美利体育登录入口官网

美利体育登录入口官网:ETSI TS 132 371-2017
数字蜂窝通信系统(第2+阶段)(GSM全球通信系统);通用移动通信系统(UMTS);长期演进技术(LTE);通信管理;安全管理概念和要求(V14.0.0;3GPP TS 32.371版本14.0.0 发行版本14)

Digital cellular telecommunications system (Phase 2+) (GSM); Universal Mobile Telecommunications System (UMTS); LTE; Telecommunication management; Security Management concept and requirements (V14.0.0; 3GPP TS 32.371 version 14.0.0 Release 14)

2018-07

标准号
ETSI TS 132 371-2017
发布
2017年
总页数
30页
发布单位
欧洲电信标准协会
替代标准
ETSI TS 132 371-2018
当前最新
ETSI TS 132 371-2024
 
 
引用标准
3GPP TS 32.101 3GPP TS 32.102 3GPP TS 32.150 3GPP TS 33.102 ITU-T M.3016 ITU-T X.800 RFC 2403 RFC 2404 RFC 2405 RFC 2406 RFC 2410 RFC 2451 RFC 3602
 
 
本体
安全域
适用范围
The present document defines, in addition to the requirements defined in 3GPP TS 32.101 [1] and 3GPP TS 32.102 [2], the requirements for Security Management IRP. The purpose of the present document is to specify the necessary security features, services and functions to protect the network management data, including Requests, Responses, Notifications and Files, exchanged across the Itf-N. Telecommunication network security can be breached by weaknesses in operational procedures, physical installations, communication links, computational processes and data storage. Of concern here in the present document is the security problems resulting from the weaknesses inherent in the communication technologies (i.e., the 3GPP-defined Interface IRPs and their supporting protocol stacks) deployed across the Itf-N. Appropriate level of security for a telecommunication network is essential. Secured access to the network management applications, and network management data, is essential. The 3GPP-defined Interface IRPs (and their supporting protocol stacks), deployed across the Itf-N, are used for such access, and therefore, their security is considered essential. Many network management security standards exist. However, there is no recommendation on how to apply them in the Itf-N context. Their deployment across the Itf-N is left to operators. The present document and the corresponding solutions identify and recommend security standards in the Itf-N context. The business case for secured Itf-N is complex as it does not relate to the functions of the Interface IRPs (the functions are constant) but rather, it relates to variants such as the cost of recovering from security breaks, the probability of security incidents and the cost of implementing Security Management, all of which differs depending on specific deployment scenarios. The present document describes the security functions for a 3G network in terms of Security Domains (subclause 4.1). Clause 5 defines the Itf-N Security Management scope in terms of its context (subclause 5.1) and the possible threats that can occur there are defined in clause 6. Clause 7 specifies the Itf-N security Requirements.
术语描述
访问控制
access control
防止未经授权使用资源,包括防止以未经授权的方式使用资源。
责任
accountability
确保实体的行为可以唯一地追溯到该实体的属性。
认证
authentication
包括数据源认证和对等实体认证,见ITU-T建议X.800。
授权
authorization
授予权利,包括基于访问权利的访问授予。
可用性
availability
属性,指在需要时可以被授权实体访问和使用。
机密性
confidentiality
属性,指信息不向未授权的个人、实体或进程提供或披露。
凭证
credentials
用于建立实体声称身份的数据。
密码学
cryptography
体现用于转换数据的原理、手段和方法的学科,以隐藏其信息内容,防止未经美利体育登录入口官网的修改和/或防止未经授权使用。
数据完整性
data integrity
属性,指数据未经未授权的方式改变或破坏。
数据源认证
data origin authentication
证实接收到的数据源与声称的一致。
拒绝服务
denial of service
防止对资源的授权访问或延迟时间关键操作。
数字签名
digital signature
附加到数据单元或数据单元的加密变换,允许接收方证明数据源的完整性和真实性,并防止伪造。
窃听
eavesdropping
通过监控通信破坏机密性。
伪造
forgery
实体伪造信息并声称该信息是从另一实体接收的或发送到另一实体的。
集成参考点
Integration Reference Point (IRP)
参见3GPP TS 32.150。
IRP代理
IRPAgent
参见3GPP TS 32.150。
IRP管理器
IRPManager
参见3GPP TS 32.150。
信息丢失或损坏
loss or corruption of information
传输的数据完整性因未授权的删除、插入、修改、重新排序、重放或延迟而受损。
操作系统
Operations System (OS)
指独立于其在管理层级中位置的管理系统通用术语。
伪装
masquerade
实体假装是另一实体。
密码
password
保密的认证信息,通常由一串字符组成。
对等实体认证
Peer Entity Authentication
证实关联中的对等实体是被声称的那个。
否认
repudiation
参与通信的一方否认其参与了全部或部分通信。
安全审计
security audit
对系统记录和活动进行的独立审查和检查,以测试系统控制的充分性,确保符合既定政策和操作程序,美利体育登录入口官网安全违规行为,并建议任何必要的控制、政策和程序变更。
威胁
threat
潜在的违反安全的行为。
未授权访问
unauthorized access
实体试图违反现行安全策略访问数据。

美利体育登录入口官网: ETSI TS 132 371-2017 中提到的仪器美利体育官网首页网址

网络元素

未提及
网络中的物理或逻辑组件,如基站、交换机等,作为管理对象。

美利体育登录入口官网: ETSI TS 132 371-2017相似标准





Copyright ?2007-2026 ANTPEDIA, All Rights Reserved
京ICP备07018254号 京公网安备1101085018 电信与信息服务业务经营许可证:京ICP证110310号
页面更新时间: 2026-07-27 23:34

美利体育(meili)官方网站_美利体育手机版下载