Secure communication method and communication apparatus
By receiving token request messages in federated learning and determining permissions from both parties, sending tokens to control model interaction, the problem of model information leakage in federated learning is solved, and the secure transmission of model information and property rights protection is realized.
Patent Information
- Application Number
- PCT/CN2025/073558
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-08
- Filing Date
- 2025-01-21
- Publication Date
- 2025-08-14
AI Technical Summary
During the federated learning process, the interaction of model information between server NWDAF and client NWDAF may lead to model information leakage, security risks, loss of model property assets of equipment providers, and other security issues.
By receiving token request messages, determining permissions of the federated learning server and client devices, sending tokens to control model interactions, ensuring that model transmission is only performed if both parties have permissions, including permission checks during generation and transmission.
It effectively reduces the risk of model information leakage, avoids the loss of model property rights assets of equipment providers, and ensures the security of the model.
Smart Images

Figure CN2025073558_14082025_PF_FP_ABST
Abstract
Description
A secure communication method and communication device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on February 8, 2024, with application number 202410178215.6, and invention name “A secure communication method and communication device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the field of communication technology, and more specifically, to a secure communication method and communication device. Background Art
[0003] Federated learning (FL), a machine learning technology in core networks, enables multiple participants (e.g., a server network data analytics function (NWDAF) and a client NWDAF) to conduct local training without exchanging training data and exchange model parameters through secure mechanisms, thereby achieving collaborative training. During the federated learning process, the exchange of model information between the server NWDAF and the client NWDAF may lead to the leakage of model information, posing a security risk. Summary of the Invention
[0004] The present application provides a secure communication method and communication device, which can reduce potential security risks.
[0005] In a first aspect, a communication method is provided. The method may be executed by a first network element, or may be executed by a chip, circuit, or logic module of the first network element, which is not limited in this application. For ease of description, the following description is based on an example of execution by the first network element.
[0006] The method includes: receiving a token request message from a federated learning server, the token request message including a first analysis identifier, an identifier of the federated learning server, and an identifier of a client device; after determining that the federated learning server is allowed to obtain a first model corresponding to the first analysis identifier from the client device, and that the client device is allowed to obtain a second model from the federated learning server, sending a first token to the federated learning server.
[0007] Based on the above solution, before sending the first token, the first network element not only determines that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, but also determines that the client device is allowed to obtain the second model generated based on the first model from the federated learning server. In other words, the particularity of the federated learning scenario is fully considered, thereby checking both the server NWDAF's authority to obtain the first model from the client NWDAF and the client NWDAF's authority to obtain the second model generated based on the first model from the server NWDAF. Then, the federated learning server sends the second model obtained after the federated learning is completed to the client device, which will not cause the leakage of the second model information, reduce security risks, and avoid security issues such as the loss of model property assets of the equipment manufacturer.
[0008] In some implementations, the first model is generated by a client device and used by a federated learning server to generate a second model; and / or the second model is provided by the federated learning server and used by the client device to generate the first model.
[0009] In some implementations, the method further includes: the first token indicating that the client device is allowed to obtain the second model from the federated learning server.
[0010] Based on the above scheme, compared with the access token in the prior art, the first token in the present application not only indicates that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, but also indicates that the client device is allowed to obtain the second model from the federated learning server. Therefore, the federated learning server can share the second model with the client device, and the client device can also report the first model obtained by local training to the federated learning client. Both have the authority to obtain each other's models, which can reduce the leakage of model information, reduce potential security risks, and avoid the loss of model property assets of equipment manufacturers.
[0011] In some implementations, the method further includes: sending third indication information to the federated learning server, where the third indication information indicates that the client device is allowed to obtain the second model from the federated learning server.
[0012] Based on the above scheme, the first network element can issue a third indication message to indicate that the client device is allowed to obtain the second model from the federated learning server. Then, based on the third indication message, the federated learning server can send the second model to the client device with model acquisition permission, thereby avoiding the leakage of model information and ensuring the security of the equipment manufacturer's model assets.
[0013] In some implementations, determining that the client device is allowed to obtain the second model from the federated learning server may specifically include: determining that a vendor identifier of the client device is included in a first interoperability identifier corresponding to a first analysis identifier supported by the federated learning server.
[0014] In other words, the first network element determines that the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server includes the device vendor identifier of the client device.
[0015] Based on the above scheme, it is determined that the equipment vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, so that the federated learning server can send the second model obtained after the completion of federated learning to the client device, without causing the leakage of the second model information, reducing security risks, and at the same time avoiding the loss of the equipment vendor's model property assets.
[0016] In some implementations, determining that the client device is allowed to obtain the second model from the federated learning server may specifically include: determining that the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server;
[0017] In other words, the first network element determines that the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server includes the second interoperability identifier corresponding to the first analysis identifier supported by the client device.
[0018] In some implementations, determining that the client device is allowed to obtain the second model from the federated learning server may specifically include: determining that the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server;
[0019] In other words, the first network element determines that the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server includes the second interoperability identifier corresponding to the first analysis identifier supported by the client device.
[0020] Based on the above solution, by ensuring that the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, not only can the federated learning server deliver the second model obtained after the federated learning is completed to the client device without leaking the second model information, thus reducing security risks, but also can prevent the loss of model property assets of the equipment manufacturer. At the same time, by limiting the second interoperability identifier corresponding to the first analysis identifier supported by the client device to be included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, consumers of the second model are guaranteed permission to obtain model information from the client device, thus preventing the client device from leaking the second model to other consumers who do not have model access permission, thereby achieving the purpose of doubly protecting the asset security of the model.
[0021] In some implementations, before receiving the token request message from the federated learning server, the method further includes: receiving a first registration request message from the federated learning server, the first registration request message including a first interoperability identifier; and sending a first registration response message to the federated learning server, the first registration response message being used to indicate that registration is complete.
[0022] Based on the above scheme, in the federated learning registration process, the first network element can obtain the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, and then use it to determine that the equipment vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, which means that the client device has the authority to obtain the second model. Then the federated learning server will send the second model to the client device, which will not cause the leakage of model information and can avoid the loss of model property assets of the equipment vendor.
[0023] In some implementations, before receiving the token request message from the federated learning server, the method further includes: receiving a second registration request message from the client device, the second registration request message including the device vendor identifier of the client device; and sending a second registration response message to the client device, the second registration response message being used to indicate that the registration is complete.
[0024] Based on the above scheme, in the federated learning registration process, the first network element can obtain the equipment vendor identifier of the client device, and then use it to determine that the equipment vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, which means that the client device has the authority to obtain the second model. Then the federated learning server will send the second model to the client device, which will not cause the leakage of model information and can avoid the loss of model property assets of the equipment vendor.
[0025] In some implementations, determining that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device may specifically include: determining that the device vendor identifier of the federated learning server is included in the second interoperability identifier corresponding to the first analysis identifier supported by the client device.
[0026] In other words, the first network element determines that the second interoperability identifier corresponding to the first analysis identifier supported by the client device includes the device vendor identifier of the federated learning server.
[0027] Based on the above scheme, it is determined that the device vendor identifier of the federated learning server is included in the second interoperability identifier corresponding to the first analysis identifier supported by the client device, so that the federated learning server has the authority to obtain the first model from the client device, which will not cause the leakage of the first model information and reduce security risks.
[0028] In some implementations, determining that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device may specifically be: determining that a first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server is included in a second interoperability identifier corresponding to the first analysis identifier supported by the client device.
[0029] In other words, the first network element determines that the second interoperability identifier corresponding to the first analysis identifier supported by the client device includes the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server.
[0030] Based on the above solution, by ensuring that the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, not only is the federated learning server authorized to obtain the first model from the client device, but the leakage of the first model information is prevented, thereby reducing security risks. Furthermore, by limiting the second interoperability identifier corresponding to the first analysis identifier supported by the client device to include the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, all consumers of the first model are authorized to obtain model information from the federated learning server, thereby preventing the federated learning server from leaking the first model to other consumers who do not have model access permission, thereby achieving the goal of doubly protecting the model's asset security.
[0031] In some implementations, before determining that the client device is allowed to obtain the second model from the federated learning server, the method further includes: determining that the federated learning server and / or the client device supports federated learning based on an identifier of the federated learning server and / or an identifier of the client device; or, determining that the token request message is associated with federated learning based on information of the first service and / or the federated learning capability type carried in the token request message, and the first service is used for federated learning between the federated learning server and the client device; or, determining that the federated learning server sends the second model to the client device based on first indication information, and the first indication information indicates that the second model is sent to the client device.
[0032] Based on the above solution, the first network element can determine, based on at least one of the identifier of the federated learning server and / or the identifier of the client device, the information of the first service and / or the federated learning capability type, the first indication information, or the second indication information, that the client device is permitted to obtain the second model from the federated learning server. That is, at least one of the identifier of the federated learning server and / or the identifier of the client device, the information of the first service and / or the federated learning capability type, the first indication information, or the second indication information can serve as a trigger condition for the first network element to determine that the client device is permitted to obtain the second model from the federated learning server.
[0033] In a second aspect, a communication method is provided. This method can be executed by a federated learning server, or by a chip, circuit, or logic module of the federated learning server, although this application does not limit this. For ease of description, the following description uses execution by a federated learning server as an example.
[0034] The method includes: sending a token request message to a first network element, the token request message including a first analysis identifier, an identifier of a federated learning server, and an identifier of a client device; receiving a first token from the first network element, or receiving a first token and third indication information from the first network element; wherein the first token indicates that the client device is allowed to obtain a second model from the federated learning server, and the third indication information indicates that the client device is allowed to obtain the second model from the federated learning server; obtaining a first model corresponding to the first analysis identifier from the client device according to the first token; generating a second model according to the first model; and sending the second model to the client device according to the first token and / or the third indication information.
[0035] In some implementations, sending the second model to the client device includes: sending the second model to the client device according to second indication information and / or local configuration, where the second indication information indicates that the client device desires to obtain the second model.
[0036] Based on the above scheme, before sending the second model to the client device, the federated learning server determines through the second indication information and / or local configuration that the client device expects to obtain the second model. That is, the federated learning server sends the second model to the client device when the client device needs to obtain the second model, which can reduce unnecessary transmission overhead and at the same time reduce the risk of model leakage and protect the asset security of the model.
[0037] In some implementations, the method further includes: receiving second indication information from the first network element or the client device.
[0038] In some implementations, the client device is allowed to obtain the second model from the federated learning server, including: the device vendor identifier of the client device includes a first interoperability identifier corresponding to a first analysis identifier supported by the federated learning server.
[0039] In some implementations, before sending a token request message to the first network element, the method also includes: sending a first registration request message to the first network element, the first registration request message including a first interoperability identifier; receiving a first registration response message from the first network element, the first registration response message being used to indicate that registration is complete.
[0040] The beneficial effects of the above-mentioned second aspect and certain implementation methods can be referred to the corresponding description of the first aspect, and will not be repeated here.
[0041] In a third aspect, a communication method is provided. This method can be executed by a federated learning server, or by a chip, circuit, or logic module within the federated learning server, though this application does not limit this. For ease of description, the following description uses execution by a federated learning server as an example.
[0042] The method includes: sending a discovery request message to a first network element, the discovery request message including a first analysis identifier; receiving a discovery response message from the first network element, the discovery response message including an identifier of a client device and an equipment vendor identifier of the client device; obtaining a first model corresponding to the first analysis identifier from the client device; generating a second model based on the first model; and after determining that the client device is allowed to obtain the second model from a federated learning server based on the equipment vendor identifier of the client device, sending the second model to the client device.
[0043] Based on the above solution, after the federated learning server obtains the second model, it performs an authority check on the client device through the client's equipment manufacturer identifier obtained in the discovery process, that is, it determines that the client device is allowed to obtain the second model from the federated learning server. In other words, the client device has the authority to obtain the second model. In this case, the federated learning server can send the second model to the client device, reducing the risk of information leakage of the second model, and at the same time avoiding the loss of model property assets of the equipment manufacturer.
[0044] In some implementations, determining that the client device is allowed to obtain the second model from the federated learning server based on the vendor identifier of the client device includes determining that the vendor identifier of the client device is included in a first interoperability identifier corresponding to a first analysis identifier supported by the federated learning server.
[0045] In some implementations, before sending a discovery request message to the first network element, the method also includes: sending a first registration request message to the first network element, the first registration request message including a first interoperability identifier; receiving a first registration response message from the first network element, the first registration response message being used to indicate that registration is complete.
[0046] In some implementations, sending the second model to the client device includes: sending the second model to the client device according to second indication information and / or local configuration, where the second indication information indicates that the client device desires to obtain the second model.
[0047] In some implementations, the method further includes: receiving second indication information from the first network element or the client device.
[0048] The beneficial effects of the third aspect and certain implementation methods mentioned above can be referred to the relevant description of the second aspect, which will not be repeated here.
[0049] In a fourth aspect, a communication method is provided. The method may be executed by a first network element, or may be executed by a chip, circuit, or logic module of the first network element, which is not limited in this application. For ease of description, the following description is based on an example of execution by the first network element.
[0050] The method includes: receiving a discovery request message from a federated learning server, the discovery request message including a first analysis identifier; sending a discovery response message to the federated learning server when it is determined that the federated learning server is allowed to obtain a first model corresponding to the first analysis identifier from a client device, the discovery response message including an identifier of the client device; receiving a request message from the federated learning server, the request message being used to request confirmation whether the client device is allowed to obtain a second model from the federated learning server, the request message including the first analysis identifier, the first model being generated by the client device and being used by the federated learning server to generate a second model; sending a response message to the federated learning server when it is determined that the client device is allowed to obtain the second model from the federated learning server.
[0051] Based on the above solution, after the federated learning server obtains the second model, it requests the first network element to check the permissions of the client device to determine whether the client device is allowed to obtain the second model from the federated learning server. Then, the federated learning server can send the second model to the client device with model acquisition permission without causing the leakage of model information, reducing potential security risks, and avoiding the loss of model property assets of the equipment manufacturer.
[0052] In some implementations, the response message includes third indication information, where the third indication information indicates that the client device is allowed to obtain the second model from the federated learning server.
[0053] In some implementations, determining that the client device is allowed to obtain the second model from the federated learning server includes determining that a vendor identifier of the client device includes a first interoperability identifier corresponding to a first analysis identifier supported by the federated learning server.
[0054] In some implementations, before receiving the discovery request message from the federated learning server, the method further includes: receiving a first registration request message from the federated learning server, the first registration request message including a first interoperability identifier; and sending a first registration response message to the federated learning server, the first registration response message being used to indicate that registration is complete.
[0055] In some implementations, before receiving the discovery request message from the federated learning server, the method further includes: receiving a second registration request message from the client device, the second registration request message including the device vendor identifier of the client device; and sending a second registration response message to the client device, the second registration response message being used to indicate that the registration is complete.
[0056] In some implementations, allowing the federated learning server to obtain the first model corresponding to the first analysis identifier from the client device includes: determining that the vendor identifier of the federated learning server is included in the second interoperability identifier corresponding to the first analysis identifier supported by the client device.
[0057] The beneficial effects of the fourth aspect and certain implementation methods mentioned above can be referred to the relevant description of the first aspect and will not be repeated here.
[0058] In a fifth aspect, a communication method is provided. This method can be executed by a federated learning server, or by a chip, circuit, or logic module of the federated learning server, although this application does not limit this. For ease of description, the following description uses execution by a federated learning server as an example.
[0059] The method includes: sending a discovery request message to a first network element, the discovery request message including a first analysis identifier; receiving a discovery response message from the first network element, the discovery response message including an identifier of a client device; obtaining a first model corresponding to the first analysis identifier from the client device; generating a second model based on the first model; sending a request message to the first network element, the request message being used to request confirmation as to whether the client device is allowed to obtain the second model from a federated learning server, the request message including the first analysis identifier; receiving a response message from the first network element, the response message indicating that the client device is allowed to obtain the second model from the federated learning server; and sending the second model to the client device.
[0060] In some implementations, the method further includes: receiving third indication information from the first network element, the third indication information indicating that the client device is allowed to obtain the second model from the federated learning server.
[0061] In some implementations, sending the second model to the client device includes: sending the second model to the client device according to second indication information and / or local configuration, where the second indication information indicates that the client device desires to obtain the second model.
[0062] In some implementations, the method further includes: receiving second indication information from the first network element or the client device.
[0063] The beneficial effects of the above-mentioned fifth aspect and certain implementation methods can be referred to the relevant description of the second aspect, and will not be repeated here.
[0064] In a sixth aspect, a communication method is provided. The method may be executed by a first network element, or may be executed by a chip, circuit, or logic module of the first network element, which is not limited in this application. For ease of description, the following description is based on an example of execution by the first network element.
[0065] The method includes: receiving a token request message from a federated learning server, the token request message including a first analysis identifier, an identifier of the federated learning server, and an identifier of a client device; after determining that the device vendor identifier of the client device is included in a first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, and determining that the device vendor identifier of the federated learning server is included in a second interoperability identifier corresponding to the first analysis identifier supported by the client device, sending a first token to the federated learning server.
[0066] For other possible implementations and the beneficial effects of certain implementations, please refer to the corresponding description of the first aspect and will not be elaborated here.
[0067] In the seventh aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the first aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0068] In some implementations, the device includes: a transceiver unit for receiving a token request message from a federated learning server, the token request message including a first analysis identifier, an identifier of the federated learning server, and an identifier of the client device; after determining that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, and that the client device is allowed to obtain the second model from the federated learning server, sending the first token to the federated learning server.
[0069] The transceiver unit can perform the receiving and sending processing in the aforementioned first aspect and its possible implementations, and the processing unit can perform other processing except receiving and sending in the aforementioned first aspect and its possible implementations.
[0070] In the eighth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the second aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0071] In some implementations, the device includes: a transceiver unit, configured to send a token request message to a first network element, the token request message including a first analysis identifier, an identifier of a federated learning server, and an identifier of a client device; receiving a first token from the first network element, or receiving a first token and third indication information from the first network element; wherein the first token indicates that the client device is allowed to obtain a second model from the federated learning server, and the third indication information indicates that the client device is allowed to obtain a second model from the federated learning server; obtaining a first model corresponding to the first analysis identifier from the client device according to the first token; a processing unit, configured to generate a second model based on the first model; and the transceiver unit, further configured to send the second model to the client device according to the first token and / or the third indication information.
[0072] The transceiver unit can perform the receiving and sending processing in the aforementioned second aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned second aspect and its possible implementations.
[0073] In the ninth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the third aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0074] In some implementations, the device includes: a transceiver unit for sending a discovery request message to a first network element, the discovery request message including a first analysis identifier; receiving a discovery response message from the first network element, the discovery response message including an identifier of the client device and an equipment vendor identifier of the client device; obtaining a first model corresponding to the first analysis identifier from the client device; a processing unit for generating a second model based on the first model; and the transceiver unit is further used to send the second model to the client device after determining that the client device is allowed to obtain the second model from the federated learning server based on the equipment vendor identifier of the client device.
[0075] The transceiver unit can perform the receiving and sending processing in the aforementioned third aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned third aspect and its possible implementations.
[0076] In the tenth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the fourth aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0077] In some implementations, the device includes: a transceiver unit, configured to receive a discovery request message from a federated learning server, the discovery request message including a first analysis identifier; upon determining that the federated learning server is allowed to obtain a first model corresponding to the first analysis identifier from a client device, sending a discovery response message to the federated learning server, the discovery response message including an identifier of the client device; receiving a request message from the federated learning server, the request message being used to request confirmation whether the client device is allowed to obtain a second model from the federated learning server, the request message including the first analysis identifier, the first model being generated by the client device, and being used by the federated learning server to generate a second model; upon determining that the client device is allowed to obtain the second model from the federated learning server, sending a response message to the federated learning server.
[0078] The transceiver unit can perform the receiving and sending processing in the aforementioned fourth aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned fourth aspect and its possible implementations.
[0079] In the eleventh aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the fifth aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0080] In some implementations, the device includes: a transceiver unit, configured to send a discovery request message to a first network element, the discovery request message including a first analysis identifier; receive a discovery response message from the first network element, the discovery response message including an identifier of a client device; obtain a first model corresponding to the first analysis identifier from the client device; a processing unit, configured to generate a second model based on the first model; send a request message to the first network element, the request message being used to request confirmation whether the client device is allowed to obtain the second model from a federated learning server, the request message including the first analysis identifier; receive a response message from the first network element, the response message indicating that the client device is allowed to obtain the second model from the federated learning server; the transceiver unit is further configured to send the second model to the client device.
[0081] The transceiver unit can perform the receiving and sending processing in the aforementioned fifth aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned fifth aspect and its possible implementations.
[0082] In the twelfth aspect, a communication device is provided, which may include modules or units corresponding to the methods / operations / steps / actions described in the sixth aspect. The modules or units may be hardware circuits, software, or a combination of hardware circuits and software.
[0083] In some implementations, the apparatus includes: a transceiver unit for receiving a token request message from a federated learning server, the token request message including a first analysis identifier, an identifier of the federated learning server, and an identifier of the client device; after determining that the vendor identifier of the client device is included in a first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, and determining that the vendor identifier of the federated learning server is included in a second interoperability identifier corresponding to the first analysis identifier supported by the client device, sending a first token to the federated learning server, wherein the first model is generated by the client device and is used for the federated learning server to generate a second model.
[0084] The transceiver unit can perform the receiving and sending processing in the aforementioned sixth aspect and its possible implementations. Optionally, the device also includes a processing unit, which can perform other processing in addition to receiving and sending in the aforementioned sixth aspect and its possible implementations.
[0085] In the thirteenth aspect, a communication device is provided, comprising at least one processor, wherein the at least one processor is used to execute computer programs or instructions, and / or, through logic circuits, so that the communication device performs a method as in any aspect from the first to the sixth aspect, or any possible implementation of these aspects.
[0086] In certain implementations, at least one processor is coupled to at least one memory, and the at least one memory stores the computer program or instructions. Optionally, the communication device further includes the at least one memory. Optionally, the at least one processor and the at least one memory are integrated.
[0087] In the fourteenth aspect, a chip or chip system is provided, including a processor and a communication interface, the communication interface being used to receive information and / or data to be processed, and to send the information and / or data to be processed to the processor, and the processor being used to process the information and / or data to be processed, so that the communication device in which the chip is installed executes a method as in any aspect of the first to sixth aspects, or any possible implementation of these aspects.
[0088] In the fifteenth aspect, a communication system is provided, comprising a communication device as in the seventh and eighth aspects, or a communication device as in the ninth aspect, or a communication device as in the tenth and eleventh aspects, or a communication device as in the twelfth aspect.
[0089] Optionally, the communication system further includes a client device.
[0090] In the sixteenth aspect, a computer-readable storage medium is provided, in which computer instructions are stored. When the computer instructions are executed on a computer, the method in any aspect from the first to the sixth aspect, or any possible implementation of these aspects, is implemented.
[0091] In the seventeenth aspect, a computer program product is provided, which includes a computer program code. When the computer program code is run on a computer, the method in any aspect from the first to the sixth aspect, or any possible implementation of these aspects, is implemented.
[0092] Among them, the technical effects of the technical solutions of aspects 7 to 17 can refer to the description of the corresponding technical effects of aspects 1 to 7 and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0093] FIG1 is a schematic diagram of a network architecture applicable to an embodiment of the present application;
[0094] FIG2 is a schematic diagram of a process in which an authorization server NWDAF requests a client NWDAF to provide a federated learning service;
[0095] FIG3 is a schematic diagram of a process in which an authorization server NWDAF requests a client NWDAF to provide a federated learning service;
[0096] FIG4 is a flow chart of a method for executing federated learning;
[0097] FIG5 is a flow chart of a communication method provided in an embodiment of the present application;
[0098] FIG6 is a flow chart of another communication method provided in an embodiment of the present application;
[0099] FIG7 is a flow chart of another communication method provided in an embodiment of the present application;
[0100] FIG8 is a schematic diagram of a communication device provided in an embodiment of the present application;
[0101] FIG9 is a schematic diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0102] The technical solution in this application will be described below with reference to the accompanying drawings.
[0103] The technical solutions provided in this application can be applied to various communication systems, such as new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc. The technical solutions provided in this application can also be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0104] In a communication system, the part operated by an operator may be referred to as a public land mobile network (PLMN), or as an operator network, etc. PLMN is a network established and operated by the government or an operator approved by it for the purpose of providing land mobile communication services to the public. It is mainly a public network in which mobile network operators (MNOs) provide mobile broadband access services to users. The PLMN described in the embodiments of the present application may specifically be a network that complies with the standards of the 3rd Generation Partnership Project (3GPP), referred to as a 3GPP network. 3GPP networks generally include but are not limited to fifth-generation mobile communication (5th-generation, 5G) networks, fourth-generation mobile communication (4th-generation, 4G) networks, and other future communication systems, such as sixth-generation mobile communication (6th-generation, 6G) networks.
[0105] For ease of description, the embodiments of the present application will be described using PLMN or 5G network as an example.
[0106] Figure 1 is a schematic diagram of a network architecture 100, using the 5G network architecture based on a service-based architecture (SBA) in a non-roaming scenario as defined in the 3GPP standardization process as an example. As shown in Figure 1 , the network architecture may include a terminal device component, a data network (DN) component, and a carrier network (PLMN) component. The carrier network PLMN component may include, but is not limited to, a (radio) access network (R)AN) 120 and a core network (CN) component.
[0107] The following is a brief description of the functions of the network elements in each part.
[0108] The terminal device portion may include a terminal device 110, which is a device that provides voice and / or data connectivity to a user. The terminal device 110 may also be referred to as a user equipment (UE). The terminal device 110 in this application is a device with wireless transceiver capabilities that can communicate with one or more core network (CN) devices via access network equipment (or access equipment) in a (radio) access network (R)AN 120. The terminal device 110 may also be referred to as an access terminal, terminal, subscriber unit, subscriber station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, or user device. The terminal device 110 may be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a smartphone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), or the like. Alternatively, the terminal device 110 may also be a handheld device with wireless communication capabilities, a computing device, or other device connected to a wireless modem, an in-vehicle device, a wearable device, a drone device, or a terminal in the Internet of Things, the Internet of Vehicles, a terminal in any form in a 5G network and future networks, a relay user device, or a terminal in a future evolved 6G network, etc. Among them, the relay user device may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. The terminal device here refers to a 3GPP terminal. The embodiments of the present application do not limit the type or category of the terminal device. For ease of explanation, this application will be described later using UE as an example to refer to a terminal device.
[0109] (R)AN 120 may include one or more access network elements or access network devices. The interface between the access network device and the terminal device may be a Uu interface (or air interface, that is, the messages exchanged between the access network device and the terminal device may be called air interface messages). In future communications, the interface name may remain unchanged or may be replaced by other names, and this application does not limit this. (R)AN 120 is a device that provides wireless communication functions for the terminal device 110, which can connect the terminal device to a node or device of a wireless network, and may also be called a network device. The above-mentioned RAN may be a 3GPP-related cellular system, such as a 5G mobile communication system, or a future-oriented evolution system (such as a 6G mobile communication system). RAN may also be an open radio access network (open RAN, O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. (R)AN 120 can be regarded as a subnetwork of the operator network, and is an implementation system between a service node in the operator network and the terminal device 110. For example, the terminal device 110 can connect to the service node of the operator network through the (R)AN120 to obtain the services provided by the service node. (R)AN 120 includes but is not limited to: the next generation node base station (gNB) in the 5G system, the evolved node B (eNB) in LTE, the radio network controller (RNC), the node B (NB), the base station controller (BSC), the base transceiver station (BTS), the home base station (for example, home evolved node B, or home node B, HNB), the base band unit (BBU), the transmission point (TRP), the transmitting point (TP), the small base station equipment, the mobile switching center, or the network equipment in the future network. The access network equipment can also be a module or unit that performs the base station function, for example, including a centralized unit (CU) and a distributed unit (DU). The embodiments of the present application do not limit the specific technology and specific equipment form adopted by the access network equipment. In systems using different wireless access technologies, the names of devices that function as access network devices may vary.For ease of description, in all embodiments of the present application, the apparatus providing wireless communication functions for the terminal device 110 is collectively referred to as an access network device or RAN for short. It should be understood that the specific type of access network device is not limited herein.
[0110] In different systems, CU (including CU-CP or CU-UP), or DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0111] The terminal device 110 or (R)AN 120 can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on the water surface (such as a ship, etc.); can also be deployed in the air (such as an airplane, balloon, and satellite, etc.).
[0112] The CN part may include but is not limited to the following network functions (NF): user plane function (UPF) 130, network exposure function (NEF) 131, network function repository function (NRF) 132, policy control function (PCF) 133, unified data management function (UDM) 134, unified data repository function (UDR) 135, network data analytics function (NWDAF) 136, application function (AF) 141, authentication server function (AUSF) 137, access and mobility management function (AMF) 138, and session management function (SMF) 139.
[0113] The data network DN 140, also called a packet data network (PDN), is typically a network outside the operator's network, such as a third-party network.
[0114] The following is a brief description of the NF functions included in CN.
[0115] 1. UPF 130 is a gateway provided by the operator, serving as the gateway for communication between the operator network and DN 140. UPF 130 network functions include packet routing and transmission, packet inspection, service usage reporting, Quality of Service (QoS) processing, lawful interception, uplink packet inspection, downlink packet storage, and other user-plane-related functions.
[0116] 2. NEF 131 is a control plane function provided by the operator. It mainly enables third parties to use the services provided by the network, supports the network to open its capabilities, event and data analysis, provide PLMN security configuration information from external applications, and convert interactive information within and outside the PLMN.
[0117] 3. NRF 132 is a control plane function provided by the operator, which can be used to maintain real-time information of network functions and services in the network.
[0118] 4. PCF 133 is a control plane function provided by the operator. It primarily supports providing a unified policy framework to control network behavior, provides policy rules to the control layer network functions, and is responsible for obtaining user subscription information related to policy decisions. For example, PCF 133 can be divided into two different PCFs: UE-PCF and AMF-PCF.
[0119] 5. UDM 134 is a control plane function provided by the operator and is responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribers in the operator's network.
[0120] 6. UDR 135 is a control plane function provided by the operator. It provides the UDM with the function of saving and retrieving subscription data, the PCF with the function of saving and retrieving policy data, and the user's NF group ID information.
[0121] 7. NWDAF 136 is a control plane function provided by the operator, which has functions such as data collection, model training, data analysis, and model reasoning. Among them, the NWDAF network element containing the analytics logical function (AnLF) can be used to infer and derive analysis information and expose analysis services. Analysis can refer to statistical information and / or predictions generated or provided according to the request of the analysis consumer (consumer). The NWDAF network element containing the model training logical function (MTLF) can be used to train machine learning (ML) models or AI models and expose new training services, such as providing trained AI models or ML models to AnLF. For the process of obtaining model-related data, AnLF can serve as a data producer (producer) network element, denoted as NFp; MTLF can serve as a data consumer network element, denoted as NFc.
[0122] Currently, AnLF can request a model from MTLF through the model subscription (MLModelProvision_Subscribe) service or message. The model can be obtained by MTLF training based on the relevant data of the model (such as samples). In addition, AnLF can use a data set tag to specify a data set, which can contain data related to a model. Therefore, a data set tag can be used to label a data set, that is, to label model-related data. The data set tag can also be understood as the index of the data set or the index of the data. MTLF can act as a consumer network element of model-related data to obtain data stored in the data store by the data producer network element, where the data producer network element can be AnLF, and the data storage network element can be a network element for storing data such as the analytics data repository functional (ADRF). In this application, relevant data can be understood as data used for vertical federated learning, such as input data, training data, inference data, model parameters or sample data.
[0123] 8. AF 141 is a control plane function provided by the operator. It mainly provides corresponding services by interacting with other NFs in the PLMN, such as providing roaming UE with visitor network selection information, guiding the routing of data flows, and accessing NEF 131.
[0124] 9. AUSF 137 is a control plane function provided by the operator, and is usually used for level 1 authentication, i.e., authentication between the terminal device 110 (subscriber) and the operator's network.
[0125] 10. AMF 138 is a control plane network function provided by the operator network, responsible for access control and mobility management of the terminal device 110 accessing the operator network, such as mobility status management, allocation of user temporary identity, authentication and authorization of users, etc.
[0126] 11. SMF 139 is a control plane network function provided by the operator network. It is responsible for managing the protocol data unit (PDU) session of the terminal device 110 (including session establishment, modification and release), and is used for the selection and reselection of user plane function network elements, the allocation of Internet Protocol (IP) addresses of terminal devices, and quality of service (QoS) control.
[0127] It is understood that the above network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented by hardware or software.
[0128] In Figure 1, Nnef, Nnrf, Npcf, Nudm, Nudr, Nnwdaf, Naf, Nausf, Namf, Nsmf, N1, N2, N3, N4, and N6 are interface serial numbers. For example, the meaning of the above interface serial numbers can be found in the meaning defined in the 3GPP standard protocol, and this application does not limit the meaning of the above interface serial numbers. It should be noted that the interface name between the various network functions in Figure 1 is only an example, and the interface name of the system architecture may also be other names, which is not limited by this application. In addition, the name of the message (or signaling) transmitted between the above network elements is only an example and does not constitute any limitation on the function of the message itself.
[0129] It should be noted that in the architecture shown in Figure 1, the interface between the (R)AN and CN can also be called the NG interface (not shown in the figure), and the (R)AN and CN are connected via the NG interface. The NG interface can include the NG-C interface and the NG-U interface. The NG-C interface is a control plane interface, connecting the (R)AN and AMF, and is used to transmit control plane data; the NG-U interface is a user plane interface, connecting the (R)AN and UPF, and is used to transmit user plane data.
[0130] It should be understood that the above network architecture 100 is only described from the perspective of a service-based architecture. In this service-based architecture, the PLMN can combine some or all network functions in an orderly manner according to specific scenario requirements, realizing customized network capabilities and services, thereby deploying dedicated networks for different services, that is, realizing 5G network slicing. Network slicing technology enables operators to respond to customer needs more flexibly and quickly, and supports flexible allocation of network resources.
[0131] It should also be understood that the above naming is defined only to facilitate the distinction between different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and other future networks. For example, in a 6G network, some or all of the above network elements may continue to use the terminology used in 5G, or may adopt other names.
[0132] To facilitate understanding, the following first introduces relevant terms, concepts, or technologies that may be involved in the embodiments of this application:
[0133] 1. Federated learning;
[0134] Federated learning (FL) is a distributed machine learning approach in which multiple participants exchange model parameters through secure mechanisms, without interacting or sharing original training data, to achieve collaborative training. In other words, federated learning is an encrypted distributed machine learning technology. Federated learning fully leverages the data and computing power of participating parties, enabling them to collaboratively build universal and robust machine learning models without sharing data. Therefore, federated learning can effectively help multiple organizations utilize data and conduct learning and modeling while meeting user privacy, data security, and government regulatory requirements. In other words, federated learning aims to enable the sharing of knowledge and parameters without exchanging any of their own data.
[0135] Federated learning includes horizontal federated learning and vertical federated learning. Amidst increasingly stringent data regulation, federated learning can address key issues such as data ownership, data privacy, data access rights, and access to heterogeneous data. A horizontal row in a data matrix represents a training example, and a vertical column represents a data feature. Horizontal federated learning combines multiple rows of samples with the same feature from multiple participants, meaning that the training data for each participant is partitioned horizontally. Horizontal federated learning, also known as feature-aligned federated learning, means that the data features of the participants are aligned. Horizontal federated learning can increase the total number of training examples. VFL, a machine learning technique, can be used to address model training and inference when participants are reluctant to share raw data. It is suitable for situations where there is significant overlap in the identification (ID) of participant training samples but little overlap in their data features. VFL combines the different data features of common samples from multiple participants for federated learning, meaning that the training data for each participant is partitioned vertically. Vertical federated learning combines the different data features of common samples from multiple participants for federated learning, meaning that the training data for each participant is partitioned vertically. Vertical federated learning is also called sample-aligned federated learning, that is, the training samples of the participants are aligned. Vertical federated learning can increase the feature dimension of the training data.
[0136] 2. Analysis ID;
[0137] An analysis identifier can be used to indicate an analysis business or analysis service (or simply, service). This service is associated with a model, meaning the model can be used to perform the service. Alternatively, the analysis identifier can be associated with the model, meaning the model can be used to perform the service associated with the analysis identifier.
[0138] Alternatively, it can be understood that the MTLF is associated with an analysis identifier, that is, the model support provided by the MTLF is used to execute the service corresponding to the analysis identifier. For example, the MTLF can be associated with one or more analysis identifiers. It can be understood that the MTLF can provide a model for the service corresponding to each of the one or more analysis identifiers. For example, MTLF1 is associated with analysis identifier 1 and analysis identifier 2, that is, MTLF1 corresponds to analysis identifier 1 and analysis identifier 2. Then, MTLF1 can provide a model for the service corresponding to analysis identifier 1, and a model for the service corresponding to analysis identifier 2.
[0139] 3. Interoperability indicator;
[0140] Illustratively, the interoperability identifier may correspond to the MTLF, or to the analysis identifier, or to the analysis identifier corresponding to the MTLF. Alternatively, the interoperability identifier may be associated with the MTLF, or the interoperability identifier may be associated with the analysis identifier. The interoperability identifier may also be referred to as an interoperability indicator, a machine learning (ML) model interoperability identifier, or an ML model interoperability indicator.
[0141] The interoperability identifier includes a list of vendors, or is described as a list of NWDAF providers (or suppliers). The vendors in the vendor list are allowed to retrieve or use models provided by the MTLF. The interoperability identifier also indicates that the MTLF supports vendors requesting models provided by the MTLF for the NWDAF of the vendors in the vendor list. The interoperability identifier also indicates that the vendors in the vendor list are allowed to obtain models from the MTLF. The interoperability identifier also indicates that the MTLF allows the vendors in the vendor list to obtain models from the MTLF.
[0142] The interoperability identifier is a list of MTLF providers, for example, the interoperability identifier represents the manufacturer identifier, or the interoperability identifier is associated with the manufacturer identifier. The interoperability identifier can be associated with the analysis identifier, such as a one-to-one correspondence between the two, indicating that the MTLF allows the corresponding manufacturer or the MTLF included in the manufacturer to obtain the model corresponding to the analysis identifier, and / or indicates that the MTLF is allowed to interoperate with the AnLF on the model corresponding to the analysis identifier. Optionally, a MTLF may have one or more interoperability identifiers. If there are multiple interoperability identifiers, the multiple interoperability identifiers correspond to different analysis identifiers respectively. For example, MTLF NF ID 1 corresponds to analysis identifier 1 and analysis identifier 2, wherein the MTLF to which MTLF NF ID 1 belongs has interoperability identifier 1 and interoperability identifier 2, interoperability identifier 1 corresponds to analysis identifier 1, and interoperability identifier 2 corresponds to analysis identifier 2. Optionally, if the MTLF to which MTLF NF ID 1 belongs and the MTLF to which MTLF NF ID 2 belongs support interoperability, the MTLF to which MTLF NF ID 2 belongs may have interoperability identifier 1 and interoperability identifier 2, wherein interoperability identifier 1 corresponds to analysis identifier 1, and / or, interoperability identifier 2 corresponds to analysis identifier 2, that is, MTLFs of the same manufacturer may have the same interoperability identifier for the same analysis identifier. In addition, if the MTLF to which MTLF NF ID 1 belongs and the MTLF to which MTLF NF ID 2 belongs belong to different manufacturers, the MTLF to which MTLF NF ID 2 belongs may have interoperability identifier 3 and interoperability identifier 4, wherein interoperability identifier 3 corresponds to analysis identifier 1, and / or, interoperability identifier 4 corresponds to analysis identifier 2, that is, MTLFs of the same manufacturer may have different interoperability identifiers for the same analysis identifier.
[0143] Exemplarily, analysis identifier 1 is associated with model 1, i.e., model 1 is used to execute the service corresponding to analysis identifier 1, and analysis identifier 1 is associated with interoperability identifier 1, i.e., model 1 is associated with interoperability identifier 1. Assume that interoperability identifier 1 includes the identifier of manufacturer 1 and the identifier of manufacturer 2, i.e., model 1 can be provided to manufacturer 1 and manufacturer 2 for use. Alternatively, it can be understood that if the manufacturer of the NWDAF is manufacturer 1 or manufacturer 2, then the NWDAF can use model 1.
[0144] For example, a MTLF may have one or more interoperability identifiers. If there are multiple interoperability identifiers, the multiple interoperability identifiers may correspond to different analysis identifiers. For example, MTLF1 corresponds to analysis identifier 1 and analysis identifier 2, where interoperability identifier 1 corresponds to analysis identifier 1 and interoperability identifier 2 corresponds to analysis identifier 2.
[0145] 4. Model producer;
[0146] A model producer is the entity that produces the model, or is authorized to provide model information to other entities based on network configuration. Consumers can obtain the model based on the model information. Model information includes, but is not limited to, the uniform resource locator (URL) of the model file, the model itself, model parameters, model identifier, or model address information.
[0147] 5. Manufacturer's logo;
[0148] The vendor ID of the vendor (vendor), which can also be expressed as network element information, identifies the vendor or manufacturer of the network element. In this application, the vendor can also be referred to as the equipment vendor or supplier, etc., for producing or providing network elements. For example, Vendor ID1 can identify the vendor of the NWDAF network element.
[0149] The vendor identifier can be used to identify the device manufacturer or supplier. A vendor identifier can correspond to one or more NWDAF network element identifiers. For example, NWDAF NF ID 1 and NWDAF NF ID 2 can both correspond to vendor identifier 1. This means that the MTLF to which MTLF NF ID 1 belongs and the MTLF to which MTLF NF ID 2 belongs belong to the same vendor, whose vendor identifier is vendor identifier 1.
[0150] The above briefly explains the terms involved in this application, which will not be repeated in the following embodiments. In addition, the above explanation of the terms is only for the purpose of facilitating understanding and does not limit the scope of protection of the embodiments of this application.
[0151] Figure 2 is a schematic diagram of the process by which an authorization server NWDAF requests a client NWDAF to provide federated learning services. As shown in Figure 2, the process includes the following steps. For parts not fully described, please refer to existing protocols.
[0152] S201: The client NWDAF sends a registration request message #1 to the NRF.
[0153] Correspondingly, NRF receives the registration request message #1 from the client NWDAF.
[0154] The registration request message #1 is used to request registration with the network.
[0155] Exemplarily, the registration request message #1 may be an Nnrf_NFManagement_NFRegister_request message, and the registration request message #1 includes configuration parameters (e.g., Client NWDAF profile), where the configuration parameters include one or more of the following: client NWDAF NF type, analysis ID(s), interoperability indication corresponding to the Analytics ID, address information of the client NWDAF, service area, FL capability type information (e.g., FL client), or a time interval for the client NWDAF to support FL.
[0156] Optionally, the present application does not limit the number of NWDAFs of the client, for example, NWDAF 1, ..., NWDAF N, where N is an integer greater than or equal to 1.
[0157] Optionally, the NRF sends a registration response message #1 to the client NWDAF. Correspondingly, the client NWDAF receives the registration response message #1 from the NRF, indicating that the registration of the client NWDAF is completed.
[0158] S202: The server NWDAF sends a registration request message #2 to the NRF.
[0159] Correspondingly, the NRF receives the registration request message #2 from the server NWDAF.
[0160] The registration request message #2 is used to request registration with the network.
[0161] Exemplarily, the registration request message #2 may be an Nnrf_NFManagement_NFRegister_request message, and the registration request message #2 includes configuration parameters (e.g., Server NWDAF profile), where the configuration parameters include one or more of the following: server NWDAF NF type, analysis ID(s), interoperability indication corresponding to the Analytics ID, address information of the server NWDAF, service area, FL capability type information (e.g., FL server), or a time interval for the server NWDAF to support FL.
[0162] It should be understood that both the server NWDAF and the client NWDAF are NWDAFs that include MTLF and can participate in federated learning training.
[0163] Furthermore, the NRF stores configuration parameters of the server NWDAF and the client NWDAF.
[0164] Exemplarily, the NRF stores the Server NWDAF profile and the Client NWDAF profile.
[0165] Optionally, the NRF sends a registration response message #2 to the server NWDAF. Correspondingly, the server NWDAF receives the registration response message #2 from the NRF, indicating that the registration of the server NWDAF is completed.
[0166] S203: The server NWDAF and NRF execute the discovery process of the client NWDAF.
[0167] Step 1: The server NWDAF sends a discovery request message to the NRF.
[0168] Correspondingly, NRF receives the discovery request message from the server NWDAF.
[0169] Exemplarily, the server NWDAF discovers available client NWDAFs in the network by sending a discovery request message to the NRF. For example, the server NWDAF invokes Nnrf_NFDiscovery_Request from a suitably configured NRF within the same PLMN, and carries the NF type of the desired NF instance (e.g., Client NWDAF) in the Nnrf_NFDiscovery_Request. Optionally, it may also carry at least one of the following: the desired service name, the NF type of the server NWDAF (e.g., Server NWDAF), and the desired target NF location. For example, the NRF determines whether to allow the server NWDAF to discover the desired NF instance based on the NF type of the desired NF instance carried in the Nnrf_NFDiscovery_Request.
[0170] Step 2: NRF sends a discovery response message to the server NWDAF.
[0171] Correspondingly, the server NWDAF receives the discovery response message from the NRF.
[0172] The discovery response message may carry one or more client NWDAFs, such as client NWDAF 1, ..., and client NWDAF N, each of which supports FL. For example, the NRF determines a set of matching NF instances based on the Nnrf_NFDiscovery_Request and internal NRF policies, and delivers the NF profiles of the NF instances, such as the client NWDAFs. Exemplarily, the discovery response message may be an Nnrf_NFDiscovery_Response message, and the NF profile of each NF instance may be sent to the server NWDAF via the Nnrf_NFDiscovery_Response message.
[0173] Optionally, if the server NWDAF carries the desired target NF location in step S203, the NRF should not restrict the set of discovered NF instances or NF service instances to the target NF location. For example, if no NF instance or NF service instance can be found for the preferred target NF location, the NRF may provide an NF instance or NF service instance whose location is not the preferred target NF location.
[0174] S204: The server NWDAF sends a token request message to the NRF.
[0175] Correspondingly, NRF receives the token request message from the server NWDAF.
[0176] The token request message is used to request an authorization token from the NRF to request federated learning services from the client NWDAF. In other words, the server NWDAF requests a token from the NRF through the token request message. This token is used to authorize the server NWDAF to request the client NWDAF to provide the FL service corresponding to the analysis ID.
[0177] Exemplarily, the token request message can be an Nnrf_AccessToken_Get Request message, which includes at least one of the following: analysis ID, NF instance ID of client NWDAF, expected client NWDAF service name (e.g., expected NF service name(s), such as FL service corresponding to the analysis ID), expected NF type (e.g., client NWDAF), NF type of client NWDAF and NF type of server NWDAF.
[0178] Optionally, the token request message may also include additional scopes (i.e., requested resources and requested operations on resources), a list of network slice selection assistance information (S-NSSAI) or a list of NSI IDs of the desired client NWDAF instance, the NF Set ID of the desired client NWDAF instance, and at least one item in the S-NSSAI list of NFc.
[0179] It should be noted that this implementation is applicable when the server NWDAF and the client NWDAF belong to the same operator, and is also applicable when the server NWDAF and the client NWDAF belong to different operators, and this application does not make specific limitations.
[0180] S205, NRF authorization, generate token.
[0181] Exemplarily, the NRF performing an authorization check on the server NWDAF may include: the NRF verifying the identity of the server NWDAF and, if the identity verification is successful, verifying whether the server NWDAF has permission to access the requested service. If the server NWDAF has permission, a token is generated, indicating that the service obtained by the server NWDAF using the token is an authorized service, thereby preventing unauthorized use of the service.
[0182] Among them, the NRF's verification of the server NWDAF's identity may include: verifying whether the parameters carried in the token acquisition request (such as the NF type of the server NWDAF) match the server NWDAF's public key certificate or NF configuration information. If they match, the identity authentication is successful, otherwise the verification fails. The NRF's verification of whether the server NWDAF has the authority to access the requested service may include: the NRF determines whether the server NWDAF has the authority to access the requested service based on the service-related parameters carried in the token acquisition request (such as the expected service name), the server NWDAF's NF type and local configuration. For example, the NRF verifies whether the server NWDAF's vendor ID contains the interoperability identifier corresponding to the analysis ID provided by the client NWDAF. If so, the verification is successful, otherwise the verification fails.
[0183] Exemplarily, if the NRF authorization check passes, the NRF generates a token containing claims. The claims include at least one of the NF instance ID of the authorized network element, the NF instance ID of the server NWDAF, the NF type of the client NWDAF, the desired service name, and the expiration time (expires_in). Optionally, the claims may also include at least one of additional scopes (allowed requested resources and requested operations on resources), the S-NSSAI list or NSI ID list of the desired client NWDAF instance, and the NF Set ID of the desired client NWDAF instance.
[0184] Optionally, claims may also include other parameters such as allowed resources, network slice information, "additional scope" information (i.e., allowed resources and allowed resource operations (service operations)), a list of NSSAI or NSI IDs of the intended client NWDAF instance, the NF Set ID of the intended client NWDAF instance, etc.
[0185] For example, if the NRF does not authorize, the NRF refuses to generate the token. Optionally, the NRF may send a reason value to the server NWDAF, indicating that the server NWDAF authorization check failed, that is, the server NWDAF cannot request the client NWDAF to execute the FL process.
[0186] Optionally, the NRF can perform security protection on the generated token, where the security protection can be integrity protection. For example, the NRF uses a shared key to generate a message authentication code (MAC) for the token. The NRF can send the MAC and token together to the server NWDAF. The MAC is used to verify whether the information in the token has been tampered with. Alternatively, the NRF uses a private key to sign the claims, and the client NWDAF can use the signature to verify whether the claims have been tampered with. The specific method of using signatures and MAC values to protect tokens is defined in RFC 7515.
[0187] S206 , the NRF sends a token response message to the server NWDAF.
[0188] Correspondingly, the server NWDAF receives the token response message from the NRF.
[0189] The token response message is used to authorize the server NWDAF to obtain the FL service from the client NWDAF, and the token response message includes a token.
[0190] Optionally, the token response message may also include the validity period of the token. The token can usually be reused within the validity period.
[0191] S207: The server NWDAF sends a service request message to the client NWDAF.
[0192] Correspondingly, the client NWDAF receives the service request message from the server NWDAF.
[0193] The service request message carries a token and an analysis ID, and is used to request the client NWDAF to execute the FL service corresponding to the analysis ID. For example, the service request message may be a service request message.
[0194] S208: The client NWDAF verifies the token and determines whether to join the federated learning.
[0195] Exemplarily, the client NWDAF verifies the token and decides whether to execute the FL service corresponding to the analysis ID. For example, the client NWDAF verifies the integrity of the token by using the NRF's public key to verify the signature or by checking the MAC value with a shared key. If the integrity verification passes, the server NWDAF is then verified to be authorized to obtain the FL service corresponding to the analysis ID. For specific implementation methods, refer to existing protocols.
[0196] S209: The client NWDAF sends a service response message to the server NWDAF.
[0197] Correspondingly, the server NWDAF receives the service response message from the client NWDAF.
[0198] Exemplarily, if the token verification is successful, the client NWDAF sends a service response message to the server NWDAF, indicating its agreement to execute the FL service corresponding to the analysis ID. For example, the service response message may be a service response message. Alternatively, if the client NWDAF fails to verify the token, the client NWDAF may refuse to provide the FL service. Optionally, the client NWDAF may send a reason value to the server NWDAF, indicating that the token verification failed and refusing to execute the FL service corresponding to the analysis ID.
[0199] S210: The server NWDAF starts a federated learning process.
[0200] The specific implementation method can be found in the method shown in FIG4 below, which will not be described here.
[0201] Based on this, the server NWDAF and the client NWDAF perform the FL service corresponding to the analysis ID.
[0202] Figure 3 is a schematic diagram of the process by which an authorization server NWDAF requests a client NWDAF to provide federated learning services. As shown in Figure 3, the process includes the following steps. For parts not fully described, please refer to existing protocols.
[0203] S301, the client NWDAF#1 sends a registration request message #1 to the NRF.
[0204] Correspondingly, the NRF receives the registration request message #1 from the client NWDAF#1.
[0205] S302: The server NWDAF sends a registration request message #2 to the NRF.
[0206] Correspondingly, the NRF receives the registration request message #2 from the server NWDAF.
[0207] It should be understood that both the server NWDAF and the client NWDAF are NWDAFs that include MTLF and can participate in federated learning training.
[0208] Furthermore, the NRF stores configuration parameters of the server NWDAF and the client NWDAF, including, for example, one or more of the following: analysis ID(s), interoperation ID, vendor ID, address information, FL capability type (ie, FL server or FL client), and service area.
[0209] S303: The server NWDAF and NRF execute the discovery process and token request process of the client NWDAF.
[0210] It should be understood that the server NWDAF requests a token from the NRF for each selected client NWDAF (eg, client NWDAF#1 obtained in the discovery process), and the token request message includes one or more of the following parameters: analysis ID, vendor ID, and FL function.
[0211] For the specific implementation of the above steps S201 to S203, reference may be made to the relevant description of steps S201 to S206 of the above method 200.
[0212] S304 , the server NWDAF sends a federated learning preparation request message to the client NWDAF# 1 .
[0213] Correspondingly, the client NWDAF#1 receives the federated learning preparation request message from the server NWDAF.
[0214] Exemplarily, the federated learning preparation request message may be a Federated Learning preparation request message carrying a token and an analysis ID. For example, the server NWDAF uses the Nnwdaf_MLModel training_subscription or Nnwdaf_MLModel training information_request service with the ML preparation flag to send a federated learning preparation request to the FL client NWDAF to check whether the client NWDAF can meet the ML model training requirements (such as analysis ID, ML model interoperability information), available data requirements (a list of event IDs of local data used for training, which may also include dataset statistical properties, a time window for data samples, and a minimum number of data samples), or availability time requirements (the time span required for the FL process).
[0215] S305: Client NWDAF#1 verifies the token and determines whether to join the federated learning group to provide FL services.
[0216] For example, client NWDAF#1 checks whether it can meet the ML model training requirements and / or, if model information is provided in the federated learning preparation request message in step S304, client NWDAF#1 also needs to check whether it can successfully download the model and decide whether to join the federated learning process based on the implementation. Example criteria used by client NWDAF#1 may be based on its availability, computing and communication capabilities, and ML model interoperability information.
[0217] S306 , the client NWDAF#1 sends a federated learning preparation response message to the server NWDAF.
[0218] Correspondingly, the server NWDAF receives the federated learning preparation response message from the client NWDAF#1.
[0219] Exemplarily, the federated learning preparation response message may be a Federated Learning preparation response message, for example, the client NWDAF#1 calls the Nnwdaf_MLModel training_subscription response service operation or the Nnwdaf_MLModel training information_request response service operation to indicate whether to join the federated learning process. If the federated learning process cannot be joined, the client NWDAF#1 may carry a reason value in the federated learning preparation response message, for example, the client NWDAF#1 currently cannot support federated learning, or the client NWDAF#1 is currently overloaded, etc.
[0220] S307: The server NWDAF updates the server NWDAF Profile.
[0221] Optionally, if there are other clients NWDAF online, for example, client NWDAF#2 is registered with NRF, then NRF can notify server NWDAF, and then server NWDAF again requests client NWDAF#2 to join the federated learning group to execute the FL service corresponding to the analysis ID, as shown in the following steps S308-S310. For the specific implementation method, please refer to the relevant description of client NWDAF#1 above.
[0222] S308, client NWDAF#2 registers.
[0223] S309 , the NRF sends a notification message to the server NWDAF. Correspondingly, the server NWDAF receives the notification message from the NRF.
[0224] The notification message is used to indicate that the client NWDAF#2 supports the FL service corresponding to the analysis ID.
[0225] S310 , the server NWDAF and the client NWDAF# 2 perform the above steps S304 - S306 with reference to each other.
[0226] Based on this, multiple client NWDAFs participate in providing the server NWDAF with FL services corresponding to the analysis IDs.
[0227] With reference to Figures 1 and 2 above, the server NWDAF can initiate a federated learning process, that is, the server NWDAF and the client NWDAF can perform federated learning training. For the specific federated learning training process, please refer to the relevant description in Figure 4 below.
[0228] FIG4 is a flow chart of a method for executing federated learning. As shown in FIG4 , the method includes the following steps. For parts not described in detail, reference may be made to existing protocols.
[0229] S401, the consumer sends a subscription request message #1 to the server NWDAF.
[0230] Correspondingly, the server NWDAF receives the subscription request message #1 from the consumer.
[0231] The subscription request message #1 is used to subscribe to ML model provisioning or training. For example, a consumer (e.g., NWDAF with AnLF or NWDAF with MTLF) uses the Nnwdaf_MLModelProvision service to send a subscription request message #1, such as "subscription request for ML model provisioning / training," to the server NWDAF to retrieve the ML model.
[0232] The subscription request message #1 includes one or more of the following: an analysis ID, an ML model metric (e.g., ML model accuracy), an accuracy reporting interval, and a predetermined status (an ML model accuracy threshold or a time when an ML model is required). It should be understood that the ML model accuracy threshold can be used to indicate the target ML model accuracy during training. When the ML model accuracy threshold is reached during training, the server NWDAF can stop the training process. If the consumer provides a time when an ML model is required, the server NWDAF can consider this information to determine the maximum response time of its client NWDAF.
[0233] S402: The server NWDAF determines the client NWDAF(s).
[0234] For specific implementations, reference may be made to the related descriptions of the above method 200 or 300. For example, the client NWDAF(s) determined by the server NWDAF include: client NWDAF1, ..., client NWDAF N.
[0235] S403: The server NWDAF sends a subscription request message #2 to the client NWDAF(s).
[0236] Correspondingly, the client NWDAF(s) receives the subscription request message #2 from the server NWDAF.
[0237] Exemplarily, the subscription request message #2 may be Nnwdaf_MLModelTraining_Subscribe, for example, the server NWDAF sends Nnwdaf_MLModelTraining_Subscribe or Nnwdaf_MLModelTrainingInfo_Request to the client NWDAF(s), requesting to perform local model training.
[0238] The subscription request message #2 carries one or more of the following: initial federated learning parameters provisioning, ML model metrics, initial ML model, or maximum response time, where the maximum response time refers to the maximum response time for the client NWDAF to report temporary local ML model information to the server NWDAF.
[0239] S404: Optionally, the client NWDAF(s) collects data.
[0240] Illustratively, if the client NWDAF does not already have local data available, each client NWDAF may collect its local data from the NF (data provider) using the current mechanism in TS 23.288.
[0241] S405 , the client NWDAF(s) sends a subscription response message #2 to the server NWDAF.
[0242] Correspondingly, the server NWDAF receives the subscription response message #2 from the client NWDAF(s).
[0243] For example, subscription response message #2 may be Nnwdaf_MLModelTraining_Notify, which is used to report local model training information. For example, during federated learning training, each client NWDAF trains the initial ML model provided by the server NWDAF based on its own data and reports the temporary local ML model information to the server NWDAF in Nnwdaf_MLModelTraing_Notify or Nnwdaf_MLModelTraingInfo_Response.
[0244] Optionally, Nnwdaf_MLModelTraining_Notify or Nnwdaf_MLModelTrainingInfo_Response may also include local ML model metrics calculated by the client NWDAF(s) and training input data information (e.g., the area covered by the dataset, sampling ratio, maximum / minimum values of each dimension of the data, etc.).
[0245] Optionally, the ML model is sent from the client NWDAF(s) to the server NWDAF during the federated learning training process. This is the information required by the server NWDAF to build an aggregate model based on the locally trained ML model. If the client NWDAF cannot complete the training of the temporary local ML model within the maximum response time provided by the server NWDAF, the client NWDAF(s) may send a delay event notification, including a delay event indication, an optional reason code (e.g., local ML model training failed, or more time is required for local ML model training), and the expected time for the client NWDAF to complete the training before the maximum response time elapses.
[0246] S406, optionally, the server NWDAF sends a subscription request message #3 to the client NWDAF(s).
[0247] Correspondingly, the client NWDAF(s) receives the subscription request message #3 from the server NWDAF.
[0248] Exemplarily, the subscription response message #3 may be Nnwdaf_MLModelTraining_Notify, carrying the extended response time and / or the current iteration round ID. For example, if the server NWDAF receives a notification / response from the client NWDAF(s) that the training cannot be completed within the maximum response time, the server NWDAF may send an ExtendedMaximumResponseTime_MLModelTrainingInfo_Request to the client NWDAF in Nnwdaf_MLModelTraining_Subscribe or Nnwdaf. Prior to this request, the client NWDAF needs to report the temporary local ML model information to the server NWDAF. Otherwise, the server NWDAF may instruct the client NWDAF to skip reporting for this iteration. The client NWDAF includes the current iteration round ID in the request message to indicate that this request is for modifying the training parameters of the current iteration round.
[0249] Optionally, the server NWDAF may notify the client NWDAF to stop ML model training by sending a termination request and report the current local ML model update.
[0250] S407: The client NWDAF performs model aggregation.
[0251] Illustratively, the client NWDAF aggregates all local ML model information retrieved in step S405 to update the global ML model. Optionally, the server NWDAF can also calculate global ML model metrics, for example, based on local ML model metrics or by applying the global model on a validation dataset (if available). The server NWDAF can update the global ML model each time the client NWDAF provides updated local ML model information, or the server NWDAF can decide to wait for local ML model information from all client NWDAFs before updating the global ML model.
[0252] If the server NWDAF provides a maximum response time for the client NWDAF to provide temporary local ML model information in step S403, or provides an extended maximum response time in step S406, the server NWDAF decides to wait for client NWDAFs that have not yet provided their temporary local ML models within the (extended) maximum response time, or to aggregate only the retrieved local ML model information instances to update the global ML model. The server NWDAF makes this decision based on the notification / response from the client NWDAF, or if no notification is received, based on the local configuration.
[0253] S408, optionally, the client NWDAF sends an update message to the consumer.
[0254] Correspondingly, the consumer receives update messages from the client NWDAF.
[0255] The update message is used to indicate the current ML training status to the consumer. For example, in response to step S401, the client NWDAF sends the Nnwdaf_MLModelProvision_Notify message to the consumer to dynamically update the global ML model metrics to the consumer periodically (e.g., after a certain number of training rounds or every 10 minutes) or when certain predetermined states are reached (e.g., when the ML model accuracy threshold is reached or the training time expires).
[0256] S409, optionally, the consumer sends a subscription request message #4 to the server NWDAF.
[0257] Correspondingly, the server NWDAF receives a subscription request message #4 from the consumer, wherein the subscription request message #4 is used to modify the subscription to update or terminate.
[0258] For example, the consumer determines whether the current model can meet the requirements, for example, whether the global ML model metrics are satisfactory to the consumer, and decides to stop or continue the training process. The user can re-call the Nnwdaf_MLModelProvision_Subscribe service operation used in step S401 to stop or continue the training process.
[0259] S410, optionally, the server NWDAF updates or terminates the federated learning training process.
[0260] Exemplarily, the server NWDAF updates or terminates the current federated learning training process based on the subscription request message #4 sent by the consumer in step S409. Optionally, if the server NWDAF receives a request to stop the federated training process in step S409, the following steps S411 and S412 are skipped.
[0261] S411, optionally, the server NWDAF sends aggregation model information to the client NWDAF(s).
[0262] Correspondingly, the client NWDAF(s) receives the aggregation model information from the server NWDAF.
[0263] In other words, if the federated learning training process continues, the server NWDAF will determine the client NWDAF and send Nnwdaf_MLModelTraingInfo_Request including the aggregated ML model information to the selected client NWDAF(s) for the next round of federated training.
[0264] S412, optionally, the client NWDAF(s) updates the local model according to the aggregated model information.
[0265] Exemplarily, each client NWDAF updates its local ML model according to the aggregated ML model information distributed by the server NWDAF in step S411 .
[0266] It should be noted that the above steps S404 to S412 are repeated until a training termination condition (for example, a maximum number of iterations, or a result of the loss function is lower than a threshold) is reached.
[0267] When the federated training process is completed, the server NWDAF requests the client NWDAF(s) to terminate the federated learning training process. In one implementation, the server NWDAF calls the Nnwdaf_MLModelTraing_Unsubscribe service with the reason code "The federated learning process has been completed" and optionally uses the final aggregated ML model information. The client NWDAF(s) then terminates local model training. If the final aggregated ML model information is received from the server NWDAF, the client NWDAF(s) may store the aggregated ML model information for further use.
[0268] As a machine learning technology in the core network, federated learning FL supports multiple participants (for example, server NWDAF and client NWDAF) to conduct local training without exchanging training data and exchange model parameters through a secure mechanism, thereby achieving the effect of collaborative training. For example, during the federated learning process, the client NWDAF can train a local model based on local data and send the local model information to the server NWDAF. The server NWDAF aggregates the local models obtained from multiple client NWDAFs, and then sends the aggregated model information to each client NWDAF participating in the federated learning, and continues to train the model based on local data, iterating repeatedly until the federated learning is completed and a global model is obtained. At this point, the server NWDAF can send the global model generated by federated learning to the client NWDAF, and the client NWDAF can store the information of the global model for further use.
[0269] However, the applicant discovered that in the current process, only the authority of the server NWDAF to obtain the model from the client NWDAF is checked, such as step S205 of the above method 200 and step S303 of the method 300, to ensure the security of the information on the client NWDAF side. However, the particularity of the federated learning scenario is ignored, that is, not only will the server NWDAF obtain the model from the client NWDAF, but the server NWDAF may also send the initial model and / or the global model generated by federated learning to the client NWDAF. Some client NWDAFs support participation in federated learning and allow the server NWDAF to obtain the model from the client NWDAF, but do not have the authority to obtain the global model from the server NWDAF. In this case, if the server NWDAF directly sends the global model to the client NWDAF, it will lead to the leakage of the global model, and even security issues such as the loss of model property assets.
[0270] In view of this, the present application provides a secure communication method and communication device. In the process of obtaining the first token, the first network element not only determines that the federated learning server (for example, server NWDAF) is allowed to obtain the first model corresponding to the first analysis identifier from the client device (for example, client NWDAF), but also determines that the client device is allowed to obtain the second model from the federated learning server to cope with the special scenarios of federated learning, so that the federated learning server sends the first model to the client device when the client device is allowed to obtain the first model from the federated learning server, thereby avoiding model leakage and reducing potential security risks.
[0271] To facilitate understanding of the above embodiments provided in this application, the following points are explained:
[0272] First, in this application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments based on their internal logical relationships.
[0273] Second, in this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Wherein a, b and c can be single or multiple, respectively.
[0274] Third, throughout this application, the terms "first," "second," and various numerical references (e.g., #1, #2, etc.) are used to distinguish between different messages for ease of description and are not intended to limit the scope of the embodiments of this application. For example, they are used to distinguish between different messages, rather than to describe a specific order or precedence. It should be understood that the terms described in this manner are interchangeable, where appropriate, to enable description of scenarios beyond the embodiments of this application.
[0275] Fourth, in this application, the terms "comprise" and "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or are inherent to these processes, methods, products or apparatuses.
[0276] Fifth, in this application, "used to indicate" can include being used for direct indication and being used for indirect indication. When describing that a certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, and does not necessarily mean that the indication information carries A.
[0277] The indication methods involved in the embodiments of this application should be understood to encompass various methods that enable the party to be indicated to obtain information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or timing of these sub-information can be the same or different. This application does not limit the specific transmission method.
[0278] In the embodiments of the present application, the "indication information" may be an explicit indication, i.e., a direct indication via signaling, or may be obtained based on parameters indicated by the signaling, in combination with other rules, other parameters, or by deduction. It may also be an implicit indication, i.e., based on a rule or relationship, or based on other parameters, or by deduction. This application does not impose specific limitations on this.
[0279] Sixth, in this application, "protocol" may refer to a standard protocol in the field of communications, such as the 5G protocol, the NR protocol, and related protocols used in future communication systems, and this application does not limit this. "Predefined" may include pre-definition. For example, protocol definition. "Preconfiguration" can be implemented by pre-saving corresponding codes, tables, or other methods that can be used to indicate relevant information in the device, and this application does not limit its specific implementation method.
[0280] Seventh, in this application, "storage" may refer to storage in one or more memories. The one or more memories may be provided separately or integrated into an encoder or decoder, a processor, or a communication device. The one or more memories may also be provided in part separately and in part integrated into a decoder, a processor, or a communication device. The memory may be any type of storage medium and is not limited in this application.
[0281] Eighth, in this application, "communication" can also be described as "data transmission", "information transmission", "data processing", etc. "Transmission" includes "sending" and "receiving".
[0282] Ninth, in this application, configuration may refer to signaling configuration, and may also be described as configuration signaling. For example, signaling configuration may be configured by a network device sending signaling, and these signalings may be radio resource control (RRC) messages, downlink control information (DCI), or system information blocks (SIBs). For another example, signaling configuration may be pre-configured, where the pre-configuration is to define or configure the values of corresponding parameters in advance in a protocol manner, and may be stored in the device during communication, and this application does not limit this.
[0283] 10. In this application, "model" may include an "initial model or base model," a "first model," and a "second model." The "initial model" refers to the model that the federated learning server sends to the client device before the federated learning process begins, for use in federated learning training. The "first model" refers to the local model obtained (or generated) by the client server during the federated learning process by training the initialization model based on local data. The client device sends information about the first model to the federated learning server (including but not limited to data that the client device is not allowed to share with others due to data privacy, data security, or data access rights). The "second model" refers to the global model, or initial model or base model, obtained by the federated learning server by aggregating the first models reported by multiple client devices. Optionally, the second model may also be provided to the client for repeated training iterations, i.e., the federated learning server sends information about the aggregated global model to each client device to facilitate the next round of federated learning training. In this application, the first model is generated by the client device and used by the federated learning server to generate the second model; and / or the second model is provided by the federated learning server and used to generate the first model.
[0284] In this application, "model" can be replaced by "model information", where "model information" may include one or more of the following: model parameters, model ID, model address information (such as IP address), or model structure, etc. Therefore, the interaction between the federated learning server domain and client devices regarding the model in the embodiment of this application can be understood as interaction regarding model parameters, model ID, model address information, or model structure.
[0285] The secure communication method provided by the embodiment of the present application will be described in detail below with reference to the accompanying drawings. The embodiment provided by the present application can be applied to the communication system shown in Figure 1 above. For example, the embodiment of the present application can be executed by a first network element (e.g., NRF), a federated learning server (e.g., server NWDAF), or a client device (e.g., client NWDAF), or it can also be executed by a chip or circuit of the first network element, the federated learning server, or the client device, or it can also be implemented by a logic module or software that can implement all or part of the functions of the communication device, and the present application does not limit this.
[0286] Figure 5 is a flow chart of a communication method 500 provided in an embodiment of the present application. As shown in Figure 5, the first network element, the federated learning server, or the client device is used as the execution subject to interact. The method includes one or more of the following steps. For parts not fully described, reference can be made to existing protocols.
[0287] S510: The federated learning server sends a token request message to the first network element.
[0288] Correspondingly, the first network element receives a token request message from the federated learning server.
[0289] In this application, the first network element may be an NRF, NEF, or other network entity. For example, the first network element supports permission checking or authorization for a federated learning server and / or a client device. Furthermore, the first network element may also support registration of the federated learning server and / or the client device. Therefore, the first network element may also be referred to as a registration function network element, an authorization function network element, or a storage function network element.
[0290] In this application, the federated learning server can be a server NWDAF, that is, a server NWDAF that includes MTLF, an NWDAF with federated learning server capabilities. For example, the federated learning server supports at least one of the following: discovering client devices; requesting the client devices to perform local model training and report local model information, specifically, sending a base model or an initial model to the client devices, thereby requesting the client devices to use local data to train the base model or the initial model to obtain a local model, and reporting local model information; aggregating local model information from client devices and generating a global model; aggregating model information from client devices after base model training and generating a global model; and returning the global model to the client devices to implement iterative training.
[0291] In the present application, the client device can be replaced by a federated learning client, and the client device can be a client NWDAF, that is, a Client NWDAF including MTLF, an NWDAF with federated learning client capabilities. For example, the client device supports at least one of the following: using available local data for federated learning training to generate local model information, specifically, receiving information about a base model or initial model sent by a federated learning server, and training the base model or initial model using available local data to generate local model information; reporting information about the trained local model to the federated learning server; reporting information about the trained base model to the federated learning server; receiving information about the global model from the federated learning server, and repeating training iterations.
[0292] It should be noted that the federated learning in this application may include at least one of the following: network performance analysis, artificial intelligence (AI) model training, network service quality analysis, network abnormal behavior detection, face recognition, or cross-institutional medical data analysis and disease prediction, etc.
[0293] Exemplarily, the token request message may be an Nnrf_AccessToken_Get Request message, which is used to request acquisition of a token (e.g., a first token). The federated learning server requests that the token request message include a first analysis identifier (analysis ID), an identifier of the federated learning server, and an identifier of the client device. The specific meanings are as follows.
[0294] (1) First analysis identifier;
[0295] For example, the first analysis identifier can be used to indicate a specific function or service associated with the model, that is, the model can be used to perform the specific function or service, or in other words, the model supports the execution of the specific function or service corresponding to the first analysis identifier. The specific function or service may be facial recognition or network performance analysis, for example.
[0296] (2) Identification of the federated learning server;
[0297] Exemplarily, the identifier of the federated learning server can be the ID of the federated learning server, the NF instance ID of the federated learning server (e.g., NF Instance Id(s) of the NF service consumer), the NF instance ID of a network element that has a federated learning server function or supports a federated learning server function (e.g., NF Instance Id(s) of the NWDAF), the address letter of the federated learning server, or other information that can identify the federated learning server.
[0298] (3) identification of the client device;
[0299] Exemplarily, the identification of the client device can be the ID of the client device, the NF instance ID of the client device (e.g., NF Instance Id(s) of the NF producer consumer), the NF instance ID of a network element having a federated learning client function or supporting a federated learning client function (e.g., NF Instance Id(s) of the NWDAF), the address information of the client device, or other information that can identify the client device.
[0300] Optionally, the token request message may also include one or more of the following: the name of the first service (service name), the NF type of the client device, the NF type of the federated learning server, the equipment vendor identifier of the client device, the equipment vendor identifier of the federated learning server, the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, the second interoperability identifier corresponding to the first analysis identifier supported by the client device, the federated learning capability type (FL capability type), additional scope (i.e., the requested resources and the requested operations on the resources), etc.
[0301] It should be understood that the parameters related to the client device carried in the token request message can be obtained through a discovery process (for example, the federated learning server discovers the client device through the first network element), thereby obtaining configuration information associated with the client device. The configuration information of the client device includes the first analysis identifier and / or the federated learning capability type. The specific implementation of the discovery process can be found below and is not described here. Alternatively, the parameters related to the client device can be obtained from a third party, such as pre-configured in the federated learning server by the network administrator.
[0302] Among them, the name of the first service can be Nnwdaf_MLModelTraining service, such as Nnwdaf_MLModelTraining_Subscribe, the first interoperability identifier is used in the following step S502a for the first network element to determine that the client device is allowed to obtain the second model from the federated learning server, and the second interoperability identifier is used in the following step S502b for the first network element to determine that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, and then generate a first token and send the first token to the federated learning server. The federated learning capability type can be FL Client or FL Server.
[0303] Optionally, the first network element may determine one or more of the following based on one or more of the parameters in the token request message (for example, the identifier of the federated learning server, the identifier of the client device, and the analysis identifier): the device vendor identifier of the client device, the device vendor identifier of the federated learning server, the second interoperability identifier corresponding to the first analysis identifier supported by the client device, and the second interoperability identifier corresponding to the first analysis identifier supported by the federated learning server. Specifically, the first network element determines the NF profile of the federated learning server based on the identifier of the federated learning server, where the NF profile includes the device vendor identifier of the federated learning server and the second interoperability identifier corresponding to the first analysis identifier supported by the federated learning server. The first network element determines the NF profile of the client device based on the identifier of the client device, where the NF profile includes the device vendor identifier of the client device and the second interoperability identifier corresponding to the first analysis identifier supported by the client device.
[0304] S520: After determining that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, and the client device is allowed to obtain the second model from the federated learning server, the first network element sends a first token to the federated learning server.
[0305] Accordingly, the federated learning server receives the first token from the first network element.
[0306] The first token may indicate that the client device is allowed to obtain the second model from the federated learning server.
[0307] It should be understood that, in this case, the first token not only indicates that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, but also indicates that the client device is allowed to obtain the second model from the federated learning server.
[0308] In one implementation, before the first network element sends the first token to the federated learning server, the method 500 may further include the following steps S520a and S520b.
[0309] S520a: The first network element determines whether the client device is allowed to obtain the second model from the federated learning server.
[0310] In the first example, the first network element determines whether the device vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, or in other words, the first network element determines whether the device vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server.
[0311] In this application, the term "vendor ID" can be replaced by a manufacturer ID, supplier ID, provider ID, or device manufacturer ID, etc., to identify a particular vendor that provides (or produces) client devices. It should be understood that a vendor can correspond to one or more network elements (e.g., an NWDAF including a MTLF). Alternatively, the term "vendor" can be replaced by a network element produced by the vendor, a device produced by the vendor, or a network element corresponding to the vendor.
[0312] In the present application, the first interoperability identifier may include a list of vendor identifiers, wherein the vendors in the vendor identifier list are allowed to obtain models from the federated learning server, or the vendors in the vendor identifier list are allowed to retrieve or use the models provided by the federated learning server, or the vendors in the vendor identifier list can obtain models from the federated learning server, or the vendors in the vendor identifier list have the authority to obtain models from the federated learning server, or the vendors in the vendor identifier list can retrieve or use the models provided by the federated learning server, or the vendors in the vendor identifier list can support or have the authority to use the federated learning service (i.e., the first service) corresponding to the analysis ID, or the vendors in the vendor identifier list can obtain the federated learning service corresponding to the analysis ID, or the vendors in the vendor identifier list have the authority to use the federated learning service provided by the federated learning server. The first interoperability identifier also indicates that the federated learning server supports the vendors requesting the model provided by the federated learning server for the client devices corresponding to the vendors in the vendor identifier list.
[0313] In this application, the phrase "the equipment vendor is allowed to..." or "the equipment vendor has the authority to use..." can be understood as meaning that the network elements or devices produced by the equipment vendor are allowed to... or the network elements or devices produced by the equipment vendor have the authority to use...
[0314] For example, if the vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, or in other words, the vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, the first network element can determine that the client device is allowed to obtain the second model from the federated learning server.
[0315] For example, if the vendor identifier of the client device is not included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, or in other words, the vendor identifier of the client device is not included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, the first network element can determine that the client device is not allowed to obtain the second model from the federated learning server.
[0316] That is, the first network element determines that the client device can obtain the second model from the federated learning server by, specifically, determining that the client device's vendor identifier is included in the list of vendor identifiers supported by the federated learning server. Conversely, the first network element determines that the client device cannot obtain the second model from the federated learning server by, specifically, determining that the client device's vendor identifier is not included in the list of vendor identifiers supported by the federated learning server. This determination ensures that the second model is sent to client devices with model access permission, thus preventing the second model from being sent to client devices without model access permission, which could result in the leakage of model information and increased security risks such as loss of model resources.
[0317] In the second example, the first network element determines whether the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, or in other words, the first network element determines whether the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server contains the second interoperability identifier corresponding to the first analysis identifier supported by the client device.
[0318] That is, the first network element determines that the client device can obtain the second model from the federated learning server by, specifically, determining that the list of vendor identifiers corresponding to the first analysis ID supported by the client device is included in the list of vendor identifiers supported by the federated learning server. Conversely, the first network element determines that the client device cannot obtain the second model from the federated learning server by, specifically, determining that the list of vendor identifiers corresponding to the first analysis ID supported by the client device is not included in the list of vendor identifiers supported by the federated learning server. This determination allows the second model to be sent to client devices with model access permission, preventing the leakage of model information and reducing security risks such as loss of model resources. Furthermore, this prevents the client device from leaking the second model to other consumers who do not have model access permission, doubly ensuring the security of the model's assets.
[0319] In a third instance, the first network element determines whether the equipment vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, and / or determines whether the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server.
[0320] That is, the first network element determines that the client device can obtain the second model from the federated learning server by, specifically, determining that the client device's vendor identifier is included in the list of vendor identifiers supported by the federated learning server, and / or determining that the list of vendor identifiers corresponding to the first analysis ID supported by the client device is included in the list of vendor identifiers supported by the federated learning server. Conversely, the first network element determines that the client device cannot obtain the second model from the federated learning server by, specifically, determining that the client device's vendor identifier is not included in the list of vendor identifiers supported by the federated learning server, and / or determining that the list of vendor identifiers corresponding to the first analysis ID supported by the client device is not included in the list of vendor identifiers supported by the federated learning server. Through the above determination, the second model is sent to client devices with model access permission, avoiding the leakage of model information and reducing security risks such as loss of model resources. At the same time, the client device is prevented from leaking the second model to other consumers who do not have model access permission, thereby doubly protecting the model's asset security.
[0321] S520b: The first network element determines whether the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device.
[0322] In the first example, the first network element determines that the device vendor identifier of the federated learning server is included in the second interoperability identifier corresponding to the first analysis identifier supported by the client device, or in other words, the first network element determines that the second interoperability identifier corresponding to the first analysis identifier supported by the client device includes the device vendor identifier of the federated learning server.
[0323] In the present application, the second interoperability identifier may include a list of vendor identifiers, wherein the vendors in the vendor identifier list are allowed to obtain models from the client device, or the vendors in the vendor identifier list are allowed to retrieve or use models provided by the client device, or the vendors in the vendor identifier list can obtain models from the client device, or the vendors in the vendor identifier list have the authority to obtain models from the client device, or the vendors in the vendor identifier list can retrieve or use models provided by the client device, or the vendors in the vendor identifier list can support or have the authority to use the federated learning service (i.e., the first service) corresponding to the analysis ID, or the vendors in the vendor identifier list can obtain the federated learning service corresponding to the analysis ID, or the vendors in the vendor identifier list have the authority to use the federated learning service provided by the federated learning server. The second interoperability identifier also indicates that the client device supports the vendor to request the model provided by the client device for the federated learning server corresponding to the vendor in the vendor identifier list.
[0324] In this application, "the equipment vendor is allowed" or "the equipment vendor has" etc. can be understood as the network elements or equipment produced by the equipment vendor being allowed.
[0325] For example, if the vendor identifier of the federated learning server is included in the first interoperability identifier corresponding to the first analysis identifier supported by the client device, or in other words, the first interoperability identifier corresponding to the first analysis identifier supported by the client device includes the vendor identifier of the federated learning server, the first network element can determine that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device.
[0326] For example, if the vendor identifier of the federated learning server is not included in the first interoperability identifier corresponding to the first analysis identifier supported by the client device, or in other words, the vendor identifier of the federated learning server is not included in the first interoperability identifier corresponding to the first analysis identifier supported by the client device, the first network element may determine that the federated learning server is not allowed to obtain the first model corresponding to the first analysis identifier from the client device.
[0327] That is, the first network element determines that the federated learning server is permitted to obtain the first model corresponding to the first analysis identifier from the client device. Specifically, this may be done by determining that the vendor identifier of the federated learning server is included in the list of vendor identifiers supported by the client device. Conversely, the first network element determines that the federated learning server is not permitted to obtain the first model corresponding to the first analysis identifier from the client device. Specifically, this may be done by determining that the vendor identifier of the federated learning server is not included in the list of vendor identifiers supported by the client device. This determination ensures that the first model is sent to the federated learning server with model acquisition permission, thus preventing the first model from being sent to other consumers without model acquisition permission, which could result in the leakage of model information and increase security risks such as loss of model resources.
[0328] In the second example, the first network element determines that the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server is included in the second interoperability identifier corresponding to the first analysis identifier supported by the client device, or in other words, the first network element determines that the second interoperability identifier corresponding to the first analysis identifier supported by the client device includes the first interoperability identifier of the federated learning server.
[0329] That is, the first network element determines that the federated learning server is permitted to obtain the first model corresponding to the first analysis identifier from the client device. Specifically, this may be done by determining that the federated learning server is permitted to obtain the first model corresponding to the first analysis identifier from the client device. Specifically, this may be done by determining that the list of vendor identifiers supported by the client device is included in the list of vendor identifiers supported by the federated learning server. Conversely, the first network element determines that the federated learning server is not permitted to obtain the first model corresponding to the first analysis identifier from the client device. Specifically, this may be done by determining that the list of vendor identifiers supported by the client device is not included in the list of vendor identifiers supported by the federated learning server. Through this determination, the first model is sent to the federated learning server with model acquisition permission, avoiding the leakage of model information and reducing security risks such as loss of model resources. At the same time, this prevents the federated learning server from leaking the first model to other consumers who do not have model acquisition permission, thereby doubly protecting the model's asset security.
[0330] Therefore, based on steps S520a and S520b above, the first network element determines that the client device is permitted to obtain the second model from the federated learning server, including but not limited to the two examples above, and the first network element determines that the federated learning server is permitted to obtain the first model corresponding to the first analysis identifier from the client device, including but not limited to the two examples above. It should be understood that the implementations provided above are merely examples for ease of understanding and do not exclude other implementations. The various examples above may be implemented independently or in combination, and this application does not limit the manner in which they are combined. For example, the first network element may determine that the client device and the federated learning server have permission to obtain models from each other through the first example of step S520a and the second example of step S520b; for another example, the first network element may determine that the client device and the federated learning server have permission to obtain models from each other through the second example of step S520a and the first example of step S520b; for another example, the first network element may determine that the client device and the federated learning server have permission to obtain models from each other through the first and second examples of step S520a and the first example of step S520b, etc.
[0331] It should be noted that this application does not specifically limit the order in which the above steps S520a and S520b are executed.
[0332] Below, an example is given for explaining the triggering condition in which the first network element determines that the client device is allowed to obtain the second model from the federated learning server.
[0333] (1) The first network element determines, based on an identifier of the federated learning server and / or an identifier of the client device, that the federated learning server and / or the client device supports federated learning.
[0334] For example, the first network element can determine the NF instance identifier (e.g., NFc Instance ID) of the federated learning server based on the identifier of the federated learning server (e.g., NF service consumer) carried in the token request message, and then determine the NFc Profile (also known as configuration information) of the federated learning server, and determine that the federated learning server supports federated learning based on the parameters or information in the NFc Profile, for example, the federated learning server is an NWDAF that includes MTLF.
[0335] For another example, the first network element can determine the NF instance identifier (e.g., NFp Instance ID) of the client device based on the identifier of the client device (e.g., NF producer consumer) carried in the token request message, and then determine the NFp Profile of the client device, and determine that the client device supports federated learning based on the parameters in the NFp Profile, for example, the client device is an NWDAF that includes MTLF.
[0336] That is, the first network element determines that the federated learning server and / or the client device supports federated learning based on the identifier of the federated learning server and / or the identifier of the client device, thereby triggering the first network element to determine whether the client device is allowed to obtain the second model from the federated learning server, that is, triggering the execution of the relevant steps of the above 502.
[0337] (2) the first network element determines, based on information about the first service and / or the federated learning capability type carried in the token request message, that the token request message is associated with federated learning, and that the first service is used for performing federated learning between the federated learning server and the client device;
[0338] It should be understood that when the first service is used for federated learning, the first service enables the federated learning server NWDAF to enable the federated learning process, obtain information of the local ML model (i.e., the first model) and the FL training status report from the client device NWDAF, and then provide information of the global ML model (i.e., the second model) to the client device NWDAF.
[0339] It should be understood that when the first service is used for federated learning, the first service can enable the federated learning server NWDAF to initiate a federated learning process, optionally send an initial model (i.e., the second model) to the client device, and obtain information about the local ML model (i.e., the first model) and the FL training status report from the client device NWDAF. Here, the local model is obtained by the client using local data to train the initial model. Subsequently, information about the global ML model (i.e., the second model) is provided to the client device NWDAF.
[0340] Optionally, the federated learning server NWDAF may also use the first service to check whether the client device can meet the ML model training requirements in the federated learning process; or, the federated learning server NWDAF may also use the first service to request the client device to calculate and provide the model accuracy of the global ML model.
[0341] For example, the information of the first service can be the name of the first service (such as Service name). The first network element can determine that the first service is an ML model training subscription based on the Service name = ML model Training Subscribe / Nnwdaf_MLModelTrainingInfo carried in the token request message, that is, it can be determined that the token request message is associated with federated learning, so it can be determined that the token request message is used by the federated learning server to request the first network element to authorize an access token for federated learning. It can be understood that the ML model Training Subscribe / Nnwdaf_MLModelTrainingInfo service is currently only used in federated learning, so it can be determined that the token request message is associated with federated learning.
[0342] For another example, the federated learning capability type (FL capability type) can be FL Server or FL Client, which is used to indicate a federated learning server or client device. The first network element can determine that the token request message is associated with federated learning based on the FL capability type = FL Client carried in the token request message, and therefore can determine that the token request message is used by the federated learning server to request the first network element to authorize an access token for federated learning.
[0343] For another example, the first network element can determine that the token request message is associated with federated learning based on other IEs related to federated learning carried in the token request message, and therefore can determine that the token request message is used by the federated learning server to request the first network element to authorize an access token for federated learning.
[0344] That is, the first network element determines that the token request message is associated with federated learning based on the information of the first service and / or the federated learning capability type carried in the token request message, thereby triggering the first network element to determine whether the client device is allowed to obtain the second model from the federated learning server.
[0345] (3) The first network element determines, based on the first indication information, that the federated learning server sends the second model to the client device.
[0346] Among them, the first indication information indicates that the second model is sent to the client device. It can be understood that the first indication information indicates that the federated learning server supports sending the second model to the client device, or that the first indication information indicates that the federated learning server is about to send the second model to the client device, or that the first indication information indicates that the federated learning server will send the second model to the client device, or that the first indication information indicates that the federated learning server can send the second model to the client device.
[0347] Optionally, the first indication information may be carried in the above-mentioned token request message, or may be included in the configuration information of the federated learning server, such as the NF Profile of the federated learning server.
[0348] That is, the first network element is triggered to determine whether the client device is allowed to obtain the second model from the federated learning server based on the fact that the federated learning server will (or will / support / can) send the second model to the client device.
[0349] (4) The first network element determines, based on the second indication information, that the client device desires to obtain the second model.
[0350] The second indication information indicates that the client device desires to obtain the second model. It can be understood that the second indication information instructs the client device to request to obtain the second model.
[0351] Optionally, the second indication information may be carried in the above-mentioned token request message, or may be included in the configuration information of the client device, such as the NF Profile of the client device.
[0352] That is, the first network element obtains the second model according to the client device's expectation (or request), thereby triggering the first network element to determine whether the client device is allowed to obtain the second model from the federated learning server.
[0353] Optionally, the action of "determining" in the four examples provided above may be executed or not. For example, in example (1), the first network element determines that the client device is allowed to obtain the second model from the federated learning server based on the identifier of the federated learning server and / or the identifier of the client device; for example, in example (2), the first network element determines that the client device is allowed to obtain the second model from the federated learning server based on the information of the first service and / or the federated learning capability type carried in the token request message; for example, in example (3), the first network element determines that the client device is allowed to obtain the second model from the federated learning server based on the first indication information; for example, in example (4), the first network element determines that the client device is allowed to obtain the second model from the federated learning server based on the second indication information. That is, at least one of the identifier of the federated learning server and / or the identifier of the client device, the information of the first service and / or the federated learning capability type, the first indication information or the second indication information can serve as a trigger condition for the first network element to determine that the client device is allowed to obtain the second model from the federated learning server.
[0354] It should be understood that the implementations provided above are merely examples for ease of understanding and do not exclude other implementations. The various implementations described above may be implemented independently or in combination, and this application does not limit this. For example, the first network element may determine, based on the federated learning capability type and the second indication information, that the client device is permitted to obtain the second model from the federated learning server.
[0355] Optionally, after the first network element determines that the client device is allowed to obtain the second model from the federated learning server, the method may further include the following step S520c.
[0356] S520c: The first network element sends third instruction information to the federated learning server.
[0357] Correspondingly, the federated learning server receives third indication information from the first network element.
[0358] The third indication information indicates that the client device is allowed to obtain the second model from the federated learning server.
[0359] Optionally, the third indication information may be carried in the first token, that is, sent to the federated learning server in step S520, or the third indication information may not be carried in the first token, which is not limited in this application.
[0360] It should be noted that, in the case where the third indication information is not carried in the first token, this application does not limit the timing and method of sending the first token and the third indication information.
[0361] In the first example, the first network element may be that when it is determined that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, the first network element sends a first token to the federated learning server, and when it is determined that the client device is allowed to obtain the second model from the federated learning server, the first network element sends third indication information to the federated learning server, that is, the first token and the first indication information can be sent separately.
[0362] In the second example, the first network element may send the first token and the third indication information to the federated learning server when it determines that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, and the client device is allowed to obtain the second model from the federated learning server, that is, the first token and the first indication information may be sent at the same time.
[0363] Below, examples are provided for the method of obtaining the first analysis identifier, the second analysis identifier, the device vendor identifier of the federated learning server, and the device vendor identifier of the client device involved in the above steps S510 and S520, as well as the method of obtaining the configuration information (NF Profile) of the federated learning server and the configuration information (NF Profile) of the client device. For example, they can be obtained through a registration process or a discovery process. The specific steps are as follows.
[0364] Optionally, before the federated learning server sends the token request message to the first network element, the method further includes the following steps S501 and S502, ie, a registration process of the federated learning server and the client device.
[0365] S501, registration process of the federated learning server.
[0366] Exemplarily, the federated learning server sends a first registration request message to the first network element, requesting registration with the network. The first registration request message includes configuration information of the federated learning server (e.g., an NF profile). It is understood that the service configuration information is an NF profile and may also be included in the NF profile, wherein the NF profile includes a first interoperability identifier. Accordingly, the first network element receives the first registration request message and stores the NF profile. The first interoperability identifier is used to determine, in step S520a, whether the client device is permitted to obtain the second model from the federated learning server. The first network element sends a first registration response message to the federated learning server, indicating that registration with the federated learning server is complete. For specific implementation methods, reference may be made to the relevant description of method 200 above.
[0367] Optionally, the first registration request message may be a Nnrf_NFManagement_NFRegister_request message, and the first registration response message may be a Nnrf_NFManagement_NFRegister_response message.
[0368] Optionally, the first registration request message may further include one or more of the following: an identifier of the federated learning server, a name of a first service supported by the federated learning server, an identifier of a vendor of the federated learning server, first indication information, a NF type, a first analysis identifier, address information of the federated learning server, a service area, FL capability type information (e.g., FL server), or a time interval during which the federated learning server supports FL, etc. For specific explanations, refer to the relevant description above. The vendor identifier of the federated learning server is used to determine, in step S520b, whether the federated learning server is allowed to obtain the first model from the client device.
[0369] S502, registration process of the client device.
[0370] Exemplarily, the client device sends a second registration request message to the first network element to request registration with the network. The second registration request message includes configuration information of the client device (e.g., an NF profile). It is understood that the service configuration information is an NF profile and may also be included in the NF profile, wherein the NF profile includes a vendor identifier of the client device. Accordingly, the first network element receives the second registration request message and stores the NF profile. The vendor identifier of the client device is used to determine, in step S520a, whether the client device is permitted to obtain the second model from the federated learning server. The first network element sends a second registration response message to the federated learning server to indicate that the client device has completed registration. For specific implementation methods, reference may be made to the relevant description of method 200 above.
[0371] Optionally, the second registration request message may be a Nnrf_NFManagement_NFRegister_request message, and the second registration response message may be a Nnrf_NFManagement_NFRegister_response message.
[0372] Optionally, the second registration request message may further include one or more of the following: an identifier of the client device, a name of a first service supported by the client device, a second interoperability identifier, second indication information, a NF type, a first analysis identifier, address information of the client device, a service area, FL capability type information (e.g., FL client), or a time interval during which the client device supports FL. For specific explanations, refer to the relevant description above. The second interoperability identifier is used to determine, in step S520b, whether the federated learning server is allowed to obtain the first model from the client device.
[0373] Optionally, before the federated learning server sends the token request message to the first network element, the method further includes the following step S503, ie, a process in which the federated learning server requests discovery of the client device.
[0374] S503: The federated learning server executes a process of discovering the client device.
[0375] Exemplarily, the federated learning server sends a discovery request message to the first network element, requesting the discovery of available client devices in the network. The discovery request message carries the NF type (e.g., FL Client NWDAF) and / or the desired federated learning capability type (e.g., FL Client) of the desired NF instance. Accordingly, the first network element receives the discovery request message and selects a client device. The first network element sends a discovery response message to the federated learning server, indicating that the federated learning server is allowed to discover the desired NF instance (e.g., client device). For specific implementation methods, reference may be made to the description of the aforementioned method 200. The discovery response message carries configuration information (e.g., NF Profile) of the client device. For configuration information of the client device, reference may be made to the description of the aforementioned step S502.
[0376] Optionally, the discovery request message may be a Nnrf_NFDiscovery_Request message, and the discovery response message may be a Nnrf_NFDiscovery_Response message.
[0377] Optionally, the discovery request message may also carry at least one of the following: the identifier of the federated learning server, the identifier of the client device, the desired service name (for example, Service name = ML model Training Subscribe / Nnwdaf_MLModelTrainingInfo), the first analysis identifier, the NF type of the NF instance of the federated learning server, the federated learning capability type of the federated learning server (for example, FL Server), or the desired target NF location, etc. For specific interpretations, please refer to the relevant description above.
[0378] Alternatively, the federated learning server may discover the client device through a local mechanism.
[0379] S530: The federated learning server obtains a first model corresponding to the first analysis identifier from the client device according to the first token.
[0380] In one implementation, a federated learning server sends a federated learning preparation request message to a client device, where the federated learning preparation request message carries a first analysis identifier and a first token, requesting the client device to prepare to participate in the execution of federated learning; correspondingly, the client device verifies the first token and determines whether to join the federated learning; the client device sends a federated learning preparation response message to the federated learning server, indicating that it agrees to join the federated learning. Furthermore, the federated learning server starts a federated learning process, and the client device generates a first model based on local data and sends it to the federated learning server. For specific implementation methods, please refer to the relevant description of the above method 300.
[0381] Optionally, the federated learning preparation request message may be a Federated Learning preparation request message, such as using Nnwdaf_MLModelTraining_Subscribe or Nnwdaf_MLModelTrainingInfo_Request, and the federated learning preparation response message may be a Federated Learning preparation response message, such as Nnwdaf_MLModelTraining_Notify or Nnwdaf_MLModelTraining_Subscribe response service operation or Nnwdaf_MLModelTrainingInfo_Request response.
[0382] Optionally, the federated learning preparation request message may also be an ML model Training Subscribe reuquest message, and the federated learning preparation response message may also be an ML model Training Notify message.
[0383] Among them, the client device generates a first model based on local data, including: the client device generates the first model based on the initial model or basic model provided by the federated learning server in the federated learning process, combined with local data; or, the client device performs federated learning training based on the initial model generated by itself and local data to obtain the first model. This application does not limit its specific implementation method.
[0384] Optionally, before the federated learning server sends the initial model or base model, the method further includes: the federated learning server determining, based on the received first token or third indication information, that the client device has permission to obtain the second model from the federated learning server, and then sending the initial model or base model to the client device. In this case, the initial model or base model can be considered the second model. Optionally, if there is no security risk associated with transmitting the initial model or base model, this determination may not be performed.
[0385] S540: The federated learning server generates a second model based on the first model.
[0386] It should be understood that the first model is generated by the client device and is used by the federated learning server to generate the second model.
[0387] Exemplarily, for the same federated learning process, there are multiple client devices participating in the execution of federated learning, that is, after the multiple client devices locally train to obtain the first model, they will send the first model to the federated learning server. The federated learning server can aggregate the first models from different client devices to obtain a global ML model, that is, the second model. The specific implementation method can refer to the relevant description of the above method 400.
[0388] S550: The federated learning server sends the second model to the client device according to the first token and / or the third indication information.
[0389] Accordingly, the client device receives the second model from the federated learning server.
[0390] Optionally, the federated learning server can send the second model directly to the client device, or the federated learning server can also send the identifier of the second model, such as Model ID, to the client device. In this case, the federated learning server also sends the NF Instance ID of the federated learning server to the client, and the client device can then request the federated learning server to obtain the second model based on the NF instance ID and Model ID.
[0391] In a first implementation, the first token indicates that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, and the client device is allowed to obtain the second model from the federated learning server. After generating the second model, the federated learning server can send the second model to the client device according to the first token.
[0392] In a second implementation manner, the federated learning server may determine, based on the third indication information, that the client device is allowed to obtain the second model from the federated learning server, and the federated learning server may send the second model to the client device based on the third indication information.
[0393] The above two implementation methods can be implemented independently or in combination, and this application does not limit this.
[0394] Optionally, before the federated learning server sends the second model to the client device, the federated learning server may also determine whether the client device desires to obtain the second model, i.e., the method further includes the following step S550a. Based on this implementation, the federated learning server sends the second model to the client device when the client device desires to obtain the second model, thereby reducing unnecessary transmission overhead, lowering the risk of model leakage, and protecting the model's asset security.
[0395] S550a: The federated learning server determines that the client device desires to obtain a second model.
[0396] In a first example, the federated learning server sends the second model to the client device according to the second instruction information.
[0397] The second indication information indicates that the client device desires to obtain the second model.
[0398] Optionally, before executing step S550a, the method further includes: the federated learning server obtaining second indication information. For example, the federated learning server may receive the second indication information from the first network element, or the federated learning server may receive the second indication information from the client device.
[0399] For example, in the discovery process of step S503 , the federated learning server may obtain configuration information of the client device from the first network element. The configuration information of the client device includes second indication information, indicating that the client device expects to obtain the second model.
[0400] For another example, after executing step S520 to obtain the first token, the first network element may further send second indication information to the federated learning server to indicate that the client device desires to obtain the second model.
[0401] For another example, after obtaining the first token, the federated learning server may receive second indication information from the client device while requesting the client device to prepare to participate in federated learning. For example, the federated learning server may send a federated learning preparation request message to the client device based on the first token. In response, after the client device verifies the first token, it may notify the federated learning server that it agrees to participate in federated learning. Simultaneously, the client device may send second indication information to the federated learning server requesting that a second model be obtained after the federated learning is completed.
[0402] For another example, after the federated learning server initiates the federated learning process, during the federated learning training process, the client may send second indication information to the federated learning server. For example, the client device may send the second indication information simultaneously with sending the first model to the federated learning server, or the client device may send the second indication information after sending the first model to the federated learning server.
[0403] In a second example, the federated learning server sends the second model to the client device according to the local configuration.
[0404] For example, if the local configuration indicates that the client device participating in the federated learning process desires to obtain the global ML model (ie, the second model), the federated learning server may send the second model to the client device according to the local configuration.
[0405] It should be noted that the local configuration can be predefined or preconfigured, where predefinition can include predefinition, such as protocol definition. Preconfiguration can be achieved by pre-saving corresponding codes, tables, strings or other methods for indicating relevant information in the federated learning server. This application does not limit its specific implementation method.
[0406] It should be understood that the examples provided above are merely examples for ease of understanding and do not exclude other implementations. The various implementations described above may be implemented independently or in combination, and this application does not limit this. For example, the federated learning server sends the second model to the client device based on the second indication information and the local configuration, where the second indication information indicates that the client device desires to obtain the second model.
[0407] For example, if the federated learning server sends an identifier of the second model, such as a Model ID, to the client device, the federated learning server also sends the NF Instance ID of the federated learning server to the client. The client device then requests the federated learning server to obtain the second model based on the NF instance ID and the Model ID.
[0408] Based on the above scheme, before sending the first token, the first network element not only determines that the federated learning server (for example, server NWDAF) is allowed to obtain the first model corresponding to the first analysis identifier from the client device (for example, client NWDAF), but also determines that the client device is allowed to obtain the second model from the federated learning server, indicating that the client device not only supports federated learning, but also has the authority to obtain the model. In this way, for the second model obtained after the completion of federated learning, the federated learning server can send the second model to the client device without causing the leakage of the second model information, reducing security risks, and avoiding the loss of model property rights of the equipment manufacturer.
[0409] In addition, considering that the discovery process in step S503 is an optional step, that is, the federated learning server can locally discover the client device, if the federated learning server does not have the ability to check whether the client device is allowed to obtain the second model from the federated learning server, and the first network element does not check the permissions of the client device in the first token acquisition process, it may result in the client not being allowed to obtain the second model from the federated learning server. Still, after the federated learning is completed, it may cause the second model information to be leaked, increasing potential security risks. Therefore, by performing a permission check on whether the client device is allowed to obtain the second model from the federated learning server in the first token acquisition process and notifying the federated learning server, the federated learning server will not send the second model trained by federated learning to client devices that do not have model acquisition permissions, thereby reducing the risk of model leakage and ensuring network security and the security of equipment vendor model assets.
[0410] Figure 6 is a flow chart of a communication method 600 provided in an embodiment of the present application. As shown in Figure 6, the method flow may include the following steps. For parts not fully described, reference may be made to the above-mentioned existing protocol.
[0411] S610: The federated learning server sends a discovery request message to the first network element.
[0412] Correspondingly, the first network element receives a discovery request message from the federated learning server.
[0413] The discovery request message includes the first analysis identifier, and is used to request the discovery of a federated learning training that supports the first analysis identifier, or in other words, to discover a model that supports the training of the first analysis identifier.
[0414] Optionally, the discovery request message may also include at least one of the following: the identifier of the federated learning server, the NF type of the desired NF instance (e.g., FL Client NWDAF), the desired federated learning capability type (e.g., FL Client), the desired service name (e.g., Service name = ML model Traning Subscribe / Nnwdaf_MLModelTrainingInfo), the NF type of the NF instance of the federated learning server, the federated learning capability type of the federated learning server (e.g., FL Server), or the desired target NF location, etc. For specific interpretations, please refer to the relevant description above.
[0415] Optionally, the discovery request message may be an Nnrf_NFDiscovery_Request message.
[0416] S620: The first network element sends a discovery response message to the federated learning server.
[0417] Correspondingly, the federated learning server receives a discovery response message from the first network element.
[0418] The discovery response message includes an identifier of the client device.
[0419] Optionally, the discovery response message may carry configuration information of the client device (eg, NFp Profile). For the configuration information of the client device, please refer to the description of step S502 above.
[0420] Optionally, the discovery response message may be an Nnrf_NFDiscovery_Response message.
[0421] It should be understood that the above steps S610 and S620 are for the process of the federated learning server requesting the NRF to discover the client device. For specific implementation methods, reference can be made to the relevant description of the above method 200.
[0422] Optionally, before executing the above step S610, the method may further include the following steps S601 and S602, ie, a registration process of the federated learning server and the client device.
[0423] S601, registration process of the federated learning server.
[0424] S602, registration process of the client device.
[0425] For the specific implementation of the above steps S601 and S602, reference may be made to the relevant description of steps S501 and S502 of the above method 500.
[0426] S630: The federated learning server obtains a first model corresponding to the first analysis identifier from the client device.
[0427] In one implementation, the federated learning server obtains the first model corresponding to the first analysis identifier from the client device according to the first token. For a specific implementation, reference may be made to the description of step S530 of the above method 500 .
[0428] Optionally, before the federated learning server obtains the first model corresponding to the first analysis identifier from the client device, the method further includes the following step S603, ie, a process of obtaining a first token.
[0429] S603: The federated learning server obtains a first token.
[0430] Exemplarily, the federated learning server sends a token request message to the first network element to request a first token; correspondingly, when the first network element determines that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, it sends the first token to the federated learning server. For specific implementation methods, please refer to the relevant description of the above method 200.
[0431] It should be understood that in the process of obtaining the first token, the first network element determines that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device. Specifically, it can be: the first network element determines that the device vendor identifier of the federated learning server is included in the second interoperability identifier corresponding to the first analysis identifier supported by the client device, or the first network element determines that the second interoperability identifier corresponding to the first analysis identifier supported by the client device includes the device vendor identifier of the federated learning server. For the specific implementation method, please refer to the relevant description of step S502b of the above method 500.
[0432] Optionally, in the process of obtaining the first token, the first network element determines that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device. Specifically, it can be: the first network element determines that the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server is included in the second interoperability identifier corresponding to the first analysis identifier supported by the client device, or in other words, the first network element determines that the second interoperability identifier corresponding to the first analysis identifier supported by the client device includes the second interoperability identifier of the federated learning server.
[0433] S640: The federated learning server generates a second model based on the first model.
[0434] The federated learning server generates the second model based on the first model. For specific implementation, please refer to the relevant description of step S540 of the above method 500.
[0435] Below, in combination with steps S650-S660, the federated learning server sends a request message to the first network element, requesting the first network element to perform an authority check on whether the client is allowed to obtain the second model from the federated learning server, and then determines that the client is allowed to obtain the second model from the federated learning server for example.
[0436] S650: The federated learning server sends a request message to the first network element.
[0437] Correspondingly, the first network element receives a request message from the federated learning server.
[0438] The request message is used to request confirmation of whether the client device is allowed to obtain the second model from the federated learning server, and the request message includes a first analysis identifier.
[0439] Optionally, the request message may also carry configuration information of the client device (e.g., NFp Profile) and / or configuration information of the federated learning server (e.g., NFc Profile), including one or more of the following: an identifier of the federated learning server, an identifier of the client device, a first interoperability identifier, an equipment vendor identifier of the federated learning server, an equipment vendor identifier of the client device, first indication information, or second indication information, etc. For specific explanations, please refer to the relevant description of the above method 500.
[0440] It should be understood that the federated learning server can obtain the configuration information (eg, NFp Profile) of the client device from the first network element through the above step S620.
[0441] S660: When it is determined that the client device is allowed to obtain the second model from the federated learning server, the first network element sends a response message to the federated learning server.
[0442] Correspondingly, the federated learning server receives a response message from the first network element.
[0443] The response message indicates that the client device is allowed to obtain the second model from the federated learning server.
[0444] Optionally, the response message may include third indication information, which indicates that the client device is allowed to obtain the second model from the federated learning server. Optionally, the third indication information may not be included in the response message, that is, the response message and the third indication information may be sent independently and separately.
[0445] In one implementation, before the first network element sends a response message to the federated learning server, the method 600 may further include the following step S660a.
[0446] S660a: The first network element determines whether the client device is allowed to obtain the second model from the federated learning server.
[0447] In one example, the first network element determines whether the vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server. In other words, the first network element determines whether the vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server. For specific implementation methods, refer to the description of step S520a of method 500 above.
[0448] In one example, the first network element determines whether the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server. In other words, the first network element determines whether the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server includes the second interoperability identifier corresponding to the first analysis identifier supported by the client device. For specific implementation methods, refer to the description of step S520a of method 500 above.
[0449] S670: The federated learning server sends the second model to the client device.
[0450] Accordingly, the client device receives the second model from the federated learning server.
[0451] That is, the federated learning server may send the second model to the client according to the response message of step S660.
[0452] For example, if the federated learning server sends an identifier of the second model, such as a Model ID, to the client device, the federated learning server also sends the NF Instance ID of the federated learning server to the client. The client device then requests the federated learning server to obtain the second model based on the NF instance ID and the Model ID.
[0453] Optionally, before the federated learning server sends the second model to the client device, the method further includes the following step S670a.
[0454] S670a: The federated learning server determines that the client device desires to obtain a second model.
[0455] In a first example, the federated learning server sends the second model to the client device according to the second instruction information.
[0456] In a second example, the federated learning server sends the second model to the client device according to the local configuration.
[0457] For details on how to obtain the second information and how the federated learning server determines that the client device desires to obtain the second model, please refer to the description of step S550a of the above method 500.
[0458] Based on the above solution, after the federated learning server obtains the second model, it requests the first network element to check the permissions of the client device to determine whether the client device is allowed to obtain the second model from the federated learning server. Then, the federated learning server can send the second model to the client device with model acquisition permission without causing the leakage of model information, reducing potential security risks, and avoiding the loss of model property rights of equipment manufacturers.
[0459] Figure 7 is a flow chart of a communication method 700 provided in an embodiment of the present application. As shown in Figure 7, the method flow may include the following steps. For parts not fully described, reference may be made to the above-mentioned existing protocol.
[0460] S710: The federated learning server sends a discovery request message to the first network element.
[0461] Correspondingly, the first network element receives a discovery request message from the federated learning server.
[0462] The discovery request message includes the first analysis identifier, and is used to request the discovery of a federated learning training that supports the first analysis identifier, or in other words, to discover a model that supports the training of the first analysis identifier.
[0463] S720: The federated learning server receives a discovery response message from the first network element.
[0464] Correspondingly, the first network element receives a discovery response message from the federated learning server.
[0465] The discovery response message includes the identifier of the client device and the vendor identifier of the client device. The vendor identifier of the client device is used in the alternative step S750 to determine whether the client device is allowed to obtain the second model from the federated learning server.
[0466] Optionally, the discovery response message may carry configuration information of the client device (eg, NFp Profile). For the configuration information of the client device, please refer to the description of step S502 above.
[0467] It should be understood that the above steps S710 and S720 are for the process of the federated learning server requesting the NRF to discover the client device. For specific implementation methods, reference can be made to the relevant description of the above method 200.
[0468] Optionally, before executing the above step S710, the method may further include the following steps S701 and S702, ie, a registration process of the federated learning server and the client device.
[0469] S701, registration process of the federated learning server.
[0470] S702, registration process of the client device.
[0471] For the specific implementation of the above steps S701 and S702, reference may be made to the relevant description of steps S601 and S602 of the above method 600.
[0472] S730: The federated learning server obtains a first model corresponding to the first analysis identifier from the client device.
[0473] For specific implementation, please refer to the relevant description of step S630 of the above method 600.
[0474] Optionally, before the federated learning server obtains the first model corresponding to the first analysis identifier from the client device, the method further includes the following step S703, ie, a process of obtaining a first token.
[0475] S703: The federated learning server obtains a first token.
[0476] For the process of obtaining the first token, reference may be made to the relevant description of the above method 200.
[0477] It should be understood that in the process of obtaining the first token, the first network element determines that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device. The specific implementation method can refer to the relevant description of step S603 of the above method 600.
[0478] S740: The federated learning server generates a second model based on the first model.
[0479] The federated learning server generates the second model based on the first model. For specific implementation, please refer to the relevant description of step S540 of the above method 500.
[0480] Next, in conjunction with step S750 , an example is given of performing an authority check on whether the client is allowed to obtain the second model from the federated learning server, and then determining whether the client is allowed to obtain the second model from the federated learning server.
[0481] S750: The federated learning server determines, based on the vendor identifier of the client device, that the client device is allowed to obtain the second model from the federated learning server.
[0482] In one implementation, the federated learning server can determine that the client device is allowed to obtain the second model from the federated learning server based on the fact that the device vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, or in other words, the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server includes the device vendor identifier of the client device.
[0483] That is to say, the federated learning server can determine that the client device can obtain the second model from the federated learning server by judging that the device vendor identifier of the client device is included in the device vendor identifier list supported by the federated learning server; conversely, the federated learning server can determine that the client device cannot obtain the second model from the federated learning server by judging that the device vendor identifier of the client device is not included in the device vendor identifier list supported by the federated learning server.
[0484] In one implementation, the federated learning server can determine that the client device is allowed to obtain the second model from the federated learning server based on the fact that the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, or in other words, the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server includes the second interoperability identifier corresponding to the first analysis identifier supported by the client device.
[0485] That is to say, the federated learning server can determine that the client device can obtain the second model from the federated learning server by determining that the second interoperability identifier corresponding to the first analysis identifier supported by the client device is included in the list of device vendor identifiers supported by the federated learning server; conversely, the federated learning server can determine that the client device cannot obtain the second model from the federated learning server by determining that the second interoperability identifier corresponding to the first analysis identifier supported by the client device is not included in the list of device vendor identifiers supported by the federated learning server.
[0486] S760: The federated learning server sends the second model to the client device.
[0487] Accordingly, the client device receives the second model from the federated learning server.
[0488] That is, the federated learning server may determine, based on the permission check in step S750 , that the client is allowed to obtain the second model from the federated learning server, and then the federated learning server may send the second model to the client device.
[0489] For example, if the federated learning server sends an identifier of the second model, such as a Model ID, to the client device, the federated learning server also sends the NF Instance ID of the federated learning server to the client. The client device then requests the federated learning server to obtain the second model based on the NF instance ID and the Model ID.
[0490] Optionally, before the federated learning server sends the second model to the client device, the method further includes the following step S760a.
[0491] S760a: The federated learning server determines that the client device desires to obtain a second model.
[0492] In a first example, the federated learning server sends the second model to the client device according to the second instruction information.
[0493] In a second example, the federated learning server sends the second model to the client device according to the local configuration.
[0494] For details on how to obtain the second information and how the federated learning server determines that the client device desires to obtain the second model, please refer to the description of step S550a of the above method 500.
[0495] Based on the above scheme, after the federated learning server obtains the second model, it performs an authority check on the client device through the equipment vendor identifier of the client obtained in the discovery process, that is, it determines that the client device is allowed to obtain the second model from the federated learning server. In other words, the client device has the authority to obtain the second model. In this case, the federated learning server can send the second model to the client device, reducing the risk of information leakage of the second model, and at the same time avoiding the loss of model ownership of the equipment vendor.
[0496] The communication method embodiment of the present application is described above in conjunction with Figures 1 to 7. The communication device embodiment of the present application will be described in detail below in conjunction with Figures 8 and 9. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for portions not described in detail, reference can be made to the above method embodiment.
[0497] FIG8 is a schematic diagram of a communication device 1000 provided in an embodiment of the present application. As shown in FIG8 , the communication device 1000 includes a communication module 1002 and a processing module 1001. The communication device 1000 may be a first network element, or a communication device applied to the first network element or used in conjunction with the first network element and capable of implementing a method executed by the first network element, such as a chip, a chip system, or a circuit; or the communication device 1000 may be a federated learning server, or a communication device applied to the federated learning server or used in conjunction with the federated learning server and capable of implementing a method executed by the federated learning server, such as a chip, a chip system, or a circuit; or the communication device 1000 may be a client device, or a communication device applied to the client device or used in conjunction with the client device and capable of implementing a method executed by the client device, such as a chip, a chip system, or a circuit.
[0498] The communication module 1002 may also be referred to as a transceiver module, transceiver, transceiver, or transceiver device. The processing module 1001 may also be referred to as a processor, processing board, processing unit, or processing device. Optionally, the communication module 1002 is configured to perform the sending and receiving operations of the first network element, federated learning server, or client device in the above method. The device in the communication module 1002 that implements the receiving function may be considered a receiving unit, and the device in the communication module 1002 that implements the sending function may be considered a sending unit. That is, the communication module 1002 includes a receiving unit and a sending unit.
[0499] When the communication device 1000 is applied to the first network element, the processing module 1001 can be used to implement the processing function of the first network element in the above embodiments, and the communication module 1002 can be used to implement the transceiver function of the first network element in the above embodiments.
[0500] Exemplarily, the communication module 1002 is used to receive a token request message from the federated learning server, where the token request message includes a first analysis identifier, an identifier of the federated learning server, and an identifier of the client device; the communication module 1002 is also used to send a first token to the federated learning server after determining that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, and that the client device is allowed to obtain the second model from the federated learning server.
[0501] When the communication device 1000 is applied to a federated learning server, the processing module 1001 can be used to implement the processing functions of the federated learning server in the above embodiments, and the communication module 1002 can be used to implement the sending and receiving functions of the federated learning server in the above embodiments.
[0502] Exemplarily, the communication module 1002 is used to send a token request message to the first network element, where the token request message includes a first analysis identifier, an identifier of the federated learning server, and an identifier of the client device; the communication module 1002 is also used to receive a first token from the first network element, or to receive a first token and third indication information from the first network element; wherein the first token indicates that the client device is allowed to obtain a second model from the federated learning server, and the third indication information indicates that the client device is allowed to obtain a second model from the federated learning server; the communication module 1002 is also used to obtain a first model corresponding to the first analysis identifier from the client device based on the first token; the processing module 1001 is used to generate a second model based on the first model; the communication module 1002 is also used to send the second model to the client device based on the first token and / or the third indication information.
[0503] When the communication device 1000 is applied to a client device, the processing module 1001 may be used to implement the processing functions of the client device in the above embodiments, and the communication module 1002 may be used to implement the transceiver functions of the client device in the above embodiments.
[0504] In addition, it should be noted that the aforementioned communication module and / or processing module can be implemented by a virtual module, for example, the processing module can be implemented by a software functional unit or a virtual device, and the communication module can be implemented by a software function or a virtual device. Alternatively, the processing module or the communication module can also be implemented by a physical device, for example, if the device is implemented using a chip / circuit (such as an integrated circuit or a logic circuit, etc.). The communication module can be an input / output circuit and / or a communication interface that performs input operations (corresponding to the aforementioned receiving operations) and output operations (corresponding to the aforementioned sending operations); the processing module is an integrated processor or microprocessor or circuit (such as an integrated circuit or a logic circuit, etc.).
[0505] The division of modules in this application is illustrative and represents only a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the examples of this application may be integrated into a single processor, exist physically as separate modules, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in either hardware or software functional modules.
[0506] FIG9 is a schematic diagram of another communication device 2000 provided in an embodiment of the present application. As shown in FIG9 , the communication device 2000 may optionally be a chip or a chip system. Optionally, in the present application, the chip system may be composed of a chip or may include a chip and other discrete devices.
[0507] The communication device 2000 can be used to implement the functions of any network element (e.g., a first network element, a federated learning server, or a client device) in the communication system described in the above example. The communication device 2000 may include a communication interface 2030 and a processor 2010. The communication device 2000 can exchange information with other devices through the communication interface 2030. Exemplarily, the communication interface 2030 can be a transceiver, a circuit, a bus, a module, a pin, or other types of communication interfaces. When the communication device 2000 is a chip-type device or circuit, the communication interface 2030 in the device 2000 can also be an input-output circuit that can input information (or receive information) and output information (or send information). The processor 2010 is an integrated processor, microprocessor, integrated circuit, or logic circuit, etc. The processor can determine the output information based on the input information.
[0508] Optionally, the processor 2010 is coupled to a memory, which may be located within the device, integrated with the processor, or external to the device. For example, the communication device 2000 may further include at least one memory 2020. The memory 2020 stores the necessary computer programs, computer programs, instructions, and / or data for implementing any of the above examples. The processor 2010 may execute the computer program stored in the memory 2020 to perform the method in any of the above examples.
[0509] Coupling in this application refers to an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information exchange between devices, units, or modules. The processor 2010 may operate in conjunction with the memory 2020 and the communication interface 2030. The specific connection medium between the processor 2010, memory 2020, and communication interface 2030 is not limited in this application.
[0510] Optionally, as shown in FIG9 , the processor 2010, the memory 2020, and the communication interface 2030 are interconnected via a bus 2040. Optionally, the bus may include an address bus, a data bus, a control bus, and other types of buses. Furthermore, for ease of illustration, FIG9 shows one bus 2040, but this does not mean that there is only one bus or only one type of bus.
[0511] It should be understood that the processors mentioned in the embodiments of the present application may be the following devices or the circuit portions of the following devices used for processing functions: a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0512] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory and / or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0513] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) can be integrated into the processor.
[0514] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0515] An embodiment of the present application also provides a computer-readable storage medium on which computer instructions are stored for implementing the method executed by at least one of the first network element, the federated learning server, or the client device in the above-mentioned method embodiments.
[0516] An embodiment of the present application also provides a computer program product, comprising instructions, which, when executed by a computer, implement the method performed by at least one of the first network element, the federated learning server, or the client device in the above-mentioned method embodiments.
[0517] An embodiment of the present application further provides a communication system, which includes at least one of the first network element, the federated learning server, or the client device in the above embodiments.
[0518] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above and will not be described again here.
[0519] In various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0520] In this application, under the premise of no logical contradiction, the examples can reference each other, for example, the methods and / or terms between method embodiments can reference each other, for example, the functions and / or terms between device embodiments can reference each other, for example, the functions and / or terms between device examples and method examples can reference each other.
[0521] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0522] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be described again here.
[0523] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0524] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0525] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0526] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.
[0527] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A secure communication method, characterized in that: include: receiving a token request message from a federated learning server, the token request message including a first analysis identifier, an identifier of the federated learning server, and an identifier of a client device; After determining that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, and the client device is allowed to obtain the second model from the federated learning server, a first token is sent to the federated learning server.
2. The method according to claim 1, characterized in that The first model is generated by the client device and is used by the federated learning server to generate the second model; and / or, The second model is provided by the federated learning server and is used by the client device to generate the first model.
3. The method according to claim 1 or 2, characterized in that The first token indicates that the client device is allowed to obtain the second model from the federated learning server.
4. The method according to claim 1 or 2, characterized in that The method further comprises: Third indication information is sent to the federated learning server, where the third indication information indicates that the client device is allowed to obtain the second model from the federated learning server.
5. The method according to any one of claims 1 to 4, characterized in that The determining that the client device is allowed to obtain the second model from the federated learning server includes: It is determined that the vendor identifier of the client device is included in a first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server.
6. The method according to claim 5, characterized in that Before receiving the token request message from the federated learning server, the method further includes: receiving a first registration request message from the federated learning server, where the first registration request message includes the first interoperability identifier; Send a first registration response message to the federated learning server, where the first registration response message is used to indicate that the registration is complete.
7. The method according to claim 5 or 6, characterized in that Before receiving the token request message from the federated learning server, the method further includes: receiving a second registration request message from the client device, wherein the second registration request message includes a vendor identifier of the client device; A second registration response message is sent to the client device, where the second registration response message is used to indicate that the registration is complete.
8. The method according to any one of claims 1 to 7, characterized in that The determining that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device includes: It is determined that the vendor identifier of the federated learning server is included in a second interoperability identifier corresponding to the first analysis identifier supported by the client device.
9. The method according to any one of claims 1 to 8, characterized in that Before determining that the client device is allowed to obtain the second model from the federated learning server, the method further includes: Determining, based on the identifier of the federated learning server and / or the identifier of the client device, that the federated learning server and / or the client device supports federated learning; or determining, based on information of a first service and / or a federated learning capability type carried in the token request message, that the token request message is associated with federated learning, wherein the first service is used for performing federated learning between the federated learning server and the client device; or Determining, according to first instruction information, that the federated learning server sends the second model to the client device, wherein the first instruction information indicates sending the second model to the client device; or It is determined according to second indication information that the client device expects to obtain the second model, where the second indication information indicates that the client device expects to obtain the second model.
10. A secure communication method, characterized in that: include: Sending a token request message to the first network element, the token request message including the first analysis identifier, the identifier of the federated learning server, and the identifier of the client device; receiving a first token from the first network element, or receiving the first token and the third indication information from the first network element; wherein the first token indicates that the client device is allowed to obtain the second model from the federated learning server, and the third indication information indicates that the client device is allowed to obtain the second model from the federated learning server; obtaining, from the client device according to the first token, a first model corresponding to the first analysis identifier; generating the second model according to the first model; The second model is sent to the client device according to the first token and / or the third indication information.
11. The method according to claim 10, characterized in that The sending the second model to the client device includes: The second model is sent to the client device according to second indication information and / or local configuration, where the second indication information indicates that the client device desires to obtain the second model.
12. The method according to claim 11, characterized in that The method further comprises: The second indication information is received from the first network element or the client device.
13. The method according to any one of claims 10 to 12, characterized in that The client device is allowed to obtain a second model from the federated learning server, including: The vendor identifier of the client device includes a first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server.
14. The method according to claim 13, characterized in that Before sending the token request message to the first network element, the method further includes: Sending a first registration request message to the first network element, where the first registration request message includes the first interoperability identifier; A first registration response message is received from the first network element, where the first registration response message is used to indicate that registration is complete.
15. A secure communication method, characterized in that: include: Sending a discovery request message to the first network element, where the discovery request message includes a first analysis identifier; receiving a discovery response message from the first network element, the discovery response message including an identifier of the client device and an identifier of a vendor of the client device; obtaining, from the client device, a first model corresponding to the first analysis identifier; generating a second model based on the first model; After determining, based on the vendor identifier of the client device, that the client device is allowed to obtain the second model from the federated learning server, the second model is sent to the client device.
16. The method according to claim 15, characterized in that The determining, based on the vendor identifier of the client device, that the client device is allowed to obtain the second model from the federated learning server includes: It is determined that the vendor identifier of the client device is included in a first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server.
17. The method according to claim 16, characterized in that Before sending the discovery request message to the first network element, the method further includes: Sending a first registration request message to the first network element, where the first registration request message includes the first interoperability identifier; A first registration response message is received from the first network element, where the first registration response message is used to indicate that registration is complete.
18. The method according to any one of claims 15 to 17, characterized in that The sending the second model to the client device includes: The second model is sent to the client device according to second indication information and / or local configuration, where the second indication information indicates that the client device desires to obtain the second model.
19. The method according to claim 18, characterized in that The method further comprises: The second indication information is received from the first network element or the client device.
20. A secure communication method, characterized in that: include: receiving a discovery request message from a federated learning server, wherein the discovery request message includes a first analysis identifier; If it is determined that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device, sending a discovery response message to the federated learning server, where the discovery response message includes the identifier of the client device; receiving a request message from the federated learning server, the request message being used to request confirmation of whether the client device is allowed to obtain a second model from the federated learning server, the request message including the first analysis identifier; If it is determined that the client device is allowed to obtain the second model from the federated learning server, a response message is sent to the federated learning server.
21. The method according to claim 20, characterized in that The response message includes third indication information, and the third indication information indicates that the client device is allowed to obtain the second model from the federated learning server.
22. The method according to claim 20 or 21, characterized in that The determining that the client device is allowed to obtain the second model from the federated learning server includes: It is determined that the vendor identifier of the client device is included in a first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server.
23. The method according to claim 22, characterized in that Before receiving the discovery request message from the federated learning server, the method further includes: receiving a first registration request message from the federated learning server, where the first registration request message includes the first interoperability identifier; Send a first registration response message to the federated learning server, where the first registration response message is used to indicate that the registration is complete.
24. The method according to claim 22 or 23, characterized in that Before receiving the discovery request message from the federated learning server, the method further includes: receiving a second registration request message from the client device, wherein the second registration request message includes a vendor identifier of the client device; A second registration response message is sent to the client device, where the second registration response message is used to indicate that the registration is complete.
25. The method according to any one of claims 20 to 24, characterized in that The determining that the federated learning server is allowed to obtain the first model corresponding to the first analysis identifier from the client device includes: It is determined that the vendor identifier of the federated learning server is included in a second interoperability identifier corresponding to the first analysis identifier supported by the client device.
26. A secure communication method, characterized in that: include: Sending a discovery request message to the first network element, where the discovery request message includes a first analysis identifier; receiving a discovery response message from the first network element, the discovery response message including an identifier of the client device; obtaining, from the client device, a first model corresponding to the first analysis identifier; generating a second model according to the first model; Sending a request message to the first network element, the request message being used to request confirmation as to whether the client device is allowed to obtain the second model from the federated learning server, the request message including the first analysis identifier; receiving a response message from the first network element, the response message indicating that the client device is allowed to obtain the second model from the federated learning server; The second model is sent to the client device.
27. The method according to claim 26, characterized in that The method further comprises: Receive third indication information from the first network element, where the third indication information indicates that the client device is allowed to obtain the second model from the federated learning server.
28. The method according to claim 26 or 27, characterized in that The sending the second model to the client device includes: The second model is sent to the client device according to second indication information and / or local configuration, where the second indication information indicates that the client device desires to obtain the second model.
29. The method according to claim 28, characterized in that The method further comprises: The second indication information is received from the first network element or the client device.
30. A secure communication method, characterized in that: include: receiving a token request message from a federated learning server, the token request message including a first analysis identifier, an identifier of the federated learning server, and an identifier of a client device; After determining that the vendor identifier of the client device is included in the first interoperability identifier corresponding to the first analysis identifier supported by the federated learning server, and that the vendor identifier of the federated learning server is included in the second interoperability identifier corresponding to the first analysis identifier supported by the client device, a first token is sent to the federated learning server.
31. A communication device, characterized in that: include: One or more functional modules, wherein the one or more functional modules or network elements are used to perform the method as described in any one of claims 1 to 9, 20 to 25, or 30, or the one or more functional modules or network elements are used to perform the method as described in any one of claims 10 to 14, 15 to 19, 26 to 29.
32. A communication device, characterized in that: include: At least one processor configured to execute a computer program or instructions so that the method of any one of claims 1 to 9, 20 to 25, or so that the method of any one of claims 10 to 14, 15 to 19, 26 to 29 is performed.
33. The communication device according to claim 32, wherein: The communication device further comprises a memory for storing the computer program or instructions; and / or, The communication device further includes a communication interface coupled to the at least one processor, wherein the communication interface is configured to input and / or output information.
34. The communication device according to claim 32 or 33, characterized in that The communication device is a chip or a chip system.
35. A communication system, characterized in that: include: A first network element and a federated learning server, wherein the first network element is used to perform the method according to any one of claims 1 to 9, 20 to 25, or 30, and the federated learning server is used to perform the method according to any one of claims 10 to 14, 15 to 19, and 26 to 29.
36. A computer-readable storage medium, characterized in that include: The computer-readable storage medium stores a computer program, which, when executed, causes the computer to execute the method according to any one of claims 1 to 30.
37. A computer program product, characterized in that The invention comprises instructions, which, when executed on a computer, enable the method according to any one of claims 1 to 30 to be implemented.
Citation Information
Patent Citations
Secure communication method and communication device
CN120475377A
Machine learning model management method, device and system
CN114529005A
Communication method, communication device and communication system
CN116193441A
Method and apparatus for training recognition model, device, and readable storage medium
WO2021184836A1