ATIS 1000054-2013 ATIS Technical Report on Next Generation Network Certificate Management.pdf
《ATIS 1000054-2013 ATIS Technical Report on Next Generation Network Certificate Management.pdf》由会员分享,可在线阅读,更多相关《ATIS 1000054-2013 ATIS Technical Report on Next Generation Network Certificate Management.pdf(23页珍藏版)》请在麦多课文档分享上搜索。
1、 TECHNICAL REPORT ATIS-1000054 ATIS TECHNICAL REPORT ON NEXT GENERATION NETWORK CERTIFICATE MANAGEMENT As a leading technology and solutions development organization, ATIS brings together the top global ICT companies to advance the industrys most-pressing business priorities. Through ATIS committees
2、 and forums, nearly 200 companies address cloud services, device solutions, emergency services, M2M communications, cyber security, ehealth, network evolution, quality of service, billing support, operations, and more. These priorities follow a fast-track development lifecycle from design and innova
3、tion through solutions that include standards, specifications, requirements, business use cases, software toolkits, and interoperability testing. ATIS is accredited by the American National Standards Institute (ANSI). ATIS is the North American Organizational Partner for the 3rd Generation Partnersh
4、ip Project (3GPP), a founding Partner of oneM2M, a member and major U.S. contributor to the International Telecommunication Union (ITU) Radio and Telecommunications sectors, and a member of the Inter-American Telecommunication Commission (CITEL). For more information, visit . Notice of Disclaimer or
5、 a web form that is only accessible through some authentication method that limits access to only authorized certificate requestors. The CA verifies the signature on the CSR and builds an X.509 certificate from the information provided. See Section 7.3 for the basic structure of NGN provider certifi
6、cates. The CA then returns the certificate to the requesting System Administrator. The request may occur through an HTTP request or it may be downloaded later by the system administrator, or it may be provided by email. The System Administrator will install the device certificate and the root certif
7、icate of the CA. 7.1.2 End User however, other mechanisms are possible based on the NGN providers security policy. For these certificates, a CSR is generated with the end user information, and the private key and the resulting certificate is sent to the end user device, over a secured channel that s
8、hould have been authenticated by some other method. Alternatively, memory devices such as an UICC (Universal Integrated Circuit Card) may be used to issue end-user certificates. 7.2 Certificate Verification All Network Elements should verify the complete certificate chain of all received certificate
9、s up to a known Certification Authority. If any step in this chain fails, then the Certificate is considered invalid and is rejected. The Network Element should reject the certificate if it has expired. 7.3 Certificate Contents for NGN Infrastructure This section describes example certificate profil
10、es for NGN infrastructure using X.509 version 3 Certificates . All certificates should indicate the following: Version: 3 Signature Algorithm: should be one of the following: o sha256withRSAEncription ( 1 2 840 113549 1 1 11 ) o sha256withRSA-PSS ( 1 2 840 113549 1 1 10 ) ATIS-1000054 5 o sha1withRS
11、A ( 1 2 840 113549 1 1 5 ) o sha1withECDSA ( 1 2 840 10045 4 1 ) Public Key Algorithm: should be one of the following and match the Signature Algorithm: o rsaEncryption ( 1 2 840 113549 1 1 1 ) o ECC ( 1 2 840 10045 2 1 ) Key Size: o A minimum of 2048 bits for the RSA Modulus o A minimum of 224 bits
12、 for the EC generator. IssuerName: Subject name will contain: C= O=Certificate Contents for NGN Provider CA Certificate This certificate corresponds to the top level Certification Authority for the NGN provider infrastructure. This certificate will be signed by the NGN provider CA. This can be viewe
13、d as self signed certificate. The following certificates elements are marked with one or more of the following notations: c: critical; m: mandatory; n: non-critical. An example format of the NGN provider CA Certificate is as follows: Issuer Name Subject Name: o C= o O= o CN= Modulus length: 2048 Ext
14、ensions keyUsagec,m(keyCertSign, cRLSign) subjectKeyIdentifiern,m authorityKeyIdentifiern,m(keyIdentifier=) basicConstraintsc,m(cA=true, pathLenConstraint=1). ATIS-1000054 6 7.3.1 Certificate Contents for NGN Network Elements This certificate is signed by the NGN provider CA and follows the requirem
15、ents outlined in section 7.3. This certificate is used to authenticate elements of the NGN infrastructure and for Session Key generation. The validity period of this certificate is determined by the NGN provider on the basis of its policies and the issuing CAs policies. An example format of the cert
16、ificate is as follows: Issuer Name Subject Name: C= O= OU= CN= Issuer Name In the above Subject Name, when using Domain Name System (DNS), the value of has to be the DNS Fully Qualified Domain Name (FQDN). The client establishing the secure connection, when using DNS, should make a DNS query to obta
17、in the IP address of the server. The client has to verify that the CN=, in the server certificate, matches the name used to query the DNS server. The server establishing the secure connection, when using DNS, has to verify that the client IP address of the client matches one of the DNS entries assoc
18、iated with the CN, in the client certificate. Modulus length: 2048 Extensions authorityKeyIdentifiern,m(keyIdentifier=) subjectAltNamen,m(dNSName=) The subjectAltName extension should be included for all servers that are capable of generating event messages. This will be the name used on the OAMklnm
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ATIS10000542013ATISTECHNICALREPORTONNEXTGENERATIONNETWORKCERTIFICATEMANAGEMENTPDF

链接地址:http://www.mydoc123.com/p-541464.html