AI/ML Model Access Tokens for Secure 5G Network Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There are no specified solutions to protect the confidentiality and integrity of AI/ML models in 5G networks, particularly when shared or stored in network equipment provided by different vendors, leading to potential unauthorized access and misuse.
Innovation Solution
Implement methods for secure transfer, storage, and retrieval of AI/ML models by using access tokens and encryption, ensuring only authorized network functions can access and use the models, including registering information with an NRF and encrypting models before storage in an ADRF.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If AI/ML models are shared or stored in network equipment provided by different vendors, then model sharing and storage capability is improved, but security and confidentiality are worsened due to potential unauthorized access and misuse
Solution Approach 1:
The patent introduces an intermediary authentication mechanism where the network function requesting access to the AI/ML model must first obtain an access token from a authentication server. This intermediary token acts as a mediator that verifies the requester's authorization before allowing model access, thereby enabling multi-vendor sharing while preventing unauthorized access.
Solution Approach 2:
The patent extracts the authentication and authorization logic from the model storage and retrieval process. By separating the authentication server component, the system can verify credentials independently before allowing model access, thus enabling secure multi-vendor model sharing without compromising confidentiality.
2Object-affected harmful factors
If access tokens and encryption are implemented for secure model transfer and storage, then security and confidentiality are improved, but system complexity increases
Solution Approach 1:
The patent segments the security mechanism into distinct components: an authentication server that issues access tokens, and a model storage/retrieval system that uses these tokens. This segmentation allows each component to have specialized security functions, improving confidentiality while managing complexity through modular design.
Solution Approach 2:
The patent uses access tokens as copies or representations of authorization. Instead of embedding complex authentication logic throughout the system, the tokens serve as simplified copies that carry authorization information, reducing the complexity of the overall authentication mechanism while maintaining security.
3Reliability
If encryption is applied to AI/ML models before storage, then data integrity and confidentiality are improved, but storage and retrieval operations become more complex
Solution Approach 1:
The patent applies encryption as a preliminary action before model storage. The model is encrypted and stored in an encrypted form, and the decryption key is made available to authorized users through the authentication mechanism. This preliminary encryption ensures data integrity and confidentiality while simplifying storage operations to standard encrypted storage operations.
Data Source
AI summary
Embodiments include methods for a consumer network function (NFc) of a communication network. Such methods include sending, to a first NF of the communication network, a first request for a first access token associated with a machine learning (ML) model. The first request includes at least one of the following associated with the ML model: an analytics identifier (ID), and an interoperability ID. Such methods include receiving from the first NF a first response that includes the first access token and sending, to a producer NF (NFp) of the communication network, a second request for the ML model. The second request includes the first access token and at least one of the analytics ID and the interoperability ID. Such methods include receiving from the NFp a second response that includes one or more of the following: the ML model; an identifier of the ML model; and an address of a storage resource associated with a second NF of the communication network, from which the ML model can be obtained.


