ETSI TS 103 161-9-2011 Access Terminals Transmission and Multiplexing (ATTM) Integrated Broadband Cable and Television Networks IPCablecom 1 5 Part 9 Security (V1 1 1)《接入 终端 传输和复用(.pdf
《ETSI TS 103 161-9-2011 Access Terminals Transmission and Multiplexing (ATTM) Integrated Broadband Cable and Television Networks IPCablecom 1 5 Part 9 Security (V1 1 1)《接入 终端 传输和复用(.pdf》由会员分享,可在线阅读,更多相关《ETSI TS 103 161-9-2011 Access Terminals Transmission and Multiplexing (ATTM) Integrated Broadband Cable and Television Networks IPCablecom 1 5 Part 9 Security (V1 1 1)《接入 终端 传输和复用(.pdf(162页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI TS 103 161-9 V1.1.1 (2011-10) Access, Terminals, Transmission and Multiplexing (ATTM); Integrated Broadband Cable and Television Networks; IPCablecom 1.5; Part 9: Security Technical Specification ETSI ETSI TS 103 161-9 V1.1.1 (2011-10)2Reference DTS/ATTM-003011-9 Keywords access, broadband, ca
2、ble, IP, multimedia, PSTN ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice Individual copies of
3、the present document can be downloaded from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
4、In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of t
5、his and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced except as au
6、thorized by written permission. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2011. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members.
7、3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TS 103 161-9 V1.1.1 (2011-10)3Contents Intellectual Property Rights 9g3Foreword . 9g31
8、 Scope and Introduction . 11g31.1 Scope 11g31.2 Goals 11g31.2.1 Assumptions . 11g31.2.2 Requirements 12g32 References 12g32.1 Normative references . 12g32.2 Informative references 14g33 Definitions and abbreviations . 14g33.1 Definitions 14g33.2 Abbreviations . 16g34 Void 18g35 Architectural Overvie
9、w of IPCablecom Security . 18g35.1 IPCablecom Reference Architecture 18g35.1.1 HFC Network 18g35.1.2 Call Management Server 19g35.1.3 Functional Categories . 19g35.1.3.1 Device and Service Provisioning 19g35.1.3.2 Dynamic Quality of Service 20g35.1.3.3 Billing System Interfaces 20g35.1.3.4 Call Sign
10、alling . 20g35.1.3.5 PSTN Interconnectivity . 20g35.1.3.6 CODEC Functionality and Media Stream Mapping . 20g35.1.3.7 Audio Server Services . 21g35.1.3.7.1 Media Player Controller (MPC) 21g35.1.3.7.2 Media Player (MP) 21g35.1.3.8 Lawful Interception . 21g35.2 Threats 21g35.2.1 Theft of Network Servic
11、es 23g35.2.1.1 MTA Clones 23g35.2.1.2 Other Clones . 23g35.2.1.3 Subscription Fraud 23g35.2.1.4 Non-Payment for Voice Communications Services 23g35.2.1.5 Protocol Attacks against an MTA . 23g35.2.1.6 Protocol Attacks against Other Network Elements . 24g35.2.1.7 Theft of Services Provided by the MTA
12、. 24g35.2.1.7.1 Attacks . 24g35.2.1.8 MTA Moved to Another Network 24g35.2.2 Bearer Channel Information Threats. 24g35.2.2.1 Attacks 24g35.2.2.1.1 Off-line Cryptanalysis . 24g35.2.3 Signalling Channel Information Threats . 24g35.2.3.1 Attacks 24g35.2.3.1.1 Caller ID 25g35.2.3.1.2 Information with Ma
13、rketing Value 25g35.2.4 Service Disruption Threats . 25g35.2.4.1 Attacks 25g35.2.4.1.1 Remote Interference 25g35.2.5 Repudiation . 25g35.2.6 Threat Summary . 26g35.2.6.1 Primary Threats. 26g3ETSI ETSI TS 103 161-9 V1.1.1 (2011-10)45.2.6.2 Secondary Threats. 27g35.3 Security Architecture 27g35.3.1 Ov
14、erview of Security Interfaces . 27g35.3.2 Security Assumptions . 30g35.3.2.1 BPI+ CMTS Downstream Messages Are Trusted. 30g35.3.2.2 Non-Repudiation Not Supported . 30g35.3.2.3 Root Private Key Compromise Protection 30g35.3.2.4 Limited Prevention of Denial-of-Service Attacks . 31g35.3.3 Susceptibilit
15、y of Network Elements to Attack 31g35.3.3.1 Managed IP Network 31g35.3.3.2 MTA 31g35.3.3.3 CMTS 32g35.3.3.4 Voice Communications Network Servers are Untrusted Network Elements 32g35.3.3.4.1 CMS 32g35.3.3.4.2 RKS . 33g35.3.3.4.3 OSS, DHCP and TFTP Servers . 33g35.3.3.5 PSTN Gateways 34g35.3.3.5.1 Med
16、ia Gateway 34g35.3.3.5.2 Signalling Gateway . 34g36 Security Mechanisms . 34g36.1 IPsec . 34g36.1.1 Overview 34g36.1.2 IPCablecom Profile for IPsec ESP (Transport Mode) 35g36.1.2.1 IPsec ESP Transform Identifiers . 35g36.1.2.2 IPsec ESP Authentication Algorithms 35g36.1.2.3 Replay Protection 36g36.1
17、.2.4 Key Management Requirements . 36g36.2 Internet Key Exchange (IKE) . 36g36.2.1 Overview 36g36.2.2 IPCablecom Profile for IKE 37g36.2.2.1 First IKE Phase . 37g36.2.2.1.1 IKE Authentication with Signatures 37g36.2.2.1.2 IKE Authentication with Public-Key Encryption 37g36.2.2.1.3 IKE Authentication
18、 with Pre-Shared Keys 37g36.2.2.2 Second IKE Phase . 37g36.2.2.3 Encryption Algorithms for IKE Exchanges 37g36.2.2.4 Diffie-Hellman Groups . 38g36.2.2.5 Security Association Renegotiation 38g36.3 SNMPv3 . 38g36.3.1 SNMPv3 Transform Identifiers 38g36.3.2 SNMPv3 Authentication Algorithms 38g36.4 Kerbe
19、ros / PKINIT . 39g36.4.1 Overview 39g36.4.1.1 Kerberos Ticket Storage 41g36.4.2 PKINIT Exchange 41g36.4.2.1 PKINIT Profile for IPCablecom . 43g36.4.2.1.1 PKINIT Request 43g36.4.2.1.2 PKINIT Reply . 45g36.4.2.1.3 Pre-Authenticator for Provisioning Server Location . 47g36.4.2.2 Profile for the Kerbero
20、s AS Request / AS Reply Messages 47g36.4.2.3 Profile for Kerberos Tickets 48g36.4.3 Symmetric Key AS Request / AS Reply Exchange 48g36.4.3.1 Profile for the Symmetric Key AS Request / AS Reply Exchanges 50g36.4.4 Kerberos TGS Request / TGS Reply Exchange 51g36.4.4.1 TGS Request Profile . 52g36.4.4.2
21、 TGS Reply Profile . 52g36.4.4.3 Error Reply 52g36.4.5 Kerberos Server Locations and Naming Conventions 53g36.4.5.1 Kerberos Realms . 53g36.4.5.2 KDC 53g36.4.5.3 CMS 54g3ETSI ETSI TS 103 161-9 V1.1.1 (2011-10)56.4.5.4 Provisioning Server . 54g36.4.5.5 Names of Other Kerberized Services 55g36.4.6 MTA
22、 Principal Names 56g36.4.7 Mapping of MTA MAC Address to MTA FQDN 56g36.4.7.1 MTA FQDN Request 56g36.4.7.2 MTA FQDN Reply . 58g36.4.7.3 MTA FQDN Error 59g36.4.8 Server Key Management Time Out Procedure . 60g36.4.9 Service Key Versioning 61g36.5 Kerberized Key Management . 61g36.5.1 Overview 61g36.5.
23、2 Kerberized Key Management Messages . 62g36.5.2.1 Rekey Messages 66g36.5.2.2 IPCablecom Profile for KRB_AP_REQ / KRB_AP_REP Messages . 69g36.5.2.3 Error Handling 69g36.5.2.3.1 Error Reply 69g36.5.2.3.2 Clock Skew Error 70g36.5.2.3.3 Handling Ticket Errors After a Wake Up 71g36.5.3 Kerberized IPsec
24、. 71g36.5.3.1 Derivation of IPsec Keys 72g36.5.3.2 Periodic Re-establishment of IPsec Security Associations . 72g36.5.3.2.1 Periodic Re-establishment of IPsec SAs at the Client . 72g36.5.3.2.2 Periodic Re-establishment of IPsec SAs at the Application Server . 73g36.5.3.3 Expiration of IPsec SAs 73g3
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSITS10316192011ACCESSTERMINALSTRANSMISSIONANDMULTIPLEXINGATTMINTEGRATEDBROADBANDCABLEANDTELEVISIONNETWORKSIPCABLECOM15PART9SECURITYV111

链接地址:http://www.mydoc123.com/p-739866.html