Communication methods, communication device, communication system, storage medium and program product
Patent Information
- Application Number
- PCT/CN2025/084243
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2026-09-24
Smart Images

Figure CN2025084243_24092026_PF_FP_ABST
Abstract
Description
Communication methods, communication equipment, communication systems, storage media and software products Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a communication method, communication device, communication system, storage medium, and program product. Background Technology
[0002] In order to protect the privacy of mobile communication users in accordance with relevant regulations (such as the General Data Protection Regulation (GDPR)), network operators may need to obtain users' consent before providing mobile communication functions when processing user data. Summary of the Invention
[0003] Under the current user consent mechanism, users cannot differentiate between different types of data, which may increase the risk of data leakage and affect user experience.
[0004] This disclosure provides a communication method, communication device, communication system, storage medium, and program product.
[0005] According to a first aspect of the present disclosure, a communication method is proposed, executed by a first node, the method comprising: performing a user consent check on first data of a first user based on first information of a first user; wherein the first information of the first user is associated with a type of personal data of the first user.
[0006] According to a second aspect of the present disclosure, a communication method is proposed, executed by a second node, the method comprising: sending first information of a first user to a first node; wherein the first information of the first user is used to perform a user consent check on first data of the first user, and the first information of the first user is associated with a type of personal data of the first user.
[0007] According to a third aspect of the present disclosure, a first node is proposed, comprising: a processing module configured to perform a user consent check on first data of a first user based on first information of a first user; wherein the first information of the first user is associated with a type of personal data of the first user.
[0008] According to a fourth aspect of the present disclosure, a second node is provided, comprising: a transceiver module configured to send first information of a first user to a first node; wherein the first information of the first user is used to perform a user consent check on the first data of the first user, and the first information of the first user is associated with a type of the first user's personal data.
[0009] According to a fifth aspect of the present disclosure, a communication device is provided, comprising: one or more processors; wherein the communication device is configured to perform a communication method as described in the first or second aspect.
[0010] According to a sixth aspect of the present disclosure, a communication system is proposed, including a first node and a second node; the first node is configured to implement the communication method as described in the first aspect; and the second node is configured to implement the communication method as described in the second aspect.
[0011] According to a seventh aspect of the present disclosure, a storage medium is provided that stores instructions which, when executed on a communication device, cause the communication device to perform a communication method as described in the first or second aspect.
[0012] According to an eighth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the communication method of the first or second aspect.
[0013] According to a ninth aspect of the present disclosure, a computer program is provided that includes code, which, when executed by a processor, implements the communication method of the first or second aspect.
[0014] According to a tenth aspect of the present disclosure, a chip or chip system is provided, the chip or chip system including processing circuitry configured to perform a communication method as described in the first or second aspect.
[0015] In this embodiment of the disclosure, the first node can perform a user consent check based on first information associated with the type of personal data, thereby enabling users to treat different types of personal data differently, reducing the risk of privacy leakage, and improving user experience. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.
[0017] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
[0018] Figures 2A and 2B are interactive schematic diagrams of a communication method according to embodiments of the present disclosure.
[0019] Figure 3 is another interactive schematic diagram of a communication method according to an embodiment of the present disclosure.
[0020] Figure 4 is a schematic diagram of the structure of a communication device provided according to an embodiment of the present disclosure.
[0021] Figure 5 is a schematic diagram of a communication device provided according to an embodiment of the present disclosure.
[0022] Figure 6 is a schematic diagram of a chip structure provided according to an embodiment of the present disclosure. Detailed Implementation
[0023] This disclosure provides a communication method, communication device, communication system, storage medium, and program product.
[0024] In a first aspect, embodiments of this disclosure provide a communication method executed by a first node, the method comprising: performing a user consent check on first data of the first user based on first information of the first user; wherein the first information of the first user is associated with the type of the first user's personal data.
[0025] In this embodiment of the disclosure, the first node can perform a user consent check based on first information associated with the type of personal data, thereby enabling users to treat different types of personal data differently, ensuring that highly sensitive data is properly protected, reducing the risk of privacy leakage, and improving user experience.
[0026] In conjunction with some embodiments of the first aspect, in some embodiments, the type of personal data includes at least one of the following: ordinary personal data, sensitive personal data.
[0027] In this embodiment of the disclosure, the first information associated with ordinary personal data is different from the first information associated with sensitive personal data. The first node can use the first information associated with sensitive personal data to perform user consent checks, which can ensure that highly sensitive data is properly protected, reduce the risk of privacy leakage, and improve user experience.
[0028] In conjunction with some embodiments of the first aspect, in some embodiments, the first information of the first user includes: second information indicating whether the first user grants user consent; third information indicating the data processing purpose permitted by the first user; and fourth information indicating the valid conditions for the first user to grant user consent.
[0029] In this embodiment of the disclosure, by adding valid conditions for granting user consent to the first information, it is possible to determine under what circumstances user consent is valid and under what circumstances it is invalid. Thus, after granting user consent, the first user does not need to revoke the granted consent, but the revocation of consent is automatically controlled by the valid conditions, thereby realizing dynamic control of user consent.
[0030] In conjunction with some embodiments of the first aspect, in some embodiments, the data processing purpose includes at least one of the following: providing data to nodes within the network where the first node is located; providing data to nodes outside the network where the first node is located; providing data to nodes outside the network where the first node is located, while the network where the first node is located stores the data; providing data to nodes outside the network where the first node is located, while the network where the first node is located does not store the data.
[0031] In some embodiments, in conjunction with the first aspect, the method further includes: receiving first information of the first user sent by the second node.
[0032] In conjunction with some embodiments of the first aspect, in some embodiments, the second node is used to store fifth information, which indicates the configuration information of the first user, the configuration information being used for the privacy protection of the first user, and the configuration information including the first information of the first user.
[0033] In this embodiment of the disclosure, the second node unbinds the first information from the contract information and stores it separately in the fifth information, which facilitates flexible updates to the first information, enhances the user's right to consent and control, and improves the user experience.
[0034] In conjunction with some embodiments of the first aspect, in some embodiments, the first user is a contracted user or a non-contracted user.
[0035] Secondly, embodiments of this disclosure provide a communication method executed by a second node, the method comprising: sending first information of a first user to a first node; wherein the first information of the first user is used to perform a user consent check on the first data of the first user, and the first information of the first user is associated with the type of the first user's personal data.
[0036] In conjunction with some embodiments of the second aspect, in some embodiments, the type of personal data includes at least one of the following: ordinary personal data, sensitive personal data.
[0037] In conjunction with some embodiments of the second aspect, in some embodiments, the first information of the first user includes: second information indicating whether the first user grants user consent; third information indicating the data processing purpose permitted by the first user; and fourth information indicating the valid conditions for the first user to grant user consent.
[0038] In conjunction with some embodiments of the second aspect, in some embodiments, the data processing purpose includes at least one of the following: providing data to nodes within the network where the first node is located; providing data to nodes outside the network where the first node is located; providing data to nodes outside the network where the first node is located, while the network where the first node is located stores the data; providing data to nodes outside the network where the first node is located, while the network where the first node is located does not store the data.
[0039] In conjunction with some embodiments of the second aspect, in some embodiments, the second node stores fifth information, which indicates the configuration information of the first user. The configuration information is used for the privacy protection of the first user and includes the first information of the first user.
[0040] In conjunction with some embodiments of the second aspect, in some embodiments, the first user is a contracted user or a non-contracted user.
[0041] Thirdly, embodiments of this disclosure provide a first node, including: a processing module configured to perform a user consent check on first data of a first user based on first information of a first user; wherein the first information of the first user is associated with the type of the first user's personal data.
[0042] In conjunction with some embodiments of the third aspect, in some embodiments, the type of personal data includes at least one of the following: ordinary personal data, sensitive personal data.
[0043] In conjunction with some embodiments of the third aspect, in some embodiments, the first information of the first user includes: second information indicating whether the first user grants user consent; third information indicating the data processing purpose permitted by the first user; and fourth information indicating the valid conditions for the first user to grant user consent.
[0044] In conjunction with some embodiments of the third aspect, in some embodiments, the data processing purpose includes at least one of the following: providing data to nodes within the network where the first node is located; providing data to nodes outside the network where the first node is located; providing data to nodes outside the network where the first node is located, while the network where the first node is located stores the data; providing data to nodes outside the network where the first node is located, while the network where the first node is located does not store the data.
[0045] In conjunction with some embodiments of the third aspect, in some embodiments, the first node further includes: a transceiver module configured to receive first information of the first user sent by the second node.
[0046] In conjunction with some embodiments of the third aspect, in some embodiments, the second node is used to store fifth information, which indicates the configuration information of the first user, the configuration information being used for the privacy protection of the first user, and the configuration information including the first information of the first user.
[0047] In conjunction with some embodiments of the third aspect, in some embodiments, the first user is a contracted user or a non-contracted user.
[0048] Fourthly, embodiments of this disclosure provide a second node, including: a transceiver module configured to send first information of a first user to a first node; wherein the first information of the first user is used to perform a user consent check on the first data of the first user, and the first information of the first user is associated with the type of the first user's personal data.
[0049] In conjunction with some embodiments of the fourth aspect, in some embodiments, the type of personal data includes at least one of the following: ordinary personal data, sensitive personal data.
[0050] In conjunction with some embodiments of the fourth aspect, in some embodiments, the first information of the first user includes: second information indicating whether the first user grants user consent; third information indicating the data processing purpose permitted by the first user; and fourth information indicating the valid conditions for the first user to grant user consent.
[0051] In conjunction with some embodiments of the fourth aspect, in some embodiments, the data processing purpose includes at least one of the following: providing data to nodes within the network where the first node is located; providing data to nodes outside the network where the first node is located; providing data to nodes outside the network where the first node is located, while the network where the first node is located stores the data; providing data to nodes outside the network where the first node is located, while the network where the first node is located does not store the data.
[0052] In conjunction with some embodiments of the fourth aspect, in some embodiments, the second node stores fifth information, which indicates the configuration information of the first user. The configuration information is used for the privacy protection of the first user and includes the first information of the first user.
[0053] In conjunction with some embodiments of the fourth aspect, in some embodiments, the first user is a contracted user or a non-contracted user.
[0054] Fifthly, embodiments of this disclosure provide a communication device, including: one or more processors; wherein the communication device is used to perform a communication method as described in the first or second aspect.
[0055] In a sixth aspect, embodiments of this disclosure provide a communication system, including: a first node and a second node; the first node is configured to implement the communication method as described in the first aspect; and the second node is configured to implement the communication method as described in the second aspect.
[0056] In a seventh aspect, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform a communication method as described in the first or second aspect.
[0057] Eighthly, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform a communication method as described in the first or second aspect.
[0058] In a ninth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the method as described in an optional implementation of the first or second aspect.
[0059] In a tenth aspect, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the method described according to an optional implementation of the first or second aspect above.
[0060] It is understood that the aforementioned communication devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0061] This disclosure provides a communication method, communication device, communication system, storage medium, and program product. In some embodiments, the terms "communication method," "user consent checking method," "data protection method," "privacy protection method," and "data collection method" can be used interchangeably, as can the terms "communication system," "user consent checking system," "data protection system," "privacy protection system," and "data collection system."
[0062] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0063] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0064] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0065] In this embodiment of the disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the," "the," "the," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular expression or a plural expression.
[0066] In the embodiments disclosed herein, "multiple" refers to two or more.
[0067] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0068] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0069] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0070] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0071] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0072] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.
[0073] In some embodiments, the terms “greater than”, “greater than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, and “above” can be used interchangeably, as can the terms “less than”, “less than or equal to”, “not greater than”, “less than”, “less than or equal to”, “not more than”, “lower than”, “lower than or equal to”, “not higher than”, and “below”.
[0074] In some embodiments, devices, etc., can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. Terms such as “device”, “equipment”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, and “subject” can be used interchangeably.
[0075] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).
[0076] In some embodiments, the terms "network devices", "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", "node", "access network node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femtocell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", and "bandwidth part (BWP)" can be used interchangeably.
[0077] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal", "mobile station (MS)", "mobile terminal (MT)", "subscriber station", "mobile unit", "subscriber unit", "wireless unit", "remote unit", "mobile device", "wireless device", "wireless communication device", "remote device", "mobile subscriber station", "access terminal", "mobile terminal", "wireless terminal", "remote terminal", "handset", "user agent", "mobile client", and "client" can be used interchangeably.
[0078] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.
[0079] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
[0080] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0081] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0082] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0083] Figure 1 is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure. As shown in Figure 1, the communication system 100 includes: a first node 101, a second node 102, a third node 103, and a fourth node 104.
[0084] In some embodiments, the first node is used to perform a user consent check. In some embodiments, the first node is used to perform a user consent authorization check. In some embodiments, the first node is used to collect data. In some embodiments, the first node is used to process the collected data. In some embodiments, the first node is used to provide data to a third node.
[0085] In some embodiments, the first node may be an access network device or a core network device.
[0086] In some embodiments, the first node may be a network exposure function (NEF) network element, an application function (AF) network element, a network data analytics function (NWDAF) network element, etc. In some embodiments, the first node may be a network element in a 6G network dedicated to security and privacy protection, such as a security function (SECF) network element or a privacy function (PRIF) network element.
[0087] In some embodiments, the name of the first node is not limited, and may be, for example, "user consent execution node", "user consent check node", "data collection node", "data provision node", "data management node", etc.
[0088] In some embodiments, the second node is used to store first information, which is used to perform a user consent check. In some embodiments, the second node is used to store fifth information, which indicates the user's configuration information for user privacy protection, and includes the first information. In some embodiments, the second node is used to store all information associated with security and privacy protection.
[0089] In some embodiments, the second node may be an access network device or a core network device.
[0090] In some embodiments, the second node may be a unified data management (UDM) network element, a unified data repository (UDR) network element, a SECF network element, or a PRIF network element.
[0091] In some embodiments, the name of the second node is not limited, and it may be, for example, a "security management node", a "privacy protection node", or a "data storage node".
[0092] In some embodiments, a third node is used to request data from a first node. In some embodiments, a third node is used to obtain data from a first node. In some embodiments, a third node is used to process the obtained data. In some embodiments, a third node can be understood as a data consuming node.
[0093] In some embodiments, the third node can be at least one of a terminal, an access network device, a core network device, or a third-party device. In one example, the third node can be an edge application server (EAS).
[0094] In some embodiments, a third-party device can be understood as a device not deployed by the carrier, a device not managed by the carrier, a device requiring authentication, or a device requiring authorization. In one example, the third-party device can be a third-party application server (AS).
[0095] In some embodiments, the fourth node is used to provide data to the first node. In some embodiments, the fourth node can be understood as a data source node. In some embodiments, the fourth node is a terminal. In some embodiments, the fourth node can be a terminal owned by a subscribed user or a terminal used by an unsubscribed user.
[0096] In some embodiments, the terminal includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.
[0097] In some implementations, access network equipment may be nodes or devices that connect terminals to a wireless network. Access network equipment may include, but is not limited to, at least one of the following: evolved NodeB (eNB), next-generation eNB (ng-eNB), next-generation NodeB (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul equipment, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in Wi-Fi system.
[0098] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0099] In some embodiments, the access network device may be composed of a centralized unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0100] In some embodiments, the core network equipment can be a single device, including NEF network elements, AF network elements, NWDAF network elements, UDM network elements, and UDR network elements, or it can be multiple devices or a group of devices, each including a subset of NEF network elements, AF network elements, NWDAF network elements, UDM network elements, and UDR network elements. Network elements can be virtual or physical. The core network includes, for example, at least one of the Evolved Packet Core (EPC), 5G Core Network (5GCN), and Next Generation Core (NGC).
[0101] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions provided in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in this disclosure are also applicable to similar technical problems.
[0102] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. The number and form of each main body are arbitrary. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0103] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0104] In some embodiments, under current user consent mechanisms, users are unable to differentiate between different types of data. On the one hand, this may lead to the over-collection of user data, resulting in highly sensitive data not being adequately protected and increasing the risk of privacy breaches. On the other hand, it may leave users unclear about how different types of data are used, making it difficult to support dynamic scenarios, thereby leading to the misuse of user data, reducing the transparency of the user consent mechanism, and damaging user trust.
[0105] In some embodiments, in the current user consent mechanism, user consent parameters are included in the contract information, or in other words, user consent parameters are bound to the contract information. On the one hand, this makes it impossible for users to update their consent settings independently. For example, when a user upgrades a service package, the system automatically retains the old consent settings without obtaining the user's consent again, resulting in inflexible user consent updates and reduced user control over consent. On the other hand, user consent is nested in lengthy contract agreements, making it difficult for users to identify the specific authorized content, leading to decreased transparency of user consent and affecting user experience.
[0106] This disclosure provides a communication method, communication device, communication system, storage medium, and program product. A first node performs a user consent check on the first user's first data based on the first user's first information. The first user's first information is associated with the type of the first user's personal data. In this way, the first node can perform a user consent check based on the first information associated with the type of personal data, thereby enabling users to treat different types of personal data differently, ensuring that highly sensitive data is properly protected, reducing the risk of privacy leakage, and improving user experience.
[0107] In some embodiments, the name of the first information is not limited, and it may be, for example, "user consent parameters", "user consent information", "user consent data", etc.
[0108] In some embodiments, personal data is any data relating to an identified or identifiable natural person. For example, personal data may include at least one of the following: identity data, location data, online behavior data, occupational data, educational data, financial data, genetic data, biometric data, health data, etc.
[0109] In some embodiments, the initial information associated with different types of personal data is different. In some embodiments, the state of user consent associated with different types of personal data is different. In some embodiments, the protection level of different types of personal data is different.
[0110] In some embodiments, the type of personal data includes at least one of the following: general personal data and sensitive personal data.
[0111] In some embodiments, the user consent status associated with ordinary personal data differs from that associated with sensitive personal data. The security level of user consent associated with sensitive personal data is higher than that of user consent associated with ordinary personal data. For example, the security level of a user consent status of "no" is higher than that of a user consent status of "yes." In some embodiments, the protection level of ordinary personal data differs from that of sensitive personal data, with the protection level of sensitive personal data being higher than that of ordinary personal data.
[0112] In some embodiments, sensitive personal data refers to information that reveals sensitive personal attributes and is highly relevant to user consent, requiring a higher level of protection than ordinary personal data. In some embodiments, sensitive personal data includes at least one of the following: genetic data (such as DNA information), biometric data (such as fingerprints, facial information), health data (such as medical data), etc.
[0113] In some embodiments, the first information associated with ordinary personal data is different from the first information associated with sensitive personal data.
[0114] In some embodiments, the types of personal data may also be classified according to other definitions or rules, and are not limited to the descriptions in the above embodiments.
[0115] In some embodiments, the first user can be a contracted user or a non-contracted user. In some embodiments, a contracted user is a user who has completed legal registration in the operator's network, whose identity information and service permissions have been explicitly recorded by the core network, and who has a service agreement with the operator. In some embodiments, a non-contracted user is a user who has not registered in the operator's network or who is not authorized to access network services.
[0116] In some embodiments, a contracted user may also be described as a subscriber. In some embodiments, a non-contracted user may also be described as a non-subscriber.
[0117] Figure 2A is an interactive schematic diagram of a communication method provided according to an embodiment of the present disclosure. As shown in Figure 2A, the present disclosure relates to a communication method. Executed by a communication system 100, the communication method includes steps S2101 to S2106.
[0118] In this embodiment of the disclosure, the first user is a non-contracted user, and the second node stores the configuration information of the non-contracted user.
[0119] In step S2101, the third node sends the first message.
[0120] In some embodiments, the first node receives a first message. In some embodiments, the first message is used to request the retrieval of first data from a first user. In one example, the first message is a data request message.
[0121] In some embodiments, the first message includes at least one of the following: a sixth message, a seventh message, and an eighth message.
[0122] In some embodiments, the sixth piece of information indicates the user identifier of the first user. In one example, the user identifier of the first user is a vertical application layer user identifier (VAL User ID). In one example, the VAL User ID can be a device identifier for an Internet of Things (IoT) device. In one example, the VAL User ID can be a device identifier for a vehicle-to-everything (V2X) device, such as a vehicle identifier.
[0123] In some embodiments, the seventh information indicates the data type of the first data. In one example, the data type of the first data is ordinary personal data. In one example, the data type of the first data is sensitive personal data. In one example, the data type of the first data is biometric data.
[0124] In some embodiments, the eighth information indicates the first purpose of data processing. The first purpose of data processing is used to indicate the purpose for which the third node requests the first user's first data, which can be understood as what kind of processing is performed on the first data and / or what goal is achieved through the first data. In some embodiments, the first purpose of data processing may be analysis, model training, network capability exposure, or EAS entity manipulating UE information to retrieve the UE's location.
[0125] In some embodiments, if the third node is a node outside the network where the first node is located, the first data processing purpose may be to provide data to the node outside the network where the first node is located, or to provide data to the node outside the network where the first node is located while the network where the first node is located stores the data, or to provide data to the node outside the network where the first node is located while the network where the first node is located does not store the data.
[0126] In some embodiments, if the third node is a node within the network where the first node is located, the first data processing purpose may be to provide data to the nodes within the network where the first node is located.
[0127] In some embodiments, step S2101 can be omitted, in which case the third node and the first node are deployed on the same device.
[0128] In step S2102, the first node sends the second message.
[0129] In some embodiments, the second node receives a second message. In some embodiments, the second message is used to request first information from the first user. In some embodiments, the second message is used to request first information associated with the data type of the first data. In some embodiments, the second message may include at least one of the following: sixth information, seventh information.
[0130] In some embodiments, the first node requests the first user's first information from the second node based on the sixth information. In some embodiments, the first node requests the first information associated with the data type of the first data from the first user's first information based on the sixth and seventh information.
[0131] In some embodiments, step S2102 can be omitted, in which case the first node and the second node are deployed on the same device.
[0132] In step S2103, the second node sends the first information of the first user.
[0133] In some embodiments, the first node receives first information from the first user.
[0134] In some embodiments, the second node stores configuration information for non-contracted users, which includes first information for the first user. In some embodiments, the first information for the first user also includes multiple pieces of first information associated with multiple types of personal data, with one piece of first information associated with each type of personal data. In some embodiments, the association of one piece of first information with each type of personal data can be understood as each type of personal data being configured with a separate piece of first information, and the first node can use the first information configured for each type of personal data to perform a user consent check on each type of personal data.
[0135] In some embodiments, the second node retrieves fifth information from the configuration information of non-subscribed users based on the user identifier of the first user. The fifth information indicates the configuration information of the first user. Then, the second node obtains the first information of the first user from the configuration information of the first user and sends the first information of the first user to the first node so that the first node can determine the first information associated with the data type of the first data from the first information of the first user.
[0136] In some embodiments, the second node can retrieve first information associated with the data type of the first data from the first user's first information, and send the first information associated with the data type of the first data to the first node.
[0137] In some embodiments, the configuration information of non-contracted users is used for the privacy protection of non-contracted users, which can be understood as all information associated with the privacy protection of non-contracted users being included in the configuration information. In some embodiments, the configuration information of the first user is used for the privacy protection of the first user, which can be understood as all information associated with the privacy protection of the first user being included in the configuration information of the first user.
[0138] In some embodiments, the name of the configuration information is not limited, and it may be, for example, "privacy profile", "security profile", "privacy configuration information", etc.
[0139] In some embodiments, the first user's first information is used to determine whether the first user consents to the collection of personal data. In some embodiments, the first user's first information is used to determine whether the first user consents to the analysis of personal data. In some embodiments, the first user's first information is used to determine whether the first user consents to the training of personal data. In some embodiments, the first user's first information is used to determine whether the first user consents to the disclosure of personal data to third parties. In some embodiments, the first user's first information is used to determine whether the first user consents to the storage of personal data on a network.
[0140] In some embodiments, the first information of the first user includes: second information, third information, and fourth information. In some embodiments, the second information indicates whether the first user grants consent. In some embodiments, the third information indicates the data processing purpose permitted by the first user. In some embodiments, the fourth information indicates the valid conditions for the first user to grant consent.
[0141] In some embodiments, the data processing purpose permitted by the first user includes at least one of the following: providing data to nodes within the network where the first node is located, providing data to nodes outside the network where the first node is located, providing data to nodes outside the network where the first node is located while the network where the first node is located stores the data, and providing data to nodes within the network where the first node is located while the network where the first node is located does not store the data.
[0142] In some embodiments, the data processing purpose permitted by the first user includes at least one of the following: providing data to nodes within the network where the first node is located, providing data to nodes outside the network where the first node is located, and providing data to nodes outside the network where the first node is located while the network where the first node is located stores the data.
[0143] In some embodiments, the data processing purpose permitted by the first user includes at least one of the following: providing data to nodes within the network where the first node is located, providing data to nodes outside the network where the first node is located, and providing data to nodes outside the network where the first node is located without storing data in the network where the first node is located.
[0144] In some embodiments, the data processing purpose permitted by the first user may also include at least one of the following: analysis, model training, network capability exposure, and EAS entity manipulation of UE information to retrieve UE location.
[0145] In some embodiments, the data processing purpose permitted by the first user includes at least one of the following: analysis, model training, network capability exposure, EAS entity manipulating UE information to retrieve UE location, providing data to nodes within the network where the first node is located, providing data to nodes outside the network where the first node is located, and providing data to nodes outside the network where the first node is located while the network where the first node is located stores the data.
[0146] In some embodiments, the data processing purpose permitted by the first user includes at least one of the following: analysis, model training, network capability exposure, EAS entity manipulating UE information to retrieve UE location, providing data to nodes within the network where the first node is located, providing data to nodes outside the network where the first node is located, and providing data to nodes outside the network where the first node is located without the network storing the data.
[0147] In some embodiments, the effective conditions for the first user to grant user consent can be understood as: under what circumstances the user consent granted by the first user is valid and under what circumstances it is invalid. In this way, after granting user consent, the first user does not need to revoke the granted consent, but the revocation of consent is automatically controlled through the effective conditions, thus realizing dynamic control of user consent.
[0148] In some embodiments, the valid conditions for the first user to grant user consent include at least one of the following: valid time, valid location, valid device status, and valid event status.
[0149] In some embodiments, the effective period of the first user's consent can be understood as: the user's consent is valid within the effective period, and expires outside the effective period.
[0150] In one example, the validity period can be a range of times. For example, a validity period of one week means that the user's agreement is valid for one week, after which the user's agreement expires.
[0151] In one example, the validity period can be a valid time cycle. For example, the validity period is weekdays, meaning the user's agreement is valid on weekdays and expires on non-weekdays. Similarly, the validity period is daytime, meaning the user's agreement is valid during the day and expires at night.
[0152] In some embodiments, the valid location for the first user to grant consent can be understood as follows: if the third node is in a valid location, the user's consent is valid; if the third node is in an invalid location, the user's consent is invalid. In some embodiments, the valid location for the first user to grant consent can be understood as follows: if the first user is in a valid location, the user's consent is valid; if the first user is in an invalid location, the user's consent is invalid.
[0153] In one example, a valid location can be a valid area range. For instance, if the valid area range is area A, then the user's consent is valid if the third node is located in area A, and invalid if the third node is located outside area A. As another example, if the first user's location is in area A, then the user's consent is valid; if the first user's location is outside area A, then the user's consent is invalid.
[0154] In one example, the effective area range can be a preset size area centered on the location of the first user. As the first user moves, the effective area range also moves. If the location of the third node is within the effective area range, the user's consent is valid. If the location of the third node is outside the effective area range, the user's consent is invalid.
[0155] In some embodiments, the valid device state for the first user's consent can be understood as follows: when the first user's device is in a valid device state, the user's consent is valid; when the first user's device is in an invalid device state, the user's consent is invalid. In some embodiments, the device state may include at least one of the following: operating state, airplane state, do-not-disturb state, and power-saving state. In some embodiments, operating state can be understood as the device being in normal operation, airplane state can be understood as the device being in airplane mode, do-not-disturb state can be understood as the device being in do-not-disturb mode, and power-saving state can be understood as the device being in power-saving mode.
[0156] In one example, if the valid device status is active, then the user's consent is valid when the first user's device is active, and invalid when the first user's device is not active.
[0157] In some embodiments, the valid event state of the first user's consent can be understood as follows: when the event state is in a valid event state, the user's consent is valid; when the event state is in an invalid event state, the user's consent is invalid. In some embodiments, the event state includes: event in progress state and event completed state.
[0158] In one example, suppose the first data is used by the third node for model training. The event states include: model training in progress and model training completed. If the valid event state is model training in progress, then the user's consent is valid during the model training in progress state, and invalid during the model training completed state.
[0159] In one example, the first message can be sent to the first node in the following way:
[0160] In some embodiments, any combination of the above-mentioned valid conditions, such as valid time, valid location, valid device status, and valid event status, can be used together to determine the validity and invalidity of user consent.
[0161] In some embodiments, the validity conditions include a valid time and a valid location. If the third node is in a valid location within the valid time, the user's consent is valid; if the third node is in a non-valid location or the validity period is invalid, the user's consent is invalid. In some embodiments, the validity conditions include a valid time and a valid location. If the first user is in a valid location within the valid time, the user's consent is valid; if the first user is in a non-valid location or the validity period is invalid, the user's consent is invalid.
[0162] In one example, if the valid time is daytime and the valid location is region A centered on the location of the first user, then the user's consent is valid during the daytime when the location of the third node is in region A, and invalid at night or when the location of the third node is outside region A.
[0163] In some embodiments, the validity conditions include a valid time and a valid device state. If the user's consent is valid during the valid time and the first user's device state is in a valid device state, the user's consent is valid. If the user's consent is invalid during a non-valid time or the first user's device state is in a non-valid device state, the user's consent is invalid.
[0164] In one example, the valid time is at night and the valid device state is power saving. Therefore, the user's consent is valid at night when the first user's device is in power saving state, and invalid during the day when the first user's device is not in power saving state.
[0165] In some embodiments, the validity conditions include a valid location and a valid device state. When the first user's location is in a valid location and the first user's device is in a valid device state, the user's consent is valid. When the first user's location is in an invalid location or the first user's device is not in a valid device state, the user's consent is invalid.
[0166] In one example, the valid location is area A, and the valid device state is power saving. When the first user's location is in area A and the first user's device is in power saving, the user's consent is valid. When the first user's location is outside area A or the first user's device is not in power saving, the user's consent is invalid.
[0167] In some embodiments, the validity conditions include a valid time and a valid event state. If the user's consent is valid when the event is valid within the valid time and the event state is valid, the user's consent is invalid when the event is invalid outside the valid time and the event state is invalid.
[0168] In one example, the valid time is daytime, and the invalid time is nighttime. The first data is used for model training. The valid event state is the model training in progress state, and the invalid event state is the model training completed state. Therefore, the user's consent is valid during the daytime when the model training is in progress state, and invalid during the nighttime or when the model training is completed state.
[0169] In some embodiments, the first information of the first user may further include at least one of the following: a condition for extending the effective period of the first user's consent to the user, or a condition for shortening the effective period of the first user's consent to the user.
[0170] In some embodiments, the conditions for extending the validity period can be understood as follows: when the extension condition is met, the validity period agreed upon by the user is extended; when the extension condition is not met, the validity period agreed upon by the user is not extended, that is, the validity period remains unchanged. In some embodiments, the conditions for shortening the validity period can be understood as follows: when the shortening condition is met, the validity period agreed upon by the user is shortened; when the shortening condition is not met, the validity period agreed upon by the user is not shortened, that is, the validity period remains unchanged.
[0171] In one example, the extension condition could be that if a first user performs a sensitive operation (e.g., a payment operation) using sensitive personal data (e.g., biometric data) for n consecutive days, the validity period of the user's consent associated with the sensitive personal data can be extended. n is a positive integer.
[0172] In one example, the delay condition could be that if a first user uses artificial intelligence (AI) or machine learning (ML) functions for m consecutive days, the validity period of user consent for data associated with AI / ML can be extended. m is a positive integer.
[0173] In one example, the shortening condition could be that if a first user has not performed any sensitive operations using sensitive personal data for n consecutive days, then the effective period of user consent associated with the sensitive personal data can be shortened.
[0174] In one example, the shortening condition could be that if a first user has not used the AI / ML function for m consecutive days, then the effective period of user consent for data associated with AI / ML can be shortened.
[0175] In some embodiments, the first information of the first user may further include at least one of the following: an increase condition for the effective area of the first user's consent, and a decrease condition for the effective area of the first user's consent.
[0176] In some embodiments, the condition for increasing the effective area can be understood as follows: when the increase condition is met, the effective area agreed upon by the user is increased; when the increase condition is not met, the effective area agreed upon by the user is not increased, that is, the effective area remains unchanged. In some embodiments, the condition for decreasing the effective area can be understood as follows: when the decrease condition is met, the effective area agreed upon by the user is decreased; when the decrease condition is not met, the effective area agreed upon by the user is not decreased, that is, the effective area remains unchanged.
[0177] In one example, the condition for expansion could be that if a first user performs sensitive operations using sensitive personal data for n consecutive days outside the valid area, then the valid area associated with the sensitive personal data can be expanded.
[0178] In one example, the narrowing condition could be that if a first user has not performed any sensitive operations using sensitive personal data within the valid area for n days, then the valid area associated with the sensitive personal data can be narrowed.
[0179] In step S2104, the first node performs a user consent check on the first user's first data based on the first user's first information.
[0180] In some embodiments, the first node determines, based on the first user's first information, whether the first user agrees that the first user's first data is intended for a first data processing purpose. If the first user agrees, the first node may provide the first data to the third node. If the first user does not agree, the first node may not provide the first data to the third node.
[0181] In some embodiments, if the first node determines that the user agrees to provide the first data, the first node may execute step S2105 to step S2106. If the first node determines that the user does not agree to provide the first data, the first node may send a third message to the third node to indicate that the first user does not agree to provide the first data.
[0182] In some embodiments, before step S2102, the first node may further determine whether the first user's first data needs to undergo a user consent check. In some embodiments, the first node may determine whether the first user's first data needs to undergo a user consent check based on the sixth information and / or the seventh information. In some embodiments, if the first user's first data does not need to undergo a user consent check, steps S2102 to S2104 are skipped, and steps S2105 to S2106 are executed directly. If the first user's first data needs to undergo a user consent check, steps S2102 to S2106 are executed.
[0183] In step S2105, the first node obtains the first user's first data from the fourth node.
[0184] In some embodiments, the first node may send a fourth message to the fourth node, the fourth message being used to request first data from the first user. The fourth node receives the fourth message and sends the first data to the first node. In some embodiments, the fourth node is deployed on the first user's device.
[0185] In step S2106, the first node sends the first data of the first user.
[0186] In some embodiments, the third node receives first data from the first user. In some embodiments, the first node may process the first data and send the processed first data to the third node.
[0187] The communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2106. For example, step S2101 may be implemented as a standalone embodiment. For example, step S2102 may be implemented as a standalone embodiment. For example, step S2103 may be implemented as a standalone embodiment. For example, step S2104 may be implemented as a standalone embodiment. For example, step S2105 may be implemented as a standalone embodiment. For example, step S2106 may be implemented as a standalone embodiment. For example, steps S2101 and S2102 may be combined as a standalone embodiment. For example, steps S2103 and S2104 may be combined as a standalone embodiment. For example, steps S2102, S2103, and S2104 may be combined as a standalone embodiment. For example, steps S2102, S2103, and S2104 may be combined as a standalone embodiment.
[0188] In some embodiments, when the first node and the third node are deployed on the same device, steps S2101, S2105 and S2106 can be omitted.
[0189] In some embodiments, when the first node and the second node are deployed on the same device, steps S2102 and S2103 can be omitted.
[0190] In some embodiments, the first user in the embodiment of FIG2A can also be a contracted user, and the second node can also store the configuration information of the contracted user. In this case, the user consent check process of the contracted user is basically the same as the above steps S2101 to S2106, and will not be described in detail here.
[0191] In some embodiments, when the first user is a subscribed user, in step S2101, the user identifier of the first user can be a subscription permanent identifier (SUPI) or a generic public subscription identifier (GPSI).
[0192] In some embodiments, where the first user is a subscribed user and the second node stores the subscribed user's configuration information, in step S2103, the second node can retrieve fifth information from the subscribed user's configuration information based on the first user's user identifier. The fifth information indicates the first user's configuration information. Then, the second node obtains the first user's first information from the first user's configuration information and sends it to the first node so that the first node can determine the first information associated with the data type of the first data from the first user's first information. In some embodiments, the second node can retrieve the first information associated with the data type of the first data from the first user's first information and send it to the first node. In some embodiments, the subscribed user's configuration information is used for the subscribed user's privacy protection; this can be understood as all information associated with the subscribed user's privacy protection being included in the configuration information.
[0193] In this embodiment, the first node obtains first information about a first user associated with the type of first data from the second node. Based on this first information, the first node performs a user consent check on the first data to determine whether the first user agrees to provide the first data. Only if the first user agrees does the first node obtain the first user's first data; otherwise, it does not. This allows for differentiated treatment of different types of personal data, ensuring that highly sensitive data receives due protection, reducing the risk of privacy breaches, and improving user experience.
[0194] Figure 2B is an interactive schematic diagram of a communication method provided according to an embodiment of the present disclosure. As shown in Figure 2B, the present disclosure relates to a communication method. Executed by a communication system 100, the communication method includes steps S2201 to S2208.
[0195] In this embodiment, the first user is a non-contracted user, and the second node stores the configuration information of the contracted user.
[0196] In step S2201, the third node sends the first message.
[0197] Optional implementations of step S2201 can also be found in optional implementations of step S2101 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0198] In step S2202, the first node determines the second user associated with the first user.
[0199] In some embodiments, the first node determines the second user associated with the first user based on a first mapping relationship, wherein the first mapping relationship is a mapping relationship between subscribed users and non-subscribed users, that is, the second user associated with the first user is a subscribed user. In some embodiments, the first node stores the first mapping relationship, or the first node can obtain the first mapping relationship from the application server associated with the non-subscribed user.
[0200] In some embodiments, a signed user can have a mapping relationship with multiple non-signed users. In one example, a signed user can be company A, and multiple non-signed users can be multiple employees of company A.
[0201] In step S2203, the first node sends the second message.
[0202] In some embodiments, the second node receives a second message. In some embodiments, the second message is used to request first information of the second user. In some embodiments, the second message is used to request first information associated with the data type of the first data from the first information of the second user. In some embodiments, the second message includes at least one of the following: seventh information and ninth information. In some embodiments, the seventh information indicates the data type of the first data. In some embodiments, the ninth information indicates the user identifier of the second user.
[0203] Optional implementations of step S2203 can also be found in optional implementations of step S2102 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0204] In step S2204, the second node sends the first information of the second user.
[0205] In some embodiments, the first node receives the first information from the second user.
[0206] In some embodiments, the second node retrieves the second user's configuration information from the subscribed user's configuration information based on the second user's user identifier. Then, the second node obtains the second user's first information from the second user's configuration information and sends the second user's first information to the first node so that the first node can determine the first information associated with the data type of the first data from the second user's first information.
[0207] In some embodiments, the second node may retrieve first information associated with the data type of the first data from the first information of the second user, and send the first information associated with the data type of the first data to the first node.
[0208] In some embodiments, the configuration information of a subscribed user is used for the privacy protection of the subscribed user, which can be understood as all information associated with the privacy protection of the subscribed user being included in the configuration information. In some embodiments, the configuration information of a second user is used for the privacy protection of the second user, which can be understood as all information associated with the privacy protection of the second user being included in the configuration information of the second user.
[0209] Optional implementations of step S2204 can also be found in optional implementations of step S2103 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0210] In step S2205, the first node determines the first information of the first user based on the first information of the second user.
[0211] In some embodiments, the first node can directly use the second user's first information as the first user's first information.
[0212] In some embodiments, the first information of the second user includes the first information of the first user. The first node can retrieve the first information of the first user from the first information of the second user based on the user identifier of the first user.
[0213] In step S2206, the first node performs a user consent check on the first user's first data based on the first user's first information.
[0214] Optional implementations of step S2206 can also be found in optional implementations of step S2104 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0215] In step S2207, the first node obtains the first user's first data from the fourth node.
[0216] Optional implementations of step S2207 can also be found in optional implementations of step S2105 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0217] In step S2208, the first node sends the first data of the first user.
[0218] Optional implementations of step S2208 can also be found in optional implementations of step S2106 in Figure 2A and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0219] The communication method involved in the embodiments of this disclosure may include at least one of steps S2201 to S2208. For example, step S2201 may be implemented as a standalone embodiment. For example, step S2202 may be implemented as a standalone embodiment. For example, step S2203 may be implemented as a standalone embodiment. For example, step S2204 may be implemented as a standalone embodiment. For example, step S2205 may be implemented as a standalone embodiment. For example, step S2206 may be implemented as a standalone embodiment. For example, step S2207 may be implemented as a standalone embodiment. For example, step S2208 may be implemented as a standalone embodiment. For example, steps S2201 and S2202 may be combined as a standalone embodiment. For example, steps S2202 and S2203 may be combined as a standalone embodiment. For example, steps S2202, S2203, and S2204 may be combined as a standalone embodiment. For example, steps S2205 and S2206 may be combined as a standalone embodiment. For example, steps S2204, S2205 and S2206 can be combined as independent embodiments.
[0220] In this embodiment, the first node can obtain the first user's first information from the second user's user identifier, and perform a user consent check on the first data based on the first user's first information associated with the type of first data to determine whether the first user agrees to provide the first data. Only if the first user agrees will the first node obtain the first user's first data; otherwise, the first node will not obtain the first user's data. This allows for differentiated treatment of different types of personal data, ensuring that highly sensitive data receives due protection, reducing the risk of privacy leaks, and improving user experience.
[0221] In some embodiments, the terms "general personal data", "ordinary personal data", and "general personal data" can be used interchangeably.
[0222] In some embodiments, the terms "privacy personal data", "sensitive personal data", and "confidential personal data" can be used interchangeably.
[0223] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.
[0224] In some embodiments, the terms “carrying,” “including,” “containing,” and “encapsulating” can be used interchangeably.
[0225] In some embodiments, the terms “radio”, “wireless”, “radio access network (RAN)”, “access network (AN)”, and “RAN-based” can be used interchangeably.
[0226] In some embodiments, “get,” “obtain,” “receive,” “transmit,” “bidirectional transmission,” and “send and / or receive” can be used interchangeably and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining through self-processing, or autonomous implementation, among other meanings.
[0227] In some embodiments, terms such as “send,” “transmit,” “report,” “transmit,” “request,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.
[0228] In some embodiments, the terms “issue,” “return,” “feedback,” “response,” and “acknowledgement” can be used interchangeably.
[0229] In some embodiments, terms such as "certain," "preset," "default," "set," "indicated," "a certain," "any," and "first" can be used interchangeably. "Certain A," "preset A," "default A," "set A," "indicated A," "a certain A," "any A," and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.
[0230] In some embodiments, if an arrow in the interaction diagram representing the sending of information, signaling, etc. from one subject to another passes through other subjects, it can be interpreted as the information being forwarded from one subject to another via other subjects, or it can be interpreted as the information being sent from one subject to another without passing through other subjects.
[0231] Figure 3 is another interactive schematic diagram of the communication method provided according to an embodiment of the present disclosure. The communication method involved in the embodiment of the present disclosure can be applied to a first terminal and a network device in a communication system 100. As shown in Figure 3, the communication method of the embodiment of the present disclosure includes steps S3101 to S3102.
[0232] In step S3101, the second node sends the first information of the first user.
[0233] The optional implementation of step S3101 can also be found in the optional implementation of step S2103 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0234] In step S3102, the first node performs a user consent check on the first user's first data based on the first user's first information.
[0235] The optional implementation of step S3102 can also be found in the optional implementation of step S2104 in Figure 2A, and other related parts in the embodiments involved in Figure 2A, which will not be repeated here.
[0236] The communication method involved in the embodiments of this disclosure may include at least one of steps S3101 to S3102. For example, step S3101 may be implemented as a standalone embodiment. For example, step S3102 may be implemented as a standalone embodiment.
[0237] In the following, the technical solutions of the embodiments of this disclosure will be described by way of specific implementation.
[0238] In some embodiments, this disclosure will be used in mobile communication systems so that operators can provide a higher level of privacy protection for subscribers' / users' personal data by allowing subscribers / users to make differentiated granting decisions between his / her general personal data and sensitive personal data.
[0239] In some embodiments, user consent parameters may also be stored as part of a subscriber / user privacy profile in a new network element specifically designed for security and privacy protection, such as SECF or PRIF. In some embodiments, when introducing new network elements specifically designed for security and privacy protection in a 6G network architecture, it is recommended that information about subscribers / users necessary for making protection decisions be stored in the NF. This information may be settings in a user privacy profile, which may include user consent parameters.
[0240] In some embodiments, the user consent parameter should be bound to SUPI / GPSI / VAL user ID / user ID. In some embodiments, VAL user ID and user ID are added to enable the user consent framework to support more user-centric service scenarios or use cases, such as mobile metaverse services / applications, where mobile communication services can be used by more end users behind the subscriber, for example, the subscriber is an organization, and the end users behind the subscriber are the employees of that organization.
[0241] In some embodiments, user consent parameters can be tied to the type or category of personal data. In some embodiments, personal data can be broadly categorized into general personal data and sensitive personal data. Under GDPR, sensitive personal data can be further categorized into genetic data, biometric data, health data, ethnic and national origin data, political opinion data, and religious or ideological belief data.
[0242] In some embodiments, the user consent parameter should include whether to grant user consent and the validity period of the granted consent.
[0243] In some embodiments, adding an expiration period for granted consent allows subscribers / users to restrict the consent granted under different conditions. For example, consent may be granted for a period of time, such as one week, one month, etc. After the expiration period, consent is no longer granted. The benefit of setting an expiration time for granted consent is that subscribers / users do not need to withdraw the granted consent. In some embodiments, consent can be granted according to the subscriber's / user's preferences. For example, consent may be granted during the day but not at night, or consent may be granted on weekdays but not on public holidays, and so on.
[0244] In some embodiments, the current user consent parameters do not support the collection and exposure of data solely for external (e.g., subscriber / user location data exposed to third parties) or internal (e.g., subscriber / user location data exposed to operations or the LMF). Furthermore, operators may or may not store the collected data after exposure to third parties. Stored data can be used by the operator to provide the same service to different third parties requesting the same user data. Therefore, it is proposed to add the following new purposes: for internal exposure, for external exposure, for external exposure without internal storage, and for both external exposure and internal storage.
[0245] In some embodiments, by adding proposed improvements to existing user consent parameters regarding data types, operators can inform subscribers / users about the types of data to be collected and processed. Depending on the type of personal data (general or sensitive), subscribers / users can make different consent decisions for different types of data, particularly highly sensitive personal data that they do not wish to disclose to any other party. This ensures a high level of protection for sensitive personal data.
[0246] In some embodiments, with the proposed improvement of adding a VAL user ID or user ID to existing user consent parameters, the user consent framework can support more user-centric service scenarios or use cases, where mobile communication services can be used by more end users behind the subscribers.
[0247] In some embodiments, through a proposed improvement by adding a valid clause to existing user consent parameters, subscribers / users are not required to withdraw granted consent, and subscribers / users can set their preferences for granted / ungranted consent.
[0248] This disclosure also proposes an apparatus for implementing any of the above methods. For example, a terminal is proposed, which includes units or modules for implementing the steps performed by the terminal in any of the above methods. Furthermore, another network device is proposed, including units or modules for implementing the steps performed by the network device (e.g., access network device, core network functional node, core network device, etc.) in any of the above methods.
[0249] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0250] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be hardware circuits designed for artificial intelligence, which can be understood as ASICs, such as Neural Network Processing Units (NPUs), Tensor Processing Units (TPUs), and Deep Learning Processing Units (DPUs).
[0251] Figure 4 is a schematic diagram of the structure of the communication device proposed in an embodiment of this disclosure. As shown in Figure 4, the communication device 4100 can be a first node or a second node.
[0252] In some embodiments, the communication device 4100 is a first node, and the communication device 4100 includes: a processing module 4101 configured to: perform a user consent check on the first data of the first user based on the first information of the first user; wherein the first information of the first user is associated with the type of the first user's personal data. In some embodiments, the communication device 4100 may further include a transceiver module 4102 configured to receive the first information of the first user. In some embodiments, the transceiver module is used to perform at least one of the communication steps such as sending and / or receiving performed by the network device in any of the above methods (e.g., steps S2101, steps S2102, but not limited thereto), which will not be described in detail here.
[0253] In some embodiments, the communication device 4100 is a second node, and the transceiver module 4102 is configured to send first information of a first user to a first node; wherein the first information of the first user is used to perform a user consent check on the first data of the first user, and the first information of the first user is associated with the type of the first user's personal data. In some embodiments, the transceiver module 4102 may be configured to perform at least one of the communication steps such as sending and / or receiving performed by the terminal in any of the above methods (e.g., step S2102, but not limited thereto), which will not be elaborated here.
[0254] In some embodiments, the transceiver module described above may include a transmitting module and / or a receiving module. The transmitting module and the receiving module may be separate or integrated together. Optionally, the transceiver module described above may be interchangeable with a transceiver.
[0255] Figure 5 is a schematic diagram of the structure of a communication device provided according to an embodiment of the present disclosure. The communication device 5100 may be a first node or a second node, or it may be a chip, chip system, or processor that supports network devices in implementing any of the above methods, or it may be a chip, chip system, or processor that supports terminals in implementing any of the above methods. The communication device 5100 can be used to implement the methods described in the above method embodiments, and for details, please refer to the description in the above method embodiments.
[0256] As shown in Figure 5, the communication device 5100 includes one or more processors 5101. The processor 5101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 5100 can be used to execute any of the above methods. Optionally, one or more processors 5101 can be used to invoke instructions to cause the communication device 5100 to execute any of the above methods.
[0257] In some embodiments, the communication device 5100 further includes one or more transceivers 5102. When the communication device 5100 includes one or more transceivers 5102, the transceiver 5102 performs at least one of the communication steps (e.g., S2101, step S2102, but not limited thereto) in the above method, such as sending and / or receiving, while the processor 5101 performs at least one of the other steps. In optional embodiments, the transceiver 5102 may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, interface, etc., can be used interchangeably; the terms transmitter, sending unit, transmitter, sending circuit, etc., can be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., can be used interchangeably.
[0258] In some embodiments, the communication device 5100 further includes one or more memories 5103 for storing data. Optionally, all or part of the memories 5103 may be located outside the communication device 5100. In optional embodiments, the communication device 5100 may include one or more interface circuits 5104. Optionally, the interface circuits 5104 are connected to the memories 5103 and can be used to receive data from the memories 5103 or other devices, and to send data to the memories 5103 or other devices. For example, the interface circuits 5104 can read data stored in the memories 5103 and send the data to the processor 5101.
[0259] The communication device 5100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 5100 described in this disclosure is not limited thereto, and the structure of the communication device 5100 may not be limited by FIG. 5. The communication device may be a standalone device or a part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0260] Figure 6 is a schematic diagram of the structure of a chip provided according to an embodiment of the present disclosure. When the communication device 6100 can be a chip or a chip system, the schematic diagram of the chip 6100 shown in Figure 6 can be referred to, but is not limited thereto.
[0261] Chip 6100 includes one or more processors 6101. Chip 6100 is used to perform any of the above methods.
[0262] In some embodiments, chip 6100 further includes one or more interface circuits 6102. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 6100 further includes one or more memories 6103 for storing data. Optionally, all or part of the memories 6103 may be located outside chip 6100. Optionally, interface circuit 6102 is connected to memory 6103, and interface circuit 6102 can be used to receive data from memory 6103 or other devices, and interface circuit 6102 can be used to send data to memory 6103 or other devices. For example, interface circuit 6102 can read data stored in memory 6103 and send the data to processor 6101.
[0263] In some embodiments, the interface circuit 6102 performs at least one of the communication steps (e.g., S2101, S2102, but not limited thereto) in the above-described method, such as sending and / or receiving. For example, the interface circuit 6102 performing the communication steps in the above-described method means that the interface circuit 6102 performs data interaction between the processor 6101, the chip 6100, the memory 6103, or the transceiver device. In some embodiments, the processor 6101 performs at least one of the other steps.
[0264] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.
[0265] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device 5100, cause the communication device 5100 to perform any of the methods described above. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0266] This disclosure also proposes a program product that, when executed by a communication device 5100, causes the communication device 5100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0267] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
[0268] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.
[0269] It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.
Claims
1. A communication method, executed by a first node, the method comprising: Based on the first user's first information, perform a user consent check on the first user's first data; The first information of the first user is associated with the type of the first user's personal data.
2. The method according to claim 1, wherein, The types of personal data include at least one of the following: ordinary personal data, sensitive personal data.
3. The method according to claim 1 or 2, wherein, The first information of the first user includes: The second piece of information indicates whether the first user has granted the user's consent; The third piece of information indicates the data processing purpose permitted by the first user; The fourth piece of information indicates the valid conditions under which the first user grants the user's consent.
4. The method according to claim 3, wherein, The data processing objectives include at least one of the following: Provide data to nodes within the network where the first node is located; Provide data to nodes outside the network where the first node is located; Provide data to nodes outside the network where the first node is located, and store the data in the network where the first node is located; Provide data to nodes outside the network where the first node is located, and the network where the first node is located does not store data.
5. The method according to any one of claims 1 to 4, wherein, The method further includes: Receive the first information of the first user sent by the second node.
6. The method according to claim 5, wherein, The second node is used to store fifth information, which indicates the configuration information of the first user. The configuration information is used for the privacy protection of the first user and includes the first information of the first user.
7. The method according to any one of claims 1 to 6, wherein, The first user can be a contracted user or a non-contracted user.
8. A communication method, executed by a second node, the method comprising: Send the first user's first information to the first node; The first user's first information is used to perform a user consent check on the first user's first data, and the first user's first information is associated with the type of the first user's personal data.
9. The method according to claim 8, wherein, The types of personal data include at least one of the following: ordinary personal data, sensitive personal data.
10. The method according to claim 8 or 9, wherein, The first information of the first user includes: The second piece of information indicates whether the first user has granted the user's consent; The third piece of information indicates the data processing purpose permitted by the first user; The fourth piece of information indicates the valid conditions under which the first user grants the user's consent.
11. The method according to claim 10, wherein, The data processing objectives include at least one of the following: Provide data to nodes within the network where the first node is located; Provide data to nodes outside the network where the first node is located; Provide data to nodes outside the network where the first node is located, and store the data in the network where the first node is located; Provide data to nodes outside the network where the first node is located, and the network where the first node is located does not store data.
12. The method according to any one of claims 8 to 11, wherein, The second node is used to store fifth information, which indicates the configuration information of the first user. The configuration information is used for the privacy protection of the first user and includes the first information of the first user.
13. The method according to any one of claims 8 to 12, wherein, The first user can be a contracted user or a non-contracted user.
14. A communication device configured to implement the communication method according to any one of claims 1 to 7, 8 to 13.
15. A communication system comprising a first node and a second node; the first node being configured to implement the communication method as described in any one of claims 1 to 7, and the second node being configured to implement the communication method as described in any one of claims 8 to 13.
16. A storage medium storing instructions that, when executed on a communication device, cause the communication device to perform a communication method as described in any one of 1 to 7, 8 to 13.
17. A computer program product comprising a computer program that, when executed by a processor, implements the communication method as described in any one of claims 1 to 7, 8 to 13.