Authorization method and apparatus for federated member, and network side device

By leveraging the Network Memory Function (NRF) to authorize vertical federated learning group members within the 3GPP system, the authorization issue between operators and third parties is resolved, enabling secure and efficient selection and authorization of federated learning group members, thereby enhancing system security and privacy protection.

WO2025237191A9PCT designated stage Publication Date: 2026-04-23VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
VIVO MOBILE COMM CO LTD
Filing Date
2025-05-09
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

In the 3GPP system, how can the selection and authorization of members be implemented in a vertical federated learning group, especially when vertical federated learning is carried out between operators and third parties, and how can the authorization mechanism of 3GPP be used for authorization?

Method used

The Network Request Function (NRF) receives token request messages, determines whether the FL server can access the FL client based on the request message, and sends an access token, including the identifier of the FL client, to the network device to authorize members of the federation group.

Benefits of technology

It enables effective authorization of members of the vertical federated learning group under the 3GPP network architecture, improves the security and privacy protection of the system, and prevents the exposure of internal network topology information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025093795_23042026_PF_FP_ABST
    Figure CN2025093795_23042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and discloses an authorization method and apparatus for a federated member, and a network side device. The authorization method for a federated member in embodiments of the present application comprises: a network repository function (NRF) receiving a token request message from a first network device, the token request message comprising an identifier of a federated learning (FL) server, an identifier of a proxy, and an identifier of a first FL client, wherein the identifier of the first FL client indicates one or more FL clients; and when the NRF determines, on the basis of the token request message, that the FL server is able to access the first FL client, sending an access token to the first network device, the access token comprising the identifier of the first FL client.
Need to check novelty before this filing date? Find Prior Art

Description

Authorization methods, devices, and network-side equipment of federal members

[0001] Cross-reference to related applications

[0002] This application claims priority to Chinese Patent Application No. 202410584384.X, filed in China on May 11, 2024, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application belongs to the field of communication technology, and specifically relates to a method, apparatus and network-side device for granting licenses to federal members. Background Technology

[0004] Federated learning refers to a method of machine learning modeling by uniting different participants (or parties, also known as data owners or clients). In federated learning, participants do not need to expose their data to other participants or the coordinator (also known as a server, parameter server, or aggregation server). Therefore, federated learning can effectively protect user privacy and ensure data security, and can solve the problem of data silos.

[0005] After applying federated learning to the communications field, especially after the introduction of vertical federated learning into the 3GPP system, how to use the 3GPP authorization mechanism to authorize each member to join the vertical federated learning group is an urgent problem to be solved. Summary of the Invention

[0006] This application provides a method, apparatus, and network-side device for authorizing federal members, which can enable the authorization of federal members.

[0007] Firstly, it provides a method for authorizing federal members, including:

[0008] The Network Storage Function (NRF) receives a token request message from a first network device. The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client, wherein the identifier of the first FL client indicates one or more FL clients.

[0009] If the NRF determines, based on the token request message, that the FL server can access the first FL client, it sends an access token to the first network device, the access token including the identifier of the first FL client.

[0010] Secondly, it provides a method for authorizing federal members, including:

[0011] The first network device sends a token request message to the Network Storage Function (NRF). The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client, wherein the identifier of the first FL client indicates one or more FL clients.

[0012] The first network device receives an access token returned by the NRF, the access token including the identifier of the first FL client;

[0013] The first network device sends a first request message to the second network device. The first request message is used for federated learning and includes the identifier of the first network device, the identifier of the first FL client, and the access token.

[0014] Thirdly, it provides a method for authorizing federal members, including:

[0015] The second network device receives a first request message sent by the first network device. The first request message is for federated learning (FL). The first request message includes the identifier of the first network device, the identifier of the first FL client, and an access token. The access token includes the identifier of the first FL client, and the identifier of the first FL client indicates one or more FL clients.

[0016] The second network device verifies the access token, and responds to the first request message after the verification is successful.

[0017] Fourthly, a method for authorizing federal members is provided, including:

[0018] The agent sends a discovery request message to the Network Storage Function (NRF), which requests the search for FL clients capable of performing federated learning (FL).

[0019] The agent receives a discovery response message returned by the NRF, the discovery response message including the original identifier of the second FL client;

[0020] The agent anonymizes the original identifier of the second FL client to obtain a temporary identifier for the second FL client, and the number of temporary identifiers is greater than the number of original identifiers;

[0021] The agent sends a temporary identifier of the second FL client to the FL server.

[0022] Fifthly, an authorization device for a federal member is provided, comprising:

[0023] The first receiving module is configured to receive a token request message from the first network device. The token request message includes the identifier of the federated learning FL server, the identifier of the agent, and the identifier of the first FL client. The identifier of the first FL client indicates one or more FL clients.

[0024] A first sending module is configured to send an access token to the first network device when the NRF determines, based on the token request message, that the FL server can access the first FL client, the access token including the identifier of the first FL client.

[0025] Sixthly, an authorization device for a federal member is provided, comprising:

[0026] The second sending module is used to send a token request message to the Network Storage Function (NRF). The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client, wherein the identifier of the first FL client indicates one or more FL clients.

[0027] The second receiving module is used to receive the access token returned by the NRF, the access token including the identifier of the first FL client;

[0028] The third sending module is used to send a first request message to the second network device. The first request message is used for federated learning and includes the identifier of the first network device, the identifier of the first FL client, and the access token.

[0029] Seventhly, an authorization device for a federal member is provided, comprising:

[0030] The third receiving module is used to receive a first request message sent by the first network device. The first request message is for federated learning (FL). The first request message includes the identifier of the first network device, the identifier of the first FL client, and an access token. The access token includes the identifier of the first FL client, and the identifier of the first FL client indicates one or more FL clients.

[0031] The first processing module is used to verify the access token and respond to the first request message after the verification is successful.

[0032] Eighthly, an authorization device for a federal member is provided, comprising:

[0033] The fourth sending module is used to send a discovery request message to the Network Storage Function (NRF), the discovery request message requesting the search for FL clients capable of performing federated learning (FL);

[0034] The fourth receiving module is used to receive the discovery response message returned by the NRF, the discovery response message including the original identifier of the second FL client;

[0035] The second processing module is used to anonymize the original identifier of the second FL client to obtain a temporary identifier of the second FL client, wherein the number of temporary identifiers is greater than the number of original identifiers;

[0036] The fifth sending module is used to send the temporary identifier of the second FL client to the FL server.

[0037] A ninth aspect provides a network-side device including a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the method as described in the first, second, third, or fourth aspect.

[0038] In a tenth aspect, a readable storage medium is provided, on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.

[0039] Eleventhly, a wireless communication system is provided, comprising: a terminal and a network-side device, wherein the network-side device can be used to perform the steps of the method described in the first, second, third, or fourth aspects.

[0040] In a twelfth aspect, a chip is provided, the chip including a processor and a communication interface coupled to the processor, the processor being configured to run a program or instructions to implement the steps of the method described in the first aspect, or the steps of the method described in the second aspect, or the steps of the method described in the third aspect, or the steps of the method described in the fourth aspect.

[0041] In a thirteenth aspect, a computer program / program product is provided, the computer program / program product being stored in a storage medium, the computer program / program product being executed by at least one processor to implement the steps of the method as described in the first aspect, or the steps of the method as described in the second aspect, or the steps of the method as described in the third aspect, or the steps of the method as described in the fourth aspect.

[0042] In this embodiment, the first network device requests an access token from the NRF. The NRF receives the token request message from the first network device, authorizes it according to the token request message, and issues an access token with the identifier of the first FL client to the first network device. This embodiment enables the authorization of federation group members. Attached Figure Description

[0043] Figure 1 is a block diagram of a wireless communication system applicable to an embodiment of this application;

[0044] Figures 2-5 are schematic flowcharts of the authorization method for federal members according to embodiments of this application;

[0045] Figures 6 and 7 are schematic flowcharts of the authorization method for federal members according to specific embodiments of this application;

[0046] Figures 8-11 are structural block diagrams of the authorized device of the federal member according to the embodiments of this application;

[0047] Figure 12 is a structural block diagram of a communication device according to an embodiment of this application;

[0048] Figure 13 is a structural block diagram of the network-side device according to an embodiment of this application. Detailed Implementation

[0049] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0050] The terms "first," "second," etc., used in this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first" and "second" are generally of the same class, not limited in number; for example, the first object can be one or more. Furthermore, "or" in this application indicates at least one of the connected objects. For example, the scope of protection for "A or B" covers at least three scenarios: Scenario 1: including A but not B; Scenario 2: including B but not A; Scenario 3: including both A and B. In addition, the terms "A and / or B," "at least one of A and B," and "at least one of A or B" also cover at least the above three scenarios. The character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0051] The term "instruction" in this application can be either a direct instruction (or explicit instruction) or an indirect instruction (or implicit instruction). A direct instruction can be understood as one in which the sender explicitly informs the receiver of specific information, the operation to be performed, or the requested result, etc., in the instruction sent. An indirect instruction can be understood as one in which the receiver determines the corresponding information based on the instruction sent by the sender, or makes a judgment and determines the operation to be performed or the requested result, etc., based on the judgment result.

[0052] It is worth noting that the technologies described in this application are not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA), or other systems. The terms "system" and "network" in this application are often used interchangeably, and the described technologies can be used with the systems and radio technologies mentioned above, as well as with other systems and radio technologies. The following description describes New Radio (NR) systems for illustrative purposes, and the term NR is used in most of the following description; however, these technologies can also be applied to systems other than NR systems, such as 5G (5G) systems. th Generation 5G communication systems and 6th generation (6G) communication systems th Generation 6G communication system.

[0053] Figure 1 shows a block diagram of a wireless communication system applicable to an embodiment of this application. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 can be a mobile phone, tablet computer, laptop computer, notebook computer, personal digital assistant (PDA), handheld computer, netbook, ultra-mobile personal computer (UMPC), mobile internet device (MID), augmented reality (AR), virtual reality (VR) device, robot, wearable device, flight vehicle, vehicle user equipment (VUE), shipboard equipment, pedestrian user equipment (PUE), smart home (home devices with wireless communication capabilities, such as refrigerators, televisions, washing machines, or furniture), game console, personal computer (PC), ATM, or self-service machine, etc. Wearable devices include: smartwatches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart chains, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. Among these, in-vehicle devices can also be referred to as in-vehicle terminals, in-vehicle controllers, in-vehicle modules, in-vehicle components, in-vehicle chips, or in-vehicle units, etc. It should be noted that the specific type of terminal 11 is not limited in this application embodiment. Network-side equipment 12 may include access network equipment or core network equipment, wherein access network equipment may also be referred to as Radio Access Network (RAN) equipment, radio access network function, or radio access network unit. Access network equipment may include base stations, Wireless Local Area Network (WLAN) access points (APs), or Wireless Fidelity (WiFi) nodes, etc.The term "base station" can be referred to as Node B (NB), Evolved Node B (eNB), Next Generation Node B (gNB), New Radio Node B (NR Node B), Access Point, Relay Base Station (RBS), Serving Base Station (SBS), Base Transceiver Station (BTS), Radio Base Station, Radio Transceiver, Basic Service Set (BSS), Extended Service Set (ESS), Home Node B (HNB), Home Evolved Node B, Transmit / Receive Point (TRP), or any other suitable term in the relevant field, as long as the same technical effect is achieved. The term "base station" is not limited to any specific technical terminology. It should be noted that this application embodiment only uses a base station in an NR system as an example for description and does not limit the specific type of base station.

[0054] Core network equipment, also known as core network nodes, core network functions, or core network elements, includes, but is not limited to, at least one of the following: Mobility Management Entity (MME), Access and Mobility Management Function (AMF), Session Management Function (SMF), User Plane Function (UPF), Policy Control Function (PCF), Policy and Charging Rules Function (PCRF), Edge Application Server Discovery Function (EASDF), Unified Data Management (UDM), Unified Data Repository (UDR), Home Subscriber Server (HSS), Centralized network configuration (CNC), Network Repository Function (NRF), Network Exposure Function (NEF), Local NEF (or L-NEF), and Binding Support. Functions include BSF, Application Function (AF), Location Management Function (LMF), Gateway Mobile Location Centre (GMLC), and Network Data Analytics Function (NWDAF). It should be noted that this application embodiment only uses core network equipment in the NR system as an example and does not limit the specific type of core network equipment. If the name of the core network equipment mentioned in this application embodiment changes in subsequent protocol versions (e.g., 6G), it will still be within the scope of protection of this application.

[0055] Optionally, the core network equipment can be implemented by one or more functional modules in a single device, or by multiple devices working together; this application does not specifically limit this. It is understood that the aforementioned functional modules can be network elements in hardware devices, software functional modules running on dedicated hardware, or virtualized functional modules instantiated on a platform (e.g., a cloud platform).

[0056] Vertical Federated Learning (VFL) is essentially the joint processing of features. It is suitable for scenarios with significant user overlap but minimal feature overlap, such as different services offered by the same user (e.g., User Equipment (UE), i.e., the same sample) in a communication network's operator domain and third-party domain. (For example, the operator provides communication services and has user location and communication feature data, while the third-party service provider provides application services and has user usage habit data, i.e., different features). By jointly processing the different data features of the common samples from the participating parties, vertical federation increases the feature dimensions of the training samples and yields a better model.

[0057] In the 3GPP system, vertical federated learning is introduced between operators (through the Network Data Analytics Function (NWDAF)) and third parties (through AF). Before conducting vertical federated learning, the members of the vertical federated learning need to be selected, which may involve VFL servers and VFL clients. Currently, there are two possible scenarios: 1) One NWDAF acts as a VFL server, and one or more AFs act as VFL clients; 2) One AF acts as a VFL server, and one or more NWDAFs act as VFL clients.

[0058] Typically, external AFs and NWDAFs communicate through NEF. NEF also has the function of hiding the internal network topology from the AF. Therefore, how to achieve the selection and authorization of members of the vertical federated learning group under the 3GPP network architecture is a problem that needs to be solved.

[0059] This application provides an authorization method for federal members, as shown in Figure 2, including:

[0060] Step 101: The Network Storage Function (NRF) receives a token request message from the first network device. The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client. The identifier of the first FL client indicates one or more FL clients.

[0061] Step 102: If the NRF determines that the FL server can access the first FL client based on the token request message, it sends an access token to the first network device, the access token including the identifier of the first FL client.

[0062] In this embodiment, the first network device requests an access token from the NRF. The NRF receives the token request message from the first network device, authorizes it according to the token request message, and issues an access token with the identifier of the first FL client to the first network device. The first network device can access the second network device by carrying the access token. The authorization of federation group members can be realized through this embodiment.

[0063] The identifier of the first FL client included in the access token may or may not be completely identical to the identifier of the first FL client included in the token request message.

[0064] For example, when the first FL client indicates one or more FL clients, the token request message may contain only the identifiers of one or more FL clients and the identifier of the FL server. The NRF can obtain the identifiers of all FL clients based on the identifiers of one or more FL clients and the identifier of the FL server, and make the access token contain the identifiers of all FL clients.

[0065] In some embodiments, the token request message may contain only the identifier of the FL server, without the identifier of the FL client. The NRF can obtain the identifiers of all FL clients based on the identifier of the FL server and make the access token contain the identifiers of all FL clients.

[0066] In some embodiments, the method further includes:

[0067] The NRF receives and saves the first information of the second network device, the first information including the identifier of the first FL client and the authorization information corresponding to the first FL client;

[0068] The NRF determines that the FL server can access the first FL client based on the token request message, including:

[0069] The NRF determines, based on the token request message and the first information, that the FL server can access the first FL client.

[0070] In this embodiment, the second network device can be registered with the NRF. After the NRF receives the token request message, it can determine whether the FL server can access the first FL client based on the token request message and the first information of the second network device registration.

[0071] In some embodiments, the authorization information includes at least one of the following:

[0072] The analysis identifier of the first FL client;

[0073] The device vendor identifier of the first FL client;

[0074] Interoperability indication for the first FL client;

[0075] The alliance identifier of the first FL client.

[0076] The analytics ID of the first FL client indicates the analytics IDs supported by the first FL client. For example, if the first FL client supports two types of analytics, then the analytics IDs of the first FL client include analytics ID1 and analytics ID2.

[0077] The vendor ID of the first FL client indicates the vendor to which the first FL client belongs.

[0078] The interoperability indicator of the first FL client indicates whether the first FL client can interoperate with devices from other vendors, such as a list of vendor identifiers.

[0079] The federation identifier of the first FL client indicates the federation to which the first FL client belongs with other devices, and devices in the same federation can perform federated learning.

[0080] In some embodiments, when the first network device is the FL server, the second network device is the agent;

[0081] In the case where the first network device is the agent, the second network device is the FL client.

[0082] In some embodiments, the token request message further includes verification information, which includes at least one of the following: network function instance identifier, analysis identifier, equipment vendor identifier, interoperability indicator, and alliance identifier; the NRF determines that the FL server can access the first FL client based on the token request message and the first information, including:

[0083] The NRF determines whether the verification information matches the authorization information based on the verification information and the first information.

[0084] The verification information is provided by the first network device, and therefore can be referred to as the verification information of the first network device.

[0085] The Network Function Instance ID (NF instance ID) of the first network device is used to indicate the first network device.

[0086] The analysis identifier of the first network device is used to indicate the analysis identifier of the first network device to prepare a request.

[0087] The vendor identifier, interoperability indicator, and alliance identifier of the first network device respectively indicate the vendor, interoperability indicator, and alliance to which the first network device belongs.

[0088] In some embodiments, the NRF determines whether the verification information matches the authorization information based on the verification information and the first information, including at least one of the following:

[0089] Determine that the analysis identifier in the verification information belongs to the analysis identifiers supported by the first FL client;

[0090] Determine that the equipment vendor identifier in the verification information belongs to a subset of the interoperability indications supported by the first FL client;

[0091] Determine whether the interoperability indication in the verification information belongs to a subset or the entire set of interoperability indications of the first FL client;

[0092] Determine whether the interoperability instructions of multiple FL clients are mutually inclusive;

[0093] The alliance identifier in the verification information is determined to be consistent with the alliance identifier of the first FL client.

[0094] It should be understood that after the second network device registers the first information of the first FL client with the NRF, the NRF has a global view and can therefore make centralized authorization judgments based on the first information and the received verification information.

[0095] In some embodiments, when the verification information only includes the network function instance identifier, before the NRF determines that the verification information matches the authorization information based on the verification information and the first information, the method further includes:

[0096] The NRF obtains at least one of the following based on the network function instance identifier: the analysis identifier, the equipment vendor identifier, the interoperability indication, and the alliance identifier.

[0097] For example, NRF can obtain at least one of the following: the analysis identifier of the first network device, the device vendor identifier, the interoperability indication, and the alliance identifier, based on the network function instance identifier of the first network device in the verification information, and then compare it with the analysis identifier, the device vendor identifier, the interoperability indication, and the alliance identifier supported by the first FL client.

[0098] In some embodiments, the access token also includes the analytics identifier.

[0099] In some embodiments, the access token also includes the identifier of the FL server.

[0100] In some embodiments, before the NRF receives the token request message from the first network device, the method further includes:

[0101] The NRF receives a discovery request message from the first network device, the discovery request message requesting to find FL clients capable of performing federated learning;

[0102] The NRF returns a discovery response message to the first network device, the discovery response message including the identifier of the first FL client.

[0103] The first network device can find FL clients capable of performing federated learning by calling the network element discovery service provided by NRF. For example, the first network device can include the analysis of the request and its requirements for federated learning, such as the role of federated learning and the federated learning algorithm, in the network element discovery service request, so that NRF can find FL clients that meet the requirements based on the above information.

[0104] In this embodiment, the NRF can search for FL clients capable of federated learning based on service requirements or FL client capability information, and send the FL clients capable of federated learning as the first FL clients to the first network device.

[0105] In some embodiments, the identifier of the first FL client in the first information is an anonymized identifier. This hides the real identifier of the first FL client from the first network device, improving the overall system security.

[0106] This application also provides an authorization method for federal members, as shown in Figure 3, including:

[0107] Step 201: The first network device sends a token request message to the Network Storage Function (NRF). The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client. The identifier of the first FL client indicates one or more FL clients.

[0108] Step 202: The first network device receives the access token returned by the NRF, the access token including the identifier of the first FL client;

[0109] Step 203: The first network device sends a first request message to the second network device. The first request message is used for federated learning and includes the identifier of the first network device, the identifier of the first FL client, and the access token.

[0110] In this embodiment, the first network device requests an access token from the NRF. The NRF receives the token request message from the first network device, authorizes it according to the token request message, and issues an access token with the identifier of the first FL client to the first network device. The first network device can access the second network device by carrying the access token. The authorization of federation group members can be realized through this embodiment.

[0111] In some embodiments, when the first network device is the FL server, the second network device is the agent;

[0112] In the case where the first network device is the agent, the second network device is the FL client.

[0113] In some embodiments, the token request message further includes verification information, which includes at least one of the following: network function instance identifier, analysis identifier, equipment vendor identifier, interoperability instruction, and alliance identifier.

[0114] In some embodiments, the access token also includes the analytics identifier.

[0115] In some embodiments, the access token also includes the identifier of the FL server.

[0116] The description of the relevant labels can be found in Figure 1.

[0117] In some embodiments, before the first network device sends a token request message to the NRF, the method further includes:

[0118] The first network device sends a discovery request message to the NRF, requesting to find FL clients capable of performing federated learning;

[0119] The first network device receives a discovery response message returned by the NRF, the discovery response message including the identifier of the first FL client.

[0120] In this embodiment, the NRF can search for FL clients capable of federated learning based on service requirements or FL client capability information, and send the FL clients capable of federated learning as the first FL clients to the first network device.

[0121] This application also provides an authorization method for federal members, as shown in Figure 4, including:

[0122] Step 301: The second network device receives a first request message sent by the first network device. The first request message is for federated learning (FL). The first request message includes the identifier of the first network device, the identifier of the first FL client, and an access token. The access token includes the identifier of the first FL client, and the identifier of the first FL client indicates one or more FL clients.

[0123] Step 302: The second network device verifies the access token, and responds to the first request message after the verification is successful.

[0124] In this embodiment, after the second network device receives the first request message from the first network device requesting to perform federated learning, it can respond to the first request message after verifying the access token, for example, by participating in federated learning; or, it can send a second request message to the FL client, requesting the FL client to perform federated learning.

[0125] Specifically, federated learning can be broken down into steps such as sample alignment, initial model alignment, and federated training. Federated learning represents the signaling interaction of any of the above steps, and this application does not impose any restrictions.

[0126] In some embodiments, verifying the access token includes:

[0127] Verify the integrity of the access token;

[0128] After the access token integrity verification is successful, determine whether to allow the first network device to access the first FL client based on at least one of the following:

[0129] Verify whether the identifier of the first FL client is included in the access token;

[0130] Verify whether the identifier of the first network device in the first request message is included in the access token;

[0131] Verify whether the analysis identifier in the first request message is included in the access token.

[0132] It should be understood that after NRF completes the authorization process in Figure 2, it writes the authorized information into the access token. Therefore, by verifying the integrity of the access token, it can prevent the access token from being tampered with. Then, it verifies whether the information in the first request information is included in the access token, thereby verifying whether the first request information has been authorized.

[0133] In some embodiments, before the second network device receives the first request message from the first network device, the method further includes:

[0134] The second network device sends first information to the Network Storage Function (NRF), the first information including the identifier of the first FL client and the authorization information corresponding to the first FL client.

[0135] In this embodiment, the second network device can be registered with the NRF. After the NRF receives the token request message, it can determine whether the FL server can access the first FL client based on the token request message and the first information of the second network device registration.

[0136] In some embodiments, before the second network device sends the first information to the Network Storage Function (NRF), the method further includes:

[0137] The second network device anonymizes the original identifier of the first FL client to obtain a temporary identifier for the first FL client, and the identifier of the first FL client in the first information is the temporary identifier. This prevents the exposure of internal network topology information, such as the number of first FL clients participating in this federated learning, thereby improving the overall security of the system.

[0138] In some embodiments, when the first network device is a proxy and the second network device is the FL client, the response to the first request message includes:

[0139] The second network device performs federated learning.

[0140] The second network device performing federated learning signifies that the FL client has responded to the first request message. For example, if the first request message is for sample alignment, the FL client responds by providing its own samples. If the first request message is for initial model alignment, the FL client responds by providing its own initial model. If the first request message is for federated training, the FL client responds by providing intermediate training parameters.

[0141] In some embodiments, when the first network device is an FL server and the second network device is a proxy, the second network device responds to the first request message by including:

[0142] The second network device sends a second request message to the first FL client, the second request message being used for federated learning.

[0143] In some embodiments, when the first network device is an FL server and the second network device is a proxy, the identifier of the first FL client indicates N FL clients, where N is an integer greater than 1. The second network device responds to the first request message by including:

[0144] The second network device sends N second request messages to each of the N FL clients, and the second request messages are used for federated learning.

[0145] This application also provides an authorization method for federal members, as shown in Figure 5, including:

[0146] Step 401: The agent sends a discovery request message to the Network Storage Function (NRF), which requests to find FL clients capable of performing federated learning (FL).

[0147] Step 402: The agent receives the discovery response message returned by the NRF, the discovery response message including the original identifier of the second FL client;

[0148] Step 403: The agent anonymizes the original identifier of the second FL client to obtain a temporary identifier for the second FL client, wherein the number of temporary identifiers is greater than the number of original identifiers;

[0149] Step 404: The agent sends the temporary identifier of the second FL client to the FL server.

[0150] In this embodiment, the original identifier of the second FL client is anonymized to obtain a temporary identifier for the second FL client. The number of temporary identifiers is different from the number of original identifiers. The temporary identifiers of the second FL client are then sent to the FL server. This can prevent the topology information of the internal network from being exposed, such as the number of second FL clients participating in this federated learning, thereby improving the overall security of the system.

[0151] In some embodiments, the anonymization of the original identifier of the second FL client by the agent includes:

[0152] The agent maps the original identifier of the second FL client to at least one temporary identifier and saves the first mapping relationship between the temporary identifier and the original identifier of the second FL client.

[0153] In some embodiments, the method further includes:

[0154] The agent receives a second request message from the FL server, the second request message being used for federated learning, the second request message including the identifier of the FL server and a temporary identifier of the second FL client;

[0155] The agent converts the temporary identifier in the second request message into the original identifier of the second FL client according to the first mapping relationship;

[0156] The agent sends a third request message to the second FL client, the third request message being used for federated learning.

[0157] In some embodiments, the method further includes:

[0158] A second mapping relationship is maintained between the identifier of the FL server and the original identifier or the temporary identifier of the second FL client.

[0159] In some embodiments, the method further includes:

[0160] The agent verifies whether the FL server can access the second FL client based on the second mapping relationship. This provides an additional verification of whether the FL server can access the second FL client, improving the overall system security.

[0161] The following description, in conjunction with the accompanying drawings, details the federal member authorization method provided in this application through some embodiments and application scenarios.

[0162] Example 1

[0163] In this embodiment, the NWDAF located within 3GPP is the Vertical Federated Learning (VFL) server, i.e., the aforementioned FL server, while the AF located outside 3GPP is the VFL client, i.e., the aforementioned FL client. NEF acts as an agent, registering information for the AF. After the FL Server obtains the access token, NEF verifies the token on behalf of the FL client. As shown in Figure 6, this embodiment includes the following steps:

[0164] Step 1: NEF sends first information to NRF. The first information includes NEF identifier (ID), at least one AF ID(s), and the authorization information corresponding to the AF.

[0165] The first piece of information can be a registration message, requesting the registration of AF's relevant capability information, such as registering AF's relevant capability information via the Nnrf_NFManagement_NFRegister Request message. Alternatively, the first piece of information can be used to update the NEF's context information, such as updating the NEF's context information via messages like Nnrf_NFManagement_NFUpdate Request. In this step, the NEF registers with the NRF in place of the AF.

[0166] The AF ID in the first piece of information can be an ID that directly identifies the AF, such as an application identifier; the AF ID can also be an ID that indirectly identifies the AF, and NEF can address the AF through the AF ID. For example, the AF ID can be an ID that NEF has anonymized, such as a session ID, event ID, etc.

[0167] In this embodiment, if the AF ID in the first information is an ID that indirectly identifies the AF, then the real ID of the AF can be hidden from the NWDAF, thereby improving the overall security of the system.

[0168] The authorization information corresponding to AF is used to indicate information that can identify the federal group, and may include at least one of the following:

[0169] (1) Analytics ID;

[0170] (2) Vendor ID;

[0171] (3) Interoperability indicator, which can be a list of vendor IDs;

[0172] (4) Alliance identifier (used to indicate a federation group).

[0173] The above information can be described with reference to Figure 1.

[0174] Step 2: The NRF receives the first message from the NEF, saves the relevant authorization information, and sends back a response message. For example, the response message could be an Nnrf_NFManagement_NFRegister response, an Nnrf_NFManagement_NFUpdate response, etc.

[0175] Step 3: NWDAF sends a discovery request message to NRF to request the search for AF network elements that can be used for vertical federated learning; for example, the discovery request message can be an Nnrf_NFDiscovery_Request service message.

[0176] Step 4: The NRF searches for AFs that can perform vertical federated learning with the NWDAF based on the discovery request message. AFs can be searched according to business needs and capability information. For example, AF ID1 and AF ID2 under NEF1 are found to meet the requirements.

[0177] Step 5: NRF sends a discovery response message to NWDAF. The discovery response message contains NEF ID1 and its corresponding AF ID1 and AF ID2.

[0178] Step 6: Before NWDAF initiates communication with AF1 or AF2, NWDAF sends a token request message to NRF, which can be done in the following two ways:

[0179] Method 1: NWDAF sends a token request message to NRF, which requests an authorization token. This token request message contains the NWDAF ID, NEF ID1, AF ID1, AF ID2, and NWDAF verification information.

[0180] Method 2: The NWDAF sends multiple token request messages to the NRF. Each token request message is for an AF and includes the NWDAF ID, NEF ID1, the AF ID it is targeting, and the NWDAF's verification information.

[0181] NWDAF's authentication information is used to indicate information that NWDAF uses for authorization detection. For example, it may be the NWDAF's Network Function Instance (NF instance) ID, the analytics ID to be executed, the vendor ID, interoperability indication, alliance identifier, etc.

[0182] In this embodiment, the token request message can be a token request.

[0183] Step 7: The NRF determines whether to authorize the NWDAF to access the AF based on the token request message.

[0184] Specifically, NRF can determine whether to authorize NWDAF to access AF based on one or more of the following:

[0185] (1) Does the AF ID correspond to the NEF ID?

[0186] (2) Whether the verification information of NWDAF matches the authorization information of AF.

[0187] When determining whether the verification information of NWDAF matches the authorization information of AF, at least one of the following can be used for judgment:

[0188] ① If the verification information is the NWDAF analytics ID, NRF determines whether the NWDAF analytics ID belongs to the analytics IDs supported by AF;

[0189] ② If the verification information is the vendor ID of the NWDAF, the NRF determines whether the vendor ID of the NWDAF belongs to a subset of the interoperability indications of the AF; optionally, the NRF also determines whether the interoperability indications of the AFs contain each other.

[0190] ③ If the verification information is an interoperability indication of NWDAF, NRF determines whether the interoperability indication of NWDAF belongs to a subset or the entire set of interoperability indications of AF.

[0191] ④ If the verification information is the NWDAF alliance identifier, NRF determines whether the NWDAF alliance identifier is consistent with the AF alliance identifier.

[0192] If the verification information in the token request message is the NWDAF's NF instance ID, NRF can obtain the NWDAF's analytics ID, vendor ID, interoperability indication, alliance identifier, etc. based on that ID.

[0193] After determining whether NWDAF is authorized to access AF, NRF generates a token, where...

[0194] For step 6, method one: The NRF generates only one token, which contains multiple AF IDs. Optionally, the token also contains an NWDAF ID and an analytics ID. In this way, the NWDAF only requests one token from the NRF. By writing more authorization information at once, the existing token can be reused in subsequent requests as much as possible, thereby reducing the signaling interactions of multiple token requests and saving communication resources.

[0195] For step 6, method two: The NRF generates a token for each token request message, and each token contains one AF ID. Optionally, the token also contains an NWDAF ID and an analytics ID. In this way, the NRF determines the authorization and verification information of federation members, thereby filtering out the set of AF IDs accessible to the NWDAF and their associated analytics IDs, and writes them into a token with integrity protection, so that the authorization information is carried in the token and notified to the NEF.

[0196] Step 8: NRF sends a token response message to NWDAF, which contains a token.

[0197] Step 9: NWDAF sends a first request message to NEF. This first request message requests vertical federated operations, which may include initial model alignment, sample alignment, and federated training. Specifically, the first request message can be sent in the following two ways:

[0198] Method 1: Send a first request message containing the NWDAF ID, multiple AF IDs, analytics ID, and a token.

[0199] Method 2: Send multiple first request messages, each targeting an AF, including NWDAF ID, AF ID, analytics ID, and the corresponding token.

[0200] Step 10: NEF verifies whether NWDAF is allowed to access AF.

[0201] Specifically, NEF makes the following judgments:

[0202] First, verify the integrity of the token. If the integrity verification passes, determine whether to allow NWDAF to access AF based on at least one of the following:

[0203] (1) Verify whether one or more AF IDs contained in the first request message are included in the token. In this embodiment, the NEF determines whether the NWDAF has the right to access the AF by judging the AF ID carried in the token, thereby preventing unauthorized NWDAF from accessing AFs that are not in the same federation group by using a coarse-grained token.

[0204] (2) Verify whether the NWDAF ID contained in the first request message is included in the token.

[0205] (3) Verify whether the analytics ID contained in the first request message is included in the token. In this embodiment, the NEF determines whether the NWDAF has the permission to call analytics by judging the analytics ID carried in the token, thereby preventing an unauthorized NWDAF from accessing an analytics service on an AF that should not be authorized by using a coarse-grained token.

[0206] Step 11: NEF sends a second request message to AF1 and AF2 respectively. The second request message is used to request vertical federation operation.

[0207] The NEF can send a second request message to AF1. Optionally, the second request message includes the NWDAF ID and the AF1 ID; the NEF can also send a second request message to AF2, which includes the NWDAF ID and the AF2 ID.

[0208] Example 2

[0209] In this embodiment, the NWDAF located within 3GPP is the VFL client, i.e., the aforementioned FL client, and the AF located outside 3GPP is the VFL server, i.e., the aforementioned FL server, with NEF acting as a proxy. After NEF obtains the token on behalf of the VFL Server, the NWDAF verifies the token. As shown in Figure 7, this embodiment includes the following steps:

[0210] Step 1: The NWDAF sends first information to the NRF. This first information includes the NWDAF ID(s) and the corresponding authorization information for the NWDAF. This first information can be a registration message requesting the registration of the NWDAF's relevant capabilities, such as registering the NWDAF's capabilities via the Nnrf_NFManagement_NFRegister Request message. In this step, the NWDAF registers itself with the NRF.

[0211] The authorization information corresponding to NWDAF is used to indicate information that can identify a federal group and may include at least one of the following:

[0212] (1) Analytics ID;

[0213] (2) Vendor ID;

[0214] (3) Interoperability indicator, which can be a list of vendor IDs;

[0215] (4) Alliance identifier (used to indicate a federation group).

[0216] Step 2: The NRF receives the first message from the NWDAF, saves the relevant authorization information, and sends back a response message. For example, the response message could be an Nnrf_NFManagement_NFRegister response.

[0217] Step 3: The AF sends a discovery request message to the NEF to request the search for NWDAF network elements that can be used for vertical federated learning; for example, the discovery request message can be a Discovery Request.

[0218] Step 4: NEF sends a discovery request message to NRF to request the search for NWDAF network elements that can be used for vertical federated learning; for example, the discovery request message can be Nnrf_NFDiscovery_Request service.

[0219] Step 5: The NRF searches for NWDAFs that can perform vertical federated learning with the AF based on the discovery request message. The search can be based on business needs and capability information. For example, NWDAF ID1 and NWDAF ID2 are found to meet the requirements.

[0220] Step 6: The NRF sends a discovery response message to the NEF. The discovery message contains information about the NWDAFs found that can be used for vertical federated learning with the AF. For example, the discovery response message may contain NWDAF ID1 and NWDAF ID2.

[0221] Step 7: Optionally, NEF anonymizes the NWDAF ID.

[0222] Specifically, NEF can map an NWDAF ID to multiple temporary IDs, such as session ID and event ID, and save the mapping relationship between the NWDAF ID and the temporary IDs.

[0223] Optionally, NEF also stores the mapping relationship between AF ID and NWDAF ID or temporary ID.

[0224] For example, if NEF maps NWDAF ID1 of an accessible AF to session ID1 and session ID2, and maps NWDAF ID2 of an accessible AF to session ID3 and session ID4, then the mapping relationship can be represented as AF ID1:NWDAF ID1:session ID1, session ID2; AF ID1:NWDAF ID2:session ID3, session ID4.

[0225] In this embodiment, the NEF is used to perform one-to-many mapping of the IDs of internal network element NWDAFs, which can prevent the topology information of the internal network from being exposed, such as the number of NWDAFs participating in this federated learning, thereby improving the overall security of the system.

[0226] Step 8: NEF sends a discovery response message to AF, which contains the NWDAF ID or a temporary ID.

[0227] Step 9: AF sends a second request message to NEF. This second request message requests vertical federated operations, which may include initial model alignment, sample alignment, and federated training. Specifically, the second request message can be sent in the following two ways:

[0228] Method 1: Send a second request message containing multiple temporary IDs and analytics IDs.

[0229] Method 2: Send multiple second request messages, each targeting a temporary ID and containing the temporary ID and analytics ID.

[0230] Step 10: Optionally, after receiving the second request message, NEF converts the temporary ID into an NWDAF ID.

[0231] Specifically, NEF converts the temporary ID back to the NWDAF ID based on the saved mapping relationship.

[0232] Optionally, NEF may additionally verify whether the AF can access the NWDAF based on the AF ID and the saved mapping relationship.

[0233] Step 11: NEF sends a token request message to NRF, which can be done in two ways:

[0234] Method 1: NEF sends a token request message to NRF, which requests an authorization token. This token request message contains NEF ID1, AF ID1, NWDAF ID1, NWDAF ID2, and AF verification information.

[0235] Method 2: NEF sends multiple token request messages to NRF. Each token request message is for an NWDAF and contains NEF ID1, AF ID, NWDAF ID and AF verification information.

[0236] The AF's verification information is used to indicate the AF's information and can be used for authorization detection. For example, it can be the AF's NF instance ID, the analytics ID to be executed, the vendor ID, interoperability indication, alliance identifier, etc.

[0237] In this embodiment, the token request message can be a token request.

[0238] Step 12: The NRF determines whether to authorize the NEF to access the NWDAF based on the token request message.

[0239] Specifically, NRF can determine whether to authorize NEF access to NWDAF based on one or more of the following:

[0240] Does the AF's verification information match the NWDAF's authorization information?

[0241] When determining whether the verification information of the AF matches the authorization information of the NWDAF, the determination can be made based on at least one of the following:

[0242] ① If the verification information is the analytics ID of the AF, the NRF determines whether the analytics ID of the AF belongs to the analytics ID supported by the NWDAF; optionally, the NRF also determines whether the interoperability indicators of the NWDAF are mutually inclusive.

[0243] ② If the verification information is the vendor ID of the AF, the NRF determines whether the vendor ID of the AF belongs to a subset of the interoperability indications of the NWDAF;

[0244] ③ If the verification information is an interoperability indication of AF, NRF determines whether the interoperability indication of AF belongs to a subset or the entire set of interoperability indications of NWDAF.

[0245] ④ If the verification information is the association identifier of AF, NRF determines whether the association identifier of AF is consistent with the association identifier of NWDAF.

[0246] If the verification information in the token request message is the NF instance ID of the AF, the NRF can obtain the AF's analytics ID, vendor ID, interoperability indication, and federation identifier based on that ID.

[0247] After determining whether NRF is authorized to access NWDAF, NRF generates a token, in which...

[0248] For step 11, method one: The NRF generates only one token, which contains multiple NWDAF IDs. Optionally, it also includes a NEF ID and an analytics ID. In this way, the NEF only requests one token from the NRF. By writing more authorization information at once, the existing token can be reused in subsequent requests as much as possible, thereby reducing the signaling interactions of multiple token requests and saving communication resources.

[0249] For step 11, method two: The NRF generates a token for each token request message, and each token contains one NWDAF ID. Optionally, it also contains a NEF ID and an analytics ID. In this way, the NRF determines the authorization and verification information of federated group members, thereby filtering out the set of NWDAF IDs accessible to the AF and their associated analytics IDs, and writing them into a token with integrity protection, so that the authorization information is carried in the token and notified to the NWDAF.

[0250] Step 13: NRF sends a token response message to NEF, which contains a token.

[0251] It should be noted that steps 11-13 can also be performed after step 6 to improve efficiency.

[0252] Step 14: NEF sends a third request message to NWDAF1 and NWDAF2 respectively. The third request message is used to request vertical federation operations. The third request message may contain the analytics ID, NEF ID, NWDAF ID, and token.

[0253] Step 15: NWDAF verifies whether NEF access is allowed.

[0254] Specifically, NWDAF makes the following judgments:

[0255] First, verify the integrity of the token. If the integrity verification passes, determine whether NEF access is allowed based on at least one of the following:

[0256] (1) Verify whether its own NWDAF ID is contained in the token. In this embodiment, by judging the NWDAF ID carried in the token through NWDAF, it can be determined whether the NEF has the right to access the NWDAF, thereby preventing unauthorized NEF from accessing the NWDAF that is not in the same federation group by using a coarse-grained token.

[0257] (2) Verify whether the NEF ID contained in the third request message is included in the token.

[0258] (3) Verify whether the analytics ID contained in the third request message is included in the token. In this embodiment, by determining the analytics ID carried in the token through NWDAF, it can be determined whether the NEF has the permission to call analytics, thereby preventing an unauthorized NEF from accessing an analytics service on the NWDAF that should not be authorized to be accessed by using a coarse-grained token.

[0259] The authorization method for federal members provided in this application can be executed by a virtual device. This application uses a virtual device to execute the authorization method for federal members as an example to illustrate the device for authorization of federal members provided in this application.

[0260] This application provides an authorization device for a federal member. As an example, the authorization device for a federal member can be a communication device or a component within a communication device, such as a chip. The communication device can be a terminal, a network-side device, or a server, etc. Exemplarily, the terminal can be, but is not limited to, the type of terminal 11 listed above, and the network-side device can be, but is not limited to, the type of network-side device 12 listed above. This application does not impose specific limitations.

[0261] The authorized device of a federal member includes a receiving module, a transmitting module, and a processing module. These modules can be implemented in software or hardware. When implemented in hardware, the processing module can be implemented by a processor. For example, the processor can include general-purpose processors, special-purpose processors, such as a Central Processing Unit (CPU), microprocessor, Digital Signal Processor (DSP), Artificial Intelligence (AI) processor, Graphics Processing Unit (GPU), Application Specific Integrated Circuit (ASIC), Network Processor (NP), Field Programmable Gate Array (FPGA), or other programmable logic devices, gate circuits, transistors, discrete hardware components, etc. The receiving and transmitting modules can be implemented by a communication interface, which can include one or more of the following: transceiver, pins, circuits, bus, radio frequency unit, etc.

[0262] Referring to Figure 8, when the authorized device of a federal member is an NRF, the authorized device of the federal member includes:

[0263] The first receiving module 11 is used to receive a token request message from the first network device. The token request message includes the identifier of the federated learning FL server, the identifier of the agent, and the identifier of the first FL client. The identifier of the first FL client indicates one or more FL clients.

[0264] The first sending module 12 is configured to send an access token to the first network device when the NRF determines, based on the token request message, that the FL server can access the first FL client, the access token including the identifier of the first FL client.

[0265] In some embodiments, the first receiving module 11 is used to receive and save the first information of the second network device, the first information including the identifier of the first FL client and the authorization information corresponding to the first FL client;

[0266] The first sending module 12 is used to determine, based on the token request message and the first information, that the FL server can access the first FL client.

[0267] In some embodiments, the authorization information is used to indicate information that can identify a federal group, including at least one of the following:

[0268] The analysis identifier of the first FL client;

[0269] The device vendor identifier of the first FL client;

[0270] Interoperability indication for the first FL client;

[0271] The alliance identifier of the first FL client.

[0272] In some embodiments, when the first network device is the FL server, the second network device is the agent;

[0273] In the case where the first network device is the agent, the second network device is the FL client.

[0274] In some embodiments, the token request message further includes verification information, which includes at least one of the following: network function instance identifier, analysis identifier, equipment vendor identifier, interoperability indicator, and alliance identifier;

[0275] The first sending module 12 is specifically used to determine whether the verification information matches the authorization information based on the verification information and the first information.

[0276] In some embodiments, the NRF determines whether the verification information matches the authorization information based on the verification information and the first information, including at least one of the following:

[0277] Determine that the analysis identifier in the verification information belongs to the analysis identifiers supported by the first FL client;

[0278] Determine that the equipment vendor identifier in the verification information belongs to a subset of the interoperability indications supported by the first FL client;

[0279] Determine whether the interoperability indication in the verification information belongs to a subset or the entire set of interoperability indications of the first FL client;

[0280] The alliance identifier in the verification information is determined to be consistent with the alliance identifier of the first FL client.

[0281] In some embodiments, where the verification information includes only the network function instance identifier, the apparatus further includes:

[0282] The acquisition module is used to acquire at least one of the analysis identifier, the equipment vendor identifier, the interoperability indication, and the alliance identifier based on the network function instance identifier.

[0283] In some embodiments, the access token also includes the analytics identifier.

[0284] In some embodiments, the access token also includes the identifier of the FL server.

[0285] In some embodiments, the first receiving module 11 is configured to receive a discovery request message from the first network device, the discovery request message requesting the search for FL clients capable of performing federated learning;

[0286] The first sending module 12 is used to return a discovery response message to the first network device, the discovery response message including the identifier of the first FL client.

[0287] In some embodiments, the identifier of the first FL client in the first information is an anonymous identifier.

[0288] Referring to Figure 9, when the authorized device of a federation member is the first network device, the authorized device of the federation member includes:

[0289] The second sending module 21 is used to send a token request message to the Network Storage Function (NRF). The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client. The identifier of the first FL client indicates one or more FL clients.

[0290] The second receiving module 22 is used to receive the access token returned by the NRF, the access token including the identifier of the first FL client;

[0291] The third sending module 23 is used to send a first request message to the second network device. The first request message is used for federated learning and includes the identifier of the first network device, the identifier of the first FL client, and the access token.

[0292] In some embodiments, when the first network device is the FL server, the second network device is the agent;

[0293] In the case where the first network device is the agent, the second network device is the FL client.

[0294] In some embodiments, the token request message further includes verification information, which includes at least one of the following: network function instance identifier, analysis identifier, equipment vendor identifier, interoperability instruction, and alliance identifier.

[0295] In some embodiments, the access token also includes the analytics identifier.

[0296] In some embodiments, the access token also includes the identifier of the FL server.

[0297] In some embodiments, the second sending module 21 is used to send a discovery request message to the NRF, requesting to find FL clients capable of performing federated learning;

[0298] The second receiving module 22 is used to receive the discovery response message returned by the NRF, the discovery response message including the identifier of the first FL client.

[0299] Referring to Figure 10, when the authorized device of a federal member is a second network device, the authorized device of the federal member includes:

[0300] The third receiving module 31 is used to receive a first request message sent by the first network device. The first request message is for federated learning (FL). The first request message includes the identifier of the first network device, the identifier of the first FL client, and an access token. The access token includes the identifier of the first FL client, and the identifier of the first FL client indicates one or more FL clients.

[0301] The first processing module 32 is used to verify the access token and respond to the first request message after the verification is successful.

[0302] In some embodiments, the first processing module 32 is specifically used to verify the integrity of the access token; after the integrity verification of the access token passes, it determines whether to allow the first network device to access the first FL client based on at least one of the following:

[0303] Verify whether the identifier of the first FL client is included in the access token;

[0304] Verify whether the identifier of the first network device in the first request message is included in the access token;

[0305] Verify whether the analysis identifier in the first request message is included in the access token.

[0306] In some embodiments, the apparatus further includes:

[0307] The sending module is used to send first information to the Network Storage Function (NRF), the first information including the identifier of the first FL client and the authorization information corresponding to the first FL client.

[0308] In some embodiments, the first processing module 32 is used to anonymize the original identifier of the first FL client to obtain a temporary identifier of the first FL client, and the identifier of the first FL client in the first information is the temporary identifier.

[0309] In some embodiments, when the first network device is an agent and the second network device is the FL client, the first processing module 32 is used to perform federated learning.

[0310] In some embodiments, when the first network device is an FL server and the second network device is an agent, the first processing module 32 is used to send a second request message to the first FL client, the second request message being used for federated learning.

[0311] In some embodiments, when the first network device is an FL server and the second network device is an agent, the identifier of the first FL client indicates N FL clients, where N is an integer greater than 1. The first processing module 32 is used to send N second request messages to the N FL clients respectively, and the second request messages are used for federated learning.

[0312] Referring to Figure 11, when the authorized device of a Federation member is an agent, the authorized device of the Federation member includes:

[0313] The fourth sending module 41 is used to send a discovery request message to the Network Storage Function (NRF), the discovery request message requesting to find FL clients capable of performing federated learning (FL);

[0314] The fourth receiving module 42 is used to receive the discovery response message returned by the NRF, the discovery response message including the original identifier of the second FL client;

[0315] The second processing module 43 is used to anonymize the original identifier of the second FL client to obtain a temporary identifier of the second FL client, wherein the number of temporary identifiers is greater than the number of original identifiers;

[0316] The fifth sending module 44 is used to send the temporary identifier of the second FL client to the FL server.

[0317] In some embodiments, the second processing module 43 is specifically used to map the original identifier of the second FL client to at least one temporary identifier, and save the first mapping relationship between the temporary identifier and the original identifier of the second FL client.

[0318] In some embodiments, the fourth receiving module 42 is specifically used to receive a second request message from the FL server, the second request message being used for federated learning, and the second request message including the identifier of the FL server and the temporary identifier of the second FL client;

[0319] The second processing module 43 is specifically used to convert the temporary identifier in the second request message into the original identifier of the second FL client according to the first mapping relationship;

[0320] The fifth sending module 44 is specifically used to send a third request message to the second FL client, the third request message being used for federated learning.

[0321] In some embodiments, the second processing module 43 is further configured to store a second mapping relationship between the identifier of the FL server and the original identifier or the temporary identifier of the second FL client.

[0322] In some embodiments, the second processing module 43 is further configured to verify whether the FL server can access the second FL client based on the second mapping relationship.

[0323] The apparatus provided in this application embodiment can implement the various processes implemented in the above method embodiment and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0324] As shown in Figure 12, this application embodiment also provides a communication device 60, including a processor 61 and a memory 62. The memory 62 stores a program or instructions that can run on the processor 61. When the communication device 60 is a network-side device, the program or instructions executed by the processor 61 implement the various steps of the above method embodiments and achieve the same technical effect. To avoid repetition, further details are omitted here.

[0325] This application also provides a network-side device, including a processor and a communication interface. The communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the steps of the method embodiments described above. This network-side device embodiment corresponds to the above-described network-side device method embodiments. All implementation processes and methods of the above-described method embodiments can be applied to this network-side device embodiment and achieve the same technical effects.

[0326] Specifically, this application also provides a network-side device. As shown in FIG13, the network-side device 70 includes a processor 71, a network interface 72, and a memory 73. This network-side device can be an authorized device of the aforementioned federal member. The network interface 72 is, for example, a Common Public Radio Interface (CPRI).

[0327] Specifically, the network-side device 70 in this application embodiment further includes: instructions or programs stored in memory 73 and executable on processor 71. Processor 71 calls the instructions or programs in memory 73 to execute the methods executed by the modules shown in Figures 8-11 and achieve the same technical effect. To avoid repetition, it will not be described in detail here.

[0328] This application also provides a readable storage medium storing a program or instructions that, when executed by a processor, implement the various processes of the above-described authorized method embodiments of the federation members and achieve the same technical effects. To avoid repetition, these will not be described again here.

[0329] The processor mentioned above is the processor in the terminal described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk. In some examples, the readable storage medium may be a non-transient readable storage medium.

[0330] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described authorized method embodiments of the federation members and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0331] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0332] This application also provides a computer program / program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the above-described authorized method embodiments of the federation members, and can achieve the same technical effects. To avoid repetition, it will not be described again here.

[0333] This application also provides a wireless communication system, including a terminal and a network-side device, wherein the network-side device can be used to perform the steps of the authorization method for federal members as described above.

[0334] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0335] From the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of computer software products plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disk, optical disk, etc.) and includes several instructions to cause the terminal or network-side device to execute the methods described in the various embodiments of this application.

[0336] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other implementations under the guidance of this application without departing from the spirit and scope of the claims. All of these implementations are within the protection scope of this application.

Claims

1. A method of authorization for federal members, comprising: The Network Storage Function (NRF) receives a token request message from a first network device. The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client, wherein the identifier of the first FL client indicates one or more FL clients. If the NRF determines, based on the token request message, that the FL server can access the first FL client, it sends an access token to the first network device, the access token including the identifier of the first FL client.

2. The method according to claim 1, further comprising: The NRF receives and saves the first information of the second network device, the first information including the identifier of the first FL client and the authorization information corresponding to the first FL client; The NRF determines that the FL server can access the first FL client based on the token request message, including: The NRF determines, based on the token request message and the first information, that the FL server can access the first FL client.

3. The method of claim 2, wherein, The authorization information includes at least one of the following: The analysis identifier of the first FL client; The device vendor identifier of the first FL client; Interoperability indication for the first FL client; The alliance identifier of the first FL client.

4. The method according to any one of claims 2-3, wherein, In the case where the first network device is the FL server, the second network device is the agent; In the case where the first network device is the agent, the second network device is the FL client.

5. The method of any one of claims 2 to 4, wherein, The token request message also includes verification information, which includes at least one of the following: network function instance identifier, analysis identifier, equipment vendor identifier, interoperability instruction, and alliance identifier; The NRF determines that the FL server can access the first FL client based on the token request message and the first information, including: The NRF determines whether the verification information matches the authorization information based on the verification information and the first information.

6. The method of claim 5, wherein, The NRF determines whether the verification information matches the authorization information based on the verification information and the first information, including at least one of the following: Determine that the analysis identifier in the verification information belongs to the analysis identifiers supported by the first FL client; Determine that the equipment vendor identifier in the verification information belongs to a subset of the interoperability indications supported by the first FL client; Determine whether the interoperability indication in the verification information belongs to a subset or the entire set of interoperability indications of the first FL client; The alliance identifier in the verification information is determined to be consistent with the alliance identifier of the first FL client.

7. The method of claim 6, wherein, When the verification information only includes the network function instance identifier, before the NRF determines whether the verification information matches the authorization information based on the verification information and the first information, the method further includes: The NRF obtains at least one of the analysis identifier, the equipment vendor identifier, the interoperability indication, and the alliance identifier based on the network function instance identifier.

8. The method of any one of claims 5-7, wherein, The access token also includes the analytics identifier.

9. The method of any one of claims 1-8, wherein, The access token also includes the identifier of the FL server.

10. The method of any one of claims 1-9, wherein, Before the NRF receives the token request message from the first network device, the method further includes: The NRF receives a discovery request message from the first network device, the discovery request message requesting to find FL clients capable of performing federated learning; The NRF returns a discovery response message to the first network device, the discovery response message including the identifier of the first FL client.

11. The method of claim 2, wherein, The identifier of the first FL client in the first information is an anonymous identifier.

12. A method of authorization for federal members, comprising: The first network device sends a token request message to the Network Storage Function (NRF). The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client, wherein the identifier of the first FL client indicates one or more FL clients. The first network device receives an access token returned by the NRF, the access token including the identifier of the first FL client; The first network device sends a first request message to the second network device. The first request message is used for federated learning and includes the identifier of the first network device, the identifier of the first FL client, and the access token.

13. The method of claim 12, wherein, In the case where the first network device is the FL server, the second network device is the agent; In the case where the first network device is the agent, the second network device is the FL client.

14. The method of claim 12 or 13, wherein, The token request message also includes verification information, which includes at least one of the following: network function instance identifier, analysis identifier, equipment vendor identifier, interoperability instruction, and alliance identifier.

15. The method of claim 14, wherein, The access token also includes the analytics identifier.

16. The method according to any one of claims 12 to 15, wherein, The access token also includes the identifier of the FL server.

17. The method of any one of claims 12-16, wherein, Before the first network device sends a token request message to the NRF, the method further includes: The first network device sends a discovery request message to the NRF, requesting to find FL clients capable of performing federated learning; The first network device receives a discovery response message returned by the NRF, the discovery response message including the identifier of the first FL client.

18. A method of authorization for federal members, comprising: The second network device receives a first request message sent by the first network device. The first request message is for federated learning (FL). The first request message includes the identifier of the first network device, the identifier of the first FL client, and an access token. The access token includes the identifier of the first FL client, and the identifier of the first FL client indicates one or more FL clients. The second network device verifies the access token, and responds to the first request message after the verification is successful.

19. The method of claim 18, wherein, The verification of the access token includes: Verify the integrity of the access token; After the access token integrity verification is successful, determine whether to allow the first network device to access the first FL client based on at least one of the following: Verify whether the identifier of the first FL client is included in the access token; Verify whether the identifier of the first network device in the first request message is included in the access token; Verify whether the analysis identifier in the first request message is included in the access token.

20. The method of claim 18 or 19, wherein, Before the second network device receives the first request message from the first network device, the method further includes: The second network device sends first information to the Network Storage Function (NRF), the first information including the identifier of the first FL client and the authorization information corresponding to the first FL client.

21. The method of claim 20, wherein, Before the second network device sends the first information to the Network Storage Function (NRF), the method further includes: The second network device anonymizes the original identifier of the first FL client to obtain a temporary identifier for the first FL client, and the identifier of the first FL client in the first information is the temporary identifier.

22. The method of any one of claims 18-21, wherein, When the first network device is a proxy and the second network device is the FL client, the response to the first request message includes: The second network device performs federated learning.

23. The method of any one of claims 18-21, wherein, When the first network device is an FL server and the second network device is a proxy, the second network device responds to the first request message, including: The second network device sends a second request message to the first FL client, the second request message being used for federated learning.

24. The method of any one of claims 18-21, wherein, When the first network device is an FL server and the second network device is a proxy, the identifier of the first FL client indicates N FL clients, where N is an integer greater than 1. The second network device responds to the first request message, including: The second network device sends N second request messages to each of the N FL clients, and the second request messages are used for federated learning.

25. A method of authorization for federal members, comprising: The agent sends a discovery request message to the Network Storage Function (NRF), which requests the search for FL clients capable of performing federated learning (FL). The agent receives a discovery response message returned by the NRF, the discovery response message including the original identifier of the second FL client; The agent anonymizes the original identifier of the second FL client to obtain a temporary identifier for the second FL client, and the number of temporary identifiers is greater than the number of original identifiers; The agent sends a temporary identifier of the second FL client to the FL server.

26. The method of claim 25, wherein, The anonymization of the original identifier of the second FL client by the agent includes: The agent maps the original identifier of the second FL client to at least one temporary identifier and saves the first mapping relationship between the temporary identifier and the original identifier of the second FL client.

27. The method of claim 26, further comprising: The agent receives a second request message from the FL server, the second request message being used for federated learning, the second request message including the identifier of the FL server and a temporary identifier of the second FL client; The agent converts the temporary identifier in the second request message into the original identifier of the second FL client according to the first mapping relationship; The agent sends a third request message to the second FL client, the third request message being used for federated learning.

28. The method according to claim 26 or 27, further comprising: A second mapping relationship is maintained between the identifier of the FL server and the original identifier or the temporary identifier of the second FL client.

29. The method of claim 28, further comprising: The agent verifies whether the FL server can access the second FL client based on the second mapping relationship.

30. An authorization device for a federal member, comprising: The first receiving module is configured to receive a token request message from the first network device. The token request message includes the identifier of the federated learning FL server, the identifier of the agent, and the identifier of the first FL client. The identifier of the first FL client indicates one or more FL clients. A first sending module is configured to send an access token to the first network device when the NRF determines, based on the token request message, that the FL server can access the first FL client, the access token including the identifier of the first FL client.

31. The authorized device of a federal member of claim 30, wherein, The token request message also includes verification information, which includes at least one of the following: network function instance identifier, analysis identifier, equipment vendor identifier, interoperability instruction, and alliance identifier; The first sending module is specifically used to determine whether the verification information matches the authorization information based on the verification information and the first information.

32. An authorization device for a federal member, comprising: The second sending module is used to send a token request message to the Network Storage Function (NRF). The token request message includes the identifier of the Federated Learning (FL) server, the identifier of the agent, and the identifier of the first FL client, wherein the identifier of the first FL client indicates one or more FL clients. The second receiving module is used to receive the access token returned by the NRF, the access token including the identifier of the first FL client; The third sending module is used to send a first request message to the second network device. The first request message is used for federated learning and includes the identifier of the first network device, the identifier of the first FL client, and the access token.

33. The authorized device of a federal member of claim 32, wherein, The token request message also includes verification information, which includes at least one of the following: network function instance identifier, analysis identifier, equipment vendor identifier, interoperability instruction, and alliance identifier.

34. An authorization device for a federal member, comprising: The third receiving module is used to receive a first request message sent by the first network device. The first request message is for federated learning (FL). The first request message includes the identifier of the first network device, the identifier of the first FL client, and an access token. The access token includes the identifier of the first FL client, and the identifier of the first FL client indicates one or more FL clients. The first processing module is used to verify the access token and respond to the first request message after the verification is successful.

35. The authorization device for a federal member according to claim 34, wherein, The first processing module is specifically used to verify the integrity of the access token; after the integrity verification of the access token passes, it determines whether to allow the first network device to access the first FL client based on at least one of the following: Verify whether the identifier of the first FL client is included in the access token; Verify whether the identifier of the first network device in the first request message is included in the access token; Verify whether the analysis identifier in the first request message is included in the access token.

36. An authorization device for a federal member, comprising: The fourth sending module is used to send a discovery request message to the Network Storage Function (NRF), the discovery request message requesting the search for FL clients capable of performing federated learning (FL); The fourth receiving module is used to receive the discovery response message returned by the NRF, the discovery response message including the original identifier of the second FL client; The second processing module is used to anonymize the original identifier of the second FL client to obtain a temporary identifier of the second FL client, wherein the number of temporary identifiers is greater than the number of original identifiers; The fifth sending module is used to send the temporary identifier of the second FL client to the FL server.

37. The authorization device for a federal member according to claim 36, wherein, The second processing module is specifically used to map the original identifier of the second FL client to at least one temporary identifier, and save the first mapping relationship between the temporary identifier and the original identifier of the second FL client.

38. A network-side device comprising a processor and a memory, the memory storing a program or instructions executable on the processor, the program or instructions, when executed by the processor, implementing the steps of the authorization method of a federal member as claimed in any one of claims 1 to 29.

39. A readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the authorization method of a federal member as described in any one of claims 1-29.