Authorization data scheduling method, authorization data scheduling device, network side device, and readable storage medium
The method and apparatus for scheduling authorized data in network elements verify user permissions to ensure compliant and secure data sharing, addressing unclear authority issues in data proxy network elements.
Patent Information
- Application Number
- JP2024529426
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-11-16
- Filing Date
- 2022-11-10
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2042-11-10
AI Technical Summary
The problem of unclear authority in data is the unclear authority in data proxy network elements is unclear in data proxy network elements is unclear in data proxy network elements, leading to unauthorized sharing of user-related data.
A method and apparatus for scheduling authorized data, where network elements verify user authorization information before sharing data, allowing them to clarify their behavior and ensure user data safety and compliance with regulations.
Ensures that data sharing is allowed based on user permissions, clarifying network element behavior and enhancing data security and compliance with GDPR.
Smart Images

Figure 0007781275000001 
Figure 0007781275000002 
Figure 0007781275000003
Abstract
Description
[Technical Field]
[0001] The present application relates to the field of wireless communication technology, and particularly to a method, apparatus and network side equipment for scheduling grant data. [Background technology]
[0002] According to the General Data Protection Regulation (GDPR), user personal data belongs to the user's personal assets and may not be freely obtained or used. For example, in a wireless communication system, data related to the user generated by the user in the wireless network communication process (such as data from the user terminal, data in the user's service server, and network data generated by the user in the network) all belong to the user's personal assets. Therefore, before obtaining or using this data, network elements in the network must obtain user authorization information from a unified database (such as a Unified Data Management (UDM) or Unified Data Repository (UDR)). Only when the user authorization information indicates that data acquisition or use is permitted can the network elements in the network obtain or use user data.
[0003] However, taking a data proxy network element as an example, if the data proxy network element itself has already acquired and stored user-related data, then when another network element requests the stored user-related data from the data proxy network element, it will cause a problem in that it is unclear whether the data proxy network element has the authority to share the stored user-related data with the other network elements. Summary of the Invention [Problem to be solved by the invention]
[0004] The embodiments of the present application provide a method, apparatus and network side equipment for scheduling authorized data, which can solve the problem that the behavior of data proxy network elements is unknown. [Means for solving the problem]
[0005] According to a first aspect, a method for scheduling authorized data is provided, comprising: a first network element receiving a data request message sent by a second network element, the data request message being used to request target data, the target data being data related to a target user stored in the first network element or a data warehouse; and the first network element performing a first operation based on the target user's authorization information, the first operation comprising refusing to provide the target data to the second network element or transmitting the target data to the second network element.
[0006] According to a second aspect, a method for scheduling authorized data is provided, comprising: a first network element receiving a data request message sent by a second network element, the data request message being used to request targeted data, and the data request message including at least authorization information of a target user, the targeted data being data related to the target user; and the first network element performing a first operation based on the authorization information of the target user, the first operation including refusing to provide the targeted data to the second network element or transmitting the targeted data to the second network element.
[0007] According to a third aspect, there is provided a method for scheduling authorized data, comprising: a second network element sending a data request message to a first network element, the data request message being used to request targeted data, and the data request message including at least authorization information of a target user, and the targeted data being relevant data of the target user.
[0008] According to a fourth aspect, there is provided an authorization data scheduling device for use in a first network element, the device including: a first transmission module for receiving a data request message sent by a second network element, the data request message being used to request target data, the target data being data related to a target user stored in the first network element or a data warehouse; and a first execution module for performing a first operation based on the target user's authorization information, the first operation including refusing to provide the target data to the second network element or transmitting the target data to the second network element.
[0009] According to a fifth aspect, there is provided an authorization data scheduling device for use in a first network element, the device including: a second transmission module for receiving a data request message sent by a second network element, the data request message being used to request target data, and the data request message including at least authorization information of a target user, the target data being data related to the target user; and a second execution module for performing a first operation based on the authorization information of the target user, the first operation including refusing to provide the target data to the second network element or transmitting the target data to the second network element.
[0010] According to a sixth aspect, there is provided an authorization data scheduling device for use in a second network element, the device including: a third transmission module for sending a data request message to a first network element, the data request message being used to request target data, and the data request message including at least authorization information of a target user, and the target data being data related to the target user.
[0011] According to a seventh aspect, there is provided a network side device, the network side device including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, the program or instructions, when executed by the processor, realizing the steps of the method according to the first aspect, the second aspect or the third aspect.
[0012] According to an eighth aspect, there is provided a network side device, the network side device comprising: a processor and a communication interface, wherein the communication interface is coupled to the processor, the processor executing a program or instructions to implement the steps of the method according to the first aspect;performing the steps of the method according to the second aspect, Or, it is used to realize the steps of the method according to the third aspect.
[0013] According to a ninth aspect, there is provided a readable storage medium having a program or instructions stored on the readable storage medium, the program or instructions being configured to, when executed by a processor, perform the steps of the method according to the first aspect, or to perform the steps of the method according to the second aspect, or to perform the steps of the method according to the third aspect.
[0014] According to a tenth aspect, there is provided a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to execute a program or instructions to perform steps of the method according to the first aspect, or to perform steps of the method according to the second aspect, or to perform steps of the method according to the third aspect.
[0015] According to an eleventh aspect, a computer program M / a program product, said computer program / program product being stored on a non-transitory storage medium; computer The program / program product is executed by at least one processor to implement the steps of the method according to the first aspect, or to implement the steps of the method according to the second aspect, or to implement the steps of the method according to the third aspect. [Effects of the Invention]
[0016] In the embodiment of the present application, before the first network element shares the user-related data stored in itself with the second network element, it needs to determine whether data sharing is allowed for the user-related data based on the user's permission information, which not only allows the first network element to clarify its own behavior, but also ensures the safety of user data and makes the network more compliant. [Brief explanation of the drawings]
[0017] [Figure 1a] 1 is a structural schematic diagram of a wireless communication system according to one exemplary embodiment of the present application; [Figure 1b] 1 is a structural schematic diagram of a system for scheduling authorization data according to an exemplary embodiment of the present application; [Figure 2] 1 is a flowchart of a method for scheduling authorization data according to an exemplary embodiment of the present application; [Figure 3] 1 is a second flowchart of a method for scheduling authorization data according to an exemplary embodiment of the present application; [Figure 4] 3 is an interaction flowchart of a method for scheduling authorization data according to an exemplary embodiment of the present application; [Figure 5] 10 is a third flowchart of a method for scheduling authorization data according to an exemplary embodiment of the present application; [Figure 6] 4 is a fourth flowchart of a method for scheduling authorization data according to an exemplary embodiment of the present application; [Figure 7] 2 is a second interaction flowchart of a method for scheduling authorization data according to an exemplary embodiment of the present application; [Figure 8] FIG. 1 is a structural schematic diagram of an authorization data scheduling device according to an exemplary embodiment of the present application; [Figure 9] FIG. 2 is a second structural schematic diagram of an authorization data scheduling apparatus according to an exemplary embodiment of the present application; [Figure 10] 3 is a third structural schematic diagram of an authorization data scheduling device according to an exemplary embodiment of the present application; [Figure 11] FIG. 2 is a structural schematic diagram of a network side device according to an exemplary embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION
[0018] The following clearly describes the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application, and it is obvious that the described embodiments are only some of the embodiments of the present application, and not all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present application fall within the scope of protection of the present application.
[0019] The terms "first," "second," etc. in the specification and claims of this application are intended to distinguish between similar objects and are not intended to describe a particular order or sequence. It should be understood that terms used in this manner are interchangeable where appropriate, so that embodiments of this application may be performed in orders other than those illustrated or described herein, and that objects distinguished by "first" and "second" are generally of the same type and do not limit the number of objects; for example, a first object may be one or more. Furthermore, "and / or" in the specification and claims indicates at least one of the connected objects, and the character " / " generally indicates an "or" relationship between the related objects.
[0020] It should be noted that the techniques described in the embodiments of the present application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be applied to other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), and other systems. The terms "system" and "network" in the embodiments of the present application are always used interchangeably, and the described techniques may be used in the above-mentioned systems and radio technologies as well as other systems and radio technologies. Although the following description describes a New Radio (NR) system for illustrative purposes and uses NR terminology in most of the following description, these techniques may be applied to applications other than NR system applications, such as 6th Generation (6G) communication systems.
[0021] 1a shows a structural schematic diagram of a wireless communication system to which the embodiments of the present application can be applied. The wireless communication system includes a terminal 11 and a network side device 12. Here, the terminal 11 may be referred to as a terminal device or user equipment (UE), and may be a terminal side device such as a mobile phone, a tablet personal computer (PDA), a laptop computer (also called a notebook computer), a personal digital assistant (PDA), a palmtop computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), a wearable device (WD), a vehicle-mounted equipment (VUE), a pedestrian-mounted equipment (PUE), etc., and wearable devices include a smart watch, a bracelet, an earphone, glasses, etc. It should be noted that the embodiments of the present application do not limit the specific type of the terminal 11. The network side equipment 12 may be a base station or a core network, where the base station may be called a Node B, an evolved Node B, an access point, a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a B node, an evolved B node (eNB), a home B node, a home evolved B node, a WLAN access point, a WiFi node, a transmitting and receiving point (TRP), or any other suitable term in the art, as long as the same technical effect is achieved. The base station is not limited to a specific technical term. For illustrative purposes, the embodiments of this application only take base stations in an NR system as examples, and do not limit the specific type of base station.
[0022] Based on the wireless communication system, as shown in FIG. 1b, is a structural schematic diagram of an authorization data scheduling system according to one exemplary embodiment of the present application, where the scheduling system may include a first network element, a second network element, a third network element, and a fourth network element.
[0023] Here, the first network element may be an associated network element or a data proxy network element that stores (or saves, caches) one or more user-related data (e.g., user history data), such as a Network Data Analytics Function (NWDAF), a Data Collection Coordination Function (DCCF), a Data Analytics Data Repository Function (ADRF), or other functional network elements in the network, such as an Access and Mobility Management Function (AMF), a Session Management Function (SMF), etc. Here, the DCCF and NWDAF can provide data management services, the AMF is used to store mobility management data related to the UE, and the SMF is used to store session management data related to the UE.
[0024] The second network element is a network element or entity that needs to acquire user-related data (e.g., user history data), and the purpose of acquiring the user-related data is for the second network element to make decisions based on different communication scenarios. For example, if the second network element is an NWDAF, the purpose of acquiring the user-related data by the second network element may be to train an AI model (identified by an analytic ID) as input data. For example, if the second network element is a 5GC NF (e.g., a Policy Control Function (PCF), an AMF, an Application Function (AF), etc.), the purpose of acquiring the user-related data by the second network element may be to analyze the acquired user history data to perform a policy decision as reference information. For example, a PCF acquires user terminal historical mobility analytics and user terminal historical service behavior analytics generated by a first network element (e.g., an NWDAF) and uses them to generate a more appropriate network-resident policy (RFSP index) for the UE.
[0025] It should be noted that the second network element may also be understood as a data consumer.
[0026] The third network element is a network element in which at least one user consent information is stored, such as a UDM, a UDR, etc., that is, each user's consent information may be stored in a UDM, a UDR as user subscription data.
[0027] The fourth network element is a related network element in the network that can provide (one or more) user-related data (e.g., user history data), such as an AMF, a Radio Access Network (RAN), an SMF, or an NWDAF, where the AMF or RAN can provide UE mobility-related data, the SMF can provide Protocol Data Unit session (PDU session)-related data, and the NWDAF can provide some data analysis results (e.g., user service behavior analysis results).
[0028] As can be understood, the fourth network element may be understood as a data source, a data warehouse, etc., and is not limited thereto.
[0029] Based on FIG. 1a and FIG. 1b, the following will describe in detail the technical solutions according to the embodiments of the present application through several embodiments and their application scenarios in conjunction with the drawings.
[0030] 2, which is a flowchart of a method 200 for scheduling authorization data according to an exemplary embodiment of the present application, the method 200 may be performed by, but is not limited to, a first network element, specifically, by hardware and / or software installed in the first network element. In this embodiment, the method 200 may include at least the following steps:
[0031] At S210, the first network element receives a data request message sent by the second network element.
[0032] Here, the data request message is used to request targeted data, and the targeted data is data related to a target user stored in the first network element or a data warehouse.
[0033] For example, the target data may be user history data related to the target user that the first network element has already acquired and stored in itself or in a data warehouse, and is not limited thereto.
[0034] Based on this, the data request message may include at least one of the following (11)-(17):
[0035] (11) Type information of the target data. Here, the type information of the target data may be type information classified based on data function, type information classified based on the size of data, type information classified based on data generation time, etc., and is not limited thereto in this embodiment.
[0036] (12) Identifier information of the target data, where the identifier information may be one or more event identifiers (event IDs), one or more analytics identifiers (analytics IDs), or the like.
[0037] (13) At least one terminal equipment identifier information (UE ID) for identifying that the target user is a user corresponding to the at least one terminal equipment identifier information, i.e., the subject of the target data requested by the second network element is one or more target users identified by UE ID.
[0038] (14) Area information for identifying that the target user is a user located in the area corresponding to the area information, i.e., identifying that the target data requested by the second network element is for one or more target users identified by the area.
[0039] It should be understood that the user granularity corresponding to (13) and (14) is different. For example, if the data request message includes the identifier information of at least one terminal device described in (13), the target data is the relevant data of the user corresponding to the identifier information of at least one terminal device. Also, for example, if the data request message includes the area information described in (14), the target data is the relevant data of each user in the area corresponding to the area information.
[0040] (15) A second time for indicating that the target data is data generated within the second time. Generally, the second time may be a history time, that is, the target data obtained by the second network element using the data request message is user history data generated within the second time.
[0041] (16) A third time for indicating a time for the first network element to feed back the target data, i.e., for indicating that the first network element feeds back the target data requested by the second network element within the third time.
[0042] Here, the second time is later than the first time, or the second time is after the first time.
[0043] (17) The second network element obtains usage information (or purpose information) of the target data, where the usage information may be determined by the second network element based on a communication scenario, such as model training, inference task, or generating data analysis results for a certain analytics ID.
[0044] It should be noted that the data request message Which of the above (11)-(17) is included in (11)-(17) may be promised by the protocol, configured by an upper layer, or configured and realized by the network side, and is not limited here.
[0045] At S220, the first network element performs a first operation based on the authorization information of the target user.
[0046] Here, the first operation includes refusing (which may be understood as stopping or canceling) the provision of the target data to the second network element, or transmitting the target data to the second network element.
[0047] For example, if the target user's permission information indicates that the target user does not agree to data sharing for the target data, the first network element refuses to provide the target data to the second network element, and, for example, if the target user's permission information indicates that the target user agrees to data sharing for the target data, the first network element transmits the target data to the second network element.
[0048] Alternatively, the target user's authorization information may be obtained by the first network element from a third network element, or may be selected by the first network element from one or more user authorization information cached by itself, and this embodiment is not limited thereto.
[0049] In addition, the authorization information of one or more users cached by the first network element itself may be stored in the cache of the first network element in the past (e.g., when the first network element requests data). message It may be understood that the authorization information of the relevant user was obtained from the third network element at a time in the past (which may be a time before the first network element received the authorization information), for example, the first network element (e.g., NWDAF) already obtained the authorization information of the relevant user from the third network element due to other reasons (e.g., it needs to perform model training or data inference).
[0050] Furthermore, the first network element determines a scenario for transmitting the target data to the second network element based on the target user's authorization information. If the target data is data related to the target user stored in the first network element, the first network element acquires the target data from itself and transmits it to the second network element. Here, the target data stored in the first network element may be understood as data related to the target user, i.e., target data, that the first network element has already acquired from a data warehouse (e.g., a data source) according to some need of itself or another network element before executing S210. For example, the first network element (e.g., NWDAF) may acquire location data of a UE as training input data from a data warehouse (e.g., AMF) because it needs to train a UE movement trajectory model.
[0051] Furthermore, if the target data is data related to the target user stored in a data warehouse, then when the first network element determines to send the target data to the second network element based on the authorization information of the target user, the first network element may send a data acquisition request message to the data warehouse, thereby acquiring the target data. Optionally, the data acquisition request message may be determined based on the data request message and may include, for example, type information of the target data, identifier information of the target data, and identifier information of at least one terminal device.
[0052] In this embodiment, before the first network element shares the user-related data stored in itself with the second network element, it may determine whether data sharing is allowed for the user-related data based on the user's permission information, which not only allows the first network element to clarify its own behavior, but also ensures the safety of user data and makes the network more compliant.
[0053] 3, which is a flowchart of a method 300 for scheduling authorization data according to an exemplary embodiment of the present application, the method 300 may be performed by, but is not limited to, a first network element, specifically, by hardware and / or software installed in the first network element. In this embodiment, the method 300 may include at least the following steps:
[0054] At S310, the first network element receives a data request message sent by the second network element.
[0055] Here, the data request message is used to request targeted data, and the targeted data is data related to a target user stored in the first network element or a data warehouse.
[0056] It can be understood that the implementation process of S310 can be referred to the relevant description in the method embodiment 200, and will not be further described here to avoid repetition.
[0057] At S320, the first network element sends an authorization request message to a third network element based on the data request message.
[0058] Wherein, the authorization request message is used to obtain the authorization information of the target user. Optionally, the authorization request message may be Nudm_SDM_Get.
[0059] In one implementation, the permission request message may include at least one of the following (21)-(27).
[0060] (21) At least one identifier information for instructing to obtain permission information of the target user corresponding to the identifier information.
[0061] (22) Requested user permission type information, including at least data sharing.
[0062] In one implementation, the user permission information may be subdivided into different types or scopes, such as whether data acquisition is permitted, whether data usage is permitted, whether data sharing is permitted, whether data processing is permitted, etc.
[0063] Additionally, the requested user permission type information may be obtained from the received data request message.
[0064] (23) A first time for indicating that the target data is data generated within the first time, i.e., the first time is the generation time of the target data, generally a historical time, that is, the target user's permission information is permission information corresponding to historical data.
[0065] (24) The second network element obtains usage information (or purpose information) of the target data, where the usage information of the target data may be obtained by the first network element from a data request message sent by the second network element, and is used to instruct the second network element to obtain the final purpose or use of the target data.
[0066] (25) First information for indicating the permitted range of use, so that the target user can determine whether to permit this range of use based on the first information.
[0067] (26) Second information for indicating the permitted usage time, so that the target user can decide whether to permit this usage time based on the second information.
[0068] (27) Third information for indicating an allowed storage time, so that the target user can decide whether to allow this storage time based on the third information.
[0069] It should be noted that whether the authorization request message includes one or more of (21)-(27) above may be determined by the protocol, configured by an upper layer, or configured and implemented by the network side, and is not limited here.
[0070] Furthermore, after receiving the authorization request message sent by the first network element, the third network element can determine whether to allow the first network element to share the target data with the second network element based on the information included in the authorization request message, and feed back the target user's authorization information to the first network element, where the target user's authorization information may include at least consent information or disapproval information, where the "consent information" indicates that the target user allows the first network element to share the target data with the second network element, and the "disapproval information" indicates that the target user does not allow the first network element to share the target data with the second network element.
[0071] Of course, the information contained in the target user's permission information is message In one implementation, the target user's permission information may include at least one of the following (31)-(34):
[0072] (31) Fourth information for instructing the target user to consent or not consent to data sharing.
[0073] (32) Fifth information for indicating an authorized use scope, i.e., indicating that the target user agrees to the second network element using the target data within the authorized use scope. Optionally, the authorized use scope may be one or more of an authorized use purpose, an object, an area, etc.
[0074] (33) Sixth information for indicating an allowed usage time, i.e., indicating that the target user agrees to the second network element using the target data within this allowed usage time.
[0075] (34) Seventh information for indicating an allowed storage time, i.e., indicating that the target user agrees to the second network element storing the target data within this allowed storage time.
[0076] That is, for (32)-(34), after the permitted use range or permitted use time or permitted storage time is exceeded, the second network element is not allowed to continue using / storing the target data, for example, the second network element may delete the target data.
[0077] It can also be understood that if the fourth information indicates that the target user agrees to data sharing, the target user's permission information may include at least one of the fifth information, the sixth information, and the seventh information; conversely, the target user's permission information may only include the fourth information, and the present application is not limited thereto.
[0078] At S330, the first network element performs a first operation based on the authorization information of the target user.
[0079] Here, the first operation includes refusing to provide the target data to the second network element, or transmitting the target data to the second network element.
[0080] It can be understood that the implementation process of S330 can refer to the relevant description in the method embodiment 200. In one possible implementation, if the target user's permission information indicates that the target user does not agree to data sharing for the targeted data, the first network element may refuse or stop providing the targeted data to the second network element, and send a first response message to the second network element, where the first response message is used to instruct at least the second network element that the first network element refuses or stops providing the targeted data.
[0081] Optionally, the first response message includes at least one of the following (41)-(44):
[0082] (41) Eighth information for instructing the first network element to refuse or stop providing the target data to the second network element. As can be understood, the eighth information is refusal / error indication information, which is used to indicate failure in obtaining the target data.
[0083] (42) Ninth information for indicating the reason why the first network element refuses or stops providing the targeted data, for example, the target user does not allow data sharing (i.e., the target user does not allow the first network element to share already acquired or stored targeted data with this second network element).
[0084] (43) Tenth information for instructing the second network element to cancel or delete a subscription request for the targeted data.
[0085] As can be understood, the data request message sent by the second network element may be a persistent subscription message or a non-persistent subscription message (i.e., a data one-time acquisition message), and if the data request message sent by the second network element is a persistent subscription message, the first response message may include tenth information, thereby instructing the second network element to cancel or delete the subscription request for the target data.
[0086] (44) Eleventh information for guiding the second network element to attempt to obtain the target data from the first network element again after the waiting time by indicating a waiting time for the second network element to request the target data from the first network element again.
[0087] For example, if the data request message is a data subscription message and the first network element has already received this data subscription message and provided related data, then if the first network element determines that the target user's permission information for data sharing is non-consent information, the first response message sent by the first network element to the second network element may be a notification message, and the eighth information included therein is used to notify the second network element that the second network element will no longer continue to provide the target data of the target user to it, the ninth information is that the target user will no longer allow data sharing (i.e., the target user will not allow the first network element to share data that has already been acquired or stored by the first network element with the second network element), and the tenth information is instruction information to cancel the subscription, requesting the second network element to cancel the data subscription for the target user.
[0088] In another possible implementation, if the target user's permission information indicates that the target user agrees to data sharing for the target data, the first network element sends a second response message to the second network element, where the second response message includes at least the target data, which may be data stored by the first network element itself or data stored in a data warehouse.
[0089] Optionally, the second response message further includes at least one of the following (51)-(53):
[0090] (51) Twelfth information for indicating an authorized scope of use, i.e., indicating that the target user consents to the second network element using the target data within this authorized scope of use.
[0091] (52) Thirteenth information for indicating an allowed usage time, i.e., indicating that the target user consents to the second network element using the target data within this allowed usage time.
[0092] (53) Fourteenth information for indicating an allowed storage time, i.e., indicating that the target user agrees to the second network element storing the target data within this allowed storage time.
[0093] As can be understood, after the permitted usage range or permitted usage time or permitted storage time has been exceeded, the second network element is not allowed to continue using / storing the target data, for example, the second network element may delete the target data.
[0094] Based on the description of the method embodiments 200 and 300, the implementation process of the method embodiments 200 and 300 will be exemplarily described below in conjunction with Fig. 4 again, as follows: It is assumed that the target data is the target user's related data stored in the first network element.
[0095] At S410, the second network element sends a data request message to the first network element.
[0096] At S420, the first network element sends an authorization request message to the third network element based on the data request message.
[0097] At S430, the third network element feeds back the authorization information of the target user to the first network element based on the authorization request message.
[0098] At S440, if the target user's permission information indicates that the target user does not agree to sharing the target data with the second network element, the first network element feeds back a first response message to the second network element.
[0099] Alternatively, if the target user's permission information indicates that the target user agrees to share the target data stored in itself or its data warehouse with the second network element, the first network element feeds back a second response message to the second network element.
[0100] As can be understood, the implementation process of the authorization data scheduling method 400 according to this embodiment can refer to the relevant descriptions in the method embodiments 200 and / or 300, and achieves the same or corresponding technical effects, and will not be further described here to avoid repetition of description.
[0101] Furthermore, the method 400 for scheduling authorization data according to this embodiment includes, but is not limited to, steps S410-S440, for example, it may include more or fewer steps than steps S410-S440, and this is not limited thereto in this embodiment.
[0102] 5, which is a flowchart of a method 500 for scheduling authorization data according to an exemplary embodiment of the present application, the method 500 may be performed by, but is not limited to, a first network element, specifically, by hardware and / or software installed in the first network element. In this embodiment, the method 500 may include at least the following steps:
[0103] At S510, the first network element receives a data request message sent by the second network element.
[0104] Here, the data request message is used to request targeted data, and the data request message includes at least the authorization information of the target user, and the targeted data is data related to the target user.
[0105] As can be understood, the target user's permission information may be whether the target user agrees to perform data processing, such as data acquisition, data use, data sharing, data storage, etc., on data related to the target user, so that the first network element can determine whether the target user agrees to perform data acquisition, data use, data sharing, data storage, etc. on data related to the target user (e.g., the target data) based on the target user's permission information, thereby avoiding the interaction of already obtained user permission information between different network elements, further avoiding duplicate detection, and achieving the purpose of reducing signaling overhead.
[0106] Alternatively, the target user's authorization information may be already obtained in advance from the third network element before the second network element sends a data acquisition request, or may be pre-configured in the second network element by a method such as promised by a protocol, and is not limited thereto.
[0107] Of course, in one possible implementation, the data request message, in addition to including the target user's authorization information, may further include at least one of the following (61)-(67):
[0108] (61) Type information of the target data. Here, the type information of the target data may be type information divided based on data function, type information classified based on the size of data amount, type information classified based on data generation event, etc., and is not limited thereto in this embodiment.
[0109] (62) Identifier information of the target data, wherein the identifier information may be one or more event identifiers (event IDs), one or more analytics identifiers (analytics IDs), or the like.
[0110] (63) At least one terminal equipment identifier information (UE ID) for identifying that the target user is a user corresponding to the at least one terminal equipment identifier information, i.e., the subject of the target data requested by the second network element is one or more target users identified by UE ID.
[0111] (64) Area information for identifying that the target user is a user located in an area corresponding to the area information, i.e., identifying that the target data requested by the second network element is for one or more target users identified by the area.
[0112] It should be understood that the user granularity corresponding to (63) and (64) is different. For example, if the data request message includes the identifier information of at least one terminal device described in (63), the target data is the relevant data of the user corresponding to the identifier information of at least one terminal device, and for example, if the data request message includes the area information described in (64), the target data is the relevant data of each user in the area corresponding to the area information.
[0113] (65) A second time for indicating that the target data is data generated within the second time. Generally, the second time may be a history time, that is, the target data obtained by the second network element using the data request message is user history data generated within the second time.
[0114] (66) A third time for indicating a time for the first network element to feed back the target data, i.e., for indicating that the first network element feeds back the target data requested by the second network element within the third time.
[0115] Here, the second time is later than the first time, or the second time is after the first time.
[0116] (67) The second network element obtains usage information (or purpose information) of the target data, where the usage information may be determined by the second network element based on a communication scenario, such as model training, inference task, or generating data analysis results for a certain analytics ID.
[0117] It should be noted that the data request message Which of the above (66)-(67) is included in (66)-(67) may be promised by the protocol, configured by an upper layer, or configured and realized by the network side, and is not limited here.
[0118] At S520, the first network element performs a first operation based on the authorization information of the target user, and the first operation includes refusing to provide the target data to the second network element or sending the target data to the second network element.
[0119] Here, the first operation includes refusing (which may be understood as stopping or canceling) providing the targeted data to the second network element or transmitting the targeted data to the second network element. For example, if the target user's authorization information indicates that the target user does not consent to data processing for the targeted data, the first network element refuses to provide the targeted data to the second network element, and for example, if the target user's authorization information indicates that the target user consents to data processing for the targeted data, the first network element transmits the targeted data to the second network element.
[0120] Further, the first network element determines a scenario for transmitting the target data to the second network element based on the target user's authorization information, and the target data may be data related to the target user stored in the first network element or a data warehouse, or may be data obtained by the first network element immediately (or in real time) from a data warehouse (e.g., AMF, etc.).
[0121] As can be understood, the target data stored in the first network element may be understood as the first network element having already acquired target user related data, i.e., target data, from a data warehouse (e.g., a data source) according to some need of itself or other network elements before executing S510. For example, the first network element (e.g., NWDAF) may acquire location data of a certain UE as training input data from a data warehouse (e.g., AMF) because it needs to train a UE movement trajectory model.
[0122] When the target data acquired by the first network element immediately (or in real time) from a data source or a data warehouse, etc. is received, if the target user's permission information indicates that the target user agrees to data processing (e.g., data acquisition, data use, data sharing, data storage, etc.) for the target data, the first network element may transmit a data acquisition request message to a data warehouse, thereby acquiring the target data. For example, the first network element transmits a data acquisition request message to an AMF, thereby acquiring the requested local (UE location) data of the terminal equipment.
[0123] Alternatively, the data acquisition request message may be determined based on the data request message, and may include, for example, type information of target data, identifier information of target data, and identifier information of at least one terminal device.
[0124] In this embodiment, by including the target user's authorization information in the data request message sent by the second network element, the first network element determines whether the target user agrees to perform data processing, such as data acquisition, data use, data sharing, data storage, etc., on data related to itself (e.g., the target data) based on the target user's authorization information, thereby not only avoiding the problem of needing to interact with already obtained user authorization information between different network elements, but also achieving the purpose of avoiding duplicate detection and reducing signaling overhead.
[0125] 6, which is a flowchart of a method 600 for scheduling authorization data according to an exemplary embodiment of the present application, the method 600 may be performed by, but is not limited to, a first network element, specifically, by hardware and / or software installed in the first network element. In this embodiment, the method 600 may include at least the following steps:
[0126] At S610, the first network element receives a data request message sent by the second network element.
[0127] Here, the data request message is used to request targeted data, and the data request message includes at least the authorization information of the target user, and the targeted data is data related to the target user.
[0128] It can be understood that the implementation process of S610 can refer to the relevant description in the method embodiment 500, and in one possible implementation form, the target user's authorization information includes at least one of the following (71)-(74):
[0129] (71) Fifteenth information for indicating whether the target user consents or does not consent to data processing, wherein the data processing includes at least one of data acquisition, data use, data storage, and data sharing.
[0130] (72) Sixteenth information for indicating an authorized scope of use, i.e., indicating that the target user consents to the second network element using the targeted data within the authorized scope of use. Optionally, the authorized scope of use may be one or more of an authorized purpose, an object, an area, etc.
[0131] (73) Seventeenth information for indicating an allowed usage time, i.e., indicating that the target user consents to the second network element using the targeted data within this allowed usage time.
[0132] (74) Eighteenth information for indicating an allowed storage time, i.e., indicating that the target user agrees to the second network element storing the target data within this allowed storage time.
[0133] That is, for (72)-(74), after the permitted use range or permitted use time or permitted storage time is exceeded, the second network element is not allowed to continue using / storing the target data, for example, the second network element may delete the target data.
[0134] At S620, the first network element determines whether the second network element is trusted or untrusted; If the second network element is trustworthy, execute S630. It should be noted that after receiving the data request message, the first network element may default to execute the first operation according to the authorization information of the target data included in the data request message, and as described in S620, the first network element first determines whether the second network element is trustworthy or not, and if the second network element is trustworthy, execute S630, and this embodiment is not limited thereto.
[0135] If the second network element is unreliable, the first network element ignores the target user's authorization information included in the data request message and obtains the target user's authorization information again from a third network element, or the first network element rejects the data request message and sends a third response message to the second network element, the third response message including at least the reason why the first network element rejects the data request message, for example, the target user's authorization information included in the data request message is different or unreliable.
[0136] Based on this, in one implementation, if the first network element determines that the second network element is trustworthy, the first network element may set the second network element as a trusted network element, and then, when it subsequently receives a data request message sent by the second network element, it may not perform authorization checks and may execute S610.
[0137] Alternatively, if the first network element determines that the second network element is untrustworthy, the first network element may set the second network element as an untrustworthy network element, and then, when receiving a data request message subsequently sent by the second network element, regardless of whether it contains authorization information from the target user, the first network element will ignore this authorization information and obtain the target user's authorization information from a third network element.
[0138] Alternatively, the first network element may determine whether the second network element is trustworthy or untrustworthy based on a security check process, for example, the first network element obtains the target user's authorization information from the third network element, and then determines whether the target user's authorization information included in the data request message matches the target user's authorization information obtained from the third network element, and if they match (e.g., the information content of the two is the same), it determines that the second network element is trustworthy; if they do not match (e.g., the information content of the two is different), it determines that the second network element is untrustworthy, and the first network element rejects the data request message of the second network element.
[0139] In addition, when the first network element obtains the authorization information of the target user from the third network element, the first network element may send an authorization request message to the third network element based on the data request message. Optionally, the authorization request message may be Nudm_SDM_Get.
[0140] In one implementation, the permission request message may include at least one of the following (81)-(87).
[0141] (81) At least one identifier information for instructing to obtain permission information of the target user corresponding to the identifier information.
[0142] (82) Requested user permission type information. In one implementation, the user permission information may be subdivided into different types or scopes, such as whether to allow data acquisition, whether to allow data use, whether to allow data sharing, whether to allow data storage, etc.
[0143] Alternatively, the requested user permission type information may be obtained from the received data request message.
[0144] (83) A first time for indicating that the target data is data generated within the first time, i.e., the first time is the generation time of the target data, generally a historical time, that is, the target user's permission information is permission information corresponding to historical data.
[0145] (84) The second network element obtains usage information (or purpose information) of the target data, where the usage information of the target data may be obtained by the first network element from a data request message sent by the second network element, and is used to instruct the second network element to obtain the final purpose or use of the target data.
[0146] (85) First information for indicating an allowed range of use, so that the third network element determines whether to allow this range of use based on the first information.
[0147] (86) Second information indicating an allowed usage time, so that the third network element determines whether to allow this usage time based on the second information.
[0148] (87) Third information for indicating an allowed storage time, so that the third network element determines whether to allow this storage time based on the third information.
[0149] It should be noted that whether the authorization request message includes one or more of (81)-(87) above may be determined by the protocol, configured by an upper layer, or configured and implemented by the network side, and is not limited here.
[0150] Furthermore, after receiving the authorization request message sent by the first network element, the third network element can determine whether to allow the first network element to process the target data based on the information included in the authorization request message, and feed back the target user's authorization information to the first network element. Here, the target user's authorization information may include at least consent information or disapproval information, where "consent information" indicates that the target user allows the first network element to process the target data, and "disapproval information" indicates that the target user does not allow the first network element to process the target data. Optionally, the aforementioned data processing includes data use, data sharing, data storage, data acquisition, etc.
[0151] At S630, the first network element performs a first operation based on the authorization information of the target user.
[0152] Here, the first operation includes refusing to provide the target data to the second network element, or transmitting the target data to the second network element.
[0153] It can be understood that the implementation process of S630 can refer to the relevant description in the method embodiment 500. In addition, as one possible implementation, if the target user's permission information indicates that the target user does not consent to data processing on the target data, the first network element may refuse or stop providing the target data to the second network element, and send a fourth response message to the second network element, where the fourth response message is used to instruct at least the second network element that the first network element refuses or stops providing the target data.
[0154] Optionally, the fourth response message includes at least one of the following (91)-(94):
[0155] (91) Nineteenth information for instructing the first network element to refuse or stop providing the target data to the second network element, as can be understood, Nineteen The information is 19th information, which is rejection / error indication information and is used to indicate failure to acquire target data.
[0156] (92) Twenty-fifth information for indicating the reason why the first network element is refusing or suspending provision of the targeted data, for example, the target user is not authorized for data processing.
[0157] (93) Twenty-first information for instructing the second network element to cancel or delete a subscription request for the targeted data.
[0158] As can be understood, the data request message sent by the second network element may be a persistent subscription message or a non-persistent subscription message (i.e., a data one-time acquisition message), and if the data request message sent by the second network element is a persistent subscription message, the first response message may include tenth information, thereby instructing the second network element to cancel or delete the subscription request for the target data.
[0159] (94) Twenty-second information for instructing the second network element to wait a time for the second network element to request the target data again from the first network element, thereby guiding the second network element to attempt to obtain the target data from the first network element after the waiting time.
[0160] In another implementation, if the target user's authorization information indicates that the target user consents to data processing on the target data, the first network element retrieves the target data and sends a fifth response message to the second network element, where the fifth response message includes at least the target data, which may be data stored by the first network element itself, or data stored in a data warehouse, or data retrieved by the first network element immediately from a data warehouse (e.g., AMF).
[0161] Optionally, the fifth response message includes at least one of the following (101)-(103):
[0162] (101) Twenty-third information for indicating an authorized scope of use, i.e., indicating that the target user consents to the second network element using the target data within this authorized scope of use.
[0163] (102) Twenty-fourth information for indicating an allowed usage time, i.e., indicating that the target user consents to the second network element using the target data within this allowed usage time.
[0164] (103) Twenty-fifth information for indicating an allowed storage time, i.e., indicating that the target user agrees to the second network element storing the target data within this allowed storage time.
[0165] As can be understood, after the permitted usage range or permitted usage time or permitted storage time has been exceeded, the second network element is not allowed to continue using / storing the target data, for example, the second network element may delete the target data.
[0166] Based on the description of the method embodiments 500 and 600, the implementation process of the method embodiments 500 and 600 will be exemplarily described below in conjunction with Fig. 7 again, as follows: It is assumed that the target data is the target user's related data stored in the first network element.
[0167] At S710, the second network element sends a data request message to the first network element, where the data request message includes at least the authorization information of the target user.
[0168] At S720, the first network element sends an authorization request message to the third network element based on the data request message.
[0169] At S730, the third network element feeds back the authorization information of the target user to the first network element based on the authorization request message.
[0170] At S740, the first network element determines whether the second network element is trustworthy or untrustworthy based on the target user's authorization information fed back from the third network element and the target user's authorization information included in the data request message.
[0171] At S750, if the second network element is trusted but the target user's authorization information indicates that the target user does not agree to the second network element processing the target data, the first network element feeds back a fourth response message to the second network element.
[0172] Alternatively, if the second network element is trustworthy and the target user's authorization information indicates that the target user agrees to have the target data processed by the second network element, the first network element feeds back a fifth response message to the second network element.
[0173] Alternatively, if the second network element is not trustworthy, the first network element feeds back a third response message to the second network element, instructing the first network element to reject the data request message.
[0174] As can be understood, the implementation process of the authorization data scheduling method 700 according to this embodiment can refer to the relevant descriptions in the method embodiments 500 and / or 600, and achieves the same or corresponding technical effects, and will not be further described here to avoid repetition of description.
[0175] Furthermore, the method 700 for scheduling authorization data according to this embodiment includes, but is not limited to, steps S710-S750, for example, it may include more or fewer steps than steps S710-S750, and this is not limited thereto in this embodiment.
[0176] It should be noted that for the authorization data scheduling method 200-700 according to the embodiment of the present application, the execution body may be an authorization data scheduling device or a control module for executing the authorization data scheduling method 200-700 in the authorization data scheduling device. In the embodiment of the present application, the authorization data scheduling device according to the embodiment of the present application will be described by taking the authorization data scheduling device executing the authorization data scheduling method 200-700 as an example.
[0177] As shown in FIG. 8, it is a structural schematic diagram of an authorization data scheduling apparatus 800 according to one exemplary embodiment of the present application, the apparatus 800 including: a first transmission module 810 for receiving a data request message sent by a second network element, the data request message is used to request target data, the target data is data related to a target user stored in the first network element or a data warehouse; and a first execution module 820 for performing a first operation based on the authorization information of the target user, the first operation including refusing to provide the target data to the second network element or transmitting the target data to the second network element.
[0178] Optionally, the first transmission module 810 is further used to send an authorization request message to a third network element based on the data request message, and the authorization request message is used to obtain authorization information of the target user.
[0179] Optionally, the permission request message includes at least one of: at least one identifier information for instructing to obtain permission information of the target user corresponding to the identifier information; requested user permission type information including at least data sharing; a first time for indicating that the target data is data generated within the first time; the second network element for obtaining usage information of the target data; first information for indicating an allowed usage range; second information for indicating an allowed usage time; and third information for indicating an allowed storage time.
[0180] Optionally, the target user's permission information includes at least one of fourth information for indicating whether the target user agrees or disagrees to data sharing, fifth information for indicating the permitted scope of use, sixth information for indicating the permitted time of use, and seventh information for indicating the permitted time of storage.
[0181] Optionally, the first execution module 820 is used to send a first response message to the second network element if the target user's permission information indicates that the target user does not agree to data sharing of the target data, wherein the first response message is used to instruct at least the second network element that the first network element refuses or stops providing the target data.
[0182] Optionally, the first response message includes at least one of: eighth information for instructing the first network element to refuse or stop providing the targeted data to the second network element; ninth information for indicating a reason for the first network element to refuse or stop providing the targeted data; tenth information for instructing the second network element to cancel or delete a subscription request for the targeted data; and eleventh information for indicating a waiting time for the second network element to request the targeted data from the first network element again.
[0183] Optionally, the first execution module 820 is further used to send a second response message to the second network element if the target user's permission information indicates that the target user agrees to data sharing for the target data, where the second response message includes at least the target data.
[0184] Optionally, the second response message further includes at least one of twelfth information for indicating an authorized use range, thirteenth information for indicating an authorized use time, and fourteenth information for indicating an authorized storage time.
[0185] Optionally, the first transmission module 810 is further used to acquire the target data stored in the data warehouse if the target data is related data of the target user stored in the data warehouse.
[0186] As shown in FIG. 9, it is a structural schematic diagram of an authorization data scheduling apparatus 900 according to one exemplary embodiment of the present application, the apparatus including: a second transmitting module 910 for receiving a data request message sent by a second network element, the data request message is used to request target data, and the data request message includes at least the authorization information of a target user, and the target data is data related to the target user; and a second execution module 920 for performing a first operation based on the authorization information of the target user, the first operation including refusing to provide the target data to the second network element or transmitting the target data to the second network element.
[0187] Optionally, the target user's permission information includes at least one of: fifteenth information for indicating whether the target user consents or does not consent to data processing, the data processing including at least one of data acquisition, data use, data storage, and data sharing; sixteenth information for indicating the permitted range of use; seventeenth information for indicating the permitted time of use; and eighteenth information for indicating the permitted time of storage.
[0188] Optionally, the second execution module 920 is further used for determining whether the second network element is trustworthy or untrustworthy, and if the second network element is trustworthy, performing the step of performing a first operation based on the authorization information of the target user; if the second network element is untrustworthy, ignoring the authorization information of the target user included in the data request message and newly obtaining the authorization information of the target user from a third network element, or rejecting the data request message and sending a third response message to the second network element, wherein the third response message includes at least the reason why the first network element rejects the data request message.
[0189] Optionally, the second execution module 920 obtains authorization information of the target user from the third network element, and is used to determine whether the authorization information of the target user included in the data request message matches the authorization information of the target user obtained from the third network element; if there is a match, determine that the second network element is trustworthy; if there is no match, determine that the second network element is not trustworthy.
[0190] Optionally, the second execution module 920 is used to send a fourth response message to the second network element if the target user's permission information indicates that the target user does not agree to data processing on the target data, where the fourth response message is used to instruct at least the second network element that the first network element refuses or stops providing the target data.
[0191] Optionally, the fourth response message includes at least one of: nineteenth information for instructing the first network element to refuse or stop providing the targeted data to the second network element; twentieth information for indicating a reason for the first network element to refuse or stop providing the targeted data; twenty-first information for instructing the second network element to cancel or delete a subscription request for the targeted data; and twenty-second information for indicating a waiting time for the second network element to request the targeted data from the first network element again.
[0192] Optionally, the second execution module 920 is used to obtain the target data and send a fifth response message to the second network element if the target user's permission information indicates that the target user agrees to perform data processing on the target data, where the fifth response message includes at least the target data.
[0193] Optionally, the fifth response message further includes at least one of twenty-third information for indicating an authorized use range, twenty-fourth information for indicating an authorized use time, and twenty-fifth information for indicating an authorized storage time.
[0194] As shown in Figure 10, it is a structural schematic diagram of an authorization data scheduling device 1000 according to one exemplary embodiment of the present application, the device including a third transmission module 1010 for sending a data request message to a first network element, the data request message is used to request target data, and the data request message includes at least the authorization information of a target user, and the target data is data related to the target user.
[0195] Optionally, the target user's permission information includes at least one of: fifteenth information for indicating whether the target user consents or does not consent to data processing, the data processing including at least one of data acquisition, data use, data storage, and data sharing; sixteenth information for indicating the permitted range of use; seventeenth information for indicating the permitted time of use; and eighteenth information for indicating the permitted time of storage.
[0196] The authorization data scheduling device 800-1000 in the embodiment of the present application may be a device, such as a device with an operating system or a network-side device, and the embodiment of the present application is not specifically limited.
[0197] The authorization data scheduling devices 800-1000 according to the embodiments of the present application can implement each process implemented by the method embodiments of Figures 2 to 7 and achieve the same technical effects, and will not be further described here to avoid repetition.
[0198] An embodiment of the present application further provides a network side device, which may include a processor and a communication interface, the communication interface being coupled to the processor, and the processor being used to execute programs or instructions and realize the steps of the methods described in embodiments 200 to 700. This network side device embodiment corresponds to the above network side device method embodiment, and the implementation processes and realization manners of the above method embodiments can all be applied to this network side device embodiment, and the same technical effects can be achieved.
[0199] Specifically, an embodiment of the present application further provides a network side device. As shown in Fig. 11, the network device 1100 includes an antenna 1101, a radio frequency device 1102, and a baseband device 1103. The antenna 1101 and the radio frequency device 1102 are connected to each other. In the uplink direction, the radio frequency device 1102 receives information through the antenna 1101 and transmits the received information to the baseband device 1103 for processing. In the downlink direction, the baseband device 1103 processes the information to be transmitted and transmits it to the radio frequency device 1102, and the radio frequency device 1102 processes the received information and then transmits it through the antenna 1101.
[0200] The above frequency band processing device may be located in a baseband device 1103, and the method performed by the network side equipment in the above embodiments may be implemented in the baseband device 1103, which includes a processor 1104 and a memory 1105.
[0201] The baseband device 1103 may include, for example, at least one baseband board, on which multiple chips are installed, and as shown in FIG. 11, one of the chips may be, for example, a processor 1104, connected to a memory 1105, and call the program in the memory 1105 to perform the network equipment operations shown in the above method embodiments.
[0202] The baseband device 1103 may further include a network interface 1106, which is used to exchange information with the radio frequency device 1102, and this interface is, for example, a common public radio interface (abbreviated as CPRI).
[0203] Specifically, the network side device of the embodiment of the present invention further includes instructions or programs stored in memory 1105 and executable on processor 1104, and processor 1104 can call the instructions or programs in memory 1105 to execute the methods performed by each module shown in Figure 8 or Figure 9 or Figure 10, and achieve the same technical effects, which will not be described further here to avoid repetition.
[0204] The embodiments of the present application further provide a readable storage medium, on which a program or instruction is stored, which, when executed by a processor, can realize each process of the above-mentioned authorization data scheduling method embodiment and achieve the same technical effect. In order to avoid repetition, no further description will be given here.
[0205] Here, the processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM).
[0206] The embodiments of the present application further provide a chip, the chip including a processor and a communication interface, the communication interface is coupled to the processor, the processor is used to execute programs or instructions of the network side device to realize each process of the above-mentioned authorization data scheduling method embodiment, and can achieve the same technical effects. In order to avoid repetition, no further description will be given here.
[0207] It should be understood that the chips referred to in the embodiments of this application may be referred to as system level chips, system chips, chip systems, or system-on-chips.
[0208] An embodiment of the present application further provides a computer program product, which includes a processor, a memory, and a program or instruction stored in the memory and executable on the processor, and when the program or instruction is executed by the processor, it can realize each process of the above-mentioned authorization data scheduling method embodiment and achieve the same technical effect. In order to avoid repetition, no further description will be given here.
[0209] It should be noted that, in this specification, the terms "comprise," "include," "includes," or any other variant thereof are intended to cover the non-exclusive "comprise," whereby a process, method, article, or apparatus comprising a set of elements not only includes those elements, but also other elements not expressly listed or inherent in such process, method, article, or apparatus. Absent further limitations, an element defined by the phrase "comprises one of" does not preclude the presence of other identical elements in the process, method, article, or apparatus comprising that element. It should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may include performing functions in an essentially simultaneous manner or in the reverse order based on such functions. For example, the described method can be performed in a different order than described, and various steps can be added, omitted, or combined. Furthermore, features described with reference to some examples can be combined in other examples.
[0210] As will be apparent to those skilled in the art from the above description of the embodiments, the methods of the above embodiments can be realized in the form of software and a required general-purpose hardware platform. Of course, they can also be realized in hardware, but in many cases, the former is a more preferred embodiment. Based on this understanding, the technical solution of the present application, in substance or in part contributing to the prior art, may be embodied in the form of a computer software product. This computer software product is stored in a storage medium (e.g., ROM / RAM, magnetic disk, optical disk) and includes a number of instructions for causing a terminal (which may be a mobile phone, computer, server, air conditioner, network device, etc.) to execute the methods described in each embodiment of the present application.
[0211] Although the above describes the embodiments of the present application in conjunction with the drawings, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not limiting. Those skilled in the art can implement many forms under the guidance of the present application without departing from the spirit and scope of protection of the claims, and all forms fall within the scope of protection of the present application.
[0212] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to Chinese Patent Application No. 202111355388.3 filed on November 16, 2021, the entire contents of which are incorporated herein by reference.
Claims
1. 1. A method for scheduling authorization data, comprising: A first network element receives a data request message sent by a second network element, the data request message is used to request targeted data, and the data request message includes at least authorization information of a target user, and the targeted data is relevant data of the target user; The first network element performs a first operation based on the authorization information of the target user, the first operation including refusing to provide the target data to the second network element or transmitting the target data to the second network element; Before the step of the first network element performing a first operation based on the authorization information of the target user, the authorization data scheduling method includes: the first network element determining whether the second network element is trusted or untrusted; If the second network element is trusted, the first network element performs the step of performing a first operation based on the authorization information of the target user; If the second network element is not trustworthy, the first network element ignores the authorization information of the target user included in the data request message and obtains the authorization information of the target user again from a third network element, or the first network element rejects the data request message and sends a third response message to the second network element, wherein the third response message includes at least the reason why the first network element rejects the data request message; The step of the first network element determining whether the second network element is trustworthy or untrustworthy comprises: The first network element obtains authorization information of the target user from the third network element; and The first network element determines whether the target user's authorization information included in the data request message matches the target user's authorization information obtained from the third network element; and If there is a match, determining that the second network element is trustworthy; and if there is no match, determining that the second network element is untrustworthy. How to schedule authorization data.
2. The target user's permission information is Fifteenth information for indicating whether the target user consents or does not consent to data processing, the data processing including at least one of data acquisition, data use, data storage, and data sharing; A sixteenth piece of information indicating the scope of permitted use; A seventeenth piece of information indicating the permitted duration of use; and eighteenth information for indicating an allowed storage time.
3. The first network element performing a step of refusing to provide the targeted data to the second network element based on authorization information of the targeted user, If the authorization information of the target user indicates that the target user does not consent to data processing on the target data, the first network element sends a fourth response message to the second network element; 2. The method for scheduling authorized data according to claim 1, wherein the fourth response message is used to instruct at least the second network element that the first network element will refuse or stop providing the target data.
4. The fourth response message includes: nineteenth information for instructing the first network element to refuse or stop providing the targeted data to the second network element; twentieth information for indicating a reason for the first network element to refuse or stop providing the targeted data; and Twenty-first information for instructing the second network element to cancel or delete the subscription request for the targeted data; and twenty-second information for indicating a waiting time for the second network element to request the target data again from the first network element.
5. The step of the first network element transmitting the targeted data to the second network element based on the authorization information of the target user includes: If the authorization information of the target user indicates that the target user agrees to perform data processing on the target data, the first network element obtains the target data and sends a fifth response message to the second network element; 2. The method of claim 1, wherein the fifth response message includes at least the target data.
6. The fifth response message comprises:
23. Information indicating the scope of permitted use; and 24th information indicating the permitted duration of use; and a twenty-fifth piece of information for indicating an allowed storage time.
7. 1. A method for scheduling authorization data, comprising: A first network element receives a data request message sent by a second network element, the data request message being used to request target data, the target data being data related to a target user stored in the first network element or a data warehouse; The first network element performs a first operation based on the authorization information of the target user, the first operation including refusing to provide the target data to the second network element or transmitting the target data to the second network element; the data request message includes a third time used to indicate a time when the first network element will feed back the target data; How to schedule authorization data.
8. Before the step of the first network element performing a first operation based on the authorization information of the target user, the authorization data scheduling method includes:
8. The method for scheduling authorized data according to claim 7, further comprising: the first network element sending an authorization request message to a third network element based on the data request message, wherein the authorization request message is used to obtain authorization information of the target user.
9. The first network element performing a step of refusing to provide the targeted data to the second network element based on the authorization information of the targeted user, If the permission information of the target user indicates that the target user does not consent to data sharing for the targeted data, the first network element sends a first response message to the second network element; 8. The method for scheduling authorized data according to claim 7, wherein the first response message is used to instruct at least the second network element that the first network element will refuse or stop providing the target data.
10. The step of the first network element transmitting the targeted data to the second network element based on the authorization information of the target user includes: If the authorization information of the target user indicates that the target user agrees to perform data sharing on the targeted data, the first network element sends a second response message to the second network element; 8. The method of claim 7, wherein the second response message includes at least the target data.
11. 1. A method for scheduling authorization data, comprising: The second network element sends a data request message to the first network element, the data request message is used to request targeted data, and the data request message includes at least authorization information of a target user, and the targeted data is relevant data of the target user; the data request message includes a third time used to indicate a time when the first network element will feed back the target data; How to schedule authorization data.
12. 1. A grant data scheduling device for use in a first network element, the grant data scheduling device comprising: a second transmitting module for receiving a data request message sent by a second network element, the data request message being used to request target data, the data request message including at least authorization information of a target user, and the target data being relevant data of the target user; a second execution module for executing a first operation based on the authorization information of the target user, the first operation including refusing to provide the target data to the second network element or transmitting the target data to the second network element; The second execution module further determines whether the second network element is trusted or untrusted; If the second network element is trusted, performing the first operation based on the authorization information of the target user; If the second network element is not trustworthy, ignore the authorization information of the target user included in the data request message and obtain the authorization information of the target user again from a third network element, or reject the data request message and send a third response message to the second network element, where the third response message includes at least the reason why the first network element rejects the data request message; The second execution module is specifically used to obtain authorization information of the target user from the third network element, and determine whether the authorization information of the target user included in the data request message is consistent with the authorization information of the target user obtained from the third network element, and if consistent, determine that the second network element is trustworthy; if not, determine that the second network element is untrustworthy; A scheduling device for authorization data.
13. the second execution module is used to send a fourth response message to the second network element when the target user's authorization information indicates that the target user does not consent to data processing on the target data; 13. The device for scheduling permitted data according to claim 12, wherein the fourth response message is used to instruct at least the second network element that the first network element will refuse or stop providing the target data.
14. A network side device comprising a processor, a memory, and a program or instruction stored in the memory and executable on the processor, the network side device implementing the steps of the method for scheduling authorization data set forth in any one of claims 1 to 6, or the steps of the method for scheduling authorization data set forth in any one of claims 7 to 10, or the steps of the method for scheduling authorization data set forth in claim 11, when the program or instruction is executed by the processor.
15. A readable storage medium having a program or instructions stored thereon, which, when executed by a processor, implements the steps of the method for scheduling authorization data set forth in any one of claims 1 to 6, or the steps of the method for scheduling authorization data set forth in any one of claims 7 to 10, or the steps of the method for scheduling authorization data set forth in claim 11.
Citation Information
Patent Citations
COMMUNICATION METHODS, DEVICES, AND SYSTEMS
JP2023536969A
Communication method, device and system, and storage medium
WO2021062793A1