1、 ETSI TS 102 921 V1.3.1 (2014-09) Machine-to-Machine communications (M2M); mIa, dIa and mId interfaces floppy3TECHNICAL SPECIFICATION ETSI ETSI TS 102 921 V1.3.1 (2014-09)2Reference RTS/M2M-00010ed131 Keywords interface, M2M, protocol, service ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Ced
2、ex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org The present document may be made availa
3、ble in electronic versions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only p
4、revailing document is the print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other
5、ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced or utilized in any form or
6、 by any means, electronic or mechanical, including photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all
7、media. European Telecommunications Standards Institute 2014. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizat
8、ional Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TS 102 921 V1.3.1 (2014-09)3Contents Intellectual Property Rights 22g3Foreword . 22g3Modal verbs terminology 22g31 Scope 23g32 References 23g32.1 Normative references . 23g32.2 Informative ref
9、erences 26g33 Definitions, symbols, abbreviations and conventions 27g33.1 Definitions 27g33.2 Symbols 27g33.3 Abbreviations . 27g33.4 Conventions 27g34 Overview 27g35 General security aspects . 28g35.1 Key provisioning and hierarchy derivation 28g35.1.1 Kmr provisioning 28g35.1.1.1 Kmr provisioning
10、independent of access network credentials 28g35.1.1.2 Kmr provisioning based on access network credentials 28g35.1.1.3 Kmr refresh and invalidation. 28g35.1.2 Kmc derivation . 29g35.1.2.1 Kmc derivation in the case of EAP based mutual authentication and key agreement . 29g35.1.2.2 Kmc derivation in
11、the case of GBA based mutual authentication and key agreement 29g35.1.2.3 Kmc derivation in the case of TLS based mutual authentication and key agreement . 29g35.1.2.4 Kmc refresh and invalidation 29g35.2 Security Assumptions . 29g36 M2M Service Bootstrapping 30g36.1 General Principles 30g36.2 Acces
12、s Network Assisted M2M Service Bootstrap Procedure . 30g36.2.1 GBA-based M2M Service Bootstrap Procedure . 30g36.2.1.1 Optional use of GBA_U with Ks_int_NAF 30g36.2.1.2 HTTP Digest Authentication and bootstrap parameter delivery . 31g36.2.1.3 M2M Root Key (Kmr) derivation . 31g36.2.2 EAP-based boots
13、trapping procedure using SIM/AKA Access Network Credentials . 32g36.2.3 Bootstrapping from EAP-based access network layer 33g36.3 Bootstrapping using other methods 34g36.3.1 Bootstrapping methods using EAP over PANA . 34g36.3.1.1 Generic procedure . 34g36.3.1.1.1 Bootstrapping 34g36.3.1.1.2 Bootstra
14、p-Erase . 38g36.3.1.2 EAP/PANA - IBAKE bootstrapping operations . 42g36.3.1.2.1 Provisioning of IBE specific parameters . 43g36.3.1.2.2 Secure IBAKE protocol . 44g36.3.1.3 EAP-TLS over PANA . 45g36.3.2 M2M Service Bootstrap Procedure using TLS over TCP . 45g36.3.2.1 Recap of M2M Service Bootstrap Pr
15、ocedure using TLS over TCP 45g36.3.2.2 Pre-Provisioning for M2M Service Bootstrap Procedure using TLS over TCP 46g36.3.2.3 Mutual Authentication for M2M Service Bootstrap Procedure using TLS over TCP 46g36.3.2.4 Parameter Delivery to D/G M2M Node for M2M Service Bootstrap Procedure using TLS over TC
16、P . 46g36.3.3 Specifications for TLS/Certificate-Based M2M Service Bootstrap Procedures . 46g36.3.3.1 Introduction . 46g36.3.3.2 TLS Details for TLS/Certificate-Based M2M Service Bootstrap Procedures . 47g3ETSI ETSI TS 102 921 V1.3.1 (2014-09)46.3.3.3 Certificate Considerations . 47g36.3.3.3.1 M2M D
17、evice/Gateway Certificate Considerations 47g36.3.3.3.2 MSBF Certificate Considerations 48g36.4 M2M Service Bootstrap Parameter Delivery Procedure For Procedures using HTTP . 49g36.4.1 Overview 49g36.4.2 bootstrapParamSet Resource 50g36.4.2.1 bootstrapParamSet Resource URI . 50g36.4.2.2 bootstrapPara
18、mSet Resource Attributes 50g36.4.3 M2M Service Bootstrap Parameter Delivery Procedure Primitives . 50g36.4.3.1 bootstrapParamSetExecuteRequestIndication . 50g36.4.3.2 bootstrapParamSetExecuteResponseConfirm (successful case) . 51g36.4.3.3 bootstrapParamSetExecuteResponseConfirm (unsuccessful case) .
19、 51g36.4.4 MSBF Filtering of Received bootstrapParamSetExecuteRequestIndication Primitives . 51g36.4.5 M2M Service Bootstrap Parameter Delivery Procedure Sequence of Events 52g37 M2M Service Connection Procedures 54g37.1 General principles. 54g37.2 M2M Service Connection Procedures leveraging access
20、 network credentials . 55g37.2.1 M2M Service Connection Procedure based on GBA . 55g37.2.1.1 TLS-PSK with GBA bootstrapped security association 55g37.2.1.1.1 M2M Connection Key (Kmc) derivation 56g37.2.2 M2M Service Connection Procedure Based On EAP/PANA with Access Network Credentials . 57g37.3 M2M
21、 Service Connection Procedures using EAP/PANA 57g37.3.1 M2M Service Connection Setup Procedure using EAP/PANA 57g37.3.2 M2M Service Connection Tear-down Procedure using EAP/PANA . 60g37.4 M2M Service Connection Procedure based on TLS-PSK 60g37.4.1 Introduction. 60g37.4.2 TLS Details for M2M Service
22、Connection Procedure Based On TLS-PSK . 60g37.4.3 Sequence of events for M2M Service Connection Procedure based on TLS-PSK . 61g37.4.4 Parameter Delivery to D/G M2M Node for M2M Service Connection Procedure based on TLS-PSK . 61g37.4.5 M2M Service Connection Parameter Delivery Procedure For TLS-PSK-
23、Based Procedures . 62g37.4.5.1 Overview . 62g37.4.5.2 connectionParamSet Resource 62g37.4.5.2.1 connectionParamSet Resource URI . 62g37.4.5.2.2 connectionParamSet Resource Attributes 62g37.4.5.3 M2M Service Connection Parameter Delivery Procedure Primitives . 63g37.4.5.3.1 connectionParamSetExecuteR
24、equestIndication . 63g37.4.5.3.2 connectionParamSetExecuteResponseConfirm (successful case) . 63g37.4.5.3.3 connectionParamSetExecuteResponseConfirm (unsuccessful case) . 64g37.4.5.4 M2M Service Connection Parameter Delivery Procedure Pre-Conditions . 64g37.4.5.5 MAS Filtering of Received connection
25、ParamSetExecuteRequestIndication Primitives . 64g37.4.5.6 M2M Service Connection Parameter Delivery Sequence of Events . 64g37.5 IVal security attributes in connection establishment 68g38 M2M Secure Communication over mId . 68g38.1 Access Network Based Security . 68g38.2 Channel Security 68g38.2.1 S
26、upported Channel Security Methods 68g38.2.1.1 Negotiation to use a Channel Security Method . 69g38.2.1.2 Supported TLS/DTLS Versions and TLS Cipher Suites for Channel Security Methods 69g38.2.1.3 Details of the DTLS/TLS Handshake . 69g38.2.1.3.1 Applicability to DTLS and TLS 69g38.2.1.3.2 TLS Client
27、Hello.server_name Field Details For Channel Security Methods 70g38.2.1.3.3 TLS ServerKeyExchange.psk_identity_hint Field Details For Channel Security Methods 70g38.2.1.3.4 TLS ClientKeyExchange.psk_identity and PSK Derivation for Channel Security Methods 70g38.3 Object Security . 71g38.3.1 Securing
28、CoAP-based mId 71g38.3.2 Securing XML-based mId 71g39 Resources . 71g310 SCL Primitives . 72g310.1 Introduction 72g3ETSI ETSI TS 102 921 V1.3.1 (2014-09)510.2 General aspects . 72g310.2.1 SCL primitives 72g310.2.2 Asynchronous and semi-asynchronous processing . 73g310.3 Common operations . 73g310.3.
29、1 Issuer actions 73g310.3.1.1 Compose RequestIndication primitive 73g310.3.1.2 Send a RequestIndication to the Receiver SCL . 74g310.3.1.2.1 Determination of the Receiver SCL 74g310.3.1.2.2 Selection of communication channel . 74g310.3.1.3 Wait for ResponseConfirm primitive 80g310.3.2 Hosting SCL ac
30、tions . 81g310.3.2.1 Check existence of the addressed resource . 81g310.3.2.2 Check the syntax of received message 81g310.3.2.3 Check validity of resource representation for CREATE . 81g310.3.2.4 Check validity of resource representation for UPDATE . 81g310.3.2.5 Check authorization of the requestin
31、gEntity based on accessRightID 82g310.3.2.6 Check authorization of the requestingEntity based on selfPermission 83g310.3.2.7 Check authorization of the requestingEntity based on default access rights . 84g310.3.2.8 Announce resource 84g310.3.2.8.1 Update of announce on request of application. 85g310
32、.3.2.8.2 Update of announce on request of local SCL 86g310.3.2.8.3 Create announced Resource . 87g310.3.2.8.4 Retrieve announced Resource . 87g310.3.2.8.5 Update announced Resource . 88g310.3.2.8.6 Delete announced Resource . 88g310.3.2.9 DeAnnounce resource . 88g310.3.2.10 Create the resource 89g31
33、0.3.2.11 Create a collection resource representation . 90g310.3.2.12 Create a successful ResponseConfirm 90g310.3.2.13 Create an unsuccessful ResponseConfirm 90g310.3.2.14 Read the addressed resource . 90g310.3.2.15 Update the addressed resource 90g310.3.2.16 Delete the addressed resource . 91g310.3
34、.2.17 Send ResponseConfirm primitive . 91g310.3.2.18 Identify the managed remote entity and the management protocol . 91g310.3.2.19 Locate the MO information to be managed on the remote entity 91g310.3.2.20 Establish a management session with the remote entity 92g310.3.2.21 Send the management reque
35、st(s) to the remote entity corresponding to the received RequestIndication primitive 92g310.3.2.22 Identify the managed remote entity and the management protocol . 93g310.3.2.23 SCL retargeting to an application 95g310.3.3 Receiver SCL actions 97g310.3.3.1 Re-targeting . 97g310.4 resource and manage
36、ment procedures 98g310.4.1 resource . 98g310.4.2 sclBaseCreate 98g310.4.3 sclBaseRetrieve . 99g310.4.3.1 sclBaseRetrieveRequestIndication 99g310.4.3.2 sclBaseRetrieveResponseConfirm (successful case) 100g310.4.3.3 sclBaseRetrieveResponseConfirm (unsuccessful case). 100g310.4.4 sclBaseUpdate . 100g31
37、0.4.4.1 sclBaseUpdateRequestIndication 100g310.4.4.2 sclBaseUpdateResponseConfirm (successful case) 101g310.4.4.3 sclBaseUpdateResponseConfirm (unsuccessful case) 101g310.4.5 sclBaseDelete 101g310.5 scls resource and management procedures . 102g310.5.1 scls resource 102g310.5.2 sclsCreate 102g310.5.
38、3 sclsRetrieve . 102g310.5.3.1 sclsRetrieveRequestIndication 102g310.5.3.2 sclsRetrieveResponseConfirm (successful case) . 103g310.5.3.3 sclsRetrieveResponseConfirm (unsuccessful case) . 103g3ETSI ETSI TS 102 921 V1.3.1 (2014-09)610.5.4 sclsUpdate . 104g310.5.4.1 sclsUpdateRequestIndication 104g310.
39、5.4.2 sclsUpdateResponseConfirm (successful case) . 105g310.5.4.3 sclsUpdateResponseConfirm (unsuccessful case) . 105g310.5.5 sclsDelete 105g310.6 resource and management procedures 106g310.6.1 resource . 106g310.6.2 sclCreate . 108g310.6.2.1 sclCreateRequestIndication . 108g310.6.2.2 sclCreateRepon
40、seConfirm(successful case) 111g310.6.2.3 sclCreateReponseConfirm(unsuccessful case) 111g310.6.3 sclRetrieve 111g310.6.3.1 sclRetrieveRequestIndication 111g310.6.3.2 sclRetrieveResponseConfirm (successful case) 112g310.6.3.3 sclRetrieveResponseConfirm (unsuccessful case) 112g310.6.4 sclUpdate 113g310
41、.6.4.1 sclUpdateRequestIndication 113g310.6.4.2 sclUpdateResponseConfirm (successful case) 114g310.6.4.3 sclUpdateResponseConfirm (unsuccessful case) 114g310.6.5 sclDelete . 115g310.6.5.1 sclDeleteRequestIndication . 115g310.6.5.2 sclDeleteResponseConfirm (successful case) . 116g310.6.5.3 sclDeleteR
42、esponseConfirm (unsuccessful case) . 116g310.7 applications resource and management procedures 116g310.7.1 applications resource. 116g310.7.2 applicationsCreate . 117g310.7.3 applicationsRetrieve 117g310.7.3.1 applicationsRetrieveRequestIndication . 117g310.7.3.2 applicationsRetrieveResponseConfirm
43、(successful case) . 118g310.7.3.3 sclsRetrieveResponseConfirm (unsuccessful case) . 118g310.7.4 applicationsUpdate 118g310.7.4.1 applicationsUpdateRequestIndication . 118g310.7.4.2 applicationsUpdateResponseConfirm (successful case) . 119g310.7.4.3 applicationsUpdateResponseConfirm (unsuccessful cas
44、e) . 119g310.7.5 applicationsDelete . 119g310.8 resource and management procedures . 120g310.8.1 resource 120g310.8.2 applicationCreate 120g310.8.2.1 applicationCreateRequestIndication 120g310.8.2.2 applicationCreateResponseConfirm (successful case) 121g310.8.2.3 applicationCreateResponseConfirm (un
45、successful case) 122g310.8.3 applicationRetrieve . 122g310.8.3.1 applicationRetrieveRequestIndication . 122g310.8.3.2 applicationRetrieveResponseConfirm (successful case) . 123g310.8.3.3 applicationRetrieveResponseConfirm (unsuccessful case) . 123g310.8.4 applicationUpdate . 123g310.8.4.1 applicatio
46、nUpdateRequestIndication 123g310.8.4.2 applicationUpdateResponseConfirm (successful case) . 125g310.8.4.3 applicationUpdateResponseConfirm (unsuccessful case) . 125g310.8.5 applicationDelete 125g310.8.5.1 applicationDeleteRequestIndication 125g310.8.5.2 applicationDeleteResponseConfirm (successful c
47、ase) 126g310.8.5.3 applicationDeleteResponseConfirm (unsuccessful case) 126g310.9 resource and management procedures . 127g310.9.1 resource . 127g310.9.2 applicationAnncCreate 127g310.9.2.1 applicationAnncCreateRequestIndication . 127g310.9.2.2 applicationAnncCreateResponseConfirm (successful case)
48、. 128g310.9.2.3 applicationAnncCreateResponseConfirm (unsuccessful case) 128g310.9.3 applicationAnncRetrieve 128g310.9.3.1 applicationAnncRetrieveRequestIndication 128g310.9.3.2 applicationAnncRetrieveResponseConfirm (successful case) 129g3ETSI ETSI TS 102 921 V1.3.1 (2014-09)710.9.3.3 applicationAn
49、ncRetrieveResponseConfirm (unsuccessful case) 129g310.9.4 applicationAnncUpdate 129g310.9.4.1 applicationAnncUpdateRequestIndication 129g310.9.4.2 applicationAnncUpdateResponseConfirm (successful case) 130g310.9.4.3 applicationAnncUpdateResponseConfirm (unsuccessful case) 130g310.9.5 applicationAnncDelete 130g310.9.5.1 applicationAnncDeleteRequestIndication . 130g310.9.5.2 applicationAnncDeleteResponseConfirm (successful case) . 131g310.9.5.3 applicationAnncDeleteResponseConfirm (unsuccessful case) 131g310.10 accessRights resource and management procedures 131g310.10.1 accessRi