Method and device for collecting data in wireless communication system

By implementing a security policy-driven data collection method at the base station, the reliability and security of data for AI/ML models in 6G communication systems are enhanced, addressing the issue of contaminated data from malicious devices and improving resource efficiency.

WO2026155273A1PCT designated stage Publication Date: 2026-07-23SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2025-01-15
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

The challenge in 6G communication systems is ensuring data security and reliability in data collection processes, particularly in scenarios where malicious or hacked devices can provide false or contaminated training data, leading to performance degradation of AI/ML models.

Method used

A method and apparatus for a base station to collect data by receiving a security policy from a core network, determining whether to perform data collection based on this policy, and ensuring that data is collected from trusted user equipment (UE) that meets specific security requirements, thereby enhancing data reliability and reducing the collection of contaminated data.

Benefits of technology

This approach improves the reliability of data collected for AI/ML models, reduces the risk of incorrect inferences, and optimizes resource utilization by minimizing the collection of manipulated or unreliable data, thus enhancing the performance and security of wireless communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025000862_23072026_PF_FP_ABST
    Figure KR2025000862_23072026_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a method by which a base station collects data in a wireless communication system. The method may comprise the steps of: receiving a security policy for data collection from a core network; determining whether to collect data for from a user equipment (UE) on the basis of the security policy; and collecting data from the UE.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for collecting data in a wireless communication system

[0001] The present disclosure relates to a wireless communication system, and more specifically, to a method and apparatus for a base station and a core network to collect data.

[0002] Looking back at the evolution of wireless communication through successive generations, technologies have been developed primarily for human-oriented services, such as voice, multimedia, and data. Following the commercialization of 5G (5th-generation) communication systems, connected devices, which have been increasing explosively, are expected to be connected to communication networks. Examples of networked objects include vehicles, robots, drones, home appliances, displays, smart sensors installed in various infrastructures, construction machinery, and factory equipment. Mobile devices are expected to evolve into various form factors, such as augmented reality glasses, virtual reality headsets, and holographic devices. In the 6G (6th-generation) era, efforts are underway to develop improved 6G communication systems to connect hundreds of billions of devices and objects to provide diverse services. For this reason, 6G communication systems are being referred to as "beyond 5G" systems.

[0003] In the 6G communication system predicted to be realized around 2030, the maximum transmission speed is tera (i.e., 1,000 gigabit) bps, and the wireless latency is 100 microseconds (μsec). In other words, compared to the 5G communication system, the transmission speed in the 6G communication system is 50 times faster, and the wireless latency is reduced to one-tenth.

[0004] To achieve such high data transmission speeds and ultra-low latency, 6G communication systems are being considered for implementation in the terahertz band (e.g., the 95 GHz to 3 terahertz (3 THz) band). In the terahertz band, due to more severe path loss and atmospheric absorption compared to the millimeter wave (mmWave) band introduced in 5G, the importance of technology capable of guaranteeing signal reach, or coverage, is expected to increase. As key technologies to ensure coverage, radio frequency (RF) devices, antennas, new waveforms that offer better coverage than orthogonal frequency division multiplexing (OFDM), beamforming, and multi-antenna transmission technologies such as massive multiple-input and multiple-output (massive MIMO), full-dimensional MIMO (FD-MIMO), array antennas, and large-scale antennas must be developed. In addition, new technologies such as metamaterial-based lenses and antennas, high-dimensional spatial multiplexing technology using orbital angular momentum (OAM), and reconfigurable intelligent surface (RIS) are being discussed to improve coverage of terahertz band signals.

[0005] In addition, to improve frequency efficiency and system network, development is underway in 6G communication systems for full duplex technology, in which uplink and downlink simultaneously utilize the same frequency resources at the same time; network technology that integrates satellites and HAPS (high-altitude platform stations); network structure innovation technology that supports mobile base stations and enables network operation optimization and automation; dynamic spectrum sharing technology through collision avoidance based on spectrum usage prediction; AI-based communication technology that utilizes AI (artificial intelligence) from the design stage and internalizes end-to-end AI support functions to realize system optimization; and next-generation distributed computing technology that realizes services of complexity exceeding the limits of terminal computing capabilities by utilizing ultra-high performance communication and computing resources (mobile edge computing (MEC), cloud, etc.). In addition, attempts are continuing to further strengthen connectivity between devices, further optimize networks, promote the softwareization of network entities, and increase the openness of wireless communication through the design of new protocols to be used in 6G communication systems, the implementation of hardware-based security environments, the development of mechanisms for the safe utilization of data, and the development of technologies regarding privacy maintenance methods.

[0006] Due to the research and development of such 6G communication systems, it is expected that a new dimension of hyper-connected experience will become possible through the hyper-connectivity of 6G communication systems, which encompasses not only connections between objects but also connections between people and objects. Specifically, it is projected that 6G communication systems will enable the provision of services such as truly immersive extended reality (truly immersive XR), high-fidelity mobile holograms, and digital replicas. Furthermore, services such as remote surgery, industrial automation, and emergency response, which are provided through 6G communication systems with enhanced security and reliability, will be applied in various fields including industry, healthcare, automotive, and home appliances.

[0007] According to an embodiment of the present disclosure, a method is provided for a base station to collect data in a wireless communication system. The method may include the step of receiving a security policy for data collection from a core network. The method may include the step of determining whether to perform data collection on a UE (user equipment) based on the security policy. The method may include the step of collecting data from the UE.

[0008] According to an embodiment of the present disclosure, a base station for collecting data in a wireless communication system is provided. The base station may include a transceiver; and at least one processor connected to the transceiver. The at least one processor may receive a security policy for data collection from a core network. The at least one processor may determine whether to perform data collection on a UE (user equipment) based on the security policy. The at least one processor may collect data from the UE.

[0009] FIG. 1 is a drawing for illustrating an AI / ML model according to one embodiment of the present disclosure.

[0010] FIG. 2 illustrates a wireless communication system according to one embodiment of the present disclosure.

[0011] FIG. 3 illustrates a data collection method according to one embodiment of the present disclosure.

[0012] FIG. 4 illustrates a data collection method according to one embodiment of the present disclosure.

[0013] FIG. 5 illustrates a data collection method according to one embodiment of the present disclosure.

[0014] FIG. 6 illustrates a data collection method according to one embodiment of the present disclosure.

[0015] FIG. 7 illustrates data according to one embodiment of the present disclosure.

[0016] FIG. 8 is a block diagram schematically illustrating the configuration of a terminal according to one embodiment of the present disclosure.

[0017] FIG. 9 is a block diagram schematically illustrating the configuration of a base station according to one embodiment of the present disclosure.

[0018] FIG. 10 is a block diagram schematically illustrating the configuration of a network function according to one embodiment of the present disclosure.

[0019] The present disclosure is subject to various modifications and may have various embodiments; specific embodiments are illustrated in the drawings and described in detail in the detailed description. However, FIGS. 1 through 10 discussed below and the various embodiments used in this specification to explain the principles of the present disclosure are merely illustrative and should not be construed as limiting the scope of the present disclosure in any way. Those skilled in the art will understand that the principles of the present disclosure may be implemented in any appropriately arranged system or device. Furthermore, those skilled in the art will understand that the principles of the present disclosure may be implemented in any appropriately configured wireless communication system.

[0020] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the dimensions of each component do not entirely reflect their actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.

[0021] In addition, numbers used in the description process of the specification (e.g., 1st, 2nd, etc.) are merely identifiers to distinguish one component from another.

[0022] The advantages and features of the present disclosure, and the methods for achieving them, will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below but may be implemented in various different forms. These embodiments are provided merely to ensure that the disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Throughout the specification, the same reference numerals refer to the same components. Furthermore, in describing the present disclosure, if it is determined that a detailed description of a related function or configuration might unnecessarily obscure the essence of the present disclosure, such detailed description is omitted. Additionally, the terms described below are defined considering their functions in the present disclosure, and these may vary depending on the intentions or conventions of the user or operator. Therefore, their definitions should be based on the content throughout the specification.

[0023] The term "couple" and its derivatives refer to any direct or indirect communication between two or more elements, whether or not they are in physical contact with each other. The terms "transmit," "receive," and "communicate," as well as their derivatives, include both direct and indirect communication. The terms "have" and "include," as well as their derivatives, imply inclusion without limitation.

[0024] In this specification, terms such as “comprising” or “having” are intended to specify the existence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should not be understood as precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.

[0025] When a part of a specification is described as "including" a certain component, this means that, unless specifically stated otherwise, it does not exclude other components but may include additional components.

[0026] The term "or" is inclusive and means "and / or." The phrase "related to" as well as its derivatives mean: to include, to be contained within, to interconnect with, to contain, to be contained within, to connect with or to, to be coupled with, to be communicable with, to cooperate with, to interleave, to juxtapose, to be close to, to be associated with or to, to have, to possess the characteristics of, to have a relationship with, etc.

[0027] In addition, when a component is described in the present disclosure as being "connected" or "connected" to another component, it should be understood that the component may be directly connected to or directly connected to the other component, but unless otherwise specifically stated, it may also be connected or connected through another component in between.

[0028] In addition, while LTE, LTE-A, or 5G systems may be described below as examples, embodiments of the present disclosure may also be applied to other communication systems having similar technical backgrounds or channel types. For example, 5G-Advance or NR-Advance or 6th generation mobile communication technology (6G) developed after 5G mobile communication technology (or new radio, NR) may be included, and the 5G below may be a concept that includes existing LTE, LTE-A, and other similar services. Furthermore, the present disclosure may be applied to other communication systems with some modifications made at the discretion of a person with skilled technical knowledge, without significantly departing from the scope of the present disclosure.

[0029] For example, while embodiments of the present disclosure are described using a 6th generation wireless communication technology (6G) system as an example, embodiments of the present disclosure may also be applied to other wireless communication systems having similar technical backgrounds or channel types. According to other examples, embodiments of the present disclosure may be applied to wireless communication systems prior to NR, such as NR, LTE, or LTE-A, and furthermore, embodiments of the present disclosure may be applied to wireless communication systems developed after NR.

[0030] Embodiments of the present disclosure may be supported by standard documents disclosed in at least one of wireless access systems, such as O-RAN (Open-RAN), 3GPP, or 3GPP2. That is, steps or parts among the embodiments of the present invention that are not described in order to clearly reveal the technical concept of the present invention may be supported by said documents.

[0031] In addition, in specifically describing the embodiments of the present disclosure, the focus is primarily on the New RAN (NR) wireless access network and the packet core (5G System, or 5G Core Network, or NG Core: Next Generation Core) of the 5G mobile communication standard specified by 3GPP, a mobile communication standardization organization; however, the main gist of the present disclosure may be applied to other communication systems having a similar technical background with slight modifications without significantly departing from the scope of the present disclosure, and this will be possible at the judgment of a person with skilled technical knowledge in the technical field of the present disclosure.

[0032] Accordingly, the present disclosure is not limited to the terms described below, and other terms having equivalent technical meanings may be used.

[0033] In one embodiment of the present disclosure, the terms “~ module” or “~ part” used may refer to software or hardware components such as a Field Programmable Gate Array (FPGA) or an Application Specific Integrated Circuit (ASIC), and the “~ part” may perform a specific role. Meanwhile, the meaning of “~ module” or “~ part” is not limited to software or hardware. The “~ module” or “~ part” may be configured to reside in an addressable storage medium or may be configured to run one or more processors. In one embodiment, the “~ module” or “~ part” may include components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. Functions provided through a specific component or a specific “~ module” or “~ part” may be combined or separated into additional components to reduce their number. Additionally, in one embodiment, the '~ module' or '~ part' may include one or more processors.

[0034] Additionally, embodiments of the present disclosure may be represented by functional block configurations and various processing steps. These functional blocks may be implemented by various numbers of hardware and / or software configurations that execute specific functions. For example, embodiments of the present disclosure may employ direct circuit configurations such as memory, processing, logic, etc., which can execute various functions under the control of one or more microprocessors or other control devices.

[0035] At this point, it will be understood that each block of the process flow diagrams and combinations of the flow diagrams can be executed by computer program instructions. Since these computer program instructions can be loaded into the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, the instructions executed through the processor of the computer or other programmable data processing equipment create means to perform the functions described in the flow diagram block(s). Since these computer program instructions can also be stored in computer-available or computer-readable memory that can be directed toward the computer or other programmable data processing equipment to implement the function in a specific way, the instructions stored in computer-available or computer-readable memory can also produce a manufactured item containing instruction means to perform the function described in the flow diagram block(s). Since computer program instructions can be loaded onto a computer or other programmable data processing equipment, instructions that perform a series of operation steps on the computer or other programmable data processing equipment to create a process executed by the computer can also provide steps for executing the functions described in the flowchart block(s).

[0036] Additionally, each block may represent a module, segment, or part of code containing one or more executable instructions for executing a specified logical function(s). It should also be noted that in some alternative practices, the functions mentioned in the blocks may occur out of order. For example, two blocks described in succession may actually be executed substantially simultaneously, or the blocks may be executed in reverse order according to their corresponding functions. Alternatively, at least some of the blocks may be omitted during execution.

[0037] In this embodiment, the term "part" refers to a software or hardware component such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit), and the "part" performs certain roles. However, the meaning of "part" is not limited to software or hardware. The "part" may be configured to reside in an addressable storage medium or configured to run one or more processors. Thus, as an example, the "part" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and "parts" may be combined into a smaller number of components and "parts" or further separated into additional components and "parts." In addition, the components and 'parts' may be implemented to utilize one or more CPUs within the device or secure multimedia card. Also, in the embodiments, 'parts' may include one or more processors.

[0038] Terms used in the following description to refer to broadcast information, control information, communication coverage, state changes (e.g., events), network entities, messages, and device components are examples provided for the convenience of explanation. Accordingly, the present disclosure is not limited to the terms described below, and other terms having equivalent technical meanings may be used.

[0039] According to one embodiment of the present disclosure, a 5G core network or an NR core network may include various NFs. A 5G core network or an NR core network may include a greater number of NFs than the NFs described below, or a smaller number of NFs.

[0040] The Access and Mobility Management Function (AMF) is a device for managing the access and mobility of terminals and can serve as a terminal-to-core network endpoint, connecting terminals to other devices in the core network via the RAN. Functions provided by the AMF may include, for example, terminal registration, connection, reachability, mobility management, access verification / authentication, and the generation of mobility events.

[0041] The Session Management Function (SMF) can perform the management of a terminal's PDU session. For example, the SMF can perform functions such as session management through the establishment, modification, and release of sessions and maintaining the necessary tunnel between the UPF and AN, IP address allocation and management functions for the terminal, ARP Proxy functions, User Plane selection and control, traffic processing control in the UPF, and billing data collection control.

[0042] The Policy Control Function (PCF) can perform the role of determining and enforcing policies regarding access / mobility and session management applied by the AMF and SMF. For example, the PCF can govern the behavior of the entire network and provide policies to be implemented to the Network Functions (NFs) that constitute the control plane. Additionally, the PCF can access information related to policy decisions by accessing the Unified Data Repository (UDR).

[0043] A Network Exposure Function (NEF) can be responsible for transmitting or receiving events and supported capabilities occurring in a mobile communication network to or from the outside. For example, an NEF can perform functions such as securely provisioning information of external applications to the core network, converting internal / external information, and storing and redistributing capabilities received from other NFs in a UDR.

[0044] Unified Data Management (UDM) can perform functions such as, for example, generating AKA authentication information for 3GPP security, processing User IDs, reverse concealment of Subscriber Concealed IDs (SUPI), managing a list of NFs supporting the current UE, managing subscription information, and managing SMS. Unified Data Repository (UDR) can perform functions such as storing and providing subscriber information managed by UDM, structured data for exposure, NEFs, or application data associated with services.

[0045] The UPF (User Plane Function) performs the role of processing actual user data and can process packets to transmit packets generated by the terminal to an external data network or to transmit data received from an external data network to the terminal.

[0046] Key functions provided by UPF may include, for example, acting as an anchor between Radio Access Technologies, providing connectivity between PDU sessions and external data networks, packet routing and forwarding, packet inspection, application of user plane policies, generation of traffic usage reports, and buffering.

[0047] The Network Repository Function (NRF) can support service discovery for NRF services and their endpoint addresses through the NRF bootstrapping service. The NRF receives NF Discovery Requests from NF instances or SCPs and can transmit information about discovered NF instances to the NF instances or SCPs. The NRF can maintain NF profiles for available NF instances and supported services. The NRF can provide notifications regarding newly registered, updated, or deregistered NF and SCP instances, along with potential NF services. The NRF maintains the status of NFs and SCPs.

[0048] The Network Data Analytics Function (NWDAF) can collect events or information occurring within the network and deliver statistics, predictions, and recommendations related to specific information to the NF, AF, and OAM using analysis tools or machine learning tools. For example, the NWDAF can perform functions such as collecting data from NF / AF / OAM (Operation, administration, and maintenance), registering the NWDAF service and exposing metadata, and providing network analysis information to NF / AF. In other words, the NWDAF analyzes collected network data using intelligent technologies such as machine learning and provides the analysis results to other 5G core network functions (e.g., NF, AF, or OAM), thereby helping to optimize and improve the performance of each network function.

[0049] The UCMF (UE Radio Capability Management Function) can perform the function of storing and providing mapping information between the ID of a wireless access-related function of a terminal assigned by the PLMN or the manufacturer and the actual function in the form of a dictionary.

[0050] Application Functions (AFs) can perform functions that interoperate with the 3GPP core network to provide services. AFs can be broadly classified into trusted and untrusted types; trusted AFs can utilize the services of network functions located within the core network without the need for separate intermediate functions such as Network Efforts (NEFs). Typical functions provided by AFs include application influence on traffic routing, utilization of network information exposure functions, interaction with policy frameworks for policy control, and IMS-related interactions.

[0051] OAM (Operation, Administration, and Maintenance) can refer to a device for managing the entire mobile communication network, including base stations and the core network. For example, OAM can perform functions related to network operation, management, maintenance, provisioning, and troubleshooting.

[0052] Furthermore, OAM can perform the function of monitoring and configuring each base station or core network to ensure smooth operation in accordance with design and policies. As a concept encompassing all management-related tools and procedures, OAM does not refer to a specific device but can include all tools, software, and procedures used by network administrators for management purposes.

[0053] A terminal (User Equipment, UE) can be connected to a (R)AN (Radio Access Network) to access core network devices of the network. The core network of a network (e.g., a 5G network) may include network functions as described above. The RAN described above may include a 5G-RAN and may include a base station that provides wireless communication functions to the terminal.

[0054] A base station (BS) is an entity that performs resource allocation for terminals and may be at least one of gNode B, eNode B, Node B (or xNode B (where x is an alphabet including g and e)), a radio access unit, a base station controller, a satellite, an airborn, or a node on a network. In this disclosure, the term base station may be used interchangeably with RAN (radio access network).

[0055] User equipment (UE) may include a Mobile Station (MS), a Vehicular, a Satellite, an Airborne, a Cellular Phone, a Smartphone, a Computer, or a Multimedia System capable of performing communication functions. In this disclosure, the terms "user equipment" and "UE" may be used interchangeably.

[0056] Additionally, in the present disclosure, a cell may represent an area covered by a single base station in wireless communication. Cells may be classified according to size into mega cells, macro cells, micro cells, pico cells, etc., but this is merely an example, and the types of cells are not limited to those described above.

[0057] In the present disclosure, a downlink (DL) may represent a wireless transmission path for a signal transmitted by a base station to a terminal, and an uplink (UL) may represent a wireless transmission path for a signal transmitted by a terminal to a base station. Additionally, a sidelink (SL) may exist, which refers to a wireless transmission path for a signal transmitted by a terminal to another terminal.

[0058] The terminal can connect to the AMF through the base station and exchange control plane signaling messages with the 5G core network. In addition, the terminal can connect to the UPF through the base station and exchange user plane data with the data network (DN).

[0059] DN may refer to a data network capable of providing operator services, internet access, or third-party services. In the following disclosure, NF, NF instance, network entity, and NF entity may be used interchangeably. That is, in the description below, the operation method of NF instance, network entity, and NF entity may correspond to the operation method of NF.

[0060] Network entities of an O-RAN may include Service Management Orchestration (SMO), non-Real Time RAN Intelligent Controller (non-RT RIC), near-Real Time RAN Intelligent Controller (near-RT RIC), Central Unit (O-CU), O-DU, and O-RU. However, the components of the O-RAN structure are not limited to the examples described above. For instance, the O-RAN structure may include more or fewer components than those described above. O-RAN refers to an open wireless access network that supports openness, interoperability, vendor neutrality, and network flexibility and scalability. An O-RAN may consist of an internal RAN structure composed of O-CU, O-DU, and O-RU, and an external RAN structure represented by RICs.

[0061] RIC can refer to a component that manages, controls, and optimizes RAN functions by utilizing Artificial Intelligence (AI) and Machine Learning (ML) technologies. RIC can be responsible for AI / ML functions. RIC can be classified into non-RT RIC and near-RT RIC.

[0062] A non-RT RIC can refer to a RIC that does not operate in real time. A non-RT RIC performs the management and control of a RAN in network situations where real-time response is not required, and can manage general aspects of network operations such as network resource allocation and service optimization.

[0063] rApp (Radio Application) can refer to AI / ML applications performed on non-RT RICs. rApps are used to provide specific radio services or functions, to efficiently utilize radio resources, and to control and optimize the radio aspects of a RAN.

[0064] A near-RT RIC can refer to a RIC that operates in real time. A near-RT RIC can make decisions or perform control tasks in real time to meet rapid and dynamic demands within a network, such as fault handling, interference management, and dynamic allocation of wireless resources.

[0065] xApp (Extended Application) may be an AI / ML application that runs on a near-RT RIC (230). In one embodiment, xApp may be an application used to extend and complement various functions of the RAN. xApp performs a wider range of functions than rApp and can be utilized for network management and optimization by applying AI / ML technology to more diverse and complex network functions.

[0066] FIG. 1 is a drawing for illustrating an AI / ML model according to one embodiment of the present disclosure.

[0067] Referring to Figure 1, AI / ML models are used in next-generation wireless communication systems such as 5G and 6G, which have higher performance and efficiency by utilizing artificial intelligence (AI) and machine learning (ML). AI / ML models can be used for network energy saving, load balancing, mobility optimization, etc.

[0068] For example, to reduce energy consumption at base stations, AI / ML models can be used to predict future energy efficiency or load conditions, enabling the implementation of corresponding energy reduction strategies. AI / ML models can be applied to fields such as location estimation, CSI prediction and precision improvement, and beam management and forecasting; this allows for increased accuracy in location measurements, conservation of resources consumed in CSI (channel state information) transmission, and efficient beam management.

[0069] AI / ML models can help solve complex modeling problems, model issues with non-linear characteristics, and address optimization problems with high implementation complexity. Technologies utilizing these AI / ML models are gradually being introduced into 5G mobile communication systems and are expected to become a core foundational technology and usage scenario in the upcoming 6G.

[0070] AI / ML models are characterized by being created through training. Here, being created through training may mean that a basic AI / ML model is trained by a learning algorithm using multiple training data, thereby creating predefined behavioral rules or an artificial intelligence model configured to perform desired characteristics (or objectives).

[0071] Such learning may be performed on the device itself, which includes the AI / ML model according to the present disclosure, or through a separate server and / or system. The trained AI model may be distributed among network functions, servers, and electronic devices. Examples of learning algorithms include, but are not limited to, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning.

[0072] An AI / ML model can be composed of multiple neural network layers. Each of the multiple neural network layers has multiple weight values, and can perform neural network operations through operations between the results of the previous layer and the multiple weights.

[0073] Multiple weights possessed by multiple neural network layers can be optimized based on the learning results of an AI / ML model. For example, multiple weights can be updated so that a loss value or cost value obtained from the AI / ML model during the learning process is reduced or minimized. In the embodiments of the present disclosure, a specific AI / ML model may be described as an example, but the method according to the embodiments of the present disclosure may be applied to various other neural network models.

[0074] For example, AI / ML models may include Bi-LSTM (Bidirectional long short-term memory) models, LSTM (long short-term memory) models, FCN (fully convolutional network), MLP-Mixer (Mixed Multi-Layer Perceptron) models, ResNet (Residual Network), RNN (Recurrent Neural Networks) based models, LSTM (Long Short-Term Memory), GRU (Gated Recurrented Unit), Autoencoder based models, GNN (Graph Neural Network) based models, Transformer based models, CNN based models, etc., but this is just one example of an AI / ML model and is not limited to the examples mentioned.

[0075] AI / ML models may include one-sided AI / ML models (101, 103, 107), two-sided AI / ML models (105), etc. One-sided AI / ML models (101, 103, 107) may be operated only at the terminal, only at the base station, or at both the terminal and the base station. Two-sided AI / ML models (105) are a pair of AI models in which joint inference is performed, and joint inference may be performed at the UE and the base station.

[0076] In this disclosure, for convenience of explanation, it is referred to as operation at a base station, but the AI / ML model of this disclosure may be operated at a network function of a core network instead of a base station, or may be operated at both a base station and a core network.

[0077] AI / ML models can be operated within the core network, such as NWDAF containing AnLF (Analytics logical function) and NWDAF containing MLTF (Model training logical function), which are network functions. NWDAF can play a role in collecting and analyzing data and providing necessary information, through which MNO can create a network that learns on its own and adapts to the environment.

[0078] AI / ML model training may be performed at the OAM, and AI / ML model inference may be performed at the base station. Alternatively, both AI / ML model training and AI / ML model inference may be performed at the base station.

[0079] Wireless communication systems can utilize AI / ML models to improve network performance. Using AI / ML models, wireless communication systems can analyze channel characteristics and optimize signals. Furthermore, using AI / ML models, wireless communication systems can analyze user behavior and preferences to provide personalized services and enhance the user experience.

[0080] Using AI / ML models, wireless communication systems can analyze network traffic and efficiently allocate network resources. Using AI / ML models, wireless communication systems can detect and recover from network failures.

[0081] By utilizing AI / ML models, wireless communication systems can enhance spectrum efficiency by optimizing dynamic resource allocation across multiple frequency bands and bandwidths. By using AI / ML models, wireless communication systems can support faster and more stable communication by utilizing more frequency bands and bandwidths.

[0082] Wireless communication systems can perform AI-based CSI prediction using AI / ML models. Wireless communication systems can perform beam prediction using AI / ML models and improve positioning tracking accuracy.

[0083] In O-RAN, the concept of RIC can be introduced to utilize AI / ML models. Non-RT RIC and near-RT RIC can operate within a set time frame (e.g., 1 second or longer, or 10 milliseconds to 1 second, respectively), and can manage RAN infrastructure using AI / ML.

[0084] FIG. 2 illustrates a wireless communication system according to one embodiment of the present disclosure.

[0085] Referring to Figure 2, AI / ML may require data input for training and inference (execution). For example, an AI / ML model can predict or compress Channel State Information (CSI) based on collected data. An AI / ML model may also be used to predict or optimize beam patterns based on collected data, or to dynamically adjust beams to match temporal variability or changes in user location. An AI / ML model may be used to predict cell signal quality degradation, predict handover failures, or predict radio link failures (RLF) based on collected data, and to minimize service downtime by optimizing handover timing. However, this is merely an example for convenience of explanation, and the applications of the AI / ML model are not limited.

[0086] A base station can collect or receive data from a terminal. The base station can transmit the collected data to a core network. Data collected in a wireless communication system can be used to train or run AI / ML models in a base station or a core network. The method of collecting data by a base station will be explained in detail with reference to FIGS. 3 through 6.

[0087] The data of the present disclosure may include at least one of L1 (Physical Layer) information, L2 information, or L3 information. For example, the data may include measurement information related to CSI (Channel State Information), CIR (Channel Impulse Response), SNR (Signal-to-Noise Ratio), RSRP (Reference Signal Received Power), RSRQ (Reference Signal Received Quality), SINR (Signal-to-Interference and Noise Ratio), RSTD (Reference Signal Time Difference), Rx-Tx time difference, interference, power, RLM (Radio Link Monitoring), RRM, TA (Timing Advance), etc., channel information, TRP (Transmission / Transmitter Point) location information, and other information transmitted through reporting procedures. However, this is merely an example for convenience of explanation and the data is not limited to the examples mentioned. For example, information disclosed in 3GPP standard specifications may also be collected as data. Radio signal information of the PHY standard specification (38.211: Physical Channels and Modulation), such as physical resource information, information disclosed in Section 4 Frame Structure, information disclosed in Section 6.3 Modulation, and information disclosed in Section 7.3 Physical Channel, may be collected as data. Control and radio quality signal information of the RRC standard specification (38.331: Radio Resource Control Protocol Specification), such as Section 5.Information disclosed in 2 System Information, information disclosed in Section 5.5 Measurements, information disclosed in Section 5.6 UE Capability, information disclosed in Section 6 Protocol Data Unit Formats and Parameters, information disclosed in Section 7 Variables and Constants, etc., may be collected as data.

[0088] For convenience of explanation, the present disclosure illustrates only the collection of information by a base station from a terminal, but the base station may collect data not only from the terminal but also from neighboring base stations. For example, the base station may collect prediction information such as predicted resource status information, feedback information such as UE performance feedback, measured UE trajectory, energy cost (EC), and other measurement information from neighboring base stations.

[0089] The trained AI / ML model can be transmitted from the core network to the base station or from the base station to the terminal. The base station, terminal, and core network can utilize the AI / ML model in the wireless communication system.

[0090] During the training of AI / ML models, adversarial machine learning can degrade their performance. For example, devices manufactured by different companies may possess various security vulnerabilities. These vulnerabilities can be exploited to collect false training data from hacked devices. Additionally, training data intended to intentionally attack AI / ML models may be collected from maliciously generated devices. Training AI / ML models using data collected from malicious or hacked devices can lead to problems, such as a decline in the model's performance or reliability. The model may overfit to contaminated training data or fail to process data in real-world environments. Furthermore, contaminated data can lead to incorrect inference results from the AI / ML model. Consequently, the demand for data security is steadily increasing.

[0091] In the LTM (Layer 1 / Layer 2 Triggered Mobility) related procedure, the terminal may report L1 measurement information to the base station via the MAC layer. The base station may determine whether mobility is required based on the L1 measurement report received from the UE. The base station may determine that mobility is required, such as when it is determined that the signal quality of the current cell is degrading or that a cell providing a better signal exists. In this case, if the L1 measurement report collected from the terminal is manipulated or unreliable, the base station may make an incorrect judgment. In the LTM (Layer 1 / Layer 2 Triggered Mobility) related procedure, if the base station decides to switch cells, the base station may transmit a cell switch command to the terminal using the MAC CE. Upon receiving the cell switch command, the terminal may switch to a target configuration using the LTM Candidate Configuration provided via the RRC and switch to the target cell. According to an embodiment of the present disclosure, the reliability of data transmitted from the terminal to the base station can be improved.

[0092] The present disclosure may provide a method for maintaining security regarding data collected for AI / ML in a wireless communication system. Additionally, a method for distinguishing between false training information and normal information for AI training operations in a wireless communication system may be provided.

[0093] According to one embodiment of the present disclosure, by transmitting a security policy related to data collection to a base station, the base station can verify the reliability of the terminal before performing data collection in accordance with the security policy related to data collection, thereby enabling the collection of reliable training data. In addition, the efficiency of resource utilization can be increased by reducing the probability of collecting contaminated or manipulated data. Resources can be used efficiently by reducing resource allocation for contaminated or manipulated data.

[0094] FIG. 3 illustrates a data collection method according to one embodiment of the present disclosure.

[0095] Referring to FIG. 3, in operation S310, the base station can receive a security policy for data collection from the core network.

[0096] The base station may receive a security policy for data collection from the core network (e.g., AMF). Instead of a security policy for data collection, terms such as a policy for trusted data collection, a policy for data integrity and security, a policy for secure data collection, or a policy for data reliability may be used instead.

[0097] In one embodiment, the security policy for data collection may include at least one of security requirements, such as a UE Requirement or a Data Requirement. The security policy for data collection may instruct to collect data from a UE that satisfies the UE Requirement, instruct to collect data from a UE that satisfies the Data Requirement, or instruct to collect data that satisfies the Data Requirement from a UE that satisfies the UE Requirement.

[0098] For example, UE requirements may require that the terminal satisfy at least one of the following: a UE that supports a TEE (trusted execution environment), a UE equipped with a TPM (trusted platform module), a UE that supports confidential computing, a UE verified by remote attestation, a UE that supports network security, or a UE that supports other functions for maintaining the integrity of the terminal.

[0099] Data requirements may require that the collected data satisfy at least one of the following: data processed by a TEE (trusted execution environment), data processed by a TPM (trusted platform module), data processed by confidential computing, data protected by network security, or data processed by a function that ensures the reliability of other data.

[0100] Instead of UE requirements, terms such as UE security requirements, UE condition, UE specifications, UE criteria, UE capability requirements, UE environment, and UE configuration may be used. Instead of data requirements, terms such as data security requirements, data condition, data processing specification, data criteria, data processing environment, and data configuration may be used.

[0101] In one embodiment, the security policy for data collection may include a policy related to the activation of a security data collection procedure. The policy related to the activation of the security data collection procedure may indicate whether to activate the security data collection procedure. If the policy related to the activation of the security data collection procedure indicates that it is required or is set to required, the base station must perform the security data collection procedure. For example, the base station and the terminal may perform operation S320 or the data collection method of FIG. 6. For convenience of explanation, some content that overlaps with FIG. 6 may be omitted.

[0102] If the policy regarding the activation of the security data collection procedure indicates "Preferred" or is set to "Preferred," the base station may determine whether to perform the security data collection procedure. If the policy regarding the activation of the security data collection procedure indicates "Not needed" or is set to "Not needed," the base station may collect data without the security data collection procedure.

[0103] In one embodiment, the security policy for data collection may include a security policy for verifying the integrity of the terminal. The security policy for verifying the integrity of the terminal may include at least one of information on whether a procedure for verifying the integrity of the terminal should be performed, or a verification periodicity. The procedure for verifying the integrity of the terminal will be described with reference to FIG. 5. For convenience of explanation, some content that overlaps with FIG. 5 may be omitted.

[0104] If the security policy for verifying the integrity of a terminal indicates that it is Required or is set to Required, the base station must perform a procedure for verifying the integrity of the terminal. For example, the base station may use Remote Attestation (RA) to verify the integrity of the terminal, such as whether the terminal has been tampered with. This may be suitable for situations requiring high security.

[0105] If the security policy for terminal integrity verification indicates or is set to Preferred, it is recommended that the base station perform the procedure for verifying the UE's integrity. The verification procedure is not mandatory but may be performed for additional security enhancement. This setting may be suitable for environments with a medium security priority.

[0106] If the security policy for verifying the integrity of the terminal indicates "Not needed" or is set to "Not needed," the base station does not perform the procedure for verifying the integrity of the UE. This can be used in environments where low reliability is acceptable or in situations where additional verification is not required.

[0107] If the security policy for verifying the integrity of the terminal indicates "Periodically" or is set to "Periodically," the base station can periodically perform procedures to verify the integrity of the UE. This allows for continuous security maintenance and rapid detection of potential threats through periodic verification.

[0108] In operation S320, the base station can determine whether to perform a data collection procedure.

[0109] The base station can determine whether to collect data from the terminal based on security policies.

[0110] In one embodiment, if the security policy for data collection includes security requirements, the base station may determine whether to collect data from the terminal based on whether the security requirements are satisfied. The security requirements may include at least one of UE requirements or data requirements.

[0111] If the security policy for data collection includes UE requirements, the base station may determine whether to collect data from a terminal based on whether the UE satisfies the UE requirements. For example, if the UE requirements stipulate 'a UE that supports TEE,' data may be collected from a terminal that supports TEE. In one embodiment, a method for determining whether to collect data from a secure terminal may be performed through the UE integrity verification procedure of FIG. 5, or a procedure to protect the data collection process using the encryption key of FIG. 6 may be performed. If the terminal does not support TEE, the base station may not collect data from the terminal or may perform other secure data collection procedures. For example, an integrity verification procedure, such as SW-based integrity verification, may be performed.

[0112] If the security policy for data collection includes data requirements, the base station may determine whether to collect data from the terminal based on whether the data satisfies the data requirements. For example, if the data requirements demand 'data protected by network security,' the base station may collect data from the terminal if the collected data is protected by network security. For example, the base station may perform a method of determining whether to collect data through the integrity verification procedure of the UE in FIG. 5, or perform a data collection procedure using the encryption key in FIG. 6. If the data is not protected by network security, the base station may not collect data from the terminal or may perform other data collection procedures.

[0113] In one embodiment, the security policy for data collection includes a security policy for verifying the integrity of the terminal, and when set to Required or Preferred, the base station may determine whether to collect data by performing a procedure for verifying the integrity of the terminal. Operation S320 may include operations S510 to S520. For convenience of explanation, some content that overlaps with FIG. 5 may be omitted.

[0114] In operation S330, the base station can perform a data collection procedure.

[0115] A base station may collect or receive data from a terminal. The data of the present disclosure may include at least one of L1 (Physical Layer) information, L2 information, or L3 information. For example, the data may include measurement information related to CSI (Channel State Information), CIR (Channel Impulse Response), SNR (Signal-to-Noise Ratio), RSRP (Reference Signal Received Power), RSRQ (Reference Signal Received Quality), SINR (Signal-to-Interference and Noise Ratio), RSTD (Reference Signal Time Difference), Rx-Tx time difference, interference, power, RLM (Radio Link Monitoring), RRM, TA (Timing Advance), etc., channel information, TRP (Transmission / Transmitter Point) location information, and other information transmitted through reporting procedures. However, this is merely an example for convenience of explanation and the data is not limited to the examples mentioned. For example, information disclosed in 3GPP standard specifications can also be collected as data. Radio signal information from the PHY standard specification (38.211: Physical Channels and Modulation), such as physical resource information, information disclosed in Section 4 Frame Structure, information disclosed in Section 6.3 Modulation, and information disclosed in Section 7.3 Physical Channel, can be collected as data. RRC standard specification (38.Control and radio quality signal information of 331: Radio Resource Control Protocol Specification), such as information disclosed in Section 5.2 System Information, information disclosed in Section 5.5 Measurements, information disclosed in Section 5.6 UE Capability, information disclosed in Section 6 Protocol Data Unit Formats and Parameters, and information disclosed in Section 7 Variables and Constants, can be collected as data.

[0116] For convenience of explanation, the present disclosure illustrates only the collection of information by a base station from a terminal, but the base station may collect data not only from the terminal but also from neighboring base stations. In one embodiment, the base station may collect prediction information such as predicted resource status information, feedback information such as UE performance feedback, measured UE trajectory, energy cost (EC), and other measurement information from neighboring base stations.

[0117] The collected data can be used to obtain outputs by training AI / ML models or by running AI / ML models. For example, data such as channel information can be used for CSI feedback using AI / ML models. Data such as L1 measurements can be used in AI / ML models that output LTM-related information. Data such as L1-RSRP measurements can be used in AI / ML models for beam management. Data such as CIR, SNR, RSRP, and TRP positions can be used in AI / ML models that predict position information. However, this is merely an example for convenience of explanation, and the AI / ML models, data inputs, outputs, and feedback of the present disclosure are not limited to the described contents.

[0118] According to an embodiment of the present disclosure, by collecting data such as measurement results or CSI from an authentic user device (Authentic UE), unnecessary resource allocation to a hacked, manipulated, or malicious UE in a communication system can be prevented, and AI / ML can be protected from adversarial machine learning.

[0119] FIG. 4 illustrates a data collection method according to one embodiment of the present disclosure.

[0120] Referring to FIG. 4, in at least one of operation S300a or operation S300b, the base station can receive UE capability information related to the security capability of the terminal.

[0121] The base station may receive UE capability information related to the security capability of the terminal to collect data from the UE or the core network. For example, the base station may receive UE capability information related to the security capability of the terminal to collect data from the AMF.

[0122] For example, UE capability information may include at least one of information regarding whether the terminal supports a trusted execution environment (TEE), information regarding whether the terminal supports a trusted platform module (TPM), information regarding whether the terminal supports confidential computing, information regarding whether the terminal can perform remote attestation, information regarding whether the terminal supports network security, information regarding the release version supported by the terminal, or information regarding whether the terminal supports other functions that maintain the integrity of the terminal.

[0123] A base station can identify at least one of the terminal's security capabilities or data processing environment based on UE capability information. For example, the base station can identify at least one of whether the terminal supports a trusted execution environment (TEE), whether the terminal supports a trusted platform module (TPM), whether the terminal supports confidential computing, whether the terminal can perform remote attestation, whether it supports network security, whether a specific release version is supported, or whether it supports other functions that maintain the integrity of the terminal. The base station can identify at least one of whether the collected data is data processed by a trusted execution environment (TEE), data processed by a trusted platform module (TPM), data processed by confidential computing, data protected by network security, or data processed by other functions that guarantee the reliability of the data.

[0124] Instead of security capability, terms such as protection capability, secure capability, defense capability, threat mitigation capability, and cybersecurity provision capability may be used.

[0125] In operation S310, the base station can receive a security policy for data collection from the core network.

[0126] The base station can receive a security policy for data collection from the AMF. Instead of a security policy for data collection, terms such as a policy for trusted data collection, a policy for data integrity and security, a policy for secure data collection, or a policy for data reliability may be used instead.

[0127] In one embodiment, the security policy for data collection may include at least one of security requirements, such as a UE Requirement or a Data Requirement. The security policy for data collection may instruct to collect data from a UE that satisfies the UE Requirement, instruct to collect data from a UE that satisfies the Data Requirement, or instruct to collect data that satisfies the Data Requirement from a UE that satisfies the UE Requirement.

[0128] For example, UE requirements may require that the terminal satisfy at least one of the following: a UE that supports a TEE (trusted execution environment), a UE equipped with a TPM (trusted platform module), a UE that supports confidential computing, a UE verified by remote attestation, a UE that supports network security, or a UE that supports other functions for maintaining the integrity of the terminal.

[0129] Data requirements may require that the collected data satisfy at least one of the following: data processed by a TEE (trusted execution environment), data processed by a TPM (trusted platform module), data processed by confidential computing, data protected by network security, or data processed by a function that ensures the reliability of other data.

[0130] Instead of UE requirements, terms such as UE security requirements, UE condition, UE specifications, UE criteria, UE capability requirements, UE environment, and UE configuration may be used. Instead of data requirements, terms such as data security requirements, data condition, data processing specification, data criteria, data processing environment, and data configuration may be used.

[0131] In one embodiment, the security policy for data collection may include a policy related to the activation of a security data collection procedure. The policy related to the activation of the security data collection procedure may indicate whether to activate the security data collection procedure. If the policy related to the activation of the security data collection procedure indicates that it is required or is set to required, the base station must perform the security data collection procedure. For example, the base station and the terminal may perform operation S320 of FIG. 3 or the data collection method of FIG. 6. For convenience of explanation, some content that overlaps with FIG. 3 and FIG. 6 may be omitted.

[0132] If the policy regarding the activation of the security data collection procedure indicates "Preferred" or is set to "Preferred," the base station may determine whether to perform the security data collection procedure. If the policy regarding the activation of the security data collection procedure indicates "Not needed" or is set to "Not needed," the base station may collect data without the security data collection procedure.

[0133] In one embodiment, the security policy for data collection may include a security policy for verifying the integrity of the terminal. The security policy for verifying the integrity of the terminal may include at least one of information on whether a procedure for verifying the integrity of the terminal should be performed, or a verification periodicity. The procedure for verifying the integrity of the terminal will be described with reference to FIG. 5. For convenience of explanation, some content that overlaps with FIG. 5 may be omitted.

[0134] If the security policy for verifying the integrity of a terminal indicates that it is Required or is set to Required, the base station must perform a procedure for verifying the integrity of the terminal. For example, the base station may use Remote Attestation (RA) to verify the integrity of the terminal, such as whether the terminal has been tampered with. This may be suitable for situations requiring high security.

[0135] If the security policy for terminal integrity verification indicates or is set to Preferred, it is recommended that the base station perform the procedure for verifying the UE's integrity. The verification procedure is not mandatory but may be performed for additional security enhancement. This setting may be suitable for environments with a medium security priority.

[0136] If the security policy for verifying the integrity of the terminal indicates "Not needed" or is set to "Not needed," the base station does not perform the procedure for verifying the integrity of the UE. This can be used in environments where low reliability is acceptable or in situations where additional verification is not required.

[0137] If the security policy for verifying the integrity of the terminal indicates "Periodically" or is set to "Periodically," the base station can periodically perform procedures to verify the integrity of the UE. This allows for continuous security maintenance and rapid detection of potential threats through periodic verification.

[0138] In operation S320, the base station can determine whether to perform a data collection procedure.

[0139] The base station can determine whether to collect data from the terminal based on security policies.

[0140] In one embodiment, if the security policy for data collection includes security requirements, the base station may determine whether to collect data from the terminal based on whether the security requirements are satisfied. The security requirements may include at least one of UE requirements or data requirements.

[0141] If the security policy for data collection includes UE requirements, the base station may determine whether to collect data from a terminal based on whether the UE satisfies the UE requirements. For example, if the UE requirements stipulate 'a UE that supports TEE,' data may be collected from a terminal that supports TEE. In one embodiment, a method for determining whether to collect data from a secure terminal may be performed through the UE integrity verification procedure of FIG. 5, or a procedure to protect the data collection process using the encryption key of FIG. 6 may be performed. If the terminal does not support TEE, the base station may not collect data from the terminal or may perform other secure data collection procedures. For example, an integrity verification procedure, such as SW-based integrity verification, may be performed.

[0142] If the security policy for data collection includes data requirements, the base station may determine whether to collect data from the terminal based on whether the data satisfies the data requirements. For example, if the data requirements demand 'data protected by network security,' the base station may collect data from the terminal if the collected data is protected by network security. A method to determine whether to collect data from a secure terminal may be performed through the integrity verification procedure of the UE in Fig. 5, or a procedure to protect the data collection process using the encryption key in Fig. 6 may be performed. If the data is not protected by network security, the base station may not collect data from the terminal or may perform other data collection procedures.

[0143] In one embodiment, the security policy for data collection includes a security policy for verifying the integrity of the terminal, and when set to Required or Preferred, the base station may determine whether to collect data by performing a procedure for verifying the integrity of the terminal. Operation S320 may include operations S510 to S520. For convenience of explanation, some content that overlaps with FIG. 5 may be omitted.

[0144] In operation S330, the base station can perform a data collection procedure.

[0145] A base station may collect or receive data from a terminal. The data of the present disclosure may include at least one of L1 (Physical Layer) information, L2 information, or L3 information. For example, it may include data secure boot, software package integrity check, etc. In the present disclosure, a remote attestation (RA) procedure may be described as an example for convenience of explanation, but embodiments of the present disclosure may be applied to other integrity verification procedures.

[0146] Through the Remote Attestation (RA) procedure, the base station can verify the integrity of the terminal, reduce security threats, and collect reliable data.

[0147] Operation S320 may include operations S510 to S570.

[0148] In operation S510, the base station can send a remote verification request message to the terminal.

[0149] The base station may determine whether to perform an integrity verification procedure based on at least one of a security policy and the security capability of the terminal. A security policy for data collection may include information on whether to perform an integrity verification procedure for the terminal.

[0150] For example, if a terminal supports an integrity verification procedure and a security policy requires or recommends performing the integrity verification procedure, the base station may perform the integrity verification procedure. If the security policy indicates that performing the integrity verification procedure is required: the base station may not collect data from terminals that do not satisfy the integrity verification conditions. If the security policy indicates that performing the integrity verification procedure is preferred: the base station may choose whether or not to collect data from terminals that do not support RA. For convenience of explanation, some content that overlaps with Figure 4 may be omitted.

[0151] If the terminal supports the RA procedure and the security policy requires or recommends performing an integrity verification procedure, the base station may decide to initiate the RA procedure and send a remote certification request message to the terminal.

[0152] In operation S520, the terminal can collect evidence.

[0153] Evidence can be used to prove the integrity of the terminal. The evidence may include an encrypted hash value and an encrypted Platform Configuration Register (PCR) associated with at least one of an operating system (OS), software, or application.

[0154] In operation S530, the terminal can transmit evidence to the base station.

[0155] The base station may receive evidence from the terminal. The evidence may include an encrypted hash value and an encrypted Platform Configuration Register (PCR) associated with at least one of an operating system (OS), software, or application.

[0156] In operation S540, the base station can send a remote authentication verification request message to the core network.

[0157] The base station may transmit a remote proof verification request message containing evidence received from the terminal to the core network (e.g., AMF). In this disclosure, the term verification may be used interchangeably with confirmation.

[0158] In operation S550, the core network can verify the evidence.

[0159] The core network can verify the integrity of the terminal based on evidence. The core network may include an AMF, UDM, AUSF, or other NFs. For example, a UDM or AUSF can verify the integrity of the terminal based on collected evidence.

[0160] The core network can decrypt the encrypted hash value or PCR and compare it with the hash value of the previously obtained operating system (OS), firmware (Firmware), software (SW), or application. For example, if the hash values ​​are identical, the core network can determine that the integrity verification condition is satisfied. In one embodiment, the core network can obtain a hash value associated with at least one of the operating system (OS), firmware (Firmware), software, or application being distributed at the time of distribution.

[0161] In operation S560, the core network can send a remote authentication acknowledgment response message to the base station.

[0162] The remote proof acknowledgment response message may include the result of verifying the integrity of the terminal. The base station may receive the remote proof acknowledgment response message from the core network.

[0163] In operation S570, the base station can determine whether to perform the data collection procedure.

[0164] The base station can verify the result of the verification regarding the integrity of the terminal in the remote proof acknowledgment response message. Based on the result of the verification regarding the integrity of the terminal, the base station can determine whether to perform data collection from the terminal. For example, if the verification result indicates the integrity of the terminal, the base station may decide to collect data from the terminal. If the verification result denies the integrity of the terminal, the base station may not collect data from the terminal.

[0165] Even after verification is complete, the base station may perform integrity verification procedures periodically or on an event basis in cases such as when abnormal behavior (e.g., abnormal data generation or excessive data transmission) is detected or unauthorized replication or hacking is suspected.

[0166] For convenience of explanation, FIG. 5 illustrates that the core network verifies the integrity of the terminal based on evidence, but the verification of the terminal's integrity may be performed by a base station rather than the core network, or by a third party (3) instead of the core network. rd It is also possible for a party to perform this. For example, the base station can perform integrity verification of the terminal using the received evidence, and can determine whether to perform the data collection procedure based on the verification result.

[0167] FIG. 6 illustrates a data collection method according to one embodiment of the present disclosure.

[0168] A base station can collect data through a key provisioning procedure. The key provisioning procedure may include procedures for generating, transmitting, sharing, or deriving encryption keys to protect data between the base station and the terminal.

[0169] In operation S601a, the base station can generate or derive an encryption key to protect data.

[0170] Base stations can enable RRC (Radio Resource Control) integrity protection to protect data collection.

[0171] In operation S601b, the base station can transmit key-related information to the terminal.

[0172] In one embodiment, key-related information may be transmitted via an AS Security Mode Command. The key-related information may include at least one of the key itself, or information indicating a generated key or a derived key. If the key itself is transmitted, it may be protected by an RRC Security Method.

[0173] In operation S601c, the base station can initiate RRC downlink ciphering.

[0174] In operation S602a, the terminal can store or derive a key to protect data.

[0175] The terminal can perform AS SMC integrity verification (Verify AS Security Mode Command Integrity). If the integrity verification is successful, the terminal can initiate RRC Integrity Protection and RRC Downlink Deciphering.

[0176] In operation S602b, the base station can receive an AS security mode command (Security Mode Complete) from the terminal.

[0177] In operation S603a, the terminal can collect data and apply a security method to the collected data.

[0178] The terminal can encrypt the collected data using a key.

[0179] In operation S603b, the terminal can transmit data to the base station.

[0180] In operation S603c, the base station can check the data.

[0181] The base station can perform verification on the collected data based on the key. The base station can perform decryption on the collected data using the key.

[0182] FIG. 7 illustrates data according to one embodiment of the present disclosure.

[0183] The data (700) of the present disclosure may include at least one of L1 (Physical Layer) information, L2 information, or L3 information. For example, the data may include measurement information related to CSI (Channel State Information), CIR (Channel Impulse Response), SNR (Signal-to-Noise Ratio), RSRP (Reference Signal Received Power), RSRQ (Reference Signal Received Quality), SINR (Signal-to-Interference and Noise Ratio), RSTD (Reference Signal Time Difference), Rx-Tx time difference, interference, power, RLM (Radio Link Monitoring), RRM, TA (Timing Advance), etc., channel information, TRP (Transmission / Transmitter Point) location information, and other information transmitted through reporting procedures. However, this is merely an example for convenience of explanation and the data is not limited to the examples mentioned. For example, information disclosed in 3GPP standard specifications can also be collected as data (700). Radio signal information of the PHY standard specification (38.211: Physical Channels and Modulation), such as physical resource information, information disclosed in Section 4 Frame Structure, information disclosed in Section 6.3 Modulation, information disclosed in Section 7.3 Physical Channel, etc., can be collected as data (700). Control and radio quality signal information of the RRC standard specification (38.331: Radio Resource Control Protocol Specification), such as Section 5.Information disclosed in 2 System Information, information disclosed in Section 5.5 Measurements, information disclosed in Section 5.6 UE Capability, information disclosed in Section 6 Protocol Data Unit Formats and Parameters, information disclosed in Section 7 Variables and Constants, etc., can be collected as data (700).

[0184] The collected data (700) may further include at least one of information regarding whether UE requirements are satisfied, information regarding whether data requirements are satisfied, UE verification status information, or data protection status information.

[0185] The collected data (700) may indicate whether UE requirements are satisfied. The collected data (700) may include information regarding at least one of whether the terminal supports a trusted execution environment (TEE), whether the terminal supports a trusted platform module (TPM), whether the terminal supports confidential computing, whether the terminal can perform remote attestation, whether network security is supported, whether a specific release version is supported, or whether other functions for maintaining the integrity of the terminal are supported.

[0186] The collected data (700) may indicate whether data requirements are satisfied. The collected data (700) may include information regarding at least one of whether the collected data is data processed by a TEE (trusted execution environment), data processed by a TPM (trusted platform module), data processed by confidential computing, data protected by network security, or data processed by other functions that guarantee the reliability of the data.

[0187] UE verification status information can indicate whether the UE has been verified through integrity verification procedures such as Remote Attestation (RA). Data protection status information can indicate whether the data is protected by network security, etc.

[0188] The collected data can be used to obtain outputs by training AI / ML models or by running AI / ML models. For example, data such as channel information can be used for CSI feedback using AI / ML models. Data such as L1 measurements can be used in AI / ML models that output LTM-related information. Data such as L1-RSRP measurements can be used in AI / ML models for beam management. Data such as CIR, SNR, RSRP, and TRP positions can be used in AI / ML models that predict position information. However, this is merely an example for convenience of explanation, and the AI / ML models, data inputs, outputs, and feedback of the present disclosure are not limited to the described contents.

[0189] FIG. 8 is a block diagram schematically illustrating the configuration of a terminal according to one embodiment of the present disclosure.

[0190] Referring to FIG. 8, the terminal (800) may be composed of a transceiver (810), a processor (830), and a memory (820). Depending on the communication method of the terminal (800) described above, the transceiver (810), the processor (830), and the memory (820) of the terminal (800) may operate. However, the components of the terminal (800) are not limited to the examples described above.

[0191] For example, the terminal (800) may include more or fewer components than the components described above. In one embodiment, the transceiver (810), the processor (830), and the memory (820) may be implemented in the form of a single chip. Additionally, the processor (830) may include one or more processors.

[0192] The terminal (800) can perform the operation or method of the terminal of FIGS. 1 to 7.

[0193] The transceiver unit (810) collectively refers to the receiver unit of the terminal (800) and the transmitter unit of the terminal (800), and can transmit and receive signals with at least one of another terminal, a base station, or a network function. The signals transmitted and received with the terminal or network function may include control information and data. To this end, the transceiver unit (810) may be composed of an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is one embodiment of the transceiver unit (810), and the components of the transceiver unit (810) are not limited to an RF transmitter and an RF receiver.

[0194] Additionally, the transceiver (810) can perform functions for transmitting and receiving signals through a wireless channel. For example, the transceiver (810) can receive a signal through a wireless channel and output it to a processor (830), and transmit the signal output from the processor (830) through a wireless channel.

[0195] The memory (820) can store programs and data necessary for the operation of the terminal (800). Additionally, the memory (820) can store control information or data included in signals obtained from a base station. The memory (820) may be composed of a storage medium or a combination of storage media such as ROM, RAM, hard disk, CD-ROM, and DVD. Additionally, the memory (820) may not exist separately but may be configured to be included in the processor (830). The memory (820) may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. Furthermore, the memory (820) can provide stored data upon the request of the processor (830).

[0196] The processor (830) can control a series of processes to enable the terminal (800) to operate according to the embodiments of the present disclosure described above. For example, the processor (830) can receive control signals and data signals through the transceiver (810) and process the received control signals and data signals. The processor (830) can transmit the processed control signals and data signals through the transceiver (810). Additionally, the processor (830) can write or read data to or from the memory (820). The processor (830) can perform the functions of the protocol stack required by the communication standard. To this end, the processor (830) may include at least one processor or microprocessor. In one embodiment, a part of the transceiver (810) or the processor (830) may be referred to as a communication processor (CP).

[0197] The processor (830) may be composed of one or more processors. In this case, the one or more processors may be general-purpose processors such as CPUs, APs, and DSPs (Digital Signal Processors), graphics-dedicated processors such as GPUs and VPUs (Vision Processing Units), or artificial intelligence-dedicated processors such as NPUs. For example, if one or more processors are artificial intelligence-dedicated processors, the artificial intelligence-dedicated processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.

[0198] According to an embodiment of the present disclosure, the processor (830) may include a processor that supports a Trusted Execution Environment (TEE), a Trusted Platform Module (TPM), confidential computing, etc. However, this is merely an example for illustrative purposes, and other security methods capable of maintaining the integrity and confidentiality of hardware and software may be used in the processor (830). FIG. 9 is a block diagram schematically illustrating the configuration of a base station according to an embodiment of the present disclosure.

[0199] Referring to FIG. 9, the base station (900) may be composed of a transceiver (910), a processor (930), and a memory (920). The transceiver (910), the processor (930), and the memory (920) of the base station (900) may operate according to the communication method of the base station (900) described above. However, the components of the base station (900) are not limited to the examples described above.

[0200] For example, the base station (900) may include more or fewer components than the components described above. In one embodiment, the transceiver (910), the processor (930), and the memory (920) may be implemented in the form of a single chip. Additionally, the processor (930) may include one or more processors.

[0201] The base station (900) can perform the operation or method of the base station or RAN of FIGS. 1 to 7 and can perform the configuration of the base station.

[0202] The transceiver unit (910) is a collective term for the receiver unit of the base station (900) and the transmitter unit of the base station (900), and can transmit and receive signals to and from terminal or network functions. The signals transmitted and received to and from terminal or network functions may include control information and data. To this end, the transceiver unit (910) may be composed of an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is one embodiment of the transceiver unit (910), and the components of the transceiver unit (910) are not limited to an RF transmitter and an RF receiver.

[0203] Additionally, the transceiver (910) can perform functions for transmitting and receiving signals through a wireless channel. For example, the transceiver (910) can receive a signal through a wireless channel and output it to a processor (930), and transmit the signal output from the processor (930) through a wireless channel.

[0204] The memory (920) can store programs and data necessary for the operation of the base station (900). Additionally, the memory (920) can store control information or data included in signals obtained from the base station. The memory (920) may be composed of a storage medium or a combination of storage media such as ROM, RAM, hard disk, CD-ROM, and DVD. Additionally, the memory (920) may not exist separately but may be configured to be included in the processor (930). The memory (920) may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. Furthermore, the memory (920) can provide stored data upon the request of the processor (930).

[0205] The processor (930) can control a series of processes to enable the base station (900) to operate according to the embodiments of the present disclosure described above. For example, the processor (930) can receive control signals and data signals through the transceiver (910) and process the received control signals and data signals. The processor (930) can transmit the processed control signals and data signals through the transceiver (910). Additionally, the processor (930) can write or read data to or from memory (920). The processor (930) can perform the functions of a protocol stack required by a communication standard. To this end, the processor (930) may include at least one processor or microprocessor. In one embodiment, a part of the transceiver (910) or the processor (930) may be referred to as a communication processor (CP).

[0206] The processor (930) may be composed of one or more processors. In this case, the one or more processors may be general-purpose processors such as CPUs, APs, and DSPs (Digital Signal Processors), graphics-dedicated processors such as GPUs and VPUs (Vision Processing Units), or artificial intelligence-dedicated processors such as NPUs. For example, if one or more processors are artificial intelligence-dedicated processors, the artificial intelligence-dedicated processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.

[0207] FIG. 10 is a block diagram schematically illustrating the configuration of a network function according to one embodiment of the present disclosure.

[0208] Referring to FIG. 10, the network function (1000) may be composed of a transceiver (1010), a processor (1030), and a memory (1020). Depending on the communication method of the network function (1000) described above, the transceiver (1010), the processor (1030), and the memory (1020) of the terminal (1000) may operate. However, the components of the terminal (1000) are not limited to the examples described above.

[0209] For example, the network function (1000) may include more or fewer components than the components described above. In one embodiment, the transceiver (1010), the processor (1030), and the memory (1020) may be implemented in the form of a single chip. Additionally, the processor (1030) may include one or more processors.

[0210] Network functions (1000) include Access and Mobility Management Function (AMF), Session Management Function (SMF), Network Repository Function (NRF), Network Data Analytics Function (NWDAF), Policy Control Function (PCF), Unified Data Management (UDM), Network Slice Selection Function (NSSF), Authentication Server Function (AUSF), Unified Data Repository (UDR), Application Function (AF), and It may be any one of DN (Data Network). Can be any of the following: Access and Mobility Management Function (AMF), Session Management Function (SMF), Network Repository Function (NRF), Network Data Analytics Function (NWDAF), Policy Control Function (PCF), Unified Data Management (UDM), Network Slice Selection Function (NSSF), Authentication Server Function (AUSF), Unified Data Repository (UDR), Application Function (AF), and Data Network (DN). there is. The network function (1000) can correspond to the core network, network entity, and network function of FIGS. 1 to 7.

[0211] The transceiver unit (1010) is a collective term for the receiver unit of the network function (1000) and the transmitter unit of the network function (1000), and can transmit and receive signals with at least one of a terminal, a base station, or other network function. The signals transmitted and received with the terminal, base station, or network function may include control information and data. To this end, the transceiver unit (1010) may be composed of an RF transmitter that up-converts and amplifies the frequency of a transmitted signal, and an RF receiver that low-noise amplifies a received signal and down-converts the frequency. However, this is one embodiment of the transceiver unit (1010), and the components of the transceiver unit (1010) are not limited to an RF transmitter and an RF receiver.

[0212] Additionally, the transceiver (1010) can perform functions for transmitting and receiving signals through a wireless channel. For example, the transceiver (1010) can receive a signal through a wireless channel and output it to a processor (1030), and transmit the signal output from the processor (1030) through a wireless channel.

[0213] The memory (1020) can store programs and data necessary for the operation of the network function (1000). Additionally, the memory (1020) can store control information or data included in signals obtained from the network function (1000). The memory (1020) may be composed of a storage medium or a combination of storage media such as ROM, RAM, hard disk, CD-ROM, and DVD. Additionally, the memory (1020) may not exist separately but may be configured to be included in the processor (1030). The memory (1020) may be composed of volatile memory, non-volatile memory, or a combination of volatile and non-volatile memory. Furthermore, the memory (1020) can provide stored data upon the request of the processor (1030).

[0214] The processor (1030) can control a series of processes to enable the network function (1000) to operate according to the embodiments of the present disclosure described above. For example, the processor (1030) can receive control signals and data signals through the transceiver (1010) and process the received control signals and data signals. The processor (1030) can transmit the processed control signals and data signals through the transceiver (1010). Additionally, the processor (1030) can write or read data to or from the memory (1020). The processor (1030) can perform the functions of the protocol stack required by the communication standard. To this end, the processor (1030) may include at least one processor or microprocessor. In one embodiment, a part of the transceiver (1010) or the processor (1030) may be referred to as a communication processor (CP).

[0215] The processor (1030) may be composed of one or more processors. In this case, the one or more processors may be general-purpose processors such as CPUs, APs, and DSPs (Digital Signal Processors), graphics-dedicated processors such as GPUs and VPUs (Vision Processing Units), or artificial intelligence-dedicated processors such as NPUs. For example, if one or more processors are artificial intelligence-dedicated processors, the artificial intelligence-dedicated processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.

[0216] According to an embodiment of the present disclosure, a method is provided for a base station to collect data in a wireless communication system. The method may include the step of receiving a security policy for data collection from a core network. The method may include the step of determining whether to perform data collection on a UE (user equipment) based on the security policy. The method may include the step of collecting data from the UE.

[0217] The method may include the step of receiving UE capability information related to the security capabilities of the UE from the UE or the core network.

[0218] The method may include a step of determining whether to perform an integrity verification procedure of the UE. If the method performs an integrity verification procedure of the UE, it may include a step of determining whether to perform data collection based on the result of the integrity verification of the UE.

[0219] The method may include the step of receiving evidence from the UE when performing an integrity verification procedure of the UE. The method may include the step of sending a message to the core network requesting the verification of the UE's integrity. The method may include the step of receiving the result of the UE's integrity verification from the core network.

[0220] The method may include a step of obtaining an encryption key. The method may include a step of transmitting information about the encryption key to a UE. The method may include a step of performing verification on collected data based on the encryption key.

[0221] The evidence may include an encrypted hash value and an encrypted Platform Configuration Register (PCR) associated with at least one of an operating system (OS), firmware (FW), software, or application.

[0222] Security policies for data collection may direct data collection from UEs that meet UE requirements.

[0223] Security policies for data collection may direct collection from UEs capable of generating data that satisfies data requirements.

[0224] The security policy for data collection may include information on whether to perform an integrity verification procedure of the above UE.

[0225] UE requirements may require that the UE satisfy at least one of the following: a UE supporting a TEE (trusted execution environment), a UE equipped with a TPM (trusted platform module), a UE supporting confidential computing, a UE with remote attestation, or a UE supporting network security.

[0226] Data requirements may require that the data satisfy at least one of the following: data processed by a TEE (trusted execution environment), data processed by a TPM (trusted platform module), data processed by confidential computing, or data protected by network security.

[0227] The collected data may further include at least one of information regarding whether UE requirements are satisfied, information regarding whether data requirements are satisfied, UE verification status information, or data protection status information.

[0228] According to an embodiment of the present disclosure, a base station for collecting data in a wireless communication system is provided. The base station may include a transceiver; and at least one processor connected to the transceiver. The at least one processor may receive a security policy for data collection from a core network. The at least one processor may determine whether to perform data collection on a UE (user equipment) based on the security policy. The at least one processor may collect data from the UE.

[0229] Embodiments of the present disclosure may be implemented or supported by one or more computer programs, and computer programs may be formed from computer-readable program code and stored on a computer-readable medium.

[0230] In embodiments of the present disclosure, “application” and “program” may represent one or more computer programs, software components, instruction sets, procedures, functions, objects, classes, instances, related data, or parts thereof suitable for implementation in computer-readable program code. “Computer-readable program code” may include various types of computer code, including source code, object code, and executable code.

[0231] "Computer-readable media" may include various types of media that can be accessed by a computer, such as ROM (read only memory), RAM (random access memory), hard disk drive (HDD), CD (compact disc), DVD (digital video disc), or various types of memory.

[0232] Additionally, the device-readable storage medium may be provided in the form of a non-transitory storage medium. Here, the 'non-transitory storage medium' is a tangible device and may exclude wired, wireless, optical, or other communication links that transmit transient electrical or other signals. Meanwhile, this 'non-transitory storage medium' does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily.

[0233] For example, a 'non-transient storage medium' may include a buffer in which data is temporarily stored. A computer-readable medium may be any available medium accessible by a computer and may include both volatile and non-volatile media, as well as removable and non-removable media. A computer-readable medium includes a medium in which data can be permanently stored and a medium in which data is stored and can be later overwritten, such as a rewritable optical disc or an erasable memory device.

[0234] According to one embodiment, the method according to the various embodiments disclosed in this document may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product.

[0235] Computer program products may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or distributed online (e.g., download or upload) through an application store or directly between two user devices (e.g., smartphones).

[0236] In the case of online distribution, at least a portion of a computer program product (e.g., a downloadable app) may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0237] The foregoing description of the present disclosure is for illustrative purposes only, and those skilled in the art will understand that modifications can be easily made to other specific forms without altering the technical spirit or essential features of the present disclosure. For example, suitable results may be achieved even if the described techniques are performed in a different order than described, and / or the components of the system, structure, device, circuit, etc. described are combined or assembled in a form different from the described method, or replaced or substituted by other components or equivalents.

[0238] Such programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, ROM (read-only memory), electrically erasable programmable read-only memory (EEPROM), magnetic disc storage devices, compact disc-ROM (CD-ROM), digital versatile discs (DVDs), or other forms of optical storage devices, magnetic cassettes. Alternatively, they may be stored in memory composed of some or all of these. Additionally, each constituent memory may include multiple units.

[0239] Additionally, the program may be stored on an attachable storage device that can be accessed via a communication network such as the Internet, Intranet, LAN (local area network), WAN (wide area network), or SAN (storage area network), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure through an external port. Additionally, a separate storage device on a communication network may be connected to a device performing an embodiment of the present disclosure.

[0240] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.

[0241] Therefore, the embodiments described above should be understood as exemplary in all respects and not limiting. For example, each component described as a single unit may be implemented in a distributed manner, and likewise, components described as distributed may be implemented in a combined form. For example, some steps of FIGS. 2 through 7 may be implemented in a combined form or in a distributed form.

[0242] The scope of the present disclosure is defined by the claims set forth below rather than by the detailed description above, and all modifications or variations derived from the meaning and scope of the claims and equivalent concepts thereof should be interpreted as being included within the scope of the present disclosure.

Claims

1. In a method for a base station to collect data in a wireless communication system, A step of receiving a security policy for data collection from a core network; A step of determining whether to perform data collection on UE (user equipment) based on the above security policy; and A method comprising the step of collecting data from the above UE.

2. In Paragraph 1, The security policy for the above data collection directs to collect the data from the said UE that satisfies the UE requirements, and A method in which the above UE requirements require that the UE satisfy at least one of a UE that supports a TEE (trusted execution environment), a UE equipped with a TPM (trusted platform module), a UE that supports confidential computing, a UE that has undergone remote attestation, or a UE that supports network security.

3. In any one of paragraphs 1 to 2, The security policy for the above data collection directs to collect the above data satisfying the data requirements from the UE, and A method in which the above data requirements require that the data satisfy at least one of data processed by a TEE (trusted execution environment), data processed by a TPM (trusted platform module), data processed by confidential computing, or data protected by network security.

4. In any one of paragraphs 1 to 3, the security policy for data collection includes information on whether to perform an integrity verification procedure of the UE, and The step of determining whether to perform data collection on the UE based on the above security policy is, A step of determining whether to perform the integrity verification procedure of the above UE; and A method comprising the step of determining whether to perform data collection based on the result of the integrity verification of the UE when performing the integrity verification procedure of the UE.

5. In Paragraph 4, the integrity verification procedure of the UE is, When performing the integrity verification procedure of the above UE, the step of receiving evidence from the above UE; A step of transmitting a message to the core network requesting the integrity verification of the UE; and A method comprising the step of receiving a result of an integrity verification of the UE from the core network.

6. The method of claim 5, wherein the evidence comprises an encrypted hash value and an encrypted Platform Configuration Register (PCR) associated with at least one of an operating system (OS), firmware (FW) software, or application.

7. A method according to any one of claims 1 to 6, further comprising the step of receiving UE capability information related to the security capability of the UE from the UE or the core network.

8. In any one of claims 1 to 7, the collected data is A method comprising at least one of information regarding whether UE requirements are satisfied, information regarding whether data requirements are satisfied, UE verification status information, or data protection status information.

9. In any one of claims 1 to 8, the step of obtaining an encryption key; A step of transmitting information about the encryption key to the UE; and A method comprising further a step of performing verification on collected data based on the above encryption key.

10. A base station that collects data in a wireless communication system, A transceiver; and at least one processor connected to the transceiver, The above-mentioned at least one processor is, Receive a security policy for data collection from the core network; Based on the above security policy, determine whether to perform data collection on the UE (user equipment); A base station that collects data from the above UE.

11. In Paragraph 10, The security policy for the above data collection directs to collect the data from the said UE that satisfies the UE requirements, and A base station that requires the above UE requirements to satisfy at least one of a UE that supports a TEE (trusted execution environment), a UE equipped with a TPM (trusted platform module), a UE that supports confidential computing, a UE that has undergone remote attestation, or a UE that supports network security.

12. In any one of paragraphs 10 to 11, The security policy for the above data collection directs to collect the above data satisfying the data requirements from the UE, and A base station that requires the data to satisfy at least one of the following data requirements: data processed by a TEE (trusted execution environment), data processed by a TPM (trusted platform module), data processed by confidential computing, or data protected by network security.

13. In any one of claims 10 to 12, the security policy for data collection includes information on whether to perform an integrity verification procedure of the UE, and The above at least one processor, in determining whether to perform data collection on the UE based on the security policy, Determine whether to perform the integrity verification procedure of the above UE; A base station that determines whether to perform data collection based on the result of the integrity verification of the UE when performing the integrity verification procedure of the UE.

14. In claim 13, the integrity verification procedure of the UE is, When performing the integrity verification procedure of the above UE, receiving evidence from the above UE; Sending a message to the core network requesting the integrity verification of the UE; and A base station comprising receiving the result of the integrity verification of the UE from the core network.

15. In claim 14, the evidence comprises an encrypted hash value and an encrypted PCR (Platform Configuration Register) associated with at least one of an operating system (OS), software, or application.