Untrusted device detection
A two-stage verification process using positioning and MDT data with a trusted device list addresses data tampering in communication networks, ensuring secure AI/ML model integrity and network optimization.
Patent Information
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-09
- Publication Date
- 2026-03-11
AI Technical Summary
Existing communication networks face challenges in ensuring the security and authenticity of data used for AI/ML model training and inference, as malicious devices can tamper with training data, leading to corrupted models and suboptimal network operations.
A two-stage verification process is employed to detect untrusted devices by analyzing positioning information and Minimization of Drive Tests (MDT) data, using a trusted device list to confirm or refute the suspicious device's trustworthiness.
This approach effectively identifies and prevents the propagation of data poisoning attacks, ensuring the integrity of AI/ML models and maintaining network optimization and management accuracy.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Various example embodiments of the present disclosure generally relate to the field of telecommunication and in particular, to methods, devices, apparatuses and computer readable storage medium for untrusted device detection. BACKGROUND
[0002] With the development of communication technology, data transmitted between devices, e.g., from user equipment (UE) to a base station, in the communication network may include data used for various purposes. In one aspect, such data may be applied for training or inference of an Aritificial intelligence (AI) / machine learning (ML) model in the communication network, e.g., for purpose of network management and optimization. The performance of an AI / ML model may be highly dependent to genuineness and authenticity of the data used in the training or inference. Thus, it is necessary to ensure the security of the data. SUMMARY
[0003] In a first aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to: obtain a result indicating that a second apparatus is suspicious to be an untrusted device based on information related to positioning of the second apparatus; and determine information indicating whether the second apparatus is the untrusted device based on at least one of a trusted device list or minimization of drive tests (MDT) data associated with the second apparatus.
[0004] In a second aspect of the present disclosure, there is provided a third apparatus. The third apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the third apparatus at least to: receive, from a first apparatus, a request for the trusted device list; and transmit, to the first apparatus, a response comprising the trusted device list for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the trusted device list indicates one or more trusted devices that are predetermined.
[0005] In a third aspect of the present disclosure, there is provided a fifth apparatus. The fifth apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the fifth apparatus at least to: in response to determining that a seventh apparatus is untrusted, transmit, to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
[0006] In a fourth aspect of the present disclosure, there is provided a sixth apparatus. The sixth apparatus comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the sixth apparatus at least to: receive, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; and perform at least one of: refraining from using data from the seventh apparatus in the first service, or transmitting the first information to an eighth apparatus.
[0007] In a fifth aspect of the present disclosure, there is provided a method. The method comprises: obtaining a result indicating that a second apparatus is suspicious to be an untrusted device based on information related to positioning of the second apparatus; and determining information indicating whether the second apparatus is the untrusted device based on at least one of a trusted device list or minimization of drive tests (MDT) data associated with the second apparatus.
[0008] In a sixth aspect of the present disclosure, there is provided a method. The method comprises: receiving, from a first apparatus, a request for the trusted device list; and transmitting, to the first apparatus, a response comprising the trusted device list for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the trusted device list indicates one or more trusted devices that are predetermined.
[0009] In a seventh aspect of the present disclosure, there is provided a method. The method comprises: in response to determining that a seventh apparatus is untrusted, transmitting to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
[0010] In an eighth aspect of the present disclosure, there is provided a method. The method comprises: receiving, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; and performing at least one of: refraining from using data from the seventh apparatus in the first service, or transmitting the first information to an eighth apparatus.
[0011] In a ninth aspect of the present disclosure, there is provided a first apparatus. The first apparatus comprises means for obtaining a result indicating that a second apparatus is suspicious to be an untrusted device based on information related to positioning of the second apparatus; and means for determining information indicating whether the second apparatus is the untrusted device based on at least one of a trusted device list or minimization of drive tests (MDT) data associated with the second apparatus.
[0012] In a tenth aspect of the present disclosure, there is provided a third apparatus. The second apparatus comprises means for receiving, from a first apparatus, a request for the trusted device list; and means for transmitting, to the first apparatus, a response comprising the trusted device list for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the trusted device list indicates one or more trusted devices that are predetermined.
[0013] In an eleventh aspect of the present disclosure, there is provided a fifth apparatus. The third apparatus comprises means for in response to determining that a seventh apparatus is untrusted, transmitting to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
[0014] In a twelfth aspect of the present disclosure, there is provided a sixth apparatus. The fourth apparatus comprises means for receiving, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; and means for performing at least one of: refraining from using data from the seventh apparatus in the first service, or transmitting the first information to an eighth apparatus.
[0015] In a thirteenth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the fifth aspect.
[0016] In a fourteenth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the sixth aspect.
[0017] In a fifteenth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the seventh aspect.
[0018] In a sixteenth aspect of the present disclosure, there is provided a computer readable medium. The computer readable medium comprises instructions stored thereon for causing an apparatus to perform at least the method according to the eighth aspect.
[0019] It is to be understood that the Summary section is not intended to identify key or essential features of embodiments of the present disclosure, nor is it intended to be used to limit the scope of the present disclosure. Other features of the present disclosure will become easily comprehensible through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Some example embodiments will now be described with reference to the accompanying drawings, where:
[0021] FIG. 1 illustrates an example communication environment in which example embodiments of the present disclosure can be implemented;
[0022] FIG. 2 illustrates a signaling flow for a process of untrusted device detection in accordance with some example embodiments of the present disclosure;
[0023] FIG. 3 illustrates an example signaling flow for a process of untrusted device detection in accordance with some example embodiments of the present disclosure;
[0024] FIG. 4 illustrates another example signaling flow for a process of untrusted device detection in accordance with some example embodiments of the present disclosure;
[0025] FIG. 5 illustrates another example communication environment in which example embodiments of the present disclosure can be implemented;
[0026] FIG. 6A illustrates a signaling flow for a process of broadcasting untrusted device information in accordance with some example embodiments of the present disclosure;
[0027] FIG. 6B illustrates another signaling flow for a process of broadcasting untrusted device information in accordance with some example embodiments of the present disclosure;
[0028] FIG. 7 illustrates an example signaling flow for a process of broadcasting untrusted device information in accordance with some example embodiments of the present disclosure;
[0029] FIG. 8 illustrates another example signaling flow for a process of broadcasting untrusted device information in accordance with some example embodiments of the present disclosure
[0030] FIG. 9 illustrates a flowchart of a method implemented at a first apparatus in accordance with some example embodiments of the present disclosure;
[0031] FIG. 10 illustrates a flowchart of a method implemented at a third apparatus in accordance with some example embodiments of the present disclosure;
[0032] FIG. 11 illustrates a flowchart of a method implemented at a fifth apparatus in accordance with some example embodiments of the present disclosure;
[0033] FIG. 12 illustrates a flowchart of a method implemented at a sixth apparatus in accordance with some example embodiments of the present disclosure;
[0034] FIG. 13 illustrates a simplified block diagram of a device that is suitable for implementing example embodiments of the present disclosure; and
[0035] FIG. 14 illustrates a block diagram of an example computer readable medium in accordance with some example embodiments of the present disclosure.
[0036] Throughout the drawings, the same or similar reference numerals represent the same or similar element. DETAILED DESCRIPTION
[0037] Principle of the present disclosure will now be described with reference to some example embodiments. It is to be understood that these embodiments are described only for the purpose of illustration and help those skilled in the art to understand and implement the present disclosure, without suggesting any limitation as to the scope of the disclosure. Embodiments described herein can be implemented in various manners other than the ones described below.
[0038] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skills in the art to which this disclosure belongs.
[0039] References in the present disclosure to “one embodiment,” “an embodiment,” “an example embodiment,” and the like indicate that the embodiment described may include a particular feature, structure, or characteristic, but it is not necessary that every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases are not necessarily referring to the same embodiment. Further, when a particular feature, structure, or characteristic is described in connection with an embodiment, it is submitted that it is within the knowledge of one skilled in the art to affect such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described.
[0040] It shall be understood that although the terms “first,” “second,”..., etc. in front of noun(s) and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another and they do not limit the order of the noun(s). For example, a first element could be termed a second element, and similarly, a second element could be termed a first element, without departing from the scope of example embodiments. As used herein, the term “and / or” includes any and all combinations of one or more of the listed terms.
[0041] As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or”, mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0042] As used herein, unless stated explicitly, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs and one or more intervening steps may be included.
[0043] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of example embodiments. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0044] As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0045] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or 5 multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device. 10
[0046] As used herein, the term “communication network” refers to a network following any suitable communication standards, such as New Radio (NR), Long Term Evolution (LTE), LTE-Advanced (LTE-A), Wideband Code Division Multiple Access (WCDMA), High-Speed Packet Access (HSPA), Narrow Band Internet of Things (NB-IoT) and so on. Furthermore, the communications between a terminal device and a network device in the 15 communication network may be performed according to any suitable generation communication protocols, including, but not limited to, the first generation (1G), the second generation (2G), 2.5G, 2.75G, the third generation (3G), the fourth generation (4G), 4.5G, the fifth generation (5G), 5.5G, the sixth generation (6G) communication protocols, and / or any other protocols either currently known or to be developed in the future. Embodiments of the present disclosure may be applied in various communication systems. Given the rapid development in communications, there will of course also be future type communication technologies and systems with which the present disclosure may be embodied. It should not be seen as limiting the scope of the present disclosure to only the aforementioned system.
[0047] As used herein, the term “network device” refers to a node in a communication network via which a terminal device accesses the network and receives services therefrom. The network device may refer to a base station (BS) or an access point (AP), for example, a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), an NR NB (also referred to as a gNB), a Remote Radio Unit (RRU), a radio header (RH), a remote radio head (RRH), a relay, an Integrated Access and Backhaul (IAB) node, a low power node such as a femto, a pico, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, an aircraft network device, and so forth, depending on the applied terminology and technology. In some example embodiments, radio access network (RAN) split architecture comprises a Centralized Unit (CU) and a Distributed Unit (DU) at an IAB donor node. An IAB node comprises a Mobile Terminal (IAB-MT) part that behaves like a UE toward the parent node, and a DU part of an IAB node behaves like a base station toward the next-hop IAB node.
[0048] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE), a Subscriber Station (SS), a Portable Subscriber Station, a Mobile Station (MS), or an Access Terminal (AT). The terminal device may include, but not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA), portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE), laptop-mounted equipment (LME), USB dongles, smart devices, wireless customer-premises equipment (CPE), an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD), a vehicle, a drone, a medical device and applications (e.g., remote surgery), an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts), a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node). In the following description, the terms “terminal device”, “communication device”, “terminal”, “user equipment” and “UE” may be used interchangeably.
[0049] As used herein, the term “resource,” “transmission resource,” “resource block,” “physical resource block” (PRB), “uplink resource,” or “downlink resource” may refer to any resource for performing a communication, for example, a communication between a terminal device and a network device, such as a resource in time domain, a resource in frequency domain, a resource in space domain, a resource in code domain, or any other combination of the time, frequency, space and / or code domain resource enabling a communication, and the like. In the following, unless explicitly stated, a resource in both frequency domain and time domain will be used as an example of a transmission resource for describing some example embodiments of the present disclosure. It is noted that example embodiments of the present disclosure are equally applicable to other resources in other domains.
[0050] Conventionally, there are multiple use cases in which a UE sends training data either to a base station, e.g., a gNB, or the core network for AI / ML model training purposes. These use cases involve, for example, but not limited to, location-based services, network management and optimization, CSI feedback, beam formation, and so on. Furthermore, a UE may send some data via MDT as well that may be used for training.
[0051] In all the above use-cases, in the case the UE tampers with the training data it sends to an AI / ML model training entity in a network (NW), or tampers the data even during inferences phase (i.e. sends a poisonous data sample for inference output to the NW), the complete AI / ML model may be tampered with to predict malicious values, or the actions the network takes may be tampered with by providing malicious data during inference.
[0052] For example, in the case of UE positioning estimation / prediction use cases, if a UE or a group of malicious UE(s) sends tampered data during the AI / ML model training phase, the complete AI / ML model can be corrupted, which may lead to incorrect positioning services to all the consumers of that AI / ML model. Furthermore, when considering the case of network management and optimization, and a malicious UE provides tampered data during inference, e.g., the UE reports incorrect network performance metrics (e.g. signal strength, data throughput), the AI / ML model predicts incorrect inference, which may lead to suboptimal network allocation and mislead network optimization algorithms.
[0053] To solve the above and / or other potential issues, example embodiments of the present disclosure provide a solution for detecting the untrusted device. The proposed solution first detects if there is a data poisoning attack or not, and identifies the malicious UE(s), which are also referred to as untrusted device(s). The information of the malicious UE(s) is proposed to be transmitted to relevant stakeholders (e.g., training nodes), such that the propagation of this attack can be prevented / minimized.
[0054] Example embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0055] FIG. I illustrates an example communication environment 100 in which example embodiments of the present disclosure can be implemented. The communication environment 100 involves a plurality of communication devices, including a first apparatus 110, a second apparatus 120, a third apparatus 130, and a fourth apparatus 140. The first apparatus 110 may communicate bidirectionally with the second apparatus 120, the third apparatus 130, or the fourth apparatus 140.
[0056] In an example of FIG. 1, the first apparatus 110 may be implemented as a network device in a radio access network (RAN), such as a base station, and the second apparatus 120 may be implemented as a terminal device, e.g., a UE served by the base station. In an alternative example, the first apparatus 110 may be implemented as a core network function entity, e.g., a device implementing a location management function (LMF), that may communicate with the first apparatus 110 bidirectionally.
[0057] In some example embodiments, if the first apparatus 110 is a network device in a RAN and the second apparatus 120 is a terminal device, a link from the second apparatus 120 to the first apparatus 110 is referred to as an uplink (UL), while a link from the first apparatus 110 to the second apparatus 120 is referred to as a downlink (DL). In UL, the second apparatus 120 is a transmitting (TX) device (or a transmitter) and the first apparatus 110 is a receiving (RX) device (or a receiver). In DL, the first apparatus 110 is a TX device (or a transmitter) and the second apparatus 120 is a RX device (or a receiver).
[0058] Moreover, the third apparatus 130 and the fourth apparatus 140 may be implemented as core network devices. In some example implementations, the third apparatus 130 may implement an access and mobility function (AMF) or operations, administration, and maintenance (0AM). The fourth apparatus 140 may implement user data management (UDM).
[0059] Communications in the communication environment 100 may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols of the first generation (1G), the second generation (2G), the third generation (3G), the fourth generation (4G), the fifth generation (5G), 5.5G, the sixth generation (6G), and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0060] It is to be understood that the number of apparatuses and their connections shown in FIG. 1 are only for the purpose of illustration without suggesting any limitation. The communication environment 100 may include any suitable number of apparatuses configured to implementing example embodiments of the present disclosure.
[0061] Reference is made to FIG. 2, which illustrates a signaling flow 200 for untrusted device detection in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the signaling flow 200 will be discussed with reference to FIG. 1. As shown in FIG. 2, the signaling flow 200 involves the first apparatus 110, the second apparatus 120, the third apparatus 130, and the fourth apparatus 140.
[0062] In some example embodiments, the first apparatus 110 may be implemented as a network device in a RAN or a network device implementing a location management function (LMF). Additionally, the second apparatus 120 may be implemented as a terminal device. Furthermore, the third apparatus 130 may be implemented as a UDM or AMF or 0AM. Moreover, the fourth apparatus 140 may be implemented as a network device implementing 0AM.
[0063] In the signaling flow 200, the first apparatus 110 obtains (2030) a result indicating that the second apparatus 120 is suspicious to be an untrusted device based on information related to positioning of the second apparatus 120. Then, the first apparatus 110 determines (2080) information indicating whether the second apparatus 120 is the untrusted device based on a trusted device list, minimization of drive tests (MDT) data associated with the second apparatus 120, and / or other suitable factors. The trusted device list may consist of devices predetermined to be trusted. The specific implementations of the steps mentioned above will be described below.
[0064] In some example implementations, the first apparatus 110 may be implemented as a network device in a RAN (also referred to as “RAN network device” for discussion), and the second apparatus 120 may be implemented as a terminal device. In this case, the second apparatus 120 transmits (2010), to the first apparatus 110, the information related to positioning of the second apparatus 120. Correspondingly, the first apparatus 110 may receive (2020), from the second apparatus 120, the information related to positioning of the second apparatus 120. Specifically, the information related to positioning may include, but not limited to, reference coordinates data (e.g., global positioning system (GPS) coordinates) of the second apparatus 120 or a first measurement result of a first reference signal , for example, measurement result of positioning reference signal (PRS), sounding reference signal (SRS), and the like.
[0065] Based on the received information related to positioning of the second apparatus 120, the first apparatus 110 may obtain the result indicating that the second apparatus 120 is suspicious to be an untrusted device. Specifically, for instance, the first apparatus 110 may determine a first candidate position of the second apparatus 120 based on the information related to positioning of the second apparatus 120 and may determine a second candidate position of the second apparatus 120 by measuring a second reference signal from the second apparatus 120. If the difference between the first candidate position and the second candidate position is larger than a first threshold, the first apparatus 110 may determine that the second apparatus 120 is suspicious to be the untrusted device.
[0066] The first threshold may be predefined, or may be predetermined e.g., by the fourth apparatus 140. The fourth apparatus 140 may determine the first threshold based on a variety of factors, such as historical values, traffic conditions, signal qualities, and so on. In some example embodiments, the fourth apparatus 140 may transmit (2002), to the first apparatus 110, a configuration indicating the first threshold. Correspondingly, the first apparatus 110 may receive (2004) the configuration from the fourth apparatus 140 and thus may obtain the first threshold.
[0067] The proposed solutions of example embodiments of the present disclosure may be considered as two-stage verification solutions. That is, a verification whether the second apparatus 120 is suspicious is carried out first, and if the second apparatus 120 is suspicious to be the untrusted device (which may be considered as the first stage of verification), the first apparatus 110 may perform a further verification (which may be considered as the second stage of verification) by, e.g., transmitting (2040) a request for the trusted device list to a third apparatus 130.
[0068] Upon receiving (2050) the request for the trusted device list from the first apparatus 110, the third apparatus 130 may transmit (2060) a response including the trusted device list to the first apparatus 110. The trusted device list may indicate one or more predetermined trusted devices that may be located in the same area as the second apparatus 120. In this way, the first apparatus 110 may receive (2070) the trusted device list within the response from the third apparatus 130. With the trusted device list, the first apparatus 110 may determine (2080) whether the second apparatus 120 is the untrusted device.
[0069] Alternatively, or in addition, other than the RAN network device, the first apparatus 110 may be implemented as a core network (CN) device, e.g., a device implementing an LMF (which is also referred to as “LMF device” or “LMF” for short), and the second apparatus 120 may be implemented as a terminal device. In this case, the first apparatus 110 may receive (2020) the information related to positioning of the second apparatus 120, which may include, but not limited to, reference coordinates data of the second apparatus 120 or a first measurement result of a first reference signal. The information related to positioning of the second apparatus 120 may be received from the second apparatus 120, or may be received from another RAN network device (not shown in FIG. 2) or a further core network device (not shown in FIG. 2).
[0070] Based on the received information related to positioning of the second apparatus 120, the first apparatus 110 may obtain the result indicating that the second apparatus 120 is suspicious to be an untrusted device. Specifically, for instance, the first apparatus 110 may determine a first candidate position of the second apparatus 120 based on the information related to positioning of the second apparatus 120 and may determine a second candidate position of the second apparatus 120 by measuring a second reference signal from the second apparatus 120. If the difference between the first candidate position and the second candidate position is larger than a first threshold, the first apparatus 110 may determine that the second apparatus 120 is suspicious to be the untrusted device.
[0071] In the case where the first apparatus 110 is a LMF, the first apparatus 110 may further verify whether the second apparats 120 is untrusted when it has been determined as being suspicious to be the untrusted device in 2030. Such verification may be performed based on MDT data, the trusted device list, and / or the like.
[0072] Specifically, in some example implementations, the first apparatus 110 may obtain the MDT data associated with the second apparatus 120. The MDT data may be assumed trusted. The MDT data may include data used in various aspects, for example, geographical location information, signal quality data, network performance metrics, mobility, and / or connectivity data.
[0073] The first apparatus 110 may obtain the MDT data in various ways. The MDT data may be received from a further network device, e.g., a network device implementing UDM or OMA, which is also referred to as “UDM” or “0AM” for short. In some example embodiments, the first apparatus 110 may first transmit, to the third apparatus 130, a request for the MDT data associated with the second apparatus 120, and then may receive, from the third apparatus 130, a response including the MDT data associated with the second apparatus 120.
[0074] Then, the first apparatus 110 may correlate the MDT data with the information related to positioning of the second apparatus 120. The information related to positioning of the second apparatus 120 may be correlated with the positioning data of the MDT data. If an anomaly from a result of the correlating is detected, the first apparatus 110 may determine that the second apparatus 120 is the untrusted device. On the contrary, if no anomaly is detected from the result of the correlating, the first apparatus 110 may further verify based on the trusted device list. For instance, it may transmit a request for the trusted device list to the third apparatus 130. Specifically, the trusted device list may indicate one or more trusted devices that are predetermined. Then, the third device 130 may transmit a response including the trusted device list to the first apparatus 110. Based on the received trusted device list, the first apparatus 110 may further verify whether the second apparatus 120 is an untrusted device.
[0075] Subsequently, the first apparatus 110 may obtain information related to positioning of a trusted device in the trusted device list, and determine the information indicating whether the second apparatus 120 is the untrusted device by comparing the information related to positioning of the second apparatus 120 and the information related to positioning of a trusted device in the trusted device list.
[0076] Regarding the information related to positioning of a trusted device in the trusted device list, the first apparatus 110 may transmit, to the trusted device, a request for such information. The trusted device, in response to receiving the request from the first apparatus, may transmit a response including the information related to positioning of the trusted device. The first apparatus 110 may thus obtain information related to positioning of a trusted device in the trusted device list from the received response.
[0077] Then, the first apparatus 110 may determine a difference between a first measurement result of a first reference signal included in the information related to positioning of the second apparatus 120 and a second measurement result of the first reference signal included in the information related to positioning of the trusted device. If the first apparatus 110 determines that the difference is larger than a second threshold, the first apparatus 110 may determine that the second apparatus 120 is untrusted or is the untrusted device. Furthermore, if the difference is less than or equal to the second threshold, the first apparatus 110 may determine that the second apparatus 120 is not the untrusted device.
[0078] Alternatively, if the first apparatus 110 determines that the difference is larger than or equal to a second threshold, the first apparatus 110 may determine that the second apparatus 120 is untrusted or is the untrusted device. Furthermore, if the difference is less than the second threshold, the first apparatus 110 may determine that the second apparatus 120 is not the untrusted device.
[0079] Moreover, the first apparatus 110 may transmit (2110), to the third apparatus 130, information indicating whether the second apparatus 120 is the untrusted device. Correspondingly, the third apparatus 130 may receive (2120) such information from the first apparatus 110. Thus, the third apparatus 130 would be aware whether the second apparatus 120 is untrusted.
[0080] In addition, in some example embodiments, the device under test, for exmaple, the second apparatus 120 (e.g., UE), when evaluated as non-untrusted, may be added to the set of trusted UEs, e.g, added to the trusted device list, from the perspective of the evaluating network device, e.g. the first apparauts 110 (gNB or LMF).
[0081] There may be several cases in which the device under test is evaluted to be non-untrusted. For example, if the device under test has successfully passed the first stage of verification (also referred to as the first test), it may be determined as being non-untrusted. Alternatively, if the device under test fails the first test but has succesfully passed the second stage of verification (also referred to as the second test), it may be determined as being non-untrusted as well.
[0082] In some example implementations, such update of the trusted device list may need to be accompanied by a validity period. That is, a future point in time may be needed, and at this future point the two tests of evaluating the trustworthiness of this UE will need to be performed again if the UE continues camping in the same cell managed by the same gNB for a period larger than the validity period.
[0083] In this way, the first apparatus 110 is able to determine whether the second apparatus 120 is the untrusted device or suspicious to be the untrusted device, so the data poisoning or data drift can be detected. Thus, the security of the communication network is ensured.
[0084] There are several ways for implementing the process of untrusted device detection, depending on whether a network device in RAN is enabled / enhanced to have AI / ML model capabilities. The signaling flows describing the proposed solutions are focused on the UE positioning estimation / prediction use case, which serves as an example, as the proposed solutions also apply to other use cases, as well (e.g., beam management, mobility optimization etc.).
[0085] Now more detailed embodiments will be further discussed below. FIG. 3 illustrates an example signaling flow 300 for untrusted device detection in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the signaling flow 300 will be discussed with reference to FIGS. 1 to 2. As shown in FIG. 3, the signaling flow 300 involves a gNB 310, a UE1 320, a UE2 322, a UDM 330, an 0AM 340, a device implementing AMF (which is also referred to as “AMF” for discussion) 350, a LMF 360, and a device implementing a network data analytics function (NWDAF) (which is also referred to as “NWDAF” for discussion) 370.
[0086] In the embodiments of FIG. 3, the gNB 310 is an implementation of the first apparatus 110 in FIGS. 1 to 2. Moreover, the UE1 320 is an implementation of the second apparatus 120 in FIGS. 1 to 2. That is, the UE1 320 may be the UE to be tested for whether the UE1 320 is the untrusted device. The UE2 322 is an implementation of a trusted device (e.g., a trusted terminal device or a trusted UE). The UDM 330 in FIG. 3 is an implementation of the third apparatus 130 in FIGS. 1 to 2. Moreover, the 0AM 340 is an implementation of the fourth apparatus 140. Alternatively, or in addition, in some example embodiments, the 0AM 340 and the UDM 330 may implement the same or similar procedures.
[0087] In the following descriptions, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable subcombination.
[0088] As illustrated in FIG. 3, at 3010, the UDM 330 transmits, to the gNB 310, the first threshold as discussed in example embodiments of FIG. 2. The first threshold may be indicated by a configuration and may be a maximum threshold indicating the maximum amount of threshold deviation from the predicted values the gNB 310 may tolerate. That is, a UE with a deviation larger than the maximum threshold may be considered to be the untrusted device or be suspicious to be the untrusted device.
[0089] In some example implementations, the maximum threshold may be determined based on, for example, the type of the analytics performed by the gNB 310, the type of data the gNB 310 receives on which the analytics is performed, and / or the position information of the gNB 310. Moreover, determining the maximum threshold may also involves the method used for the analytics and the time resources for analyzing data. Additionally, the maximum threshold may include temporal and positioning information.
[0090] In some example embodiments, the 0AM 340, during the ML process configuration phase at gNB 310, may also indicate the maximum amount of the threshold deviation from the predicted values the gNB 310 can tolerate, that is, the first threshold.
[0091] The value of the first threshold may be configured based upon the analytics that the gNB 310 is performing, the type of data the gNB 310 receives on which this analytics is performed, and also the geographical area the gNB 310 is located at. This first threshold may also vary with respect to specific ways in which particular analytics is performed, and also the time interval during which a data is analyzed. There, the first threshold configured by the 0AM may consist of both temporal and geographical aspects with respect to the analytics which is being performed.
[0092] At 3020, the UE1 320 may transmit, to the gNB 310, positioning information of the UE1 320. In some example implementations, the positioning information may be implemented as measurements of positioning reference signal (PRS). Moreover, the UE1 320 may also transmit, to the gNB 310, ground truth if available. In these cases, the UE1 320 may transmit GPS coordinates data of the UE1 320 to the gNB 310. In some example embodiments, the GPS coordinates data of the UE1 320 may serve as data labels in AI / ML model training. It is to be understood that using the positioning information for determining whether the UE1 320 is the untrusted device is an example implementation of the present disclosure. There may be other type of information can be used for testing the UE1 320. The scope of the present disclosure is not limited in this respect.
[0093] Then, at 3030, the gNB 310 may determine the first candidate position of the UE1 320 based on the positioning information of the UE1 320. Specifically, the gNB 310 may use the downlink data at 3030. In some example embodiments, the gNB 310 may use a trusted or predetermined AI / ML model to estimate the first candidate position of the UE1 320. In these cases, the gNB 310 may consider the AI / ML model to be genuine. That is, the AI / ML model may be considered not to trained on tampered or poisoned data. Alternatively, the gNB 310 may use signal processing methods to obtain the first candidate position of the UE1 320, such as enhanced cell identification (E-CID), downlink time difference of arrival (DL-TDOA), or downlink angle of arrival (DL-AOA). Additionally, the gNB 310 may use the positioning information, for example, downlink (DL) PRS as the input.
[0094] It is to be understood that it is assumed that the AI / ML model is genuine and is not trained on tampered or poisoned data.
[0095] Furthermore, the gNB 310 may determine the second candidate position of the UE1 320. The gNB 310 may use the uplink data for determining the second candidate position of the UE1 320, for example, sounding reference signal (SRS). Specifically, the method used are similar to those previously described and will not be repeated here. Since the first candidate position is determined based on the positioning information received from the UE1 320 and the second candidate position is determined based on the UL signal of the UE1 320, the second candidate position may be considered as the position of the UE1 320.
[0096] Subsequently, at 3040, the gNB 310 may compare the first and the second candidate position of the UE1 320 and obtain the difference between the first and the second candidate position. If the difference is larger than the maximum threshold, the gNB 310 may determine the UE1 320 to be suspicious to be the untrusted device. In these cases, the gNB 310 may transmit the identification (ID) of the UE1 320 to the core network devices for further verification, which will be described in the following sections. It is to be understood that although the UE1 320 is described to be suspicious to be the untrusted device, the UE1 320 may be determined to be the untrusted device at 3040 in some example embodiments of the present disclosure. The scope of the present disclosure is not limited in this respect.
[0097] Specifically, the gNB 310 estimates the UE location by observing it's uplink reference signals, e.g. SRS. The gNB 310 then compares the estimations 3030 and 3040 and marks the UE1 320 as suspicious if the value of the difference is higher than the first threshold received in step 3010 and the UE ID is sent to the core network for further verification.
[0098] At 3050, if the gNB 310 determines that the UE1 320 is suspicious to be the untrusted device at 3040, the gNB 310 may transmit a request for the trusted device list to the 0AM 340. Specifically, the gNB 310 may transmit the request via the AMF 350 to the 0AM 340 and the 0AM 340 may transmit the request to the UDM 330. Alternatively, the gNB 310 may transmit the request to the UDM 330.
[0099] Moreover, the trusted device list may include the ID and positioning information of trusted devices that is considered nearby the position of the UE1 320. In these cases, the position of the UE1 320 may be the second candidate position. The trusted devices with a distance from the UE1 320 smaller than a predetermined distance threshold or located in a predetermined range centered around the position of UE1 320 may be considered nearby the position of UE1 320. In FIG. 3, the UE2 322 may be an implementation of one of the trusted devices in the trusted device list.
[0100] Furthermore, the request may include the position of the UE1 320, the positioning information received from the UE1 320, and the determination that the UE1 320 is suspicious to be the untrusted device.
[0101] Then, at 3060, the 0AM 340 or the UDM 330 may determine the trusted device list after receiving the request from the gNB 310. Specifically, the 0AM 340 or the UDM 330 may select the trusted devices considered nearby the position of the UE1 320 into the trusted device list. Furthermore, the 0AM 340 or the UDM 330 may obtain the measurements of positioning reference signal of the selected trusted devices, for example, measurements of the SRS or the PRS of the trusted devices. In some example embodiments, the trusted devices may be the UEs that are determined no to be the untrusted devices previously, or predetermined trusted devices.
[0102] Moreover, at 3070, the 0AM 340 may transmit the trusted device list to the gNB 310. Specifically, the trusted device list may be transmitted in a response to the gNB 310. Furthermore, the 0AM 340 may transmit the position information of the trusted devices in the trust device list to the gNB 310 in the response. Alternatively, in some example embodiments, the UDM 330 may be the device transmitting the trusted device list within the response to the gNB 310 instead of the 0AM 340.
[0103] That is, at 3060 and 3070, the 0AM 340 or the UDM 330 discovers the trusted device list (e.g., a list of trusted UEs) for that location and also for the measurements that the tested UE (e.g., UE 1 320) is providing, since, due to different data retention policies that may be applied at the 0AM 340 / the UDM 330, all the trusted UE may not able to provide all the data measurements using which the UE in test can be evaluated. Then, the OAM 340 or the UDM 330 may send the neighborhood UE list which are trusted based upon the past data collections to the requesting gNB 310.
[0104] Additionally, at 3080, after receiving the trusted device list within the response from the OAM 340, the gNB 310 may select one or more trusted devices from the trusted device list which will be involved in the following procedures. In an example, the selected trusted device may be the UE2 322.
[0105] Then, at 3090, the gNB 310 may transmit, to the trusted device, a request for the measurements of reference signal of the trusted devices. For example, the gNB 310 may transmit, to the UE2 322, a request for the measurements of the PRS or the SRS of the UE2 322.
[0106] Correspondingly, at 3100, the UE2 322 may transmit, to the gNB 310, the response with the measurements of the PRS or the SRS (also referred to as PRS / SRS measurements) of the UE2 322. It is to be understood that there may be one or more trusted device in the trusted device list. The scope of the present disclosure is not limited in this respect.
[0107] Subsequently, at 3110, the gNB 310 may determine whether the UE1 320 is the untrusted device based on the information received from the UE2 322. For example, the gNB 310 may analyze the PRS / SRS measurements received at 3100 against the PRS / SRS measurements received at 3020. In the case they diverge from a second threshold (which may be different from the first threshold), the gNB 310 may indicate this UE1 320 under test as suspicious.
[0108] Specifically, the gNB 310 may determine a difference between the measurements of the of reference signal of the UE1 320 and the UE2 322. For example, by comparing the measurements of the PRS or the SRS of the UE1 320 and the UE2 322, the gNB 310 may obtain the difference. Moreover, if the difference is larger than a predetermined threshold, the gNB 310 may determine that the UE1 320 is the untrusted device. Additionally, if the difference is smaller or equal to the predetermined threshold, the gNB 310 may determine that the UE1 320 is not the untrusted device. Furthermore, the predetermined threshold may be configured based on the trust level of the communication network and the strength of the defensive mechanisms required.
[0109] Then, at 3120, if the UE1 320 is determined to be the untrusted device, the gNB 310 may transmit the ID of the UE1 320 to the UDM 330, such that the data from that UE1 320 should not be considered for data analytics.
[0110] Specifically, the gNB 310 may transmit the ID of the UE1 320 to other devices, for example, the AMF 350, the LMF 360, the NWDAF 370, and the 0AM 340, to broadcast the result of untrusted device detection. In these cases, the RAN core interface may be envisioned to be service-based interface (SBI). Moreover, the data uploaded by the UE1 320 may be considered poisoned or tempered and should be discarded.
[0111] Alternatively, if the UE1 320 is determined not to be the untrusted device, the gNB 310 may also transmit the ID of the UE1 320 to other core network devices to check if the UE may be added in the trusted device list or not.
[0112] It is to be understood that in the example embodiments discussed above, it is assumed that the UE(s) in the same location or nearby location, will provide similar measurements to the gNB, and then divergence in individual measurements will not be more than a set threshold. This threshold may be set by the operator also based upon the trust level of the system and strength of defensive mechanisms required.
[0113] In this way, the gNB 310 is able to determine whether the UE1 320 is the untrusted device or suspicious to be the untrusted device. Thus, the security of the communication network and the authentication of the data uploaded by the UEs is ensured.
[0114] Another example embodiments related to FIG.2 will be described below with reference to FIG. 4. FIG. 4 illustrates another example signaling flow 400 for untrusted device detection in accordance with some example embodiments of the present disclosure. The signaling flow 400 is an alternative to the signaling flow 300 discussed with respect to FIG. 3. For the purpose of discussion, the signaling flow 400 will be discussed with reference to FIGS. 1 to 2. As shown in FIG. 4, the signaling flow 400 involves a LMF 410, a UE1 420, a UE2 422, a UDM 430, an 0AM 440, an AMF 450, a gNB 460, and a NWDAF 470.
[0115] In the example embodiments of FIG. 4, the LMF 410 is an implementation of the first apparatus 110 in FIGS. 1 to 2. Moreover, the UE1 420 is an implementation of the second apparatus 120 in FIGS. 1 to 2. That is, the UE1 420 may be the UE to be tested for whether the UE1 420 is the untrusted device. The UE2 422 is an implementation of a trusted device (e.g., a trusted terminal device or a trusted UE). The UDM 430 in FIG. 4 is an implementation of the third apparatus 130. Moreover, the 0AM 440 is an implementation of the fourth apparatus 140. Alternatively, or in addition, in some example implementations, the 0AM 440 and the UDM 430 may implement the same or similar procedures.
[0116] In the example embodiments discussed with reference to FIG. 4, the LMF 410 may be AI / ML capable and may perform inference using trained AI / ML model. The LMF 410 may perform statistical analysis to detect if there is any kind of data drift or not. Furthermore, the solution proposed may be performed by any proper core network entity. The scope of the present disclosure is not limited in this respect.
[0117] As illustrated in FIG. 4, at 4010, the 0AM 440 transmits, to the LMF 410, the first threshold as discussed in example embodiments of FIG. 2. The first threshold may be a maximum threshold indicated by a configuration. The maximum threshold may be associated with the ID of the UE to be tested or the data and the measurements used in the testing on the UE. Additionally, the threshold may be transmitted to the NWDAF 470.
[0118] Then, at 4020, the UE1 420 may transmit, to the gNB 460, positioning information of the UE1 420. In some example implementations, the positioning information may be implemented as measurements of the PRS or the SRS of the UE1 420. Moreover, the UE1 420 may also transmit, to the gNB 460, ground truth if available. In these cases, the UE1 420 may transmit the global navigation satellite system (GNSS) coordinates data of the UE1 420 to the gNB 460. In some example embodiments, the GNSS coordinates data of the UE1 420 may serve as data labels in AI / ML model training. It is to be understood that using the positioning information for verifying or testing the UE1 420 is an example implementation of the present disclosure. There may be other type of information can be used for testing the UE1 420. The scope of the present disclosure is not limited in this respect.
[0119] Subsequently, at 4030, the gNB 460 transmit, to the LMF 410, the positioning information of the UE1 420. That is, the UE1 420 may transmit the positioning information to the LMF 410 via the gNB 460. It is to be understood that the UE1 420 may transmit the positioning information of itself to the LMF 410 in any proper way or via any devices that can implement the transmission. The scope of the present disclosure is not limited in this respect.
[0120] At 4040, the LMF 410 may determine the first candidate position of the UE1 420 based on the positioning information of the UE1 420. In some example embodiments, the LMF 410 may use a trusted or predetermined AI / ML model to estimate the first candidate position of the UE1 420. In these cases, the LMF 410 considers the AI / ML model to be genuine. Alternatively, the LMF 410 may use signal processing methods to obtain the first candidate position of the UE1 420, such as E-CID, DL-TDOA, or downlink angle of departure (DL-AoD). Additionally, the LMF 410 may use the positioning information, for example, PRS as the input.
[0121] Furthermore, the LMF 410 may determine the second candidate position of the UE1 420, for example, using the measurements of the reference signal of the UE1 420. Specifically, the method used are similar to those previously described and will not be repeated here. Since the first candidate position is determined based on the positioning information received from the UE1 420 and the second candidate position is determined based on the measurements of the reference signal of the UE1 420, the second candidate position may be considered as the position of the UE1 420.
[0122] Subsequently, at 4050, the LMF 410 may compare the first and the second candidate position of the UE1 420 and obtain the difference between the first and the second candidate position. If the difference is larger than the maximum threshold, the LMF 410 may determine the UE1 420 to be suspicious to be the untrusted device. In these cases, the LMF 410 may transmit the ID of the UE1 420 to the core network devices for further verification, which will be described in the following sections. It is to be understood that although the UE1 420 is described to be suspicious to be the untrusted device, the UE1 420 may be determined to be the untrusted device at 4050 in some example embodiments of the present disclosure. The scope of the present disclosure is not limited in this respect.
[0123] At 4060, if the LMF 410 determines that the UE1 420 is suspicious to be the untrusted device at 4050, the LMF 410 may transmit, to the 0AM 440, a request for MDT data associated with the UE1 420. Furthermore, the MDT data is assumed to be trusted. That is, the MDT data is considered not to tampered or poisoned. Additionally, the NWDAF 470 may transmit the request for the MDT data to the 0AM 440. Alternatively, or in addition, the request for the MDT data may include the ID of the UE1 420 for which the MDT data is requested.
[0124] The 0AM 440, at 4070, transmit, to the LMF 410, a response within the MDT data associated with the UE1 420. Additionally, the 0AM 440 may transmit the response within the MDT data to the NWDAF 470.
[0125] Then, at 4080, the LMF 410 or the NWDAF 470 correlate the MDT data with the positioning information of the UE1 420. It is to be understood that there are various ways or algorithms for preforming the correlation. The exact algorithm used in the correlation of MDT data with other measurement data received from the UE1 420 depends on specific implementations or use case, which does not suggest any limitation to the present disclosure.
[0126] Subsequently, at 4090, if an anomaly is detected from a result of the correlating at 4080, the LMF 410 may determine that the UE1 420 is suspicious to be the untrusted device. It is to be understood that although the UE1 420 is described to be suspicious to be the untrusted device, the UE1 420 may be determined to be the untrusted device at 4090 directly in some example embodiments of the present disclosure. The scope of the present disclosure is not limited in this respect. Furthermore, the LMF 410 may broadcast the ID of the UE1 420 to other network devices that may receive data from the UE1 420.
[0127] Alternatively, at 4100, if no anomaly is detected from the result of the correlating at 4080, the LMF 410 may determine to implement another test on the UE1 420 with a trusted device list.
[0128] In some example embodiments, a UE are deemed trusted in the case the UE passes all the three stages of verification. And then for specific analytics, the data provided by the UE for future is deemed trusted, its data / measurements also serve as a reference point to detect any malicious / abnormal data drift in the measurements received from an untrusted UE.
[0129] At 4110, the LMF 410 may transmit, to the UDM 430, a request for the trusted device list. Furthermore, the NWDAF 470 may transmit the request for the trusted device list to the UDM 430.
[0130] At 4120, the LMF 410 or the NWDAF 470 may receive, from the UDM 430, a response including the trusted device list. Furthermore, the trusted device list may be transmitted from the AMF 450. Moreover, the trusted device list may include the ID and positioning information of trusted devices that is considered nearby the position of the UE1 420. In these cases, the position of the UE1 420 may be the second candidate position. The trusted devices with a distance from the UE1 420 smaller than a predetermined distance threshold or located in a predetermined range centered around the position of UE1 420 may be considered nearby the position of UE1 420. In FIG. 4, the UE2 422 may be an implementation of one of the trusted devices in the trusted device list.
[0131] Then, at 4130, the LMF 410 or the NWDAF 470 may determine to obtain measurements of reference signal of the trusted devices in the trusted device list, such as UE2 422. Specifically, the measurements of reference signal may include measurements of the PRS or the SRS. Furthermore, the reference signal of the UE2 422 may be same to the reference signal of the UE1 420.
[0132] At 4140, the LMF 410 or the NWDAF 470 may transmit, to the trusted devices, such as, UE2 422, a request for the measurements of the PRS or the SRS of the UE2 422. Furthermore, the request for the measurements is transmitted to the gNB 460 and the gNB 460 may transmit the request to the UE2 422. That is, the request for the measurements is transmitted from the LMF 410 or the NWDAF 470 to the UE2 422 via the gNB 460.
[0133] Correspondingly, at 4150, the UE2 422 may transmit, to the LMF 410 or the NWDAF 470 via the gNB 460, a response including the measurements of the PRS or the SRS of the UE2 422.
[0134] Moreover, the LMF 410 or the NWDAF 470, at 4160, may determine whether the UE1 420 is the untrusted device based on the information received from the UE2 422. Specifically, the LMF 410 or the NWDAF 470 may determine a difference between the measurements of the of reference signal of the UE1 420 and the UE2 422. For example, by comparing the measurements of the PRS or the SRS of the UE1 420 and the UE2 422, the LMF 410 or the NWDAF 470 may obtain the difference. Moreover, if the difference is larger than a predetermined threshold, the LMF 410 or the NWDAF 470 may determine that the UE1 420 is the untrusted device. Additionally, if the difference is smaller or equal to the predetermined threshold, the LMF 410 or the NWDAF 470 may determine that the UE1 420 is not the untrusted device. Furthermore, the predetermined threshold may be configured based on the trust level of the communication network and the strength of the defensive mechanisms required.
[0135] Then, at 4170, if the UE1 420 is determined to be the untrusted device, the LMF 410 may transmit the ID of the UE1 420 to the UDM 430. Furthermore, the LMF 410 may transmit the ID of the UE1 420 to other devices, for example, the AMF 450, the gNB 460, the NWDAF 470, and the OAM 440, to broadcast the result of untrusted device detection. Moreover, the data uploaded by the UE1 420 may be considered poisoned or tempered and should be discarded.
[0136] Alternatively, if the UE1 420 is determined not to be the untrusted device, the LMF 410 may transmit the ID of the UE1 420 to other network devices associated with the UE1 420 to inform them that the UE1 420 is a “trusted data provider”.
[0137] In this way, whether the UE1 420 is the untrusted device or suspicious to be the untrusted device can be determined by the LMF 410 in a flexible way. Thus, the security of the communication network and the authentication of the data uploaded by the UEs is ensured. Moreover, the flexibility of the untrusted device detection is improved.
[0138] Once a terminal device, e.g., a UE which might be malicious and inducing data poisoning are detected in the communication network, it is important to identify that the malicious UE across the different entities and broadcast this information such that the attack is not propagated, and other nodes are not affected.
[0139] In this regard, in addition to the example process of determining whether a second apparatus 120, e.g., a UE, is an untrusted device as described above, example embodiments of the present disclosure also provide a process of identification and broadcasting of the untrusted UE(s) information to other stakeholders (for instance gNB(s) or other network functions in the core network) to prevent attack propagation, which will be detailed below with reference to FIGS. 5 to 8.
[0140] FIG. 5 illustrates another example communication environment 500 in which example embodiments of the present disclosure can be implemented. The communication environment 500 involves a plurality of communication devices, including a fifth apparatus 510, a sixth apparatus 520, a seventh apparatus 530, and an eighth apparatus 540.
[0141] In some example embodiments of the FIG. 5, the fifth apparatus 510 may be implemented as a network device in a RAN, such as a base station. The sixth apparatus 520 may be implemented as another network device in the RAN. Alternatively, in some example implementations, the fifth apparatus 510 may be implemented as a network device in a RAN, while the sixth apparatus 520 may be implemented as a core network device, e.g., an AMF entity.
[0142] In the above both cases, the seventh apparatus 530 may be implemented as a terminal device, e.g., a UE served by first apparatus 110, e.g., the base station. As to the eighth apparatus 540, it may be implemented as another network device in the RAN. For example, the eighth apparatus 540 may be a base station (e.g., a gNB) to which the UE is to be switched.
[0143] In some example embodiments, if the fifth apparatus 510 is a network device in a RAN and the seventh apparatus 530 is a terminal device, a link from the seventh apparatus 530 to the fifth apparatus 510 is referred to as an uplink (UL), while a link from the fifth apparatus 510 to the seventh apparatus 530 is referred to as a downlink (DL). In UL, the seventh apparatus 530 is a transmitting (TX) device (or a transmitter) and the fifth apparatus 510 is a receiving (RX) device (or a receiver). In DL, the first apparatus 110 is a TX device (or a transmitter) and the seventh apparatus 530 is a RX device (or a receiver).
[0144] Communications in the communication environment 500 may be implemented according to any proper communication protocol(s), comprising, but not limited to, cellular communication protocols of the first generation (1G), the second generation (2G), the third generation (3G), the fourth generation (4G), the fifth generation (5G), 5.5G, the sixth generation (6G), and the like, wireless local network communication protocols such as Institute for Electrical and Electronics Engineers (IEEE) 802.11 and the like, and / or any other protocols currently known or to be developed in the future. Moreover, the communication may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA), Frequency Division Multiple Access (FDMA), Time Division Multiple Access (TDMA), Frequency Division Duplex (FDD), Time Division Duplex (TDD), Multiple-Input Multiple-Output (MIMO), Orthogonal Frequency Division Multiple (OFDM), Discrete Fourier Transform spread OFDM (DFT-s-OFDM) and / or any other technologies currently known or to be developed in the future.
[0145] It is to be understood that the number of apparatuses and their connections shown in FIG. 5 are only for the purpose of illustration without suggesting any limitation. The communication environment 500 may include any suitable number of apparatuses configured to implementing example embodiments of the present disclosure.
[0146] Reference is made to FIG. 6A, which illustrates a signaling flow 600A for broadcasting the untrusted device information in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the signaling flow 600A will be discussed with reference to FIG. 5. As shown in FIG. 6A, the signaling flow 600A involves the fifth apparatus 510, the sixth apparatus 520, and the seventh apparatus 530.
[0147] In the embodiment of FIG. 6A, the fifth apparatus 510 is implemented as a network device in a RAN (also referred to as “RAN network device” for discussion) or a network device implementing a LMF (which is also referred to as “LMF device” or “LMF” for short). Moreover, the sixth apparatus 520 may be implemented as a further network device in a RAN. Additionally, the seventh apparatus 530 may be implemented as a terminal device.
[0148] In the signaling flow 600A, if the seventh apparatus 530 is determined untrusted, the fifth apparatus 510 transmits (6010), to the sixth apparatus 520, first information indicating that the seventh apparatus 530 is the untrusted device for a first service. Correspondingly, the sixth apparatus 520 receives (6020), from the fifth apparatus 510, the first information indicating that the seventh apparatus 530 is the untrusted device for the first service. Furthermore, the first service may include positioning. It is to be understood that positioning is only an implementation of the first service. The first service may include various services, for example, signal quality measuring, tracking efficiency of handovers, signal strength measuring, and the like.
[0149] With the knowledge that the seventh apparatus 530 is the untrusted device for the first service, the sixth apparatus 520 refrains (6030) from using data from the seventh apparatus 530 in the first service.
[0150] Optionally, in some example embodiments, in the case where the sixth apparatus 520 determines that the seventh apparatus 530 can be trusted, for example, after appropriate testing or verification, the sixth apparatus 520 may transmit (6040) second information indicating that the seventh apparatus 530 is a trusted device for a second service. Thus, the fifth apparatus 510 may receive (6050) the second information from the sixth apparatus 520 and have the knowledge that the seventh apparatus 530 is a trusted device for the second service. In this case, the first information and the second information may share the same context. Specifically, for instance, the first and the second information may include the same element indicating the use of each information.
[0151] Then, the fifth apparatus 510 may perform the second service by using data from the seventh apparatus 530. It is to be understood that, the data of the seventh apparatus 530 used for the first and the second services may be different.
[0152] In this way, the first apparatus 510 is able to notify the sixth apparatus 520 that the seventh apparatus 530 is the untrusted device, so that the sixth apparatus 520 stops using the data from the untrusted device. With the notifying scheme, malicious data or untrusted data may be excluded from being applied in various services. Thus, security and robustness in the communication network can be improved.
[0153] Reference is made to FIG. 6B, which illustrates another signaling flow 600B for broadcasting the untrusted device information in accordance with some example embodiments of the present disclosure. Similar as the signaling flow 600A, the signaling flow 600B will be discussed with reference to FIG. 5 as well. As shown in FIG. 6B, the signaling flow 600B involves the fifth apparatus 510, the sixth apparatus 520, the seventh apparatus 530, and the eighth apparatus 540.
[0154] In the embodiments of FIG. 6B, the fifth apparatus 510 may be implemented as a network device in a RAN or a network device implementing an LMF. Moreover, the sixth apparatus 520 may be implemented as a further network device implementing a device implementing AMF (which is also referred to as “AMF” for discussion). Furthermore, the seventh apparatus 530 may be implemented as a terminal device. Additionally, the eighth apparatus 540 may be implemented as a further network device in the RAN.
[0155] In the signaling flow 600B, if the seventh apparatus 530 is determined as being untrusted, the fifth apparatus 510 transmits (6010) to the sixth apparatus 520, first information indicating that the seventh apparatus 530 is the untrusted device for a first service. The first service may be for example, positioning, signal quality determination, and so on. Correspondingly, the sixth apparatus 520 receives (6020) from the fifth apparatus 510, the first information indicating that the seventh apparatus 530 is the untrusted device for the first service.
[0156] Furthermore, the sixth apparatus 520 transmits (6040) information indicating that the seventh apparatus 530 is the untrusted device for a first service to the eighth apparatus 540. Upon receiving (6050) such information, the eighth apparatus 540 understands the same. Thus, the eighth apparatus 540 may refrain from using data from the seventh apparatus 530 in the first service.
[0157] The sixth apparatus 520 may store the first information in context information associated with the seventh apparatus 530. Additionally, if the sixth apparatus 520 receives, from the eighth apparatus 540, a request for context information associated with the seventh apparatus 520, the sixth apparatus 520 may transmit the first information to the eighth apparatus 540.
[0158] In this way, the first apparatus 510 is able to notify the eighth apparatus 540 that the seventh apparatus 530 is the untrusted device via the second apparatus 520. The eighth apparatus 540 is protected from using data of the untrusted device. Thus, the data security of the communication network is improved.
[0159] There are several example embodiments of the signaling flow 600A or 600B. For instance, FIG. 7 illustrates an example implementation of the signaling flow 600A, and FIG. 8 illustrates an example implementation of the signaling flow 600B. Now more detailed embodiments will be further discussed below.
[0160] FIG. 7 illustrates an example signaling flow 700 for a process of untrusted device detection in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the signaling flow 700 will be discussed with reference to FIGS. 5 and 6A. As shown in FIG. 7, the signaling flow 700 involves a source gNB 710, a target gNB 720, and a UE 730.
[0161] When a UE mobility event, i.e., handover to another gNB (the target gNB 720), occurs, the target gNB 720 may be informed about the level of trust of the UE 730 (in the sense of data collection for UE positioning estimation, as an example).
[0162] In this case, the source gNB 710, after classifying the tested UE 730 as untrusted, may inform the target gNB 720 accordingly via proper messaging over the Xn interface by means of a new Boolean IE “Trusted UE” that takes the value of FALSE by default and another IE “Data Use” indicating the use case (and, therefore, the relevant UE measurements) for which data collection is needed. Since the UE ID changes when the UE camps on different cells and, as the source gNB 710 would need to be informed about possible change of trust level for this UE, e.g., in the case this UE redirects to the source gNB 710 in the future, a context may be created involving the source gNB 710 and the target gNB 720 by means of a Measurement ID pair. More details will be discussed in FIG. 7 below.
[0163] In the embodiments of FIG. 7, the source gNB 710 is an implementation of the fifth apparatus 510 in FIGS. 5 and 6A. Moreover, the target gNB 720 is an implementation of the sixth apparatus 520 in FIGS. 5 and 6A. The UE 730 is an implementation of the seventh apparatus 530 in FIGS. 5 and 6A.
[0164] In the following, while operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, while several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment may also be implemented in multiple embodiments separately or in any suitable sub-combination.
[0165] As illustrated in FIG. 7, at 7010, the source gNB 710 transmits, to the target gNB 720, a data collection request message. Specifically, the message may include a new trusted UE information element (IE) of which the default value is FALSE. Furthermore, the message may include a new data use IE that clarifies for which use case data collection is considered as untrusted.
[0166] Additionally, the data collection request message may further include a measurement ID of the source gNB 710, a flag of the use of the data. For example, the form of the data collection request message may be as follows: (NG-RAN node 1 Measurement ID, Trusted UE = FALSE, Data use = “POSITIONING”). The “NG-RAN node 1 Measurement ID” may represent the measurement used for the source gNB 710. Moreover, the “Trusted UE = FALSE” may indicate that the UE 730 is the untrusted device. The “Data use” may indicate the type of the service for which the data of the UE 730 is used by the source gNB 710.
[0167] At 7020, the target gNB 720 may transmit a response to the source gNB 710. In some example implementations, the response may be implemented as a data collection response message responsive to the request from the source gNB 710. The response may include the measurement ID of the target gNB 720, for example, “NG-RAN node 2 Measurement ID”. Thus, a measurement ID pair of the target gNB 720 and the source gNB 710 may be determined as including, e.g., the “NG-RAN node 1 Measurement ID” and the “NG-RAN node 2 Measurement ID”.
[0168] Then, at 7030, the source gNB 710 may determine that the UE 730 is an untrusted device, for example, by using the solutions discussed with respect to FIGS. 2 to 4. Alternatively, the source gNB 710 may determine the UE 730 as the untrusted device by receiving information indicating the same from other devices. The scope of the present disclosure is not limited in this respect.
[0169] Subsequently, at 7040, the source gNB 710 may transmit a handover request message to the target gNB 720. Specifically, the handover request message may include the measurement ID pair.
[0170] At 7050, the target gNB 720 may refrain from using the data of the UE 730. Specifically, the target gNB 720 may refrain from using the data of the UE 730 for the service of the service type of “Data use”. For example, the target gNB 720 may refrain from using the data for positioning estimation or prediction of the UE 730.
[0171] In some example embodiments, the target gNB 720 may directly use or first evaluate trustworthiness level of this UE 730 regarding collection of different data from the ones needed for UE positioning estimation / prediction.
[0172] At 7060, an event may occur where this UE 730 is evaluated as trusted, either by the target gNB 720 itself or as informed by another neighboring gNB to which the UE 730 had connected before returning to the coverage area of target gNB 730. As shown in FIG. 7, the target gNB 720 may determine, at 7060, the UE 730 as a trusted device for example by using untrusted device detection solutions discussed above.
[0173] Then, at 7070, the target gNB 720 may transmit a data collection update request to the source gNB 710. Specifically, the data collection update request may include the measurement ID pair (for identification of the UE), where the value of the new trusted UE IE changes to TRUE, for the needs of the UE position estimation / prediction use case. For example, the form of the data collection update request message may be as follows: (NG-RAN node 1 Measurement ID, NG-RAN node 2 Measurement ID, Trusted UE = TRUE, Data use = “POSITIONING”).
[0174] At 7080, the target gNB 720 may transmit, to the source gNB 710, a handover request message including the measurement ID pair.
[0175] Then, at 7090, the source gNB 710 may use the data of the UE 730 for the service for which the data of the UE 730 is genuine and authentic, for example, positioning estimation or prediction. Furthermore, after a length of time, the UE 730 may be re-tested. That is, the UE 730 may be detected periodically to determine whether the UE 730 is the untrusted device.
[0176] In this way, the source gNB 710 is able to notify the target gNB 720 to refrain from using the data from the untrusted device (UE 730). Moreover, the target gNB 720 may update a trustiness status of the UE 730. In this way, the UE 730 may be a trusted device in some circumstances or when some conditions are met, and its data may be then used by the source gNB 710 or other devices. Thus, the effectiveness and efficiency of the data used in the communication network are both improved.
[0177] In some other example embodiments, when a UE mobility event, i.e., handover to the target gNB, occurs, the target gNB may be informed about the level of trust of the UE (in the sense of data collection for UE positioning estimation, as an example) via the AMF.
[0178] In this case, the source gNB, after classifying the UE as untrusted, may inform the AMF over next generation application protocol (NGAP). The AMF may inform to the (every) target gNB2 via an NGAP interface, for example, by means of a new Boolean IE “Trusted UE” and another IE “Data Use” indicating the use case (similar to example embodiments of FIG. 7).
[0179] More details of these example embodiments will be discussed below with respect to FIG. 8, which illustrates another example signaling flow 800 for untrusted device detection in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the signaling flow 800 will be discussed with reference to FIGS. 5 and 6B. As shown in FIG. 8, the signaling flow 800 involves a source gNB or gNBl 810, an AMF 820, a UE 830, and a target gNB or gNB2 840.
[0180] In the embodiments of FIG. 8, the gNBl 810 is an implementation of the fifth apparatus 510 in FIGS. 5 and 6B. Moreover, the AMF 820 is an implementation of the sixth apparatus 520 in FIGS. 5 and 6B. The UE 830 is an implementation of the seventh apparatus 530 in FIGS. 5 and 6B. In this case, the UE 830 may be an untrusted device. Moreover, the gNB2 840 in FIG. 8 is an implementation of the eighth apparatus 540 in FIGS. 5 and 6B.
[0181] As illustrated in FIG. 8, at 8010, the gNBl 810 determines that the UE 830 is the untrusted device. In some example implementations, the determination that the UE 830 is the untrusted device is made by using the untrusted device detection method described above. Alternatively, the gNBl 810 may determine the UE 830 as the untrusted device by receiving the determination from other devices. The scope of the present disclosure is not limited in this respect.
[0182] Then, at 8020, the gNBl 810 may transmit, to the AMF 820, a NGAP message including a new trusted UE IE of which the value is TRUE. Furthermore, the gNBl 810 may transmit, to the AMF 820, a new data use IE that clarifies for which use case data collection is considered untrusted. That is, the gNBl 810 may inform the AMF 820 that the UE 830 is the untrusted device. In an implementation, the gNBl 810 may send aNGAP message to the AMF 820 including a new Trusted UE IE that takes the value “TRUE”, along with another new Data Use IE that clarifies for which use case data collection is deemed as untrusted.
[0183] At 8030, the AMF 820 may store the message received from the gNBl 810. Specifically, the AMF 820 may store the same as the message from the gNBl 810 in the UE context. In some example implementations, the AMF 820 may store the message in UDM along with other UE information.
[0184] It is to be understood that, for future purposes, and for discovery, the AMF 820 may then store it in a device implementing UDM (also referred to as UDM for short) along with other UE information.
[0185] Subsequently, at 8040, the UE 830 may move to the range of gNB2 840. That is, the gNB2 840 may begin to serve the UE 830.
[0186] Moreover, the gNB2 840, at 8050, may communicate with the AMF 820. Specifically, the gNB2 840 may transmit a request to the AMF 820 for determining whether the UE 830 is the untrusted device. Moreover, the AMF 820 may transmit, to the gNB2 840, the information indicating that the UE 830 is the untrusted device.
[0187] At 8060, the AMF 820 may transmit, to the gNB2 840, a trusted UE IE and a data uses IE. Specifically, the AMF 820 may inform the gNB2 840 about the UE determined trusted and the corresponding use of the data of the trusted UE.
[0188] In this way, the gNBl 810 is able to broadcast the information of the untrusted UE 830 to a further gNB via AMF 820 or other network devices. Thus, the authentication of the data used in the communication network is ensured.
[0189] FIG. 9 shows a flowchart of an example method 900 implemented at a first apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 900 will be described from the perspective of the first apparatus 110 in FIG. 1.
[0190] At block 910, the first apparatus 110 obtains a result indicating that a second apparatus is suspicious to be an untrusted device based on information related to positioning of the second apparatus.
[0191] At block 920, the first apparatus 110 determines information indicating whether the second apparatus is the untrusted device based on at least one of a trusted device list or minimization of drive tests (MDT) data associated with the second apparatus.
[0192] In some example embodiments, the method 900 further comprises: receiving, from the second apparatus, the information related to positioning of the second apparatus, the information related to positioning comprising at least one of reference coordinates data of the second apparatus or a first measurement result of a first reference signal; determining a first candidate position of the second apparatus based on the information related to positioning of the second apparatus; determining a second candidate position of the second apparatus by measuring a second reference signal from the second apparatus; and in response to a difference between the first candidate position and the second candidate position is larger than a first threshold, determining that the second apparatus is suspicious to be the untrusted device.
[0193] In this way, the first apparatus 110 is able to determine whether the second apparatus is the untrusted device via a two-stage verification process. Thus, the security of the communication network is improved.
[0194] In some example embodiments, the method 900 further comprises: in response to determining that the second apparatus is suspicious to be the untrusted device, transmitting a request for the trusted device list to a third apparatus, wherein the trusted device list indicates one or more trusted devices that are predetermined; and receiving a response comprising the trusted device list from the third apparatus. As such, the trusted device list can be obtained conveniently and efficiently.
[0195] In some example embodiments, the method 900 further comprises: receiving the information related to positioning of the second apparatus, the information related to positioning comprising at least one of reference coordinates data of the second apparatus or a first measurement result of a first reference signal; determining a first candidate position of the second apparatus based on the information related to positioning of the second apparatus; determining a second candidate position of the second apparatus by measuring a second reference signal from the second apparatus; and in response to a difference between the first candidate position and the second candidate position is larger than a first threshold, determining that the second apparatus is suspicious to be the untrusted device. As such, the first stage of verification can be accomplished.
[0196] In some example embodiments, the method 900 further comprises: determining the information indicating whether the second apparatus is the untrusted device by comparing the information related to positioning of the second apparatus and information related to positioning of a trusted device in the trusted device list. In some example implementations, in response to determining that a difference between a first measurement result of a first reference signal comprised in the information related to positioning of the second apparatus and a second measurement result of the first reference signal comprised in the information related to positioning of the trusted device is larger than a second threshold, the first apparatus 110 determines that the second apparatus is the untrusted device; and in response to determining that the difference is less than or equal to the second threshold, the first apparatus 110 determines that the second apparatus is not the untrusted device. As such, the second stage of verification can be accomplished based on the trusted device list.
[0197] In some example embodiments, the method 900 further comprises: transmitting, to the trusted device, a request for the information related to positioning of the trusted device; and receiving, from the trusted device, a response comprising the information related to positioning of the trusted device. Thus, the trusted device list can be obtained conveniently.
[0198] In some example embodiments, the first apparatus 110 may obtain the MDT data associated with the second apparatus, wherein the MDT data is assumed trusted; correlating the MDT data with the information related to positioning of the second apparatus; and in response to detecting an anomaly from a result of the correlating, determining that the second apparatus is the untrusted device. In some example implementations, in response to that no anomaly is detected from the result of the correlating, the first apparatus 110 may transmit a request for the trusted device list to a third apparatus, where the trusted device list indicates one or more trusted devices that are predetermined. Then, the first apparatus 110 may receive a response comprising the trusted device list from the third apparatus. As such, the second stage of verification can be accomplished based on the MDT data.
[0199] In some example embodiments, the method 900 further comprises: transmitting, to a third apparatus, a request for the MDT data associated with the second apparatus; and receiving, from the third apparatus, a response comprising the MDT data associated with the second apparatus. Thus, the MDT data can be obtained conveniently.
[0200] In some example embodiments, the method 900 further comprises: receiving, from a fourth apparatus, a configuration indicating the first threshold. Thus, the first threshold may be flexible configured by another device.
[0201] In some example embodiments, the method 900 further comprises: transmitting, to a third apparatus, the information indicating whether the second apparatus is the untrusted device. In this way, the first apparatus 110 is able to inform the untrusted device to other devices in the communication network. Thus, information about the untrusted device may be notified to entities in the network.
[0202] In some example embodiments, the fourth apparatus may comprise a network device implementing operations, administration, and maintenance (0AM).
[0203] In some example embodiments, the third apparatus may comprise a network device implementing user data management (UDM) or access and mobility function (AMF) or operations, administration, and maintenance (0AM).
[0204] FIG. 10 shows a flowchart of an example method 1000 implemented at a third apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1000 will be described from the perspective of the third apparatus 130 in FIG. 1.
[0205] At block 1010, the third apparatus 130 receives, from a first apparatus, a request for the trusted device list.
[0206] At block 1020, the third apparatus 130 transmits, to the first apparatus, a response comprising the trusted device list for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the trusted device list indicates one or more trusted devices that are predetermined.
[0207] In this way, the third apparatus 110 is able to provide the trusted device list efficiently, so that the security of the communication network is improved.
[0208] In some example embodiments, the third apparatus 130 may receive, from the first apparatus, a request for the MDT data associated with the second apparatus, wherein the MDT data is assumed trusted; and transmitting, to the first apparatus, a response comprising the MDT data associated with the second apparatus. Thus, the MDT data can be provided conveniently.
[0209] In some example embodiments, the third apparatus 130 may receive, from the first apparatus, the information indicating whether the second apparatus is the untrusted device. Thus, information about the untrusted device may be notified to entities in the communication network, which further improves the security of the communication network.
[0210] In some example embodiments, the first apparatus may comprise a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the second apparatus may comprise a terminal device, and the third apparatus may comprise a network device implementing user data management (UDM) or access and mobility function (AMF) or operations, administration, and maintenance (0AM).
[0211] FIG. 11 shows a flowchart of an example method 1100 implemented at a fifth apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1100 will be described from the perspective of the fifth apparatus 510 in FIG. 5.
[0212] At block 1110, in response to determining that a seventh apparatus is untrusted, the fifth apparatus 510 transmits, to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
[0213] As such, information about the untrusted device may be notified to entities in the communication network, which improves the security of the communication network.
[0214] In some example embodiments, the fifth apparatus 510 may receive, from the sixth apparatus, second information indicating that the seventh apparatus is a trusted device for a second service, wherein the first information and the second information share the same context. In this way, the untrusted device may be changed to be a trusted device in certain scenarios or when some conditions are met. Thus, the level of trustiness of a device may be changed flexibly or dynamically.
[0215] In some example embodiments, the fifth apparatus 510 may perform the second service by using data from the seventh apparatus.
[0216] In some example embodiments, the fifth apparatus 510 may comprise a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth apparatus may comprise a further network device in a radio access network (RAN) or implementing an access and mobility management function (AMF), and the seventh apparatus may comprise a terminal device.
[0217] FIG. 12 shows a flowchart of an example method 1200 implemented at a sixth apparatus in accordance with some example embodiments of the present disclosure. For the purpose of discussion, the method 1200 will be described from the perspective of the sixth apparatus 520 in FIG. 5.
[0218] At block 1210, the sixth apparatus 520 receives, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
[0219] At block 1220, the sixth apparatus 520 performs at least one of: refraining from using data from the seventh apparatus in the first service, or transmitting the first information to an eighth apparatus.
[0220] As such, entities in the communication network may know information about the untrusted device effectively, which improves the security of the communication network.
[0221] In some example embodiments, the fifth apparatus may comprise a network device in a radio access network (RAN) and the sixth apparatus 520 may comprise a further network device in a radio access network (RAN), wherein the sixth apparatus 520 may refrain from using data from the seventh apparatus in the first service; and in response to determining that the seventh apparatus is not untrusted, the sixth apparatus 520 may transmit to the fifth apparatus, second information indicating that the seventh apparatus is a trusted device for a second service, wherein the first information and the second information share the same context.
[0222] In this way, the untrusted device may be changed to be a trusted device in certain scenarios or when some conditions are met. Thus, the level of trustiness of a device may be changed flexibly or dynamically.
[0223] In some example embodiments, the fifth apparatus may comprise a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth apparatus 520 may comprise a network device implementing an access and mobility management function (AMF), and wherein the sixth apparatus 520 may store the first information in context information associated with the seventh apparatus; and / or in response to receiving, from an eighth apparatus, a request for context information associated with the seventh apparatus, the sixth apparatus 520 may transmit the first information to the eighth apparatus.
[0224] In this way, the information about the untrusted device may be further notified to other devices in the communication network. Thus, the security of the communication network may be improved flexibly and effectively.
[0225] In some example embodiments, the eighth apparatus may comprise a further network device in the radio access network (RAN).
[0226] In some example embodiments, a first apparatus capable of performing any of the method 900 (for example, the first apparatus 110 in FIG. 1) may comprise means for performing the respective operations of the method 900. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The first apparatus may be implemented as or included in the first apparatus 110 in FIG. 1.
[0227] In some example embodiments, the first apparatus comprises means for obtaining a result indicating that a second apparatus is suspicious to be an untrusted device based on information related to positioning of the second apparatus; and means for determining information indicating whether the second apparatus is the untrusted device based on at least one of a trusted device list or minimization of drive tests (MDT) data associated with the second apparatus.
[0228] In some example embodiments, the first apparatus further comprises: means for receiving, from the second apparatus, the information related to positioning of the second apparatus, the information related to positioning comprising at least one of reference coordinates data of the second apparatus or a first measurement result of a first reference signal; means for determining a first candidate position of the second apparatus based on the information related to positioning of the second apparatus; means for determining a second candidate position of the second apparatus by measuring a second reference signal from the second apparatus; and means for in response to a difference between the first candidate position and the second candidate position is larger than a first threshold, determining that the second apparatus is suspicious to be the untrusted device.
[0229] In some example embodiments, the first apparatus further comprises: means for in response to determining that the second apparatus is suspicious to be the untrusted device, transmitting a request for the trusted device list to a third apparatus, wherein the trusted device list indicates one or more trusted devices that are predetermined; and means for receiving a response comprising the trusted device list from the third apparatus.
[0230] In some example embodiments, the first apparatus further comprises: means for receiving the information related to positioning of the second apparatus, the information related to positioning comprising at least one of reference coordinates data of the second apparatus or a first measurement result of a first reference signal; means for determining a first candidate position of the second apparatus based on the information related to positioning of the second apparatus; means for determining a second candidate position of the second apparatus by measuring a second reference signal from the second apparatus; and means for in response to a difference between the first candidate position and the second candidate position is larger than a first threshold, determining that the second apparatus is suspicious to be the untrusted device.
[0231] In some example embodiments, the first apparatus further comprises: means for obtaining the MDT data associated with the second apparatus, wherein the MDT data is assumed trusted; means for correlating the MDT data with the information related to positioning of the second apparatus; and means for in response to detecting an anomaly from a result of the correlating, determining that the second apparatus is the untrusted device.
[0232] In some example embodiments, the first apparatus further comprises: means for transmitting, to a third apparatus, a request for the MDT data associated with the second apparatus; and means for receiving, from the third apparatus, a response comprising the MDT data associated with the second apparatus.
[0233] In some example embodiments, the first apparatus further comprises: means for in response to that no anomaly is detected from the result of the correlating, transmitting a request for the trusted device list to a third apparatus, wherein the trusted device list indicates one or more trusted devices that are predetermined; and means for receiving a response comprising the trusted device list from the third apparatus.
[0234] In some example embodiments, the first apparatus further comprises: means for determining the information indicating whether the second apparatus is the untrusted device by comparing the information related to positioning of the second apparatus and information related to positioning of a trusted device in the trusted device list.
[0235] In some example embodiments, the first apparatus further comprises: means for transmitting, to the trusted device, a request for the information related to positioning of the trusted device; and means for receiving, from the trusted device, a response comprising the information related to positioning of the trusted device.
[0236] In some example embodiments, the first apparatus further comprises: means for in response to determining that a difference between a first measurement result of a first reference signal comprised in the information related to positioning of the second apparatus and a second measurement result of the first reference signal comprised in the information related to positioning of the trusted device is larger than a second threshold, determining that the second apparatus is the untrusted device; and in response to determining that the difference is less than or equal to the second threshold, determining that the second apparatus is not the untrusted device.
[0237] In some example embodiments, the first apparatus further comprises: means for receiving, from a fourth apparatus, a configuration indicating the first threshold.
[0238] In some example embodiments, the fourth apparatus comprises a network device implementing operations, administration, and maintenance (0AM).
[0239] In some example embodiments, the first apparatus further comprises: means for transmitting, to a third apparatus, the information indicating whether the second apparatus is the untrusted device.
[0240] In some example embodiments, the third apparatus comprises a network device implementing user data management (UDM) or access and mobility function (AMF) or operations, administration, and maintenance (0AM).
[0241] In some example embodiments, a third apparatus capable of performing any of the method 1000 (for example, the third apparatus 130 in FIG. 1) may comprise means for performing the respective operations of the method 1000. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The third apparatus may be implemented as or included in the third apparatus 130 in FIG. 1.
[0242] In some example embodiments, the third apparatus comprises means for receiving, from a first apparatus, a request for the trusted device list; and means for transmitting, to the first apparatus, a response comprising the trusted device list for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the trusted device list indicates one or more trusted devices that are predetermined.
[0243] In some example embodiments, the third apparatus is caused to: means for receiving, from the first apparatus, a request for the MDT data associated with the second apparatus, wherein the MDT data is assumed trusted; and means for transmitting, to the first apparatus, a response comprising the MDT data associated with the second apparatus.
[0244] In some example embodiments, the third apparatus is caused to: means for receiving, from the first apparatus, the information indicating whether the second apparatus is the untrusted device.
[0245] In some example embodiments, the first apparatus comprises a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the second apparatus comprises a terminal device, and the third apparatus comprises a network device implementing user data management (UDM) or access and mobility function (AMF) or operations, administration, and maintenance (0AM).
[0246] In some example embodiments, a fifth apparatus capable of performing any of the method 1100 (for example, the fifth apparatus 510 in FIG. 5) may comprise means for performing the respective operations of the method 1100. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The fifth apparatus may be implemented as or included in the fifth apparatus 510 in FIG. 5.
[0247] In some example embodiments, the fifth apparatus comprises means for in response to determining that a seventh apparatus is untrusted, transmitting to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
[0248] In some example embodiments, the fifth apparatus is caused to: means for receiving, from the sixth apparatus, second information indicating that the seventh apparatus is a trusted device for a second service, wherein the first information and the second information share the same context.
[0249] In some example embodiments, the fifth apparatus is caused to: means for performing the second service by using data from the seventh apparatus.
[0250] In some example embodiments, the fifth apparatus comprises a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth apparatus comprises a further network device in a radio access network (RAN) or implementing an access and mobility management function (AMF), and the seventh apparatus comprises a terminal device.
[0251] In some example embodiments, a sixth apparatus capable of performing any of the method 1200 (for example, the sixth apparatus 520 in FIG. 5) may comprise means for performing the respective operations of the method 1200. The means may be implemented in any suitable form. For example, the means may be implemented in a circuitry or software module. The fourth apparatus may be implemented as or included in the sixth apparatus 520 in FIG. 5.
[0252] In some example embodiments, the sixth apparatus comprises means for receiving, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; and means for performing at least one of: refraining from using data from the seventh apparatus in the first service, or transmitting the first information to an eighth apparatus.
[0253] In some example embodiments, the fifth apparatus comprises a network device in a radio access network (RAN) and the sixth apparatus comprises a further network device in a radio access network (RAN), wherein the sixth apparatus is caused to: means for refraining from using data from the seventh apparatus in the first service; and means for in response to determining that the seventh apparatus is not untrusted, transmitting to the fifth apparatus, second information indicating that the seventh apparatus is a trusted device for a second service, wherein the first information and the second information share the same context.
[0254] In some example embodiments, the fifth apparatus comprises a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth apparatus comprises a network device implementing an access and mobility management function (AMF), and wherein the sixth apparatus is caused to: means for storing the first information in context information associated with the seventh apparatus; and / or means for in response to receiving, from an eighth apparatus, a request for context information associated with the seventh apparatus, transmit the first information to the eighth apparatus.
[0255] In some example embodiments, the eighth apparatus comprises a further network device in the radio access network (RAN).
[0256] FIG. 13 is a simplified block diagram of a device 1300 that is suitable for implementing example embodiments of the present disclosure. The device 1300 may be provided to implement a communication device, for example, the first apparatus 110 and the third apparatus 130 as shown in FIG. 1, as well as the fifth apparatus 510, and the sixth apparatus 520 as shown in FIG. 5. As shown, the device 1300 includes one or more processors 1310, one or more memories 1320 coupled to the processor 1310, and one or more communication modules 1340 coupled to the processor 1310.
[0257] The communication module 1340 is for bidirectional communications. The communication module 1340 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interfaces may represent any interface that is necessary for communication with other network elements. In some example embodiments, the communication module 1340 may include at least one antenna.
[0258] The processor 1310 may be of any type suitable to the local technical network and may include one or more of the following: general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs) and processors based on multicore processor architecture, as non-limiting examples. The device 1300 may have multiple processors, such as an application specific integrated circuit chip that is slaved in time to a clock which synchronizes the main processor.
[0259] The memory 1320 may include one or more non-volatile memories and one or more volatile memories. Examples of the non-volatile memories include, but are not limited to, a Read Only Memory (ROM) 1324, an electrically programmable read only memory (EPROM), a flash memory, a hard disk, a compact disc (CD), a digital video disk (DVD), an optical disk, a laser disk, and other magnetic storage and / or optical storage. Examples of the volatile memories include, but are not limited to, a random-access memory (RAM) 1322 and other volatile memories that will not last in the power-down duration.
[0260] A computer program 1330 includes computer executable instructions that are executed by the associated processor 1310. The instructions of the program 1330 may include instructions for performing operations / acts of some example embodiments of the present disclosure. The program 1330 may be stored in the memory, e.g., the ROM 1324. The processor 1310 may perform any suitable actions and processing by loading the program 1330 into the RAM 1322.
[0261] The example embodiments of the present disclosure may be implemented by means of the program 1330 so that the device 1300 may perform any process of the disclosure as discussed with reference to FIG. 2 to FIG. 12. The example embodiments of the present disclosure may also be implemented by hardware or by a combination of software and hardware.
[0262] In some example embodiments, the program 1330 may be tangibly contained in a computer readable medium which may be included in the device 1300 (such as in the memory 1320) or other storage devices that are accessible by the device 1300. The device 1300 may load the program 1330 from the computer readable medium to the RAM 1322 for execution. In some example embodiments, the computer readable medium may include any types of non-transitory storage medium, such as ROM, EPROM, a flash memory, a hard disk, CD, DVD, and the like. The term “non-transitory,” as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e g., RAM vs. ROM).
[0263] FIG. 14 shows an example of the computer readable medium 1400 which may be in form of CD, DVD or other optical storage disk. The computer readable medium 1400 has the program 1330 stored thereon.
[0264] Generally, various embodiments of the present disclosure may be implemented in hardware or special purpose circuits, software, logic or any combination thereof. Some aspects may be implemented in hardware, and other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device. Although various aspects of embodiments of the present disclosure are illustrated and described as block diagrams, flowcharts, or using some other pictorial representations, it is to be understood that the block, apparatus, system, technique or method described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0265] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer readable medium, such as a non-transitory computer readable medium. The computer program product includes computerexecutable instructions, such as those included in program modules, being executed in a device on a target physical or virtual processor, to carry out any of the methods as described above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, or the like that perform particular tasks or implement particular abstract data types. The functionality of the program modules may be combined or split between program modules as desired in various embodiments. Machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in both local and remote storage media.
[0266] Program code for carrying out methods of the present disclosure may be written in any combination of one or more programming languages. The program code may be provided to a processor or controller of a general-purpose computer, special purpose computer, or other programmable data processing apparatus, such that the program code, when executed by the processor or controller, cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may execute entirely on a machine, partly on the machine, as a stand-alone software package, partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0267] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier to enable the device, apparatus or processor to perform various processes and operations as described above. Examples of the carrier include a signal, computer readable medium, and the like.
[0268] The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable medium may include but not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the computer readable storage medium would include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random-access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0269] Further, although operations are depicted in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing may be advantageous. Likewise, although several specific implementation details are contained in the above discussions, these should not be construed as limitations on the scope of the present disclosure, but rather as descriptions of features that may be specific to particular embodiments. Unless explicitly stated, certain features that are described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, unless explicitly stated, various features that are described in the context of a single embodiment may also be implemented in a plurality of embodiments separately or in any suitable sub-combination.
[0270] Although the present disclosure has been described in languages specific to structural features and / or methodological acts, it is to be understood that the present disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.
Claims
1. A first apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to:obtain a result indicating that a second apparatus is suspicious to be an untrusted device based on information related to positioning of the second apparatus; anddetermine information indicating whether the second apparatus is the untrusted device based on at least one of a trusted device list or minimization of drive tests (MDT) data associated with the second apparatus.
2. The first apparatus of claim 1, wherein the first apparatus comprises a network device in a radio access network (RAN) and the second apparatus comprises a terminal device, and wherein the first apparatus is caused to:receive, from the second apparatus, the information related to positioning of the second apparatus, the information related to positioning comprising at least one of reference coordinates data of the second apparatus or a first measurement result of a first reference signal;determine a first candidate position of the second apparatus based on the information related to positioning of the second apparatus;determine a second candidate position of the second apparatus by measuring a second reference signal from the second apparatus; andin response to a difference between the first candidate position and the second candidate position is larger than a first threshold, determine that the second apparatus is suspicious to be the untrusted device.
3. The first apparatus of claim 2, wherein the first apparatus is caused to:in response to determining that the second apparatus is suspicious to be the untrusted device, transmit a request for the trusted device list to a third apparatus, wherein the trusted device list indicates one or more trusted devices that are predetermined; andreceive a response comprising the trusted device list from the third apparatus.
4. The first apparatus of claim 1, wherein the first apparatus comprises a network device implementing a location management function (LMF) and the second apparatus comprises a terminal device, and wherein the first apparatus is caused to:receive the information related to positioning of the second apparatus, the information related to positioning comprising at least one of reference coordinates data of the second apparatus or a first measurement result of a first reference signal;determine a first candidate position of the second apparatus based on the information related to positioning of the second apparatus;determine a second candidate position of the second apparatus by measuring a second reference signal from the second apparatus; andin response to a difference between the first candidate position and the second candidate position is larger than a first threshold, determine that the second apparatus is suspicious to be the untrusted device.
5. The first apparatus of claim 1 or 4, wherein the first apparatus is caused to:obtain the MDT data associated with the second apparatus, wherein the MDT data is assumed trusted;correlate the MDT data with the information related to positioning of the second apparatus; andin response to detecting an anomaly from a result of the correlating, determine that the second apparatus is the untrusted device.
6. The first apparatus of claim 5, wherein the first apparatus is caused to:transmit, to a third apparatus, a request for the MDT data associated with the second apparatus; andreceive, from the third apparatus, a response comprising the MDT data associated with the second apparatus.
7. The first apparatus of claim 5 or 6, wherein the first apparatus is caused to:in response to that no anomaly is detected from the result of the correlating, transmit a request for the trusted device list to a third apparatus, wherein the trusted device list indicates one or more trusted devices that are predetermined; andreceive a response comprising the trusted device list from the third apparatus.
8. The first apparatus of any of claims 1 to 7, wherein the first apparatus is causedto:determine the information indicating whether the second apparatus is the untrusted device by comparing the information related to positioning of the second apparatus and information related to positioning of a trusted device in the trusted device list.
9. The first apparatus of claim 8, wherein the first apparatus is caused to:transmit, to the trusted device, a request for the information related to positioning of the trusted device; andreceive, from the trusted device, a response comprising the information related to positioning of the trusted device.
10. The first apparatus of claim 8 or 9, wherein the first apparatus is caused to:in response to determining that a difference between a first measurement result of a first reference signal comprised in the information related to positioning of the second apparatus and a second measurement result of the first reference signal comprised in the information related to positioning of the trusted device is larger than a second threshold, determine that the second apparatus is the untrusted device; andin response to determining that the difference is less than or equal to the second threshold, determine that the second apparatus is not the untrusted device.
11. The first apparatus of any of claims 2 to 10, wherein the first apparatus is caused to:receive, from a fourth apparatus, a configuration indicating the first threshold.
12. The first apparatus of claim 11, wherein the fourth apparatus comprises a network device implementing operations, administration, and maintenance (0AM).
13. The first apparatus of any of claims 1 to 12, wherein the first apparatus is caused to:transmit, to a third apparatus, the information indicating whether the second apparatus is the untrusted device.
14. The first apparatus of any of claims 3, 6 to 13, wherein the third apparatuscomprises a network device implementing user data management (UDM) or access and mobility function (AMF) or operations, administration, and maintenance (0AM).
15. A third apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the first apparatus at least to:receive, from a first apparatus, a request for the trusted device list; andtransmit, to the first apparatus, a response comprising the trusted device list for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the trusted device list indicates one or more trusted devices that are predetermined.
16. The third apparatus of claim 15, wherein the third apparatus is caused to:receive, from the first apparatus, a request for the MDT data associated with the second apparatus, wherein the MDT data is assumed trusted; andtransmit, to the first apparatus, a response comprising the MDT data associated with the second apparatus.
17. The third apparatus of claim 15 or 16, wherein the third apparatus is caused to: receive, from the first apparatus, the information indicating whether the second apparatus is the untrusted device.
18. The third apparatus of any of claims 15 to 17, wherein the first apparatus comprises a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the second apparatus comprises a terminal device, and the third apparatus comprises a network device implementing user data management (UDM) or access and mobility function (AMF) or operations, administration, and maintenance (0AM).
19. A fifth apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the fifth apparatus at least to:in response to determining that a seventh apparatus is untrusted, transmit, to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
20. The fifth apparatus of claim 19, wherein the fifth apparatus is caused to:receive, from the sixth apparatus, second information indicating that the seventh apparatus is a trusted device for a second service, wherein the first information and the second information share the same context.
21. The fifth apparatus of claim 20, wherein the fifth apparatus is caused to: perform the second service by using data from the seventh apparatus.
22. The fifth apparatus of any of claims 15 to 17, wherein the fifth apparatus comprises a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth apparatus comprises a further network device in a radio access network (RAN) or implementing an access and mobility management function (AMF), and the seventh apparatus comprises a terminal device.
23. A sixth apparatus comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the sixth apparatus at least to:receive, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; andperform at least one of: refraining from using data from the seventh apparatus in the first service, or transmitting the first information to an eighth apparatus.
24. The sixth apparatus of claim 23, wherein the fifth apparatus comprises a network device in a radio access network (RAN) and the sixth apparatus comprises a further network device in a radio access network (RAN), wherein the sixth apparatus is caused to:refraining from using data from the seventh apparatus in the first service; andin response to determining that the seventh apparatus is not untrusted, transmit, tothe fifth apparatus, second information indicating that the seventh apparatus is a trusted device for a second service, wherein the first information and the second information share the same context.
25. The sixth apparatus of claim 23, wherein the fifth apparatus comprises a network device in a radio access network (RAN) or a network device implementing a location management function (LMF), the sixth apparatus comprises a network device implementing an access and mobility management function (AMF), and wherein the sixth apparatus is caused to:store the first information in context information associated with the seventh apparatus; and / orin response to receiving, from an eighth apparatus, a request for context information associated with the seventh apparatus, transmit the first information to the eighth apparatus.
26. The sixth apparatus of claim 25, wherein the eighth apparatus comprises a further network device in the radio access network (RAN).
27. A method comprising:obtaining a result indicating that a second apparatus is suspicious to be an untrusted device based on information related to positioning of the second apparatus.determining information indicating whether the second apparatus is the untrusted device based on at least one of a trusted device list or minimization of drive tests (MDT) data associated with the second apparatus.
28. A method comprising:receiving, from a first apparatus, a request for the trusted device list.transmitting, to the first apparatus, a response comprising the trusted device list for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the trusted device list indicates one or more trusted devices that are predetermined.
29. A method comprising:in response to determining that a seventh apparatus is untrusted, transmitting, to asixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
30. A method comprising:receiving, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.performing at least one of: refraining from using data from the seventh apparatus in the first service, or transmitting the first information to an eighth apparatus.
31. A first apparatus comprising:means for obtaining a result indicating that a second apparatus is suspicious to be an untrusted device based on information related to positioning of the second apparatus; andmeans for determining information indicating whether the second apparatus is the untrusted device based on at least one of a trusted device list or minimization of drive tests (MDT) data associated with the second apparatus.
32. A third apparatus comprising:means for receiving, from a first apparatus, a request for the trusted device list; andmeans for transmitting, to the first apparatus, a response comprising the trusted device list for the first apparatus to determine information indicating a second apparatus is an untrusted device, wherein the trusted device list indicates one or more trusted devices that are predetermined.
33. A fifth apparatus comprising:means for, in response to determining that a seventh apparatus is untrusted, transmitting to a sixth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service.
34. A sixth apparatus comprising:means for receiving, from a fifth apparatus, first information indicating that a seventh apparatus is an untrusted device for a first service; andmeans for performing at least one of: refraining from using data from the seventhapparatus in the first service, or transmitting the first information to an eighth apparatus.
35. A computer readable medium comprising instructions stored thereon for causing an apparatus at least to perform the method of claim 27 or the method of claim 28 5 or the method of claim 29 or the method of claim 30.Application No: GB2413204.5Examiner:Adam TuckerClaims searched: 1-14, 27 &31Date of search: 21 January 2025Patents Act 1977: Search Report under Section 17Documents considered to be relevant:Category Relevant to claims Identity of document and passage or figure of particular relevance X Y Y A A A A X: 1, 5,6, 13, 14, 27 &31; Y: 1, 2, 4-6, 11-14, 27, 31 1, 2, 4-6, 11-14, 27, 31 US 2023 / 0354033 Al (Reeves) See the whole document and in particular Figures 2, 3 and paragraphs 18, 19, 23, 42-45, 50, 51 &56 WO 2024 / 093905 Al (Huawei Tech.) See the whole document and in particular the claims and pages 1, 2 &5-8 WO 2023 / 239411 Al (Nokia Technologies) See the whole document US 2024 / 0098496 Al (Marzban et al.) See the whole document WO 2014 / 092997 Al (Apple Inc.) See the whole document US 2019 / 0289433 Al (Arunkumar et al.) See the whole documentCategories:X Document indicating lack of novelty or inventive step A Document indicating technological background and / or state of the art. Y Document indicating lack of inventive step if p Document published on or after the declared priority date but combined with one or more other documents of same category. before the filing date of this invention. & Member of the same patent family E Patent document published on or after, but with priority date earlier than, the filing date of this application.Field of Search:58International Classification:Subclass Subgroup Valid From H04L 0009 / 32 01 / 01 / 2006 H04L 0009 / 40 01 / 01 / 2022 H04L 0067 / 52 01 / 01 / 2022 H04W 0004 / 029 01 / 01 / 2018 H04W 0012 / 122 01 / 01 / 2021 H04W 0012 / 63 01 / 01 / 2021 G01S 0005 / 00 01 / 01 / 2006 H04W 0064 / 00 01 / 01 / 2009
Citation Information
Patent Citations
Mobile device location proofing
US20190289433A1
Fraud detection in wireless communication networks
US20230354033A1
Managing untrusted user equipment (UES) for data collection
US20240098496A1
Location data regression
WO2014092997A1
Verification of UE location for wireless networks based on signal timing measurements
WO2023239411A1