Federated Learning Authorization for Secure AI/ML Model Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authorization capabilities in the 3GPP SBA framework are insufficiently granular to provide the necessary level of security for federated learning of AI/ML models in 5G networks, particularly for Network Data Analytics Functions (NWDAFs) operating as clients and servers, exposing confidential models to unauthorized parties.

Innovation Solution

Implement methods for registering and authorizing Network Functions (NFs) in a network repository function (NRF) with detailed authorization information, including identifiers and scopes, to ensure only authorized NFs can join federated learning groups, preventing unauthorized access and fraud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current authorization capabilities in 3GPP SBA framework are used, then network function authorization is provided, but the authorization granularity is insufficient to secure federated learning of AI/ML models

Engineering Contradiction:
Improvesecurity of federated learningVSAvoidauthorization capability complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization capability into finer-grained components by introducing FL group-specific authorization information that includes FL group identifier, model identifier, and scope parameters. This allows differentiated authorization control for different federated learning groups and models, resolving the contradiction between providing secure authorization and maintaining system simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds new dimensions to the authorization framework by introducing FL group identifier and model identifier as additional authorization parameters. This dimensional expansion enables granular control over which network functions can access which models in which federated learning groups, thereby enhancing security without overwhelming complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Object-affected harmful factors

If detailed authorization information is registered in NRF, then unauthorized access to models is prevented, but the complexity of authorization management increases

Engineering Contradiction:
Improveunauthorized access to modelsVSAvoidauthorization management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent uses the Network Repository Function (NRF) as an intermediary to centralize and manage authorization information. By registering FL group authorization information in the NRF, the system simplifies authorization management while preventing unauthorized access, as the NRF acts as a single point of truth for authorization decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authorization registration where authorization information is registered before federated learning operations commence. This preliminary action ensures that unauthorized access is prevented from the outset, while the structured registration process in NRF manages complexity by establishing clear authorization boundaries in advance.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If NFs are authorized to join FL groups, then secure model sharing is enabled, but the complexity of joining and managing FL groups increases

Engineering Contradiction:
Improvesecure model sharingVSAvoidjoining and managing FL groups
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent makes the authorization mechanism universal by using the same NRF registration process for all FL group authorization scenarios. This multi-functional approach handles different FL group configurations and network function roles through a unified authorization framework, simplifying operations while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the NRF provides authorization status information to network functions, enabling them to make informed decisions about joining FL groups. This feedback loop simplifies the joining process by providing clear authorization guidance, while maintaining secure model sharing through verified authorization.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260075060A1Security for AI/ML Model Storage and Sharing
Publication Date: 2026.03.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20260075060A1 patent drawing
  • US20260075060A1 patent drawing
  • US20260075060A1 patent drawing

AI summary

Methods for a first network function (NF) configured to operate as a server of a federated learning (FL) group in a communication network. Such methods include registering, in a network repository function (NRF) of the communication network, information associated with the FL group. The FL group includes the first NF and one or more further NFs configured to operations as clients in the FL group. The registered information includes authorization information for additional NFs to join the FL group as clients. Such methods include receiving an indication of a second NF, of the communication network, that is a candidate client for the FL group and obtaining an indication that the second NF is authorized to join the FL group as a client. The indication is based on the registered authorization information. Such methods include, based on the indication, updating the FL group to include the second NF as a client.