1、 ETSI TR 1Digital cellular telecoFraud InformatServ(3GPP TR 41.0TECHNICAL REPORT 141 031 V13.0.0 (2016communications system (Phaation Gathering System (FIGService requirements; Stage 0 .031 version 13.0.0 Release 13GLOBAL SYSTEMOBILE COMMUN16-01) hase 2+); GS); 13) TEM FOR ICATIONSRETSI ETSI TR 141
2、031 V13.0.0 (2016-01)13GPP TR 41.031 version 13.0.0 Release 13Reference RTR/TSGS-0341031vd00 Keywords GSM,SECURITY ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enr
3、egistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any electronic and/or print versions of the present d
4、ocument shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (PDF) version kept on a specific network drive w
5、ithin ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present docu
6、ment, please send your comment to one of the following services: https:/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm except as authorized by wr
7、itten permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2016. All rights reserved. DECTTM, PLUGTESTSTM, U
8、MTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI E
9、TSI TR 141 031 V13.0.0 (2016-01)23GPP TR 41.031 version 13.0.0 Release 13Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ETSI members and
10、 non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server (https:/ipr.etsi.org/).
11、 Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the presen
12、t document. Foreword This Technical Report (TR) has been produced by ETSI 3rd Generation Partnership Project (3GPP). The present document may refer to technical specifications or reports using their 3GPP identities, UMTS identities or GSM identities. These should be interpreted as being references t
13、o the corresponding ETSI deliverables. The cross reference between GSM, UMTS, 3GPP and ETSI identities can be found under http:/webapp.etsi.org/key/queryform.asp. Modal verbs terminology In the present document “shall“, “shall not“, “should“, “should not“, “may“, “need not“, “will“, “will not“, “can
14、“ and “cannot“ are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. ETSI ETSI TR 141 031 V13.0.0 (2016-01)33GPP TR 41.031 version 13
15、.0.0 Release 13Contents Intellectual Property Rights 2g3Foreword . 2g3Modal verbs terminology 2g3Foreword . 4g31 Scope 5g32 Normative references . 5g33 Definitions and abbreviations . 5g33.1 Definitions 5g33.2 Abbreviations . 5g34 Fraud Information Gathering System overview . 6g35 The need for fraud
16、 detection systems and controls 6g35.1 Outline of present situation 6g35.2 General Principles 7g35.3 Capabilities . 7g35.4 Service conditions 7g35.5 Information Delivery Time. 7g35.6 Subscriber Data Volumes . 8g36 Interface between HPLMN and FDS . 8g37 Security of the system 8g3Annex A: Change Histo
17、ry . 9g3History 10g3ETSI ETSI TR 141 031 V13.0.0 (2016-01)43GPP TR 41.031 version 13.0.0 Release 13Foreword This Technical Report has been produced by the 3rdGeneration Partnership Project (3GPP). The contents of the present document are subject to continuing work within the TSG and may change follo
18、wing formal TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an identifying change of release date and an increase in version number as follows: Version x.y.z where: x the first digit: 1 presented to TSG for information; 2 presented to
19、TSG for approval; 3 or greater indicates TSG approved document under change control. y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, updates, etc. z the third digit is incremented when editorial only changes have been incorporated in the docu
20、ment. ETSI ETSI TR 141 031 V13.0.0 (2016-01)53GPP TR 41.031 version 13.0.0 Release 131 Scope This Technical Report describes the requirements (at a stage 0 level) of the Fraud Information Gathering System (FIGS). FIGS provides the means for the HPLMN to monitor a defined set of subscriber activities
21、. The aim is to enable service providers/network operators to use FIGS, and service limitation controls such as Operator Determined Barring (ODB) and Immediate Service Termination (IST), to limit their financial exposure to large unpaid bills produced on subscriber accounts whilst the subscriber is
22、roaming outside their HPLMN. HPLMNs may also choose to collect information on subscriber activities whilst their subscribers are within the HPLMN. 2 Normative references The following documents contain provisions which, through reference in this text, constitute provisions of the present document. R
23、eferences are either specific (identified by date of publication, edition number, version number, etc.) or non-specific. For a specific reference, subsequent revisions do not apply. For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including a G
24、SM document), a non-specific reference implicitly refers to the latest version of that document in the same Release as the present document. 1 GSM 01.04: “Digital cellular telecommunications system (Phase 2+); Abbreviations and acronyms“. 2 GSM 02.33: “Digital cellular telecommunications system (Pha
25、se 2+); Lawful Interception - stage 1“. 3 Definitions and abbreviations 3.1 Definitions For the purposes of this report the following definitions apply: monitored activities: subscriber activities that must be reported to the HPLMN. These can be call related events (e.g. call-set-up, call terminatio
26、n) or the invocation of call related and call independent supplementary services (e.g. Call Hold, Call Waiting, Call Transfer, Call Forwarding, Unstructured Supplementary Service Data). Home Network: The home PLMN including non-GSM elements such as the Fraud Detection System (FDS), customer service
27、systems and billing. 3.2 Abbreviations Abbreviations used in this report are listed in GSM 01.04. For the purposes of this report the following abbreviations apply: FIGS Fraud Information Gathering System FDS Fraud Detection System This is not necessarily an automatic system but may be one that requ
28、ires human intervention. IST Immediate Service Termination ETSI ETSI TR 141 031 V13.0.0 (2016-01)63GPP TR 41.031 version 13.0.0 Release 134 Fraud Information Gathering System overview A number of proposals have been suggested for a Subscriber Supervisory System (SSS) for which specifications were pr
29、oduced from May 1995 through to December 1996. Following joint review between SMG1 and SMG10, it was agreed that the system should be re-specified to take account of network operator and manufacturer needs for a Fraud Information Gathering System (FIGS). This report provides an outline of such a sys
30、tem. This report describes a method by which the Home Network can be provided with data on the activities of its subscribers in a VPLMN. The Home Network can make inferences about what the subscriber is doing and then take decisions on what the subscriber should be allowed to do. This report does no
31、t address any Fraud Detection systems or the intelligence that is used to advise the HPLMN on the controls to be applied to a subscriber. Figure 1 shows the flow of messages between the HPLMN and the VPLMN and between the HPLMN and the FDS. FraudDetectionSystemHPLMNFIGS SetFIGS DataVPLMN1VPLMN3FIGS
32、SetFIGS DataVPLMN2Figure 1: Flow of messages between the HPLMN and the VPLMN and between the HPLMN and the FDS 5 The need for fraud detection systems and controls 5.1 Outline of present situation Modern telecommunications networks, particularly mobile networks provide the potential for fraudsters to
33、 make use of telecommunication services (Voice, Data, Fax etc.) without the intent to pay. A number of different scenarios are exploited and it is up to the network operator or service provider to detect misuse where it occurs and to stop it at the earliest possible opportunity. The scale of frauds
34、can be many thousand of ECU per day on a single account when International or Premium rate numbers are called. The most common types of fraud that effect networks like GSM are related to the ability to sell calls at below market price using stolen air-time/equipment where the user of the equipment d
35、oes not intend to pay the network operator or service provider. Fraudulent subscribers often avoid payment by obtaining a handset and a subscription to a GSM network by fraudulently giving details and justifications to the network operators/service provider. If there are not good controls within the
36、 network the subscriber can make a large volume of calls to expensive destinations and accumulate a large bill. ETSI ETSI TR 141 031 V13.0.0 (2016-01)73GPP TR 41.031 version 13.0.0 Release 13Roaming, in co-ordination with advanced services such as call transfer and multi-party calls, complicates the
37、 issue further, requiring control of the customer within the VPLMN. Many simultaneous calls can be set up and large bills accumulated in a short time. At present no system exists within the GSM network architecture for speedily transferring information on subscriber activity from the VPLMN to the HP
38、LMN. In the future, SIMs may roam to non-GSM networks, further broadening the area over which control is required. It is recognised that if FIGS is implemented in non-GSM networks that suitable inter-working units will be required to translate commands and information. 5.2 General Principles The PLM
39、N network should be able to supply relevant information to the HPLMN network so it can make a decision on whether to terminate a call or to change the Operator Determined Barring (ODB) configuration for the specific subscriber. This decision will be carried out by the HPLMN or service provider. It i
40、s recognised that there is a limit to the type and volume of information that can be transferred between the VPLMN and the HPLMN. Therefore the requirement for the system is that distilled and standardised information must be supplied between the VPLMN and HPLMN. 5.3 Capabilities The following minim
41、um capabilities are required. See figure 1. Within the Home Network: - to mark a subscriber, defined by the IMSI or MSISDN, as being under FIGS control (“FIG Set“); - to receive from the VPLMN the data described below; - to remove the monitoring of a subscriber“s activities (“FIGS Unset“). Within th
42、e VPLMN: - to transmit to the HPLMN information (FIGS Data): - at the start of a call; - at the end of a call; - during a call for long calls or at the mid-call invocation of supplementary services. 5.4 Service conditions The following service conditions shall apply: - FIGS shall not modify the VPLM
43、Ns service; - FIGS should not alter any standard GSM functionality seen by the customer or effect the service quality; - If the VPLMN network does not have the resources to support a FIGS Set command it shall respond accordingly to the HPLMN. 5.5 Information Delivery Time The need for up to date inf
44、ormation is a critical part of any fraud information system. The sooner data is transferred to the HPLMN, the sooner fraud can be stopped. Therefore the proscribed information shall be transferred from the VPLMN to the HPLMN within two minutes of the occurrence of a FIGS-monitored event The informat
45、ion shall preferably be transferred from the VPLMN to the HPLMN over existing communication links (e.g. SS7 signalling links). ETSI ETSI TR 141 031 V13.0.0 (2016-01)83GPP TR 41.031 version 13.0.0 Release 135.6 Subscriber Data Volumes If the support of FIGS is causing overload within the VPLMN the FI
46、GS system shall not permit the marking of new subscribers. The VPLMN should therefore handle up to a realistic limit any requests for marking of subscribers and be able to support the associated data transfer. The setting of this limit is outside the scope of this report. Each VPLMN should limit the
47、 number of subscribers that each HPLMN may request to be monitored using FIGS. Otherwise an HPLMN may take more than its fair share of the FIGS processing capability of a VPLMN. A mechanism shall be required whereby a VPLMN can charge an HPLMN for the bulk data transfer made to that HPLMN. 6 Interfa
48、ce between HPLMN and FDS The interface between the home network and the network“s fraud detection and processing systems shall be through a specific interface. This will be used to present information to the fraud detection systems. The contents of messages sent on this interface shall be specified
49、but not the transfer mechanism. This is in line with the approach used for the X-interface as specified in GSM 02.33. The FDS will indicate to the HPLMN subscribers that should be subject to FIGS monitoring. This information will update the HPLMN HLR. Information, as listed in subclause 5.3 gathered from the VPLMN will be transferred to the FDS system. Following processing of this information, the FDS system can take no action or can advise the home network to do one of the following: a) update ODB categories; b) instigate an Immediate Service Termination (IST);
copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1