Real-Time User Consent Data Notification via CAPIF
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G systems support static user consent handling, which is inadequate for real-time applications and user data exposure control, potentially impacting user privacy and application experience.
Innovation Solution
Implementing methods and apparatuses that enable secure user consent data notification, allowing user equipment (UE) to provide, update, and revoke user consent data in real-time through a common application programming interface (API) framework or core network function, using a key derived from the CAPIF security context.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If static user consent data is stored as part of subscription data, then the system is simple to implement, but it cannot support real-time user consent updates and dynamic data exposure control
Solution Approach 1:
The patent transforms static consent data into dynamic, real-time updatable consent information. The CAPIF framework enables consent data to be modified dynamically by network functions, allowing users to update their consent preferences in real-time without requiring system reconfiguration, thus achieving adaptability while maintaining manageable complexity through standardized procedures
Solution Approach 2:
The patent introduces a CAPIF (Common API Framework) as an intermediary layer between the user equipment and the network functions. This framework mediates consent data management, providing a standardized interface for real-time consent updates while abstracting the complexity from both the user equipment and core network functions, enabling real-time adaptability without proportionally increasing overall system complexity
2Adaptability or versatility
If general consent data is used for all services, then the implementation is straightforward, but it cannot provide service-specific consent control and impacts user privacy
Solution Approach 1:
The patent segments consent data into service-specific units within the CAPIF framework. Each service or network function can access and manage its own specific consent data independently, allowing granular control over what data is shared with which service. This segmentation enables service-specific consent control while keeping data management organized and manageable through the standardized CAPIF interface
Solution Approach 2:
The patent implements local quality by allowing different consent data to be associated with different services, network functions, or data exposure scenarios. Each service receives only the consent data relevant to its specific function, enabling precise control over data exposure for each service while maintaining overall system coherence through the CAPIF framework's standardized management procedures
3Productivity
If user consent data is exposed to application servers, then application functionality is enhanced, but user privacy and data security are compromised
Solution Approach 1:
The CAPIF framework acts as a secure intermediary between user equipment and application servers. It validates and controls the exposure of user consent data, ensuring that only authorized services receive appropriate consent information. This intermediary layer enhances application functionality by enabling controlled data sharing while simultaneously protecting user privacy through standardized security procedures and authorization mechanisms
Solution Approach 2:
The patent implements feedback mechanisms where the CAPIF framework continuously monitors and controls data exposure based on current consent status. When user consent changes, the framework provides feedback to relevant network functions and application servers to update their access permissions accordingly. This feedback loop ensures that application services operate with current, authorized consent data while maintaining ongoing security validation
Data Source
AI summary
Various aspects of the present disclosure relate to a user equipment (UE) that transmits information, such as to a common application programming interface framework (CAPIF) function or to a core network function (CNF), to trigger a user consent provisioning procedure. The UE also transmits a data exposure notification comprising at least user consent data, and the UE receives a data exposure response acknowledgement (ACK) that indicates the user consent data is stored for reference of the user consent.


