1、 ETSI TS 1Digital cellular telecommUniversal Mobile Tel3GPP System ASecurity aspe(3GPP TS 33.4TECHNICAL SPECIFICATION133 402 V13.0.0 (2016mmunications system (Phase elecommunications System (LTE; Architecture Evolution (SAEpects of non-3GPP accesses .402 version 13.0.0 Release 1316-03) e 2+) (GSM);
2、(UMTS); AE); es 13) ETSI ETSI TS 133 402 V13.0.0 (2016-03)13GPP TS 33.402 version 13.0.0 Release 13Reference RTS/TSGS-0333402vd00 Keywords GSM, LTE, UMTS ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF
3、 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any electronic
4、 and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (PDF) ver
5、sion kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp
6、 If you find errors in the present document, please send your comment to one of the following services: https:/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying a
7、nd microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2016. All
8、rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered a
9、nd owned by the GSM Association. ETSI ETSI TS 133 402 V13.0.0 (2016-03)23GPP TS 33.402 version 13.0.0 Release 13Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is
10、publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the
11、ETSI Web server (https:/ipr.etsi.org/). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be,
12、 or may become, essential to the present document. Foreword This Technical Specification (TS) has been produced by ETSI 3rd Generation Partnership Project (3GPP). The present document may refer to technical specifications or reports using their 3GPP identities, UMTS identities or GSM identities. The
13、se should be interpreted as being references to the corresponding ETSI deliverables. The cross reference between GSM, UMTS, 3GPP and ETSI identities can be found under http:/webapp.etsi.org/key/queryform.asp. Modal verbs terminology In the present document “shall“, “shall not“, “should“, “should not
14、“, “may“, “need not“, “will“, “will not“, “can“ and “cannot“ are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. ETSI ETSI TS 133 4
15、02 V13.0.0 (2016-03)33GPP TS 33.402 version 13.0.0 Release 13Contents Intellectual Property Rights 2g3Foreword . 2g3Modal verbs terminology 2g3Foreword . 6g31 Scope 7g32 References 7g33 Definitions, symbols and abbreviations . 8g33.1 Definitions 8g33.2 Symbols 8g33.3 Abbreviations . 9g33.4 Conventio
16、ns 9g34 Overview of Security Architecture for non-3GPP Accesses to EPS 9g34.1 General . 9g34.2 Trusted non-3GPP Access 10g34.3 Untrusted non-3GPP Access 10g35 Security Features Provided by EPS for non-3GPP Accesses . 11g35.1 User-to-Network security . 11g35.1.1 User identity and device identity conf
17、identiality 11g35.1.2 Entity authentication . 11g35.2 User data and signalling data confidentiality 11g35.3 User data and signalling data integrity . 11g36 Authentication and key agreement procedures . 12g36.1 General . 12g36.2 Authentication and key agreement for trusted access . 14g36.3 Fast re-au
18、thentication procedure for trusted access 19g36.4 Authentication and key agreement for untrusted access . 21g36.5 Authentication and authorization with S2b for Private network access from Untrusted non-3GPP Access networks . 21g36.5.1 General 21g36.5.2 Authentication and authorization for the Privat
19、e network access (the External AAA Server performs PAP procedure) . 22g36.5.3 Authentication and authorization for the Private network access (the External AAA Server performs CHAP procedure) 24g37 Establishment of security contexts in the target access system 27g37.1 General assumptions. 27g37.2 Es
20、tablishment of security context for Trusted non-3GPP Access 27g37.2.1 CDMA-2000 HRPD EPS Interworking 27g37.2.1.1 EPS-HRPD Architecture . 27g37.2.1.2 Network Elements . 28g37.2.1.2.1 E-UTRAN . 28g37.2.1.2.2 MME . 28g37.2.1.2.3 Gateway . 28g37.2.1.2.3.1 General . 28g37.2.1.2.3.2 Serving GW . 28g37.2.
21、1.2.3.3 PDN GW 29g37.2.1.2.4 PCRF . 29g37.2.1.3 Reference Points . 29g37.2.1.3.1 List of Reference Points 29g37.2.1.3.2 Protocol assumptions. 29g37.2.1.4 Security of the initial access to EPS via HRPD 29g37.2.1.5 Security of handoff and pre-registration . 29g3ETSI ETSI TS 133 402 V13.0.0 (2016-03)43
22、GPP TS 33.402 version 13.0.0 Release 137.2.2 WIMAX EPS Interworking 29g37.2.3 Trusted WLAN Access (TWAN) . 30g37.2.3.1 General 30g37.2.3.2 Security for WLAN Control Protocol (WLCP). 30g37.2.3.2.1 Authentication and key agreement 30g37.2.3.2.2 Fast re-authentication 30g37.2.3.2.3 Protection of WLCP s
23、ignalling 30g37.2.3.2.4 DTLS profile . 31g37.3 Establishment of security context between UE and untrusted non-3GPP Access 31g38 Establishment of security between UE and ePDG . 32g38.1 General . 32g38.2 Mechanisms for the set up of UE-initiated IPsec tunnels . 32g38.2.1 General 32g38.2.2 Tunnel full
24、authentication and authorization 32g38.2.3 Tunnel fast re-authentication and authorization 35g38.2.4 Security profiles 37g38.2.5 Handling of IPsec tunnels in mobility events . 37g38.2.5.1 General 37g38.2.5.2 Idle mode mobility 38g38.2.5.3 Active mode mobility 38g39 Security for IP based mobility sig
25、nalling . 39g39.1 General . 39g39.2 Host based Mobility . 39g39.2.1 MIPv4 . 39g39.2.1.1 General 39g39.2.1.2 Bootstrapping of MIPv4 FACoA parameters 39g39.2.1.2.1 Procedures . 39g39.2.1.2.2 MIPv4 Key Derivation 40g39.2.1.2.3 Key Usage . 42g39.2.1.2.4 Key Distribution for MIPv4 42g39.2.2 DS-MIPv6 . 42
26、g39.2.2.1 General 42g39.2.2.2 Bootstrapping of DSMIPv6 parameters 43g39.2.2.2.1 Full Authentication and authorization . 43g39.2.2.2.2 Fast re-authentication and authorization 45g39.2.2.3 Security Profiles 47g39.2.2.4 Enhanced Security Support . 47g39.3 Network based Mobility . 47g39.3.1 Proxy Mobile
27、 IP 47g39.3.1.1 Introduction . 47g39.3.1.2 PMIP security requirements 48g39.3.1.3 PMIP security mechanisms . 48g310 Security interworking between 3GPP access networks and non-3GPP access networks 49g310.1 General . 49g310.2 CDMA2000 Access Network . 49g310.2.1 Idle Mode Mobility . 49g310.2.1.1 E-UTR
28、AN to HRPD Interworking 49g310.2.1.2 HRPD to E-UTRAN Interworking 49g310.2.2 Active mode mobility . 49g310.2.2.1 E-UTRAN to HRPD Interworking 49g310.2.2.2 HRPD to E-UTRAN Interworking 49g311 Network Domain Security 50g312 UE-ANDSF communication security . 50g312.1 UE-ANDSF communication security req
29、uirements . 50g312.2 UE-ANDSF communication security solution . 50g313 Security Aspects of Emergency Call Handling 51g313.1 General . 51g3ETSI ETSI TS 133 402 V13.0.0 (2016-03)53GPP TS 33.402 version 13.0.0 Release 1313.2 Requirements for Emergency Call handling 51g3Annex A (normative): Key derivati
30、on functions . 52g3A.1 KDF interface and input parameter construction . 52g3A.2 Function for the derivation of CK“, IK“ from CK, IK 52g3A.3 Function for the derivation of WLCP key from EMSK . 52g3Annex B (normative): Tunnelling of UE Services over Restrictive Access Networks . 53g3B.1 Overview 53g3B
31、.2 Service and Media Reachability for Users over Restrictive Firewalls - Untrusted Non 3GPP access 53g3Annex C (informative): Change history . 55g3History 57g3ETSI ETSI TS 133 402 V13.0.0 (2016-03)63GPP TS 33.402 version 13.0.0 Release 13Foreword This Technical Specification has been produced by the
32、 3rdGeneration Partnership Project (3GPP). The contents of the present document are subject to continuing work within the TSG and may change following formal TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an identifying change of rele
33、ase date and an increase in version number as follows: Version x.y.z where: x the first digit: 1 presented to TSG for information; 2 presented to TSG for approval; 3 or greater indicates TSG approved document under change control. y the second digit is incremented for all changes of substance, i.e.
34、technical enhancements, corrections, updates, etc. z the third digit is incremented when editorial only changes have been incorporated in the document. ETSI ETSI TS 133 402 V13.0.0 (2016-03)73GPP TS 33.402 version 13.0.0 Release 131 Scope The present document specifies the security architecture, i.e
35、., the security feature groups and the security mechanisms performed during inter working between non-3GPP accesses and the Evolved Packet System (EPS). 2 References The following documents contain provisions which, through reference in this text, constitute provisions of the present document. Refer
36、ences are either specific (identified by date of publication, edition number, version number, etc.) or non-specific. For a specific reference, subsequent revisions do not apply. For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including a GSM d
37、ocument), a non-specific reference implicitly refers to the latest version of that document in the same Release as the present document. 1 3GPP TR 21.905: “Vocabulary for 3GPP Specifications“. 2 IETF RFC 4877: “Mobile IPv6 Operation with IKEv2 and the Revised IPsec Architecture“. 3 Void. 4 IETF RFC
38、5778: “Diameter Mobile IPv6: Support for Home Agent to Diameter Server Interaction“. 5 3GPP TS 23.402: “Architecture enhancements for non-3GPP accesses“. 6 3GPP TS 33.210: “3G security; Network Domain Security (NDS); IP network layer security“. 7 IETF RFC 4187 (January 2006): “Extensible Authenticat
39、ion Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA)“. 8 3GPP TS 23.003: “Numbering, addressing and identification“. 9 3GPP TS 33.234: “3G: security; Wireless Local Area Network (WLAN) interworking security“. 10 IETF RFC 4072 (August 2005): “Diameter Extensible Authentic
40、ation Protocol (EAP) Application“. 11 3GPP TS 33.102: “3G security; Security architecture“. 12 3GPP TS 33.310: “Network Domain Security (NDS); Authentication Framework (AF)“. 13 3GPP TS 23.401: “General Packet Radio Service (GPRS) enhancements for Evolved Universal Terrestrial Radio Access Network (
41、E-UTRAN) access“. 14 3GPP TS 23.203: “Policy and charging control architecture“. 15 3GPP TS 36.300: “Evolved Universal Terrestrial Radio Access (E-UTRA) and Evolved Universal Terrestrial Radio Access (E-UTRAN); Overall description; Stage 2“. 16 3GPP TS 33.401: “3GPP System Architecture Evolution (SA
42、E); Security Architecture“. 17 IETF RFC 3344: “IP Mobility Support for IPv4“. 18 IETF RFC 4555: “IKEv2 Mobility and Multihoming Protocol (MOBIKE)“. 19 IETF RFC 5295: “Specification for the Derivation of Root Keys from an Extended Master Session Key (EMSK)“. ETSI ETSI TS 133 402 V13.0.0 (2016-03)83GP
43、P TS 33.402 version 13.0.0 Release 1320 3GPPP TS 24.303: “Mobility Management based on Dual-Stack Mobile IPv6; Stage 3“. 21 IETF RFC 4433: “Mobile IPv4 Dynamic Home Agent (HA) Assignment“. 22 3GPP TS 24.302: “Access to the 3GPP Evolved Packet Core (EPC) via non-3GPP access networks; Stage 3 “. 23 IE
44、TF RFC 5448: “Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA) “. 24 3GPP TS 33.222: “Generic Authentication Architecture (GAA); Access to network application functions using Hypertext Transfer Protocol over Transport Layer Security (HT
45、TPS)“. 25 3GPP TS 29.109: “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Generic Authentication Architecture (GAA); Zh and Zn Interfaces based on the Diameter protocol; Stage 3“. 26 - 28 Void. 29 3GPP TS 33.223: “Generic Authentication Architecture (GA
46、A); Generic Bootstrapping Architecture (GBA) Push function“. 30 IETF RFC 5996: “Internet Key Exchange Protocol Version 2 (IKEv2)“. 31 3GPP TS 29.274: “3GPP Evolved Packet System (EPS); Evolved General Packet Radio Service (GPRS) Tunnelling Protocol for Control plane (GTPv2-C); Stage 3“. 32 3GPP TS 2
47、9.275: “Proxy Mobile IPv6 (PMIPv6) based Mobility and Tunnelling protocols; Stage 3“. 33 IETF RFC 4739: “Multiple Authentication Exchanges in the Internet Key Exchange (IKEv2) Protocol“. 34 3GPP TS 33.203: “Access security for IP-based services“. 35 IETF RFC 3948: “UDP Encapsulation of IPsec ESP Pac
48、kets“. 36 IETF RFC 2616: “Hypertext Transfer Protocol - HTTP/1.1“. 37 IETF RFC 6347: “Datagram Transport Layer Security Version 1.2“. 38 3GPP TS 33.310: “Network Domain Security (NDS); Authentication Framework (AF)“. 39 3GPP TS 23.402: “Architecture enhancements for non-3GPP accesses“. 3 Definitions
49、, symbols and abbreviations 3.1 Definitions For the purposes of the present document, the terms and definitions given in TR 21.905 1 and the following apply. A term defined in the present document takes precedence over the definition of the same term, if any, in TR 21.905 1. IPsec Security Association (IPsec SA): A unidirectional logical connection created for security purposes. All traffic traversing an IPsec SA is provided the same security protection. The IPsec SA itself is a set of par
copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1