Secure data collection via a messaging framework
Various aspects of the present disclosure relate to secure data collection via a messaging framework. An apparatus includes at least one memory and at least one processor that is configured to receive a subscription request from a data consumer function, the subscription request comprising a data tag associated with a data producer function, generate a security key for the data tag, generate a binding for the data tag between the security key, the data consumer function, and the data producer function, and transmit, for use in data transmissions between the data producer function and the data consumer function a service request message to the data producer function, the service request message comprising the data tag and the security key, and a data exposure response message to the data consumer function, the data exposure response message comprising the data tag and the security key.
1 . A network equipment for wireless communication, comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the network equipment to:
receive a subscription request from a data consumer function, the subscription request comprising a data tag associated with a data producer function;
generate a security key for the data tag;
generate a binding for that associates the data tag, the security key, the data producer function, and the data consumer function, wherein the binding defines an end-to-end data protection relationship between the data producer function and the data consumer function;
transmit a service request message comprising the data tag and the security key to the data producer function; and
transmit a data exposure response comprising the data tag and the security key to the data consumer function.
2 . The network equipment of claim 1 , wherein the at least one processor is configured to cause the network equipment to:
receive a subscription request from one or more second data consumer functions, the subscription request comprising the data tag associated with the data producer function; and
initiate a key refresh procedure for the data tag in response to determining that a binding exists for the data tag between the security key, the data consumer function, and the data producer function.
3 . The network equipment of claim 2 , wherein the at least one processor is configured to cause the network equipment to, for the key refresh procedure:
generate a new security key for the data tag;
identify based on the data tag, the data consumer function, the one or more second data consumer functions, and the data producer function;
delete the binding for the data tag between the security key, the data consumer function, and the data producer function;
generate a new binding for the data tag between the new security key, the data consumer function, the one or more second data consumer functions, and the data producer function; and
transmit a key refresh request to the data consumer function, the one or more second data consumer functions, and the data producer function, the key refresh request comprising the new security key.
4 . The network equipment of claim 2 , wherein the at least one processor is configured to cause the network equipment to, for the key refresh procedure, generate asymmetric keys for the data consumer function, the one or more second data consumer functions, and the data producer function, the asymmetric keys comprising a public key provisioned for the data producer function and corresponding private keys provisioned for the data consumer function and the one or more second data consumer functions.
5 . The network equipment of claim 1 , wherein the data tag comprises one or more of data requested from the data producer function, identifying information for a device associated with the data consumer function, identifying information for the data producer function, and filtering information.
6 . The network equipment of claim 1 , wherein the at least one processor is configured to cause the network equipment to select a security algorithm for generating the security key and transmit the security algorithm, along with the security key, to the data consumer function and the data producer function.
7 . The network equipment of claim 1 , wherein the at least one processor is configured to cause the network equipment to register the data consumer function with a messaging framework for notifications related to the data tag.
8 . A method performed by a network equipment, comprising:
receiving a subscription request from a data consumer function, the subscription request comprising a data tag associated with a data producer function;
generating a security key for the data tag;
generating a binding that associates the data tag, the security key, the data producer function, and the data consumer function, wherein the binding defines an end-to-end data protection relationship between the data producer function and the data consumer function;
transmitting a service request message comprising the data tag and the security key to the data producer function; and
transmitting a data exposure response comprising the data tag and the security key to the data consumer function.
9 . The method of claim 8 , further comprising:
receiving a subscription request from one or more second data consumer functions, the subscription request comprising the data tag associated with the data producer function; and
initiating a key refresh procedure for the data tag in response to determining that a binding exists for the data tag between the security key, the data consumer function, and the data producer function.
10 . The method of claim 9 , further comprising, for the key refresh procedure:
generating a new security key for the data tag;
identifying based on the data tag, the data consumer function, the one or more second data consumer functions, and the data producer function;
deleting the binding for the data tag between the security key, the data consumer function, and the data producer function;
generating a new binding for the data tag between the new security key, the data consumer function, the one or more second data consumer functions, and the data producer function; and
transmitting a key refresh request to the data consumer function, the one or more second data consumer functions, and the data producer function, the key refresh request comprising the new security key.
11 . The method of claim 10 , further comprising, for the key refresh procedure, generating asymmetric keys for the data consumer function, the one or more second data consumer functions, and the data producer function, the asymmetric keys comprising a public key provisioned for the data producer function and corresponding private keys provisioned for the data consumer function and the one or more second data consumer functions.
12 . The method of claim 8 , wherein the data tag comprises one or more of data requested from the data producer function, identifying information for a device associated with the data consumer function, identifying information for the data producer function, and filtering information associated with the data.