ATIS 0100001-2004 User Plane Security Guidelines and Requirements.pdf
《ATIS 0100001-2004 User Plane Security Guidelines and Requirements.pdf》由会员分享,可在线阅读,更多相关《ATIS 0100001-2004 User Plane Security Guidelines and Requirements.pdf(13页珍藏版)》请在麦多课文档分享上搜索。
1、 AMERICAN NATIONAL STANDARD FOR TELECOMMUNICATIONS ATIS-0100001.2004(R2013) User Plane Security Guidelines and Requirements As a leading technology and solutions development organization, ATIS brings together the top global ICT companies to advance the industrys most-pressing business priorities. Th
2、rough ATIS committees and forums, nearly 200 companies address cloud services, device solutions, emergency services, M2M communications, cyber security, ehealth, network evolution, quality of service, billing support, operations, and more. These priorities follow a fast-track development lifecycle f
3、rom design and innovation through solutions that include standards, specifications, requirements, business use cases, software toolkits, and interoperability testing. ATIS is accredited by the American National Standards Institute (ANSI). ATIS is the North American Organizational Partner for the 3rd
4、 Generation Partnership Project (3GPP), a founding Partner of oneM2M, a member and major U.S. contributor to the International Telecommunication Union (ITU) Radio and Telecommunications sectors, and a member of the Inter-American Telecommunication Commission (CITEL). For more information, visit. AME
5、RICAN NATIONAL STANDARD Approval of an American National Standard requires review by ANSI that the requirements for due process, consensus, and other criteria for approval have been met by the standards developer. Consensus is established when, in the judgment of the ANSI Board of Standards Review,
6、substantial agreement has been reached by directly and materially affected interests. Substantial agreement means much more than a simple majority, but not necessarily unanimity. Consensus requires that all views and objections be considered, and that a concerted effort be made towards their resolut
7、ion. The use of American National Standards is completely voluntary; their existence does not in any respect preclude anyone, whether he has approved the standards or not, from manufacturing, marketing, purchasing, or using products, processes, or procedures not conforming to the standards. The Amer
8、ican National Standards Institute does not develop standards and will in no circumstances give an interpretation of any American National Standard. Moreover, no person shall have the right or authority to issue an interpretation of an American National Standard in the name of the American National S
9、tandards Institute. Requests for interpretations should be addressed to the secretariat or sponsor whose name appears on the title page of this standard. CAUTION NOTICE: This American National Standard may be revised or withdrawn at any time. The procedures of the American National Standards Institu
10、te require that action be taken periodically to reaffirm, revise, or withdraw this standard. Purchasers of American National Standards may receive current information on all standards by calling or writing the American National Standards Institute. Notice of Disclaimer changes cannot be prevented un
11、less the system is perfect (error-free) and no malicious user has access. However, a system that offers data integrity service might also attempt to correct and recover from changes. Relationship between data integrity service and authentication services: Although data integrity service is defined s
12、eparately from data origin authentication service and peer entity authentication service, it is closely related to them. Authentication services depend, by definition, on companion data integrity services. Data origin authentication service provides verification that the identity of the original sou
13、rce of a received data unit is as claimed; there can be no such verification if the data unit has been altered. Peer entity authentication service provides verification that the identity of a peer entity in a current association is as claimed; there can be no such verification if the claimed identit
14、y has been altered. 10 2ATIS-0100001.2004 3.1.8 Emergency Telecommunications Service: A telecommunications service offering available on public communications networks that facilitates the work of authorized emergency personnel in times of disaster, national emergency, or for executive/governmental
15、communications relating to National Security/Emergency Preparedness (NS/EP). 3.2 Acronyms & Abbreviations 3GPP 3rd Generation Partnership Project AES Advanced Encryption Standard ANSI American National Standards Institute ATIS Alliance for Telecommunications Industry Solutions EPA Environmental Prot
16、ection Agency ETS Emergency Telecommunications Service FEMA Federal Emergency Management Agency FIPS Federal Information Processing Standards GETS Government Emergency Telecommunications Service HAZMAT Hazardous Materials HMAC Keyed-Hash Message Authentication Code NS/EP National Security / Emergenc
17、y Preparedness PIN Personal Identification Number PLMN Public Land Mobile Network PSTN Public Switched Telephone Network SHA Secure Hash Algorithm SHS Secure Hash Standard WPS Wireless Priority Service 4 BASIC GUIDELINES FOR SECURITY AND CRYPTOGRAPHIC MECHANISMS AND THEIR IMPLEMENTATION 1. Wherever
18、possible, security protocols will be open source and standardized. 2. Where encryption is used, AES (in its current FIPS equivalent) will be utilized wherever it applies. 3. Where encryption is used for integrity, HMAC (SHA-1) will be used. 4. Simplicity, reliability, and wide-spread implementabilit
19、y will be valued over the inclusion of a plethora of options. 5. Security mechanisms for ETS communications (other than AES and HMAC-SHA1) will be reviewed by qualified security/cryptographic experts before selection. The selected mechanisms (beyond those already provided in the public network) shou
20、ld be implemented by qualified security/cryptographic experts. It should be noted that certain FIPS Standards will be required in applications contracted by the U.S. Government (e.g., AES, HMAC-SHA). 3ATIS-0100001.2004 5 SECURITY LEVELS FOR ETS COMMUNICATIONS In developing security guidelines for ET
21、S, it is useful to ascertain the level of security that is needed for a particular ETS communication. It is recognized that different users of this service will require differing levels of security. While authentication is needed in all cases, some cases may not need data confidentiality. In Annex A
22、, 5 levels (1 is highest) of emergency users/priorities are listed in Table A.1. Annex A also offers descriptive scenarios to further clarify the distinctions between the different levels. These levels are supported in the Wireless Priority Service2. It is expected that the number of priority levels
23、 might be different for other networks (e.g., the Internet). Because they are already part of an existing ETS, the 5 levels defined in Annex A are used to delineate the different levels of security needed for an ETS communication. Even though some network types (e.g., the Internet) may only offer on
24、e priority level for ETS communications, the network may provide different security mechanisms to different classes of users. From a user-plane perspective, security will be end-to-end. 6 SECURITY REQUIREMENTS FOR ETS COMMUNICATIONS 6.1 Authentication Requirements ETS users must be able to be authen
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ATIS01000012004USERPLANESECURITYGUIDELINESANDREQUIREMENTSPDF

链接地址:http://www.mydoc123.com/p-540837.html