Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); Feasibility Study of Security of NGN Interconnection at the NNI for Release 3; Interconnection security

DTR/TISPAN-07043-NGN-R3

General Information

Status
Published
Publication Date
14-Feb-2011
Technical Committee
Current Stage
12 - Completion
Due Date
14-Feb-2011
Completion Date
15-Feb-2011
Ref Project
Standard
tr_187019v030101p - Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); Feasibility Study of Security of NGN Interconnection at the NNI for Release 3; Interconnection security
English language
13 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)


Technical Report
Telecommunications and Internet converged Services and
Protocols for Advanced Networking (TISPAN);
Feasibility Study of Security of NGN
Interconnection at the NNI for Release 3;
Interconnection security
2 ETSI TR 187 019 V3.1.1 (2011-02)

Reference
DTR/TISPAN-07043-NGN-R3
Keywords
interworking, IP, NNI, security
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88

Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
http://portal.etsi.org/tb/status/status.asp
If you find errors in the present document, please send your comment to one of the following services:
http://portal.etsi.org/chaircor/ETSI_support.asp
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.

© European Telecommunications Standards Institute 2011.
All rights reserved.
TM TM TM TM
DECT , PLUGTESTS , UMTS , TIPHON , the TIPHON logo and the ETSI logo are Trade Marks of ETSI registered
for the benefit of its Members.
TM
3GPP is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners.
LTE™ is a Trade Mark of ETSI currently being registered
for the benefit of its Members and of the 3GPP Organizational Partners.
GSM® and the GSM logo are Trade Marks registered and owned by the GSM Association.
ETSI
3 ETSI TR 187 019 V3.1.1 (2011-02)
Contents
Intellectual Property Rights . 4
Foreword . 4
1 Scope . 5
2 References . 5
2.1 Normative references . 5
2.2 Informative references . 5
3 Abbreviations . 6
4 Main interconnection use cases . 7
4.1 TISPAN Interconnection scenarios . 7
4.2 Main NNI scenarios relevant for security consideration . 7
4.2.1 Direct SoIx . 7
5 NGN Reference points and current security mechanisms . 8
History . 13

ETSI
4 ETSI TR 187 019 V3.1.1 (2011-02)
Intellectual Property Rights
IPRs essential or potentially essential to the present document may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in
respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web
server (http://webapp.etsi.org/IPR/home.asp).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web
server) which are, or may be, or may become, essential to the present document.
Foreword
This Technical Report (TR) has been produced by ETSI Technical Committee Telecommunications and Internet
converged Services and Protocols for Advanced Networking (TISPAN).
ETSI
5 ETSI TR 187 019 V3.1.1 (2011-02)
1 Scope
The present document addresses issues related to interoperator NNI interface interconnection. Security issues on NNI
interconnections between the different subsystems of the NGN will also be addressed. The present document will
identify the impact on 3GPP and TISPAN specifications.
2 References
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
reference document (including any amendments) applies.
Referenced documents which are not found to be publicly available in the expected location might be found at
http://docbox.etsi.org/Reference.
NOTE: While any hyperlinks included in this clause were valid at the time of publication ETSI cannot guarantee
their long term validity.
2.1 Normative references
The following referenced documents are necessary for the application of the present document.
Not applicable.
2.2 Informative references
The following referenced documents are not necessary for the application of the present document but they assist the
user with regard to a particular subject area.
[i.1] ETSI TS 187 001: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); NGN SECurity (SEC); Requirements".
[i.2] ETSI TS 187 003: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); NGN Security; Security Architecture".
[i.3] ETSI TS 187 005: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); NGN Release 2 Lawful Interception; Stage 1 and Stage 2
definition".
[i.4] ETSI TR 187 009: "Telecommunications and Internet Converged Services and Protocols for
Advanced Networking (TISPAN); Feasibility study of prevention of unsolicited communication in
the NGN".
[i.5] ETSI TS 133 210: "Digital cellular telecommunications system (Phase 2+); Universal Mobile
Telecommunications System (UMTS); LTE; 3G security; Network Domain Security (NDS); IP
network layer security (3GPP TS 33.210)".
[i.6] ETSI ES 282 001: "Telecommunications and Internet Converged Services and Protocols for
Advanced Networking (TISPAN); NGN Functional Architecture".
[i.7] ETSI TS 181 005: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); Service and Capability Requirements".
[i.8] ETSI TR 184 008: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); Infrastructure ENUM Options for a TISPAN IPX".
[i.9] IETF RFC 2246 (1999): "Transport Layer Security version 1.0".
ETSI
6 ETSI TR 187 019 V3.1.1 (2011-02)
[i.10] ETSI TS 133 203: "Digital cellular telecommunications system (Phase 2+); Universal Mobile
Telecommunications System (UMTS); LTE; 3G security; Access security for IP-based services
(3GPP TS 33.203)".".
[i.11] ETSI TS 133 310: "Universal Mobile Telecommunications System (UMTS); LTE; Network
Domain Security (NDS); Authentication Framework (AF) (3GPP TS 33.310)".".
[i.12] ETSI TS 124 229: "Digital cellular telecommunications system (Phase 2+); Universal Mobile
Telecommunications System (UMTS); LTE; IP multimedia call control protocol based on Session
Initiation Protocol (SIP) and Session Description Protocol (SDP); Stage 3 (3GPP TS 24.229)".
[i.13] ETSI TR 187 008: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); NAT traversal feasibility study report".
[i.14] ETSI TR 187 007: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); Feasibility study on Media Security in TISPAN NGN".
[i.15] ETSI TS 133 328: "Universal Mobile Telecommunications System (UMTS); LTE; IP Multimedia
Subsystem (IMS) media plane security (3GPP TS 33.328)".".
[i.16] ETSI TR 187 015: "Telecommunications and Internet converged Services and Protocols for
Advanced Networking (TISPAN); Specifications for PUC (Prevention of Unsolicited
Communication) in the NGN".
[i.17] ETSI TS 133 220: "Digital cellular telecommunications system (Phase 2+); Universal Mobile
Telecommunications System (UMTS); LTE; Generic Authentication Architecture (GAA); Generic
Bootstrapping Architecture (GBA) (3GPP TS 33.220)".
[i.18] IETF RFC 3261: "SIP: Session Initiation Protocol".
3 Abbreviations
For the purposes of the present document, the following abbreviations apply:
3G 3rd Generation
3GPP 3rd Generation Partnership Project
AS Application Server
CoIx Connectivity oriented Interconnection
CSCF Call Session Control Function
DoS Denial-of-Service
I-BGF Interconnect Border Gateway Function
ID IDentity
IKE Internet Key Exchange
IMS IP Multimedia Subsystem
IP Internet Protocol
IPSEC Internet Protocol Security
IT Information Technology
IWF Inter-Working Function
NAF operator controlled Network Application Function
NAPT Network Address and Port Translations
NASS Network Access SubSystem
NAT Network Address Translation
NDS Network Domain Security
NGN Next Generation Network
NNI Network to Network Interface
PES PSTN/ISDN Emulation Subsystem
RACS Resource Admission Control Subsystem
SBC Session Border Controller
SEGF SEcurity Gateway Functions
SIP Session Initiation Protocol
SoIx Service oriented Interconnection
THIG Topology-Hiding Inter-network Gateway
ETSI
7 ETSI TR 187 019 V3.1.1 (2011-02)
TISPAN Telecommunication and Internet converged Services and Protocols for Advanced Networking
TLS Transport Layer Security
TS Technical Specification
UMTS Universal Mobile Telecommunication System
UNI User to Network Interface
4 Main interconnection use cases
This clause contains the main interconnection use cases to take into consideration for the security analysis of the present
document. The scope of the clause is to list the already defined interconnection scenarios, without defining new ones.
4.1 TISPAN Interconnection scenarios
The ES 282 001 NGN Functional Architecture [i.6] describes all the NGN interconnection scenarios relevant for the
TISPAN context. The NNI interconnection scenarios have been divided taking into account the layer involved.
Currently the following categories have been defined:
• Interconnection at the transport layer:
- Interconnection at NASS level;
- Interconnection ad RACS level;
- NGN Interconnection could also occur with other PSTN/ISDN networks (non IP networks). This kind of
interconnection can be considered as an inter-working scenario between NGN with legacy networks and
as such already covered by other specifications.
• Interconnection at the Service layer (PES, IPTV and IMS are the current service layer subsystems).
Moreover, all kind of NGN interconnections can be recognized as one of the following types:
• Service Oriented Interconnection (SoIx), characterized by the presence of the service-related signalling
(mandatory) in order to enable the end-to-end service awareness; and
• Connection oriented Interconnection (CoIx) that characterized by the absence of the service-related signalling.
This implies that there is no service awareness in CoIx Interconnection.
Finally Both SoIx and CoIx can also be "direct interconnection", which refers to the interconnection between two
network domains without any intermediate network domain, or "indirect interconnection", where interconnection
between two network domains is achieved by means of one or more intermediate network domain(s) acting as transit
networks. The intermediate network domain(s) provide(s) transit functionality to the two other network domains.
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.

Loading comments...