Federated learning (FL) in artificial intelligence (AI) and machine learning (ML)
Secure authorization procedures for FL members using access tokens address security vulnerabilities in wireless communications systems by controlling access to AI/ML services and resources, reducing unauthorized access and threats.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- LENOVO UNITED STATES INC
- Filing Date
- 2026-03-24
- Publication Date
- 2026-07-30
AI Technical Summary
Wireless communications systems lack sufficient authorization and verification procedures for federated learning (FL), leading to security vulnerabilities such as data breaches, model theft, and adversarial attacks due to unauthorized access to FL resources.
Implement secure authorization procedures for FL members by issuing access tokens with specific claims, enabling secure FL member registration, event subscription, and training, using an authorization server to validate credentials and control access to AI/ML services and resources.
Reduces unauthorized access to AI/ML services and resources, minimizing security threats and unauthorized resource usage in wireless communications systems.
Smart Images

Figure IB2026052855_30072026_PF_FP_ABST
Abstract
Description
Lenovo Ref. No. SMM920240311-WO-PCT1FEDERATED LEARNING (FL) IN ARTIFICIAL INTELLIGENCE (Al) AND MACHINE LEARNING (ML)RELATED APPLICATION
[0001] This application claims priority to U.S. Non-Provisional Application Serial No.19 / 091,696 filed 26 March 2025 entitled “FEDERATED LEARNING (FL) IN ARTIFICIAL INTELLIGENCE (Al) AND MACHINE LEARNING (ML),” the disclosure of which is incorporated by reference herein in its entirety.TECHNICAL FIELD
[0002] The present disclosure relates to wireless communications, and more specifically to artificial intelligence (Al) and machine learning (ML) (AI / ML) in wireless communications.BACKGROUND
[0003] A wireless communications system may include one or multiple network communication devices, which may be otherwise known as network equipment (NE), supporting wireless communications for one or multiple user communication devices, which may be otherwise known as user equipment (UE), or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communication system (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like)). Additionally, the wireless communications system may support wireless communications across various radio access technologies including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, among other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY
[0004] An article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT2and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on”. Further, as used herein, including in the claims, a “set” may include one or more elements.
[0005] An apparatus (e.g., NE, network function) for wireless communication is described. The apparatus may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the apparatus may be configured to, capable of, or operable to receive a first message including a request for an access token, where the first message includes first AI / ML information associated with federated learning (FL); and transmit a second message including the access token, where the access token includes second AI / ML information associated with EL.
[0006] A processor (e.g., a standalone processor chipset, or a component of an apparatus (e.g., NE, network function)) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. Lor example, the processor may be configured to, capable of, or operable to receive a first message including a request for an access token, where the first message includes first AI / ML information associated with EL; and transmit a second message including the access token, where the access token includes second AI / ML information associated with EL.
[0007] A method performed or performable by an apparatus (e.g., NE, network function) for wireless communication is described. The method may include receiving a first message including a request for an access token, where the first message includes first AI / ML information associated with EL; and transmitting a second message including the access token, where the access token includes second AI / ML information associated with EL.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT3
[0008] In some implementations of the apparatus, the processor, and the method described herein, the first AI / ML information associated with FL includes information associated with one or more of: FL member registration service; FL member registration update service; FL events subscription service; FL events notification service; horizontal HFL training service; FL member grouping service; or vertical FL training service.
[0009] In some implementations of the apparatus, the processor, and the method described herein, the access token includes token claims for one or more of: FL member registration; FL events notification; horizontal FL (HFL) training; FL member grouping; FL member ID;FL member type (server or client); FL member capabilities; FL related events ID or name; FL type; FL task information; allowed list of member client IDs / client list; allowed location information for member client selection; FL service area of interest; allowed ML model ID list / ML model information for FL; allowed ML model training notification target address; ML model selection filtering criteria; FL member location information; analytics ID; issuer claim as an authorization server ID or an AIMLE server ID FL member; or vertical FL (VFL) training.
[0010] In some implementations of the apparatus, the processor, and the method described herein, the apparatus, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to receive a third message including an AI / ML model training request, where the third message includes security information including one or more of security credentials, authorization information, or the access token; determine one or more FL members based at least in part on a verification of the security information; and transmit, based at least in part on the determined one or more FL members, a fourth message including an AI / ML training response.
[0011] In some implementations of the apparatus, the processor, and the method described herein, the AI / ML model training request is associated with horizontal FL.
[0012] In some implementations of the apparatus, the processor, and the method described herein, the apparatus, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to receive a third message including a FL grouping request, where the third message includes security information including one or more of security credentials, authorization information, or the access token; obtain, based at least in part onAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT4verification of the security information, FL member information; and transmit, based at least in part on the FL member information, a fourth message including a FL grouping response.
[0013] In some implementations of the apparatus, the processor, and the method described herein, the NE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to receive a third message including an AI / ML model training request, where the third message includes one or more client selection criteria and security information including one or more of security credentials, authorization information, or the access token; select one or more FL clients based at least in part on a verification of the security information and the one or more client selection criteria; and transmit, based at least in part on the selected one or more FL clients, a fourth message including an A I / ML training response.
[0014] In some implementations of the apparatus, the processor, and the method described herein, the AI / ML model training request is associated with vertical FL.
[0015] In some implementations of the apparatus, the processor, and the method described herein, the NE includes an AI / ML server or an AI / ML enabler (AIMLE) server.
[0016] An apparatus (e.g., NE, network function) for wireless communication is described. The apparatus may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the apparatus may be configured to, capable of, or operable to receive a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and transmit a second message including a FL member registration response.
[0017] A processor (e.g., a standalone processor chipset, or a component of an apparatus (e.g., NE, network function)). The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to receive a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and transmit a second message including a FL member registration response.
[0018] A method performed or performable by an apparatus (e.g., NE, network function) for wireless communication is described. The method may include receiving a first message including aAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT5registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and transmitting a second message including a FL member registration response.
[0019] In some implementations of the apparatus, the processor, and the method described herein, the apparatus, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to receive a third message including a FL event subscription request, where the third message includes one or more of the security credentials, the authorization information, or the access token; perform authorization for FL event subscription based at least in part on the one or more of the security credentials, the authorization information, or the access token; and transmit, based at least in part on the authorization for FL event subscription, a fourth message including a FL event subscription response.
[0020] In some implementations of the apparatus, the processor, and the method described herein, the apparatus includes an AI / ML repository.
[0021] In some implementations of the apparatus, the processor, and the method described herein, the security credentials include a client certificate or a root certificate configured to validate the client certificate.
[0022] An apparatus (e.g., NE, network function, UE) for wireless communication is described. The apparatus may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the apparatus may be configured to, capable of, or operable to transmit a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and receive a second message including a FL member registration response.
[0023] A processor (e.g., a standalone processor chipset, or a component of a NE and / or a UE) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to transmit a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and receive a second message including a FL member registration response.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT6
[0024] A method performed or performable by a NE and / or a UE for wireless communication is described. The method may include transmitting a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and receiving a second message including a FL member registration response.
[0025] In some implementations of the apparatus, the processor, and the method described herein, the UE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to transmit a third message including a FL event subscription request, where the third message includes one or more of the security credentials, the authorization information, or the access token; and receive, based at least in part on the FL event subscription request, a fourth message including a FL event subscription response.
[0026] In some implementations of the apparatus, the processor, and the method described herein, the apparatus includes one or more of a vertical application layer (VAL) server, AI / ML client, AIMLE client, AIMLE server, or an AI / ML server.
[0027] In some implementations of the apparatus, the processor, and the method described herein, the security credentials include a client certificate or a root certificate configured to validate the client certificate.
[0028] An apparatus (e.g., an NE, a UE) for wireless communication is described. The apparatus may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the apparatus may be configured to, capable of, or operable to transmit a first message including a FL grouping request, where the first message includes one or more of authentication information or an access token; and receive a second message including a FL grouping response.
[0029] A processor (e.g., a standalone processor chipset, or a component of an apparatus (e.g., an NE, a network function)) for wireless communication is described. The processor may be configured to, capable of, or operable to perform one or more operations as described herein. For example, the processor may be configured to, capable of, or operable to transmit a first message including a FL grouping request, where the first message includes one or more of authentication information or an access token; and receive a second message including a FL grouping response.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT7
[0030] A method performed or performable by an apparatus (e.g., an NE, a network function) for wireless communication is described. The method may include transmitting a first message including a FL grouping request, where the first message includes one or more of authentication information or an access token; and receiving a second message including a FL grouping response.
[0031] In some implementations of the apparatus, the processor, and the method described herein, the NE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to transmit a third message including an AI / ML model training request, where the third message includes security information including one or more of security credentials, authorization information, or the access token; and receive, based at least in part on the AI / ML model training request, a fourth message including an A I / ML training response.
[0032] In some implementations of the apparatus, the processor, and the method described herein, the AI / ML model training request is associated with horizontal FL.
[0033] In some implementations of the apparatus, the processor, and the method described herein, the NE, the processor, and the method may further be configured to, capable of, operable to, performed to, or performable to transmit a third message including an AI / ML model training request, where the third message includes one or more client selection criteria and security information including one or more of security credentials, authorization information, or the access token; and receive, based at least in part on the AI / ML model training request, a fourth message including an AI / ML training response.
[0034] In some implementations of the apparatus, the processor, and the method described herein, the AI / ML model training request is associated with vertical FL.
[0035] In some implementations of the apparatus, the processor, and the method described herein, the apparatus includes a VAL server.BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.
[0037] Figure 2 illustrates an example system in accordance with aspects of the present disclosure.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT8
[0038] Figure 3 illustrates an example system in accordance with aspects of the present disclosure.
[0039] Figure 4 illustrates an example system in accordance with aspects of the present disclosure.
[0040] Figure 5 illustrates a system in accordance with aspects of the present disclosure.
[0041] Figure 6 illustrates a system in accordance with aspects of the present disclosure.
[0042] Figure 7 illustrates a system in accordance with aspects of the present disclosure.
[0043] Figure 8 illustrates a system in accordance with aspects of the present disclosure.
[0044] Figure 9 illustrates a system in accordance with aspects of the present disclosure.
[0045] Figure 10 illustrates an example of a UE in accordance with aspects of the present disclosure.
[0046] Figure 11 illustrates an example of a processor in accordance with aspects of the present disclosure.
[0047] Figure 12 illustrates an example of an NE in accordance with aspects of the present disclosure.
[0048] Figure 13 illustrates a flowchart of a method in accordance with aspects of the present disclosure.
[0049] Figure 14 illustrates a flowchart of a method in accordance with aspects of the present disclosure.
[0050] Figure 15 illustrates a flowchart of a method in accordance with aspects of the present disclosure.
[0051] Figure 16 illustrates a flowchart of a method in accordance with aspects of the present disclosure.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT9DETAILED DESCRIPTION
[0052] In a wireless communications system, a UE and an NE (e.g., a base station, gNB) may support wireless communication (e.g., reception and / or transmission of wireless communication) using time-frequency resources. By using time-frequency resources, wireless communications systems can utilize AI / ML (which may also be referred to herein as “Al” or “ML”) for a variety of different purposes, such as for network operation, network optimization, automated processing (e.g., self-driving cars in vehicle to everything (V2X) scenarios), network planning, security information and event management (SIEM), etc. AI / ML can leverage AI / ML models (which may be referred to herein as “models”), which represent programs and / or algorithms trained on a set of data to provide outputs, such as to recognize patterns, make decisions, generate content, etc. AI / ML models, for instance, can apply different algorithms to data inputs to provide data output for performing different tasks.
[0053] AI / ML models can be trained in different ways to enable the models to perform different wireless communications tasks, including training via distributed learning (DL) and FL. In DL, training data and inference data can be distributed across multiple systems and devices, and training tasks can be performed across the multiple systems and devices. In FL, models can be trained on local systems and / or devices, where training data can be protected from possible exposure to external entities. FL can thus provide increased data security, such as compared with other training modalities such as DL.
[0054] In some wireless communications systems, an AIMLE service framework supports procedures for FL member registration, FL-related event subscription, HFL training, FL member grouping, and VFL. Some wireless communications systems, however, do not support sufficient authorization and verification, which can result in security vulnerabilities. In one example, a candidate FL member (e.g., VAL server, AIMLE server) can register to an ML registry and subscribe to FL related events notifications. However, an unauthorized entity obtaining access to FL resources (e.g., registering to an FL process, performing HFL or VFL, being part of a FL group to perform FL processes) and consuming the FL events information related to the ML models for which the member has no authorization can lead to security vulnerabilities such as data breaches, model theft, data poisoning, and adversarial attacks, which may result in security and operational disruptions.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT10
[0055] Aspects of the present disclosure are described in the context of a wireless communications system and include implementations that provide a secure environment in which different ML model tasks can be performed. In implementations, procedures are described to authorize a client (AIMLE client, VAL server, VAL UE) to participate in FL of models that participate in different AI / ML tasks in a wireless communications environment. By performing the described techniques, a wireless communications system can implement secure procedures for controlling access to different AI / ML services and resources. The described techniques can reduce unauthorized access to AI / ML services and resources, which can reduce security threats and reduce unauthorized resource usage in wireless communications systems that utilize AI / ML functionality.
[0056] Reference is made herein to communicating data or information, such as signaling communication resources and / or communications that are transmitted or received between devices. It is to be appreciated that other terms may be used interchangeably with communicating, such as signaling, transmitting, receiving, outputting, forwarding, retrieving, obtaining, and so forth.
[0057] Aspects of the present disclosure are described in the context of a wireless communications system.
[0058] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more NEs 102, one or more UEs 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a 4G network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a NR network, such as a 5G network, a 5G-Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT11
[0059] The one or more NEs 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NEs 102 described herein may be or include or may be referred to as a network node, a base station, an access point (AP), a network element, a network function, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, which may be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.
[0060] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.
[0061] The one or more UEs 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of-Everything (loE) device, or machine-type communication (MTC) device, among other examples.
[0062] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle-to-vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular-V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT12
[0063] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N6, or other network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, the NE 102 may communicate with each other indirectly (e.g., via the CN 106). In some implementations, one or more NEs 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as radio heads, smart radio heads, or transmission-reception points (TRPs).
[0064] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME), an access and mobility management function (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a packet data network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NEs 102 associated with the CN 106.
[0065] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N6, or other network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).
[0066] In the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100 (e.g., time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers)) to perform Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT13various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.
[0067] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0068] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0069] Additionally, or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, / =l , / r=2, / r=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT14subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols. The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., / r=0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0070] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.
[0071] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing; a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing; and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing; and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.
[0072] According to implementations, one or more of the NEs 102 and the UEs 104 are operable to implement various aspects of the techniques described with reference to the present Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT15disclosure. For example, an NE 102 (e.g., a network function) receives (e.g., from another NE 102 and / or a UE 104) a first message including a request for an access token, where the first message includes first Al / ML information associated with FL. The NE 102 transmits a second message including the access token, where the access token includes second AI / ML information associated with FL.
[0073] According to implementations, an NE 102 receives a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token. The NE 102 transmits a second message including a FL member registration response.
[0074] According to implementations, an NE 102 or a UE 104 transmits a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token. The NE 102 or the UE 104 receives a second message including a FL member registration response.
[0075] According to implementations, an NE 102 transmits a first message including a FL grouping request, where the first message includes one or more of authentication information or an access token. The NE 102 receives a second message including a FL grouping response.
[0076] Reference is made herein to communicating data or information, such as signaling communication resources and / or communications that are transmitted or received between devices. It is to be appreciated that other terms may be used interchangeably with communicating, such as signaling, transmitting, receiving, outputting, forwarding, retrieving, obtaining, and so forth.
[0077] Figure 2 illustrates an example system 200 in accordance with aspects of the present disclosure. The system 200 represents an example on-network functional model of AI / ML enablement (AIMLE). In a VAL 202, a VAL client 204 (e.g., as part of a UE 104) communicates via a 3GPP network system 206 with VAL servers 208 over a VAL-UU reference point 210. VAL-UU can support unicast and multicast delivery modes. The AIMLE functional entities on the UE 104 and the server are grouped into AIMLE clients 212 and AIMLE servers 214, respectively.
[0078] At a service enabler architecture layer (SEAL) 216 for verticals, the system 200 includes a common set of services for AIML functionality, including FL and distributed learning (e.g., FL client registration management, FL client discovery and selection), and reference points. The Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT16AIMLE services can be provided to the VAL 202. The AIMLE clients 212 can communicate with the AIMLE servers 214 over AIML-UU reference points 218. The AIMLE clients 212 can provide functionality to the VAL client 204 over an AIML-C reference point 220. The VAL servers 208 can communicate with the AIMLE servers 214 over AIML-S reference points 222. The AIMLE servers 214 communicate with the 3GPP network system 206 using 3GPP network interfaces 224 specified by the 3GPP network system 206. An AIML-E reference point 228 enables interactions between multiple AIMLE servers 214, e.g., between central and edge AIMLE servers 214. An AIMLE server 214 can interact with an AI / ML repository 230, which serves as a repository for AI / ML models and AI / ML participants over AIML-R 232.
[0079] Figure 3 illustrates an example system 300 in accordance with aspects of the present disclosure. The system 300 represents an example off-network functional model of AIMLE. In a VAL 302, a VAL client 304a at a VAL UE 306a communicates with a VAL client 304b at a VAL UE 306b over VAL-PC5 reference point 308. VAL-PC5 can support unicast and multicast delivery modes. The VAL UE 306a, if connected to the network via a Uu reference point, can also act as a UE-to-network relay to enable the VAL UE 306b to access VAL servers over a VAL-UU reference point. An AIMLE client 310a at the VAL UE 306a can communicate with an AIMLE client 310b at the VAL UE 306b over AIML-PC5 reference points 312. An AIMLE client 310 can provide functionality to the VAL clients 304 over AIML-C reference points 314. Such communication can support local AI / ML operations (training, distribution, inference) in a coordinated manner.
[0080] The present disclosure includes solutions for EL in AI / ML. Lor instance, solutions are provided to secure access to EL resources in wireless communications systems.
[0081] Figure 4 illustrates an example system 400 in accordance with aspects of the present disclosure. The system 400 can be implemented to authorize a client 402 (e.g., AIMLE client, VAL server, VAL UE) to perform EL enabler service management. Examples of EL enabler service management include EL member registration, EL member registration update, EL related event subscription, notification, HEL training, EL member grouping, supporting VEL services, etc. EL enabler service management may be associated with EL of model information related to one or more ML model ID(s) or analytics ID(s). Authorization of the client 402 can be performed via interaction with an authorization server 404 (e.g., a SIM server, AIMLE server, SEAL server) by issuing an access token or authorization information.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT17
[0082] In the system 400: At step (0), the client 402 and the authorization server 404 perform mutual authentication. At step (1), the client 402 communicates an access token request to the authorization server 404. The access token request may include information such as an ID of the client 402 (e.g., requestor identifier) and FL enabler service information. At step (2), and based on the access token request, the authorization server 404 generates an access token with claims that are specific to the FL enabler service information. At step (3), the authorization server 404 communicates an access token response to the client 402 that includes the access token.
[0083] In implementations, to obtain an access token (and optionally a refresh token) the client 402 (SEAL client, AIMLE client, VAL Server, VAL UE) can communicate a constrained application protocol (CoAP) request to the authorization server 404 token endpoint by sending the parameters from Table 1 below using the “application / ace+cbor” content format and with a concise binary object representation (CBOR) map in the CoAP payload. Alternatively, or in addition, the access token request can be any of AIMLE service access token request or AIMLE FL service access token request.Table 1
[0084] For an access token response, if the access token request is valid and authorized, the authorization server 404 can return an access token (and optionally a refresh token) to the client 402Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT18in an access token response message; otherwise, it may return an error. Table 2 includes example access token response parameters.Table 2
[0085] In implementations, the client 402 may use the access token to make protected and authorized requests to the authorization server 404. Implementations, such as described with reference to the system 400, can be used for an access request related to FL member registration request or FL member registration update request, e.g., using the following adaptations. The client 402 can obtain, in the step (3) access token response message, authorization information or an access token which can include access token claims such as FL member ID as subject, FL member registration service as scope, FL member type (server or client), FL member capabilities, FL related events ID or name, FL type, FL task information, allowed list of member client IDs / client list, allowed location information for member client selection, FL service area of interest, allowed ML model ID list / ML model information for FL, allowed ML model training notification target address, Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT19ML model selection filtering criteria, FL member location information, issuer claim as authorization server ID / AIMLE server ID, etc. This information may be received from the authorization server 404 when the access token request in step (1) indicates FL member registration service in the access token request message.
[0086] In such implementations, the access token request can include an information element (IE) as described herein, and based on local configuration or authorization information available, the authorization information or the access token claims can additionally include the received information from the access token request.
[0087] In implementations, the system 400 can be used for access requests related to FL related events subscription or notification request, e.g., with the following adaptations. The client 402 can obtain, in the step (3) access token response message, authorization information or an access token which can include claims requestor ID as subject, FL-related event subscription service as scope, FL member type (server or client), FL related events ID or name, FL type, FL member ID, FL task information, allowed list of member client IDs / client list, allowed location information for member client selection, allowed ML model ID list / ML model information for FL, allowed ML model training notification target address, ML model selection filtering criteria, issuer claim as authorization server ID / AIMLE server ID / SEAL server ID, etc. This information can be received from the authorization server 404 when the access token request in step (1) indicates FL related events subscription or notification service in the access token request message.
[0088] In such implementations, the access token request can include IES as described herein, and based on local configuration or authorization information, the authorization server 404 can generate the authorization information or the access token claims to additionally include received information from the access token request.
[0089] In implementations, the system 400 can be used for access requests related to HFL training service requests, e.g., with the following adaptations. The client 402 can obtain, in the step (3) access token response message, authorization information or an access token which can include claims requestor ID as subject, HFL training service as scope, AIML model (e.g., model ID / type) and model parameters, dataset ID(s), allowed FL members (allowed list of member client IDs) to use as Al MLE clients for HFL or ML model training, training type (VFL or HFL, or both VFL andAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT20HFL), allowed Al MLE client selection / filtering criteria, allowed ML model ID list / ML model information for training, ML model selection filtering criteria, issuer claim as authorization server ID / AIMLE server ID / SEAL server ID, etc. This information may be obtained from the authorization server 404 when the access token request in step (1) indicates HEL training service in the access token request message.
[0090] In implementations where the access token request includes IES as described herein, the authorization server, based on local configuration or authorization information, can generate the authorization information or access token claims to additionally include received information from the access token request.
[0091] In implementations, the system 400 can be used for an access request related to FL member grouping service request, e.g., with the following adaptations. The client 402 may obtain, in the step (3) access token response message, authorization information or an access token that can include claims requestor ID as subject, FL member grouping service as scope, VAL service ID, service area information, AIML model (e.g., model ID / type), application data analytics and enablement (ADAE) analytics ID, ML model profile information (e.g., ID for which the FL grouping is to be used), ML task information / ID (e.g., FL training task or FL inference task), allowed FL members (allowed list of member client IDs) to use as Al MLE clients / server for FL, training type (VFL or HFL, or both VFL and HFL), allowed Al MLE client selection / filtering criteria, allowed ML model ID list / ML model information for training, FL / ML model selection filtering criteria, issuer claim as authorization server ID / AIMLE Server ID / SEAL server ID, etc. This information may be received from the authorization server 404 when the access token request in step (1) indicates FL member registration service in the access token request message.
[0092] In such implementations, the access token request can include an IE as described herein, and based on local configuration or authorization information available, the authorization information or the access token claims can additionally include the received information from the access token request.
[0093] In implementations, the system 400 can be used for access requests related to VFL Training service requests, e.g., with the following adaptations. The client 402 may obtain, in the step (3) access token response message, authorization information or an access token which canAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT21include claims requestor ID as subject, VFL training service as scope, AIML model (e.g., model ID / type) and model parameters, feature information, dataset ID(s), allowed different data domains information, allowed FL members (allowed list of member client IDs) to use as Al MLE clients for VFL model training (e.g., per domain), training type (VFL), allowed Al MLE client selection / filtering criteria, allowed ML model ID list / ML model information for training, VEL model selection filtering criteria, issuer claim as authorization server ID / AIMLE server ID / SEAL server ID, etc. This information may be received from the authorization server 404 when the access token request in step ( 1 ) indicates VEL Training service in the access token request message.
[0094] In such implementations, the access token request can include an IE as described herein, and based on local configuration or authorization information available, the authorization information or the access token claims can additionally include the received information from the access token request.
[0095] Implementations provide for secure EL member registration using authorization / access permission verification for access control. Implementations, for example, include procedures for the authorization and authorization verification of registration and registration update of candidate FL members in an ML repository. The ML repository may serve as a service registry for the FL members undertaking a task related to the ML model lifecycle, such as ML model local training. Candidate FL members can be application layer entities at the server side (e.g., VAL server, AIMLE server), which can potentially be selected as FL clients or FL server for a particular ASP / vertical parameter. If a VAL server is a candidate FL member, the VAL server can register indirectly via an AIMLE server to the ML repository.
[0096] Figure 5 illustrates a system 500 in accordance with aspects of the present disclosure. The system 500 can be implemented to perform FL member registration. In the system 500, the registration of a candidate FL member 502 can occur via a ML repository 504, e.g., where the ML repository 504 can serve as an AIML service registry.
[0097] In examples, if the candidate FL member 502 is a VAL server, the VAL server can register indirectly via an AIMLE server with the ML repository. In examples where the VAL server is the candidate FL member 502 which registers indirectly via an AIMLE server to the MLAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT22repository 504, step (1) and (3) described below can be forwarded by the AIMLE server between the candidate FL member 502 and the ML repository 504, respectively.
[0098] In the system 500: At step (1), the candidate FL member 502 (e.g., VAL server, AIMLE server) sends an FL member registration request with security credentials (e.g., authorization information or access token) to the ML repository 504 for registering with the ML repository 504. The ML repository can function as an AIML service registry. Authorization information or an access token can include claims FL member ID as subject, FL member registration service as scope, FL member type (server or client), FL member capabilities, FL related events ID or name, FL Type, FL task information, Allowed List of member client IDs / Client List, Allowed location information for member client selection, FL service area of interest, allowed ML model ID list / ML model information for FL, allowed ML model training notification target address, ML model selection filtering criteria, FL member location information, issuer claim as authorization server ID / AIMLE server ID / SEAL server, etc.
[0099] Alternatively, or in addition, the VAL server as the candidate FL member 502 at step (1) sends the message to the AIMLE server, and the AIMLE service verifies the security credentials, e.g., authorization information or access token. If the security credentials verification is successful, the AIMLE server can forward the step (1) message to the ML repository 504.
[0100] At step (2), the ML repository 504 validates the received request and security credentials (e.g., authorization information or access token), and if the verification is successful, the ML repository 504 generates the identity and other security related information for the FL members listed in the registration request. At step (3), the ML repository 504 sends the generated information in the FL member registration response message to the candidate FL member 502. Alternatively, or in addition, the ML repository 504 sends the generated information in the FL member registration response message from step (3) to the candidate FL member 502 via the AIMLE server.
[0101] Implementations include solutions where a registration update of a candidate FL member can be performed via the ML repository. For example, registration update can be implemented via the system 500. At step (1), the candidate FL member 502 (VAL server, AIMLE server) can send an FL member registration update request with security credentials (e.g., authorization information or access token) to the ML repository 504 serving as an AIML service registry for updating theAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT23registration of the FL member. Alternatively, or in addition, the candidate FL member 502 can send the step (1) message to an AIMLE server, and an AIMLE service verifies the security credentials, e.g., authorization information or access token. If the security credentials verification is successful, the AIMLE server can forward the step (1) message to the ML repository 504.
[0102] At step (2), the ML repository 504 validates the received update request and security credentials, and if the verification is successful, generates the identity and other security related information for the FL member. At step (3), the ML repository 504 sends the generated information in the FL member registration update response message to the candidate FL member 502.Alternatively, the ML repository sends the generated information in the FL member registration response message in step (3) to the candidate FL member 502 via the AIMLE server.
[0103] Table 3 describes IES for an FL member registration request from the candidate FL member 502 to the ML repository 504. Alternatively, or in addition, authorization information or an access token can be part of security credentials. Alternatively, or in addition, if security credentials and authorization information / access token are included in a separate IE, then security credentials can include client certificate and / or root certificate to validate the client certificate.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT24Table 3Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT25
[0104] Table 4 describes IES for the FL member registration response to the candidate FL member 502 from the ML repository 504.Table 4
[0105] Table 5 describes IEs for the FL member registration update request from the candidate FL member 502 to the ML repository 504.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT26Table 5Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT27
[0106] Table 6 describes IES for the FL member registration update response to the candidate FL member 502 from the ML repository 504. Alternatively, or in addition, authorization information or access token can be part of security credentials. Alternatively, or in addition, if security credentials and authorization information / access token are included in a separate IE, then security credentials can include client certificate and / or root certificate to validate the client certificate.Table 6
[0107] Implementations provide for secure FL related events subscription and notification via authorization / access permission verification for access control. For example, authorization and authorization verification procedures are described related to subscription for the FL related events and event notification procedures. In examples, a global ML repository can serve as an AIML service registry which monitors the status and changes to the availability and capabilities of the FL members. The subscriber can be the AIMLE server or VAL server which is to be notified on the FL member availability. If the VAL server is the subscriber, the VAL server can register indirectly via AIMLE server for FL-related events.
[0108] Figure 6 illustrates a system 600 in accordance with aspects of the present disclosure. The system 600 can be implemented to enable FL related events associated with FL member availability. In examples, the AIMLE server is authorized to subscribe for the FL related events. In scenarios where the VAL server is a subscriber, a request can be sent indirectly via AIMLE server to the ML repository, and steps (1) and (3) described with reference to the system 600 can be forwarded by the AIMLE server between the VAL server and the ML repository respectively.
[0109] In the system 600: At step (1), a subscriber 602 (AIMLE server, VAL server) sends an FL related event subscription request with security credentials (e.g., authorization information or Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT28access token) to the ML repository 504 to receive notification of FL related events and in particular, the availability of an FL member for a target area and time. The authorization information or access token can include claims requestor ID as subject, FL-related event subscription service as scope, FL member Type (server or client), FL related events ID or name, FL Type, FL member ID, FL task information, allowed list of member client IDs / client list, allowed location information for member client selection, allowed ML model ID list / ML model information for FL, allowed ML model training notification target address, ML model selection filtering criteria, issuer claim as authorization server ID / AIMLE server ID / SEAL server ID.
[0110] At step (2), upon receiving the event subscription request from the AIMLE server, the ML repository 504 checks for the relevant authorization for the event subscription security credentials (e.g., authorization information or access token) and if the verification is successful, then it determines to generate and store the subscription information in the ML repository. If the authorization is successful, the ML repository stores the subscription information. At step (3), the ML repository sends an FL-related event subscription response to the subscriber 602 indicating successful operation.
[0111] Implementations provide for an event notification procedure for the FL member availability. This can be triggered based on a change in the availability or capabilities of the candidate or selected FL members. In examples, a subscription procedure was performed by the AIMLE server or VAL server (via AIMLE server). The FL member has registered its capabilities or availability to the ML repository based on the support for FL registration capability.
[0112] At step (1), an ML repository detects a change related to the availability of an FL member and generates events to be consumed by the AIMLE server, based on the notification, or based on a received updated registration from an FL member, who has already registered at the ML repository. At step (2), for the generated event, the ML repository retrieves the list of corresponding subscriptions. At step (3), the ML repository sends FL-related event notification to entities (e.g., AIMLE servers) that have subscribed for the FL-related event matching the criteria. If notification reception information is available as part of the FL-related event subscription, then the notification reception information is used by the ML repository to send event notifications to the corresponding AIMLE servers. At step (4), the notified subscriber(s) sends an event notification acknowledgement to the ML repository.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT29
[0113] Table 7 includes example definitions of FL related events in accordance with aspects of the present disclosure.Table 7
[0114] Table 8 describes IES for FL-related event subscription request from the subscriber 602 to the ML repository 504. Alternatively, or in addition, authorization information or access token can be part of security credentials. Alternatively, or in addition, if security credentials and authorization information / access token are included in a separate IE, then security credentials can include client certificate and / or root certificate to validate the client certificate.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT30Table 8Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT31
[0115] Table 9 describes IES for the FL-related event subscription response to the subscriber (e.g. AIMLE server) from the ML repository.Table 9
[0116] Table 10 describes IEs for the FL-related event notification from the ML repository to the requestor (e.g., AIMLE server).Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT32Table 10
[0117] Table 11 describes IES for the FL-related event notification acknowledgement from the AIMLE server to the ML repository.Table 11
[0118] Implementations provide for secure HFL training via authorization / access permission verification for access control. AI / ML training can be an iterative process and can be performed over multiple training rounds. In the cases of FL and DL, the training can be performed with multiple AIMLE clients. An AIMLE server can be configured to manage the training process overAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT33multiple training rounds for VAL servers. In examples, an HFL training procedure may support HFL, distributed learning, transfer learning, and split AI / ML.
[0119] Figure 7 illustrates a system 700 in accordance with aspects of the present disclosure. The system 700 can be implemented for HFL training. In examples, AIMLE client discovery and selection have been performed. Datasets can be available and prepared for AI / ML training at the AIMLE clients. The datasets can be assigned identifiers for use in HFL training.
[0120] In the system 700: At step (1), an AIMLE server 702 receives an ML model training request from a VAL server 704, where the request includes security credentials, e.g., authorization information or access token. If the AIMLE server 702 determines to use HFL training, the procedure continues to step (2). Authorization information or access token can include claims requestor ID as subject, HFL training service (e.g., horizontal federated learning, distributed learning, transfer learning, and split AI / ML) as scope, AI / ML model (e.g., model ID / type) and model parameters, dataset ID(s), allowed FL members (allowed List of member client IDs) to use as Al MLE clients for HFL or ML model training, training type (VFL or HFL or both VFL and HFL), allowed AIMLE client selection / filtering criteria, allowed ML model ID list / ML model information for training, ML model selection filtering criteria, issuer claim as authorization server ID / AIMLE server ID / SEAL server ID.
[0121] At step (2), the AIMLE server verifies the security credentials (e.g., authorization information or access token), and if the verification is successful, retrieves the indicated ML model. At step (3), for the HFL training, if the security credentials verification is successful, the AIMLE server 702 performs AIMLE client selection using the AIMLE client selection criteria or a list of AIMLE clients provided in step (1) based on the verified authorization information or access token claims. If AIMLE client selection criteria are provided in step (1), then the AIMLE server 702 monitors and selects AIMLE clients 706 for the HFL training. If a list of AIMLE clients is provided in step (1), the AIMLE server 702 selects the provided AIMLE clients 706 for the HFL training based on the verified authorization information or access token claims.
[0122] At step (4), based on the AIMLE client set determined in step (3), the AIMLE server 702 based on the verified authorization information or access token claims checks with the selected AIMLE clients 706 for their capability and participation in the HFL training. At step (5), theAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT34AIMLE server 702 configures a training schedule for each of the AIMLE clients 706 and sends a HFL training subscription request. At step (6), each AIMLE client 706 sends a HFL training subscription response with information such as described in Table 13. If the AIMLE client 706 is not able to grant the subscription (e.g., is not able to perform the training), the AIMLE client 706 sends a response with a failure status and the system skips to step (8).
[0123] At step (7), each AIMLE client performs local training using the configured AI / ML model, model parameters, and the prepared local data associated with the dataset identifier for the specified number of samples according to the operational schedule. At step (8), upon completion or due to errors in the training, each AIMLE client 706 sends a HFL training notification to the AIMLE server 702. The notification includes information as described in Table 14. The AIMLE client 706 provides an AIMLE service ID for the HFL training operation.
[0124] At step (9), if errors were encountered, the system 700 skips to step (10). At step (9), if training was successful, the AIMLE server 702 aggregates (e.g. averages) the model parameters received from the AIMLE clients 706. If a training schedule is not complete (e.g., there are remaining training rounds), the AIMLE server 702 configures the next set of training schedules and steps (3) to (8) can be repeated for the next training round. When the training schedule has been completed (e.g. there are no remaining training rounds), the AIMLE server 702 can perform a ML model information storage request to store the AI / ML model in the ML repository 504. At step (10), the AIMLE server 702 sends a ML model training notification to the VAL server 704.
[0125] Table 12 shows the request sent by the AIMLE server 702 to AIMLE clients 706 for an HFL training subscription procedure.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT35Table 12
[0126] Table 13 illustrates the response sent by AIMLE clients 706 to the AIMLE server 702 for the HFL training subscription procedure.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT36Table 13
[0127] Table 14 illustrates the notification sent by AIMLE clients 706 to the AIMLE server 702 for the HFL training subscription procedure.Table 14
[0128] Implementations provide for an authorization and authorization verification procedure for the grouping of the FL members using AIMLE. Such grouping for the given FL process can be applicable to a specific VAL request or ML model ID or ADAE analytics ID. This grouping can be applicable also for a given service area in which one or more FL processes are expected to run. The grouping of FL members is performed for optimizing the process of selection and updating FL members which are entering or leaving the group.
[0129] Figure 8 illustrates a system 800 in accordance with aspects of the present disclosure. In the system 800, the AIMLE support capability is described for grouping the FL members, where the grouping is tailored to a specific ML task (VAL triggered task or analytics event / ID). In examples,Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT37the VAL server 704 is connected to the AIMLE server 702. The candidate / selected FL member 502 has registered to the FL member registry based on a capability.
[0130] In the system 800: At step (1), the VAL server 704 sends to the AIMLE server an FL member grouping support request with security credentials e.g., authentication information such as certificates, authorization information or access token for supporting an FL process. Authorization information or access token can include claims requestor ID as subject, FL member grouping service as scope, VAL service ID, service area information, AIML model (e.g., model ID / type), ADAE analytics ID, ML model profile information (e.g., ID for which the FL grouping is to be used), ML task information / ID (e.g., FL training task or FT inference task), allowed FL members (allowed list of member client IDs) to use as Al MLE clients / server for FL, training type (VFL or HFL or both VFL and HFL), allowed Al MLE client selection / filtering criteria, allowed ML model ID list / ML model information for training, FL / ML model selection filtering criteria, issuer claim as authorization server ID / AIMLE server ID / SEAL server ID, etc.
[0131] At step (2), the AIMLE Server 702 based on the request, verifies the security credentials e.g., authentication information such as certificates, authorization information or access token. If the verification is successful, the AIMLE server 702 determines to create a group including the FL members for a given ML task (e.g., an ML model training / inference job ID). The FL aggregator can be either the VAL server 704 or the AIMLE server 702, e.g., based on the request. The case for creating a FL member group may be based on an ML task for a given AIMLE service area or for a given AIMLE service area where one or more ML tasks are expected to run, e.g., based on the step (1) request.
[0132] At step (3), the AIMLE server 702, based on the verified security credentials (e.g., authentication information such as certificates, authorization information or access token), obtains the available FL members 502 for the given ML task (e.g., an ML model training / inference job ID) from the ML repository 504. Based on this information, the AIMLE server 702 (e.g., based on the verified security credentials e.g., authorization security credentials e.g., authorization information or access token) may select one or more FL members 502 for the group for the ML task.
[0133] At step (4), the AIMLE Server 702 configures the FL member group based on the available or selected FL members by the FL server / aggregator. Criteria for determining the groupAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT38members can be the capabilities of the FL participants, or whether the candidate participants are fixed or mobile nodes and their availabilities, and the proximity of the participants. At step (5), the AIMLE Server 702 notifies the candidate FL members (including AIMLE client if the candidate is VAL UEs) of the group ID and the group member identities for the ML model ID / analytics ID based on the request in step (1). At step (6), the AIMLE server 702 sends a FL member grouping support response to the VAL server 704 indicating the group creation and the group information.
[0134] Table 15 shows the request sent by the VAL server 704 to AIMLE server 702 for the FL member grouping procedure.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT39Table 15Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT40
[0135] Table 16 shows the response sent by the AIMLE server 702 to the VAL server 704 for the FL member grouping procedure.Table 16
[0136] Table 17 shows the notification sent by the AIMLE server 702 to the EL members 502 (AIMLE clients, VAL servers) for the EL member grouping procedure.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT41Table 17
[0137] Implementations provide for secure support of the VFL training procedure by authorization / access permission verification for access control. For example, authorization and authorization verification procedures are provided for supporting VFL among application layer multiple UEs. In examples, VFL members have registered their VFL profile with the AIMLE Server 702. The VFL members may update their status or information in their VFL profile to the AIMLE Server 702. In examples, datasets of each of the UEs (where the AIMLE Clients as VFL members are deployed on) belong to more than one different data domain. The VAL server 704 has successfully subscribed / registered with the AIMLE server 702 for model training notifications.
[0138] Figure 9 illustrates a system 900 in accordance with aspects of the present disclosure. The system 900 can be implemented to support VFL. In the system 900: At step (1), an AIMLE server 702 receives an ML model training request with security credentials (e.g., authentication information such as certificates, authorization information or access token) from a VAL server 704, such as described throughout this disclosure. If an ML model training request is received and the AIMLE server 702 determines to use VFL training (VFL training between different data domains),Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT42the system 900 can proceed to step (2). Authorization information or access token can include claims requestor ID as subject, VFL training service as scope, AIML model (e.g., model ID / Type) and model parameters, feature information, dataset ID(s), allowed different data domains information, allowed FL members (allowed list of member client IDs) to use as Al MLE clients for VFL model training (e.g., per domain), training type (VFL), allowed AIMLE client selection / filtering criteria, allowed ML model ID list / ML model information for training, VEL model selection filtering criteria, issuer claim as authorization server ID / AIMLE server ID / SEAL server ID, etc.
[0139] At step (2) (optionally), the AIMLE server 702 verifies the security credentials (e.g., authorization security credentials (e.g., authorization information or access token), and if the verification is successful, the AIMLE server 702 retrieves the indicated ML model from step (1) using an ML model retrieval procedure such as described throughout this disclosure. If the retrieved model is already trained and meets the machine learning parameters requested by a consumer, the system 900 can proceed to step (7).
[0140] At step (3), if AIMLE client selection criteria are provided in step (1), the AIMLE server 702 based on the verified authentication information such as certificates, authorization information or access token claims, can monitor and select AIMLE clients 902 for the VEL training. If a list of AIMLE clients is provided in step (1), the AIMLE server 702 based on the verified authorization information or access token claims, can select the provided AIMLE clients 902 for the VEL training.
[0141] At step (4), the AIMLE server 702 obtains VEL members 904 information (the VEL members information may be included in the request in step (1) or be obtained through step (3)). The AIMLE server 702 interacts with the VEL members (AIMLE clients which are deployed on UEs) for each data domain for ML model training capability evaluation. The VEL members 904 may include VAL clients 906.
[0142] At step (5), the AIMLE server 702 determines the VEL members for the VEL training process based on the information received in step (4) and parameters received in step (1), and based on the verified authentication information such as certificates, authorization information or access token claims. The AIMLE server 702 determines VEL members 904 for each data domain based onAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT43the verified authorization information or access token claims. The criteria used by the AIMLE server may include: Available data at the AIMLE server may include: available data and minimum number of data samples for the same sample among the VFL members 904; feature alignment of the sample / datasets with data labels among the VFL members 904; available time of the VFL members 904 to support the VFL training operations; capability and minimum number of the VFL members 904 for the VFL training operations; AIML model information for the VFL members 904 and for the AIMLE server 702; and successful verification of authentication information such as certificates, authorization information or access token claims.
[0143] At step (6), the AIMLE server 702 coordinates the selected VFL members 904 for VFL training. During a VFL training process, the VFL members 904 send intermediate results to the AIMLE server 702, and the AIMLE server 702 responds to the VFL members 904 with the updated information (e.g., gradients). The information from the AIMLE server 702 can be used to update the model parameters maintained at each VFL member 904 for the different data domains. At step (6a), the AIMLE server 702 may report to the VAL server 704 with the training status that includes intermediate training results, and the VAL server 704 may adjust its request for the ML model training. If the VAL server 704 is providing data labels to complete the training, the VAL server 704 may send updated training parameters for the AIMLE server 702 to distribute to the VFL members 904. The updated training parameters may apply for models of VFL members 904 associated with each data domain. At step (7), the AIMLE server 702 sends an ML model training notification to the VAL server 704. If the training schedule is not complete (e.g., there are remaining training rounds), the AIMLE server 702 configures the next set of training schedules, and steps (3) through (6) may be repeated for the next training round.
[0144] Figure 10 illustrates an example of a UE 1000 in accordance with aspects of the present disclosure. The UE 1000 may include a processor 1002, a memory 1004, a controller 1006, and a transceiver 1008. The processor 1002, the memory 1004, the controller 1006, or the transceiver 1008, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT44
[0145] The processor 1002, the memory 1004, the controller 1006, or the transceiver 1008, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0146] The processor 1002 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 1002 may be configured to operate the memory 1004. In some other implementations, the memory 1004 may be integrated into the processor 1002. The processor 1002 may be configured to execute computer-readable instructions stored in the memory 1004 to cause the UE 1000 to perform various functions of the present disclosure.
[0147] The memory 1004 may include volatile or non-volatile memory. The memory 1004 may store computer-readable, computer-executable code including instructions when executed by the processor 1002 cause the UE 1000 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 1004 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0148] Additionally, or alternatively, the UE 1000 may support at least one memory (e.g., the memory 1004) and at least one processor (e.g., the processor 1002) coupled with the at least one memory and configured to cause the UE to transmit a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and receive a second message including a FL member registration response.
[0149] Additionally, the UE 1000 may be configured to support any one or combination of where the at least one processor is operable to cause the UE to: transmit a third message including a FL event subscription request, where the third message includes one or more of the securityAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT45credentials, the authorization information, or the access token; and receive, based at least in part on the FL event subscription request, a fourth message including a FL event subscription response; the apparatus includes one or more of a VAL server, AI / ML client, AIMLE client, AIMLE server, or an AI / ML server; the security credentials include a client certificate or a root certificate configured to validate the client certificate.
[0150] The controller 1006 may manage input and output signals for the UE 1000. The controller 1006 may also manage peripherals not integrated into the UE 1000. In some implementations, the controller 1006 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 1006 may be implemented as part of the processor 1002.
[0151] In some implementations, the UE 1000 may include at least one transceiver 1008. In some other implementations, the UE 1000 may have more than one transceiver 1008. The transceiver 1008 may represent a wireless transceiver. The transceiver 1008 may include one or more receiver chains 1010, one or more transmitter chains 1012, or a combination thereof.
[0152] A receiver chain 1010 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1010 may include one or more antennas to receive a signal over the air or a wireless medium. The receiver chain 1010 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 1010 may include at least one demodulator configured to demodulate the received signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1010 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.
[0153] A transmitter chain 1012 may be configured to generate and transmit signals(e.g., control information, data, packets). The transmitter chain 1012 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 1012 may also include at least one power amplifier configured to amplify the modulated signal toAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT46an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 1012 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0154] Figure 11 illustrates an example of a processor 1100 in accordance with aspects of the present disclosure. The processor 1100 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 1100 may include a controller 1102 configured to perform various operations in accordance with examples as described herein. The processor 1100 may optionally include at least one memory 1104, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 1100 may optionally include one or more arithmetic-logic units (ALUs) 1106. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
[0155] The processor 1100 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 1100) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM), magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).
[0156] The controller 1102 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 1100 to cause the processor 1100 to support various operations in accordance with examples as described herein. For example, the controller 1102 may operate as a control unit of the processor 1100, generating control signals that manage the operation of various components of the processor 1100. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT47
[0157] The controller 1102 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 1104 and determine subsequent instruction(s) to be executed to cause the processor 1100 to support various operations in accordance with examples as described herein. The controller 1102 may be configured to track memory addresses of instructions associated with the memory 1104. The controller 1102 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 1102 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 1100 to cause the processor 1100 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 1102 may be configured to manage flow of data within the processor 1100. The controller 1102 may be configured to control transfer of data between registers, ALUs 1106, and other functional units of the processor 1100.
[0158] The memory 1104 may include one or more caches (e.g., memory local to or included in the processor 1100 or other memory, such as RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc.). In some implementations, the memory 1104 may reside within or on a processor chipset (e.g., local to the processor 1100). In some other implementations, the memory 1104 may reside external to the processor chipset (e.g., remote to the processor 1100).
[0159] The memory 1104 may store computer-readable, computer-executable code including instructions that, when executed by the processor 1100, cause the processor 1100 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 1102 and / or the processor 1100 may be configured to execute computer-readable instructions stored in the memory 1104 to cause the processor 1100 to perform various functions. For example, the processor 1100 and / or the controller 1102 may be coupled with or to the memory 1104, the processor 1100, and the controller 1102, and may be configured to perform various functions described herein. In some examples, the processor 1100 may include multiple processors and the memory 1104 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT48
[0160] The one or more ALUs 1106 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 1106 may reside within or on a processor chipset (e.g., the processor 1100). In some other implementations, the one or more ALUs 1106 may reside external to the processor chipset (e.g., the processor 1100). One or more ALUs 1106 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 1106 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 1106 may be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 1106 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 1106 to handle conditional operations, comparisons, and bitwise operations.
[0161] The processor 1100 may support wireless communication in accordance with examples as disclosed herein. The processor 1100 may be configured to or operable to support at least one controller (e.g., the controller 1102) coupled with at least one memory (e.g., the memory 1104) and configured to cause the processor to receive a first message including a request for an access token, where the first message includes first AI / ML information associated with FL; and transmit a second message including the access token, where the access token includes second AI / ML information associated with FL.
[0162] Additionally, the processor 1100 may be configured to or operable to support any one or combination of where the first AI / ML information associated with FL learning includes information associated with one or more of: FL member registration service; FL member registration update service; FL events subscription service; FL events notification service; horizontal HFL training service; FL member grouping service; or vertical FL training service; the access token includes token claims for one or more of: FL member registration; FL events notification; horizontal FL (HFL) training; FL member grouping; FL member ID;FL member type (server or client); FL member capabilities; FL related events ID or name; FL type; FL task information; allowed list of member client IDs / client list; allowed location information for member client selection; FL service area of interest; allowed ML model ID list / ML model information for FL; allowed ML model training notification target address; ML model selection filtering criteria; FL member locationAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT49information; analytics ID; issuer claim as an authorization server ID or an AIMLE server ID FL member; or vertical FL (VFL) training; the at least one controller is operable to cause the processor to: receive a third message including an AI / ML model training request, where the third message includes security information including one or more of security credentials, authorization information, or the access token; determine one or more FL members based at least in part on a verification of the security information; and transmit, based at least in part on the determined one or more FL members, a fourth message including an AI / ML training response.
[0163] Additionally, the processor 1100 may be configured to or operable to support any one or combination of where the AI / ML model training request is associated with horizontal FL; the at least one controller is operable to cause the processor to: receive a third message including a FL grouping request, where the third message includes security information including one or more of security credentials, authorization information, or the access token; obtain, based at least in part on verification of the security information, FL member information; and transmit, based at least in part on the FL member information, a fourth message including a FL grouping response; the at least one controller is operable to cause the processor to: receive a third message including an AI / ML model training request, where the third message includes one or more client selection criteria and security information including one or more of security credentials, authorization information, or the access token; select one or more FL clients based at least in part on a verification of the security information and the one or more client selection criteria; and transmit, based at least in part on the selected one or more FL clients, a fourth message including an AI / ML training response; the AI / ML model training request is associated with vertical FL; the apparatus includes an AI / ML server or an AIMLE server.
[0164] The processor 1100 may support wireless communication in accordance with examples as disclosed herein. The processor 1100 may be configured to or operable to support at least one controller (e.g., the controller 1102) coupled with at least one memory (e.g., the memory 1104) and configured to cause the processor to receive a first message including a registration request to register as a FE member, where the first message includes one or more of security credentials, authorization information, or an access token; and transmit a second message including a FE member registration response.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT50
[0165] Additionally, the processor 1100 may be configured to or operable to support any one or combination of where the at least one controller is operable to cause the processor to: receive a third message including a FL event subscription request, where the third message includes one or more of the security credentials, the authorization information, or the access token; perform authorization for FL event subscription based at least in part on the one or more of the security credentials, the authorization information, or the access token; and transmit, based at least in part on the authorization for FL event subscription, a fourth message including a FL event subscription response; the apparatus includes an AI / ML repository; the security credentials include a client certificate or a root certificate configured to validate the client certificate.
[0166] The processor 1100 may support wireless communication in accordance with examples as disclosed herein. The processor 1100 may be configured to or operable to support at least one controller (e.g., the controller 1102) coupled with at least one memory (e.g., the memory 1104) and configured to cause the processor to transmit a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and receive a second message including a FL member registration response.
[0167] Additionally, the processor 1100 may be configured to or operable to support any one or combination of where the at least one controller is operable to cause the processor to: transmit a third message including a FL event subscription request, where the third message includes one or more of the security credentials, the authorization information, or the access token; and receive, based at least in part on the FL event subscription request, a fourth message including a FL event subscription response; the processor includes one or more of a VAL server, AI / ML client, AIMLE client, AIMLE server, or an AI / ML server; the security credentials include a client certificate or a root certificate configured to validate the client certificate.
[0168] The processor 1100 may support wireless communication in accordance with examples as disclosed herein. The processor 1100 may be configured to or operable to support at least one controller (e.g., the controller 1102) coupled with at least one memory (e.g., the memory 1104) and configured to cause the processor to transmit a first message including a FL grouping request, where the first message includes one or more of authentication information or an access token; and receive a second message including a FL grouping response.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT51
[0169] Additionally, the processor 1100 may be configured to or operable to support any one or combination of where the at least one controller is operable to cause the processor to: transmit a third message including an AI / ML model training request, where the third message includes security information including one or more of security credentials, authorization information, or the access token; and receive, based at least in part on the AI / ML model training request, a fourth message including an AI / ML training response; the AI / ML model training request is associated with horizontal FL; the at least one controller is operable to cause the processor to: transmit a third message including an AI / ML model training request, where the third message includes one or more client selection criteria and security information including one or more of security credentials, authorization information, or the access token; and receive, based at least in part on the AI / ML model training request, a fourth message including an AI / ML training response; the AI / ML model training request is associated with vertical FL; the apparatus includes a VAL server.
[0170] Figure 12 illustrates an example of an NE 1200 in accordance with aspects of the present disclosure. The NE 1200 may include a processor 1202, a memory 1204, a controller 1206, and a transceiver 1208. The processor 1202, the memory 1204, the controller 1206, or the transceiver 1208, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0171] The processor 1202, the memory 1204, the controller 1206, or the transceiver 1208, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0172] The processor 1202 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 1202 may be configured to operate the memory 1204. In some other implementations, the memory 1204 may be integrated into the processor 1202. The processor 1202Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT52may be configured to execute computer-readable instructions stored in the memory 1204 to cause the NE 1200 to perform various functions of the present disclosure.
[0173] The memory 1204 may include volatile or non-volatile memory. The memory 1204 may store computer-readable, computer-executable code including instructions when executed by the processor 1202 cause the NE 1200 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as the memory 1204 or another type of memory. Computer-readable media includes both non-transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or special-purpose computer.
[0174] Additionally, or alternatively, the NE 1200 may support at least one memory (e.g., the memory 1204) and at least one processor (e.g., the processor 1202) coupled with the at least one memory and configured to cause the NE to receive a first message including a request for an access token, where the first message includes first AI / ML information associated with FL; and transmit a second message including the access token, where the access token includes second AI / ML information associated with FL.
[0175] Additionally, the NE 1200 may be configured to support any one or combination of where the first AI / ML information associated with FL learning includes information associated with one or more of: FL member registration service; FL member registration update service; FL events subscription service; FL events notification service; horizontal HFL training service; FL member grouping service; or vertical FL training service; the access token includes token claims for one or more of: FL member registration; FL events notification; horizontal FL (HFL) training; FL member grouping; FL member ID; FL member type (server or client); FL member capabilities; FL related events ID or name; FL type; FL task information; allowed list of member client IDs / client list; allowed location information for member client selection; FL service area of interest; allowed ML model ID list / ML model information for FL; allowed ML model training notification target address; ML model selection filtering criteria; FL member location information; analytics ID; issuer claim as an authorization server ID or an AIMLE server ID FL member; or vertical FL (VFL) training; the at least one processor is operable to cause the apparatus to: receive a third message including an AI / ML model training request, where the third message includes security information including one Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT53or more of security credentials, authorization information, or the access token; determine one or more FL members based at least in part on a verification of the security information; and transmit, based at least in part on the determined one or more FL members, a fourth message including an AI / ML training response.
[0176] Additionally, the NE 1200 may be configured to support any one or combination of where the AI / ML model training request is associated with horizontal FL; the at least one processor is operable to cause the NE to: receive a third message including a FL grouping request, where the third message includes security information including one or more of security credentials, authorization information, or the access token; obtain, based at least in part on verification of the security information, FL member information; and transmit, based at least in part on the FL member information, a fourth message including a FL grouping response; the at least one processor is operable to cause the NE to: receive a third message including an AI / ML model training request, where the third message includes one or more client selection criteria and security information including one or more of security credentials, authorization information, or the access token; select one or more FL clients based at least in part on a verification of the security information and the one or more client selection criteria; and transmit, based at least in part on the selected one or more FL clients, a fourth message including an AI / ML training response; the AI / ML model training request is associated with vertical FL; the apparatus includes an AI / ML server or an AIMLE server.
[0177] Additionally, or alternatively, the NE 1200 may support at least one memory (e.g., the memory 1204) and at least one processor (e.g., the processor 1202) coupled with the at least one memory and configured to cause the NE to receive a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and transmit a second message including a FL member registration response.
[0178] Additionally, the NE 1200 may be configured to support any one or combination of where the at least one processor is operable to cause the NE to: receive a third message including a FL event subscription request, where the third message includes one or more of the security credentials, the authorization information, or the access token; perform authorization for FL event subscription based at least in part on the one or more of the security credentials, the authorization information, or the access token; and transmit, based at least in part on the authorization for FL Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT54event subscription, a fourth message including a FL event subscription response; the apparatus includes an AI / ML repository; the security credentials include a client certificate or a root certificate configured to validate the client certificate.
[0179] Additionally, or alternatively, the NE 1200 may support at least one memory (e.g., the memory 1204) and at least one processor (e.g., the processor 1202) coupled with the at least one memory and configured to cause the NE to transmit a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token; and receive a second message including a FL member registration response.
[0180] Additionally, the NE 1200 may be configured to support any one or combination of the at least one processor is operable to cause the NE to: transmit a third message including a FL event subscription request, where the third message includes one or more of the security credentials, the authorization information, or the access token; and receive, based at least in part on the FL event subscription request, a fourth message including a FL event subscription response; the apparatus includes one or more of a VAL server, AI / ML client, AIMLE client, AIMLE server, or an AI / ML server; the security credentials include a client certificate or a root certificate configured to validate the client certificate.
[0181] Additionally, or alternatively, the NE 1200 may support at least one memory (e.g., the memory 1204) and at least one processor (e.g., the processor 1202) coupled with the at least one memory and configured to cause the NE to transmit a first message including a FL grouping request, where the first message includes one or more of authentication information or an access token; and receive a second message including a FL grouping response.
[0182] Additionally, the NE 1200 may be configured to support any one or combination of where the at least one processor is operable to cause the NE to: transmit a third message including an AI / ML model training request, where the third message includes security information including one or more of security credentials, authorization information, or the access token; and receive, based at least in part on the AI / ML model training request, a fourth message including an AI / ML training response; the AI / ML model training request is associated with horizontal FL; the at least one processor is operable to cause the NE to: transmit a third message including an AI / ML modelAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT55training request, where the third message includes one or more client selection criteria and security information including one or more of security credentials, authorization information, or the access token; and receive, based at least in part on the Al / ML model training request, a fourth message including an Al / ML training response; the AI / ML model training request is associated with vertical FL; the NE includes a VAL server.
[0183] The controller 1206 may manage input and output signals for the NE 1200. The controller 1206 may also manage peripherals not integrated into the NE 1200. In some implementations, the controller 1206 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 1206 may be implemented as part of the processor 1202.
[0184] In some implementations, the NE 1200 may include at least one transceiver 1208. In some other implementations, the NE 1200 may have more than one transceiver 1208. The transceiver 1208 may represent a wireless transceiver. The transceiver 1208 may include one or more receiver chains 1210, one or more transmitter chains 1212, or a combination thereof.
[0185] A receiver chain 1210 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 1210 may include one or more antennas to receive a signal over the air or wireless medium. The receiver chain 1210 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 1210 may include at least one demodulator configured to demodulate the received signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 1210 may include at least one decoder for decoding the demodulated signal to receive the transmitted data.
[0186] A transmitter chain 1212 may be configured to generate and transmit signals(e.g., control information, data, packets). The transmitter chain 1212 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 1212 may also include at least one power amplifier configured to amplify the modulated signal toAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT56an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 1212 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0187] Figure 13 illustrates a flowchart of a method 1300 in accordance with aspects of the present disclosure. The operations of the method may be implemented by an NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0188] At 1302, the method may include receiving a first message including a request for an access token, where the first message includes first AI / ML information associated with FL. The operations of 1302 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1302 may be performed by an NE as described with reference to Figure 12.
[0189] At 1304, the method may include transmitting a second message including the access token, where the access token includes second AI / ML information associated with FL. The operations of 1304 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1304 may be performed by an NE as described with reference to Figure 12.
[0190] Figure 14 illustrates a flowchart of a method 1400 in accordance with aspects of the present disclosure. The operations of the method may be implemented by an NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0191] At 1402, the method may include receiving a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token. The operations of 1402 may beAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT57performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1402 may be performed by an NE as described with reference to Figure 12.
[0192] At 1404, the method may include transmitting a second message including a FL member registration response. The operations of 1404 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1404 may be performed by an NE as described with reference to Figure 12.
[0193] Figure 15 illustrates a flowchart of a method 1500 in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE and / or a UE as described herein. In some implementations, the NE and / or the UE may execute a set of instructions to control the function elements of the NE and / or the UE to perform the described functions. It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0194] At 1502, the method may include transmitting a first message including a registration request to register as a FL member, where the first message includes one or more of security credentials, authorization information, or an access token. The operations of 1502 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1502 may be performed by a UE as described with reference to Figure 10 and / or an NE as described with reference to Figure 12.
[0195] At 1504, the method may include receiving a second message including a FL member registration response. The operations of 1504 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1504 may be performed by a UE as described with reference to Figure 10 and / or an NE as described with reference to Figure 12.
[0196] Figure 16 illustrates a flowchart of a method 1600 in accordance with aspects of the present disclosure. The operations of the method may be implemented by an NE as described herein. In some implementations, the NE may execute a set of instructions to control the functional elements of the NE to perform the described functions. It should be noted that the method describedAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT58herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0197] At 1602, the method may include transmitting a first message including a FL grouping request, where the first message includes one or more of authentication information or an access token. The operations of 1602 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1602 may be performed by an NE as described with reference to Figure 12.
[0198] At 1604, the method may include receiving a second message including a FL grouping response. The operations of 1604 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 1604 may be performed by an NE as described with reference to Figure 12.
[0199] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.Attorney Ref. No. SMM920240311-WO-PCT
Claims
1. Lenovo Ref. No. SMM920240311-WO-PCT59CLAIMSWhat is claimed is:
1. An apparatus for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and operable to cause the apparatus to:receive a first message comprising a request for an access token, wherein the first message includes first artificial intelligence (Al) machine learning (ML) information associated with federated learning (FL); andtransmit a second message including the access token, wherein the access token includes second AI / ML information associated with FL.
2. The apparatus of claim 1, wherein the first AI / ML information associated with FL learning comprises information associated with one or more of:FL member registration service;FL member registration update service;FL events subscription service;FL events notification service;horizontal HFL training service;FL member grouping service; orvertical FL training service.
3. The apparatus of claim 1 , wherein the at least one processor is operable to cause the apparatus to:receive a third message comprising an AI / ML model training request, wherein the third message includes security information comprising one or more of security credentials, authorization information, or the access token;determine one or more FL members based at least in part on a verification of the security information; andAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT60transmit, based at least in part on the determined one or more FL members, a fourth message comprising an AI / ML training response.
4. The apparatus of claim 3, wherein the AI / ML model training request is associated with horizontal FL.
5. The apparatus of claim 1 , wherein the at least one processor is operable to cause the apparatus to:receive a third message comprising a federated learning (FL) grouping request, wherein the third message includes security information comprising one or more of security credentials, authorization information, or the access token;obtain, based at least in part on verification of the security information, FL member information; andtransmit, based at least in part on the FL member information, a fourth message comprising a FL grouping response.
6. The apparatus of claim 1 , wherein the at least one processor is operable to cause the apparatus to:receive a third message comprising an AI / ML model training request, wherein the third message includes one or more client selection criteria and security information comprising one or more of security credentials, authorization information, or the access token;select one or more FL clients based at least in part on a verification of the security information and the one or more client selection criteria; andtransmit, based at least in part on the selected one or more FL clients, a fourth message comprising an AI / ML training response.
7. The apparatus of claim 6, wherein the AI / ML model training request is associated with vertical FL.
8. The apparatus of claim 1, wherein the apparatus comprises an AI / ML server or an AI / ML enabler (AIMLE) server.Attorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT619. An apparatus for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and operable to cause the apparatus to:receive a first message comprising a registration request to register as a federated learning (FL) member, wherein the first message includes one or more of security credentials, authorization information, or an access token; andtransmit a second message comprising a FL member registration response.
10. The apparatus of claim 9, wherein the at least one processor is operable to cause the apparatus to:receive a third message comprising a FL event subscription request, wherein the third message includes one or more of the security credentials, the authorization information, or the access token;perform authorization for FL event subscription based at least in part on the one or more of the security credentials, the authorization information, or the access token; andtransmit, based at least in part on the authorization for FL event subscription, a fourth message comprising a FL event subscription response.
11. The apparatus of claim 9, wherein the apparatus comprises an AI / ML repository.
12. The apparatus of claim 9, wherein the security credentials comprise a client certificate or a root certificate configured to validate the client certificate.
13. An apparatus for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and operable to cause the apparatus to:transmit a first message comprising a registration request to register as a federated learning (FL) member, wherein the first message includes one or more of security credentials, authorization information, or an access token; andAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT62receive a second message comprising a FL member registration response.
14. The apparatus of claim 13, wherein the at least one processor is operable to cause the apparatus to:transmit a third message comprising a FL event subscription request, wherein the third message includes one or more of the security credentials, the authorization information, or the access token; andreceive, based at least in part on the FL event subscription request, a fourth message comprising a FL event subscription response.
15. The apparatus of claim 13, wherein the apparatus comprises one or more of a vertical application layer (VAL) server, AI / ML client, AI / ML enabler (AIMLE) client, AIMLE server, or an AI / ML server.
16. The apparatus of claim 13, wherein the security credentials comprise a client certificate or a root certificate configured to validate the client certificate.
17. An apparatus for wireless communication, comprising:at least one memory; andat least one processor coupled with the at least one memory and operable to cause the apparatus to:transmit a first message comprising a federated learning (FL) grouping request, wherein the first message includes one or more of authentication information or an access token; andreceive a second message comprising a FL grouping response.
18. The apparatus of claim 17, wherein the at least one processor is operable to cause the apparatus to:transmit a third message comprising an AI / ML model training request, wherein the third message includes security information comprising one or more of security credentials, authorization information, or the access token; andAttorney Ref. No. SMM920240311-WO-PCTLenovo Ref. No. SMM920240311-WO-PCT63receive, based at least in part on the AI / ML model training request, a fourth message comprising an AI / ML training response.
19. The apparatus of claim 18, wherein the AI / ML model training request is associated with horizontal FL.
20. The apparatus of claim 17, wherein the at least one processor is operable to cause the apparatus to:transmit a third message comprising an AI / ML model training request, wherein the third message includes one or more client selection criteria and security information comprising one or more of security credentials, authorization information, or the access token; andreceive, based at least in part on the AI / ML model training request, a fourth message comprising an AI / ML training response.Attorney Ref. No. SMM920240311-WO-PCT