Abstract

Description of security mechanisms for networks like ISDN including confidentiality authentication access control, authorization procedures - Identification of necessary levels of security

Status
Published
Publication Date
30-Nov-2003
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
01-Dec-2003
Due Date
01-Dec-2003
Completion Date
01-Dec-2003

Buy Documents

Standard

SIST EN 301 132 V1.1.1:2003

English language (14 pages)
Preview
Preview
e-Library read for
×1 day

SIST EN 301 132 V1.1.1:2003 is the Slovenian standard identical to ETSI EN 301 132 V1.1.1, a European telecommunications standard from ETSI. SIST EN 301 132 V1.1.1:2003 specifies Security Tools (SET) for use within ISDN telecommunication services, with a focus on PIN and TAN methods used to support service security. It is aimed at service providers, network operators, and users of protected ISDN services.

What does SIST EN 301 132 V1.1.1:2003 specify?

SIST EN 301 132 V1.1.1:2003 specifies Security Tools (SET) for ISDN telecommunication services from the user’s point of view. It describes how SETs support service security, but not the details of the human interface.

The document is organized into:

  • Clause 1 - Scope
  • Clause 2 - References
  • Clause 3 - Definitions and abbreviations
  • Clause 4 - General aspects
  • Clause 5 - Security Tools (SET), covering PIN and TAN
  • History

Clause 4 covers general SET handling such as provision, registration, invocation, and intercommunication across networks. Clause 5 then develops the two SETs named in the standard: Personal Identification Number (PIN) and Transaction Number (TAN).

The scope also places charging principles outside the document and states that no method of testing is provided.

What are the key requirements of SIST EN 301 132 V1.1.1:2003?

SIST EN 301 132 V1.1.1:2003 sets out how a service provider chooses, provisions, registers, and controls SETs so that a telecommunication service is used with an appropriate level of security. In practice, it tells the provider what data to keep, what the user must enter, and when access must be blocked.

General SET rules

  • Clause 4.1 says SETs are used to support protection of information, authenticity, availability, integrity, confidentiality, access control, and non-repudiation. This matters because the provider must match the security tool to the actual service risk.
  • Clause 4.1 also says the provider shall apply the two-stage method from the referenced ETSI security documents when choosing SETs. In practice, the choice starts with security requirements capture and then moves to selecting the mechanism.
  • Clause 4.2 requires the service provider to supply the served user with the confidential information needed to use the SET. That means the access data must be handled carefully because misuse becomes a shared responsibility issue.
  • Clause 4.2.2 requires registration of the SET type, its value, and the telecommunication services linked to it. This keeps the network aligned with the service being protected.
  • Clause 4.2.4 says invocation happens together with the related service operation, and the result is sent to that service. In practice, the SET is part of the access flow, not a separate action.
  • Clause 4.3 allows intercommunication across several networks. That matters where the same protected service must work beyond one network boundary.

PIN requirements

  • Clause 5.1 limits a PIN to 4 to 12 alphanumerical characters and allows the served user to change it at any time after initial provision. This gives the provider a length policy while still allowing user-managed renewal.
  • Clause 5.1.3 requires the user to enter the old PIN, then the new PIN twice, with the terminal validating the two new entries. In practice, the change procedure needs both user entry and network overwrite of the old value.
  • Clause 5.1.3.1 says primitive PINs such as easy character combinations shall be rejected by the network. This reduces weak passwords in service use.
  • Clause 5.1.4.1 and 5.1.4.3 require blocking after repeated failed attempts, with the limit set by the provider but at least 3. This limits brute-force guessing.

TAN requirements

  • Clause 5.2 defines TAN as a one-time password and limits its length to 6 to 12 alphanumerical characters. In practice, each TAN is consumed once and then removed from use.
  • Clause 5.2.1 says TANs are supplied either as a list of randomly generated values or by an electronic device that generates the next TAN. This gives two operational models for authentication.
  • Clause 5.2.1 also requires TANs to be used in sequence and once only. That means the user must know the next valid TAN and cannot reuse old ones.
  • Clause 5.2.4.3 allows blocking after repeated failed TAN attempts, with the threshold set by the provider but at least 3. As with PIN, repeated wrong entry triggers service control.

What terms does SIST EN 301 132 V1.1.1:2003 define?

  • Security Tool (SET) - A tool provided to support the security of a service.
  • Personal Identification Number (PIN) - An alphanumerical access value used to authenticate a user for a telecommunication service.
  • Transaction Number (TAN) - A one-time password used for service access, usually together with a PIN.
  • confidential information - The information needed to make use of a SET.
  • served user - The user to whom a SET is provided together with a telecommunication service.
  • network operator - The entity that provides the network operating elements and resources needed to execute the Security Tool.
  • telecommunication service - The service context in which the SET is used, including basic services, teleservices, and supplementary services.

Who uses SIST EN 301 132 V1.1.1:2003?

SIST EN 301 132 V1.1.1:2003 is used by service providers, network operators, and security planners for ISDN services. It is especially relevant when a service needs user-controlled protection such as Remote Control (RC) or Outgoing Call Barring - User Controlled (OCB-UC).

Engineers use it to design PIN and TAN handling, registration, blocking, and reset behavior. Quality managers and buyers use it to check what security functions a service implementation should support and how those functions are administered.

Which standards are used with SIST EN 301 132 V1.1.1:2003?

  • ITU-T Recommendation I.112 - Supplies ISDN vocabulary and the base definition of telecommunication service and ISDN.
  • CCITT Recommendation I.130 - Defines the stage two and stage three method used for characterizing telecommunication services and network capabilities.
  • ETR 232 - Provides additional security terminology.
  • ETR 237 - Describes baseline security standards and the features and mechanisms that include SET principles.
  • ETR 236 - Guides security standards policy and the security requirements capture process.
  • TCR-TR 49 - Covers security requirements capture and supports the two-stage selection method for SETs.
  • ETS 300 391-1 - Gives a security architecture for UPT phase 1 and is cited for the DTMF example.

What does the SIST EN 301 132 V1.1.1:2003 document contain?

The document is mainly procedural. It describes how SETs are provisioned, registered, activated through use, withdrawn, erased, and blocked when repeated incorrect entries occur. It also states how the user is informed during PIN and TAN entry and when a validation attempt fails.

Clause 5 gives the detailed behavior for PIN and TAN, including change procedures, automatic erasure of used TANs, and provider-controlled reset or reinitialization options. The document also includes the standard’s references, definitions, abbreviations, intellectual property notice, foreword, and publication history.

Buy Documents

Standard

SIST EN 301 132 V1.1.1:2003

English language (14 pages)
Preview
Preview
e-Library read for
×1 day

Get Certified

Connect with accredited certification bodies for this standard

ANCE

Mexican certification and testing association.

EMA Mexico Verified

Intertek Slovenia

Intertek testing, inspection, and certification services in Slovenia.

UKAS Slovenia Verified

LNE (Laboratoire National de Métrologie et d'Essais)

French national laboratory for metrology and testing.

COFRAC France Verified

Sponsored listings

Frequently Asked Questions

SIST EN 301 132 V1.1.1:2003 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Integrated Services Digital Network (ISDN); Security tools (SET) for use within telecommunication services". This standard covers: Description of security mechanisms for networks like ISDN including confidentiality authentication access control, authorization procedures - Identification of necessary levels of security

Description of security mechanisms for networks like ISDN including confidentiality authentication access control, authorization procedures - Identification of necessary levels of security

SIST EN 301 132 V1.1.1:2003 is classified under the following ICS (International Classification for Standards) categories: 33.080 - Integrated Services Digital Network (ISDN). The ICS classification helps identify the subject area and facilitates finding related standards.

SIST EN 301 132 V1.1.1:2003 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.Digitalno omrežje z integriranimi storitvami (ISDN) – Varnostna orodja (SET) za uporabo v telekomunikacijskih storitvahIntegrated Services Digital Network (ISDN); Security tools (SET) for use within telecommunication services33.080Digitalno omrežje z integriranimi storitvami (ISDN)Integrated Services Digital Network (ISDN)ICS:Ta slovenski standard je istoveten z:EN 301 132 Version 1.1.1SIST EN 301 132 V1.1.1:2003en01-december-2003SIST EN 301 132 V1.1.1:2003SLOVENSKI
STANDARD
EN 301 132 V1.1.1 (1998-10)European Standard (Telecommunications series)Integrated Services Digital Network (ISDN);Security tools (SET) for use within telecommunication servicesSIST EN 301 132 V1.1.1:2003

ETSIEN 301 132 V1.1.1 (1998-10)2ReferenceDEN/NA-020036 (ahc00ico.PDF)KeywordsISDN, securityETSIPostal addressF-06921 Sophia Antipolis Cedex - FRANCEOffice address650 Route des Lucioles - Sophia AntipolisValbonne - FRANCETel.: +33 4 92 94 42 00
Fax: +33 4 93 65 47 16Siret N° 348 623 562 00017 - NAF 742 CAssociation à but non lucratif enregistrée à laSous-Préfecture de Grasse (06) N° 7803/88Internetsecretariat@etsi.frhttp://www.etsi.orgCopyright NotificationNo part may be reproduced except as authorized by written permission.The copyright and the foregoing restriction extend to reproduction in all media.© European Telecommunications Standards Institute 1998.All rights reserved.SIST EN 301 132 V1.1.1:2003

ETSIEN 301 132 V1.1.1 (1998-10)3ContentsIntellectual Property Rights.4Foreword.41Scope.52References.52.1Normative references.52.2Informative references.63Definitions and abbreviations.63.1Definitions.63.2Abbreviations.64General aspects.74.1Description.74.2Procedures.74.2.1Provision and withdrawal.74.2.2Activation, deactivation and registration.84.2.3Erasure.84.2.4Invocation and operation.84.2.5Interrogation.84.3Intercommunication considerations.85Security Tools (SET).85.1Personal Identification Number (PIN).85.1.1Description.85.1.2Provision and withdrawal.95.1.3Normal procedures.95.1.3.1Registration and erasure.95.1.3.2Activation, deactivation.95.1.3.3Invocation and operation.105.1.3.4Interrogation.105.1.4Exceptional procedures.105.1.4.1Activation, deactivation and registration.105.1.4.2Erasure.105.1.4.3Invocation and operation.105.1.4.4Interrogation.115.2Transaction Number (TAN).115.2.1Description.115.2.2Provision and withdrawal.115.2.3Procedures.125.2.3.1Activation, deactivation and registration.125.2.3.2Erasure.125.2.3.3Invocation and operation.125.2.3.4Interrogation.125.2.4Exceptional procedures.125.2.4.1Activation, deactivation and registration.125.2.4.2Erasure.125.2.4.3Invocation and operation.125.2.4.4Interrogation.13History.14SIST EN 301 132 V1.1.1:2003

ETSIEN 301 132 V1.1.1 (1998-10)4Intellectual Property RightsIPRs essential or potentially essential to the present document may have been declared to ETSI. The informationpertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be foundin SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respectof ETSI standards", which is available free of charge from the ETSI Secretariat. Latest updates are available on theETSI Web server (http://www.etsi.org/ipr).Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guaranteecan be given as to the existence of other IPRs not referenced in SR 000 314 (or the updates on the ETSI Web server)which are, or may be, or may become, essential to the present document.ForewordThis European Standard (Telecommunications series) has been produced by ETSI Technical Committee NetworkAspects (NA).National transposition datesDate of adoption of this EN: 30 October 1998Date of latest announcement of this EN (doa): 31 January 1999Date of latest publication of new National Standardor endorsement of this EN (dop/e): 31 July 1999Date of withdrawal of any conflicting National Standard (dow): 31 July 1999SIST EN 301 132 V1.1.1:2003

ETSIEN 301 132 V1.1.1 (1998-10)51ScopeThe present document is a description of Security Tools (SET) for use within ISDN telecommunication services fromthe user's point of view. It does not deal with the details of the human interface itself.NOTE 1:The SETs are in principle application independent. Although they are designed for the use within ISDN,they could be applicable to other networks such as B-ISDN or PSTN depending on the requirements forthe telecommunication service to be protected and the service provider's decision.Charging principles are outside the scope of the present document.The use of one of the SET helps in providing an appropriate level of security for a given ISDN telecommunicationservices.NOTE 2:The present document describes two security tools for the use in ISDN, i.e. Personal IdentificationNumber (PIN) and Transaction Number (TAN). These are intended to be used for the Integrated ServicesDigital Network (ISDN) Remote Control (RC) service and Outgoing Call Barring – User Controlled(OCB-UC) supplementary service. Due to the increasing demand for enhanced security mechanisms intelecommunication services, more tools may be added in future versions of the standard. Possiblecandidates for the use within N-ISDN are described in ETR 237 [4].The present document is applicable to the stage two and stage three standards for the ISDN Security Tools. The terms"stage two" and "stage three" are also defined in CCITT Recommendation I.130 [2]. Where the text indicates the statusof a requirement (i.e. as strict command or prohibition, as authorization leaving freedom, as a capability or possibility),this shall be reflected in the text of the relevant stage two and stage three standards.Furthermore, conformance to the present document is met by conforming to the stage three standards with the field ofapplication appropriate to the equipment being implemented. Therefore, no method of testing is provided for the presentdocument.2ReferencesReferences may be made to:a)specific versions of publications (identified by date of publication, edition number, version number, etc.), inwhich case, subsequent revisions to the referenced document do not apply; orb)all versions up to and including the identified version (identified by "up to and including" before the versionidentity); orc)all versions subsequent to and including the identified version (identified by "onwards" following the versionidentity); ord)publications without mention of a specific version, in which case the latest version applies.A non-specific reference to an ETS shall also be taken to refer to later versions published as an EN with the samenumber.2.1Normative references[1]ITU-T Recommendation I.112 (1993): "Vocabulary of terms for ISDNs".[2]CCITT Recommendation I.130 (1988): "Method for the characterization of telecommunicationservices supported by an ISDN and network capabilities of an ISDN".[3]ETR 232 (1996): "Security Technical Advisory Group (STAG); Glossary of security terminology".[4]ETR 237 (1996): "Security Technical Advisory Group (STAG); Baseline security standards;Features and mechanisms".SIST EN 301 132 V1.1.1:2003

ETSIEN 301 132 V1.1.1 (1998-10)6[5]ETR 236 (1996): "Security Technical Advisory Group (STAG); A guide to the ETSI securitystandards policy".[6]TCR-TR 49: "Security Technical Advisory Group (STAG); Security requirements capture".[7]ETS 300 391-1 (1995): "Universal Personal Telecommunication (UPT); Specification of thesecurity architecture for UPT phase 1; Part 1: specification".2.2Informative referencesNone3Definitions and abbreviations3.1DefinitionsFor the purposes of the present document, the following definitions in addition to those contained in ETR 232 [3] apply:telecommunication service: see ITU-T Recommendation I.112 [1], subclause 2.2, definition 201. In the context of thepresent document, the term telecommunication service includes basic services, teleservices and supplementary services.confidential information: the information that is necessary to make use of a SET.Integrated Services Digital Network (ISDN): see ITU-T Recommendation I.112 [1], subclause 2.3, definition 308.network operator: the entity which provides the network operating elements and resources for the execution of theSecurity Tool.Security Tool (SET): a tool provided in support of the security of a service.served user: the user to whom a SET is provided to in combination with a telecommunication service.Transaction Number (TAN): a TAN is a one time password.3.2AbbreviationsFor the purposes of the present document, the following abbreviations apply:(N)-ISDN(Narrowband)-Integrated Services Digital NetworkB-ISDNBroadband Integrated Services Digital NetworkDTMFDual Tone Multi F
...