Privacy protection in wireless communication network
By introducing open functions into wireless communication systems for privacy adaptation and anonymization, the privacy protection issue when sharing data across geographical boundaries is resolved, ensuring the security and compliance of data in external application functions.
Patent Information
- Application Number
- CN202380100795.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-07-28
- Filing Date
- 2023-09-14
- Publication Date
- 2026-02-24
AI Technical Summary
Existing wireless communication systems are prone to violating national privacy requirements when sharing privacy-sensitive data across geographical boundaries, and existing technologies have failed to effectively protect the security of privacy-sensitive data in external application functions.
Privacy protection is achieved through open functionality, including data producers performing privacy adaptations before data is made public, transforming or anonymizing sensitive data, and providing privacy-protected data for external analysis through open functionality.
It achieves privacy protection when sharing data across geographical boundaries, complies with national privacy requirements, and ensures the security and privacy of data in external application functions.
Smart Images

Figure CN121569464A_ABST
Abstract
Description
Technical Field
[0001] The topics disclosed in this document generally relate to the area of achieving privacy protection in wireless communication networks. This document defines network functions (NFs) in wireless communication networks and their implementation methods. Background Technology
[0002] A wireless communication system may include one or more network communication devices, such as base stations, which can support wireless communication with one or more user communication devices, also referred to as user equipment (UE) or other suitable terms. The wireless communication system can support wireless communication with one or more user communication devices by utilizing the resources of the wireless communication system (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers, etc.)). Furthermore, the wireless communication system can support wireless communication across various wireless access technologies, including third-generation (3G), fourth-generation (4G), fifth-generation (5G), and other suitable wireless access technologies beyond 5G (e.g., sixth-generation (6G)). Summary of the Invention
[0003] The article “a (a)” preceding an element is unrestricted and should be understood to mean “at least one” or “one or more” of those elements. The terms “a (a),” “at least one,” “one or more,” and “at least one of one or more” are interchangeable. As used herein, including in claims, “or” as used in a list of items (e.g., a list of items beginning with phrases such as “at least one of…” or “one or more of…” or “one or two of…”) indicates an inclusive list, such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Furthermore, as used herein, the phrase “based on” should not be construed as a reference to a closed set of conditions. For example, an example step described as “based on condition A” could be based on both condition A and condition B without departing from the scope of this disclosure. In other words, as used herein, the phrase “based on” should be interpreted in the same manner as the phrase “at least partially based on.” Furthermore, as used herein, including in claims, “set” can include one or more elements.
[0004] An open function in a wireless communication network is provided, the open function comprising: at least one memory; and at least one processor coupled to the at least one memory and configured such that the open function: receives a request for data from a second network function NF, the second NF performing external analysis on the data; determines a third NF for sending the request for data; and sends the request for data and an application ID associated with the second NF to the third NF.
[0005] A method performed by an open function in a wireless communication network is also provided, the method comprising: receiving a request for data from a second network function NF, the second NF performing external analysis on the data; determining a third NF 803 for sending the request for data; and sending the request for data and an application ID associated with the second NF to the third NF. Attached Figure Description
[0006] Figure 1 The diagram illustrates the collection of data and the sharing of this data with third-party applications.
[0007] Figure 2 Examples of wireless communication systems according to various aspects of this disclosure are illustrated.
[0008] Figure 3 The illustrations illustrate the privacy protection processes under this disclosure.
[0009] Figure 4 The illustration shows the further privacy protection process according to various aspects of this disclosure.
[0010] Figure 5 The illustration shows the further privacy protection process according to various aspects of this disclosure.
[0011] Figure 6 The illustration shows the further privacy protection process according to various aspects of this disclosure.
[0012] Figure 7 The illustration shows the further privacy protection process according to various aspects of this disclosure.
[0013] Figure 8 The diagram illustrates a flowchart of a method performed by an open function according to various aspects of this disclosure.
[0014] Figure 9 Examples of user equipment (UE) according to various aspects of this disclosure are illustrated.
[0015] Figure 10 Examples of processors according to various aspects of this disclosure are illustrated.
[0016] Figure 11Examples of network devices (NEs) or NFs according to various aspects of this disclosure are illustrated. Detailed Implementation
[0017] 5G systems allow for the collection and processing of various types of data (e.g., for network analysis, attack detection, security assessment, security monitoring, etc.). Data collected from different wireless network functions, entities, and UEs may include privacy-sensitive data, including but not limited to public IP addresses, MAC addresses, IMSI, GUTI, control plane parameters, subscriber names, email addresses, cell IDs and names, as well as information about the region, operator user identity, location information from UEs and BTSs, etc.
[0018] If the collected privacy-sensitive data is shared with processing teams or applications across geographical boundaries, it may violate country-specific privacy requirements.
[0019] Furthermore, if the collected privacy-sensitive data is shared with external application functions (e.g., third-party application functions) for any processing reason, privacy (i.e., privacy-sensitive information about subscribers, networks, and / or network topology) will be affected.
[0020] When collecting operational and management logs (such as system logs, BTS snapshot logs, trace data, performance metrics, configuration management data, or fault management data (alerts)) from different network entities, privacy-sensitive information may be included. If such privacy-sensitive data is shared with processing teams or applications across geographical boundaries, it may violate country-specific privacy requirements.
[0021] In a multi-vendor environment, management data may be shared between entities provided by different vendors. Data may be shared with third-party automation applications or processing teams located in different parts of the world. Country-specific privacy requirements may be violated. These aspects are addressed in 3GPP TSG SA WG3 (SA3) Release 19, which addresses the Services and Systems Aspects (TSG SA) within the 3GPP Technical Specification Group.
[0022] Figure 1 The illustration shows a general system 100 in which data is collected and can be made available to third-party applications for data analysis (e.g., network data analysis and / or security analysis for monitoring).
[0023] System 100 includes multiple first network entities 102, multiple second network entities 104, an operator’s network management system (NMS) or OAM 106, third-party analytics applications 108 (such as SIEM), and third-party or outsourced troubleshooting teams 110.
[0024] At point 112, management data collected from different network entities 102 and 104 is sent to the operator's NMS / OAM 106. This collected management data may include privacy-sensitive information.
[0025] At point 114, management data can be sent to a third-party outsourcing team 110 for analysis, and / or to a third-party automated analytics application 108.
[0026] Therefore, there is a risk that privacy-sensitive data may be unintentionally disclosed to many unauthorized individuals / entities. Thus, privacy protections to ensure data confidentiality are beneficial.
[0027] Another example is that in many organizations, customer support and R&D teams are located in different countries around the world. Country-specific regulations require the protection of privacy-sensitive information. Data shared outside of mobile operator networks may face security risks, or even if such data remains on the operator's premises, the entity that collects it may be vulnerable to attack. Therefore, privacy protections to ensure the confidentiality of data are essential.
[0028] TS 23.288 describes the data collection and data analysis processes of the prior art.
[0029] In some existing technology applications, NEF allows interaction with third-party application functions (AFs). NEF performs authentication and authorization for the AFs.
[0030] However, existing technological solutions have several limitations. For example, current 3GPP data collection and network data analysis processes do not involve making data available to external applications for data processing or analysis (e.g., network data analysis / parsing / security analysis for monitoring, etc.). Therefore, existing technological solutions often do not consider privacy preservation or protection.
[0031] The embodiments described herein advantageously enable privacy protection of collected data through open functionality, making it available for external analysis (e.g., network data analysis / parsing for monitoring, or management data analysis / parsing, or security assessment / analysis, etc.). The embodiments describe variations for application privacy adaptation (i.e., application functions that convert privacy-sensitive data into privacy-preserving / protected data and make it available outside the network in an untrusted domain).
[0032] Other embodiments described herein advantageously tend to enable privacy protection of the collected data for external analysis by application functions residing in a trusted domain (e.g., network data analysis / parsing for monitoring (or) management data analysis / parsing (or) security assessment / analysis, etc.). The embodiments describe variations for application privacy adaptation (i.e., converting privacy-sensitive data into privacy-preserving / protected data) and making it available to application functions.
[0033] The embodiments described herein illustrate the process of anonymizing / pseudo-anonymizing privacy-sensitive data during data collection and dissemination.
[0034] One embodiment described herein is a method for determining a privacy adaptation based on a privacy policy (e.g., which may be specific to an event ID), and for applying the aforementioned privacy adaptation to data by a data producer (e.g., any network function, application function, or RAN node) to enable privacy-preserving data collection and openness via open functionality.
[0035] Another embodiment described herein is a method for determining a privacy adaptation based on a privacy policy (e.g., which may be specific to an event ID), and for applying the aforementioned privacy adaptation to the collected data by a data consumer / collector (e.g., any network function, application function, or administrative function) so that the privacy-preserving data can be made available for external analysis via open functionality.
[0036] Another embodiment described herein is a method for determining a privacy adaptation based on a privacy policy (e.g., which may be specific to an event ID), and applying the aforementioned privacy adaptation to the collected data by a data openness function (e.g., any network openness function or management openness entity / function), so that the privacy-preserving data can be provided for external analysis via the openness function.
[0037] Another embodiment described herein is a method for determining a privacy adaptation based on a privacy policy (e.g., which may be specific to an event ID), and for applying the aforementioned privacy adaptation by a data producer (e.g., any network function, application function, or RAN node) to enable privacy-preserving data collection.
[0038] Another embodiment described herein is a method for determining a privacy adaptation based on a privacy policy (e.g., which may be specific to an event ID), and for applying the privacy adaptation to the collected data by a data consumer / collector (e.g., any network function, application function, management function) so that the privacy-preserving data can be made available for external analysis.
[0039] Various aspects of this disclosure are described in the context of wireless communication systems.
[0040] Figure 2 An example of a wireless communication system 200 according to various aspects of this disclosure is illustrated. The wireless communication system 200 may include one or more NEs 202, one or more UEs 204, and a core network (CN) 206. The wireless communication system 200 may support various wireless access technologies. In some implementations, the wireless communication system 200 may be a 4G network, such as an LTE network or an LTE-Advanced (LTE-A) network. In some other implementations, the wireless communication system 200 may be an NR network, such as a 5G network, an 5G-Advanced (5G-A) network, or a 5G Ultra Wideband (5G-UWB) network. In other implementations, the wireless communication system 200 may be a combination of 4G and 5G networks, or other suitable wireless access technologies, including IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20. The wireless communication system 200 may support wireless access technologies other than 5G, such as 6G. In addition, the wireless communication system 200 can support technologies such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA).
[0041] One or more NEs 202 may be distributed throughout a geographic area to form a wireless communication system 200. The one or more NEs 202 described herein may be, include, or may be referred to as network nodes, base stations, network elements, network functions, network entities, radio access networks (RANs), Node Bs, eNodeBs (eNBs), next-generation Node Bs (gNBs), or other suitable terms. NEs 202 and UEs 204 may communicate via a communication link, which may be a wireless or wired connection. For example, NEs 202 and UEs 204 may perform wireless communication (e.g., receive signaling, send signaling) via a Uu interface.
[0042] NE 202 can provide a geographic coverage area, and NE 202 can support the services of one or more UE 204s within that geographic coverage area. For example, NE 202 and UE 204 can support wireless communication of signals associated with services (e.g., voice, video, packet data, messaging, broadcasting, etc.) based on one or more radio access technologies. In some implementations, NE 202 can be mobile, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies can overlap, but different geographic coverage areas can be associated with different NE 202s.
[0043] One or more UEs 204 may be distributed throughout the geographic area of the wireless communication system 200. UE 204 may include or be referred to as a remote unit, mobile device, wireless device, remote device, subscriber device, transmitter device, receiver device, or some other suitable term. In some implementations, among other examples, UE 204 may be referred to as a unit, station, terminal, or client. Additionally or alternatively, UE 204 may be referred to as an Internet of Things (IoT) device, an Internet of Everything (IoE) device, or a Machine Type Communication (MTC) device, among other examples.
[0044] UE 204 may be able to support direct wireless communication with other UE 204s via a communication link. For example, UE 204 may support direct wireless communication with another UE 204 via a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular V2X deployments, the communication link 214 may be referred to as a sidechain. For example, UE 204 may support direct wireless communication with another UE 204 via a PC5 interface.
[0045] NE 202 can support communication with CN 206 or with another NE 202, or both. For example, NE 202 can interface with other NE 202 or CN 206 via one or more backhaul links (e.g., S1, N2, N2, or network interfaces). In some implementations, NE 202 can communicate directly with each other. In some other implementations, NE 202 can communicate indirectly with each other (e.g., via CN 206). In some implementations, one or more NE 202 may include sub-components, such as access network entities, which may be examples of access node controllers (ANCs). The ANC can communicate with one or more UE 204s via one or more other access network transport entities (which may be referred to as radio heads, smart radio heads, or transmit-receive points (TRPs)).
[0046] CN 206 can support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. CN 206 can be an evolved packet core (EPC) or a 5G core (5GC), which may include control plane entities that manage access and mobility (e.g., a mobility management entity (MME), access and mobility management functions (AMF)) and user plane entities that route packets or interconnects to external networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entities may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signaling bearers, etc.) for one or more UEs 204 served by one or more NEs 202 associated with CN 206.
[0047] CN 206 can communicate with the packet data network via one or more backhaul links (e.g., via S1, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more UEs 204 can communicate with the application server. UE 204 can establish a session with CN 206 via NE 202 (e.g., a Protocol Data Unit (PDU) session, etc.). CN 206 can use the established session (e.g., an established PDU session) to route services (e.g., control information, data, etc.) between UE 204 and the application server. The PDU session may be an example of a logical connection between UE 204 and CN 206 (e.g., one or more network functions of CN 206).
[0048] In the wireless communication system 200, NE 202 and UE 204 can use the resources of the wireless communication system 200 (e.g., time resources (e.g., symbols, time slots, subframes, frames, etc.) or frequency resources (e.g., subcarriers, carriers)) to perform various operations (e.g., wireless communication). In some implementations, NE 202 and UE 204 can support different resource structures. For example, NE 202 and UE 204 can support different frame structures. In some implementations, such as in 4G, NE 202 and UE 204 can support a single frame structure. In some other implementations, such as in 5G and other suitable radio access technologies, NE 202 and UE 204 can support various frame structures (i.e., multiple frame structures). NE 202 and UE 204 can support various frame structures based on one or more digital technologies.
[0049] One or more digital technologies may be supported in the wireless communication system 200, and the digital technologies may include subcarrier spacing and cyclic prefix. The first digital technology (e.g., μ=0) can be associated with the first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first digital technique (e.g., ...) associated with the first subcarrier spacing (e.g., 15 kHz) is... μ =0) Each subframe can utilize one time slot. Second digital technology (e.g., μ =1) can be associated with the second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. The third digital technology (e.g., μ =2) can be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth digital technology (e.g., μ =3) can be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth digital technology (e.g., μ =4) can be associated with the fifth subcarrier spacing (e.g., 240 kHz) and the normal cyclic prefix.
[0050] The time intervals of resources (e.g., communication resources) can be organized according to frames (also called radio frames). Each frame can have a duration, for example, 10 milliseconds (ms). In some implementations, each frame can include multiple subframes. For example, each frame can include 10 subframes, and each subframe can have a duration, for example, 1 ms. In some implementations, each frame can have the same duration. In some implementations, each subframe of a frame can have the same duration.
[0051] Alternatively or concurrently, the time intervals of resources (e.g., communication resources) can be organized according to time slots. For example, a subframe may include a certain number (e.g., quantity) of time slots. The number of time slots in each subframe may also depend on one or more digital technologies supported in the wireless communication system 200. For example, a first digital technology, a second digital technology, a third digital technology, a fourth digital technology, and a fifth digital technology (i.e., ...) associated with corresponding subcarrier intervals of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz. μ =0、 μ =1、 μ =2、 μ =3、 μ=4) One time slot per subframe, two time slots per subframe, four time slots per subframe, eight time slots per subframe, and 16 time slots per subframe can be used, respectively. Each time slot can include a certain number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of time slots in a subframe can depend on the digital technique. For a normal cyclic prefix, a time slot can include 14 symbols. For an extended cyclic prefix (e.g., for a 60kHz subcarrier spacing), a time slot can include 12 symbols. The relationship between the number of symbols per time slot, the number of time slots per subframe, and the number of time slots per frame for both normal and extended cyclic prefixes can depend on the digital technique. It should be understood that the first digital technique (e.g., quantity) associated with the first subcarrier spacing (e.g., 15kHz) can be... μ The reference of =0 can be used interchangeably between subframes and time slots.
[0052] In the wireless communication system 200, the electromagnetic (EM) spectrum can be divided into various categories, frequency bands, frequency channels, etc., based on frequency or wavelength. For example, the wireless communication system 200 can support one or more operating frequency bands, such as frequency range names FR1 (410MHz-7.125GHz), FR2 (24.25GHz-52.6GHz), FR3 (7.125GHz-24.25GHz), FR4 (52.6GHz-114.25GHz), FR4a or FR4-1 (52.6GHz-71GHz), and FR5 (114.25GHz-300GHz). In some implementations, NE 202 and UE 204 can perform wireless communication on one or more operating frequency bands. In some implementations, FR1 can be used by NE 202 and UE 204, along with other devices or apparatuses, for cellular communication services (e.g., control information, data). In some implementations, FR2 can be used by NE 202 and UE 204, along with other devices or apparatuses, for short-range, high data rate capabilities.
[0053] FR1 can be associated with one or more digital technologies (e.g., at least three digital technologies). For example, FR1 can be associated with the following: a first digital technology (e.g., μ =0), which includes a 15kHz subcarrier spacing; second digital technology (e.g., μ =1), which includes a 30kHz subcarrier spacing; and a third digital technology (e.g., μ =2), which includes a subcarrier spacing of 60 kHz. FR2 can be associated with one or more digital technologies (e.g., at least two digital technologies). For example, FR2 can be associated with a third digital technology (e.g., μ =2), which includes a 60kHz subcarrier spacing; and a fourth digital technology (e.g., μ =3), which includes a subcarrier spacing of 120kHz.
[0054] Figure 3 An embodiment of the privacy protection process 300 is illustrated.
[0055] Process 300 involves data producers 302 (such as any NF, AF, or RAN), UDM 304 (or other managed NFs, such as UDR, UDSF, or NRF), data consumers or collectors 306, open functions 308 (such as EGMF or NEF), and AF 310.
[0056] AF 310 can reside within the carrier network or be located outside the carrier network, i.e., an external AF. AF 310 can be considered to be in an untrusted domain.
[0057] Open Function 308 can be any function in the operator's network that facilitates requesting data collection and providing the collected data for external analysis / monitoring. In this embodiment, Open Governance Management Function (EGMF) or Network Open Function (NEF) or any network function / management function can play the role of Open Function 308.
[0058] In this embodiment, data producer 302 performs privacy protection adaptation before the data is made public.
[0059] Process 300 is a method for determining a privacy adaptation based on a privacy policy, and for applying the privacy adaptation to data by data producer 302 to enable privacy-preserving data collection and disclosure via open functionality. The privacy adaptation described in this embodiment (e.g., transforming / aggregating / mapping privacy-sensitive data or replacing privacy-sensitive data with equivalent privacy-preserving data) can be a service provided by a logical function co-located with data producer 302, or it can be a standalone function. In the latter case, data producer 302 can request and receive the privacy adaptation service (e.g., by providing input data and receiving privacy-preserving input data).
[0060] Process 300 begins at 312, where AF 310 sends a monitoring event data open subscription / request message to open function 308. This message includes an event identifier (event ID) and / or (multiple) external analysis IDs, event reporting target information, and optional reporting type and / or period.
[0061] Event reporting target information can indicate (multiple) objects whose data is requested to enable analysis and monitoring. It can indicate entities such as a specific UE, a group (multiple) UEs, or any UE (i.e., all UEs), network functions, application functions, RAN nodes, etc.
[0062] In some embodiments, event reporting target information may be considered as “external analysis report or monitoring target information” or “event reporting target external ID”.
[0063] If step 312 involves a NEF playing the role of open function 308, then steps 312, 332, and 336 may use any appropriate NEF-related service operation message. Alternatively, if step 312 involves any other management domain function playing the role of open function 308, then steps 312, 332, and 336 may use any appropriate management-related service message.
[0064] At 314, based on local configuration or by querying UDM / UDR / UDSF / NRF 304, open function 308 identifies the data collector 306 specific to the received event report target information.
[0065] In the first option (Option 1), the data collector-related identification information is associated with NWDAF / DCCF / MFAF / ADRF. That is, in Option 1, data collector 306 can be NWDAF / DCCF / MFAF / ADRF. For example, the service NF and / or (multiple) RAN nodes associated with the event reporting target can be regarded as data collectors, or based on local policies, event reporting target information can also be regarded as data collector 306.
[0066] In the second option (Option 2), the data consumer / data collection point related identification information is associated with OAM / NMS / MDAF / MnS. That is, in Option 2, the data collector 306 can be OAM / NMS / MDAF / MnS.
[0067] The open function 308 sends a monitoring event data open subscription / request message to the identified data collector 306. The message includes an event identifier (event ID) and / or (multiple) external analysis IDs, event reporting target information, and reporting type and / or period (if received in step 312).
[0068] Optionally, the open function 308 sends the application ID (the application ID of the AF 310 that sends the event data open subscription / request) to, for example, the identified data collector 306.
[0069] In some embodiments, at 314, the open function 308 can query UDM / UDR / UDSF / NRF 304 by sending a request message (e.g., a data collection information request), which may include the application ID of AF 310 that sent the event data open subscription / request, and the received event reporting target information.
[0070] In response to sending a message, Open Function 308 may receive a response message (e.g., a data collection information response) that may include identification information (an ID / FQDN or address associated with NWDAF / DCCF / MFAF / ADRF or OAM / NMS / MDAF). Alternatively, Open Function 308 may receive a message (e.g., a data collection information response) that may include a "Open Not Allowed" indication corresponding to the application ID of AF 310.
[0071] If the open function 308 receives an "open not allowed" instruction for AF 310, the open function 308 can prevent or oppose opening to the data collector 306 of AF 310.
[0072] Steps 314, 330, and 338 may use any appropriate data collection function-related service operation messages to subscribe to / request, receive notifications / responses related to data openness, and provide monitoring results. Alternatively, steps 314, 330, and 338 may use appropriate openness-related network service operation messages or management service messages to allow data collector 306 to subscribe to external analysis-related data openness request notifications and to allow data collector 306 to provide anonymous input data to openness function 308 and receive monitoring results respectively.
[0073] At 316, data collector 306 requests or subscribes to a set of event IDs (which may include multiple event IDs) from data producer 302 by invoking the Nnf_EventExposure_Subscribe or Nnf_EventExposure_Request service operation, which may include multiple event IDs. For example, this operation can be performed if process 300 follows option 1.
[0074] The (multiple) event IDs can be the event IDs received in step 314, or the data collector 306 can use a locally configured set of event IDs associated with the external analytics IDs received in step 314. The data collector 306 may include an anonymity request flag (i.e., any indication that a privacy-preserving adaptation is required) in its message at 316.
[0075] Data collector 306 can check whether data should be collected for users (i.e., SUPI or GPSI) or related network functions / RAN nodes.
[0076] According to local policies and regulations, data collector 306 can check user consent by retrieving user consent information from UDM / UDR / UDSF / NRF 304 using Nudm_SDM_Get, which includes the data type "User Consent". For example, this can be performed if the event reporting target information indicates any UE ID. If user consent is not granted, data collector 306 does not subscribe to event openness for events related to that user, and data collection for that SUPI or GPSI ceases. Furthermore, if the event reporting target information indicates any NF ID / AF ID / RAN ID (e.g., gNB ID) or any UE ID, the data collector can check the privacy policy associated with the event ID / external analytics ID(s).
[0077] In some embodiments, when needed, the data collector 306 can unsubscribe from the set of event IDs(s) by invoking the Nnf_EventExposure_Unsubscribe service operation.
[0078] The report type or time period can indicate whether to report immediately or periodically, and when or how often data can be collected and made available for external analysis.
[0079] In some embodiments, if the data producer 302 is a RAN node, the data collector 306 may send an EventExposure_Subscribe message to the data producer 302, which may include an event ID and an anonymity request flag (i.e., any indication that a privacy protection adaptation is required).
[0080] At point 318, based on local policies and / or received anonymity request flags / instructions, data producer 302 determines to examine the privacy policy related to the indicated event-based data collection.
[0081] Data producer 302 sends a data collection policy request (i.e., Nudm / Nnf_Data collection policy request) to UDM / UDR / UDSF / NRF 304. The data collection policy request may include (multiple) NF IDs, UE ID sets / group ID sets (based on event reporting target information), and (multiple) event IDs and / or external analysis IDs.
[0082] At position 320, UDM / UDR / UDSF / NRF 304 is pre-configured based on the operator's local policy and a privacy policy for data collection and disclosure. This privacy policy includes privacy-adapted datasets associated with various entities (e.g., NF ID, AFID, RAN node, UE ID / UE group ID, slice S-NSSAI), (multiple) external analytics IDs and / or (multiple) event IDs, as well as related "input data". Example privacy policies are shown in Table 1.1 below.
[0083] Privacy-adapted data includes mappings of privacy-sensitive information to their associated privacy-protected IDs / names / codes (e.g., masking information).
[0084] At 322, based on the external analysis ID / (multiple) event ID and (multiple) NF ID / UE ID set / group ID set (i.e., event reporting target information), UDM / UDR / UDSF / NRF 304 extracts appropriate privacy-adaptive data (i.e., equivalent privacy-preserving data).
[0085] UDM / UDR / UDSF / NRF 304 sends a data collection policy response (i.e., Nudm / Nnf_Data collection policy response) to data producer 302. The data collection policy response may include (multiple) event IDs / external analysis IDs and (multiple) NFID / UE ID sets / group ID sets (i.e., event reporting target information) as well as specific privacy adaptation data.
[0086] In some embodiments, privacy-adapted data may include privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include input data, privacy requirements, and privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include privacy policies associated with event IDs / external analysis IDs(multiple).
[0087] At point 324, if data producer 302 determines that any one or more of the collected / input data are privacy-sensitive data, then data producer 302 applies a privacy adaptation to that input data. Specifically, data producer 302 (i.e., replaces, masks, or covers the privacy-sensitive input data with the received equivalent privacy-adapted data (i.e., a privacy-preserving version of the data)).
[0088] In some embodiments, data producer 302 is configured with privacy-adapted data or privacy policies for data collection and disclosure as described in Table 1.1. In this case, steps 318-322 can be omitted, and data producer 302 can apply privacy adaptation to the input data based on the configuration information.
[0089] At 326, data collector 306 sends privacy-preserving (i.e., anonymous) input data to data collector 306. For example, if data collector 306 subscribes to a set of event IDs, data producer 302 notifies data collector 306 of the privacy-preserving (i.e., anonymous) input data (e.g., utilizing event reports) by invoking the Nnf_EventExposure_Notify service operation based on event reporting information in the subscription. For example, this operation can be performed if process 300 follows option 1.
[0090] As an alternative to steps 316-326, at 328, if data collection is not performed directly from data producer 302 (by following steps 316-326), data collector 306 can perform data collection from the data producer via OAM (i.e., OAM-based data collection). In this case, data collector 306 can subscribe to / request OAM and receive notifications from OAM, or receive data related to event-related privacy-preserving input data. This can be performed in a manner similar to steps 316-326, but OAM manages the data collection from data producer 302 and provides the collected privacy-preserving data to data collector 306, rather than data producer 302 generating the input data. In the case of OAM-based data collection, data producer 302 can perform steps 318-324, or only step 324, for example, if privacy-adaptive data is configured in data producer 302 to allow OAM to extract privacy-preserving input data from data producer 302 and provide it to data collector 306.
[0091] At 330, the data collector 306 sends a monitoring event open notification / response message with privacy-protected input data (i.e., anonymous input data) to the data open function 308.
[0092] At 332, the open function 308 sends a monitoring event open notification / response message with privacy-preserving input data (i.e., anonymous input data) to AF 310.
[0093] At 334, using the received privacy-preserving input data, AF 310 performs data analysis and parsing based on operator implementations (e.g., using any AI / ML algorithm or intelligent tool, such as threat detection tools, security information and incident management (SIEM) tools, security orchestration, automation and response (SOAR) tools, etc.) for network security assessment and security monitoring / general monitoring.
[0094] At 336, AF 310 sends the monitoring results (i.e., external analysis output) to open function 308.
[0095] Monitoring results may include (multiple) trust values or reliability metrics that can be associated with the target information of the incident report. Trust values or reliability metrics can represent a range of reliability for the monitoring results, such as 0-20% = low, 21-50% = medium, 50-99% = high, and 100% = fully trustworthy.
[0096] Monitoring results can be related to the target information in the event report and can be specific to the indicated ID. Monitoring results may include cause codes, which can indicate whether any of the following occurred: configuration issues, attack / threat alerts (e.g., DOS / DDoS / NF hijacking, malicious code injection, NF leaks, etc.), fault alerts, and / or flood alerts. Monitoring results may include anomalous behavior statistics / predictions (those listed in Tables 1.3 and 1.4 below), and / or time windows that external analytics consumers can use to rely on data up to that time window.
[0097] Table 1.2 below shows an example of privacy-preserving input data collected from data producer 302 (e.g., NF / AF / RAN node) for anomaly detection.
[0098] Table 1.2
[0099] Table 1.3 below shows an example of statistics on abnormal / abnormal behavior.
[0100] Table 1.3
[0101] Table 1.4 below shows an example of predicting abnormal / abnormal behavior.
[0102] Table 1.4
[0103] At point 338, the open function 308 sends the received monitoring results to the data collector 306.
[0104] At 340, if any service consumer has subscribed to external analytics based on local configuration (e.g., associated with any (external) monitoring-related analytics ID), the data collector 306 can notify the monitoring results.
[0105] In this embodiment, if the RAN node acts as a data producer 302 at steps 316 and 318, any event open subscription / notification and request / response messages can be used.
[0106] In this embodiment, the data collector 306 can also perform data distribution.
[0107] In some implementations, the data collector 306 can initiate step 316 based on a local policy and can perform further steps.
[0108] Therefore, a privacy protection process 300 is provided.
[0109] In the embodiments described herein, a data producer may be one or more data producers neutrally selected from a group of data producers comprising the following: Authentication Server Function (AUSF); Access and Mobility Management Function (AMF); Data Network (DN), such as operator services, Internet access, or third-party services; Unstructured Data Storage Function (UDSF); Network Open Function (NEF); Network Repository Function (NRF); Network Slice Admission Control Function (NSACF); Network Slice-Specific and SNPN Authentication and Authorization Function (NSSAAF); Network Slice Selection Function (NSSF); Policy Control Function (PCF); Session Management Function (SMF); Unified Data Management (UDM); Unified Data Repository (UDR); User Plane Function (UPF); UE Radio Capability Management Function (UCMF); Application Function (AF); User Equipment (UE); (Radio) Access Network ((R)AN); 5G Device Identifier Register (5G-EIR); Network Data Analytics Function (NWDAF); Charging Function (CHF); Time-Sensitive Network AF (TSN). AF); Time-Sensitive Communication and Time Synchronization Function (TSCTSF); Data Collection Coordination Function (DCCF); Analysis Data Repository Function (ADRF) (Note that functions provided by DCCF and / or ADRF can also be hosted by NWDAF); Messaging Framework Adapter Function (MFAF); Non-Seamless WLAN Offload Function (NSWOF); Edge Application Server Discovery Function (EASDF).
[0110] The 5G system architecture may also include one or more of the following network entities: Serving Communication Agent (SCP); Secure Edge Protection Agent (SEPP); Non-3GPP Interoperability Function (N3IWF); Trusted Non-3GPP Gateway Function (TNGF); Wired Access Gateway Function (W-AGF); Trusted WLAN Interoperability Function (TWIF).
[0111] Figure 4 An embodiment of the privacy protection process 400 is illustrated.
[0112] Process 400 involves data producers 402 (such as any NF, AF, or RAN), UDM 404 (or other administrative NFs, such as UDR, UDSF, or NRF), data consumers or collectors 406, open functions 408 (such as EGMF or NEF), and AF 410.
[0113] AF 410 can reside within the carrier network or be located outside the carrier network, i.e., an external AF. AF410 can be considered to be in an untrusted domain.
[0114] Open Function 408 can be any function in the operator's network that facilitates requesting data collection and providing the collected data for external analysis / monitoring. In this embodiment, EGMF or NEF or any network function / management function can play the role of Open Function 408.
[0115] In this embodiment, the data collector 406 performs privacy protection adaptation before the data is made public.
[0116] Process 400 is a method for determining a privacy adaptation based on a privacy policy, and for applying this privacy adaptation to data by a data collector 406 (e.g., any network function such as NWDAF / DCCF / MFAF / ADRF, application function, management function) to enable privacy-preserving data collection and openness via open function 408. The privacy adaptation described in this embodiment (e.g., transforming / aggregating / mapping privacy-sensitive data or replacing privacy-sensitive data with equivalent privacy-preserving data) can be a service provided by a logical function co-located with data collector 406, or it can be a standalone function. In the latter case, data collector 406 can request and receive the privacy adaptation service (e.g., by providing input data and receiving privacy-preserving input data).
[0117] Process 400 begins at 412, where AF 410 sends a monitoring event data open subscription / request message to open function 408. This message includes an event identifier (event ID) / (multiple) external analysis IDs, event reporting target information, and optionally, the reporting type and / or period.
[0118] Event reporting target information can indicate (multiple) objects whose data are requested for analysis and monitoring. It can indicate entities such as a specific UE, a group (multiple) UEs, or any UE (i.e., all UEs), network functions, application functions, RAN nodes, etc.
[0119] In some embodiments, event reporting target information may be considered as 'external analysis report or monitoring target information' or 'event reporting target external ID'.
[0120] If step 412 involves a NEF playing the role of open function 408, then steps 412, 434, and 438 may use any NEF-related service operation messages. Alternatively, if step 412 involves any other management domain function playing the role of open function 408, then steps 412, 434, and 438 may use any management-related service messages.
[0121] At 414, based on local configuration or by querying UDM / UDR / UDSF / NRF 404, open function 408 to identify data collector 406 specific to the received event reporting target information.
[0122] In the first option (Option 1), the data collector-related identification information is associated with NWDAF / DCCF / MFAF / ADRF. That is, in Option 1, data collector 406 can be NWDAF / DCCF / MFAF / ADRF. For example, the service NF and / or (multiple) RAN nodes associated with the event reporting target can be regarded as data collectors, or based on local policies, event reporting target information can also be regarded as data collector 406.
[0123] In the second option (Option 2), the data consumer / data collection point related identification information is associated with OAM / NMS / MDAF / MnS. That is, in Option 2, the data collector 406 can be OAM / NMS / MDAF / MnS.
[0124] The open function 408 sends a monitoring event data open subscription / request message to the identified data collector 406. The message includes an event identifier (event ID) and / or (multiple) external analysis IDs, event reporting target information, and reporting type and / or cycle (if received in step 412).
[0125] Optionally, the open function 408 sends, for example, the application ID of the AF 410 that sends event data open subscription / request to the data collector 406 as identified:
[0126] In some embodiments, at 414, the open function 408 can query UDM / UDR / UDSF / NRF 404 by sending a request message (e.g., a data collection information request), which may include the application ID of AF 410 that sent the event data open subscription / request, and the received event reporting target information.
[0127] In response to sending a message, Open Function 408 may receive a response message (e.g., a data collection information response) that may include identification information (an ID / FQDN or address associated with NWDAF / DCCF / MFAF / ADRF or OAM / NMS / MDAF). Alternatively, Open Function 408 may receive a message (e.g., a data collection information response) that may include a "Open Not Allowed" indication corresponding to the application ID of AF 410.
[0128] If the open function 408 receives an "open not allowed" instruction from AF 410, the open function 408 can prevent or oppose opening to the data collector 406 of AF 410.
[0129] Steps 414, 432, and 440 may use any appropriate data collection function-related service operation messages to subscribe to / request, receive notifications / responses related to data openness, and provide monitoring results. Alternatively, steps 414, 432, and 440 may use appropriate openness-related network service operation messages or management service messages to allow data collector 406 to subscribe to external analysis-related data openness request notifications and to allow data collector 408 to provide anonymous input data to openness function 408 and receive monitoring results respectively.
[0130] At 416, data collector 406 requests or subscribes to a set of event IDs from data producer 402 by invoking the Nnf_EventExposure_Subscribe or Nnf_EventExposure_Request service operation, which may include event IDs. For example, this operation can be performed if process 400 follows option 1.
[0131] The (multiple) event IDs can be the event IDs received in step 414, or the data collector 406 can use a set of event IDs based on local configuration, which is associated with the external analysis IDs received in step 414.
[0132] Data collector 406 can check whether data should be collected for a user (i.e., SUPI or GPSI) or related network function / RAN node. According to local policies and regulations, data collector 406 can check user consent by obtaining user consent information from UDM / UDR / UDSF / NRF 404 using Nudm_SDM_Get, which includes the data type "User Consent" (if the event reporting target information indicates any UE ID). If user consent is not granted, data collector 406 does not subscribe to event openness for events related to that user, and data collection for that SUPI or GPSI ceases thereafter. Furthermore, if the event reporting target information indicates any NF ID / AF ID / RAN ID (e.g., gNB ID) or any UE ID, data collector 406 can check the privacy policy associated with the event ID / external analysis ID(s).
[0133] In some embodiments, when needed, the data collector 406 can unsubscribe from the set of event IDs(s) by invoking the Nnf_EventExposure_Unsubscribe service operation.
[0134] Reporting type or frequency can indicate whether reporting is immediate or periodic, and when or how often data can be collected and made available for external analysis.
[0135] In some embodiments, if the data producer 402 is a RAN node, the data collector 406 may send an EventExposure_Subscribe message to the data producer 402, which may include an event ID and an anonymity request flag (i.e., any indication that a privacy protection adaptation is required).
[0136] At 418, data producer 402 sends input data to data collector 406. For example, if data collector 406 subscribes to a set of event IDs, data producer 402 (i.e., NF) notifies data collector 406 of the input data (e.g., using event reports) by invoking the Nnf_EventExposure_Notify service operation based on event reporting information in the subscription. Furthermore, if data producer 402 is configured with such information associated with the event IDs, the input data message (e.g., the Nnf_EventExposure_Notify service message) may include an anonymity request flag.
[0137] At 420, based on a local policy, data collector 406 may be configured with an anonymity request flag associated with event(s) ID(s) or an external analytics ID associated with event(s). Alternatively, if data collector 406 receives an anonymity request flag from data producer 402 in step 418, data collector 406 may determine to extract privacy-adaptive data from UDM / UDR / UDSF / NRF 404 to apply the privacy-adaptive data to the collected input(s) set(s).
[0138] In this embodiment, at 422, based on local policies and anonymity requirements, data collector 406 determines to examine the privacy policy associated with the indicated event-based data collection input.
[0139] The data collector 406 sends a data collection policy request (i.e., Nudm / Nnf_Data collection policy request) to the UDM / UDR / UDSF / NRF 404. The data collection policy request may include (multiple) NF IDs, UE ID sets / group ID sets (based on event reporting target information), and (multiple) event IDs / external analysis IDs.
[0140] At position 424, UDM / UDR / UDSF / NRF 404 is pre-configured based on the operator's local policy and a privacy policy for data collection and disclosure. This privacy policy includes privacy-adapted datasets associated with various entities (e.g., NF ID, AFID, RAN node, UE ID / UE group ID, slice S-NSSAI), (multiple) external analytics IDs and / or (multiple) event IDs, as well as related "input data". Example privacy policies are shown in Table 2.1 below.
[0141] Privacy-adaptive data can include mappings of sensitive information to their associated privacy-protected IDs / names / codes (e.g., masking information).
[0142] At 426, based on the external analysis ID / (multiple) event ID and (multiple) NF ID / UE ID set / group ID set (i.e., event reporting target information), UDM / UDR / UDSF / NRF 404 extracts appropriate privacy-adaptive data (i.e., equivalent privacy-preserving data).
[0143] UDM / UDR / UDSF / NRF 404 sends a data collection policy response (i.e., Nudm / Nnf_Data collection policy response) to data collector 406. The data collection policy response may include (multiple) event IDs / external analysis IDs and (multiple) NFID / UE ID sets / group ID sets (i.e., event reporting target information) as well as specific privacy adaptation data.
[0144] In some embodiments, privacy-adapted data may include privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include input data, privacy requirements, and privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include privacy policies associated with event IDs / external analysis IDs(multiple).
[0145] In Option 2, as an alternative to steps 416-426, at 428, if data collection is not performed directly from data producer 402 (by following steps 416-426), data collector 406 may perform data collection from data producer 402 via OAM (i.e., OAM-based data collection). In this case, data collector 406 may subscribe to / request OAM and receive notifications from OAM, or receive data related to event-related privacy-preserving input data. This can be performed similarly to steps 416-418, but OAM manages the data collection from data producer 402 and provides the collected privacy-preserving data to data collector 406, rather than data producer 402 generating the input data. In the case of OAM-based data collection, collector 406 may perform steps 420-426, or only steps 420 and 430, for example, if privacy-adaptive data is configured in data collector 406 to enable the application of privacy protection / privacy adaptation to the collected input data, as described in step 430.
[0146] At 430, if data collector 406 determines that any one or more of the collected input data (associated with the event ID) are privacy-sensitive, then data collector 406 applies a privacy adaptation to the input data. Specifically, data collector 406 replaces, masks, or overwrites the privacy-sensitive input data with the received equivalent privacy-adapted data (i.e., produces a privacy-preserving version of the data).
[0147] In some embodiments, the data collector 406 is configured with privacy-adapted data or privacy policies for data collection and disclosure as described in Table 2.1. In this case, steps 422-426 can be omitted, and the data collector 406 can directly perform step 430, that is, the data collector 406 can apply privacy adaptation to the input data based on the configuration information.
[0148] At 432, the data collector 406 sends a monitoring event open notification / response message with privacy-protected input data (i.e., anonymous input data) to the data open function 408.
[0149] At 434, the open function 408 sends a monitoring event open notification / response message with privacy-preserving input data (i.e., anonymous input data) to AF 410.
[0150] At 436, using the received privacy-preserving input data, AF 410 performs data analysis and parsing based on operator implementations (e.g., using any AI / ML algorithm or intelligent tool, such as threat detection tools, security information and incident management (SIEM) tools, security orchestration, automation and response (SOAR) tools, etc.) for network security assessment and security monitoring / general monitoring.
[0151] At 438, AF 310 sends the monitoring results (i.e., external analysis output) to open function 408.
[0152] Monitoring results may include (multiple) trust values or reliability metrics that can be associated with the target information of the incident report. Trust values or reliability metrics can represent a range of reliability for the monitoring results, such as 0-20% = low, 21-50% = medium, 50-99% = high, and 100% = fully trustworthy.
[0153] Monitoring results can be related to the target information of the event report and can be specific to the indicated ID. Monitoring results may include cause codes, which can indicate whether any of the following have occurred: configuration problems, attack / threat alerts (e.g., DOS / DDoS / NF hijacking, malicious code injection, NF leaks, etc.), fault alerts, and / or flood alerts. Monitoring results may include anomalous behavior statistics / predictions (such as those listed in Tables 1.3 and 1.4 above), and / or time windows that external analytics consumers can use to rely on data up to that time window.
[0154] At 440, the open function 408 sends the received monitoring results to the data collector 406.
[0155] At 442, if any service consumer has subscribed to external analytics based on local configuration (e.g., associated with any (external) monitoring-related analytics ID), the data collector 406 can notify the monitoring results.
[0156] In this embodiment, if the RAN node acts as a data producer 402 at steps 416 and 418, any event open subscription / notification and request / response messages can be used.
[0157] In this embodiment, the data collector 406 can also perform data distribution.
[0158] In some implementations, the data collector 406 can initiate step 416 based on a local policy and can perform further steps.
[0159] Therefore, a privacy protection process 400 is provided.
[0160] Figure 5 The illustration shows an embodiment of the privacy protection process 500.
[0161] Process 500 involves data producers 502 (such as any NF, AF, or RAN), UDM 504 (or other administrative NFs, such as UDR, UDSF, or NRF), data consumers or collectors 506, open functions 508 (such as EGMF or NEF), and AF 510.
[0162] The AF 510 can reside within the carrier network or be located outside the carrier network, i.e., an external AF. The AF 510 can be considered to be in an untrusted domain.
[0163] Open Function 508 can be any function in the operator's network that facilitates requesting data collection and providing the collected data for external analysis / monitoring. In this embodiment, EGMF or NEF or any network function / management function can play the role of Open Function 508.
[0164] In this embodiment, the open function 508 performs privacy protection adaptation before the data is made public.
[0165] Process 500 is a method for determining a privacy adaptation based on a privacy policy, and applying the privacy adaptation to data by a data openness function 508 (e.g., any network openness function, management openness entity / function) to achieve privacy-preserving data collection and openness via the openness function 508. The privacy adaptation described in this embodiment (e.g., transforming / aggregating / mapping privacy-sensitive data or replacing privacy-sensitive data with equivalent privacy-preserving data) can be a service provided by a logical function co-located with the openness function 508, or it can be a standalone function. In the latter case, the openness function 508 can request and receive the privacy adaptation service (e.g., by providing input data and receiving privacy-preserving input data).
[0166] Process 500 begins at 512, where AF 510 sends a monitoring event data open subscription / request message to open function 508. This message includes the event identifier (event ID) / (multiple) external analysis IDs, event reporting target information, and optional reporting type and / or period.
[0167] Event reporting target information can indicate (multiple) objects whose data is requested to enable analysis and monitoring. It can indicate entities such as a specific UE, a group (multiple) UEs, or any UE (i.e., all UEs), network functions, application functions, RAN nodes, etc.
[0168] In some embodiments, event reporting target information may be considered as “external analysis report or monitoring target information” or “event reporting target external ID”.
[0169] If step 512 involves a NEF playing the role of open function 508, then steps 512, 532, and 536 may use any appropriate NEF-related service operation message. Alternatively, if step 512 involves any other management domain function playing the role of open function 508, then steps 512, 532, and 536 may use any appropriate management-related service message.
[0170] At 514, based on local configuration or by querying UDM / UDR / UDSF / NRF 504, open function 508 identifies the data collector 506 specific to the received event report target information.
[0171] In the first option (Option 1), the data collector-related identification information is associated with NWDAF / DCCF / MFAF / ADRF. That is, in Option 1, data collector 506 can be NWDAF / DCCF / MFAF / ADRF. For example, the service NF and / or (multiple) RAN nodes associated with the event reporting target can be regarded as data collectors, or based on local policies, event reporting target information can also be regarded as data collector 506.
[0172] In the second option (Option 2), the data consumer / data collection point related identification information is associated with OAM / NMS / MDAF / MnS. That is, in Option 2, the data collector 506 can be OAM / NMS / MDAF / MnS.
[0173] The open function 508 sends a monitoring event data open subscription / request message to the identified data collector 506. The message includes an event identifier (event ID) and / or (multiple) external analysis IDs, event reporting target information, and reporting type and / or cycle (if received in step 512).
[0174] Optionally, the open function 508 sends, for example, the application ID of the AF 510 that sends event data open subscription / request to the data collector 406 as identified:
[0175] In some embodiments, at 514, the open function 508 can query UDM / UDR / UDSF / NRF 504 by sending a request message (e.g., a data collection information request), which may include the application ID of AF 510 that sent the event data open subscription / request, and the received event reporting target information.
[0176] In response to sending a message, Open Function 508 may receive a response message (e.g., a data collection information response) that may include identification information (an ID / FQDN or address associated with NWDAF / DCCF / MFAF / ADRF or OAM / NMS / MDAF). Alternatively, Open Function 508 may receive a message (e.g., a data collection information response) that may include a "Open Not Allowed" indication corresponding to the application ID of AF 510.
[0177] If the open function 508 receives an "open not allowed" instruction from AF 510, the open function 508 can prevent or oppose opening to the data collector 406 of AF 510.
[0178] Steps 514, 522, and 538 may use any appropriate data collection function-related service operation messages to subscribe to / request, receive notifications / responses related to data openness, and provide monitoring results. Alternatively, steps 514, 522, and 538 may use appropriate openness-related network service operation messages or management service messages to allow data collector 506 to subscribe to external analysis-related data openness request notifications, and to allow data collector 504 to provide anonymous input data to openness function 508 and receive monitoring results respectively.
[0179] At 516, data collector 506 requests or subscribes to a set of event IDs (which may include multiple event IDs) from data producer 502 by invoking the Nnf_EventExposure_Subscribe or Nnf_EventExposure_Request service operation. For example, this operation can be performed if process 500 follows option 1.
[0180] The (multiple) event IDs can be the event IDs received in step 514, or the data collector 506 can use a set of event IDs based on local configuration, which is associated with the external analysis IDs received in step 514.
[0181] Data collector 506 can check whether data should be collected for a user (i.e., SUPI or GPSI) or related network function / RAN node. According to local policies and regulations, data collector 506 can check user consent by using Nudm_SDM_Get to obtain user consent information from UDM / UDR / UDSF / NRF 504 (if the event reporting target information indicates any UE ID), including the data type "user consent". If user consent is not granted, data collector 506 does not subscribe to event openness for events related to that user, and data collection for that SUPI or GPSI ceases thereafter. Furthermore, if the event reporting target information indicates any NF ID / AF ID / RAN ID (e.g., gNB ID) or any UE ID, data collector 506 can check the privacy policy associated with the event ID / external analysis ID(s).
[0182] In some embodiments, when needed, the data collector 506 can unsubscribe from the set of event IDs(s) by invoking the Nnf_EventExposure_Unsubscribe service operation.
[0183] Reporting type or frequency can indicate whether reporting is immediate or periodic, and when or how often data can be collected and made available for external analysis.
[0184] In some embodiments, if the data producer 502 is a RAN node, the data collector 406 may send an EventExposure_Subscribe message to the data producer 502, which may include event IDs(s).
[0185] At point 518, data producer 502 sends input data to data collector 506. For example, if data collector 506 subscribes to a set of event IDs, data producer 502 (i.e., NF) notifies data collector 506 of the input data (e.g., with event reports) by invoking the Nnf_EventExposure_Notify service operation based on event reporting information in the subscription. Furthermore, if data producer 502 is configured with such information associated with the event IDs, the input data message (e.g., the Nnf_EventExposure_Notify service message) may include an anonymity request flag.
[0186] In Option 2, as an alternative to steps 516-518, at 520, if data collection is not performed directly from data producer 502 (by following steps 516-518), data collector 506 may perform data collection from data producer 502 via OAM (i.e., OAM-based data collection). In this case, data collector 506 may subscribe to / request OAM and receive notifications from OAM, or receive data related to event-related privacy-preserving input data. This can be performed similarly to steps 516-518, but OAM manages the data collection from data producer 502 and provides the collected event-related privacy-preserving data to data collector 506, instead of data producer 502 generating the input data.
[0187] At point 522, data collector 506 sends a monitoring event open notification / response message with the collected input data and an anonymity request flag to data open function 508.
[0188] Based on local policies, data collector 506 can be configured with an anonymity request flag associated with event(s) or an external analytics ID associated with event(s). Alternatively, if data collector 506 receives an anonymity request flag from data producer 502 in step 518, data collector 506 can include the anonymity request flag in the monitoring event open notification / response message at 522.
[0189] At 524, based on a local policy, the open function 508 can be configured with an anonymity request flag associated with one or more event IDs or an external analytics ID associated with one or more event IDs. Alternatively, if the open function 508 receives an anonymity request flag from the data collector 506 in step 522, the open function 508 performs steps 524-528 to apply privacy adaptation / protection to the input data before opening.
[0190] In this embodiment, based on local policies and anonymity requirements, open function 508 determines to examine the privacy policy associated with the indicated event-based data collection input.
[0191] Open Function 508 sends a data collection / open policy request (i.e., Nudm / Nnf_Data collection / open policy request) to UDM / UDR / UDSF / NRF 504. This request may include (multiple) NF IDs, UE ID sets / group ID sets (based on event reporting target information), and (multiple) event IDs / external analysis IDs.
[0192] At point 526, UDM / UDR / UDSF / NRF 504 pre-configures operator-local policies and data collection and open privacy policies. This privacy policy includes privacy-adaptive datasets associated with various entities (e.g., NF ID, AF ID, RAN node, UE ID / UE group ID, slice S-NSSAI), (multiple) external analytics IDs and / or (multiple) event IDs, and related "input data". Example privacy policies are shown in Table 3.1 below.
[0193] Privacy-adapted data can include mappings of sensitive information to their associated privacy-protected IDs / names / codes (e.g., masking information).
[0194] At 528, based on the external analysis ID / (multiple) event ID and (multiple) NF ID / UE ID set / group ID set (i.e., event reporting target information), UDM / UDR / UDSF / NRF 504 extracts appropriate privacy-adaptive data (i.e., equivalent privacy-preserving data).
[0195] UDM / UDR / UDSF / NRF 504 sends a data collection policy response (i.e., Nudm / Nnf_Data collection policy response) to Open Function 508. This data collection policy response may include (multiple) event IDs / external analysis IDs and (multiple) NFID / UE ID sets / group ID sets (i.e., event reporting target information) as well as specific privacy adaptation data.
[0196] In some embodiments, privacy-adapted data may include privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include input data, privacy requirements, and privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include privacy policies associated with event IDs / external analysis IDs(multiple).
[0197] At point 530, if Open Function 508 determines that any one or more of the collected input data (associated with the event ID) are privacy-sensitive, Open Function 508 applies a privacy adaptation to the input data. Specifically, Open Function 508 replaces, masks, or overwrites the privacy-sensitive input data with the received equivalent privacy-adapted data (i.e., privacy-preserving data / data retention version).
[0198] In some embodiments, the open function 508 is configured with privacy-adapted data or privacy policies for data collection and openness as described in Table 3.1. In this case, steps 524-528 can be omitted, and the open function 508 can directly perform step 530, that is, the open function 508 can apply privacy adaptation to the input data based on the configuration information.
[0199] At 532, the open function 508 sends a monitoring event open notification / response message with privacy-preserving input data (i.e., anonymous input data) to AF 510.
[0200] At point 534, using the received privacy-preserving input data, AF 510 performs data analysis and parsing based on operator implementations (e.g., using any AI / ML algorithm or intelligent tool, such as threat detection tools, security information and incident management (SIEM) tools, security orchestration, automation and response (SOAR) tools, etc.) for network security assessment and security monitoring / general monitoring.
[0201] At 536, AF 510 sends the monitoring results (i.e., external analysis output) to open function 508.
[0202] Monitoring results may include (multiple) trust values or reliability metrics that can be associated with the target information of the incident report. Trust values or reliability metrics can represent a range of reliability for the monitoring results, such as 0-20% = low, 21-50% = medium, 50-99% = high, and 100% = fully trustworthy.
[0203] Monitoring results can be related to the target information of the event report and can be specific to the indicated ID. Monitoring results may include cause codes, which can indicate whether any of the following have occurred: configuration problems, attack / threat alerts (e.g., DOS / DDoS / NF hijacking, malicious code injection, NF leaks, etc.), fault alerts, and / or flood alerts. Monitoring results may include anomalous behavior statistics / predictions (such as those listed in Tables 1.3 and 1.4 above), and / or time windows that external analytics consumers can use to rely on data up to that time window.
[0204] At point 538, the open function 508 sends the received monitoring results to the data collector 506.
[0205] At 540, if any service consumer has subscribed to external analytics based on local configuration (e.g., associated with any (external) monitoring-related analytics ID), the data collector 506 can notify the monitoring results.
[0206] In this embodiment, if the RAN node acts as a data producer 502 at steps 516 and 518, any event open subscription / notification and request / response messages can be used.
[0207] In this embodiment, the data collector 506 can also perform data distribution.
[0208] In some implementations, the data collector 506 can initiate step 516 based on a local policy and can perform further steps.
[0209] Open function 508 can be an Open Governance Management Function (EGMF) as defined in TS 28.533. Open function 508 can be an MnF that provides management capabilities Open Governance (MCEG) as described in TR 28.824.
[0210] Therefore, a privacy protection process 500 is provided.
[0211] Figure 6 An embodiment of the privacy protection process 600 is illustrated.
[0212] Process 600 involves data producers 602 (such as any NF, AF, or RAN), UDM 604 (or other administrative NFs, such as UDR, UDSF, or NRF), data consumers or collectors 606, and AF 608.
[0213] AF 608 can reside within the carrier network or be located outside the carrier network, i.e., an external AF. AF 608 can be considered to be in a trusted domain.
[0214] In this embodiment, data producer 602 performs privacy protection adaptation before the data is made public.
[0215] Process 600 is a method for determining a privacy adaptation based on a privacy policy, and for data producer 602 to apply the privacy adaptation to data to enable privacy-preserving data collection and disclosure. The privacy adaptation described in this embodiment (e.g., transforming / aggregating / mapping privacy-sensitive data or replacing privacy-sensitive data with equivalent privacy-preserving data) can be a service provided by a logical function co-located with data producer 602, or it can be a standalone function. In the latter case, data producer 602 can request and receive the privacy adaptation service (e.g., by providing input data and receiving privacy-preserving input data).
[0216] Process 600 begins at 612, where AF 608 sends a monitoring event data open subscription request message to data collector 606. This monitoring event data open subscription request message includes an event identifier (event ID) / (multiple) external analysis IDs, event reporting target information, and optional reporting type and / or period.
[0217] Event reporting target information can indicate (multiple) objects whose data is requested for analysis and monitoring. It can indicate entities such as a specific UE, a group (multiple) UEs, or any UE (i.e., all UEs), network functions, application functions, RAN nodes, etc.
[0218] In some embodiments, event reporting target information may be considered as “external analysis report or monitoring target information” or “event reporting target external ID”.
[0219] Based on local configuration or by querying UDM / UDR / UDSF / NRF 604, AF 608 identifies data collectors 606 specific to event reporting target information (e.g., identification information related to data consumers / data collection points associated with NWDAF / DCCF / MFAF / ADRF) (e.g., service NF / RAN nodes associated with event reporting targets can be considered data collectors, or event reporting target information can also be considered data collectors based on local policies).
[0220] In the first option (Option 1), the data collector-related identification information is associated with NWDAF / DCCF / MFAF / ADRF. That is, in Option 1, the data collector 606 can be NWDAF / DCCF / MFAF / ADRF. For example, the service NF and / or (multiple) RAN nodes associated with the event reporting target can be considered as data collectors, or event reporting target information can also be considered as data collectors based on local policies.
[0221] Alternatively, based on local configuration or by querying UDM / UDR / UDSF / NRF 604 or any management function (e.g., the management repository function in TS 28.537 or the MnS discovery service producer), AF 608 identifies the data collector 606 (e.g., data consumer / data collection point related identification information associated with OAM / NMS / MDAF / MnS) that is specific to the event reporting target information.
[0222] In the second option (Option 2), the data consumer / data collection point related identification information is associated with OAM / NMS / MDAF / MnS. That is, in Option 2, the data collector 506 can be OAM / NMS / MDAF / MnS.
[0223] Steps 612, 628, and 632 may use any data collection function-related service operation message to subscribe to / request, receive notifications / responses related to data openness, and receive or provide monitoring results. Alternatively, steps 612, 628, and 632 may use appropriate openness-related network service operation messages or management service messages to allow AF 608 to subscribe to external analysis-related data openness requests / notifications and receive anonymous input from data collector 606 and receive or provide monitoring results, respectively.
[0224] At 614, data collector 606 requests or subscribes to a set of event IDs (which may include multiple event IDs) from data producer 302 by invoking the Nnf_EventExposure_Subscribe or Nnf_EventExposure_Request service operation, which may include multiple event IDs. For example, this operation can be performed if process 600 follows option 1.
[0225] The (multiple) event IDs can be the event IDs received in step 612, or the data collector 606 can use a set of event IDs based on local configuration, which is associated with the external analytics IDs received in step 612. The data collector 606 may include an anonymity request flag (i.e., any indication that a privacy-preserving adaptation is required) in its message at 614.
[0226] Data collector 606 can check whether data needs to be collected for users (i.e., SUPI or GPSI) or related network functions / RAN nodes.
[0227] According to local policies and regulations, data collector 606 can check user consent by retrieving user consent information from UDM / UDR / UDSF / NRF 604 using Nudm_SDM_Get, which includes the data type "User Consent". For example, this can be done if the event reporting target information indicates any UE ID. If user consent is not granted, data collector 606 does not subscribe to event openness for events related to that user, and data collection for that SUPI or GPSI ceases. If the event reporting target information indicates any NF ID / AF ID / RAN ID (e.g., gNB ID) or any UE ID, the data collector can check the privacy policy associated with the event ID / external analytics ID(s).
[0228] In some embodiments, when needed, the data collector 606 can unsubscribe from the set of event IDs(s) by invoking the Nnf_EventExposure_Unsubscribe service operation.
[0229] Reporting type or frequency can indicate whether reporting is immediate or periodic, and when or how often data can be collected and made available for external analysis.
[0230] In some embodiments, if the data producer 602 is a RAN node, the data collector 606 may send an EventExposure_Subscribe message to the data producer 602, which may include an event ID and an anonymity request flag (i.e., any indication that a privacy protection adaptation is required).
[0231] Data collector 606 (i.e., data consumer, such as NWDAF) can send messages directly or request event exposure via DCCF. In the latter case, data collector 606 can subscribe to data via DCCF by invoking the Ndccf_DataManagement_Subscribe (Service_Operation, Data Specification, Formatting Instruction, Processing Instruction, NF (or NF set) ID, ADRF Information) service operation. Data collector 606 can specify one or more notification endpoints. Service_Operation is the service operation to be used by DCCF to request data (e.g., Namf / Nnf_EventExposure_Subscribe or OAM subscription) from the data source (i.e., data producer 602). Data Specification provides service operation-specific parameters for retrieving data (e.g., event ID, (multiple) UE-IDs, event reporting target received in 602, etc.). DCCF determines (multiple) NF types and / or OAM based on the requested service operation to retrieve the data. If data collector 606 does not provide an NF instance or NF set ID, DCCF determines the NF instance from which data can be provided based on the received event ID and local configuration (i.e., one or more data sources can be configured from which data associated with the event ID will be collected). When new output data is available, the data source sends the data to DCCF using Nnf_EventExposure_Notify. DCCF uses Ndccf_DataManagement_Notify to send the data to all notification endpoints indicated in step 614. The data sent to the notification endpoints can be processed and formatted by DCCF so that they conform to the delivery requirements of each data consumer or notification endpoint.
[0232] At point 616, based on local policies and the received anonymity request instructions, data producer 602 determines to examine the privacy policy related to the instructed event-based data collection.
[0233] The data producer 602 sends a data collection policy request (i.e., Nudm / Nnf_Data collection policy request) to UDM / UDR / UDSF / NRF 604. The data collection policy request may include (multiple) NF IDs, UE ID sets / group ID sets (based on event reporting target information), and (multiple) event IDs and / or external analysis IDs.
[0234] At point 618, UDM / UDR / UDSF / NRF 604 pre-configures operator-local policies and data collection and open privacy policies. This privacy policy includes privacy-adaptive datasets associated with various entities (e.g., NF ID, AF ID, RAN node, UE ID / UE group ID, slice S-NSSAI), (multiple) external analytics IDs and / or (multiple) event IDs, and related "input data." Example privacy policies are shown in Table 1.1 above.
[0235] Privacy-adapted data includes mappings of sensitive information to their associated privacy-protected IDs / names / codes (e.g., masking information).
[0236] At 620, based on the external analysis ID / (multiple) event ID and (multiple) NF ID / UE ID set / group ID set (i.e., event reporting target information), UDM / UDR / UDSF / NRF 604 extracts appropriate privacy-adaptive data (i.e., equivalent privacy-preserving data).
[0237] UDM / UDR / UDSF / NRF 604 sends a data collection policy response (i.e., Nudm / Nnf_Data collection policy response) to data producer 602. The data collection policy response may include (multiple) event IDs / external analysis IDs and (multiple) NFID / UE ID sets / group ID sets (i.e., event reporting target information) as well as specific privacy adaptation data.
[0238] In some embodiments, privacy-adapted data may include privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include input data, privacy requirements, and privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include privacy policies associated with event IDs / external analysis IDs(multiple).
[0239] At 622, if data producer 602 determines that any one or more of the collected / input data are privacy-sensitive data, then data producer 602 applies a privacy adaptation to that input data. Specifically, data producer 602 (i.e., replaces, masks, or covers the privacy-sensitive input data with the received equivalent privacy-adapted data (i.e., a privacy-preserving version of the data)).
[0240] In some embodiments, data producer 602 is configured with privacy-adapted data or privacy policies for data collection and disclosure as described in Table 1.1. In this case, steps 616-620 can be omitted, and data producer 602 can apply privacy adaptation to the input data based on the configuration information.
[0241] At 624, data producer 602 sends privacy-preserving (i.e., anonymous) input data to data collector 606. For example, if data collector 606 subscribes to a set of event IDs, data producer 602 notifies data collector 606 of the privacy-preserving (i.e., anonymous) input data (e.g., utilizing event reports) by invoking the Nnf_EventExposure_Notify service operation based on event reporting information in the subscription. This operation can be performed, for example, if process 600 follows option 1.
[0242] In Option 2, as an alternative to steps 616-624, at 626, if data collection is not performed directly from data producer 602 (by following steps 616-624), data collector 606 may perform data collection from data producer 602 via OAM (i.e., OAM-based data collection). In this case, data collector 606 may subscribe to / request OAM and receive notifications from OAM, or receive data related to event-related privacy-preserving input data. This can be performed similarly to steps 614-624, but OAM manages the data collection from data producer 602 and provides the collected privacy-preserving data to data collector 606, rather than data producer 602 generating the input data. In the case of OAM-based data collection, data producer 602 may perform steps 616-624, or only step 624, for example, if privacy-adaptive data is configured in data producer 602 to allow OAM to extract privacy-preserving input data from data producer 602 and provide it to data collector 606.
[0243] At 628, data collector 606 sends a monitoring event open notification / response message with privacy-preserving input data (i.e., anonymous input data) to AF 608.
[0244] At 630, using the received privacy-preserving input data, AF 608 performs data analysis and parsing based on operator implementations (e.g., using any AI / ML algorithm or intelligent tool, such as threat detection tools, security information and incident management (SIEM) tools, security orchestration, automation and response (SOAR) tools, etc.) for network security assessment and security monitoring / general monitoring.
[0245] At 632, AF 608 sends the monitoring results (i.e., external analysis output) to data collector 606.
[0246] Monitoring results may include (multiple) trust values or reliability metrics that can be associated with the target information of the incident report. Trust values or reliability metrics can represent a range of reliability for the monitoring results, such as 0-20% = low, 21-50% = medium, 50-99% = high, and 100% = fully trustworthy.
[0247] Monitoring results can be related to the target information in the event report and can be specific to the indicated ID. Monitoring results may include cause codes, which can indicate whether any of the following occurred: configuration issues, attack / threat alerts (e.g., DOS / DDoS / NF hijacking, malicious code injection, NF leaks, etc.), fault alerts, and / or flood alerts. Monitoring results may include anomalous behavior statistics / predictions (those listed in Tables 1.3 and 1.4 below), and / or time windows that external analytics consumers can use to rely on data up to that time window.
[0248] At 634, if any service consumer has subscribed to external analytics based on local configuration (e.g., associated with any (external) monitoring-related analytics ID), the data collector 606 can notify the monitoring results.
[0249] In this embodiment, the data collector 606 can also perform data distribution.
[0250] In some implementations, the data collector 606 can initiate step 614 based on a local policy and can perform further steps.
[0251] Therefore, a privacy protection process 600 is provided.
[0252] Figure 7 An embodiment of the privacy protection process 700 is illustrated.
[0253] Process 700 involves data producers 702 (such as any NF, AF, or RAN), UDM 704 (or other administrative NFs, such as UDR, UDSF, or NRF), data consumers or collectors 706, and AF 708.
[0254] The AF 708 can reside within the carrier network or be located outside the carrier network, i.e., an external AF.
[0255] In this embodiment, the data collector 706 performs privacy protection adaptation before the data is made public.
[0256] Process 700 is a method for determining a privacy adaptation based on a privacy policy, and for applying this privacy adaptation to data by a data collector 706 (e.g., any network function such as NWDAF / DCCF / MFAF / ADRF, application function, management function) to enable privacy-preserving data collection and openness. The privacy adaptation described in this embodiment (e.g., transforming / aggregating / mapping privacy-sensitive data or replacing privacy-sensitive data with equivalent privacy-preserving data) can be a service provided by a logical function co-located with the data collector 706, or it can be a standalone function. In the latter case, the data collector 706 can request and receive the privacy adaptation service (e.g., by providing input data and receiving privacy-preserving input data).
[0257] Process 700 begins at 712, where AF 708 sends a monitoring event data open subscription / request message to data collector 706. This message includes the event identifier (event ID) / (multiple) external analysis IDs, event reporting target information, and optional reporting type and / or period.
[0258] Event reporting target information can indicate (multiple) objects whose data is requested for analysis and monitoring. It can indicate entities such as a specific UE, a group (multiple) UEs, or any UE (i.e., all UEs), network functions, application functions, RAN nodes, etc.
[0259] In some embodiments, event reporting target information may be considered as "external analysis report or monitoring target information" or "event reporting target external ID".
[0260] Based on local configuration or by querying UDM / UDR / UDSF / NRF 704, AF 708 identifies data collectors 706 specific to event reporting target information (e.g., identification information related to data consumers / data collection points associated with NWDAF / DCCF / MFAF / ADRF) (e.g., service NF / RAN nodes associated with event reporting targets can be considered data collectors, or event reporting target information can also be considered data collectors based on local policies).
[0261] In the first option (Option 1), the data collector-related identification information is associated with NWDAF / DCCF / MFAF / ADRF. That is, in Option 1, data collector 706 can be NWDAF / DCCF / MFAF / ADRF. For example, the service NF and / or (multiple) RAN nodes associated with the event reporting target can be regarded as data collectors, or based on local policies, event reporting target information can also be regarded as data collector 706.
[0262] Alternatively, based on local configuration or by querying UDM / UDR / UDSF / NRF 704 or any management function (e.g., the management repository function in TS 28.537 or the MnS discovery service producer), AF 708 identifies the data collector 706 specific to the event reporting target information (e.g., data consumer / data collection point related identification information associated with OAM / NMS / MDAF / MnS).
[0263] In the second option (Option 2), the data consumer / data collection point related identification information is associated with OAM / NMS / MDAF / MnS. That is, in Option 2, the data collector 706 can be OAM / NMS / MDAF / MnS.
[0264] Steps 712, 730, and 734 may use any appropriate data collection function-related service operation messages to subscribe to / request, receive notifications / responses related to data openness, and provide monitoring results. Alternatively, steps 712, 730, and 734 may use appropriate openness-related network service operation messages or management service messages to allow AF 708 to subscribe to external analysis-related data openness requests / notifications, receive anonymous input from data collector 706, and provide monitoring results respectively.
[0265] At 714, data collector 706 requests or subscribes to a set of event IDs from data producer 702 by invoking the Nnf_EventExposure_Subscribe or Nnf_EventExposure_Request service operation, which may include multiple event IDs. For example, this operation can be performed if process 700 follows option 1.
[0266] The (multiple) event IDs can be the event IDs received in step 712, or the data collector 706 can use a set of event IDs based on local configuration, which is associated with the external analysis IDs received in step 712.
[0267] Data collector 706 can check whether data should be collected for a user (i.e., SUPI or GPSI) or related network function / RAN node. According to local policies and regulations, data collector 706 can check user consent by obtaining user consent information from UDM / UDR / UDSF / NRF 704 using Nudm_SDM_Get, which includes the data type "User Consent" (if the event reporting target information indicates any UE ID). If user consent is not granted, data collector 706 does not subscribe to event openness for events related to that user, and data collection for that SUPI or GPSI ceases. Furthermore, if the event reporting target information indicates any NF ID / AF ID / RAN ID (e.g., gNB ID) or any UE ID, data collector 706 can check the privacy policy associated with the event ID / external analysis ID(s).
[0268] In some embodiments, when needed, the data collector 706 can unsubscribe from the set of event IDs(s) by invoking the Nnf_EventExposure_Unsubscribe service operation.
[0269] Reporting type or frequency can indicate whether reporting is immediate or periodic, and when or how often data can be collected and made available for external analysis.
[0270] In some embodiments, if the data producer 702 is a RAN node, the data collector 706 may send an EventExposure_Subscribe message to the data producer 702, which may include an event ID and an anonymity request flag (i.e., any indication that a privacy protection adaptation is required).
[0271] Data collector 706 (i.e., data consumer, such as NWDAF) can send messages directly or request event exposure via DCCF. In the latter case, data collector 706 subscribes to data via DCCF by invoking the Ndccf_DataManagement_Subscribe (Service_Operation, Data Specification, Formatting Instructions, Processing Instructions, NF (or NF set) ID, ADRF Information) service operation. The formatting instructions may include privacy-adaptive data / anonymity request flags. Data collector 706 may specify one or more notification endpoints. Service_Operation is the service operation to be used by DCCF to request data (e.g., Namf / Nnf_EventExposure_Subscribe or OAM subscription) from the data source (i.e., data producer 702). The data specification provides service operation-specific parameters for obtaining data (e.g., event ID, (multiple) UE-IDs, event reporting target received in step 712). DCCF determines (multiple) NF types and / or OAM based on the requested service operation to obtain data. If data collector 706 does not provide an NF instance or NF set ID, DCCF determines the NF instance from which data can be provided based on the received event ID and local configuration (i.e., one or more data sources can be configured from which data related to the event ID will be collected). When new output data is available, the data source sends the data to DCCF using Nnf_EventExposure_Notify. DCCF then sends the data to all notification endpoints indicated in step 714 using Ndccf_DataManagement_Notify. Data sent to notification endpoints can be processed and formatted by the DCCF so that it conforms to the delivery requirements for each data consumer or notification endpoint (i.e., if the DCCF receives a formatting instruction associated with a privacy-adapted data / anonymity request flag, it can apply privacy protection to the data (i.e., convert privacy-sensitive data into privacy-protected data). Based on one implementation, as an alternative, if the formatting and processing instructions include an anonymity request flag or privacy-adapted data, the DCCF can perform security / privacy filtering or masking on the collected data. In one implementation, the DCCF can be configured with privacy-adapted data, or this data can be extracted from UDM / UDR / UDSF / NRF 704. When using a messaging framework, the DCCF sends formatting and / or processing instructions to the messaging framework via the Nmfaf_3daData_Management service so that the MFAF can format and / or process the data before sending notifications to data consumers / notification endpoints. When using data delivery via the DCCF, the DCCF performs formatting and / or processing before sending notifications.
[0272] At 716, data producer 702 sends input data to data collector 706. For example, if data collector 706 subscribes to a set of event IDs, data producer 702 (i.e., NF) notifies data collector 706 of the input data (e.g., utilizing event reports) by invoking the Nnf_EventExposure_Notify service operation based on event reporting information in the subscription. Furthermore, if data producer 702 is configured with such information associated with the event IDs, the input data message (e.g., the Nnf_EventExposure_Notify service message) may include an anonymity request flag.
[0273] At 718, based on a local policy, data collector 706 may be configured with an anonymity request flag associated with event(s) ID(s) or an external analytics ID associated with event(s). Alternatively, if data collector 706 receives an anonymity request flag from the data producer in step 716, data collector 706 may determine to extract privacy-adaptive data from UDM / UDR / UDSF / NRF 704 to apply the privacy-adaptive data to the collected input(s) set(s).
[0274] In this embodiment, at 720, based on local policies and anonymity requirements, the data collector 706 determines to examine the privacy policy associated with the indicated event-based data collection input.
[0275] The data collector 706 sends a data collection policy request (i.e., Nudm / Nnf_Data collection policy request) to the UDM / UDR / UDSF / NRF 704. The data collection policy request may include (multiple) NF IDs, UE ID sets / group ID sets (based on event reporting target information), and (multiple) event IDs / external analysis IDs.
[0276] At point 722, UDM / UDR / UDSF / NRF 704 pre-configures operator-local policies and data collection and open privacy policies. This privacy policy includes privacy-adaptive datasets associated with various entities (e.g., NF ID, AF ID, RAN node, UE ID / UE group ID, slice S-NSSAI), (multiple) external analytics IDs and / or (multiple) event IDs, and related "input data." Example privacy policies are shown in Table 2.1 above.
[0277] Privacy-adapted data can include mappings of sensitive information to their associated privacy-protected IDs / names / codes (e.g., masking information).
[0278] At 724, based on the external analysis ID / (multiple) event ID and (multiple) NF ID / UE ID set / group ID set (i.e., event reporting target information), UDM / UDR / UDSF / NRF 704 extracts appropriate privacy-adaptive data (i.e., equivalent privacy-preserving data).
[0279] UDM / UDR / UDSF / NRF 704 sends a data collection policy response (i.e., Nudm / Nnf_Data collection policy response) to data collector 706. The data collection policy response may include (multiple) event IDs / external analysis IDs and (multiple) NFID / UE ID sets / group ID sets (i.e., event reporting target information) as well as specific privacy adaptation data.
[0280] In some embodiments, privacy-adapted data may include privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include input data, privacy requirements, and privacy-preserving data equivalent to the input data used for event / external analysis. In some embodiments, privacy-adapted data may include privacy policies associated with event IDs / external analysis IDs(multiple).
[0281] In Option 2, as an alternative to steps 714-724, at 726, if data collection is not performed directly from data producer 702 (by following steps 714-724), data collector 706 can perform data collection from the data producer via OAM (i.e., OAM-based data collection). In this case, data collector 706 can subscribe to / request OAM and receive data related to event-related privacy-preserving input data from OAM. This can be performed similarly to steps 714-724, but OAM manages the data collection from data producer 702 and provides the collected privacy-preserving data to data collector 706, rather than data producer 702 generating the input data. In the case of OAM-based data collection, data collector 706 can perform steps 718-728, or only steps 718 and 728, for example, if privacy-adaptive data is configured in data collector 706 to enable the application of privacy protection / privacy adaptation to the collected input data, as described in step 728.
[0282] At 728, if the data collector 706 determines that any one or more of the collected input data (associated with the event ID) are privacy-sensitive, the data collector 706 applies a privacy adaptation to the input data. Specifically, the data collector 706 replaces, masks, or overwrites the privacy-sensitive input data with the received equivalent privacy-adapted data (i.e., produces a privacy-preserving version of the data).
[0283] In some embodiments, the data collector 706 is configured with privacy-adapted data or privacy policies for data collection and disclosure as described in Table 2.1. In this case, steps 720-724 can be omitted, and the data collector 706 can directly perform step 728, that is, the data collector 706 can apply privacy adaptation to the input data based on the configuration information.
[0284] At 730, data collector 706 sends a monitoring event open notification / response message with privacy-preserving input data (i.e., anonymous input data) to AF 708.
[0285] At 732, using the received privacy-preserving input data, AF 708 performs data analysis and parsing based on operator implementations (e.g., using any AI / ML algorithm or intelligent tool, such as threat detection tools, security information and incident management (SIEM) tools, security orchestration, automation and response (SOAR) tools, etc.) for network security assessment and security monitoring / general monitoring.
[0286] At 734, AF 310 sends the monitoring results (i.e., external analysis output) to data collector 706.
[0287] Monitoring results may include (multiple) trust values or reliability metrics that can be associated with the target information of the incident report. Trust values or reliability metrics can represent a range of reliability for the monitoring results, such as 0-20% = low, 21-50% = medium, 50-99% = high, and 100% = fully trustworthy.
[0288] Monitoring results can be related to the target information of the event report and can be specific to the indicated ID. Monitoring results may include cause codes, which can indicate whether any of the following have occurred: configuration problems, attack / threat alerts (e.g., DOS / DDoS / NF hijacking, malicious code injection, NF leaks, etc.), fault alerts, and / or flood alerts. Monitoring results may include anomalous behavior statistics / predictions (such as those listed in Tables 1.3 and 1.4 above), and / or time windows that external analytics consumers can use to rely on data up to that time window.
[0289] At 736, if any service consumer has subscribed to external analytics based on local configuration (e.g., associated with any (external) monitoring-related analytics ID), the data collector 706 can notify the monitoring results.
[0290] In this embodiment, if the RAN node acts as a data producer 702 at steps 714 and 716, any event open subscription / notification and request / response messages can be used.
[0291] In this embodiment, the data collector 706 can also perform data distribution.
[0292] In some implementations, the data collector 706 can initiate step 714 based on a local policy and can perform further steps.
[0293] Therefore, a privacy protection process 700 is provided.
[0294] An open function in a wireless communication network is provided, the open function comprising: at least one memory; and at least one processor coupled to the at least one memory and configured such that the open function: receives a request for data from a second network function NF (e.g., an application function), the second NF performing external analysis (e.g., external analysis and / or security monitoring) on the data; determines a third NF for sending the request for data; and sends the request for data and an application ID associated with the second NF to the third NF.
[0295] A request for data can be an event-based request. This request may include one or more event IDs and / or external analytics IDs (which may correspond to one or more event IDs). Open functionality may include or have access to a mapping of one or more external analytics IDs to a corresponding set of event IDs associated with those external analytics IDs. A request for data can be a monitoring event open subscription or request message. A monitoring event open subscription or request message can be a request or subscription request for event-based data that corresponds to one or more event IDs and / or external analytics IDs. One or more event IDs and / or external analytics IDs may be associated with external security monitoring, such as external security monitoring specific to external security monitoring.
[0296] One or more event IDs can identify one or more events selected from an event group, which consists of the following: abnormal behavior of network functions; violation of predefined service operation messages; violation of specified message inputs or outputs; messages exceeding preconfigured limits; resource utilization; authentication failures, such as repeated authentication failures; and authorization failures, such as repeated authorization failures.
[0297] Normal operation (e.g., permitted predefined message formats (e.g., between NFs, RANs and NFs, and between RANs for network communication), interface operation message exchange based on designated (SBI) services, etc.) can be considered normal behavior and are used as the baseline for identifying any violations and any formatted error messages to collect input data (e.g., any violation of normal designated behavior, i.e., the network function service inputs / outputs as specified in Clause 5.2 of TS 23.502).
[0298] Furthermore, depending on the operator implementation, NF / RAN can maintain a threshold (as a baseline) for message volume / service request processing capacity over a certain period. If this threshold is exceeded, this information can be collected as part of the input data (e.g., to identify whether any flooding attacks or denial-of-service attacks are being initiated or experienced). Depending on the operator implementation, this information can also be collected as part of the input data if any alerts arise due to configuration changes. This data can help identify any traces of attacks related to both active and passive attacks for security monitoring.
[0299] Resource utilization events can be information related to NF / network slice / RAN level load information. For example, resource utilization can refer to the usage of allocated virtual resources currently used by an NF instance (e.g., average utilization of virtual CPUs, memory, disks, etc.) and can belong to a specific network slice instance as defined in Clause 5.7 of TS 28.552 [8]. As another example, resource utilization threshold span can be: the number of times a resource utilization threshold is reached, exceeded, or crossed on a network slice instance, and the time when it occurs. This may occur if the consumer provides the threshold as an analysis filter. As another example, resource utilization threshold span time period (l..max) can be a resource utilization threshold span vector that includes the time elapsed between the times each threshold is reached, exceeded, or crossed on a network slice instance. This may occur if the consumer provides the threshold as an analysis filter.
[0300] Authentication failure events can be events that occur during the authentication process of the NF / RAN. Data related to the NF ID / RAN ID, as well as authentication failure status / information, authentication failure frequency, and the maximum number of authentication failures, can be maintained and collected as input data.
[0301] An authorization failure event can be an event that fails to grant authorization during the authorization process (e.g., for NF / RAN nodes). Data related to the corresponding NF ID / RAN ID, as well as authorization failure status / information, authorization failure frequency, maximum number of authorization failures, etc., can be maintained and collected as input data.
[0302] The second NF can be AF, such as the external AF.
[0303] The third NF can be a data consumer or collector selected from a group of data consumers or collectors, which consists of the following: Network Data Analysis Function (NWDAF); Data Collection Coordination Function (DCCF); Messaging Framework Adapter Function (MFAF); Analysis Data Repository Function (ADRF); Operation, Administration and Maintenance Function (OAM); Network Management System (NMS); and Management Data Analysis Service (MDAF).
[0304] At least one processor may also be configured to enable the following function: in response to receiving a request for data, to determine / identify a third NF, and to send the request for data and the application ID to that third NF.
[0305] At least one processor can also be configured to enable the following function: to determine / identify a third NF based on local configuration or by querying the management NF (such as UDM / UDR / UDSF / NRF).
[0306] At least one processor may also be configured to enable the open function to receive an indication that opening certain data (e.g., data related to the aforementioned or certain event IDs) from the third NF to the second NF is permitted / disallowed; and if an indication that opening is not permitted is received, to prevent or oppose the opening of certain data from the third NF to the second NF.
[0307] An indication that certain data from the third NF is not permitted to open to the second NF is received from an entity selected from an entity group consisting of: the third NF, for example, in response to sending an application ID to the third NF; and the fourth NF, for example, a management NF such as UDM / UDR / UDSF / NRF, to which the open function may have queried to identify the third NF.
[0308] At least one processor may also be configured to enable the following functions: receiving input data (i.e., requested data, which may be event-based data corresponding to a requested event ID, such as data associated with an external analytics ID) from a third NF, the input data including privacy-sensitive data (which may correspond to one or more event IDs); identifying corresponding privacy-adapted data for the privacy-sensitive data based on a privacy policy (which may be event-specific privacy-adapted data, such as event ID-specific privacy-adapted data); processing the input data to replace or mask the privacy-sensitive data using the corresponding privacy-adapted data, thereby generating privacy-preserving input data; and sending the privacy-preserving input data to a second NF.
[0309] Privacy-adapted data can be anonymized data, in which identifier details such as user, user device, location information, network slice identifier information, network location information and / or network function identifier entity information can be removed.
[0310] Privacy-adapted data may include mappings of privacy-sensitive information elements to their associated anonymized information (e.g., privacy-protected ID / name / code) to allow external use.
[0311] Privacy-adaptive data can typically be allocated by the operator as part of the configuration and can include “equivalent anonymized data or privacy-preserving data / privacy-retaining data / masked data / data for external use referred to as “external data””.
[0312] At least one processor can also be configured to indicate that input data received from a third NF will be subject to privacy protection.
[0313] At least one processor may also be configured to enable the technetium open function: in response to acquiring input data, send a policy request to a fourth NF for, for example, corresponding privacy adaptation data having one or more event IDs; and receive corresponding (event ID specific) privacy adaptation data from the fourth NF.
[0314] The fourth NF can be an NF selected from an NF group consisting of the following: a Unified Data Management (UDM) entity; a Unified Data Repository (UDR); an Unstructured Data Storage Function (UDSF); and a Network Repository Function (NRF); and is configured to maintain privacy policies for data collection and disclosure.
[0315] At least one processor may also be configured to enable the following function: in response to sending privacy-preserving input data to the second NF, receiving monitoring results based on the privacy-preserving input data from the second NF.
[0316] At least one processor can also be configured to enable the function of sending monitoring results to a third NF.
[0317] NF can be an open function selected from the Open Functions Group, which consists of the following: Open Governance Management Function (EGMF) or Network Open Function (NEF).
[0318] Data requests can specify the target data source, for example, by the NF ID, UEID, NF type, RAN ID, network slice ID, network slice instance, etc., which are related to the data to be collected.
[0319] A processor for wireless communication is also provided, the processor comprising: at least one controller coupled to at least one memory and configured such that the processor: receives a request for data from a second network function NF; and sends the request for data and an application ID associated with the second NF to a third NF.
[0320] Figure 8A flowchart of method 800 according to various aspects of this disclosure is illustrated. Operation of method 800 can be implemented using an open function described herein. In some implementations, the open function can execute a set of instructions to control the functional elements of the open function to perform the described functions.
[0321] Method 800 includes: receiving 802 a request for data from a second network function NF, the second NF performing external analysis (e.g., external analysis and / or security monitoring) on the data; determining 803 a third NF for sending the request for data; and sending 804 the request for data and an application ID associated with the second NF to the third NF.
[0322] The operations of receiving 802, determining 803, and the second 804 can be performed according to the examples described herein. In some implementations, aspects of the operations of receiving 802, determining 803, and the second 804 can be derived from references. Figure 11 The aforementioned open functions and / or references Figure 10 The processor executes the commands.
[0323] It should be noted that the method described in this paper describes one possible implementation, and the operations and steps can be rearranged or otherwise modified, and other implementations are also possible.
[0324] A network function in a network is provided. This network function is configured to: receive a request from an open function containing an external analytics ID and / or an application ID; determine which event IDs to collect for which data is associated with the external analytics ID and / or application ID; examine a privacy policy for event-based data collection; send an event open request to another network function, optionally with a data anonymization requirement indication; receive an event open response containing anonymized / privacy-protected input data; send a response containing anonymized / privacy-protected input data to the open function; and receive monitoring results.
[0325] Privacy policies may include one or more of the following: external analytics ID, event ID, and / or data anonymization requirements.
[0326] If the network function is a data collector, then an event open request can be sent to the data producer.
[0327] A network function in a network is provided. This network function is configured to: examine a privacy policy for event-based data collection; determine to apply privacy adaptations to the data; perform privacy adaptations on privacy-sensitive data; and send privacy-protected data to a second network function.
[0328] Privacy policies may include one or more of the following: one or more external analytics IDs and / or one or more event IDs, and optionally also include input data types, input data values, privacy requirements, equivalent privacy-protected input data values for external use, etc.
[0329] The network function can also be configured to receive data anonymity requests.
[0330] Network functions can be configured with data anonymity requirements specified by one or more event IDs.
[0331] Network functions can be configured to perform privacy adaptation by transforming / aggregating / mapping privacy-sensitive data or replacing privacy-sensitive data with equivalent privacy-preserving input data values for external use.
[0332] Figure 9 An example of a UE 900 according to various aspects of this disclosure is illustrated. The UE 900 may include a processor 902, a memory 904, a controller 906, and a transceiver 908. The processor 902, memory 904, controller 906, or transceiver 908, or various combinations thereof, or various components thereof, may be examples of parts for performing the various aspects of this disclosure described herein. These components may be coupled via one or more interfaces (e.g., operational ground, communication ground, functional ground, electronic ground, electrical ground).
[0333] Processor 902, memory 904, controller 906, or transceiver 908, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof, configured or otherwise supporting components for performing the functions described in this disclosure.
[0334] Processor 902 may include intelligent hardware devices (e.g., a general-purpose processor, DSP, CPU, ASIC, FPGA, or any combination thereof). In some implementations, processor 902 may be configured to operate memory 904. In some other implementations, memory 904 may be integrated into processor 902. Processor 902 may be configured to execute computer-readable instructions stored in memory 904 to cause UE 900 to perform various functions of this disclosure.
[0335] Memory 904 may include volatile or non-volatile memory. Memory 904 may store computer-readable, computer-executable code, including instructions that, when executed by processor 902, cause UE 900 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as memory 904 or another type of memory. Computer-readable media include both non-transitory computer storage media and communication media, including any medium that facilitates the transfer of computer programs from one place to another. Non-transitory storage media may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0336] In some implementations, processor 902 and memory 904 coupled to processor 902 may be configured such that UE 900 performs one or more functions described herein (e.g., processor 902 executes instructions stored in memory 904). For example, according to the examples disclosed herein, processor 902 may support wireless communication at UE 900. UE 900 may be configured to support components for performing privacy protections as described herein.
[0337] Controller 906 manages the input and output signals of UE 900. Controller 906 can also manage peripheral devices not integrated into UE 900. In some implementations, controller 906 can utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, controller 906 can be implemented as part of processor 902.
[0338] In some implementations, UE 900 may include at least one transceiver 908. In other implementations, UE 900 may have more than one transceiver 908. Transceiver 908 may represent a wireless transceiver. Transceiver 908 may include one or more receiver chains 910, one or more transmitter chains 912, or a combination thereof.
[0339] Receiver chain 910 can be configured to receive signals (e.g., control information, data, packets) via a wireless medium. For example, receiver chain 910 may include one or more antennas for receiving signals over the air or via a wireless medium. Receiver chain 910 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 910 may include at least one demodulator configured to demodulate the received signal and acquire transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 910 may include at least one decoder for decoding and processing the demodulated signal to receive transmitted data.
[0340] Transmitter chain 912 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 912 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 912 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 912 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0341] Figure 10 An example of a processor 1000 according to various aspects of this disclosure is illustrated. The processor 1000 may be an example of a processor configured to perform various operations according to the examples described herein. The processor 1000 may include a controller 1002 configured to perform various operations according to the examples described herein. The processor 1000 may optionally include at least one memory 1004, which may be, for example, an L1 / L2 / L3 cache. Additionally or alternatively, the processor 1000 may optionally include one or more arithmetic logic units (ALUs) 1006. One or more of these components may be electronically communicated or otherwise coupled (e.g., operative ground, communicative ground, functional ground, electronic ground, electrical ground) via one or more interfaces (e.g., buses).
[0342] Processor 1000 may be a processor chipset and includes a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receive, acquire, retrieve, send, output, forward, store, determine, identify, access, write, read) according to the examples described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to the processor chipset or included in the processor chipset (e.g., processor 1000)) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase-change memory (PCM), etc.).
[0343] Controller 1002 can be configured to manage and coordinate various operations of processor 1000 (e.g., signaling, receiving, acquiring, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, and reading) to enable processor 1000 to support various operations according to the examples described herein. For example, controller 1002 can operate as a control unit of processor 1000 to generate control signals for managing the operation of various components of processor 1000. These control signals include enabling or disabling functional units, selecting data paths, initiating memory accesses, and coordinating operation timing.
[0344] Controller 1002 may be configured to fetch (e.g., fetch, retrieve, receive) instructions from memory 1004 and determine subsequent instructions(s) to be executed, enabling processor 1000 to support various operations according to the examples described herein. Controller 1002 may be configured to track the memory addresses of instructions associated with memory 1004. Controller 1002 may be configured to decode instructions to determine the operations to be performed and the operands involved. For example, controller 1002 may be configured to interpret instructions and determine control signals to be output to other components of processor 1000, enabling processor 1000 to support various operations according to the examples described herein. Additionally or alternatively, controller 1002 may be configured to manage data flow within processor 1000. Controller 1002 may be configured to control data transfers between registers, arithmetic logic unit (ALU), and other functional units of processor 1000.
[0345] Memory 1004 may include one or more caches (e.g., memory local to processor 1000 or included therein, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc.). In some implementations, memory 1004 may reside within or on the processor chipset (e.g., locally to processor 1000). In some other implementations, memory 1004 may reside outside the processor chipset (e.g., remotely to processor 1000).
[0346] Memory 1004 may store computer-readable, computer-executable code, including instructions that, when executed by processor 1000, cause processor 1000 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as system memory or another type of memory. Controller 1002 and / or processor 1000 may be configured to execute computer-readable instructions stored in memory 1004 to cause processor 1000 to perform various functions. For example, processor 1000 and / or controller 1002 may be coupled to or coupled to memory 1004, and processor 1000, controller 1002, and memory 1004 may be configured to perform the various functions described herein. In some examples, processor 1000 may include multiple processors, and memory 1004 may include multiple memories. One or more of the multiple processors may be coupled to one or more of the multiple memories, which may be configured individually or collectively to perform the various functions described herein.
[0347] One or more ALU 1006s can be configured to support a variety of operations as described in the examples herein. In some implementations, one or more ALU 1006s may reside within or on a processor chipset (e.g., processor 1000). In some other implementations, one or more ALU 1006s may reside outside the processor chipset (e.g., processor 1000). One or more ALU 1006s can perform one or more calculations on data, such as addition, subtraction, multiplication, and division. For example, one or more ALU 1006s can receive input operands and opcodes that determine the operation to be performed. One or more ALU 1006s are configured with various logic and arithmetic circuitry, including adders, subtractors, shifters, and logic gates, to process and manipulate data according to the operations. Alternatively or concurrently, one or more ALU 1006 may support logical operations such as AND, OR, XOR, NOR, and NAND, enabling one or more ALU 1006 to handle conditional operations, comparisons, and bitwise operations.
[0348] Based on the examples disclosed herein, processor 1000 may support wireless communication. Processor 1000 may be configured or operable to support components for performing privacy protections as described herein.
[0349] Figure 11An example of an NF or NE 1100 according to various aspects of this disclosure is illustrated. NE 1100 may include a processor 1102, a memory 1104, a controller 1106, and a transceiver 1108. Processor 1102, memory 1104, controller 1106, or transceiver 1108, or various combinations thereof, or various components thereof, may be examples of parts for performing various aspects of this disclosure described herein. These components may be coupled via one or more interfaces (e.g., operational ground, communication ground, functional ground, electronic ground, electrical ground).
[0350] Processor 1102, memory 1104, controller 1106, or transceiver 1108, or various combinations or components thereof, may be implemented in hardware (e.g., a circuit system). The hardware may include a processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof, configured or otherwise supporting components for performing the functions described in this disclosure.
[0351] Processor 1102 may include intelligent hardware devices (e.g., a general-purpose processor, DSP, CPU, ASIC, FPGA, or any combination thereof). In some implementations, processor 1102 may be configured to operate memory 1104. In some other implementations, memory 1104 may be integrated into processor 1102. Processor 1102 may be configured to execute computer-readable instructions stored in memory 1104 to cause NE 1100 to perform various functions of this disclosure.
[0352] Memory 1104 may include volatile or non-volatile memory. Memory 1104 may store computer-readable, computer-executable code, including instructions that, when executed by processor 1102, cause NE 1100 to perform the various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as memory 1104 or another type of memory. Computer-readable media include both non-transitory computer storage media and communication media, including any medium that facilitates the transfer of computer programs from one place to another. Non-transitory storage media may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0353] In some implementations, processor 1102 and memory 1104 coupled to processor 1102 may be configured such that NE 1100 performs one or more functions described herein (e.g., processor 1102 executes instructions stored in memory 1104). For example, according to the examples disclosed herein, processor 1102 may support wireless communication at NE 1100. NE 1100 may be configured to support components for performing privacy protections as described herein.
[0354] Controller 1106 can manage the input and output signals of NE 1100. Controller 1106 can also manage peripheral devices not integrated into NE 1100. In some implementations, controller 1106 can utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, controller 1106 can be implemented as part of processor 1102.
[0355] In some implementations, NE 1100 may include at least one transceiver 1108. In other implementations, NE 1100 may have more than one transceiver 1108. Transceiver 1108 may represent a wireless transceiver. Transceiver 1108 may include one or more receiver chains 1110, one or more transmitter chains 1112, or a combination thereof.
[0356] Receiver chain 1110 can be configured to receive signals (e.g., control information, data, packets) via a wireless medium. For example, receiver chain 1110 may include one or more antennas for receiving signals over the air or via a wireless medium. Receiver chain 1110 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. Receiver chain 1110 may include at least one demodulator configured to demodulate the received signal and acquire transmitted data by reversing the modulation technique applied during signal transmission. Receiver chain 1110 may include at least one decoder for decoding and processing the demodulated signal to receive transmitted data.
[0357] Transmitter chain 1112 can be configured to generate and transmit signals (e.g., control information, data, packets). Transmitter chain 1112 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques, such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes such as phase shift keying (PSK) or quadrature amplitude modulation (QAM). Transmitter chain 1112 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over a wireless medium. Transmitter chain 1112 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0358] The description provided herein is intended to enable those skilled in the art to make or use this disclosure. Various modifications to this disclosure will be apparent to those skilled in the art, and the general principles defined herein can be applied to other variations without departing from the scope of this disclosure. Therefore, this disclosure is not limited to the examples and designs described herein, but should be given the widest scope consistent with the principles and novel features disclosed herein.
[0359] The following abbreviations are related to the areas covered in this document: 5GC: 5G Core Network 5G-AN: 5G Access Network 5G-RG: 5G Residential Gateway NG-RAN: 5G Radio Access Network ADRF: Analysis Data Repository Functionality AMF: Access and Mobility Management Functions ARPF: Credentials Repository and Processing Functionality AUN3: Can authenticate non-3GPP devices AUSF: Authentication Server Function Cell-ID: Cell Identifier CIoT: Cellular Internet of Things cNRF: Consumer NRF CP: Control Plane CU: Central Unit DCCF: Data Collection Coordination Function DN: Data Network DNN: Data Network Name DU: Distributed Unit EDT: Early Data Transmission EN-DC: E-UTRA-NR Dual Connection ENSI: External Network Slice Information EPS: Evolved Packet System FN-RG: Fixed Network RG FS: Fault Monitoring gNB: NR Node B GUTI: Globally Unique Temporary UE Identifier IAB: Integrated Access and Backhaul IPUPS: PLMN Inter-UP Security IPX: IP Switching Service LI: Legal Interception MBSF: Multicast / Broadcast Service Function MBSSF: Security Features for Multicast / Broadcast Services MBSTF: Multicast / Broadcast Service Transmission Function MeNB: Main eNB MFAF: Message Passing Framework Adapter Functionality MN: Master Node ME: Managed Component MO-EDT: Mobile Initiated Early Data Transmission MT-EDT: Early Data Transmission for Mobile Termination MnS: Managed Services N3IWF: Non-3GPP Access Interoperability Function NWDAF: Network Data Analysis Function NAI: Network Access Identifier NF: Network Functions NG: Next Generation NMS: Network Management System ng-eNB: Next-Generation Evolved Node B NR: New Radio NRF: Network Repository Functionality NSSAI: Network Slice Selection Auxiliary Information OAM: Operations, Management and Maintenance PDN: Packet Data Network PEI: Permanent Device Identifier SEAF: Safety Anchoring Function SCP: Service Communication Agent SEPP: Secure Edge Protection Agent SgNB: auxiliary gNB SIDF: Subscription Identifier Hiding Functionality SMF: Session Management Function SN Id: Service Network Identifier SUCI: Subscription Hidden Identifier SUPI: Subscription Permanent Identifier TNAN: Trusted Non-3GPP Access Network TNAP: Trusted Non-3GPP Access Point TNGF: Trusted Non-3GPP Gateway Function TWAP: Trusted WLAN Access Point TWIF: Trusted WLAN Interoperability Function UE: User Equipment UDM: Unified Data Management UDR: Unified Data Repository UPF: User Plane Functionality USIM: Universal Subscriber Identity Module UDSF: Unstructured Data Storage Function
Claims
1. An open function in a wireless communication network, the open function comprising: At least one memory; as well as At least one processor, coupled to the at least one memory, and configured to enable the following functions: The system receives a request for data from a second network function (NF), which will then perform external analysis on the data. Determine the third NF for use in sending the request for data; as well as Send the request for data and the application ID associated with the second NF to the third NF.
2. The open functionality of claim 1, wherein the request for data is a request for event-based data, the request including one or more event IDs and / or external analytics IDs.
3. The open functionality according to claim 1 or 2, wherein the open functionality includes or has access to: a mapping of one or more external analytics IDs to a corresponding set of event IDs associated with the external analytics IDs.
4. The open functionality according to claim 2 or 3, wherein the request for data is a monitoring event open subscription or request message, the monitoring event open subscription or request message being a request for event-based data or a subscription request for event-based data, the event-based data corresponding to the one or more event IDs and / or external analysis IDs, the one or more event IDs and / or external analysis IDs being associated with external security monitoring.
5. The open functionality according to any one of claims 2 to 4, wherein the one or more event IDs identify one or more events selected from an event group, the event group comprising: Abnormal behavior of network functions; Violations of predefined service operation messages; violations of specified message inputs or outputs; messages exceeding pre-configured limits; resource utilization issues; authentication failures; and authorization failures.
6. The open function according to any one of claims 1 to 5, wherein the second NF is an application function AF.
7. The open functionality according to any one of claims 1 to 6, wherein the third NF is a data consumer or collector selected from a group of data consumers or collectors, the group of data consumers or collectors comprising: Network Data Analysis Function (NWDAF) Data Collection Coordination Function (DCCF); information Pass-frame adapter function MFAF; The system includes the Data Analysis Repository Function (ADRF); Operations, Administration, and Maintenance Function (OAM); Network Management System (NMS); and Management Data Analysis Service (MDAF).
8. The open function according to any one of claims 1 to 7, wherein the at least one processor is further configured to: determine the third NF based on local configuration or by querying the NF.
9. The open function according to claim 1 or 8, wherein the at least one processor is further configured to cause the open function to: Receive the following instruction: Is the accessibility of certain data from the third NF to the second NF allowed / disallowed? If an instruction that opening is not permitted is received, then opening certain data from the third NF to the second NF is prevented or opposed.
10. The open function of claim 9, wherein the indication that openness of certain data from the third NF to the second NF is not permitted is received from an entity, the entity being selected from an entity group consisting of: The third NF; as well as Fourth NF.
11. The open function according to any one of claims 1 to 10, wherein the at least one processor is further configured to cause the open function to: Receive input data from the third NF, the input data including privacy-sensitive data; Based on a privacy policy, identify the corresponding privacy-adaptive data for the aforementioned privacy-sensitive data; The input data is processed to replace or mask the privacy-sensitive data using the corresponding privacy-adaptive data, thereby generating privacy-protected input data; as well as Send the privacy-protected input data to the second NF.
12. The open functionality according to claim 11, wherein the privacy-adapted data is anonymous data.
13. The open functionality according to claim 11 or 12, wherein the at least one processor is further configured to: receive an indication from the third NF that the input data will be subject to privacy protection.
14. The open function according to any one of claims 11 to 13, wherein the at least one processor is further configured to cause the open function to: In response to acquiring the input data, a policy request for the corresponding privacy adaptation data, which has one or more event IDs, is sent to the fourth NF; and Receive privacy-adapted data specific to the corresponding event ID from the fourth NF.
15. The open function of claim 14, wherein the fourth NF is an NF selected from a group of NFs, the group of NFs consisting of: Unified Data Management (UDM) entities; Unified Data Repository (UDR); And unstructured data storage functionality UDSF; And the Network Repository Function (NRF); and the fourth NF is configured to maintain privacy policies for data collection and openness.
16. The open function according to any one of claims 11 to 15, wherein the at least one processor is further configured to: cause the open function to receive monitoring results based on the privacy-preserving input data from the second NF in response to sending the privacy-preserving input data to the second NF.
17. The open function of claim 16, wherein the at least one processor is further configured to: cause the open function to send the monitoring result to the third NF.
18. The open function according to any one of claims 1 to 17, wherein the NF is an open function selected from a group of open functions, the group of open functions comprising: Open governance management function EGMF or network open function NEF.
19. The open functionality according to any one of claims 1 to 18, wherein the request for data specifies a target data source related to the data to be collected.
20. A method performed by an open function in a wireless communication network, the method comprising: The system receives a request for data from a second network function (NF), which will then perform external analysis on the data. Determine the third NF for use in sending the request for data; as well as Send the request for data and the application ID associated with the second NF to the third NF.