Enabling collection of data with privacy policies applied thereto
The described solution addresses the lack of privacy policy application in UE data collection by implementing an apparatus that applies privacy policies to UE data, ensuring compliance with user preferences and regional regulations.
Patent Information
- Application Number
- PCT/EP2024/081993
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-17
- Filing Date
- 2024-11-12
- Publication Date
- 2025-05-22
AI Technical Summary
Current communication systems lack a mechanism to apply privacy policies to user equipment (UE) data before collection, violating user privacy and failing to comply with regional regulations.
An apparatus and method for applying privacy policies to UE data, involving receiving privacy policies from a user equipment data collection entity, applying these policies to the UE data, and transmitting the data with applied policies to a data collection provisioning entity.
Ensures that UE data is processed in accordance with user privacy preferences and regional regulations, maintaining user consent and privacy throughout the data collection process.
Smart Images

Figure EP2024081993_22052025_PF_FP_ABST
Abstract
Description
[0001] ENABLING COLLECTION OF DATA WITH PRIVACY POLICIES APPLIED THERETO
[0002] TECHNICAL FIELD
[0003] Various example embodiments of this disclosure relate to a method, apparatus, system and computer program and in particular but not exclusively to provide a framework for UE data collection and reporting.
[0004] BACKGROUND
[0005] A communication network can be seen as a facility that enables communications between two or more communication devices, or provides communication devices access to a data network. A mobile or wireless communication network is one example of a communication network. A communication device may be provided with a service by an application server.
[0006] Such communication networks operate in according with standards such as those provided by 3GPP (Third Generation Partnership Project) or ETSI (European Telecommunications Standards Institute). Examples of standards are the so-called 5G (5th Generation) standards provided by 3GPP.
[0007] A feature of modern communication systems is known as using a minimizing drive testing (MDT) report or an EVEX framework for user equipment (UE) data collection.
[0008] SUMMARY
[0009] Some example embodiments of this disclosure will be described with respect to certain aspects. These aspects are not intended to indicate key or essential features of the embodiments of this disclosure, nor are they intended to be used to limit the scope of thereof. Other features, aspects, and elements will be readily apparent to a person skilled in the art in view of this disclosure.
[0010] According to an aspect there is provided an apparatus for a user equipment data collection client, the apparatus comprising: means for receiving one or more privacy policies from a user equipment data collection entity; means for receiving user equipment data of a user equipment; means for applying the one or more privacy policies to the user equipment data; and means for transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto. According to some examples, the user equipment data is received from an application running on the user equipment.
[0011] According to some examples, the apparatus further comprises means for sending the one or more privacy policies to the application running on the user equipment.
[0012] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0013] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0014] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0015] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0016] According to some examples, the apparatus comprises or is comprised in the user equipment.
[0017] According to some examples, the user equipment data collection client is comprised in the apparatus.
[0018] According to some examples, the user equipment data collection client is running on the apparatus.
[0019] According to some examples, the user equipment data collection client is a direct data collection client.
[0020] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0021] According to an aspect, there is provided an apparatus for a user equipment data collection entity, comprising: means for receiving information of one or more privacy preferences of a user of a user equipment; means for converting the information of the one or more privacy preferences into one or more privacy policies; and means for transmitting the one or more privacy policies to a user equipment data collection client. According to some examples, the information of the one or more privacy preferences is based on at least one of: information received from the user equipment; information received from an application running on the user equipment; stored information on regional regulations; or stored information of one or more personalised privacy policies.
[0022] According to some examples, the apparatus further comprises means for receiving information, from a data collection provisioning entity, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to user equipment data of the user equipment.
[0023] According to some examples, the apparatus further comprises means for receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment.
[0024] According to some examples, the apparatus further comprises means for transmitting the user equipment data to a data collection provisioning entity.
[0025] According to some examples, the apparatus further comprises means for receiving information, from a data collection provisioning entity, indicating whether the user equipment has successfully applied the one or more privacy policies to the user equipment data.
[0026] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0027] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0028] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0029] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0030] According to some examples, the apparatus comprises or is comprised in the user equipment data collection entity.
[0031] According to some examples, the user equipment data collection entity is an application service provider. According to some examples, the user equipment data collection entity is a network entity of a mobile network.
[0032] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0033] According to an aspect, there is provided an apparatus for a user equipment, comprising: means for receiving one or more privacy policies from a user equipment data collection client; means for applying the one or more privacy policies to user equipment data; and means for transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
[0034] According to some examples, the apparatus further comprises means for receiving information from a data collection provisioning entity, indicating whether the apparatus has successfully applied the one or more privacy policies to the user equipment data.
[0035] According to some examples, the apparatus further comprises means for sending user equipment data to the user equipment data collection client, for applying one or more privacy policies to the user equipment data.
[0036] According to some examples, the apparatus further comprises means for receiving information, from a data collection provisioning entity, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data received from the apparatus.
[0037] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0038] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0039] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0040] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field. According to some examples, the apparatus comprises or is comprised in the user equipment.
[0041] According to some examples, the means for receiving one or more privacy policies from the user equipment data collection client comprises means for receiving, by an application running on the user equipment, one or more privacy policies from the user equipment data collection client.
[0042] According to some examples, the user equipment data collection client is comprised in the user equipment.
[0043] According to some examples, the user equipment data collection client is running on the user equipment.
[0044] According to some examples, the user equipment data collection client is a direct data collection client.
[0045] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0046] According to some examples, an application is stored on the apparatus, the application configured to perform operations of the apparatus.
[0047] According to an aspect, there is provided an apparatus for a data collection provisioning entity, comprising: means for receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; means for transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; means for receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and means for comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0048] According to some examples, comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client comprises means for verifying at least one of: whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data; or whether the user equipment has successfully applied the one or more privacy policies to the user equipment data received by the user equipment data collection entity. According to some examples, the apparatus further comprises means for transmitting at least one of: information, to at least one of the user equipment data collection entity or the user equipment, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data; or information, to at least one of the user equipment data collection entity or the user equipment, indicating whether the user equipment has successfully applied the one or more privacy policies to the user equipment data received by the user equipment data collection entity.
[0049] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0050] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0051] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0052] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0053] According to some examples, the apparatus comprises or is comprised in the data collection provisioning entity.
[0054] According to some examples, the data collection provisioning entity is a data collection application function.
[0055] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0056] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive one or more privacy policies from a user equipment data collection entity; receive user equipment data of a user equipment; apply the one or more privacy policies to the user equipment data; and transmit, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
[0057] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive information of one or more privacy preferences of a user of a user equipment; convert the information of the one or more privacy preferences into one or more privacy policies; and transmit the one or more privacy policies to a user equipment data collection client.
[0058] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive one or more privacy policies from a user equipment data collection client; apply the one or more privacy policies to user equipment data; and transmit the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
[0059] According to an aspect there is provided an apparatus comprising at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmit a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receive user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and compare the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0060] According to an aspect there is provided a method, performed by an apparatus for a user equipment data collection client, the method comprising: receiving one or more privacy policies from a user equipment data collection entity; receiving user equipment data of a user equipment; applying the one or more privacy policies to the user equipment data; and transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
[0061] According to some examples, the user equipment data is received from an application running on the user equipment.
[0062] According to some examples, the method further comprises sending the one or more privacy policies to the application running on the user equipment.
[0063] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0064] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields. According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0065] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0066] According to some examples, the apparatus comprises or is comprised in the user equipment.
[0067] According to some examples, the user equipment data collection client is comprised in the apparatus.
[0068] According to some examples, the user equipment data collection client is running on the apparatus.
[0069] According to some examples, the user equipment data collection client is a direct data collection client.
[0070] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0071] According to an aspect there is provided a method, performed by an apparatus for a user equipment data collection entity, the method comprising: receiving information of one or more privacy preferences of a user of a user equipment; converting the information of the one or more privacy preferences into one or more privacy policies; and transmitting the one or more privacy policies to a user equipment data collection client.
[0072] According to some examples, the information of the one or more privacy preferences is based on at least one of: information received from the user equipment; information received from an application running on the user equipment; stored information on regional regulations; or stored information of one or more personalised privacy policies.
[0073] According to some examples, the method further comprises: receiving information, from a data collection provisioning entity, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to user equipment data of the user equipment.
[0074] According to some examples, the method further comprises: receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment.
[0075] According to some examples, the method further comprises: transmitting the user equipment data to a data collection provisioning entity. According to some examples, the method further comprises: receiving information, from a data collection provisioning entity, indicating whether the user equipment has successfully applied the one or more privacy policies to the user equipment data.
[0076] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0077] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0078] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0079] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0080] According to some examples, the apparatus comprises or is comprised in the user equipment data collection entity.
[0081] According to some examples, the user equipment data collection entity is an application service provider.
[0082] According to some examples, the user equipment data collection entity is a network entity of a mobile network.
[0083] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0084] According to an aspect there is provided a method, performed by an apparatus for a user equipment, the method comprising: receiving one or more privacy policies from a user equipment data collection client; applying the one or more privacy policies to user equipment data; and transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto. According to some examples, the method further comprises: receiving information from a data collection provisioning entity, indicating whether the apparatus has successfully applied the one or more privacy policies to the user equipment data.
[0085] According to some examples, the method further comprises: sending user equipment data to the user equipment data collection client, for applying one or more privacy policies to the user equipment data.
[0086] According to some examples, the method further comprises: receiving information, from a data collection provisioning entity, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data received from the apparatus.
[0087] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0088] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0089] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0090] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0091] According to some examples, the apparatus comprises or is comprised in the user equipment.
[0092] According to some examples, receiving one or more privacy policies from the user equipment data collection client comprises receiving, by an application running on the user equipment, one or more privacy policies from the user equipment data collection client.
[0093] According to some examples, the user equipment data collection client is comprised in the user equipment.
[0094] According to some examples, the user equipment data collection client is running on the user equipment. According to some examples, the user equipment data collection client is a direct data collection client.
[0095] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0096] According to some examples, an application is stored on the apparatus, the application configured to perform operations of the apparatus.
[0097] According to an aspect there is provided a method, performed by an apparatus for a data collection provisioning entity, the method comprising: receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0098] According to some examples, comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client comprises means for verifying at least one of: whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data; or whether the user equipment has successfully applied the one or more privacy policies to the user equipment data received by the user equipment data collection entity.
[0099] According to some examples, the method further comprises transmitting at least one of: information, to at least one of the user equipment data collection entity or the user equipment, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data; or information, to at least one of the user equipment data collection entity or the user equipment, indicating whether the user equipment has successfully applied the one or more privacy policies to the user equipment data received by the user equipment data collection entity.
[0100] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0101] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0102] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0103] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0104] According to some examples, the apparatus comprises or is comprised in the data collection provisioning entity.
[0105] According to some examples, the data collection provisioning entity is a data collection application function.
[0106] According to some examples, an application is stored on the apparatus, the application configured to perform operations of the apparatus.
[0107] According to an aspect there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: receiving one or more privacy policies from a user equipment data collection entity; receiving user equipment data of a user equipment; applying the one or more privacy policies to the user equipment data; and transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
[0108] According to some examples, the user equipment data is received from an application running on the user equipment.
[0109] According to some examples, the computer program comprises instructions for further causing the apparatus to send the one or more privacy policies to the application running on the user equipment.
[0110] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0111] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0112] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities. According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0113] According to some examples, the apparatus comprises or is comprised in the user equipment.
[0114] According to some examples, the user equipment data collection client is comprised in the apparatus.
[0115] According to some examples, the user equipment data collection client is running on the apparatus.
[0116] According to some examples, the user equipment data collection client is a direct data collection client.
[0117] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0118] According to an aspect there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: receiving information of one or more privacy preferences of a user of a user equipment; converting the information of the one or more privacy preferences into one or more privacy policies; and transmitting the one or more privacy policies to a user equipment data collection client.
[0119] According to some examples, the information of the one or more privacy preferences is based on at least one of: information received from the user equipment; information received from an application running on the user equipment; stored information on regional regulations; or stored information of one or more personalised privacy policies.
[0120] According to some examples, the computer program comprises instructions for further causing the apparatus to receive information, from a data collection provisioning entity, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to user equipment data of the user equipment.
[0121] According to some examples, the computer program comprises instructions for further causing the apparatus to receive user equipment data, with one or more privacy policies applied thereto, from the user equipment.
[0122] According to some examples, the computer program comprises instructions for further causing the apparatus to transmit the user equipment data to a data collection provisioning entity. According to some examples, the computer program comprises instructions for further causing the apparatus to receive information, from a data collection provisioning entity, indicating whether the user equipment has successfully applied the one or more privacy policies to the user equipment data.
[0123] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0124] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0125] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0126] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0127] According to some examples, the apparatus comprises or is comprised in the user equipment data collection entity.
[0128] According to some examples, the user equipment data collection entity is an application service provider.
[0129] According to some examples, the user equipment data collection entity is a network entity of a mobile network.
[0130] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0131] According to an aspect there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: receiving one or more privacy policies from a user equipment data collection client; applying the one or more privacy policies to user equipment data; and transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto. According to some examples, the computer program comprises instructions for further causing the apparatus to receive information from a data collection provisioning entity, indicating whether the apparatus has successfully applied the one or more privacy policies to the user equipment data.
[0132] According to some examples, the computer program comprises instructions for further causing the apparatus to send user equipment data to the user equipment data collection client, for applying one or more privacy policies to the user equipment data.
[0133] According to some examples, the computer program comprises instructions for further causing the apparatus to receive information, from a data collection provisioning entity, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data received from the apparatus.
[0134] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0135] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0136] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0137] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0138] According to some examples, the apparatus comprises or is comprised in the user equipment.
[0139] According to some examples, receiving one or more privacy policies from the user equipment data collection client comprises receiving, by an application running on the user equipment, one or more privacy policies from the user equipment data collection client.
[0140] According to some examples, the user equipment data collection client is comprised in the user equipment.
[0141] According to some examples, the user equipment data collection client is running on the user equipment. According to some examples, the user equipment data collection client is a direct data collection client.
[0142] According to some examples, the user equipment data is user equipment application layer data or non-application layer data.
[0143] According to some examples, an application is stored on the apparatus, the application configured to perform operations of the apparatus.
[0144] According to an aspect there is provided a computer program comprising instructions for causing an apparatus to perform at least the following: receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0145] According to some examples, comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client comprises means for verifying at least one of: whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data; or whether the user equipment has successfully applied the one or more privacy policies to the user equipment data received by the user equipment data collection entity.
[0146] According to some examples, the computer program comprises instructions for further causing the apparatus to transmit at least one of: information, to at least one of the user equipment data collection entity or the user equipment, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data; or information, to at least one of the user equipment data collection entity or the user equipment, indicating whether the user equipment has successfully applied the one or more privacy policies to the user equipment data received by the user equipment data collection entity.
[0147] According to some examples, the one or more privacy policies comprise one or more policy rules.
[0148] According to some examples, the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; Y1 information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
[0149] According to some examples, the information indicating at least one geographic area comprises one or more tracking area identities.
[0150] According to some examples, the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
[0151] According to some examples, the apparatus comprises or is comprised in the data collection provisioning entity.
[0152] According to some examples, the data collection provisioning entity is a data collection application function.
[0153] According to some examples, an application is stored on the apparatus, the application configured to perform operations of the apparatus.
[0154] According to an aspect there is provided a system comprising: means for receiving information of one or more privacy preferences of a user of a user equipment; means for converting the information of the one or more privacy preferences into one or more privacy policies; means for transmitting the one or more privacy policies to a user equipment data collection client; means for receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; means for transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; means for receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and means for comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0155] According to an aspect there is provided at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the system at least to: receive information of one or more privacy preferences of a user of a user equipment; convert the information of the one or more privacy preferences into one or more privacy policies; transmit the one or more privacy policies to a user equipment data collection client; receive user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmit a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receive user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and compare the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0156] According to an aspect there is provided a computer program comprising instructions stored thereon for performing at least the following: receiving one or more privacy policies from a user equipment data collection entity; receiving user equipment data of a user equipment; applying the one or more privacy policies to the user equipment data; and transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
[0157] According to an aspect there is provided a computer program comprising instructions stored thereon for performing at least the following: receiving information of one or more privacy preferences of a user of a user equipment; converting the information of the one or more privacy preferences into one or more privacy policies; and transmitting the one or more privacy policies to a user equipment data collection client.
[0158] According to an aspect there is provided a computer program comprising instructions stored thereon for performing at least the following: receiving one or more privacy policies from a user equipment data collection client; applying the one or more privacy policies to user equipment data; and transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
[0159] According to an aspect there is provided a computer program comprising instructions stored thereon for performing at least the following: receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0160] According to an aspect there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving one or more privacy policies from a user equipment data collection entity; receiving user equipment data of a user equipment; applying the one or more privacy policies to the user equipment data; and transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto. According to an aspect there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving information of one or more privacy preferences of a user of a user equipment; converting the information of the one or more privacy preferences into one or more privacy policies; and transmitting the one or more privacy policies to a user equipment data collection client.
[0161] According to an aspect there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving one or more privacy policies from a user equipment data collection client; applying the one or more privacy policies to user equipment data; and transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
[0162] According to an aspect there is provided a non-transitory computer readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0163] According to an aspect there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least the following: receiving one or more privacy policies from a user equipment data collection entity; receiving user equipment data of a user equipment; applying the one or more privacy policies to the user equipment data; and transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
[0164] According to an aspect there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least the following: receiving information of one or more privacy preferences of a user of a user equipment; converting the information of the one or more privacy preferences into one or more privacy policies; and transmitting the one or more privacy policies to a user equipment data collection client.
[0165] According to an aspect there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least the following: receiving one or more privacy policies from a user equipment data collection client; applying the one or more privacy policies to user equipment data; and transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
[0166] According to an aspect there is provided a non-transitory computer readable medium comprising program instructions stored thereon for performing at least the following: receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0167] According to an aspect there is provided a computer readable medium comprising program instructions that, when executed by an internet protocol multimedia subsystem apparatus, cause the apparatus to perform at least the following: receiving one or more privacy policies from a user equipment data collection entity; receiving user equipment data of a user equipment; applying the one or more privacy policies to the user equipment data; and transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
[0168] According to an aspect there is provided a computer readable medium comprising program instructions that, when executed by an internet protocol multimedia subsystem apparatus, cause the apparatus to perform at least the following: receiving information of one or more privacy preferences of a user of a user equipment; converting the information of the one or more privacy preferences into one or more privacy policies; and transmitting the one or more privacy policies to a user equipment data collection client.
[0169] According to an aspect there is provided a computer readable medium comprising program instructions that, when executed by an internet protocol multimedia subsystem apparatus, cause the apparatus to perform at least the following: receiving one or more privacy policies from a user equipment data collection client; applying the one or more privacy policies to user equipment data; and transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
[0170] According to an aspect there is provided a computer readable medium comprising program instructions that, when executed by an internet protocol multimedia subsystem apparatus, cause the apparatus to perform at least the following: receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0171] According to an aspect there is provided a computer readable medium comprising program instructions stored thereon for performing at least the following: receiving one or more privacy policies from a user equipment data collection entity; receiving user equipment data of a user equipment; applying the one or more privacy policies to the user equipment data; and transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
[0172] According to an aspect there is provided a computer readable medium comprising program instructions stored thereon for performing at least the following: receiving information of one or more privacy preferences of a user of a user equipment; converting the information of the one or more privacy preferences into one or more privacy policies; and transmitting the one or more privacy policies to a user equipment data collection client.
[0173] According to an aspect there is provided a computer readable medium comprising program instructions stored thereon for performing at least the following: receiving one or more privacy policies from a user equipment data collection client; applying the one or more privacy policies to user equipment data; and transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
[0174] According to an aspect there is provided a computer readable medium comprising program instructions stored thereon for performing at least the following: receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client. In the above, many different embodiments have been described. It should be appreciated that further embodiments may be provided by the combination of any two or more of the embodiments described above.
[0175] DESCRIPTION OF FIGURES
[0176] Some example embodiments will now be described, by way of non-limiting and illustrative example only, with reference to the accompanying FIGs in which:
[0177] FIG. 1 shows a representation of a 5thgeneration communication system;
[0178] FIG.2 shows a schematic representation of an EVEX Framework;
[0179] FIG. 3 shows signalling diagram according to an example embodiment;
[0180] FIG. 4 shows signalling diagram according to an example embodiment;
[0181] FIG. 5 shows a representation of a control apparatus according to some example embodiments;
[0182] FIG. 6 shows a representation of an apparatus for the communication system of FIG. 1 according to some example embodiments;
[0183] FIG. 7 shows a flow chart of a method according to an example embodiment;
[0184] FIG. 8 shows a flow chart of a method according to an example embodiment;
[0185] FIG. 9 shows a flow chart of a method according to an example embodiment;
[0186] FIG. 10 shows a flow chart of a method according to an example embodiment; and
[0187] FIG. 11 shows a representation of an apparatus according to some example embodiments.
[0188] DETAILED DESCRIPTION
[0189] In the following various example embodiments are explained with reference to communication devices capable of communication with a communication system. Before explaining in detail the embodiments of the methods and apparatuses of the present disclosure, a 5thgeneration communication system (5GS), an access network and a core network (5GC) thereof, and communication devices are briefly explained with reference to FIGs 1, 5 and 6.
[0190] FIG. 1 shows a schematic representation of a 5G communication system (5GS). The 5GS may comprise a user equipment (UE) 100, an access network such as a 5G radio access network (5G-RAN) 102 or next generation radio access network (NG-RAN), a 5G core network (5GC) 104, and one or more application functions. An application function may be deployed in the 5GS as a trusted application function or may be deployed or hosted on one or more application servers of the data network. Such application functions may be untrusted application functions. The 5GS connects the UE 100 to a data network of the access network and the 5GC (e.g., a UPF 118 of the 5GC 104).
[0191] The 5G-RAN 102 may comprise one or more radio access nodes, such as gNodeB (GNB). A gNB may include one or more gNodeB (GNB) distributed units connected to one or more gNodeB (GNB) centralized units.
[0192] The 5GC 104 may comprise the following network functions: Network Slice Selection Function (NSSF); Network Exposure Function (NEF) 108; Network Repository Function (NRF); Policy Control Function (PCF); Unified Data Management (UDM) 110; Application Function (AF) 106; Authentication Server Function (AUSF) 112; an Access and Mobility Management Function (AMF) 114; and Session Management Function (SMF) 116; and a user plane function (UPF) 118. FIG. 1 also shows the various interfaces (Nl, N2 etc.) that may be implemented between the various elements of the system.
[0193] 3GPP TS 26.531 defines an EVEX framework. FIG. 2 shows an EVEX framework that can be used for UE data collection and reporting. The functional entities for data collection and reporting in a EVEX framework may include the following: a UE 200; a UE Application 202; a Direct Data Collection Client (DDCC) 204; a Network Repository Function (NRF) 206; a Data Collection Application Function (DCAF) 208; a Network Data Analytics Function (NWDAF) 210; a Network Exposure Function (NEF) 212; an Application Server (AS) 214; an Application Service Provider (ASP) 216; a Provisioning Application Function 218; an Indirect Data Collection Client (IDCC) 220; an Event Consumer Application Function 222. It will be noted that the UE application 202 and the DDCC 204 are comprised in the UE 200.
[0194] Within this specification, references are made to an application running on a UE and / or a UE application 202. Such applications and / or the UE Application 202 may be stored or hosted on an apparatus. For example, the application and / or UE Application 202 may be stored or hosted on a UE 200 or a chip of a UE.
[0195] Further, within this specification reference is made to one or more entities within a UE 200 that communicate with each other. For example, reference is made to a UE Application 202 communicating with a DDCC 204. It will be appreciated that such entities may be hosted or stored on the same apparatus (such as a chip within the UE) or may be stored or hosted on different apparatus (such as different chips) within the same UE 200. In some examples, the application and / or UE application 202 is running on the UE. In some examples, the DDCC 204 is running on the UE. In some examples, the UE Application 202 transmits or sends relevant data to the DDCC 204, via the R7 interface. The R7 interface may be client API offered by the DDCC 204. In some examples, the UE Application 202 transmits or sends relevant data to the DDCC 204, via the R7 interface when the DDCC
[0196] 204 is not embedded in the UE Application 202 (i.e., when the DDCC 204 is a separate entity to the UE Application 202). This may be achieved as a combination of application design, application configuration via the R8 interface and / or application configuration via the R7 interface. In some examples, when the DDCC 204 is embedded in the UE Application 202, the R7 interface is not used. Depending on the provisioning information provided by the ASP 216, the DCAF 208 may provide a data collection and reporting configuration to the DDCC 204 via the R2 interface. The DDCC 204 may provide the data collection and reporting configuration to an IDCC 220 via interface R3 and / or to an AS 214 via the R4 interface. The DCAF 208 receives data reports from the AS 214 and / or IDCC 220 via those same interfaces. An ASP 216 may collect data from the UE Application 202 via the R8 interface and employ an IDCC subfunction to send data reports to the DCAF 208 via the R3 interface. In some examples, the data reports sent via the R3 interface are sent by invoking a Ndcaf_DataReporting service according to a data collection and reporting configuration previously obtained by the ASP 216 from the DCAF 208 via the R3 interface.
[0197] Therefore, in the current EVEX framework, UE data can be collected at the DCAF 208 via two interfaces: directly via the R2 interface between the DDCC 204 and the DCAF 208 (a user / control plane connection); and indirectly via the R8 interface, between the UE Application 202 and the ASP 216, and via the R3 interface, between the IDCC 220 and DCAF 208 (a tunnelled user plane connection that is out of band).
[0198] When UE data is transmitted via the R2 interface, the data travels from the DDCC 204 of the UE 200 to the DCAF 208 via a Radio Access Network (RAN) and subsequently via a UPF (if data transmission is a user plane transfer) or an AMF (if data transmission is a control plane transfer). As the UE data is sent to the DCAF 208 in an unprotected manner (i.e., without any privacy protection applied to the UE data), all the intermediaries at the R2 interface have access to UE private data.
[0199] When UE data is transmitted via the R8 and R3 interfaces to the DCAF 208, there is no current mechanism that ensures the UE Application 202 of the UE 200 preserves the privacy of UE data before providing the data to the ASP 216 and subsequently the DCAF 208. For example, if the UE 200 is to collect sensor data environment pictures(for example pictures of surroundings of the UE 200 and / or the location of the UE 200) following a request from the ASP 216, the UE Application 202 of the UE 200 may provide the collected sensor data environment pictures to the ASP 216 via the R8 interface, without preserving the privacy of the sensor data environment pictures. However, there are various government regulations which indicate that certain area pictures (for example, area pictures provided by a drone) should not be shared by a UE. Therefore, the current EVEX framework may not satisfy such government regulations as there is no current mechanism that provides privacy policies to the UE 200 such that the UE 200 can apply privacy policies to UE data before providing the UE data to the ASP 216 or DCAF 208.
[0200] Additionally, there is no current mechanism available that enables verification of whether the UE data sent via the R8 interface and / or R2 interface is privacy preserved or not. Nor is there a current mechanism that enables verification of user consent before sending the UE data to the ASP 216 and / or DCAF 208.
[0201] Embodiments herein propose a mechanism wherein privacy policies are provided to a UE. In some examples, privacy preferences of a user of the UE are converted into privacy policies by a user equipment data collection apparatus. In some examples the privacy policies may be transmitted to the DDCC of the UE via the DCAF. In some examples the privacy policies may be transmitted to the UE Application of the UE from the DDCC. In this way, UE data may be processed by the UE Application and / or the DDCC to apply the privacy policies before sending the UE data further. Embodiments herein additionally propose a mechanism wherein the DCAF verifies whether the privacy policies have been applied to the UE data. In some examples, the DCAF verifies whether the privacy policies have been applied to the UE data by comparing UE data received directly from the DDCC via the R2 interface and UE data received indirectly from the UE application via the R8 and R3 interfaces.
[0202] FIG.3 shows an example signalling procedure for enabling privacy preservation of UE data. In some examples, the signalling procedure occurs between a UE Application 300 of a UE, a user equipment data collection client 302 of a UE, a data collection provisioning entity 304 and a user equipment data collection apparatus 306. In some examples, the UE Application 300 is comprised in the UE. In some examples, the UE Application 300 is stored an d / or hosted and / or running on the UE. In some examples, the user equipment data collection client 302 is comprised in the UE. In some examples, the user equipment data collection client 302 is stored and / or hosted and / or running on the UE. In some examples, the user equipment data collection client 302 is a DDCC. In some examples, the data collection provisioning entity 304 is a DCAF. In some examples, the user equipment data collection apparatus 306 is an ASP. In some examples, the user equipment data collection apparatus 306 is an MNO. In some examples, the user equipment data collection apparatus 306 is a network entity of a mobile network. In some examples, an ASP is deployed in a mobile network. In some examples, the ASP is not deployed in a mobile network.
[0203] It will be appreciated that in this example, any data collection provisioning entity may be configured to perform the operations of the DCAF 304. It will further be appreciated that a UE may be configured to perform operations of the UE Application 300. It will further be appreciated that references to the term "user equipment data collection apparatus" may be interchanged by the term "user equipment data collection entity".
[0204] In the example of Figure 3, at S301, privacy preferences are transmitted to the user equipment data collection apparatus 306. In some examples, the privacy preferences are privacy preferences of a user of a UE. For example, the privacy preferences of the user are provided by the user to the user equipment data collection apparatus 306. In some examples, the privacy preferences are based on information received from the user equipment. In some examples, the privacy preferences are based on information received from the UE Application 300 and / or an application running on the user equipment. In some examples, the privacy preferences are based on stored information of one or more personalised privacy policies. For example, the personalised privacy policies may be generated for the user by a mobile operator. In some examples, the privacy policies are based on regional regulations. For example, based on stored information on regional regulations. In some examples a UE transmits privacy preferences of the user of the UE to the user equipment data collection apparatus 306. In some examples, the UE Application 300 of the UE transmits privacy preferences of the user of the UE to the user equipment data collection apparatus 306. In some examples, the privacy preferences may include user consent preferences. For example, the UE Application 300 may transmit user consent preferences to the user equipment data collection apparatus 306. In some examples, user consent preferences may comprise information indicating what UE data the user of the UE may or may not want to share with the network. In some examples, the UE Application 300 transmits user privacy preferences and / or user consent preferences to the user equipment data collection apparatus 306 via the R8 interface. In some examples, user privacy preferences and / or user consent preferences are transmitted to the user equipment data collection apparatus 306 out of band. In some examples, user privacy preferences are transmitted to the user equipment data collection apparatus 306 based on at least one of: location of the UE; context of the UE; environment of the UE; the UE Application 300 used by the UE. In some examples, the context of the UE is defined as the purpose in which the UE data is to be used (e.g., advertising and / or network optimizations). In some examples, the environment of the UE is at least one of the current surroundings in which the UE is located and the current surrounding elements of the UE (e.g., weather, temperature, density of neighbouring UEs, traffic situations etc.). In an example, if the UE is in a Home Public Land Mobile Network (HPLMN), then user privacy preferences may include information indicating that the location should be anonymous. In some examples, information of the user privacy preferences may include whether at least one of the town, country and area of the UE should be anonymous.
[0205] At S302, the user equipment data collection apparatus 306 converts the user privacy preferences into one or more privacy policies. In some examples, the one or more privacy policies include one or more user consent policies. In some examples, the user equipment data collection apparatus 306 converts the user consent preferences into one or more user consent policies. In some examples, the user equipment data collection apparatus 306 updates the one or more privacy policies and / or the one or more user consent policies, corresponding to specific UEs, in the storage of the user equipment data collection apparatus 306. In an example, the user privacy preferences may include information indicating that when the UE is in HPLMN, location of the UE should be anonymous at the level of town, country and area of the UE. In this case, the user equipment data collection apparatus 306 may convert the user privacy preferences into the following data structure / policy: UE ID = abc; Location Anonymization = true; Level of anonymization = high; Area = Tracking Area ID (Tai) list. In some examples, the TAI identifies cells and / or area radio deployment. In some examples, the one or more privacy policies comprise one or more policy rules. In some examples, the one or more policy rules comprise at least one of: identifiers of one or more UE in which the one or more policy rules are to be applied to: information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; and information indicating the level of privacy that is to be applied to the one or more data fields. For example, the one or more policy rules comprise identifiers of one or more UE, wherein the one or more policies rules are to be applied to the UE data of the one or more UEs identified. In some examples, the information indicating at least one geographic area may comprise one or more tracking area identities. In some examples, the one or more data fields may include location of the UE and / or an identification of the UE. For example, the policy rule may include information indicating that privacy protection is to be applied to the location of the UE. In some examples, the level of privacy that is to be applied to a data field comprises at least one of: removing the data field (e.g., removing location of the UE); replacing the data field with a less accurate value; and anonymizing the data field. In some examples, the user consent policies include information indicating what data the UE can generate and / or share with the user equipment data collection apparatus 306. In some examples, the user consent policies include information indicating what data the UE cannot generate and / or share with the user equipment data collection apparatus 306.
[0206] At S303, the user equipment data collection apparatus 306 transmits the one or more privacy policies to the UE data collection client 302. In some examples, the user equipment data collection apparatus 306 transmits the one or more user consent policies to the UE data collection client 302. In some examples, the user equipmentdata collection apparatus 306 transmits the one or more privacy policies and / or the one or more user consent policies to the UE data collection client 302 via the DCAF 304. In some examples, an MNO transmits privacy policies generated based on regional regulations to the UE data collection client 302. In some examples, an ASP transmits privacy policies generated based on user preferences received by the UE Application 300 of the UE. At S304, the UE data collection client 302 sends the one or more privacy policies to the UE Application 300 of the UE. In some examples the UE data collection client 302 sends the one or more user consent policies to the UE Application of the UE 300. In some examples, the UE data collection client 302 sends the one or more privacy policies and / or the one or more user consent policies to the UE Application 300 when the UE data is to be transmitted via the R8 interface.
[0207] At S305, a UE data collection request message is transmitted from the user equipment data collection apparatus 306 to the UE (for example to the UE Application 300). In some examples, the user equipment data collection apparatus 306 transmits a UE data collection request message to the DCAF 304. In some examples, the DCAF 304 transmits the UE data collection request message to the UE data collection client 302. In some examples, the UE data collection client 302 sends a UE data collection request message to the UE Application 300. In some examples, the UE data collection request message is a message requesting UE data.
[0208] At S306, the UE data collection client 302 receives UE data of the UE. For example, the UE Application 300 sends UE data to the UE data collection client 302. In some examples, the UE data is UE application data. In some examples, the UE data may be application layer data or non-application layer data. In some examples, the UE Application 300 transmits privacy sensitive data to the UE data collection client 302. In some examples, the UE Application 300 transmits UE data to the UE data collection client 302 via the R7 interface.
[0209] At S307, the UE data collection client 302 applies the one or more privacy policies received in S303 to the UE data. In some examples, the UE data collection client 302 applies one or more user consent policies to the UE data. In some examples, the UE data collection client 302 applies the one or more privacy policies and / or the one or more user consent policies before transmitting the UE data any further.
[0210] At S308, the UE data collection client 302 transmits UE data to the DCAF 304. In some examples, the UE data collection client 302 transmits UE data with the one or more privacy policies applied thereto. In some examples, the UE data collection client 302 transmits UE data with the one or more user consent policies applied thereto. In some examples, the UE data collection client 302 transmits UE data to the DCAF 304 via the R2 interface.
[0211] At S309, the UE Application 300 transmits UE data to the user equipment data collection apparatus 306. In some examples, the UE Application 300 transmits UE data to the user equipment data collection apparatus 306 when the UE data has been requested from the UE Application 300 via the R8 interface. In some examples, the UE Application 300 applies the one or more privacy policies, received from the UE data collection client 302 in S304, to the UE data before sending the UE data to the user equipment data collection apparatus 306. In some examples, the UE Application 300 applies the one or more user consent policies, received from the UE data collection client 302 in S304, to the UE data before sending the UE data to the user equipment data collection apparatus 306.
[0212] FIG. 4 shows an example signalling procedure for enabling verification of privacy preservation of UE data. For example, the DCAF verifies whether privacy policies and / or user consent policies were applied to the UE data transmitted by the UE (for example, the UE Application 400) to the user equipment data collection apparatus 406, via the R8 interface.
[0213] In some examples, the signalling procedure occurs between a UE Application 400 of a UE, a user equipment data collection client 402 of a UE, a data collection provisioning entity 404 and a user equipment data collection apparatus 406 (or user equipment data collection entity). In some examples, the UE Application 400 is comprised in the UE. In some examples, the UE Application 400 is stored and / or hosted and / or running on the UE. In some examples, the user equipment data collection client 402 is comprised in the UE. In some examples, the user equipment data collection client 402 is stored and / or hosted and / or running on the UE. In some examples, the user equipment data collection client 402 is a DDCC. In some examples, the data collection provisioning entity 404 is a DCAF. In some examples, the user equipment data collection apparatus 406 is an ASP. In some examples, the user equipment data collection apparatus 406 is an MNO. In some examples, the user equipment data collection apparatus 306 is a network entity of a mobile network. In some examples, an ASP is deployed in a mobile network. In some examples, the ASP is not deployed in a mobile network.
[0214] It will be appreciated that in this example, any data collection provisioning entity may be configured to perform the operations of the DCAF. It will further be appreciated that a UE may be configured to perform operations of the UE Application 400. It will further be appreciated that references to the term "user equipment data collection apparatus" may be interchanged by the term "user equipment data collection entity".
[0215] In some examples, verification of privacy preservation of UE data occurs after the signalling procedure of FIG. 3.
[0216] In this example, at S401, the UE transmits UE data to the user equipment data collection apparatus 406. For example, the UE Application 400 transmits UE data to the user equipment data collection apparatus 406. In some examples, the UE data is UE application data. In some examples, the UE data may be application layer data or non-application layer data. In some examples, the UE Application 400 transmits UE data to the user equipment data collection apparatus 406 when the UE data has been requested from the UE Application 400 via the R8 interface. In some examples, the UE Application 400 applies one or more privacy policies, received from the UE data collection client 402 in S404, to the UE data before sending the UE data to the user equipment data collection apparatus 406. In some examples, the UE Application 400 applies one or more user consent policies, received from the UE data collection client 402 in S404, to the UE data before sending the UE data to the user equipment data collection apparatus 406.
[0217] At S402, the user equipment data collection apparatus 406 transmits UE data to the DCAF 404. In some examples, the user equipment data collection apparatus 406 transmits UE data received from the UE Application 400. In some examples, the user equipment data collection apparatus 406 transmits UE data, received from the UE Application 400, to the DCAF 404 via the R3 interface. In some examples, the user equipment data collection apparatus 406 transmits the received UE data to the DCAF 404 from an Indirect Data Collection Client apparatus of the user equipment data collection apparatus 406, via the R3 interface.
[0218] At S403, the DCAF 404 transmits a message to the UE data collection client 402 requesting the same UE data received from the user equipment data collection apparatus 406. In some examples, the DCAF 404 analyses the UE data received from the user equipment data collection apparatus 406 before transmitting the message to the UE data collection client 402. In some examples, analysing the UE data comprises selecting a sample of the UE data. In some examples, to ensure that the DCAF 404 requests exactly the same UE data from the UE data collection client 402, at least one contextual feature may be used. For example, the DCAF 404 may use at least one of: a timestamp of the UE data generation and collection; a type of UE data collected; a topic and / or event for which the UE data was collected.
[0219] At S404, the UE data collection client 402 sends a message to the UE Application 400, requesting UE data from the UE Application 400.
[0220] At S405, the UE Application 400 sends UE data to the UE data collection client 402. In some examples, the UE Application 400 sends privacy sensitive data to the UE data collection client 402. In some examples, the UE Application 400 sends UE data to the UE data collection client 402 via the R7 interface.
[0221] At S406, the UE data collection client 402 applies one or more privacy policies received to the UE data. In some examples, the UE data collection client 402 applies one or more user consent policies to the UE data. In some examples, the UE data collection client 402 applies the one or more privacy policies and / or the one or more user consent policies before transmitting the UE data any further.
[0222] At S407, the UE data collection client 402 transmits UE data to the DCAF 404. In some examples, the UE data collection client 402 transmits UE data with the one or more privacy policies applied thereto. In some examples, the UE data collection client 402 transmits UE data with the one or more user consent policies applied thereto. In some examples, the UE data collection client 402 transmits UE data to the DCAF 404 via the R2 interface.
[0223] At S408, the DCAF 404 analyses the UE data received from the user equipment data collection apparatus 406 (from S402) and the UE data received from the UE data collection client 402 (from S407). In some examples, the DCAF 404 compares the UE data received from the user equipment data collection apparatus 406 and the UE data received from the UE data collection client 402. In some examples, the DCAF 404 compares the UE data to verify whether the UE Application 400 successfully applied the one or more privacy policies and / or the one or more user consent policies to the UE data, before transmitting the UE data to the user equipment data collection apparatus 406 via the R8 interface. In some examples, the DCAF 404 compares the UE data to verify whether the UE data collection client 402 successfully applied the one or more privacy policies and / or the one or more user consent policies to the UE data, before transmitting the UE data to the DCAF 404 via the R2 interface. In some examples, the DCAF 404 can detect which entity has not performed the privacy preservation as configured.
[0224] At S409, the DCAF 404 sends a message to the UE, indicating whether privacy preservation was successful. In some examples, the DCAF 404 sends a message to the UE Application 400 indicating whether the UE Application 400 successfully applied the one or more privacy policies and / or the one or more user consent policies to the UE data, before transmitting the UE data to the user equipment data collection apparatus 406 via the R8 interface. In some examples, the DCAF 404 sends the message to the UE Application 400 via the UE data collection client 402. In some examples, the DCAF 404 sends a message to the UE Application 400 indicating whether the UE data collection client 402 successfully applied the one or more privacy policies and / or the one or more user consent policies to the UE data, before transmitting the UE data to the DCAF 404 via the R2 interface.
[0225] At S410, the DCAF 404 sends a message to the user equipment data collection apparatus 406, indicating whether privacy preservation was successful. In some examples, the DCAF 404 sends a message to the user equipment data collection apparatus 406 indicating whether the UE Application 400 successfully applied the one or more privacy policies and / or the one or more user consent policies to the UE data, before transmitting the UE data to the user equipment data collection apparatus 406 via the R8 interface. In some examples, the DCAF 404 sends a message to the user equipment data collection apparatus 406 indicating whether the UE data collection client 402 successfully applied the one or more privacy policies and / or the one or more user consent policies to the UE data, before transmitting the UE data to the DCAF 404 via the R2 interface.
[0226] An advantage of the examples disclosed herein include ensuring privacy and user consent of UE data is preserved. For example, examples herein ensure that the privacy of UE data, based on user preferences, is preserved before the UE data is transmitted to a network and / or user equipment data collection apparatus (via either the R2 or R8 interface). Examples disclosed herein ensure that user consent for collection of UE data is preserved before the UE data is transmitted to a network and / or user equipment data collection apparatus (via either the R2 or R8 interface). Examples disclosed herein ensure that regional regulations for ensuring privacy of UE data are preserved before the UE data is transmitted to a network and / or user equipment data collection apparatus (via either the R2 or R8 interface). A further advantage of the examples disclosed herein includes enabling the verification that privacy and / or user consent of UE data has been preserved.
[0227] FIG. 5 illustrates an example of a control apparatus 500 for controlling a function of the access network (e.g., a 5G-RAN or the NG-RAN illustrated in FIG. 1) illustrated on FIG. 1. The control apparatus 500 may comprise at least one random access memory (RAM) 511a, at least on read only memory (ROM) 511b, at least one processor 512, 513 and a network interface 514. The at least one processor 512, 513 may be coupled to the RAM 511a and the ROM 511b. The at least one processor 512, 513 may be configured to execute an appropriate software code 515. Execution of the software code 515 may for example cause the apparatus to perform operations for controlling a function of the access network. The software code 515 may be stored in the ROM 511b. The control apparatus 500 may be interconnected with another control apparatus 500 for controlling another function of the 5G-RAN or the NG-RAN. In some embodiments, each function of the 5G-RAN or the NG-RAN is deployed or hosted on a control apparatus 500. In alternative embodiments, two or more functions of the 5G-RAN or the NG-RAN may share a control apparatus.
[0228] FIG. 6 illustrates an example of a communication device 600, such as the UE illustrated on FIG. 1. The communication device 600 may be provided by any device capable of sending and receiving radio signals. Non-limiting examples of a communication device 600 comprise a user equipment, a mobile station (MS) or mobile device such as a mobile phone or what is known as a 'smart phone', a computer provided with a wireless interface card or other wireless interface facility (e.g., USB dongle), a personal data assistant (PDA) or a tablet provided with wireless communication capabilities, a machine-type communications (MTC) device, an Internet of things (loT) type communication device or any combinations of these or the like. The communication device 600 may comprise a transceiver for transmitting and / or receiving, for example, wireless signals carrying communications, for example radio signals. The communications may be one or more of voice, electronic mail (email), text messages, multimedia data, machine data and so on.
[0229] The communication device 600 may receive wireless signals (e.g., radio signals) over an air or radio interface 607 via appropriate apparatus for receiving and may transmit wireless signals via appropriate apparatus for transmitting radio signals. In FIG. 6 transceiver is designated schematically by block 606. The transceiver 606 may comprise, for example, a radio part and associated antenna arrangement. The antenna arrangement may be arranged internally or externally to the mobile device and may comprise one or more antenna elements. The antenna arrangement may be a multi-input multi output (MIMO) antenna.
[0230] The communication device 600 may be provided with at least one processor 601, at least one memory ROM 602a, at least one RAM 602b and other possible components 603 for use in software and hardware aided execution of tasks it is designed to perform, including control of access to and communications with access networks (e.g., the 5G-RAN or NG-RAN illustrated in FIG. 1) and other communication devices. The at least one processor 601 is coupled to the RAM 602b and the ROM 602a. The at least one processor 601 may be configured to execute an appropriate software code 608. The software code 608 may for example allow to perform one or more operations of the communication device 600. The software code 608 may be stored in the ROM 602a.
[0231] The processor, the ROM, and the RAM, the transceiver and other circuitry of the communication device (e.g., a modem) can be provided on a circuit board, in chipsets, or in a system on chip. This circuit board, chipsets or system on chip is denoted by reference 604. The communication device 600 may optionally have a user interface such as key pad 605, touch sensitive screen or pad, combinations thereof or the like. Optionally one or more of a display, a speaker and a microphone may be provided depending on the type of the communication device.
[0232] Figure 7 is a flow chart of a method according to an example. The flow chart of Figure 7 is viewed from the perspective of an apparatus. For example, the apparatus may be for a user equipment data collection client. In some examples, the apparatus comprises or is comprised in a UE. In some examples, the user equipment data collection client is comprised in the apparatus. In some examples, the user equipment data collection client is running on the apparatus. In some examples, the user equipment data collection client is a direct data collection client.
[0233] As shown at S701, the method comprises receiving one or more privacy policies from a user equipment data collection entity.
[0234] At S702, the method comprises receiving user equipment data of a user equipment.
[0235] At S703, the method comprises applying the one or more privacy policies to the user equipment data.
[0236] At S704, the method comprises transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
[0237] Figure 8 is a flow chart of a method according to an example. The flow chart of Figure 8 is viewed from the perspective of an apparatus. For example, the apparatus is for a UE data collection entity. In some examples, the apparatus comprises or is comprised in the user equipment data collection entity. In some examples, the user equipment data collection entity is an application service provider. In some examples, the user equipment data collection entity is a network entity of a mobile network.
[0238] As shown at S801, the method comprises receiving information of one or more privacy preferences of a user of a user equipment.
[0239] At S802, the method comprises converting the information of the one or more privacy preferences into one or more privacy policies.
[0240] At S803, the method comprises transmitting the one or more privacy policies to a user equipment data collection client.
[0241] Figure 9 is a flow chart of a method according to an example. The flow chart of Figure 9 is viewed from the perspective of an apparatus. For example, the apparatus is for a UE. In some examples, the apparatus comprises or is comprised in a UE. In some examples, an application is stored on the apparatus. In some examples, the application is configured to perform operations of the apparatus.
[0242] As shown at S901, the method comprises receiving one or more privacy policies from a user equipment data collection client.
[0243] At S902, the method comprises applying the one or more privacy policies to user equipment data.
[0244] At S903, the method comprises transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
[0245] Figure 10 is a flow chart of a method according to an example. The flow chart of Figure 10 is viewed from the perspective of an apparatus. For example, the apparatus is for a data collection provisioning entity. In some examples, the apparatus comprises or is comprised in the data collection provisioning entity. In some examples, the data collection provisioning entity is a data collection application function.
[0246] As shown at S1001, the method comprises receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment.
[0247] At S1002, the method comprises transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity. At S1003, the method comprises receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client.
[0248] At S1004, the method comprises comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
[0249] FIG. 11 shows a schematic representation of non-volatile memory media 1100a (e.g. computer disc (CD) or digital versatile disc (DVD)) and 1100b (e.g. universal serial bus (USB) memory stick) storing instructions and / or parameters 1102 which when executed by a processor allow the processor to perform one or more of the steps of the method of FIGs. 7, 8, 9 and 10.
[0250] It is understood that references in the above to various network functions (e.g., to an AMF, an SMF, TNF etc.) may comprise apparatus that perform at least some of the functionality associated with those network functions. Further, an apparatus comprising a network function may comprise a virtual network function instance of that network function.
[0251] It should be understood that the apparatuses may comprise or be coupled to other units or modules etc., such as radio parts or radio heads, used in or for transmission and / or reception. Although the apparatuses have been described as one entity, different modules and memory may be implemented in one or more physical or logical entities.
[0252] It is noted that whilst some embodiments have been described in relation to 5G networks, similar principles can be applied in relation to other networks and communication systems. Therefore, although certain embodiments were described above by way of example with reference to certain example architectures for wireless networks, technologies and standards, embodiments may be applied to any other suitable forms of communication systems than those illustrated and described herein.
[0253] It is also noted herein that while the above describes example embodiments, there are several variations and modifications which may be made to the disclosed solution without departing from the scope of the present invention.
[0254] As used herein, "at least one of the following: " and "at least one of " and similar wording, where the list of two or more elements are joined by "and" or "or", mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0255] In general, the various embodiments may be implemented in hardware or special purpose circuitry, software, logic or any combination thereof. Some aspects of the disclosure may be implemented in hardware, while other aspects may be implemented in firmware or software which may be executed by a controller, microprocessor or other computing device, although the disclosure is not limited thereto. While various aspects of the disclosure may be illustrated and described as block diagrams, flow charts, or using some other pictorial representation, it is well understood that these blocks, apparatus, systems, techniques or methods described herein may be implemented in, as non-limiting examples, hardware, software, firmware, special purpose circuits or logic, general purpose hardware or controller or other computing devices, or some combination thereof.
[0256] As used herein, the term "circuitry" may refer to one or more or all of the following:
[0257] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and
[0258] (b) combinations of hardware circuits and software, such as (as applicable):
[0259] (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and
[0260] (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software, and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
[0261] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation."
[0262] This definition of circuitry applies to all uses of this term herein, including in any claims. As a further example, as used herein, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0263] The embodiments of this disclosure may be implemented by computer software executable by a data processor of the mobile device, such as in the processor entity, or by hardware, or by a combination of software and hardware. Computer software or program, also called program product, including software routines, applets and / or macros, may be stored in any apparatus-readable data storage medium and they comprise program instructions to perform particular tasks. A computer program product may comprise one or more computer-executable components which, when the program is run, are configured to carry out embodiments. The one or more computer-executable components may be at least one software code or portions of it.
[0264] Further in this regard it should be noted that any blocks of the logic flow as in the FIGs may represent program steps, or interconnected logic circuits, blocks and functions, or a combination of program steps and logic circuits, blocks and functions. The software may be stored on such physical media as memory chips, or memory blocks implemented within the processor, magnetic media such as hard disk or floppy disks, and optical media such as for example DVD and the data variants thereof, CD. The physical media is a non-transitory media.
[0265] The term "non-transitory," as used herein, is a limitation of the medium itself (i.e., tangible, not a signal ) as opposed to a limitation on data storage persistency (e.g., RAM vs. ROM).
[0266] The memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The data processors may be of any type suitable to the local technical environment, and may comprise one or more of general purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), application specific integrated circuits (ASIC), FPGA, gate level circuits and processors based on multi core processor architecture, as non-limiting examples.
[0267] Various example embodiments of the disclosure may be practiced in various components such as integrated circuit modules. The design of integrated circuits is by and large a highly automated process. Complex and powerful software tools are available for converting a logic level design into a semiconductor circuit design ready to be etched and formed on a semiconductor substrate.
[0268] The scope of protection sought for various example embodiments of the disclosure is set out by the independent claims. The example embodiments and features thereof, if any, described in this disclosure that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various example embodiments of the disclosure.
[0269] The foregoing description has provided, by way of non-limiting and illustrative examples, a full and informative description of the various example embodiments of this disclosure. However, various modifications and adaptations may become apparent to those skilled in the relevant arts in view of the foregoing description, when read in conjunction with the accompanying drawings and the claims. However, all such and similar modifications of the teachings will still fall within the various example embodiments of the disclosure as set forth in the claims. By way of non-limiting and illustrative example, there is a further example embodiment comprising a combination of one or more example embodiments with any of the other example embodiments previously discussed.
Claims
CLAIMS1. An apparatus for a user equipment data collection client, the apparatus comprising: means for receiving one or more privacy policies from a user equipment data collection entity; means for receiving user equipment data of a user equipment; means for applying the one or more privacy policies to the user equipment data; and means for transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
2. The apparatus of claim 1, wherein the user equipment data is received from an application running on the user equipment.
3. The apparatus of claim 2, wherein the apparatus further comprises means for sending the one or more privacy policies to the application running on the user equipment.
4. The apparatus of any of claims 1 to 3, wherein the one or more privacy policies comprise one or more policy rules.
5. The apparatus of claim 4, wherein the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
6. The apparatus of claim 5, wherein the information indicating at least one geographic area comprises one or more tracking area identities.
7. The apparatus of claim 5 or claim 6, wherein the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
8. The apparatus of any of claims 1 to 7 , wherein the apparatus comprises or is comprised in the user equipment.
9. The apparatus of any of claims 1 to 8, wherein the user equipment data collection client is comprised in the apparatus.
10. The apparatus of any of claims 1 to 9, wherein the user equipment data collection client is running on the apparatus.
11. The apparatus of any of claims 1 to 10, wherein the user equipment data collection client is a direct data collection client.
12. An apparatus for a user equipment data collection entity, comprising: means for receiving information of one or more privacy preferences of a user of a user equipment; means for converting the information of the one or more privacy preferences into one or more privacy policies; andmeans for transmitting the one or more privacy policies to a user equipment data collection client.
13. The apparatus of claim 12, wherein the information of the one or more privacy preferences is based on at least one of: information received from the user equipment; information received from an application running on the user equipment; stored information on regional regulations; or stored information of one or more personalised privacy policies.
14. The apparatus of claim 12 or claim 13, wherein the apparatus further comprises means for receiving information, from a data collection provisioning entity, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to user equipment data of the user equipment.
15. The apparatus of any of claims 12 to 14, wherein the apparatus further comprises means for receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment.
16. The apparatus of claim 15, wherein the apparatus further comprises means for transmitting the user equipment data to a data collection provisioning entity.
17. The apparatus of claim 15 or claim 16, wherein the apparatus further comprises means for receiving information, from a data collection provisioning entity, indicating whether the user equipment has successfully applied the one or more privacy policies to the user equipment data.
18. The apparatus of any of claims 12 to 17, wherein the one or more privacy policies comprise one or more policy rules.
19. The apparatus of claim 18, wherein the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
20. The apparatus of claim 19, wherein the information indicating at least one geographic area comprises one or more tracking area identities.
21. The apparatus of claim 19 or claim 20, wherein the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
22. The apparatus of any of claims 12 to 21, wherein the apparatus comprises or is comprised in the user equipment data collection entity.
23. The apparatus of any of claims 12 to 22, wherein the user equipment data collection entity is an application service provider.
24. The apparatus of any of claims 12 to 23, wherein the user equipment data collection entity is a network entity of a mobile network.
25. An apparatus for a user equipment, comprising: means for receiving one or more privacy policies from a user equipment data collection client; means for applying the one or more privacy policies to user equipment data; and means for transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
26. The apparatus of claim 25, wherein the apparatus further comprises means for receiving information from a data collection provisioning entity, indicating whether the apparatus has successfully applied the one or more privacy policies to the user equipment data.
27. The apparatus of claim 25 or claim 26, further comprising means for sending user equipment data to the user equipment data collection client, for applying one or more privacy policies to the user equipment data.
28. The apparatus of claim 27, further comprising means for receiving information, from a data collection provisioning entity, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data received from the apparatus.
29. The apparatus of any of claims 25 to 28, wherein the one or more privacy policies comprise one or more policy rules.
30. The apparatus of claim 29, wherein the one or more policy rules comprise at least one of:identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
31. The apparatus of claim 30, wherein the information indicating at least one geographic area comprises one or more tracking area identities.
32. The apparatus of claim 30 or claim 31, wherein the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.th33. The apparatus of any of claims 25 to 32, wherein the apparatus comprises or is comprised in the user equipment.
34. The apparatus of any of claims 25 to 33, wherein the means for receiving one or more privacy policies from the user equipment data collection client comprises means for receiving, by an application running on the user equipment, one or more privacy policies from the user equipment data collection client.
35. The apparatus of any one of claims 25 to 34, wherein the user equipment data collection client is comprised in the user equipment.
36. The apparatus of any one of claims 25 to 35, wherein the user equipment data collection client is running on the user equipment.
37. The apparatus of any one of claims 25 to 36, wherein the user equipment data collection client is a direct data collection client.
38. An apparatus for a data collection provisioning entity, comprising: means for receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; means for transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; means for receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and means for comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
39. The apparatus of claim 38, wherein comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client comprises means for verifying at least one of: whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data; or whether the user equipment has successfully applied the one or more privacy policies to the user equipment data received by the user equipment data collection entity.
40. The apparatus of claim 38 or claim 39, wherein the apparatus further comprises means for transmitting at least one of:information, to at least one of the user equipment data collection entity or the user equipment, indicating whether the user equipment data collection client has successfully applied the one or more privacy policies to the user equipment data; or information, to at least one of the user equipment data collection entity or the user equipment, indicating whether the user equipment has successfully applied the one or more privacy policies to the user equipment data received by the user equipment data collection entity.
41. The apparatus of any of claims 38 to 40, wherein the one or more privacy policies comprise one or more policy rules.
42. The apparatus of claim 41, wherein the one or more policy rules comprise at least one of: identifiers of one or more user equipment in which the one or more policy rules are to be applied to; information indicating at least one geographic area in which the one or more policy rules are to be applied; information indicating whether the one or more privacy policies are to be applied to one or more data fields; or information indicating a level of privacy that is to be applied to the one or more data fields.
43. The apparatus of claim 42, wherein the information indicating at least one geographic area comprises one or more tracking area identities.
44. The apparatus of claim 42 or claim 43, wherein the information indicating the level of privacy that is to be applied to the one or more data fields comprises at least one of: removing the data field; replacing the data field with a less accurate value; or anonymizing the data field.
45. The apparatus of any of claims 38 to 44, wherein the apparatus comprises or is comprised in the data collection provisioning entity.
46. The apparatus of any of claims 38 to 45, wherein the data collection provisioning entity is a data collection application function.
47. A method, performed by an apparatus for a user equipment data collection client, the method comprising: receiving one or more privacy policies from a user equipment data collection entity; receiving user equipment data of a user equipment; applying the one or more privacy policies to the user equipment data; and transmitting, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
48. A method, performed by an apparatus for a user equipment data collection entity, the method comprising: receiving information of one or more privacy preferences of a user of a user equipment; converting the information of the one or more privacy preferences into one or more privacy policies; and transmitting the one or more privacy policies to a user equipment data collection client.
49. A method, performed by an apparatus for a user equipment, the method comprising: receiving one or more privacy policies from a user equipment data collection client; applying the one or more privacy policies to user equipment data; and transmitting the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
50. A method, performed by an apparatus for a data collection provisioning entity, the method comprising: receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
51. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive one or more privacy policies from a user equipment data collection entity; receive user equipment data of a user equipment; apply the one or more privacy policies to the user equipment data; and transmit, to a data collection provisioning entity, the user equipment data with the one or more privacy policies applied thereto.
52. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive information of one or more privacy preferences of a user of a user equipment;convert the information of the one or more privacy preferences into one or more privacy policies; and transmit the one or more privacy policies to a user equipment data collection client.
53. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive one or more privacy policies from a user equipment data collection client; apply the one or more privacy policies to user equipment data; and transmit the user equipment data to a user equipment data collection entity with the one or more privacy policies applied thereto.
54. An apparatus comprising: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to: receive user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmit a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receive user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and compare the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
55. A computer readable medium comprising program instructions for causing an apparatus to perform at least the method of any of claims 47, 48, 49 or 50.
56. A system comprising: means for receiving information of one or more privacy preferences of a user of a user equipment; means for converting the information of the one or more privacy preferences into one or more privacy policies; means for transmitting the one or more privacy policies to a user equipment data collection client; means for receiving user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; means for transmitting a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; means for receiving user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and means for comparing the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
57. A system comprising: at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the system at least to: receive information of one or more privacy preferences of a user of a user equipment; convert the information of the one or more privacy preferences into one or more privacy policies; transmit the one or more privacy policies to a user equipment data collection client;receive user equipment data, with one or more privacy policies applied thereto, from a user equipment data collection entity, transmitted to the user equipment data collection entity from a user equipment; transmit a message, to a user equipment data collection client, requesting the same user equipment data as received from the user equipment data collection entity; receive user equipment data, with one or more privacy policies applied thereto, from the user equipment data collection client; and compare the user equipment data received from the user equipment data collection entity and the user equipment data received from the user equipment data collection client.
Citation Information
Patent Citations
Method of harvesting usage data and apparatus for harvesting of usage data
KR1020050074619A
Preference editor to facilitate privacy controls over user identities
US10402591B1
Method and apparatus for applying privacy policies to structured data
US20120110680A1