World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS ANFOV - Milano, 14 November 2007 Autore:Paolo DE LUTIIS Telecom Italia Security.

Slides:



Advertisements
Similar presentations
Potential Smart Grid standardisation work in ETSI Security and privacy aspects Carmine Rizzo on behalf of Scott CADZOW, C3L © ETSI All rights reserved.
Advertisements

World Class Standards 1 SCP(11)0001 SCP Plenary #47 January 12-14, 2011 Title*: Update on TC M2M activities (and Smart Metering Mandate) Submitted by:
U M T S F o r u m © UMTS 2002 UMTS Security aspects UMTS Forum ICTG Chair Bosco Fernandes Siemens AG
Internet Protocol Security (IP Sec)
D1 - 16/05/2014 Le présent document contient des informations qui sont la propriété de France Télécom. L'acceptation de ce document par son destinataire.
22-23 June 2004TISPAN-3GPP Workshop - Sophia-Antipolis 1 TISPAN NGN Architecture Overview Richard Brennan pulver.com, WG2 Chair
LTE Security. Agenda Intro … Intro … The LTE System Radio Side (LTE – Long Term Evolution/Evolved UTRAN - EUTRAN) – Improvements in spectral efficiency,
SIP and IMS Enabled Residential Gateway Sergio Romero Telefónica I+D Jan Önnegren Ericsson AB Alex De Smedt Thomson Telecom.
Omniran GPP Trusted WLAN Access to EPC Use Case Analysis Date: Authors: NameAffiliationPhone Max RiegelNSN
D1 - 12/05/2015 The present document contains information that remains the property of France Telecom. The recipient’s acceptance of this document implies.
IP Multimedia Subsystem (IMS) 江培文. Agenda Background IMS Definition IMS Architecture IMS Entities IMS-CS Interworking.
1 Network Architecture and Design Advanced Issues in Internet Protocol (IP) IPv4 Network Address Translation (NAT) IPV6 IP Security (IPsec) Mobile IP IP.
Presents H.323 Forum ETSI TIPHON Presented by: Richard Brennan - Telxxis LLC Vice-Chair ETSI-TIPHON.
Lawful Interception in 3G IP Multimedia Subsystem
6 The IP Multimedia Subsystem Selected Topics in Information Security – Bazara Barry.
SIP and the application of SIP as used in 3GPP Keith Drage - Lucent Technologies.
1 © NOKIA MitM.PPT/ 6/2/2015 / Kaisa Nyberg (NRC/MNW), N.Asokan (NRC/COM) The Insecurity of Tunnelled Authentication Protocols N. ASOKAN, VALTTERI NIEMI,
SIP roaming solution amongst different WLAN-based service providers Julián F. Gutiérrez 1, Alessandro Ordine 1, Luca Veltri 2 1 DIE, University of Rome.
1 © NOKIA MitM.PPT/ 6/2/2015 / Kaisa Nyberg (NRC/MNW), N.Asokan (NRC/COM) The Insecurity of Tunnelled Authentication Protocols N. ASOKAN, VALTTERI NIEMI,
Doc.: IEEE /0408r0 Submission March 2004 Colin Blanchard, BTSlide 1 3GPP WLAN Interworking Security Colin Blanchard British Telecommunications.
SIPPING IETF51 3GPP Security and Authentication Peter Howard 3GPP SA3 (Security) delegate
Internet Protocol Security (IPSec)
LTE roaming – a whole new world Acme Packet 3 Session Border Control (SBC) category creator and leader with over 60% market share Mission: enable delivery.
Issues of HIP in an Operators Network Nick Papadoglou Thomas Dietz.
World Class Standards Update on NGN Standards ETSI TISPAN Sonia Compans ETSI Technical Officer February 2009.
Report of ETSI NGN IPTV activities Rainer Münch, TISPAN Chairman Presenter: Ian Spiers DOCUMENT #:GSC13-PLEN-56 FOR:Presentation SOURCE:Rainer Münch, Ian.
Interworking Architecture Between 3GPP and WLAN Systems 張憲忠, 何建民, 黃瑞銘, 紀嘉雄, 李有傑.
21-07-xxxx IEEE MEDIA INDEPENDENT HANDOVER DCN: Title: MIH Protocol Security Date Submitted: December, 2007 Presented.
ATIS & TISPAN JOINT MEETING ON NGN Washington D.C., 1 April 2005 MEETING SUMMARY Draft v2 (4 April 2005) Based on Notes from David Boswarthick (ETSI),
22-23 June 2004TISPAN-3GPP Workshop - Sophia-Antipolis 1 Joint 3GPP & TISPAN Workshop on NGN-IMS - NGN-IMS issues handling - Alain Le Roux (France Telecom),
“Securing IP Multimedia Subsystem (IMS) infrastructures …,” M. Tsagkaropoulos UNIVERSITY OF PATRAS Department of Electrical & Computer Engineering Wireless.
Doc.: IEEE /01149r1 Submission September 2012 Slide 1 WLAN Standardization in 3GPP A Tutorial Date: Authors:
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All IPTV in ETSI Bruno Chatras, ETSI TC TISPAN Vice-Chairman Document No: GSC16-PLEN-09 Source: ETSI.
June 2006 Roles of Session Border Controllers in IMS Networks CANTO - June 2006.
World Class Standards WG8 presentation of current Subscription Management Activities TISPAN WG8 – 3GPP SA#5 Joint meeting Sophia Antipolis, May14th - 15.
Completing the Convergence Puzzle: A Survey and A Roadmap IEEE Wireless Communications ‧ June 2009 DJAMAL-EDDINE MEDDOUR, USMAN JAVAID, AND NICOLAS BIHANNIC,
2003/12/291 Security Aspects of 3G-WLAN Interworking 組別: 2 組員: 陳俊文 , 李奇勇 , 黃弘光 , 林柏均
Jun Li DHCP Option for Access Network Information draft-lijun-dhc-clf-nass-option-01.
September 28, 2006 Page 1 3GPP2 MMD Status for IMS Workshop - draft - Jack Nasielski
CP-a Emergency call stage 2 requirements - A presentation of the requirements from 3GPP TS Keith Drage.
INTRODUCTION. 1.1 Why the Internet Protocol Multimedia Subsystem 1.2 Where did it come from?
Page 1 January 16, 2008 Source: 3GPP2 TSG-S WG4 (Security) Contacts: Anand Palanigounder, Chair, TSG-S WG4 ( Zhibi Wang,
11 SECURING NETWORK COMMUNICATION Chapter 9. Chapter 9: SECURING NETWORK COMMUNICATION2 OVERVIEW  List the major threats to network communications. 
All Rights Reserved © Alcatel-Lucent 2006, ##### 2G IMS CAVE Based Security Replay Protection Alec Brusilovsky, Zhibi Wang Alcatel-Lucent, July 24, 2007.
IETF67 DIME WG Towards the specification of a Diameter Resource Control Application Dong Sun IETF 67, San Diego, Nov 2006 draft-sun-dime-diameter-resource-control-requirements-00.txt.
Doc.: IEEE /209r0 Submission 1 March GPP SA2Slide 1 3GPP System – WLAN Interworking Principles and Status From 3GPP SA2 Presented.
All Rights Reserved © Alcatel-Lucent 2006, ##### 2G IMS CAVE Based Security Replay Protection Zhibi Wang January, 2007.
Deb Barclay GPP2 All IP Emergency Calls SDO Emergency Services Coordination Workshop Washington DC
1 Access Authentication to IMS Systems in Next Generation Networks Authors: Silke Holtmanns, Son Phan-Anh ICN’07 IEEE Speaker: Wen-Jen Lin.
World Class Standards Common IMS in TISPAN SA3LITISPANWG7_08_02 Scott CADZOW.
Implications of Trust Relationships for NSIS Signaling (draft-tschofenig-nsis-casp-midcom.txt) Authors: Hannes Tschofenig Henning Schulzrinne.
User Notification Protocol Nikolai Leung, QUALCOMM Incorporated (703) Notice: QUALCOMM Incorporated grants.
September 28, 2006 Page 1 3GPP2 MMD Status for IMS Workshop Jack Nasielski
1 3GPP2 IMS Charging Infrastructure Presented for 3GPP2 TSG-X by Nick Mazzarella of Lucent Technologies September 25, 2004.
1 Objectives Wireless Access IPSec Discuss Network Access Protection Install Network Access Protection.
World Class Standards SuM Functional Architecture SuM NGN OSS Service Interfaces (NOSIs) TISPAN WG8 – 3GPP SA#5 Joint meeting Sophia Antipolis, May14th.
Washinton D.C., November 2004 IETF 61 st – mip6 WG MIPv6 authorization and configuration based on EAP (draft-giaretta-mip6-authorization-eap-02) Gerardo.
November 2001 Lars Falk, TeliaSlide 1 doc.: IEEE /617r1 Submission Status of 3G Interworking Lars Falk, Telia.
1 IPSec: An Overview Dr. Rocky K. C. Chang 4 February, 2002.
Jeju, 13 – 16 May 2013Standards for Shared ICT IPTV & Content Delivery in ETSI Presenter: Chantal Bonardi ETSI Secretariat Technical Officer Document No:
Update on ETSI Cyber Security work Charles Brookson OCG Security Chairman Largely based on presentations given by Judith E. Y. Rossebø ETSI TISPAN WG7.
ETSI–3GPP NGN ACTIVITIES
ETSI–3GPP NGN ACTIVITIES
IEEE 802 OmniRAN EC SG July 2013 Conclusion
Bruno Chatras, ETSI TC TISPAN Vice-Chairman
Securing Access to Mobile Operator Core Networks using IKEv2
January doc.: IEEE xx/xxxx January 2006
Presenter: Richard Brennan, Vice-Chair TC TISPSAN
ETSI–3GPP NGN ACTIVITIES
IPTV & Content Delivery in ETSI
Presentation transcript:

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS ANFOV - Milano, 14 November 2007 Autore:Paolo DE LUTIIS Telecom Italia Security Innovation ETSI TISPAN NGN Security Presentazione per l’Osservatorio Sicurezza Anfov

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 2 Table of Contents  ETSI TISPAN: WG7 activities  TISPAN NGN overview  TISPAN NGN security:  Security areas  Network Domain Security  TISPAN IMS Security IMS-AKA NASS bundled HTTP DIGEST  Application security  TISPAN NGN Security Standards  Main technical documents  Conclusion

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS ETSI TISPAN: WG7 activities

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 4 WG7 - security  TISPAN Working Group (WG) 7 is responsible for the management and co-ordination of the development of security specifications for TC TISPAN.  For TISPAN NGN, TISPAN WG7 is responsible for:  Defining the security requirements;  Defining the security architecture for NGN;  Conducting threat and risk analyses for specific NGN use cases;  Proposing security countermeasures;  WG7 security standardization process is risk-based. The Threats, Vulnerability and Risk Analysis (TVRA) methodology has been defined specifically to address the needs of the NGN security. The TVRA is ISO15408 (Common Criteria)-based

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 5 WG7 security – Current focus (NGN rel. 2):  Fixed-mobile convergence (authentication schema coexistence)  Media security  Network Address Translation  IPTV security  Impact of unsolicited communication in the NGN environment  Identity Management  Customer Premises Network Security

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS TISPAN NGN overview

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 7 TISPAN NGN outline UMTS FTTx WiFi/WiMax xDSL PSTN / ISDN Broadcast IP Transport layer NASS RACS Service layer PES Other… User Profile Applications PSTN Other network IMS

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS TISPAN NGN security

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 9 Security areas NGN Access Security Interconnection Security Intra-Operator Security Subsystems

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 10 Security Domains  A security domain (TS ) consists of the functional entities administered by a single authority (e.g. the same operator's network). A security domain is required to:  protect the integrity and the confidentiality of its functional elements,  ensure the availability of the elements and activities under its protection.  Interdomain interfaces are protected by security gateway functions (SEGF)  SEGFs connect domains using IPsec in ESP tunnel mode with Internet Key Exchange (IKE)  The actual inter-security domain policy is not standardized and is left to the discretion of the roaming agreements of the operators

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 11 TISPAN NGN Security Domains SEGF Access Network Security Domain Visited Network Security Domain Home Network Security Domain 3Party ASP Security Domain 3Party ASP Security Domain SEGF Securty Gateway Function IPSEC tunnel

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 12 Access Security  Access domain registration involves access-level authentication and authorization procedures between the UE and the Access Network.  Fixed broadband access (and non-3GPP WLAN access) may employ different access domain registration methods based on the access network configuration and operator policy.  These solutions usually do not rely on any kind of security token. An AAA infrastructure is used for bearer-level registration.  TISPAN requirements (TS ) states that NGN shall support both the use explicit (e.g. PPP or IEEE 802.1x) and/or implicit line authentication (e.g. MAC address authentication or line authentication) of the users/subscribers at the NASS layer.

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 13 IMS Security  The IMS is independent of the transport network.  The identity of the accessing UE is checked at the edge of the IMS. The nodes in the IMS domain will trust SIP messages with asserted identity headers.  At the border of the IMS the P-CSCF is in charge of authenticate the UE and insert within each SIP request an asserted identity (token). This identity is passed between nodes in the IMS domain, with no need for further authentication.  IMS Authentication options (TS ):  Full IMS security: Authentication and Key Agreement (AKA) as defined by 3GPP (plus NAT traversal)  Early deployment scenarios: NASS bundled authentication HTTP DIGEST

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 14 IMS and call control P-CSCF I-CSCF S-CSCF P-CSCF I-CSCF S-CSCF P-CSCF I-CSCF S-CSCF Access VisitedHomeCalled UPSF DNS

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 15 UE Full IMS Security (IMS-AKA) NASS P-CSCFI/S-CFCS UPSF IMS NASS Auth. UICC User credential and secret Key IPSEC protects signalling confidentiality and integrity User profile, credential and keys NGN and UE are mutually authenticated (AKA) SIP protocol

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 16 UE NASS Bundled Authentication (NBA) NASS P-CSCFI/S-CFCS UPSF IMS NASS Auth. SIP protocol CLF NO UICC and NO IMS credential required NO IPSEC, the signalling is transmitted in the clear The authentication is one-way: only the NGN authenticates the UE User profile, no credential required

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 17 HTTP Digest (HD) UE NASS P-CSCFI/S-CFCS UPSF IMS NASS Auth. SIP Protocol NO UICC required (user credential and keys in the UE memory) Explicit authentication NO IPSEC: the signalling is transmitted in the clear User profile, credential and keys NGN and UE are mutually authenticated

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 18 Application Security (optional) UE UICC AS BSF UPSF HD over TLS GBA-u mode

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS ETSI TISPAN NGN Security Standards

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 20 Security ETSI TISPAN specifications  Main Technical Specification  NGN Security requirements (TS )  NGN Security architecture (TS )  NGN Lawful Interception functional entities, information flow and reference points (TS )  Main Technical Report (feasibility studies).  NGN Threats, Vulnerability and Risk Analysis (TVRA) (TR )  NAT traversal (TR )  Media security (TR )  Impact of unsolicited communication in the NGN (WI )  Identity Management (WI )  Data Retention (WI ) All the TISPAN activities related to the core IMS have been delegated to the 3GPP

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS Conclusions

World Class Standards ANFOV - Milano, 14 November 2007 – Paolo DE LUTIIS 22 Conclusions  NGN is divided into Security domains. Domains are considered to be trusted environment  Core or intra-domain security is mainly under the responsibility of the Operator  Inter-domain security is provided by SEGF  Access Authentication is performed on both service layer (e.g. IMS) and network attachment (NASS)  IMS-AKA (as defined by 3GPP plus NAT support) is the preferred solution for IMS authentication:  Identity and keys stored on smart card (UICC)  Mutual authentication between Network and UE (AKA)  IPSEC for the protection of the signalling only  Other authentication mechanisms (NBA, HD) have been defined for early deployment scenarios (short term solutions).