VFL role based authorization
A common authorization framework for VFL in cellular networks addresses role authorization issues, enhancing data privacy and collaboration efficiency by managing VFL roles and interactions, thus improving the accuracy of machine learning models.
Patent Information
- Application Number
- PCT/IB2025/053483
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-04
- Filing Date
- 2025-04-02
- Publication Date
- 2025-10-09
AI Technical Summary
There is no framework to address the authorization of different roles in vertical federated learning (VFL) groups within cellular networks, particularly in scenarios involving different domains and vendors, which is crucial for ensuring data privacy and collaboration efficiency.
A common authorization framework is proposed for vertical federated learning in cellular networks, involving enhanced NF profile registration, updated access token requests, and access token claims to manage and authorize various VFL roles and interactions between network function service producers and consumers.
This framework enables secure and efficient collaboration among network functions in VFL by defining and managing different roles, ensuring data privacy and improving the accuracy of machine learning models through authorized interactions.
Smart Images

Figure 00000050_0000 
Figure 00000053_0000 
Figure 00000054_0000
Abstract
Description
VFL ROLE BASED AUTHORIZATIONTECHNICAL FIELD
[0001] Examples of embodiments herein relate generally to cellular networks and, more specifically, relate to application of vertical federated learning (VFL) to issues in the cellular networks.BACKGROUND
[0002] Vertical federated learning (VFL) is a privacy -preserving machine learning technique that allows multiple parties to collaboratively train a machine learning (ML) model on their combined datasets without sharing their raw data with each other. This approach is particularly useful in scenarios where data privacy is a concern, such as when dealing with sensitive personal information or proprietary business data.
[0003] In traditional federated learning, multiple parties each have access to their own datasets, and a central server coordinates the training process by aggregating model updates from each party. However, in some cases, the datasets held by different parties may contain complementary information that could improve the accuracy of the trained model if combined. Vertical federated learning addresses this scenario by allowing parties to collaborate on model training while keeping their datasets separate and private.
[0004] The term "vertical" in vertical federated learning refers to the structure of the data being used for training. In this context, the data held by each party typically represents different features or attributes of the same set of entities (e.g., users, customers, patients). For example, one party may have access to demographic information about individuals, while another party may have access to their purchasing history. By collaboratively training a machine learning model on these vertically partitioned datasets, parties can leverage the complementary information to improve the model's performance without sharing sensitive data directly.
[0005] VFL can be applied to cellular networks, though issues remain.BRIEF SUMMARY
[0006] This section is intended to include examples and is not intended to be limiting.
[0007] In an exemplary embodiment, a method is disclosed that includes registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token claims comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
[0008] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0009] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating oneor more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token claims comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
[0010] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token claims comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
[0011] In another exemplary embodiment, an apparatus comprises means for: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profilehaving one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token claims comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
[0012] In an exemplary embodiment, a method is disclosed that includes sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
[0013] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein thecomputer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0014] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
[0015] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction andindicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
[0016] In another exemplary embodiment, an apparatus comprises means for: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
[0017] In an exemplary embodiment, a method is disclosed that includes registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network functionprofile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
[0018] An additional exemplary embodiment includes a computer program, comprising instructions for performing the method of the previous paragraph, when the computer program is run on an apparatus. The computer program according to this paragraph, wherein the computer program is a computer program product comprising a computer-readable medium bearing the instructions embodied therein for use with the apparatus. Another example is the computer program according to this paragraph, wherein the program is directly loadable into an internal memory of the apparatus.
[0019] An exemplary apparatus includes one or more processors and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
[0020] An exemplary computer program product includes a computer-readable storage medium bearing instructions that, when executed by an apparatus, cause the apparatus to perform at least the following: registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learningrole and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
[0021] In another exemplary embodiment, an apparatus comprises means for: registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings use reference numerals, where the same reference numerals may be used to refer to like parts throughout, but parts having the same reference numeral can differ in operation and components. In the attached drawings:
[0023] FIG. 1 is a signaling diagram illustrating NF service consumer obtaining access token before NF service access;
[0024] FIG. 2 is a table including VFL information in accordance with an exemplary embodiment;
[0025] FIG. 3 is a table providing definition of type AccessTokenClaims in an exemplary embodiment;
[0026] FIG. 4 is a signaling diagram for VFL Role Based Authorization; and
[0027] FIG. 5 is a block diagram of one possible and non-limiting exemplary system in which the exemplary embodiments may be practiced.DETAILED DESCRIPTION OF THE DRAWINGS
[0028] Abbreviations that may be found in the specification and / or the drawing figures are defined below, at the end of the detailed description section.
[0029] The word “exemplary” is used herein to mean “serving as an example, instance, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments. All of the embodiments described in this Detailed Description are exemplary embodiments provided to enable persons skilled in the art to make or use the examples.
[0030] When more than one drawing reference numeral, word, or acronym is used within this description with “ / ”, and in general as used within this description, the “ / ” may be interpreted as “or”, “and”, or “both”. As used herein, “at least one of the following: ” and “at least one of ” and similar wording, where the list of two or more elements are joined by “and” or “or,” mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.
[0031] As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises”, “comprising”, “has”, “having”, “includes” and / or “including”, when used herein, specify the presence of stated features, elements, and / or components etc., but do not preclude the presence or addition of one or more other features, elements, components and / or combinations thereof.
[0032] It is noted that capital and lowercase words or phrases are considered to be the same herein. For instance, the words Slice and slice are the same, as are the phrases Network Repository Function and network repository function.
[0033] Any flow diagram or signaling diagram (such as FIGS, land 4) herein is considered to be a logic flow diagram, and illustrates the operation of an exemplary method, results of execution of computer program instructions embodied on a computer readable memory, functions performed by logic implemented in hardware, and / or interconnected means for performing functions in accordance with an exemplary embodiment. Block diagrams (such asFIG. 5) also illustrate the operation of an exemplary method, results of execution of computer program instructions embodied on a computer readable memory, functions performed by logic implemented in hardware, and / or interconnected means for performing functions in accordance with an exemplary embodiment. For methods, flow diagrams, and signaling diagrams, the orders of method steps, blocks in the flow, or signaling are not critical and instead are examples.
[0034] Technical context is now provided for technical areas related to the understanding of the examples. The following has been agreed in SA3 SID:
[0035] Based on the SA2 endorsed document SP-231800 and progress, some objectives are related to security aspects:
[0036] (I) WT#1: Study whether and how to consider enhancements to LCS to support AI / ML based Positioning considering the conclusions in 3GPP TR 38.843.
[0037] a) Potential security aspect:
[0038] b) Based on conclusions in 3GPP TR 38.843 and RAN-approved WID RP- 234039, five use cases (i.e., case 1, 2a, 2b, 3a, 3b) which will be studied by RAN. And as agreed in 3GPP TR 23.700-84, only case 2b and case 3b (i.e., model is on the LMF) will be studied at this stage, and the main issue is to study model transition between LMF and NWDAF. Thus, the authorization of ML model retrieval should be considered.
[0039] c) For case 1 and 2a, the model is located in the UE side, and for case 3 a, the model is located in gNB side. There is no ML model transition, the only issue may be privacy of collected data, so it is based on RAN conclusion.
[0040] II) WT2: Study whether and what potential enhancements are needed to enable 5G system to assist in collaborative AI / ML operation involving 5GC / NWDAF and / or AF for “Vertical Federated Learning (VFL)”. The work will be based only on and limited to the scope of justified use cases.
[0041] a) Potential security aspect:
[0042] b) Authorization of members of VFL group. Security aspects of supporting cross-domain (i.e., 5G Core and AF) data transfer for Al model training using VFL, e.g., key exchange among members of VFL group if required, or the like.
[0043] 1. Objective
[0044] WT#1: Study security aspects on enhancements to LCS to support AI / ML based Positioning considering the conclusions in 3GPP TR 38.843 and TR 23.700-84.
[0045] WT#2: Security aspects of cross-domain (i.e., 5G Core and AF) VerticalFederated Learning:
[0046] WT#2.1 Authorization of members of the VFL group.
[0047] WT#2.2 Security aspects of enhancements on SA2 architecture to supportVFL.
[0048] For VFL, the following use cases exist:
[0049] 1 ) VFL among NWDAFs.
[0050] 2) VFL between AF and NWDAFs.
[0051] 3) NWDAF assisting VFL among AFs.
[0052] The following VFL roles are possible:
[0053] 1 ) VFL Initiator: Determines a VFL training process should be performed, involved in the discovery of VFL participants and VFL Model Training Preparation Phase.
[0054] 2) VFL Coordinator: The VFL Coordinator may need to be involved in theVFL process. When involved, the VFL Coordinator is responsible for maintaining the VFL process, i.e., by collecting required inputs from a set of participants in every iteration and providing them with the information needed to run the next iteration and for authorizing or removing VFL participants.
[0055] 3) Active VFL Participant: NF performing the VFL model training with the required data labels.
[0056] 4) Passive VFL Participant: NF performing the VFL model training without the data labels.
[0057] The combination of the roles depends on the specific scenario using the VFL joint model training process.
[0058] There is no framework to address these roles and their corresponding authorization of members of the VFL groups in a cellular network.
[0059] The examples herein address at least these issues. Since one can expect different roles in VFL belonging to different domains and vendors, a common authorization framework is proposed in examples, which can be used in various combinations of these aspects.
[0060] The following form parts of the examples.
[0061] 1. NF profile registration enhancement. NF (for, e.g., NWDAF, but can also be any other core NF involved in VFL) or AF (via NEF) registers its NF profile (referred hereinas an enhanced NF profile for the extra elements added) to the NRF. The enhanced NF profile will include additional VFL related parameters (relative to a current NF profile), consider the following:
[0062] a) AllowedVFLConsumerRole: Allowed VFL consumer role.
[0063] b) AllowedVendorperVFLConsumerRole: Allowed Vendors per VFL consumer role., e.g., when the VFL consumer is a passive participant, then allowed vendors of A, B; when the VFL consumer is an active participant, then allowed vendors of C, D. For instance, the vendor A could be Nokia, the vendor B could be Ericsson, and vendors C and D would be other vendors. This assumes A, B are not the same as C, D, but it could be possible that one or more would be the same (e.g., A, B for passive; A, D for active).
[0064] c) AllowedDomainForVFL (core or AF): Indicates whether a NF service consumer is allowed (e.g., to access a VFL interaction) from a core domain (e.g., a domain corresponding to a core network) or an AF domain.
[0065] It should be noted that there will be four VFL consumer roles defined, as follows: VFL Initiator, VFL coordinator, Active Participant, Passive Participant.
[0066] 2. Enhance Access Token Request procedure to include the requested domain.
[0067] In the Access Token Request (i.e., Nnrf_AccessToken_Get), the NF Service Consumer includes the Target NF / AF role of VFL, Source VFL role, Source VFL role domain, Vendor per VFL role, Target Domain per VFL role the consumer would like to access.
[0068] Referring to FIG. 1 , this figure is a signaling diagram illustrating NF service consumer obtaining access token before NF service access. See also 3GPP TS 33.501 section 13.4. This figure has signaling between an NF service consumer 99-1 and an authorization server (NRF) 99-2.
[0069] In step 1 , the NF service consumer 99- 1 requests an access token from the NRF 99-2 in the same PLMN using the Nnrf_AccessToken_Get request operation. The message includes the NF Instance Id(s) of the NF service consumer, the requested "scope" including the expected NF service name(s) and optionally "additional scope" information (i.e., requested resources and requested actions (service operations) on the resources), NF type of the expected NF producer instance and NF consumer. The service consumer may also include a list of NSSAIs or list of NSI IDs for the expected NF producer instances.
[0070] The message may include the NF Set ID of the expected NF service producer instances.
[0071] The message may also include the VFL information, i.e., the source VFL information (info) 120 comprising: Source NF / AF role of VFL, Source VFL role domain, Source VFL role vendor; and the target VFL information 110 comprising Target NF / AF role of VFL, Target VFL role domain, Target VFL role vendor. The VFL role can be VFL Initiator, VFL coordinator, Active Participant, Passive Participant.
[0072] In step 2, the NRF may optionally authorize the NF service consumer based on the requested VFL information and available VFL information in the NFprofile. See block 150. The NRF shall then generate an access token with appropriate claims included. The NRF digitally signs the generated access token based on a shared secret or private key as described in RFC 7515 (IETF RFC 7515: "JSON Web Signature (JWS)").
[0073] As is known, a claim provides assertions about one, such as a client application, to another, such as a resource server. Claims are name or value pairs that relay facts about the token subject. For example, a claim might contain facts about the security principle that the authorization server authenticated. The claims present in a specific token depend on many items, such as the type of token, the type of credential used to authenticate the subject, and the application configuration.
[0074] The claims in the token include the NF Instance Id of NRF (issuer), NF Instance Id of the NF Service consumer (subject), NF type of the NF Service producer (audience), expected service name(s), scope (scope), expiration time (expiration) and optionally "additional scope" information (allowed resources and allowed actions (service operations) on the resources). The claims may include a list of NSSAIs or NSI IDs for the expected NF producer instances. The claims may include the NF Set ID of the expected NF service producer instances. As seen in block 160, the claim may also include the allowed VFL role or forbidden VFL role of the expected NF producer and allowed vendor per VFL role, allowed Domain (Core or AF) of the source VFL role, and allowed domain (Core or AF) of the target VFL role.
[0075] In step 3, if the authorization is successful, the NRF sends an access token to the NF service consumer in the Nnrf_AccessToken_Get response operation, otherwise the NRF should reply based on OAuth 2.0 error response defined in RFC 6749, IETF RFC 6749: "OAuth2.0 Authorization Framework". The other parameters (e.g., the expiration time,“expires_in”, allowed scope) sent by NRF in addition to the access token are described in 3GPP TS 29.510.
[0076] The NF service consumer may store the received token(s). Stored tokens may be re-used for accessing service(s) from producer NF type listed in the claims (e.g., comprising scope, audience) during their validity time. See block 170.
[0077] Referring to FIG. 2, a table is shown including VFL information in accordance with an exemplary embodiment. The table can be applied to 3GPP TS 29.510, table 6.3.5.2.2-1: Definition of type AccessTokenReq. This IE contains the request information for the access token request, and may be used in step 1 of FIG. 1. Entry 210 shows an attribute name of Source VFL role, which has a data type of role, is optional (O), has a cardinality of 1...M, and a description of “This IE shall contain the source NF role”. Entry 220 shows an attribute name of Target VFL role, which has a data type of role, is optional (O), has a cardinality of 1...M, and a description of “This IE shall contain the source NF role”. Entry 230 has an attribute name of Source VFL role domain, with a data type of Domaininfo and a description of “This IE shall contain the sour NF role domain information”. Entry 240 has an attribute name of Target VFL role domain, with a data type of Domaininfo and a description of “This IE shall contain the sour NF role domain information”.
[0078] 3: Update Access Token claims to include allowed Resources within the NF producer.
[0079] Turning to FIG. 3, this figure is a table providing definition of type AccessTokenClaims in an exemplary embodiment. The table can be applied to table 6.3.5.2.4-1: Definition of type AccessTokenClaims, in 3GPP TS 29.510. Entry 310 has an attribute name of allowedVFLRole, with a data type of Array(Role), it is optional, has a cardinality of 0..N, and a description of “A white list of allowed VFL role that the consumer is allowed to target or access”. Entry 320 has an attribute name of forbiddenVFLRole, with a data type of Array(Role), it is optional, has a cardinality of 0..N, and a description of “A black list of allowed VFL role that the consumer is not allowed to target or access”. Entry 330 has an attribute name of allowedVendorPerVFLRole, with a data type of Vendor(Array(Role)), it is optional, has a cardinality of 0..N, and a description of “A white list of allowed vendor per VFL role that the consumer is allowed to target or access”. Entry 340 has an attribute name of forbiddenVendorPerVFLRole, with a data type of Vendor(Array(Role)), it is optional, has acardinality of 0..N, and a description of “A black list of vendors per VFL role that the consumer is not allowed to target or access”. Entry 350 has an attribute name of allowedDomainPerVFLRole, with a data type of Vendor(Array(Role)), it is optional, has a cardinality of 0..N, and a description of “A white list of allowed domain per VFL role that the consumer is allowed to target or access”. Entry 360 has an attribute name of forbiddenDomainPerVFLRole, with a data type of Vendor(Array(Role)), it is optional, has a cardinality of 0..N, and a description of “A black list of domains per VFL role that the consumer is not allowed to target or access”. As is known, a black list is a list of elements that are not allowed to be accessed, and a white list is a list of elements that are allowed to be accessed.
[0080] Entries 310-360 contain information useful for authorization, such as what can be used by the NFp (the NF service producer) to authorize the NFc (NF service consumer). This is described in more detail below. Note that one or more of 310-360 may be used.
[0081] 4 : Access token validation at the NFp (NF producer).
[0082] The NFp should authorize the NFc (NF consumer) based on enhanced access token validation and performs the roles allowed by access token.
[0083] Referring to FIG. 4, this figure is a signaling diagram for VFL Role Based Authorization. The entities are as follows: the NF service consumer 99-1; an NF service producer (e.g., NWDAF) 99-3; an authorization server (NRF) 99-2; an NEF 99-4; and an AF1 99-5. In the left side step 0, the NF service producer 99-2 registers with the NRF 99-2, the NFprofile having Allow VFLXX parameters defined above, e.g., in entries 310-360 of FIG. 3. This flow results in a VFL interaction between the NF service consumer 99-1 and the NF service producer 99-3.
[0084] In the right side of step 0, the NEF 99-4 registers with the NRF 99-2 with NEF1 NFprofile having AF details (AF1, AF2..), and Allow VFLXX parameters defined above, e.g., in entries 310-360 of FIG. 3. That is, in step 0, the NFp registers to the NRF about which NFc(s) are allowed at which role.
[0085] In step 1, the NF Service Consumer 99-1 discovers AF1 99-5 registered in NEF 99-4, and NRF 99-2 provides NEF1 NFprofile accordingly. In step 2, there is an Nnrf_AccessToken_Get Request (target NF Id: NWDAF, Consumer NF type, client id, SourceVFLRole, TargetVFLRole). The Source VFLRole may be defined by entry 210 in FIG. 2, and this defines the source NF role. The TargetVFLRole may be defined by entry 220 in FIG. 2,and this defines the target NF role. The request is one way the NFc can request attempt to participate in a VFL interaction (e.g., with the NFp).
[0086] In step 3, the NRF 99-2 authorizes the client to access the target and participate in the VFL interaction based on the parameters set in step 0, generate an enhanced access token with additional claims as defined in, e.g., entries 310-360. It is noted that another possibility is the NRF 99-2 denies access, although this is not addressed here. Step 4 is a response: 200 OK (AccessTokenRsp), and the content of the response contains the requested access token and the token type set to value "Bearer". The response in addition should contain the expiration time for the token unless the expiration time of the token is made available by other means, and contain the NF service name(s) of the requested NF service producer(s), if it is different from the scope included in the access token request.
[0087] In step 5, a service request is performed, between the NF service consumer 99-1 and the NF service producer 99-2, with Access_token(... allowedVFLxx..), where the allowedVFLxx 410 indicates at least with the source VFL role (see entry 210). There are multiple reasons for a service request for a VFL interaction to be performed. As an example: Asking for data for or a model of a different VFL role. This acts as a request for the NFc to participate in a VFL interaction with the NFp, e.g., based on a certain role for at least the NFc.
[0088] In step 6, the NF service producer 99-2 performs access token verification with additional claims, and in the case of successful verification the producer authorizes the VFL to initiate or be a part of the process or continue the processing. In particular, the NFc is allowed to access the NFp after the authorization, and this provides the NF service consumer access to be or become part of a process for the VFL interaction with the network function service producer. The additional claims include the claims in entries 310-360 of FIG. 3. It is further noted that the AllowVFLXX parameters set up for the registration in step 0 may be used here.
[0089] Turning to FIG. 5, this figure shows a block diagram of one possible and nonlimiting example of a cellular network 1 that is connected to a user equipment (UE) 10. A number of network elements are shown in the cellular network of FIG. 5: a base station 70; and a core network 90.
[0090] In FIG. 5, a user equipment (UE) 10 is in wireless communication via radio link 11 with the base station 70 of the cellular network 1. A UE 10 is a wireless communication device, such as a mobile device, that is configured to access a cellular network. The UE 10 isillustrated with one or more antennas 28. The ellipses 2 indicate there could be multiple UEs 10 in wireless communication via radio links with the base station 70. The UE 10 includes one or more processors 13, one or more memories 15, and other circuitry 16. The other circuitry 16 includes one or more receivers (Rx(s)) 17 and one or more transmitters (Tx(s)) 18. A program 12 is used to cause the UE 10 to perform the operations described herein. For a UE 10, the other circuitry 16 could include circuitry such as for user interface elements (not shown) like a display. The program 12 may be implemented via instructions stored in memory / memories 15 and executed by processor(s) 13, or by hardware such being implemented as part of the processor(s) or other hardware elements, or both.
[0091] The base station 70, as a network element of the cellular network 1, provides the UE 10 access to cellular network 1 and to the data network 91 via the core network 90 (e.g., via a user plane function (UPF) of the core network 90). As such, the base station 70 may be considered to be an access node, which provides access by UE(s) 10 to the cellular network 1. The base station 70 is illustrated as having one or more antennas 58. In general, the base station 70 may be referred to as RAN node 70, although many will make reference to this as a gNB (gNode B, a base station for NR, new radio) instead. There are, however, many other examples of RAN nodes including an eNB (evolved Node B) or TRP (Transmission-Reception Point). The base station 70 includes one or more processors 73, one or more memories 75, and other circuitry 76. The other circuitry 76 includes one or more receivers (Rx(s)) 77 and one or more transmitters (Tx(s)) 78. A program 72 is used to cause the base station 70 to perform the operations described herein. The program 72 may be implemented via instructions stored in memory / memories 75 and executed by processor(s) 73, or by hardware such being implemented as part of the processor(s) or other hardware elements, or both.
[0092] Two or more base stations 70 communicate using, e.g., link(s) 79. The link(s) 79 may be wired or wireless or both and may implement, e.g., an Xn interface for 5G (fifth generation), an X2 interface for LTE (Long Term Evolution), or other suitable interface for other standards.
[0093] The cellular network 1 may include a core network 90, as a second network element or elements, that may include core network functionality, and which provide connectivity via a link or links 81 with a data network 91, such as a telephone network and / or a data communications network (e.g., the Internet). The core network 90 includes one or moreprocessors 93, one or more memories 95, and other circuitry 96. The other circuitry 96 includes one or more receivers (Rx(s)) 97 and one or more transmitters (Tx(s)) 98. A program 92 is used to cause the core network 90 to perform the operations described herein. The program 92 may be implemented via instructions stored in memory / memories 95 and executed by processor(s) 93, or by hardware such being implemented as part of the processor(s) or other hardware elements, or both.
[0094] The core network 90 could be a 5GC (5G core network). The core network 90 can implement or comprise multiple network functions (NF(s)) 99, and the program 92 may comprise one or more of the NFs 99. A 5G core network may use hardware such as memory and processors and a virtualization layer. It could be a single standalone computing system, a distributed computing system, or a cloud computing system. The NFs 99, as network elements, of the core network could be containers or virtual machines running on the hardware of the computing system(s) making up the core network 90.
[0095] Core network 90 functionality for 5G may include access and mobility management functionality that is provided by a network function 99 such as an access and mobility management function (AMF), session management functionality that is provided by a network function such as a session management function (SMF). Core network functionality for access and mobility management in an LTE (Long Term Evolution) network may be provided by an MME (Mobility Management ) and / or SGW (Serving Gateway) functionality, which routes data to the data network. Many others are possible, as illustrated by the examples in FIG. 5: NFc 99-1; Auth (authorization) server 99-2; NFp 99-3; NEF 99-4; AF1 99-5; SMF; MME; SGW; GMLC (Gateway Mobile Location Center); LMF (Location Management Function); UDM (Unified Data Management) / UDR (Unified Data Repository); and / or E-SMLC (Evolved Serving Mobile Location Center). These are merely exemplary core network functionality that may be provided by the core network 90, and note that both 5G and LTE core network functionality might be provided by the core network 90. The N3IN 210 is coupled via a link 31 to the core network 90.
[0096] In the data network 91, there is a computer-readable medium 94. The computer-readable medium 94 contains instructions that, when downloaded and installed into the memories 15, 75, or 95 of the corresponding UE 10, base station 70, and / or core network element(s) 90 and NFs 99, and executed by processor(s) 13, 73, or 93, cause the respectivedevice to perform corresponding actions described herein. The computer-readable medium 94 may be implemented in other forms, such as via a compact disc or memory stick.
[0097] Block 2 illustrates that the core network 90 has a set of resources including 92, 93, 95, and 96. The individual NFs 99, such as the NFc 99-1, Auth server 99-2, NFp 99-3, NEF 99-4, AF1 99-5, can be implemented via a corresponding subset 2’ of resources comprising 92’, 93’, 95’, and 96’. Regardless of how the individual NFs 99 are implemented, such as via a virtualization layer on top of the subset 2’ of resources, the NFs 99 are implemented via circuitry like the processors 93’, memories 95’, and other circuitry 96’, and the virtualization layer can be part or all of the program 92’.
[0098] The NWDAF is designed to overcome market fragmentation and proprietary solutions in the area of network analytics, streamlining the way core network data is produced and consumed, as well as generating insights and taking actions based on these insights. The NWDAF addresses three primary standardization points: Data collection interface from network nodes; Predefined analytics insights; and Data exposure interface for consumers. Various entities may have multiple roles. For instance, the NWDAF may behave as a client and will then be referred to as a NF service consumer. The NWDAF may also behave has a server and will then be referred to as a NF service producer. The role depends on whether the NF is producing information for other NFs to consumer or whether the NF is consuming information produced by another NF. The Network Repository Function (NRF) serves as a centralized repository within 5G networks, responsible for storing and managing network functions and services. The NRF orchestrates various functions such as network slicing, service discovery, and inter-operator interactions. By providing a unified view of network resources and capabilities, the NRF enables seamless communication and coordination between network elements, ensuring efficient service delivery and resource utilization. The Network Exposure Function (NEF) provides a platform for creating new services by consolidating APIs and presenting unified access to the API framework for developers. This may include the following: Secure exposure of network services (voice, data connectivity, charging, subscriber data, and the like) towards third party applications; Developer environment for operator and community; Service combinations for creating end-to-end offering by combining any of the network assets into an application; and Integration layer that connects an application to operator’s network. The Application Function (AF) interacts with the 3GPP Core Network in order to provide services. An NEF provides aplatform for creating new services by consolidating APIs (application programming interfaces) and presenting unified access to the API framework for developers.
[0099] The programs 12, 72, and 92 contain instructions (as part of a corresponding program 12, 72, and 92) stored by corresponding one or more memories 15, 75, or 95. These instructions, when executed by the corresponding one or more processors 13, 73, or 93, cause the corresponding apparatus 10, 70, or 90, to perform the operations described herein. The computer readable memories 15, 75, or 95 are circuitry and may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, firmware, magnetic memory devices and systems, optical memory devices and systems, fixed memory and removable memory. The processors 13, 73, and 93, are circuitry and may be of any type suitable to the local technical environment. For example, these processors may include one or more of general-purpose computers, special purpose computers, microprocessors, digital signal processors (DSPs), processors based on a multi-core processor architecture, and may also include specialized circuits such as field-programmable gate arrays (FPGAs), application specific circuits (ASICs), signal processing devices and other devices, or combinations of these devices, as non-limiting examples.
[0100] The receivers 17, 77, and 97, and the transmitters 18, 78, and 98 may implement wired or wireless interfaces. The receivers and transmitters may be grouped together as transceivers.
[0101] The cellular network 1 may implement network virtualization, which is the process of combining hardware and software network resources and network functionality into a single, software -based administrative, a virtual network. Network virtualization involves platform virtualization, often combined with resource virtualization. Network virtualization is categorized as either external, combining many networks, or parts of networks, into a virtual unit, or internal, providing network-like functionality to software containers on a single system. Note that the virtualized entities (such as network functions 99) that result from the network virtualization are still implemented, at some level, using hardware such as processors 73 and / or 93 and memories 75 and / or 95, and also such virtualized entities create technical effects.
[0102] Without in any way limiting the scope, interpretation, or application of the claims appearing below, a technical effect and / or advantage of one or more of the example embodiments disclosed herein is that only authorized entities are allowed in a VFL process.
[0103] The following are additional examples.
[0104] Example 1. A method, comprising: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token examples comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
[0105] Example 2. The method according to example 1 , wherein entries in the access token examples comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the network function service consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
[0106] Example 3. The method according to example 1 or 2, wherein the one or more parameters for the network function profile comprise one or more of the following: an allowed vertical federated learning consumer role; one or more allowed vendors per vertical federated learning consumer role; or whether the network function service consumer is allowed to access the vertical federated learning interaction from a core domain or application function domain.
[0107] Example 4. The method according to example 3, wherein for the one or more allowed vendors per vertical federated learning consumer role, when the network function service consumer is a passive participant, then allowed vendors are one or more first vendors; and when the network function service consumer is an active participant, then allowed vendors are one or more second vendors.
[0108] Example 5. The method according to any of examples 1 to 4, wherein the access token examples in the performing verification are based on the registering by the network function service producer using the one or more parameters.
[0109] Example 6. A method, comprising: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
[0110] Example 7. The method according to example 6, wherein the request includes one or more of the following: source vertical federated learning information; or target vertical federated learning information.
[0111] Example 8. The method according to example 7, wherein the source vertical federated learning information comprises one or more of the following: a source network function role, or source application function role, or both the source network function role and the source application function role of vertical federated learning; a source vertical federated learning role domain; or a source vertical federated learning role vendor.
[0112] Example 9. The method according to example 7 or 8, wherein the target vertical federated learning information comprises one or more of the following: a target network function role, or target application function role, or both the target network function role and target application function role of vertical federated learning; a target vertical federated learning role domain; or a target vertical federated learning role vendor.
[0113] Example 10. The method according to any of examples 8 or 9, wherein a role for the source network function role, the source application function role, the target network function role, or the target application function role of vertical federated learning is one of the following: a vertical federated learning initiator; a vertical federated learning coordinator; an active participant; or a passive participant.
[0114] Example 11. A method, comprising: registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
[0115] Example 12. The method according to example 11 wherein the one or more parameters indicate entries in access token examples that comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
[0116] Example 13. The method according to example 11 or 12, further comprising: participating, by the authorization server, in a registration of a network exposure function with the authorization server, the registration involving details of an application function and involving the one or more parameters.
[0117] Example 14. The method according to any of examples 11 to 13, wherein the authorization server comprises a network repository function.
[0118] Example 15. An apparatus, comprising means for: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token examples comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, thenetwork function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
[0119] Example 16. The apparatus according to example 15, wherein entries in the access token examples comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the network function service consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
[0120] Example 17. The apparatus according to example 15 or 16, wherein the one or more parameters for the network function profile comprise one or more of the following: an allowed vertical federated learning consumer role; one or more allowed vendors per vertical federated learning consumer role; or whether the network function service consumer is allowed to access the vertical federated learning interaction from a core domain or application function domain.
[0121] Example 18. The apparatus according to example 17, wherein for the one or more allowed vendors per vertical federated learning consumer role, when the network function service consumer is a passive participant, then allowed vendors are one or more first vendors; and when the network function service consumer is an active participant, then allowed vendors are one or more second vendors.
[0122] Example 19. The apparatus according to any of examples 15 to 18, wherein the access token examples in the performing verification are based on the registering by the network function service producer using the one or more parameters.
[0123] Example 20. An apparatus, comprising means for: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interactionbetween the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
[0124] Example 21. The apparatus according to example 20, wherein the request includes one or more of the following: source vertical federated learning information; or target vertical federated learning information.
[0125] Example 22. The apparatus according to example 21, wherein the source vertical federated learning information comprises one or more of the following: a source network function role, or source application function role, or both the source network function role and the source application function role of vertical federated learning; a source vertical federated learning role domain; or a source vertical federated learning role vendor.
[0126] Example 23. The apparatus according to example 21 or 22, wherein the target vertical federated learning information comprises one or more of the following: a target network function role, or target application function role, or both the target network function role and target application function role of vertical federated learning; a target vertical federated learning role domain; or a target vertical federated learning role vendor.
[0127] Example 24. The apparatus according to any of examples 22 or 23, wherein a role for the source network function role, the source application function role, the target network function role, or the target application function role of vertical federated learning is one of the following: a vertical federated learning initiator; a vertical federated learning coordinator; an active participant; or a passive participant.
[0128] Example 25. An apparatus, comprising means for: registering, by an authorization server in a core network of a cellular network, a network function service producerin the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
[0129] Example 26. The apparatus according to example 25 wherein the one or more parameters indicate entries in access token examples that comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
[0130] Example 27. The apparatus according to example 25 or 26, wherein the means are further configured for : participating, by the authorization server, in a registration of a network exposure function with the authorization server, the registration involving details of an application function and involving the one or more parameters.
[0131] Example 28. The apparatus according to any of examples 25 to 27, wherein the authorization server comprises a network repository function.
[0132] Example 29. The apparatus of any preceding apparatus example, wherein the means comprises: at least one processor; and at least one memory storing instructions that, when executed by at least one processor, cause the performance of the apparatus.
[0133] Example 30. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token examples comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
[0134] Example 31. The apparatus according to example 30, wherein entries in the access token examples comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the network function service consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
[0135] Example 32. The apparatus according to example 30 or 31, wherein the one or more parameters for the network function profile comprise one or more of the following: anallowed vertical federated learning consumer role; one or more allowed vendors per vertical federated learning consumer role; or whether the network function service consumer is allowed to access the vertical federated learning interaction from a core domain or application function domain.
[0136] Example 33. The apparatus according to example 32, wherein for the one or more allowed vendors per vertical federated learning consumer role, when the network function service consumer is a passive participant, then allowed vendors are one or more first vendors; and when the network function service consumer is an active participant, then allowed vendors are one or more second vendors.
[0137] Example 34. The apparatus according to any of examples 30 to 33, wherein the access token examples in the performing verification are based on the registering by the network function service producer using the one or more parameters.
[0138] Example 35. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
[0139] Example 36. The apparatus according to example 35, wherein the request includes one or more of the following: source vertical federated learning information; or target vertical federated learning information.
[0140] Example 37. The apparatus according to example 36, wherein the source vertical federated learning information comprises one or more of the following: a source network function role, or source application function role, or both the source network function role and the source application function role of vertical federated learning; a source vertical federated learning role domain; or a source vertical federated learning role vendor.
[0141] Example 38. The apparatus according to example 36 or 37, wherein the target vertical federated learning information comprises one or more of the following: a target network function role, or target application function role, or both the target network function role and target application function role of vertical federated learning; a target vertical federated learning role domain; or a target vertical federated learning role vendor.
[0142] Example 39. The apparatus according to any of examples 37 or 38, wherein a role for the source network function role, the source application function role, the target network function role, or the target application function role of vertical federated learning is one of the following: a vertical federated learning initiator; a vertical federated learning coordinator; an active participant; or a passive participant.
[0143] Example 40. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
[0144] Example 41. The apparatus according to example 40 wherein the one or more parameters indicate entries in access token examples that comprise one or more of the followingdescriptions: a white list of one or more allowed vertical federated learning roles that the consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
[0145] Example 42. The apparatus according to example 40 or 41, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: participating, by the authorization server, in a registration of a network exposure function with the authorization server, the registration involving details of an application function and involving the one or more parameters.
[0146] Example 43. The apparatus according to any of examples 40 to 42, wherein the authorization server comprises a network repository function.
[0147] Example 44. A computer program, comprising instructions for performing the methods of any of examples 1 to 14, when the computer program is run on an apparatus.
[0148] Example 45. The computer program according to example 44, wherein the computer program is a computer program product comprising a computer-readable medium bearing instructions embodied therein for use with the apparatus.
[0149] Example 46. The computer program according to example 44, wherein the computer program is directly loadable into an internal memory of the apparatus.
[0150] As used in this application, the term “circuitry” may refer to one or more or all of the following:
[0151] (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) and
[0152] (b) combinations of hardware circuits and software, such as (as applicable): (i) a combination of analog and / or digital hardware circuit(s) with software / firmware and (ii) any portions of hardware processor(s) with software (including digital signal processor(s)), software,and memory(ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) and
[0153] (c) hardware circuit(s) and or processor(s), such as a microprocessor(s) or a portion of a microprocessor(s), that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation.
[0154] This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.
[0155] Embodiments herein may be implemented in software (executed by one or more processors), hardware (e.g., an application specific integrated circuit), or a combination of software and hardware. In an example embodiment, the software (e.g., application logic, an instruction set) is maintained on any one of various conventional computer-readable media. In the context of this document, a “computer-readable medium” may be any media or means that can contain, store, communicate, propagate or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer, with one example of a computer described and depicted, e.g., in FIG. 5. A computer-readable medium may comprise a computer-readable storage medium (e.g., memories 15, 75, and 95 or other device) that may be any media or means that can contain, store, and / or transport the instructions for use by or in connection with an instruction execution system, apparatus, or device, such as a computer. A computer-readable storage medium does not comprise propagating signals, and therefore may be considered to be non-transitory. The term “non-transitory”, as used herein, is a limitation of the medium itself (i.e., tangible, not a signal) as opposed to a limitation on data storage persistency (e.g., RAM, random access memory, versus ROM, readonly memory).
[0156] If desired, the different functions discussed herein may be performed in a different order and / or concurrently with each other. Furthermore, if desired, one or more of the above-described functions may be optional or may be combined.
[0157] Although various aspects of the invention are set out in the independent claims, other aspects of the invention comprise other combinations of features from the described embodiments and / or the dependent claims with the features of the independent claims, and not solely the combinations explicitly set out in the claims.
[0158] It is also noted herein that while the above describes example embodiments of the invention, these descriptions should not be viewed in a limiting sense. Rather, there are several variations and modifications which may be made without departing from the scope of the present invention as defined in the appended claims.
[0159] The following abbreviations that may be found in the specification and / or the drawing figures are defined as follows:
[0160] 5G fifth generation
[0161] 5GC fifth generation core (network)
[0162] AF application function
[0163] Al artificial intelligence
[0164] AMF access and mobility management function
[0165] E-SMLC evolved serving mobile location center
[0166] eNB (or eNodeB) evolved Node B (e.g., an LTE base station)
[0167] GMLC Gateway Mobile Location Center
[0168] gNB (or gNodeB) base station for 5G / NR
[0169] IE information element
[0170] I / F interface
[0171] LCS Location Services
[0172] LMF Location Management Function
[0173] LTE long term evolution
[0174] ML machine learning
[0175] MME mobility management
[0176] NEF Network Exposure Function
[0177] NF network function
[0178] ng or NG next generation
[0179] NR new radio
[0180] NRF Network Repository Function
[0181] NSI Network Slice Instance
[0182] NSSAI Network Slice Selection Assistance Information
[0183] N / W or NW network
[0184] NWDAF Network data analytics function
[0185] RAN radio access network
[0186] Rx receiver
[0187] SA2 3GPP TSG SA WG2, 3GPP Technical Specification Group (TSG) Service and System Aspects, WG = working group
[0188] SA3 3GPP TSG SA WG3, 3GPP Technical Specification Group Service and System Aspects (TSG SA), WG = Working group
[0189] SGW serving gateway
[0190] SID study item description
[0191] SMF session management function
[0192] TRP transmission-reception point
[0193] Tx transmitter
[0194] UDM unified data management
[0195] UDR unified data repository
[0196] UE user equipment (e.g., a wireless, typically mobile device)
[0197] UPF user plane function
[0198] VFL Vertical Federated Learning
[0199] WID Working item description
[0200] WT work task
Claims
What is claimed is:
1. A method, comprising: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token claims comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
2. The method according to claim 1 , wherein entries in the access token claims comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the network function service consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access;a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
3. The method according to claim 1 or 2, wherein the one or more parameters for the network function profile comprise one or more of the following: an allowed vertical federated learning consumer role; one or more allowed vendors per vertical federated learning consumer role; or whether the network function service consumer is allowed to access the vertical federated learning interaction from a core domain or application function domain.
4. The method according to claim 3, wherein for the one or more allowed vendors per vertical federated learning consumer role, when the network function service consumer is a passive participant, then allowed vendors are one or more first vendors; and when the network function service consumer is an active participant, then allowed vendors are one or more second vendors.
5. The method according to any of claims 1 to 4, wherein the access token claims in the performing verification are based on the registering by the network function service producer using the one or more parameters.
6. A method, comprising: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the networkfunction service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
7. The method according to claim 6, wherein the request includes one or more of the following: source vertical federated learning information; or target vertical federated learning information.
8. The method according to claim 7, wherein the source vertical federated learning information comprises one or more of the following: a source network function role, or source application function role, or both the source network function role and the source application function role of vertical federated learning; a source vertical federated learning role domain; or a source vertical federated learning role vendor.
9. The method according to claim 7 or 8, wherein the target vertical federated learning information comprises one or more of the following: a target network function role, or target application function role, or both the target network function role and targetapplication function role of vertical federated learning; a target vertical federated learning role domain; or a target vertical federated learning role vendor.
10. The method according to any of claims 8 or 9, wherein a role for the source network function role, the source application function role, the target network function role, or the target application function role of vertical federated learning is one of the following: a vertical federated learning initiator; a vertical federated learning coordinator; an active participant; or a passive participant.
11. A method, comprising: registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
12. The method according to claim 11 wherein the one or more parameters indicate entries in access token claims that comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the consumer is allowed to target or access;a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
13. The method according to claim 11 or 12, further comprising: participating, by the authorization server, in a registration of a network exposure function with the authorization server, the registration involving details of an application function and involving the one or more parameters.
14. The method according to any of claims 11 to 13, wherein the authorization server comprises a network repository function.
15. An apparatus, comprising means for: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token claims comprising entries the network function serviceproducer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
16. The apparatus according to claim 15, wherein entries in the access token claims comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the network function service consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
17. The apparatus according to claim 15 or 16, wherein the one or more parameters for the network function profile comprise one or more of the following: an allowed vertical federated learning consumer role; one or more allowed vendors per vertical federated learning consumer role; or whether the network function service consumer is allowed to access the vertical federated learning interaction from a core domain or application function domain.
18. The apparatus according to claim 17, wherein for the one or more allowed vendors per vertical federated learning consumer role, when the network function service consumer is a passive participant, then allowed vendors are one or more first vendors; and when the network function service consumer is an active participant, then allowed vendors are one or more second vendors.
19. The apparatus according to any of claims 15 to 18, wherein the access token claims in the performing verification are based on the registering by the network function service producer using the one or more parameters.
20. An apparatus, comprising means for: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
21. The apparatus according to claim 20, wherein the request includes one or more of the following: source vertical federated learning information; or target vertical federated learning information.
22. The apparatus according to claim 21, wherein the source vertical federated learning information comprises one or more of the following: a source network function role, or source application function role, or both the source network function role and the source application function role of vertical federated learning; a source vertical federated learning role domain; or a source vertical federated learning role vendor.
23. The apparatus according to claim 21 or 22, wherein the target vertical federated learning information comprises one or more of the following: a target network function role, or target application function role, or both the target network function role and target application function role of vertical federated learning; a target vertical federated learning role domain; or a target vertical federated learning role vendor.
24. The apparatus according to any of claims 22 or 23, wherein a role for the source network function role, the source application function role, the target network function role, or the target application function role of vertical federated learning is one of the following: a vertical federated learning initiator; a vertical federated learning coordinator; an active participant; or a passive participant.
25. An apparatus, comprising means for: registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learninginteraction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
26. The apparatus according to claim 25 wherein the one or more parameters indicate entries in access token claims that comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
27. The apparatus according to claim 25 or 26, wherein the means are further configured for : participating, by the authorization server, in a registration of a network exposure function with the authorization server, the registration involving details of an application function and involving the one or more parameters.
28. The apparatus according to any of claims 25 to 27, wherein the authorization server comprises a network repository function.
29. The apparatus of any preceding apparatus claim, wherein the means comprises: at least one processor; and at least one memory storing instructions that, when executed by at least one processor, cause the performance of the apparatus.
30. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: registering, by a network function service producer in a core network of a cellular network, with an authorization server of the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer; receiving, by the network function service producer and from a network function service consumer, a service request comprising an access token indicating one or more parameters for the vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; performing, by the network function service producer, verification of the access token with access token claims comprising entries the network function service producer uses to determine whether to authorize the network function service consumer to be part of a process and what resources the vertical federated learning role is allowed to access; determining, by the network function service producer, the access token of the network function service consumer is verified; and authorizing, by the network function service producer, the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer.
31. The apparatus according to claim 30, wherein entries in the access token claims comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the network function service consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
32. The apparatus according to claim 30 or 31 , wherein the one or more parameters for the network function profile comprise one or more of the following: an allowed vertical federated learning consumer role; one or more allowed vendors per vertical federated learning consumer role; or whether the network function service consumer is allowed to access the vertical federated learning interaction from a core domain or application function domain.
33. The apparatus according to claim 32, wherein for the one or more allowed vendors per vertical federated learning consumer role, when the network function service consumer is a passive participant, then allowed vendors are one or more first vendors; and when the network function service consumer is an active participant, then allowed vendors are one or more second vendors.
34. The apparatus according to any of claims 30 to 33, wherein the access token claims in the performing verification are based on the registering by the network function service producer using the one or more parameters.
35. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: sending, by a network function service consumer in a core network of a cellular network to an authorization server in the core network, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and a network function service producer as a target; receiving, by the network function service consumer from the authorization server, an access token comprising information for the vertical federated learning interaction; sending, by the network function service consumer to the network function service producer, a service request comprising an access token indicating one or more parameters for vertical federated learning interaction and indicating at least a vertical federated learning role for the network function service consumer; receiving, by the network function service consumer from the network function service producer, authorization for the network function service consumer to be or become part of a process for the vertical federated learning interaction with the network function service producer; and participating, by the network function service consumer, in the vertical federated learning interaction.
36. The apparatus according to claim 35, wherein the request includes one or more of the following: source vertical federated learning information; or target vertical federated learning information.
37. The apparatus according to claim 36, wherein the source vertical federated learning information comprises one or more of the following: a source network function role, or source application function role, or both the source network function role and the source application function role of vertical federated learning; a source vertical federated learning role domain; or a source vertical federated learning role vendor.
38. The apparatus according to claim 36 or 37, wherein the target vertical federated learning information comprises one or more of the following: a target network function role, or target application function role, or both the target network function role and target application function role of vertical federated learning; a target vertical federated learning role domain; or a target vertical federated learning role vendor.
39. The apparatus according to any of claims 37 or 38, wherein a role for the source network function role, the source application function role, the target network function role, or the target application function role of vertical federated learning is one of the following: a vertical federated learning initiator; a vertical federated learning coordinator; an active participant; or a passive participant.
40. An apparatus, comprising: one or more processors; and one or more memories storing instructions that, when executed by the one or more processors, cause the apparatus at least to perform: registering, by an authorization server in a core network of a cellular network, a network function service producer in the core network, the registering involving a network function profile having one or more parameters defining what the network function service producer supports for vertical federated learning interaction with a network function service consumer;receiving, by the authorization server from a network function service consumer, a request for an access token comprising a source vertical federated learning role and a target vertical federated learning role for a vertical federated learning interaction between the network function service consumer as a source and the network function service producer as a target; authorizing, by the authorization server, the network function service consumer to access the target based on the network function profile having the one or more parameters; and generating, by the authorization server, an access token comprising information for the vertical federated learning interaction.
41. The apparatus according to claim 40 wherein the one or more parameters indicate entries in access token claims that comprise one or more of the following descriptions: a white list of one or more allowed vertical federated learning roles that the consumer is allowed to target or access; a black list of one or more vertical federated learning roles that the network function service consumer is not allowed to target or access; a white list of allowed vendors per vertical federated learning role that the network function service consumer is allowed to target or access; a black list of vendors per vertical federated learning role that the network function service consumer is not allowed to target or access; a white list of allowed domains per vertical federated learning role that the network function service consumer is allowed to target or access; or a black list of domains per vertical federated learning role that the network function service consumer is not allowed to target or access.
42. The apparatus according to claim 40 or 41, wherein the one or more memories further store instructions that, when executed by the one or more processors, cause the apparatus at least to perform: participating, by the authorization server, in a registration of anetwork exposure function with the authorization server, the registration involving details of an application function and involving the one or more parameters.
43. The apparatus according to any of claims 40 to 42, wherein the authorization server comprises a network repository function.
44. A computer program, comprising instructions for performing the methods of any of claims 1 to 14, when the computer program is run on an apparatus.
45. The computer program according to claim 44, wherein the computer program is a computer program product comprising a computer-readable medium bearing instructions embodied therein for use with the apparatus.
46. The computer program according to claim 44, wherein the computer program is directly loadable into an internal memory of the apparatus.
Citation Information
Patent Citations
Secure access control in communication system
US20220248225A1
Registering and Requesting Services in a Service Based Architecture
US20220248316A1
Apparatuses and methods relating to authorisation of network functions
US20220353255A1