Network digital twin service based solutions against security threats

WO2026165746A1PCT designated stage Publication Date: 2026-08-13NOKIA SOLUTIONS (SHANGHAI) CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2026-08-13

Smart Images

  • Figure CN2025075951_13082026_PF_FP_ABST
    Figure CN2025075951_13082026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are network digital twin, NDT, service based solutions against security threats. An example apparatus for a management service, MnS, consumer may include at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to: transmit to a NDT service producer, a threat protection request for potential security threat assessment with at least one object; and receive from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.
Need to check novelty before this filing date? Find Prior Art

Description

NETWORK DIGITAL TWIN SERVICE BASED SOLUTIONS AGAINST SECURITY THREATSTECHNICAL FIELD

[0001] Various example embodiments relate to network digital twin (NDT) service based solutions against security threats.BACKGROUND

[0002] Currently the cybersecurity is increasingly complex due to evolving threats, technological advancements, and other factors, such as ransomware attacks and phishing and social engineering etc. There are countermeasures to deal with security issue in several ways, for example, anti-malware scanning, vulnerability shielding, threat detection and response, exploit prevention / memory protection, integrity assurance, identity-based segmentation, etc. Some artificial intelligence (AI)  / machine learning (ML) based cyberattack protection solutions have been studied, which focus on AI threat analysis and AI security mitigation strategies. However, it is impossible to perform such cyberattack protection solutions, for example, vulnerability scanning, security test, security risk analysis and applying countermeasures, in a living mobile network without side effect, e.g. causing delay of communication or even service interruption.SUMMARY

[0003] A brief summary of exemplary embodiments is provided below to provide basic understanding of some aspects of various embodiments. It should be noted that this summary is not intended to identify key features of essential elements or define scopes of the embodiments, and its sole purpose is to introduce some concepts in a simplified form as a preamble for a more detailed description provided below.

[0004] In a first aspect, disclosed is an apparatus for a MnS consumer. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to:transmit to a NDT service producer, a threat protection request for potential security threat assessment with at least one object; and receive from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.

[0005] In a second aspect, disclosed is an apparatus for a NDT service producer. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to: receive from a MnS consumer, a threat protection request for potential security threat assessment with at least one object; transmit to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and transmit to the MnS consumer, the threat assessment report.

[0006] In a third aspect, disclosed is an apparatus for a NF. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to: receive from a UE a first indicator indicating the UE supports security NDT; and transmit to the UE a second indicator indicating whether the security NDT is allowed for the UE.

[0007] In a fourth aspect, disclosed is an apparatus for a MnS producer. The apparatus may comprise at least one processor and at least one memory. The at least one memory may store instructions that, when executed by the at least one processor, may cause the apparatus at least to:receive from a NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and perform the countermeasure against the security threat based on the threat assessment report.

[0008] In a fifth aspect, disclosed is a method performed by an apparatus for a MnS consumer. The method may comprise: transmitting to a NDT service producer, a threat protection request for potential security threat assessment with at least one object; and receiving from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.

[0009] In a sixth aspect, disclosed is a method performed by an apparatus for a NDT service producer. The method may comprise: receiving from a MnS consumer, a threat protection request for potential security threat assessment with at least one object; transmitting to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and transmitting to the MnS consumer, the threat assessment report.

[0010] In a seventh aspect, disclosed is a method performed by an apparatus for a NF. The method may comprise: receiving from a UE a first indicator indicating the UE supports security NDT; and transmitting to the UE a second indicator indicating whether the security NDT is allowed for the UE.

[0011] In an eighth aspect, disclosed is a method performed by an apparatus for a MnS producer. The method may comprise: receiving from a NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and performing the countermeasure against the security threat based on the threat assessment report.

[0012] In a ninth aspect, disclosed is an apparatus for a MnS consumer. The apparatus may comprise: means for transmitting to a NDT service producer, a threat protection request for potential security threat assessment with at least one object; and means for receiving from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.

[0013] In a tenth aspect, disclosed is an apparatus for a NDT service producer. The apparatus may comprise: means for receiving from a MnS consumer, a threat protection request for potential security threat assessment with at least one object; means for transmitting to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and means for transmitting to the MnS consumer, the threat assessment report.

[0014] In an eleventh aspect, disclosed is an apparatus for a NF. The apparatus may comprise: means for receiving from a UE a first indicator indicating the UE supports security NDT; and means for transmitting to the UE a second indicator indicating whether the security NDT is allowed for the UE.

[0015] In a twelfth aspect, disclosed is an apparatus for a MnS producer. The apparatus may comprise: means for receiving from a NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and means for performing the countermeasure against the security threat based on the threat assessment report.

[0016] In a thirteenth aspect, a computer-readable medium is disclosed. The computer-readable medium may comprise program instructions that, when executed by an apparatus for a MnS consumer, may cause the apparatus at least to: transmit to a NDT service producer, a threat protection request for potential security threat assessment with at least one object; and receive from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.

[0017] In a fourteenth aspect, a computer-readable medium is disclosed. The computer-readable medium may comprise program instructions that, when executed by an apparatus for a NDT service producer, may cause the apparatus at least to: receive from a MnS consumer, a threat protection request for potential security threat assessment with at least one object; transmit to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and transmit to the MnS consumer, the threat assessment report.

[0018] In a fifteenth aspect, a computer-readable medium is disclosed. The computer-readable medium may comprise program instructions that, when executed by an apparatus for a NF, may cause the apparatus at least to: receive from a UE a first indicator indicating the UE supports security NDT; and transmit to the UE a second indicator indicating whether the security NDT is allowed for the UE.

[0019] In a sixteenth aspect, a computer-readable medium is disclosed. The computer-readable medium may comprise program instructions that, when executed by an apparatus for a MnS producer, may cause the apparatus at least to: receive from a NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and perform the countermeasure against the security threat based on the threat assessment report.

[0020] Other features and advantages of the example embodiments of the present disclosure will also be apparent from the following description of specific embodiments when read in conjunction with the accompanying drawings, which illustrate, by way of example, the principles of example embodiments of the present disclosure.BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Some example embodiments will now be described, by way of non-limiting examples, with reference to the accompanying drawings.

[0022] FIG. 1 illustrates an example of a communication network to which examples disclosed herein may be applied.

[0023] FIG. 2A shows an architecture to which the example embodiments according to the present disclosure can be implemented.

[0024] FIG. 2B shows an architecture to which the example embodiments according to the present disclosure can be implemented.

[0025] FIG. 3A shows an example diagram according to the example embodiments of the present disclosure.

[0026] FIG. 3B shows an example diagram for creating NDT instance to which the example embodiments of the present disclosure can be implemented.

[0027] FIG. 4A shows an example diagram according to the example embodiments of the present disclosure.

[0028] FIG. 4B shows an example diagram according to the example embodiments of the present disclosure.

[0029] FIG. 5 shows a flow chart illustrating an example method 500 according to the example embodiments of the present disclosure.

[0030] FIG. 6 shows a flow chart illustrating an example method 600 according to the example embodiments of the present disclosure.

[0031] FIG. 7 shows a flow chart illustrating an example method 700 according to the example embodiments of the present disclosure.

[0032] FIG. 8 shows a flow chart illustrating an example method 800 according to the example embodiments of the present disclosure.

[0033] FIG. 9 shows a block diagram illustrating an example apparatus according to the example embodiments of the present disclosure.

[0034] FIG. 10 shows a block diagram illustrating an example apparatus 1000 according to the example embodiments of the present disclosure.

[0035] FIG. 11 shows a block diagram illustrating an example apparatus 1100 according to the example embodiments of the present disclosure.

[0036] FIG. 12 shows a block diagram illustrating an example apparatus 1200 according to the example embodiments of the present disclosure.

[0037] FIG. 13 shows a block diagram illustrating an example apparatus 1300 according to the example embodiments of the present disclosure.

[0038] Throughout the drawings, same or similar reference numbers indicate same or similar elements. A repetitive description on the same elements would be omitted.DETAILED DESCRIPTION

[0039] Herein below, some example embodiments are described in detail with reference to the accompanying drawings. The following description includes specific details for the purpose of providing a thorough understanding of various concepts. However, it will be apparent to those skilled in the art that these concepts may be practiced without these specific details. In some instances, well known circuits, techniques and components are shown in block diagram form to avoid obscuring the described concepts and features.

[0040] The following embodiments are exemplary. Although the specification may refer to “an” , “one” , or “some” embodiment (s) in several locations of the text, this does not necessarily mean that each reference is made to the same embodiment (s) , or that a particular feature only applies to a single embodiment. Single features of different embodiments may also be combined to provide other embodiments. Further, when a particular feature, structure, or characteristic is described in connection of an embodiment, it is within the knowledge of one skilled in the art to apply such feature, structure, or characteristic in connection with other embodiments whether or not explicitly described. It shall be understood that although the terms “first, ” “second” and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.

[0041] For the purposes of the present disclosure, the phrases “at least one of A or B” , “at least one of A and B” , and “A and / or B” means (A) , (B) , or (A and B) . For the purposes of the present disclosure, the phrase “A, B, and / or C” means (A) , (B) , (C) , (A and B) , (A and C) , (B and C) , or (A, B, and C) .

[0042] Embodiments described may be implemented in a communication network, such as any of the following radio access technologies (RATs) : Worldwide Interoperability for Micro-wave Access (WiMAX) , Global System for Mobile communications (GSM, 2G) , GSM EDGE radio access Network (GERAN) , General Packet Radio Service (GRPS) , Universal Mobile Telecommunication System (UMTS, 3G) based on basic wideband-code division multiple access (W-CDMA) , high-speed packet access (HSPA) , Long Term Evolution (LTE) , LTE-Advanced, and enhanced LTE (eLTE) , 5G (also called NR) , or any future RAT such as 6G. Moreover, communication within the communication network may utilize any proper wireless communication technology, comprising but not limited to: Code Division Multiple Access (CDMA) , Frequency Division Multiple Access (FDMA) , Time Division Multiple Access (TDMA) , Frequency Division Duplex (FDD) , Time Division Duplex (TDD) , Multiple-Input Multiple-Output (MIMO) , Orthogonal Frequency Division Multiple (OFDM) , and / or Discrete Fourier Transform spread OFDM (DFT-s-OFDM) .

[0043] As used herein, the term “network device” or “network node” refers to a node in a communication network via which user equipment may access the network and / or which is capable of controlling radio communication and managing radio resources within a cell. The network node or network device may be referred to as a base station (BS) , an access point (AP) or an access node. The network device may be, depending on the applied technology, for example, a node B (NodeB or NB) , an evolved NodeB (eNodeB or eNB) , an NR NB (also referred to as a gNB) , a Remote Radio Unit (RRU) , a radio head (RH) , a remote radio head (RRH) , a relay, an Integrated Access and Backhaul (IAB) node, a low power node, a non-terrestrial network (NTN) or non-ground network device such as a satellite network device, a low earth orbit (LEO) satellite and a geosynchronous earth orbit (GEO) satellite, or an aircraft network device.

[0044] Moreover, in connection of split radio access network (RAN) , the network device may refer to a centralized unit (CU) of a base station and / or a distributed unit (DU) of a base station. An interface between CU and DU may be referred to as an F1 interface in NR. In the split RAN architecture, node operations may be carried out, at least partly, in the central / centralized unit, CU, (e.g. server, host or node) operationally coupled to the DU, (e.g. a radio head / node) . One CU may control one or more DUs, acting at least as transmit / receive (Tx / Rx) nodes. In some embodiments, the DUs may comprise e.g. a radio link control (RLC) , medium access control (MAC) layer and a physical (PHY) layer, whereas the CU may comprise the layers above RLC layer, such as a packet data convergence protocol (PDCP) layer, a radio resource control (RRC) and an internet protocol (IP) layers. Other functional splits are possible too. In practice, any processing task may be performed in either the CU or the DU and the boundary where the responsibility is shifted between the CU and the DU may depend on the applied implementation.

[0045] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example, a terminal device may be referred to as a communication device, user equipment (UE) , a Subscriber Station (SS) , or a Mobile Station (MS) . The terminal device may include a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, USB dongles, an Internet of Things (IoT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like.

[0046] A term “resource” , as used herein, may refer to radio resources in time domain, in frequency domain, in space domain, and / or in code domain. Some examples of resources include e.g. a physical resource block (PRB) , a radio frame, a subframe, a time slot, a subband, a frequency region, a sub-carrier, a beam, etc. The term “transmission” and / or “reception” may refer to wirelessly transmitting and / or receiving via a wireless propagation channel on radio resources.

[0047] FIG. 1 illustrates an example of a communication network to which examples disclosed herein may be applied. The communication network or a cellular communication network may comprise a network node 110 providing one or more cells, such as cell 100, and a network node 112 providing one or more other cells, such as cell 102. Each cell may be, e.g., a macro cell, a micro cell, femto, or a pico cell, for example. The cell may define a coverage area or a service area of the corresponding access node.

[0048] The network node 110 may provide a user equipment (UE) 120 (one or more UEs) with wireless access to the communication network. The wireless access may comprise downlink (DL) communication from the network node to the UE 120 and uplink (UL) communication from the UE 120 to the network node. Examples of uplink channels comprise physical uplink control channel (PUCCH) for transmitting control information and physical uplink shared channel (PUSCH) for transmitting data towards the network. Examples of downlink channels comprise physical downlink control channel (PDCCH) for transmitting control information and physical downlink shared channel (PDSCH) for transmitting data towards the user equipment.

[0049] There may be a plurality of UEs 120, 122 in the system. Each of them may be served by the same or by different network nodes 110, 112. UE may be configured with dual connectivity (DC) , wherein the UE, e.g. UE 120, may be connected to multiple network nodes 110, 112. The UEs 120, 122 may communicate with each other, in case device-to-device (D2D) communication interface is established between them via a so-called sidelink (SL) . Such D2D communications may be referred to as machine-to-machine, peer-to-peer (P2P) communications, or vehicle-to-vehicle (V2V) , for example.

[0050] In the case of multiple network nodes in the communication network, the network nodes may be connected to each other via an interface. LTE specifications call such an interface as X2 interface. An interface between an LTE node and a 5G node, or between two 5G nodes may be called Xn interface.

[0051] The network nodes 110 and 112 may be further connected via another interface to a core network 116 of the communication network. The LTE specifications specify the core network as an evolved packet core (EPC) , and the core network may comprise e.g. a mobility management entity (MME) and a gateway node. The MME may handle mobility of terminal devices in a tracking area encompassing a plurality of cells and handle signalling connections between the terminal devices and the core network. The gateway node may handle data routing in the core network and to / from the terminal devices. The 5G specifications specify the core network as a 5G core (5GC) . The 5G core may comprise e.g. an access and mobility management function (AMF) and a user plane function / gateway (UPF) and other functions. The AMF may handle termination of non-access stratum (NAS) signalling, NAS ciphering &integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management. The UPF node may support packet routing and forwarding, packet inspection and quality of service (QoS) handling, for example.

[0052] Artificial intelligence (AI) can be broadly defined as getting computers to perform tasks mimicking the human brain. Machine learning (ML) is one category of AI techniques: computer algorithms able to automatically improve their performance without explicit programming. AI algorithms were first conceived in the 1950’s but only in recent years AI / ML has become useful in vast area of real-world applications, partly due to advancements in computational power and in providing storage capacity for data.

[0053] AI / ML can help adjust and optimize radio access network (RAN) parameters and settings using (real-time) monitoring and prediction of network performance, quality, and demand. Additionally, AI / ML can identify and diagnose degradation in network performance, as well as provide protection from cyberattacks. AI / ML is usable in energy saving, load balancing, mobility optimization, link adaptation and security just to mention but a few.

[0054] It is envisioned that AI / ML will enable real-time analysis as well as automated operation and control in 5G and beyond RAN. This requires the availability of data streamed from wireless devices in a timely manner, especially in extremely time-critical applications such as real-time video monitoring and extended reality (XR) . This may be reflected in network architecture, such as by placing and moving ML agents to the required locations in the network, for example for data collection. User devices (mobile devices) may assist network in decision-making in resource management, thus a user device may act as an infrastructure resource.

[0055] As the network evolves to programmable and flexible cloud native implementation, AI / ML-based network automation will be used to simplify network management and optimization. It is expected that parts of the air interface, in particular signal processing algorithms, are supported and eventually even replaced with machine learning models. Thus, a 6G wireless communication standard will natively support an AI-based air interface.

[0056] Machine learning algorithms are usually classified into four different types: supervised learning, unsupervised learning, semi-supervised learning and reinforcement learning.

[0057] In supervised learning the algorithm learns from labelled data. For training, the algorithm receives input data and corresponding correct output labels. The algorithm is trained to predict accurate labels for new data.

[0058] In unsupervised learning the algorithm analyses unlabeled data. The aim is to discover patterns, relationships, or structures within the data, for example, unsupervised learning algorithms make groups of similar data points.

[0059] Semi-supervised learning is a hybrid machine learning approach that combines labelled and unlabelled data for training. A limited amount of labelled data and a larger set of unlabelled data is used to improve training. This approach is useful when acquiring labelled data is expensive or time-consuming as is the case in many real-world applications. Semi-supervised learning techniques can be applied to various tasks, such as classification, regression, and anomaly detection, allowing models to make more accurate predictions and generalize better in real-world scenarios.

[0060] Reinforcement learning is a machine learning algorithm which learns from trial and error. An ML agent interacts with environment and learns from experience aiming to maximize cumulative rewards. The ML agent receives feedback through rewards or penalties based on its actions. The agent learns to take actions that lead to the most favourable outcomes over time. The algorithm adapts to changing environments, and achieve long-term goals through a sequence of actions.

[0061] An example of an ML algorithm found applicable to adjust and optimize the radio access network (RAN) parameters and settings is deep learning. Deep learning is a subset of machine learning algorithms using a neural network. Neural networks are also known as artificial neural networks (ANNs) or simulated neural networks (SNNs) . Deep learning can be based on supervised, semi-supervised or unsupervised learning.

[0062] Artificial neural networks (ANNs) are comprised of an input layer, one or more hidden layers, and an output layer. Each node of a layer, or an artificial neuron, connects to another one and has an associated weight as well as a threshold value. If the output of an individual node is above the threshold value specified to this node, the node is activated and sending or passing data to the next layer of the neural network.

[0063] In the case the supervised learning is applied in the training of a neural network, the training is carried out by using examples, each of which contains a known "input" and "result" , forming probability-weighted associations between them. The training comprises determining the difference between the output of the neural network (aprediction) for an input and a target output for the same input. The difference is called an error value. The neural network then adjusts its weighted associations according to a learning rule and using this error value. Successive adjustments make the neural network produce output that is approaching the target output. After a sufficient number of these adjustments, the training can be terminated based on certain criteria.

[0064] Below issues regarding security assessment are common for user equipment (UE) and network: (1) No changes can be made to the 3rd Generation Partnership Project (3GPP) mobile network  without full qualification. Operations, such as security issue scanning, dynamic AI / ML analysis, or measuring response of network to traffic after applying countermeasures cannot be performed directly on the mobile network. (2) Real-time factors need to be considered after identifying security issues and applying  countermeasures. (3) A UE, group of UE or internet of things (IoT) device, e.g. IoT UE does not have a fully  functional lossless detection service on the current mobile network.

[0065] Currently, 3GPP does not have a complete solution for real-time analysis and resolution of security issues, and there is no self-security threat detection and protection system.

[0066] Network digital twin, i.e. NDT, can be used as a replica of a mobile network to emulate / simulate the behavior of the actual network. With the NDT, operations such as security scanning, AI-based defense, adversarial networks, and the application of countermeasures can be conducted in the virtual replica before making changes to the real 3GPP network.

[0067] Example embodiments of the present disclosure provide intelligent defense of the network, which may be termed as security threats assessment and mitigation automatically (STAAMA) based on NDT. According to example embodiments of the present disclosure, in case of a UE, group of UE, or IoT devices, deployed in a factory environment, wants to perform the vulnerability scanning, security test, security risk analysis and applying countermeasures in the factory environment, without side effect, network operator provided NDT service can be used.

[0068] For example, message tampering is a common threat that can originate from UE side or occur along a communication path, and happen on different layers, such as 3GPP transport layer or application layer. It can be caused by exploiting misconfiguration, e.g. disabled user plane (UP) integrity protection, or bidding down attack during policy negotiation, etc. Detecting such message tampering typically requires a comprehensive flow analysis across network functions (NFs) in the communication path, which demands significant resources such as network, central processing unit (CPU) and memory, and hence impacts the existing service. Operator may deploy NDT service to simulate different threat / attack scenarios, analyze the associated behavior, and identify the root cause, and then verify / validate corresponding countermeasure in the NDT before applying to the actual network.

[0069] According to example embodiments of the present disclosure, a UE, group of UE, IoT devices, and a network can be protected against unknown security threats / risks through NDT simulation synchronized automatic detection, diagnosis, and resolution. The example embodiments can assist in enhancing native security defenses, improving network security self-immunity, and efficiently verifying defense solutions against network security threats. Further, the example embodiments can construct a comprehensive view of the UE, network topology and traffic, which helps in monitoring, predicting, and addressing potential security issues in end-to-end or single-domain scenarios. By using management service (MnS) , the management and orchestration system can obtain results of verification and potential security risk defense solutions, helping to prevent threats from impacting the UE and actual network. Moreover, the example embodiments can enhance the security assurance methodology, e.g. described in 3GPP Technical Report (TR) 23.916, extend capability of the NDT and extend the NDT based security assurance use case, e.g. described in 3GPP TR 28.915. The example embodiments can build an intelligent security auto detection and mitigation system, which may be a self-security threat detection and protection system, to protect sixth generation of mobile communication system (6G) components.

[0070] The example embodiments can utilize NDT simulation to simulate threat attacks and explore defense methods against the threat attacks in a real environment. In the example embodiments, various simulated attacks include automated attacks, simulated hacking attempts, and creation of unknown attacks. The example embodiments can also generate different defense strategies by means of AI / ML. According to the example embodiments, continuous training takes place between attackers and defenders, so as to collect attack behavior patterns and generate corresponding defense strategies, which may be termed as “vaccines” . The vaccines, i.e. defense strategies, can be added to an immune repository and used by the physical / actual system. When the actual system faces the same threats, the actual system can respond rapidly to the same attacks with the defense strategies. The vaccines can be updated during the time cycle based on vaccine execution feedback and extended to include new attack defense schemes.

[0071] FIG. 2A shows an architecture to which the example embodiments according to the present disclosure can be implemented. Referring to FIG. 2A, a MnS consumer 210 may represent any device or entity which consumes management service and needs self-protection against security threat in a communication system. The MnS consumer 210 may be a UE, a network device, a network element, or a NF, etc. The network element may comprise radio access network (RAN) element, for example, a base station (BS) , such as a next generation node B (gNB) . An object 230 may represent one or more devices or entities which provide the management service for the MnS consumer 210. The object 230 may comprise a NF, an application function (AF) , a UE, a MnS producer, and / or a network management function, etc. in the communication system. The MnS producer may also be referred to as MnS provider. As the object 230, one or more NFs may comprise network data analytics function (NWDAF) , management data analytics (MDA) , audit logs, and / or performance management (PM) data, etc. Alternatively, or additionally, the at least one object 230 may be entities managed by core network (CN) . A NDT service producer 220 may represent any device or entity which provides NDT service for the MnS consumer 210 in the communication system. For the MnS consumer 210, the NDT service producer 220 may be a MnS producer, and for the object 230, the NDT service producer 220 may be a MnS consumer. The NDT service producer may also be referred to as NDT service provider.

[0072] The MnS consumer 210 may transmit to the NDT service producer 220, a threat protection request 212 for potential security threat assessment with the at least one object 230. For example, the MnS consumer 210 may invoke an application programming interface (API) for the threat protection request 212 to request self-protection. The threat protection request 212 may also be referred to as request 212 for threat protection or request 212 for protection against threat.

[0073] Receiving the threat protection request 212, the NDT service producer 220 may create a threat protection instance for starting security threat monitoring and defense of the security threat, based on the threat protection request 212. The NDT service producer 220 may repeatedly provide the management service of the potential security threat assessment for the MnS consumer 210 by means of the threat protection instance, until the MnS consumer 210 cancels the subscription of this management service.

[0074] The NDT service producer 220 may collect security related data 214 from the object 230. The security related data 214 may comprise audit log, advanced and intrusion detection environment (AIDE) log, etc. An AI / ML defense analytics 222 of the NDT service producer 220 may identify a security threat based on the security related data 214, e.g. finding a security threat by analyzing the collected logs. Here, a security threat may represent one or more identified potential security threats.

[0075] An immune repository 228 of the NDT service producer 220 may comprise a set of security threats and corresponding countermeasures already generated for mitigating / solving the security threats. In case the security threat occurs in an actual system, the actual system can use the corresponding countermeasure to defend or mitigate the security threat.

[0076] The AI / ML defense analytics 222 may check whether the identified security threat is already in the immune repository 228. In case the identified security threat is already in the immune repository 228, in some embodiments, the NDT service producer 220 may generate a threat assessment report 216 comprising the identified security threat and the corresponding countermeasure against the security threat and transmit the threat assessment report 216 to the MnS consumer 210. The threat assessment report 216 may also be referred to as report 216 on threat assessment or report 216 on assessment of threat.

[0077] In some embodiments, even if the identified security threat is already in the immune repository 228, the NDT service producer 220 may apply the countermeasure against the security threat in the NDT and generate the threat assessment report 216 in case the countermeasure can defend or mitigate the security threat in the NDT. Then, the NDT service producer 220 may transmit the threat assessment report 216 to the MnS consumer 210.

[0078] If the identified security threat is not in the immune repository 228, for example, the set of security threats in the immune repository 228 does not comprise the identified security threat or the set of security threats is empty and thus does not comprise any security threat, in some embodiments, then the NDT service producer 220 may create a simulator system 226, e.g. by the AI / ML defense analytics 222. The simulator system 226 may be created based on the security related data 214, to mirror the actual object 230.

[0079] In some embodiments, the NDT service producer 220 may create an attack simulator 224, e.g. by the AI / ML defense analytics 222. The attack simulator 224 may be created based on the identified security threat, to simulate the attack of the security threat against the simulator system 226.

[0080] The AI / ML defense analytics 222 may perform defense analysis to generate the countermeasure and generate the threat assessment report 216 in case of verifying the countermeasure successfully defends or mitigates the security threat. The detailed embodiments of the generation of the defense strategies will be described later.

[0081] Then, the NDT service producer 220 may transmit to the MnS consumer 210, the threat assessment report 216. In some embodiments, the threat assessment report 216 may comprise the identified security threat and the corresponding countermeasure against the security threat. Thus, in case of the occurrence of the security threat, the MnS consumer 210 may take appropriate action accordingly, for example, doing mitigation according to the countermeasure. In some embodiments, the NDT service producer 220 may also add / inject into the immune repository 228, the threat assessment report 216, or the identified security threat and the corresponding countermeasure.

[0082] FIG. 2B shows an architecture to which the example embodiments according to the present disclosure can be implemented. Compared to FIG. 2A, in FIG. 2B, the MnS consumer 210 is a UE 232 or a group 234 of UE, and a UE 235 may represent any UE of the group 234 of UE. The UE 232 or the UE 235 may be an IoT device 236, i.e. IoT UE 236. The UE 232, the UE 235, or the IoT UE 236 may transmit the threat protection request 212 to a UP function 248 and / or a control plane (CP) function 249.

[0083] For example, the UE 232, the UE 235, or the IoT UE 236 may invoke an API for the threat protection request 212 which may comprise metadata related to factory setup and / or UE positions. In some embodiments, the threat protection request 212 may be transmitted via non-access stratum (NAS) message to access and mobility management function (AMF) . Alternatively, in some embodiments, the threat protection request 212 may be transmitted to an AF.

[0084] The AMF may forward the threat protection request 212 to invoke the NDT service producer 220, e.g. via service based architecture (SBA) , to create the threat protection instance. Alternatively, the AF may forward the threat protection request 212, e.g. via network exposure function (NEF) , to invoke the NDT service producer 220 to create the threat protection instance. Then, the NDT service producer 220 may generate the threat assessment report 216 according to the operations described with respect to FIG. 2A. The threat assessment report 216 may be transmitted to the UE 232, the UE 235, or the IoT UE 236 via the path for the transmission of the threat protection request 212. In case the identified security threat is not in the immune repository 228, the NDT service producer 220 may add / inject into the immune repository 228, the threat assessment report 216, or the identified security threat and the corresponding countermeasure.

[0085] FIG. 3A shows an example diagram according to the example embodiments of the present disclosure. The operations shown in FIG. 3A may be performed by the MnS consumer 210, the NDT service producer 220, and the object 230.

[0086] The MnS consumer 210 may transmit to the NDT service producer 220, the threat protection request 212 for potential security threat assessment with the at least one object 230.

[0087] In some embodiments, the threat protection request 212 may comprise at least one of the following: origin type of the threat protection request, granularity period for security threat monitoring, or the at least one object for which a potential security threat is to be assessed. The origin type may indicate the source of the threat protection request 212, for example, the threat protection request 212 is initiated from a UE or a network. The granularity period may indicate the time period to monitor, for example, the security logs. The at least one object may also be referred to as target entity, which may be, for example, AMF, AF, etc., and be indicated by an identity of the target entity, such as distinguished name (DN) , universally unique identifier (UUID) , or uniform resource identifier (URI) , etc.

[0088] Receiving the threat protection request 212, in an operation 314, in some embodiments the NDT service producer 220 may create the threat protection instance for starting security threat monitoring and defense of the security threat, based on the threat protection request 212. The NDT service producer 220 may also perform a feasibility check to check whether the threat protection request 212 is feasible (success) or infeasible (failure) , and transmit to the MnS consumer 210, a response 316 indicating the status of the threat protection request 212.

[0089] Then, the NDT service producer 220 repeatedly performs the operations in Loop 1, until the MnS consumer 210 cancels the subscription of the security threat assessment.

[0090] In some embodiments, in an operation 318, the NDT service producer 220 may perform synchronization with the object 230. In the operation 318, the NDT service producer 220 as a MnS consumer may collect from the object 230 first security related data for simulation and verification which may be the security related data 214 shown in FIG. 2A and FIG. 2B. The first security related data may comprise, for example, network capability related information, network slicing information regarding resource aspects and / or other relevant data (e.g., the number of current subscribers, traffic collected in recent and historical periods) for simulation and verification of the behavior of security threats.

[0091] After synchronization with the object 230, in an operation 322, the NDT service producer 220 may identify the security threat based on the first security related data collected from the object 230. In the operation 322, the NDT service producer 220 may identify at least one security threat or find no security threat. In case of not finding security threat, the NDT service producer 220 may restart Loop 1 again to monitor security threat.

[0092] After identifying the security threat in the operation 322, in an operation 324, the NDT service producer 220 may check whether the security threat is in an immune repository, which may be the immune repository 228.

[0093] In case the identified security threat is already in the immune repository, in some embodiments, the NDT service producer 220 may generate the threat assessment report 216 comprising the identified security threat and the corresponding countermeasure against the security threat and transmit the threat assessment report 216 to the MnS consumer 210.

[0094] In case the identified security threat is already in the immune repository, in some embodiments, the NDT service producer 220 may apply the countermeasure against the security threat in the NDT and generate the threat assessment report 216 in case the countermeasure can defend or mitigate the security threat in the NDT. The verification of the countermeasure being capable of defending or mitigating the security threat may also be referred to as validation of the countermeasure. Then, the NDT service producer 220 may transmit the threat assessment report 216 to the MnS consumer 210.

[0095] In case the identified security threat is not in the immune repository, in an operation 326, the NDT service producer 220 may simulate the attack of the security threat against the simulated object 230 in the NDT. For example, the NDT service producer 220 may create the simulator system 226 based on the collected first security related data, and the simulator system 226 may comprise the simulated object mirroring the actual object 230. Then, for example, the NDT service producer 220 may create the attack simulator 224 based on the identified security threat, to simulate the attack of the security threat against the simulated object 230.

[0096] Then, in an operation 328, the NDT service producer 220 may conduct assessment and calculation for the security threat based on second security related data collected from the simulation of the attack of the security threat, in case the second security related data match the first security related data. During the simulation of the attack of the security threat, the NDT service producer 220 may collect the second security related data, which may comprise, for example, audit logs, fault management data, e.g., alarms, performance management data, e.g., performance measurement / key performance indicator (KPI) , configuration management data e.g., network topology and configuration, etc. If the second security related data match the first security related data, the simulation of the attack of the security threat is successful. In some embodiments, the NDT service producer 220 may perform the operation 328 at the AI / ML defense analytics 222.

[0097] Then, in an operation 332, the NDT service producer 220 may generate the countermeasure for the security threat based on the assessment and calculation by doing defense analysis. For example, the AI / ML defense analytics 222 may perform defense analysis and generate the countermeasure based on the assessment and calculation.

[0098] Then, in an operation 334, the NDT service producer 220 may generate the threat assessment report 216, in case of verifying the countermeasure successfully defends or mitigates the security threat. In some embodiments, the threat assessment report 216 may comprise at least one of the security assessment result or the countermeasure against the security threat.

[0099] In some embodiments, the security assessment result may comprise at least one of the following: an identifier (ID) of the security threat, a name of the security threat, a category of the security threat, a consequence of the security threat, or an impact level of the security threat. In some embodiments, the countermeasure may be used by the actual system to mitigate or defend the security threat.

[0100] In some embodiments, the NDT service producer 220 may also add into the immune repository, the threat assessment report 216, or the identified security threat and the corresponding countermeasure.

[0101] In some embodiments, the NDT service producer 220 may repeatedly perform the operations in Loop 2, until the validation of the countermeasure. In some embodiments, there may be a maximum number for the repetition of the operations in Loop 2. In case the number of times the operations in Loop 2 performed reaches the maximum number, but no countermeasure can be verified to successfully defend or mitigate the security threat, the NDT service producer 220 may perform the operation 334 to generate the threat assessment report 216 without a countermeasure.

[0102] The NDT service producer 220 may transmit the threat assessment report 216 to the MnS consumer 210. In some embodiments, the NDT service producer 220 may transmit the threat assessment report 216 to the object 230. In this case, in an operation 338, the object 230, as an actual system, may perform the countermeasure against the security threat based on the threat assessment report.

[0103] In some embodiments, the countermeasure may protect the object 230 in a reactive manner. For example, the performed countermeasure may defend the object 230 from being attacked by the occurrence of the security threat. Alternatively, for example, the performed countermeasure may mitigate / relieve the effect of the attack of the security threat.

[0104] In some embodiments, the countermeasure may protect the object 230 in a proactive manner. For example, the performed countermeasure may defend the object 230, such that the security threat cannot occur.

[0105] FIG. 3B shows an example diagram for creating NDT instance to which the example embodiments of the present disclosure can be implemented. The operations shown in FIG. 3B may be performed by the MnS consumer 210, the NDT service producer 220, and the object 230. The NDT service producer 220 and the at least one object 230 can be in CN domain, the NDT service producer 220 may be a MnS producer providing NDT management service, and the at least one object 230 may be managed entities.

[0106] The MnS consumer 210 may transmit to the NDT service producer 220, a NDT creation request 342 for creating an NDT instance. The NDT creation request 342 may comprise network modeling requirements with modeling scope and modeling scenarios, to specify the scope of the network to be modelled and network scenario to be modelled. The NDT service producer 220 may create a new information object class (IOC) , which may be a name contained in a subnetwork or a managed function.

[0107] Receiving the NDT creation request 342, based on the modeling requirements, the NDT service producer 220 may perform an operation 344 to collect data from the object 230 and create a NDT instance. The NDT service producer 220 may transmit to the MnS consumer 210 a notification 346 notifying that the NDT instance is created. Then, the MnS consumer 210, the NDT service producer 220, and the object 230 may perform the operations with respect to FIG. 3A.

[0108] The following Table 1 shows an example of context data in the threat protection request 212 according to example embodiments of the present disclosure. Table 1: threatProtectionRequest Context Data (M indicates mandatory, O indicates optional)

[0109] The following Table 2 shows an example of context data in the threat assessment report 216 according to example embodiments of the present disclosure. Table 2: threatAssesmentReport Context Data

[0110] FIG. 4A shows an example diagram according to the example embodiments of the present disclosure. The example embodiments with respect to FIG. 4A may be implemented to a scenario where an operator provides NDT service to UE, a user has bought this subscription and also consented the operator to collect data for security analysis with NDT service. The operator assigns NDT client ID “ABC” to the UE. The user can provide live camera feed to an AF or can provide factory details to the AF owned by the operator. The operator deploys security NDT service in CN and the NDT service is registered to a network repository function (NRF) . For example, in an operation 414, the NDT service producer 220 registers a service of a security NDT in a NRF 450.

[0111] In the example embodiments with respect to FIG. 4A, the MnS consumer 210 is a UE 410, which may be the UE 232, the UE 235, or the IoT UE 236 shown in FIG. 2B. The UE 410 may be a device in the intelligent factory.

[0112] The UE 410 may transmit to a CP function 420, an indicator 412 indicating the UE 410 supports security NDT. The CP function 420 may be, for example, mobility management (MM) NF, or MM AMF, etc. The indicator 412 may be transmitted, for example, via a UE registration request.

[0113] Receiving the UE registration request, the CP function 420 may find that the UE registration request comprises the indicator 412 for the security NDT. In an operation 416, the CP function 420 may check with the NRF 450, whether a service of the security NDT is available.

[0114] In case the service of the security NDT is available, in an operation 418, the CP function 420 may check with a unified data management (UDM) 430, whether the service of the security NDT belongs to subscription of the UE 410 and the UE 410 is allowed to collect data for the service of the security NDT, to determine whether the security NDT is allowed for the UE 410. For example, if the service of security NDT is part of the subscription and the user allows to collect data for the service, the CP function 420 may determine that the security NDT is allowed for the UE 410.

[0115] Then, the CP function 420 may transmit to the UE 410, an indicator 422 indicating whether the security NDT is allowed for the UE 410. The indicator 422 may be transmitted, for example, via registration accept message. Assuming that the security NDT is allowed for the UE 410, example embodiments with respect to FIG. 4B can be implemented to the scenario of FIG. 4A.

[0116] FIG. 4B shows an example diagram according to the example embodiments of the present disclosure. Assuming that there are many UEs / IoT devices in a factory, and these UEs / IoT devices are connected or configured to do a job, the UE 410 may represent any of the UEs / IoT devices in the factory.

[0117] In the example embodiments with respect to FIG. 4B, the threat protection request 212 and the threat assessment report 216 can be transmitted via at least one of the following: a UP function 460, or a CP function 470. The CP function 470 may be the same as or different from the CP function 420 shown in FIG. 4A.

[0118] In Option 1 shown in FIG. 4B, the UE 410 transmits the threat protection request 212 to the UP function 460. For example, for the UE 410 to request NDT service from the operator, the user may invoke an application (App) , and the App may cause the UE 410 to send a NAS message carrying the threat protection request 212 to the UP function 460. If the UE 410 is a robot UE, the UE 410 may itself decide to request the NDT service from the network.

[0119] In some embodiments, the threat protection request 212 may contain the following: a threat assessment report from NDT service is requested; client ID, which is ABC; and metadata. In some embodiments, the metadata may comprise context data in Table 1. In some embodiments, the metadata may further comprise, for example, factory layout, which may be three-dimension (3D) model or different representation. Alternatively, based on an agreement between the user (factory owner) and the operator, the metadata may comprise live camera feed. Alternatively, based on the client ID, a NF of the operator can fetch the live camera feed from an AF. Depending on the factory setup or IoT clustering, the threat protection request 212 may comprise information on neighboring UEs.

[0120] Then, the UP function 460 may transmit the threat protection request 212 to the NDT service producer 220. If the NDT service producer 220 is in management domain, then the UP function 460 can transmit the threat protection request 212 via operation administration and maintenance (OAM) interface.

[0121] Receiving the threat protection request 212, at 434, the NDT service producer 220 may generate the threat assessment report 216 according to the operations described with respect to FIG. 2A, FIG. 2B, FIG. 3A and / or FIG. 3B. Then, the NDT service producer 220 may transmit the threat assessment report 216 to the UE 410 via the UP function 460.

[0122] Those skilled in the art may understand that in the example embodiments of Option 1, the threat protection request 212 and the threat assessment report 216 may be transmitted further via a UP function and / or a CP function.

[0123] In Option 2 shown in FIG. 4B, the UE 410 transmit the threat protection request 212 to the CP function 470. For example, for the UE 410 to request NDT service from the operator, the user may invoke an App and the App may cause the UE 410 to send a message carrying the threat protection request 212 to the CP function 470.

[0124] Then, the CP function 470 may transmit the threat protection request 212 to the NDT service producer 220. At 434, the NDT service producer 220 may generate the threat assessment report 216 according to the operations described with respect to FIG. 2A, FIG. 2B, FIG. 3A and / or FIG. 3B. Then, the NDT service producer 220 may transmit the threat assessment report 216 to the UE 410 via the CP function 470.

[0125] Those skilled in the art may understand that in the example embodiments of Option 2, the threat protection request 212 and the threat assessment report 216 may be transmitted further via a UP function and / or a CP function.

[0126] Based on the threat assessment report 216, in an operation 438, the UE 410 may perform countermeasure against the security threat and transmit to the NDT service producer 220 a feedback 442 of performing the countermeasure.

[0127] In some embodiments, the countermeasure may protect the UE 410 in a reactive manner. For example, the performed countermeasure may defend the UE 410 from being attacked by the occurrence of the security threat. Alternatively, for example, the performed countermeasure may mitigate / relieve the effect of the attack of the security threat.

[0128] In some embodiments, the countermeasure may protect the UE 410 in a proactive manner. For example, the performed countermeasure may defend the UE 410, such that the security threat cannot occur.

[0129] For example, in the operation 438, the UE 410 may take appropriate actions as the countermeasure accordingly and transmit to the NDT service producer 220 the feedback 442 of performing the actions. In some embodiments, the UE 410 may take the appropriate actions automatically, for example, performing the countermeasure automatically in case of the occurrence of the security threat. Alternatively, or additionally, in some embodiments, the UE 410 may inform the user to take the actions.

[0130] In some embodiments, the actions may comprise: sending the content of the threat assessment report 216 to upper / application layer, and the application layer may display the content so that the user can be take appropriate action; stopping / starting the other devices, such as a camera, sensor, etc., associated with the UE 410. If the UE 410 is a robot UE, the UE 410 may instruct other UE (s) over device-to-device (D2D) to align the overall procedures. For example, the robot UE 410 may instruct other UE (s) to stop protocol data unit (PDU) , and / or the robot UE 410 may instruct another robot UE to stop / start the other devices, such as camera, sensor, etc., associated with the UE 410. Based on the feedback 442, the NDT service producer 220 may get positive, negative, or any other information regarding the performing of the countermeasure.

[0131] The example embodiments according to the present disclosure can calculate and evaluate whether there is potential security threat (s)  / risk (s) and generate countermeasure (s) against identified threat (s)  / risk (s) , based on analysis model supported by AI / ML relevant statistical analysis solutions, with collected security log such as audit logs, AIDE logs, PM, or alarms, etc., and using the security NDT service to simulate an attack of evolved security threat (s) and do defense analysis.

[0132] The example embodiments according to the present disclosure can also support to simulate UE to UE, UE to network, and / or network to network interaction, by potential security threat / risk scanning, analysis, and solution exploration. According to the example embodiments, after a resolution / countermeasure is generated, the resolution / countermeasure can be verified in security NDT, and in case of validation, the resolution / countermeasure can be used to defend or mitigate the security threat in actual system.

[0133] The example embodiments can supplement and enhance the security risk defense information in 3GPP and zero-touch network and service management (ZSM) . For example, the example embodiments can improve security and trust protection mechanism, such as spanning network security, user data confidentiality, service continuity, mitigation of emerging threats, and integration of quantum-safe security mechanisms. Further, an interface between a UE and an AF, for example, the API invoked by the MnS consumer 210 for the threat protection request 212, can be introduced to support UE and network automatic security assessment.

[0134] FIG. 5 shows a flow chart illustrating an example method 500 according to the example embodiments of the present disclosure. The example method 500 may be performed, for example, by an apparatus for a MnS consumer, such as the MnS consumer 210 above mentioned.

[0135] Referring to FIG. 5, the example method 500 may comprise: an operation 510 of transmitting to a NDT service producer, a threat protection request for potential security threat assessment with at least one object; and an operation 520 of receiving from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.

[0136] In some embodiments, the threat protection request may comprise at least one of the following: origin type of the threat protection request, granularity period for security threat monitoring, or the at least one object for which a potential security threat is to be assessed.

[0137] In some embodiments, the security assessment result may comprise at least one of the following: an identifier of the security threat, a name of the security threat, a category of the security threat, a consequence of the security threat, or an impact level of the security threat.

[0138] In some embodiments, the countermeasure may be used by an actual system to defend or mitigate the security threat.

[0139] In some embodiments, the MnS consumer may be a network element and / or a network function.

[0140] In some embodiments, the MnS consumer may be a UE, and the threat protection request and the threat assessment report are transmitted via at least one of the following: a UP function, or a first CP function.

[0141] In some embodiments, the UE may be an IoT UE.

[0142] In some embodiments, the example method 500 may comprise: transmitting to a second CP function, a first indicator indicating the UE supports security NDT; and receiving from the second CP function, a second indicator indicating whether the security NDT is allowed for the UE.

[0143] In some embodiments, the example method 500 may comprise: performing the countermeasure against the security threat based on the threat assessment report; and transmitting to the NDT service producer, a feedback of performing the countermeasure.

[0144] In some embodiments, the at least one object comprises at least one of the following: a NF, an AF, a UE, or a MnS producer.

[0145] FIG. 6 shows a flow chart illustrating an example method 600 according to the example embodiments of the present disclosure. The example method 600 may be performed, for example, by an apparatus for a NDT service producer, such as the NDT service producer 220 above mentioned.

[0146] Referring to FIG. 6, the example method 600 may comprise: an operation 610 of receiving from a MnS consumer, a threat protection request for potential security threat assessment with at least one object; an operation 620 of transmitting to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and an operation 630 of transmitting to the MnS consumer, the threat assessment report.

[0147] In some embodiments, the example method 600 may comprise: creating a threat protection instance for starting security threat monitoring and defense of the security threat, based on the threat protection request.

[0148] In some embodiments, the example method 600 may comprise: identifying the security threat based on first security related data collected from the object after synchronization with the at least one object; and checking whether the security threat is in an immune repository, which comprises a set of security threats and corresponding countermeasures.

[0149] In some embodiments, in case the security threat is in the immune repository, the example method 600 may comprise: generating the threat assessment report based on the immune repository.

[0150] In some embodiments, in case the security threat is in the immune repository, the example method 600 may comprise: applying the countermeasure against the security threat in the NDT; and generating the threat assessment report in case the countermeasure successfully defends or mitigates the security threat in the NDT.

[0151] In some embodiments, in case the security threat is not in the immune repository, the example method 600 may comprise: simulating an attack of the security threat against the simulated object in the NDT; conducting assessment and calculation for the security threat based on second security related data collected from the simulation of the attack of the security threat, in case the second security related data match the first security related data; generating the countermeasure for the security threat based on the assessment and calculation by doing defense analysis; and generating the threat assessment report and add the threat assessment report into the immune repository, in case of verifying the countermeasure successfully defends or mitigates the security threat.

[0152] In some embodiments, the at least one object may comprise at least one of the following: a NF, an AF, a UE, or a MnS producer.

[0153] FIG. 7 shows a flow chart illustrating an example method 700 according to the example embodiments of the present disclosure. The example method 700 may be performed, for example, by an apparatus for a NF, such as the CP function 420 above mentioned.

[0154] Referring to FIG. 7, the example method 700 may comprise: an operation 710 of receiving from a UE a first indicator indicating the UE supports security NDT; and an operation 720 of transmitting to the UE a second indicator indicating whether the security NDT is allowed for the UE.

[0155] In some embodiments, the example method 700 may comprise: checking with a NRF, whether a service of the security NDT is available; and in case the service of the security NDT is available, checking with a UDM whether the service of the security NDT belongs to subscription of the UE and the UE is allowed to collect data for the service of the security NDT, to determine whether the security NDT is allowed for the UE.

[0156] In some embodiments, the NF may be a CP function.

[0157] FIG. 8 shows a flow chart illustrating an example method 800 according to the example embodiments of the present disclosure. The example method 800 may be performed, for example, by an apparatus for a MnS producer, such as the object 230 above mentioned.

[0158] Referring to FIG. 8, the example method 800 may comprise: an operation 810 of receiving from a NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and an operation 820 of performing the countermeasure against the security threat based on the threat assessment report.

[0159] Fig. 9 shows, by way of example, a block diagram of an apparatus 10. The apparatus 10 comprises, for example, at least one processor 12 and at least one memory 14 storing instructions 15 that, when executed by the at least one processor, cause the apparatus 10 at least to perform the method or methods as disclosed herein, and any of the embodiments thereof. In an example, the at least one memory and the instructions (e.g. a computer program code, software) , are configured, with the at least one processor, to cause the apparatus 10 to perform the method or methods as disclosed herein, and any of the embodiments thereof.

[0160] A processor 12 may comprise circuitry, or be constituted as circuitry or circuitries, the circuitry or circuitries being configured to perform phases of methods in accordance with example embodiments described herein. As used in this application, the term “circuitry” may refer to one or more or all of the following: (a) hardware-only circuit implementations, such as implementations in only analog and / or digital circuitry, and (b) combinations of hardware circuits and software, such as, as applicable: (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a user equipment, to perform various functions) and (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to all uses of this term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the particular claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0161] The memory 14 may be implemented using any suitable data storage technology. The memory may comprise a database for storing data. The memory 14 may be at least in part external to apparatus 10 but accessible to apparatus 10.

[0162] The instructions 15 may be comprised in a computer readable medium or a non-transitory computer readable medium. A term non-transitory, as used herein, is a limitation of the medium itself (i.e. tangible, not a signal) as opposed to a limitation on data storage persistency (e.g. random access memory, RAM, vs. read only memory, ROM) .

[0163] For example, the apparatus 10 is a MnS consumer, such as the MnS consumer 210. As another example, the apparatus is comprised in such a MnS consumer, e.g. as a chipset configured to control the MnS consumer 210. The apparatus 10 may be caused or configured to perform at least the method 500 and / or any one or more of the embodiments described.

[0164] As another example, the apparatus 10 is a NDT service producer, e.g. the NDT service producer 220. In another embodiment, the apparatus is comprised in such a NDT service producer, e.g. as a chipset configured to control the NDT service producer. The apparatus 10 may be caused or configured to perform at least the method 600 and / or any one or more of the embodiments described.

[0165] As another example, the apparatus 10 is a NF, e.g. the CP function 420. In another embodiment, the apparatus is comprised in such a NF, e.g. as a chipset configured to control the NF. The apparatus 10 may be caused or configured to perform at least the method 700 and / or any one or more of the embodiments described.

[0166] As another example, the apparatus 10 is a MnS producer, e.g. the object 230. In another embodiment, the apparatus is comprised in such a MnS producer, e.g. as a chipset configured to control the MnS producer. The apparatus 10 may be caused or configured to perform at least the method 800 and / or any one or more of the embodiments described.

[0167] The apparatus may comprise one or more entities of any of protocol layers, such as a MAC entity, an RRC entity, an RLC entity, a PDCP entity or a PHY entity. In some embodiments, the entity is configured to perform at least the method 500, the method 600, the method 700, or the method 800, and / or any one or more of the embodiments described.

[0168] The apparatus 10 comprises a radio interface 16. The radio interface 16 may provide the apparatus 10 with communication capabilities. The radio interface 16 may comprise a receiver configured to receive information in accordance with at least one cellular or non-cellular standard. The radio interface 16 may comprise a transmitter configured to transmit information in accordance with at least one cellular or non-cellular standard. The receiver may comprise more than one receiver. The transmitter may comprise more than one transmitter. The radio interface 16 may comprise a transceiver configured to receive and transmit information in accordance with at least one cellular or non-cellular standard. The transceiver may comprise more than one transceiver.

[0169] The apparatus 10 may comprise a user interface 18 comprising, for example, at least one of a keypad, a microphone, a touch display, a display, a speaker, etc. The user interface 18 may be used to control the apparatus by the user. The user interface 18 may be external to the apparatus 10. For example, the apparatus 10 may be connected to another device, such as a computer, either via wireless or wired connection, and the apparatus 10 is controlled by the user via the computer.

[0170] In an embodiment, at least some of the processes described herein may be carried out by an apparatus comprising means for carrying out at least some of the described processes. Means for performing method steps as disclosed herein may include software and / or hardware components of the apparatus 10. For example, the at least one processor 12, the memory 14, and the computer program code form means for carrying out the method or methods as disclosed herein, and any of the embodiments thereof. As used herein the term “means” is to be construed in singular form, i.e. referring to a single element, or in plural form, i.e. referring to a combination of single elements. Therefore, terminology “means for [performing A, B, C] ” , is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C. Further, terminology “means for performing A, means for performing B, means for performing C” is to be interpreted to cover an apparatus in which there is only one means for performing A, B and C, or where there are separate means for performing A, B and C, or partially or fully overlapping means for performing A, B, C.

[0171] FIG. 10 shows a block diagram illustrating an example apparatus 1000 according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of a MnS consumer, such as the MnS consumer 210 in the above examples.

[0172] As shown in FIG. 10, the example apparatus 1000 may comprise: means 1010 for transmitting to a NDT service producer, a threat protection request for potential security threat assessment with at least one object; and means 1020 for receiving from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.

[0173] In some embodiments, the threat protection request may comprise at least one of the following: origin type of the threat protection request, granularity period for security threat monitoring, or the at least one object for which a potential security threat is to be assessed.

[0174] In some embodiments, the security assessment result may comprise at least one of the following: an identifier of the security threat, a name of the security threat, a category of the security threat, a consequence of the security threat, or an impact level of the security threat.

[0175] In some embodiments, the countermeasure may be used by an actual system to defend or mitigate the security threat.

[0176] In some embodiments, the MnS consumer may be a network element and / or a network function.

[0177] In some embodiments, the MnS consumer may be a UE, and the threat protection request and the threat assessment report are transmitted via at least one of the following: a UP function, or a first CP function.

[0178] In some embodiments, the UE may be an IoT UE.

[0179] In some embodiments, the apparatus 1000 may comprise: means for transmitting to a second CP function, a first indicator indicating the UE supports security NDT; and means for receiving from the second CP function, a second indicator indicating whether the security NDT is allowed for the UE.

[0180] In some embodiments, the apparatus 1000 may comprise: means for performing the countermeasure against the security threat based on the threat assessment report; and means for transmitting to the NDT service producer, a feedback of performing the countermeasure.

[0181] In some embodiments, the at least one object comprises at least one of the following: a NF, an AF, a UE, or a MnS producer.

[0182] In some example embodiments, examples of means in the example apparatus 1000 may include circuitries. For example, an example of means 1010 may include a circuitry configured to perform the operation 510 of the example method 500, and an example of means 1020 may include a circuitry configured to perform the operation 520 of the example method 500.

[0183] The example apparatus 1000 may further include means comprising circuitry configured to perform the example method 500. In some example embodiments, examples of means may also include software modules and any other suitable function entities.

[0184] FIG. 11 shows a block diagram illustrating an example apparatus 1100 according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of a NDT service producer, such as the NDT service producer 220 in the above examples.

[0185] As shown in FIG. 11, the example apparatus 1100 may comprise: means 1110 for receiving from a MnS consumer, a threat protection request for potential security threat assessment with at least one object; means 1120 for transmitting to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and means 1130 for transmitting to the MnS consumer, the threat assessment report.

[0186] In some embodiments, the apparatus 1100 may comprise: means for creating a threat protection instance for starting security threat monitoring and defense of the security threat, based on the threat protection request.

[0187] In some embodiments, the apparatus 1100 may comprise: means for identifying the security threat based on first security related data collected from the object after synchronization with the at least one object; and means for checking whether the security threat is in an immune repository, which comprises a set of security threats and corresponding countermeasures.

[0188] In some embodiments, in case the security threat is in the immune repository, the apparatus 1100 may comprise: means for generating the threat assessment report based on the immune repository.

[0189] In some embodiments, in case the security threat is in the immune repository, the apparatus 1100 may comprise: means for applying the countermeasure against the security threat in the NDT; and means for generating the threat assessment report in case the countermeasure successfully defends or mitigates the security threat in the NDT.

[0190] In some embodiments, in case the security threat is not in the immune repository, the apparatus 1100 may comprise: means for simulating an attack of the security threat against the simulated object in the NDT; means for conducting assessment and calculation for the security threat based on second security related data collected from the simulation of the attack of the security threat, in case the second security related data match the first security related data; means for generating the countermeasure for the security threat based on the assessment and calculation by doing defense analysis; and means for generating the threat assessment report and add the threat assessment report into the immune repository, in case of verifying the countermeasure successfully defends or mitigates the security threat.

[0191] In some embodiments, the at least one object may comprise at least one of the following: a NF, an AF, a UE, or a MnS producer.

[0192] In some example embodiments, examples of means in the example apparatus 1100 may include circuitries. For example, an example of means 1110 may include a circuitry configured to perform the operation 610 of the example method 600, an example of means 1120 may include a circuitry configured to perform the operation 620 of the example method 600, and an example of means 1130 may include a circuitry configured to perform the operation 630 of the example method 600.

[0193] The example apparatus 1100 may further include means comprising circuitry configured to perform the example method 600. In some example embodiments, examples of means may also include software modules and any other suitable function entities.

[0194] FIG. 12 shows a block diagram illustrating an example apparatus 1200 according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of a NF, such as the CP function 420 in the above examples.

[0195] As shown in FIG. 12, the example apparatus 1200 may comprise: means 1210 for receiving from a UE a first indicator indicating the UE supports security NDT; and means 1220 for transmitting to the UE a second indicator indicating whether the security NDT is allowed for the UE.

[0196] In some embodiments, the apparatus 1200 may comprise: means for checking with a NRF, whether a service of the security NDT is available; and means for in case the service of the security NDT is available, checking with a UDM whether the service of the security NDT belongs to subscription of the UE and the UE is allowed to collect data for the service of the security NDT, to determine whether the security NDT is allowed for the UE.

[0197] In some embodiments, the NF may be a CP function.

[0198] In some example embodiments, examples of means in the example apparatus 1200 may include circuitries. For example, an example of means 1210 may include a circuitry configured to perform the operation 710 of the example method 700, and an example of means 1220 may include a circuitry configured to perform the operation 720 of the example method 700.

[0199] The example apparatus 1200 may further include means comprising circuitry configured to perform the example method 700. In some example embodiments, examples of means may also include software modules and any other suitable function entities.

[0200] FIG. 13 shows a block diagram illustrating an example apparatus 1300 according to the example embodiments of the present disclosure. The apparatus, for example, may be at least part of a MnS producer, such as the object 230 in the above examples.

[0201] As shown in FIG. 13, the example apparatus 1300 may comprise: means 1310 for receiving from a NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and means 1320 for performing the countermeasure against the security threat based on the threat assessment report.

[0202] In some example embodiments, examples of means in the example apparatus 1300 may include circuitries. For example, an example of means 1310 may include a circuitry configured to perform the operation 810 of the example method 800, and an example of means 1320 may include a circuitry configured to perform the operation 820 of the example method 800.

[0203] The example apparatus 1300 may further include means comprising circuitry configured to perform the example method 800. In some example embodiments, examples of means may also include software modules and any other suitable function entities.

[0204] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for a MnS consumer, such as the MnS consumer 210 in the above examples, may cause the apparatus at least to: transmit to a NDT service producer, a threat protection request for potential security threat assessment with at least one object; and receive from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.

[0205] In some embodiments, the threat protection request may comprise at least one of the following: origin type of the threat protection request, granularity period for security threat monitoring, or the at least one object for which a potential security threat is to be assessed.

[0206] In some embodiments, the security assessment result may comprise at least one of the following: an identifier of the security threat, a name of the security threat, a category of the security threat, a consequence of the security threat, or an impact level of the security threat.

[0207] In some embodiments, the countermeasure may be used by an actual system to defend or mitigate the security threat.

[0208] In some embodiments, the MnS consumer may be a network element and / or a network function.

[0209] In some embodiments, the MnS consumer may be a UE, and the threat protection request and the threat assessment report are transmitted via at least one of the following: a UP function, or a first CP function.

[0210] In some embodiments, the UE may be an IoT UE.

[0211] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: transmit to a second CP function, a first indicator indicating the UE supports security NDT; and receive from the second CP function, a second indicator indicating whether the security NDT is allowed for the UE.

[0212] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: perform the countermeasure against the security threat based on the threat assessment report; and transmit to the NDT service producer, a feedback of performing the countermeasure.

[0213] In some embodiments, the at least one object comprises at least one of the following: a NF, an AF, a UE, or a MnS producer.

[0214] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for a NDT service producer, such as the NDT service producer 220 in the above examples, may cause the apparatus at least to: receive from a MnS consumer, a threat protection request for potential security threat assessment with at least one object; transmit to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and transmit to the MnS consumer, the threat assessment report.

[0215] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: create a threat protection instance for starting security threat monitoring and defense of the security threat, based on the threat protection request.

[0216] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: identify the security threat based on first security related data collected from the object after synchronization with the at least one object; and check whether the security threat is in an immune repository, which comprises a set of security threats and corresponding countermeasures.

[0217] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, in case the security threat is in the immune repository, may cause the apparatus to: generate the threat assessment report based on the immune repository.

[0218] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, in case the security threat is in the immune repository, may cause the apparatus to: apply the countermeasure against the security threat in the NDT; and generate the threat assessment report in case the countermeasure successfully defends or mitigates the security threat in the NDT.

[0219] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, in case the security threat is not in the immune repository, may cause the apparatus to: simulate an attack of the security threat against the simulated object in the NDT; conduct assessment and calculation for the security threat based on second security related data collected from the simulation of the attack of the security threat, in case the second security related data match the first security related data; generate the countermeasure for the security threat based on the assessment and calculation by doing defense analysis; and generate the threat assessment report and add the threat assessment report into the immune repository, in case of verifying the countermeasure successfully defends or mitigates the security threat.

[0220] In some embodiments, the at least one object may comprise at least one of the following: a NF, an AF, a UE, or a MnS producer.

[0221] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for a NF, such as the CP function 420 in the above examples, may cause the apparatus at least to: receive from a UE a first indicator indicating the UE supports security NDT; and transmit to the UE a second indicator indicating whether the security NDT is allowed for the UE.

[0222] In some embodiments, the computer-readable medium may include instructions that, when executed by the apparatus, may cause the apparatus to: check with a NRF, whether a service of the security NDT is available; and in case the service of the security NDT is available, check with a UDM whether the service of the security NDT belongs to subscription of the UE and the UE is allowed to collect data for the service of the security NDT, to determine whether the security NDT is allowed for the UE.

[0223] In some embodiments, the NF may be a CP function.

[0224] The example embodiments of the present disclosure also provide a computer-readable medium comprising program instructions that, when executed by an apparatus for a MnS producer, such as the object 230 in the above examples, may cause the apparatus at least to: receive from a NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; and perform the countermeasure against the security threat based on the threat assessment report.

[0225] As used herein, “at least one of the following: <a list of two or more elements>” and “at least one of <a list of two or more elements>” and similar wording, where the list of two or more elements are joined by “and” or “or” , mean at least any one of the elements, or at least any two or more of the elements, or at least all the elements.

[0226] The term “terminal device” refers to any end device that may be capable of wireless communication. By way of example rather than limitation, a terminal device may also be referred to as a communication device, user equipment (UE) , a Subscriber Station (SS) , a Portable Subscriber Station, a Mobile Station (MS) , or an Access Terminal (AT) . The terminal device may include, but is not limited to, a mobile phone, a cellular phone, a smart phone, voice over IP (VoIP) phones, wireless local loop phones, a tablet, a wearable terminal device, a personal digital assistant (PDA) , portable computers, desktop computer, image capture terminal devices such as digital cameras, gaming terminal devices, music storage and playback appliances, vehicle-mounted wireless terminal devices, wireless endpoints, mobile stations, laptop-embedded equipment (LEE) , laptop-mounted equipment (LME) , USB dongles, smart devices, wireless customer-premises equipment (CPE) , an Internet of Things (loT) device, a watch or other wearable, a head-mounted display (HMD) , a vehicle, a drone, a medical device and applications (e.g., remote surgery) , an industrial device and applications (e.g., a robot and / or other wireless devices operating in an industrial and / or an automated processing chain contexts) , a consumer electronics device, a device operating on commercial and / or industrial wireless networks, and the like. The terminal device may also correspond to a Mobile Termination (MT) part of an IAB node (e.g., a relay node) . In the above description, the terms “terminal device” , “communication device” , “terminal” , “user equipment” and “UE” may be used interchangeably.

[0227] The term “circuitry” throughout this disclosure may refer to one or more or all of the following: (a) hardware-only circuit implementations (such as implementations in only analog and / or digital circuitry) ; (b) combinations of hardware circuits and software, such as (as applicable) (i) a combination of analog and / or digital hardware circuit (s) with software / firmware and (ii) any portions of hardware processor (s) with software (including digital signal processor (s) ) , software, and memory (ies) that work together to cause an apparatus, such as a mobile phone or server, to perform various functions) ; and (c) hardware circuit (s) and or processor (s) , such as a microprocessor (s) or a portion of a microprocessor (s) , that requires software (e.g., firmware) for operation, but the software may not be present when it is not needed for operation. This definition of circuitry applies to one or all uses of this term in this disclosure, including in any claims. As a further example, as used in this disclosure, the term circuitry also covers an implementation of merely a hardware circuit or processor (or multiple processors) or portion of a hardware circuit or processor and its (or their) accompanying software and / or firmware. The term circuitry also covers, for example and if applicable to the claim element, a baseband integrated circuit or processor integrated circuit for a mobile device or a similar integrated circuit in server, a cellular network device, or other computing or network device.

[0228] Another example embodiment may relate to computer program codes or instructions which may cause an apparatus to perform at least the respective methods described above. Another example embodiment may be related to a computer-readable medium having such computer program codes or instructions stored thereon. In some embodiments, such a computer-readable medium may include at least one storage medium in various forms such as a volatile memory and / or a non-volatile memory. The volatile memory may include, but is not limited to, for example, a RAM, a cache, and so on. The non-volatile memory may include, but is not limited to, a ROM, a hard disk, a flash memory, and so on. The non-volatile memory may also include, but is not limited to, an electric, a magnetic, an optical, an electromagnetic, an infrared, or a semiconductor system, apparatus, or device or any combination of the above. The volatile memory and the non-volatile memory may be non-transitory memory.

[0229] Unless the context clearly requires otherwise, throughout the description and the claims, the words “comprise, ” “comprising, ” and the like are to be construed in an inclusive sense, as opposed to an exclusive or exhaustive sense; that is to say, in the sense of “including, but is not limited to. ” The word “coupled” , as generally used herein, refers to two or more elements that may be either directly connected, or connected by way of one or more intermediate elements. Likewise, the word “connected” , as generally used herein, refers to two or more elements that may be either directly connected, or connected by way of one or more intermediate elements. Additionally, the words “herein, ” “above, ” “below, ” and words of similar import, when used in this application, shall refer to this application as a whole and not to any particular portions of this application. Where the context permits, words in the description using the singular or plural number may also include the plural or singular number respectively. The word “or” in reference to a list of two or more items, that word covers all of the following interpretations of the word: any of the items in the list, all of the items in the list, and any combination of the items in the list.

[0230] Moreover, conditional language used herein, such as, among others, “can, ” “could, ” “might, ” “may, ” “e.g., ” “for example, ” “such as” and the like, unless specifically stated otherwise, or otherwise understood within the context as used, is generally intended to convey that certain embodiments include, while other embodiments do not include, certain features, elements and / or states. Thus, such conditional language is not generally intended to imply that features, elements and / or states are in any way required for one or more embodiments or that one or more embodiments necessarily include logic for deciding, with or without author input or prompting, whether these features, elements and / or states are included or are to be performed in any particular embodiment.

[0231] As used herein, the term "determine / determining" (and grammatical variants thereof) can include, not least: calculating, computing, processing, deriving, measuring, investigating, looking up (for example, looking up in a table, a database or another data structure) , ascertaining and the like. Also, "determining" can include receiving (for example, receiving information) , accessing (for example, accessing data in a memory) , obtaining and the like. Also, "determine / determining" can include resolving, selecting, choosing, establishing, and the like.

[0232] While some embodiments have been described, these embodiments have been presented by way of example, and are not intended to limit the scope of the disclosure. Indeed, the apparatus, methods, and systems described herein may be embodied in a variety of other forms; furthermore, various omissions, substitutions, and changes in the form of the methods and systems described herein may be made without departing from the spirit of the disclosure. For example, while blocks are presented in a given arrangement, alternative embodiments may perform similar functionalities with different components and / or circuit topologies, and some blocks may be deleted, moved, added, subdivided, combined, and / or modified. At least one of these blocks may be implemented in a variety of different ways. The order of these blocks may also be changed. Any suitable combination of the elements and actions of the some embodiments described above can be combined to provide further embodiments. The accompanying claims and their equivalents are intended to cover such forms or modifications as would fall within the scope and spirit of the disclosure.

[0233] Abbreviations used in the description and / or in the figures are defined as follows: 3GPP TR 3rd Generation Partnership Project Technical Report 6G        sixth generation of mobile communication system  AF               application function AI                artificial intelligence AIDE            advanced and intrusion detection environment  AMF             access and mobility management function API              application programming interface App              application BS               base station CN               core network CP               control plane CPU             central processing unit DN              distinguished name D2D             device-to-device gNB            next generation node B ID               identifier IMEI            international mobile equipment identity IMSI            international mobile subscriber identity IOC             information object class IoT              internet of things KPI              key performance indicator MDA            management data analytics ML              machine learning MM              mobility management MnS             management service NAS             non-access stratum NDT             network digital twin NEF             network exposure function NF               network function NRF             network repository function NWDAF         network data analytics function OAM            operation administration and maintenance PDU             protocol data unit PM              performance management RAN             radio access network SBA             service based architecture STAAMA   security threats assessment and mitigation automatically UDM            unified data management UE              user equipment UP              user plane URI              uniform resource identifier UUID           universally unique identifier ZSM             zero-touch network and service management

Claims

1.An apparatus for a management service, MnS, consumer, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:transmit to a network digital twin, NDT, service producer, a threat protection request for potential security threat assessment with at least one object; andreceive from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.2.The apparatus of claim 1, wherein the threat protection request comprises at least one of the following:origin type of the threat protection request,granularity period for security threat monitoring, orthe at least one object for which a potential security threat is to be assessed.3.The apparatus of claim 1 or 2, wherein the security assessment result comprises at least one of the following:an identifier of the security threat,a name of the security threat,a category of the security threat,a consequence of the security threat, oran impact level of the security threat.4.The apparatus of any of claims 1 to 3, wherein the countermeasure is to be used by an actual system to defend or mitigate the security threat.5.The apparatus of any of claims 1 to 4, wherein the MnS consumer is a network element and / or a network function.6.The apparatus of any of claims 1 to 4, wherein the MnS consumer is a user equipment, UE, and the threat protection request and the threat assessment report are transmitted via at least one of the following:a user plane, UP, function, ora first control plane, CP, function.7.The apparatus of claim 6, wherein the UE is an internet of things, IoT, UE.8.The apparatus of claim 6 or 7, wherein the apparatus is configured to:transmit to a second CP function, a first indicator indicating the UE supports security NDT; andreceive from the second CP function, a second indicator indicating whether the security NDT is allowed for the UE.9.The apparatus of any of claims 6 to 8, wherein the apparatus is configured to:perform the countermeasure against the security threat based on the threat assessment report; andtransmit to the NDT service producer, a feedback of performing the countermeasure.10.The apparatus of any of claims 1 to 9, wherein the at least one object comprises at least one of the following:a network function,an application function,a user equipment, ora MnS producer.11.An apparatus for a network digital twin, NDT, service producer, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:receive from a management service, MnS, consumer, a threat protection request for potential security threat assessment with at least one object;transmit to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; andtransmit to the MnS consumer, the threat assessment report.12.The apparatus of claim 11, wherein the apparatus is configured to:create a threat protection instance for starting security threat monitoring and defense of the security threat, based on the threat protection request.13.The apparatus of claim 11 or 12, wherein the apparatus is configured to:identify the security threat based on first security related data collected from the object after synchronization with the at least one object; andcheck whether the security threat is in an immune repository, which comprises a set of security threats and corresponding countermeasures.14.The apparatus of claim 13, wherein, in case the security threat is in the immune repository, the apparatus is configured to:generate the threat assessment report based on the immune repository.15.The apparatus of claim 13, wherein, in case the security threat is in the immune repository, the apparatus is configured to:apply the countermeasure against the security threat in the NDT; andgenerate the threat assessment report in case the countermeasure successfully defends or mitigates the security threat in the NDT.16.The apparatus of claim 13, wherein, in case the security threat is not in the immune repository, the apparatus is configured to:simulate an attack of the security threat against the simulated object in the NDT;conduct assessment and calculation for the security threat based on second security related data collected from the simulation of the attack of the security threat, in case the second security related data match the first security related data;generate the countermeasure for the security threat based on the assessment and calculation by doing defense analysis; andgenerate the threat assessment report and add the threat assessment report into the immune repository, in case of verifying the countermeasure successfully defends or mitigates the security threat.17.The apparatus of any of claims 11 to 16, wherein the at least one object comprises at least one of the following:a network function,an application function,a user equipment, ora MnS producer.18.An apparatus for a network function, NF, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:receive from a user equipment, UE, a first indicator indicating the UE supports security network digital twin, NDT; andtransmit to the UE a second indicator indicating whether the security NDT is allowed for the UE.19.The apparatus of claim 18, wherein the apparatus is configured to:check with a network repository function, NRF, whether a service of the security NDT is available; andin case the service of the security NDT is available, check with a unified data management, UDM, whether the service of the security NDT belongs to subscription of the UE and the UE is allowed to collect data for the service of the security NDT, to determine whether the security NDT is allowed for the UE.20.The apparatus of claim 18 or 19, wherein the NF is a control plane, CP, function.21.An apparatus for a management service, MnS, producer, comprising:at least one processor; andat least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to:receive from a network digital twin, NDT, service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; andperform the countermeasure against the security threat based on the threat assessment report.22.A method performed by an apparatus for a management service, MnS, consumer, comprising:transmitting to a network digital twin, NDT, service producer, a threat protection request for potential security threat assessment with at least one object; andreceiving from the NDT service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat.23.The method of claim 22, wherein the threat protection request comprises at least one of the following:origin type of the threat protection request,granularity period for security threat monitoring, orthe at least one object for which a potential security threat is to be assessed.24.The method of claim 22 or 23, wherein the security assessment result comprises at least one of the following:an identifier of the security threat,a name of the security threat,a category of the security threat,a consequence of the security threat, oran impact level of the security threat.25.The method of any of claims 22 to 24, wherein the countermeasure is to be used by an actual system to defend or mitigate the security threat.26.The method of any of claims 22 to 25, wherein the MnS consumer is a network element and / or a network function.27.The method of any of claims 22 to 25, wherein the MnS consumer is a user equipment, UE, and the threat protection request and the threat assessment report are transmitted via at least one of the following:a user plane, UP, function, ora first control plane, CP, function.28.The method of claim 27, wherein the UE is an internet of things, IoT, UE.29.The method of claim 27 or 28, comprising:transmitting to a second CP function, a first indicator indicating the UE supports security NDT; andreceiving from the second CP function, a second indicator indicating whether the security NDT is allowed for the UE.30.The method of any of claims 27 to 29, comprising:performing the countermeasure against the security threat based on the threat assessment report; andtransmitting to the NDT service producer, a feedback of performing the countermeasure.31.The method of any of claims 22 to 30, wherein the at least one object comprises at least one of the following:a network function,an application function,a user equipment, ora MnS producer.32.A method performed by an apparatus for a network digital twin, NDT, service producer, comprising:receiving from a management service, MnS, consumer, a threat protection request for potential security threat assessment with at least one object;transmitting to the at least one object, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; andtransmitting to the MnS consumer, the threat assessment report.33.The method of claim 32, comprising:creating a threat protection instance for starting security threat monitoring and defense of the security threat, based on the threat protection request.34.The method of claim 32 or 33, comprising:identifying the security threat based on first security related data collected from the object after synchronization with the at least one object; andchecking whether the security threat is in an immune repository, which comprises a set of security threats and corresponding countermeasures.35.The method of claim 34, wherein, in case the security threat is in the immune repository, the method comprises:generating the threat assessment report based on the immune repository.36.The method of claim 34, wherein, in case the security threat is in the immune repository, the method comprises:applying the countermeasure against the security threat in the NDT; andgenerating the threat assessment report in case the countermeasure successfully defends or mitigates the security threat in the NDT.37.The method of claim 34, wherein, in case the security threat is not in the immune repository, the method comprises:simulating an attack of the security threat against the simulated object in the NDT;conducting assessment and calculation for the security threat based on second security related data collected from the simulation of the attack of the security threat, in case the second security related data match the first security related data;generating the countermeasure for the security threat based on the assessment and calculation by doing defense analysis; andgenerating the threat assessment report and add the threat assessment report into the immune repository, in case of verifying the countermeasure successfully defends or mitigates the security threat.38.The method of any of claims 32 to 37, wherein the at least one object comprises at least one of the following:a network function,an application function,a user equipment, ora MnS producer.39.A method performed by an apparatus for a network function, NF, comprising:receiving from a user equipment, UE, a first indicator indicating the UE supports security network digital twin, NDT; andtransmitting to the UE a second indicator indicating whether the security NDT is allowed for the UE.40.The method of claim 39, comprising:checking with a network repository function, NRF, whether a service of the security NDT is available; andin case the service of the security NDT is available, checking with a unified data management, UDM, whether the service of the security NDT belongs to subscription of the UE and the UE is allowed to collect data for the service of the security NDT, to determine whether the security NDT is allowed for the UE.41.The method of claim 39 or 40, wherein the NF is a control plane, CP, function.42.A method performed by an apparatus for a management service, MnS, producer, comprising:receiving from a network digital twin, NDT, service producer, a threat assessment report comprising at least one of a security assessment result or a countermeasure against a security threat; andperforming the countermeasure against the security threat based on the threat assessment report.43.An apparatus for a management service, MnS, consumer, comprising means for performing the method of any of claims 22 to 31.44.An apparatus for a network digital twin, NDT, service producer, comprising means for performing the method of any of claims 32 to 38.45.An apparatus for a network function, NF, comprising means for performing the method of any of claims 39 to 41.46.An apparatus for a management service, MnS, producer, comprising means for performing the method of claim 42.47.A computer-readable medium comprising program instructions that, when executed by an apparatus for a management service, MnS, consumer, cause the apparatus to at least perform the method of any of claims 22 to 31.48.A computer-readable medium comprising program instructions that, when executed by an apparatus for a network digital twin, NDT, service producer, cause the apparatus to at least perform the method of any of claims 32 to 38.49.A computer-readable medium comprising program instructions that, when executed by an apparatus for a network function, NF, cause the apparatus to at least perform the method of any of claims 39 to 41.50.A computer-readable medium comprising program instructions that, when executed by an apparatus for a management service, MnS, producer, cause the apparatus to at least perform the method of claim 42.