General Information

Abstract

To update the standard in light of discovered shortcomings and to realign with update of ETS 300 392-2.

Status
Published
Publication Date
30-Nov-2003
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
01-Dec-2003
Due Date
01-Dec-2003
Completion Date
01-Dec-2003

Buy Documents

Standard

SIST EN 300 392-7 V2.1.1:2003

English language (153 pages)
Preview
Preview
e-Library read for
×1 day

Overview

SIST EN 300 392-7 V2.1.1:2003 is a Slovenian national adaptation of the European standard for Terrestrial Trunked Radio (TETRA); Voice plus Data (V+D); Part 7: Security. Published by the Slovenski inštitut za standardizacijo (SIST), this standard defines the security requirements, procedures, and mechanisms for TETRA systems handling both voice and data communication.

The purpose of this standard is to address identified security shortcomings in prior versions and to align with the updated ETS 300 392-2. It supports organizations seeking robust and interoperable TETRA security solutions across mission-critical public safety, transportation, utilities, and related sectors.


Key Topics

  • Security Classes: Classification of various security levels and their specific features within TETRA systems.
  • Authentication Mechanisms: Procedures for authenticating both users and infrastructure, including mutual authentication and key management on the air interface.
  • Key Management: Detailed methods for key generation, distribution (including Over-The-Air Rekeying, OTAR), and lifecycle management (update, association, and revocation of cipher keys).
  • Enable/Disable Mechanisms: Protocols for remotely enabling or disabling TETRA mobile terminals and subscriptions for enhanced operational security.
  • Air Interface and End-to-End Encryption: Application of encryption at multiple levels, from the radio interface to end-to-end protection for both voice and data streams.
  • Security Protocols and Primitives: Definitions of messages and procedures used during authentication, encryption, key changes, and other security-related operations.

Applications

The SIST EN 300 392-7 V2.1.1:2003 standard is crucial in sectors where secure and reliable communications are essential. Examples of practical applications include:

  • Public Safety Networks: Ensuring confidentiality and integrity for police, fire, and emergency services communication.
  • Transportation: Securing operational communications for railways, airports, and public transit authorities.
  • Utilities: Protecting sensitive voice and data exchanges relating to energy and water distribution.
  • Industrial Environments: Supporting secure group communication in oil, gas, and critical infrastructure.
  • Government and Defense: Facilitating mission-critical, encrypted communications in secure government operations.

By implementing this standard, organizations can ensure compliance with European TETRA requirements, reduce the risk of eavesdropping and unauthorized access, and maintain operational continuity during security events.


Related Standards

To ensure comprehensive interoperability and regulatory compliance, consider these related standards:

  • ETS 300 392-2: TETRA; Voice plus Data (V+D); Part 2: Air Interface (main reference for alignment and updates in Part 7).
  • SIST EN 300 392-1: TETRA; Voice plus Data; Part 1: General network and service description.
  • SIST EN 300 392-3: TETRA; Interworking at the interfaces.
  • EN 102 361-1 Series: General framework and additional requirements for secure radio communications.

Staying current with updates and revisions to these standards is essential for effective and secure deployment of TETRA systems in accordance with European and national regulations.


Keywords: TETRA, terrestrial trunked radio, security, authentication, encryption, key management, OTAR, public safety communications, mission-critical radio, transport security standards, SIST EN 300 392-7 V2.1.1:2003.

Buy Documents

Standard

SIST EN 300 392-7 V2.1.1:2003

English language (153 pages)
Preview
Preview
e-Library read for
×1 day

Get Certified

Connect with accredited certification bodies for this standard

ANCE

Mexican certification and testing association.

EMA Mexico Verified

Intertek Slovenia

Intertek testing, inspection, and certification services in Slovenia.

UKAS Slovenia Verified

LNE (Laboratoire National de Métrologie et d'Essais)

French national laboratory for metrology and testing.

COFRAC France Verified

Sponsored listings

Frequently Asked Questions

SIST EN 300 392-7 V2.1.1:2003 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Terrestrial Trunked Radio (TETRA); Voice plus Data (V+D); Part 7: Security". This standard covers: To update the standard in light of discovered shortcomings and to realign with update of ETS 300 392-2.

To update the standard in light of discovered shortcomings and to realign with update of ETS 300 392-2.

SIST EN 300 392-7 V2.1.1:2003 is classified under the following ICS (International Classification for Standards) categories: 33.070.10 - Terrestrial Trunked Radio (TETRA). The ICS classification helps identify the subject area and facilitates finding related standards.

SIST EN 300 392-7 V2.1.1:2003 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.Prizemni snopovni radio (TETRA) – Govor in podatki (V+D) – 7. del: VarnostTerrestrial Trunked Radio (TETRA); Voice plus Data (V+D); Part 7: Security33.070.10Prizemni snopovni radio (TETRA)Terrestrial Trunked Radio (TETRA)ICS:Ta slovenski standard je istoveten z:EN 300 392-7 Version 2.1.1SIST EN 300 392-7 V2.1.1:2003en01-december-2003SIST EN 300 392-7 V2.1.1:2003SLOVENSKI
STANDARD
ETSIEN300392-7V2.1.1(2001-02)EuropeanStandard(Telecommunicationsseries)TerrestrialTrunkedRadio(TETRA);VoiceplusData(V+D);Part7:SecuritySIST EN 300 392-7 V2.1.1:2003

ETSIETSIEN300392-7V2.1.1(2001-02)2ReferenceREN/TETRA-06001-7KeywordsTETRA,V+D,SecurityETSI650RoutedesLuciolesF-06921SophiaAntipolisCedex-FRANCETel.:+33492944200Fax:+33493654716SiretN°34862356200017-NAF742CAssociationàbutnonlucratifenregistréeàlaSous-PréfecturedeGrasse(06)N°7803/88ImportantnoticeIndividualcopiesofthepresentdocumentcanbedownloadedfrom:http://www.etsi.orgThepresentdocumentmaybemadeavailableinmorethanoneelectronicversionorinprint.Inanycaseofexistingorperceiveddifferenceincontentsbetweensuchversions,thereferenceversionisthePortableDocumentFormat(PDF).Incaseofdispute,thereferenceshallbetheprintingonETSIprintersofthePDFversionkeptonaspecificnetworkdrivewithinETSISecretariat.Usersofthepresentdocumentshouldbeawarethatthedocumentmaybesubjecttorevisionorchangeofstatus.InformationonthecurrentstatusofthisandotherETSIdocumentsisavailableathttp://www.etsi.org/tb/status/Ifyoufinderrorsinthepresentdocument,sendyourcommentto:editor@etsi.frCopyrightNotificationNopartmaybereproducedexceptasauthorizedbywrittenpermission.Thecopyrightandtheforegoingrestrictionextendtoreproductioninallmedia.©EuropeanTelecommunicationsStandardsInstitute2001.Allrightsreserved.SIST EN 300 392-7 V2.1.1:2003

ETSIETSIEN300392-7V2.1.1(2001-02)3ContentsIntellectualPropertyRights.9Foreword.91Scope.101.1Securityclasses.101.2Documentlayout.102References.113Definitions,symbolsandabbreviations.123.1Definitions.123.2Abbreviations.144AirInterfaceauthenticationandkeymanagementmechanisms.164.1Airinterfaceauthenticationmechanisms.164.1.1Overview.164.1.2Authenticationofauser.164.1.3Authenticationoftheinfrastructure.174.1.4Mutualauthenticationofuserandinfrastructure.184.1.5Theauthenticationkey.204.1.5.1MakingKavailableinanMS.214.1.6Equipmentauthentication.214.2AirInterfacekeymanagementmechanisms.214.2.1TheDCK.224.2.2TheGCK.224.2.3TheCCK.234.2.4TheSCK.244.2.5TheGSKO.254.2.5.1SCKdistributiontogroupswithOTAR.264.2.5.2GCKdistributiontogroupswithOTAR.264.2.6EncryptedShortIdentity(ESI)mechanism.264.2.7EncryptionCipherKey.274.2.8SummaryofAIkeymanagementmechanisms.284.3Servicedescriptionandprimitives.294.3.1Authenticationprimitives.294.3.2SCKtransferprimitives.304.3.3GCKtransferprimitives.304.3.4GSKOtransferprimitives.314.4Authenticationprotocol.324.4.1Authenticationstatetransitions.324.4.1.1Descriptionofauthenticationstates.354.4.2Authenticationprotocolsequencesandoperations.354.4.2.1MSCsforauthentication.364.4.2.2MSCsforauthenticationType-3element.424.4.2.3ControlofauthenticationtimerT354atMS.464.5OTARProtocols.474.5.1CCKdelivery-protocolfunctions.474.5.1.1SwMI-initiatedCCKprovision.484.5.1.2MS-initiatedCCKprovisionwithU-OTARCCKDemand.494.5.1.3MS-initiatedCCKprovisionwithannouncedcellreselection.504.5.2OTARprotocolfunctions-SCK.504.5.2.1MSrequestsprovisionofSCK(s).514.5.2.2SwMIprovidesSCK(s)toindividualMS.524.5.2.3SwMIprovidesSCK(s)togroupofMSs.534.5.3OTARprotocolfunctions-GCK.544.5.3.1MSrequestsprovisionofGCK.554.5.3.2SwMIprovidesGCKtoanindividualMS.564.5.3.3SwMIprovidesGCKtoagroupofMSs.57SIST EN 300 392-7 V2.1.1:2003

ETSIETSIEN300392-7V2.1.1(2001-02)44.5.4Cipherkeyassociationtogroupaddress.594.5.4.1SCKassociationforDMO.594.5.4.2GCKassociation.604.5.5Notificationofkeychangeovertheair.614.5.5.1ChangeofDCK.634.5.5.2ChangeofCCK.634.5.5.3ChangeofGCK.634.5.5.4ChangeofSCKforTMO.634.5.5.5ChangeofSCKforDMO.634.5.5.6SynchronizationofCipherKeyChange.644.5.6Securityclasschange.644.5.6.1Changeofsecurityclasstosecurityclass1.644.5.6.2Changeofsecurityclasstosecurityclass2.644.5.6.3Changeofsecurityclasstosecurityclass3.655Enableanddisablemechanism.665.1Generalrelationships.665.2Enable/disablestatetransitions.665.3Mechanisms.675.3.1DisableofMSequipment.685.3.2DisableofMSsubscription.685.3.3DisableanMSsubscriptionandequipment.685.3.4EnableanMSequipment.685.3.5EnableanMSsubscription.685.3.6EnableanMSequipmentandsubscription.685.4Enable/disableprotocol.695.4.1Generalcase.695.4.2Statusofcipherkeymaterial.695.4.3Specificprotocolexchanges.695.4.3.1DisablinganMSwithauthentication.705.4.3.2EnablinganMSwithauthentication.715.4.4EnablinganMSwithoutauthentication.725.4.5DisablinganMSwithoutauthentication.735.4.6Rejectionofenableordisablecommand.735.4.7MMserviceprimitives.745.4.7.1TNMM-DISABLINGprimitive.745.4.7.2TNMM-ENABLINGprimitive.756AirInterface(AI)encryption.766.1Generalprinciples.766.2Securityclass.776.2.1ConstraintsonLAarisingfromcellclass.786.3KeyStreamGenerator(KSG).786.3.1KSGnumberingandselection.796.3.2Interfaceparameters.796.3.2.1InitialValue(IV).796.3.2.2CipherKey.806.4Encryptionmechanism.806.4.1AllocationofKSStologicalchannels.816.4.2AllocationofKSStologicalchannelswithPDUassociation.816.4.3Synchronizationofdatacallswheredataismulti-slotinterleaved.836.4.4Recoveryofstolenframesfrominterleaveddata.836.5Useofcipherkeys.846.5.1IdentificationofencryptionstateofdownlinkMACPDUs.856.5.1.1Class1cells.856.5.1.2Class2cells.856.5.1.3Class3cells.856.5.2IdentificationofencryptionstateofuplinkMACPDUs.866.6Mobilityprocedures.866.6.1Generalrequirements.866.6.1.1Additionalrequirementsforclass3systems.866.6.2Protocoldescription.86SIST EN 300 392-7 V2.1.1:2003

ETSIETSIEN300392-7V2.1.1(2001-02)56.6.2.1Negotiationofcipherparameters.876.6.2.1.1Class1cells.876.6.2.1.2Class2cells.876.6.2.1.3Class3cells.876.6.2.2Initialandundeclaredcellre-selection.876.6.2.3Unannouncedcellre-selection.896.6.2.4Announcedcellre-selectiontype-3.896.6.2.5Announcedcellre-selectiontype-2.896.6.2.6Announcedcellre-selectiontype-1.906.6.2.7Keyforwarding.906.7Encryptioncontrol.926.7.1Datatobeencrypted.926.7.1.1Downlinkcontrolchannelrequirements.926.7.1.2EncryptionofMACheaderelements.926.7.1.3Trafficchannelencryptioncontrol.926.7.2Servicedescriptionandprimitives.936.7.2.1MobilityManagement(MM).946.7.2.2MobileLinkEntity(MLE).946.7.2.3Layer2.966.7.3Protocolfunctions.966.7.3.1MM.966.7.3.2MLE.966.7.3.3LLC.966.7.3.4MAC.966.7.4PDUsforciphernegotiation.977End-to-endencryption.977.1Introduction.977.2Voiceencryptionanddecryptionmechanism.987.2.1Protectionagainstreplay.997.3Dataencryptionmechanism.997.4Exchangeofinformationbetweenencryptionunits.997.4.1Synchronizationofencryptionunits.997.4.2Encryptedinformationbetweenencryptionunits.1007.4.3Transmission.1017.4.4Reception.1037.4.5Stolenframeformat.1037.5Locationofsecuritycomponentsinthefunctionalarchitecture.1047.6End-to-endKeyManagement.106AnnexA(normative):PDUandelementdefinitions.107A.1AuthenticationPDUs.107A.1.1D-AUTHENTICATIONDEMAND.107A.1.2D-AUTHENTICATIONREJECT.107A.1.3D-AUTHENTICATIONRESPONSE.108A.1.4D-AUTHENTICATIONRESULT.108A.1.5U-AUTHENTICATIONDEMAND.108A.1.6U-AUTHENTICATIONREJECT.109A.1.7U-AUTHENTICATIONRESPONSE.109A.1.8U-AUTHENTICATIONRESULT.110A.2OTARPDUs.110A.2.1D-OTARCCKProvide.110A.2.2U-OTARCCKDemand.110A.2.3U-OTARCCKResult.111A.2.4D-OTARGCKProvide.111A.2.5U-OTARGCKDemand.112A.2.6U-OTARGCKResult.112A.2.7D-OTARSCKProvide.113A.2.8U-OTARSCKDemand.113A.2.9U-OTARSCKResult.114A.2.10D-OTARGSKOProvide.114SIST EN 300 392-7 V2.1.1:2003

ETSIETSIEN300392-7V2.1.1(2001-02)6A.2.11U-OTARGSKODemand.114A.2.12U-OTARGSKOResult.115A.3PDUsforkeyassociationtoGTSI.115A.3.1D-OTARKEYASSOCIATEDEMAND.115A.3.2U-OTARKEYASSOCIATESTATUS.116A.4PDUstosynchronisekeyorsecurityclasschange.116A.4.1D-CKCHANGEDEMAND.116A.4.2U-CKCHANGERESULT.117A.5OthersecuritydomainPDUs.118A.5.1U-TEIPROVIDE.118A.5.2U-OTARPREPARE.118A.5.3D-OTARNEWCELL.119A.6PDUsforEnableandDisable.119A.6.1D-DISABLE.119A.6.2D-ENABLE.120A.6.3U-DISABLESTATUS.120A.7MMPDUtype3informationelementscoding.121A.7.1Authenticationdownlink.121A.7.2Authenticationuplink.121A.8PDUInformationelementscoding.122A.8.1Acknowledgementflag.122A.8.2Addressextension.122A.8.3Authenticationchallenge.122A.8.4Authenticationrejectreason.122A.8.5Authenticationresult.122A.8.6Authenticationsub-type.123A.8.7CCKidentifier.123A.8.8CCKinformation.123A.8.9CCKLocationareainformation.123A.8.10CCKrequestflag.124A.8.11Changeofsecurityclass.124A.8.12Cipherparameters.124A.8.13CKprovisionflag.124A.8.14CKprovisioninginformation.125A.8.15CKrequestflag.125A.8.16ClassChangeflag.125A.8.17DCKforwardingresult.125A.8.18Disablingtype.125A.8.19Enable/Disableresult.126A.8.20Encryptionmode.126A.8.20.1Class1cells.126A.8.20.2Class2cells.126A.8.20.3Class3cells.127A.8.21Equipmentdisable.127A.8.22Equipmentenable.127A.8.23Equipmentstatus.127A.8.24Framenumber.127A.8.25Futurekeyflag.128A.8.26GCKdata.128A.8.27GCKkeyandidentifier.128A.8.28GCKNumber(GCKN).128A.8.29GCKselectnumber.128A.8.30GCKVersionNumber(GCK-VN).129A.8.31Groupassociation.129A.8.32GSKOVersionNumber(GSKO-VN).129A.8.33GSSI.129A.8.34Hyperframenumber.129A.8.35Intent/confirm.129SIST EN 300 392-7 V2.1.1:2003

ETSIETSIEN300392-7V2.1.1(2001-02)7A.8.36IV.130A.8.37Keyassociationstatus.130A.8.38Keyassociationtype.130A.8.39Keychangetype.131A.8.40Keytypeflag.131A.8.41KSG-number.131A.8.42Locationarea.131A.8.43Locationareabitmask.131A.8.44Locationareaselector.132A.8.45Locationarealist.132A.8.46Locationarearange.132A.8.47Mobilecountrycode.132A.8.48Mobilenetworkcode.132A.8.49Multiframenumber.132A.8.50Mutualauthenticationflag.133A.8.51Networktime.133A.8.52NumberofGCKschanged.133A.8.53Numberofgroups.133A.8.54Numberoflocationareas.133A.8.55NumberofSCKschanged.134A.8.56NumberofSCKsprovided.134A.8.57NumberofSCKsrequested.134A.8.58OTARsub-type.135A.8.59PDUtype.135A.8.60Proprietary.136A.8.61Provisionresult.136A.8.62Randomchallenge.136A.8.63Randomseed.136A.8.64RandomseedforOTAR.136A.8.65Rejectcause.137A.8.66Responsevalue.137A.8.67SCKdata.137A.8.68SCKinformation.137A.8.69SCKkeyandidentifier.138A.8.70SCKnumber(SCKN).138A.8.71SCKnumberandresult.138A.8.72SCKprovisionflag.138A.8.73SCKselectnumber.139A.8.74SCKuse.139A.8.75SCKversionnumber.139A.8.76SealedKey(SealedCCK,SealedSCK,SealedGCK,SealedGSKO).139A.8.77Securityinformationelement.140A.8.78Sessionkey.140A.8.79SlotNumber.140A.8.80SSI.140A.8.81Subscriptiondisable.141A.8.82Subscriptionenable.141A.8.83Subscriptionstatus.141A.8.84TEI.141A.8.85TEIrequestflag.142A.8.86Timetype.142A.8.87Type3elementidentifier.142SIST EN 300 392-7 V2.1.1:2003

ETSIETSIEN300392-7V2.1.1(2001-02)8AnnexB(normative):Boundaryconditionsforthecryptographicalgorithmsandprocedures.143B.1Dimensioningofthecryptographicparameters.148B.2Summaryofthecryptographicprocesses.149AnnexC(normative):Timers.151C.1T354,authorisationprotocoltimer.151C.2T371,DelaytimerforgroupaddresseddeliveryofSCKandGCK.151C.3T372,Keyforwardingtimer.151AnnexD(informative):Bibliography.152History.153SIST EN 300 392-7 V2.1.1:2003

ETSIETSIEN300392-7V2.1.1(2001-02)9I
...