ATIS 1000019-2007 Network to Network Interface (NNI) Standard for Signaling and Control Security for Evolving VoP Multimedia Networks.pdf
《ATIS 1000019-2007 Network to Network Interface (NNI) Standard for Signaling and Control Security for Evolving VoP Multimedia Networks.pdf》由会员分享,可在线阅读,更多相关《ATIS 1000019-2007 Network to Network Interface (NNI) Standard for Signaling and Control Security for Evolving VoP Multimedia Networks.pdf(27页珍藏版)》请在麦多课文档分享上搜索。
1、 AMERICAN NATIONAL STANDARD FOR TELECOMMUNICATIONS ATIS-1000019.2007(R2012) Network to Network Interface (NNI) Standard for Signaling and Control Security for Evolving VoP Multimedia Networks ATIS is the leading technical planning and standards development organization committed to the rapid develop
2、ment of global, market-driven standards for the information, entertainment and communications industry. More than 200 companies actively formulate standards in ATIS Committees and Forums, covering issues including: IPTV, Cloud Services, Energy Efficiency, IP-Based and Wireless Technologies, Quality
3、of Service, Billing and Operational Support, Emergency Services, Architectural Platforms and Emerging Networks. In addition, numerous Incubators, Focus and Exploratory Groups address evolving industry priorities including Smart Grid, Machine-to-Machine, Connected Vehicle, IP Downloadable Security, P
4、olicy Management and Network Optimization. ATIS is the North American Organizational Partner for the 3rd Generation Partnership Project (3GPP), a member and major U.S. contributor to the International Telecommunication Union (ITU) Radio and Telecommunications Sectors, and a member of the Inter-Ameri
5、can Telecommunication Commission (CITEL). ATIS is accredited by the American National Standards Institute (ANSI). For more information, please visit .AMERICAN NATIONAL STANDARD Approval of an American National Standard requires review by ANSI that the requirements for due process, consensus, and oth
6、er criteria for approval have been met by the standards developer. Consensus is established when, in the judgment of the ANSI Board of Standards Review, substantial agreement has been reached by directly and materially affected interests. Substantial agreement means much more than a simple majority,
7、 but not necessarily unanimity. Consensus requires that all views and objections be considered, and that a concerted effort be made towards their resolution. The use of American National Standards is completely voluntary; their existence does not in any respect preclude anyone, whether he has approv
8、ed the standards or not, from manufacturing, marketing, purchasing, or using products, processes, or procedures not conforming to the standards. The American National Standards Institute does not develop standards and will in no circumstances give an interpretation of any American National Standard.
9、 Moreover, no person shall have the right or authority to issue an interpretation of an American National Standard in the name of the American National Standards Institute. Requests for interpretations should be addressed to the secretariat or sponsor whose name appears on the title page of this sta
10、ndard. CAUTION NOTICE: This American National Standard may be revised or withdrawn at any time. The procedures of the American National Standards Institute require that action be taken periodically to reaffirm, revise, or withdraw this standard. Purchasers of American National Standards may receive
11、current information on all standards by calling or writing the American National Standards Institute. Notice of Disclaimer however, new security challenges are introduced. Threats in the end-user plane now become threats to the signaling and control plane since the signaling and control plane become
12、s more accessible to the multitude of end-users. Connections between carrier VoIP networks have been made via TDM or analogue mechanisms. Using TDM or analogue techniques isolates VoIP networks from each other and circumvents many interoperability issues, but it also adds unnecessary service limitat
13、ions, cost, and complexity. It also degrades VoIP quality, as multiple TDM to IP transcoding hops increase latency and can add distortion. These undesirable effects undermine service quality and the potential to deliver voice, video, and other real-time communication services over a cost-effective c
14、onverged infrastructure. To realize the full benefits of VoIP, networks must be able to be connected directly at the IP level without converting to TDM. To enable direct IP connection between carrier networks, stringent security mechanisms must be in place at the network to network interface to ensu
15、re the networks are not vulnerable to attack. These security mechanisms help allow desired IP telephony traffic to enter the network while blocking intruders and attacks in a controlled manner to protect internal network resources. To ensure a secure network to network interface, a concept that is u
16、seful is that of a Border Security Function (BSF). The BSF is a set of security functions to enables secure communication to occur across the network to network interface. The security functions included in the BSF may be distributed into various network elements such as Call Servers or Soft Switche
17、s, or the security functions may be included in stand alone network elements such as a Session Border Controller (SBC). Implementation topology recommendations for the BSF are beyond the scope of this document. Other non-security related functions may also included at the NNI such as signaling trans
18、lation and QoS policy enforcement; however, such non-security related functions are beyond the scope of this document. ATIS-1000019.2007 A diagram of two interconnected networks is given below in Figure 2. The BSF security functions may include, but are not limited to: Access control mechanisms to a
19、llow only desired peer networks to access a network across the NNI. Authentication mechanisms to ensure the identity of signaling plane peer entities communicating across the NNI, and data origin authentication of signaling messages being sent across the NNI. Non-repudiation services for signaling m
20、essages being sent across the NNI. Data confidentiality services for signaling plane information being sent across the NNI to ensure it cannot be viewed by unauthorized parties. Security of communication across the NNI interface. Data integrity services for signaling plane information being sent acr
21、oss the NNI to ensure that it cannot be modified by unauthorized parties. Security services to enhance availability; for example to protect networks from denial of service attacks at the NNI. Security services, to ensure privacy of sensitive data and internal network topologies. In Figure 2, an IP T
22、ransport Network is shown for completeness between different VoIP/Multimedia Networks. IP Transport Networks may or may not implement their own Border Security Function depending on particular IP Transport Network security policy. For simplicity, subsequent diagrams in this document do not show the
23、IP transport network. Figure 2 - Architectural Diagram of Interconnected VoIP/Multimedia Networks 2 SCOPE, PURPOSE, 2. Security Layers (Applications Security, Network Services Security and Infrastructure Security); and 3. Security Dimensions (Access Control, Authentication, Non-repudiation/Audit Log
24、ging, Data Confidentiality and Privacy, Data Integrity, Availability). This standard is related to the ITU-T Recommendation X.805 model in the following manner: 1. Security Planes Addressed: Signaling and Control Plane Only. 2. Security Layers Addressed: Applications Security only (H.323 and SIP). 3
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ATIS10000192007NETWORKTONETWORKINTERFACENNISTANDARDFORSIGNALINGANDCONTROLSECURITYFOREVOLVINGVOPMULTIMEDIANETWORKSPDF

链接地址:http://www.mydoc123.com/p-541431.html