ETSI TS 102 723-8-2016 Intelligent Transport Systems (ITS) OSI cross-layer topics Part 8 Interface between security entity and network and transport layer (V1 1 1)《智能运输系统(ITS) OSI跨_1.pdf

上传人:twoload295 文档编号:739431 上传时间:2019-01-11 格式:PDF 页数:36 大小:287.04KB
下载 相关 举报
ETSI TS 102 723-8-2016 Intelligent Transport Systems (ITS) OSI cross-layer topics Part 8 Interface between security entity and network and transport layer (V1 1 1)《智能运输系统(ITS) OSI跨_1.pdf_第1页
第1页 / 共36页
ETSI TS 102 723-8-2016 Intelligent Transport Systems (ITS) OSI cross-layer topics Part 8 Interface between security entity and network and transport layer (V1 1 1)《智能运输系统(ITS) OSI跨_1.pdf_第2页
第2页 / 共36页
ETSI TS 102 723-8-2016 Intelligent Transport Systems (ITS) OSI cross-layer topics Part 8 Interface between security entity and network and transport layer (V1 1 1)《智能运输系统(ITS) OSI跨_1.pdf_第3页
第3页 / 共36页
ETSI TS 102 723-8-2016 Intelligent Transport Systems (ITS) OSI cross-layer topics Part 8 Interface between security entity and network and transport layer (V1 1 1)《智能运输系统(ITS) OSI跨_1.pdf_第4页
第4页 / 共36页
ETSI TS 102 723-8-2016 Intelligent Transport Systems (ITS) OSI cross-layer topics Part 8 Interface between security entity and network and transport layer (V1 1 1)《智能运输系统(ITS) OSI跨_1.pdf_第5页
第5页 / 共36页
点击查看更多>>
资源描述

1、 ETSI TS 102 723-8 V1.1.1 (2016-04) Intelligent Transport Systems (ITS); OSI cross-layer topics; Part 8: Interface between security entity and network and transport layer TECHNICAL SPECIFICATION ETSI ETSI TS 102 723-8 V1.1.1 (2016-04)2 Reference DTS/ITS-0050008 Keywords adaption, addressing, interfa

2、ce, ITS ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded

3、from: http:/www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or p

4、erceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to r

5、evision or change of status. Information on the current status of this and other ETSI documents is available at https:/portal.etsi.org/TB/ETSIDeliverableStatus.aspx If you find errors in the present document, please send your comment to one of the following services: https:/portal.etsi.org/People/Co

6、mmiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the writte

7、n authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2016. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM

8、and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TS 102 723-8 V1.1.1 (2016-04)3 Contents Intellectual Property Rights 5g3Foreword . 5g3Modal v

9、erbs terminology 5g3Introduction 5g31 Scope 6g32 References 6g32.1 Normative references . 6g32.2 Informative references 6g33 Definitions and abbreviations . 7g33.1 Definitions 7g33.2 Abbreviations . 7g34 Architecture integration 8g34.1 General . 8g34.1.1 Introduction. 8g34.1.2 Vertical message flow

10、. 8g34.1.3 Horizontal control communication . 9g34.1.4 Protocol work split 10g34.1.5 Multiple instances . 10g34.1.6 Error handling . 10g34.2 Security services . 10g35 Interfaces between the security entity and the networking and transport layers 11g35.1 Interface services 11g35.2 Service primitives

11、and parameters 12g35.2.1 SN-SIGN 12g35.2.1.1 Description 12g35.2.1.2 SN-SIGN.request 12g35.2.1.3 SN-SIGN.confirm . 13g35.2.2 SN-VERIFY . 13g35.2.2.1 Description 13g35.2.2.2 SN-VERIFY.request . 13g35.2.2.3 SN-VERIFY.confirm 13g35.2.3 SN-ENCRYPT 14g35.2.3.1 Description 14g35.2.3.2 SN-ENCRYPT.request 1

12、4g35.2.3.3 SN-ENCRYPT.confirm 15g35.2.4 SN-DECRYPT 15g35.2.4.1 Description 15g35.2.4.2 SN-DECRYPT.request 15g35.2.4.3 SN-DECRYPT.confirm 15g35.2.5 SN-IDCHANGE-SUBSCRIBE 15g35.2.5.1 Description 15g35.2.5.2 SN-IDCHANGE-SUBSCRIBE.request 16g35.2.5.3 SN-IDCHANGE-SUBSCRIBE.confirm . 16g35.2.6 SN-IDCHANGE

13、-EVENT . 16g35.2.6.1 Description 16g35.2.6.2 SN-IDCHANGE-EVENT.indication 16g35.2.6.3 SN-IDCHANGE-EVENT.response 16g35.2.7 SN-IDCHANGE-UNSUBSCRIBE 17g35.2.7.1 Description 17g35.2.7.2 SN-IDCHANGE-UNSUBSCRIBE.request 17g35.2.7.3 SN-IDCHANGE-UNSUBSCRIBE.confirm . 17g35.2.8 SN-IDCHANGE-TRIGGER. 17g35.2.

14、8.1 Description 17g35.2.8.2 SN-IDCHANGE-TRIGGER.request 17g3ETSI ETSI TS 102 723-8 V1.1.1 (2016-04)4 5.2.8.3 SN-IDCHANGE-TRIGGER.confirm . 17g35.2.9 SN-ID-LOCK . 17g35.2.9.1 Description 17g35.2.9.2 SN-ID-LOCK.request . 18g35.2.9.3 SN-ID-LOCK.confirm 18g35.2.10 SN-ID-UNLOCK 18g35.2.10.1 Description 1

15、8g35.2.10.2 SN-ID-UNLOCK.request 18g35.2.10.3 SN-ID-UNLOCK.confirm 18g35.2.11 SN-LOG-SECURITY-EVENT. 18g35.2.11.1 Description 18g35.2.11.2 SN-LOG-SECURITY-EVENT.request 18g35.2.11.3 SN-LOG-SECURITY-EVENT.confirm . 21g35.2.12 SN-ENCAP . 21g35.2.12.1 Description 21g35.2.12.2 SN-ENCAP.request . 21g35.2

16、.12.3 SN-ENCAP.confirm 21g35.2.13 SN-DECAP . 22g35.2.13.1 Description 22g35.2.13.2 SN-DECAP.request . 22g35.2.13.3 SN-DECAP.confirm 22g36 SN-SAP procedures 23g36.1 Outbound message handling. 23g36.1.1 Using SN-SIGN and SN-ENCRYPT 23g36.1.2 Using SN-ENCAP 24g36.2 Inbound message handling . 24g36.2.1

17、Using SN-VERIFY and SN-DECRYPT . 24g36.2.2 Using SN-DECAP 24g36.3 ID Management 25g36.3.1 IDCHANGE Notifications 25g36.3.1.1 Introduction . 25g36.3.1.2 Id-change event hook 25g36.3.1.3 Two phase commit process . 25g36.3.2 Prevent IDCHANGES 28g36.3.3 Trigger IDCHANGES 29g36.4 Log security event 29g3A

18、nnex A (informative): SN-Command . 30g3A.1 Overview 30g3A.2 Description . 30g3A.2.1 SN-IDCHANGE-EVENT service: SN-COMMAND.request (see clause 5.2.6.2) 30g3A.2.2 SN-IDCHANGE-EVENT service: SN-COMMAND.confirm (see clause 5.2.6.3) . 31g3Annex B (informative): SN-Request . 32g3B.1 Overview 32g3B.2 Descr

19、iption . 32g3B.2.1 SN-ENCRYPT service: SN-REQUEST.request (see clause 5.2.3.2) . 32g3B.2.2 SN-ENCRYPT service: SN-REQUEST.confirm (see clause 5.2.3.3) 33g3Annex C (informative): Example of service primitives description in the framework of ISO 24102-3 34g3C.1 Overview 34g3C.1.1 Introduction 34g3C.1.

20、2 Class for SN-SAP Command.request service primitive functions . 34g3C.1.3 Class for SN-SAP Command.confirm service primitive functions 34g3C.1.4 Class for SN-SAP Request.request service primitive functions . 35g3C.1.5 Class for SN-SAP Request.confirm service primitive functions 35g3History 36g3ETSI

21、 ETSI TS 102 723-8 V1.1.1 (2016-04)5 Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ET

22、SI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server (https:/ipr.etsi.org/). Pursuant to the ETSI IPR Policy, no

23、 investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the present document. Foreword This Technical

24、Specification (TS) has been produced by ETSI Technical Committee Intelligent Transport Systems (ITS). The present document is part 8 of a multi-part deliverable. Full details of the entire series can be found in part 1 i.1. Modal verbs terminology In the present document “shall“, “shall not“, “shoul

25、d“, “should not“, “may“, “need not“, “will“, “will not“, “can“ and “cannot“ are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. Int

26、roduction ITS stations are complex systems that may be implemented in different ways. The reference architecture is described in the communications architecture standard ETSI EN 302 665 1, clause 4.4. The present document aims to address the security interface from a functional point of view. Access

27、 control to the Service Access Point and further definitions of station internals are out of scope of the present document. The SAP specification is specific to the ITS architecture but generic to the concrete technologies used. Therefore, the present document is structured in the following way: Fir

28、st, the architecture integration is outlined. Secondly, functionalities are collected from related standards and mapped to service primitives. Finally, the use of service primitives in procedures is described. ETSI ETSI TS 102 723-8 V1.1.1 (2016-04)6 1 Scope The present document specifies interfaces

29、 between the ITS security entity and the ITS network and transport layers including interface services and service primitives which are extensible in order to achieve general applicability. Additionally, it specifies related procedures and common parameters. The SN-SAP description in the present doc

30、ument is functional as according to the ISO model as modified by ETSI EN 302 665 1. 2 References 2.1 Normative references References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references, only the cited version applie

31、s. For non-specific references, the latest version of the referenced document (including any amendments) applies. Referenced documents which are not found to be publicly available in the expected location might be found at https:/docbox.etsi.org/Reference/. NOTE: While any hyperlinks included in thi

32、s clause were valid at the time of publication, ETSI cannot guarantee their long term validity. The following referenced documents are necessary for the application of the present document. 1 ETSI EN 302 665: “Intelligent Transport Systems (ITS); Communications Architecture“. 2 ETSI TS 102 940: “Int

33、elligent Transport Systems (ITS); Security; ITS communications security architecture and security management“. 2.2 Informative references References are either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references, only the cite

34、d version applies. For non-specific references, the latest version of the referenced document (including any amendments) applies. NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee their long term validity. The following referenced documen

35、ts are not necessary for the application of the present document but they assist the user with regard to a particular subject area. i.1 ETSI TS 102 723-1: “Intelligent Transport Systems (ITS); OSI cross-layer topics; Part 1: Architecture and addressing schemes“. i.2 ETSI TS 101 539-2: “Intelligent T

36、ransport System (ITS); V2X Applications; Intersection Collision Risk Warning (ICRW) application requirements specification“. i.3 ETSI TS 101 539-3: “Intelligent Transport Systems (ITS); V2X Applications; Part 3: Longitudinal Collision Risk Warning (LCRW) application requirements specification“. i.4

37、PRE-DRIVE C2X Deliverable D1.3: “Security Architecture“. i.5 EVITA Deliverable D3.2: “Secure On-board Architecture Specification“. i.6 ETSI TS 102 637-1: “Intelligent Transport Systems (ITS); Vehicular Communications; Basic Set of Applications; Part 1: Functional Requirements“. i.7 ETSI TS 102 637-2

38、: “Intelligent Transport Systems (ITS);Vehicular Communications; Basic Set of Applications; Part 2: Specification of Cooperative Awareness Basic Service“. ETSI ETSI TS 102 723-8 V1.1.1 (2016-04)7 i.8 ETSI ES 202 663: “Intelligent Transport Systems (ITS); European profile standard for the physical an

39、d medium access control layer of Intelligent Transport Systems operating in the 5 GHz frequency band“. i.9 ISO 24102-3: “Intelligent transport systems - Communications access for land mobiles (CALM) - ITS station management - Part 3: Service access points“. i.10 ETSI TS 103 097: “Intelligent Transpo

40、rt Systems (ITS); Security; Security header and certificate formats“. 3 Definitions and abbreviations 3.1 Definitions For the purposes of the present document, the terms and definitions given in ETSI EN 302 665 1, ETSI TS 102 940 2 and the following apply: security association: addressing informatio

41、n and security material for connecting to the security management entity NOTE: This corresponds to enrolment authorities and authorization authorities. security entity: functional entity inside an ITS station which offers security mechanisms security protocol: protocol used to encode and decode secu

42、rity material and messages between ITS Stations 3.2 Abbreviations For the purposes of the present document, the abbreviations given in ETSI EN 302 665 1, ETSI TS 102 940 2 and the following apply: ASN Abstract Syntax Notation CAM Cooperative Awareness Message DENM Decentralized Environmental Notific

43、ation Message ICRW Intersection Collision Risk Warning ID pseudonym identity IN-SAP access layer - networking & transport layer SAP ISO International Organization for Standardization ITS-S ITS-Station LCRW Longitudinal Collision Risk Warning NF-SAP Networking & transport layer - Facilities layer SAP

44、 RX ReceiverSA Security Association NOTE: SA is contextual dependent either “name of interface between security entity and ITS-S applications“ as given in ETSI EN 302 665 1 or “Security Association“. SAP Service Access Point SF-SAP Security entity - Facilities layer SAP SN-SAP Security entity - Netw

45、orking & transport layer SAP TX TransmitterETSI ETSI TS 102 723-8 V1.1.1 (2016-04)8 4 Architecture integration 4.1 General 4.1.1 Introduction Figure 1 shows the ITS station reference architecture, as defined in ETSI EN 302 665 1. The present document contains the specification of the Service Access

46、Points (SAP), connecting the security entity and the networking and transport layers, i.e. SN-SAP. Figure 1: ITS station reference architecture Interaction between the security entity and the layers may follow two principles. First, the vertical message flow through the layers from top to bottom or

47、vice versa. Secondly, the horizontal control communication from the security entity towards the corresponding layer. Both are described in clauses 4.1.2 and 4.1.3. 4.1.2 Vertical message flow Figure 2 extends the ITS station reference architecture by illustrating the overall information flow through

48、 the layers, from originating application on the left hand side, to the receiving application on the right hand side. Figure 2: TX (left) and RX (right) information flow through the ITS station ETSI ETSI TS 102 723-8 V1.1.1 (2016-04)9 The present document specifies only the SN-SAP, therefore only a

49、subset of the ITS station reference architecture has to be taken into account. Figure 3 shows the typical information flow between any sending (TX) and receiving (RX) party, with regard to the SN-SAP only. The security entity acts like a layer inside the networking and transport layers, i.e. it is called during the processing of messages traversing the networking and transport layers. The security entity will however not act as a layer above or below the networking and transport layers. This means that interactions wi

展开阅读全文
相关资源
猜你喜欢
  • DIN EN 50128-2012 Railway applications - Communication signalling and processing systems - Software for railway control and protection systems German version EN 50128 2011《轨道交通 通信、.pdf DIN EN 50128-2012 Railway applications - Communication signalling and processing systems - Software for railway control and protection systems German version EN 50128 2011《轨道交通 通信、.pdf
  • DIN EN 50129 Bb 1-2008 Railway applications - Communication signalling and processing systems - Application Guide for EN 50129 - Part 1 Cross-acceptance German version CLC TR 50506.pdf DIN EN 50129 Bb 1-2008 Railway applications - Communication signalling and processing systems - Application Guide for EN 50129 - Part 1 Cross-acceptance German version CLC TR 50506.pdf
  • DIN EN 50130 Bb 1-2008 Alarm systems - Guidelines to achieving compliance with EC directives for equipment of alarm systems German version CLC TR 50456 2008《报警系统 实现报警系统设备与EC指令一致用指南.pdf DIN EN 50130 Bb 1-2008 Alarm systems - Guidelines to achieving compliance with EC directives for equipment of alarm systems German version CLC TR 50456 2008《报警系统 实现报警系统设备与EC指令一致用指南.pdf
  • DIN EN 50130-5-2012 Alarm systems - Part 5 Environmental test methods German version EN 50130-5 2011《警报设备 第5部分 环境试验方法》.pdf DIN EN 50130-5-2012 Alarm systems - Part 5 Environmental test methods German version EN 50130-5 2011《警报设备 第5部分 环境试验方法》.pdf
  • DIN EN 50131-2-2-2008 Alarm systems - Intrusion and hold-up systems - Part 2-2 Intrusion detectors - Passive infrared detectors German version EN 50131-2-2 2008《报警设备 侵入和拦截系统 第2-2部分.pdf DIN EN 50131-2-2-2008 Alarm systems - Intrusion and hold-up systems - Part 2-2 Intrusion detectors - Passive infrared detectors German version EN 50131-2-2 2008《报警设备 侵入和拦截系统 第2-2部分.pdf
  • DIN EN 50131-2-3-2009 Alarm systems - Intrusion and hold-up systems - Part 2-3 Requirements for microwave detectors German version EN 50131-2-3 2008《报警系统 入侵和拦截系统 第2-3部分 微波探测器要求》.pdf DIN EN 50131-2-3-2009 Alarm systems - Intrusion and hold-up systems - Part 2-3 Requirements for microwave detectors German version EN 50131-2-3 2008《报警系统 入侵和拦截系统 第2-3部分 微波探测器要求》.pdf
  • DIN EN 50131-2-5-2009 Alarm systems - Intrusion and hold-up systems - Part 2-5 Requirements for combined passive infrared and ultrasonic detectors German version EN 50131-2-5 2008《.pdf DIN EN 50131-2-5-2009 Alarm systems - Intrusion and hold-up systems - Part 2-5 Requirements for combined passive infrared and ultrasonic detectors German version EN 50131-2-5 2008《.pdf
  • DIN EN 50131-2-6-2009 Alarm systems - Intrusion and hold-up systems - Part 2-6 Opening contacts (magnetic) German version EN 50131-2-6 2008《报警系统 入侵和拦截系统 第2-6部分 开放式(磁性)触点》.pdf DIN EN 50131-2-6-2009 Alarm systems - Intrusion and hold-up systems - Part 2-6 Opening contacts (magnetic) German version EN 50131-2-6 2008《报警系统 入侵和拦截系统 第2-6部分 开放式(磁性)触点》.pdf
  • DIN EN 50131-3-2010 Alarm systems - Intrusion and hold-up systems - Part 3 Control and indicating equipment German version EN 50131-3 2009《报警系统 侵入和拦截系统 第3部分 控制和显示设备 德文版本EN 50131-3-.pdf DIN EN 50131-3-2010 Alarm systems - Intrusion and hold-up systems - Part 3 Control and indicating equipment German version EN 50131-3 2009《报警系统 侵入和拦截系统 第3部分 控制和显示设备 德文版本EN 50131-3-.pdf
  • 相关搜索

    当前位置:首页 > 标准规范 > 国际标准 > 其他

    copyright@ 2008-2019 麦多课文库(www.mydoc123.com)网站版权所有
    备案/许可证编号:苏ICP备17064731号-1