Communication Network Data Collection with Domain-Based Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing data collection methods for Network Data Analytics Function (NWDAF) in 5G networks expose all data to the NWDAF, compromising data security.

Innovation Solution

Implement authorization verification on data obtaining requests from data usage network elements to determine the authenticity and domain alignment before sending data, ensuring that only authorized elements receive specific data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the network side network element opens all data to the NWDAF, then the NWDAF can obtain comprehensive data for analysis, but data security is greatly reduced

Engineering Contradiction:
Improvedata completenessVSAvoiddata security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent segments data access rights by introducing the concept of data domains. The network element identifier space is divided into multiple data domains, and each NWDAF is assigned authorization to access only specific data domains. This segmentation allows the system to provide comprehensive data access within authorized domains while maintaining security boundaries between domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by making data access rights domain-specific rather than universal. Each NWDAF receives tailored authorization for specific data domains based on its functional requirements. This allows different levels of data access for different network elements, providing comprehensive data where needed while maintaining security where not required.

Inventive Principle:
Principle #3Local quality

2Reliability

If authorization verification is performed on data obtaining requests, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing authorization verification at the moment a data obtaining request is received, before any data transmission occurs. The data collection network element checks whether the requesting network element is authorized to access the requested data domain before proceeding with data collection. This preliminary verification ensures security without requiring complex continuous monitoring mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by having the data collection network element respond to authorization verification results. When a network element requests data, the system provides feedback on whether the request is authorized, and only proceeds with data collection if authorization is confirmed. This feedback mechanism maintains security while keeping the system response straightforward and manageable.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12355630B2Method and apparatus for data collection in communication network
Publication Date: 2025.07.08 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • US12355630B2 patent drawing
  • US12355630B2 patent drawing
  • US12355630B2 patent drawing

AI summary

The present application provides data collection methods and apparatuses. A method is applied to a data collection network element, where the method includes: receiving a data obtaining request sent by a data usage network element, wherein the data obtaining request is used to request the data collection network element to provide data to the data usage network element; performing authorization verification on the data obtaining request sent by the data usage network element to obtain a result of the authorization verification; determining whether to send the data to the data usage network element, and/or, determining a content of the data to be sent to the data usage network element, according to the result of the authorization verification. Compared with the prior art, the authorization verification will be performed on the data obtaining request sent by the data usage network element when providing data, thus it can be ensured that only an authorized data usage network element can obtain data, thereby data security can be improved.