Untrusted device detection

By employing detection methods based on location information and lists of trusted devices or MDT data, the problem of untrusted devices sending tampered data in communication networks is solved, ensuring the security of communication networks and the accuracy of AI/ML models.

CN121645245APending Publication Date: 2026-03-10NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-06
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

In communication networks, there is a problem of untrusted devices sending tampered data, which leads to performance degradation of AI/ML models or network optimization errors.

Method used

By using location information and a list of trusted devices or MDT data, the system can detect and verify whether a terminal device is untrusted, thus preventing it from sending tampered data.

Benefits of technology

Effectively detect and identify untrusted devices, prevent data poisoning attacks, and ensure the security of communication networks and the accuracy of AI/ML models.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121645245A_ABST
    Figure CN121645245A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a method, equipment and device for untrusted equipment detection in a communication network and a computer readable storage medium. In a method, a first apparatus obtains a result indicating that a second apparatus is suspected to be an untrusted device based on information related to positioning of the second apparatus. The first apparatus determines information indicating whether the second apparatus is an untrusted device based on at least one of a list of trusted devices associated with the second apparatus or minimization of drive test data. In this way, the security of the communication network is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunications, and in particular, to methods, devices, apparatuses, and computer-readable storage media for untrusted device detection. BACKGROUND

[0002] With the development of communication technology, data transmitted between devices in a communication network (e.g., from a user equipment (UE) to a base station) can include data for various purposes. In one aspect, such data can be applied to training or inference of artificial intelligence (AI) / machine learning (ML) models in the communication network, for example, for the purpose of network management and optimization. The performance of AI / ML models can be highly dependent on the authenticity and originality of the data used in the training or inference. Therefore, it is necessary to guarantee the security of the data. SUMMARY

[0003] In a first aspect of the present disclosure, a first apparatus is provided. The first apparatus includes at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to: obtain, based on information related to positioning of a second apparatus, a result indicating that the second apparatus is suspected to be an untrusted device; and determine, based on at least one of a list of trusted devices or minimization of drive tests (MDT) data associated with the second apparatus, information indicating whether the second apparatus is an untrusted device.

[0004] In a second aspect of the present disclosure, a third apparatus is provided. The third apparatus includes at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the third apparatus at least to: receive, from a first apparatus, a request for a list of trusted devices; and transmit, to the first apparatus, a response including the list of trusted devices for the first apparatus to determine the information indicating that a second apparatus is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that are predetermined.

[0005] In a third aspect of the present disclosure, a fifth apparatus is provided. The fifth apparatus includes at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the fifth apparatus at least to: in response to determining that a seventh apparatus is untrusted, transmit, to a sixth apparatus, first information indicating that the seventh apparatus is an untrusted device for a first service.

[0006] In a fourth aspect of the disclosure, a sixth apparatus is provided. The sixth apparatus includes at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the sixth apparatus at least to receive, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; and perform at least one of the following: refraining from using data from the seventh apparatus in the first service, and sending the first information to an eighth apparatus.

[0007] In a fifth aspect of the disclosure, a method is provided. The method includes obtaining, based on information related to positioning of a second apparatus, a result indicating that the second apparatus is suspected to be an untrusted device; and determining, based on at least one of a list of trusted devices or minimization of drive tests (MDT) data associated with the second apparatus, information indicating whether the second apparatus is an untrusted device.

[0008] In a sixth aspect of the disclosure, a method is provided. The method includes receiving, from a first apparatus, a request for a list of trusted devices; and sending, to the first apparatus, a response including the list of trusted devices for the first apparatus to determine information indicating that a second apparatus is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that are predetermined.

[0009] In a seventh aspect of the disclosure, a method is provided. The method includes sending, to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service, in response to determining that the seventh apparatus is untrusted.

[0010] In an eighth aspect of the disclosure, a method is provided. The method includes receiving, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; and performing at least one of the following: refraining from using data from the seventh apparatus in the first service, and sending the first information to an eighth apparatus.

[0011] In a ninth aspect of the disclosure, a first apparatus is provided. The first apparatus includes means for obtaining, based on information related to positioning of a second apparatus, a result indicating that the second apparatus is suspected to be an untrusted device; and means for determining, based on at least one of a list of trusted devices or minimization of drive tests (MDT) data associated with the second apparatus, information indicating whether the second apparatus is an untrusted device.

[0012] In a tenth aspect of the disclosure, a third apparatus is provided. The third apparatus includes means for receiving, from a first apparatus, a request for a list of trusted devices; and means for sending, to the first apparatus, a response including the list of trusted devices for the first apparatus to determine information indicating that a second apparatus is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that are predetermined.

[0013] In an eleventh aspect of the disclosure, a fifth apparatus is provided. The fifth apparatus comprises: means for sending, to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service in response to determining that the seventh apparatus is untrusted.

[0014] In a twelfth aspect of the disclosure, a sixth apparatus is provided. The sixth apparatus comprises: means for receiving, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; and means for performing at least one of: refraining from using data from the seventh apparatus in the first service, and sending the first information to an eighth apparatus.

[0015] In a thirteenth aspect of the disclosure, a computer-readable medium is provided. The computer-readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fifth aspect.

[0016] In a fourteenth aspect of the disclosure, a computer-readable medium is provided. The computer-readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the sixth aspect.

[0017] In a fifteenth aspect of the disclosure, a computer-readable medium is provided. The computer-readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the seventh aspect.

[0018] In a sixteenth aspect of the disclosure, a computer-readable medium is provided. The computer-readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the eighth aspect.

[0019] It should be understood that the Summary is not intended to identify key or essential features of embodiments of the disclosure, nor is it intended to limit the scope of the disclosure. Other features of the disclosure will be readily apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0020] Some example embodiments will now be described with reference to the accompanying drawings, in which:

[0021] Figure 1 An example communication environment in which example embodiments of the disclosure can be implemented is shown;

[0022] Figure 2 A signaling flow of a procedure for untrusted device detection according to some example embodiments of the disclosure is shown;

[0023] Figure 3 An example signaling flow of a procedure for untrusted device detection according to some example embodiments of the disclosure is shown;

[0024] Figure 4Another example signaling flow illustrating a process of untrusted device detection according to some example embodiments of the disclosure is shown;

[0025] Figure 5 Another example communication environment in which example embodiments of the disclosure can be implemented is shown;

[0026] Figure 6A A signaling flow illustrating a process of broadcasting untrusted device information according to some example embodiments of the disclosure is shown;

[0027] Figure 6B Another signaling flow illustrating a process of broadcasting untrusted device information according to some example embodiments of the disclosure is shown;

[0028] Figure 7 An example signaling flow illustrating a process of broadcasting untrusted device information according to some example embodiments of the disclosure is shown;

[0029] Figure 8 Another example signaling flow illustrating a process of broadcasting untrusted device information according to some example embodiments of the disclosure is shown;

[0030] Figure 9 A flow diagram illustrating a method implemented at a first apparatus according to some example embodiments of the disclosure is shown;

[0031] Figure 10 A flow diagram illustrating a method implemented at a third apparatus according to some example embodiments of the disclosure is shown;

[0032] Figure 11 A flow diagram illustrating a method implemented at a fifth apparatus according to some example embodiments of the disclosure is shown;

[0033] Figure 12 A flow diagram illustrating a method implemented at a sixth apparatus according to some example embodiments of the disclosure is shown;

[0034] Figure 13 A simplified block diagram of a device suitable for implementing example embodiments of the disclosure is shown; and

[0035] Figure 14 A block diagram of an example computer-readable medium according to some example embodiments of the disclosure is shown.

[0036] Throughout the drawings, identical or similar reference numerals can represent same or similar elements. DETAILED DESCRIPTION

[0037] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that these embodiments are described for illustrative purposes only and help the skilled person understand and implement the present disclosure without implying any limitation to the scope of the present disclosure. The embodiments described herein can be implemented in various ways other than those described below.

[0038] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0039] Reference within this disclosure to “one embodiment”, “an embodiment”, “example embodiments”, etc., indicates that a described embodiment can include a particular feature, structure, or characteristic, but every embodiment can not necessarily include the particular feature, structure, or characteristic. Moreover, these phrases are not necessarily referring to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that

[0040] It should be understood that although the antecedent term such as “first”, “second” etc. before (multiple) noun(s) can be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another, and they do not limit the order of (multiple) noun(s). For example, a first element can be called a second element, and similarly, a second element can be called a first element without departing from the scope of the example embodiments. As used herein, the term “and / or” includes any of the listed terms and all combinations of the listed terms.

[0041] As used herein, “at least one of: ” and “one or more of: ” and similar phrases, where a list of two or more elements is conjoined by “and” or “or”, means at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.

[0042] As used herein, unless explicitly stated, performing a step “in response to A” does not indicate that the step is performed immediately after A occurs, and one or more intervening steps can be included.

[0043] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises," "comprising," "includes" and / or "including," when used herein, specify the presence of stated features, elements and / or components etc. but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.

[0044] As used in this application, the term "circuitry" can refer to one or more or all of the following: (a) hardware-only circuitry such as only analog and / or digital circuitry; (b) combinations of hardware circuits and software, such as (as applicable): (i) combinations of analog and / or digital hardware circuit(s) with software / firmware; (ii) portions of hardware processor(s) with software (including digital signal processors); and (iii) hardware logic with portions of hardware processor(s) and software (including digital signal processors); and (c) hardware circuit(s) that when activated, does not require software for operation, but can benefit from software, such as a software application.

[0045] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation that has a hardware circuit or processor (or multiple processors) and software (or firmware) that works together to make and use the circuitry, but the software can not be present when it is not needed for the circuitry's operation. For example, where a software application is involved, a hardware circuit can implement its functions but not use software, for example, a

[0046] As used herein, the term "communication network" refers to a network that conforms to any suitable communication standard, such as New Radio (NR), Long Term Evolution (LTE), LTE-A Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed ​​Packet Access (HSPA), Narrowband Internet of Things (NB-IoT), etc. Furthermore, communication between terminal devices and network devices in a communication network can be performed according to any suitable generation of communication protocol, including but not limited to first-generation (1G), second-generation (2G), 2.5G, 2.75G, third-generation (3G), fourth-generation (4G), 4.5G, fifth-generation (5G), 5.5G, sixth-generation (6G) communication protocols and / or any other currently known or future-developed protocols. Embodiments of this disclosure can be applied to a variety of communication systems. Given the rapid development of communications, there will naturally be future types of communication technologies and systems that can be implemented using this disclosure. This disclosure should not be construed as limiting its scope to the aforementioned systems.

[0047] As used herein, the term "network device" refers to a node in a communications network through which terminal devices access the network and receive services. Network devices can refer to base stations (BS) or access points (APs), such as Node B (or NB), evolved Node B (eNode B or eNB), NR NB (also known as gNB), Remote Radio Unit (RRU), Radio Head (RH), Remote Radio Head (RRH), relay, Integrated Access and Backhaul (IAB) node, low-power node (such as femtosecond), picosecond, non-terrestrial network (NTN) or non-terrestrial network equipment (such as satellite network equipment, low Earth orbit (LEO) satellites and geostationary Earth orbit (GEO) satellites), spacecraft network equipment, etc., depending on the terminology and technology applied. In some example embodiments, the Radio Access Network (RAN) split architecture includes a centralized unit (CU) and a distributed unit (DU) at the IAB donor node. An IAB node includes a mobile terminal (IAB-MT) portion that behaves as a UE to its parent node, and the DU portion of the IAB node behaves as a base station to the next-hop IAB node.

[0048] The term "terminal device" refers to any end device with wireless communication capabilities. As an example and not a limitation, a terminal device can refer to communication equipment, user equipment (UE), subscriber station (SS), portable subscriber station, mobile station (MS), or access terminal (AT). Terminal devices can include, but are not limited to, mobile phones, cellular phones, smartphones, Voice over IP (VoIP) phones, wireless local loop phones, tablets, wearable terminal devices, personal digital assistants (PDAs), portable computers, desktop computers, image acquisition terminal devices (such as digital cameras), gaming terminal devices, music storage and playback devices, in-vehicle wireless terminal devices, wireless endpoints, mobile stations, laptop embedded devices (LEE), laptop mounted devices (LME), USB dongles, smart devices, wireless client devices (CPE), Internet of Things (IoT) devices, watches or other wearable devices, head-mounted displays (HMDs), vehicles, drones, medical devices and applications (e.g., remote surgery), industrial devices and applications (e.g., robots and / or other wireless devices operating in the context of industrial and / or automated processing chains), consumer electronic devices, devices operating on commercial and / or industrial wireless networks, etc. The terminal device may also correspond to the mobile terminal (MT) portion of an IAB node (e.g., a relay node). In the following description, the terms "terminal device," "communication device," "terminal," "user equipment," and "UE" are used interchangeably.

[0049] As used herein, the terms “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” can refer to any resource used to perform communication, such as communication between a terminal device and a network device, including resources in the time domain, frequency domain, spatial domain, code domain, or any other combination of time-domain, frequency-domain, spatial, and / or code-domain resources used to implement communication. In the following, unless explicitly stated otherwise, resources in the frequency and time domains will be used as examples of transmission resources used to describe some exemplary embodiments of this disclosure. Note that the exemplary embodiments of this disclosure are equally applicable to other resources in other domains.

[0050] Typically, there are various use cases where the UE sends training data to the base station (e.g., gNB) or core network for AI / ML model training purposes. These use cases involve, but are not limited to, location-based services, network management and optimization, CSI feedback, beamforming, etc. Additionally, the UE may also send some data that can be used for training via the MDT.

[0051] In all the above use cases, the complete AI / ML model can be tampered with to predict malicious values, or the actions taken by the network can be tampered with by providing malicious data during inference, in cases where the UE tampers with the training data of the AI / ML model it sends to the network (NW) to train entities, or even tampers with the data during the inference phase (i.e., sending toxic data samples to the NW for inference output).

[0052] For example, in the case of UE location estimation / prediction, if a UE or a group(s) of malicious UEs sends tampered data during the AI / ML model training phase, it could corrupt the entire AI / ML model, potentially leading to incorrect location services for all consumers of that AI / ML model. Furthermore, considering network management and optimization, if a malicious UE provides tampered data during inference—for example, the UE reports incorrect network performance metrics (e.g., signal strength, data throughput)—the AI / ML model will make incorrect inference predictions, potentially resulting in suboptimal network allocation and misleading network optimization algorithms.

[0053] To address the aforementioned and / or other potential problems, exemplary embodiments of this disclosure provide a solution for detecting untrusted devices. The proposed solution first detects the presence of a data poisoning attack and identifies (multiple) malicious UEs, also referred to as (multiple) untrusted devices. Information about the (multiple) malicious UEs is then sent to relevant stakeholders (e.g., training nodes) to prevent / minimize the spread of such attacks.

[0054] The exemplary embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0055] Figure 1 An example communication environment 100 in which exemplary embodiments of the present disclosure may be implemented is shown. The communication environment 100 relates to a plurality of communication devices, including a first device 110, a second device 120, a third device 130, and a fourth device 140. The first device 110 may communicate bidirectionally with the second device 120, the third device 130, or the fourth device 140.

[0056] exist Figure 1 In one example, the first device 110 can be implemented as a network device in a radio access network (RAN) (such as a base station), and the second device 120 can be implemented as a terminal device, such as a UE served by the base station. In an alternative example, the first device 110 can be implemented as a core network functional entity capable of bidirectional communication with the first device 110, such as a device implementing a location management function (LMF).

[0057] In some exemplary embodiments, if the first device 110 is a network device in the RAN and the second device 120 is a terminal device, the link from the second device 120 to the first device 110 is referred to as an uplink (UL), and the link from the first device 110 to the second device 120 is referred to as a downlink (DL). In the UL, the second device 120 is a transmitting (TX) device (or transmitter), and the first device 110 is a receiving (RX) device (or receiver). In the DL, the first device 110 is a TX device (or transmitter), and the second device 120 is an RX device (or receiver).

[0058] Furthermore, the third device 130 and the fourth device 140 can be implemented as core network equipment. In some example implementations, the third device 130 can implement Access and Mobility Functions (AMF) or Operation, Administration and Maintenance (OAM). The fourth device 140 can implement User Data Management (UDM).

[0059] Communication in communication environment 100 can be implemented according to any suitable communication protocol(s), including but not limited to cellular communication protocols such as first-generation (1G), second-generation (2G), third-generation (3G), fourth-generation (4G), fifth-generation (5G), 5.5G, and sixth-generation (6G), wireless local area network communication protocols such as IEEE 802.11, and / or any other currently known or future-developed protocols. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple Access (OFDM), Discrete Fourier Transform Extended OFDM (DFT-s-OFDM), and / or any other currently known or future-developed technologies.

[0060] It should be understood that Figure 1 The number of devices and their connections shown are for illustrative purposes only and do not imply any limitation. Communication environment 100 may include any suitable number of devices configured to implement the exemplary embodiments of this disclosure.

[0061] refer to Figure 2 This illustrates a signaling flow 200 for untrusted device detection according to some example embodiments of the present disclosure. For discussion purposes, reference will be made to... Figure 1 Discuss signaling flow 200. For example... Figure 2 As shown, signaling flow 200 involves a first device 110, a second device 120, a third device 130, and a fourth device 140.

[0062] In some example embodiments, the first device 110 may be implemented as a network device in the RAN or a network device implementing Location Management Function (LMF). Additionally, the second device 120 may be implemented as a terminal device. Furthermore, the third device 130 may be implemented as a UDM, AMF, or OAM. And, the fourth device 140 may be implemented as a network device implementing OAM.

[0063] In signaling flow 200, the first device 110 obtains (2030) a result indicating that the second device 120 is suspected to be an untrusted device based on information related to the location of the second device 120. Then, the first device 110 determines (2080) information indicating whether the second device 120 is an untrusted device based on a trusted device list, minimal drive test (MDT) data associated with the second device 120, and / or other suitable factors. The trusted device list may include devices pre-defined as trusted. The specific implementation of the above steps will be described below.

[0064] In some example implementations, the first device 110 may be implemented as a network device in the RAN (also referred to as "RAN network device" for the purposes of discussion), and the second device 120 may be implemented as a terminal device. In this case, the second device 120 sends (2010) location-related information to the first device 110. Accordingly, the first device 110 can receive (2020) location-related information from the second device 120. Specifically, the location-related information may include, but is not limited to, reference coordinate data of the second device 120 (e.g., Global Positioning System (GPS) coordinates) or first measurement results of a first reference signal, such as the measurement results of a Positioning Reference Signal (PRS), Sounding Reference Signal (SRS), etc.

[0065] Based on the received information related to the location of the second device 120, the first device 110 can obtain a result indicating that the second device 120 is suspected to be an untrusted device. Specifically, for example, the first device 110 can determine a first candidate location of the second device 120 based on the information related to the location of the second device 120, and can determine a second candidate location of the second device 120 by measuring a second reference signal from the second device 120. If the difference between the first candidate location and the second candidate location is greater than a first threshold, the first device 110 can determine that the second device 120 is suspected to be an untrusted device.

[0066] The first threshold may be predefined or may be predetermined, for example, by the fourth device 140. The fourth device 140 may determine the first threshold based on various factors, such as historical values, service conditions, signal quality, etc. In some example embodiments, the fourth device 140 may send (2002) a configuration indicating the first threshold to the first device 110. Accordingly, the first device 110 may receive (2004) the configuration from the fourth device 140 and thus obtain the first threshold.

[0067] The proposed solution in the example embodiments of this disclosure can be considered a two-stage verification solution. That is, verification of whether the second device 120 is suspicious is performed first, and if the second device 120 is suspected to be an untrusted device (which can be considered the first stage of verification), the first device 110 can perform further verification (which can be considered the second stage of verification) by, for example, sending (2040) a request for a list of trusted devices to the third device 130.

[0068] Upon receiving (2050) a request for a list of trusted devices from the first device 110, the third device 130 may send (2060) a response to the first device 110 including the list of trusted devices. The list of trusted devices may indicate one or more pre-determined trusted devices that may be located in the same area as the second device 120. In this way, the first device 110 can receive (2070) the list of trusted devices in the response from the third device 130. Using the list of trusted devices, the first device 110 may determine (2080) whether the second device 120 is an untrusted device.

[0069] Alternatively or additionally, besides RAN network equipment, the first device 110 can be implemented as a core network (CN) device, such as a device implementing LMF (hereinafter referred to as "LMF device" or "LMF"), and the second device 120 can be implemented as a terminal device. In this case, the first device 110 can receive (2020) location-related information of the second device 120, which may include, but is not limited to, reference coordinate data of the second device 120 or a first measurement result of a first reference signal. The location-related information of the second device 120 can be received from the second device 120, or from another RAN network device ( Figure 2 (not shown in the image) or another core network device ( Figure 2 (Not shown in the image) Received.

[0070] Based on the received information related to the location of the second device 120, the first device 110 can obtain a result indicating that the second device 120 is suspected to be an untrusted device. Specifically, for example, the first device 110 can determine a first candidate location of the second device 120 based on the information related to the location of the second device 120, and can determine a second candidate location of the second device 120 by measuring a second reference signal from the second device 120. If the difference between the first candidate location and the second candidate location is greater than a first threshold, the first device 110 can determine that the second device 120 is suspected to be an untrusted device.

[0071] If the first device 110 is an LMF (Leadership Default Factor), and the second device 120 has been identified as a suspected untrusted device in 2030, the first device 110 can still verify whether the second device 120 is untrusted. This verification can be performed based on MDT (Multi-Demand Analytical Testing) data, a list of trusted devices, etc.

[0072] Specifically, in some example implementations, the first device 110 may acquire MDT data associated with the second device 120. The MDT data may be assumed to be reliable. The MDT data may include data used in various aspects, such as geographic location information, signal quality data, network performance metrics, mobility and / or connectivity data.

[0073] The first device 110 can acquire MDT data in various ways. MDT data can be received from another network device (e.g., a network device implementing UDM or OMA, also referred to simply as "UDM" or "OAM"). In some example embodiments, the first device 110 may first send a request to a third device 130 for MDT data associated with the second device 120, and then receive a response from the third device 130 including the MDT data associated with the second device 120.

[0074] Subsequently, the first device 110 can correlate the MDT data with location-related information of the second device 120. The location-related information of the second device 120 can be correlated with the location data of the MDT data. If an anomaly is detected from the correlation results, the first device 110 can determine that the second device 120 is an untrusted device. Conversely, if no anomaly is detected from the correlation results, the first device 110 can further verify based on a list of trusted devices. For example, it can send a request for the list of trusted devices to the third device 130. Specifically, the list of trusted devices can indicate one or more pre-determined trusted devices. The third device 130 can then send a response including the list of trusted devices to the first device 110. Based on the received list of trusted devices, the first device 110 can further verify whether the second device 120 is an untrusted device.

[0075] Subsequently, the first device 110 can acquire information related to the location of trusted devices in the trusted device list, and determine information indicating whether the second device 120 is an untrusted device by comparing the information related to the location of the second device 120 with the information related to the location of trusted devices in the trusted device list.

[0076] Regarding information related to the location of trusted devices in the trusted device list, the first device 110 may send a request for such information to the trusted device. In response to receiving the request from the first device, the trusted device may send a response including information related to the location of the trusted device. Therefore, the first device 110 can obtain the information related to the location of trusted devices in the trusted device list from the received response.

[0077] Subsequently, the first device 110 can determine the difference between a first measurement result of the first reference signal included in the positioning-related information of the second device 120 and a second measurement result of the first reference signal included in the positioning-related information of the trusted device. If the first device 110 determines that the difference is greater than a second threshold, then the first device 110 can determine that the second device 120 is an untrusted or unreliable device. Furthermore, if the difference is less than or equal to the second threshold, then the first device 110 can determine that the second device 120 is not an unreliable device.

[0078] Alternatively, if the first device 110 determines that the difference is greater than or equal to the second threshold, then the first device 110 may determine that the second device 120 is an untrusted or unreliable device. Furthermore, if the difference is less than the second threshold, then the first device 110 may determine that the second device 120 is not an unreliable device.

[0079] Furthermore, the first device 110 can send (2110) information to the third device 130 indicating whether the second device 120 is an untrusted device. Accordingly, the third device 130 can receive such information (2120) from the first device 110. Therefore, the third device 130 will know whether the second device 120 is untrusted.

[0080] Additionally, in some example embodiments, the device under test (e.g., the second device 120 (e.g., UE)) may be added to the set of trusted UEs when it is assessed as non-untrusted, for example, from the perspective of evaluating network devices (e.g., the first device 110 (gNB or LMF)).

[0081] There are several scenarios in which the device under test (DUT) might be assessed as untrustworthy. For example, if the DUT has successfully passed the first phase of validation (also known as the first test), it can be determined to be untrustworthy. Alternatively, if the DUT fails the first test but has successfully passed the second phase of validation (also known as the second test), it can also be determined to be untrustworthy.

[0082] In some example implementations, such updates to the trusted device list may have an expiration date. That is, it may require a future point in time, and at that future point, if the UE continues to camp in the same cell managed by the same gNB for a period longer than the expiration date, the two tests assessing the UE's trustworthiness will need to be performed again.

[0083] In this way, the first device 110 can determine whether the second device 120 is an untrusted device or a suspected untrusted device, thus detecting data poisoning or data drift. This ensures the security of the communication network.

[0084] Depending on whether the network devices in the RAN are enabled / enhanced to have AI / ML model capabilities, there are several ways to implement the process for untrusted device detection. The signaling flow describing the proposed solution focuses on the UE location estimation / prediction use case, which is used as an example because the proposed solution is also applicable to other use cases (e.g., beam management, mobility optimization, etc.).

[0085] More detailed embodiments will now be discussed below. Figure 3 An example signaling flow 300 for untrusted device detection according to some example embodiments of this disclosure is shown. Reference will be made to this document for discussion purposes. Figure 1-2 Discuss signaling flow 300. For example... Figure 3 As shown, signaling flow 300 involves gNB 310, gNB UE1 320, gNB UE2 322, UDM 330, OAM 340, device 350 implementing AMF (also referred to as "AMF" for discussion), LMF 360, and device 370 implementing Network Data Analysis Function (NWDAF) (also referred to as "NWDAF" for discussion).

[0086] exist Figure 3 In the embodiment, gNB 310 is Figure 1-2 The implementation of the first device 110 in UE1. Furthermore, UE1 320 is... Figure 1-2 The second device 120 is implemented in the UE. That is, UE1 320 can be a UE to be tested to determine whether UE1 320 is an untrusted device. UE2 322 is an implementation of a trusted device (e.g., a trusted terminal device or a trusted UE).Figure 3 UDM 330 in the middle is Figure 1-2 The third device 130 is implemented in the above. Furthermore, OAM 340 is an implementation of the fourth device 140. Alternatively or additionally, in some example embodiments, OAM 340 and UDM 330 may implement the same or similar processes.

[0087] In the following description, although operations are depicted in a specific order, this should not be construed as requiring that such operations be performed in the specific order shown or sequentially, or that all of the shown operations be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0088] like Figure 3 As shown, at position 3010, UDM 330 sends the first threshold to gNB 310, as follows: Figure 2 The example embodiments discussed herein. The first threshold may be indicated by configuration and may be a maximum threshold indicating the maximum amount of deviation from the predicted value that gNB 310 can tolerate. That is, a UE with a deviation greater than the maximum threshold may be considered an untrusted device or a suspected untrusted device.

[0089] In some example implementations, the maximum threshold can be determined based on, for example, the type of analysis performed by the gNB 310, the type of data for which the analysis received by the gNB 310 is performed, and / or the location information of the gNB 310. Furthermore, determining the maximum threshold may also involve the method used for the analysis and the time resources used for analyzing the data. Additionally, the maximum threshold may include time and location information.

[0090] In some example embodiments, during the ML process configuration phase at gNB 310, OAM 340 may also indicate the maximum amount of threshold deviation from the predicted value that gNB 310 can tolerate, i.e., a first threshold.

[0091] The value of the first threshold can be configured based on the analysis being performed by the gNB 310, the data type of the analysis received by the gNB 310 for which it is being performed, and the geographic region where the gNB 310 is located. This first threshold can also vary relative to the specific manner in which a particular analysis is performed and the time intervals during which data is analyzed. In that respect, the first threshold configured by OAM can include temporal and geographic aspects related to the analysis being performed.

[0092] At 3020, UE1 320 can send its location information to gNB 310. In some example implementations, the location information can be implemented as a measurement of a Positioning Reference Signal (PRS). Furthermore, if ground real-time data is available, UE1 320 can also send ground real-time data to gNB 310. In these cases, UE1 320 can send its GPS coordinate data to gNB 310. In some example embodiments, the GPS coordinate data of UE1 320 can be used as data labels in AI / ML model training. It should be understood that using location information to determine whether UE1 320 is an untrusted device is an example implementation of this disclosure. Other types of information that can be used to test UE1 320 may exist. The scope of this disclosure is not limited in this respect.

[0093] Subsequently, at 3030, gNB 310 can determine the first candidate location of UE1 320 based on the location information of UE1 320. Specifically, gNB 310 can use downlink data at 3030. In some example embodiments, gNB 310 can use a trusted or predetermined AI / ML model to estimate the first candidate location of UE1 320. In these cases, gNB 310 can assume that the AI / ML model is real. That is, the AI / ML model can be assumed not to have been trained on tampered or poisoned data. Alternatively, gNB 310 can use signal processing methods to obtain the first candidate location of UE1 320, such as enhanced cell identifier (E-CID), downlink time difference of arrival (DL-TDOA), or downlink angle of arrival (DL-AOA). Additionally, gNB 310 can use location information (e.g., downlink (DL)PRS) as input.

[0094] It should be understood that the AI / ML model is assumed to be real and not trained on tampered or poisoned data.

[0095] Furthermore, gNB 310 can determine a second candidate location for UE1 320. gNB 310 can use uplink data (e.g., sounding reference signal (SRS)) to determine the second candidate location for UE1 320. Specifically, the method used is similar to that described above and will not be repeated here. Since the first candidate location is determined based on the location information received from UE1 320, and the second candidate location is determined based on the UL signal of UE1 320, the second candidate location can be considered as the location of UE1 320.

[0096] Subsequently, at 3040, gNB 310 can compare the first candidate location and the second candidate location of UE1 320 and obtain the difference between the first candidate location and the second candidate location. If the difference is greater than a maximum threshold, gNB 310 can determine that UE1 320 is suspected to be an untrusted device. In these cases, gNB 310 can send the identifier (ID) of UE1 320 to the core network equipment for further verification, which will be described in the following sections. It should be understood that although UE1 320 is described as a suspected untrusted device, in some example embodiments of this disclosure, UE1 320 can be determined to be an untrusted device at 3040. The scope of this disclosure is not limited in this respect.

[0097] Specifically, gNB 310 estimates the UE location by observing its uplink reference signal (e.g., SRS). Then, gNB 310 compares estimates 3030 and 3040, and if the difference is higher than the first threshold received in step 3010, UE1 320 is marked as suspicious, and the UEID is sent to the core network for further verification.

[0098] At 3050, if gNB 310 determines at 3040 that UE1 320 is suspected to be an untrusted device, gNB 310 can send a request for a list of trusted devices to OAM 340. Specifically, gNB 310 can send the request to OAM 340 via AMF 350, and OAM 340 can send the request to UDM 330. Alternatively, gNB 310 can send the request to UDM 330.

[0099] Furthermore, the list of trusted devices may include the IDs and location information of trusted devices considered to be near the location of UE1 320. In these cases, the location of UE1 320 can be a second candidate location. Trusted devices that are less than a predetermined distance threshold from UE1 320 or located within a predetermined range centered on the location of UE1 320 can be considered to be near the location of UE1 320. Figure 3 In this context, UE2 322 can be an implementation of one of the trusted devices in the trusted device list.

[0100] In addition, the request may include the location of UE1 320, location information received from UE1 320, and determination that UE1 320 is suspected to be an untrusted device.

[0101] Subsequently, at 3060, OAM 340 or UDM 330 can determine a list of trusted devices after receiving a request from gNB 310. Specifically, OAM 340 or UDM 330 can select trusted devices considered to be near the location of UE1 320 into the list of trusted devices. Furthermore, OAM 340 or UDM 330 can acquire measurements of the location reference signals of the selected trusted devices, such as measurements of the trusted device's SRS or PRS. In some example embodiments, the trusted device may be a UE previously identified as an untrusted device or a pre-determined trusted device.

[0102] Furthermore, at 3070, OAM 340 can send a list of trusted devices to gNB 310. Specifically, the list of trusted devices can be sent in response to gNB 310. Additionally, OAM 340 can send location information of trusted devices from the list of trusted devices to gNB 310 in the response. Alternatively, in some example embodiments, UDM 330 may be a device that sends the list of trusted devices to gNB 310 in the response instead of OAM 340.

[0103] In other words, at locations 3060 and 3070, OAM 340 or UDM 330 identifies a list of trusted devices (e.g., a list of trusted UEs) providing measurements for that location and also for the UE under test (e.g., UE 1 320). This is because, due to different data retention policies that can be applied at OAM 340 / UDM 330, not all trusted UEs may be able to provide all data measurements that can be used to evaluate the UEs under test. Subsequently, OAM 340 or UDM 330 can send a list of trusted neighboring UEs based on past data collection to request gNB 310.

[0104] Additionally, at 3080, after receiving the list of trusted devices within the response from OAM 340, gNB 310 can select one or more trusted devices from the list of trusted devices that will be involved in the following processes. In the example, the selected trusted device could be UE2 322.

[0105] Subsequently, at 3090, gNB 310 can send a request to the trusted device for a measurement of the trusted device's reference signal. For example, gNB 310 can send a request to UE2 322 for a measurement of UE2 322's PRS or SRS.

[0106] Accordingly, at 3100, UE2 322 can send a response to gNB 310 containing a measurement of UE2 322's PRS or SRS (also referred to as a PRS / SRS measurement). It should be understood that one or more trusted devices may exist in the trusted device list. The scope of this disclosure is not limited in this respect.

[0107] Subsequently, at 3110, gNB 310 can determine whether UE1 320 is an untrusted device based on information received from UE2 322. For example, gNB 310 can analyze the PRS / SRS measurements received at 3100 against the PRS / SRS measurements received at 3020. If they deviate from a second threshold (which may be different from the first threshold), gNB 310 can indicate that UE1 320 under test is suspicious.

[0108] Specifically, gNB 310 can determine the difference between the measurements of the reference signals of UE1 320 and UE2 322. For example, gNB 310 can obtain the difference by comparing the measurements of PRS or SRS of UE1 320 and UE2 322. Furthermore, if the difference is greater than a predetermined threshold, gNB 310 can determine that UE1 320 is an untrusted device. Additionally, if the difference is less than or equal to the predetermined threshold, gNB 310 can determine that UE1 320 is not an untrusted device. Moreover, the predetermined threshold can be configured based on the trust level of the communication network and the strength of the required defense mechanisms.

[0109] Subsequently, at 3120, if UE1 320 is determined to be an untrusted device, gNB 310 can send the ID of UE1 320 to UDM330 so that data from UE1 320 should not be considered for data analysis.

[0110] Specifically, gNB 310 can send the ID of UE1 320 to other devices (e.g., AMF 350, LMF 360, NWDAF 370, and OAM 340) to broadcast the results of untrusted device detection. In these cases, the RAN core interface can be conceived as a service-based interface (SBI). Furthermore, data uploaded by UE1 320 can be considered poisoned or tampered with and should be discarded.

[0111] Alternatively, if UE1 320 is not determined to be an untrusted device, gNB 310 can also send UE1 320's ID to other core network devices to check whether the UE can be added to the list of trusted devices.

[0112] It should be understood that in the example embodiments discussed above, it is assumed that (multiple) UEs in the same or nearby locations will provide similar measurements to the gNB, and that the divergence in individual measurements will not exceed a set threshold. This threshold can also be set by the operator based on the system's trust level and the required strength of the defense mechanisms.

[0113] In this way, gNB 310 can determine whether UE1 320 is an untrusted device or a suspected untrusted device. This ensures the security of the communication network and the authenticity of the data uploaded by the UE.

[0114] The following will refer to Figure 4 Description and Figure 2 Another related example embodiment. Figure 4 Another example signaling flow 400 for untrusted device detection is shown according to some example embodiments of this disclosure. Signaling flow 400 is about... Figure 3 The signaling flow 300 is being discussed as an alternative. For discussion purposes, references will be made. Figure 1-2 Discuss signaling flow 400. For example... Figure 4 As shown, signaling flow 400 involves LMF 410, UE1 420, UE2 422, UDM 430, OAM 440, AMF 450, gNB 460 and NWDAF 470.

[0115] exist Figure 4 In the example embodiment, LMF 410 is Figure 1-2 The first device 110 in the implementation. Furthermore, UE1420 is... Figure 1-2 The second device 120 is an implementation of UE1 420. That is, UE1 420 can be a UE to be tested to determine whether UE1 420 is an untrusted device. UE2 422 is an implementation of a trusted device (e.g., a trusted terminal device or a trusted UE). Figure 4 UDM 430 is an implementation of the third device 130. Furthermore, OAM 440 is an implementation of the fourth device 140. Alternatively or additionally, in some example implementations, OAM 440 and UDM 430 may implement the same or similar processes.

[0116] Reference Figure 4 In the example embodiments discussed, the LMF 410 may have AI / ML capabilities and can perform inference using a trained AI / ML model. The LMF 410 can perform statistical analysis to detect the presence of any type of data drift. Furthermore, the proposed solution can be implemented by any suitable core network entity. The scope of this disclosure is not limited in this respect.

[0117] like Figure 4As shown, at 4010, OAM 440 sends the first threshold to LMF 410, as follows: Figure 2 The example embodiments discussed herein. The first threshold may be a maximum threshold indicated by configuration. The maximum threshold may be associated with the ID of the UE to be tested or with the data and measurements used in the test of the UE. Additionally, the threshold may be sent to NWDAF 470.

[0118] Subsequently, at 4020, UE1 420 can send its positioning information to gNB 460. In some example implementations, the positioning information can be implemented as a measurement of UE1 420's PRS or SRS. Furthermore, if ground real-time data is available, UE1 420 can also send ground real-time data to gNB 460. In these cases, UE1 420 can send its Global Navigation Satellite System (GNSS) coordinate data to gNB 460. In some example embodiments, UE1 420's GNSS coordinate data can be used as data labels in AI / ML model training. It should be understood that using positioning information to verify or test UE1 420 is an example implementation of this disclosure. Other types of information can be used to test UE1 420. The scope of this disclosure is not limited in this respect.

[0119] Subsequently, at 4030, gNB 460 sends the location information of UE1 420 to LMF 410. That is, UE1 420 can send location information to LMF 410 via gNB 460. It should be understood that UE1 420 can send its own location information to LMF 410 in any suitable manner or via any device capable of transmission. The scope of this disclosure is not limited in this respect.

[0120] At 4040, LMF 410 can determine the first candidate location of UE1 420 based on the location information of UE1 420. In some example embodiments, LMF 410 can use a trusted or predetermined AI / ML model to estimate the first candidate location of UE1 420. In these cases, LMF 410 assumes the AI / ML model is true. Alternatively, LMF 410 can use signal processing methods to obtain the first candidate location of UE1 420, such as E-CID, DL-TDOA, or downlink departure angle (DL-AoD). Additionally, LMF 410 can use location information (e.g., PRS) as input.

[0121] Furthermore, LMF 410 can determine a second candidate location for UE1 420, for example, by using measurements of the reference signal of UE1 420. Specifically, the method used is similar to that described above and will not be repeated here. Since the first candidate location is determined based on the location information received from UE1 420, and the second candidate location is determined based on measurements of the reference signal of UE1 420, the second candidate location can be considered as the location of UE1 420.

[0122] Subsequently, at 4050, LMF 410 can compare the first candidate location and the second candidate location of UE1 420 and obtain the difference between the first candidate location and the second candidate location. If the difference is greater than a maximum threshold, LMF 410 can determine that UE1 420 is suspected to be an untrusted device. In these cases, LMF 410 can send the ID of UE1 420 to the core network device for further verification, which will be described in the following sections. It should be understood that although UE1 420 is described as a suspected untrusted device, in some example embodiments of this disclosure, UE1 420 can be determined to be an untrusted device at 4050. The scope of this disclosure is not limited in this respect.

[0123] At 4060, if LMF 410 determines at 4050 that UE1 420 is suspected to be an untrusted device, LMF 410 may send a request to OAM 440 for MDT data associated with UE1 420. Furthermore, the MDT data is assumed to be trustworthy. That is, the MDT data is considered untampered or poisoned. Additionally, NWDAF 470 may send a request for MDT data to OAM 440. Alternatively or additionally, the request for MDT data may include the MDT data for the ID of the requested UE1 420.

[0124] At 4070, OAM 440 sends the response within the MDT data associated with UE1 420 to LMF 410. Additionally, OAM 440 may send the response within the MDT data to NWDAF 470.

[0125] Subsequently, at 4080, LMF 410 or NWDAF 470 correlates the MDT data with the positioning information of UE1 420. It should be understood that various methods or algorithms exist for performing this correlation. The exact algorithm used in the correlation of the MDT data with other measurement data received from UE1 420 depends on the specific implementation or use case, and this does not imply any limitation on this disclosure.

[0126] Subsequently, at 4090, if an anomaly is detected from the relevant result at 4080, LMF 410 can determine that UE1 420 is suspected to be an untrusted device. It should be understood that although UE1 420 is described as suspected to be an untrusted device, in some example embodiments of this disclosure, UE1 420 can be directly determined to be an untrusted device at 4090. The scope of this disclosure is not limited in this respect. Furthermore, LMF 410 can broadcast the ID of UE1 420 to other network devices that can receive data from UE1 420.

[0127] Alternatively, at 4100, if the anomaly is not detected from the relevant results at 4080, then LMF 410 can determine to perform another test on UE1 420 using a list of trusted devices.

[0128] In some example implementations, the UE is considered trustworthy if it passes all three stages of verification. Subsequently, for a particular analysis, data provided by the UE for future use is considered trustworthy, and its data / measurements are also used as reference points to detect any malicious / abnormal data drift from measurements received from an untrusted UE.

[0129] At 4110, LMF 410 can send a request for a list of trusted devices to UDM 430. Additionally, NWDAF470 can send a request for a list of trusted devices to UDM 430.

[0130] At 4120, LMF 410 or NWDAF 470 can receive a response including a list of trusted devices from UDM 430. Furthermore, the list of trusted devices can be sent from AMF 450. Additionally, the list of trusted devices may include the IDs and location information of trusted devices considered to be near the location of UE1 420. In these cases, the location of UE1 420 can be a second candidate location. Trusted devices that are less than a predetermined distance threshold from UE1 420 or located within a predetermined range centered on the location of UE1 420 can be considered to be near the location of UE1 420. Figure 4 In this context, UE2 422 can be an implementation of one of the trusted devices in the trusted device list.

[0131] Subsequently, at 4130, LMF 410 or NWDAF 470 can determine the measurement of a reference signal for a trusted device (such as UE2 422) in the trusted device list. Specifically, the measurement of the reference signal may include a measurement of PRS or SRS. Furthermore, the reference signal of UE2 422 may be the same as the reference signal of UE1 420.

[0132] At 4140, LMF 410 or NWDAF 470 can send a request for PRS or SRS measurements for UE2 422 to a trusted device (such as UE2 422). Furthermore, the measurement request is sent to gNB 460, and gNB 460 can send the request to UE2 422. That is, the measurement request is sent to UE2 422 via gNB 460 from LMF 410 or NWDAF 470.

[0133] Accordingly, at 4150, UE2 422 can send a response including the measurement of UE2 422's PRS or SRS to LMF 410 or NWDAF 470 via gNB 460.

[0134] Furthermore, at 4160, LMF 410 or NWDAF 470 can determine whether UE1 420 is an untrusted device based on information received from UE2 422. Specifically, LMF 410 or NWDAF 470 can determine the difference between measurements of reference signals of UE1 420 and UE2 422. For example, LMF 410 or NWDAF 470 can obtain the difference by comparing the measurements of PRS or SRS of UE1 420 and UE2 422. Furthermore, if the difference is greater than a predetermined threshold, LMF 410 or NWDAF 470 can determine that UE1 420 is an untrusted device. Additionally, if the difference is less than or equal to the predetermined threshold, LMF 410 or NWDAF 470 can determine that UE1 420 is not an untrusted device. Moreover, the predetermined threshold can be configured based on the trust level of the communication network and the strength of the required defense mechanisms.

[0135] Subsequently, at 4170, if UE1 420 is determined to be an untrusted device, LMF 410 can send UE1 420's ID to UDM 430. Furthermore, LMF 410 can send UE1 420's ID to other devices (e.g., AMF 450, gNB 460, NWDAF 470, and OAM440) to broadcast the result of the untrusted device detection. Additionally, data uploaded by UE1 420 can be considered poisoned or tampered with and should be discarded.

[0136] Alternatively, if UE1 420 is determined not to be an untrusted device, LMF 410 may send the ID of UE1 420 to other network devices associated with UE1 420 to notify them that UE1 420 is a "trusted data provider".

[0137] In this way, the LMF 410 can flexibly determine whether UE1 420 is an untrusted device or a suspected untrusted device. This ensures the security of the communication network and the originality of the data uploaded by the UE. Furthermore, it improves the flexibility of untrusted device detection.

[0138] Once a terminal device (e.g., a potentially malicious UE that has caused data poisoning) is detected in a communication network, it is important to identify the malicious UE across different entities and broadcast this information so that the attack is not propagated and other nodes are not affected.

[0139] In this regard, in addition to the example process described above for determining whether the second device 120 (e.g., UE) is an untrusted device, example embodiments of this disclosure also provide a process for identifying and broadcasting untrusted UE information to other stakeholders (e.g., multiple gNBs or other network functions in the core network) to prevent the spread of attacks, which will be referred to below. Figure 5-8 Provide a detailed description.

[0140] Figure 5 Another example communication environment 500 in which exemplary embodiments of the present disclosure may be implemented is shown. Communication environment 500 relates to a plurality of communication devices, including a fifth device 510, a sixth device 520, a seventh device 530, and an eighth device 540.

[0141] exist Figure 5 In some example embodiments, the fifth device 510 may be implemented as a network device in the RAN, such as a base station. The sixth device 520 may be implemented as another network device in the RAN. Alternatively, in some example implementations, the fifth device 510 may be implemented as a network device in the RAN, while the sixth device 520 may be implemented as a core network device, such as an AMF entity.

[0142] In both of the above scenarios, the seventh device 530 can be implemented as a terminal device, such as a UE served by the first device 110 (e.g., a base station). Regarding the eighth device 540, it can be implemented as another network device in the RAN. For example, the eighth device 540 could be a base station (e.g., a gNB) to which the UE is to be handed over.

[0143] In some exemplary embodiments, if the fifth device 510 is a network device in the RAN and the seventh device 530 is a terminal device, the link from the seventh device 530 to the fifth device 510 can be referred to as an uplink (UL), and the link from the fifth device 510 to the seventh device 530 can be referred to as a downlink (DL). In the UL, the seventh device 530 is a transmitting (TX) device (or transmitter), and the fifth device 510 is a receiving (RX) device (or receiver). In the DL, the first device 110 is a TX device (or transmitter), and the seventh device 530 is an RX device (or receiver).

[0144] Communication in the communication environment 500 can be implemented according to any suitable communication protocol(s), including but not limited to cellular communication protocols such as first-generation (1G), second-generation (2G), third-generation (3G), fourth-generation (4G), fifth-generation (5G), 5.5G, and sixth-generation (6G), wireless local area network communication protocols such as IEEE 802.11, and / or any other currently known or future-developed protocols. Furthermore, communication can utilize any suitable wireless communication technology, including but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple Access (OFDM), Discrete Fourier Transform Extended OFDM (DFT-s-OFDM), and / or any other currently known or future-developed technologies.

[0145] It should be understood that Figure 5 The number of devices and their connections shown are for illustrative purposes only and do not imply any limitation. The communication environment 500 may include any suitable number of devices configured to implement the exemplary embodiments of this disclosure.

[0146] refer to Figure 6A This illustrates a signaling stream 600A for broadcasting untrusted device information according to some example embodiments of the present disclosure. For discussion purposes, reference will be made to... Figure 5 Discuss the signaling flow of 600A. For example... Figure 6A As shown, signaling flow 600A involves fifth device 510, sixth device 520 and seventh device 530.

[0147] exist Figure 6A In the embodiments, the fifth device 510 is implemented as a network device in the RAN (also referred to as a "RAN network device" for the purposes of discussion) or a network device implementing an LMF (also simply referred to as an "LMF device" or "LMF"). Furthermore, the sixth device 520 can be implemented as another network device in the RAN. Additionally, the seventh device 530 can be implemented as a terminal device.

[0148] In signaling flow 600A, if the seventh device 530 is determined to be untrusted, the fifth device 510 sends (6010) first information indicating that the seventh device 530 is an untrusted device for the first service to the sixth device 520. Correspondingly, the sixth device 520 receives (6020) the first information indicating that the seventh device 530 is an untrusted device for the first service from the fifth device 510. Furthermore, the first service may include location. It should be understood that location is only one implementation of the first service. The first service may include various services, such as signal quality measurement, handover tracking efficiency, signal strength measurement, etc.

[0149] Knowing that the seventh device 530 is an untrusted device for the first service, the sixth device 520 avoids (6030) using data from the seventh device 530 in the first service.

[0150] Optionally, in some example embodiments, if the sixth device 520 determines that the seventh device 530 may be trusted, for example, after appropriate testing or verification, the sixth device 520 may send (6040) second information indicating that the seventh device 530 is a trusted device for the second service. Therefore, the fifth device 510 can receive (6050) the second information from the sixth device 520 and know that the seventh device 530 is a trusted device for the second service. In this case, the first information and the second information can share the same context. Specifically, for example, the first information and the second information may include the same elements indicating the use of each information.

[0151] Subsequently, the fifth device 510 can perform the second service by using data from the seventh device 530. It should be understood that the data used by the seventh device 530 for the first and second services may be different.

[0152] In this way, the first device 510 can notify the sixth device 520 that the seventh device 530 is an untrusted device, causing the sixth device 520 to stop using data from the untrusted device. Using this notification scheme, malicious or untrusted data can be excluded from various services. Therefore, the security and robustness of communication networks can be improved.

[0153] refer to Figure 6B This illustrates another signaling stream 600B for broadcasting untrusted device information according to some example embodiments of this disclosure. Similar to signaling stream 600A, reference will also be made to... Figure 5 Discuss signaling flow 600B. For example... Figure 6B As shown, signaling flow 600B involves fifth device 510, sixth device 520, seventh device 530 and eighth device 540.

[0154] exist Figure 6BIn the embodiments described, the fifth device 510 can be implemented as a network device in the RAN or a network device implementing LMF. Furthermore, the sixth device 520 can be implemented as another network device implementing AMF (also referred to as "AMF" for the purposes of discussion). Additionally, the seventh device 530 can be implemented as a terminal device. Furthermore, the eighth device 540 can be implemented as another network device in the RAN.

[0155] In signaling stream 600B, if the seventh device 530 is determined to be untrusted, the fifth device 510 sends (6010) first information to the sixth device 520 indicating that the seventh device 530 is an untrusted device for the first service. The first service may be, for example, location, signal quality determination, etc. Accordingly, the sixth device 520 receives (6020) the first information from the fifth device 510 indicating that the seventh device 530 is an untrusted device for the first service.

[0156] Furthermore, the sixth device 520 sends (6040) a message to the eighth device 540 indicating that the seventh device 530 is an untrusted device for the first service. Upon receiving (6050) such a message, the eighth device 540 understands this. Therefore, the eighth device 540 can avoid using data from the seventh device 530 in the first service.

[0157] The sixth device 520 may store the first information in context information associated with the seventh device 530. Additionally, if the sixth device 520 receives a request from the eighth device 540 for context information associated with the seventh device 520, the sixth device 520 may send the first information to the eighth device 540.

[0158] In this way, the first device 510 can notify the eighth device 540 via the second device 520 that the seventh device 530 is an untrusted device. This protects the eighth device 540 from using data from untrusted devices, thereby improving the data security of the communication network.

[0159] Several example embodiments of signaling stream 600A or 600B exist. For example, Figure 7 An example implementation of the signaling flow 600A is shown, and Figure 8 An example implementation of signaling flow 600B is shown. More detailed embodiments will now be discussed below.

[0160] Figure 7 An example signaling flow 700 for a process of untrusted device detection according to some example embodiments of this disclosure is shown. Reference will be made to this document for discussion purposes. Figure 5 and 6A Discuss signaling flow 700. For example... Figure 7As shown, signaling flow 700 involves source gNB 710, target gNB 720 and UE 730.

[0161] When a UE mobility event occurs (i.e., a handover to another gNB (target gNB 720)), the trust level of UE 730 can be notified to the target gNB 720 (in the sense of data collection used for UE location estimation, for example).

[0162] In this scenario, after classifying the tested UE 730 as untrusted, the source gNB 710 can accordingly notify the target gNB 720 via appropriate message transmission on the Xn interface using a new Boolean IE "Trusted UE" with a default value of (FALSE) and another IE "Data Use" indicating the use case (and therefore related UE measurements) for which data collection is required. Since the UE ID changes when the UE camps on different cells, and since the source gNB 710 will need to be notified of possible changes in the UE's trust level, for example, in the event that the UE will be redirected to the source gNB 710 in the future, a context involving the source gNB 710 and the target gNB 720 can be created using measurement ID pairs. Further details will follow. Figure 7 The discussion is ongoing.

[0163] exist Figure 7 In the embodiment, the source gNB 710 is Figure 5 and Figure 6A The implementation of the fifth device 510 in the [system / process]. Furthermore, the target gNB 720 is [the following]. Figure 5 and Figure 6A The implementation of the sixth device 520 in UE 730. Figure 5 and Figure 6A The implementation of the seventh device 530 in the process.

[0164] In the following description, although operations are depicted in a specific order, this should not be construed as requiring that such operations be performed in the specific order shown or sequentially, or that all of the shown operations be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0165] like Figure 7As shown, at 7010, the source gNB 710 sends a data collection request message to the target gNB 720. Specifically, this message may include a new trusted UE information element (IE) with a default value of FALSE. Furthermore, the message may include a new data usage IE that clarifies which use case data collection is considered untrusted.

[0166] Additionally, the data collection request message may also include the measurement ID of the source gNB 710 and a data usage flag. For example, the data collection request message may take the form of: (NG-RAN Node 1 Measurement ID, Trusted UE = FALSE, Data Usage = "Location"). "NG-RAN Node 1 Measurement ID" can indicate the measurement used for the source gNB 710. Furthermore, "Trusted UE = FALSE" can indicate that UE 730 is an untrusted device. "Data Usage" can indicate the type of service for which UE 730 uses data from its source gNB 710.

[0167] At 7020, the target gNB 720 can send a response to the source gNB 710. In some example implementations, the response can be implemented as a data collection response message in response to a request from the source gNB 710. The response may include the measurement ID of the target gNB 720, such as "NG-RAN Node 2 Measurement ID". Therefore, the measurement ID pair of the target gNB 720 and the source gNB 710 can be determined to include, for example, "NG-RAN Node 1 Measurement ID" and "NG-RAN Node 2 Measurement ID".

[0168] Subsequently, at 7030, the source gNB 710 can, for example, use via about Figure 2-4 The proposed solution determines that UE 730 is an untrusted device. Alternatively, the source gNB 710 can determine UE 730 as an untrusted device by receiving information from other devices indicating that UE 730 is an untrusted device. The scope of this disclosure is not limited in this respect.

[0169] Subsequently, at 7040, the source gNB 710 can send a handover request message to the target gNB 720. Specifically, the handover request message may include a measurement ID pair.

[0170] At 7050, the target gNB 720 can avoid using data from UE 730. Specifically, the target gNB 720 can avoid using UE 730's data for services of the "Data Usage" service type. For example, the target gNB 720 can avoid using data for UE 730's location estimation or prediction.

[0171] In some example embodiments, the target gNB 720 may directly use or first assess the confidence level of the UE 730 regarding the collection of different data from the data required for UE positioning estimation / prediction.

[0172] At 7060, an event can occur in which UE 730 is assessed as trustworthy: UE 730 is assessed as trustworthy either by notification from the target gNB 720 itself, or by notification from another adjacent gNB that UE 730 has already connected to before returning to the coverage area of ​​the target gNB 730. For example... Figure 7 As shown, at 7060, the target gNB 720 can identify the UE 730 as a trusted device, for example, by using the untrusted device detection solution discussed above.

[0173] Subsequently, at 7070, the target gNB 720 can send a data collection update request to the source gNB 710. Specifically, the data collection update request may include a measurement ID pair (for identifying the UE), where the value of the new trusted UE IE is changed to true (TRUE) for use in UE location estimation / prediction use cases. For example, the data collection update request message may take the form of: (NG-RAN Node 1 Measurement ID, NG-RAN Node 2 Measurement ID, Trusted UE = TRUE, Data Use = "Location").

[0174] At 7080, the target gNB 720 can send a handover request message, including a measurement ID pair, to the source gNB 710.

[0175] Subsequently, at 7090, the source gNB 710 can use the data from UE 730 to ensure that the data from UE 730 is genuine and original, for services such as location estimation or prediction. Furthermore, UE 730 can be retested after a period of time. That is, UE 730 can be periodically tested to determine whether UE 730 is an untrusted device.

[0176] In this way, the source gNB 710 can notify the target gNB 720 to avoid using data from an untrusted device (UE 730). Furthermore, the target gNB 720 can update the trust status of UE 730. In this manner, under certain circumstances or when certain conditions are met, UE 730 can be a trusted device, and its data can then be used by the source gNB 710 or other devices. Therefore, the effectiveness and efficiency of data used in the communication network are improved.

[0177] In some other example embodiments, when a UE mobility event occurs (i.e., a handover to the target gNB), the UE's trust level can be notified to the target gNB via the AMF (as an example, in the sense of data collection used for UE location estimation).

[0178] In this scenario, after classifying the UE as untrusted, the source gNB can notify the AMF via the Next Generation Application Protocol (NGAP). The AMF can then notify the target gNB2 via the NGAP interface, for example, by means of a new Boolean IE "Trusted UE" and another IE indicating the use case "Data Usage" (similar to...). Figure 7 (Example embodiments).

[0179] The following will be about Figure 8 To discuss further details of these example embodiments, Figure 8 Another example signaling flow 800 for untrusted device detection according to some example embodiments of this disclosure is shown. Reference will be made to this document for discussion purposes. Figure 5 and Figure 6B Discuss signaling flow 800. For example... Figure 8 As shown, signaling flow 800 involves source gNB or gNB1 810, AMF 820, UE 830 and target gNB or gNB2 840.

[0180] exist Figure 8 In the embodiment, gNB1 810 is Figure 5 and Figure 6B The implementation of the fifth device 510 in [the system]. Furthermore, AMF 820 is [the implementation of the fifth device 510]. Figure 5 and Figure 6B The implementation of the sixth device 520 in UE 830. Figure 5 and Figure 6B The implementation of the seventh device 530 in the system. In this case, UE 830 can be an untrusted device. Furthermore, Figure 8 gNB2840 in the text is Figure 5 and Figure 6B The implementation of the eighth device 540 in the process.

[0181] like Figure 8 As shown, at 8010, gNB1 810 determines that UE 830 is an untrusted device. In some example implementations, UE 830 is determined to be an untrusted device by using the untrusted device detection method described above. Alternatively, gNB1 810 can determine UE 830 as an untrusted device by receiving this determination from another device. The scope of this disclosure is not limited in this respect.

[0182] Subsequently, at 8020, gNB1 810 can send an NGAP message to AMF 820, which includes a new trusted UE IE with a value of TRUE. Furthermore, gNB1 810 can send a new data use IE to AMF 820, which clarifies for which use case data collection is considered untrusted. That is, gNB1 810 can notify AMF 820 that UE 830 is an untrusted device. In one implementation, gNB1 810 can send an NGAP message to AMF 820, which includes a new trusted UE IE with a value of "TRUE" and another new data use IE clarifying for which use case data collection is considered untrusted.

[0183] At 8030, AMF 820 can store messages received from gNB1 810. Specifically, AMF 820 can store the same message as the one from gNB1 810 in the UE context. In some example implementations, AMF 820 can store the message in the UDM along with other UE information.

[0184] It should be understood that, for future purposes and for discovery purposes, the AMF 820 may then store it together with other UE information in a device that implements the UDM (also referred to as UDM).

[0185] Subsequently, at point 8040, UE 830 can move to the range of gNB2 840. That is, gNB2 840 can begin serving UE 830.

[0186] Furthermore, at 8050, gNB2 840 can communicate with AMF 820. Specifically, gNB2 840 can send a request to AMF 820 to determine whether UE 830 is an untrusted device. Additionally, AMF 820 can send information to gNB2 840 indicating that UE 830 is an untrusted device.

[0187] At 8060, AMF 820 can send a Trusted UE IE and a Data Usage IE to gNB2 840. Specifically, AMF 820 can notify gNB2 840 of the UEs identified as trusted and the corresponding data usage of those trusted UEs.

[0188] In this way, gNB1 810 can broadcast information about untrusted UE 830 to other gNBs via AMF 820 or other network devices. This ensures the integrity of the data used in the communication network.

[0189] Figure 9A flowchart of an example method 900 implemented at a first device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1 The angle description method of the first device 110 in the middle is 900.

[0190] In frame 910, the first device 110 obtains a result indicating that the second device is suspected to be an untrusted device based on information related to the location of the second device.

[0191] In block 920, the first device 110 determines information indicating whether the second device is an untrusted device based on at least one of a list of trusted devices or minimal road test (MDT) data associated with the second device.

[0192] In some example embodiments, method 900 further includes: receiving positioning-related information from the second device, the positioning-related information including at least one of reference coordinate data of the second device or a first measurement result of a first reference signal; determining a first candidate location of the second device based on the positioning-related information; determining a second candidate location of the second device by measuring a second reference signal from the second device; and determining that the second device is suspected to be an untrusted device in response to a difference between the first candidate location and the second candidate location being greater than a first threshold.

[0193] In this way, the first device 110 can determine whether the second device is an untrusted device through a two-stage verification process. Therefore, the security of the communication network is improved.

[0194] In some example embodiments, method 900 further includes: in response to determining that the second device is suspected to be an untrusted device, sending a request for a list of trusted devices to a third device, wherein the list of trusted devices indicates one or more pre-determined trusted devices; and receiving a response from the third device including the list of trusted devices. In this manner, the list of trusted devices can be obtained conveniently and efficiently.

[0195] In some example embodiments, method 900 further includes: receiving positioning-related information, the positioning-related information including at least one of reference coordinate data of the second device or a first measurement result of a first reference signal; determining a first candidate location of the second device based on the positioning-related information; determining a second candidate location of the second device by measuring a second reference signal from the second device; and determining that the second device is suspected to be an untrusted device in response to a difference between the first candidate location and the second candidate location being greater than a first threshold. Thus, the first stage of verification can be completed.

[0196] In some example embodiments, method 900 further includes determining information indicating whether the second device is an untrusted device by comparing location-related information of the second device with location-related information of trusted devices in a trusted device list. In some example implementations, in response to determining that the difference between a first measurement result of a first reference signal included in the location-related information of the second device and a second measurement result of the first reference signal included in the location-related information of the trusted device is greater than a second threshold, the first device 110 determines that the second device is an untrusted device; in response to determining that the difference is less than or equal to the second threshold, the first device 110 determines that the second device is not an untrusted device. Thus, the second stage of verification can be completed based on a trusted device list.

[0197] In some example embodiments, method 900 further includes: sending a request to a trusted device for location-related information concerning the trusted device; and receiving a response from the trusted device including the location-related information concerning the trusted device. This allows for convenient acquisition of a list of trusted devices.

[0198] In some example embodiments, the first device 110 may acquire MDT data associated with the second device, wherein the MDT data is assumed to be trustworthy; correlate the MDT data with information related to the location of the second device; and determine that the second device is an untrusted device in response to detecting an anomaly from the correlation results. In some example implementations, in response to no anomaly being detected from the correlation results, the first device 110 may send a request for a list of trusted devices to a third device, wherein the list of trusted devices indicates one or more pre-determined trusted devices. The first device 110 may then receive a response from the third device including the list of trusted devices. Thus, the second phase of verification can be completed based on the MDT data.

[0199] In some example embodiments, method 900 further includes: sending a request to a third device for MDT data associated with the second device; and receiving a response from the third device including the MDT data associated with the second device. This allows for convenient acquisition of the MDT data.

[0200] In some example embodiments, method 900 further includes receiving a configuration indicating a first threshold from a fourth device. Therefore, the first threshold can be flexibly configured by another device.

[0201] In some example embodiments, method 900 further includes sending information to a third device indicating whether the second device is an untrusted device. In this way, the first device 110 can notify other devices in the communication network of untrusted devices. Therefore, information about untrusted devices can be communicated to entities in the network.

[0202] In some example embodiments, the fourth device may include a network device that implements operation, management and maintenance (OAM).

[0203] In some example embodiments, the third device may include network equipment that implements User Data Management (UDM), Access and Mobility Functions (AMF), or Operation, Management and Maintenance (OAM).

[0204] Figure 10 A flowchart of an example method 1000 implemented at a third device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 1 The angle description method 1000 of the third device 130 in the middle.

[0205] At box 1010, the third device 130 receives a request for a list of trusted devices from the first device.

[0206] At box 1020, the third device 130 sends a response to the first device including a list of trusted devices for the first device to determine information indicating that the second device is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined.

[0207] In this way, the third device 110 can efficiently provide a list of trusted devices, thereby improving the security of the communication network.

[0208] In some example embodiments, the third device 130 may receive from the first device a request for MDT data associated with the second device, wherein the MDT data is assumed to be reliable; and send a response to the first device including the MDT data associated with the second device. This allows for convenient provision of the MDT data.

[0209] In some example embodiments, the third device 130 can receive information from the first device indicating whether the second device is an untrusted device. Therefore, information about untrusted devices can be communicated to entities in the communication network, further enhancing the security of the communication network.

[0210] In some example embodiments, the first device may include network equipment in a radio access network (RAN) or network equipment implementing location management function (LMF), the second device may include terminal equipment, and the third device may include network equipment implementing user data management (UDM) or access and mobility function (AMF) or operation, management and maintenance (OAM).

[0211] Figure 11 A flowchart of an example method 1100 implemented at a fifth device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 5The angle description method 1100 of the fifth device 510 in the middle.

[0212] In box 1110, in response to determining that the seventh device is untrusted, the fifth device 510 sends first information to the sixth device indicating that the seventh device is an untrusted device for the first service.

[0213] This allows entities within the communication network to be notified of information about untrusted devices, thereby improving the security of the communication network.

[0214] In some example embodiments, the fifth device 510 can receive second information from the sixth device indicating that the seventh device is a trusted device for the second service, wherein the first and second information share the same context. In this way, an untrusted device can be changed to a trusted device in certain scenarios or when certain conditions are met. Therefore, the trust level of a device can be changed flexibly or dynamically.

[0215] In some example embodiments, the fifth device 510 may perform a second service by using data from the seventh device.

[0216] In some exemplary embodiments, the fifth device 510 may include network equipment in a radio access network (RAN) or network equipment implementing location management functions (LMF), the sixth device may include other network equipment in a radio access network (RAN) or other network equipment implementing access and mobility management functions (AMF), and the seventh device may include terminal equipment.

[0217] Figure 12 A flowchart of an example method 1200 implemented at a sixth device according to some example embodiments of the present disclosure is shown. For the purposes of discussion, [the following will be discussed]. Figure 5 The sixth device 520 in the method of angle description 1200.

[0218] In frame 1210, the sixth device 520 receives from the fifth device first information indicating that the seventh device is an untrusted device for the first service.

[0219] In box 1220, the sixth device 520 performs at least one of the following: avoids using data from the seventh device in the first service, and sends the first information to the eighth device.

[0220] In this way, entities in the communication network can effectively know information about untrusted devices, which improves the security of the communication network.

[0221] In some example embodiments, the fifth device may include a network device in a radio access network (RAN), and the sixth device 520 may include another network device in the radio access network (RAN), wherein the sixth device 520 may avoid using data from the seventh device in the first service; and in response to determining that the seventh device is not untrusted, the sixth device 520 may send second information to the fifth device indicating that the seventh device is a trusted device for the second service, wherein the first information and the second information share the same context.

[0222] In this way, an untrusted device can be transformed into a trusted device in certain scenarios or when certain conditions are met. Therefore, the trust level of a device can be changed flexibly or dynamically.

[0223] In some example embodiments, the fifth device may include a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth device 520 may include a network device implementing an access and mobility management function (AMF), and wherein the sixth device 520 may store the first information in context information associated with the seventh device; and / or in response to receiving a request from the eighth device for context information associated with the seventh device, the sixth device 520 may send the first information to the eighth device.

[0224] In this way, information about untrusted devices can also be communicated to other devices in the communication network. This allows for a flexible and effective improvement in the security of the communication network.

[0225] In some example embodiments, the eighth device may include another network device in the radio access network (RAN).

[0226] In some example embodiments, a first means capable of performing any of the methods in method 900 (e.g., Figure 1 The first device 110 may include a component for performing the corresponding operation of method 900. This component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module. The first device may be implemented as or included in... Figure 1 In the first device 110.

[0227] In some example embodiments, the first device includes components for obtaining results indicating that the second device is suspected to be an untrusted device based on information related to the location of the second device; and components for determining whether the information indicating that the second device is an untrusted device is based on at least one of a list of trusted devices associated with the second device or minimal road test (MDT) data.

[0228] In some example embodiments, the first device further includes: components for receiving positioning-related information from the second device, the positioning-related information including at least one of reference coordinate data of the second device or a first measurement result of a first reference signal; components for determining a first candidate location of the second device based on the positioning-related information; components for determining a second candidate location of the second device by measuring a second reference signal from the second device; and components for determining that the second device is suspected to be an untrusted device in response to a difference between the first candidate location and the second candidate location being greater than a first threshold.

[0229] In some example embodiments, the first device further includes: a component for sending a request for a list of trusted devices to a third device in response to determining that the second device is suspected to be an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined; and a component for receiving a response from the third device including the list of trusted devices.

[0230] In some example embodiments, the first device further includes: components for receiving positioning-related information of the second device, the positioning-related information including at least one of reference coordinate data of the second device or a first measurement result of a first reference signal; components for determining a first candidate location of the second device based on the positioning-related information of the second device; components for determining a second candidate location of the second device by measuring a second reference signal from the second device; and components for determining that the second device is suspected to be an untrusted device in response to a difference between the first candidate location and the second candidate location being greater than a first threshold.

[0231] In some example embodiments, the first device further includes: components for acquiring MDT data associated with the second device, wherein the MDT data is assumed to be trustworthy; components for correlating the MDT data with information related to the location of the second device; and components for determining that the second device is an untrustworthy device in response to detecting an anomaly from the correlating results.

[0232] In some example embodiments, the first device further includes: a component for sending a request to a third device for MDT data associated with the second device; and a component for receiving a response from the third device including the MDT data associated with the second device.

[0233] In some example embodiments, the first device further includes: a component for sending a request for a list of trusted devices to a third device in response to no anomaly detected from the associated results, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined; and a component for receiving a response from the third device including the list of trusted devices.

[0234] In some example embodiments, the first device further includes a component for determining whether information indicating whether the second device is an untrusted device by comparing information related to the location of the second device with information related to the location of trusted devices in a list of trusted devices.

[0235] In some example embodiments, the first apparatus further includes: a component for sending a request to a trusted device for information related to the location of the trusted device; and a component for receiving a response from the trusted device including the location-related information of the trusted device.

[0236] In some exemplary embodiments, the first device further includes: a component for: determining that the second device is an untrusted device in response to determining that the difference between a first measurement result of a first reference signal included in information related to the positioning of the second device and a second measurement result of a first reference signal included in information related to the positioning of a trusted device is greater than a second threshold; and determining that the second device is not an untrusted device in response to determining that the difference is less than or equal to the second threshold.

[0237] In some example embodiments, the first device further includes a component for receiving a configuration indicating a first threshold from the fourth device.

[0238] In some example embodiments, the fourth device includes a network device that implements operation, management and maintenance (OAM).

[0239] In some example embodiments, the first device further includes a component for sending information to the third device indicating whether the second device is an untrusted device.

[0240] In some example embodiments, the third device includes a network device that implements User Data Management (UDM), Access and Mobility Functions (AMF), or Operation, Management and Maintenance (OAM).

[0241] In some example embodiments, a third means (e.g., capable of performing any of the methods in method 1000) Figure 1 The third device 130 may include a component for performing the corresponding operation of method 1000. This component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module. The third device may be implemented as or included in... Figure 1 The third device 130 in the middle.

[0242] In some example embodiments, the third device includes: a component for receiving a request for a list of trusted devices from the first device; and a component for sending a response including the list of trusted devices to the first device for the first device to determine information indicating that the second device is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined.

[0243] In some example embodiments, the third device includes: a component for receiving from the first device a request for MDT data associated with the second device, wherein the MDT data is assumed to be trustworthy; and a component for sending to the first device a response including the MDT data associated with the second device.

[0244] In some example embodiments, the third device includes a component for receiving information from the first device indicating whether the second device is an untrusted device.

[0245] Optionally, the first device includes network equipment in a radio access network (RAN) or network equipment implementing location management function (LMF), the second device includes terminal equipment, and the third device includes network equipment implementing user data management (UDM), access and mobility function (AMF), or operation, management and maintenance (OAM).

[0246] In some example embodiments, a fifth means capable of performing any of the methods in method 1100 (e.g., Figure 5 The fifth device 510 may include a component for performing a corresponding operation of method 1100. This component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module. The fifth device may be implemented as or included in... Figure 5 The fifth device 510 in the process.

[0247] In some example embodiments, the fifth device includes a component for sending first information to the sixth device in response to determining that the seventh device is untrusted, indicating that the seventh device is an untrusted device for the first service.

[0248] In some example embodiments, the fifth device includes a component for receiving second information from the sixth device indicating that the seventh device is a trusted device for the second service, wherein the first information and the second information share the same context.

[0249] In some example embodiments, the fifth device includes a component for performing a second service by using data from the seventh device.

[0250] In some exemplary embodiments, the fifth device includes a network device in a radio access network (RAN) or a network device implementing location management functions (LMF), the sixth device includes another network device in a radio access network (RAN) or another network device implementing access and mobility management functions (AMF), and the seventh device includes a terminal device.

[0251] In some example embodiments, a sixth device capable of performing any of the methods in method 1200 (e.g., Figure 5The sixth device 520 may include a component for performing a corresponding operation of method 1200. This component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module. The fourth device may be implemented as or included in... Figure 5 The sixth device 520 in the system.

[0252] In some example embodiments, the sixth device includes: components for receiving first information from the fifth device indicating that the seventh device is an untrusted device for the first service; and components for performing at least one of: avoiding the use of data from the seventh device in the first service, and sending the first information to the eighth device.

[0253] In some example embodiments, the fifth device includes network equipment in a radio access network (RAN), and the sixth device includes additional network equipment in the radio access network (RAN), wherein the sixth device includes: components for avoiding the use of data from the seventh device in the first service; and components for sending second information to the fifth device in response to determining that the seventh device is not untrusted, indicating that the seventh device is a trusted device for the second service, wherein the first information and the second information share the same context.

[0254] In some example embodiments, the fifth device includes a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth device includes a network device implementing an access and mobility management function (AMF), and wherein the sixth device includes: components for storing first information in context information associated with the seventh device; and / or components for sending the first information to the eighth device in response to receiving a request from the eighth device for context information associated with the seventh device.

[0255] In some example embodiments, the eighth device includes additional network equipment in the radio access network (RAN).

[0256] Figure 13 This is a simplified block diagram of a device 1300 suitable for implementing exemplary embodiments of the present disclosure. The device 1300 can be provided to implement a communication device, such as... Figure 1 The first device 110 and the third device 130 shown, and as... Figure 5 The fifth device 510 and the sixth device 520 are shown. As shown, device 1300 includes one or more processors 1310, one or more memories 1320 coupled to processor 1310, and one or more communication modules 1340 coupled to processor 1310.

[0257] Communication module 1340 is used for bidirectional communication. Communication module 1340 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interface can represent any interface necessary for communication with other network elements. In some example embodiments, communication module 1340 may include at least one antenna.

[0258] Processor 1310 can be of any type suitable for a local technology network, and by way of non-limiting example, can include one or more of the following: general-purpose computer, special-purpose computer, microprocessor, digital signal processor (DSP), and processor based on a multi-core processor architecture. Device 1300 can have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock of a synchronous main processor.

[0259] Memory 1320 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 1324, electrically programmable read-only memory (EPROM), flash memory, hard disk, optical disc (CD), digital video disc (DVD), optical disc, laser disc, and other magnetic and / or optical storage devices. Examples of volatile memories include, but are not limited to, random access memory (RAM) 1322 and other volatile memories that will not be maintained during power loss.

[0260] Computer program 1330 includes computer-executable instructions that are executed by an associated processor 1310. The instructions of program 1330 may include instructions for performing operations / actions of some example embodiments of this disclosure. Program 1330 may be stored in memory, such as ROM 1324. Processor 1310 may perform any suitable actions and processes by loading program 1330 into RAM 1322.

[0261] Example embodiments of this disclosure can be implemented using program 1330, enabling device 1300 to execute as described in the reference. Figure 2-12 Any process discussed in this disclosure. Exemplary embodiments of this disclosure may also be implemented in hardware or a combination of software and hardware.

[0262] In some example embodiments, program 1330 may be tangibly contained in a computer-readable medium, which may be included in device 1300 (such as in memory 1320) or other storage devices accessible to device 1300. Device 1300 may load program 1330 from the computer-readable medium into RAM 1322 for execution. In some example embodiments, the computer-readable medium may include any type of non-transient storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. As used herein, the term "non-transient" refers to a limitation on the medium itself (i.e., tangible, not tactile), rather than a limitation on data storage persistence (e.g., RAM versus ROM).

[0263] Figure 14 An example of a computer-readable medium 1400, which may be in the form of a CD, DVD, or other optical storage disc, is shown. A program 1330 is stored on the computer-readable medium 1400.

[0264] In general, the various embodiments of this disclosure can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, and others can be implemented in firmware or software executed by a controller, microprocessor, or other computing device. While various aspects of the embodiments of this disclosure are illustrated and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof, as examples of non-limiting examples.

[0265] Some exemplary embodiments of this disclosure also provide at least one computer program product tangibly stored on a computer-readable medium (such as a non-transitory computer-readable medium). The computer program product includes computer-executable instructions, such as those included in a program module, which are executed in a device on a target physical or virtual processor to perform any of the methods described above. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc., that perform a particular task or implement a particular abstract data type. The functionality of the program module can be combined or split as needed among program modules in various embodiments. The machine-executable instructions for the program module can execute within a local or distributed device. In a distributed device, the program module can reside on both local and remote storage media.

[0266] Program code for implementing the methods of this disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that, when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0267] In the context of this disclosure, computer program code or related data may be carried on any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.

[0268] Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any suitable combination thereof. More specific examples of computer-readable storage media include electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable optical disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0269] Furthermore, although operations are described in a specific order, this should not be construed as requiring that such operations be performed in the specific order shown or sequentially, or that all shown operations be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the discussion above, these should not be construed as limiting the scope of this disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated otherwise, certain features described in the context of a single embodiment may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated otherwise, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0270] Although this disclosure has been described in language specific to structural features and / or methodological actions, it should be understood that the disclosure as defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms of implementing the claims.

[0271] Clause 1. A first device comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first device to at least: obtain a result indicating that the second device is suspected to be an untrusted device based on information related to the location of a second device; and determine information indicating whether the second device is an untrusted device based on at least one of a list of trusted devices associated with the second device or minimal road test (MDT) data.

[0272] Clause 2. The first device according to Clause 1, wherein the first device includes network equipment in a radio access network (RAN), and the second device includes terminal equipment, and wherein the first device is configured to: receive from the second device information relating to the location of the second device, the information relating to the location including at least one of reference coordinate data of the second device or a first measurement result of a first reference signal; determine a first candidate location of the second device based on the information relating to the location of the second device; determine a second candidate location of the second device by measuring a second reference signal from the second device; and determine that the second device is suspected to be the untrusted device in response to a difference between the first candidate location and the second candidate location being greater than a first threshold.

[0273] Clause 3. The first device according to Clause 2, wherein the first device is configured to: in response to determining that the second device is suspected to be the untrusted device, send a request to the third device for the list of trusted devices, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined; and receive a response from the third device including the list of trusted devices.

[0274] Clause 4. The first device according to Clause 1, wherein the first device includes a network device implementing a Location Management Function (LMF), and the second device includes a terminal device, and wherein the first device is configured to: receive information relating to the location of the second device, the information relating to the location including at least one of reference coordinate data of the second device or a first measurement result of a first reference signal; determine a first candidate location of the second device based on the information relating to the location of the second device; determine a second candidate location of the second device by measuring a second reference signal from the second device; and determine that the second device is suspected to be the untrusted device in response to a difference between the first candidate location and the second candidate location being greater than a first threshold.

[0275] Clause 5. The first device according to Clause 1 or 4, wherein the first device is configured to: acquire MDT data associated with the second device, wherein the MDT data is assumed to be trustworthy; correlate the MDT data with information related to the location of the second device; and determine the second device as an untrustworthy device in response to detecting an anomaly from the correlation result.

[0276] Clause 6. The first device according to Clause 5, wherein the first device is configured to: send a request to a third device for the MDT data associated with the second device; and receive from the third device a response including the MDT data associated with the second device.

[0277] Clause 7. The first device according to Clause 5 or 6, wherein the first device is configured to: in response to the absence of anomalies detected from the relevant results, send a request to the third device for the list of trusted devices, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined; and receive a response from the third device including the list of trusted devices.

[0278] Clause 8. A first device according to any one of Clauses 1 to 7, wherein the first device is configured to: determine, by comparing information relating to the location of the second device with information relating to the location of trusted devices in the trusted device list, information indicating whether the second device is an untrusted device.

[0279] Clause 9. The first means according to Clause 8, wherein the first means is configured to: send a request to the trusted device for information relating to the location of the trusted device; and receive from the trusted device a response including the information relating to the location of the trusted device.

[0280] Clause 10. The first device according to Clause 8 or 9, wherein the first device is configured to: determine that the second device is the untrusted device in response to determining that the difference between a first measurement result of a first reference signal included in the information related to the location of the second device and a second measurement result of the first reference signal included in the information related to the location of the trusted device is greater than a second threshold; and determine that the second device is not the untrusted device in response to determining that the difference is less than or equal to the second threshold.

[0281] Clause 11. A first device according to any one of Clauses 2 to 10, wherein the first device is configured to: receive a configuration indicating the first threshold from a fourth device.

[0282] Clause 12. The first device pursuant to Clause 11, wherein the fourth device includes network equipment for implementing operation, administration and maintenance (OAM).

[0283] Clause 13. The first device according to any one of Clauses 1 to 12, wherein the first device is caused to:

[0284] Send the information to the third device indicating whether the second device is the untrusted device.

[0285] Clause 14. A first device under any one of Clauses 3, 6 to 13, wherein the third device includes network equipment that implements User Data Management (UDM) or Access and Mobility Function (AMF) or Operation, Administration and Maintenance (OAM).

[0286] Clause 15. A third means comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third means to at least: receive a request for a list of trusted devices from a first means; and send a response to the first means including the list of trusted devices for the first means to determine information indicating that a second means is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined.

[0287] Clause 16. The third device according to Clause 15, wherein the third device is configured to: receive from the first device a request for MDT data associated with the second device, wherein the MDT data is assumed to be reliable; and send to the first device a response including the MDT data associated with the second device.

[0288] Clause 17. A third device pursuant to Clause 15 or 16, wherein the third device is configured to: receive from the first device information indicating whether the second device is an untrusted device.

[0289] Clause 18. A third device under any one of Clauses 15 to 17, wherein the first device includes network equipment in a radio access network (RAN) or network equipment implementing location management functions (LMF), the second device includes terminal equipment, and the third device includes network equipment implementing user data management (UDM) or access and mobility functions (AMF) or operation, management and maintenance (OAM).

[0290] Clause 19. A fifth device, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fifth device to at least: in response to determining that a seventh device is untrusted, send first information to a sixth device indicating that the seventh device is an untrusted device for a first service.

[0291] Clause 20. The fifth device pursuant to Clause 19, wherein the fifth device is configured to: receive from the sixth device second information indicating that the seventh device is a trusted device for the second service, wherein the first information and the second information share the same context.

[0292] Clause 21. The fifth device pursuant to Clause 20, wherein the fifth device is configured to perform the second service by using data from the seventh device.

[0293] Clause 22. A fifth device under any one of Clauses 15 to 17, wherein the fifth device includes network equipment in a radio access network (RAN) or network equipment implementing location management functions (LMF), the sixth device includes additional network equipment in a radio access network (RAN) or additional network equipment implementing access and mobility management functions (AMF), and the seventh device includes terminal equipment.

[0294] Clause 23. A sixth device, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the sixth device to at least: receive first information from a fifth device indicating that a seventh device is an untrusted device for a first service; and perform at least one of the following: avoid using data from the seventh device in the first service, and send the first information to an eighth device.

[0295] Clause 24. The sixth device pursuant to Clause 23, wherein the fifth device includes network equipment in a radio access network (RAN), and the sixth device includes additional network equipment in the radio access network (RAN), wherein the sixth device is configured to: avoid using data from the seventh device in the first service; and, in response to determining that the seventh device is not untrusted, send second information to the fifth device indicating that the seventh device is a trusted device for the second service, wherein the first information and the second information share the same context.

[0296] Clause 25. The sixth device pursuant to Clause 23, wherein the fifth device includes a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth device includes a network device implementing an access and mobility management function (AMF), and wherein the sixth device is configured to: store the first information in context information associated with the seventh device; and / or, in response to receiving a request from the eighth device for context information associated with the seventh device, send the first information to the eighth device.

[0297] Clause 26. The sixth device pursuant to Clause 25, wherein the eighth device includes additional network equipment in the radio access network (RAN).

[0298] Clause 27. A method comprising: obtaining, based on information relating to the location of a second device, a result indicating that the second device is suspected to be an untrusted device; and determining, based on at least one of a list of trusted devices associated with the second device or minimal road test (MDT) data, information indicating whether the second device is an untrusted device.

[0299] Clause 28. A method comprising: receiving from a first device a request for a list of trusted devices; and sending to the first device a response including the list of trusted devices for the first device to determine information indicating that a second device is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined.

[0300] Clause 29. A method comprising: in response to determining that a seventh device is untrusted, sending to a sixth device first information indicating that the seventh device is an untrusted device for a first service.

[0301] Clause 30. A method comprising: receiving from a fifth device first information indicating that a seventh device is an untrusted device for a first service; and performing at least one of the following: avoiding the use of data from the seventh device in the first service, and sending the first information to an eighth device.

[0302] Clause 31. A first apparatus comprising: a component for obtaining a result indicating that the second device is suspected to be an untrusted device based on information related to the location of the second device; and a component for determining, based on at least one of a list of trusted devices or minimized drive test (MDT) data associated with the second device, information indicating whether the second device is an untrusted device.

[0303] Clause 32. A third apparatus comprising: components for receiving a request for a list of trusted devices from a first apparatus; and components for sending a response to the first apparatus including the list of trusted devices for the first apparatus to determine information indicating that a second apparatus is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices that have been predetermined.

[0304] Clause 33. A fifth device, comprising: a component for sending first information to a sixth device in response to determining that a seventh device is untrusted, indicating that the seventh device is an untrusted device for the first service.

[0305] Clause 34. A sixth device, comprising: components for receiving from a fifth device first information indicating that a seventh device is an untrusted device for a first service; and components for performing at least one of: avoiding the use of data from the seventh device in the first service, and sending the first information to an eighth device.

[0306] Clause 35. A computer-readable medium comprising instructions stored thereon for causing a device to perform at least the method pursuant to Clause 27, or the method pursuant to Clause 28, or the method pursuant to Clause 29, or the method pursuant to Clause 30.

Claims

1. A first apparatus for communication, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to: obtain, based on information related to positioning of a second apparatus, a result indicating that the second apparatus is suspected to be an untrustworthy device; and determine, based on at least one of a list of trustworthy devices or minimization of drive tests, MDT, data associated with the second apparatus, information indicating whether the second apparatus is an untrustworthy device.

2. The first apparatus of claim 1, wherein the first apparatus comprises a network device in a radio access network, RAN, and the second apparatus comprises a terminal device, and wherein the first apparatus is caused to: receive, from the second apparatus, the information related to positioning of the second apparatus, the information related to positioning comprising at least one of reference coordinate data of the second apparatus or first measurement results of first reference signals; determine, based on the information related to positioning of the second apparatus, a first candidate position of the second apparatus; determine, by measuring second reference signals from the second apparatus, a second candidate position of the second apparatus; and determine, in response to a difference between the first candidate position and the second candidate position being greater than a first threshold, that the second apparatus is suspected to be the untrustworthy device.

3. The first apparatus of claim 2, wherein the first apparatus is caused to: in response to determining that the second apparatus is suspected to be the untrustworthy device, send, to a third apparatus, a request for the list of trustworthy devices, wherein the list of trustworthy devices indicates one or more trustworthy devices that are predetermined; and receive, from the third apparatus, a response comprising the list of trustworthy devices.

4. The first apparatus of claim 1, wherein the first apparatus comprises a network device implementing a location management function, LMF, and the second apparatus comprises a terminal device, and wherein the first apparatus is caused to: receive the information related to positioning of the second apparatus, the information related to positioning comprising at least one of reference coordinate data of the second apparatus or first measurement results of first reference signals; determine, based on the information related to positioning of the second apparatus, a first candidate position of the second apparatus; determine, by measuring second reference signals from the second apparatus, a second candidate position of the second apparatus; and determine, in response to a difference between the first candidate position and the second candidate position being greater than a first threshold, that the second apparatus is suspected to be the untrustworthy device.

5. The first apparatus of claim 1 or 4, wherein the first apparatus is caused to: obtain MDT data associated with the second apparatus, wherein the MDT data is assumed to be trustworthy; correlate the MDT data with the information related to positioning of the second apparatus; and determine, in response to detecting an anomaly from a result of the correlation, that the second apparatus is an untrustworthy device.

6. The first apparatus of claim 5, wherein the first apparatus is caused to: ​ ​ ​ ​ sending, to a third apparatus, a request for the MDT data associated with the second apparatus; and receiving, from the third apparatus, a response including the MDT data associated with the second apparatus.

7. The first apparatus of claim 5, wherein the first apparatus is caused to: in response to not detecting an anomaly from the results of the correlation, send, to a third apparatus, a request for the list of trusted devices, wherein the list of trusted devices indicates one or more trusted devices predetermined; and receive, from the third apparatus, a response including the list of trusted devices.

8. A third apparatus for communication, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third apparatus at least to: receive, from a first apparatus, a request for a list of trusted devices; and send, to the first apparatus, a response including the list of trusted devices for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the list of trusted devices indicates one or more trusted devices predetermined.

9. A fifth apparatus for communication, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fifth apparatus at least to: in response to determining a seventh apparatus is untrusted, send, to a sixth apparatus, first information indicating the seventh apparatus is an untrusted device for a first service.

10. A sixth apparatus for communication, comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the sixth apparatus at least to: receive, from a fifth apparatus, first information indicating a seventh apparatus is an untrusted device for a first service; and perform at least one of: avoid using data from the seventh apparatus in the first service, and send the first information to an eighth apparatus.