SIST ETS 300 391-2 E1:2003
(Main)Universal Personal Telecommunication (UPT); Specification of the security architecture for UPT phase 1; Part 2: Implementation Conformance Statement (ICS) proforma specification
- Abstract
ICS for ETS 300 391-1
- Status
- Published
- Publication Date
- 30-Nov-2003
- Current Stage
- 6060 - National Implementation/Publication (Adopted Project)
- Start Date
- 01-Dec-2003
- Due Date
- 01-Dec-2003
- Completion Date
- 01-Dec-2003
SIST ETS 300 391-2 E1:2003 is the Slovenian adoption of ETS 300 391-2 Edition 1 from ETSI. It provides Implementation Conformance Statement (ICS) proformas for the security architecture of UPT phase 1, covering the advanced Dual Tone Multi Frequency (DTMF) device and the Authenticating Entity (AE). Suppliers, implementors, test laboratories, and UPT service providers use it to declare and check conformance to ETS 300 391-1.
What does SIST ETS 300 391-2 E1:2003 specify?
SIST ETS 300 391-2 E1:2003 specifies the ICS proformas that support conformance assessment for the UPT phase 1 security architecture. The document is focused on the advanced DTMF device and the AE used in authentication procedures.
The main structure is:
| Clause | What it covers |
|---|---|
| 1 | Scope for the ICS proformas |
| 2 | Normative references |
| 3 | Symbols and abbreviations |
| 4 | Conformance rules for suppliers |
| 5 | ICS proforma for advanced DTMF devices |
| 6 | ICS proforma for the AE |
The content is organized as checklists and tables that let a supplier state which functions are implemented and let a reader compare those claims with ETS 300 391-1.
What are the key requirements of SIST ETS 300 391-2 E1:2003?
SIST ETS 300 391-2 E1:2003 is a conformance questionnaire, but it still sets out the practical points that an implementation has to declare. The key requirement is that a supplier claiming conformance to ETS 300 391-1 must complete the relevant ICS proforma and identify the implementation and responsible contacts.
Conformance statement and identification
Clause 4 requires a supplier of an advanced DTMF device or an AE to complete the relevant ICS proforma. Clause 5.1 and 6.1 require identification of the implementation, the supplier or test laboratory client, and a contact person. In practice, this gives the conformance claim a clear owner and makes follow-up possible during procurement or testing.
Clause 5.3 and 6.3 require a global Yes/No statement on whether the implementation meets all mandatory requirements. If the answer is No, the unsupported mandatory capabilities must be identified and explained. That matters because the document is not just a checklist - it also records where an implementation falls short.
Advanced DTMF device
Tables 1 to 5 cover the advanced DTMF device. They ask whether sensitive information is protected in a Security Module (SM), whether Device Holder Verification (DHV) is implemented when the service provider does not perform DHV centrally, and whether the device has an authentication algorithm. In practice, these items tell a buyer or test lab where secrets are stored and who performs the local verification step.
The device proforma also checks authentication processing: the Authentication Code (AC) is derived from the authentication key and n, n is derived from n_s, n is incremented for each authentication process, and the output is sent as DTMF tones. Table 5 records which authentication algorithm family is supported - the UPT algorithm, TESA 7, or a proprietary algorithm. This is the part that shows how the device actually carries out the authentication exchange.
Authenticating Entity
Tables 6 to 8 cover the AE. The AE may support weak authentication, strong authentication, or both, and it also checks blacklisted Personal User Identities (PUIs). For weak authentication, the tables cover PIN length, PIN change, blocking after incorrect PIN entries, optional use of a Special Personal Identification Number (SPIN), and optional limits on unblocking attempts. For strong authentication, the AE checks the allowed range of n_s, compares AC' with AC, and updates n' after successful authentication. In practice, this is the section that shows how the network-side authentication logic is implemented and controlled.
What terms does SIST ETS 300 391-2 E1:2003 define?
SIST ETS 300 391-2 E1:2003 defines the symbols and abbreviations used in the ICS proformas. The most important ones are:
- Authentication Code (AC) - the code calculated in the UPT access device for the authentication process.
- Authentication Code (AC') - the code calculated in the AE for comparison with the received code.
- Authenticating Entity (AE) - the network-side entity that performs or supports authentication checks.
- Dual Tone Multi Frequency (DTMF) - the tone method used by the device to produce the authentication output.
- Device Holder Verification (DHV) - the verification step that confirms the device holder before authentication.
- Personal User Identity (PUI) - the identity that may be blocked after repeated incorrect PIN entries.
- Remaining Authentication Attempts (RAA) - the counter used to track how many incorrect attempts remain.
- Security Module (SM) - the module in the DTMF device that holds protected authentication material.
- Local Personal Identification Number (LPIN) - the PIN used when DHV is performed locally in the device.
- Special Personal Identification Number (SPIN) - the special PIN used to disable blocking in weak authentication.
Who uses SIST ETS 300 391-2 E1:2003?
SIST ETS 300 391-2 E1:2003 is used by UPT service providers, suppliers of advanced DTMF devices, suppliers of AEs, and test laboratories. They use it when preparing a conformance claim, completing an ICS, or checking whether a product meets the security architecture in ETS 300 391-1.
Quality and procurement teams use it to compare declared features such as DHV, PIN handling, sequence-number checks, key storage, and authentication algorithm support. That helps them check both the technical function and the scope of the supplier’s claim.
Which standards are used with SIST ETS 300 391-2 E1:2003?
| Standard or part | What it contributes |
|---|---|
| ETS 300 391-1 | The security architecture specification for UPT phase 1 that the ICS proformas apply to |
| ISO/IEC 9646-2 | The conformance testing methodology and framework that the ETS follows |
| ETS 300 391-3 | The Conformance Test Specification part of the same ETS series |
| ETS 300 391-1 Part 1 | The specification part named in the foreword as the first part of the series |
What does the SIST ETS 300 391-2 E1:2003 document contain?
The document contains two ICS proformas: one for advanced DTMF devices and one for the AE. Each proforma includes identification fields, a standard identification section, a global conformance statement, and feature tables that map back to ETS 300 391-1 references.
Tables 1 to 5 cover the advanced DTMF device, including the Security Module, local DHV, the authentication process, and supported authentication algorithms. Tables 6 to 8 cover the AE, including weak authentication, strong authentication, and blacklisted PUI checking. The result is a structured checklist that supports supplier declarations, laboratory review, and conformance audits.
Get Certified
Connect with accredited certification bodies for this standard

ANCE
Mexican certification and testing association.

Intertek Slovenia
Intertek testing, inspection, and certification services in Slovenia.
LNE (Laboratoire National de Métrologie et d'Essais)
French national laboratory for metrology and testing.
Sponsored listings
Frequently Asked Questions
SIST ETS 300 391-2 E1:2003 is a standard published by the Slovenian Institute for Standardization (SIST). Its full title is "Universal Personal Telecommunication (UPT); Specification of the security architecture for UPT phase 1; Part 2: Implementation Conformance Statement (ICS) proforma specification". This standard covers: ICS for ETS 300 391-1
ICS for ETS 300 391-1
SIST ETS 300 391-2 E1:2003 is classified under the following ICS (International Classification for Standards) categories: 33.040.35 - Telephone networks. The ICS classification helps identify the subject area and facilitates finding related standards.
SIST ETS 300 391-2 E1:2003 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
SLOVENSKI STANDARD
01-december-2003
Svetovne osebne telekomunikacije (UPT) – Specifikacija varnostne arhitekture za
1. fazo sistema UPT – 2. del: Proformi izjave o skladnosti izvedbe (ICS)
Universal Personal Telecommunication (UPT); Specification of the security architecture
for UPT phase 1; Part 2: Implementation Conformance Statement (ICS) proforma
specification
Ta slovenski standard je istoveten z: ETS 300 391-2 Edition 1
ICS:
33.040.35 Telefonska omrežja Telephone networks
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.
EUROPEAN ETS 300 391-2
TELECOMMUNICATION August 1995
STANDARD
Source: ETSI TC-NA Reference: DE/NA-071404
ICS: 33.040
Authentication, DTMF, UPT
Key words:
Universal Personal Telecommunication (UPT);
Specification of the security architecture for UPT phase 1;
Part 2: Implementation Conformance Statement (ICS) proformas
ETSI
European Telecommunications Standards Institute
ETSI Secretariat
F-06921 Sophia Antipolis CEDEX - FRANCE
Postal address:
650 Route des Lucioles - Sophia Antipolis - Valbonne - FRANCE
Office address:
c=fr, a=atlas, p=etsi, s=secretariat - secretariat@etsi.fr
X.400: Internet:
Tel.: +33 92 94 42 00 - Fax: +33 93 65 47 16
Copyright Notification: No part may be reproduced except as authorized by written permission. The copyright and the
foregoing restriction extend to reproduction in all media.
© European Telecommunications Standards Institute 1995. All rights reserved.
New presentation - see History box
Page 2
ETS 300 391-2: August 1995
Whilst every care has been taken in the preparation and publication of this document, errors in content,
typographical or otherwise, may occur. If you have comments concerning its accuracy, please write to
"ETSI Editing and Committee Support Dept." at the address shown on the title page.
Page 3
ETS 300 391-2: August 1995
Contents
Foreword .5
Introduction.5
1 Scope .7
2 Normative references.7
3 Symbols and abbreviations .7
4 Conformance.7
5 ICS proforma for advanced DTMF devices.8
5.1 Identification of the implementation, product supplier and test laboratory client .8
5.2 Identification of the standard.8
5.3 Global statement of conformance.8
5.4 Main features .8
6 ICS proforma for the AE.10
6.1 Identification of the implementation, product supplier and test laboratory client .10
6.2 Identification of the standard.10
6.3 Global statement of conformance.10
6.4 Main features .11
History.12
Page 4
ETS 300 391-2: August 1995
Blank page
Page 5
ETS 300 391-2: August 1995
Foreword
This European Telecommunication Standard (ETS) has been produced by the Network Aspects (NA)
Technical Committee of the European Telecommunications Standards Institute (ETSI).
This ETS consists of 3 parts as follows:
Part 1: "Specification".
Part 2: "Implementation Conformance Statement (ICS) proformas".
Part 3: "Conformance Test Specification (CTS)".
Transposition dates
Date of adoption of this ETS: 28 July 1995
Date of latest announcement of this ETS (doa): 30 November 1995
Date of latest publication of new National Standard
or endorsement of this ETS (dop/e): 31 May 1996
Date of withdrawal of any conflicting National Standard (dow): 31 May 1996
Introduction
To evaluate conformance of a particular implementation, it is necessary to have a statement of which
capabilities and options have been implemented. Such a statement is called an Implementation
Conformance Statement (ICS).
Page 6
ETS 300 391-2: August 1995
Blank page
Page 7
ETS 300 391-2: August 1995
1 Scope
This European Telecommunication Standard (ETS) provides the Implementation Conformance Statement
(ICS) proformas for the advanced Dual Tone Multi Frequency (DTMF) device and the Authenticating Entity
(AE) specified in ETS 300 391-1 [1]. These components relate to the authentication procedures of UPT
phase 1. They are the most relevant components for interoperability and the overall security.
This ETS allows either the service provider of a UPT system to formulate the requirements on these
implementations or to decide whether an implementation meets these requirements. It details the in
tabular form mandatory and optional functions for these implementations.
This ETS is in compliance with the relevant requirements and the guidelines given in ISO/IEC 9646-2 [2].
2 Normative references
This ETS incorporates by dated and undated reference, provisions from other publications. These
normative references are cited at the appropriate places in the text and the publications are listed
hereafter. For dated references, subsequent amendments to or revisions of any of these publications
apply to this ETS only when incorporated in it by amendment or revision. For undated references the latest
edition of the publication referred to applies.
[1] ETS 300 391-1: "Universal Personal Telecommunications (UPT); Specification
of the security architecture for UPT Phase 1; Part 1: Specification".
[2] ISO/IEC 9646-2: "Conformance testing methodology and f
...



