ETSI GS INS 002-2010 Identity and Access Management for Networks and Services Distributed Access Control for Telecommunications Use Cases and Requirements (V1 1 1)《通信使用案例和要求的网络和服务分_1.pdf
《ETSI GS INS 002-2010 Identity and Access Management for Networks and Services Distributed Access Control for Telecommunications Use Cases and Requirements (V1 1 1)《通信使用案例和要求的网络和服务分_1.pdf》由会员分享,可在线阅读,更多相关《ETSI GS INS 002-2010 Identity and Access Management for Networks and Services Distributed Access Control for Telecommunications Use Cases and Requirements (V1 1 1)《通信使用案例和要求的网络和服务分_1.pdf(34页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI GS INS 002 V1.1.1 (2010-09)Group Specification Identity and Access Management for Networks and ServicesDistributed Access Control for TelecommunicationsUse Cases and RequirementsETSI ETSI GS INS 002 V1.1.1 (2010-09) 2Reference DGS/INS-002 Keywords access, control, ID, management, network, serv
2、ice ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice Individual copies of the present document c
3、an be downloaded from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF). In case of dispute, th
4、e reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI doc
5、uments is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced except as authorized by written pe
6、rmission. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2010. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTM, TIPHONTM, the TIPHON logo and the ETSI logo are Trade Marks of ETSI registered for the benefit of its Mem
7、bers. 3GPPTM is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. LTE is a Trade Mark of ETSI currently being registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and o
8、wned by the GSM Association. ETSI ETSI GS INS 002 V1.1.1 (2010-09) 3Contents Intellectual Property Rights 5g3Foreword . 5g3Introduction 5g31 Scope 6g32 References 6g32.1 Normative references . 6g32.2 Informative references 6g33 Abbreviations . 7g34 Current Landscape 8g34.1 General Access Control Fra
9、meworks . 8g34.1.1 IETF Geopriv Working Group Policies Frameworks . 8g34.1.2 eXtensible Access Control Markup Language 9g34.1.3 Enterprise Privacy Authorization Language (EPAL) 10g34.2 Access Control in Telecommunications . 11g34.2.1 3GPP Policy Control and Charging (PCC) . 11g34.2.1.1 Application F
10、unction (AF) 12g34.2.1.2 Subscription Profile Repository (SPR) 12g34.2.1.3 Policy Control and Charging Rule Function (PCRF) 12g34.2.1.4 Policy and Charging Enforcement Function (PCEF) 12g34.2.2 ETSI TISPAN Resource and Admission Control Sub-systems (RACS) 13g34.2.2.1 Application Function (AF) 14g34.
11、2.2.2 Service Policy Decision Function (SPDF) 14g34.2.2.3 Generic Resource and Admission Control Function (x-RACF) 14g34.2.2.4 Border Gateway Function (BGF) 14g34.2.2.5 Resource Control Enforcement Function (RCEF) 14g34.2.3 ITU-T Resource and Admission Control Functions (RACF) . 15g34.2.3.1 Service
12、Control Function (SCF) 15g34.2.3.2 Policy Decision Function Entity (PD-FE) . 15g34.2.3.3 Network Attachment Control Functions (NACF) . 15g34.2.3.4 Transport Resource Control Functional Entity (TRC-FE) 15g34.2.3.5 Policy Enforcement Functional Entity (PE-FE) 16g35 Use Cases . 16g35.1 UC1: Software as
13、 a Service 16g35.1.1 Description 16g35.1.2 Actors 16g35.1.2.1 Actors specific Issues 17g35.1.2.2 Actors specific benefits . 17g35.1.3 Pre-Conditions 17g35.1.4 Post-Condition 18g35.1.5 Normal Flow . 18g35.2 UC2: Enterprise Environment 19g35.2.1 Description 19g35.2.2 Actors 19g35.2.2.1 Actors specific
14、 Issues 19g35.2.2.2 Actors specific Benefits 19g35.2.3 Pre-Conditions 20g35.2.4 Post-Conditions. 20g35.2.5 Normal Flow . 20g35.3 UC3: Roaming Network Access 21g35.3.1 Description 21g35.3.2 Actors 21g35.3.2.1 Actors Specific Issues . 21g35.3.2.2 Actor Specific Benefits . 22g3ETSI ETSI GS INS 002 V1.1
15、.1 (2010-09) 45.3.3 Pre-conditions . 22g35.3.4 Post-conditions . 22g35.3.5 Example Flow . 23g35.4 Summary Table of Use Cases. 23g36 Requirements 24g36.1 General Access Control Framework Requirements . 24g36.1.1 Policy Management 24g36.1.2 Decision 25g36.1.3 Enforcement 26g36.2 Distributed Access Con
16、trol Requirements . 26g36.2.1 Policy Management 27g36.2.2 Decision 27g36.2.3 Enforcement 27g36.3 Telecommunications Requirements . 28g36.4 Access Control and Identity Management Requirements. 29g36.5 Summary Table of Requirements and Map to Use Cases 30g37 Conclusion 32g3Annex A (informative): Bibli
17、ography . 33g3History 34g3ETSI ETSI GS INS 002 V1.1.1 (2010-09) 5Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-mem
18、bers, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server (http:/webapp.etsi.org/IPR/home
19、.asp). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the
20、present document. Foreword This Group Specification (GS) has been produced by ETSI Industry Specification (ISG) Identity and access management for Networks and Services (INS). Introduction Service and network providers need to restrict access to their functions in order to efficiently charge, protec
21、t critical systems and offer personalization. While historically this has been the case for many years, a new type of access control surrounding the user and its data becomes paramount in this day and age. Users are targeted by many different services, not all of them friendly, and require mechanism
22、s to protect their data and information. In addition, the more social services are available, the more information about them is available and the harder it is to ensure that users sensitive data would not be easily subject to theft and misuse. In the present document we analyse not only the require
23、ments for access control related to identity management but also bring this question one step further in considering that providers need to cooperate in order to enforce all the policies related to that users data. This cooperation can be achieved either by exchanging data about the user or the cont
24、ext of the request, sharing policies or, in the case we will evaluate in this document, sharing the decision. In the first part of the present document a summary of some of the activities around access control languages and mechanisms can be found. The second part of the document presents those use
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSIGSINS0022010IDENTITYANDACCESSMANAGEMENTFORNETWORKSANDSERVICESDISTRIBUTEDACCESSCONTROLFORTELECOMMUNICATIONSUSECASESANDREQUIREMENTSV111

链接地址:http://www.mydoc123.com/p-733255.html