Data management method and apparatus, system, storage medium, and program product
Patent Information
- Application Number
- PCT/CN2025/076075
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-04
- Filing Date
- 2025-02-06
- Publication Date
- 2025-10-02
AI Technical Summary
When the network management service provider entity performs twin services, it cannot effectively guarantee the security of data, resulting in the exposure of private data.
Through network management services, the consuming entity instructs the providing entity to allow the sharing of data sets and provides sharing policies, including whitelists, blacklists, usage permissions, data identification or types, etc., to ensure the security of data during the sharing process.
It improves the security and privacy of data during the execution of twin services and prevents improper sharing of data between different network management service consumption entities.
Smart Images

Figure CN2025076075_02102025_PF_FP_ABST
Abstract
Description
Data management method, device, system, storage medium and program product
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on March 4, 2024, with application number 202410244557.3 and invention name “Data management method, device, system, storage medium and program product”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to a data management method, device, system, storage medium, and program product. Background Art
[0003] A network management service provider can execute twin services for multiple network management service consuming entities. Typically, when executing twin service 1 for network management service consuming entity A, the network management service provider uses some data from network management service consuming entity A. Furthermore, upon receiving a request from network management service consuming entity B, the network management service provider will determine based on data similarity whether to continue using the aforementioned data when executing twin service 2. This makes it impossible to guarantee data security and results in the exposure of private data.
[0004] In view of this, how to manage data and improve data security when executing twin businesses is an urgent problem to be solved. Summary of the Invention
[0005] The present application provides a data management method, device, system, storage medium and program product to perform data management and improve data security.
[0006] In a first aspect, a data management method is provided. The method can be executed by a network management service provider, or by a chip or circuit configured in the network management service provider, or by a logic module or software capable of implementing all or part of the network management service provider's functions. This application is not limited thereto.
[0007] The method includes: a network management service providing entity receives first information from a first network management service consuming entity, the first information being used to indicate that sharing of a first data set from the first network management service consuming entity is allowed; the network management service providing entity receives a first request from a second network management service consuming entity, the first request being used to request a second twin service; and the network management service providing entity sends a response to the first request to the second network management service consuming entity based on the first request and at least a portion of the data in the first data set, the response including the execution result of the second twin service.
[0008] In this aspect, the first network management service consuming entity that provides data indicates to the network management service providing entity that it allows sharing of the data, so that when the network management service providing entity receives a request from the second network management service consuming entity, it can use the data to perform the requested twin service according to the indication, thereby improving the security of the data.
[0009] In combination with the first aspect, in a possible implementation, the first request includes at least one of the following information: twin object, twin business type, and business configuration.
[0010] In combination with the first aspect, in another possible implementation, the method also includes: the network management service providing entity receives a second request from the first network management service consuming entity, and the second request is used to request a first twin service; the network management service providing entity creates a first twin instance based on the second request, and the first twin instance includes the first data set; the network management service providing entity executes the first twin service based on the first twin instance; the network management service providing entity sends a response to the first request to the second network management service consuming entity based on the first request and at least part of the data in the first data set, including: the network management service providing entity determines to use at least part of the data in the first data set to execute the second twin service based on the first request and the first information; the network management service providing entity executes the second twin service based on at least part of the data in the first data set.
[0011] In combination with the first aspect, in another possible implementation, the method also includes: the network management service providing entity stores the first data set in a database based on the first information; the network management service providing entity sends a response to the first request to the second network management service consuming entity based on the first request and at least a part of the data in the first data set, including: the network management service providing entity searches for at least a part of the data in the first data set in the database based on the first request; and the network management service providing entity executes the second twin service based on at least a part of the data in the first data set.
[0012] In combination with the first aspect, in another possible implementation, the first information is carried in the second request.
[0013] In this implementation, by carrying the first information in the second request, when the first network management service consumer entity sends the second request (the first data set is required to execute the first twin service), it indicates that other network management service consumer entities are allowed to share the first data set, which simplifies the subsequent use process of the first data set and improves data management efficiency.
[0014] In combination with the first aspect, in another possible implementation, after the network management service providing entity receives a first request from a second network management service consuming entity, the method further includes: the network management service providing entity sends a third request to the first network management service consuming entity based on the first request, and the third request is used to request permission to share at least part of the data in the first data set, and the first information is carried in the response to the third request.
[0015] In combination with the first aspect, in another possible implementation, the network management service providing entity sends a third request to the first network management service consuming entity based on the first request, including: the network management service providing entity determines, based on the first request, to use at least one partial data in the first data set to execute the second twin instance; and the network management service providing entity sends the third request to the first network management service consuming entity.
[0016] In this implementation, upon receiving a request from a network management service consuming entity other than the first network management service consuming entity, the network management service providing entity only requests permission to share at least a portion of the first data set provided by the first network management service consuming entity if it determines that it needs to use the at least a portion of the data in the first data set provided by the first network management service consuming entity. This allows the first network management service consuming entity to more accurately decide whether to share the first data set, better protecting data privacy and improving data security.
[0017] In combination with the first aspect, in another possible implementation, the method also includes: the network management service providing entity receives a sharing policy for the first data set from the first network management service consuming entity; wherein the sharing policy includes at least one of the following information: a list of network management service consuming entities that are allowed to share and use the first data set; or a list of network management service consuming entities that are not allowed to share and use the first data set; or usage rights for the first data set, the usage rights including at least one of the following: read-only, write-only, read-write, use only; or an identifier of the data in the first data set that is allowed to be shared; or the type of data in the first data set that is allowed to be shared.
[0018] In this implementation, the first network management service consuming entity can indicate in the sharing policy the list of network management service consuming entities that are allowed to share and use the first data set based on its own privacy requirements, that is, the network management service consuming entities in the list can share the first data set. For example, the list of network management service consuming entities that are allowed to share and use the first data set includes the second network management service consuming entity, the third network management service consuming entity, etc., but does not include the fourth network management service consuming entity. Then, when the network management service providing entity receives a request from the second network management service consuming entity and the third network management service consuming entity, the first data set can be shared with the second network management service consuming entity and the third network management service consuming entity; when the network management service providing entity receives a request from the fourth network management service consuming entity, the first data set cannot be shared with the fourth network management service consuming entity. The above request is used to request a twin service.
[0019] On the contrary, the first network management service consumer entity may also indicate in the sharing policy a list of network management service consumer entities that are not allowed to share the first data set based on its own privacy requirements, that is, the network management service consumer entities in the list cannot share the first data set. For example, the list of network management service consumer entities that are not allowed to share the first data set includes the fourth network management service consumer entity, but does not include the second network management service consumer entity, the third network management service consumer entity, and so on. Then, when the network management service provider entity receives a request from the second network management service consumer entity and the third network management service consumer entity, the first data set may be shared with the second network management service consumer entity and the third network management service consumer entity; when the network management service provider entity receives a request from the fourth network management service consumer entity, the first data set may not be shared with the fourth network management service consumer entity. The above request is used to request twin services.
[0020] There are multiple permissions for data usage. The first network management service consumer entity can indicate the specific usage permissions for the first data set in the sharing policy. The first network management service consumer entity can indicate sharing of one or more of the above usage permissions. Furthermore, the first network management service consumer entity can also indicate different usage permissions corresponding to different network management service consumer entities in a fine-grained manner. For example, the usage permissions corresponding to network management service consumer entities 1 to 10 are: read-only; the usage permissions corresponding to network management service consumer entities 20 to 30 are: read and write.
[0021] The first network management service consumer entity enables sharing of the first data set by sending the first information. The first network management service consumer entity may also send a sharing policy for the first data set. The sharing policy includes the identifier of the data in the first data set that is allowed to be shared. For example, each data packet or each group of data in the first data set has a corresponding unique identifier. For example, the first data set includes 10 data packets, id1 to id10, and the identifiers of the data packets allowed to be shared indicated in the sharing policy are id1 and id2, that is, the data packets corresponding to id1 and id2 are shared, while the data packets corresponding to id3 to id10 are not allowed to be shared.
[0022] The first network management service consumer entity enables sharing of the first data set by sending a first message. The first network management service consumer entity may also send a sharing policy for the first data set. The sharing policy includes the types of data in the first data set that are permitted to be shared. For example, the first data set includes the following types of data: network data, environmental data, and traffic data. The type of data permitted to be shared indicated in the sharing policy is traffic data, while network data and environmental data are not permitted to be shared.
[0023] It is understood that the at least one item of information included in the aforementioned sharing policy may be separate or combined. For example, the sharing policy may indicate a list of network management service consuming entities permitted to share and use the first data set, and may further indicate usage permissions for the first data set in the sharing policy. For another example, the sharing policy may indicate a list of network management service consuming entities permitted to share and use the first data set, and may further indicate the identifiers and / or types of data in the first data set permitted to be shared in the sharing policy.
[0024] In a second aspect, a data management method is provided. The method can be executed by a first network management service consuming entity, or by a chip or circuit configured in the first network management service consuming entity, or by a logic module or software capable of implementing all or part of the functions of the first network management service consuming entity. This application is not limited to this.
[0025] The method includes: a first network management service consuming entity sends first information to a network management service providing entity, where the first information is used to indicate that sharing of a first data set from the first network management service consuming entity is allowed.
[0026] In this aspect, when the first network management service consuming entity allows sharing of its own data, it indicates to the network management service providing entity that sharing of the data is allowed, so that when the network management service providing entity receives a request from the second network management service consuming entity, it can use the data to execute the requested twin service according to the instruction, thereby improving the security of the data.
[0027] In combination with the second aspect, in a possible implementation, the method also includes: the first network management service consumption entity sends a second request to the network management service providing entity, and the second request is used to request a first twin service; wherein the first data set is included in the first twin instance created by the network management service providing entity according to the second request.
[0028] In combination with the second aspect, in another possible implementation, the first information is carried in the second request.
[0029] In combination with the second aspect, in another possible implementation, the method also includes: the first network management service consuming entity receives a third request from the network management service providing entity, the third request is used to request permission to share at least part of the data in the first data set, and the first information is carried in the response to the third request.
[0030] In combination with the second aspect, in another possible implementation, the method also includes: the first network management service consuming entity sends a sharing policy of the first data set to the network management service providing entity; wherein the sharing policy includes at least one of the following information: a list of network management service consuming entities that are allowed to share and use the first data set; or a list of network management service consuming entities that are not allowed to share and use the first data set; or usage rights of the first data set, the usage rights including at least one of the following: read-only, write-only, read-write, use only; or an identifier of the data in the first data set that is allowed to be shared; or the type of data in the first data set that is allowed to be shared.
[0031] In a third aspect, a data management method is provided. The method can be executed by a second network management service consuming entity, or by a chip or circuit configured in the second network management service consuming entity, or by a logic module or software capable of implementing all or part of the functions of the second network management service consuming entity. This application is not limited to this.
[0032] The method includes: the second network management service consumer entity sends a first request to the network management service provider entity, and the first request is used to request the second twin service; and the second network management service consumer entity receives a response to the first request from the network management service provider entity, and the response includes the execution result of the second twin service. The response is obtained based on the first request and at least part of the data in the first data set, the first data set comes from the first network management service consumer entity, and the first network management service consumer entity indicates that sharing of the first data set is allowed.
[0033] In this aspect, when the second network management service consuming entity requests the network management service providing entity to execute the twin service, the network management service providing entity obtains the execution result of the twin service according to at least a part of the data in the first data set according to the instructions of the first network management service consuming entity, thereby improving the efficiency of the twin.
[0034] In combination with the third aspect, in one possible implementation, the first request includes at least one of the following information: twin object, twin business type, and business configuration.
[0035] In a fourth aspect, a data management device is provided that can implement the method of the network management service provider entity described in the first aspect or any implementation of the first aspect. For example, the network management service provider entity can be a chip or circuit. The method can be implemented through software, hardware, or hardware executing corresponding software.
[0036] In one possible implementation, the device includes: a transceiver unit, and may also include a processing unit; wherein the transceiver unit is used to receive first information from a first network management service consumption entity, and the first information is used to indicate that sharing of a first data set from the first network management service consumption entity is allowed; the transceiver unit is also used to receive a first request from a second network management service consumption entity, and the first request is used to request a second twin service; and the transceiver unit is also used to send a response to the first request to the second network management service consumption entity based on the first request and at least a part of the data in the first data set, and the response includes the execution result of the second twin service.
[0037] Optionally, the first request includes at least one of the following information: twin object, twin business type, and business configuration.
[0038] Optionally, the transceiver unit is also used to receive a second request from the first network management service consumption entity, and the second request is used to request a first twin service; the processing unit is used to create a first twin instance according to the second request, and the first twin instance includes the first data set; the processing unit is also used to execute the first twin service based on the first twin instance; the processing unit is also used to determine the use of at least a part of the data in the first data set to execute the second twin service based on the first request and the first information; the processing unit is also used to execute the second twin service based on at least a part of the data in the first data set.
[0039] Optionally, the processing unit is also used to store the first data set in a database based on the first information; the processing unit is also used to search for at least a portion of the data in the first data set in the database based on the first request; and the processing unit is also used to execute the second twin business based on at least a portion of the data in the first data set.
[0040] Optionally, the first information is carried in the second request.
[0041] Optionally, the transceiver unit is also used to send a third request to the first network management service consumption entity based on the first request, and the third request is used to request permission to share at least part of the data in the first data set, and the first information is carried in the response to the third request.
[0042] Optionally, the processing unit is also used to determine, based on the first request, to use at least part of the data in the first data set to execute the second twin instance; and the transceiver unit is also used to send the third request to the first network management service consumption entity.
[0043] Optionally, the transceiver unit is also used to receive a sharing policy for the first data set from the first network management service consumer entity; wherein the sharing policy includes at least one of the following information: a list of network management service consumer entities that are allowed to share and use the first data set; or a list of network management service consumer entities that are not allowed to share and use the first data set; or usage rights for the first data set, the usage rights including at least one of the following: read-only, write-only, read-write, use only; or an identifier of the data in the first data set that is allowed to be shared; or the type of data in the first data set that is allowed to be shared.
[0044] In a fifth aspect, a data management device is provided that can implement the method of the first network management service consuming entity described in the second aspect or any implementation of the second aspect. For example, the first network management service consuming entity can be a chip or circuit. The method can be implemented using software, hardware, or hardware executing corresponding software.
[0045] In one possible implementation, the device includes: a transceiver unit and may also include a processing unit; wherein the transceiver unit is used to send first information to a network management service providing entity, and the first information is used to indicate that sharing of a first data set from the first network management service consuming entity is allowed.
[0046] Optionally, the transceiver unit is also used to send a second request to the network management service provider entity, and the second request is used to request a first twin service; wherein the first data set is included in a first twin instance created by the network management service provider entity based on the second request.
[0047] Optionally, the first information is carried in the second request.
[0048] Optionally, the transceiver unit is further used to receive a third request from the network management service providing entity, where the third request is used to request permission to share at least a portion of the data in the first data set, and the first information is carried in a response to the third request.
[0049] Optionally, the transceiver unit is also used to send a sharing policy of the first data set to the network management service providing entity; wherein the sharing policy includes at least one of the following information: a list of network management service consuming entities that are allowed to share and use the first data set; or a list of network management service consuming entities that are not allowed to share and use the first data set; or usage rights of the first data set, the usage rights including at least one of the following: read-only, write-only, read-write, use only; or an identifier of the data in the first data set that is allowed to be shared; or the type of data in the first data set that is allowed to be shared.
[0050] In a sixth aspect, a data management device is provided that can implement the method of the second network management service consuming entity described in the third aspect or any implementation of the third aspect. For example, the second network management service consuming entity can be a chip or circuit. The method can be implemented using software, hardware, or hardware executing corresponding software.
[0051] In one possible implementation, the device includes: a transceiver unit, and may also include a processing unit; wherein the transceiver unit is used to send a first request to a network management service providing entity, and the first request is used to request a second twin service; and the transceiver unit is also used to receive a response to the first request from the network management service providing entity, and the response includes the execution result of the second twin service, and the response is obtained based on the first request and at least part of the data in the first data set, the first data set comes from the first network management service consuming entity, and the first network management service consuming entity indicates that sharing of the first data set is allowed.
[0052] Optionally, the first request includes at least one of the following information: twin object, twin business type, and business configuration.
[0053] In combination with the fourth to sixth aspects or any one of the fourth to sixth aspects, in another possible implementation, the data management device in the fourth to sixth aspects or any one of the fourth to sixth aspects includes a processor coupled to a memory; the processor is configured to support the device in performing the corresponding functions in the above-mentioned data management method. The memory is used to couple with the processor, which stores the necessary programs (instructions) and / or data for the device. Optionally, the data management device may further include a communication interface for supporting communication between the device and other network elements. Optionally, the memory may be located inside the data management device or outside the data management device.
[0054] In combination with the fourth to sixth aspects or any one of the fourth to sixth aspects, in another possible implementation, the data management device in the fourth to sixth aspects or any one of the fourth to sixth aspects includes a processor and a transceiver device, the processor is coupled to the transceiver device, the processor is used to execute a computer program or instruction to control the transceiver device to receive and send information; when the processor executes the computer program or instruction, the processor is also used to implement the above method through a logic circuit or execute code instructions. The transceiver device can be a transceiver, a transceiver circuit or an input-output interface, which is used to receive signals from other devices outside the data management device and transmit them to the processor or send signals from the processor to other devices outside the data management device. When the data management device is a chip, the transceiver device is a transceiver circuit or an input-output interface.
[0055] When the data management device in any of the fourth to sixth aspects or the fourth to sixth aspects is a chip or chip module, the sending unit may be an output unit, such as an output circuit or a communication interface; and the receiving unit may be an input unit, such as an input circuit or a communication interface. When the data management device is a terminal or access network device, the sending unit may be a transmitter or a transmitter; and the receiving unit may be a receiver or a receiver.
[0056] In the seventh aspect, a data management system is provided, comprising a data management device as described in the fourth aspect or any one of the fourth aspects, a data management device as described in the fifth aspect or any one of the fifth aspects, and a data management device as described in the sixth aspect or any one of the sixth aspects.
[0057] In an eighth aspect, a computer-readable storage medium is provided, in which a computer program or instruction is stored. When a computer executes the computer program or instruction, the methods described in the above aspects are implemented.
[0058] In a ninth aspect, a computer program product comprising instructions is provided, which, when executed on a data management device, causes the data management device to execute the methods described in the above aspects. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 is a schematic diagram of a shared twin instance process;
[0060] Figure 2 is a schematic diagram of data sharing;
[0061] FIG3 is a schematic diagram of the architecture of a data management system;
[0062] FIG4 is a flow chart of a data management method provided in an embodiment of the present application;
[0063] FIG5 is a flow chart of another data management method provided in an embodiment of the present application;
[0064] FIG6 is a flow chart of another data management method provided in an embodiment of the present application;
[0065] FIG7 is a schematic structural diagram of a data management device provided in an embodiment of the present application;
[0066] FIG8 is a schematic structural diagram of another data management device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0067] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application.
[0068] Digital twin (DT) is a technology related to system automation. A DT is a virtual replica of a real-world system, upon which operations can be executed. Faced with the ever-increasing types, scale, and complexity of services, communication networks are leveraging digital twin technology to seek better solutions beyond physical networks. Twin instances are the application of digital twin technology in the communication network field, aiming to develop a variety of network applications and achieve efficient, data-driven network management and maintenance.
[0069] A network digital twin instance (NDT instance) is a digital twin whose physical counterpart is a communication network or some portion of a communication network. A communication network may include, for example, physical network elements and components, virtualized network functions (VNFs) (i.e., network function elements instantiated as software-based entities), physical hosts, services, and traffic flows for such VNFs, etc.
[0070] Specifically, a twin instance refers to a digital mirror of a physical network established in a digital way, and the physical network is digitized with the help of the historical network data, real-time network data and algorithmic models of the physical network to achieve synchronous analysis, prediction and improvement optimization of the physical network. That is, the twin instance contains a digital expression of the physical network and is used to simulate the physical network. Among them, the digital expression includes algorithmic models and data, etc. The twin instance can also be called a network twin, which is not limited in this application. Among them, the physical network is a network formed by connecting various physical devices or network elements (such as hosts, routers, switches, etc.) and media (optical cables, cables, twisted pairs, etc.) in the network. The physical network can be a mobile access network, a transmission network, a mobile core network, a backbone network, etc.; the physical network can also be a data center network, a campus network, an industrial Internet of Things, etc. Network data can also be called network operation data, which is used to represent the operating status of the physical network. It can be configuration parameters, alarm data, performance data, etc. of physical devices or network elements.
[0071] A key application of twin instances is simulation. In simulation, the twin instance acts as a secure sandbox, safely verifying the impact of specific network management operations on the physical network, such as verifying network element energy-saving solutions. Twin instances can also model the behavior of real networks to estimate expected network behavior, for example, for latency prediction and network failure prediction.
[0072] As mentioned earlier, a twin instance contains a digital representation of a physical network and is used to simulate it. This digital representation includes algorithmic models and data. The model can be used to represent basic network information (including network element information and topology) and can also be used to simulate the physical network.
[0073] Multiple network management service consuming entities may send multiple twin business requests to the network management service providing entity simultaneously or at different times. By concurrently processing multiple twin business requests, the network management service providing entity can enable multiple twin businesses to efficiently and independently share network twin capabilities. All or part of the basic data, models, and functions of multiple twin business requests may be similar. Therefore, in order to achieve efficient resource utilization, similar twin business requests can be identified and twin instances can be shared.
[0074] Therefore, in the current network digital twin service, when the network management service provider receives similar twin business requests issued at the same time, it can improve resource utilization by sharing twin instances. The content that can be shared is data, models, and the capabilities provided by the models. In order to decide whether sharing is possible, the network management service provider analyzes the twin instance to be built based on the twin object, twin business type, and business configuration required by the received business request, and compares it with the existing twin instance. If there are identical parts, they can be shared. There are three ways to achieve sharing:
[0075] 1. Create a new twin instance: When all existing twin instances cannot provide the data or model for the current request, a new twin instance is created that is completely independent of the existing twin instance.
[0076] 2. Fully shared twin instances: Directly share all models and capabilities of existing twin instances without creating new twin instances. When the network management service provider finds that an existing twin instance can meet all the twin objects, service configurations, and twin service types required for the current twin service request, it does not create a new twin instance, but uses the existing twin instance to complete the twin service request.
[0077] 3. Partially shared twin instance: A partially shared twin instance is formed by sharing part of the model or capabilities of an existing twin instance.
[0078] As shown in Figure 1, a flow chart of a shared twin instance provided in an embodiment of the present application is provided. The network management service consuming entity sends a twin business request to the network management service providing entity. The twin business request includes a twin object, a twin business type, and a business configuration; the network management service providing entity decides whether the existing twin instance can be shared, and decides to create a new twin instance or share the existing twin instance; the network management service providing entity sends a twin business response to the network management service consuming entity. The twin business response includes request acceptance information and twin instance information. The twin instance can be newly created or shared. Furthermore, the network management service providing entity may also trigger the deletion of twin instances that are no longer needed. At the request of the network management service consuming entity, the network management service providing entity may also provide a network digital twin resource utilization report.
[0079] The above describes the sharing of twin instances. However, when executing twin services, sharing of other data may also be involved.
[0080] For example, as shown in Figure 2, a data sharing diagram is provided for an embodiment of the present application. In a signaling storm scenario, the network management service consumer entity A obtains the current user traffic information of area 1 in some way, and there are 5 possible flow control strategies that need to be verified. The network management service consumer entity A hopes to use the user traffic information to verify these strategies on the twin instance and find the optimal strategy.
[0081] The network management service provider entity can realize the sharing of twin instances. The network management service consumer entity A can verify the above five flow control strategies through five twin instances (twin instance 1 to twin instance 5). Among them, twin instance 1 is newly created; twin instance 2 to twin instance 5 are partially shared twin instances, sharing the created twin instance 1, that is, sharing the user traffic information and access and mobility management function (AMF) network element model of the created twin instance 1.
[0082] However, when network management service consumer entity B needs to monitor the traffic in the same area (i.e., area 1), it also sends a twin service request to the network management service provider entity. At this time, the network management service provider entity finds that it has obtained the user traffic information in this area from network management service consumer entity A, and will directly provide the user traffic information to network management service consumer entity B for use. The user traffic information is the data initially injected by network management service consumer entity A, but after the twin instance is built, the source of the data is not distinguished, which will cause data exposure problems for network management service consumer entity A and reduce the data security of network management service consumer entity A.
[0083] The above data can be included in the twin instance. Currently, twin instance sharing can be used for all twin business requests, but directly sharing the twin instance for all twin business requests may cause the exposure of private data between different twin businesses, greatly reducing the security of the data. For example, in the above example, the current judgment of whether to share is based only on the content and data similarity of the twin instance, and it does not take into account that some data is only owned by the network management service consumer entity A. The network management service consumer entity A may not want to share, which will not meet the network management service consumer entity A's requirements for data privacy.
[0084] The above data can also be independent of the twin instance. This data is used to execute the twin business. The network management service consumer entity that injects this data may not want to share it.
[0085] Therefore, it is necessary to ensure the security and privacy of data used to execute twin services.
[0086] To this end, the present application provides a data management solution, in which the network management service consuming entity that provides data indicates to the network management service providing entity that it allows the sharing of the data. When the network management service providing entity receives a request from other network management service consuming entities, it can use the data to execute the requested twin service according to the instruction, thereby improving the security of the data.
[0087] As shown in Figure 3, a schematic diagram of the architecture of a data management system provided in an embodiment of the present application is shown. The data management system 3000 includes a first network management service consumption entity 301, a second network management service consumption entity 302 and a network management service providing entity 303. The first network management service consumption entity 301 and the second network management service consumption entity 302 can interact with the network management service providing entity 303 respectively. Exemplarily, the first network management service consumption entity 301 and the second network management service consumption entity 302 can be located in a network management system (NMS); the network management service providing entity 303 can be located in an equipment management system (EMS). The first network management service consumption entity 301 and the second network management service consumption entity 302 are used to make requests (request twin services, such as calling the simulation service of a twin instance) and receive responses; the network management service providing entity 303 is used to execute twin services, for example, it can perform simulation according to the above request, send network management operation instructions to the physical network, etc.
[0088] Based on the above data management system, the data management method provided by this application is described below.
[0089] FIG4 is a flow chart of a data management method provided in an embodiment of the present application. Exemplarily, the method may include the following steps:
[0090] S401. A first network management service consuming entity sends first information to a network management service providing entity.
[0091] Correspondingly, the network management service providing entity receives the first information.
[0092] The first information may be used to indicate that sharing of a first data set from a first network management service consumption entity is allowed.
[0093] The first network management service consuming entity sends the first information, which may have the following two meanings:
[0094] In one implementation, the first network management service consuming entity sending the first information means that the entire first data set can be shared with any other network management service consuming entity.
[0095] In another implementation, the first network management service consuming entity sends the first information, which means that the sharing of the first data set is enabled. However, the sharing rights, data usage rights, and specific shared content are further determined by the sharing policy of the first data set. Therefore, the first network management service consuming entity can also send the sharing policy of the first data set to the network management service providing entity:
[0096] The sharing policy may include at least one of the following information:
[0097] a list of network management service consuming entities that are permitted to share and use the first data set (referred to as a "white list"); or
[0098] a list of network management service consuming entities that are not permitted to share and use the first data set (referred to as a "blacklist"); or
[0099] The usage rights of the first data set, where the usage rights include at least one of the following: read-only, write-only, read-write, and use-only; or
[0100] an identification of the data in the first data set that is permitted to be shared; or
[0101] The types of data in the first data set that are allowed to be shared.
[0102] Among them, the first network management service consumer entity can indicate in the sharing policy the list of network management service consumer entities that are allowed to share and use the first data set according to its own privacy requirements, that is, the network management service consumer entities in the list can share the first data set. For example, the list of network management service consumer entities that are allowed to share and use the first data set includes the second network management service consumer entity, the third network management service consumer entity, etc., but does not include the fourth network management service consumer entity. Then, when the network management service provider entity receives a request from the second network management service consumer entity and the third network management service consumer entity, the first data set can be shared with the second network management service consumer entity and the third network management service consumer entity; when the network management service provider entity receives a request from the fourth network management service consumer entity, the first data set cannot be shared with the fourth network management service consumer entity. The above request is used to request twin services.
[0103] On the contrary, the first network management service consumer entity may also indicate in the sharing policy a list of network management service consumer entities that are not allowed to share the first data set based on its own privacy requirements, that is, the network management service consumer entities in the list cannot share the first data set. For example, the list of network management service consumer entities that are not allowed to share the first data set includes the fourth network management service consumer entity, but does not include the second network management service consumer entity, the third network management service consumer entity, and so on. Then, when the network management service provider entity receives a request from the second network management service consumer entity and the third network management service consumer entity, the first data set may be shared with the second network management service consumer entity and the third network management service consumer entity; when the network management service provider entity receives a request from the fourth network management service consumer entity, the first data set may not be shared with the fourth network management service consumer entity. The above request is used to request twin services.
[0104] There are multiple permissions for data usage. The first network management service consumer entity can indicate the specific usage permissions for the first data set in the sharing policy. The first network management service consumer entity can indicate sharing of one or more of the above usage permissions. Furthermore, the first network management service consumer entity can also indicate different usage permissions corresponding to different network management service consumer entities in a fine-grained manner. For example, the usage permissions corresponding to network management service consumer entities 1 to 10 are: read-only; the usage permissions corresponding to network management service consumer entities 20 to 30 are: read and write.
[0105] The first network management service consumer entity enables sharing of the first data set by sending the first information. The first network management service consumer entity may also send a sharing policy for the first data set. The sharing policy includes the identifier of the data in the first data set that is allowed to be shared. For example, each data packet or each group of data in the first data set has a corresponding unique identifier. For example, the first data set includes 10 data packets, id1 to id10, and the identifiers of the data packets allowed to be shared indicated in the sharing policy are id1 and id2, that is, the data packets corresponding to id1 and id2 are shared, while the data packets corresponding to id3 to id10 are not allowed to be shared.
[0106] The first network management service consumer entity enables sharing of the first data set by sending a first message. The first network management service consumer entity may also send a sharing policy for the first data set. The sharing policy includes the types of data in the first data set that are permitted to be shared. For example, the first data set includes the following types of data: network data, environmental data, and traffic data. The type of data permitted to be shared indicated in the sharing policy is traffic data, while network data and environmental data are not permitted to be shared.
[0107] It is understandable that at least one item of information included in the above-mentioned sharing policy may be separate or combined. For example, the sharing policy indicates a list of network management service consumer entities that are allowed to share and use the first data set, and the sharing policy may further indicate the usage rights of the first data set. For another example, the sharing policy indicates a list of network management service consumer entities that are allowed to share and use the first data set, and the sharing policy may further indicate the identifier and / or type of data in the first data set that is allowed to be shared. Exemplarily, the above-mentioned first information and the sharing policy of the above-mentioned first data set may be included in different messages or in the same message.
[0108] Among them, the first data set is provided by the first network management service consuming entity to the network management service providing entity. The first data set may include user data of the first network management service consuming entity, which may be one or more data packets, or a certain type of data, without limitation. For example, when the first network management service consuming entity requests the network management service providing entity to execute the first twin service or before requesting to execute the first twin service, the first data set is provided to the network management service providing entity. The first data set may be sent separately by the first network management service consuming entity to the network management service providing entity, or it may be carried in a request sent to the network management service providing entity, which request is used for the first twin service.
[0109] Since the first data set is provided by the first network management service consuming entity and may be private data of the first network management service consuming entity, the first network management service consuming entity may decide whether to share it with other network management service consuming entities.
[0110] It should be noted that step S401 is an optional step and other implementation methods can also be used. For example, if the first network management service consuming entity does not send the first information to the network management service providing entity, the network management service providing entity cannot share the first data set with other network management service consuming entities. For another example, the first network management service consuming entity sends second information to the network management service providing entity, and the second information is used to indicate that the first data set from the first network management service consuming entity is not allowed to be shared; then, the network management service providing entity cannot share the first data set with other network management service consuming entities, but can share data other than the first data set with other network management service consuming entities. In this way, the privacy of the data from the first network management service consuming entity can be protected and the security of its data can be improved.
[0111] S402. The second network management service consuming entity sends a first request to the network management service providing entity.
[0112] Accordingly, the network management service providing entity receives the first request.
[0113] In the communication scenario, there may be other network management service consuming entities (eg, a second network management service consuming entity) that sends a first request to the network management service providing entity.
[0114] The first request is used to request the second twin service.
[0115] The second network management service consumption entity is any network management service consumption entity except the first network management service consumption entity.
[0116] S403. The network management service providing entity sends a response to the first request to the second network management service consuming entity based on the first request and at least a portion of the data in the first data set.
[0117] Accordingly, the second network management service consumer entity receives the response. The response may include the execution result of the second twin service. For example, the second twin service is a simulation of a certain strategy, and the execution result may include a simulation result of whether the strategy can achieve the expected effect when executed on the physical network.
[0118] Exemplarily, after receiving the first request, the network management service providing entity determines that at least a portion of the data in the first data set needs to be used when executing the second twin service. Furthermore, if the network management service providing entity has received the first information, the network management service providing entity uses at least a portion of the data in the first data set to execute the second twin service, obtains the execution result of the second twin service, and sends a response to the first request to the second network management service consuming entity.
[0119] The at least part of the data may be part of the data or all of the data in the first data set, without limitation.
[0120] According to a data management method provided in an embodiment of the present application, the first network management service consumer entity that provides data indicates to the network management service providing entity that it allows sharing of the data, so that when the network management service providing entity receives a request from the second network management service consumer entity, it can use the data to execute the requested twin service according to the indication, thereby improving the security of the data.
[0121] Optionally, in an implementation scenario of the above embodiment, the above method also includes: the network management service providing entity receives a second request from the first network management service consuming entity, and the second request is used to request a first twin service; the network management service providing entity creates a first twin instance based on the second request, and the first twin instance includes a first data set; and the network management service providing entity executes the first twin service based on the first twin instance.
[0122] At this time, step S403 may include: the network management service providing entity determines to use at least part of the data in the first data set to execute the second twin service based on the first request and the first information; and the network management service providing entity executes the second twin service based on at least part of the data in the first data set.
[0123] In this implementation scenario, the first data set is included in the first twin instance. When the network management service providing entity executes the second twin service, it needs to execute the second twin service based on the twin instance. When receiving the first request, the network management service providing entity determines whether to create a new twin instance, or partially share the existing twin instance (such as the first twin instance mentioned above), or fully share the existing twin instance. In the prior art, all currently created twin instances can be shared and reused by default, but due to the different privacy requirements of the data in the twin instances, the existing methods cannot guarantee the isolation and security of the data between twin instances. In this embodiment, when the network management service providing entity resolves and executes the second twin service, it determines that the first twin instance can be shared to execute the second twin service based on the first information. If the first network management service consuming entity does not carry the first information in the second request, or the first network management service consuming entity indicates that sharing the first twin instance is not allowed, the network management service providing entity cannot share the first twin instance to execute the second twin service. If the above-mentioned first data set is included in the first twin instance, when the first twin instance is partially or completely shared to execute the second twin business, it is considered that the first data set is partially or completely used at the same time.
[0124] After receiving the first request, the network management service providing entity parses the second twin object, the second twin service type, and the second service configuration included in the first request, and determines to use at least a portion of the data in the first data set to execute the second twin service. The at least a portion of the data in the first data set may be part or all of the data in the first data set.
[0125] Still referring to Figure 2 , when network management service consuming entity A requests the network management service providing entity to execute its own flow control policy simulation service, it provides user traffic data to the network management service providing entity. When network management service consuming entity B requests the network management service providing entity to execute another policy of its own (e.g., an energy-saving policy), the network management service providing entity determines that executing network management service consuming entity B's policy also requires the use of the aforementioned user traffic data.
[0126] After the network management service providing entity determines to use at least a portion of the data in the first data set to execute the second twin service, and determines based on the first information that the first network management service consuming entity allows sharing of the first data set, the network management service providing entity uses at least a portion of the data in the first data set to execute the second twin service.
[0127] Optionally, in another implementation scenario of the above embodiment, the above method further includes: the network management service providing entity stores the first data set in a database based on the first information.
[0128] At this time, step S403 may include: the network management service provider entity searches for at least part of the data in the first data set in the database according to the first request; and the network management service provider entity executes the second twin service according to at least part of the data in the first data set.
[0129] In this implementation scenario, when the first data set is not included in the first twin instance but is stored separately in the database, the network management service provider entity determines, after receiving the first request, to use at least a portion of the data in the first data set to execute the second twin service based on the first request. And the network management service provider entity determines, based on the first information, that the first network management service consumer entity is allowed to share the first data set. The network management service provider entity then searches the database for at least a portion of the data in the first data set, and executes the second twin service based on at least a portion of the data in the first data set. In this scenario, the network management service provider entity may execute the second twin service based on the twin instance, or it may not execute the second twin service based on the twin instance.
[0130] In one scenario, the first information may be carried in the second request sent by the first network management service consuming entity. This is described below through an embodiment:
[0131] As shown in Figure 5, it is a flowchart of another data management method provided in an embodiment of the present application. Exemplarily, the method may include the following steps:
[0132] S501. A first network management service consuming entity sends a second request to a network management service providing entity.
[0133] Correspondingly, the network management service providing entity receives the second request.
[0134] Among them, the second request is used to request the first twin service, that is, to request the network management service provider entity to execute the first twin service.
[0135] The second request may include at least one of the following information: a first twin object, a first twin service type, and a first service configuration. For example, the first twin object may be a network element in a communication system, such as an AMF; the first twin service type may be a simulation of executing a certain policy on a physical network; and the first service configuration may be the resource configuration required to execute the policy.
[0136] In this embodiment, the first network management service consuming entity provides a first data set to the network management service providing entity. For example, the first network management service consuming entity provides the first data set to the network management service providing entity when requesting the network management service providing entity to perform the first twin service or before requesting the execution of the first twin service.
[0137] Among them, the first data set can be sent separately by the first network management service consuming entity to the network management service providing entity (the step of sending the first data set separately can occur before step S501, or can be performed simultaneously with step S501, or can occur after step S501, and this application does not impose any restrictions on this), or it can be carried in the above-mentioned second request without any restrictions.
[0138] Since the first data set is provided by the first network management service consuming entity and may be private data of the first network management service consuming entity, the first network management service consuming entity may decide whether to share it with other network management service consuming entities.
[0139] The second request may further include first information, wherein the first information is used to indicate permission to share the first data set from the first network management service consuming entity.
[0140] It should be pointed out that if the first information is not included in the second request, the network management service providing entity cannot share the first data set with other network management service consuming entities. Alternatively, if the second request includes second information, and the second information is used to indicate that the sharing of the first data set from the first network management service consuming entity is not allowed, the network management service providing entity cannot share the first data set with other network management service consuming entities. This can protect the privacy of the data from the first network management service consuming entity and improve the security of its data. By carrying the first information in the second request, when the first network management service consuming entity sends the second request (the first data set is required to execute the first twin business), it indicates that other network management service consuming entities are allowed to share the first data set, which simplifies the subsequent use process of the first data set and improves data management efficiency.
[0141] Optionally, the first network management service consuming entity may further indicate whether different data in the first data set can be shared by indicating a sharing policy for the first data set, thereby enabling partial data sharing without privacy risks. Therefore, the first network management service consuming entity may further send the sharing policy for the first data set to the network management service providing entity. For details, see the relevant description in step S401 and will not be repeated here.
[0142] S502. The network management service providing entity creates a first twin instance based on the second request.
[0143] In this embodiment, the network management service providing entity executes the above-mentioned first twin service based on the twin instance. Therefore, after receiving the second request, the network management service providing entity creates the first twin instance according to the second request.
[0144] Exemplarily, creating a first twin instance means obtaining corresponding data from the physical network and obtaining a corresponding model based on at least one of the following information included in the second request: a first twin object, a first twin service type, and a first service configuration. The first twin instance is used to simulate the network environment in which the physical network operations included in the first twin service are executed on the physical network.
[0145] S503. The network management service providing entity executes the first twin service based on the first twin instance. After the network management service providing entity creates the first twin instance, it executes the first twin service based on the first twin instance. For example, if the first twin service is a simulation energy-saving strategy, executing the first twin service means simulating the execution of the energy-saving strategy in the physical network and obtaining the results of the execution, such as the energy-saving effect achieved.
[0146] When the network management service providing entity executes the first twin service, it needs to use the above-mentioned first data set.
[0147] In one implementation, the first data set may be included in the first twin instance, that is, when the network management service provider entity creates the first twin instance, the first data set is included in the first twin instance. The first information may be used to indicate that the first twin instance is allowed to be shared. After receiving the first information, the network management service provider entity may determine that the first network management service consumer entity allows the sharing of the first data set in the first twin instance.
[0148] In another implementation, the first data set may be independent of the first twin instance, that is, the first twin instance created by the network management service provider does not include the first data set. After receiving the first data set, the network management service provider may store the first data set in a database.
[0149] S504. The network management service providing entity sends a response to the second request to the first network management service consuming entity.
[0150] Accordingly, the first network management service consuming entity receives the response.
[0151] Among them, the response includes the execution result of the first twin business.
[0152] S505. The second network management service consuming entity sends a first request to the network management service providing entity.
[0153] Accordingly, the network management service providing entity receives the first request.
[0154] In the communication scenario, there may be other network management service consuming entities (e.g., a second network management service consuming entity) that sends a first request to the network management service providing entity. The first request is used to request a second twin service. The second network management service consuming entity is any network management service consuming entity other than the first network management service consuming entity.
[0155] The first request includes at least one of the following information: a second twin object, a second twin business type, and a second business configuration. For the meanings of the second twin object, the second twin business type, and the second business configuration, please refer to the descriptions of the first twin object, the first twin business type, and the first business configuration, respectively, and will not be repeated here.
[0156] S506. The network management service providing entity determines, based on the first request and the first information, to use at least a portion of the data in the first data set to execute the second twin service.
[0157] After receiving the first request, the network management service provider entity parses the second twin object, the second twin service type, and the second service configuration included in the first request, and determines that at least a portion of the data in the first data set is required to execute the second twin service. The at least a portion of the data in the first data set may be part or all of the data in the first data set.
[0158] Still referring to Figure 2 , when network management service consuming entity A requests the network management service providing entity to execute its own flow control policy simulation service, it provides user traffic data to the network management service providing entity. When network management service consuming entity B requests the network management service providing entity to execute another policy of its own (e.g., an energy-saving policy), the network management service providing entity determines that executing network management service consuming entity B's policy also requires the use of the aforementioned user traffic data.
[0159] S507. The network management service providing entity executes the second twin service based on at least a portion of the data in the first data set.
[0160] After the network management service providing entity determines to use at least a portion of the data in the first data set to execute the second twin service, and determines based on the first information that the first network management service consuming entity allows sharing of the first data set, the network management service providing entity uses at least a portion of the data in the first data set to execute the second twin service.
[0161] The specific implementation of the above steps S506 and S507 can refer to the relevant description in the embodiment shown in FIG4 , which will not be repeated here.
[0162] S508. The network management service providing entity sends a response to the first request to the second network management service consuming entity.
[0163] Accordingly, the second network management service consuming entity receives the response.
[0164] After the network management service provider executes the second twin service, it obtains the execution result of the second twin service. The network management service provider sends a response to the first request to the second network management service consumer. The response includes the execution result of the second twin service.
[0165] According to a data management method provided by an embodiment of the present application, the first network management service consumer entity that provides data indicates to the network management service providing entity that it allows sharing of the data, so that when the network management service providing entity receives a request from the second network management service consumer entity, it can use the data to execute the requested twin service according to the instruction, thereby improving data security; and by carrying the first information in the second request, when the first network management service consumer entity sends the second request (the first data set is required to execute the first twin service), it indicates that other network management service consumer entities are allowed to share the first data set, which simplifies the subsequent use process of the first data set and improves data management efficiency.
[0166] In another scenario, since not all network management service consumption entities need to use the first data set when requesting twin services, the above-mentioned first information is not carried in the twin service request sent by the first network management service consumption entity. Instead, after the network management service providing entity receives the twin service request from the second network management service consumption entity, it confirms that it needs to use at least part of the data in the first data set, and then requests the first network management service consumption entity whether it can share at least part of the data in the first data set. The following is a description through embodiments:
[0167] FIG6 is a flow chart of another data management method provided in an embodiment of the present application. Exemplarily, the method may include the following steps:
[0168] S601. The first network management service consuming entity sends a second request to the network management service providing entity.
[0169] Correspondingly, the network management service providing entity receives the second request.
[0170] The second request is used to request the first twin service. The second request may include at least one of the following information: the first twin object, the first twin service type, and the first service configuration.
[0171] In one implementation, the second request further includes the first data set.
[0172] In another implementation, the first network management service consuming entity sends the first data set separately to the network management service providing entity. This step may occur before step S601, or may be performed simultaneously with step S601, or may occur after step S601, and this application does not limit this.
[0173] The specific implementation of this step may refer to step S501 of the embodiment shown in Figure 5. Different from step S501, the second request does not include the first information, ie, does not include information indicating permission to share the first data set.
[0174] S602. The network management service providing entity creates a first twin instance based on the second request.
[0175] For the specific implementation of this step, reference may be made to step S502 of the embodiment shown in FIG5 .
[0176] S603. The network management service providing entity executes the first twin business based on the first twin instance.
[0177] For the specific implementation of this step, reference may be made to step S503 of the embodiment shown in FIG5 .
[0178] S604: The network management service providing entity sends a response to the second request to the first network management service consuming entity. Correspondingly, the first network management service consuming entity receives the response.
[0179] Among them, the response includes the execution result of the first twin business.
[0180] For the specific implementation of this step, reference may be made to step S504 of the embodiment shown in FIG5 .
[0181] S605: The second network management service consuming entity sends a first request to the network management service providing entity. Correspondingly, the network management service providing entity receives the first request.
[0182] The first request is used to request the second twin service. The first request includes at least one of the following information: a second twin object, a second twin service type, and a second service configuration.
[0183] For the specific implementation of this step, reference may be made to step S505 of the embodiment shown in FIG5 .
[0184] S606. The network management service providing entity determines, based on the first request, that at least a portion of the data in the first data set needs to be used.
[0185] For the specific implementation of this step, reference may be made to step S506 of the embodiment shown in FIG5 .
[0186] S607: The network management service providing entity sends a third request to the first network management service consuming entity. Correspondingly, the first network management service consuming entity receives the third request.
[0187] In this embodiment, after the network management service providing entity determines, based on the first request, that it needs to use at least a portion of the data in the first data set, it sends a third request to the first network management service consuming entity. The third request is used to request permission to share at least a portion of the data in the first data set. Furthermore, the third request may also include an identifier of the second network management service consuming entity.
[0188] In some communication scenarios, since not all network management service consuming entities need to use the first data set when requesting twin services, the network management service providing entity, after receiving requests from other network management service consuming entities other than the first network management service consuming entity, determines that it needs to use at least a portion of the data in the first data set provided by the first network management service consuming entity, and then requests the first network management service consuming entity whether to allow the sharing of at least a portion of the data in the first data set. In this way, the first network management service consuming entity can make a more accurate decision on whether to allow the sharing of the first data set, better protect the privacy of the data, and improve the security of the data.
[0189] S608: The first network management service consuming entity sends a response to the third request to the network management service providing entity. Correspondingly, the network management service providing entity receives the response.
[0190] After receiving the third request from the network management service providing entity, the first network management service consuming entity determines whether to allow sharing of the first data set, and sends a response to the third request to the network management service providing entity. The response includes first information indicating that sharing of the first data set from the first network management service consuming entity is allowed.
[0191] Furthermore, the first network management service consuming entity can also indicate whether different data in the first data set can be shared by indicating the sharing policy of the first data set, thereby achieving partial data sharing without privacy risks. Therefore, the first network management service consuming entity can also send the sharing policy of the first data set to the network management service providing entity.
[0192] The sharing policy includes at least one of the following information:
[0193] a list of network management service consuming entities that are permitted to share the first data set; or
[0194] a list of network management service consuming entities that are not permitted to share the first data set; or
[0195] The usage rights of the first data set, where the usage rights include at least one of the following: read-only, write-only, read-write, and use-only; or
[0196] an identification of the data in the first data set that is permitted to be shared; or
[0197] The types of data in the first data set that are allowed to be shared.
[0198] For the meaning of this sharing strategy, please refer to the description above.
[0199] S609. The network management service providing entity executes the second twin service based on the first information and at least a portion of the data in the first data set.
[0200] For the specific implementation of this step, reference may be made to step S507 of the embodiment shown in FIG5 .
[0201] S610. The network management service providing entity sends a response to the first request to the second network management service consuming entity. Correspondingly, the second network management service consuming entity receives the response.
[0202] Among them, the response includes the execution result of the second twin business.
[0203] For the specific implementation of this step, reference may be made to step S508 of the embodiment shown in FIG. 5 .
[0204] According to a data management method provided by an embodiment of the present application, upon receiving a request from a network management service consuming entity other than a first network management service consuming entity, a network management service providing entity only requests the first network management service consuming entity whether to allow sharing of at least a portion of the first data set provided by the first network management service consuming entity if the entity determines that it needs to use the at least a portion of the data in the first data set. This allows the first network management service consuming entity to more accurately decide whether to allow sharing of the first data set, thereby better protecting data privacy and improving data security.
[0205] It can be understood that in each of the above embodiments, the methods and / or steps implemented by the network management service providing entity can also be implemented by components (such as chips or circuits) that can be used for the network management service providing entity; the methods and / or steps implemented by the first network management service consuming entity can also be implemented by components (such as chips or circuits) that can be used for the first network management service consuming entity; the methods and / or steps implemented by the second network management service consuming entity can also be implemented by components (such as chips or circuits) that can be used for the second network management service consuming entity.
[0206] The above description primarily describes the solutions provided by the embodiments of the present application from the perspective of interactions between various entities. Accordingly, embodiments of the present application also provide a data management device for implementing the various methods described above. The data management device can be a network management service provider entity in the above method embodiments, or a component usable by the network management service provider entity; alternatively, the data management device can be a first network management service consumer entity in the above method embodiments, or a component usable by the first network management service consumer entity; alternatively, the data management device can be a second network management service consumer entity in the above method embodiments, or a component usable by the second network management service consumer entity. It will be understood that, to implement the aforementioned functions, the data management device includes hardware structures and / or software modules corresponding to each function. Those skilled in the art will readily appreciate that, in conjunction with the various exemplary units and algorithm steps described in the embodiments disclosed herein, the present application can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0207] In the embodiment of the present application, the data management device may be divided into functional modules according to the above method embodiment. For example, each functional module may be divided according to each function, or two or more functions may be integrated into one processing unit. The above integrated modules may be implemented in the form of hardware or software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. In actual implementation, other division methods may be used.
[0208] Based on the same concept of the above data management method, this application also provides the following data management device:
[0209] As shown in FIG7 , a schematic diagram of the structure of a data management device provided in an embodiment of the present application is shown. The data management device 7000 includes a transceiver unit 701 and a processing unit 702 .
[0210] When the data management device is used to implement the functions of the network management service provider entity in the above-mentioned method embodiment, the transceiver unit 701 is used to execute one or more of steps S401 to S403 performed by the network management service provider entity in the embodiment shown in FIG4 . Alternatively, the transceiver unit 701 is used to execute one or more of steps S501, S504, S505, and S508 performed by the network management service provider entity in the embodiment shown in FIG5 ; and the processing unit 702 is used to execute one or more of steps S502, S503, S506, and S507 performed by the network management service provider entity in the embodiment shown in FIG5 . Alternatively, the transceiver unit 701 is used to execute one or more of steps S601, S604, S605, S607, S608, and S610 performed by the network management service provider entity in the embodiment shown in FIG6 ; and the processing unit 702 is used to execute one or more of steps S602, S603, S606, and S609 performed by the network management service provider entity in the embodiment shown in FIG6 .
[0211] When the data management device is used to implement the functions of the first network management service consuming entity in the above-mentioned method embodiment, the transceiver unit 701 is used to execute the steps performed by the first network management service consuming entity in step S401 in the embodiment shown in FIG4 . Alternatively, the transceiver unit 701 is used to execute one or more of the steps performed by the first network management service consuming entity in steps S501 and S504 in the embodiment shown in FIG5 . Alternatively, the transceiver unit 701 is used to execute one or more of the steps performed by the first network management service consuming entity in steps S601, S604, S607, and S608 in the embodiment shown in FIG6 .
[0212] When the data management device is used to implement the functions of the second network management service consuming entity in the above-mentioned method embodiment, the transceiver unit 701 is used to execute one or more of the steps S402 and S403 executed by the second network management service consuming entity in the embodiment shown in FIG4 . Alternatively, the transceiver unit 701 is used to execute one or more of the steps S505 and S508 executed by the second network management service consuming entity in the embodiment shown in FIG5 . Alternatively, the transceiver unit 701 is used to execute one or more of the steps S605 and S610 executed by the second network management service consuming entity in the embodiment shown in FIG6 .
[0213] For the specific implementation of the above-mentioned transceiver unit 701 and the processing unit 702, reference may be made to the description in the above-mentioned method embodiment, which will not be repeated here.
[0214] As shown in Figure 8, a schematic diagram of the structure of another data management device provided in an embodiment of the present application is shown. The data management device 8000 includes a processor 801 and an interface circuit 802, and may also include a memory 803 (represented by a dotted line in the figure). The processor 801 and the interface circuit 802 are coupled to each other. It is understood that the interface circuit 802 can be a transceiver or an input / output interface. The memory 803 is used to store instructions executed by the processor 801, or to store input data required by the processor 801 to execute instructions, or to store data generated after the processor 801 executes instructions.
[0215] When the data management device is used to implement the functions of the network management service provider entity in the above-mentioned method embodiment, the interface circuit 802 is used to execute one or more of steps S401 to S403 performed by the network management service provider entity in the embodiment shown in FIG4 . Alternatively, the interface circuit 802 is used to execute one or more of steps S501, S504, S505, and S508 performed by the network management service provider entity in the embodiment shown in FIG5 ; and the processor 801 is used to execute one or more of steps S502, S503, S506, and S507 performed by the network management service provider entity in the embodiment shown in FIG5 . Alternatively, the interface circuit 802 is used to execute one or more of steps S601, S604, S605, S607, S608, and S610 performed by the network management service provider entity in the embodiment shown in FIG6 ; and the processor 801 is used to execute one or more of steps S602, S603, S606, and S609 performed by the network management service provider entity in the embodiment shown in FIG6 .
[0216] When the data management device is used to implement the functions of the first network management service consuming entity in the above-mentioned method embodiment, the interface circuit 802 is used to execute the steps performed by the first network management service consuming entity in step S401 in the embodiment shown in FIG4 . Alternatively, the interface circuit 802 is used to execute one or more of the steps performed by the first network management service consuming entity in steps S501 and S504 in the embodiment shown in FIG5 . Alternatively, the interface circuit 802 is used to execute one or more of the steps performed by the first network management service consuming entity in steps S601, S604, S607, and S608 in the embodiment shown in FIG6 .
[0217] When the data management device is used to implement the functions of the second network management service consuming entity in the above-mentioned method embodiment, the interface circuit 802 is used to execute one or more items executed by the second network management service consuming entity in steps S402 and S403 of the embodiment shown in FIG4 . Alternatively, the interface circuit 802 is used to execute one or more items executed by the second network management service consuming entity in steps S505 and S508 of the embodiment shown in FIG5 . Alternatively, the interface circuit 802 is used to execute one or more items executed by the second network management service consuming entity in steps S605 and S610 of the embodiment shown in FIG6 .
[0218] When the data management device is a chip applied to a network management service provider, the chip implements the functions of the network management service provider in the above method embodiment. The chip receives information from other modules (such as a radio frequency module or an antenna) in the network management service provider, and the information is sent to the network management service provider by the first network management service consumer or the second network management service consumer; or the chip sends information to other modules (such as a radio frequency module or an antenna) in the network management service provider, and the information is sent to the first network management service consumer or the second network management service consumer by the network management service provider.
[0219] When the data management device is a chip applied to the first / second network management service consuming entity, the chip implements the functions of the first / second network management service consuming entity in the above method embodiment. The chip receives information from other modules (such as a radio frequency module or antenna) in the first / second network management service consuming entity, where the information is sent by the network management service providing entity to the first / second network management service consuming entity; or the chip sends information to other modules (such as a radio frequency module or antenna) in the first / second network management service consuming entity, where the information is sent by the first / second network management service consuming entity to the network management service providing entity.
[0220] In addition, it should be noted that the aforementioned transceiver unit and / or processing unit may be implemented through virtual modules, for example, the processing unit may be implemented through a software function unit or a virtual device, and the transceiver unit may be implemented through a software function or a virtual device. Alternatively, the processing unit or transceiver unit may also be implemented through a physical device, for example, if the device is implemented using a chip / chip circuit, the transceiver unit may be an input / output circuit and / or a communication interface, performing input operations (corresponding to the aforementioned receiving operations) and output operations (corresponding to the aforementioned sending operations); the processing unit is an integrated processor or microprocessor or integrated circuit.
[0221] The division of modules in this application is illustrative and represents only a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the examples of this application may be integrated into a single processor, exist physically as separate modules, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in either hardware or software functional modules.
[0222] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0223] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is executed, the method in the above embodiment is implemented.
[0224] An embodiment of the present application further provides a computer program product comprising instructions, which, when executed on a computer, enables the computer to execute the method in the above embodiment.
[0225] An embodiment of the present application also provides a data management system, including the above-mentioned data management device.
[0226] The present application also provides a circuit, which is coupled to a memory and is used to execute the method shown in the above embodiment. The circuit may include a chip circuit.
[0227] It should be noted that the above units or one or more of the units can be implemented by software, hardware, or a combination of the two. When any of the above units or units is implemented by software, the software exists in the form of computer program instructions and is stored in a memory, and a processor can be used to execute the program instructions and implement the above method flow.
[0228] In this application, a processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the methods, steps, and logic block diagrams disclosed in this application. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in this application may be directly executed by a hardware processor, or by a combination of hardware and software modules within the processor.
[0229] The processor can be built into a system on chip (SoC) or ASIC, or it can be a standalone semiconductor chip. In addition to the core that executes software instructions to perform calculations or processing, the processor can also include necessary hardware accelerators, such as field programmable gate arrays (FPGAs), programmable logic devices (PLDs), or logic circuits that implement specialized logic operations.
[0230] When the above units or units are implemented in hardware, the hardware can be any one or any combination of a CPU, a microprocessor, a digital signal processing (DSP) chip, a microcontroller unit (MCU), an artificial intelligence processor, an ASIC, a SoC, an FPGA, a PLD, a dedicated digital circuit, a hardware accelerator or a non-integrated discrete device, which can run the necessary software or not rely on the software to execute the above method flow.
[0231] Optionally, an embodiment of the present application further provides a chip system, comprising: at least one processor and an interface, wherein the at least one processor is coupled to a memory via the interface, and when the at least one processor executes a computer program or instruction in the memory, the chip system executes the method in any of the above method embodiments. Optionally, the chip system may be composed of a chip, or may include a chip and other discrete devices, which is not specifically limited in the embodiments of the present application.
[0232] In the present application, the memory may be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or a volatile memory, such as a random-access memory (RAM). The memory is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory in the present application may also be a circuit or any other device that can implement a storage function, for storing program instructions and / or data.
[0233] The terms "comprising" and "having," as used in this application, and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or device comprising a series of steps or units is not limited to the listed steps or units, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to the process, method, product, or device. "A" or "an" does not exclude a plurality. It should be noted that, in this application, words such as "exemplary" or "for example" are used to indicate an example, illustration, or illustration. Any method or design described in this application as "exemplary" or "for example" should not be construed as preferred or advantageous over other methods or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner. A single processor or other unit may perform several of the functions listed in a claim. The fact that certain measures are recited in different dependent claims does not mean that these measures cannot be combined to produce advantageous results.
[0234] The following specific embodiments illustrate the implementation of the present application. Those skilled in the art can understand other advantages and effects of the present application from the contents disclosed in this specification. Although the description of the present application will be introduced in conjunction with the preferred embodiment, this does not mean that the features of this application are limited to this implementation. On the contrary, the purpose of introducing the application in conjunction with the implementation is to cover other options or modifications that may be extended based on the claims of the present application. In order to increase the in-depth understanding of the present application, the following description will contain many specific details. The present application can also be implemented without using these details. In addition, in order to avoid confusion or blurring the focus of the present application, some specific details will be omitted in the description. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other unless there is a conflict.
[0235] It should be understood that in the description of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B; wherein A and B can be singular or plural. Also, in the description of this application, unless otherwise specified, "multiple" means two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, wherein a, b, c can be single or multiple. "And / or" describes the association relationship of the associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In the description of this application, unless otherwise specified, "multiple" means two or more. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0236] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using a software program, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital versatile disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).
[0237] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.
[0238] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0239] The components in the device of the embodiment of the present application can be merged, divided, or deleted according to actual needs. Those skilled in the art can combine or combine the different embodiments and features of the different embodiments described in this specification.
[0240] The above embodiments are intended only to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they may still modify the technical solutions described in the aforementioned embodiments or replace some of the technical features therein with equivalents; and such modifications or replacements do not deviate from the essence of the corresponding technical solutions within the scope of the technical solutions of the embodiments of the present application.
[0241] In this application, under the premise of no logical contradiction, the examples can reference each other, for example, the methods and / or terms between method embodiments can reference each other, for example, the functions and / or terms between device embodiments can reference each other, for example, the functions and / or terms between device examples and method examples can reference each other.
[0242] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.
Claims
1. A data management method, characterized in that: The method comprises: The network management service providing entity receives first information from a first network management service consuming entity, where the first information is used to indicate that sharing of a first data set from the first network management service consuming entity is allowed; The network management service providing entity receives a first request from a second network management service consuming entity, where the first request is used to request a second twin service; The network management service providing entity sends a response to the first request to the second network management service consuming entity based on the first request and at least a portion of the data in the first data set, and the response includes the execution result of the second twin service.
2. The method according to claim 1, wherein The first request includes at least one of the following information: twin object, twin business type, and business configuration.
3. The method according to claim 1 or 2, wherein: The method further comprises: The network management service providing entity receives a second request from the first network management service consuming entity, where the second request is used to request a first twin service; The network management service providing entity creates a first twin instance according to the second request, where the first twin instance includes the first data set; The network management service providing entity executes the first twin service based on the first twin instance; The network management service providing entity sends a response to the first request to the second network management service consuming entity according to the first request and at least a portion of the data in the first data set, including: The network management service providing entity determines, based on the first request and the first information, to use at least a portion of the data in the first data set to execute the second twin service; The network management service providing entity executes the second twin service based on at least a portion of the data in the first data set.
4. The method according to claim 1 or 2, wherein: The method further comprises: The network management service providing entity stores the first data set in a database according to the first information; The network management service providing entity sends a response to the first request to the second network management service consuming entity according to the first request and at least a portion of the data in the first data set, including: The network management service providing entity searches the database for at least a portion of the data in the first data set according to the first request; The network management service providing entity executes the second twin service based on at least a portion of the data in the first data set.
5. The method according to claim 3, wherein The first information is carried in the second request.
6. The method according to any one of claims 1 to 4, wherein After the network management service providing entity receives the first request from the second network management service consuming entity, the method further includes: The network management service providing entity sends a third request to the first network management service consuming entity based on the first request, wherein the third request is used to request permission to share at least a portion of the data in the first data set, and the first information is carried in the response to the third request.
7. The method according to claim 6, wherein The network management service providing entity sends a third request to the first network management service consuming entity according to the first request, including: The network management service providing entity determines, according to the first request, to use at least a portion of the data in the first data set to execute the second twin instance; The network management service providing entity sends the third request to the first network management service consuming entity.
8. The method according to claim 5 or 6, wherein: The method further comprises: The network management service providing entity receives a sharing policy for the first data set from the first network management service consuming entity; wherein the sharing policy includes at least one of the following information: a list of network management service consuming entities that are permitted to share and use said first data set; or a list of network management service consuming entities that are not permitted to share the use of said first data set; or The usage rights of the first data set, wherein the usage rights include at least one of the following: read-only, write-only, read-write, and use-only; or an identification of the data in the first data set that is allowed to be shared; or The types of data in the first data set that are allowed to be shared.
9. A data management method, characterized in that: The method comprises: A first network management service consuming entity sends first information to a network management service providing entity, where the first information is used to indicate that sharing of a first data set from the first network management service consuming entity is allowed.
10. The method according to claim 9, wherein The method further comprises: The first network management service consuming entity sends a second request to the network management service providing entity, where the second request is used to request a first twin service; The first data set is included in a first twin instance created by the network management service providing entity according to the second request.
11. The method according to claim 10, wherein The first information is carried in the second request.
12. The method according to claim 9, wherein The method further comprises: The first network management service consuming entity receives a third request from the network management service providing entity, where the third request is used to request permission to share at least a portion of the first data set, and the first information is carried in a response to the third request.
13. The method according to any one of claims 9 to 12, wherein: The method further comprises: The first network management service consuming entity sends a sharing policy for the first data set to the network management service providing entity; wherein the sharing policy includes at least one of the following information: a list of network management service consuming entities that are permitted to share and use said first data set; or a list of network management service consuming entities that are not permitted to share the use of said first data set; or The usage rights of the first data set, wherein the usage rights include at least one of the following: read-only, write-only, read-write, and use-only; or an identification of the data in the first data set that is allowed to be shared; or The types of data in the first data set that are allowed to be shared.
14. A data management method, characterized in that: The method comprises: The second network management service consuming entity sends a first request to the network management service providing entity, where the first request is used to request a second twin service; The second network management service consuming entity receives a response to the first request from the network management service providing entity, the response including the execution result of the second twin business, the response being obtained based on the first request and at least a portion of the data in the first data set, the first data set coming from the first network management service consuming entity, and the first network management service consuming entity indicating that sharing of the first data set is allowed.
15. The method according to claim 14, wherein The first request includes at least one of the following information: twin object, twin business type, and business configuration.
16. A data management device, characterized in that: The apparatus comprises a unit for implementing the method according to any one of claims 1 to 8, or comprises a unit for implementing the method according to any one of claims 9 to 13, or comprises a unit for implementing the method according to claim 14 or 15.
17. A data management device, characterized in that: The data management device comprises a processor, a memory, and instructions stored in the memory and executed on the processor, wherein when the instructions are executed, the data management device executes the method as described in any one of claims 1 to 8, or executes the method as described in any one of claims 9 to 13, or executes the method as described in claim 14 or 15.
18. A data management system, characterized in that: The method comprises a network management service providing entity, a first network management service consuming entity and a second network management service consuming entity, wherein the network management service providing entity is used to execute the method according to any one of claims 1 to 8, the first network management service consuming entity is used to execute the method according to any one of claims 9 to 13, and the second network management service consuming entity is used to execute the method according to claim 14 or 15.
19. A computer-readable storage medium, characterized in that The computer-readable storage medium includes instructions, and when the instructions are executed by a processor, the method according to any one of claims 1 to 15 is implemented.
20. A computer program product comprising instructions, characterized in that When the instruction is executed on a data management device, the data management device is caused to execute the method according to any one of claims 1 to 15.