ETSI TR 118 508-2014 Analysis of Security Solutions for the oneM2M System (V1 0 0)《oneM2M系统安全解决方案分析 (V1 0 0)》.pdf
《ETSI TR 118 508-2014 Analysis of Security Solutions for the oneM2M System (V1 0 0)《oneM2M系统安全解决方案分析 (V1 0 0)》.pdf》由会员分享,可在线阅读,更多相关《ETSI TR 118 508-2014 Analysis of Security Solutions for the oneM2M System (V1 0 0)《oneM2M系统安全解决方案分析 (V1 0 0)》.pdf(44页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI TR 118 508 V1.0.0 (2014-07) Analysis of Security Solutions for the oneM2M System Technical Report ETSI ETSI TR 118 508 V1.0.0 (2014-07) 2Reference DTR/oneM2M-000008 Keywords Countermeasures, M2M, Security, Threat Analysis, Vulnerabilities ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Ce
2、dex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org The present document may be made avail
3、able in electronic versions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only
4、prevailing document is the print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other
5、 ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced or utilized in any form o
6、r by any means, electronic or mechanical, including photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all
7、 media. European Telecommunications Standards Institute 2014. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organiza
8、tional Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TR 118 508 V1.0.0 (2014-07) 3Contents Intellectual Property Rights 5g3Foreword . 5g31 Scope 6g32 References 6g32.1 Normative references . 6g32.2 Informative references 6g33 Definitions and ab
9、breviations . 7g33.1 Definitions 7g33.2 Abbreviations . 7g34 Conventions 8g35 Overview 9g35.1 oneM2M Security Context and Domains . 9g35.2 Applications . 9g35.3 Common Services. 9g35.4 Underlying Network . 10g36 Generic Security Mechanisms 10g36.1 Secure Storage 10g36.2 Sensitive Functions. 11g36.3
10、Secure Connection 11g37 Security Vulnerabilities and Threats 11g37.1 Introduction 11g37.2 Discovery of Long-Term Service-Layer Keys Stored in M2M Devices or M2M Gateways . 12g37.3 Deletion of Long-Term Service-Layer Keys stored in M2M Devices or M2M Gateways 12g37.4 Replacement of Long-Term Service-
11、Layer Keys stored in M2M Devices or M2M Gateways . 13g37.5 Discovery of Long-Term Service-Layer Keys stored in M2M Infrastructure 13g37.6 Deletion of Long-Term Service-Layer Keys stored in M2M Infrastructure equipment . 14g37.7 Discovery of sensitive Data in M2M Devices or M2M Gateways . 14g37.8 Gen
12、eral Eavesdropping on M2M Service-Layer Messaging between Entities 15g37.9 Alteration of M2M Service-Layer Messaging between Entities 15g37.10 Replay of M2M Service-Layer Messaging between Entities . 16g37.11 Unauthorized or corrupted Applications or Software in M2M Devices/Gateways 16g37.12 M2M Sys
13、tem Interdependencies Threats and cascading Impacts 17g37.13 M2M Security Context Awareness 17g37.14 Eaves Dropping/Man in the Middle Attack 18g37.15 Transfer of keys via independent security element 18g37.16 Buffer Overflow . 19g37.17 Injection 19g37.18 Session Management and Broken Authentication
14、19g37.19 Security Misconfiguration 20g37.20 Insecure Cryptographic Storage . 20g37.21 Invalid Input Data . 21g37.22 Cross Scripting . 21g38 Countermeasures 21g38.1 Introduction 21g38.2 Countermeasures 22g38.2.1 Tamper resistant Storage of long-term Service-Layer Keys within M2M Devices/Gateways . 22
15、g38.2.2 Secure Storage of long-term Service-Layer Keys within M2M Infrastructure Equipment. 22g38.2.3 Non-access to Service-Layer Keys stored within HSM/server-HSM . 22g38.2.4 Secure Execution of sensitive Functions in M2M Devices/M2M Gateways 23g38.2.5 Physical/logical Binding of HSM to M2M Device/
16、Gateway 23g38.2.6 Strong Authentication for Access to long-term Service-Layer Keys 23g3ETSI ETSI TR 118 508 V1.0.0 (2014-07) 48.2.7 Use of Security Associations, mutual Authentication and Confidentiality . 24g38.2.8 Proven Resistance to Man-in-the-Middle Attacks 24g38.2.9 Limited Life Session Keys b
17、ound to Service Layer 24g38.2.10 Replay Protection 25g38.2.11 Keys can be derived from M2M Service-layer keys . 25g38.2.12 Integrity Verification 25g38.2.13 Policy based Actions . 26g38.2.14 Shared Asset Inventory . 26g38.2.15 Sensitivity Assessment . 26g38.2.16 Risk Assessment . 26g38.2.17 Context
18、Inventory and Assessment on Sensitivity 27g38.2.18 Risk Assessment . 27g38.2.19 Secure Communication Link 27g38.2.20 Secure Coding Practices . 27g38.2.21 Prevent Injection of un-trusted Data . 27g38.2.22 Security Controls 28g38.2.23 Clean Application Architecture 28g38.2.24 Standard Algorithms . 28g
19、38.2.25 Protection of Storage by Privileges . 28g38.2.26 Whitelist 28g39 Security Requirements . 29g39.1 Authentication requirements 29g39.1.1 Levels of Assurance for Authentication 29g39.2 Authorization requirements 29g39.3 Privacy related requirements 30g39.4 RBAC Token Based Feature Requirements
20、. 30g310 Authorization and Access Control . 30g310.1 Authorization 30g310.1.1 Solutions for token based authorization 30g310.1.1.1 Solution 1: OAuth . 30g310.1.1.1.1 Status of Specification . 30g310.1.1.1.2 Usage Scenario 31g310.2 Access Control Management 32g310.2.1 Role Based Access Control (RBAC)
21、 33g310.2.1.1 RBAC Overview . 33g310.2.1.2 Benefits of RBAC . 34g310.2.1.3 Limitations of RBAC 34g310.2.2 Attribute Based Access Control (ABAC) . 35g310.2.2.1 ABAC Overview. 35g310.2.2.2 Benefits of ABAC . 36g310.2.2.3 Limitations of ABAC 36g311 GBA (Generic Bootstrapping Architecture) framework 37g
22、311.1 GBA overview 37g312 Suitable Security and Privacy Procedures and Processes . 38g312.1 Trust Enabling Architecture . 39g312.2 Enroling M2M Nodes and M2M applications for oneM2M services . 39g312.3 M2M initial provisioning Procedures . 40g312.3.1 M2M Node Enrolment and Service Provisioning . 40g
23、312.3.2 M2M Application enrolment 40g312.4 M2M operational security procedures 41g312.4.1 Identification of CSE and AE . 41g312.4.2 Authentication of CSE and AE . 41g312.4.3 M2M Security Association Establishment 41g312.4.4 M2M Authorization procedure . 42g3Annex A: Bibliography 43g3History 44g3ETSI
24、 ETSI TR 118 508 V1.0.0 (2014-07) 5Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ETSI
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSITR1185082014ANALYSISOFSECURITYSOLUTIONSFORTHEONEM2MSYSTEMV100ONEM2M 系统安全 解决方案 分析 V100PDF

链接地址:http://www.mydoc123.com/p-736522.html