Authorization method and device
Patent Information
- Application Number
- CN202511209437.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-06
- Publication Date
- 2025-12-02
Smart Images

Figure CN121056865A_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese patent application No. 202380090109.6, entitled "Authorized Method and Apparatus", which entered the Chinese national phase of PCT international patent application PCT / CN2023 / 071098, filed on January 6, 2023. Technical Field
[0002] This application relates to the field of communications, and more specifically, to authorized methods and devices. Background Technology
[0003] User data in communication networks involves user privacy, and the security of user data must be guaranteed; how to authorize user data is a technical problem that needs to be solved. Summary of the Invention
[0004] This application provides an authorization method and device that can authorize user data.
[0005] This application provides an authorization method, including:
[0006] The first network element checks the user's authorization information and provides the user's data and / or data analysis results to the second network element when the check results are as follows:
[0007] Allows the collection and / or analysis of the user's data; and,
[0008] Allow the second network element to provide the user's data and / or data analysis results.
[0009] This application also provides an authorization method, including:
[0010] The third network element sends the user's authorization information to the first network element so that the first network element can check the user's authorization information.
[0011] This application also provides an authorization method, including:
[0012] The second network element sends a data authorization request, which is used to request user data and / or data analysis results.
[0013] This application also provides an authorization method, including:
[0014] The third network element sends a message revoking the user's authorization.
[0015] This application also provides an authorization method, including:
[0016] FirstNetElement receives information about the revocation of user authorization.
[0017] This application also provides an authorization method, including:
[0018] The second network element receives information about the revocation of user authorization.
[0019] This application embodiment also provides a first network element, including:
[0020] The inspection module is used to check the user's authorization information. When the inspection result is as follows, it provides the user's data and / or data analysis results to the second network element:
[0021] Allows the collection and / or analysis of the user's data; and,
[0022] Allow the second network element to provide the user's data and / or data analysis results.
[0023] This application embodiment also provides a third network element, including:
[0024] The first sending module is used to send the user's authorization information to the first network element so that the first network element can check the user's authorization information.
[0025] This application embodiment also provides a second network element, including:
[0026] The second sending module is used to send a data authorization request, which is used to request user data and / or data analysis results.
[0027] This application embodiment also provides a third network element, including:
[0028] The third sending module is used to send the user's authorization revocation information.
[0029] This application embodiment also provides a first network element, including:
[0030] The second receiving module is used to receive user authorization revocation information.
[0031] This application embodiment also provides a second network element, including:
[0032] The third receiving module is used to receive user authorization revocation information.
[0033] In this embodiment of the application, the user's authorization information is checked by the first network element, which can realize two-layer user authorization checking, thereby strengthening the protection of user data. Attached Figure Description
[0034] Figure 1 This is a schematic diagram illustrating an application scenario of an embodiment of this application.
[0035] Figure 2AThis is a diagram illustrating how NWDAF obtains NF authorization based on user consent.
[0036] Figure 2B This is a diagram illustrating how user consent is checked on NEF / CAPIF.
[0037] Figure 2C This is a diagram illustrating how users agree to updates.
[0038] Figure 3 This is a flowchart illustrating the implementation of an authorized method 300 according to an embodiment of this application.
[0039] Figure 4 This is a schematic diagram of a two-tiered user authorization mechanism for AI / ML application auxiliary data according to an embodiment of this application.
[0040] Figure 5 This is a schematic diagram of a two-layer user consent check and data collection process according to an embodiment of this application.
[0041] Figure 6 This is a schematic diagram of another two-layer user consent check and data collection process according to an embodiment of this application.
[0042] Figure 7 This is a schematic flowchart of an authorized method 700 according to an embodiment of this application.
[0043] Figure 8 This is a schematic flowchart of an authorized method 800 according to an embodiment of this application.
[0044] Figure 9 This is a schematic flowchart of an authorized method 900 according to an embodiment of this application.
[0045] Figure 10 This is a schematic diagram of a user consent withdrawal process according to an embodiment of this application.
[0046] Figure 11 This is a schematic flowchart of an authorized method 1100 according to an embodiment of this application.
[0047] Figure 12 This is a schematic flowchart of an authorized method 1200 according to an embodiment of this application.
[0048] Figure 13 This is a schematic diagram of the structure of the first network element 1300 according to an embodiment of this application.
[0049] Figure 14 This is a schematic diagram of the structure of the first network element 1400 according to an embodiment of this application.
[0050] Figure 15 This is a schematic diagram of the structure of the third network element 1500 according to an embodiment of this application.
[0051] Figure 16 This is a schematic diagram of the structure of the second network element 1600 according to an embodiment of this application.
[0052] Figure 17 This is a schematic diagram of the structure of the third network element 1700 according to an embodiment of this application.
[0053] Figure 18 This is a schematic diagram of the structure of the first network element 1800 according to an embodiment of this application.
[0054] Figure 19 This is a schematic diagram of the structure of the first network element 1900 according to an embodiment of this application.
[0055] Figure 20 This is a schematic diagram of the structure of the second network element 2000 according to an embodiment of this application.
[0056] Figure 21 This is a schematic diagram of the structure of the second network element 2100 according to an embodiment of this application.
[0057] Figure 22 This is a schematic structural diagram of a communication device 2200 according to an embodiment of this application.
[0058] Figure 23 This is a schematic structural diagram of chip 2300 according to an embodiment of this application. Detailed Implementation
[0059] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0060] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of the embodiments of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. The objects described by "first" and "second" may be the same or different.
[0061] The technical solutions of this application embodiment can be applied to various communication systems, such as: Global System for Mobile Communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, Advanced Long Term Evolution (LTE-A) system, New Radio (NR) system, evolution of NR system, LTE-based access to unlicensed spectrum (LTE-U) system, NR-based access to unlicensed spectrum (NR-U) system, Non-Terrestrial Networks (NTN) system, Universal Mobile Telecommunication System (UMTS), Wireless Local Area Networks (WLAN), and Wireless Fidelity (WF). Fidelity (WiFi), 5th-Generation (5G) communication systems, or other communication systems.
[0062] Traditional communication systems typically support a limited number of connections and are easy to implement. However, with the development of communication technology, mobile communication systems will not only support traditional communication but also, for example, device-to-device (D2D) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), vehicle-to-vehicle (V2V) communication, or vehicle-to-everything (V2X) communication. The embodiments of this application can also be applied to these communication systems.
[0063] In one implementation, the communication system in this application embodiment can be applied to a carrier aggregation (CA) scenario, a dual connectivity (DC) scenario, or a standalone (SA) network deployment scenario.
[0064] In one embodiment, the communication system in this application can be applied to unlicensed spectrum, wherein the unlicensed spectrum can also be considered as shared spectrum; or, the communication system in this application can also be applied to licensed spectrum, wherein the licensed spectrum can also be considered as non-shared spectrum.
[0065] This application describes various embodiments in conjunction with network devices and terminal devices. The terminal device may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user device, etc.
[0066] Terminal devices can be stations (STAION, ST) in WLANs, cellular phones, cordless phones, Session Initiation Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistant (PDA) devices, handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, in-vehicle devices, wearable devices, terminal devices in next-generation communication systems such as NR networks, or terminal devices in future evolved Public Land Mobile Network (PLMN) networks, etc.
[0067] In the embodiments of this application, the terminal device can be deployed on land, including indoor or outdoor, handheld, wearable or vehicle-mounted; it can also be deployed on water (such as ships); and it can also be deployed in the air (such as airplanes, balloons and satellites).
[0068] In the embodiments of this application, the terminal device may be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical care, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, or a wireless terminal device in a smart home, etc.
[0069] By way of example and not limitation, in this embodiment, the terminal device can also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for devices that utilize wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not merely hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are feature-rich, large in size, and can achieve complete or partial functions without relying on a smartphone, such as smartwatches or smart glasses, as well as those that focus on a specific type of application function and require the use of other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0070] In the embodiments of this application, the network device can be a device for communicating with mobile devices. The network device can be an access point (AP) in WLAN, a base station (BTS) in GSM or CDMA, a base station (NodeB, NB) in WCDMA, an evolved Node B (eNB or eNodeB) in LTE, a relay station or access point, or a vehicle-mounted device, wearable device, or a network device (gNB) in an NR network, or a network device in a future evolved PLMN network or an NTN network, etc.
[0071] By way of example and not limitation, in this embodiment, the network device may have mobility characteristics; for example, the network device may be a mobile device. Optionally, the network device may be a satellite or a balloon station. For example, the satellite may be a low Earth orbit (LEO) satellite, a medium Earth orbit (MEO) satellite, a geostationary earth orbit (GEO) satellite, a high elliptical orbit (HEO) satellite, etc. Optionally, the network device may also be a base station located on land, water, or other similar locations.
[0072] In this embodiment, the network device can provide services to a cell. The terminal device communicates with the network device through the transmission resources (e.g., frequency domain resources, or spectrum resources) used by the cell. The cell can be the cell corresponding to the network device (e.g., a base station). The cell can belong to a macro base station or to a base station corresponding to a small cell. The small cell can include: metro cell, micro cell, pico cell, femto cell, etc. These small cells have the characteristics of small coverage area and low transmission power, and are suitable for providing high-speed data transmission services.
[0073] Figure 1 An exemplary communication system 100 is shown. The communication system includes a network device 110 and two terminal devices 120. In one embodiment, the communication system 100 may include multiple network devices 110, and the coverage area of each network device 110 may include other numbers of terminal devices 120, which is not limited in this application embodiment.
[0074] In one embodiment, the communication system 100 may also include other network entities such as a Mobility Management Entity (MME) and an Access and Mobility Management Function (AMF), which are not limited in this application.
[0075] Network equipment can be further divided into access network equipment and core network equipment. That is, the wireless communication system also includes multiple core networks used to communicate with the access network equipment. Access network equipment can be evolved Node Bs (eNBs or e-NodeBs) in Long-Term Evolution (LTE), Next-Generation Radio (NR) (mobile communication system), or Authorized Auxiliary Access Long-Term Evolution (LAA-LTE) systems, such as macro base stations, micro base stations (also called "small base stations"), pico base stations, access points (APs), transmission points (TPs), or new generation Node Bs (gNodeBs).
[0076] It should be understood that devices with communication functions in the network / system of this application embodiment can be referred to as communication devices. Figure 1 Taking the communication system shown as an example, the communication equipment may include network devices and terminal devices with communication functions. The network devices and terminal devices may be specific devices in the embodiments of this application, which will not be described in detail here. The communication equipment may also include other devices in the communication system, such as network controllers, mobility management entities and other network entities, which are not limited in the embodiments of this application.
[0077] It should be understood that the terms "system" and "network" are often used interchangeably in this document. The term "and / or" in this document merely describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Furthermore, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0078] It should be understood that the term "instruction" mentioned in the embodiments of this application can be a direct instruction, an indirect instruction, or an indication of a relationship. For example, A instructing B can mean that A directly instructs B, such as B being able to obtain information through A; it can also mean that A indirectly instructs B, such as A instructing C, so B can obtain information through C; or it can mean that there is a relationship between A and B.
[0079] In the description of the embodiments of this application, the term "correspondence" may indicate that there is a direct or indirect correspondence between two things, or that there is an association between two things, or that there is a relationship of instruction and being instructed, configuration and being configured, etc.
[0080] To facilitate understanding of the technical solutions of the embodiments of this application, the relevant technologies of the embodiments of this application are described below. The following relevant technologies are optional solutions and can be combined with the technical solutions of the embodiments of this application in any way, and they all fall within the protection scope of the embodiments of this application.
[0081] To enable the Network Data Analytics Function (NWDAF) to collect and use UE-related privacy data, related technologies have proposed a scheme for NWDAF to obtain network function (NF) authorization based on user consent, such as... Figure 2A As shown, the solution includes the following steps:
[0082] Step 0: User Data Management (UDM) maintains user consent for subscribers.
[0083] Step 1: If the NWDAF receives a specific analysis request from a consumer network element, such as collecting UE information for UE-related analysis, the NWDAF will check whether the analysis requires user consent in accordance with local policies (e.g., regulations).
[0084] Step 2: If user consent is required and there is no UserConsent parameter in the NWDAF UE context, the NWDAF will send a Nudm_SDM_Get Request message to the UDM to request the user consent parameter.
[0085] Step 3: UDM retrieves user consent parameters.
[0086] Step 4: The UDM sends a Nudm_SDM_Get Response message to the NWDAF. This message includes user consent parameters. The NWDAF stores the user consent parameters in the NWDAF's UE context.
[0087] Step 5: Based on the user's agreed parameters, NWDAF sends a data / analysis request to the producer network element (such as AMF or SMF). This request includes the user's identifier (such as the Subscription Permanent Identifier (SUPI)) and the analysis ID.
[0088] Step 6: The data provider begins collecting the requested data based on the results.
[0089] To achieve secure exposure of information to third parties and protect user privacy, related technologies have proposed schemes for checking user consent on Network Exposure Function (NEF) / Common API Framework (CAPIF), such as... Figure 2B As shown, the solution includes the following steps:
[0090] Step 0: UDM maintains user consent parameters as subscription data.
[0091] Step 1: The Access Stratum (AS) sends an Application Programming Interface (API) call to the NEF / CAPIF to request the processing of user data. For example, if the service called is "Nnef_Location_LocationUpdateNotify" and the input is AF ID and GPSI, it means that the Application Function (AF) requests the NEF / CAPIF to retrieve the location of the UE with the Generic Public Subscription Identifier (GPSI).
[0092] Step 2: NEF / CAPIF determines whether the service being called requires user consent based on the operator's local policy. If user consent is not required, proceed to Step 7; otherwise, proceed to Step 3.
[0093] Step 3: If there are no relevant user consent parameters in the UE context, proceed to step 4; if there are relevant user consent parameters in the UE context, proceed to step 6.
[0094] Step 4: NEF / CAPIF sends a Nudm_SDM_Get Request message to UDM. This message should include the UE ID and may also include the data processing purpose and data processor ID.
[0095] Step 5: UDM returns the requested user consent parameters.
[0096] Step 6: NEF / CAPIF determines whether to authorize the API call based on the user consent parameters. If the API call is determined to be disallowed based on the user consent parameters, NEF / CAPIF will reject the AF's request for a specific reason. If the API call is determined to be allowed based on the user consent parameters, NEF / CAPIF will accept the AF's request. If there are no explicit user consent parameters, NEF / CAPIF can decide to reject or accept the AF's request based on the operator's local policies. Furthermore, if the user consent result for data processing purposes is permitted, NEF / CAPIF can use the Nudm_SDM_Subscribe service to subscribe to user consent parameter change events on the UDM to maintain unexpired user consent.
[0097] Step 7: Based on the situation determined in Step 6, respond to the NEF / CAIPF of the API call.
[0098] Data consumers or intermediary NFs (e.g., including NWDAF / NEF) can subscribe to user consent revocation as a service of the UDM, reusing the subscription notification process. Any NF that obtains user consent from the UDM can register for this revocation service. Related technologies have proposed user consent update schemes when user consent is changed or revoked, such as... Figure 2C As shown, the solution includes the following steps:
[0099] Step 1: Upon the user's request, the user's consent is withdrawn, and the UDM updates the subscription information. Users can request to withdraw specific user consents associated with user data (such as location, identity).
[0100] Step 2a: The UDM sends a Nudm_SDM_Notify message to the intermediate NF, which includes the UE ID, processor ID, processing purpose, and user consent result. The UE ID is related to the user ID, such as the user's SUPI or GPSI identifier; the processor ID indicates the data processor that processes the data for the UE, and can be represented by a PLMN ID, AF ID, etc. The processing purpose is associated with the revoked service. The user consent result means that the data processor agrees to process the data according to the purpose of data processing (e.g., allow or disallow). Upon receiving the request, the intermediate NF should delete the consented data. If the intermediate NF has data processing functions, such as analysis or collection functions, then the intermediate NF should stop processing the consented data.
[0101] Step 3: If the consumer network element accesses the producer network element through an intermediate NF, the intermediate NF should send a user consent revocation request message to the consumer network element. Upon receiving the request, the consumer network element should delete the data that has already been approved by the user. If the intermediate NF has data processing functions, such as analysis or collection functions, the intermediate NF should stop processing the data that has already been approved by the user.
[0102] Step 2b: The UDM directly sends a Nudm_SDM_Notify message to the consumer network element. This message is the same as the one provided to the intermediate NF. Upon receiving the request, the consumer network element should delete the data that has already been approved by the user. If the intermediate NF has data processing capabilities, such as analysis or collection functions, the intermediate NF should stop processing the data that has already been approved by the user.
[0103] The existing 3GPP procedures for obtaining and revoking user consent only consider whether user data can be exposed to network elements within the core network, without considering whether user data can be exposed to third-party entities. Therefore, the protection of user privacy data is insufficient.
[0104] This application provides an authorization method. Figure 3 This is a schematic flowchart of an authorized method 300 according to an embodiment of this application, which can be applied to... Figure 1 The system shown is not limited to this. The method includes at least a portion of the following.
[0105] S310: The first network element checks the user's authorization information and provides the user's data and / or data analysis results to the second network element when the check result is as follows:
[0106] Allows the collection and / or analysis of the user's data; and,
[0107] Allow the second network element to provide the user's data and / or data analysis results.
[0108] In some implementations, the second network element can be an application function (AF). For example, in artificial intelligence (AI) / machine learning (ML) application scenarios, the AF requires user data and / or data analysis results to support the AF in completing AI / ML operations.
[0109] This application embodiment considers a two-tiered user consent mechanism for the second network element (such as the AF) and the core network element before providing user data and / or data analysis results to the second network element. Specifically, the core network element should obtain user consent before collecting and / or analyzing user data; and the core network element should also obtain user consent before exposing user data and / or data analysis results (such as user privacy data) to the second network element (such as the AF). This comprehensively considers user privacy strategies and achieves the goal of maximizing the protection of user privacy data. The two-tiered authorization mechanism proposed in this application embodiment consists of two stages, including a two-tiered user consent check and a two-tiered user consent revocation. Figure 3 The authorization method shown corresponds to the first stage, namely the two-layer user consent check stage.
[0110] Figure 4 This is a schematic diagram of a two-tiered user authorization mechanism for AI / ML application auxiliary data according to an embodiment of this application. Figure 4 As shown, in order to provide AI / ML services to users, the AI / ML AF needs to collect user data. The AI / ML AF requests data from the core network, and the core network collects user data. Before collecting user data and providing it to the AI / ML AF, the core network can check the user's consent parameters to determine whether the user agrees to the core network collecting or analyzing their data, and whether they agree to provide the user's data or data analysis results to the AI / ML AF. If the user agrees to the core network collecting or analyzing their data and agrees to provide the user's data or data analysis results to the AI / ML AF, then the core network collects or analyzes the user's data and provides it to the AI / ML AF.
[0111] Taking a 5G core network as an example, the AI / ML-related operations can only be completed with the assistance of the 5G core network. Therefore, the AF first needs to initiate an auxiliary information request to the 5G core network. This auxiliary data can be collected and analyzed through the Network Data Analytics Function (NWDAF) in the core network. Therefore, the user needs to confirm whether the relevant data is allowed to be collected by the NWDAF and whether the requested data or analysis results can be disclosed to the AF. This data may include AI / ML auxiliary data.
[0112] In some implementations, the first network element includes an NWDAF or NEF, and the second network element includes an AF. The first network element can receive a data authorization request from the second network element and then check the authorization information of the user involved in the data authorization request. For example, after receiving a data authorization request from an AF, the NWDAF or NEF checks the user's authorization information. If it determines that the collection and / or analysis of the user's data is permitted, and that the user's data and / or data analysis results are permitted to be provided to the AF, then it begins to collect and analyze the user's data and exposes the results of the collection and analysis to the AF. Through this two-layer user authorization mechanism, the collection of user privacy data by the core network and the exposure of privacy data by the core network to the AF are checked separately, which can comprehensively consider user privacy policies and achieve maximum protection of user privacy data. For example, when the AF belongs to an operator's network function entity, the NWDAF can perform the above-mentioned authorization checks, data collection and analysis, and / or exposure of data results to the AF; when the AF belongs to a third-party function entity independent of the operator, the NEF can perform the above-mentioned authorization checks, data collection and analysis, and / or exposure of data results to the AF.
[0113] Upon receiving a data authorization request, the first network element can determine whether it is necessary to check the user's authorization information. If so, it can obtain the user's first authorization information and / or the user's second authorization information and check the user's authorization information.
[0114] In some implementations, the first network element determines whether it is necessary to check the user's authorization information based on a first policy and / or the data type involved in the data authorization request. The first policy may include at least one of operator policies and regulatory requirements.
[0115] In roaming scenarios, the first network element (such as NWDAF or NEF) and the second network element (such as AF) belong to different Public Land Mobile Networks (PLMNs). For example, the second network element (such as AF) belongs to the Home Public Land Mobile Network (HPLMN), which is the network to which the UE belongs; the first network element (such as NWDAF or NEF) belongs to the Visit Public Land Mobile Network (VPLMN), which is the network to which the UE connects. In this case, the first network element can check the local laws and regulations of the countries and regions where the VPLMN and HPLMN are located to determine whether it is necessary to check the first authorization information and the second authorization information respectively; and if it is necessary to check, it can obtain and check the first authorization information and the second authorization information respectively.
[0116] In non-roaming scenarios, the first network element (such as NWDAF or NEF) and the second network element (such as AF) belong to the same PLMN. In this case, the first network element can determine whether it is necessary to check the first authorization information and the second authorization information based on the local laws and regulations of the country and region where the UE is located; and if it is necessary to check, it can obtain the first authorization information and the second authorization information through one or more signaling interactions.
[0117] In some implementations, the first network element can check the user's first authorization information and second authorization information separately. The first authorization information indicates whether the collection and / or analysis of the user's data is permitted; the second authorization information indicates whether the provision of the user's data and / or data analysis results to the second network element is permitted. For example, if the authorization information includes user consent, then the first authorization information may include user consent to the first network element (such as NWDAF or NEF), and the second authorization information may include user consent to the second network element (such as AF).
[0118] User authorization information (such as User Consent) can be stored in a third-party network element, such as a UDM. The third-party network element maintains the user's authorization information as subscription data for the first-party network element. The user's User Consent can include User Consent to the AF and User Consent to the NWDAF.
[0119] When the first network element checks the user's first authorization information, it can obtain the user's first authorization information from the third network element. After obtaining it, the user's first authorization information can be stored locally. In some embodiments, the first network element checks the user's first authorization information, including: the first network element obtaining the user's first authorization information; and the first network element determining, based on the first authorization information, whether to allow the collection and / or analysis of the user's data.
[0120] For example, the first network element queries the locally stored UE context and obtains the user's first authorization information from the UE context.
[0121] Alternatively, the first network element obtains the user's first authorization information from the third network element.
[0122] For the method of obtaining the user's first authorization information from a third network element, the first network element may send at least one of the UE's identifier, application identifier, and data purpose to the third network element (such as UDM); and receive the user's first authorization information from the third network element.
[0123] Similarly, when the first network element checks the user's second authorization information, it can obtain the user's second authorization information from the third network element. After obtaining it, the user's second authorization information can be stored locally. In some embodiments, the first network element checks the user's second authorization information, including: the first network element obtaining the user's second authorization information; and the first network element determining, based on the second authorization information, whether to allow the provision of user data and / or data analysis results to the second network element.
[0124] For example, the first network element queries the locally stored UE context and obtains the user's second authorization information from the UE context.
[0125] Alternatively, the first network element obtains the user's second authorization information from the third network element.
[0126] For the method of obtaining the user's second authorization information from a third network element, the first network element may send at least one of the UE's identifier, application identifier, and data purpose to the third network element (such as UDM); and receive the user's second authorization information from the third network element.
[0127] It should be noted that in non-roaming scenarios, the first network element uses a single judgment and signaling interaction to obtain the user's first and second authorization information from the third network element.
[0128] Figure 5 This is a schematic diagram of a two-layer user consent check and data collection process according to an embodiment of this application. This process can be applied to roaming scenarios. In a roaming scenario, the UDM belongs to the home network (HPLMN), the AF belongs to the home network (HPLMN), and the NEF can belong to the visited network. The NWDAF belongs to the visited network (VPLMN), which is the network the UE is connected to. Therefore, in the following steps, step 2 obtains the user consent of the AF, without considering the visited network's policy. Step 8 obtains the user consent of the NWDAF or NEF. The local auxiliary data of the NWDAF or NEF is subject to the policies required for checking according to the local laws and regulations of the country and region where the VPLMN is located, and may be inconsistent with the user consent obtained in step 2. Figure 5 The specific steps are as follows:
[0129] Step 0: The UDM stores user consent information, carrier policies, or regulatory policies. User consent information is associated with the user's SUPI and is stored in the UDM as subscription data.
[0130] Step 1: AF initiates an AI / ML data authorization request (such as an auxiliary information request) to NWDAF or NEF.
[0131] Step 2: The NWDAF or NEF checks the operator's local policies to determine whether the data (such as auxiliary data) requested by the AF needs to be checked for the AF's user consent; for example, whether it needs to be regulated, whether it involves the user's privacy data (such as UE location, mobility and abnormal behavior, etc.), as detailed in Table 1 below.
[0132] Table 1
[0133]
[0134]
[0135] Taking Table 1 as an example, user location, UE mobility, the list of UEs selected in the target AOI, the geographical distribution information of the candidate UEs, and network load predictions regarding UE locations are strongly correlated with privacy. The user's training time period is weakly correlated with privacy. These factors, combined with local operator policies and laws and regulations, are used to determine whether it is necessary to check the user's consent in the AF (Automatic Feedback Analyzer). The auxiliary information in this application embodiment is not limited to the data contained in Table 1; this auxiliary information can change as the AI / ML services of the AF change.
[0136] If it is necessary to check the user consent of the AF, proceed to step 3; otherwise, skip steps 3-6 and proceed directly to step 6. The AF belongs to the home network, i.e., HPLMN, therefore steps 2-6 consider the user consent of the HPLMN, but not the user consent of the VPLMN.
[0137] Step 3: The NWDAF or NEF retrieves relevant user consent information, i.e., the AF's user consent information, from the relevant context of the UE maintained in its database. If the AF's user consent information is missing from the UE context, proceed to Step 4. If the AF's user consent information is found in the relevant context of the UE, proceed to Step 6.
[0138] Step 4: The NWDAF or NEF sends (UE ID, [auxiliary data purpose, Application ID]) to the UDM via the Nudm_SDM_GET_Request interface to check user consent information. This interface is used to provide UDM subscription data management services, retrieving UE subscription data related to consumer network elements from the UDM through a Get service operation.
[0139] Step 5: The UDM retrieves the user consent information, specifically the AF's user consent information, and sends a Nudm_SDM_Get Response message to the NWDAF or NEF, returning the queried subscription data including the AF's user consent information. Upon receiving the response message, the NWDAF or NEF stores the user consent information in the NWDAF's UE context.
[0140] Step 6: Based on operator policies, regulatory policies, and the user's consent from the AF, the NWDAF or NEF determines whether to provide the user's data or data analysis results to the AF. If the data returned by the UDM indicates authorized data use, then the NWDAF or NEF determines that providing the user's data or data analysis results to the AF is authorized, and proceeds to Step 8; otherwise, the NWDAF or NEF determines that providing the user's data or data analysis results to the AF is unauthorized, and proceeds to Step 7.
[0141] Step 7: NWDAF or NEF rejects AF's auxiliary data request, terminates the process, and provides a specific reason.
[0142] Step 8: The NWDAF or NEF searches local data to see if relevant auxiliary data exists. If it exists, it means the NWDAF or NEF has obtained user consent from the NWDAF / NEF and no further user consent check is needed. In this case, proceed directly to step 12 to expose the relevant auxiliary data to the AF. If it does not exist, the NWDAF or NEF needs to retrieve user consent parameters from the UDM to determine whether collecting and analyzing relevant UE data is permitted. Proceed to step 9. Since the NWDAF or NEF is located in a VPLMN, the user consent terms to be retrieved may differ from those in an HPLMN, as data classification and grading laws and regulations may vary in different regions. Therefore, the local auxiliary data retrieved by the NWDAF or NEF is subject to the policies required by the local laws and regulations of the country and region where the VPLMN is located, and may differ from the user consent scope terms in steps 2-6 of the HPLMN.
[0143] Step 9: NWDAF or NEF retrieves user consent for NWDAF / NEF from the UDM via the Nudm_SDM_GET_Request interface.
[0144] Step 10: UDM retrieves the user consent information from NWDAF / NEF and sends a Nudm_SDM_Get_Response message to NWDAF or NEF, which contains the NWDAF / NEF user consent information; after receiving the NWDAF / NEF user consent information, NWDAF or NEF stores the NWDAF / NEF user consent parameters in the UE context.
[0145] Step 11: Based on the user consent parameters of NWDAF / NEF, if it is determined that NWDAF or NEF is allowed to collect and analyze user data, then NWDAF or NEF sends a data / analysis request to the data provider. The data provider may include core network elements such as AMF and SMF, and may also include core network elements that may be added later. Then, NWDAF or NEF begins to collect the requested data based on the result.
[0146] Step 12: NWDAF or NEF notifies AF of the data or analysis results.
[0147] Figure 6 This is a schematic diagram of another two-layer user consent check and data collection process according to an embodiment of this application. This process can be applied to non-roaming scenarios. In non-roaming scenarios, AF, NEF, and NWDAF all belong to the home network (HPLMN). Therefore, in the following steps, the home network's strategy can be considered to determine whether it is necessary to obtain the user consent of AF and the user consent of NWDAF. If it is necessary, the user consent of AF and the user consent of NWDAF / NEF can be obtained through a single signaling interaction, thereby saving signaling resources. Figure 6 The specific steps are as follows:
[0148] Step 0: The UDM stores user consent information, carrier policies, or regulatory policies. User consent information is associated with the user's SUPI and is stored in the UDM as subscription data.
[0149] Step 1: AF initiates an AI / ML data authorization request (such as an auxiliary data information request) to NWDAF or NEF.
[0150] Step 2: The NWDAF or NEF checks the operator's local policies to determine whether the data requested by the AF (such as auxiliary data) requires verification of the AF's user consent and the NWDAF / NEF's user consent; for example, whether it needs to be monitored, whether it involves user privacy data (such as UE location, mobility, and abnormal behavior, etc.). Detailed information can be found in Table 1 above. If verification of both the AF's and NWDAF's user consent is required, proceed to Step 3; otherwise, skip Steps 3-6 and proceed directly to Step 7. Since both the AF and NWDAF belong to the home network, i.e., the HPLMN, user consent from the HPLMN must be considered in Steps 2-6.
[0151] Step 3: The NWDAF or NEF retrieves relevant user consent information from the UE's relevant context maintained in its database, namely the AF's user consent information and the NWDAF / NEF's user consent information. If the AF's user consent information and the NWDAF / NEF's user consent information are missing from the UE's context, proceed to Step 4. If the AF's user consent information and the NWDAF / NEF's user consent information are found in the UE's relevant context, proceed to Step 6.
[0152] Step 4: The NWDAF or NEF sends (UE ID, [auxiliary data purpose, Application ID]) to the UDM via the Nudm_SDM_GET_Request interface to check the user consent information of the AF and the NWDAF / NEF. This interface is used to provide UDM subscription data management services, retrieving UE subscription data related to consumer network elements from the UDM through the Get service operation.
[0153] Step 5: The UDM retrieves user consent information, specifically the AF's user consent information and the NWDAF / NEF's user consent information, and sends a Nudm_SDM_Get Response message to the NWDAF or NEF. The returned subscription data includes the AF's and NWDAF / NEF's user consent information. Upon receiving the response message, the NWDAF or NEF stores the AF's and NWDAF / NEF's user consent information in its UE context.
[0154] Step 6: Based on operator policies, regulatory policies, AF user consent, and NWDAF / NEF user consent, NWDAF or NEF determines whether to analyze the user's data and provide the data analysis results to AF. For example, if the data returned by UDM is authorized for use, then NWDAF or NEF determines that analyzing the user's data and providing the data analysis results to AF is authorized, and proceeds to step 8; otherwise, NWDAF or NEF determines that analyzing the user's data and providing the data analysis results to AF is not authorized, and proceeds to step 7.
[0155] Step 7: NWDAF or NEF rejects AF's auxiliary data request, terminates the process, and provides a specific reason.
[0156] Step 8: The NWDAF or NEF searches the local data to see if there is relevant auxiliary data. If so, it directly exposes the relevant auxiliary data to the AF. If not, the NWDAF or NEF sends a data / analysis request to the data provider, which may include core network elements such as AMF and SMF, and may also include network elements that may be added later. Based on the results, the NWDAF or NEF begins to collect the requested data and finally exposes the relevant auxiliary data to the AF.
[0157] In the above embodiments, NWDAF or NEF uses the Nudm_SDM_Get Response message to obtain user consent information for AF and NWDAF / NEF from UDM. This allows obtaining user consent information for AF and NWDAF / NEF to be completed in a single signaling interaction, thereby saving signaling resources. Of course, NWDAF or NEF can also obtain user consent information for AF and NWDAF / NEF separately.
[0158] In this embodiment, when the AF belongs to the operator's network function entity, the NWDAF can perform functions such as authorization checks, data collection and analysis, and / or exposing data results to the AF; when the AF belongs to a third-party function entity independent of the operator, the NEF can perform functions such as authorization checks, data collection and analysis, and / or exposing data results to the AF.
[0159] The message parameters involved in the protocol interaction process described above are merely examples, and the specific parameters may change as AI / ML services change.
[0160] In summary, the authorization method proposed in this application considers a two-layer user consent mechanism for both the AF and the core network element. Specifically, the core network element obtains user consent before collecting user-related privacy data; and the core network element also obtains user consent before exposing UE-related privacy data to the AF; furthermore, when determining whether to check user consent, the local policy of the operator's country / region is considered.
[0161] This application also proposes an authorization method. Figure 7 This is a schematic flowchart of an authorized method 700 according to an embodiment of this application, which can be applied to... Figure 1 The system shown is not limited to this. The method includes at least a portion of the following.
[0162] S710: The third network element sends the user's authorization information to the first network element so that the first network element can check the user's authorization information.
[0163] The third network element may include UDM, and the first network element may include NWDAF or NEF.
[0164] In some implementations, the user's authorization information may include first authorization information and second authorization information, wherein the first authorization information is used to indicate whether the collection and / or analysis of user data is permitted; and the second authorization information is used to indicate whether the user's data and / or data analysis results are permitted to be provided to the second network element.
[0165] The second network element may include AF.
[0166] User data may include AI / ML-assisted data.
[0167] In some implementations, the authorization information includes user consent; the first authorization information includes user consent for a first network element (such as NWDAF or NEF), and the first authorization information includes user consent for a second network element (such as AF).
[0168] The third network element sends the user's authorization information to the first network element, which may include:
[0169] The third network element receives at least one of the UE's identifier, application identifier, and data purpose from the first network element;
[0170] The third network element sends the user's first authorization information and / or second authorization information to the first network element.
[0171] The third network element can send the user's first authorization information and second authorization information in a single signaling interaction, or it can send the first authorization information and second authorization information to the first network element in stages.
[0172] The specific implementation method of this embodiment can be referred to the above. Figure 3-6 The details regarding the third network element in the implementation methods are not repeated here.
[0173] This application also proposes an authorization method. Figure 8 This is a schematic flowchart of an authorized method 800 according to an embodiment of this application, which can be applied to... Figure 1 The system shown is not limited to this. The method includes at least a portion of the following.
[0174] S810: The second network element sends a data authorization request to the first network element. The data authorization request is used to request user data and / or data analysis results.
[0175] The second network element may include AF, and the first network element may include NWDAF or NEF.
[0176] This data may include AI / ML-assisted data.
[0177] The specific implementation method of this embodiment can be referred to the above. Figure 3-6 The details regarding the second network element in the relevant implementation methods will not be repeated here.
[0178] The above describes the two-layer user consent check phase in the two-layer authorization mechanism proposed in the application embodiments. This disclosure also proposes a two-layer user consent revocation method. Taking user consent revocation in an AI / ML scenario as an example, all relevant entities (such as AF, NEF, NWDAF) can subscribe to user consent revocation as a service in the UDM and use a subscription notification procedure. When a user's privacy policy changes, such as no longer agreeing to NWDAF or NEF collecting user data or using the data for analysis, the UDM can notify the network elements subscribed to the data change service to stop collecting or using the relevant data for analysis. This process can respond promptly to changes in user consent and prevent user privacy leaks.
[0179] Figure 9 This is a schematic flowchart of an authorized method 900 according to an embodiment of this application, which can be applied to... Figure 1 The system shown is not limited to this. The method includes at least a portion of the following.
[0180] S910: The third network element sends a message indicating the revocation of user authorization.
[0181] This third network element may include UDM.
[0182] In some implementations, the user authorization revocation information may include revocation information for a first authorization and / or revocation information for a second authorization; wherein,
[0183] The revocation of the first authorization indicates that the collection and / or analysis of the user's data is no longer permitted.
[0184] The revocation of the second authorization indicates that the user's data and / or data analysis results are no longer permitted to be provided to the second network element.
[0185] The data mentioned above may include AI / ML-assisted data.
[0186] Third-party network elements can send revocation information when user authorization is withdrawn. By sending revocation information to network elements that have subscribed to users who have agreed to withdraw their authorization, the latest user consent information can be promptly provided to the relevant network elements when user consent information changes, thereby protecting user privacy data.
[0187] In some implementations, the revocation information for user authorization includes the revocation information for user consent.
[0188] When sending information to revoke user authorization, the system may send the user's consent result, as well as at least one of the UE's identifier, application identifier, and data purpose.
[0189] In some implementations, a third network element may send a user authorization revocation message to a first network element to instruct the first network element to cease collecting and / or analyzing user data. This first network element may include an NWDAF or a NEF.
[0190] In some implementations, the third network element can send a user authorization revocation message to the second network element to instruct the deletion of data related to the user authorization. The second network element may include an AF (Automatic Feedback Controller).
[0191] In some implementations, the third network element may send a user authorization revocation message to the second network element according to a second policy. This second policy may include at least one of operator policies and regulatory requirements.
[0192] Figure 10 A schematic diagram of a user consent revocation process according to an embodiment of this application. All relevant entities (such as AF, NEF, NWDAF, etc.) can subscribe to user consent revocation as a service in the UDM and reuse the subscription notification program. When a user's privacy policy changes, such as no longer agreeing to NWDAF collecting user data or using data for analysis, or no longer agreeing to provide user data and / or data analysis results to an AF, the UDM should notify the network elements subscribed to the data change service to stop collecting or using the relevant data for analysis, and to stop providing user data and / or data analysis results to that AF. This process can respond promptly to changes in user consent and prevent user privacy leakage. Figure 10As shown, the user's consent withdrawal process includes the following steps:
[0193] Step 0: Data users (such as AF) subscribe to the UDM with the user's consent to withdraw as a service and reuse the subscription notification program. Similarly, NWDAF or NEF subscribes to the UDM with the user's consent to withdraw as a service and reuse the subscription notification program.
[0194] Step 1: UDM updates subscription information to allow users to withdraw their consent upon request. Users can change their consent, such as their consent to NWDAF or NEF collecting and analyzing user data, or their consent to AF using user data for AI / ML operations.
[0195] Step 2: The UDM sends a Nudm_SDM_Notify message to the NWDAF or NEF, including the UE ID, Application ID, and user consent result. The UE ID is related to the user ID (e.g., SUPI). The user consent result indicates whether the data processor is allowed to process the data for the intended purpose. Upon receiving the request, the NWDAF or NEF will stop analyzing and collecting the specified user's data and delete all related consent data.
[0196] Step 3: UDM reviews local policies, regulations, and regulatory policies to determine whether to notify the AF user of their consent to the revocation. If notified, proceed to the next step depending on whether the AF is within a trusted domain.
[0197] Step 4: The UDM sends a Nudm_SDM_Notify message to the AF. This message may contain the UE ID, ApplicationID, purpose of the auxiliary data, and user consent result. Upon receiving this message, the AF processes the relevant data according to local policies and regulations, such as deleting data that has already been approved by the user.
[0198] As can be seen, the authorization mechanism proposed in this application can be applied to the authorization of AF (Automatic Feedback Controller) collecting and utilizing data related to 5G core network and user privacy in AI / ML scenarios, including the checking and revocation of user consent for core network elements and AF. This avoids exposing unnecessary information to AF or related core network elements, thereby protecting user privacy.
[0199] Figure 11 This is a schematic flowchart of an authorized method 1100 according to an embodiment of this application, which can be applied to... Figure 1 The system shown is not limited to this. The method includes at least a portion of the following.
[0200] S1110: The first network element receives the user's authorization revocation information.
[0201] The first network element may include NWDAF or NEF.
[0202] In some implementations, the user authorization revocation information may include first authorization revocation information and / or second authorization revocation information; wherein, the first authorization revocation information indicates that the collection and / or analysis of user data is not permitted; and the second authorization revocation information indicates that the user's data and / or data analysis results are not permitted to be provided to the second network element.
[0203] The data mentioned above may include AI / ML-assisted data.
[0204] In some implementations, the revocation information for user authorization includes the revocation information for user consent.
[0205] The first network element receiving the user's authorization revocation information may include: the first network element receiving the user's consent result, and also receiving at least one of the UE's identifier, application identifier, and data purpose.
[0206] Upon receiving a user's authorization revocation information, the first network element can stop collecting and / or analyzing the user's data based on the revocation information.
[0207] Prior to step S1110 above, the first network element may subscribe to a notification service for user authorization revocation from the third network element. The third network element may include a UDM.
[0208] The specific implementation method of this embodiment can be referred to the above. Figure 9-10 The description of the first network element in the relevant implementation methods will not be repeated here.
[0209] Figure 12 This is a schematic flowchart of an authorized method 1200 according to an embodiment of this application, which can be applied to... Figure 1 The system shown is not limited to this. The method includes at least a portion of the following.
[0210] S1210: The second network element receives the user's authorization revocation information.
[0211] The second network element may include AF.
[0212] In some implementations, the user authorization revocation information may include first authorization revocation information and / or second authorization revocation information; wherein, the first authorization revocation information indicates that the collection and / or analysis of user data is not permitted; and the second authorization revocation information indicates that the provision of user data and / or data analysis results to the second network element is not permitted.
[0213] The data mentioned above may include AI / ML-assisted data.
[0214] In some implementations, the revocation information for user authorization may include the revocation information for user consent.
[0215] In some implementations, the second network element receiving the user's authorization revocation information may include: the second network element receiving the user's consent result, and also receiving at least one of the UE's identifier, application identifier, and data purpose.
[0216] In some implementations, the second network element may also delete data related to the user's authorization based on the user's authorization revocation information.
[0217] In some implementations, prior to step S1210, the second network element may subscribe to a notification service for user authorization revocation from the third network element. The third network element may include a UDM.
[0218] The specific implementation method of this embodiment can be referred to the above. Figure 9-10 The details regarding the second network element in the relevant implementation methods will not be repeated here.
[0219] This application also proposes a first network element in its embodiments. Figure 13 This is a schematic diagram of the structure of the first network element 1300 according to an embodiment of this application, including...
[0220] The inspection module 1310 checks the user's authorization information and provides the user's data and / or data analysis results to the second network element when the inspection result is as follows:
[0221] Allows the collection and / or analysis of the user's data; and,
[0222] Allow the second network element to provide the user's data and / or data analysis results.
[0223] In some implementations, the inspection module 1310 is used to inspect the user's first authorization information and second authorization information, wherein;
[0224] This first authorization information is used to indicate whether the collection and / or analysis of the user's data is permitted;
[0225] The second authorization information is used to indicate whether it is permissible to provide the user's data and / or data analysis results to the second network element.
[0226] In some implementations, the authorization information includes User Consent;
[0227] This first authorization information includes the user's consent to the first network element;
[0228] The first authorization information includes the user's consent to the second network element.
[0229] In some embodiments, the inspection module 1310 includes:
[0230] The first acquisition submodule 1311 is used to acquire the user's first authorization information;
[0231] The first determining submodule 1312 is used to determine, based on the first authorization information, whether to allow the collection and / or analysis of the user's data.
[0232] In some implementations, the first acquisition submodule 1311 is used to query the locally stored UE context and obtain the user's first authorization information from the UE context.
[0233] In some implementations, the first acquisition submodule 1311 is used to acquire the user's first authorization information from a third network element.
[0234] In some implementations, the first acquisition submodule 1311 is used for:
[0235] Send at least one of the UE's identifier, application identifier, and data purpose to the third network element;
[0236] The third network element receives the user's first authorization information.
[0237] In some embodiments, the inspection module 1310 includes:
[0238] The second acquisition submodule 1313 is used to acquire the user's second authorization information;
[0239] The second determining submodule 1314 is used to determine, based on the second authorization information, whether it is permissible to provide the user's data and / or data analysis results to the second network element.
[0240] In some implementations, the second acquisition submodule 1313 is used to query the locally stored UE context and obtain the user's second authorization information from the UE context.
[0241] In some implementations, the second acquisition submodule 1313 is used to acquire the user's second authorization information from the third network element.
[0242] In some implementations, the second acquisition submodule 1313 is used for:
[0243] Send to the third network element at least one of the UE's identifier, application identifier, and data purpose;
[0244] The user's second authorization information is received from the third network element.
[0245] Figure 14This is a schematic diagram of the structure of a first network element 1400 according to an embodiment of this application. The first network element 1400 includes one or more features of the first network element embodiment described above. In one possible implementation, this embodiment of the application further includes:
[0246] The first receiving module 1420 is used to receive the data authorization request of the second network element.
[0247] In some implementations, it also includes:
[0248] The determination module 1430 is used to determine whether it is necessary to check the user's authorization information. If so, it obtains the user's first authorization information and / or the user's second authorization information.
[0249] In some implementations, the determining module 1430 is configured to determine whether the user's authorization information needs to be checked based on the first policy and / or the data type involved in the data authorization request.
[0250] In some implementations, the first strategy includes at least one of operator policies and regulatory requirements.
[0251] In some implementations, the first network element includes NWDAF or NEF.
[0252] In some implementations, the second network element includes an AF.
[0253] In some implementations, the third network element includes a UDM.
[0254] In some implementations, this data includes AI / ML-assisted data.
[0255] In some implementations, the first network element and the second network element belong to the same PLMN or different PLMNs.
[0256] It should be understood that the above and other operations and / or functions of the modules in the communication device according to the embodiments of this application are respectively for implementing Figure 3 The corresponding process of the first network element in method 300 will not be elaborated here for the sake of brevity.
[0257] This application also proposes a third network element in its embodiments. Figure 15 This is a schematic diagram of the structure of the third network element 1500 according to an embodiment of this application, including:
[0258] The first sending module 1510 is used to send the user's authorization information to the first network element so that the first network element can check the user's authorization information.
[0259] In some implementations, the user's authorization information includes checking both first authorization information and second authorization information, wherein;
[0260] This first authorization information is used to indicate whether the collection and / or analysis of the user's data is permitted;
[0261] The second authorization information is used to indicate whether it is permitted to provide the user's data and / or data analysis results to the second network element.
[0262] In some implementations, the authorization information includes User Consent;
[0263] This first authorization information includes the user's consent to the first network element;
[0264] The second authorization information includes the user's consent to the second network element.
[0265] In some implementations, the first transmitting module 1510 is configured to:
[0266] Receive at least one of the UE's identifier, application identifier, and data purpose from the first network element;
[0267] Send the user's first authorization information and / or second authorization information to the first network element.
[0268] In some implementations, the first network element includes NWDAF or NEF.
[0269] In some implementations, the third network element includes a UDM.
[0270] In some implementations, the second network element includes an AF.
[0271] In some implementations, this data includes AI / ML-assisted data.
[0272] It should be understood that the above and other operations and / or functions of the modules in the communication device according to the embodiments of this application are respectively for implementing Figure 7 The corresponding process of the third network element in Method 700 will not be elaborated here for the sake of brevity.
[0273] This application also proposes a second network element in its embodiments. Figure 16 This is a schematic diagram of the structure of the second network element 1600 according to an embodiment of this application, including:
[0274] The second sending module 1610 is used to send a data authorization request, which is used to request user data and / or data analysis results.
[0275] In some implementations, the second network element includes an AF.
[0276] In some implementations, the first network element includes NWDAF or NEF.
[0277] In some implementations, this data includes AI / ML-assisted data.
[0278] It should be understood that the above and other operations and / or functions of the modules in the communication device according to the embodiments of this application are respectively for implementing Figure 8 The corresponding process of the second network element in Method 800 will not be elaborated here for the sake of brevity.
[0279] This application also proposes a third network element in its embodiments. Figure 17 This is a schematic diagram of the structure of the third network element 1700 according to an embodiment of this application, including:
[0280] The third sending module 1710 is used to send the user's authorization revocation information.
[0281] In some implementations, the user authorization revocation information includes revocation information for a first authorization and / or revocation information for a second authorization; wherein,
[0282] The revocation of this first authorization indicates that the collection and / or analysis of the user's data is no longer permitted;
[0283] The revocation of the second authorization indicates that the user's data and / or data analysis results are no longer permitted to be provided to the second network element.
[0284] In some implementations, this data includes AI / ML-assisted data.
[0285] In some implementations, the revocation information for user authorization includes the revocation information for User Consent.
[0286] In some implementations, the third sending module 1710 is used to send the user consent result, and also to send at least one of the UE's identifier, application identifier, and data purpose.
[0287] In some implementations, the third sending module 1710 is used to send revocation information of user authorization when user authorization is revoked.
[0288] In some implementations, the third sending module 1710 is used to send user authorization revocation information to the first network element to instruct the first network element to stop collecting and / or analyzing the user's data.
[0289] In some implementations, the third sending module 1710 is used to send user authorization revocation information to the second network element to instruct the deletion of data related to the user authorization.
[0290] In some implementations, the third sending module 1710 is used to send user authorization revocation information to the second network element according to the second strategy.
[0291] In some implementations, the second strategy includes at least one of operator policies and regulatory requirements.
[0292] In some implementations, the third network element includes a UDM.
[0293] In some implementations, the first network element includes NWDAF or NEF.
[0294] In some implementations, the second network element includes an AF.
[0295] It should be understood that the above and other operations and / or functions of the modules in the communication device according to the embodiments of this application are respectively for implementing Figure 9 The corresponding process of the third network element in Method 900 will not be elaborated here for the sake of brevity.
[0296] This application also proposes a first network element in its embodiments. Figure 18 This is a schematic diagram of the structure of the first network element 1800 according to an embodiment of this application, including:
[0297] The second receiving module 1810 is used to receive the user's authorization revocation information.
[0298] In some implementations, the user authorization revocation information includes revocation information for a first authorization and / or revocation information for a second authorization; wherein,
[0299] The revocation of this first authorization indicates that the collection and / or analysis of the user's data is no longer permitted;
[0300] The revocation of the second authorization indicates that the user's data and / or data analysis results are no longer permitted to be provided to the second network element.
[0301] In some implementations, this data includes AI / ML-assisted data.
[0302] In some implementations, the revocation information for user authorization includes the revocation information for User Consent.
[0303] In some implementations, the second receiving module 1810 is used to receive the user consent result and also to receive at least one of the UE's identifier, application identifier, and data purpose.
[0304] Figure 19 This is a schematic diagram of the structure of a first network element 1900 according to an embodiment of this application. The first network element 1900 includes one or more features of the first network element 1800 embodiment described above. In one possible implementation, this embodiment of the application further includes:
[0305] Stop module 1920 is used to stop collecting and / or analyzing the user's data based on the user's authorized revocation information.
[0306] In some implementations, it also includes:
[0307] The first authorization module 1930 is used to provide notification services for the revocation of authorization to third-party network element subscribers.
[0308] In some implementations, the first authorization module 1930 is used to receive user authorization revocation information from the third network element.
[0309] In some implementations, the first network element includes NWDAF or NEF.
[0310] In some implementations, the third network element includes a UDM.
[0311] It should be understood that the above and other operations and / or functions of the modules in the communication device according to the embodiments of this application are respectively for implementing Figure 11 The corresponding process of the first network element in method 1100 will not be elaborated here for the sake of brevity.
[0312] This application also proposes a second network element in its embodiments. Figure 20 This is a schematic diagram of the structure of the second network element 2000 according to an embodiment of this application, including:
[0313] The third receiving module 2010 is used to receive user authorization revocation information.
[0314] In some implementations, the user authorization revocation information includes revocation information for a first authorization and / or revocation information for a second authorization; wherein,
[0315] The revocation of this first authorization indicates that the collection and / or analysis of the user's data is no longer permitted;
[0316] The revocation of the second authorization indicates that the user's data and / or data analysis results are no longer permitted to be provided to the second network element.
[0317] In some implementations, this data includes AI / ML-assisted data.
[0318] In some implementations, the revocation information for user authorization includes the revocation information for User Consent.
[0319] In some implementations, the third receiving module 2010 is used to receive the user consent result and also to receive at least one of the UE's identifier, application identifier, and data purpose.
[0320] Figure 21This is a schematic diagram of the structure of a second network element 2100 according to an embodiment of this application. The second network element 2100 includes one or more features of the second network element 2000 embodiment described above. In one possible implementation, this embodiment of the application further includes:
[0321] The deletion module 2120 is used to delete data related to the user's authorization based on the user's authorization revocation information.
[0322] In some implementations, it also includes:
[0323] The second authorization module 2130 is used to provide a notification service for the revocation of authorization to the third network element subscriber.
[0324] In some implementations, the second network element includes an AF.
[0325] In some implementations, the third network element includes a UDM.
[0326] It should be understood that the above and other operations and / or functions of the modules in the communication device according to the embodiments of this application are respectively for implementing Figure 12 The corresponding process of the second network element in Method 1200 will not be elaborated here for the sake of brevity.
[0327] It should be noted that the functions described in the various modules (sub-modules, units, or components, etc.) of the communication device in the embodiments of this application can be implemented by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.). For example, the first receiving module and the second receiving module can be different modules or the same module, both of which can realize their corresponding functions in the embodiments of this application. In addition, the transmitting module and receiving module in the embodiments of this application can be implemented by the transceiver of the device, and some or all of the other modules can be implemented by the processor of the device.
[0328] Figure 22 This is a schematic structural diagram of a communication device 2200 according to an embodiment of this application. Figure 22 The communication device 2200 shown includes a processor 2210, which can call and run computer programs from memory to implement the methods in the embodiments of this application.
[0329] In some implementations, such as Figure 22 As shown, the communication device 2200 may further include a memory 2220. The processor 2210 can retrieve and run computer programs from the memory 2220 to implement the methods described in this embodiment.
[0330] The memory 2220 can be a separate device independent of the processor 2210, or it can be integrated into the processor 2210.
[0331] In some implementations, such as Figure 22 As shown, the communication device 2200 may also include a transceiver 2230. The processor 2210 can control the transceiver 2230 to communicate with other devices. Specifically, it can send information or data to other devices or receive information or data sent by other devices.
[0332] The transceiver 2230 may include a transmitter and a receiver. The transceiver 2230 may further include an antenna, and the number of antennas may be one or more.
[0333] In some implementations, the communication device 2200 may be the first network element, the second network element, or the third network element in the embodiments of this application, and the communication device 2200 may implement the corresponding processes implemented by the first network element, the second network element, or the third network element in the various methods of the embodiments of this application. For the sake of brevity, these will not be described in detail here.
[0334] Figure 23 This is a schematic structural diagram of chip 2300 according to an embodiment of this application. Figure 23 The chip 2300 shown includes a processor 2310, which can call and run computer programs from memory to implement the methods in the embodiments of this application.
[0335] In some implementations, such as Figure 23 As shown, chip 2300 may further include memory 2320. Processor 2310 can retrieve and run computer programs from memory 2320 to implement the methods described in this embodiment.
[0336] The memory 2320 can be a separate device independent of the processor 2310, or it can be integrated into the processor 2310.
[0337] In some embodiments, the chip 2300 may further include an input interface 2330. The processor 2310 can control the input interface 2330 to communicate with other devices or chips; specifically, it can acquire information or data sent by other devices or chips.
[0338] In some embodiments, the chip 2300 may further include an output interface 2340. The processor 2310 can control the output interface 2340 to communicate with other devices or chips; specifically, it can output information or data to other devices or chips.
[0339] In some implementations, the chip can be applied to the communication device in the embodiments of this application, and the chip can implement the corresponding processes implemented by the network device in the various methods of the embodiments of this application. For the sake of brevity, it will not be described in detail here.
[0340] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0341] The processors mentioned above can be general-purpose processors, digital signal processors (DSPs), field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), or other programmable logic devices, transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processors mentioned above can be microprocessors or any conventional processor.
[0342] The aforementioned memory can be volatile memory or non-volatile memory, or a combination of both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM).
[0343] It should be understood that the above-described memory is exemplary and not a limiting description. For example, the memory in the embodiments of this application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DR RAM), etc. That is to say, the memory in the embodiments of this application is intended to include, but is not limited to, these and any other suitable types of memory.
[0344] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. This computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
[0345] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0346] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0347] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. An authorization method, comprising: The first network element checks the user's authorization information and provides the user's data and / or data analysis results to the second network element when the check result is as follows: Allows the collection and / or analysis of the user's data; and, Allows the second network element to provide the user's data and / or data analysis results.
2. An authorization method, comprising: First network element subscribes to third network element for a notification service that allows users to revoke their authorization; The first network element receives the user authorization revocation information from the third network element, wherein the user authorization revocation information includes the revocation information of the user's consent; The first network element stops collecting and / or analyzing user data based on the user's authorization revocation information.
3. The method according to claim 2, wherein, The first network element includes Network Data Analysis Function (NWDAF) or Network Open Function (NEF).
4. The method according to claim 2 or 3, wherein, The third network element includes the User Data Management (UDM) function.
5. An authorization method, comprising: The second network element receives user authorization revocation information, wherein the user authorization revocation information includes revocation information of user consent; The second network element deletes the data related to the user authorization based on the user authorization revocation information.
6. A first network element, comprising: The inspection module is used to inspect the user's authorization information. When the inspection result is as follows, it provides the user's data and / or data analysis results to the second network element: Allows the collection and / or analysis of the user's data; and, Allows the second network element to provide the user's data and / or data analysis results.
7. A first network element, comprising: The first authorization module is used to provide notification services for the revocation of authorization to third-party network element subscribers; The second receiving module is used to receive user authorization revocation information from the third network element, wherein the user authorization revocation information includes revocation information of user consent; The stop module is used to stop collecting and / or analyzing user data based on the user's authorized revocation information.
8. The method according to claim 7, wherein, The first network element includes Network Data Analysis Function (NWDAF) or Network Open Function (NEF).
9. The method according to claim 7 or 8, wherein, The third network element includes the User Data Management (UDM) function.
10. A second network element, comprising: The third receiving module is used to receive user authorization revocation information, wherein the user authorization revocation information includes revocation information of user consent; The deletion module is used to delete data related to the user's authorization based on the user's authorization revocation information.
Citation Information
Patent Citations
Early data transmission authorization control
CN111357381A
User information analysis result feedback method and device
CN114760619A
Data collection method and device
CN114788229A
Communication method, device and system, and storage medium
WO2021062793A1