General Information

Abstract

Upgrade  to Release 1998

Status
Published
Publication Date
30-Nov-2003
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
01-Dec-2003
Due Date
01-Dec-2003
Completion Date
01-Dec-2003

Buy Documents

Standard

SIST EN 300 920 V7.0.1:2003

English language (11 pages)
Preview
Preview
e-Library read for
×1 day

Overview

SIST EN 300 920 V7.0.1:2003 defines essential security features for the Digital Cellular Telecommunications System (GSM Phase 2+) focusing on Release 1998. Published by the Slovenian Institute for Standardization (SIST) in alignment with ETSI EN 300 920, this standard outlines mandatory security measures for GSM Public Land Mobile Networks (PLMN). The primary aim is to protect both users and network operators from unauthorized access, data interception, and privacy breaches in mobile communication environments.

With the unique vulnerabilities introduced by radiocommunications in mobile networks, the standard details how security features should be integrated into GSM systems to ensure data confidentiality, user privacy, and network integrity.

Key Topics

  • Subscriber Identity Confidentiality:
    Protects the International Mobile Subscriber Identity (IMSI) from being disclosed or traced by unauthorized parties. Temporary identifiers are utilized to enhance subscriber privacy during over-the-air communication.

  • Subscriber Identity Authentication:
    Ensures that mobile subscriber identities presented during access requests genuinely belong to the claimed entities. The authentication process helps prevent fraudulent network access and impersonation.

  • User Data Confidentiality on Physical Connections:
    Mandates the encryption of both voice and non-voice data over GSM traffic channels. Supports multiple ciphering algorithms for flexibility and robust protection against eavesdropping.

  • Connectionless User Data Confidentiality:
    Safeguards user information transmitted in packet modes, such as SMS or other signalling channels, to prevent data leakage during connectionless exchanges.

  • Signalling Information Element Confidentiality:
    Protects sensitive signalling information-such as equipment identifiers, subscriber numbers, and SIM data-especially during and after connection establishment, maintaining both privacy and system integrity.

Applications

SIST EN 300 920 V7.0.1:2003 is vital for organizations that design, deploy, or maintain GSM-based telecommunications infrastructure. Its security framework is applied in:

  • Mobile Network Infrastructure:
    Operators utilize these security requirements for configuring and securing GSM radio access, core networks, and related components. This ensures that voice, data, and signalling traffic remain confidential and protected from unauthorized interception or access.

  • SIM and Mobile Equipment Development:
    Device manufacturers implement standardized security algorithms, authentication routines, and confidentiality features to comply with regulatory and operator requirements.

  • Roaming and Inter-Network Security:
    Security features are mandatory for all roaming subscribers, providing consistent protection across different networks and geographical regions.

  • Compliance and Risk Management:
    Regulatory bodies and telecommunication enterprises rely on the standard for internal audits, compliance verification, and minimizing risk related to mobile data breaches or network misuse.

Related Standards

For comprehensive GSM security and interoperability, SIST EN 300 920 V7.0.1:2003 should be considered alongside:

  • GSM 01.04: Abbreviations and acronyms for GSM standards.
  • GSM 02.02: Specification of Bearer Services supported by GSM PLMN.
  • GSM 02.03: Teleservices supported by GSM networks.
  • GSM 03.20: Detailed specifications for security-related network functions.
  • GSM 11.11: SIM - ME interface specification, important for SIM security policy.

By aligning with these referenced standards, organizations can achieve a robust, end-to-end security posture for GSM mobile communications in conformity with European and global telecommunications requirements.


Keywords: GSM security, digital cellular telecommunications, mobile network security, IMSI confidentiality, authentication, user data confidentiality, GSM signalling protection, Release 1998, SIST EN 300 920, ETSI standards.

Buy Documents

Standard

SIST EN 300 920 V7.0.1:2003

English language (11 pages)
Preview
Preview
e-Library read for
×1 day

Get Certified

Connect with accredited certification bodies for this standard

ANCE

Mexican certification and testing association.

EMA Mexico Verified

Intertek Slovenia

Intertek testing, inspection, and certification services in Slovenia.

UKAS Slovenia Verified

LNE (Laboratoire National de Métrologie et d'Essais)

French national laboratory for metrology and testing.

COFRAC France Verified

Sponsored listings

Frequently Asked Questions

SIST EN 300 920 V7.0.1:2003 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Digital cellular telecommunications system (Phase 2+) (GSM); Security aspects (GSM 02.09 version 7.0.1 Release 1998)". This standard covers: Upgrade to Release 1998

Upgrade to Release 1998

SIST EN 300 920 V7.0.1:2003 is classified under the following ICS (International Classification for Standards) categories: 33.070.50 - Global System for Mobile Communication (GSM). The ICS classification helps identify the subject area and facilitates finding related standards.

SIST EN 300 920 V7.0.1:2003 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


SLOVENSKI STANDARD
01-december-2003
'LJLWDOQLFHOLþQLWHOHNRPXQLNDFLMVNLVLVWHP ID]D ±9DUQRVWQLYLGLNL *60
UD]OLþLFDL]GDMD
Digital cellular telecommunications system (Phase 2+) (GSM); Security aspects (GSM
02.09 version 7.0.1 Release 1998)
Ta slovenski standard je istoveten z: EN 300 920 Version 7.0.1
ICS:
33.070.50 Globalni sistem za mobilno Global System for Mobile
telekomunikacijo (GSM) Communication (GSM)
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

European Standard (Telecommunications series)
Digital cellular telecommunications system (Phase 2+);
Security aspects
(GSM 02.09 version 7.0.1 Release 1998)
R
GLOBAL SYSTEM FOR
MOBILE COMMUNICATIONS
(GSM 02.09 version 7.0.1 Release 1998) 2 ETSI EN 300 920 V7.0.1 (2000-01)
Reference
REN/SMG-010209Q7
Keywords
Digital cellular telecommunications system,
Global System for Mobile communications (GSM)
ETSI
Postal address
F-06921 Sophia Antipolis Cedex - FRANCE
Office address
650 Route des Lucioles - Sophia Antipolis
Valbonne - FRANCE
Tel.:+33492944200 Fax:+33493654716
Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88
Internet
secretariat@etsi.fr
Individual copies of this ETSI deliverable
can be downloaded from
http://www.etsi.org
If you find errors in the present document, send your
comment to: editor@etsi.fr
Important notice
This ETSI deliverable may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network
drive within ETSI Secretariat.
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.
© European Telecommunications Standards Institute 2000.
All rights reserved.
ETSI
(GSM 02.09 version 7.0.1 Release 1998) 3 ETSI EN 300 920 V7.0.1 (2000-01)
Contents
Intellectual Property Rights.4
Foreword.4
1 Scope .5
1.1 References .5
1.2 Abbreviations .5
2 General .6
3 Security features provided in a GSM PLMN.6
3.1 Subscriber identity confidentiality.6
3.1.1 Definition.6
3.1.2 Purpose .6
3.1.3 Functional requirements.7
3.2 Subscriber identity authentication .7
3.2.1 Definition.7
3.2.2 Purpose .7
3.2.3 Functional requirements.7
3.2.4 Authentication during a malfunction of the network.7
3.3 User data confidentiality on physical connections (Voice and Non-voice) .8
3.3.1 Definition.8
3.3.2 Purpose .8
3.3.3 Functional requirements.8
3.4 Connectionless user data confidentiality .8
3.4.1 Definition.8
3.4.2 Purpose .8
3.4.3 Functional requirements.9
3.5 Signalling information element confidentiality.9
3.5.1 Definition.9
3.5.2 Purpose .9
3.5.3 Functional requirements.9
Annex A (informative): Change history .10
History .11
ETSI
(GSM 02.09 version 7.0.1 Release 1998) 4 ETSI EN 300 920 V7.0.1 (2000-01)
Intellectual Property Rights
IPRs essential or potentially essential to the present document may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect
of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server
(http://www.etsi.org/ipr).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in SR 000 314 (or the updates on the ETSI Web server)
which are, or may be, or may become, essential to the present document.
Foreword
This European Standard (Telecommunications series) has been produced by the Special Mobile Group (SMG).
The present document defines security features within the digital cellular telecommunications system.
The contents of the present document may be subject to continuing work within SMG and may change following formal
SMG approval. Should SMG modify the contents of the present document it will then be re-submitted for formal
approval procedures by ETSI with an identifying change of release date and an increase in version number as follows:
Version 7.x.y
where:
7 GSM Phase 2+ Release 1998;
x the second digit is incremented for changes of substance, i.e. technical enhancements, corrections, updates,
etc.;
y the third digit is incremented when editorial only changes have been incorporated in the specification.
National transposition dates
Date of adoption of this EN: 31 December 1999
Date of latest announcement of this EN (doa): 31 March 2000
Date of latest publication of new National Standard
or endorsement of this EN (dop/e): 30 September 2000
Date of withdrawal of any conflicting National Standard (dow): 30 September 2000
ETSI
(GSM 02.09 version 7.0.1 Release 1998) 5 ETSI EN 300 920 V7.0.1 (2000-01)
1 Scope
Bearer and Teleservices, as respectively defined in GSM 02.02 and GSM 02.03, are the objects which the GSM PLMN
operators offer to their customers. Besides these basic telecommunications services, features which aim at up-grading
these basic services need also to be offered. Due to the use of radiocommunications in a PLMN, which are of a special
nature compared to classical distribution transmission techniques used in the fixed networks, such a category of features
is related to security aspects.
In a GSM PLMN, both the users and the network operator have to be protected against undesirable intrusion of third
parties. However, measures should be provided for in order to insure maximum protection of the rights of the
individuals concerns. As a consequence, a security feature is either a supplementary service to Tele or Bearer services,
which can be selected by the subscriber, or a network function involved in the provision of one or several
telecommunication services.
The purpose of the present document is to define the security features which are to be available in a GSM PLMN,
together with the associated levels of protection. The present document is only concerned with those security features
which aim at the up-grading of the security in a GSM PLMN. In particular, end-to-end security is outside the scope of
the present document.
The implementation aspects of security features are described in GSM 03.20.
1.1 References
The following documents contain provisions which, through reference in this text, constitute provisions of the present
document.
• References are either specific (identified by date of publication, edition number, version number, etc.) or
non-specific.
• For a specific reference, subsequent revisions do not apply.
• For a non-specific reference, the latest version applies.
• A non-specific reference to an ETS shall also be taken to refer to later versions published as an EN with the same
number.
• For this Release 1998 document, references to GSM documents are for Release 1998 versions (version 7.x.y).
[1] GSM 01.04: "Digital cellular telecommunications system (Phase 2+); Abbreviations and
acronyms".
[2] GSM 02.02: "Digital cellular telecommunications system (Phase 2+); Bearer Services (BS)
supported by a GSM Public Land Mobile Network (PLMN)".
[3] GSM 02.03: "Digital cellular telecommunications system (Phase 2+); Teleservices supported by a
GSM Public Land Mobile Network (PLMN)".
[4] GSM 03.20: "Digital cellular telecommunications system (Phase 2+); Security related network
fun
...