5G Data Collection Authorization for Secure NWDAF Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data collection methods for Network Data Analytics Function (NWDAF) in 5G networks suffer from low data security due to all data being made available to the NWDAF, compromising network security.
Innovation Solution
Implementing a data collection method and apparatus that performs authorization verification on data obtaining requests from data usage network elements, ensuring only authorized elements receive specific data by determining the data domain to which they belong and adjusting data content accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If all data is opened to the NWDAF for data collection, then the NWDAF can obtain comprehensive data for analysis, but data security is greatly reduced
Solution Approach 1:
The patent applies local quality by differentiating data access permissions for different network elements. Instead of uniform data access, each network element is assigned specific data domains it can access based on its function and authorization level. The NWDAF receives only the data subsets it is authorized to access, implementing differentiated data security policies that maintain both data completeness for analysis and security through localized access control.
2Reliability
If authorization verification is implemented on data obtaining requests, then data security is improved, but system complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-configuring authorization relationships between network elements and data domains before data access occurs. The system establishes which network elements can access which data domains in advance, so that during actual data collection, the NWDAF simply checks against pre-established authorization rules rather than performing complex real-time verification, thereby reducing system complexity while maintaining security.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present application provides data collection methods and apparatuses. A method is applied to a data collection network element, where the method includes: receiving a data obtaining request sent by a data usage network element, wherein the data obtaining request is used to request the data collection network element to provide data to the data usage network element; performing authorization verification on the data obtaining request sent by the data usage network element to obtain a result of the authorization verification; determining whether to send the data to the data usage network element, and/or, determining a content of the data to be sent to the data usage network element, according to the result of the authorization verification. Compared with the prior art, the authorization verification will be performed on the data obtaining request sent by the data usage network element when providing data, thus it can be ensured that only an authorized data usage network element can obtain data, thereby data security can be improved.