Managing end-to-end data protection
Apparatuses, methods, and systems are disclosed for managing the end-to-end (“e2e”) data protection. One apparatus includes a transceiver that receives, from an application server, a management requirement for managing e2e data protection for at least one service. The apparatus includes a processor that obtains at least one digital identifier (“DIG-ID”) of at least one client device for the at least one service in response to receiving the management requirement and verifies the at least one DIG-ID with a distributed transaction verification network. The transceiver further sends a request to a mobile communication network, the request providing the at least one verified DIG-ID, and sends a trigger event to the at least one client device for connecting to the mobile communication network using the at least one verified DIG-ID.
1 . A method performed by a trusted application entity, the method comprising:
receiving, from an application server, a management requirement for managing end-to-end (“e2e”) data protection for at least one service;
obtaining at least one digital identifier (“DID”) of at least one user equipment (“UE”) for the at least one service in response to receiving the management requirement, wherein each respective DID is a verifiably secure identity comprising a decentralized and globally unique persistent identifier or a self-sovereign identifier;
verifying the at least one DID with a distributed transaction verification network associated with the at least one DID, wherein the distributed transaction verification network comprises a distributed ledger technology (“DLT”) network, a blockchain network, or a trust service provider (“TSP”) network;
transmitting a request to a mobile communication network, the request providing the at least one verified DID, wherein the at least one verified DID allows service provisioning of the at least one UE in the mobile communication network; and
transmitting a trigger event to the at least one UE for connecting to the mobile communication network using the at least one verified DID.
2 . The method of claim 1 , wherein the service corresponds to one or more of: a geographical service area, an edge enabler service area, an edge data network service area, an application service identity, or a service type identity.
3 . The method of claim 1 , wherein the management requirement corresponds to a request to the trusted application entity for e2e data protection for a control plane transaction.
4 . The method of claim 1 , wherein the management requirement corresponds to a request for e2e data protection for a user plane transaction.
5 . The method of claim 1 , wherein the management requirement comprises:
a subscription for the at least one service; or
a one-time request for the at least one service.
6 . The method of claim 1 , wherein obtaining the at least one DID comprises:
transmitting, prior to receiving the at least one DID, a second request to the at least one UE in response to receiving the management requirement; and
wherein the at least one DID is received in response to the second request.
7 . The method of claim 6 , wherein the second request is carried via application enabler layer signaling, wherein the second request comprises the following parameters:
a request for a DID corresponding to the client device at least one UE;
a service identifier; and
a configuration of DID reporting.
8 . The method of claim 1 , wherein verifying the at least one DID comprises:
transmitting a verification request to the distributed transaction verification network; and
receiving a verification response from the distributed transaction verification network.
9 . The method of claim 1 , where the trusted application entity is a distributed ledger technology-enabled node.
10 . The method of claim 1 , wherein the at least one verified DID is usable as a subscription identifier by the at least one UE for subscribing with the mobile communication network.
11 . The method of claim 1 , wherein transmitting the request to the mobile communication network comprises transmitting a request to a 5G core network function for updating a subscription corresponding to the application with the at least one verified DID.
12 . The method of claim 11 , wherein the request to the mobile communication network comprises one or more of the following parameters:
an application function identifier corresponding to the trusted application entity;
a list of one or more DIDs corresponding to vertical application layer (“VAL”) UE entries to be added;
a list of one or more VAL-user IDs corresponding to the VAL UE entries to be added;
a list of one or more VAL group IDs;
a request to use DID as SUPI;
a request to use DID as SUCI; or
a request to use a VAL-user ID as a GPSI and/or external ID.
13 . The method of claim 1 , wherein the trigger event is provided via application enabler layer signaling, wherein the trigger event comprises one or more of the following parameters:
a vertical application layer (“VAL”) server ID;
a registration trigger indication;
a PLMN ID;
a NPN ID;
an indication to use the DID as a subscription permanent identifier (“SUPI”); or
an indication to use the DID as a subscription concealed identifier (“SUCI”).
14 . The method of claim 1 , wherein the trigger event provides assistance information for switching to a secure network.
15 . An apparatus providing a trusted application entity, comprising:
at least one memory; and
at least one processor coupled with the at least one memory and configured to cause the apparatus to:
receive, from an application server, a management requirement for managing end-to-end (“e2e”) data protection for at least one service;
obtain at least one digital identifier (“DID”) of at least one UE for the at least one service in response to receiving the management requirement, wherein each respective DID is a verifiably secure identity comprising a decentralized and globally unique persistent identifier or a self-sovereign identifier;
verify the at least one DID with a distributed transaction verification network associated with the at least one DID, wherein the distributed transaction verification network comprises a distributed ledger technology (“DLT”) network, a blockchain network, or a trust service provider (“TSP”) network;
transmit a request to a mobile communication network, the request providing the at least one verified DID, wherein the at least one verified DID allows service provisioning of the at least one UE in the mobile communication network; and
transmit a trigger event to the at least one UE for connecting to the mobile communication network using the at least one verified DID.
16 . The apparatus of claim 15 , wherein the service corresponds to one or more of: a geographical service area, an edge enabler service area, an edge data network service area, an application service identity, or a service type identity.
17 . The apparatus of claim 15 , wherein the management requirement corresponds to a request to the trusted application entity for e2e data protection for a control plane transaction.
18 . The apparatus of claim 15 , wherein the management requirement corresponds to a request for e2e data protection for a user plane transaction.
19 . The apparatus of claim 15 , wherein the management requirement comprises:
a subscription for the at least one service, or
a one-time request for the at least one service.
20 . The apparatus of claim 15 , wherein to obtain the at least one DID, the at least one processor is configured to cause the apparatus to:
transmit, prior to receiving the at least one DID, a second request to the at least one UE in response to receiving the management requirement; and
wherein the at least one DID is received in response to the second request.