SIST ETS 300 920 E2:2003
(Main)Digital cellular telecommunications system (Phase 2+) (GSM); Security aspects (GSM 02.09 version 5.1.1)
General Information
- Abstract
Bearer and Teleservices, as respectively defined in GSM 02.02 and GSM 02.03, are the objects which the GSM PLMN operators offer to their cus tomers. Besides these basic telecommunications services, features whic h aim at up grading these basic services need also to be offered. Due to the use of radiocommunications in a PLMN, which are of a special na ture compared to classical distribution transmission techniques used i n the fixed networks, such a category of features is related to securi ty aspects. In a GSM PLMN, both the users and the network operator have to be prot ected against undesirable intrusion of third parties. However, measure s should be provided for in order to insure maximum protection of the rights of the individuals concerns. As a consequence, a security featu re is either a supplementary service to Tele or Bearer services, which can be selected by the subscriber, or a network function involved in the provision of one or several telecommunication services. The purpose of this European Telecommunication Standard (ETS) is to de fine the security features which are to be available in a GSM PLMN, to gether with the associated levels of protection. This ETS is only conc erned with those security features which aim at the up grading of the security in a GSM PLMN. In particular, end to end security is outside the scope of this ETS. The implementation aspects of security features are described in GSM 0 3.20.
- Status
- Published
- Publication Date
- 30-Nov-2003
- Current Stage
- 6060 - National Implementation/Publication (Adopted Project)
- Start Date
- 01-Dec-2003
- Due Date
- 01-Dec-2003
- Completion Date
- 01-Dec-2003
Overview
SIST ETS 300 920 E2:2003 defines the security aspects for digital cellular telecommunications systems (GSM Phase 2+), as specified in GSM 02.09 version 5.1.1. Developed by the Slovenski inštitut za standardizacijo (SIST) and aligned with ETSI standards, this document outlines the fundamental security features to protect both network operators and users within GSM Public Land Mobile Networks (PLMN). Its scope extends specifically to features that upgrade the security of bearer and teleservices, as defined in related GSM standards, while excluding end-to-end security considerations.
Key Topics
Security Features in GSM PLMN
This standard establishes five essential security features, which must be supported by both mobile equipment and network infrastructure:
Subscriber Identity Confidentiality
Ensures the subscriber's identity (IMSI) is not disclosed or available to unauthorized parties.Subscriber Identity Authentication
Verifies the authenticity of the subscriber accessing the network, protecting against impersonation and fraud.User Data Confidentiality on Physical Connections
Protects user data on traffic channels (voice and non-voice) by ensuring its privacy through encryption mechanisms.Connectionless User Data Confidentiality
Safeguards user data sent via signalling channels (for example, short messages) from unauthorized access.Signalling Information Element Confidentiality
Secures sensitive signalling information exchanged between mobile stations and base stations during and after connection setup.
Protection Mechanisms
- Utilizes temporary identities and authentication procedures to enhance privacy and security.
- Provides encryption options for both fixed and roaming subscribers, adapting to operator agreements.
- Enforces physical and logical protection of key mobile equipment identifiers, such as IMSI and IMEI.
Applications
Implementing the security requirements of SIST ETS 300 920 E2:2003 is vital for:
Mobile Network Operators:
- Reducing risk of unauthorized access or misuse of network resources.
- Fulfilling regulatory and industry security obligations.
- Enhancing trust and reliability of offered bearer and teleservices.
Mobile Device Manufacturers:
- Ensuring devices support mandatory GSM security features.
- Maintaining compliance with international standards for equipment sold in regulated markets.
Subscribers and End Users:
- Improving privacy protection during mobile communication.
- Minimizing exposure to eavesdropping or location tracking.
Security Auditors and Compliance Teams:
- Assessing GSM PLMN networks and equipment for adherence to essential security practices.
- Supporting the implementation and testing of authentication and confidentiality mechanisms.
Related Standards
To fully implement and understand the security aspects of GSM networks, the following standards are closely related to SIST ETS 300 920 E2:2003:
- GSM 02.02 (ETS 300 904): Bearer Services in GSM PLMN.
- GSM 02.03 (ETS 300 905): Teleservices in GSM PLMN.
- GSM 03.20 (ETS 300 929): Security-related network functions (providing implementation details).
- GSM 11.11 (ETS 300 977): Subscriber Identity Module (SIM) and Mobile Equipment Interface.
- GSM 01.04 (ETR 350): Abbreviations and acronyms for digital cellular telecommunications.
By adhering to SIST ETS 300 920 E2:2003 and its companion standards, stakeholders can ensure robust security for GSM communication systems, fostering a trusted environment for both service providers and users.
Get Certified
Connect with accredited certification bodies for this standard

ANCE
Mexican certification and testing association.

Intertek Slovenia
Intertek testing, inspection, and certification services in Slovenia.
LNE (Laboratoire National de Métrologie et d'Essais)
French national laboratory for metrology and testing.
Sponsored listings
Frequently Asked Questions
SIST ETS 300 920 E2:2003 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Digital cellular telecommunications system (Phase 2+) (GSM); Security aspects (GSM 02.09 version 5.1.1)". This standard covers: Bearer and Teleservices, as respectively defined in GSM 02.02 and GSM 02.03, are the objects which the GSM PLMN operators offer to their cus tomers. Besides these basic telecommunications services, features whic h aim at up grading these basic services need also to be offered. Due to the use of radiocommunications in a PLMN, which are of a special na ture compared to classical distribution transmission techniques used i n the fixed networks, such a category of features is related to securi ty aspects. In a GSM PLMN, both the users and the network operator have to be prot ected against undesirable intrusion of third parties. However, measure s should be provided for in order to insure maximum protection of the rights of the individuals concerns. As a consequence, a security featu re is either a supplementary service to Tele or Bearer services, which can be selected by the subscriber, or a network function involved in the provision of one or several telecommunication services. The purpose of this European Telecommunication Standard (ETS) is to de fine the security features which are to be available in a GSM PLMN, to gether with the associated levels of protection. This ETS is only conc erned with those security features which aim at the up grading of the security in a GSM PLMN. In particular, end to end security is outside the scope of this ETS. The implementation aspects of security features are described in GSM 0 3.20.
Bearer and Teleservices, as respectively defined in GSM 02.02 and GSM 02.03, are the objects which the GSM PLMN operators offer to their cus tomers. Besides these basic telecommunications services, features whic h aim at up grading these basic services need also to be offered. Due to the use of radiocommunications in a PLMN, which are of a special na ture compared to classical distribution transmission techniques used i n the fixed networks, such a category of features is related to securi ty aspects. In a GSM PLMN, both the users and the network operator have to be prot ected against undesirable intrusion of third parties. However, measure s should be provided for in order to insure maximum protection of the rights of the individuals concerns. As a consequence, a security featu re is either a supplementary service to Tele or Bearer services, which can be selected by the subscriber, or a network function involved in the provision of one or several telecommunication services. The purpose of this European Telecommunication Standard (ETS) is to de fine the security features which are to be available in a GSM PLMN, to gether with the associated levels of protection. This ETS is only conc erned with those security features which aim at the up grading of the security in a GSM PLMN. In particular, end to end security is outside the scope of this ETS. The implementation aspects of security features are described in GSM 0 3.20.
SIST ETS 300 920 E2:2003 is classified under the following ICS (International Classification for Standards) categories: 33.070.50 - Global System for Mobile Communication (GSM). The ICS classification helps identify the subject area and facilitates finding related standards.
SIST ETS 300 920 E2:2003 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-december-2003
'LJLWDOQLFHOLþQLWHOHNRPXQLNDFLMVNLVLVWHPID]D±9DUQRVWQLYLGLNL*60
UD]OLþLFD
Digital cellular telecommunications system (Phase 2+) (GSM); Security aspects (GSM
02.09 version 5.1.1)
Ta slovenski standard je istoveten z: ETS 300 920 Edition 2
ICS:
33.070.50 Globalni sistem za mobilno Global System for Mobile
telekomunikacijo (GSM) Communication (GSM)
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
EUROPEAN ETS 300 920
TELECOMMUNICATION December 1997
STANDARD Second Edition
Source: SMG Reference: RE/SMG-010209QR1
ICS: 33.020
Key words: Digital cellular telecommunications system, Global System for Mobile communications (GSM)
R
GLOBAL SYSTEM FOR
MOBILE COMMUNICATIONS
Digital cellular telecommunications system (Phase 2+);
Security aspects
(GSM 02.09 version 5.1.1)
ETSI
European Telecommunications Standards Institute
ETSI Secretariat
Postal address: F-06921 Sophia Antipolis CEDEX - FRANCE
Office address: 650 Route des Lucioles - Sophia Antipolis - Valbonne - FRANCE
X.400: c=fr, a=atlas, p=etsi, s=secretariat - Internet: secretariat@etsi.fr
Tel.: +33 4 92 94 42 00 - Fax: +33 4 93 65 47 16
Copyright Notification: No part may be reproduced except as authorized by written permission. The copyright and the
foregoing restriction extend to reproduction in all media.
© European Telecommunications Standards Institute 1997. All rights reserved.
Page 2
ETS 300 920 (GSM 02.09 version 5.1.1): December 1997
Whilst every care has been taken in the preparation and publication of this document, errors in content,
typographical or otherwise, may occur. If you have comments concerning its accuracy, please write to
"ETSI Editing and Committee Support Dept." at the address shown on the title page.
Page 3
ETS 300 920 (GSM 02.09 version 5.1.1): December 1997
Contents
Foreword .5
1 Scope .7
1.1 Normative references .7
1.2 Abbreviations .7
2 General.8
3 Security features provided in a GSM PLMN.8
3.1 Subscriber identity confidentiality. 8
3.1.1 Definition .8
3.1.2 Purpose .8
3.1.3 Functional requirements.9
3.2 Subscriber identity authentication .9
3.2.1 Definition .9
3.2.2 Purpose .9
3.2.3 Functional requirements.9
3.2.4 Authentication during a malfunction of the network .10
3.3 User data confidentiality on physical connections (Voice and Non-voice).10
3.3.1 Definition .10
3.3.2 Purpose .10
3.3.3 Functional requirements.10
3.4 Connectionless user data confidentiality.11
3.4.1 Definition .11
3.4.2 Purpose .11
3.4.3 Functional requirements.11
3.5 Signalling information element confidentiality.11
3.5.1 Definition .11
3.5.2 Purpose .11
3.5.3 Functional requirements.11
History.12
Page 4
ETS 300 920 (GSM 02.09 version 5.1.1): December 1997
Blank page
Page 5
ETS 300 920 (GSM 02.09 version 5.1.1): December 1997
Foreword
This second edition European Telecommunication Standard (ETS) has been produced by the Special
Mobile Group (SMG) of the European Telecommunications Standards Institute (ETSI).
This ETS defines security features within the digital cellular telecommunications system.
The specification from which this ETS has been derived was originally based on CEPT documentation,
hence the presentation of this ETS may not be entirely in accordance with the ETSI/PNE Rules.
Transposition dates
Date of adoption of this ETS: 5 December 1997
Date of latest announcement of this ETS (doa): 31 March 1998
Date of latest publication of new National Standard
or endorsement of this ETS (dop/e): 30 September 1998
Date of withdrawal of any conflicting National Standard (dow): 30 September 1998
Page 6
ETS 300 920 (GSM 02.09 version 5.1.1): December 1997
Blank page
Page 7
ETS 300 920 (GSM 02.09 version 5.1.1): December 1997
1 Scope
Bearer and Teleservices, as respectively defined in GSM 02.02 and GSM 02.03, are the objects which the
GSM PLMN operators offer to their customers. Besides these basic telecommunications services,
features which aim at up-grading these basic services need also to be offered. Due to the use of
radiocommunications in a PLMN, which are of a special nature compared to classical distribution
transmission techniques used in the fixed networks, such a category of features is related to security
aspects.
In a GSM PLMN, both the users and the network operator have to be protected against undesirable
intrusion of third parties. However, measures should be provided for in order to insure maximum
protection of the rights of the individuals concerns. As a consequence, a security feature is either a
supplementary service to Tele or Bearer services, which can be selected by the subscriber, or a network
function involved in the provision of one or several telecommunication services.
The purpose of this European Telecommunication Standard (ETS) is to define the security features which
are to be available in a GSM PLMN, together with the associated levels of protection. This ETS is only
concerned with those security features which aim at the up-grading of the security in a GSM PLMN. In
particular, end-to-end security is outside the scope of this ETS.
The implementation aspects of security features are described in GSM 03.20.
1.1 Normative references
This ETS incorporates by dated and undated reference, provisions from other publications. These
normative references are cited at the appropriate places in the text and the publications are listed
hereafter. For dated references, subsequent amendments to or revisions of any of these publications
apply to this ETS only when incorporated in it by amendment or revision. For undated references, the
latest edition of the publication referred to applies.
[1] GSM 01.04 (ETR 350): "Digital cellular telecommunications system (Phase 2+);
Abbreviations and acronyms".
[2] GSM 02.02 (ETS 300 904): "Digital cellular telecommunications system
(Phase 2+); Bearer Services (BS) supported by a GSM Public Land Mobile
Network (PLMN)".
[3] GSM 02.03 (ETS 300 905): "Digital cellular telecommunications system
(Phase 2+); Teleservices supported by a GSM Public Land Mobile Network
(PLMN)".
[4] GSM 03.20 (ETS 300 929): "Digital cellular telecommunications system
(Phase 2+); Security related network functions".
[5] GSM 11.11 (ETS 300 977): "Digital cellular telecommunications system
(Phase 2+); Specification of the Subscriber Identity Module - Mobile Equipment
(SIM - ME) interface".
1.2 Abbreviations
Abbreviations used in this ETS are listed in GSM 01.04.
Page 8
ETS 300 920 (GSM 02.09 version 5.1.1): December 1997
2 General
The use of radiocommunications for transmission to the mobile subscribers makes PLMNs particularly
sensitive to:
- misuse of their resources by unauthorized persons using manipulated Mobile Stations, who try to
impersonate authorized subscribers; and
- eavesdropping of the various information which are exchanged on the radio path.
It can be seen that PLMNs intrinsically do not provide the same level of protection to their operators and
subscribers as the traditional telecommunication networks provide. This fact leads to the need to
implement security features in a GSM PLM
...



