International Telecommunication Union ETSI Security Standardization Dr. Carmine Rizzo CISA, CISM, CISSP, ITIL, PRINCE2 ITU-T Workshop on “New challenges.

Slides:



Advertisements
Similar presentations
Mike Fisher, ETSI TC CLOUD Chairman ETSI TC GRID / CLOUD.
Advertisements

Potential Smart Grid standardisation work in ETSI Security and privacy aspects Carmine Rizzo on behalf of Scott CADZOW, C3L © ETSI All rights reserved.
Fostering worldwide interoperabilityGeneva, July 2009 Overview of Security work in ETSI Presenter: Mike Sharpe, VP ETSI ESP Source: Charles Brookson,
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All GTSC-9 Summary Glenn Parsons, GTSC-9 Chair, ISACC Document No: GSC16-CL-04 Source: GTSC-9 Contact:
World Class Standards Osservatorio Sicurezza ANFOV - Milano, 14 Novembre 2007 What is ETSI? Osservatorio Sicurezza Anfov Dionisio Zumerle Technical Officer.
Geneva, Switzerland, September 2014 ETSI TC Cyber Charles Brookson Chairman ETSI TC Cyber Zeata Security Ltd and Azenby Ltd ITU.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All ETSI Standardization Activities on M2M communications Joachim Koss, ETSI Board Member Document No:
ETSI Security activities Charles Brookson Chairman OCG Security Source: ETSI GTSC-1 Agenda item For: Information GSC
DOCUMENT #:GSC15-PLEN-25r1 FOR:Presentation SOURCE:TIA AGENDA ITEM:6.3 CONTACT(S):Cheryl Blum Betsy Covell
DOCUMENT #:GSC15-PLEN-37 FOR:Presentation SOURCE:ITU-T AGENDA ITEM:Plenary 6.6 Networked Vehicle Chaesub Lee and Yushi.
IETF ECRIT WG workshop 1 ETSI EMTEL (Special Committee on Emergency Communications) Producing and maintaining Standards for Emergency Communications Presented.
Geneva, Switzerland, 4 December 2014 ITU-T Study Group 17 activities in the context of digital financial services and inclusion: Security and Identity.
GLOBAL ICT STANDARDISATION FORUM FOR INDIA (GISFI) Prof. Dr. Ramjee Prasad, CTiF, Aalborg University Fellow IEEE, FIET, FIETE, FWWRF - Founding Chairman,
World Class Standards © ETSI 2007 All rights reserved ETSI Tomorrow’s World Today.
DOCUMENT #: GSC15-GTSC8-02 FOR: Presentation SOURCE: ATIS AGENDA ITEM: GTSC8; 4.1 CONTACT(S): Wayne Zeuch ATIS:
World Class Standards Update on NGN Standards ETSI TISPAN Sonia Compans ETSI Technical Officer February 2009.
DOCUMENT #: GSC15-PLEN-10 FOR:Presentation SOURCE:TIA AGENDA ITEM:4.7 TIA PSO Report to GSC-15 TIA: “Advancing Global Communications”
27/08/2015 Intelligent Transport Services ETSI activities 1GSC-9, Seoul SOURCE:ETSI (ERM TG#37) TITLE:Intelligent Transport Services – ETSI activities.
DOCUMENT #:GSC15-GTSC-05 FOR:Presentation SOURCE:ITU-T AGENDA ITEM:4.1 NGN, Testing specification and Beyond Chaesub.
Security and LI; ETSI’s role in standards
PRESENTATION OF ETSI © ETSI All rights reserved Sophia Antipolis, 22 May 2014 Luis Jorge Romero Director General, ETSI.
ATIS & TISPAN JOINT MEETING ON NGN Washington D.C., 1 April 2005 MEETING SUMMARY Draft v2 (4 April 2005) Based on Notes from David Boswarthick (ETSI),
DOCUMENT #:GSC15-PLEN-53 FOR:Presentation SOURCE:ETSI AGENDA ITEM:PLEN 6.11 CONTACT(S):Emmanuel Darmois, Board Member Marylin Arndt, TC M2M chair Smart.
ITU Regional Standardization Forum for Americas (Washington D.C., United States, 21 September 2015) The CITEL Standards Coordination Role in Bridging the.
Fostering worldwide interoperabilityGeneva, July 2009 cdma2000 ® Femto Activities Wireless access including RLANs and ad-hoc Networking Global Standards.
What is ETSI EMTEL all about Claire d’Esclercs Technical Officer for EMTEL European Telecommunications Standards Institute.
2003/12/291 Security Aspects of 3G-WLAN Interworking 組別: 2 組員: 陳俊文 , 李奇勇 , 黃弘光 , 林柏均
Third TETRA World Congress A Report on ‘TETRA Release 2’ Brian Oliver Chairman, ETSI Project TETRA.
International Telecommunication Union Committed to connecting the world ITU/EBU Workshop Accessibility to Broadcasting and IPTV ACCESS for ALL, 23 – 24.
ITU Overview Empowering global ICT development Malcolm Johnson DOCUMENT #:GSC13-XXXX-nn FOR:Presentation SOURCE:ITU AGENDA ITEM:Opening Plenary, 4.6 CONTACT(S):Malcolm.
DOCUMENT #:GSC15-PLEN-58 FOR:Presentation SOURCE:ETSI AGENDA ITEM:PLEN 6.1 CONTACT(S): Marylin Arndt, TC M2M chair M2M and Internet of Services "When the.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All Security activities in ETSI Presenter: Mike Sharpe, ETSI VP ESP (ETSI Standardization Projects) Document.
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All ETSI Conformance and Interoperability Testing Jørgen Friis VP ETSI SES (Standards Enabling Services)
25/11/2015 ITU-T NGN - Progress and Plans Brian Moore Lucent Technologies Chairman of ITU-T Study Group 13 1GSC-9, Seoul SOURCE:ITU-T TITLE:ITU-T NGN -
GSC Global Standards Collaboration GSC August – 2 September 2005 Sophia Antipolis, France August 28 – September 2, ISACC Opening Plenary Presentation.
1 Status Report on CJK NGN Working Group China Communications Standards Association 9 th CJK meeting April 2009 HeyuanXu, Chairman of NGN-WG.
ITU-T SG16 and JCA-IoT activities
International Telecommunication Union Workshop on Satellites in IP and Multimedia Geneva, 9-11 December 2002 MediaCom 2004 ITU-T Standardisation Framework.
Fostering worldwide interoperabilityGeneva, July 2009 Intelligent Transport Systems Presenter: Soeren Hess Chairman TC ITS Global Standards Collaboration.
Cybersecurity Presented by Charles Brookson OBE CEng FIET FRSA
Emergency Services Workshop, 21th-24 th of October, Vienna, Austria Page 1 IP-Based Emergency Applications and Services for Next Generation Networks PEACE.
International Telecommunication Union ITU-T Cybersecurity Symposium - Florianópolis, Brazil, 4 October 2004 Infrastructure Security: The impact on Telecommunications.
NCP Info DAY, Brussels, 23 June 2010 NCP Information Day: ICT WP Call 7 - Objective 1.3 Internet-connected Objects Alain Jaume, Deputy Head of Unit.
Update on ETSI Security work Charles Brookson OCG Security Chairman DOCUMENT #:GSC13-PLEN-57 FOR:Information SOURCE:Charles Brookson AGENDA ITEM:6.3
Introduction to 3GPP Specification & new Trends in Radio Networks
ITU-T Activities in Bridging The Standardization Gap Vijay Mauree Programme Coordinator, TSB ITU ITU Regional Standardization Forum for Asia-Pacific (Jakarta,
Jeju, 13 – 16 May 2013Standards for Shared ICT Recent Progress of CCSA’s Standardization Activities Hequan WU Chairman of the Council, CCSA Document No:
ETSI Technical Committee TCCE TETRA and Critical Communications Evolution Seminar "Education about Standartisation for SMEs Sofia, 14th March 2016.
Update on ETSI Cyber Security work Charles Brookson OCG Security Chairman Largely based on presentations given by Judith E. Y. Rossebø ETSI TISPAN WG7.
12 March Workshop on Multimedia Convergence ITU-T Geneva, 12 March 2002 ETSI’s Approach to IPCablecom Standardization Jim Price, C.Eng, M.I.E.E.
Jeju, 13 – 16 May 2013Standards for Shared ICT ETSI Conformance and Interoperability Testing Jørgen Friis ETSI Chief Services Officer (CSO) Document No:
ANSI – ESOs meeting Washington February 2017
© ETSI All rights reserved
Recent Progress of CCSA’s Standardization Activities
Security Activities in ETSI
Technical Organization and approval procedures
ETSI Conformance and Interoperability Testing
Dirk Weiler, chairman of the board, ETSI
Glenn Parsons, GTSC-9 Chair, ISACC
Update on Security and LI activities in ETSI
Security Activities in ETSI
Cybersecurity Presented by Charles Brookson OBE CEng FIET FRSA
How your R&I projects can benefit from ETSI
ETSI role in Identity Management and Identification Systems
ETSI Activities Related to IP and Multimedia
Recent Progress of CCSA’s Standardization Activities
Didier Chauveau ETSI OCG ECN&S Chairman ETSI Board Vice Chairman
ETSI Standardization Activities on Smart Grids
ETSI Contribution to 3rd Meeting of EC Expert Group on RRS
Glenn Parsons, GTSC-9 Chair, ISACC
Presentation transcript:

International Telecommunication Union ETSI Security Standardization Dr. Carmine Rizzo CISA, CISM, CISSP, ITIL, PRINCE2 ITU-T Workshop on “New challenges for Telecommunication Security Standardizations" Geneva, 9(pm)-10 February 2009 ETSI Security Standardization

International Telecommunication Union ETSI Security Standardization 2 Agenda Introduction ETSI Security activities in Technical Bodies ETSI Security horizontal activities

International Telecommunication Union ETSI Security Standardization 3 Introduction ETSI Security activities in Technical Bodies ETSI Security horizontal activities

International Telecommunication Union 4 The three roles of ETSI GSP Global Standards Producer ESO European Standards Organization SPO Service Providing Organization ESO (European Standards Organization): Standardization for European needs GSP (Global Standards Producer): Standardization for the global level SPO (Service Providing Organization): services such as interoperability testing, forum management etc. ETSI Security Standardization

International Telecommunication Union ETSI Security Standardization 5 The role of Security Standards Information Security Standards are essential to ensure interoperability Standardization ensures products are compliant with Adequate levels of security Legislations ETSI : over 20 years of experience in Security All ETSI Members participate directly in the Standardization process

International Telecommunication Union ETSI Security Standardization 6 Introduction ETSI Security activities in Technical Bodies ETSI Security horizontal activities

International Telecommunication Union ETSI Security Standardization 7 Areas of security Standardization Next Generation Networks (NGN) Mobile/Wireless Communications (GSM/UMTS, TETRA, DECT…) Lawful Interception and Data Retention Electronic Signatures Smart Cards Algorithms Emergency Communications / Public Safety RFID Quantum Key Distribution (QKD) In 3GPP: SAE/LTE and Common IMS

International Telecommunication Union ETSI Security Standardization 8 NGN Security Standardization ETSI TISPAN WG7 standardizes NGN security Achievements Security Requirements, Design Guide, Architecture Analysis of risks and threats Current work Lawful Interception / Data Retention IPTV, RFID, safety services (emergency communications) TISPAN: TISPAN Telecommunication and Internet converged Services and Protocols for Advanced Networking

International Telecommunication Union ETSI Security Standardization 9 GSM/UMTS Security Standardization: key success factor for GSM IMEI (International Mobile Equipment Identity) Protection/deterrent against theft FIGS (Fraud Information Gathering System) Terminate fraudulent calls of roaming subscribers Safety Services (enhancements for UMTS) Priority access for specific user categories Location services

International Telecommunication Union ETSI Security Standardization 10 TETRA TErrestrial Trunked RAdio Mobile radio communications Used for public safety services (e.g. emergency scenarios) Security features Mutual Authentication Encryption Anonymity

International Telecommunication Union ETSI Security Standardization 11 Lawful Interception Delivery of intercepted communications to Authorised Organisations To support criminal investigation, counter terrorism Applies to data in transit Data Retention Directive 2006/24/EC Data generated/processed in electronics comms need to be retained Applies to data location ETSI Data Retention standard published in 2008 ETSI TB Lawful Interception (LI) works on both LI and DR Define handover interface from Operator to Authorised Organization

International Telecommunication Union ETSI Security Standardization 12 Electronic Signatures TB ESI (Electronic Signatures and Infrastructures) Supports eSignature EC Directive – in cooperation with CEN Created ETSI electronic signatures Successful international collaboration (US, Japan) Current work Digital accounting (eInvoicing) Registered (REM) framework ETSI electronic signatures in PDF documents

International Telecommunication Union ETSI Security Standardization 13 Smart Cards ETSI Smart Card Standardization TB Smart Card Platform (SCP) GSM SIM Cards: among most widely deployed smart cards ever Work extended with USIM Card and UICC Platform Current work Further extend the smart card and UICC platforms Global roaming Secure financial transactions Operate in M2M communications USIM USIM: UMTS Subscriber Identity Module UICC UICC: Universal Integrated Circuit Card MM M2M: Machine-to-Machine

International Telecommunication Union ETSI Security Standardization 14 Algorithms ETSI is world leader in creating cryptographic algorithms / protocols ETSI SAGE (Security Algorithm Group of Experts) ETSI is owner and/or custodian of a number of security algorithms Algorithms for GSM, GPRS, EDGE, UMTS, TETRA, DECT, 3GPP … Developed UEA1 (standard algorithm for confidentiality) UIA1 (standard algorithm for integrity) Developed also a second set of algorithms UEA2 and UIA2, fundamentally different in nature from UEA1 and UIA1 Advances in cryptanalysis are unlikely to impact both sets of algorithm UEA UEA: UMTS Encryption Algorithm UIA UIA: UMTS Integrity Algorithm

International Telecommunication Union ETSI Security Standardization 15 Emergency Communications / Public Safety EMTEL ( ETSI Special Committee on Emergency Telecommunications ) Co-operation with other TBs and partnership projects, including 3GPP Requirements for telecommunications infrastructure MESA ( Mobility for Emergency and Safety Applications ) Partnership project: ETSI TIA (USA), others members globally Define digital mobile broadband – “systems of systems” approach Interoperability is key!

International Telecommunication Union ETSI Security Standardization 16 GSM ongoing work (public safety) GSM onboard aircrafts Prevent undesired communications Between terrestrial networks and handheld terminals on aircrafts! GSM eCalls Automatic emergency calls from vehicles In case of crash or other catastrophic events GSM Direct Mode Operations (DMO) Terminals to communicate directly In tunnels (e.g. railways) or breakdown of telecomms network infrastructure

International Telecommunication Union ETSI Security Standardization 17 SAE/LTE and Common IMS (in 3GPP) System Architecture Evolution / Long Term Evolution (SAE/LTE) Deliver Global Mobile Broadband at increased data throughput Security features: integrity and confidentiality Developed in 3GPP and ETSI SAGE Common IP Multimedia Subsystem (IMS) Architectural framework to deliver IP multimedia to mobile users Security requirements from TISPAN, CableLabs and 3GPP2

International Telecommunication Union ETSI Security Standardization 18 RFID RFID Security and Privacy by design In TISPAN WG7 to act on EC Mandate December 2008 (M 436) RFID as gateway for the future “Internet of Things” (IoT) More RFID work in other TBs Intelligent Transport Systems (ITS)

International Telecommunication Union ETSI Security Standardization 19 Quantum Key Distribution New ETSI Industry Specification Group (ISG) Create an environment for quantum cryptography in ICT networks Security Assurance Requirements Requirements for users, components, applications Security certification of quantum cryptographic equipment

International Telecommunication Union ETSI Security Standardization 20 Introduction ETSI Security activities in Technical Bodies ETSI Security horizontal activities

International Telecommunication Union ETSI Security Standardization 21 OCG Security Operational Co-ordination ad hoc Group on Security (OCG Sec) Chairman: Charles Brookson Technical Officer: Carmine Rizzo Horizontal co-ordination structure for security issues Ensure new work is addressed by proper TB Detect any conflicting or duplicate work

International Telecommunication Union ETSI Security Standardization 22 Future Challenges ETSI to address open issues on security Prioritization in security Standardization Security Metrics Privacy How to “evaluate” security standards in implementation … ETSI is ready to address these challenges Proactively supporting its Members according to requirements and trends Proactively promoting security Standardization In collaboration with other SDOs

International Telecommunication Union ETSI Security Standardization 23 ETSI Security Workshop Yearly event hosted at ETSI premises, Sophia Antipolis, France Security Standardization keeps evolving New threats arising ETSI needs feedback to: Ensure timely Standardization on gaps or hot topics Initiate new work according to the requirements of ETSI Membership Next, to be confirmed 5th ETSI Security Workshop 2010 (possibly January) Watch for the Call for Papers Reports and presentations of all ETSI Security Workshops

International Telecommunication Union ETSI Security Standardization 24 ETSI Security White Paper ETSI achievements and current work in all security areas List of all security-related ETSI publications Edition No. 2 published in October 2008 Carmine Rizzo (ETSI Security point of reference) Charles Brookson (Chairman of ETSI OCG Security) Freely downloadable

International Telecommunication Union Thanks! Available for your ? ETSI Security Standardization