1、 ETSI TS 1Digital cellular telecommUniversal Mobile Tel3GPP System ASecurity aspe(3GPP TS 33.4TECHNICAL SPECIFICATION133 402 V13.1.0 (2017mmunications system (Phase elecommunications System (LTE; Architecture Evolution (SAEpects of non-3GPP accesses .402 version 13.1.0 Release 1317-01) e 2+) (GSM);
2、(UMTS); AE); es 13) ETSI ETSI TS 133 402 V13.1.0 (2017-01)13GPP TS 33.402 version 13.1.0 Release 13Reference RTS/TSGS-0333402vd10 Keywords GSM,LTE,SECURITY,UMTS ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 0001
3、7 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any ele
4、ctronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (P
5、DF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at https:/portal.etsi.org/TB/ETSIDeliv
6、erableStatus.aspx If you find errors in the present document, please send your comment to one of the following services: https:/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, includi
7、ng photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Ins
8、titute 2017. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade M
9、arks registered and owned by the GSM Association. ETSI ETSI TS 133 402 V13.1.0 (2017-01)23GPP TS 33.402 version 13.1.0 Release 13Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential
10、IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are
11、available on the ETSI Web server (https:/ipr.etsi.org/). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) whic
12、h are, or may be, or may become, essential to the present document. Foreword This Technical Specification (TS) has been produced by ETSI 3rd Generation Partnership Project (3GPP). The present document may refer to technical specifications or reports using their 3GPP identities, UMTS identities or GS
13、M identities. These should be interpreted as being references to the corresponding ETSI deliverables. The cross reference between GSM, UMTS, 3GPP and ETSI identities can be found under http:/webapp.etsi.org/key/queryform.asp. Modal verbs terminology In the present document “shall“, “shall not“, “sho
14、uld“, “should not“, “may“, “need not“, “will“, “will not“, “can“ and “cannot“ are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. E
15、TSI ETSI TS 133 402 V13.1.0 (2017-01)33GPP TS 33.402 version 13.1.0 Release 13Contents Intellectual Property Rights 2g3Foreword . 2g3Modal verbs terminology 2g3Foreword . 6g31 Scope 7g32 References 7g33 Definitions, symbols and abbreviations . 9g33.1 Definitions 9g33.2 Symbols 9g33.3 Abbreviations .
16、 9g33.4 Conventions 10g34 Overview of Security Architecture for non-3GPP Accesses to EPS 10g34.1 General . 10g34.2 Trusted non-3GPP Access 11g34.3 Untrusted non-3GPP Access 11g35 Security Features Provided by EPS for non-3GPP Accesses . 11g35.1 User-to-Network security . 11g35.1.1 User identity and
17、device identity confidentiality 11g35.1.2 Entity authentication . 11g35.2 User data and signalling data confidentiality 11g35.3 User data and signalling data integrity . 12g36 Authentication and key agreement procedures . 12g36.1 General . 12g36.2 Authentication and key agreement for trusted access
18、. 14g36.3 Fast re-authentication procedure for trusted access 19g36.4 Authentication and key agreement for untrusted access . 21g36.5 Authentication and authorization with S2b for Private network access from Untrusted non-3GPP Access networks . 21g36.5.1 General 21g36.5.2 Authentication and authoriz
19、ation for the Private network access (the External AAA Server performs PAP procedure) . 22g36.5.3 Authentication and authorization for the Private network access (the External AAA Server performs CHAP procedure) 25g37 Establishment of security contexts in the target access system 28g37.1 General ass
20、umptions. 28g37.2 Establishment of security context for Trusted non-3GPP Access 28g37.2.1 CDMA-2000 HRPD EPS Interworking 28g37.2.1.1 EPS-HRPD Architecture . 28g37.2.1.2 Network Elements . 29g37.2.1.2.1 E-UTRAN . 29g37.2.1.2.2 MME . 29g37.2.1.2.3 Gateway . 29g37.2.1.2.3.1 General . 29g37.2.1.2.3.2 S
21、erving GW . 29g37.2.1.2.3.3 PDN GW 30g37.2.1.2.4 PCRF . 30g37.2.1.3 Reference Points . 30g37.2.1.3.1 List of Reference Points 30g37.2.1.3.2 Protocol assumptions. 30g37.2.1.4 Security of the initial access to EPS via HRPD 30g37.2.1.5 Security of handoff and pre-registration . 30g3ETSI ETSI TS 133 402
22、 V13.1.0 (2017-01)43GPP TS 33.402 version 13.1.0 Release 137.2.2 WIMAX EPS Interworking 30g37.2.3 Trusted WLAN Access (TWAN) . 31g37.2.3.1 General 31g37.2.3.2 Security for WLAN Control Protocol (WLCP). 31g37.2.3.2.1 Authentication and key agreement 31g37.2.3.2.2 Fast re-authentication 31g37.2.3.2.3
23、Protection of WLCP signalling 31g37.2.3.2.4 DTLS profile . 32g37.3 Establishment of security context between UE and untrusted non-3GPP Access 32g38 Establishment of security between UE and ePDG . 33g38.1 General . 33g38.2 Mechanisms for the set up of UE-initiated IPsec tunnels . 33g38.2.1 General 33
24、g38.2.2 Tunnel full authentication and authorization 33g38.2.3 Tunnel fast re-authentication and authorization 36g38.2.4 Security profiles 38g38.2.4.1 Profile of IKEv2 38g38.2.4.2 Profile of IPSec ESP . 39g38.2.4.3 Profile for ePDG certificates . 39g38.2.5 Handling of IPsec tunnels in mobility event
25、s . 40g38.2.5.1 General 40g38.2.5.2 Idle mode mobility 40g38.2.5.3 Active mode mobility 40g39 Security for IP based mobility signalling . 41g39.1 General . 41g39.2 Host based Mobility . 41g39.2.1 MIPv4 . 41g39.2.1.1 General 41g39.2.1.2 Bootstrapping of MIPv4 FACoA parameters 41g39.2.1.2.1 Procedures
26、 . 41g39.2.1.2.2 MIPv4 Key Derivation 42g39.2.1.2.3 Key Usage . 44g39.2.1.2.4 Key Distribution for MIPv4 44g39.2.2 DS-MIPv6 . 44g39.2.2.1 General 44g39.2.2.2 Bootstrapping of DSMIPv6 parameters 45g39.2.2.2.1 Full Authentication and authorization . 45g39.2.2.2.2 Fast re-authentication and authorizati
27、on 47g39.2.2.3 Security Profiles 49g39.2.2.4 Enhanced Security Support . 49g39.3 Network based Mobility . 49g39.3.1 Proxy Mobile IP 49g39.3.1.1 Introduction . 49g39.3.1.2 PMIP security requirements 50g39.3.1.3 PMIP security mechanisms . 50g310 Security interworking between 3GPP access networks and n
28、on-3GPP access networks 51g310.1 General . 51g310.2 CDMA2000 Access Network . 51g310.2.1 Idle Mode Mobility . 51g310.2.1.1 E-UTRAN to HRPD Interworking 51g310.2.1.2 HRPD to E-UTRAN Interworking 51g310.2.2 Active mode mobility . 51g310.2.2.1 E-UTRAN to HRPD Interworking 51g310.2.2.2 HRPD to E-UTRAN I
29、nterworking 51g311 Network Domain Security 52g312 UE-ANDSF communication security . 52g312.1 UE-ANDSF communication security requirements . 52g312.2 UE-ANDSF communication security solution . 52g3ETSI ETSI TS 133 402 V13.1.0 (2017-01)53GPP TS 33.402 version 13.1.0 Release 1313 Security aspects of em
30、ergency call handling 53g313.1 General . 53g313.2 Requirements for emergency call handling 53g314 Temporary identity management 53g314.1 Temporary identity generation . 53g314.2 Key management 54g314.3 Impact on permanent user identities . 55g314.4 Acknowledged limitations 55g314.5 UE behaviour on r
31、eceiving requests to send the IMSI-based user identity 56g3Annex A (normative): Key derivation functions . 57g3A.1 KDF interface and input parameter construction . 57g3A.2 Function for the derivation of CK“, IK“ from CK, IK 57g3A.3 Function for the derivation of WLCP key from EMSK . 57g3Annex B (nor
32、mative): Tunnelling of UE Services over Restrictive Access Networks . 58g3B.1 Overview 58g3B.2 Service and Media Reachability for Users over Restrictive Firewalls - Untrusted Non 3GPP access 58g3Annex C (informative): Change history . 60g3History 62g3ETSI ETSI TS 133 402 V13.1.0 (2017-01)63GPP TS 33
33、.402 version 13.1.0 Release 13Foreword This Technical Specification has been produced by the 3rdGeneration Partnership Project (3GPP). The contents of the present document are subject to continuing work within the TSG and may change following formal TSG approval. Should the TSG modify the contents o
34、f the present document, it will be re-released by the TSG with an identifying change of release date and an increase in version number as follows: Version x.y.z where: x the first digit: 1 presented to TSG for information; 2 presented to TSG for approval; 3 or greater indicates TSG approved document
35、 under change control. y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, updates, etc. z the third digit is incremented when editorial only changes have been incorporated in the document. ETSI ETSI TS 133 402 V13.1.0 (2017-01)73GPP TS 33.402 ve
36、rsion 13.1.0 Release 131 Scope The present document specifies the security architecture, i.e., the security feature groups and the security mechanisms performed during inter working between non-3GPP accesses and the Evolved Packet System (EPS). 2 References The following documents contain provisions
37、 which, through reference in this text, constitute provisions of the present document. References are either specific (identified by date of publication, edition number, version number, etc.) or non-specific. For a specific reference, subsequent revisions do not apply. For a non-specific reference,
38、the latest version applies. In the case of a reference to a 3GPP document (including a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same Release as the present document. 1 3GPP TR 21.905: “Vocabulary for 3GPP Specifications“. 2 IETF RFC 4877
39、: “Mobile IPv6 Operation with IKEv2 and the Revised IPsec Architecture“. 3 Void. 4 IETF RFC 5778: “Diameter Mobile IPv6: Support for Home Agent to Diameter Server Interaction“. 5 3GPP TS 23.402: “Architecture enhancements for non-3GPP accesses“. 6 3GPP TS 33.210: “3G security; Network Domain Securit
40、y (NDS); IP network layer security“. 7 IETF RFC 4187 (January 2006): “Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA)“. 8 3GPP TS 23.003: “Numbering, addressing and identification“. 9 3GPP TS 33.234: “3G: security; Wireless Local Area Network (
41、WLAN) interworking security“ (Release 12). 10 IETF RFC 4072 (August 2005): “Diameter Extensible Authentication Protocol (EAP) Application“. 11 3GPP TS 33.102: “3G security; Security architecture“. 12 3GPP TS 33.310: “Network Domain Security (NDS); Authentication Framework (AF)“. 13 3GPP TS 23.401: “
42、General Packet Radio Service (GPRS) enhancements for Evolved Universal Terrestrial Radio Access Network (E-UTRAN) access“. 14 3GPP TS 23.203: “Policy and charging control architecture“. 15 3GPP TS 36.300: “Evolved Universal Terrestrial Radio Access (E-UTRA) and Evolved Universal Terrestrial Radio Ac
43、cess (E-UTRAN); Overall description; Stage 2“. 16 3GPP TS 33.401: “3GPP System Architecture Evolution (SAE); Security Architecture“. 17 IETF RFC 3344: “IP Mobility Support for IPv4“. 18 IETF RFC 4555: “IKEv2 Mobility and Multihoming Protocol (MOBIKE)“. ETSI ETSI TS 133 402 V13.1.0 (2017-01)83GPP TS
44、33.402 version 13.1.0 Release 1319 IETF RFC 5295: “Specification for the Derivation of Root Keys from an Extended Master Session Key (EMSK)“. 20 3GPPP TS 24.303: “Mobility Management based on Dual-Stack Mobile IPv6; Stage 3“. 21 IETF RFC 4433: “Mobile IPv4 Dynamic Home Agent (HA) Assignment“. 22 3GP
45、P TS 24.302: “Access to the 3GPP Evolved Packet Core (EPC) via non-3GPP access networks; Stage 3 “. 23 IETF RFC 5448: “Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA) “. 24 3GPP TS 33.222: “Generic Authentication Architecture (GAA); Ac
46、cess to network application functions using Hypertext Transfer Protocol over Transport Layer Security (HTTPS)“. 25 3GPP TS 29.109: “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Generic Authentication Architecture (GAA); Zh and Zn Interfaces based on t
47、he Diameter protocol; Stage 3“. 26 - 28 Void. 29 3GPP TS 33.223: “Generic Authentication Architecture (GAA); Generic Bootstrapping Architecture (GBA) Push function“. 30 IETF RFC 5996: “Internet Key Exchange Protocol Version 2 (IKEv2)“. 31 3GPP TS 29.274: “3GPP Evolved Packet System (EPS); Evolved Ge
48、neral Packet Radio Service (GPRS) Tunnelling Protocol for Control plane (GTPv2-C); Stage 3“. 32 3GPP TS 29.275: “Proxy Mobile IPv6 (PMIPv6) based Mobility and Tunnelling protocols; Stage 3“. 33 IETF RFC 4739: “Multiple Authentication Exchanges in the Internet Key Exchange (IKEv2) Protocol“. 34 3GPP
49、TS 33.203: “Access security for IP-based services“. 35 IETF RFC 3948: “UDP Encapsulation of IPsec ESP Packets“. 36 IETF RFC 2616: “Hypertext Transfer Protocol - HTTP/1.1“. 37 IETF RFC 6347: “Datagram Transport Layer Security Version 1.2“. 38 3GPP TS 33.310: “Network Domain Security (NDS); Authentication Framework (AF)“. 39 3GPP TS 23.402: “Architecture enhancements for non-3GPP accesses“. 40 Federal Information Processing Standard (FIPS) draft standard: “Advanced Encryption Standard (AES)“,
copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
备案/许可证编号:苏ICP备17064731号-1