacy and avoid leakage of private information.

[0109] The TruA ​​module 131 in the functional component module 130 is the first interaction point in the functional component module 130 for communicating with an external interface outside the functional component module 130. Once the functional component module 130 receives the request 420, the TruA ​​module 131 requests authorization (440) from the user through the Nuser (GUI) interface and, after receiving the agreement, maps the consent request to the privacy enabler module 141. The TruA ​​module 131 sends (443) a GFlowPoint_Request (enablerID, SerProvID, SerID, Consent_Request, data) 445 to the flow point module 133 to request the flow point module 133 to call the privacy enabler module 141. The flow point module 133 then sends (448) a request for consent 450 to the privacy enabler module 141 through GPrivacy_UserConsent_Request (SerProvID, ServID, Consent_Request, data). The privacy enabler module 141 checks ( 455 ) the user consent 143 .

[0110] The privacy enabler module 141 sends a response 460 (458) to the flow point module 133 via GPrivacy_UserConsent_Response (SerProvID, SerID, Consent_Response, data). The flow point module 133 sends a response 465 together with the enabler identifier (EnablerID) and the service provider identifier (SerProvID) in GFlowPoint_Response (EnablerID, SerProvID, SerID, Consent_Response, data) to the TruA ​​module 131 (463). The enabler ID indicates that the response is from the privacy enabler module 141 and corresponds to the identifier of the privacy enabler module 141. In this way, through several requests and responses within the functional component module in the TD 105, the data request from the NWDAF 301 to the NF 303 for analysis purposes can be permitted by the user consent 143 in the functional component module 130 in the TD 105 to avoid leakage of private information in data analysis.

[0111] The TruA ​​module 131 converts (425) the response 465 to the external interface and then sends (428) a message 430 to the NWDAF 301 via Response_for_data(UserID, PLMNID, SerProvID, SerID, Consent_Response, data). The user ID and PLMNID are indicated in the message along with the consent response and other parameters. The NWDAF 301 finally sends (433) a response 435 to the third-party service provider 401 via Response_for_data(UserID, PLMNID, SerPovID, SerID, Consent_Response, data). In this way, the third-party service 401 can obtain a response message with the user ID and PLMNID. The response message indicates the data access rights from the user consent 143 to prevent privacy information leakage during data analysis.

[0112] Figure 5 FIG. 5 shows an example of a process 500 for performing a privacy update with user consent provided by some exemplary embodiments of the present invention. It should be understood that the process 500 is as follows: Figure 2B A more specific example of the process flow 240 is shown. NF501 is an example of the network device 107, and the functional component 130 is a module of the terminal device 105.

[0113] In some embodiments of the present invention, privacy refers to updates to user consent made by the user. When a user updates their consent for a specific service, the third-party service provider or NF must update the user data privacy policy accordingly. For example, if a user unsubscribes from a mobility analytics service and does not wish the NF or third-party service provider to collect their mobility data, the NF or third-party service provider must delete the mobility-related user data. Under some data protection regulations, users have a "right to be forgotten."

[0114] The privacy threat is that if the user makes any changes to their consent, their data must be destroyed accordingly, otherwise their privacy will be compromised. The security threat is that if any attacker modifies the user's consent, the service may be granted access to the user's data, or the user may be denied access to a specific service. In the first case, the user's data will be shared with a third-party service without their knowledge.

[0115] like Figure 5 As shown, at 510, the user modifies the privacy settings of the subscribed service and updates the user consent 143. The privacy enabler module 141 sends (513) a message 515 mentioning the service provider ID, service ID, consent update, and data update to the flow point module 133 in the functional component module. The following is the detailed message sent by the privacy enabler 141: GPrivacy_UserConsent_Update (SerPovID, SerID, Consent_Update, data). The flow point module 133 sends (518) a message 520 to the TruA ​​module 131 via GFlowPoint_UserConsent_Update (enabler ID, SerPovID, SerID, Consent_Update, data). The TruA ​​module 131 converts the message (524) to the external interface and sends it (523) to the specific NF 303 or third-party service provider via NTruGear_UserConsent_Update(UserID, PLMNID, SerPovID, SerID, Consent_Update, Data) 525. The NF 303 authenticates the user and updates the user data privacy settings. In this way, the user update in the user consent 143 can be sent to the NF 303 or third-party service provider to prevent access to the user's private data and avoid privacy leakage.

[0116] Figure 6An example of a method 600 implemented at a terminal device 105, provided by some exemplary embodiments of the present invention, is shown. In block 610, terminal device 105 receives a consent request from first network device 101, wherein the consent request is for user consent to provide user data of the user stored in first network device 101 to second network device 103. In block 620, terminal device 105 determines whether the user permits provision of the user data to the second network device based on the user consent information stored in terminal device 105. In block 630, based on determining that the user permits provision of the user data to second network device 103, terminal device 105 sends a consent response to first network device 101, including an indication of the user's consent.

[0117] In some embodiments of the present invention, the terminal device 105 includes a functional component module 130, which is configured to store user consent information and protect the privacy of user data. In some embodiments of the present invention, to determine whether the user allows the user data to be provided to the second network device 103, based on receiving a consent request, the terminal device 105 may cause a trustworthiness association (TruA) module 131 in the functional component module 130 to request authorization from the user. In addition, based on receiving the authorization from the user, the terminal device 105 may cause the TruA ​​module 131 to map the consent request to the privacy enabler module 141 in the functional component module 130. In addition, the terminal device 105 may cause the TruA ​​module 131 to send a first consent request to the flow point module 133 in the functional component module 130, invoking the privacy enabler module 141. Finally, the terminal device 105 may cause the TruA ​​module 131 to receive a first consent response from the flow point module 133, the first consent response including an indication of the user's consent.

[0118] In some embodiments of the present invention, in order to send a consent response to the first network device 101 , the terminal device 105 may enable the TruA ​​module 131 to send a consent response to the first network device 101 .

[0119] In some embodiments of the present invention, to determine whether the user permits the provision of user data to the second network device 103, the terminal device 105 may cause the stream point module 133 to receive a first consent request from the TruA ​​module 131 to invoke the privacy enabler module 141. Additionally, the terminal device 105 may cause the stream point module 133 to send a second consent request for the user's consent to the privacy enabler module 141. Additionally, the terminal device 105 may cause the stream point module 133 to receive a second consent response from the privacy enabler module 141, the second consent response including an indication of the user's consent. Additionally, the terminal device 105 may cause the stream point module 133 to send a first consent response to the TruA ​​module 131, the first consent response including an indication of the user's consent.

[0120] In some embodiments of the present invention, to determine whether the user permits the provision of user data to the second network device 103, the terminal device 105 causes the privacy enabler module 141 to receive a second consent request from the stream point module 133. Alternatively, the terminal device 105 may cause the privacy enabler module 141 to determine, based on the user consent information, that the user permits the provision of user data to the second network device 103. Alternatively, the terminal device 105 may cause the privacy enabler module 141 to send a second consent response to the stream point module.

[0121] In some embodiments of the present invention, first network device 101 comprises a network function (NF) in a public land mobile network (PLMN); second network device 103 comprises a network data analytics function (NWDAF) in the PLMN. In some embodiments of the present invention, first network device 101 comprises an NWDAF in the PLMN; and second network device 103 comprises a third-party service provider for the PLMN.

[0122] Figure 7 An example of method 700 implemented at first network device 101, provided by some exemplary embodiments of the present invention, is shown. In block 710, first network device 101 receives a data request from second network device 103 for user data of a user stored on the first network device. In block 720, first network device 101 sends a consent request to terminal device 105, which stores user consent information for the user, regarding the user's consent to provide the user data to the second network device. In block 730, upon receiving a consent response from terminal device 105 including an indication of the user's consent, first network device 101 sends a data response to second network device 103, including the user data and an indication of the user's consent.

[0123] In some embodiments of the present invention, in order to send the consent request to terminal device 105, first network device 101 can cause first network device 101 to determine whether second network device 103 is authorized to access user data. In addition, based on determining that second network device 103 is authorized to access user data, first network device 101 sends the consent request to terminal device 105.

[0124] In some embodiments of the present invention, first network device 101 determines whether providing user data requires user consent in order to send a consent request to terminal device 105. Additionally, based on determining that providing user data requires user consent, first network device 101 sends a consent request to terminal device 105.

[0125] In some embodiments of the present invention, first network device 101 comprises a network function (NF) in a public land mobile network (PLMN); second network device 103 comprises a network data analytics function (NWDAF) in the PLMN. In some embodiments of the present invention, first network device 101 comprises an NWDAF in the PLMN; and second network device 103 comprises a third-party service provider for the PLMN.

[0126] Figure 8 An example of a method 800 implemented at the second network device 103 according to some exemplary embodiments of the present invention is shown. In block 810, the second network device 103 sends a data request to the first network device 101 for user data of a user stored in the first network device 101. In block 820, if the user allows the user data to be provided to the second network device 103, the second network device 103 receives a data response from the first network device 101, the data response including the user data and an indication that the user agrees to provide the user data to the second network device 103.

[0127] In some embodiments of the present invention, first network device 101 comprises a network function (NF) in a public land mobile network (PLMN); second network device 103 comprises a network data analytics function (NWDAF) in the PLMN. In some embodiments of the present invention, first network device 101 comprises an NWDAF in the PLMN; and second network device 103 comprises a third-party service provider for the PLMN.

[0128] Figure 9 An example of a method 900 implemented at a terminal device 105 according to some exemplary embodiments of the present invention is shown. In block 910, the terminal device 105 determines that user consent information of a user stored in the terminal device 105 has been updated by the user. In block 910, the terminal device 105 sends a consent update message to the network device 107, the consent update message indicating the update of the user consent information.

[0129] In some embodiments of the present invention, terminal device 105 includes a functional component module 130 configured to store user consent information and protect the privacy of user data. In some embodiments of the present invention, the consent update message is a first consent update message. Upon determining that the user consent information has been updated, privacy enabler module 141 in functional component module 130 sends a second consent update message to flow point 133 in functional component module 130, the second consent update message indicating the update of the user consent.

[0130] In some embodiments of the present invention, the flow point module 133 receives a second consent update message from the privacy enabler module 141. The flow point module 133 sends a third consent update message to the trustworthiness association (TruA) module 131 in the functional component module 130, wherein the third consent update message indicates the update of the user consent. In some embodiments of the present invention, in order to send the consent update message to the network device 107, based on receiving the third consent update message from the flow point module 133, the terminal device 105 may cause the TruA ​​module 131 to send the first consent update message to the network device 107. In some embodiments of the present invention, the network device 107 includes a network function (NF) in a public land mobile network (PLMN) or a third-party service provider relative to the PLMN.

[0131] Figure 10 An example of method 1000 implemented at network device 107, provided by some exemplary embodiments of the present invention, is shown. In block 1010, network device 107 receives a consent update message from terminal device 105 storing user consent information for a user, the consent update message indicating an update to the user consent information. In block 1020, network device 107 updates privacy settings associated with user data of the user stored in network device 107 based on the update to the user consent information.

[0132] In some embodiments of the present invention, before updating the privacy settings, the network device 107 authenticates the user. In some embodiments of the present invention, the network device 107 comprises a network function (NF) in a public land mobile network (PLMN) or a third-party service provider relative to the PLMN.

[0133] Figure 11 1 shows a simplified block diagram of a communication device 1100 suitable for implementing some exemplary embodiments of the present invention. For example, the communication device 1100 may be used to implement Figure 1A As another example, a communication device 1100 may be provided to implement the following: Figure 1B As another example, a communication device 1100 may be provided to implement the following Figure 1C The terminal device 125, the first core network device 123, the third-party service provider 127 or the second core network device 129 shown.

[0134] like Figure 11 As shown, the communication device 1100 includes one or more processors 1110, one or more memories 1130, and one or more communication interfaces 1120. The processor 1110 can be of any type suitable for the local technology network and can include one or more of the following: a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture, as non-limiting examples. The communication device 1100 can have multiple processors, such as application-specific integrated circuit chips that are time-slave to a clock synchronized with a main processor.

[0135] The memory 1130 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM), electrically programmable read-only memory (EPROM), flash memory, hard disks, compact discs (CDs), digital video disks (DVDs), and other magnetic and / or optical memories. Examples of volatile memories include, but are not limited to, random access memory (RAM) and other volatile memories that do not persist during a power outage.

[0136] The communication interface 1120 may be used for bidirectional communication. The communication interface 1120 may have at least one antenna to facilitate communication. The communication interface 1120 may represent any interface required to communicate with other network elements.

[0137] Processor 1110 is configured to control communication interface 1120 to receive and transmit signals. Memory 1130 is configured to store computer programs. Processor 1110 is configured to call and execute computer programs from memory 1130, causing communication device 1100 to perform corresponding processes and / or operations in various embodiments of the communication method disclosed herein.

[0138] Figure 12 Another simplified block diagram of a terminal device suitable for implementing some exemplary embodiments of the present invention is shown; Figure 12 As shown, terminal device 105 includes a sending unit 1210, a receiving unit 1220, and a determining unit 1230. Receiving unit 1220 receives a consent request from first network device 101, wherein the consent request is for the user to consent to providing the user data of the user stored in first network device 101 to second network device 103. Determining unit 1230 determines whether the user permits the user data to be provided to second network device 103 based on the user consent information stored in terminal device 105. Based on determining that the user permits the user data to be provided to second network device 103, sending unit 1210 sends a consent response including an indication of the user's consent to first network device 101.

[0139] Figure 13 A simplified block diagram of a first network device suitable for implementing some exemplary embodiments of the present invention is shown. First network device 101 includes a sending unit 1310 and a receiving unit 1320. Receiving unit 1320 receives a data request from second network device 103 for user data of a user stored in first network device 101. Sending unit 1310 sends a consent request to terminal device 105 storing user consent information for the user, the consent request being for the user's consent to provide the user data to second network device 103. Upon receiving a consent response from terminal device 105 including an indication of the user's consent, sending unit 1310 sends a data response to second network device 103, the data response including the user data and the indication of the user's consent.

[0140] and Figure 13Similarly, the second network device includes a sending unit 1310 and a receiving unit 1320. The sending unit 1310 sends a data request for user data of a user stored in the first network device 101 to the first network device 101. If the user allows the user data to be provided to the second network device 103, the receiving unit 1320 receives a data response from the first network device 101, the data response including the user data and an indication that the user agrees to provide the user data to the second network device 103.

[0141] Figure 14 Another simplified block diagram of a terminal device suitable for implementing some exemplary embodiments of the present invention is shown. Figure 14 As shown, the terminal device 105 includes a sending unit 1410 and a determining unit 1430. The determining unit 1430 determines that the user consent information stored in the terminal device 105 is updated by the user. The sending unit 1410 sends a consent update message to the network device 107, wherein the consent update message indicates the update of the user consent information.

[0142] Figure 15 1 shows a simplified block diagram of a network device suitable for implementing some exemplary embodiments of the present invention. Figure 15 As shown, network device 107 includes a receiving unit 1520 and a determining unit 1530. Receiving unit 1520 receives a consent update message from terminal device 105 storing user consent information of a user, the consent update message indicating an update of the user consent information. Determining unit 1530 updates privacy settings associated with the user data of the user stored in network device 107 based on the update of the user consent information.

[0143] Those skilled in the art will appreciate that, in combination with the units and algorithms of the various examples described in the embodiments disclosed in this specification, the present application can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether the function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the functions described in each specific application, but it should not be considered that the implementation method exceeds the scope of this application.

[0144] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-mentioned systems, devices and units refer to the corresponding processes in the above-mentioned method embodiments and are not repeated here.

[0145] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described are merely exemplary. For example, unit division is merely a logical function division, and other division methods can be used in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not performed. In addition, the mutual coupling or direct coupling or communication connection shown or described can be implemented through some interfaces. The indirect coupling or communication connection between devices or units can be implemented through electronic, mechanical or other forms.

[0146] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, may be located in one location, or may be distributed across multiple network units. Some or all of the units may be selected based on actual needs to achieve the objectives of the embodiments.

[0147] In addition, the functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0148] When these functions are implemented in the form of software functional units and sold or used as independent products, these functions can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for instructing a computer device (which can be a personal computer, a server or a network device) to perform all or part of the steps of the method described in the embodiment of the present application. The above-mentioned storage medium includes: any medium that can store program code, such as a USB flash drive, a removable hard disk, a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk.

[0149] The above description is only a specific implementation of the present application and is not intended to limit the scope of protection of the present application. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A method for communication, characterized in that include: receiving, at a terminal device, a consent request from a first network device, the consent request being for a user to consent to providing user data of the user stored in the first network device to a second network device; determining, based on user consent information stored in the terminal device, whether the user permits the user data to be provided to the second network device; Based on determining that the user permits provision of the user data to the second network device, a consent response is sent to the first network device, the consent response including an indication of the user's consent.

2. The method according to claim 1, characterized in that The terminal device includes a functional component module, which is used to store the user consent information and protect the privacy of the user data.

3. The method according to claim 2, characterized in that The determining whether the user allows the user data to be provided to the second network device includes: Based on the receipt of the consent request, a Trustworthiness Association (TruA) module in the functional component module requests authorization from the user; causing the TruA ​​module to map the consent request to a privacy enabler module in the functional component module based on receiving the authorization from the user; The TruA ​​module sends a first consent request for calling the privacy enabler module to the flow point module in the functional component module; The TruA ​​module is caused to receive a first consent response from the streaming point module, the first consent response including the indication of the consent of the user.

4. The method according to claim 3, characterized in that The sending the consent response to the first network device includes: The TruA ​​module is caused to send the consent response to the first network device.

5. The method according to claim 3 or 4, characterized in that The determining whether the user allows the user data to be provided to the second network device further includes: causing the flow point module to receive a first consent request for invoking the privacy enabler module from the TruA ​​module; causing the streaming point module to send a second consent request for the user's consent to the privacy enabler module; causing the streaming point module to receive a second consent response from the privacy enabler module, the second consent response including the indication of the consent of the user; The streaming point module is caused to send a first consent response to the TruA ​​module, the first consent response including the indication of the consent of the user.

6. The method according to claim 5, characterized in that The determining whether the user allows the user data to be provided to the second network device further includes: causing the privacy enabler module to receive the second consent request from the stream point module; causing the privacy enabler module to determine, based on the user consent information, that the user permits the user data to be provided to the second network device; The privacy enabler module is caused to send the second consent response to the streaming point module.

7. The method according to any one of claims 1 to 6, characterized in that: The first network device includes a network function (NF) in a public land mobile network (PLMN); The second network device includes a network data analytics function (NWDAF) in the PLMN.

8. The method according to any one of claims 1 to 6, characterized in that: The first network device includes an NWDAF in the PLMN; The second network device includes a third-party service provider with respect to the PLMN.

9. A method for communication, characterized in that include: receiving, at a first network device, from a second network device, a data request for user data of a user stored in the first network device; Sending a consent request to a terminal device storing user consent information of the user, where the consent request is for the user to agree to provide the user data to the second network device; Based on receiving a consent response from the terminal device, the consent response including the indication of the user's consent, sending a data response to the second network device, the data response including the user data and the indication of the user's consent.

10. The method according to claim 9, characterized in that The sending the consent request to the terminal device includes: determining whether the second network device is authorized to access the user data; Based on determining that the second network device is authorized to access the user data, the consent request is sent to the terminal device.

11. The method according to claim 9, characterized in that The sending the consent request to the terminal device includes: determining whether the user's consent is required for providing the user data; Based on determining that the user's consent is required for providing the user data, the consent request is sent to the terminal device.

12. The method according to any one of claims 9 to 11, characterized in that: The first network device includes a network function (NF) in a public land mobile network (PLMN); The second network device includes a network data analytics function (NWDAF) in the PLMN.

13. The method according to any one of claims 9 to 11, characterized in that: The first network device includes an NWDAF in the PLMN; The second network device includes a third-party service provider with respect to the PLMN.

14. A method for communication, characterized in that include: sending, at the second network device, to the first network device, a data request for user data of a user stored in the first network device; If the user allows the user data to be provided to the second network device, a data response is received from the first network device, the data response including the user data and an indication that the user agrees to provide the user data to the second network device.

15. The method according to claim 14, characterized in that: The first network device includes a network function (NF) in a public land mobile network (PLMN); The second network device includes a network data analytics function (NWDAF) in the PLMN.

16. The method according to claim 14, wherein: The first network device includes an NWDAF in the PLMN, The second network device includes a third-party service provider with respect to the PLMN.

17. A method for communication, characterized in that include: determining, at a terminal device, that user consent information of a user stored in the terminal device is updated by the user; A consent update message is sent to a network device, wherein the consent update message indicates that the user consents to the update of the information.

18. The method according to claim 17, characterized in that The terminal device includes a functional component module, which is used to store the user consent information and protect the privacy of the user data.

19. The method according to claim 18, characterized in that The consent update message is a first consent update message, and the method further includes: Based on determining that the user consent information is updated, the privacy enabler module in the functional component module sends a second consent update message to the flow point in the functional component module, where the second consent update message indicates the update of the user consent.

20. The method according to claim 19, characterized in that Also includes: causing the streaming point module to receive the second consent update message from the privacy enabler module; The flow point module is enabled to send a third consent update message to a trustworthiness association (TruA) module in the functional component module, where the third consent update message indicates the update agreed to by the user.

21. The method according to claim 20, characterized in that The sending the consent update message to the network device includes: The TruA ​​module is caused to send the first consent update message to the network device based on receiving the third consent update message from the flow point module.

22. The method according to any one of claims 17 to 21, characterized in that The network device includes a network function (NF) in a public land mobile network (PLMN) or a third-party service provider relative to the PLMN.

23. A method for communication, characterized in that include: receiving, at a network device, a consent update message from a terminal device storing user consent information of a user, the consent update message indicating an update of the user consent information; A privacy setting is updated based on the update of the user consent information, the privacy setting being associated with user data of the user stored in the network device.

24. The method according to claim 23, wherein Also includes: Before updating the privacy settings, the user is authenticated.

25. The method according to claim 23 or 24, characterized in that The network device includes a network function (NF) in a public land mobile network (PLMN) or a third-party service provider relative to the PLMN.

26. A terminal device, characterized in that: include: Communication interface; at least one processor coupled to the communication interface; a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: receiving a consent request from the first network device through the communication interface, the consent request being for a user to consent to providing user data of the user stored in the first network device to the second network device; determining, based on user consent information stored in the terminal device, whether the user permits the user data to be provided to the second network device; Based on determining that the user permits provision of the user data to the second network device, a consent response is sent to the first network device via the communication interface, the consent response including an indication of the user's consent.

27. A first network device, characterized in that: include: Communication interface; at least one processor coupled to the communication interface; a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: receiving, from a second network device through the communication interface, a data request for user data of a user stored in the first network device; sending a consent request to a terminal device storing user consent information of the user through the communication interface, wherein the consent request is used by the user to agree to provide the user data to the second network device; Based on receiving a consent response from the terminal device through the communication interface, the consent response includes the indication of the user's consent, and sending a data response to the second network device through the communication interface, the data response includes the user data and the indication of the user's consent.

28. A second network device, characterized in that: include: Communication interface; at least one processor coupled to the communication interface; a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: sending a data request for user data of a user stored in the first network device to the first network device through the communication interface; If the user allows the user data to be provided to the second network device, a data response is received from the first network device through the communication interface, where the data response includes the user data and an indication that the user agrees to provide the user data to the second network device.

29. A terminal device, characterized in that: include: Communication interface; at least one processor coupled to the communication interface; a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: determining that user consent information of the user stored in the terminal device is updated by the user; A consent update message is sent to the network device through the communication interface, where the consent update message indicates that the user agrees to the update of the information.

30. A network device, characterized in that: include: Communication interface; at least one processor coupled to the communication interface; a memory coupled to the at least one processor and storing program instructions for execution by the at least one processor, the program instructions instructing the at least one processor to: receiving a consent update message from a terminal device storing user consent information of a user through the communication interface, the consent update message indicating an update of the user consent information; A privacy setting is updated based on the update of the user consent information, the privacy setting being associated with user data of the user stored in the network device.

31. A computer-readable storage medium, characterized in that Instructions are stored which, when executed by one or more processors of a computing device, cause the computing device to perform the method according to any one of claims 1 to 25.