Mechanism to define granular and optimized data access authorization for ML process
The method addresses the lack of authorization verification in ML model training by generating access tokens based on data source mapping, ensuring secure and authorized data access for ML model training.
Patent Information
- Application Number
- PCT/IB2025/053549
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-05
- Filing Date
- 2025-04-03
- Publication Date
- 2025-10-09
AI Technical Summary
Existing machine learning (ML) model training processes lack a mechanism to verify if the service consumer is authorized to access data from all required data sources, potentially leading to unauthorized data collection.
A method involving a first node that receives authorization information, determines the authorization of a second node for ML analytics data, and generates an access token based on data source mapping information, ensuring only authorized consumers can access the required data.
Ensures secure and authorized data access for ML model training by verifying the authorization of service consumers and data sources, preventing unauthorized data collection.
Smart Images

Figure IB2025053549_09102025_PF_FP_ABST
Abstract
Description
MECHANISM TO DEFINE GRANULAR AND OPTIMIZED DATA ACCESS AUTHORIZATION FOR ML PROCESSFIELD
[0001] Various example embodiments relate generally to wireless networks and, more particularly, for a mechanism to define granular and optimized data access authorization for a machine learning (ML) process.BACKGROUND
[0002] During machine learning (ML) model training or analytics service, a model training function collects training data from multiple data sources, and there exists no mechanism to check if the model service consumer is authorized to receive data from all of these sources or not. In the case the service consumer is not authorized to collect data from a certain data source (e.g., network function a (NFa)), the model training function may be requested to train the model which requires the data from NFa.
[0003] However, the consumer may not be authorized by NFa in the first place.SUMMARY
[0004] In an aspect of the present disclosure, a method includes receiving, at a first node, information relating to authorization for one or more functionalities. The first node receives a request from a second node, the request including a request for machine learning (ML) model analytics data, determines an authorization of the second node for the ML analytics data based upon the information relating to authorization for one or more functionalities, and transmits based upon the authorization, an access token to the second node relating to authorization for the ML analytics data.
[0005] In an aspect of the method, the first node transmits a request to a third node, the third node being a model analytics function to retrieve the data source mapping information.
[0006] In an aspect of the method, the first node receives the data source mapping information and data parameters from the third node.
[0007] In an aspect of the method, the data source mapping information includes information relating to data used to retrieve data sources required for ML model training.
[0008] In an aspect of the method, the determining of an authorization of the second node includes reviewing, by the first node, whether the second node is a registered consumer to access the requested ML analytics data.
[0009] In an aspect of the method, the method further includes generating, by the first node, the access token upon a determination of authorization for the second node.
[0010] In an aspect of the method, the access token includes a service consumer as a source and a model analytics function as a producer.
[0011] In an aspect of the method, the access token includes an indication of data sources the service consumer is authorized to receive data.
[0012] In an aspect of the method, the method further includes receiving, by the first node, an access token request from the third node and determining whether the third node is authorized to access data from a requested data source indicated in the access token request.
[0013] In an aspect of the method, upon a determination that the third node is authorized to access data from a requested data source indicated in access token request, generating, by the first node, an enhanced access token and transmitting the enhanced access token to the third node.
[0014] In an aspect of the method, the enhanced access token includes the third node as a source.
[0015] In an aspect of the present disclosure, a method includes receiving, by a model training function (MTLF) entity, a request for machine learning (ML) analytics data from a first node, and transmitting, by the MTLF entity, based on an authorization of the first apparatus, the ML analytics data to the first node.
[0016] In an aspect of the method, the first apparatus is a service consumer entity or an authorization server entity.
[0017] In an aspect of the method, the request for ML analytics data includes an access token.
[0018] In an aspect of the method, the method further includes verifying, by the MTLF entity, the access token.
[0019] In an aspect of the method, upon ML analytics data not being available, transmitting, by the MTLF entity, a request to a data repository, the request including the access token.
[0020] In an aspect of the present disclosure, a method includes receiving, by a service consumer entity, an access token for a requested machine learning (ML) model analytics data from an authorization server, transmitting, by the service consumer entity, a request for the ML model analytics data to a model training function (MTLF) entity, and receiving, by the service consumer entity, the ML model analytics data from the MTLF entity.
[0021] In an aspect of the method, the method further includes transmitting an access token request for data producers to the authorization server.
[0022] In an aspect of the present disclosure, a method includes receiving, by a data repository entity, a request for data from a model training function (MTLF) entity, the request for data including an access token and service consumer information for a service consumer, determining, by the data repository entity, whether the service consumer is authorized to receive the data, and transmitting, by the data repository entity, the data based to the MTLF entity upon the determined authorization of the service consumer.
[0023] In an aspect of the present disclosure, an apparatus includes at least one processor, and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform any of the foregoing methods.
[0024] In an aspect of the present disclosure, a processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus at least to perform any of the foregoing methods.
[0025] According to some aspects, there is provided the subject matter of the independent claims. Some further aspects are defined in the dependent claims.BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Some example embodiments will now be described with reference to the accompanying drawings.
[0027] FIG. 1 is a diagram of an example embodiment of wireless networking between a network system and a user equipment (UE), according to one illustrated aspect of the disclosure;
[0028] FIG. 2 is a diagram of example components of a network system, according to one illustrated aspect of the disclosure;
[0029] FIG. 3 is a diagram of an example embodiment of signals and operations among a service consumer, an authorization server, a model training function and a data repository, according to one illustrated aspect of the disclosure;
[0030] FIG. 4 is a diagram of an example embodiment of signals and operations among a service consumer, an authorization server, a model training function and a data repository, according to another illustrated aspect of the disclosure; and
[0031] FIG. 5 is a diagram of an example embodiment of components of a UE or of a network apparatus, according to one illustrated aspect of the present disclosure.DETAILED DESCRIPTION
[0032] In the following description, certain specific details are set forth in order to provide a thorough understanding of disclosed aspects. However, one skilled in the relevant art will recognize that aspects may be practiced without one or more of these specific details or with other methods, components, materials, etc. In other instances, well-known structures associated with transmitters, receivers, or transceivers have not been shown or described in detail to avoid unnecessarily obscuring descriptions of the aspects.
[0033] Reference throughout this specification to “one aspect” or “an aspect” means that a particular feature, structure, or characteristic described in connection with the aspect is included in at least one aspect. Thus, the appearances of the phrases “in one aspect” or “in an aspect” in various places throughout this specification are not necessarily all referring to the same aspect. Furthermore, the particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.
[0034] Embodiments described in the present disclosure may be implemented in wireless networking apparatuses, such as, without limitation, apparatuses utilizing Worldwide Interoperability for Microwave Access (WiMAX), Global System for Mobile communications (GSM, 2G), GSM EDGE radio access Network (GERAN), General Packet Radio Service (GRPS), Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband- code division multiple access (W-CDMA), high-speed packet access (HSPA), Long Term Evolution (LTE), LTE-Advanced, enhanced LTE (eLTE), 5G New Radio (5G NR), 5G Advance, 6G (and beyond) and 802.1 lax (Wi-Fi 6), among other wireless networking systems. The term ‘eLTE’ here denotes the LTE evolution that connects to a 5G core. LTE is also known as evolved UMTS terrestrial radio access (EUTRA) or as evolved UMTS terrestrial radio access network (EUTRAN).
[0035] The present disclosure may use the term “serving network device” to refer to a network node or network device (or a portion thereof) that services a UE. As used herein, the terms “transmit to,” “receive from,” and “cooperate with,” (and their variations) include communications that may or may not involve conununications through one or more intermediate devices or nodes. The term “acquire” (and its variations) includes acquiring in the first instance or reacquiring after the first instance. The term “connection” may mean a physical connection or a logical connection.
[0036] The present disclosure uses 5G NR as an example of a wireless network and may use smartphones and / or extended reality headsets as an example of UEs. It is intended and shallbe understood that such examples are merely illustrative, and the present disclosure is applicable to other wireless networks and user equipment.
[0037] FIG. 1 is a diagram depicting an example of wireless networking between a network system 100 and a user equipment (UE) 150. The network system 100 may include one or more network nodes 120, one or more servers 110, and / or one or more network equipment 130 (e.g., test equipment). The network nodes 120 will be described in more detail below. As used herein, the term “network apparatus” may refer to any component of the network system 100, such as the server 110, the network node 120, the network equipment 130, any component(s) of the foregoing, and / or any other component(s) of the network system 100. Examples of network apparatuses include, without limitation, apparatuses implementing aspects of 5G NR, among others. The present disclosure describes embodiments related to 5G NR and embodiments that involve aspects defined by 3rd Generation Partnership Project (3GPP). However, it is contemplated that embodiments relating to other wireless networking technologies are encompassed within the scope of the present disclosure.
[0038] The following description provides further details of examples of network nodes. In a 5G NR network, a gNodeB (also known as gNB) may include, e.g., a node that provides new radio (NR) user plane and control plane protocol terminations towards the UE and that is connected via a NG interface to the 5G core (5GC), e.g., according to 3GPP TS 38.300 V16.6.0 (2021-06) section 3.2, which is hereby incorporated by reference herein.
[0039] A gNB supports various protocol layers, e.g., Layer 1 (LI) - physical layer, Layer 2 (L2), and Layer 3 (L3).
[0040] The layer 2 (L2) of NR is split into the following sublayers: Medium Access Control (MAC), Radio Link Control (RLC), Packet Data Convergence Protocol (PDCP) and Service Data Adaptation Protocol (SDAP), where, e.g.: o The physical layer offers to the MAC sublayer transport channels; o lire MAC sublayer offers to the RLC sublayer logical channels; o The RLC sublayer offers to the PDCP sublayer RLC channels; o The PDCP sublayer offers to the SDAP sublayer radio bearers; o The SDAP sublayer offers to 5GC quality of service (QoS) flows; o Control channels include broadcast control channel (BCCH) and physical control channel (PCCH).
[0041] Layer 3 (L3) includes, e.g., radio resource control (RRC), e.g., according to 3GPP TS 38.300 V16.6.0 (2021-06) section 6, which is hereby incorporated by reference herein.
[0042] A gNB central unit (gNB-CU) includes, e.g., a logical node hosting, e.g., radio resource control (RRC), service data adaptation protocol (SDAP), and packet data convergence protocol (PDCP) protocols of the gNB or RRC and PDCP protocols of the en-gNB, that controls the operation of one or more gNB distributed units (gNB-DUs). The gNB-CU terminates the Fl interface connected with the gNB -DU. A gNB-CU may also be referred to herein as a CU, a central unit, a centralized unit, or a control unit.
[0043] A gNB Distributed Unit (gNB-DU) includes, e.g., a logical node hosting, e.g., radio link control (RLC), media access control (MAC), and physical (PHY) layers of the gNB or en- gNB, and its operation is partly controlled by the gNB-CU. One gNB-DU supports one or multiple cells. One cell is supported by only one gNB-DU. The gNB-DU terminates the Fl interface connected with the gNB-CU. A gNB-DU may also be referred to herein as DU or a distributed unit.
[0044] As used herein, the term “network node” may refer to any of a gNB, a gNB-CU, or a gNB-DU, or any combination of them. A RAN (radio access network) node or network node such as, e.g., a gNB, gNB-CU, or gNB-DU, or parts thereof, may be implemented using, e.g., an apparatus with at least one processor and / or at least one memory with processor-readable instructions (“program”) configured to support and / or provision and / or process CU and / or DU related functionality and / or features, and / or at least one protocol (sub-)layer of a RAN (radio access network), e.g., layer 2 and / or layer 3. Different functional splits between the central and distributed unit are possible. An example of such an apparatus and components will be described in connection with FIG. 5 below.
[0045] The gNB-CU and gNB-DU pails may, e.g., be co-located or physically separated. The gNB-DU may even be split further, e.g., into two parts, e.g., one including processing equipment and one including an antenna. A central unit (CU) may also be called baseband unit / radio equipment controller / cloud-RAN / virtual-RAN (BBU / REC / C-RAN / V-RAN), open- RAN (O-RAN), or part thereof. A distributed unit (DU) may also be called remote radio head / remote radio unit / radio equipment / radio unit (RRH / RRU / RE / RU), or part thereof. Hereinafter, in various example embodiments of the present disclosure, a network node, which supports at least one of central unit functionality or a layer 3 protocol of a radio access network, may be, e.g., a gNB-CU. Similarly, a network node, which supports at least one of distributed unit functionality or a layer 2 protocol of the radio access network, may be, e.g., a gNB-DU.
[0046] A gNB-CU may support one or multiple gNB-DUs. A gNB-DU may support one or multiple cells and, thus, could support a serving cell for a user equipment (UE) or support acandidate cell for handover, dual connectivity, and / or carrier aggregation, among other procedures.
[0047] The user equipment (UE) 150 may be or include a wireless or mobile device, an apparatus with a radio interface to interact with a RAN (radio access network), a smartphone, an in-vehicle apparatus, an loT device, or a M2M device, among other types of user equipment. Such UE 150 may include: at least one processor; and at least one memory’ including program code; where the at least one memory' and the computer program code are configured to, with the at least one processor, cause the apparatus at least to perform certain operations, such as, e.g., RRC connection to the RAN. An example of components of a UE will be described in connection with FIG. 5. In embodiments, the UE 150 may be configured to generate a message (e.g., including a cell ID) to be transmitted via radio towards a RAN (e.g., to reach and communicate with a serving cell). In embodiments, the UE 150 may generate and transmit and receive RRC messages containing one or more RRC PDUs (packet data units). Persons skilled in the art will understand RRC protocol as well as other procedures a UE may perform.
[0048] With continuing reference to FIG. 1, in the example of a 5G NR network, the network system 100 provides one or more cells, which define a coverage area of the network system 100. As described above, the network system 100 may include a gNB of a 5G NR network or may include any other apparatus configured to control radio communication and manage radio resources within a cell. As used herein, the term “resource” may refer to radio resources, such as a resource block (RB), a physical resource block (PRB), a radio frame, a subframe, a time slot, a sub-band, a frequency region, a sub-carrier, a beam, etc. In embodiments, the network node 120 may be called a base station.
[0049] FIG. 1 provides an example and is merely illustrative of a network system 100 and a UE 150. Persons skilled in the art will understand that the network system 100 includes components not illustrated in FIG. 1 and will understand that other user equipment may be in communication with the network system 100.
[0050] FIG. 2 is a block diagram of example components of the network system 100 of FIG. 1. A 5G NR network may be described as an example of the network system 100, and it is intended that aspects of the following description shall be applicable to other types of network systems, as well. The network system may operate in accordance with the signals and connections shown in FIG. 1 such that the UE 150 is in communication with the network system 100 through the radio access network 225. Additionally, the network system may be divided into user plane components and functions and control plane components and functions, as shown and described herein. Unless indicated otherwise, the terms “component”, “function”,and “service” may be used interchangeably herein, and they may refer to and be implemented by instructions executed by one or more processors.
[0051] Example functions of the components are described below. The example functions are merely illustrative, and it shall be understood that additional operations and functions may be performed by the components described herein. Additionally, the connections between components may be virtual connections over service-based interfaces such that any component may communicate with any other component. In this manner, any component may act as a service “producer,” for any other component that is a service “consumer,” to provide services for network functions.
[0052] For example, a core network 210 is described in the control plane of the network system. The core network 210 may include an authentication server function (AUSF) 211, an access and mobility function (AMF) 212, and a session management function (SMF) 213. The core network 210 may also include a network slice selection function (NSSF) 214, a network exposure function (NEF) 215, a network repository function (NRF) 216, and a unified data management function (UDM) 217, which may include a uniform data repository (UDR) 224.
[0053] Additional components and functions of the core network 210 may include an application function 218, policy control function (PCF) 219, network data analytics function (NWDAF) 220, analytics data repository function (ADRF) 221, management data analytics function (MDAF) 222, and operations and management function (0AM) 223.
[0054] The user plane includes the UE 150, a radio access network (RAN) 225, a user plane function (UPF) 226, and a data network (DN) 227. The RAN 225 may include one or more components described in connection with FIG. 1, such as one or more network nodes. However, the RAN 225 may not be limited to such components. The UPF 226 provides connection for data being transmitted over the RAN 225. The DN 226 identifies services from service providers, Internet access, and third party services, for example.
[0055] The AMF 212 processes connection and mobility tasks. The AUSF 211 receives authentication requests from the AMF 212 and interacts with UDM 217 to authenticate and validate network responses for determination of successful authentication. The SMF 213 conducts packet data unit (PDU) session management, as well as manages session context with the UPF 226.
[0056] The NSSF 214 may select a network slicing instance (NSI) and determine the allowed network slice selection assistance information (NSSAI). This selection and determination is utilized to set the AMF 212 to provide service to the UE 150. The NEF 215 secures access to network services for third parties to create specialized network services. TheNRF 216 acts as a repository to store network functions to allow the functions to register with and discover each other.
[0057] The UDM 217 generates authentication vectors for use by the AUSF 211 and ADM 212 and provides user identification handling. The UDM 217 may be connected to the UDR 224 which stores data associated with authentication, applications, or the like. The AF 218 provides application services to a user (e.g., streaming services, etc.). The PCF 219 provides policy control functionality. For example, the PCF 219 may assist in network slicing and mobility management, as well as provide quality of service (QoS) and charging functionality.
[0058] The NWDAF 220 collects data (e.g., from the UE 150 and the network system) to perform network analytics and provide insight to functions that utilize the analytics in the providing of services. The ADRF 221 allows the storage, retrieval, and removal of data and analytics by consumers. The MDAF 222 provides additional data analytics services for network functions. The 0AM 223 provides provisioning and management processing functions to manage elements in or connected to the network (e.g., UE 150, network nodes, etc.).
[0059] FIG. 2 is merely an example of components of a network system, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the network system may include other components not illustrated in FIG. 2. In embodiments, the network system may not include every component illustrated in FIG. 2. In embodiments, the components and connections may be implemented with different connections than those illustrated in FIG. 2. Such and other embodiments are contemplated to be within the scope of the present disclosure.
[0060] Although further detail will be provided below, a method is described herein, which in various embodiments may be at a network function (NF) or any node where machine learning (ML) training is performed. In various embodiments, a data source mapping service wherein a Model Training Function (e.g., MTLF) can be queried to retrieve all the data sources providing the training data, the exact data required from each data source corresponding to every analytic ID or ML Model. In various embodiments, the node performing the model training may store the information on which input data has been used in every ML Model and / or Analytics, and the relation among the input data and ML model / Analytics are used as authorization criteria for fetching the model (model sharing) or Analytics.
[0061] In various embodiments, an NWDAF AnLF may function as model service consumer and an NWDAF MTLF as a model producer, that includes the training function. In various embodiments, the NWDAF MTLF may also act as well as model service consumer asking for the model to another NWDAF MTLF on behalf of another AnLF. In variousembodiments, the authorization for fetching the AI / ML models may be based upon vendor ID and Interoperability indicator.
[0062] In a model delivery phase, the service consumer which is not authorized to receive data X, may infer the training data X via the model received.
[0063] In various embodiments, in a 5G advanced system and 6G system, native Al may be employed, in which case data level and data source level authorization for every Al ML based service consumer may be desirable. Since every NF will be Al ML enabled, there may be a significant number of service consumers of Al ML and the Al ML Model producers may also increase. Therefore, in various embodiments, enabling data level authorization ensures that a service consumer will only be authorized to receive the ML model in the case it is authorized by the subsequent data producers providing the training data to train that particular ML model which is requested.
[0064] In various embodiments, the NRF or NFc sends a request to the MTLF (e.g., in the NWDAF) to retrieve this data source mapping. In various embodiments, the authorization mechanism may include the authorization server (e.g. NRF) requesting from the model training function information X, the service producer can directly provide this information X (i.e. source mapping) to NRF, or the training function registers this information X directly at the NRF so that NRF can use it, where the information X refers to the exact mapping of analytics ID / Model VS data sources from where the training data will be collected and the dataset is needed from each source.
[0065] In various embodiments, the NRF checks if the service consumer is authorized to receive the data required for training a particular analytics ID or model, from all the data sources and if applicable also the subsequent data sets.
[0066] In various embodiments, the NRF generates an access token with the Service Consumer as source, MTLF as producer, and an additional claim of data producers indicating all the data sources for which the consumer is authorized to receive the data and in the additional scope can specify which data (data set) can be consumed from which producer. In various embodiments, the TAI / Service area of the data sources, and also the service area of the ML model or analytics ID for which the Service consumer is authorized to access may be provided.
[0067] It can also be considered that when authorizing such requests, the geographical area or TAI or the data source is taken into consideration. For instance, the case that for certain analytics ID, (e.g. advertisement), the data source of a certain region does not want to provide the data in general, or specifically to service consumers located in certain regions. In suchcases, the authorization of the request may fail, and an alternate data source can be suggested. In various embodiments, certain analytics ID / ML models are restricted to some specific service area / TAI, and then the during authorization, the service area of Service consumer may be taken into account during authorization, and while generating the access token claims the service area of the data source and / or of ML model and / or of Analytics ID is also added to indicate exactly what the consumer is authorized for.
[0068] As used herein, a communication with a radio access network (RAN) may refer to and mean a communication with a portion of a RAN, such as with a network node (e.g., a DU and / or a CU), or another portion of a RAN. As used herein, a communication with a core network may refer to and mean a communication with one or more services / applications of the core network, such as AMF or another service of a core network.
[0069] As used herein, the terms “first” and “second”, or the like, may refer to a first or second instance of a message being transmitted / received by a component (e.g., UE, apparatus, etc.), or a first or second component in a sequence of described components. As such, the terms are used in a non-limiting manner, and can refer to any message, operation, device, component, or the like.
[0070] In accordance with the brief description, FIG. 3 is a diagram of an example embodiment of signals and operations among a service consumer, an authorization server, a model training function and a data repository, according to one illustrated aspect of the disclosure. In various embodiments, the components depicted in FIG. 3 may correspond to similar components described above in FIGS. 1 and 2. It will be understood that a described signal may have associated operations and a described operation may have associated signals.
[0071] At operation 301, the service consumer transmits an access token request to the authorization server (e.g., NRF) to consume analytics / trained ML model from the model training function (e.g., NWDAF MTLF), and the authorization server receives the access token request.
[0072] At operation 302, the authorization server transmits a request to retrieve analytics / model ID and data sources mapping to the model training function (e.g., NWDAF MTLF) and the model training function receives the request to retrieve analytics / model ID and data sources mapping. In various embodiments, the “data source mapping service” may be defined as an MTLF function wherein the MTLF can be queried to retrieve all the data sources, the exact training data required from each data source corresponding to every analytic ID or ML Model. In various embodiments, the NRF sends a request to MTLF to retrieve this data source mapping.
[0073] In various embodiments, the MTLF when registering in the NRF may register this information, and in the case new data producers are added the MTLF updates the same in its profile registered in the NRF. In various embodiments, the NRF does not query the MTLF for this information.
[0074] At operation 303, the model training function transmits all the data sources and data parameters required to train the requested ML model or derive the analytics ID to the authorization server and the authorization server receives the data sources and data parameters. In various embodiments, data sources may include core network functions and / or application functions.
[0075] At operation 304, the authorization server, based on the NF profiles of the data sources registered, authorizes the service consumer if it can access a particular ML model or analytics ID or not, by verifying if the data producers needed to train a ML model (e.g., information received at operation 303) in their profiles registered in the NRF have allowed the service consumer to receive data from them or not.
[0076] At operation 305, the authorization server, in the case of successful authorization, generates an access token with Service Consumer as source, MTLF as producer, and additional claim including “data producers” indicating all the data sources for which the consumer is authorized to receive the data and in the additional scope can specify which dataset can be consumed from which data producer. In various embodiments, additional information may include the TAI / Service area of the data sources, and also the service area of the ML model or analytics ID for which the service consumer is authorized to access.
[0077] In various embodiments, when authorizing such requests, the geographical area or TAI or the data source is taken into consideration. For instance, the case that for certain analytics ID, (e.g. advertisement), a data source of certain region does not want to provide the data in general, or specifically to service consumers located in certain regions. Then in such cases the authorization of request may fail, and an alternate data source can be suggested. In various embodiments, certain analytics ID / ML models are restricted to some specific service area / TAI, and then the during authorization, the service area of the service consumer may be taken into account during authorization. In such cases then the geographical area or region or TAI of the data source is also appended to the data source in the access token claims.
[0078] In various embodiments, the trained ML model or analytics ID may be geographically restricted to only certain consumers belonging to specific TAI, therefore, in the case the region information of ML model or analytics is also specified by the ML model producer (for instance in the, for example, NWDAF MTLF) then the NRF also verifies thatand only then provides the access token. The access token in such case may include the TAI / region of the ML model / analytics ID for which the consumer is authorized.
[0079] At operation 306, the authorization server transmits the access token (enhanced token) to the service consumer and the service consumer receives the access token.
[0080] At operation 307, the service consumer transmits a service request for requested analytics ID / Model with enhanced access token received to the model training function and the model training function receives the service request.
[0081] At operation 308a, the model training function verifies the enhanced access token and verifies if the NFc is indeed authorized to receive the ML model / analytics or not. In the case of geographical constraints or region based authorization, it also verifies if the ML model can be consumed by a service consumer present in the certain TAI or region or not. In the case of successful verification, and in the case, it already has the trained ML model or analytics ID, it transmits the ML model / analytics to the service consumer and the service consumer receives the ML model / analytics.
[0082] In the case the ML model or analytics ID and data required is not available, at operation 308b, the model training function sends the request to a the data repository (e.g., DCCF, ADRF, or a direct data source) with access token received at operation 307, CCA of Service Consumer and CCA of MTLF.
[0083] At operation 309b, using the CCA of Service Consume and CCA of MTLF, the data repository verifies that the request indeed came from service consumer and if the Service Consumer is authorized to consume the required data for all the requested data sources, and also verifies it against the geographical restriction if inserted by data producers when storing data in the data repository.
[0084] At operation 310b, the data repository transmits the requested data to the model training function and the model training function receives the requested data. At operation 311b, the model training function transmits the requested data to the service consumer and the service consumer receives the requested data.
[0085] In various embodiments, at operation 308c, the model training function transmits a request for access token to the authorization server such that it can request the data needed for ML training from the data repository on behalf of the service consumer. At operation 309c, the model training function transmits the enhanced access token received from the service consumer at operation 307 and CCA of Service Consumer to the authorization server and the authorization server receives the enhanced access token.
[0086] At operation 310c, the authorization server verifies if the model training function can access the data from the requested data sources and generates an access token such that both service consumer and model training function are present as sources, the service producer is the data repository and additional information includes “data producers” indicating all the data sources for which the consumer is authorized to receive the data and in the additional scope can specify which data can be consumed from which producer. In various embodiments, the additional information may include the TAI / Service area of the data sources, and also the service area of the ML model or analytics ID for which the Service consumer is authorized to access.
[0087] At operation 311c, the authorization server transmits the generated enhanced access token to the model training function and the model training function receives the enhanced access token. At operation 312c, the model training function transmits the generated enhanced access token to the data repository along with its CCA to request data for analytics or ML model training and the data repository receives the generated enhanced access token to the data repository along with its CCA to request data for analytics or ML model training.
[0088] At operation 313c, the data repository verifies if the service consumer and model training function is authorized to consume data for all the data sources and for the data parameters requested or not.
[0089] If the decision at operation 313c is that the service consumer and model training function is authorized to consume data for all the data sources and for the data parameters requested, at operation 314c, the data repository transmits the requested data to the model training function and the model training function receives the requested data.
[0090] At operation 314c, the model training function trains the requested ML model and / or transmits the requested analytics ID to the service consumer and the service consumer receives the requested analytics ID.
[0091] The operations of FIG. 3 are merely illustrative, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the operations may include other operations not illustrated in FIG. 3. In embodiments, the operations may not include every operation illustrated in FIG. 3. In embodiments, the operations may be implemented in a different order than that illustrated in FIG. 3. Such and other embodiments are contemplated to be within the scope of the present disclosure. Persons of skill in the art will appreciate that, although various example components are described as perform various functions, other components may perform those functions described in FIG. 3.
[0092] FIG. 4 is a diagram of an example embodiment of signals and operations among a service consumer, an authorization server, a model training function and a data repository, according to another illustrated aspect of the disclosure. In various embodiments, the components depicted in FIG. 3 may correspond to similar components described above in FIGS. 1 and 2. It will be understood that a described signal may have associated operations and a described operation may have associated signals.
[0093] At operation 401, the service consumer transmits an access token request to the authorization server (e.g., NRF) to discover the data producers required for a particular analytics ID or model, and the authorization server receives the access token request, as well as to consume the analytics / model ID and data source mapping”.
[0094] Upon authorization, at operation 402, the authentication server transmits an access token for the requested service to the service consumer and the service consumer receives the access token.
[0095] At operation 403, the service consumer transmits a service request to retrieve data providers for respective analytics ID or ML Model with the access token received at operation 402 to the model training function and the model training function receives the service request.
[0096] At operation 404, the model training function transmits the data producer details as a service response to the service consumer and the service consumer receives the data producer details.
[0097] At operation 405, the service consumer transmits an enhanced access token request to the authorization server and the authorization server receives the enhanced access token request. In various embodiments, the enhanced access token request includes a request for data from all the data producers present in the response received at operation 404. In various embodiments, the enhanced access token request may include the authorization needed for exact data required from each data source.
[0098] At operation 404b, the authorization server, based on the NF profiles of the data sources registered, authorizes the service consumer if it can access a particular ML model or analytics ID or not, by verifying if the data producers needed to train a ML model (e.g., information received at operation 303) in their profiles registered in the NRF have allowed the service consumer to receive data from them or not.
[0099] At operation 405b, the authorization server, in the case of successful authorization, generates an access token with Service Consumer as source, MTLF as producer, and additional “data producers” indicating all the data sources for which the consumer is authorized to receive the data and in the additional scope can specify which dataset can be consumed from whichdata producer. In various embodiments, additional information may include the TAI / Service area of the data sources, and also the service area of the ML model or analytics ID for which the service consumer is authorized to access.
[0100] In various embodiments, when authorizing such requests, the geographical area or TAI or the data source is taken into consideration. For instance, the case that for certain analytics ID, (e.g. advertisement), a data source of certain region does not want to provide the data in general, or specifically to service consumers located in certain regions. Then in such cases the authorization of request may fail, and an alternate data source can be suggested. In various embodiments, certain analytics ID / ML models are restricted to some specific service area / TAI, and then the during authorization, the service area of the service consumer may be taken into account during authorization. In such cases then the geographical area or region or TAI of the data source is also appended to the data source in the access token claims.
[0101] In various embodiments, the trained ML model or analytics ID may be geographically restricted to only certain consumers belonging to specific TAI, therefore, in the case the region information of ML model or analytics is also specified by the ML model producer (for instance in the, for example, NWDAF MTLF) then the NRF also verifies that and only then provides the access token. The access token in such case may include the TAI / region of the ML model / analytics ID for which the consumer is authorized.
[0102] At operation 406, the authorization server transmits the access token (enhanced token) to the service consumer and the service consumer receives the access token.
[0103] At operation 407, the service consumer transmits a service request for requested analytics ID / Model with enhanced access token received to the model training function and the model training function receives the service request.
[0104] At operation 408a, the model training function verifies the enhanced access token and verifies if the NFc is indeed authorized to receive the ML model / analytics or not. In the case of geographical constraints or region based authorization, it also verifies if the ML model can be consumed by a service consumer present in the certain TAI or region or not. In the case of successful verification, and in the case, it already has the trained ML model or analytics ID, it transmits the ML model / analytics to the service consumer and the service consumer receives the ML model / analytics.
[0105] In the case the ML model or analytics ID and data required is not available, at operation 408b, the model training function sends the request to a the data repository (e.g., DCCF or ADRF) with access token received at operation 407, CCA of Service Consumer and CCA of MTLF.
[0106] At operation 409b, using the CCA of Service Consume and CCA of MTLF, the data repository verifies that the request indeed came from service consumer and if the Service Consumer is authorized to consume the required data for all the requested data sources, and also verifies it against the geographical restriction if inserted by data producers when storing data in the data repository.
[0107] At operation 410b, the data repository transmits the requested data to the model training function and the model training function receives the requested data. At operation 311b, the model training function transmits the requested data to the service consumer and the service consumer receives the requested data.
[0108] In various embodiments, at operation 408c, the model training function transmits a request for access token to the authorization server such that it can request the data needed for ML training from the data repository on behalf of the service consumer. At operation 409c, the model training function transmits the enhanced access token received from the service consumer at operation 407 and CCA of Service Consumer to the authorization server and the authorization server receives the enhanced access token.
[0109] At operation 410c, the authorization server verifies if the model training function can access the data from the requested data sources and generates an access token such that both service consumer and model training function are present as sources, the service producer is the data repository and additional information includes “data producers” indicating all the data sources for which the consumer is authorized to receive the data and in the additional scope can specify which data can be consumed from which producer. In various embodiments, the additional information may include the TAI / Service area of the data sources, and also the service area of the ML model or analytics ID for which the Service consumer is authorized to access.
[0110] At operation 411c, the authorization server transmits the generated enhanced access token to the model training function and the model training function receives the enhanced access token. At operation 412c, the model training function transmits the generated enhanced access token to the data repository along with its CCA to request data for analytics or ML model training and the data repository receives the generated enhanced access token to the data repository along with its CCA to request data for analytics or ML model training.
[0111] At operation 413c, the data repository verifies if the service consumer and model training function is authorized to consume data for all the data sources and for the data parameters requested or not.
[0112] If the decision at operation 413c is that the service consumer and model training function is authorized to consume data for all the data sources and for the data parameters requested, at operation 414c, the data repository transmits the requested data to the model training function and the model training function receives the requested data.
[0113] At operation 414c, the model training function trains the requested ML model and / or transmits the requested analytics ID to the service consumer and the service consumer receives the requested analytics ID.
[0114] The operations of FIG. 4 are merely illustrative, and variations are contemplated to be within the scope of the present disclosure. In embodiments, the operations may include other operations not illustrated in FIG. 4. In embodiments, the operations may not include every operation illustrated in FIG. 4. In embodiments, the operations may be implemented in a different order than that illustrated in FIG. 4. Such and other embodiments are contemplated to be within the scope of the present disclosure. Persons of skill in the art will appreciate that, although various example components are described as perform various functions, other components may perform those functions described in FIG. 4.
[0115] In various embodiments, the service consumer, authorization server, MTLF and data repository may be referred to as entities.
[0116] The following describes operations from the perspective of an authorization server. From such a perspective, a method may include receiving, at a first node, information relating to authorization for one or more functionalities, receiving, by the first node, a request from a second node, the request including a request for machine learning (ML) model analytics data, determining, by the first node, an authorization of the second node for the ML analytics data based upon the information relating to authorization for one or more functionalities, and transmitting, by the first node, based upon the authorization, an access token to the second node relating to authorization for the ML analytics data.
[0117] The following describes operations from the perspective of an MTLF. From such a perspective, a method may include receiving, by a model training function (MTLF) entity, a request for machine learning (ML) analytics data from a first node, and transmitting, by the MTLF entity, based on an authorization of the first apparatus, the ML analytics data to the first node.
[0118] The following describes operations from the perspective of a service consumer entity. From such a perspective, a method may include receiving, by the service consumer entity, an access token for a requested machine learning (ML) model analytics data from an authorization server, transmitting, by the service consumer entity, a request for the ML modelanalytics data to a model training function (MTLF) entity, and receiving, by the service consumer entity, the ML model analytics data from the MTLF entity.
[0119] The following describes operations from the perspective of a data repository entity. From such a perspective, a method may include receiving, by the data repository entity, a request for data from a model training function (MTLF) entity, the request for data including an access token and service consumer information for a service consumer, determining, by the data repository entity, whether the service consumer is authorized to receive the data, and transmitting, by the data repository entity, the data based to the MTLF entity upon the determined authorization of the service consumer.
[0120] Referring now to FIG. 5, there is shown a block diagram of example components of a UE or a network apparatus (e.g., of a RAN or a core network). The apparatus includes an electronic storage 510, a processor 520, a network interface 540, and a memory 550. The various components may be communicatively coupled with each other. The processor 520 may be and may include any type of processor, such as a single-core central processing unit (CPU), a multi-core CPU, a microprocessor, a digital signal processor (DSP), a System-on-Chip (SoC), or any other type of processor. The memory 550 may be a volatile type of memory, e.g., RAM, or a non-volatile type of memory, e.g., NAND flash memory. The memory 550 includes processor-readable instructions that are executable by the processor 520 to cause the apparatus to perform various operations, including those mentioned herein, such as the operations described in FIGS. 3A-4B.
[0121] The electronic storage 510 may be and include any type of electronic storage used for storing data, such as hard disk drive, solid state drive, optical disc, and / or other non- transitory computer-readable mediums, among other types of electronic storage. The electronic storage 510 stores processor-readable instructions for causing or configured for causing the apparatus to perform its operations and also stores data associated with such operations, such as storing data relating to 5G NR standards, among other data. The network interface 540 may implement wireless networking technologies such as 5G NR and / or other wireless networking technologies.
[0122] The components shown in FIG. 5 are merely examples, and persons skilled in the art will understand that an apparatus includes other components not illustrated and may include multiples of any of the illustrated components. Such and other embodiments are contemplated to be within the scope of the present disclosure. For example, a transmitter and a receiver may be included as components for transmitting and receiving signals.
[0123] Further embodiments of the present disclosure include the following examples.
[0124] Example 1.1. An apparatus comprising: means for receiving, at a first node, information relating to authorization for one or more functionalities; means for receiving, by the first node, a request from a second node, the request including a request for machine learning (ML) model analytics data; means for determining, by the first node, an authorization of the second node for the ML analytics data based upon the information relating to authorization for one or more functionalities; and means for transmitting, by the first node, based upon the authorization, an access token to the second node relating to authorization for the ML analytics data.
[0125] Example 1.2. The apparatus of example 1.1, wherein the first node transmits a request to a third node, the third node being a model analytics function to retrieve the data source mapping information.
[0126] Example 1.3. The apparatus of example 1.2, wherein the first node receives the data source mapping information and data parameters from the third node.
[0127] Example 1.4. The apparatus of example 1.3, wherein the data source mapping information includes information relating to data used to retrieve data sources required for ML model training.
[0128] Example 1.5. The apparatus as in any one of examples 1.1 to 1.4, wherein the determining of an authorization of the second node includes reviewing, by the first node, whether the second node is a registered consumer to access the requested ML analytics data.
[0129] Example 1.6. The apparatus as in any one of examples 1.1 to 1.5, further comprising means for generating, by the first node, the access token upon a determination of authorization for the second node.
[0130] Example 1.7. The apparatus as in any one of examples 1.1 to 1.6, wherein the access token includes a service consumer as a source and a model analytics function as a producer.
[0131] Example 1.8. The apparatus of example 1.7, wherein the access token includes an indication of data sources the service consumer is authorized to receive data.
[0132] Example 1.9. The apparatus as in any one of examples 1.1 to 1.8, further comprising means for receiving, by the first node, an access token request from the third node and determining whether the third node is authorized to access data from a requested data source indicated in the access token request.
[0133] Example 1.10. The apparatus of example 1.9, wherein upon a determination thatthe third node is authorized to access data from a requested data source indicated in access token request, generating, by the first node, an enhanced access token and transmitting the enhanced access token to the third node.
[0134] Example 1.11. The apparatus of example 1.10, wherein the enhanced access token includes the third node as a source.
[0135] Example. 2.1. An apparatus, comprising: means for receiving, by a model training function (MTLF) entity, a request for machine learning (ML) analytics data from a first node; and means for transmitting, by the MTLF entity, based on an authorization of the first apparatus, the ML analytics data to the first node.
[0136] Example 2.2. The apparatus of example 2.1, wherein the first apparatus is a service consumer entity or an authorization server entity.
[0137] Example 2.3. The apparatus as in any one of examples 2.1 or 2.2, wherein the request for ML analytics data includes an access token.
[0138] Example 2.4. The apparatus of example 2.3, further comprising means for verifying, by the MTLF entity, the access token.
[0139] Example 2.5. The apparatus as in any one of examples 2.1 to 2.4, wherein uponML analytics data not being available, transmitting, by the MTLF entity, a request to a data repository, the request including the access token.
[0140] Example 3.1. An apparatus, comprising: means for receiving, by a service consumer entity, an access token for a requested machine learning (ML) model analytics data from an authorization server; means for transmitting, by the service consumer entity, a request for the ML model analytics data to a model training function (MTLF) entity; and means for receiving, by the service consumer entity, the ML model analytics data from the MTLF entity.
[0141] Example 3.2. The apparatus of example 3.1, further comprising means for transmitting an access token request for data producers to the authorization server.
[0142] Example 4.1. An apparatus, comprising: means for receiving, by a data repository entity, a request for data from a model training function (MTLF) entity, the request for data including an access token and service consumer information for a service consumer; means for determining, by the data repository entity, whether the service consumer is authorized to receive the data; andmeans for transmitting, by the data repository entity, the data based to the MTLF entity upon the determined authorization of the service consumer.
[0143] Example 5.1. An apparatus, comprising: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform: receiving, at a first node, information relating to authorization for one or more functionalities; receiving, by the first node, a request from a second node, the request including a request for machine learning (ML) model analytics data; determining, by the first node, an authorization of the second node for the ML analytics data based upon the information relating to authorization for one or more functionalities; and transmitting, by the first node, based upon the authorization, an access token to the second node relating to authorization for the ML analytics data.
[0144] Example 6.1. An apparatus, comprising: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform: receiving, by a model training function (MTLF) entity, a request for machine learning (ML) analytics data from a first node; and transmitting, by the MTLF entity, based on an authorization of the first apparatus, the ML analytics data to the first node.
[0145] Example 7.1. An apparatus, comprising: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform: receiving, by a service consumer entity, an access token for a requested machine learning (ML) model analytics data from an authorization server; transmitting, by the service consumer entity, a request for the ML model analytics data to a model training function (MTLF) entity; and receiving, by the service consumer entity, the ML model analytics data from the MTLF entity.
[0146] Example 8.1. An apparatus, comprising: at least one processor; andat least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform: receiving, by a data repository entity, a request for data from a model training function (MTLF) entity, the request for data including an access token and service consumer information for a service consumer; determining, by the data repository entity, whether the service consumer is authorized to receive the data; and transmitting, by the data repository entity, the data based to the MTLF entity upon the determined authorization of the service consumer.
[0147] The embodiments and aspects disclosed herein are examples of the present disclosure and may be embodied in various forms. For instance, although certain embodiments herein are described as separate embodiments, each of the embodiments herein may be combined with one or more of the other embodiments herein. Specific structural and functional details disclosed herein are not to be interpreted as limiting, but as a basis for the claims and as a representative basis for teaching one skilled in the art to variously employ the present disclosure in virtually any appropriately detailed structure. Like reference numerals may refer to similar or identical elements throughout the description of the figures.
[0148] The phrases “in an aspect,” “in aspects,” “in various aspects,” “in some aspects,” or “in other aspects” may each refer to one or more of the same or different aspects in accordance with this present disclosure. The phrase “a plurality of’ may refer to two or more.
[0149] In various embodiments, the terms “first message” and “second message”, as well as any subsequent messages may refer to any messages that are transmitted or received in an order and are not necessarily limited to any particular message.
[0150] The phrases “in an embodiment,” “in embodiments,” “in various embodiments,” “in some embodiments,” or “in other embodiments” may each refer to one or more of the same or different embodiments in accordance with the present disclosure. A phrase in the form “A or B” means “(A), (B), or (A and B).” A phrase in the form “at least one of A, B, or C” means “(A); (B); (C); (A and B); (A and C); (B and C); or (A, B, and C) ”
[0151] Any of the herein described methods, programs, algorithms or codes may be converted to, or expressed in, a programming language or computer program. The terms “programming language” and “computer program,” as used herein, each include any language used to specify instructions to a computer, and include (but is not limited to) the following languages and their derivatives: Assembler, Basic, Batch files, BCPL, C, C+, C++, Delphi, Fortran, Java, JavaScript, machine code, operating system command languages, Pascal, Perl,PL1, Python, scripting languages, Visual Basic, metalanguages which themselves specify programs, and all first, second, third, fourth, fifth, or further generation computer languages. Also included are database and other data schemas, and any other meta-languages. No distinction is made between languages which are interpreted, compiled, or use both compiled and interpreted approaches. No distinction is made between compiled and source versions of a program. Thus, reference to a program, where the programming language could exist in more than one state (such as source, compiled, object, or linked) is a reference to any and all such states. Reference to a program may encompass the actual instructions and / or the intent of those instructions.
[0152] While aspects of the present disclosure have been shown in the drawings, it is not intended that the present disclosure be limited thereto, as it is intended that the present disclosure be as broad in scope as the art will allow and that the specification be read likewise. Therefore, the above description should not be construed as limiting, but merely as exemplifications of particular aspects. Those skilled in the art will envision other modifications within the scope and spirit of the claims appended hereto.
Claims
Claims:
1. A method, comprising: receiving, at a first node, information relating to authorization for one or more functionalities; receiving, by the first node, a request from a second node, the request including a request for machine learning (ML) model analytics data; determining, by the first node, an authorization of the second node for the ML analytics data based upon the information relating to authorization for one or more functionalities; and transmitting, by the first node, based upon the authorization, an access token to the second node relating to authorization for the ML analytics data.
2. The method of claim 1 , wherein the first node transmits a request to a third node, the third node being a model analytics function to retrieve the data source mapping information.
3. The method of claim 2, wherein the first node receives the data source mapping information and data parameters from the third node.
4. The method of claim 3, wherein the data source mapping information includes information relating to data used to retrieve data sources required for ML model training.
5. The method as in any one of claims 1 to 4, wherein the determining of an authorization of the second node includes reviewing, by the first node, whether the second node is a registered consumer to access the requested ML analytics data.
6. The method as in any one of claims 1 to 5, further comprising generating, by the first node, the access token upon a determination of authorization for the second node.
7. The method as in any one of claims 1 to 6, wherein the access token includes a service consumer as a source and a model analytics function as a producer.
8. The method of claim 7, wherein the access token includes an indication of data sources the service consumer is authorized to receive data.
9. The method as in any one of claims 1 to 8, further comprising receiving, by the first node, an access token request from the third node and determining whether the third node is authorized to access data from a requested data source indicated in the access token request.
10. The method of claim 9, wherein upon a determination that the third node is authorized to access data from a requested data source indicated in access token request, generating, by the first node, an enhanced access token and transmitting the enhanced access token to the third node.
11. The method of claim 10, wherein the enhanced access token includes the third node as a source.
12. A method, comprising: receiving, by a model training function (MTLF) entity, a request for machine learning (ML) analytics data from a first node; and transmitting, by the MTLF entity, based on an authorization of the first apparatus, the ML analytics data to the first node.
13. The method of claim 12, wherein the first apparatus is a service consumer entity or an authorization server entity.
14. The method as in any one of claims 12 or 13, wherein the request for ML analytics data includes an access token.
15. The method of claim 14, further comprising verifying, by the MTLF entity, the access token.
16. The method as in any of claims 12 to 15, wherein upon ML analytics data not being available, transmitting, by the MTLF entity, a request to a data repository, the request including the access token.
17. A method, comprising: receiving, by a service consumer entity, an access token for a requested machine learning (ML) model analytics data from an authorization server;transmitting, by the service consumer entity, a request for the ML model analytics data to a model training function (MTLF) entity; and receiving, by the service consumer entity, the ML model analytics data from the MTLF entity.
18. The method of claim 17, further comprising transmitting an access token request for data producers to the authorization server.
19. A method, comprising: receiving, by a data repository entity, a request for data from a model training function (MTLF) entity, the request for data including an access token and service consumer information for a service consumer; determining, by the data repository entity, whether the service consumer is authorized to receive the data; and transmitting, by the data repository entity, the data based to the MTLF entity upon the determined authorization of the service consumer.
20. An apparatus, comprising: at least one processor; and at least one memory storing instructions which, when executed by the at least one processor, cause the apparatus at least to perform a method as in any one of claims 1-19.
21. A processor-readable medium storing instructions which, when executed by at least one processor of an apparatus, cause the apparatus at least to perform a method as in any one of claims 1-19.
Citation Information
Patent Citations
Authorized machine learning model retrieval for a communications network
US20230353561A1