Perceptual service privacy
By introducing a new perceptual privacy profile and enhancing UDM/SeMF functionality, the privacy protection issue of perceptual services in 5G systems has been addressed, enabling compliant output of perceptual data and protection of sensitive information.
Patent Information
- Application Number
- CN202480031675.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-05-11
- Filing Date
- 2024-03-26
- Publication Date
- 2025-12-12
AI Technical Summary
Existing 5G systems lack effective privacy profiles and privacy inspection mechanisms, failing to meet the diverse privacy requirements of perceived services, especially in sensitive data detection and object feature privacy protection in the area surrounding the UE.
New types of perception privacy profiles are introduced, including location-aware, UE-aware, and object-aware privacy indicators. The functionality of UDM and SeMF is enhanced to implement privacy checks and data obfuscation mechanisms during the perception process, and to support perception service requests in the LCS architecture.
It achieves privacy protection for sensing services, ensures compliant output of sensing data and privacy protection for sensitive information, and meets the privacy requirements of different environments and objects.
Smart Images

Figure CN121128201A_ABST
Abstract
Description
Technical Field
[0001] Various example embodiments relate to privacy-aware services. More specifically, various example embodiments relate to methods (including methods, apparatus, and computer program products) for implementing privacy-aware services. Background Technology
[0002] This disclosure generally relates to sensing services and privacy aspects of sensing services. The goal of sensing services is to acquire perception of the scene surrounding the sensing device, including the ability to detect, locate and track objects, form images, and / or extract features for identification / classification purposes. Integrated communication and sensing (ISAC) can help achieve both high data rate communication and high-resolution obstacle detection using the same hardware and spectrum resources. Different types of applications can benefit from the integrated communication and sensing services available from 5G or beyond systems. Sensing services can be requested by a user equipment (UE) or application function (AF), or a client in the network (e.g., a location service (LCS) client) or network function (NF). Summary of the Invention
[0003] Various exemplary aspects of the exemplary embodiments are set forth in the appended claims.
[0004] According to an example, a method is provided, the method comprising: generating perception service-related privacy profile information, the perception service-related privacy profile information indicating: a profile type corresponding to the perception service-related privacy profile information, and sending the perception service-related privacy profile information, wherein the perception service-related privacy profile information includes: an indication of whether perception of a perception target dependent on the profile type is permitted, the perception target dependent on the profile type being associated with the perception service-related privacy profile information.
[0005] According to one example aspect, a method is provided, the method comprising: receiving sensing service-related privacy profile information, the sensing service-related privacy profile information indicating: a profile type of the sensing service-related privacy profile corresponding to the sensing service-related privacy profile information; and storing the sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information.
[0006] According to one example aspect, a method is provided, the method comprising: receiving a sensing service request, and performing a sensing privacy check on the sensing service request based on sensing service-related privacy profile information indicating a profile type of a sensing service-related privacy profile corresponding to the sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information.
[0007] According to one example aspect, an apparatus is provided, comprising: a generation circuitry system configured to generate sensing service-related privacy profile information, the sensing service-related privacy profile information indicating: a profile type of a sensing service-related privacy profile corresponding to the sensing service-related privacy profile information; and a transmission circuitry system configured to transmit the sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information.
[0008] According to one example aspect, an apparatus is provided, comprising: a receiving circuitry system configured to receive sensing service-related privacy profile information, the sensing service-related privacy profile information indicating: a profile type of a sensing service-related privacy profile corresponding to the sensing service-related privacy profile information; and a storage circuitry system configured to store the sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information.
[0009] According to one example aspect, an apparatus is provided, comprising: a receiving circuitry system configured to receive a sensing service request; and an execution circuitry system configured to perform a sensing privacy check on the sensing service request based on sensing service-related privacy profile information indicating a profile type corresponding to sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information.
[0010] According to one example aspect, an apparatus is provided, comprising: at least one processor, at least one memory including computer program code, and at least one interface configured to communicate with at least another apparatus, wherein the at least one processor, together with the at least one memory and the computer program code, is configured to cause the apparatus to perform: generating perception service-related privacy profile information, the perception service-related privacy profile information indicating: a profile type of the perception service-related privacy profile corresponding to the perception service-related privacy profile information, and sending the perception service-related privacy profile information, wherein the perception service-related privacy profile information includes: an indication of whether perception of a perception target dependent on the profile type is permitted, the perception target dependent on the profile type being associated with the perception service-related privacy profile information.
[0011] According to one example aspect, an apparatus is provided, comprising: at least one processor, at least one memory including computer program code, and at least one interface configured to communicate with at least another apparatus, wherein the at least one processor, together with the at least one memory and the computer program code, is configured to cause the apparatus to perform: receiving sensing service-related privacy profile information, the sensing service-related privacy profile information indicating: a profile type of the sensing service-related privacy profile corresponding to the sensing service-related privacy profile information, and storing the sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information.
[0012] According to one example aspect, an apparatus is provided, comprising: at least one processor, at least one memory including computer program code, and at least one interface configured to communicate with at least another apparatus, wherein the at least one processor, together with the at least one memory and the computer program code, is configured to cause the apparatus to perform: receiving a sensing service request, and performing a sensing privacy check on the sensing service request based on sensing service-related privacy profile information indicating a profile type corresponding to sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a profile-type-dependent sensing target is permitted, the profile-type-dependent sensing target being associated with the sensing service-related privacy profile information.
[0013] According to one example aspect, a computer program product including computer-executable computer program code is provided, which, when run on a computer (e.g., a computer of an apparatus according to any of the foregoing apparatus-related example aspects of this disclosure), is configured to cause the computer to perform a method according to any of the foregoing apparatus-related example aspects of this disclosure.
[0014] Such computer program products may include (or be embodied in) a (tangible) computer-readable (storage) medium on which computer-executable computer program code is stored, and / or the program may be directly loaded into the internal memory of a computer or its processor.
[0015] Any of the foregoing aspects enables the provision of privacy profiles applicable to the perceived service, as well as an efficient supply of privacy checks for the perceived service. Various of the foregoing aspects can resolve at least some of the problems and deficiencies identified herein regarding the prior art.
[0016] Through example embodiments, service-aware privacy is provided. More specifically, through example embodiments, methods and mechanisms for implementing service-aware privacy are provided.
[0017] Therefore, improvements are achieved through methods, devices, and computer program products that enable / realize privacy-aware services. Attached Figure Description
[0018] In the following, this disclosure will be described in more detail by way of non-limiting example with reference to the accompanying drawings, in which:
[0019] Figure 1 This is a block diagram illustrating an apparatus according to an example embodiment.
[0020] Figure 2 This is a block diagram illustrating an apparatus according to an example embodiment.
[0021] Figure 3 This is a block diagram illustrating an apparatus according to an example embodiment.
[0022] Figure 4 This is a block diagram illustrating an apparatus according to an example embodiment.
[0023] Figure 5 This is a block diagram illustrating an apparatus according to an example embodiment.
[0024] Figure 6 This is a block diagram illustrating an apparatus according to an example embodiment.
[0025] Figure 7 This is a schematic diagram of a process according to an example embodiment.
[0026] Figure 8 This is a schematic diagram of a process according to an example embodiment.
[0027] Figure 9 This is a schematic diagram of a process according to an example embodiment.
[0028] Figure 10 A schematic diagram of a signaling sequence according to an example embodiment is shown.
[0029] Figure 11 A schematic diagram of a signaling sequence according to an example embodiment is shown.
[0030] Figure 12 A schematic diagram of a signaling sequence according to an example embodiment is shown.
[0031] Figure 13 A schematic diagram of a signaling sequence according to an example embodiment is shown.
[0032] Figure 14 A schematic diagram of a signaling sequence according to an example embodiment is shown, and
[0033] Figure 15 A block diagram of an apparatus according to an example embodiment is shown alternatively. Detailed Implementation
[0034] This disclosure is described herein with reference to specific non-limiting examples and embodiments that are now considered conceivable. Those skilled in the art will recognize that this disclosure is not intended to be limited to these examples and can be applied more broadly.
[0035] It should be noted that the following description and embodiments of this disclosure primarily refer to specifications used as non-limiting examples for certain example network configurations and deployments. That is, this disclosure and its embodiments are primarily described with respect to 3GPP specifications used as non-limiting examples for certain example network configurations and deployments. Therefore, the description of the example embodiments given herein specifically refers to terms directly related to them. Such terms are used only in the context of the presented non-limiting examples and naturally do not limit this disclosure in any way. Rather, any other communication or communication-related system deployments, etc., may be utilized as long as they conform to the features described herein.
[0036] In the following, various embodiments and implementations of this disclosure and its aspects or examples are described using several variations and / or alternatives. It is generally noted that, depending on certain requirements and limitations, all said variations and / or alternatives may be provided individually or in any conceivable combination (including combinations of individual features of various variations and / or alternatives).
[0037] As used herein, “at least one of the following:” and “at least one of the following” and similar wording, where a list of two or more elements is connected by “and” or “or”, indicates at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.
[0038] Ensuring the data privacy of sensing services and sensing objects is a key function that should be provided by 5G and higher communication systems.
[0039] Since sensing can be used in almost the entire environment covered by radio frequency (RF) signals, the privacy of sensing operations is an important consideration for practical deployment.
[0040] For private areas, private permission is required to sense actions from homeowners (for home sensing) or building management (for sensing within buildings). For public areas, such as public roads, parks, and airports, permission from public area management is required. For specific objects (e.g., rainfall), the content of the sensing results report is restricted based on the permissions of the sensing requester; for example, climate and rainfall detection may be reported to the weather bureau.
[0041] For sensing objects that support 3GPP UE capabilities, 5GS should notify the UE of sensing events before sensing the objects and ensure user permission.
[0042] These privacy policies need to be configured on the 5GS and can be flexibly modified by relevant parties under the control of the operator.
[0043] There are various applications that can benefit from sensing services, which can be implemented in various environments (e.g., public environments such as roads, indoor areas such as industrial plants) and sense different types of information (e.g., vehicles, people, buildings, health characteristics, environmental characteristics, etc.), which can be privacy-sensitive.
[0044] Different use cases have different privacy requirements, which is important for ISAC systems embedded in 5G and higher systems, and allows data owners to define privacy rules and use them in different awareness methods and requests.
[0045] Existing privacy mechanisms defined for LCS have been developed to have a specific UE as a core part of their legitimacy, for example, described by a Subscription Permanent Identifier (SUPI). However, this is insufficient for awareness services.
[0046] That is, there is no existing privacy profile data maintained in the 5G core network, or the existing privacy profile data does not support multiple privacy requirements of several use cases, as follows: - Allow or disallow the definition of a region or geographic area (non-UE privacy aspects). - Allow or disallow the detection of connection objects that do not have SUPI or cannot typically be described by communication-related identifiers, and - To obfuscate, hide, or alter important / sensitive features of the detected object (e.g., size, shape, etc.).
[0047] In addition, the perception request from the UE or AF to the 5GC should also pass the required privacy check, because the area around the UE may include sensitive privacy data (e.g., objects, features, etc.), which is not supported and required in LCS-related privacy checks.
[0048] Specifically, it is known that the UE can generate (or update) a UE location privacy indicator, and the UE sends the location privacy indicator to the AMF in an N1 NAS message. The UE location privacy indicator specifies whether or not to respond to subsequent LCS requests for the UE. The Access and Mobility Functions then invoke the Nudm_ParameterProvision_Update (LCS Privacy) service operation to the Unified Data Management (UDM), and this service operation carries the location privacy indicator information. The UDM accordingly stores or updates the UE LCS privacy profile in the Unified Data Repository (UDR) by invoking Nudr_DM_Update (SUPI, Subscription Data).
[0049] Additionally, it is known that in the case of a location service request, the privacy profile settings of the target UE should always be checked in the UE's Home Public Land Mobile Network (PLMN) before the location estimate is delivered. Specifically, the (H)GMLC calls the Nudm_SDM_Get service operation to the target UE's UDM to obtain the UE's privacy settings identified by its GPSI or SUPI.
[0050] The UDM returns the target UE's privacy settings, and the (H)GMLC checks the UE's LCS privacy profile. If the target UE is not allowed to locate, the corresponding UE's location information is not provided. A similar privacy check is performed before providing location information.
[0051] It is also envisioned that 5G systems should be able to provide security mechanisms to ensure the privacy of perceived data within the perceived service area. In other words, given the specific requirements of the sensing process, the need for privacy considerations in perceived services is recognized, but has not yet been addressed in existing specifications.
[0052] In other words, in general, existing / conceptual 5G systems do not have the specified privacy features for the sensing services with new requirements as described above.
[0053] Therefore, the need for privacy features for perceived services has arisen.
[0054] Therefore, there is a need to provide privacy-aware services.
[0055] Various example embodiments are intended to address at least some of the problems and / or defects described above.
[0056] According to example embodiments, methods and mechanisms are typically provided for (enabling / implementing) awareness of service privacy.
[0057] Specifically, according to the example embodiments, methods are provided regarding how, for example, the AF and UE can define privacy profiles applicable to the sensing service, and regarding new privacy checks required by the sensing service.
[0058] In short, according to the example embodiments, configuration files, methods, and functions (e.g., 5GS-specific functions) are provided to enable privacy checks for sensing services in 5G systems.
[0059] Thus, the new privacy profile and its management have been defined.
[0060] This new perceived privacy profile is defined to support a variety of perceived services that include privacy data related to both users and non-users.
[0061] According to the example implementation, the following types of privacy-aware profiles are introduced: -Location-aware privacy indications -UE-aware privacy indication, and - Object-aware privacy indications. For example, the configuration file type can be at least one of the following: location-aware type, terminal type, or object-aware type.
[0062] The new perceptual privacy profile according to the example embodiment provides information for configuring and executing the perceptual process, as well as information about whether and which perceptual data outputs should be exposed.
[0063] Thus, according to the example embodiment, the UDM is enhanced to store and manage user / subscriber-related privacy profile information (e.g., UE-aware privacy indications), while non-user-related privacy information (e.g., location-aware awareness privacy indications and object-aware awareness privacy indications) can be stored and managed by new features according to the example embodiment (e.g., awareness management function (SeMF)) and / or by a repository according to the example embodiment (e.g., awareness data management (SDM)), or the awareness data management can be implemented in existing network functions.
[0064] Additionally, according to the example embodiment, signaling is defined to configure and update perceived privacy profiles generated or updated by external entities via AF or by the UE at the UDM and / or SeMF or any other network function (NF).
[0065] Furthermore, it defines privacy and the implementation of rules.
[0066] Thus, according to the example embodiment, a method is provided to enable a perception privacy check at SeMF prior to the initiation of the perception process, based on a perception service request from a perception client and taking into account an appropriate perception privacy profile.
[0067] Specifically, according to the example embodiment, SeMF determines the appropriate sensing configuration based on the limitations or parameters provided by the retrieved sensing privacy profile. Additionally, according to the example embodiment, after the sensing process is completed, a sensing privacy check can be performed by SeMF to determine / check the sensing outputs that can be exposed to sensing clients from SeMF based on the relevant sensing privacy profile.
[0068] Furthermore, signaling and procedures for privacy checks in perceived service requests are defined, and enhancements are provided to the interfaces / methods of LCS-based architectures, GMLC functions, and existing location services to enable perceived privacy checks for perceived service requests using the LCS architecture.
[0069] Additionally, according to the example embodiment, the aware privacy profile can initiate the obfuscation of aware data (e.g., obfuscating objects or objects of a specific type) and can provide information about the obfuscation configuration, methods, etc., performed at SeMF or RAN or another NF.
[0070] The example embodiments are described in more detail below.
[0071] Figure 1 This is a block diagram illustrating an apparatus according to an example embodiment. The apparatus may be a network node or entity 10, such as a user equipment or application function entity, including a generation circuitry system 11 and a transmission circuitry system 12. The generation circuitry system 11 generates awareness service-related privacy profile information, which indicates the profile type of the awareness service-related privacy profile corresponding to the awareness service-related privacy profile information. In one example embodiment, the awareness service-related privacy profile includes a privacy profile related to the awareness service; the privacy profile may be a policy type, which may be, for example, a location-aware type, a UE type, and an object-aware type; the awareness service-related privacy profile information includes the awareness service-related privacy profile and the profile type used for the awareness service-related privacy profile.
[0072] The transmitting circuit system 12 transmits privacy profile information related to the sensing service. This privacy profile information includes an indication of whether sensing of a sensing target dependent on a profile type is permitted, the sensing target being associated with the privacy profile information. In one example embodiment, the privacy profile information includes sensing targets dependent on a profile type, and an indication of whether sensing of the sensing targets dependent on a profile type is permitted; the sensing targets dependent on a profile type include targets whose sensing depends on the target's profile type. Figure 7 This is a schematic diagram of a process according to an example embodiment. According to Figure 1 The device can perform Figure 7 The method is applicable, but not limited to this method. Figure 7 The method can be derived from Figure 1 The device performs the operation, but is not limited to performing the operation by that device.
[0073] like Figure 7As shown, the process according to the example embodiment includes an operation (S71) of generating privacy profile information related to the perception service, which indicates the profile type of the privacy profile related to the perception service, and an operation (S72) of sending the privacy profile information related to the perception service. The privacy profile information related to the perception service includes an indication of whether perception of a perception target dependent on the profile type is permitted, the perception target dependent on the profile type being associated with the privacy profile information related to the perception service.
[0074] Figure 2 This is a block diagram illustrating an apparatus according to an example embodiment. Specifically, Figure 2 It shows Figure 1 The device shown is modified. Therefore, according to Figure 2 The device may also include a transmitting circuit system 21.
[0075] In an embodiment, Figure 1 At least some of the functions of the apparatus shown in (or 2) can be shared between two physically separate devices forming an operational entity. Therefore, the apparatus can be considered as an operational entity comprising one or more physically separate devices for performing at least some of the processes.
[0076] According to another example embodiment, the configuration file type is at least one of the following: Location-awareness is related to perceived privacy. Terminal-sensory privacy related, or Object-aware perception related to privacy. For example, the configuration file type can be at least one of the following: location-aware type, terminal type, or object-aware type.
[0077] According to the example embodiments, examples of terminals include user equipment (UE), vehicles with communication capabilities, drones with communication capabilities, robots with communication capabilities, etc.
[0078] According to another example embodiment, the configuration file type is location-aware privacy-related, and the privacy configuration file information related to the awareness service includes at least one of the following: Information about the geographic region corresponding to the perceived target that depends on the configuration file type. Information regarding perceptually allowed configurations. Information regarding the validity period of the privacy configuration file information related to the aforementioned perception service. Information regarding exceptions to the privacy profile information related to the aforementioned perception service. Information about object obfuscation Information regarding the validity period of the indicated instruction. Information about the receiver that outputs privacy profile information related to the perception service during the perception process, or Information about the settings entity for privacy profile information related to the perception service.
[0079] According to example embodiments, examples of obfuscation or obfuscation processing (or masking, blurring) include: obfuscating or hiding or altering important / sensitive features (e.g., location, size, shape, etc.) of the detected object.
[0080] According to another example embodiment, the configuration file type is terminal-aware privacy-related, and the privacy configuration file information related to the awareness service includes at least one of the following: Information regarding perceptually allowed configurations. Information regarding a geographic region, for which the instructions are valid. Information regarding time or time period, for which the instruction is valid. Information about the perception service role that depends on the perception target of the configuration file type.
[0081] According to another example embodiment, the configuration file type is object-aware privacy-related, and the privacy configuration file information related to the awareness service includes at least one of the following: Information about the object type of the perception target that depends on the configuration file type. Information about perception-permissive configurations, or Information about the receiver that outputs privacy profile information related to the perception service during the perception process.
[0082] According to another example embodiment, the perception-permissive configuration defines at least one of the following: Obfuscation of object characteristics is enabled, or No object or terminal identifier was indicated.
[0083] according to Figure 7 The variations in the process shown provide example details of the sending operation (S72), which are intrinsically independent of each other. Such an example sending operation (S72) according to the example embodiment may include sending the privacy profile information related to the sensing service together with a sensing service privacy profile setting request, or a sensing service privacy profile creation request, or a sensing service privacy profile update request.
[0084] according to Figure 7The variations in the process shown provide example additional operations, which are intrinsically independent of each other. According to this variation, an example method based on an example embodiment may include: sending an operation instructing the deletion of a privacy profile related to the awareness service.
[0085] Figure 3 This is a block diagram illustrating an apparatus according to an example embodiment. The apparatus may be a network node or entity 30 including a receiving circuitry system 31 and a storage circuitry system 32, such as a unified data management entity, a perception management function entity, a perception data management entity, or an entity providing such functionality. The receiving circuitry system 31 receives perception service-related privacy profile information, indicating the profile type of the perception service-related privacy profile corresponding to the privacy profile information. The storage circuitry system 32 stores the perception service-related privacy profile information. The perception service-related privacy profile information includes: an indication of whether perception of a perception target dependent on the profile type is permitted, the perception target dependent on the profile type being associated with the perception service-related privacy profile information. Figure 8 This is a schematic diagram of a process according to an example embodiment. According to Figure 3 The device can perform Figure 8 The method is applicable, but not limited to this method. Figure 8 The method can be derived from Figure 3 The device performs the operation, but is not limited to performing the operation by that device.
[0086] like Figure 8 As shown, the process according to the example embodiment includes an operation (S81) of receiving privacy profile information related to a sensing service, which indicates the profile type of the privacy profile related to the sensing service corresponding to the privacy profile information, and an operation (S82) of storing the privacy profile information related to the sensing service. The privacy profile information related to the sensing service includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the privacy profile information related to the sensing service.
[0087] Figure 4 This is a block diagram illustrating an apparatus according to an example embodiment. Specifically, Figure 4 It shows Figure 3 The device shown is modified. Therefore, according to Figure 4 The apparatus may also include a deletion circuit system 41, a sending circuit system 42, an execution circuit system 43, a request circuit system 44, a decision circuit system 45, a determination circuit system 46, and / or a receiving circuit system 47.
[0088] In an embodiment, Figure 3 At least some of the functions of the apparatus shown in (or 4) can be shared between two physically separate devices forming an operational entity. Therefore, the apparatus can be considered as an operational entity comprising one or more physically separate devices for performing at least some of the processes.
[0089] according to Figure 8 The process shown is modified. Example additional operations are given, which are intrinsically independent of each other. According to this modification, the example method according to the example embodiment may include: determining at least one network entity to store received privacy profile information related to the perceived service.
[0090] According to another example embodiment, the storage device includes at least one of the following: a unified data warehouse (UDR), or a unified data management (UDM), or a sensed management function (SeMF), or any storage database.
[0091] That is, UE-specific perceived privacy settings can be initiated by the UE, and perceived privacy settings can be initiated by the transmitter (e.g., AF).
[0092] Therefore, according to the example embodiment, the transmitter (e.g., AF) can send data via NEF instead of directly to the UDM, SeMF, or SDM, and then the NEF can decide whether to store it in the UDM / UDR or SeMF. On the other hand, according to the example embodiment, the UE can send data directly to the UDM (SeMF, SDM), and then it can always be stored in the UDM.
[0093] According to another example embodiment, the configuration file type is at least one of the following: Location-awareness is related to perceived privacy. Terminal-sensory privacy related, or Object-aware perception related to privacy.
[0094] According to another example embodiment, the configuration file type is location-aware privacy-related, and the privacy configuration file information related to the awareness service includes at least one of the following: Information about the geographic region corresponding to the perceived target that depends on the configuration file type. Information regarding perceptually allowed configurations. Information regarding the validity period of the privacy configuration file information related to the aforementioned perception service. Information regarding exceptions to the privacy profile information related to the aforementioned perception service. Information about object obfuscation Information regarding the validity period of the indicated instruction. Information about the receiver that outputs privacy profile information related to the perception service during the perception process, or Information about the settings entity for privacy profile information related to the perception service.
[0095] According to another example embodiment, the configuration file type is terminal-aware privacy-related, and the privacy configuration file information related to the awareness service includes at least one of the following: Information regarding perceptually allowed configurations. Information regarding a geographic region, for which the instructions are valid. Information regarding time or time period, for which the instruction is valid. Information about the perception service role that depends on the perception target of the configuration file type.
[0096] According to another example embodiment, the configuration file type is object-aware privacy-related, and the privacy configuration file information related to the awareness service includes at least one of the following: Information about the object type of the perception target that depends on the configuration file type. Information about perception-permissive configurations, or Information about the receiver that outputs privacy profile information related to the perception service during the perception process.
[0097] According to another example embodiment, the perception-permissive configuration defines at least one of the following: Obfuscation of object characteristics is enabled, or No object or terminal identifier was indicated.
[0098] According to another example embodiment, the privacy profile information related to the sensing service is received together with the sensing service privacy profile setting request, or the sensing service privacy profile creation request, or the sensing service privacy profile update request.
[0099] according to Figure 8 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. According to this variation, an example method according to an example embodiment may include: receiving an operation indicating a request to delete a privacy profile related to a privacy profile for a perception service, and deleting the perception service-related privacy profile information corresponding to the privacy profile related to the perception service.
[0100] according to Figure 8The variations in the process shown provide example additional operations, which are intrinsically independent of each other. According to this variation, an example method based on an example embodiment may include: sending a subscription notification to at least one subscriber entity indicating a change in a privacy profile related to the awareness service.
[0101] according to Figure 8 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. According to this variation, an example method based on an example embodiment may include: receiving a sensing service request, and performing a sensing privacy check on the sensing service request based on privacy profile information associated with the sensing service.
[0102] according to Figure 8 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. Based on this variation, an example method according to an example embodiment may include: the operation of requesting privacy profile information related to the perception service.
[0103] according to Figure 8 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. Based on this variation, an example method according to an example embodiment may include: determining, based on the result of the perceived privacy check, an operation to initiate a perceived process corresponding to the perceived service request.
[0104] according to Figure 8 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. Based on this variation, an example method according to an example embodiment may include: determining an operation for the perception configuration of the perception process based on privacy profile information related to the perception service.
[0105] according to Figure 8 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. Based on such variations, an example method according to an example embodiment may include: operations for receiving a perception result regarding the perception process, and operations for determining a perception output based on the perception result.
[0106] According to example embodiments, examples of sensing results (or sensing measurement information, or sensing data) include data derived from radio signals (e.g., 3GPP, non-3GPP, WiFi, radar, lidar, etc.) that are affected by the object of interest or the environment for sensing purposes (e.g., reflection, refraction, diffraction) and optionally processed (e.g., within a 5G / 6G system, external server, application server, edge server, etc.).
[0107] According to an example embodiment, examples of sensing input include (e.g., sensing data requested by a service consumer) processed sensing data.
[0108] according to Figure 8 The variations in the process shown provide example details of the determination operations, which are intrinsically independent of each other. Such example determination operations according to the example embodiments may include: obfuscating the perception results based on privacy profile information related to the perception service, and / or performing a perception privacy check on the perception results based on the privacy profile information related to the perception service.
[0109] according to Figure 8 The variations in the process shown provide example additional operations that are intrinsically independent of each other. According to this variation, an example method based on an example embodiment may include: determining, based on the result of the obfuscation process and / or the result of the perceived privacy check, an operation to send the perceived result to a perceived consumer; or determining, based on the result of the obfuscation process and / or the result of the perceived privacy check, an operation to modify the features of the perceived result and send the modified perceived result to a perceived consumer.
[0110] According to another example embodiment, the perception configuration includes an obfuscated configuration. Alternatively, or additionally, according to another example embodiment, the perception result includes an obfuscated perception result.
[0111] The obfuscation configuration includes at least one of the following: Information about the characteristics of the object to be obfuscated. Information about obfuscation types, or Information regarding object feature removal.
[0112] according to Figure 8 The variations in the process shown provide example additional operations that are intrinsically independent of each other. Based on this variation, an example method according to an example embodiment may include the operation of sending the obfuscation configuration.
[0113] Figure 5This is a block diagram illustrating an apparatus according to an example embodiment. The apparatus may be a network node or entity 50 including a receiving circuitry 51 and an execution circuitry (or checking circuitry) 52, such as a perception management function entity, a perception data management entity, or an entity providing such functionality. The receiving circuitry 51 receives a perception service request. The execution circuitry (or checking circuitry) 52 performs a perception privacy check on the perception service request based on perception service-related privacy profile information indicating a profile type corresponding to the perception service-related privacy profile information. The perception service-related privacy profile information includes: an indication of whether perception of a profile-type-dependent perception target is permitted, the profile-type-dependent perception target being associated with the perception service-related privacy profile information. Figure 9 This is a schematic diagram of a process according to an example embodiment. According to Figure 5 The device can perform Figure 9 The method is applicable, but not limited to this method. Figure 9 The method can be derived from Figure 5 The device performs the operation, but is not limited to performing the operation by that device.
[0114] like Figure 9 As shown, the process according to the example embodiment includes: receiving a sensing service request (S91), and performing a sensing privacy check on the sensing service request based on sensing service-related privacy profile information indicating a profile type corresponding to the sensing service-related privacy profile information (S92). The sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information.
[0115] Figure 6 This is a block diagram illustrating an apparatus according to an example embodiment. Specifically, Figure 6 It shows Figure 5 The device shown is modified. Therefore, according to Figure 6 The apparatus may also include a request circuit system 61, a decision circuit system 62, a determination circuit system 63, a receiving circuit system 64, and / or a sending circuit system 65.
[0116] In an embodiment, Figure 5 At least some of the functions of the apparatus shown in (or 6) can be shared between two physically separate devices forming an operational entity. Therefore, the apparatus can be considered as an operational entity comprising one or more physically separate devices for performing at least some of the processes.
[0117] according to Figure 9 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. Based on this variation, an example method according to an example embodiment may include: the operation of requesting privacy profile information related to the perception service.
[0118] according to Figure 9 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. Based on this variation, an example method according to an example embodiment may include: determining, based on the result of the perceived privacy check, an operation to initiate a perceived process corresponding to the perceived service request.
[0119] according to Figure 9 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. Based on this variation, an example method according to an example embodiment may include: determining an operation for the perception configuration of the perception process based on privacy profile information related to the perception service.
[0120] according to Figure 9 The variations in the process shown provide example additional operations, which are intrinsically independent of each other. Based on such variations, an example method according to an example embodiment may include: operations for receiving a perception result regarding the perception process, and operations for determining a perception output based on the perception result.
[0121] According to example embodiments, examples of sensing results (or sensing measurement information, or sensing data) include data derived from radio signals (e.g., 3GPP, non-3GPP, WiFi, radar, lidar, etc.) that are affected by the object of interest or the environment for sensing purposes (e.g., reflection, refraction, diffraction) and optionally processed (e.g., within a 5G / 6G system, external server, application server, edge server, etc.).
[0122] According to an example embodiment, examples of perception outputs include (e.g., perception data requested by a service consumer) processed perception data.
[0123] according to Figure 8 The variations in the process shown provide example details of the determination operations, which are intrinsically independent of each other. Such example determination operations according to the example embodiments may include: obfuscating the perception results based on privacy profile information related to the perception service, and / or performing a perception privacy check on the perception results based on the privacy profile information related to the perception service.
[0124] according to Figure 9The variations in the process shown provide example additional operations that are intrinsically independent of each other. According to this variation, an example method based on an example embodiment may include: determining, based on the result of the obfuscation process and / or the result of the perceived privacy check, an operation to send the perceived result to a perceived consumer; or determining, based on the result of the obfuscation process and / or the result of the perceived privacy check, an operation to modify the features of the perceived result and send the modified perceived result to a perceived consumer.
[0125] According to another example embodiment, the perception configuration includes an obfuscated configuration. Alternatively, or additionally, according to another example embodiment, the perception result includes an obfuscated perception result.
[0126] The obfuscation configuration includes at least one of the following: Information about the characteristics of the object to be obfuscated. Information about obfuscation types, or Information regarding object feature removal.
[0127] according to Figure 9 The variations in the process shown provide example additional operations that are intrinsically independent of each other. Based on this variation, an example method according to an example embodiment may include the operation of sending the obfuscated configuration.
[0128] The example embodiments outlined and specified above are explained below in more specific terms.
[0129] Regarding the definition and management of the new privacy profile outlined above, in order to address the question of how AF and UE can define privacy profiles applicable to the awareness service, according to an example embodiment, the awareness privacy profile can be implemented as follows.
[0130] Specifically, according to the example embodiment, a new privacy profile is defined and can be set and stored in the core network (CN) (e.g., in a UDM for a UE-specific profile, or in a new NF for a non-UE-specific privacy profile) to allow or disallow awareness services. Three types of privacy profiles have been identified: a) Location-aware perceived privacy indications may include one or more of the following information elements: - Geographical region description, for example, using GPS coordinates, various locations, etc. - Perception is allowed (default). - Perception is not permitted. - The effective period for perceived privacy indicators - Object-aware privacy indication types are excluded. - Enable object obfuscation, - (Optional) Define a selected configuration for obfuscation / masking / blurring of the defined or all identified objects. - Perceive whether a timestamp or time period is allowed or not. - In terms of consumer type or defined IP, the perceived output is provided to the defined receiver. - Privacy awareness indicator setters, such as AF, UE, etc. b) UE-aware privacy indications may include one or more of the following information elements: - Perception is allowed (default). - Perception is not permitted. - Awareness can be enabled through specific configurations. - Obfuscation of the characteristics of the enabling object. - Indication that no identifier exists (e.g., SUPI). - Perceive geographical areas that are permitted or not. - Timestamp - Whether participation in perception is permitted or not (e.g., as a speaker, initiator, or transmitter of a perception signal). - This applies to situations where the UE initiates the sensing process by another UE or the network request. c) Object-aware privacy indications may include one or more of the following information elements: - Object type, - A descriptor for the object's category (e.g., person, vehicle) or characteristics of the object (e.g., size, mobility characteristics, etc.). - Identifier, - Perception is allowed (default). - Perception is not permitted. - Awareness can be enabled through specific configurations. - Obfuscation of the characteristics of the enabling object. - Indication that no identifier exists (e.g., SUPI). - The perceived output is provided to the defined receiver in terms of consumer type or defined identifier (e.g., IP address, credentials, etc.).
[0131] According to an example embodiment, a location-aware perception privacy indicator specifies whether subsequent perception requests are allowed or not allowed in a particular area.
[0132] Additionally, according to the example embodiment, the UE-aware privacy indicator specifies whether subsequent awareness requests are allowed or not allowed for a specific UE, and / or whether they are invoked during the awareness process.
[0133] Additionally, according to the example embodiment, the object-aware perception privacy indicator specifies whether subsequent perception requests are allowed or not allowed for a specific object, based on the corresponding descriptor.
[0134] The aforementioned configuration file and its included features / information consist of two aspects: - How to configure and / or execute the awareness process, and - How and whether to expose the output of perceived data.
[0135] According to the example embodiments, different network functions are used to store different parts of the perceived privacy profile. For example, UDM / UDR can be used for user-related privacy profile information (e.g., UE perceived privacy indication), and another dedicated repository or function (e.g., perceived data management function, SeMF) can be used for non-user-related privacy information (e.g., location-aware perceived privacy indication and object-aware perceived privacy indication).
[0136] According to another example embodiment, the UE-aware privacy indication is a portion of the LCS privacy profile stored in the UDM for the UE subscriber.
[0137] Regarding the definition and management of the new privacy profile outlined above, in order to address the question of how AF and UE can define privacy profiles applicable to the awareness service, according to the example embodiment, the setting / registration of the awareness privacy profile can be implemented as follows.
[0138] Specifically, according to the example embodiment, the perceived privacy profile can be as follows: Figure 10 As shown, it is set up by an external entity via AF (e.g., a regulator or building owner), or as... Figure 11 As shown, this is set by the UE. Both can set and modify any type and parameter of the perceived privacy profile defined above. It is reasonable to consider that the UE can set a UE perceived privacy indicator, while the AF can set a location-aware perceived privacy indicator and / or an object-aware perceived privacy indicator. However, the example embodiment is not limited to such an allocation.
[0139] Figure 10 A schematic diagram of a signaling sequence according to an example embodiment is shown, and in particular, signaling for a new process for aware privacy settings initiated by the AF is shown.
[0140] like Figure 10 As shown, AF requests awareness privacy profile information from 5GS via NEF (as described above).
[0141] According to the example embodiment, AF uses a new service or an enhanced existing service, such as Nnef_ParameterProvision_Create (step 1).
[0142] According to the example implementation, AF can request to update or delete the aware privacy profile using a new service or an enhanced existing service, for example, using Nnef_ParameterProvision_Update and Nnef_ParameterProvision_Delete respectively.
[0143] If the AF is provided with parameters by the NEF authorization, then the NEF is stored in the 5GC data repository. This data repository can be, for example, UDM / UDR or SeMF.
[0144] NEF may optionally determine whether to selectively store UE-specific privacy settings in UDM / UDR and store other settings (i.e., non-UE / general privacy settings) in SeMF or any storage database.
[0145] Therefore, according to the example embodiment, NEF requests UDM / UDR to create, update and store, or delete supplied parameters (e.g., via Nnef_ParameterProvision_Create, Nnef_ParameterProvision_Update request messages), which includes aware privacy profile information (steps 3a and 3b).
[0146] To support the discussion below Figure 14 In the architecture, NEF can forward only the information received from AF to GMLC, that is, before steps 3a and 3b.
[0147] If AF is not authorized to provide a privacy-aware profile, NEF indicates the reason for the failure in the privacy-aware profile setting response message (e.g., using the Nnef_ParameterProvision_Create / Update / Delete response message).
[0148] According to the example embodiment, the UDM and / or SeMF respond to the request by creating a privacy-aware parameter response, which indicates the successful or failed creation or update of its privacy-aware profile. If the process has failed, the reason value indicates the reason (steps 4a and 4b).
[0149] According to the example embodiment, NEF provides a response to AF, for example, via the Nnef_ParameterProvision_Create / Update / Delete response message (step 5).
[0150] Figure 11 A schematic diagram of a signaling sequence according to an example embodiment is shown, and in particular, signaling for a new procedure for UE-specific aware privacy settings initiated by the UE is shown.
[0151] like Figure 11 As shown in the example embodiment, the UE then sends the perceived privacy profile information (UE perceived privacy indication, location-aware perceived privacy indication, or object-aware perceived privacy indication as described above) to the AMF.
[0152] The UE can, for example, send an Aware Privacy Profile Setting Request in an N1 NAS message to the AMF via the UE (step 1).
[0153] According to an example embodiment, the AMF requests the UDM to create, update, and store supplied parameters (e.g., via Nudm_ParameterProvision_Create, Nudm_ParameterProvision_Update request messages), which include awareness privacy profile information (step 2).
[0154] According to the example embodiment, the UDM can also store or update the privacy profile in the UDR, for example, by calling the Nudr_DM_Update(SUPI, Subscription Data) service operation accordingly when the UE is aware of the privacy indication.
[0155] According to the example embodiment, the UDM responds to the AMF by creating a privacy-aware parameter response, which indicates the success or failure of its privacy-aware profile creation or update. If the process fails, the reason value indicates the cause (step 3).
[0156] According to the example embodiment, the AMF responds to the UE via the Aware Privacy Profile setting response in the N1 NAS message (step 4).
[0157] According to the example implementation, the UDM can use the UDR, for example, via Nudr_DM, to allow the UDR and / or other NF consumers to retrieve, create, update, subscribe to, unsubscribe from, and delete privacy-aware profiles stored in the UDR based on a dataset applicable to the consumer.
[0158] According to the example embodiment, the network function (NF) or management entity (e.g., OAM) can also use Figure 10 Signaling generation or updates related to privacy settings.
[0159] According to the example embodiment, after the successful completion of step 3 in the AF initiation process ( Figure 10 ) or after the successful completion of step 2 in the context of the UE-initiated process ( Figure 11 The UDM (or SeMF) can, for example, notify subscribed NFs (e.g., SeMF, GMLC, NEF) of updated awareness privacy profiles via a Nudm_SDM_Notification message. This information can be used in ongoing or future awareness processes and / or privacy checks.
[0160] In the above description, it is assumed that UDM and UDR are used to manage and store aware privacy profiles, respectively. However, according to the example embodiment, other network functions (existing or new) can be used to store and manage aware privacy profiles, particularly for non-UE-specific privacy profiles used for aware privacy settings initiated by the UE or AF (see [link to example embodiment]). Figure 10 In this case, the setup / registration of the aforementioned privacy-aware profile is performed together with other network functions (e.g., SeMF, awareness data management functions, etc.).
[0161] Regarding the definition of enhanced privacy outlined above, and the rules for addressing the new privacy checks required for perceived services, perceptual privacy checks can be implemented as follows, according to an example embodiment.
[0162] Figure 12 A schematic diagram of a signaling sequence according to an example embodiment is shown, and in particular, signaling is shown for a new process that ensures privacy concerns related to a sensing service request and the corresponding sensing service response.
[0163] According to the example embodiment, when a sensing client (e.g., UE, AF, BS, NF) sends a sensing request directly (NAS or SBA) or via NEF to the SeMF, a privacy check is performed at the SeMF. Figure 12 Signaling for an example procedure for a privacy check following the receipt of a sensing service request, according to an example embodiment, is shown.
[0164] Accordingly, SeMF performs authorization for the perceived customer, and based on the type and attributes of the perceived service request, SeMF can determine the corresponding privacy requirements and the privacy checks that should be performed (step 2).
[0165] According to the example embodiment, SeMF requests perceived privacy profile information from UDM (step 3), wherein the request includes descriptors of the required privacy information, such as identifiers of the UE involved (e.g., SUPI), the target perceived area, the target / requested object, etc.
[0166] According to the example embodiment, SeMF also requests a non-UE-specific privacy profile (information) from other storage devices or itself (depending on where the non-UE-specific privacy profile is stored) (step 3), wherein the request includes descriptors of the required privacy information, such as identifiers of the target awareness area involved, the target / requested object, etc.
[0167] According to the example embodiment, the UDM and / or other NF storing non-UE privacy profiles retrieve the appropriate profile and provide the privacy profile information to the SeMF (step 4): - (Multiple) target UE perception privacy profiles: In the case of perception requests for one or more UEs, for example, identified by their GPSI or SUPI, - Perception privacy profile for target perception area: In the case of perception requests for areas defined, such as those described by GPS coordinates or other location information. - Aware privacy profile for the target object: to obtain privacy settings for objects identified by, for example, object type, object category, object characteristics, etc.
[0168] According to the example embodiment, the UDM and / or other NF that store non-UE privacy profile settings can also indicate the need for obfuscated objects or specific types of objects, and provide information about obfuscation configurations, methods, etc.
[0169] Depending on the different options for sensing privacy profiles discussed above, some or all or specific sensing privacy profiles (e.g., sensing privacy profiles for target sensing areas, sensing privacy profiles for target objects) can be stored in SeMF or other dedicated functions (e.g., sensing data management).
[0170] According to the example embodiment, SeMF performs appropriate privacy checks based on the information in (all) received privacy profiles and sensing service requests (step 5). For example, if the sensing process is not permitted at the "sensing location" in the sensing service request according to the sensing privacy profile, the process can be stopped, and a notification of the reason for the failure can be provided to the sensing client. Furthermore, as another example, if the requested "sensing granularity / resolution" is not permitted according to the sensing privacy profile, an alternative "sensing resolution" can be provided if it is acceptable to the sensing client; otherwise, the sensing process stops, indicating the reason for the failure.
[0171] Subsequently, according to the example embodiment, SeMF determines an appropriate sensing configuration (step 6) based on the requirements included in the sensing service request and taking into account the limitations or parameters provided by the retrieved sensing privacy profile, which can be provided to the entities involved in the sensing process (e.g., base station (BS), UE, etc.).
[0172] According to the example embodiment, SeMF collaborates with the relevant BS and / or UE to request and collect sensing measurement information based on the selected sensing method. Based on the received input, SeMF determines the sensing output (step 7).
[0173] Optionally, in step 8, SeMF can obfuscate the objects already detected in step 7. SeMF can modify / blur / mask the detected objects to alter one or more of their features (e.g., shape, location, size, etc.) based on pre-configured information and / or privacy-aware profiles received by the UDM.
[0174] According to the example embodiment, SeMF can also apply additional privacy checks to the detected objects based on the privacy profile already retrieved by UDM / UDR (step 9).
[0175] Similar to step 5, the privacy check can provide one or more of the following aspects: detected UE(s), sensed data, detected objects, etc., and use information from the sensed privacy profile.
[0176] Finally, according to the example embodiment, SeMF provides a sensing service response to the sensing customer (e.g., via NEF to AF).
[0177] As another option, NEF or any existing network function can be used. Figure 12 Step 5, "Perceived Privacy Check," performs some or all of its functions. In this case, the NEF or an existing network function retrieves a perceived privacy profile from the UDM or another NF (e.g., SeMF). Additionally, the NEF may also perform a perceived output privacy check. Figure 12 Step 9).
[0178] Figure 13 A schematic diagram of a signaling sequence according to an example embodiment is shown, and in particular, a process of enabling and configuring obfuscation is shown before providing a sensing response to the requested sensing service.
[0179] In particular, as an alternative, confusion can occur on the RAN side or on both the RAN and CN network sides (e.g., SeMF).
[0180] In this case, such as Figure 13As shown in step 7, according to the example embodiment, after sensing privacy checks, determining sensing configuration, and determining the privacy information required for anonymization / obfuscation and / or privacy checks, SeMF provides an indication to enable obfuscation and provides obfuscation configuration to the RAN entities (e.g., BS) and / or UE involved in the sensing process, or SeMF itself can perform obfuscation.
[0181] According to an example embodiment, obfuscation information may be a portion of a dedicated message and / or other perception-related message sent using NAS and / or RRC and / or Application Protocol (NGAP) signaling.
[0182] According to the example embodiment, the obfuscation configuration can indicate the type of obfuscation that should be applied to the following: - Characteristics of the object that should be altered / blurred / obscured (e.g., the object's size, shape, and positional accuracy). - Obfuscated types applied by referencing specific methods from a list of methods, or by describing modifications to specific characteristics of an object to be applied (e.g., instead of providing the object's exact shape, representing it as geometry), and / or - Removes the characteristics of objects that can directly indicate the object's identity.
[0183] According to the example embodiment, such as Figure 13 As shown in step 9, the UE and / or RAN entity involved in the obfuscated configuration has received the received configuration during the sensing process and / or before providing its sensing output to other entities (e.g., SeMF).
[0184] Figure 14 A schematic diagram of a signaling sequence according to an example embodiment is shown. In particular, signaling is shown that employs enhancements to the existing LCS architecture to ensure privacy concerns related to the sensing service request and the corresponding sensing service response within the sensing service request.
[0185] Specifically, this example illustrates enhancements to existing interfaces of existing locations (e.g., as presented in TS23.273) to provide awareness services.
[0186] GMLC receives sensing requests from sensing clients (e.g., AF) and executes them. Figure 12 The entities in steps 2 to 5 include: - Determine the appropriate privacy requirements and the privacy checks that should be conducted. - Request and receive aware privacy profile information from the UDM; according to the example embodiment, the GMLC can invoke the Nudm_SDM_Get service operation to retrieve the appropriate privacy settings, and / or - Check the perception privacy profile in conjunction with the perception service request; for example, if one or more UEs or areas are allowed to be perceived, then according to the example embodiment, skip the following / subsequent steps and provide a notification to the perception customer.
[0187] Subsequently, according to the example embodiment, the GMLC provides perceived privacy parameters to the AMF and then to the LMF (or SeMF) for consideration in the perceived configuration and / or perceived process. The GMLC also involves additional privacy checks on the detected objects based on a privacy profile already retrieved by the UDM / UDR or the new NF (step 9).
[0188] The above processes and functions can be implemented by the corresponding functional elements, processing, etc., as described below.
[0189] In the above example description of network entities, only units relevant to understanding the principles of this disclosure have been described using functional blocks. A network entity may include additional units required for its corresponding operation. However, descriptions of these units are omitted in this specification. The arrangement of functional blocks in the device is not to be construed as limiting this disclosure, and the function may be performed by a single block or further divided into sub-blocks.
[0190] When a device, i.e., a network entity (or some other component), is described in the above description as being configured to perform certain functions, this will be interpreted as equivalent to the description of a processor or corresponding circuit system, possibly in cooperation with computer program code stored in the memory of the respective device, configured to cause the device to at least perform the functions described herein. Furthermore, such functions will be interpreted as being equivalent to being implemented by a specifically configured circuit system or a component for performing the corresponding function (i.e., the expression "a unit configured as..." is interpreted as equivalent to expressions such as "a component for...").
[0191] exist Figure 15 In this document, alternative descriptions of the apparatus according to example embodiments are depicted. For example... Figure 15As indicated in the example embodiment, device (network node or entity) 10' (corresponding to network node or entity 10) includes a processor 151, a memory 152, and an interface 153, which are connected via a bus 153, etc. Additionally, according to the example embodiment, device (network node or entity) 30' (corresponding to network node or entity 30) includes a processor 151, a memory 152, and an interface 153, which are connected via a bus 153, etc. Furthermore, according to the example embodiment, device (network node or entity) 50' (corresponding to network node or entity 50) includes a processor 151, a memory 152, and an interface 153, which are connected via a bus 153, etc. Devices 10', 30', and 50' can be connected to other devices (e.g., corresponding other devices of devices 10', 30', and 50') via link 155.
[0192] Processor 151 and / or interface 153 may also include modems, etc., to facilitate communication over a (hardwired or wireless) link. Interface 153 may include suitable transceivers coupled to one or more antennas or communication components for (hardwired or wireless) communication with the linked or connected device. Interface 153 is typically configured to communicate with at least one other device (i.e., its interface).
[0193] The memory 152 may store a corresponding program assumed to include program instructions or computer program code, which, when executed by the corresponding processor, enables the corresponding electronic device or apparatus to operate according to the example embodiment.
[0194] Generally, the corresponding device / apparatus (and / or part thereof) may refer to a component for performing the corresponding operation and / or demonstrating the corresponding function, and / or the corresponding device (and / or part thereof) may have the function for performing the corresponding operation and / or demonstrating the corresponding function.
[0195] When a device (or some other component) is described in the foregoing as being configured to perform certain functions, this is to be interpreted as equivalent to stating that at least one processor, possibly in cooperation with computer program code stored in the memory of the respective device, is configured to cause the device to perform at least the functions described herein. Furthermore, such functions are to be interpreted as equivalent to those implemented by components specifically configured to perform the corresponding functions (i.e., the statement "a processor configured [to cause the device] to perform xxx-ing" is interpreted as equivalent to statements such as "components for xxx-ing").
[0196] According to an example embodiment, the apparatus representing a network node or entity 10 includes at least one processor 151, at least one memory 152 including computer program code, and at least one interface 153 configured to communicate with at least another apparatus. The processor (i.e., at least one processor 151 together with at least one memory 152 and the computer program code) is configured to perform: generating awareness service-related privacy profile information indicating: a profile type corresponding to the awareness service-related privacy profile information (therefore the apparatus includes a corresponding component for generation); and performing: sending the awareness service-related privacy profile information, wherein the awareness service-related privacy profile information includes: an indication of whether awareness of a profile-type-dependent awareness target is permitted, the profile-type-dependent awareness target being associated with the awareness service-related privacy profile information (therefore the apparatus includes a corresponding component for sending).
[0197] According to an example embodiment, the apparatus representing a network node or entity 30 includes at least one processor 151, at least one memory 152 including computer program code, and at least one interface 153 configured to communicate with at least another apparatus. The processor (i.e., at least one processor 151 together with at least one memory 152 and computer program code) is configured to perform: receiving sensing service-related privacy profile information indicating: a profile type of the sensing service-related privacy profile corresponding to the sensing service-related privacy profile information (therefore the apparatus includes a corresponding component for receiving); and performing: storing the sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information (therefore the apparatus includes a corresponding component for storage).
[0198] According to an example embodiment, the apparatus representing a network node or entity 50 includes at least one processor 151, at least one memory 152 including computer program code, and at least one interface 153 configured to communicate with at least another apparatus. The processor (i.e., at least one processor 151 together with at least one memory 152 and computer program code) is configured to perform: receiving a sensing service request (therefore the apparatus includes corresponding components for receiving), and performing: performing a sensing privacy check on the sensing service request based on sensing service-related privacy profile information indicating a profile type corresponding to sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a profile-type-dependent sensing target is permitted, the profile-type-dependent sensing target being associated with the sensing service-related privacy profile information (therefore the apparatus includes corresponding components for performing this check).
[0199] For further details regarding the operability / functionality of individual devices, please refer to the above combination. Figures 1 to 14 Description of any one of them.
[0200] For the purposes of this disclosure as described above, attention should be paid to - The method steps, which may be implemented as software code and run using a processor at a network server or network entity (as an example of a device, apparatus and / or its modules, or as an example of an entity including an apparatus and / or its modules), are independent of the software code and can be specified using any known or future-developed programming language, as long as the functionality defined by the method steps is maintained. - Generally, any method steps are suitable to be implemented in software or hardware without changing the idea of the embodiment or its modifications in terms of the functionality implemented. - The method steps and / or devices, units, or components that may be implemented as hardware components at the apparatus defined above, or any of their modules (e.g., devices performing the functions of the apparatus according to the above embodiments) are hardware-independent and can be implemented using any known or future-developed hardware technology or any combination of the following technologies: such as MOS (Metal-Oxide-Semiconductor), CMOS (Complementary MOS), BiMOS (Bipolar MOS), BiCMOS (Bipolar CMOS), ECL (Emitter-Coupled Logic), TTL (Transistor-Transistor Logic), etc., or for example using: ASIC (Application-Specific Integrated Circuit) components, FPGA (Field-Programmable Gate Array) components, CPLD (Complex Programmable Logic Device) components, or DSP (Digital Signal Processor) components. - A device, unit, or component (e.g., a network entity or network register as defined above, or any of its corresponding units / components) may be implemented as a single device, unit, or component, but this does not preclude it from being implemented in a distributed manner throughout the system, as long as the functionality of the device, unit, or component is maintained. - Devices similar to user equipment and network entities / network registers can be represented by semiconductor chips, chipsets, or (hardware) modules including such chips or chipsets; however, this does not preclude the possibility that the functionality of the device or module is implemented as software rather than hardware in (software) modules (such as computer programs or computer program products including executable software code for execution / running on a processor); - For example, a device can be considered as an apparatus or a component of multiple apparatuses, whether they are functionally cooperative or functionally independent of each other, but they are all housed in the same apparatus housing.
[0201] Generally, it should be noted that the corresponding functional blocks or elements according to the foregoing aspects can be implemented in hardware and / or software by any known components, if they are only suitable for performing the functions described in the corresponding sections. The mentioned method steps can be implemented in a single functional block or by a single device, or one or more method steps can be implemented in a single functional block or by a single device.
[0202] Generally, without altering the spirit of this disclosure, any method steps are suitable for implementation as software or by hardware. Devices and components may be implemented as single devices, but this does not preclude their implementation in a distributed manner throughout the system, as long as the functionality of the devices is maintained. Such and similar principles are considered to be known to those skilled in the art.
[0203] In the sense of this specification, software includes software code, which includes code components or portions for performing corresponding functions, or computer programs or computer program products, and software (or computer programs or computer program products) implemented on tangible media (such as computer-readable (storage) media having corresponding data structures or code components / individually stored thereon) or implemented in signals or in chips, may be used during their processing.
[0204] This disclosure also covers any conceivable combination of the above-described method steps and operations, as well as any conceivable combination of the above-described nodes, devices, modules or elements, provided that the concepts of the above-described method and structural arrangements apply.
[0205] In view of the foregoing, a method for sensing service privacy is provided. In one embodiment, the method includes: generating sensing service-related privacy profile information indicating: a profile type of the sensing service-related privacy profile corresponding to the sensing service-related privacy profile information; and sending the sensing service-related privacy profile information, wherein the sensing service-related privacy profile information includes: an indication of whether sensing of a sensing target dependent on the profile type is permitted, the sensing target dependent on the profile type being associated with the sensing service-related privacy profile information.
[0206] Although the present disclosure has been described above with reference to examples in the accompanying drawings, it should be understood that the present disclosure is not limited thereto. Rather, it will be apparent to those skilled in the art that various modifications can be made to the present disclosure without departing from the scope of the inventive spirit disclosed herein. List of abbreviations 3GPP Third Generation Partnership Project AF application functions AGV (Automated Guided Vehicle) AMF Access and Mobility Management Functions AMR (Autonomous Mobile Robot) BS base station DL downlink GMLC Gateway Mobile Location Center GPS Global Positioning System GPSI General Public Subscription Identifier ISAC Communication and Sensing Integration LCS Location Services LMF location management function NAS Non-Access Layer NEF Network Open Functions OAM Operation, Management and Maintenance NF Network Functions NLOS (Non-line-of-sight) PCF policy control function PLMN Public Land Mobile Network QoS (Quality of Service) SeMF Sensing Management Function SNPN (Standard Non-Public Network) V2X Connectivity of Everything U2N End-to-Network UAV (Unmanned Aerial Vehicle) UDM Unified Data Management UDR Unified Data Repository URI (Uniform Resource Identifier) SUPI subscription permanent identifier UE User Equipment UL uplink VR Virtual Reality XR Extended Reality
Claims
1. A method comprising: Generate privacy profile information related to the perception service, wherein the privacy profile information related to the perception service indicates the profile type of the privacy profile related to the perception service, and Send the privacy configuration file information related to the perception service, wherein The privacy profile information related to the perception service includes: an indication of whether perception of a perception target dependent on the profile type is permitted, wherein the perception target dependent on the profile type is associated with the privacy profile information related to the perception service.
2. The method according to claim 1, wherein The configuration file type is at least one of the following: Location-awareness is related to perceived privacy. Terminal-sensory privacy related, or Object-aware perception related to privacy.
3. The method according to claim 2, wherein The configuration file type is location-aware and privacy-related, and The privacy profile information related to the perception service includes at least one of the following: Information about the geographic region corresponding to the perceived target that depends on the configuration file type. Information regarding perceptually allowed configurations. Information regarding the validity period of the privacy configuration file information related to the aforementioned perception service. Information regarding exceptions to the privacy profile information related to the aforementioned perception service. Information about object obfuscation Information regarding the validity period of the indicated instruction. Information about the receiver that outputs privacy profile information related to the perception service during the perception process, or Information about the settings entity for privacy profile information related to the perception service.
4. The method of claim 2, wherein The configuration file type is related to terminal-aware privacy, and The privacy profile information related to the perception service includes at least one of the following: Information regarding perceptually allowed configurations. Regarding the geographical region, the instructions are valid for that region. Information regarding time or time period, and the indication being valid for said time or time period. Information about the perception service role that depends on the perception target of the configuration file type.
5. The method according to claim 2, wherein The configuration file type is object-aware privacy-related, and The privacy profile information related to the perception service includes at least one of the following: Information about the object type of the perception target that depends on the configuration file type. Information about perception-permissive configurations, or Information about the receiver that outputs privacy profile information related to the perception service during the perception process.
6. The method according to any one of claims 3 to 5, wherein The perception-permissive configuration defines at least one of the following: Obfuscation of object characteristics is enabled, or No object or terminal identifier was indicated.
7. The method according to any one of claims 1 to 6, wherein Regarding the sending, the method further includes: Send the privacy profile information related to the perception service together with the perception service privacy profile setting request, perception service privacy profile creation request, or perception service privacy profile update request.
8. The method according to any one of claims 1 to 7, further comprising: Send a request to delete the privacy profile of the perception service related to the perception service.
9. A method comprising: Receive privacy profile information related to the perception service, wherein the privacy profile information related to the perception service indicates the profile type of the privacy profile related to the perception service, and Store the privacy configuration file information related to the perception service, wherein The privacy profile information related to the perception service includes: an indication of whether perception of a perception target dependent on the profile type is permitted, wherein the perception target dependent on the profile type is associated with the privacy profile information related to the perception service.
10. The method of claim 9, further comprising: At least one network entity is identified to store the privacy profile information received in relation to the perceived service.
11. The method of claim 10, wherein the storage device comprises at least one of the following: a unified data warehouse (UDR), or a unified data management (UDM), or a sensed management function (SeMF), or any storage database.
12. The method according to any one of claims 9 to 11, wherein The configuration file type is at least one of the following: Location-awareness is related to perceived privacy. Terminal-sensory privacy related, or Object-aware perception related to privacy.
13. The method of claim 12, wherein... The configuration file type is location-aware and privacy-related, and The privacy profile information related to the perception service includes at least one of the following: Information about the geographic region corresponding to the perceived target that depends on the configuration file type. Information regarding perceptually allowed configurations. Information regarding the validity period of the privacy configuration file information related to the aforementioned perception service. Information regarding exceptions to the privacy profile information related to the aforementioned perception service. Information about object obfuscation Information regarding the validity period of the indicated instruction. Information about the receiver that outputs privacy profile information related to the perception service during the perception process, or Information about the settings entity for privacy profile information related to the perception service.
14. The method of claim 12, wherein... The configuration file type is related to terminal-aware privacy, and The privacy profile information related to the perception service includes at least one of the following: Information regarding perceptually allowed configurations. Regarding the geographical region, the instructions are valid for that region. Information regarding time or time period, and the indication being valid for said time or time period. Information about the perception service role that depends on the perception target of the configuration file type.
15. The method of claim 12, wherein... The configuration file type is object-aware privacy-related, and The privacy profile information related to the perception service includes at least one of the following: Information about the object type of the perception target that depends on the configuration file type. Information about perception-permissive configurations, or Information about the receiver that outputs privacy profile information related to the perception service during the perception process.
16. The method according to any one of claims 13 to 15, wherein The perception-permissive configuration defines at least one of the following: Obfuscation of object characteristics is enabled, or No object or terminal identifier was indicated.
17. The method according to any one of claims 9 to 16, wherein The privacy profile information related to the sensing service is received together with the sensing service privacy profile setting request, or the sensing service privacy profile creation request, or the sensing service privacy profile update request.
18. The method according to any one of claims 9 to 17, further comprising: Receive requests to delete privacy profiles related to the awareness service, and Delete the privacy configuration file information related to the perception service that corresponds to the privacy configuration file related to the perception service.
19. The method according to any one of claims 9 to 18, further comprising: Send subscription notifications to at least one subscriber entity indicating changes to the privacy profile related to the awareness service.
20. The method according to any one of claims 9 to 19, further comprising: Receive perception service requests, and Based on the privacy profile information related to the perception service, a perception privacy check is performed on the perception service request.
21. The method according to any one of claims 9 to 20, further comprising: Request privacy profile information related to the perception service.
22. The method according to claim 20 or 21, further comprising: Based on the results of the privacy check, a perception process corresponding to the perception service request is initiated.
23. The method of claim 22, further comprising: Based on the privacy configuration file information related to the perception service, the perception configuration used for the perception process is determined.
24. The method according to claim 22 or 23, further comprising: Receive the perception results regarding the perception process, and The perception output is determined based on the perception results.
25. The method of claim 24, wherein Regarding the determination, the method further includes: Based on the privacy profile information related to the perception service, the perception results are obfuscated, and / or Based on the privacy configuration file information related to the perception service, a perception privacy check is performed on the perception results.
26. The method of claim 25, further comprising: Based on the result of the obfuscation process and / or the result of the perceived privacy check, a decision is made to send the perceived result to the perceived consumer, or Based on the results of the obfuscation process and / or the results of the perceived privacy check, a decision is made to modify the features of the perceived result and send the modified perceived result to the perceived consumer.
27. The method of claim 24, wherein... The perception configuration includes obfuscation configuration, and / or The perception results include confused perception results.
28. The method of claim 27, wherein The obfuscation configuration includes at least one of the following: Information about the characteristics of the object to be obfuscated. Information about obfuscation types, or Information regarding object feature removal.
29. The method according to claim 27 or 28, further comprising: Send the obfuscation configuration.
30. A method comprising: Receive perception service requests, and Based on the perception service-related privacy profile information, which indicates the profile type of the perception service-related privacy profile information corresponding to the perception service-related privacy profile information, a perception privacy check is performed on the perception service request, wherein... The privacy profile information related to the perception service includes: an indication of whether perception of a perception target dependent on the profile type is permitted, wherein the perception target dependent on the profile type is associated with the privacy profile information related to the perception service.
31. The method of claim 30, further comprising: Request privacy profile information related to the perception service.
32. The method according to claim 30 or 31, further comprising: Based on the results of the privacy check, a perception process corresponding to the perception service request is initiated.
33. The method of claim 32, further comprising: Based on the privacy configuration file information related to the perception service, the perception configuration used for the perception process is determined.
34. The method according to claim 32 or 33, further comprising: Receive the perception results regarding the perception process, and The perception output is determined based on the perception results.
35. The method of claim 34, wherein Regarding the determination, the method further includes: Based on the privacy profile information related to the perception service, the perception results are obfuscated, and / or Based on the privacy configuration file information related to the perception service, a perception privacy check is performed on the perception results.
36. The method of claim 35, further comprising: Based on the result of the obfuscation process and / or the result of the perceived privacy check, a decision is made to send the perceived result to the perceived consumer, or Based on the results of the obfuscation process and / or the results of the perceived privacy check, a decision is made to modify the features of the perceived result and send the modified perceived result to the perceived consumer.
37. The method of claim 34, wherein... The perception configuration includes obfuscation configuration, and / or The perception results include confused perception results.
38. The method of claim 37, wherein The obfuscation configuration includes at least one of the following: Information about the characteristics of the object to be obfuscated. Information about obfuscation types, or Information regarding object feature removal.
39. The method according to claim 37 or 38, further comprising: Send the obfuscation configuration.
40. An apparatus comprising components for performing the method according to any one of claims 1 to 39.
41. A computer program comprising instructions that, when executed by a device, cause the device to perform the method according to any one of claims 1 to 39.