ETSI TR 102 420-2005 Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN) Review of activity on security (V1 1 1)《电信和互联网融合业务及高级网络协议(TIS_1.pdf
《ETSI TR 102 420-2005 Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN) Review of activity on security (V1 1 1)《电信和互联网融合业务及高级网络协议(TIS_1.pdf》由会员分享,可在线阅读,更多相关《ETSI TR 102 420-2005 Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN) Review of activity on security (V1 1 1)《电信和互联网融合业务及高级网络协议(TIS_1.pdf(144页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI TR 102 420 V1.1.1 (2005-05)Technical Report Telecommunications and Internet converged Services andProtocols for Advanced Networking (TISPAN);Review of activity on securityETSI ETSI TR 102 420 V1.1.1 (2005-05) 2 Reference DTR/TISPAN-07011-Tech Keywords management, report, security ETSI 650 Rout
2、e des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice Individual copies of the present document can be downloaded
3、from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF). In case of dispute, the reference shall
4、 be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is availab
5、le at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced except as authorized by written permission. The cop
6、yright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2005. All rights reserved. DECTTM, PLUGTESTSTM and UMTSTM are Trade Marks of ETSI registered for the benefit of its Members. TIPHONTMand the TIPHON logo are Trade Marks currently
7、 being registered by ETSI for the benefit of its Members. 3GPPTM is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. ETSI ETSI TR 102 420 V1.1.1 (2005-05) 3 Contents Intellectual Property Rights5 Foreword.5 1 Scope 6 2 References 6 3 Definitions
8、 and abbreviations.8 3.1 Definitions8 3.2 Abbreviations .8 4 Introduction 9 5 Review of other security domain specifications.9 5.1 ISO/IEC 17799.9 6 ENUM Case study9 6.1 Purpose.9 6.2 Overview of ENUM .9 6.3 Security and common criteria in ENUM11 6.3.1 Privacy concerns.11 6.3.2 Security concerns11 6
9、.3.2.1 DNS security mechanisms 12 6.3.3 Security critical ENUM operations.13 6.3.3.1 Registration of an E.164 number in the ENUM database .13 6.3.3.2 Processes for creation, modification and deletion of NAPTR Records in the Tier 2 database .14 6.3.3.3 Processes for removal of E.164 numbers from ENUM
10、 databases.15 6.3.3.4 Processes for changing Registrars.16 6.3.4 ENUM assets 16 6.3.4.1 NAPTR records.16 6.3.4.2 ENUM query.17 6.3.5 Composite security model 17 6.4 CORAS method application in ENUM analysis 18 6.4.1 Introduction.18 6.4.2 CORAS platform and UML profile 18 6.4.3 The risk management pr
11、ocess.21 6.4.4 The risk documentation framework 23 7 UML modelling24 7.1 Introduction 24 7.2 Core security model24 7.3 Development of stereotypes .26 7.4 Application of stereotypes29 Annex A: UML modelling of ISO/IEC 15408-2.30 A.1 Introduction 30 A.2 Structure of the UML model 33 A.3 UML model for
12、ISO/IEC 15408-2 .34 A.3.1 TSF Package Dependency34 A.3.2 Package TSF_FAU.35 A.3.3 Package TSF_FCO.45 A.3.4 Package TSF_FCS50 A.3.5 Package TSF_FIA 76 A.3.6 Package TSF_FMT.86 A.3.7 Package TSF_FPR96 A.3.8 Package TSF_FPT103 A.3.9 Package TSF_FRU.124 ETSI ETSI TR 102 420 V1.1.1 (2005-05) 4 A.3.10 Pac
13、kage TSF_FTA .130 A.3.11 Package TSF_FTP139 History 144 ETSI ETSI TR 102 420 V1.1.1 (2005-05) 5 Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly availab
14、le for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server
15、(http:/webapp.etsi.org/IPR/home.asp). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, o
16、r may become, essential to the present document. Foreword This Technical Report (TR) has been produced by ETSI Technical Committee Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN). ETSI ETSI TR 102 420 V1.1.1 (2005-05) 6 1 Scope The present document g
17、athers together and presents information regarding the progress of work in the development of guidelines on the use of the Common Criteria for the evaluation of IT security (ISO/IEC 15408 22). The purpose of the present document is to be a repository for information which is of interest but which ha
18、s no clear place in the core guidance documents, thus: notes on information studied in order to prepare the core guidance documents: - method for application of Common Criteria to ETSI deliverables, EG 202 387 1; - method and proforma for defining Protection Profiles, ES 202 382 2; - method and prof
19、orma for defining Security Targets, ES 202 383 3. notes on use of tools and tool development; and notes on the assistance given to TISPAN-WG4 on the ENUM privacy analysis. 2 References For the purposes of this Technical Report (TR), the following references apply: 1 ETSI EG 202 387: “Telecommunicati
20、ons and Internet converged Services and Protocols for Advanced Networking (TISPAN); Security Design Guide; Method for application of Common Criteria to ETSI deliverables“. 2 ETSI ES 202 382: “Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); Security
21、Design Guide; Method and proforma for defining Protection Profiles“. 3 ETSI ES 202 383: “Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); Security Design Guide; Method and proforma for defining Security Targets“. 4 IETF RFC 3761 (2004): “The E.164 to
22、 Uniform Resource Identifiers (URI) Dynamic Delegation Discovery System (DDDS) Application (ENUM)“. 5 ETSI TS 102 051: “ENUM administration in Europe“. 6 ETSI TS 102 172: “Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); Minimum requirements for inte
23、roperability of ENUM implementations“. 7 IETF RFC 2915: “The Naming Authority Pointer (NAPTR) DNS Resource Record“. 8 IETF STD 013: “Domain Names - Concepts And Facilities“. 9 IETF RFC 2535: “Domain Name System Security Extensions“. 10 ETSI TS 102 165-1: “Telecommunications and Internet Protocol Har
24、monization over Networks (TIPHON) Release 4; Protocol Framework Definition; Methods and Protocols for Security; Part 1: Threat Analysis“. 11 IETF RFC 1034 (1987): “Domain names - concepts and facilities“. 12 IETF RFC 1035 (1987): “Domain names - implementation and specification“. 13 Draft-ietf-dnsex
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSITR1024202005TELECOMMUNICATIONSANDINTERNETCONVERGEDSERVICESANDPROTOCOLSFORADVANCEDNETWORKINGTISPANREVIEWOFACTIVITYONSECURITYV111

链接地址:http://www.mydoc123.com/p-735909.html