5G Analytics Exposure Control via Segmented Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for exposing analytics information in 5G communication networks to third-party application functions do not allow network operators to customize or differentiate the treatment of requests, leading to a single mode of operation where third-party applications are either fully allowed or fully restricted, lacking granular control over access and usage.
Innovation Solution
The implementation of an enhanced network function that applies distinct exposure service models, including 'Mirror', 'Restrictive', and 'Surrogate', to manage access and usage of analytics information, using Analytics Visibility Rules (AVR) to enforce inbound, outbound, and temporal restrictions, allowing operators to customize and control how third-party applications interact with analytics services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If current solutions are used for exposing analytics information to third-party application functions, then the network operator can authorize or deny access to analytics information, but the operator cannot differentiate or customize the treatment for different third-party AF requests
Solution Approach 1:
The patent segments the authorization process into multiple rule types (inbound restrictions, outbound restrictions, temporal restrictions) that can be independently configured and applied to different third-party AFs. This allows granular control over analytics information exposure without requiring a completely new system architecture, thus improving customization capability while managing complexity through structured rule management.
Solution Approach 2:
The patent introduces dynamic rule management where operators can configure different exposure service models (Mirror, Restriction, Surrogate) that can be activated or deactivated based on operational needs. The system can dynamically adjust authorization decisions based on time-based rules and condition-based rules, enabling adaptable control without requiring complex reconfiguration of the entire system.
2Ease of operation
If a single mode of operation is used for third-party AF access, then the system is simple to operate, but the operator loses the ability to apply different parameters or restrictions to different requests
Solution Approach 1:
The patent applies local quality by allowing different authorization rules to be applied to different third-party AFs based on their specific characteristics and requirements. Instead of a uniform treatment, the system can apply inbound restrictions to control what parameters AFs can use, outbound restrictions to control what information is returned, and temporal restrictions to control when access is allowed, all while maintaining a unified system architecture that simplifies operation.
3Productivity
If analytics information is exposed without customisation rules, then third-party applications can access information freely, but security and control over the exposed information are compromised
Solution Approach 1:
The patent implements preliminary action by establishing authorization rules before analytics information exposure occurs. Operators can pre-configure inbound restrictions to validate request parameters, outbound restrictions to control information disclosure, and temporal restrictions to limit access timing. This preliminary rule setup enables fast, unrestricted access for compliant requests while automatically blocking harmful access attempts, thus maintaining both productivity and security without requiring real-time security checks that would slow down legitimate requests.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a first entity (403; 101) for a communication network, in particular a mobile communication network, configured to obtain, from a second entity (201) and/or a third entity (101, 401), information for the second entity (201) comprising a request for analytics information and/or a request for a rule related to analytics information that can be provided by the first entity (403; 101). The first entity (403; 101) can be further configured to provide to the second entity (201) analytics information according to one or more rules, in particular according to the request for analytics information, and/or the requested rule. Alternatively, the first entity (403; 101) can be further configured to forward the obtained information to a fourth entity (401, 403) according to one or more rules. Moreover, the invention relates to a corresponding method.