Communication Network Data Collection with Domain-Based Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing data collection methods for Network Data Analytics Function (NWDAF) in 5G networks expose all data to the NWDAF, compromising data security.
Innovation Solution
Implement authorization verification on data obtaining requests from data usage network elements to determine the authenticity and domain alignment before sending data, ensuring that only authorized elements receive specific data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If the network side network element opens all data to the NWDAF, then the NWDAF can obtain comprehensive data for analysis, but data security is greatly reduced
Solution Approach 1:
The patent segments data access rights by introducing the concept of data domains. The network element identifier space is divided into multiple data domains, and each NWDAF is assigned authorization to access only specific data domains. This segmentation allows the system to provide comprehensive data access within authorized domains while maintaining security boundaries between domains.
Solution Approach 2:
The patent implements local quality by making data access rights domain-specific rather than universal. Each NWDAF receives tailored authorization for specific data domains based on its functional requirements. This allows different levels of data access for different network elements, providing comprehensive data where needed while maintaining security where not required.
2Reliability
If authorization verification is performed on data obtaining requests, then data security is improved, but system complexity increases
Solution Approach 1:
The patent applies preliminary action by performing authorization verification at the moment a data obtaining request is received, before any data transmission occurs. The data collection network element checks whether the requesting network element is authorized to access the requested data domain before proceeding with data collection. This preliminary verification ensures security without requiring complex continuous monitoring mechanisms.
Solution Approach 2:
The patent implements feedback by having the data collection network element respond to authorization verification results. When a network element requests data, the system provides feedback on whether the request is authorized, and only proceeds with data collection if authorization is confirmed. This feedback mechanism maintains security while keeping the system response straightforward and manageable.
Data Source
AI summary
The present application provides data collection methods and apparatuses. A method is applied to a data collection network element, where the method includes: receiving a data obtaining request sent by a data usage network element, wherein the data obtaining request is used to request the data collection network element to provide data to the data usage network element; performing authorization verification on the data obtaining request sent by the data usage network element to obtain a result of the authorization verification; determining whether to send the data to the data usage network element, and/or, determining a content of the data to be sent to the data usage network element, according to the result of the authorization verification. Compared with the prior art, the authorization verification will be performed on the data obtaining request sent by the data usage network element when providing data, thus it can be ensured that only an authorized data usage network element can obtain data, thereby data security can be improved.


