Privacy preservation in UE data collection for artificial intelligence and machine learning

The integration of a DCAF in the 5G Core network with UE-based DDCC implements privacy-preserving techniques like anonymization and user consent management, addressing data exposure issues and ensuring regulatory compliance in UE data collection for AI/ML applications.

WO2026065055A1PCT designated stage Publication Date: 2026-04-02APPLE INC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing wireless communication systems lack sophisticated privacy preservation techniques for UE data collection, leading to inadvertent exposure of user data without adequate transformation, failing to meet varying data consumer needs and regulatory requirements.

Method used

Implementing a DCAF in the 5G Core network as a proxy for enforcing privacy-preserving techniques, such as data anonymization, aggregation, and randomization, and ensuring user consent management for UE data exposure, while facilitating data collection through a DDCC in the UE.

Benefits of technology

Ensures that UE data exposure meets local regulatory requirements and privacy levels are commensurate with the use-case needs of AI/ML applications, enhancing data security and compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024121516_02042026_PF_FP_ABST
    Figure CN2024121516_02042026_PF_FP_ABST
Patent Text Reader

Abstract

Systems and methods are provided for data collection in a wireless network. A user equipment (UE) performs, with an Access and Mobility Management Function (AMF) in the wireless network, a registration procedure to establish a session between a Direct Data Collection Client (DDCC) within the UE and a Data Collection Application Function (DCAF) in the wireless network. The UE receives, at the DDCC within the UE, a data collection and reporting configuration generated by the DCAF, wherein the data collection and reporting configuration comprises a privacy requirement. The UE collects data at the UE according to the data collection and reporting configuration. The UE processes the collected data, via the DDCC, by applying a privacy-preservation technique according to the privacy requirement within the data collection and reporting configuration. The UE transmits the processed data to the DCAF.
Need to check novelty before this filing date? Find Prior Art

Description

PRIVACY PRESERVATION IN UE DATA COLLECTION FOR ARTIFICIAL INTELLIGENCE AND MACHINE LEARNINGTECHNICAL FIELD

[0001] This application relates generally to wireless communication systems, including privacy preservation in UE data collection for Artificial Intelligence and / or Machine Learning) AIML.BACKGROUND

[0002] Wireless mobile communication technology uses various standards and protocols to transmit data between a base station and a wireless communication device. Wireless communication system standards and protocols can include, for example, 3rd Generation Partnership Project (3GPP) Long Term Evolution (LTE) (e.g., 4G) , 3GPP New Radio (NR) (e.g., 5G) , and Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard for Wireless Local Area Networks (WLAN) (commonly known to industry groups as  ) .

[0003] As contemplated by the 3GPP, different wireless communication systems' standards and protocols can use various radio access networks (RANs) for communicating between a base station of the RAN (which may also sometimes be referred to generally as a RAN node, a network node, or simply a node) and a wireless communication device known as a user equipment (UE) . 3GPP RANs can include, for example, Global System for Mobile communications (GSM) , Enhanced Data Rates for GSM Evolution (EDGE) RAN (GERAN) , Universal Terrestrial Radio Access Network (UTRAN) , Evolved Universal Terrestrial Radio Access Network (E-UTRAN) , and / or Next-Generation Radio Access Network (NG-RAN) .

[0004] Each RAN may use one or more radio access technologies (RATs) to perform communication between the base station and the UE. For example, the GERAN implements GSM and / or EDGE RAT, the UTRAN implements Universal Mobile Telecommunication System (UMTS) RAT or other 3GPP RAT, the E-UTRAN implements LTE RAT (sometimes simply referred to as LTE) , and NG-RAN implements NR RAT (sometimes referred to herein as 5G RAT, 5G NR RAT, or simply NR) . In certain deployments, the E-UTRAN may also implement NR RAT. In certain deployments, NG-RAN may also implement LTE RAT.

[0005] A base station used by a RAN may correspond to that RAN. One example of an E-UTRAN base station is an Evolved Universal Terrestrial Radio Access Network (E-UTRAN) Node B (also commonly denoted as evolved Node B, enhanced Node B, eNodeB, or eNB) . One example of an NG-RAN base station is a next generation Node B (also sometimes referred to as a g Node B or gNB) .

[0006] A RAN provides its communication services with external entities through its connection to a core network (CN) . For example, E-UTRAN may utilize an Evolved Packet Core (EPC) while NG-RAN may utilize a 5G Core Network (5GC) .

[0007] BRIEF DESCRIPTION OF THE SEVERAL VIEWS OF THE DRAWINGS

[0008] To easily identify the discussion of any particular element or act, the most significant digit or digits in a reference number refer to the figure number in which that element is first introduced.

[0009] FIG. 1 illustrates an example architecture for data collection and reporting within a wireless network, according to some embodiments disclosed herein.

[0010] FIG. 2 illustrates an exemplary schematic of a data collection client architecture in a UE, according to some embodiments disclosed herein.

[0011] FIG. 3 illustrates a data flow diagram of an example process for applying privacy preservation techniques to data collected within a RAN, according to some embodiments disclosed herein.

[0012] FIG. 4 illustrates a data flow diagram of an example process for UE session establishment for performing the example process of FIG. 3, according to some embodiments disclosed herein.

[0013] FIG. 5 illustrates a data flow diagram of an example process for managing UE data exposure during the example data collection process of FIG. 3, according to some embodiments disclosed herein.

[0014] FIG. 6 illustrates an example architecture of a wireless communication system, according to embodiments disclosed herein.

[0015] FIG. 7 illustrates a system for performing signaling between a wireless device and a network device, according to embodiments disclosed herein.DETAILED DESCRIPTION

[0016] Various embodiments are described with regard to a UE. However, reference to a UE is merely provided for illustrative purposes. The example embodiments may be utilized with any electronic component that may establish a connection to a network and is configured with the hardware, software, and / or firmware to exchange information and data with the network. Therefore, the UE as described herein is used to represent any appropriate electronic component.

[0017] Data collection and reporting for analytics.

[0018] In certain wireless systems, indirect and direct methods may be used for data collection. Indirect data collection refers to a method of gathering application layer data from the UE through an Application Service Provider and reporting it to a Data Collection Application Function (DCAF) (e.g., over an R3 interface) . Direct data collection refers to a method of collecting data directly from the UE, and sending the data to the DCAF (e.g., over the R2 interface) via a Direct Data Collection Client (DDCC) . The UE can be equipped with a DDCC (e.g., as a software component) , which can communicate with the DCAF or other network data collection and analytics function services (Ndcaf services) over the user plane. In some embodiments, the DCAF can be responsible for provisioning the reporting configuration, while the DDCC can manage the reporting of measurements.

[0019] FIG. 1 illustrates an example architecture for data collection and reporting within a wireless network, according to some embodiments disclosed herein. In the indirect data collection method, data can be collected from a UE 102 via an application service provider (ASP 106) . Collected data can then be reported to a data collection application function (DCAF 116) over the R3 interface via an indirect data collection client 110. Within the ASP 106, additional components such as a provisioning AF 108 and an event consumer AF 112 can facilitate communication with the DCAF 116. For example, in some cases, the provisioning AF 108 can communicate with the DCAF 116 over the R1 interface to manage provisioning of data collection configurations. Similarly, the event consumer AF 112 can communicate with the DCAF 116 over the R6 interface to receive or process event related data.

[0020] In the illustrated example, the UE 102 includes a UE Application 104 in communication with a DDCC 118 through an R7 interface. The UE Application 104 also communicates with the ASP 106 through an R8 interface. To execute a direct data collection method, the DDCC 118 can directly transfer data from the UE 102 to the  DCAF 116 over the R2 interface. As discussed further below, the DCAF 116 can communicate directly to the DCAF 116 over the user plane.

[0021] In some embodiments, the DCAF 116 can further communicate with several network functions to support the data collection and analysis. For example, in some cases, the DCAF 116 can communicate with a network repository function (e.g., NRF 114) that can help discover or register network functions. In some cases, the DCAF 116 can communicate to a network exposure function (e.g., Network Exposure Function (NEF 122) via the N33 interface) to expose network service and capabilities to external applications. In some cases, the DCAF 116 can communicate to the application server (e.g., Application Server (AS 124) via the R4 interface) to transmit application-related data. The DCAF 116 can also communicate with a network data analytics function (e.g., NWDAF 120 via the R5 interface) , which can handle further analysis on the collected data.

[0022] Data collection for RAN AIML operations

[0023] In certain wireless systems, the purpose of data collection can include, but is not limited, to facilitating functions such as artificial intelligence / machine learning model training, inference, model performance monitoring, model selection, and model updates. Latency requirements can vary according to purpose and function. For example, in some embodiments, for all types of offline model training (e.g., whether UE-based, network-based, or two-sided) , there is no latency requirement for data collection. In some embodiments related to inference, when data is obtained from other entities, a latency requirement can be imposed. Similarly, in embodiments related to real-time, performance monitoring, when monitoring data (e.g., performance metrics) is sourced from other entities, a latency requirement can be similarly imposed.

[0024] In some cases, it is assumed that analysis and / or selection of data collection frameworks focus on the RRC_CONNECTED state, for instance, for both data generation and reporting. Certain wireless systems support Downlink Positioning Reference Signal (DL PRS) measurement and UE positioning in both RRC_CONNECTED and RRC_INACTIVE states.

[0025] Consolidated requirements

[0026] In some cases, consolidated requirements for data collection and model transfer can be identified. Data collection can include control plane reporting that can be latency- sensitive and handle short (er) parcels of data, and user plane reporting that can be latency-tolerant and manage larger parcels of data.

[0027] For model transfer and delivery, latency-sensitive model updates (e.g., with a total size of less than 45 kB) can be transferred over the control plane and larger models can be transferred over the user plane using a PDTQ (Planned Data transfer with QoS) mechanism. Additional data collection and reporting can be under the control of a Mobile Network Operator (MNO) . In some embodiments, this can ensure compliance with data privacy regulatory requirements.

[0028] Gaps in the certain architectures

[0029] Certain network architectures may lack sophisticated privacy preservation techniques, which can inadvertently result in exposed UE data. Although exposure of any data can be guided by a user (e.g., through consent stored in the UDM) , collected data often forgoes any transformation, and can be generally exposed to application functions (AFs) .

[0030] In some cases, different AI / ML AFs can have varying needs of the UE data. For instance, in some embodiments, some may use only aggregated data (e.g., that prevents identification of individual UEs within a report) . Others may use only anonymized data (e.g., without any UE identifiers) . In some cases, still others, can accept the addition of random noise (e.g., to prevent granular exposure of sensitive information) .

[0031] Thus, existing approaches can fail to provide adequate, or any, mechanisms that allow data consumers to request a privacy level commensurate their use-case. Accordingly, a 5G Core (5GC) , as contemplated herein, can be able to enforce that data exposure meets local regulatory requirements.

[0032] Overall architecture

[0033] In certain embodiments, an architecture evolves the Data Collection AF (DCAF) and Direct Data Collection Client (DDCC) . However, in some embodiments, the architecture may also be implemented in Network Analytics Data Function (NWDAF) or implemented as new network functions (NFs) (e.g., AIML Data Management Function) in the 5G Core (5GC) .

[0034] The architecture can include a DCAF, located in the Core Network, which can be responsible for configuring and collecting data from UEs. The DCAF can thus provide a service to other AFs to request data collection and facilitate control plane data  transfer to a UE for short and latency-sensitive reporting. Additionally, a DCAF can act as a proxy for enforcing privacy-preserving techniques before the data is reported out of an operator's domain.

[0035] In addition, or in other embodiments, the DCAF can provide a service-based interface for all NFs to configure data collection and reporting for UEs, e.g., in some cases referred to as Ndcaf_DataReportingProvisioning. AFs or other 5GC NFs can therefor invoke DCAF services directly or through the Network Exposure Function (e.g., untrusted AFs) . The DCAF can utilize the Namf N1N2_MessageTransfer service to send messages to a UE, and thus support a control plane session with the UE.

[0036] Data collection client architecture in the UE

[0037] In certain embodiments, the network architecture includes a UE that has a functionality for data collection coordination, which can be facilitated by a DDCC. The DDCC can be responsible for receiving configuration instructions from the network regarding data collection and reporting requirements. In some embodiments, the DDCC initiates measurements or gathers reports from various sub-components within a modem. Collected data can then be carried in one of two ways: through a user plane for data collected for training or via SRB2 (Signaling Radio Bearer 2) for data for inference.

[0038] The interface between the DDCC and the modem can support services that include receiving the DCAF configuration from the network, requesting the establishment of a UE session with the DCAF through either the control plane or user plane, requesting measurements based on the received data reporting configuration, and / or reporting measurements back to the DCAF.

[0039] FIG. 2 illustrates an exemplary schematic of a data collection client architecture in a UE, according to some embodiments disclosed herein. In this example, the network architecture includes a UE 202 with functionality for coordinating data collection through a DDCC 204. As discussed, the DDCC 204 is responsible for receiving configuration instructions from the network regarding data collection and reporting requirements. The DDCC 204 can initiate measurements or gather reports from various sub-components within a Modem 206.

[0040] Privacy preservation in UE data collection

[0041] In some embodiments, the DCAF can act as a proxy for other NFs and / or AFs in the 5GC to trigger or initiate UE data collection. For example, a RAN including an AI or  ML function can require specific measurement data collection for operations like beam prediction. The DCAF can facilitate this data collection.

[0042] The DCAF can provide a service through which other NFs can request coordination for data collection from UEs. For example, in some embodiments, requests for coordinated data collection can include requests for details such as UE identifiers (e.g., identifying groups of UEs) or filter conditions, timeframe, data anonymization, data aggregation, and whether data collection should be control plane based, or user plane based. If specific UE identifiers are not provided by an NF, the DCAF can perform selection of member UEs. DCAF ensures that selected UEs have user consent to participate in data collection procedure.

[0043] To preserve privacy, the DCAF can apply one or more techniques such as data anonymization, which can involve removing UE identifiers from a reported results-performed by either the DCAF or the DDCC based on a configuration.

[0044] To perform data aggregation (e.g., in cases where data collection from multiple UEs is requested) , the DCAF can aggregate the results. For instance, in some embodiments, the DCAF can report only an aggregate value (s) to the AF without reference to contributing or individual UEs.

[0045] Additionally, randomization of reports from a UE can be configured. For instance, in some embodiments, when configured by the AF, the DDCC or DCAF can choose a random time within a configured time window to report results without including a UE identifier.

[0046] In some embodiments, random noise is generated and / or added to the data by DDCC or DCAF before reporting to the AF.

[0047] In some embodiments, the DCAF acts as a proxy for the UEs. For instance, when a specific UE identifier is not chosen by the NF and is not requested in the report, the DCAF can provide a proxied identifier for the UEs.

[0048] FIG. 3 illustrates a data flow diagram of an example process for applying privacy preservation techniques to data collected within a RAN, according to some embodiments disclosed herein. In the illustrated example, a DCAF 304 serves as a proxy for other NFs and AFs (e.g., AF 306) to trigger or initiate UE data collection. For example, in some embodiments, the AF 306 transmits a Ndcaf_DataReportingProvisioning 308 message, including requests from the AF. For instance, the Ndcaf_DataReportingProvisioning 308 message can include a request for  data such as: target UE IDs; UE filter information; privacy requirements such as TimeWindow for randomization, data anonymizations allowed, data aggregation allowed, and random noise allowed; reporting path preference such as control plane or user plane; and / or security parameters (e.g., as seen at 310) .

[0049] As seen at block 312, if only filtering conditions for UEs are provided (i.e., if specific UE IDs are not provided) , the DCAF 304 uses a Member UE Selection service to gather potential UE IDs (e.g., as seen at block 312) .

[0050] As seen at block 314, in some embodiments, the DCAF 304 selects the appropriate privacy technique to apply. In some embodiments, if data anonymization is set to allowed, the DCAF 304 configures whether a UE DDCC 302 is responsible or whether the DCAF 304 is responsible for applying the data anonymization privacy technique.

[0051] As seen at block 316, the DCAF 304 selects the appropriate path to reach the UE. If the session is established through control plane, the DCAF 304 uses the Namf-N1N2-MessageTransfer service to reach the UE.

[0052] The DCAF 304 then forwards a communication UE Reporting Configuration 318 to the UE DDCC 302.

[0053] As seen at block 320, in some embodiments, the UE DDCC 302 then collects reporting data as configured. For instance, in some embodiments, the UE DDCC 302 can apply data anonymization or random noise addition as required. If a time window for reporting is configured, the UE DDCC 302 can start a timer for randomization of the report transfer.

[0054] The UE DDCC 302 then reports the data to the DCAF 304 via communication UE reports 322.

[0055] At block 324, the DCAF 304 then performs any required privacy ensuring techniques and wait for reports from multiple UEs (e.g., if data aggregation is to be performed) . If configured to, the DCAF 304 can add random noise to UE reported data. If configured, the DCAF 304 can hide UE identities with a proxy identifier.

[0056] The DCAF 304 transmits the results of the data collection (e.g., Data Collection Results 328) to the AF 306 within a Ndcaf_DataReportingProvisioning 326 message.

[0057] UE establishing session to the DCAF.

[0058] As part of the registration procedure, the UE can indicate its capabilities for data collection and reporting for AIML operations. AIML capabilities can be reported as part of Non-Access Stratum Mobility Management (NAS MM) capabilities and can be detailed, for instance, according to the granularity of the types of AIML operations supported.

[0059] Based on reported capabilities, the AMF can discover the DCAF and retrieve the DCAF configuration, to be provisioned to the UE. Alternatively, the DCAF configuration can also be locally configured in the AMF.

[0060] In some embodiments, the DCAF configuration can include information such as whether the user plane or control plane transport is used. The DCAF configuration can also include the DCAF ID or address for user plane connection.

[0061] In some embodiments, the DDCC in the UE can receive the DCAF configuration in the Registration Accept message. Alternatively, the DCAF configuration may be pre-provisioned in the UE.

[0062] In some embodiments, if the control plane transport is configured, the DDCC in the UE can initiate session establishment through non access stratum (NAS) signaling (e.g., through the acquisition of a client configuration) . In such cases, the messages from the DDCC to the DCAF can be carried in uplink (UL) NAS Transport. Messages from the DCAF to the DDCC over the control plane can be carried in downlink (DL) NAS Transport.

[0063] In some embodiments, the UE can perform a registration procedure to establish a session with a DCAF.

[0064] FIG. 4 illustrates a data flow diagram of an example process for UE session establishment for performing the example process of FIG. 3, according to some embodiments disclosed herein. In the illustrated example, as part of a registration procedure, a UE 402 declares its capabilities to an AMF 404 related to data collection and reporting for AIML operations within a Registration Request (UE Data Collection capability) for AIML operations 408.

[0065] As seen at block 410, the UE is registered, and the AMF 404 discovers a DCAF (e.g., DCAF 406) to be contacted based on the UE capability for data collection. The AMF 404 then indicates whether a session is to be initiated towards the DCAF over the control plane or the user plane.

[0066] The AMF 404 forwards the DCAF configuration and the control plane or user plane configuration to the UE 402 within the registration accept message (e.g., Registration Accept (DCAF configuration, User Plane or Control Plane) 412) .

[0067] As seen in FIG. 4, the UE 402 then initiates session establishment through NAS signaling (e.g., acquisition of client configuration as outlined in TS 26.531) . This process includes transmitting communication UL NAS Transport (payload: acquire client configuration) 414 to the AMF 404.

[0068] The AMF 404 then forwards the client configuration request to the DCAF 406 as Ndcaf_DataReporting_Req (Request client configuration) 416. In response, the DCAF 406 sends back the client configuration via Ndcaf_DataReporting_Response (clientConfiguration) 418, which is then transported to the UE 402 using DL NAS Transport (Provision client configuration) 420.

[0069] At block 422, the UE 402 performs measurements as per the client configuration and reports the collected data back to the DCAF 406.

[0070] User consent management for UE data exposure

[0071] In current versions of 5GC architecture, user consent for network analytics is managed as an entry in the UDM. UDM data for user consent can be stored under UE subscription data. User consent is stored together for each defined purpose, and can be updated through administrative services. Purposes supported can include, analytics, model training for 5GC NFs, network capability exposure, and UE location for Edge Applications.

[0072] To support RAN AIML operations, current user consent management processes can be enhanced. For example, in some cases, UDM subscription data type can be enhanced to include fields for UE data exposure to external AFs. This field can include the ability to be defined per RAN AIML operations, such as beam prediction and Channel State Information (CSI) . Additionally, user consents can store AF information on data exposure (e.g., information on which AFs are permitted to access) for each RAN AIML operation.

[0073] Additionally, in some embodiments, the DCAF can check or verify user consent for each operation and requester AF before provisioning the UE with UE data reporting configurations.

[0074] FIG. 5 illustrates a data flow diagram of an example process for managing UE data exposure during the example data collection process of FIG. 3, according to some embodiments disclosed herein. In this example, a configuration for AIML data collection is transmitted to a DCAF 506 from an AF 508 through a message (e.g., as seen with Ndcaf_DataReportingProvisioning 510) . As shown at block 512, the configuration can include target UE IDs, UE Filter information, and privacy requirements (e.g., TimeWindow for randomization, data anonymization allowed, data aggregation allowed, and random noise allowed) . The configuration also includes a reporting path preference such as control plane or user plane.

[0075] In response, the DCAF 506 forwards user consent for a subscription permanent identifier (SUPI) , a purpose, and a requester AF ID (e.g., as seen at block 516) to a UDM 504 via Nudm_SDMData_Request 514. The UDM 504 responsively provides Ndcaf_DataReportingProvisioning 518, including User Consent status 520.

[0076] As seen at block 522, if the user consent level matches the requested operation type, the DCAF 506 proceeds with provisioning a UE (e.g., a UE DDCC 502) with the data collection reporting configuration.

[0077] As seen at block 524, alternatively or additionally, the DCAF 506 can check the user consent status before exposure of results to the AF 508.

[0078] The DCAF 506 transmits any data collection results (e.g., Data Collection Results 528) to the AF 508 within a Ndcaf_DataReportingProvisioning 526 message.

[0079] Example UE process

[0080] In certain embodiments, as shown in FIG. 3 to FIG. 5, a UE is configured to perform data collection in a wireless network, by: performing, with an Access and Mobility Management Function (AMF) in the wireless network, a registration procedure to establish a session between a Direct Data Collection Client (DDCC) within the UE and a Data Collection Application Function (DCAF) in the wireless network; receiving, at the DDCC within the UE, a data collection and reporting configuration generated by the DCAF, wherein the data collection and reporting configuration comprises a privacy requirement; collecting data at the UE according to the data collection and reporting configuration; processing the collected data, via the DDCC, by applying a privacy-preservation technique according to the privacy requirement within the data collection and reporting configuration; and transmitting the processed data to the DCAF.

[0081] In certain such embodiments, performing the registration procedure to establish the session between the DDCC within the UE and the DCAF in the wireless network comprises: transmitting a registration request message to the AMF; receiving a registration accept message from the AMF comprising a DCAF configuration; transmitting a configuration request to the DCAF; and transmitting the data collection and reporting configuration from the DCAF to the DDCC within the UE.

[0082] In certain embodiments, transmitting the processed data to the DCAF comprises: selecting a reporting method based on the data collection and reporting configuration provided by the DCAF; and initiating, by the DDCC, a reporting of the processed data to the DCAF according to the selected reporting method. In certain such embodiments, selecting the reporting method based on the data collection and reporting configuration provided by the DCAF comprises selecting a random time within a configured time window to report the processed data. In other embodiments, selecting the reporting method based on the data collection and reporting configuration provided by the DCAF comprises selecting whether to report the processed data to the DCAF via a control plane or a user plane.

[0083] In certain embodiments, the privacy requirement comprises at least one of: data anonymization; data aggregation; or addition of random noise.

[0084] In certain embodiments, the privacy-preservation technique comprises at least one of: data anonymization; data aggregation; or addition of random noise.

[0085] Example DCAF process

[0086] In certain embodiments, as shown in FIG. 3 to FIG. 5, a DCAF performs data collection in a wireless network, by: receiving, at the DCAF, from an application function (AF) or a network function (NF) , a request for data collection by a plurality of user equipments (UEs) , the request comprising data report provisioning parameters including privacy requirements; generating, at the DCAF, a data collection and reporting configuration based on the report provisioning parameters, the data collection and reporting configuration including one or more selected privacy requirement of the privacy requirements; sending, from the DCAF to the plurality of UEs, the data collection and reporting configuration; receiving, at the DCAF from the plurality of UEs, reports comprising reported data collected according to the one or more selected privacy requirement; processing the reported data by applying one or more privacy-preservation technique according to the privacy requirements in the data report provisioning  parameters to produce data collection results with privacy preservation; and sending, from the DCAF to the AF or the NF, the data collection results with privacy preservation.

[0087] In certain such embodiments, the data report provisioning parameters including privacy requirements include at least one of: a UE ID; filter conditions; a request for a reporting timeframe; a request for data anonymization; a request for data aggregation; a request for reporting via a control plane; or a request for reporting over a user plane; or security parameters for encrypting the report to the AF.

[0088] In certain embodiments, sending, from the DCAF to the plurality of UEs, the data collection and reporting configuration comprises using a MemberUE Selection service to gather UE IDs.

[0089] In certain embodiments, generating a data collection and reporting configuration based on the report provisioning parameters comprises selecting whether the DDCC or the DCAF is responsible for applying a privacy-preservation technique of the one or more privacy-preservation techniques.

[0090] In certain embodiments, sending, from the DCAF to the plurality of UEs, the data collection and reporting configuration comprises selecting the appropriate path to reach the plurality of UEs.

[0091] In certain embodiments, sending, from the DCAF to the plurality of UEs, the data collection and reporting configuration comprises: verifying a user consent level associated with an allowance policy for data collected from the plurality of UEs; and comparing the verified user consent level against the privacy requirements within the data report provisioning parameters.

[0092] In certain embodiments, sending, from the DCAF to the AF or the NF, the data collection results with privacy preservation comprises verifying a user consent status.

[0093] In certain embodiments, sending, from the DCAF to the AF or the NF, the data collection results with privacy preservation comprises performing verification of the privacy-preservation technique applied to the collected data by the DDCC.

[0094] In certain embodiments, the privacy requirement comprises at least one of: data anonymization; data aggregation; or addition of random noise.

[0095] In certain embodiments, the privacy-preservation technique comprises at least one of: data anonymization; data aggregation; or addition of random noise.

[0096] In certain embodiments, the security parameters for encrypting the report, i.e. wholly or pre-agreed parts in the report, such that content is not visible in the DCAF. In such cases, the DCAF transparently forwards the report content to the AF. The security parameters comprise the parts of report that are to be encrypted and the public key with which the reporting UE encrypts the requested report contents.

[0097] In certain embodiments, the data collection and reporting configuration are configured based on a request from the application function (AF) or the network function (NF) .

[0098] Example Architecture

[0099] FIG. 6 illustrates an example architecture of a wireless communication system 600, according to embodiments disclosed herein. The following description is provided for an example wireless communication system 600 that operates in conjunction with the LTE system standards and / or 5G or NR system standards as provided by 3GPP technical specifications.

[0100] As shown by FIG. 6, the wireless communication system 600 includes UE 602 and UE 604 (although any number of UEs may be used) . In this example, the UE 602 and the UE 604 are illustrated as smartphones (e.g., handheld touchscreen mobile computing devices connectable to one or more cellular networks) , but may also comprise any mobile or non-mobile computing device configured for wireless communication.

[0101] The UE 602 and UE 604 may be configured to communicatively couple with a RAN 606. In embodiments, the RAN 606 may be NG-RAN, E-UTRAN, etc. The UE 602 and UE 604 utilize connections (or channels) (shown as connection 608 and connection 610, respectively) with the RAN 606, each of which comprises a physical communications interface. The RAN 606 can include one or more base stations (such as base station 612 and base station 614) that enable the connection 608 and connection 610.

[0102] In this example, the connection 608 and connection 610 are air interfaces to enable such communicative coupling, and may be consistent with RAT (s) used by the RAN 606, such as, for example, an LTE and / or NR.

[0103] In some embodiments, the UE 602 and UE 604 may also directly exchange communication data via a sidelink interface 616. The UE 604 is shown to be configured to access an access point (shown as AP 618) via connection 620. By way of example, the connection 620 can comprise a local wireless connection, such as a connection consistent  with any IEEE 802.11 protocol, wherein the AP 618 may comprise a  router. In this example, the AP 618 may be connected to another network (for example, the Internet) without going through a CN 624.

[0104] In embodiments, the UE 602 and UE 604 can be configured to communicate using orthogonal frequency division multiplexing (OFDM) communication signals with each other or with the base station 612 and / or the base station 614 over a multicarrier communication channel in accordance with various communication techniques, such as, but not limited to, an orthogonal frequency division multiple access (OFDMA) communication technique (e.g., for downlink communications) or a single carrier frequency division multiple access (SC-FDMA) communication technique (e.g., for uplink and ProSe or sidelink communications) , although the scope of the embodiments is not limited in this respect. The OFDM signals can comprise a plurality of orthogonal subcarriers.

[0105] In some embodiments, all or parts of the base station 612 or base station 614 may be implemented as one or more software entities running on server computers as part of a virtual network. In addition, or in other embodiments, the base station 612 or base station 614 may be configured to communicate with one another via interface 622. In embodiments where the wireless communication system 600 is an LTE system (e.g., when the CN 624 is an EPC) , the interface 622 may be an X2 interface. The X2 interface may be defined between two or more base stations (e.g., two or more eNBs and the like) that connect to an EPC, and / or between two eNBs connecting to the EPC. In embodiments where the wireless communication system 600 is an NR system (e.g., when CN 624 is a 5GC) , the interface 622 may be an Xn interface. The Xn interface is defined between two or more base stations (e.g., two or more gNBs and the like) that connect to 5GC, between a base station 612 (e.g., a gNB) connecting to 5GC and an eNB, and / or between two eNBs connecting to 5GC (e.g., CN 624) .

[0106] The RAN 606 is shown to be communicatively coupled to the CN 624. The CN 624 may comprise one or more network elements 626, which are configured to offer various data and telecommunications services to customers / subscribers (e.g., users of UE 602 and UE 604) who are connected to the CN 624 via the RAN 606. The components of the CN 624 may be implemented in one physical device or separate physical devices including components to read and execute instructions from a machine-readable or computer-readable medium (e.g., a non-transitory machine-readable storage medium) .

[0107] In embodiments, the CN 624 may be an EPC, and the RAN 606 may be connected with the CN 624 via an S1 interface 628. In embodiments, the S1 interface 628 may be split into two parts, an S1 user plane (S1-U) interface, which carries traffic data between the base station 612 or base station 614 and a serving gateway (S-GW) , and the S1-MME interface, which is a signaling interface between the base station 612 or base station 614 and mobility management entities (MMEs) .

[0108] In embodiments, the CN 624 may be a 5GC, and the RAN 606 may be connected with the CN 624 via an NG interface 628. In embodiments, the NG interface 628 may be split into two parts, an NG user plane (NG-U) interface, which carries traffic data between the base station 612 or base station 614 and a user plane function (UPF) , and the S1 control plane (NG-C) interface, which is a signaling interface between the base station 612 or base station 614 and access and mobility management functions (AMFs) .

[0109] Generally, an application server 630 may be an element offering applications that use internet protocol (IP) bearer resources with the CN 624 (e.g., packet switched data services) . The application server 630 can also be configured to support one or more communication services (e.g., VoIP sessions, group communication sessions, etc. ) for the UE 602 and UE 604 via the CN 624. The application server 630 may communicate with the CN 624 through an IP communications interface 632.

[0110] FIG. 7 illustrates a system 700 for performing signaling 732 between a wireless device 702 and a network device 718, according to embodiments disclosed herein. The system 700 may be a portion of a wireless communications system as herein described. The wireless device 702 may be, for example, a UE of a wireless communication system. The network device 718 may be, for example, a base station (e.g., an eNB or a gNB) of a wireless communication system.

[0111] The wireless device 702 may include one or more processor (s) 704. The processor (s) 704 may execute instructions such that various operations of the wireless device 702 are performed, as described herein. The processor (s) 704 may include one or more baseband processors implemented using, for example, a central processing unit (CPU) , a digital signal processor (DSP) , an application specific integrated circuit (ASIC) , a controller, a field programmable gate array (FPGA) device, another hardware device, a firmware device, or any combination thereof configured to perform the operations described herein.

[0112] The wireless device 702 may include a memory 706. The memory 706 may be a non-transitory computer-readable storage medium that stores instructions 708 (which may include, for example, the instructions being executed by the processor (s) 704) . The instructions 708 may also be referred to as program code or a computer program. The memory 706 may also store data used by, and results computed by, the processor (s) 704.

[0113] The wireless device 702 may include one or more transceiver (s) 710 that may include radio frequency (RF) transmitter circuitry and / or receiver circuitry that use the antenna (s) 712 of the wireless device 702 to facilitate signaling (e.g., the signaling 732) to and / or from the wireless device 702 with other devices (e.g., the network device 718) according to corresponding RATs.

[0114] The wireless device 702 may include one or more antenna (s) 712 (e.g., one, two, four, or more) . For embodiments with multiple antenna (s) 712, the wireless device 702 may leverage the spatial diversity of such multiple antenna (s) 712 to send and / or receive multiple different data streams on the same time and frequency resources. This behavior may be referred to as, for example, multiple input multiple output (MIMO) behavior (referring to the multiple antennas used at each of a transmitting device and a receiving device that enable this aspect) . MIMO transmissions by the wireless device 702 may be accomplished according to precoding (or digital beamforming) that is applied at the wireless device 702 that multiplexes the data streams across the antenna (s) 712 according to known or assumed channel characteristics such that each data stream is received with an appropriate signal strength relative to other streams and at a desired location in the spatial domain (e.g., the location of a receiver associated with that data stream) . Certain embodiments may use single user MIMO (SU-MIMO) methods (where the data streams are all directed to a single receiver) and / or multi user MIMO (MU-MIMO) methods (where individual data streams may be directed to individual (different) receivers in different locations in the spatial domain) .

[0115] In certain embodiments having multiple antennas, the wireless device 702 may implement analog beamforming techniques, whereby phases of the signals sent by the antenna (s) 712 are relatively adjusted such that the (joint) transmission of the antenna (s) 712 can be directed (this is sometimes referred to as beam steering) .

[0116] The wireless device 702 may include one or more interface (s) 714. The interface (s) 714 may be used to provide input to or output from the wireless device 702. For example, a wireless device 702 that is a UE may include interface (s) 714 such as  microphones, speakers, a touchscreen, buttons, and the like in order to allow for input and / or output to the UE by a user of the UE. Other interfaces of such a UE may be made up of transmitters, receivers, and other circuitry (e.g., other than the transceiver (s) 710 / antenna (s) 712 already described) that allow for communication between the UE and other devices and may operate according to known protocols (e.g., and the like) .

[0117] The wireless device 702 may include a data collection module 716. The data collection module 716 may be implemented via hardware, software, or combinations thereof. For example, the data collection module 716 may be implemented as a processor, circuit, and / or instructions 708 stored in the memory 706 and executed by the processor (s) 704. In some examples, the data collection module 716 may be integrated within the processor (s) 704 and / or the transceiver (s) 710. For example, the data collection module 716 may be implemented by a combination of software components (e.g., executed by a DSP or a general processor) and hardware components (e.g., logic gates and circuitry) within the processor (s) 704 or the transceiver (s) 710.

[0118] The data collection module 716 may be used for various aspects of the present disclosure, for example, aspects of FIG. 3 to FIG. 5.

[0119] The network device 718 may include one or more processor (s) 720. The processor (s) 720 may execute instructions such that various operations of the network device 718 are performed, as described herein. The processor (s) 720 may include one or more baseband processors implemented using, for example, a CPU, a DSP, an ASIC, a controller, an FPGA device, another hardware device, a firmware device, or any combination thereof configured to perform the operations described herein.

[0120] The network device 718 may include a memory 722. The memory 722 may be a non-transitory computer-readable storage medium that stores instructions 724 (which may include, for example, the instructions being executed by the processor (s) 720) . The instructions 724 may also be referred to as program code or a computer program. The memory 722 may also store data used by, and results computed by, the processor (s) 720.

[0121] The network device 718 may include one or more transceiver (s) 726 that may include RF transmitter circuitry and / or receiver circuitry that use the antenna (s) 728 of the network device 718 to facilitate signaling (e.g., the signaling 732) to and / or from the network device 718 with other devices (e.g., the wireless device 702) according to corresponding RATs.

[0122] The network device 718 may include one or more antenna (s) 728 (e.g., one, two, four, or more) . In embodiments having multiple antenna (s) 728, the network device 718 may perform MIMO, digital beamforming, analog beamforming, beam steering, etc., as has been described.

[0123] The network device 718 may include one or more interface (s) 730. The interface (s) 730 may be used to provide input to or output from the network device 718. For example, a network device 718 that is a base station may include interface (s) 730 made up of transmitters, receivers, and other circuitry (e.g., other than the transceiver (s) 726 / antenna (s) 728 already described) that enables the base station to communicate with other equipment in a core network, and / or that enables the base station to communicate with external networks, computers, databases, and the like for purposes of operations, administration, and maintenance of the base station or other equipment operably connected thereto.

[0124] Embodiments contemplated herein include an apparatus comprising means to perform one or more elements of the UE methods disclosed herein. This apparatus may be, for example, an apparatus of a UE (such as a wireless device 702 that is a UE, as described herein) .

[0125] Embodiments contemplated herein include one or more non-transitory computer-readable media comprising instructions to cause an electronic device, upon execution of the instructions by one or more processors of the electronic device, to perform one or more elements of the UE methods disclosed herein. This non-transitory computer-readable media may be, for example, a memory of a UE (such as a memory 706 of a wireless device 702 that is a UE, as described herein) .

[0126] Embodiments contemplated herein include an apparatus comprising logic, modules, or circuitry to perform one or more elements of the UE methods disclosed herein. This apparatus may be, for example, an apparatus of a UE (such as a wireless device 702 that is a UE, as described herein) .

[0127] Embodiments contemplated herein include an apparatus comprising: one or more processors and one or more computer-readable media comprising instructions that, when executed by the one or more processors, cause the one or more processors to perform one or more elements of the UE methods disclosed herein. This apparatus may be, for example, an apparatus of a UE (such as a wireless device 702 that is a UE, as described herein) .

[0128] Embodiments contemplated herein include a signal as described in or related to one or more elements of the UE methods disclosed herein.

[0129] Embodiments contemplated herein include a computer program or computer program product comprising instructions, wherein execution of the program by a processor is to cause the processor to carry out one or more elements of the UE methods disclosed herein. The processor may be a processor of a UE (such as a processor (s) 704 of a wireless device 702 that is a UE, as described herein) . These instructions may be, for example, located in the processor and / or on a memory of the UE (such as a memory 706 of a wireless device 702 that is a UE, as described herein) .

[0130] For one or more embodiments, at least one of the components set forth in one or more of the preceding figures may be configured to perform one or more operations, techniques, processes, and / or methods as set forth herein. For example, a baseband processor as described herein in connection with one or more of the preceding figures may be configured to operate in accordance with one or more of the examples set forth herein. For another example, circuitry associated with a UE, base station, network element, etc. as described above in connection with one or more of the preceding figures may be configured to operate in accordance with one or more of the examples set forth herein.

[0131] Any of the above described embodiments may be combined with any other embodiment (or combination of embodiments) , unless explicitly stated otherwise. The foregoing description of one or more implementations provides illustration and description, but is not intended to be exhaustive or to limit the scope of embodiments to the precise form disclosed. Modifications and variations are possible in light of the above teachings or may be acquired from practice of various embodiments.

[0132] Embodiments and implementations of the systems and methods described herein may include various operations, which may be embodied in machine-executable instructions to be executed by a computer system. A computer system may include one or more general-purpose or special-purpose computers (or other electronic devices) . The computer system may include hardware components that include specific logic for performing the operations or may include a combination of hardware, software, and / or firmware.

[0133] It should be recognized that the systems described herein include descriptions of specific embodiments. These embodiments can be combined into single systems,  partially combined into other systems, split into multiple systems or divided or combined in other ways. In addition, it is contemplated that parameters, attributes, aspects, etc. of one embodiment can be used in another embodiment. The parameters, attributes, aspects, etc. are merely described in one or more embodiments for clarity, and it is recognized that the parameters, attributes, aspects, etc. can be combined with or substituted for parameters, attributes, aspects, etc. of another embodiment unless specifically disclaimed herein.

[0134] It is well understood that the use of personally identifiable information should follow privacy policies and practices that are generally recognized as meeting or exceeding industry or governmental requirements for maintaining the privacy of users. In particular, personally identifiable information data should be managed and handled so as to minimize risks of unintentional or unauthorized access or use, and the nature of authorized use should be clearly indicated to users.

[0135] Although the foregoing has been described in some detail for purposes of clarity, it will be apparent that certain changes and modifications may be made without departing from the principles thereof. It should be noted that there are many alternative ways of implementing both the processes and apparatuses described herein. Accordingly, the present embodiments are to be considered illustrative and not restrictive, and the description is not to be limited to the details given herein, but may be modified within the scope and equivalents of the appended claims.

Claims

1.A method for a User Equipment (UE) to perform data collection in a wireless network, the method comprising:performing, with an Access and Mobility Management Function (AMF) in the wireless network, a registration procedure to establish a session between the UE and a Network Entity (NE) in the wireless network;receiving, at the UE, a data collection and reporting configuration generated by the NE, wherein the data collection and reporting configuration comprises a privacy requirement;collecting data at the UE according to the data collection and reporting configuration to produce collected data;processing the collected data, at the UE, to produce processed data by applying a privacy-preservation technique according to the privacy requirement within the data collection and reporting configuration; andtransmitting the processed data to the NE.2.The method of claim 1, wherein performing the registration procedure to establish the session between the UE and the NE in the wireless network comprises:transmitting a registration request message to the AMF;receiving a registration accept message from the AMF comprising an NE configuration;transmitting a configuration request to the NE through the AMF; andreceiving the data collection and reporting configuration from the NE through the AMF to the UE.3.The method of claim 1, wherein transmitting the processed data to the NE comprises:selecting a reporting method based on the data collection and reporting configuration provided by the NE;encrypting at least part of the collected data based on security parameters in the data collection and reporting configuration; andinitiating, by the UE, a reporting of the processed data to the NE according to the selected reporting method.4.The method of claim 3, wherein selecting the reporting method based on the data collection and reporting configuration provided by the NE comprises selecting a random time within a configured time window to report the processed data.5.The method of claim 3, wherein selecting the reporting method based on the data collection and reporting configuration provided by the NE comprises selecting whether to report the processed data to the NE via a control plane or a user plane.6.The method of claim 1, wherein the privacy requirement comprises at least one of:data anonymization;data aggregation; oraddition of random noise.7.The method of claim 1, wherein the privacy-preservation technique comprises at least one of:data anonymization;data aggregation; oraddition of random noise.8.The method of 1, wherein the UE comprises a Direct Data Collection Client (DDCC) or other module configured to perform the registration procedure with the NE, handle the data collection and reporting configuration, and process the collected data.9.The method of claim 1, wherein the NE comprises a Data Collection Application Function (DCAF) .10.A method for a Network Entity (NE) to perform data collection in a wireless network, the method comprising:receiving, at the NE, from an application function (AF) or a network function (NF) , a request for data collection by a plurality of user equipments (UEs) , the request comprising data report provisioning parameters including privacy requirements;generating, at the NE, a data collection and reporting configuration based on the report provisioning parameters, the data collection and reporting configuration including one or more selected privacy requirement of the privacy requirements;sending, from the NE to the plurality of UEs, the data collection and reporting configuration;receiving, at the NE from the plurality of UEs, reports comprising reported data collected according to the one or more selected privacy requirement;processing the reported data by applying one or more privacy-preservation technique according to the privacy requirements in the data report provisioning parameters to produce data collection results with privacy preservation; andsending, from the NE to the AF or the NF, the data collection results with privacy preservation.11.The method of claim 10, wherein the data report provisioning parameters including privacy requirements comprising at least one of:a UE ID;filter conditions;a request for a reporting timeframe;a request for data anonymization;a request for data aggregation;a request for reporting via a control plane; ora request for reporting over a user plane.12.The method of claim 10, wherein sending, from the NE to the plurality of UEs, the data collection and reporting configuration comprises using a MemberUE Selection service to gather UE IDs.13.The method of claim 10, wherein generating a data collection and reporting configuration based on the report provisioning parameters comprises selecting whether the UE or the NE is responsible for applying a privacy-preservation technique of the one or more privacy-preservation techniques.14.The method of claim 10, wherein sending, from the NE to the plurality of UEs, the data collection and reporting configuration comprises selecting a path to reach the plurality of UEs.15.The method of claim 10, wherein sending, from the NE to the plurality of UEs, the data collection and reporting configuration comprises:verifying a user consent level associated with an allowance policy for data collected from the plurality of UEs; andcomparing the verified user consent level against the privacy requirements within the data report provisioning parameters.16.The method of claim 10, wherein sending, from the NE to the AF or the NF, the data collection results with privacy preservation comprises verifying a user consent status.17.The method of claim 10, wherein sending, from the NE to the AF or the NF, the data collection results with privacy preservation comprises performing verification of the privacy-preservation technique applied to the collected data by the UE.18.The method of claim 10, wherein the privacy requirements comprise at least one of:data anonymization;data aggregation; oraddition of random noise.19.The method of claim 10, wherein the privacy-preservation technique comprises at least one of:data anonymization;data aggregation; oraddition of random noise.20.The method of claim 10, wherein the data collection and reporting configuration is configured based on the request from the AF or the NF, and wherein the data collection and reporting configuration comprises security parameters received in the request for data collection from the AF or the NF for the plurality of UEs to encrypt at least a portion of the reports that is not to be visible to the NE.21.The method of claim 10, wherein the NE comprises a Data Collection Application Function (DCAF) in the wireless network.22.An apparatus comprising means to perform the method of any of claim 1 to claim 21.23.A computer-readable media comprising instructions to cause an electronic device, upon execution of the instructions by one or more processors of the electronic device, to perform the method of any of claim 1 to claim 21.24.An apparatus comprising logic, modules, or circuitry to perform the method of any of claim 1 to claim 21.25.A baseband processor for a user equipment (UE) that is configured to cause the UE to perform one or more elements of any one of claim 1 to claim 9.

Citation Information

Patent Citations

  • Provisioning of VLAN ids in 5g systems

    CN113228570A

  • Data collection method and communication device

    CN116074807A

  • Communication method and apparatus

    WO2023221604A1

  • Data collection and reporting in a wireless communication system

    WO2024110081A1