ISO IEC TR 16166-2010 Information technology - Telecommunications and information exchange between systems - Next Generation Corporate Networks (NGCN) - Securit.pdf
《ISO IEC TR 16166-2010 Information technology - Telecommunications and information exchange between systems - Next Generation Corporate Networks (NGCN) - Securit.pdf》由会员分享,可在线阅读,更多相关《ISO IEC TR 16166-2010 Information technology - Telecommunications and information exchange between systems - Next Generation Corporate Networks (NGCN) - Securit.pdf(34页珍藏版)》请在麦多课文档分享上搜索。
1、 Reference number ISO/IEC TR 16166:2010(E) ISO/IEC 2010TECHNICAL REPORT ISO/IEC TR 16166 First edition 2010-08-01Information technology Telecommunications and information exchange between systems Next Generation Corporate Networks (NGCN) Security of session-based communications Technologies de linfo
2、rmation Tlinformatique Rseaux dentreprise de prochaine gnration (NGCN) Scurit des communications sur la base de sessions ISO/IEC TR 16166:2010(E) PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not
3、be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe
4、is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO mem
5、ber bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. COPYRIGHT PROTECTED DOCUMENT ISO/IEC 2010 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form
6、 or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISOs member body in the country of the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 4
7、7 E-mail copyrightiso.org Web www.iso.org Published in Switzerland ii ISO/IEC 2010 All rights reservedISO/IEC TR 16166:2010(E) ISO/IEC 2010 All rights reserved iiiContents Page Foreword . v Introduction vi 1 Scope 1 2 References . 1 3 Terms and definitions . 3 3.1 External definitions . 3 3.2 Other
8、definitions 4 4 Abbreviations . 4 5 Background 5 6 General principles . 5 6.1 Threats and counter-measures 5 6.2 Threats to session level security . 6 6.3 Authorisation . 7 6.4 Security and mobile users 8 6.5 Security and NGN 8 6.6 Security and software status . 8 6.7 Call recording and audit . 8 7
9、Signalling security . 8 7.1 Security of access to session level services . 9 7.2 Securing a SIP signalling hop 9 7.2.1 TLS for securing SIP signalling . 10 7.2.2 IPsec for security SIP signalling 10 7.2.3 The role of SIP digest authentication 10 7.3 Ensuring that all SIP signalling hops are secured
10、. 11 7.4 End-to-end signalling security . 12 7.4.1 End-to-end security using S/MIME 12 7.4.2 Near end-to-end security using SIP Identity . 13 7.5 Authenticated identity delivery 13 7.5.1 P-Asserted-Identity (PAI) 14 7.5.2 Authenticated Identity Body (AIB) . 14 7.5.3 SIP Identity . 14 7.5.4 Authentic
11、ated response identity 15 7.6 NGN considerations 16 7.7 Public Switched Telephony Network (PSTN) interworking . 17 8 Media security 18 8.1 SRTP . 18 8.2 Key management for SRTP 18 8.2.1 Key management on the signalling path 18 8.2.2 Key management on the media path . 20 8.3 Authentication . 21 8.3.1
12、 Authentication with key management on the signalling path 21 8.3.2 Authentication with DTLS-SRTP 22 8.3.3 Authentication with ZRTP . 22 8.4 Media recording . 22 8.5 NGN considerations 23 9 Use of certificates 24 10 User interface considerations 24 ISO/IEC TR 16166:2010(E) iv ISO/IEC 2010 All rights
13、 reserved11 Summary of requirements, recommendations and standardisation gaps 25 11.1 Requirements on NGNs 25 11.2 Recommendations on enterprise networks 25 11.3 Standardisation gaps 26 ISO/IEC TR 16166:2010(E) ISO/IEC 2010 All rights reserved vForeword ISO (the International Organization for Standa
14、rdization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organizati
15、on to deal with particular fields of technical activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the work. In the field of information technology, I
16、SO and IEC have established a joint technical committee, ISO/IEC JTC 1. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2. The main task of the joint technical committee is to prepare International Standards. Draft International Standards adopte
17、d by the joint technical committee are circulated to national bodies for voting. Publication as an International Standard requires approval by at least 75 % of the national bodies casting a vote. Attention is drawn to the possibility that some of the elements of this document may be the subject of p
18、atent rights. ISO and IEC shall not be held responsible for identifying any or all such patent rights. ISO/IEC TR 16166 was prepared by Ecma International (as ECMA TR/100) and was adopted, under a special “fast-track procedure”, by Joint Technical Committee ISO/IEC JTC 1, Information technology, in
19、parallel with its approval by national bodies of ISO and IEC. ISO/IEC TR 16166:2010(E) vi ISO/IEC 2010 All rights reservedIntroduction This Technical Report is one of a series of Ecma publications that explore IP-based enterprise communication involving Corporate telecommunication Networks (CNs) (al
20、so known as enterprise networks) and in particular Next Generation Corporate Networks (NGCN). The series particularly focuses on inter-domain communication, including communication between parts of the same enterprise, between enterprises and between enterprises and carriers. This particular Technic
21、al Report discusses issues related to the security of session-based communications and builds upon concepts introduced in ISO/IEC TR 12860. This Technical Report is based upon the practical experience of Ecma member companies and the results of their active and continuous participation in the work o
22、f ISO/IEC JTC1, ITU-T, ETSI, IETF and other international and national standardization bodies. It represents a pragmatic and widely based consensus. In particular, Ecma acknowledges valuable input from experts in ETSI TISPAN. TECHNICAL REPORT ISO/IEC TR 16166:2010 (E) ISO/IEC 2010 All rights reserve
23、d 1Information technology Telecommunications and information exchange between systems Next Generation Corporate Networks (NGCN) Security of session-based communications 1 Scope This Technical Report is one of a series of publications that provides an overview of IP-based enterprise communication inv
24、olving Corporate telecommunication Networks (CNs) (also known as enterprise networks) and in particular Next Generation Corporate Networks (NGCN). The series particularly focuses on session level communication based on the Session Initiation Protocol (SIP) 4, with an emphasis on inter-domain communi
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ISOIECTR161662010INFORMATIONTECHNOLOGYTELECOMMUNICATIONSANDINFORMATIONEXCHANGEBETWEENSYSTEMSNEXTGENERATIONCORPORATENETWORKSNGCNSECURITPDF

链接地址:http://www.mydoc123.com/p-1257394.html