SIST EN 300 920 V6.1.1:2003
(Main)Digital cellular telecommunications system (Phase 2+) (GSM); Security aspects (GSM 02.09 version 6.1.1 Release 1997)
General Information
- Abstract
CR SMG#31
- Status
- Published
- Publication Date
- 30-Nov-2003
- Current Stage
- 6060 - National Implementation/Publication (Adopted Project)
- Start Date
- 01-Dec-2003
- Due Date
- 01-Dec-2003
- Completion Date
- 01-Dec-2003
Overview
SIST EN 300 920 V6.1.1:2003 specifies the security aspects for the digital cellular telecommunications system (GSM Phase 2+), based on GSM 02.09 version 6.1.1 Release 1997. Developed by the Slovenski inštitut za standardizacijo (SIST) as an adoption of ETSI EN 300 920, this standard focuses on defining and enforcing essential security features within the Global System for Mobile Communications (GSM) networks. It aims to ensure protection for both users and network operators against unauthorized access, misuse of telecommunications resources, and eavesdropping on wireless channels.
Security features addressed in the standard are crucial for maintaining the integrity and privacy of subscriber data and safeguarding telecommunications services offered by GSM Public Land Mobile Networks (PLMNs).
Key Topics
This standard covers a comprehensive set of security measures specific to GSM networks, including:
- Subscriber Identity Confidentiality: Ensures that the International Mobile Subscriber Identity (IMSI) is not disclosed to unauthorized individuals or entities, thus enhancing user privacy and preventing tracking and unauthorized identification.
- Subscriber Identity Authentication: Provides mechanisms for the network to verify that the subscriber identity provided during network access is legitimate, protecting against impersonation and unauthorized usage.
- User Data Confidentiality on Physical Connections: Encrypts user data (both voice and non-voice communications) on traffic channels, preventing third-party interception and unauthorized disclosure.
- Connectionless User Data Confidentiality: Protects user information transferred over signaling channels, including non-voice data such as short messages, ensuring privacy for packet-mode exchanges.
- Signalling Information Element Confidentiality: Safeguards critical signaling information between mobile stations and network infrastructure, particularly during connections, while ensuring secure handling of sensitive identifiers such as IMEI and IMSI.
These security features are mandatory both on the network infrastructure and the mobile station (MS) side to guarantee a consistent security baseline across all GSM PLMNs.
Applications
Implementing SIST EN 300 920 V6.1.1:2003 provides practical benefits in the operation and management of GSM-based mobile networks:
- Mobile Network Operators: Ensures regulatory compliance, enhances network integrity, and protects subscriber identities from unauthorized access or misuse.
- Device Manufacturers: Guides the design of mobile equipment, particularly regarding the secure storage and handling of subscriber and equipment identities.
- Telecommunication Service Providers: Supports secure delivery of bearer and teleservices, such as voice calls, SMS, and data services, safeguarding user privacy and increasing trust in the network.
- Roaming Scenarios: Mandates security feature interoperability for roaming subscribers, ensuring consistent protection regardless of network boundaries.
Network operators and suppliers benefit from reduced risk of fraud, improved user confidence, and compliance with international mobile security best practices.
Related Standards
For a comprehensive approach to GSM security, the following standards and documents are closely linked to SIST EN 300 920 V6.1.1:2003:
- GSM 02.02: Bearer Services supported by a GSM PLMN
- GSM 02.03: Teleservices supported by a GSM PLMN
- GSM 03.20: Security-related network functions, including the implementation details of network security features
- GSM 11.11: Specification of the Subscriber Identity Module (SIM) - Mobile Equipment (ME) interface for secure subscriber identity management
- GSM 01.04: List of abbreviations and acronyms used across GSM standards
Together, these standards establish a robust security framework for the global deployment and operation of GSM mobile communication systems, affirming industry-wide best practices for telecommunications security and user protection.
Get Certified
Connect with accredited certification bodies for this standard

ANCE
Mexican certification and testing association.

Intertek Slovenia
Intertek testing, inspection, and certification services in Slovenia.
LNE (Laboratoire National de Métrologie et d'Essais)
French national laboratory for metrology and testing.
Sponsored listings
Frequently Asked Questions
SIST EN 300 920 V6.1.1:2003 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Digital cellular telecommunications system (Phase 2+) (GSM); Security aspects (GSM 02.09 version 6.1.1 Release 1997)". This standard covers: CR SMG#31
CR SMG#31
SIST EN 300 920 V6.1.1:2003 is classified under the following ICS (International Classification for Standards) categories: 33.070.50 - Global System for Mobile Communication (GSM). The ICS classification helps identify the subject area and facilitates finding related standards.
SIST EN 300 920 V6.1.1:2003 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-december-2003
'LJLWDOQLFHOLþQLWHOHNRPXQLNDFLMVNLVLVWHPID]D±9DUQRVWQLYLGLNL*60
UD]OLþLFDL]GDMD
Digital cellular telecommunications system (Phase 2+) (GSM); Security aspects (GSM
02.09 version 6.1.1 Release 1997)
Ta slovenski standard je istoveten z: EN 300 920 Version 6.1.1
ICS:
33.070.50 Globalni sistem za mobilno Global System for Mobile
telekomunikacijo (GSM) Communication (GSM)
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
European Standard (Telecommunications series)
Digital cellular telecommunications system (Phase 2+);
Security aspects
(GSM 02.09 version 6.1.1 Release 1997)
R
GLOBAL SYSTEM FOR
MOBILE COMMUNICATIONS
2 ETSI EN 300 920 V6.1.1 (2000-08)
(GSM 02.09 version 6.1.1 Release 1997)
Reference
REN/SMG-010209Q6R1
Keywords
Digital cellular telecommunications system,
Global System for Mobile communications (GSM)
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.:+33492944200 Fax:+33 493654716
Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88
Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at http://www.etsi.org/tb/status/
If you find errors in the present document, send your comment to:
editor@etsi.fr
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.
© European Telecommunications Standards Institute 2000.
All rights reserved.
ETSI
3 ETSI EN 300 920 V6.1.1 (2000-08)
(GSM 02.09 version 6.1.1 Release 1997)
Contents
Intellectual Property Rights.4
Foreword.4
1 Scope .5
1.1 References .5
1.2 Abbreviations .5
2 General .6
3 Security features provided in a GSM PLMN .6
3.1 Subscriber identity confidentiality .6
3.1.1 Definition.6
3.1.2 Purpose .6
3.1.3 Functional requirements .7
3.2 Subscriber identity authentication .7
3.2.1 Definition.7
3.2.2 Purpose .7
3.2.3 Functional requirements .7
3.2.4 Authentication during a malfunction of the network .7
3.3 User data confidentiality on physical connections (Voice and Non-voice).8
3.3.1 Definition.8
3.3.2 Purpose .8
3.3.3 Functional requirements .8
3.4 Connectionless user data confidentiality .8
3.4.1 Definition.8
3.4.2 Purpose .8
3.4.3 Functional requirements .9
3.5 Signalling information element confidentiality .9
3.5.1 Definition.9
3.5.2 Purpose .9
3.5.3 Functional requirements .9
Annex A (informative): Change history .10
History .11
ETSI
4 ETSI EN 300 920 V6.1.1 (2000-08)
(GSM 02.09 version 6.1.1 Release 1997)
Intellectual Property Rights
IPRs essential or potentially essential to the present document may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in
respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web
server (http://www.etsi.org/ipr).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web
server) which are, or may be, or may become, essential to the present document.
Foreword
This European Standard (Telecommunications series) has been produced by ETSI Technical Committee Special Mobile
Group (SMG).
The present document defines security features within the digital cellular telecommunications system.
The contents of this standard may be subject to continuing work within SMG and may change following formal SMG
approval. Should SMG modify the contents of this standard it will then be re-submitted for formal approval procedures
by ETSI with an identifying change of release date and an increase in version number as follows:
Version 6.x.y
where:
6 GSM Phase 2+ Release 1997;
x the second digit is incremented for changes of substance, i.e. technical enhancements, corrections, updates,
etc.;
y the third digit is incremented when editorial only changes have been incorporated in the specification.
National transposition dates
Date of adoption of this EN: 14 July 2000
Date of latest announcement of this EN (doa): 31 October 2000
Date of latest publication of new National Standard
or endorsement of this EN (dop/e): 30 April 2001
Date of withdrawal of any conflicting National Standard (dow): 30 April 2001
ETSI
5 ETSI EN 300 920 V6.1.1 (2000-08)
(GSM 02.09 version 6.1.1 Release 1997)
1 Scope
Bearer and Teleservices, as respectively defined in GSM 02.02 and GSM 02.03, are the objects which the GSM PLMN
operators offer to their customers. Besides these basic telecommunications services, features which aim at up-grading
these basic services need also to be offered. Due to the use of radiocommunications in a PLMN, which are of a special
nature compared to classical distribution transmission techniques used in the fixed networks, such a category of features
is related to security aspects.
In a GSM PLMN, both the users and the network operator have to be protected against undesirable intrusion of third
parties. However, measures should be provided for in order to insure maximum protection of the rights of the
individuals concerns. As a consequence, a security feature is either a supplementary service to Tele or Bearer services,
which can be selected by the subscriber, or a network function involved in the provision of one or several
telecommunication services.
The purpose of this EN is to define the security features which are to be available in a GSM PLMN, together with the
associated levels of protection. This EN is only concerned with those security features which aim at the up-grading of
the security in a GSM PLMN. In particular, end-to-end security is outside the scope of this EN.
The implementation aspects of security features are described in GSM 03.20.
1.1 References
The following documents contain provisions which, through reference in this text, constitute provisions of the present
document.
• References are either specific (identified by date of publication, edition number, version number, etc.) or
non-specific.
• For a specific reference, subsequent revisions do not apply.
• For a non-specific reference, the latest version applies.
• A non-specific reference to an ETS shall also be taken to refer to later versions published as an EN with the same
number.
• For this Release 1997 document, references to GSM documents are for Release 1997 versions (version 6.x.y).
[1] GSM 01.04: "Digital cellular telecommunications system (Phase 2+); Abbreviations and
acronyms".
[2] GSM 02.02: "Digital cellular telecommunications system (Phase 2+); Bearer Services (BS)
supported by a GSM Public Land Mobile Network (PLMN)".
[3] GSM 02.03: "Digital cellular telecommunications system (Phase 2+); Teleservices supported by a
GSM Public Land Mobile Network (PLMN)".
[4] GSM 03.20: "Digital cellular telecommunications system (Phase 2+); Security related network
functions".
[5] GSM 11.11: "Digital cellular telecommunications system (Phase 2+); Specification of the
Subscri
...



