Untrusted data collection coordination function
A data collection coordination function, DCCF, network node receives (1a) a request for data from a data consumer, determines (2) a data source for the requested data, verifies (3a, 3b) with a network node that the data consumer and the DCCF are authorized by the data source, receives (3b) a message container for the data consumer from the network node, the message container for the data consumer including a data encryption key K E and a data integrity key Ki, and receives (3 b ) a message container for the data source from the network node, the message container for the data source including the data encryption key K E and the data integrity key Ki. The DCCF network node transmits (4 a ) the message container for the data consumer to the data consumer and transmits (5) the message container for the data source to the data source.
1 . A method performed by a Third Generation Partnership Project (3GPP) data collection coordination function (DCCF) network node, comprising:
receiving a request for data from a data consumer;
determining a data source for the requested data;
verifying with a network repository function (NRF) network node that the data consumer and the DCCF network node are authorized by the data source;
receiving a message container for the data consumer from the NRF network node, the message container for the data consumer including a data encryption key K E and a data integrity key K 1 ;
receiving a message container for the data source from the NRF network node, the message container for the data source including the data encryption key K E and the data integrity key K 1 ;
transmitting the message container for the data consumer to the data consumer; and
transmitting the message container for the data source to the data source.
2 . The method of claim 1 , further comprising:
transmitting a subscription request to the data source;
upon a triggering event, receiving data from the data source, wherein the data is protected by at least one of the data encryption key K E and the data integrity key K I ; and
transmitting the received data to the data consumer.
3 . The method of claim 1 , wherein the data encryption key K E and the data integrity key K 1 within the message container for the data consumer are encrypted using a public key of the data consumer.
4 . The method of claim 1 , wherein the data encryption key K E and the data integrity key K 1 within the message container for the data source are encrypted using a public key of the data source.
5 . The method of claim 1 , wherein the message container for the data consumer and the message container for the data source are each signed by a private key of the NRF network node.
6 . A Third Generation Partnership Project (3GPP) data collection coordination function (DCCF) network node, comprising:
processing circuitry and memory collectively configured to:
receive a request for data from a data consumer;
determine a data source for the requested data;
verify with a network repository function (NRF) network node that the data consumer and the DCCF network node are authorized by the data source;
receive a message container for the data consumer from the NRF network node, the message container for the data consumer including a data encryption key K E and a data integrity key K 1 ;
receive a message container for the data source from the NRF network node, the message container for the data source including the data encryption key K E and the data integrity key K 1 ;
transmit the message container for the data consumer to the data consumer; and
transmit the message container for the data source to the data source.
7 . The DCCF network node of claim 6 , wherein the processing circuitry and memory are further collectively configured to:
transmit a subscription request to the data source;
upon a triggering event, receive data from the data source, wherein the data is protected by at least one of the data encryption key K E and the data integrity key K I ; and
transmit the received data to the data consumer.
8 . The DCCF network node of claim 6 , wherein the data encryption key K E and the data integrity key K I within the message container for the data consumer are encrypted using a public key of the data consumer.
9 . The DCCF network node of claim 6 , wherein the data encryption key K E and the data integrity key K I within the message container for the data source are encrypted using a public key of the data source.
10 . The DCCF network node of claim 6 , wherein the message container for the data consumer and the message container for the data source are each signed by a private key of the network node.