1、 ETSI TR 187 012 V2.1.1 (2009-11)Technical Report Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN);NGN Security;Report and recommendations on compliance to the data retention directive for NGN-R2ETSI ETSI TR 187 012 V2.1.1 (2009-11) 2Reference DTR/TIS
2、PAN-07032-NGN-R2 Keywords data, retention ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice Indiv
3、idual copies of the present document can be downloaded from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Documen
4、t Format (PDF). In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the cur
5、rent status of this and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reprodu
6、ced except as authorized by written permission. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2009. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTM, TIPHONTM, the TIPHON logo and the ETSI logo are Trade Marks of ETSI
7、 registered for the benefit of its Members. 3GPPTM is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. LTE is a Trade Mark of ETSI currently being registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM
8、 logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TR 187 012 V2.1.1 (2009-11) 3Contents Intellectual Property Rights 5g3Foreword . 5g31 Scope 6g32 References 6g32.1 Normative references . 6g32.2 Informative references 7g33 Definitions and abbreviations . 8g33.1 Definitions
9、 8g33.2 Abbreviations . 8g34 Introduction 9g35 NGN overview with respect to data retention 10g35.1 Data categorisation . 10g35.2 Retention obligation . 10g36 Abstract architecture for data retention in the NGN 11g36.1 Overview 11g36.2 Mapping of NGN architecture to DR abstract architecture 12g36.3 S
10、ecurity considerations for DR in generic CSP 14g36.3.1 Privacy considerations in the NGN with respect to DR 14g3Annex A: Analysis of Directive with respect to the NGN . 15g3Annex B: Comparison of terms between Directive and NGN 18g3Annex C: National declarations regarding application of the directiv
11、e 19g3C.1 Austria 19g3C.2 Belgium 19g3C.3 Republic of Cyprus . 19g3C.4 Czech Republic 19g3C.5 Estonia 19g3C.6 Finland 19g3C.7 Germany . 20g3C.8 The Hellenic Republic 20g3C.9 Republic of Latvia 20g3C.10 Republic of Lithuania . 20g3C.11 The Grand Duchy of Luxembourg . 20g3C.12 The Netherlands . 20g3C.
12、13 Republic of Poland . 21g3C.14 Slovenia 21g3C.15 Sweden . 21g3C.16 United Kingdom . 21g3Annex D: Mapping to LEA requirements (TS 102 656) . 22g3D.1 User (LEA) requirements . 22g3ETSI ETSI TR 187 012 V2.1.1 (2009-11) 4D.1.1 Introduction 22g3D.1.2 General requirements . 22g3D.1.3 Requests . 22g3D.1.
13、4 Request for retained data 22g3D.1.5 Delivery 22g3D.1.6 Content of delivery . 23g3D.1.7 Location information 23g3D.1.8 Availability constraints . 23g3D.1.9 Information transmission and information protection requirements 23g3D.1.10 Internal security 23g3D.1.11 Technical handover interfaces and form
14、at requirements 23g3D.1.12 Temporary obstacles to transmission . 24g3D.1.13 Identification of the request criteria 24g3D.1.14 Multiple requests 24g3Annex E: Bibliography 25g3History 26g3ETSI ETSI TR 187 012 V2.1.1 (2009-11) 5Intellectual Property Rights IPRs essential or potentially essential to the
15、 present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI
16、in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server (http:/webapp.etsi.org/IPR/home.asp). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as
17、 to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the present document. Foreword This Technical Report (TR) has been produced by ETSI Technical Committee Telecommunications and Internet converge
18、d Services and Protocols for Advanced Networking (TISPAN). ETSI ETSI TR 187 012 V2.1.1 (2009-11) 61 Scope The present document identifies the impact on the NGN in achieving compliance to the data retention directive i.1. The present document makes a number of recommendations to operators and manufac
19、turers that may be sufficient to ensure compliance, and identifies where future standardisation may be required. The present document applies to TISPAN NGN services as specified by TR 180 001 i.12 (for release 1 specific capabilities) and TR 180 002 i.13 (for release 2 specific capabilities), and wh
20、ere the NGN user is identified as specified in TS 184 002 i.11.The present document is structured in the following way: NGN analysis with respect to Data Retention: - annex containing an analysis of the existing Directive and the available provisions in the NGN; - annex providing a comparison of ter
21、ms between Directive and NGN. Identification of the data that is expected to be retained in the NGN under the DR Directive and a mapping to determine if the data is available in the NGN. The present document does not define the handover domain which is specified in TS 102 657 i.2 nor does the docume
22、nt cover any conformance aspects relating to IMS. However where other standards bodies are directly impacted by the DR Directive in the NGN the present document identifies in outline form the affected publications from such SDOs. The present document does not address the application of Data Retentio
23、n in Customer Premises Networks (CPN) or Next Generation Corporate Networks (NGCN). 2 References References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For a specific reference, subsequent revisions do not apply. Non-specific refer
24、ence may be made only to a complete document or a part thereof and only in the following cases: - if it is accepted that it will be possible to use all future changes of the referenced document for the purposes of the referring document; - for informative references. Referenced documents which are n
25、ot found to be publicly available in the expected location might be found at http:/docbox.etsi.org/Reference. NOTE: While any hyperlinks included in this clause were valid at the time of publication ETSI cannot guarantee their long term validity. 2.1 Normative references The following referenced doc
26、uments are not essential to the use of the present document but they assist the user with regard to a particular subject area. For non-specific references, the latest version of the referenced document (including any amendments) applies. Not applicable. ETSI ETSI TR 187 012 V2.1.1 (2009-11) 72.2 Inf
27、ormative references The following referenced documents are not essential to the use of the ETSI deliverable but they assist the user with regard to a particular subject area. For non-specific references, the latest version of the referenced document (including any amendments) applies. i.1 Directive
28、2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and amending Directive 2002/58/EC. i.2 ETSI TS 102
29、657: “Lawful Interception (LI); Retained data handling; Handover interface for the request and delivery of retained data“. i.3 ETSI TS 102 656: “Lawful Interception (LI); Retained Data; Requirements of Law Enforcement Agencies for handling Retained Data“. i.4 Directive 2002/58/EC of the European Par
30、liament and of the council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications). i.5 Recommendation of the OECD Council in 1980 concerning guidelines governing the protect
31、ion of privacy and transborder flows of personal data (the OECD guidelines for personal data protection. i.6 Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of
32、 such data . i.7 ETSI ES 282 001: “Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); NGN Functional Architecture“. i.8 ETSI SR 002 211 (V1.1.1): “List of standards and/or specifications for electronic communications networks, services and associated f
33、acilities and services; in accordance with Article 17 of Directive 2002/21/EC“. i.9 ETSI TR 102 661: “Lawful Interception (LI); Security framework in Lawful Interception and Retained Data environment“. i.10 ETSI TS 187 005: “Telecommunications and Internet converged Services and Protocols for Advanc
34、ed Networking (TISPAN); NGN Release 2 Lawful Interception; Stage 1 and Stage 2 definition“. i.11 ETSI TS 184 002: “Telecommunications and Internet Converged Services and Protocols for Advanced Networking (TISPAN); Identifiers (IDs) for NGN“. i.12 ETSI TR 180 001: “Telecommunications and Internet con
35、verged Services and Protocols for Advanced Networking (TISPAN); NGN Release 1; Release definition“. i.13 ETSI TR 180 002: “Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); Release 2 definition“. i.14 ETSI TR 187 010: “Telecommunications and Internet
36、converged Services and Protocols for Advanced Networking (TISPAN); NGN Security; Report on issues related to security in identity imanagement and their resolution in the NGN“. i.15 ETSI TS 187 001: “Telecommunications and Internet converged Services and Protocols for Advanced Networking (TISPAN); NG
37、N SECurity (SEC); Requirements“. ETSI ETSI TR 187 012 V2.1.1 (2009-11) 83 Definitions and abbreviations 3.1 Definitions For the purposes of the present document, the terms and definitions given in Directive 2006/24/EC i.1, TS 102 657 i.2 and the following apply: Point of Retention (PoR): NGN Functio
38、nal Entity that is assigned to retain a particular data item NOTE: In any implementation a data element may appear at multiple NGN FEs per retention event and in practice should only be retained once per retention event. Satisfying this recommendation may require that particular NGN FEs may be assig
39、ned as the primary or master point of retention for a particular data item. retention event: event triggered by an NGN user giving rise to the retention of data as defined by the data retention directive i.1 or by national law 3.2 Abbreviations For the purposes of the present document, the following
40、 abbreviations apply: AN Access Network CPN Customer Premises Networks CSCF Call Session Control Function CSP Communications Service Provider DNS Domain Name System DR Data Retention ECN Electronic Communications Network ECN a2) additional parameters for the specific purpose of law enforcement, whic
41、h require dedicated functions. NOTE: Depending on the countrys legal requirements difference functions have to be implemented in the systems for the fulfilment of law enforcement: a1) above requires some processing in order to deliver the information according to handover requirements; a2) above ref
42、ers to functions to be implemented solely for law enforcement. b) Parameters may be: b1) created in the domain of the CSP delivering the information; b2) created outside the domain. The obliged CSP can take responsibility for the parameters b1), while for the parameters b2), the correctness is not g
43、uaranteed, unless c1) (below) applies. c) Parameters may be: c1) mandatory for successful communication completion, i.e. self-verifying; c2) not relevant for successful communication completion and not verifiable, i.e. they may be wrong. The obliged CSP can take responsibility for the parameters c1)
44、, while for the parameters c2), the correctness is not guaranteed, unless b1) applies.g3ETSI ETSI TR 187 012 V2.1.1 (2009-11) 11Some of the terms used in the Directive are not in common use in the NGN (see annexes A and B). Whilst the detail of the directive identifies the following classes of netwo
45、rk either in isolation or in groups the NGN as specified in ETSI does not fall cleanly into any of the classes: Fixed network telephony. Fixed network telephony and mobile telephony. Internet access, Internet e-mail and Internet telephony. Internet e-mail and Internet telephony. Mobile telephony. Th
46、e obligation to ensure retention of data however is understood to apply irrespective of the network class but to CSPs in general. 6 Abstract architecture for data retention in the NGN 6.1 Overview Figure 6.1 is the reference model for the request and transmission of retained telecommunications data
47、taken from TS 102 657 i.2. NOTE 1: The term Authorized Organization covers any agency legally authorized to make Retained Data Handover Interface requests. NOTE 2: Handover Interface-B delivers data from CSP to the Authorized Organization. There may be related supporting lower level messages from th
48、e Authorized Organization to CSP on HI-B. Figure 6.1: Functional diagram showing handover interface HI Within the CSP block three internal CSP functions have been identified in TS 102 657 i.2 and are shown in figure 6.2: an administrative function to manage the Retained Data handover requests and re
49、sponses; a data collection function to collect data from the various internal network elements and prepare the data for retention. NOTE: The data collection function will gather data from Points of Retention (PoR) in the NGN. a data store management function to index and store the data, execute queries, and manage the maximum retention period for Retained Data. The internal functions, and the interfaces between them, are examined with respect to the NGN in the present document. Handover interface HI-B:
copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1