Resource authorization during federated learning process in 5G core

By introducing a resource authorization mechanism in the 5G core network, resources are allocated rationally based on information such as analysis identifiers and supplier identifiers, which solves the problem of uneven resource consumption in federated learning and improves the training efficiency and data security of machine learning models.

CN121220004APending Publication Date: 2025-12-26NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480032901.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-05-15
Filing Date
2024-05-14
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

In existing 5G core networks, the lack of an effective resource authorization mechanism in the federated learning process leads to uneven resource consumption and unreasonable priority settings, affecting the training efficiency and security of machine learning models.

Method used

A resource authorization mechanism is introduced, which uses information such as analysis identifiers, interoperability identifiers, and supplier identifiers through authorization servers and client devices to clarify resource utilization and time limits, thereby ensuring the rational allocation and management of resource consumption.

Benefits of technology

It enables resource authorization and restriction for the federated learning process, prevents overload, ensures efficient training of machine learning models and data privacy and security, and improves the efficiency and security of network analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121220004A_ABST
    Figure CN121220004A_ABST
Patent Text Reader

Abstract

An authorization server apparatus configured to implement a resource authorization mechanism for a federated learning (FL) training process, comprising: at least one processor; and the at least one memory stores instructions that, when executed by the at least one processor, cause the apparatus to at least: receive FL registration information including FL utilization information from the first network device; receiving, from a second network device, an access token request for a first network device including request utilization information, the first network device being a potential FL client; determining whether the second network device is authorized for the first network device based on the FL utilization information and the request utilization information; and when the access token request for the first network device is authorized, sending the access token for the first network device to the second network device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Technical field of the disclosure Various exemplary embodiments disclosed herein relate to resource authorization during a federated learning procedure in a 5G core. BACKGROUND

[0002] Federated learning (FL) can be used among network data analytics functions (NWDAFs) in a 5G network. Federated learning is a machine learning technique that trains an algorithm across multiple decentralized edge devices or servers that hold local data samples without exchanging the local data. This approach contrasts with traditional centralized machine learning techniques, where all local data sets are uploaded to one server, and more classic decentralized approaches that typically assume local data samples are identically distributed. Federated learning enables multiple participants to build a common, robust machine learning model without sharing data, allowing for solving key problems such as data privacy, data security, data access rights, and access to heterogeneous data. SUMMARY

[0003] Summaries of various exemplary embodiments are given below.

[0004] Various embodiments relate to an authorization server apparatus configured to implement a resource authorization mechanism for a federated learning (FL) training procedure, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from a first network device, FL registration information comprising FL utilization information; receive, from a second network device, an access token request for the first network device comprising request utilization information, the first network device being a potential FL client; determine, based on the FL utilization information and the request utilization information, whether the second network device is authorized for the first network device; and send, to the second network device, an access token for the first network device when the access token request for the first network device is authorized.

[0005] Various embodiments are described in which the utilization information comprises maximum resource utilization information.

[0006] Various embodiments are described in which the maximum resource utilization information comprises processor throughput, memory, and storage space.

[0007] Various embodiments are described in which the utilization information comprises maximum resource utilization information based on at least one of: an analytics identity (ID), an interoperability ID, a vendor ID of the second network device, regulatory constraints, a number of FL servers that have been served, and a network function instance ID of the second network device.

[0008] Various embodiments are described in which the utilization information includes at least one of: a geographic region of the second network device, a maximum number of second network device instances from a same vendor allowed to use the FL client, a maximum number of FL client instances from a same vendor used by one or more second network devices from the same vendor, and a geographic region limit per analytics ID.

[0009] Various embodiments are described in which the utilization information includes maximum FL process execution time information.

[0010] Various embodiments are described in which the utilization information includes maximum FL process execution time information based on at least one of: an analytics identification (ID), an interoperability ID, a vendor ID of the second network device, a regulatory constraint, a number of FL servers that have been served, and a network function instance ID of the second network device.

[0011] Various embodiments are described in which the access token request includes at least one of a FL process execution time, a maximum resource consumption, and a geographic region required per analytics ID of the second network device.

[0012] Various embodiments are described in which the access token includes at least one of a total FL process execution time and a geographic region of the second network device.

[0013] Various embodiments are described in which the authorization server is a network repository function (NRF) and the first network device and the second network device are a network data analytics function (NWDAF).

[0014] Further various embodiments relate to a FL client apparatus configured to implement a resource authorization mechanism for a federated learning (FL) training process, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: send, to an authorization server, FL registration information including utilization information; receive, from a second network device, a FL service request, the FL service request including an analytics ID, FL model parameters, and an access token including the utilization information; verify the access token; and send a success response, the success response indicating that the FL client is to use its analytics data to train and update a FL machine learning model.

[0015] Various embodiments are described in which the at least one memory stores instructions that, when executed by the at least one processor, cause the apparatus to: train the FL machine learning model using analytics data associated with the analytics ID to update FL machine learning model parameters; and send the updated FL machine learning model parameters to the second network device.

[0016] Various embodiments are described in which the utilization information includes maximum resource utilization information.

[0017] Various embodiments are described in which the utilization information includes maximum resource utilization information.

[0018] Various embodiments are described in which the utilization information includes maximum resource utilization information based on at least one of: an analytics identification (ID), an interoperability ID, a vendor ID of the second network device, regulatory constraints, a number of FL servers that have been served, and a network function instance ID of the second network device.

[0019] Various embodiments are described in which the utilization information includes at least one of: a geographic region of the second network device, a maximum number of second network device instances from a same vendor that are allowed to use a FL client from the same vendor, a maximum number of FL client instances from a same vendor used by one or more second network devices from the same vendor, and a geographic region limit per analytics ID.

[0020] Various embodiments are described in which the utilization information includes maximum FL process execution information.

[0021] Various embodiments are described in which the utilization information includes maximum FL process execution time information based on at least one of: an analytics identification (ID), an interoperability ID, a vendor ID of the second network device, regulatory constraints, a number of FL servers that have been served, and a network function instance ID of the second network device.

[0022] Various embodiments are described in which the FL client is a network data analytics function (NWDAF).

[0023] Further various embodiments relate to a FL server apparatus configured to implement an authorization mechanism for a federated learning (FL) training process, comprising: at least one processor; at least one data storage apparatus; and at least one memory having stored therein instructions that, when executed by the at least one processor, cause the apparatus at least to: send a discovery request to an authorization server; receive information about potential FL clients from the authorization server; send an access token request to the authorization server for a potential FL client including a request for utilization information; receive an access token for the FL client from the authorization server when the access token request for the FL client is authorized; and send a FL service request access token including the utilization information to the FL client.

[0024] Various embodiments are described in which the utilization information includes maximum resource utilization information.

[0025] Various embodiments are described in which the maximum resource utilization information includes processor throughput, memory, and storage space.

[0026] Various embodiments are described in which the utilization information includes maximum resource utilization information based on at least one of: an analytics identification (ID), an interoperability ID, a vendor ID of the FL server, regulatory constraints, a number of FL servers that have been served, and a network function instance ID of the FL server.

[0027] Various embodiments are described in which the utilization information includes at least one of: a geographic region of the FL server, a maximum number of FL server instances from a same vendor that are allowed to use the FL client, a maximum number of FL client instances from a same vendor used by one or more FL servers from the same vendor, and a geographic region limit per analytics ID.

[0028] Various embodiments are described in which the utilization information includes maximum FL procedure execution time information.

[0029] Various embodiments are described in which the utilization information includes maximum FL procedure execution time information based on at least one of: an analytics identification (ID), an interoperability ID, a vendor ID of the FL server, regulatory constraints, a number of FL servers that have been served, and a network function instance ID of the FL server.

[0030] Various embodiments are described in which the FL server is a network data analytics function (NWDAF).

[0031] The foregoing has outlined rather broadly the features and technical advantages of examples according to the disclosure in order that the detailed description that follows can be better understood. Additional features and advantages will be described hereinafter. The disclosed concepts and specific examples can be readily utilized as bases upon which the other structures can be built employing the principles of this disclosure. Such equivalent constructions do not depart from the scope of the appended claims. The features, their organization, and method of operation, as well as the associated advantages, of the concepts disclosed herein will become more fully apparent from the following description when considered in connection with the accompanying drawings. Each figure is provided by way of explanation and is not meant as a limitation on the scope of the claims. BRIEF DESCRIPTION OF DRAWINGS

[0032] In order that the above-recited features and advantages of the present disclosure can be understood in detail, a more particular description will be rendered by reference to various aspects, some of which are illustrated in the appended drawings. It is appreciated that the drawings are not limiting on the scope of this disclosure, as described herein, and are merely provided as illustrative forms from which the scope of the relevant claims will become apparent. Like reference numerals can be used to identify like elements throughout the several views.

[0033] Figure 1 A portion of a 5G core network that provides network data analytics services is shown.

[0034] Figure 2 An implementation of a resource authorization mechanism in a 5G core is shown.

[0035] Figure 3 An exemplary hardware schematic for implementing the authorization mechanism is shown. DETAILED DESCRIPTION

[0036] Various aspects of the disclosure are described more fully below with reference to the accompanying drawings. This disclosure may, however, be embodied in many different forms and should not be construed as limited to any specific structure or function presented throughout this disclosure. Rather, these aspects are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art. Based on the teachings herein one skilled in the art should appreciate that the scope of the disclosure is intended to cover any aspect of the disclosure disclosed herein, whether implemented independently of, or combined with, any other aspect of the disclosure. For example, an apparatus can be implemented or a method can be practiced using any number of the aspects set forth herein. In addition, the scope of the disclosure is intended to cover such an apparatus or method which is practiced using, in addition to or in place of the aspects set forth herein, other structures, functionalities or structures and functions disclosed herein. It will be understood that any of the aspects of the disclosure disclosed herein can be embodied by one or more elements of a claim.

[0037] Several aspects of federated learning in 5G systems will now be presented with reference to various apparatus and techniques. These apparatus and techniques will be described in the following detailed description and illustrated in the accompanying drawings by various blocks, modules, components, circuits, steps, processes, algorithms, etc. (collectively referred to as “elements”). These elements can be implemented using hardware, software, or combinations thereof. Whether such elements are implemented as hardware or software depends on the particular application and design constraints imposed on the overall system.

[0038] It should be noted that while aspects can be described herein using terminology commonly associated with 5G mobile network technologies, aspects of the present disclosure can be applied to other past, current, and future public land mobile networks, such as 6G and later.

[0039] Federated learning (FL) can be used between network data analytics functions (NWDAFs) in a 5G network to develop machine learning (ML) models trained using various data analytics from the NWDAFs. FL uses FL servers that collect and consume data from FL clients. The FL servers are able to develop machine learning models based on data analytics from various NWDAIs. Applying FL to data analytics in the 5G core results in better machine learning models. It also allows the analytics data at various NWDAIs to remain private and secure. To implement FL in the 5G core, various mechanisms have been defined to enable authorization of NWDAIs as various mechanisms for FL servers and FL clients to operate. The authorization framework for the 5G core using OAuth 2.0 is currently defined in TS 33.501 clause 13. Tdoc S2-2306099 (https: / / www.3gpp.org / ftp / tsg_sa / WG2_Arch / TSGS2_156E_Electronic_2023-04 / Docs / S2-2306099.zip) defines procedures and services for ML model training that are part of and enable federated learning procedures in the 5G core. The problem that currently exists with FL authorization is that client NWDAF (model training logic function (MTLF)) resources can be exhausted because they are included in many federated learning groups. The currently proposed solution does not address this threat. Currently, FL servers can send requests to FL client(s) and consume their resources on a first-come, first-served basis. There is currently no defined mechanism to define resource authorization and limits for a given FL server when sending FL processing requests to relevant FL clients. Embodiments will be described herein that define resource authorization and limits for a given FL server when sending FL processing requests to relevant FL clients. In addition, these embodiments describe authorization schemes that govern how FL servers from one vendor use computing resources from FL clients from another vendor.

[0040] To this end, embodiments described herein implement an authorization mechanism in which FL clients can explicitly indicate resource utilization (e.g., in terms of central processing unit (CPU), graphics processing unit (GPU), memory consumption, maximum allowed usage time, maximum number of NF instances, number of epochs required, FL round, etc.) for a given FL server and analytics identifier (ID).

[0041] As mentioned above, there can be situations where multiple FL servers are requesting FL procedures on a FL client, and therefore only the FL servers that are authorized to consume the resources of the FL procedure should be allowed and served. Moreover, there can be situations where some analytics ID(s) have higher priority compared to other analytics IDs, and therefore there is no mechanism to set the priority when FL procedure requests are received for various different analytics ID(s).

[0042] Figure 1 A portion of a 5G core network that provides network data analytics services is shown. The 5G network is implemented using a service-based architecture (SBA), in which various software services can be implemented in a cloud computing environment. The SBA provides a modular framework in which components of different origins and vendors can be used to deploy common applications. The 3GPP defines the SBA whereby the control plane functions and common data repositories of the 5G network are delivered by a set of interconnected network functions (NFs), each with authorization to access services of one another. The NFs assume the role of either a service consumer or a service producer, are self-contained, independent, and reusable. Each NF service exposes its functionality through a service-based interface (SBI).

[0043] In Figure 1 , the network is divided into a visited public land mobile network (VPLMN) and a home public land mobile network (HPLMN). The VPLMN includes an application function (AF) 102, a visited security edge protection proxy (vSEPP) 110, and other NFs 114. The AF 102 can act as a FL server, as will be further described below. The security edge protection proxy (SEPP) enables secure interconnection between 5G networks. The SEPP ensures end-to-end confidentiality and / or integrity between source and destination networks for all 5G interconnect roaming messages. The VPLMN can include other NFs 114 that perform various functions.

[0044] The HPLMN includes a network repository function (NRF) 104, a NWADF 106, a unified data management (UDM) 108, a home SEPP (hSEPP) 112, and other NFs 116. The SBA employs a centralized discovery framework that utilizes the NRF 104. The NRF 104 is an authorized server that maintains a record of available NF instances and their supported services. It allows other NF instances to subscribe and be notified of registrations from NF instances of a given type. The NRF 104 supports service discovery by receiving discovery requests from NF instances and receiving details of which NF instances support a particular service.

[0045] The NWDAF 106 is a network function that collects data from 5G core network functions, performs network analytics, and provides insights with closed loop automation to authorized data consumers. These include external users leveraging open Application Programming Interfaces (APIs) to help generate greater insights into network performance. The NWDAF makes analytics available where varying latency requirements need to be met to satisfy 5G use cases. This approach of collecting, analyzing, and exposing data allows service providers to more effectively manage, automate, and optimize their 5G network operations. The NWDAF architecture is a cloud-native, multi-vendor, and probeless solution that makes it easy to collect and analyze data from networks and services. The data collected and provided by the NWDAI 106 can be used to train machine learning models using FL to model various aspects of the 5G network.

[0046] The UDM 108 is a converged repository for serving multiple NFs' subscriber information. The HPLMN can include other NFs 116 that perform various functions. The hSEPP 112 is a home SEPP. In Figure 1 In the figure, the dashed lines illustrate various steps of an embodiment of an authorization mechanism that will be further described below.

[0047] Figure 2 An implementation of a resource authorization mechanism in a 5G core is illustrated. The 5G core can include a NWDAF FL server 202, a NRF 204 (which can be an authorization server), and a NWDAF MTLF FL client 206. The NWDAF FL server 202 develops machine learning models to model network analytics. The machine learning models at the NWDAF FL server 202 are trained at the NWDAF MTLF FL client 206 using analytics data available at the NWDAF MTLF FL client 206.

[0048] The various steps performed by the NWDAF FL server 202, the NRF 204, and the NWDAF MTLF FL client 206 implementing the resource authorization mechanism 200 will be described.

[0049] The resource authorization mechanism 200 begins with the NWDAF MTLF FL client 206 registering its network function (NF) profile 208 that includes registration information. The registration information can include utilization information, such as maximum resource utilization (e.g., CPU, memory, and disk storage) to run FL process requests. These external resource utilization values can be specified per analytics ID, interoperability ID, FL server’s vendor ID, FL server’s NF instance ID, regulatory constraints, number of FL servers already served, etc. That is, the maximum resource utilization limits can be placed per these different parameters. The analytics ID can identify a particular analytics of interest or a set of analytics. The interoperability ID can indicate that interoperability is generally allowed, or can be a list of vendors for which interoperability is allowed. The FL server’s vendor ID identifies the vendor of a particular FL server, and can also include model and version information. Since the NWDAF FL server 202 can execute different network functions, each of these different defined network functions can have a NF instance ID. The regulatory constraints can mean that, for example, FL clients in one jurisdiction cannot interact with FL servers in a second particular jurisdiction.

[0050] The registration information can also include execution time information, which includes a maximum time to run a FL process request or an availability time needed to run a FL process. Note that a FL process can include several rounds of client / server interaction. Accordingly, the maximum and / or availability time to run a FL process request can be for each particular interaction or for an aggregate of the first interactions until a process termination occurs. These maximum and / or availability times to run a FL process request can be specified per analytics ID, interoperability ID, FL server’s vendor ID, FL server’s NF instance ID, regulatory constraints, number of FL servers already served, etc.

[0051] The NWDAF MTLF FL client 206 can also specify a total maximum time to run all FL processes and a maximum resource utilization for all FL processes per FL server’s analytics ID, vendor ID, NF instance ID, etc.

[0052] The utilization information can also include a geographical area of the NWDAF FL server 202. That is, the geographical area served by the NWDAF FL server 202. In addition, the utilization information can also include a maximum number of FL server instances from the same vendor that are allowed to use the FL client by the FL client. This can prevent one vendor from taking all of the resources of the NWDAF MTLF FL client 206. The utilization information can also include a maximum number of FL client instances from the same vendor used by one or more FL servers from the same vendor. Finally, the utilization information can include geographical area limits per analytics ID (i.e., per each given analytics ID for which the NWDAF FL server 202 wishes to run FL procedures for the geographical area of the FL server). Note that various other information can also be used as utilization information.

[0053] Next, the NWDAF FL server 202 can initiate a discovery request 210 to the NRF 204 for potential NWDAF MTLF FL clients 206. For example, the request can request analytics data associated with a particular analytics ID. The NWDAF FL server 202 then sends an access token request to the NRF 212 after discovering the relevant NWDAF MTLF FL clients 206 that can handle the request. The access token request also includes request utilization information, such as the required FL procedure run time per analytics ID, maximum resource consumption, geographical area of the NWDAF MTLF FL client, etc. The request utilization information can then be matched to the capabilities of the different NWDAF MTLF FL clients 206 to see if they can handle the request.

[0054] Next, the NRF 204 authorizes the request of the NWDAF FL server 214 based on the information registered in the NF profile in step 208 and the information provided in the access token request in step 212. This step can prevent requests from the NWDAF FL server 202 that would exceed the resource and run time limits of the NWDAF MTLF client 206 and allow the NRF 204 to authorize requests that fit within the resource and run time limits of the NWDAF MTLF client 206. In addition, if the analytics ID has associated priorities, these priorities can be used to determine whether the request should be authorized.

[0055] Once authorized, the NRF 204 provides an access token with enhanced claims to the resources 216. These enhanced claims to the resources can include total time for the FL procedure, vendor ID, geographical area of the NWDAF FL server, analytics ID, etc. If the NRF 204 cannot authorize the request, the NRF 204 denies the token request 218.

[0056] Next, the NWDAF FL server 202 sends a service request to the NWDAF MTLF client 206 with the access token(s) received previously 220. In addition to the FL model parameters, FL model ID, access token, and analytics ID, this service request now includes the total FL processing time and maximum resource utilization.

[0057] Finally, the NWDAF MTLF FL client 206 validates the access token(s), and when the tokens are successfully validated, the FL process is initialized 222. In addition, the NWDAF MTLF FL client 206 can send back a response that the tokens have been successfully authorized.

[0058] In the resource authorization mechanism 200, the NWDAF MTLF FL client 206 registers the maximum resource utilization and time for running the FL process according to various parameters. The NRF 204 then uses this registration information to accept or reject FL requests from the NWDAF FL server 202. This resource authorization mechanism 200 can thus manage and limit the utilization of the NWDAF MTLF FL client 206 to prevent overloading or monopolization of the NWDAF MTLF FL client 206.

[0059] Figure 3 An example hardware diagram 300 for implementing the authorization mechanism is shown. The example hardware 300 can correspond to the NWDAF FL server 202, the NRF 204, and / or the NWDAF MTLF client 206 of Figure 2 As shown, the device 300 includes a processor 320, a memory 330, a user interface 340, a network interface 350, and a storage 360 interconnected via one or more system buses 310. It should be understood that the actual organization of the components of the device 300 can be more complex than shown, with some aspects constituting abstractions. Figure 3 In some aspects constitute abstractions, and the actual organization of the components of the device 300 can be more complex than shown.

[0060] The processor 320 can be any hardware device capable of executing instructions or processing data stored in the memory 330 or the storage 360. Thus, the processor can include a microprocessor, a microcontroller, a graphics processing unit (GPU), a neural network processor, a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), or other similar devices.

[0061] The memory 330 can include various memories, such as LI, L2, or L3 caches or system memory. As such, the memory 330 can include static random access memory (SRAM), dynamic RAM (DRAM), flash memory, read-only memory (ROM), or other similar memory devices.

[0062] User interface 340 can include one or more devices for enabling communications with a user, such as an administrator. For example, user interface 340 can include a display, touch interface, mouse, and / or keyboard for receiving user commands. In some embodiments, user interface 340 can include a command line interface or graphical user interface that can be presented to a remote terminal via network interface 350.

[0063] Network interface 350 can include one or more devices for enabling communications with other hardware devices. For example, network interface 350 can include a network interface card (NIC) configured to communicate according to Ethernet protocols or other communication protocols, including wireless protocols. Additionally, network interface 350 can implement a transmission control protocol / internet protocol (TCP / IP) stack for communicating according to TCP / IP protocols. Various alternative or additional hardware or configurations of network interface 350 will be apparent.

[0064] Storage 360 can include one or more machine -readable storage media, such as read-only memory (ROM), random access memory (RAM), magnetic disk storage media, optical storage media, flash memory devices, or similar storage media. In various embodiments, storage 360 can store instructions for execution by processor 320 or data upon which processor 320 can operate. For example, storage 360 can store a basic operating system 361 for controlling various basic operations of hardware 300. Storage 362 can include instructions for implementing the resource authorization mechanisms described herein.

[0065] It will be apparent that various information described as being stored in storage 360 can additionally or alternatively be stored in memory 330. In this regard, memory 330 can also be considered to constitute a "storage device," and storage 360 can be considered a "memory." Various other arrangements will be apparent. Moreover, both memory 330 and storage 360 can be considered "non-transitory machine-readable media." As used herein, the term "non-transitory" will be understood to exclude transitory signals, but to include all forms of storage, including both volatile and non-volatile memory.

[0066] System bus 310 allows communication among processor 320, memory 330, user interface 340, storage 360, and network interface 350.

[0067] While the host device 300 is shown to include each of the described components, various components are replicated in various embodiments. For example, the processor 320 can include multiple microprocessors that are configured to independently execute the methods described herein or configured to perform steps or subroutines of the methods described herein, cause multiple processors to cooperate to achieve the functionality described herein. Further, where the device 300 is implemented in a cloud computing system, various hardware components can belong to separate physical systems. For example, the processor 320 can include a first processor in a first server and a second processor in a second server. Further, the authorization mechanism can be implemented using cloud computing to perform the various functions described above.

[0068] The foregoing disclosure provides illustration and description, but is not intended to be exhaustive or to limit the aspects to the precise form disclosed. Modifications and variations can be made in light of the above disclosure or can be acquired from practice of the aspects.

[0069] As used herein, the term “component” is intended to be broadly interpreted to include hardware, firmware, and / or combinations of hardware and software. As used herein, a processor is implemented in hardware, firmware, and / or combinations of hardware and software.

[0070] As used herein, depending on the context, satisfying a threshold can refer to being greater than the threshold, being greater than or equal to the threshold, being less than the threshold, being less than or equal to the threshold, being equal to the threshold, not being equal to the threshold, and / or the like. It will be apparent to those skilled in the art that the systems and / or methods described herein can be implemented in different forms of hardware, firmware, and / or a combination of hardware and software. The actual specialized control hardware or software code used to implement these systems and / or methods is not limiting of the aspects. Thus, the operation and behavior of the systems and / or methods were described herein without reference to specific software code — it being understood that software and hardware can be designed to implement the systems and / or methods based, at least in part, on the description herein.

[0071] As used herein, the term “non-transitory machine-readable storage medium” will be understood to exclude transitory propagating signals, but to include all forms of non- volatile memory. Where a software is implemented on a processor, the combination of software and processor becomes a specific purpose machine.

[0072] Because the data processing implementing embodiments described herein is made up of largely electronic components and circuits known to those skilled in the art, to the extent that circuit details are not deemed necessary to an understanding of the basic concepts of the aspects described herein, and to the extent that such details would tend to obscure the teachings of the aspects described herein, circuit details will not be explained in greater detail than is deemed necessary.

[0073] Terms such as “first” and “second” are used to arbitrarily distinguish between elements described by these terms. Thus, these terms are not necessarily intended to indicate a time or other priority.

[0074] Those of skill in the art will understand that any flowchart representation of a process as described herein is a conceptual representation of the process and that the actual implementation of the process can vary from the conceptual representation.

[0075] While each of the above embodiments is described above in terms of structural arrangements, it should be appreciated that these aspects also encompass the associated methods of using the above-described embodiments.

[0076] Even if a particular combination of features is recited in a claim and / or disclosed in the specification, those combinations are not intended to limit the disclosure of the various aspects. Rather, many of the features can be combined in ways not specifically recited in the claims and / or disclosed in the specification. Although each of the following claims lists a single dependent claim, the disclosure of the various aspects includes each dependent claim in combination with every other claim in the set of claims. Phrases such as “at least one of’ a list of items refers to any combination of those items, including single members. As an example, “at least one of a, b, or c” is intended to cover a, b, c, a-b, a-c, b-c, and a-b-c, as well as any combination with multiples of the same element (e.g., a-a, a-a-a, a-a-b, a-a-c, a-b-b, a-c-c, b-b, b-b-b, b-b-c, c-c, and c-c-c or any other ordering of a, b, and c).

[0077] As used herein, “at least one of ” and “” and similar phrases, where the list of two or more elements is bound by “and” or “or” means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0078] No element, act or instruction used herein should be construed as critical or essential unless explicitly described as such. Also, as used herein, the articles “a” and “an” are intended to include one or more items, and can be used interchangeably with “one or more.” Furthermore, as used herein, the terms “set” and “group” are intended to include one or more items (e.g., related items, unrelated items, a combination of related and unrelated items, and / or the like), and can be used interchangeably with “one or more.” Where only one item is intended, the phrase “only one” or similar language is used. Also, as used herein, the terms “has,” “have,” “having,” or the like are intended to be open-ended terms that do not limit any claim. Figure 1In the case of an application claiming priority under 35 U.S.C. § 119 from an application designating the United States, only the phrase "only one" or similar language can be used in the specification. In addition, as used herein the terms "have," "has," "having," or the like are intended to be open-ended terms. Further, the phrase "based on" is intended to mean "based, at least in part, on" unless explicitly stated otherwise.

Claims

1. An authorization server apparatus configured to implement a resource authorization mechanism for a federated learning (FL) training process, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive, from a first network device, FL registration information including FL utilization information; receive, from a second network device, an access token request for the first network device including requested utilization information, the first network device being a potential FL client; determine whether the second network device is authorized for the first network device based on the FL utilization information and the requested utilization information; and send, to the second network device, an access token for the first network device when the access token request for the first network device is authorized.

2. The authorization server apparatus of claim 1, wherein the utilization information includes maximum resource utilization information.

3. The authorization server apparatus of claim 2, wherein the maximum resource utilization information includes processor throughput, memory, and storage space.

4. The authorization server apparatus of claim 1, wherein the utilization information includes maximum resource utilization information based on at least one of an analytics identity (ID), an interoperability ID, a vendor ID of the second network device, regulatory constraints, a number of FL servers already served, and a network function instance ID of the second network device.

5. The authorization server apparatus of claim 1, wherein the utilization information includes at least one of a geographic region of the second network device, a maximum number of second network device instances from a same vendor allowed to use the FL client, a maximum number of FL client instances from a same vendor used by one or more second network devices from the same vendor, and a geographic region limit per analytics ID.

6. The authorization server apparatus of claim 1, wherein the utilization information includes maximum FL process execution time information.

7. The authorization server apparatus of claim 1, wherein the utilization information includes maximum FL process execution time information based on at least one of an analytics identity (ID), an interoperability ID, a vendor ID of the second network device, regulatory constraints, a number of FL servers already served, and a network function instance ID of the second network device.

8. The authorization server apparatus of claim 1, wherein the access token request includes at least one of a FL process execution time, a maximum resource consumption, and a geographic region required by the second network device per analytics ID.

9. The authorization server apparatus of claim 1, wherein the access token includes at least one of a total FL process execution time and a geographic region of the second network device. ​ 10. The apparatus of any of claims 1 to 9, wherein the authorization server is a network storage function (NRF) and the first network device and the second network device are network data analytics functions (NWDAFs).

11. A federated learning (FL) client apparatus for implementing a resource authorization mechanism for a FL training process, comprising: at least one processor; and at least one memory having stored instructions that, when executed by the at least one processor, cause the apparatus at least to: send, to an authorization server, FL registration information including utilization information; receive, from a second network device, a FL service request, the FL service request including an analytics ID, FL model parameters, and an access token including utilization information; verify the access token; and send a success response indicating that the FL client will use its analytics data to train and update a FL machine learning model.

12. The FL client apparatus of claim 11, wherein the at least one memory stores instructions that, when executed by the at least one processor, cause the apparatus at least to: train the FL machine learning model using analytics data associated with the analytics ID to update FL machine learning model parameters; and send the updated FL machine learning model parameters to the second network device.

13. The FL client apparatus of claim 11, wherein the utilization information includes maximum resource utilization information.

14. The FL client apparatus of claim 13, wherein the maximum resource utilization information includes processor throughput, memory, and storage space.

15. The FL client apparatus of claim 11, wherein the utilization information includes maximum resource utilization information based on at least one of: an analytics identification (ID), an interoperability ID, a vendor ID of the second network device, regulatory constraints, a number of FL servers already served, and a network function instance ID of the second network device.

16. The FL client apparatus of claim 11, wherein the utilization information includes at least one of: a geographic area of the second network device, a maximum number of second network device instances from a same vendor allowed to use a FL client, a maximum number of FL client instances from a same vendor used by one or more second network devices from the same vendor, and a geographic area limit per analytics ID.

17. The FL client apparatus of claim 11, wherein the utilization information includes maximum FL process execution information.

18. The FL client apparatus of claim 11, wherein the utilization information includes maximum FL process execution time information based on at least one of: an analytics identification (ID), an interoperability ID, a vendor ID of the second network device, regulatory constraints, a number of FL servers already served, and a network function instance ID of the second network device. ​ 19. The apparatus of any of claims 11 to 18, wherein the FL client is a network data analytics function (NWDAF).

20. A FL server apparatus for implementing an authorization mechanism for federated learning (FL) training processes, comprising: at least one processor; at least one data storage apparatus; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: send a discovery request to an authorization server; receive information about potential FL clients from the authorization server; send an access token request to the authorization server for the potential FL clients including a request utilization information; receive an access token for the FL client from the authorization server when the access token request for the FL client is authorized; and send a FL service request access token including utilization information to the FL client.

21. The FL server apparatus of claim 20, wherein the utilization information includes maximum resource utilization information.

22. The FL server apparatus of claim 21, wherein the maximum resource utilization information includes processor throughput, memory, and storage space.

23. The FL server apparatus of claim 20, wherein the utilization information includes maximum resource utilization information based on at least one of an analytics identity (ID), an interoperability ID, a vendor ID of the FL server, regulatory constraints, a number of FL servers already served, and a network function instance ID of the FL server.

24. The FL server apparatus of claim 20, wherein the utilization information includes at least one of a geographic region of the FL server, a maximum number of FL server instances from a same vendor allowed to use FL clients, a maximum number of FL client instances from a same vendor used by one or more FL servers from the same vendor, and a geographic region limit per analytics ID.

25. The FL server apparatus of claim 20, wherein the utilization information includes maximum FL process execution time information.

26. The FL server apparatus of claim 20, wherein the utilization information includes maximum FL process execution time information based on at least one of an analytics identity (ID), an interoperability ID, a vendor ID of the FL server, regulatory constraints, a number of FL servers already served, and a network function instance ID of the FL server.

27. The apparatus of any of claims 20 to 26, wherein the FL server is a network data analytics function (NWDAF).