RAN Insight Processing for Trusted and Untrusted Exposure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no standardized way to securely expose Radio Access Network (RAN) data to external applications while avoiding direct exposure of raw, sensitive data and ensuring appropriate normalization and domain trust considerations.

Innovation Solution

A RAN function node processes RAN data to generate tailored RAN insights, which are then exposed to trusted or untrusted domains based on the receiver's trust status, using message buses to manage the distribution and ensure secure, appropriate exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If RAN data is directly exposed to external applications, then applications can access raw network data for analysis and service creation, but sensitive raw data security is compromised and data normalization is lacking

Engineering Contradiction:
Improveapplication accessibility to RAN dataVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary processing layer between the RAN data source and external applications. This layer collects raw RAN data, processes it through normalization and analysis functions, and exposes only the processed insights to applications. The intermediary prevents direct access to sensitive raw data while still enabling application functionality through exposed insights.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If RAN data is processed to generate insights, then data security is improved and applications receive useful information, but system complexity increases

Engineering Contradiction:
Improvedata security riskVSAvoiddata processing system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the data processing function into distinct modular components: data collection from RAN, data processing and normalization, insight generation, and exposure to applications. Each segment performs a specific function, making the overall complex system manageable through modular architecture where each component can be independently implemented and maintained.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If trusted and untrusted domains are separated, then data exposure security is enhanced, but infrastructure complexity increases

Engineering Contradiction:
Improveunauthorized data accessVSAvoiddomain separation infrastructure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies different quality characteristics to different domains: the trusted domain receives comprehensive, detailed RAN insights with full information access, while the untrusted domain receives normalized, aggregated insights with limited sensitivity. This local quality differentiation secures the system by providing appropriate data fidelity to each domain based on its trust level, rather than applying a uniform data exposure policy.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4252445B1Method and system for exposing radio access network (RAN) data
Publication Date: 2025.07.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4252445B1 patent drawingFigure 1
  • EP4252445B1 patent drawingFigure 2
  • EP4252445B1 patent drawingFigure 3

AI summary

A method performed by a Radio Area Network, RAN, function node for handling connectivity in a RAN of a wireless communications network is provided. The RAN function node receives (201) from a network node, a first subscription request for one or more RAN insights relating to the connectivity, requested for an application related to a wireless device. The RAN function node identifies (202) RAN data needed to fulfil the subscription request for the one or more RAN insights. The RAN function node sends (203) to a RAN node, a second subscription request for the identified RAN data. When RAN data according to the second subscription request is available, the RAN function node receives (204) from the RAN node, published RAN data according to the second subscription request. The RAN function node generates (205) the one or more RAN insights according to the first subscription request based on the received RAN data. The RAN function node establishes (206) which domain out of a trusted domain or an untrusted domain the generated one or more RAN insights are to be exposed in. The RAN function node publishes (207) the generated one or more RAN insights according to the first subscription request to reach the network node. The publishing comprises an indication, indicating to the network node the established domain out of a trusted domain or an untrusted domain, that the generated one or more RAN insights are to be exposed in.