Hierarchical Consent Framework for 5G Data Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G communication networks lack a mechanism for obtaining and managing user consent for data use in a way that is understandable to users, particularly for analytics and model training purposes, leading to a disconnect between user comprehensible consent and the permissions required for data gathering.

Innovation Solution

A hierarchical consent framework is introduced that maps user comprehensible data types and purposes to technology-specific purposes and data types, allowing for implied consent based on policies, enabling users to grant permissions for specific purposes while adhering to 3GPP requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a detailed technology-specific consent mechanism is implemented, then the precision and granularity of consent management is improved, but the complexity of the system increases and user comprehensibility deteriorates

Engineering Contradiction:
Improveconsent granularityVSAvoidconsent system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the consent system into two distinct hierarchical levels: a user-facing level with simplified, comprehensible consent options, and a technology-specific level with detailed data type and purpose classifications. This segmentation allows the system to maintain high consent granularity internally while presenting a simplified interface to users, thereby resolving the contradiction between precision and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a mapping mechanism as an intermediary layer that translates between user-comprehensible consent categories and technology-specific data types and purposes. This intermediary mapping table enables the system to handle detailed consent requirements without exposing the complexity to users, effectively bridging the gap between simple user interaction and complex technical implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If a comprehensive data collection policy is implemented, then the productivity and capability of analytics services is improved, but the loss of user trust and compliance reliability deteriorates

Engineering Contradiction:
Improveanalytics capabilityVSAvoidcompliance reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by obtaining explicit user consent before any data collection or analytics processing occurs. The consent mechanism is established in advance, with users granting permission for specific data types and purposes before the network entity collects or processes their data. This preliminary consent ensures that productivity-generating analytics operations always have a valid compliance foundation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback mechanism where the system continuously monitors and enforces consent boundaries. When data processing operations are initiated, the system checks against the stored consent policies to ensure compliance. This feedback loop maintains reliability by preventing unauthorized data collection while still enabling productive analytics within consented boundaries.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20230345247A1Hierarchical consent in a communication network
Publication Date: 2023.10.26 NOKIA TECHNOLOGIES OY
  • US20230345247A1 patent drawing
  • US20230345247A1 patent drawing
  • US20230345247A1 patent drawing

AI summary

Techniques for user consent in a communication network are disclosed. For example, a method comprises receiving, at a network entity of a communication network, a first level user consent for a first level data type for a first level purpose. The method further comprises applying, at the network entity, at least one hierarchical consent policy to the first level user consent to determine whether the first level user consent implies a second level user consent for a second level data type for a second level purpose.