SIST-V ETSI/EG 201 510 V1.1.2:2003
(Main)Intelligent Network (IN) - Security aspects of Switching Control Function (SCF) - Service Switching Function (SSF) interconnection between networks - Part 1: Capability Set 1 (CS1) based operations
- Abstract
This ETSI Guide is the copy of the published TR 101 510-1 in January 2000.
- Status
- Published
- Publication Date
- 31-Oct-2003
- Technical Committee
- SPN - Services and Protocols for Networks
- Current Stage
- 6060 - National Implementation/Publication (Adopted Project)
- Start Date
- 01-Nov-2003
- Due Date
- 01-Nov-2003
- Completion Date
- 01-Nov-2003
SIST-V ETSI/EG 201 510 V1.1.2:2003 is the Slovenian copy of ETSI EG 201 510 V1.1.2, an ETSI Guide on security aspects of Intelligent Network (IN) interconnection between the Service Control Function (SCF) and the Service Switching Function (SSF). It specifies the security concerns and countermeasures for Capability Set 1 (CS1) based operations, mainly for inter-network call control in telecommunication networks.
What does SIST-V ETSI/EG 201 510 V1.1.2:2003 specify?
SIST-V ETSI/EG 201 510 V1.1.2:2003 describes security aspects of connecting two IN-structured networks, with the focus on SCF-SSF interconnection. It narrows the subject to a CS1 subset used for CAMEL phase 1 and organizes the material into scope, references, definitions and abbreviations, functionality, operation-by-operation security considerations, and security countermeasures.
The guide also places the work in context for later extensions to CS2 and CS3 based operation sets. In practice, that tells a reader that the document is about a specific signaling relationship and not about all Intelligent Network functions.
What are the key requirements of SIST-V ETSI/EG 201 510 V1.1.2:2003?
Clause 4 sets the functional model: the SSF interacts with the SCF to recognize service triggers, manage signaling, and adapt call processing, while the SCF controls call handling and may use other functions for data and resources. This matters because the security model depends on who controls the call and where that control is allowed to come from.
The guide limits the interconnection discussion to a small CS1 operation set: InitialDP, Connect, ReleaseCall, EventReportBCSM, RequestReportBCSMEvent, Continue and ActivityTest. For implementers, that means the security analysis is focused on these messages and the way they move between SSF and SCF.
- InitialDP starts the SCF request after a trigger is detected. The stated risk is session hijacking, so the signaling relationship must be protected from takeover by another SCF.
- Connect and ReleaseCall must stay within the SCF’s jurisdiction. Unauthorized use could allocate network resources incorrectly or tear down calls without approval.
- RequestReportBCSMEvent sets monitoring for call events. The guide treats unauthorized monitoring, resource flooding and loss of confidentiality as the main risks.
- Continue resumes call processing at the suspended point. The concern is that an unauthorized SCF could send the message early and disturb the call state sequence.
- ActivityTest checks that the SCF-SSF relationship still exists. It uses system resources, so it has a small but real availability cost.
- EventReportBCSM reports a requested call event back to the SCF. Clause 5 does not identify a specific security issue for this operation.
Clause 6 groups the countermeasures into topology, authentication, access control, integrity, confidentiality, non-repudiation, accountability and auditing, network security management, and testing and operation maintenance. In practice, this means limiting exposure, verifying identities, controlling access, protecting message contents, recording security events, and including security in interoperability and operational procedures.
What terms does SIST-V ETSI/EG 201 510 V1.1.2:2003 define?
- Service Switching Function (SSF) - The SSF is the switching-side function that recognizes service triggers and interacts with the SCF.
- Service Control Function (SCF) - The SCF controls call processing for IN services and may consult other functions for data or logic.
- Basic Call State Model (BCSM) - The BCSM is the call-state model used to detect events and suspend processing at detection points.
- Capability Set 1 (CS1) - CS1 is the capability set whose interconnection operations are the subject of this guide.
- Customized Applications for Mobile Enhanced Logic (CAMEL) - CAMEL is the application context used here for SCF-SSF interconnection.
- Trigger Detection Point - Request (TDP-R) - A TDP-R is the point where the SSF detects a trigger and asks the SCF for instructions.
- Denial of service - This is the prevention or slowing of authorized access to resources or time-critical operations.
Who uses SIST-V ETSI/EG 201 510 V1.1.2:2003?
Telecom operators, network architects, switch and service-platform engineers, and security managers use this guide when planning or reviewing IN interconnection between networks. It is also relevant to interoperability test teams and maintenance teams that need to check SCF-SSF signaling, control access, and handle operational security for CAMEL phase 1 style services.
What changed in SIST-V ETSI/EG 201 510 V1.1.2:2003 from the previous edition?
SIST-V ETSI/EG 201 510 V1.1.2:2003 is identified as the Slovenian copy of the published TR 101 510-1 from January 2000.
Which standards are used with SIST-V ETSI/EG 201 510 V1.1.2:2003?
- ITU-T Recommendation Q.1228 (1997) - Provides the IN CS2 interface recommendation that the guide uses as a functional reference for SCF and SSF behavior.
- ETSI ETR 232 - Supplies the glossary of security terminology used for the threat and countermeasure discussion.
- Part 2: Capability Set 2 (CS2) based operations - The foreword identifies this as the companion part covering CS2 based operations.
What does the SIST-V ETSI/EG 201 510 V1.1.2:2003 document contain?
The document contains a scope, reference list, definitions and abbreviations, a functionality overview, operation-by-operation security considerations, and a structured set of security countermeasures. Table 1 lists the CS1 operations between SSF and SCF and shows their direction. Figure 1 illustrates an interworking scenario for SCF-SSF communication across domains. Clause 5 gives the purpose, parameters and security remarks for each operation, and clause 6 turns those risks into practical security measures for design, testing, operation and maintenance.
Get Certified
Connect with accredited certification bodies for this standard

ANCE
Mexican certification and testing association.

Intertek Slovenia
Intertek testing, inspection, and certification services in Slovenia.
LNE (Laboratoire National de Métrologie et d'Essais)
French national laboratory for metrology and testing.
Sponsored listings
Frequently Asked Questions
SIST-V ETSI/EG 201 510 V1.1.2:2003 is a guide published by the Slovenian Institute for Standardization (SIST). Its full title is "Intelligent Network (IN) - Security aspects of Switching Control Function (SCF) - Service Switching Function (SSF) interconnection between networks - Part 1: Capability Set 1 (CS1) based operations". This standard covers: This ETSI Guide is the copy of the published TR 101 510-1 in January 2000.
This ETSI Guide is the copy of the published TR 101 510-1 in January 2000.
SIST-V ETSI/EG 201 510 V1.1.2:2003 is classified under the following ICS (International Classification for Standards) categories: 33.040.35 - Telephone networks. The ICS classification helps identify the subject area and facilitates finding related standards.
SIST-V ETSI/EG 201 510 V1.1.2:2003 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-november-2003
Inteligentno omrežje (IN) - Varnostni vidiki funkcije krmiljenja storitev (SCF) -
Funkcija komutacije storitve (SSF) medsebojnega povezovanja omrežij - Operacije
na podlagi prvega nabora zmožnosti (CS1)
Intelligent Network (IN) - Security aspects of Switching Control Function (SCF) - Service
Switching Function (SSF) interconnection between networks - Part 1: Capability Set 1
(CS1) based operations
Ta slovenski standard je istoveten z: EG 201 510 Version 1.1.2
ICS:
33.040.35 Telefonska omrežja Telephone networks
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
ETSI Guide
Intelligent Network (IN);
Security aspects of Switching Control Function (SCF) -
Service Switching Function (SSF)
interconnection between networks;
Part 1: Capability Set 1 (CS1) based operations
2 ETSI EG 201 510 V1.1.2 (2000-05)
Reference
DEG/SPAN-061212-1
Keywords
CS1, IN, interworking, security
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.:+33492944200 Fax:+33493654716
Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88
Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network
drive within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at http://www.etsi.org/tb/status/
If you find errors in the present document, send your comment to:
editor@etsi.fr
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.
© European Telecommunications Standards Institute 2000.
All rights reserved.
ETSI
3 ETSI EG 201 510 V1.1.2 (2000-05)
Contents
Intellectual Property Rights.4
Foreword .4
Introduction .4
1 Scope.5
2 References.5
3 Definitions and abbreviations .5
3.1 Definitions.5
3.2 Abbreviations .6
4 Functionality .6
4.1 SSF .6
4.2 SCF.6
4.3 SSF-SCF Interconnection.7
5 Security considerations of operations .8
5.1 initialDP .8
5.2 connect .8
5.3 releaseCall .8
5.4 eventReportBCSM .8
5.5 requestReportBCSMEvent .8
5.6 continue .9
5.7 activityTest .9
6 Security countermeasures.9
6.1 Topology .9
6.2 Authentication .9
6.3 Access control .9
6.4 Integrity .10
6.5 Confidentiality.10
6.6 Non Repudiation.10
6.7 Accountability and auditing.10
6.8 Network security management .10
6.9 Testing and operation maintenance .10
Bibliography.11
History.12
ETSI
4 ETSI EG 201 510 V1.1.2 (2000-05)
Intellectual Property Rights
IPRs essential or potentially essential to the present document may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect
of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server
(http://www.etsi.org/ipr).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in SR 000 314 (or the updates on the ETSI Web server)
which are, or may be, or may become, essential to the present document.
Foreword
This ETSI Guide (EG) has been produced by ETSI Technical Committee Services and Protocols for Advanced
Networks (SPAN).
The present document is part 1 of a multi-part EG covering the Intelligent Network (IN); Security aspects of Switching
Control Function (SCF) - Service Switching Function (SSF) interconnection between networks, as identified below:
Part 1: "Capability Set 1 (CS1) based operations";
Part 2: "Capability Set 2 (CS2) based operations".
Introduction
Under IN CS1 and CS2, the IN SCP to SSP relationship, or Service Control to Switch, is confined to a single network
operator's domain and may actually be physically co-located as an SSCP. To optimize performance, the switch requires
little security, particularly if implemented within a 'single unit' or SSCP. By not using the local processor for security,
switch performance may be optimized toward call processing with security and network protection measures provided at
the Service Control Point.
In the case of inter-connected networks, direct implementation of the Inter-network Control to Switch relationship would
require appropriate security and authentication measures to be provided and managed at each SSF.
Within a single network, potential conflict between multiple SCFs is avoided by their management within a common
domain. When two networks are interconnected two (or more) SCFs in different domains can potentially control the
same resource (SSF). Then some secure resource allocation and management procedure must be deployed. Suitable
mechanisms have not yet been standardized. Network operators may prefer the option of utilizing the established
inter-network SCF to SCF security procedures and route inter-network service switching signalling messages via each
Network's Service Control Point. In this case appropriate security and authentication measures would be provided and
managed at each SCF.
ETSI
5 ETSI EG 201 510 V1.1.2 (2000-05)
1 Scope
The present document describes security aspects in conjunction with the interconnection of two IN structured networks.
The present document concentrates on the SCF - SSF interconnection.
The purpose of the present document is to describe the security aspects of interconnection of SCF to SSF. The
operations considered in this interconnection are a subset of CS1. For the time being CAMEL is the only application of
SCF - SSF interconnection, therefore the present document considers only CAMEL phase 1 operations. A later edition
may also consider other CS1 operations.
Future parts of the present document will investigate the security aspects of operation sets that are a subset of CS2
and CS3.
2 References
The following documents contain provisions which, through reference in this text, constitute provisions of the present
document.
• References are either specific (identified by date of publication, edition number, version number, etc.) or
non-specific.
• For a specific reference, subsequent revisions do not apply.
• For a non-specific reference, the latest version applies.
• A non-specific reference to an ETS shall also be taken to refer to later versions published as an EN with the same
number.
[1] ITU-T Recommendation Q.1228 (1997): "Interface Recommendation for intelligent network
Capability Set 2".
[2] ETSI ETR 232: "Security Techniques Advisory Group (STAG); Glossary of security terminology".
3 Definitions and abbreviations
3.1 Definitions
For the purposes of the present document, the following terms and definitions apply:
masquerade ("spoofing"): pretence of an entity to be a different entity. This may be a basis for other threats like
unauthorized access or forgery
unauthorized access: entity attempts to access data in violation to the security policy in force
eavesdropping: breach of confidentiality by monitoring communication
loss or corruption of information: integrity of data (transferred) is compromised by unauthorized deletion, insertion,
modification, reordering, replay or delay
replay of information: repetition of previously valid commands and responses with the intention of corrupting service
or causing an overload
repudiation: denial by one of the entities involved in a communication of having participated in all or part of the
communication
forgery: entity fabricates information and claims that such information was received from another entity or sent to
another entity
ETSI
6 ETSI EG 201 510 V1.1.2 (2000-05)
denial of service: prevention of authorized access to resources or the delaying of time critical operat
...



