1、 ETSI TS 1Digital cellular telecUniversal Mobile TeFraud InformatSe(3GPP TS 22.0TECHNICAL SPECIFICATION122 031 V13.0.0 (2016ecommunications system (PhasTelecommunications System (ULTE; 3G Security; a ion Gathering System (FIGS)Service description; Stage 1 .031 version 13.0.0 Release 1316-02) ase 2+)
2、; (UMTS); S); 13) ETSI ETSI TS 122 031 V13.0.0 (2016-02)13GPP TS 22.031 version 13.0.0 Release 13Reference RTS/TSGS-0322031vd00 Keywords GSM,LTE,SECURITY,UMTS ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017
3、- NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice The present document can be downloaded from: http:/www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any elect
4、ronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (PDF
5、) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at http:/portal.etsi.org/tb/status/statu
6、s.asp If you find errors in the present document, please send your comment to one of the following services: https:/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopy
7、ing and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2016.
8、 All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registe
9、red and owned by the GSM Association. ETSI ETSI TS 122 031 V13.0.0 (2016-02)23GPP TS 22.031 version 13.0.0 Release 13Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any
10、, is publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on
11、 the ETSI Web server (https:/ipr.etsi.org/). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or ma
12、y be, or may become, essential to the present document. Foreword This Technical Specification (TS) has been produced by ETSI 3rd Generation Partnership Project (3GPP). The present document may refer to technical specifications or reports using their 3GPP identities, UMTS identities or GSM identities
13、. These should be interpreted as being references to the corresponding ETSI deliverables. The cross reference between GSM, UMTS, 3GPP and ETSI identities can be found under http:/webapp.etsi.org/key/queryform.asp. Modal verbs terminology In the present document “shall“, “shall not“, “should“, “shoul
14、d not“, “may“, “need not“, “will“, “will not“, “can“ and “cannot“ are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. ETSI ETSI TS
15、122 031 V13.0.0 (2016-02)33GPP TS 22.031 version 13.0.0 Release 13Contents Intellectual Property Rights 2g3Foreword . 2g3Modal verbs terminology 2g3Foreword . 4g31 Scope 5g32 Normative references . 5g33 Definitions and abbreviations . 5g33.1 Definitions 5g33.2 Abbreviations . 6g34 Fraud Information
16、Gathering System high level requirements 6g34.1 Description . 6g34.2 Applicability . 6g34.3 Normal Procedure. 6g35 Service conditions 7g35.1 Control of monitoring of subscriber activities 7g35.2 Number of calls monitored by a VPLMN 7g35.3 Interworking with non-supporting networks 7g35.4 Information
17、Delivery Time. 8g36 Monitored activity 8g37 Interface between HPLMN and FDS . 8g38 Security Requirements between HPLMN and VPLMN 8g3Annex A (normative): Information transferred by the VPLMN . 9g3Annex B (normative): Message flow in FIGS monitoring, normal procedure . 11g3Annex C (informative): Chang
18、e history . 12g3History 13g3ETSI ETSI TS 122 031 V13.0.0 (2016-02)43GPP TS 22.031 version 13.0.0 Release 13Foreword This Technical Specification has been produced by the 3rdGeneration Partnership Project (3GPP). The contents of the present document are subject to continuing work within the TSG and m
19、ay change following formal TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an identifying change of release date and an increase in version number as follows: Version x.y.z where: x the first digit: 1 presented to TSG for information;
20、2 presented to TSG for approval; 3 or greater indicates TSG approved document under change control. y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, updates, etc. z the third digit is incremented when editorial only changes have been incorpora
21、ted in the document. ETSI ETSI TS 122 031 V13.0.0 (2016-02)53GPP TS 22.031 version 13.0.0 Release 131 Scope This Technical Specification specifies the stage 1 description of the Fraud Information Gathering System (FIGS) feature which provides the means for the HPLMN to monitor the activities of its
22、subscribers in a VPLMN. The purpose of this network feature is to enable the HPLMN to monitor the activities of its subscribers while they are roaming. The VPLMN collects information about a defined set of activities on monitored subscribers and sends this information back to the HPLMN. This enables
23、 the HPLMN to clear certain types of calls and so stop fraudulent use of the GSM system. This specification enables service providers/ network operators to use FIGS, and service limitation controls such as Operator Determined Barring (ODB) and Immediate Service Termination (IST), to limit their fina
24、ncial exposure to subscribers producing large unpaid bills. HPLMNs may also choose to monitor the activities of its subscribers within the HPLMN. 2 Normative references The following documents contain provisions which, through reference in this text, constitute provisions of the present document. Re
25、ferences are either specific (identified by date of publication, edition number, version number, etc.) or non-specific. For a specific reference, subsequent revisions do not apply. For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including a GS
26、M document), a non-specific reference implicitly refers to the latest version of that document in the same Release as the present document. 1 GSM 01.04: “Digital cellular telecommunications system (Phase 2+); Abbreviations and acronyms“. 2 3GPP TS 42.033: “Digital cellular telecommunications system
27、(Phase 2+); Lawful Interception - stage 1“. 3 Definitions and abbreviations 3.1 Definitions For the purposes of this specification the following definitions apply: A subscriber: The calling mobile subscriber. B subscriber: The mobile subscriber originally called by the A subscriber. C subscriber: Th
28、e subscriber to whom the B subscriber has requested that calls be forwarded. The C subscriber may be fixed or mobile. call: both connection-oriented and connectionless services/events. call information: information about a call. call reference: a reference number for a call that shall remain constan
29、t throughout the duration of that call and that shall be unique to that call and the switch on which the call was made for a period of at least one week. home network: The home PLMN including non-GSM elements such as the Fraud Detection System (FDS), customer service systems and billing. ETSI ETSI T
30、S 122 031 V13.0.0 (2016-02)63GPP TS 22.031 version 13.0.0 Release 13monitored activities: subscriber activities that shall be reported to the HPLMN. These can be call related events (e.g. call-set-up, call termination) or the invocation of call related and call independent supplementary services (e.
31、g. Call Hold, Call Waiting, Call Transfer, Call Forwarding, Unstructured Supplementary Service Data). 3.2 Abbreviations Abbreviations used in this specification are also listed in GSM 01.04. For the purposes of this specification the following abbreviations apply: FIGS Fraud Information Gathering Sy
32、stem FDS Fraud Detection System IST Immediate Service Termination MO Mobile Originated MT Mobile TerminatedCGI Cell Global Identifier 4 Fraud Information Gathering System high level requirements 4.1 Description It shall be possible for the HPLMN to request the VPLMN to supply certain information abo
33、ut a subscriber from the time the subscriber registers in that VPLMN to the time the last of the monitored activities is finished in that VPLMN, which can be after the subscriber“s de-registration from the VPLMN. The information received by the HPLMN shall be passed to the relevant network or servic
34、e providers and used to instruct the VPLMN to act in an appropriate way. Fraud information gathering is controlled by the HPLMN and can be activated and deactivated by the HPLMN only. The information is received in the HPLMN and is forwarded to fraud detection and control systems. Such systems are o
35、ut of the scope of this standard. The subscriber is specified by the IMSI or MSISDN. 4.2 Applicability This network feature applies to all subscribed Bearer Services and Teleservices and supplementary services of the subscriber. It is not possible to apply FIGS independently to individual Services.
36、The HPLMN shall be able to specify whether it would like call information on MO calls, MT calls, or both. 4.3 Normal Procedure The HPLMN shall be able to request a VPLMN to monitor a subscriber. See Annex A for the definition of the information to be sent for each call event. If the VPLMN cannot mon
37、itor the subscriber, it shall indicate this as a response to the FIGS request. The FDS will process this information and may then limit the activities of the subscriber using ODB or terminate the subscriber activities using IST, or may allow the subscriber to proceed. When the home network no longer
38、 wishes the subscriber to be monitored by the VPLMN it requests the VPLMN to stop monitoring the activities of the subscriber. Figure B.1 shows the sequence of FIGS messages passed during a normal case. ETSI ETSI TS 122 031 V13.0.0 (2016-02)73GPP TS 22.031 version 13.0.0 Release 135 Service conditio
39、ns 5.1 Control of monitoring of subscriber activities The HPLMN can request a VPLMN to begin monitoring the activities of a subscriber when the subscriber has registers on that VPLMN or at any time after registration. If the VPLMN is able to monitor a subscriber as requested it shall send a confirma
40、tion of monitoring message to the HPLMN. The HPLMN does not need to know the status of the target subscriber before initiation or subsequent termination of fraud information gathering. Fraud information cannot be switched on or off by the subscriber or other (unauthorised) party. Subscribers upon wh
41、ich fraud information gathering has been set shall not be able by interrogating the network to determine that they are subject to fraud information gathering. Subscribers upon which fraud information gathering has been set shall not be able, for example by significant changes to normal call set up t
42、imes, speech quality or general transmission characteristics, to determine that they are subject to fraud information gathering. If the VPLMN receives a request to monitor the activities of a subscriber and an activity to be monitored is already ongoing it is not necessary for the VPLMN to send info
43、rmation on this particular activity to the HPLMN. If the VPLMN receives a request to cease monitoring the activities of a subscriber and an activity is already ongoing and being monitored, the VPLMN shall immediately cease sending information on this activity to the HPLMN. 5.2 Number of calls monito
44、red by a VPLMN If the VPLMN has to monitor the activities of a large number of subscribers for FIGS this may degrade the performance of the VPLMN. Each VPLMN (in reality, each network entity involved in FIGS monitoring) will therefore have a maximum number of subscribers that it can monitor. If the
45、number of monitored subscribers has reached this upper limit the VPLMN shall reject requests for monitoring of subscribers from HPLMNs until the number of monitored subscribers decreases below the limit. Each VPLMN may have a limit per HPLMN on the number of subscribers from that HPLMN that it will
46、monitor. When an HPLMN has requested a VPLMN to monitor a number of subscribers equal to the limit for that HPLMN, the VPLMN can refuse any subsequent requests for FIGS monitoring from that PLMN, until the number of monitored subscribers drops below the limit. The principles behind the setting of th
47、ese limits are outside the scope of this specification. In order to minimise the number of subscribers that a VPLMN has to monitor, the HPLMN should ideally limit itself to requesting information about subscribers monitored activities in: - the current VPLMN; - the last previously served VPLMN. 5.3
48、Interworking with non-supporting networks If the HPLMN does not receive a positive acknowledgement to the request for FIGS monitoring sent to a VPLMN, it shall assume that the VPLMN does not support FIGS. The HPLMN may then act as appropriate (e.g. put appropriate ODB categories in place). ETSI ETSI
49、 TS 122 031 V13.0.0 (2016-02)83GPP TS 22.031 version 13.0.0 Release 135.4 Information Delivery Time The need for up to date information is a critical part of any fraud information system. The sooner data is transferred to the HPLMN, the sooner fraud can be stopped. Therefore the prescribed information shall be transferred from the VPLMN network to the HPLMN within two minutes of the occurrence of a FIGS-monitored event, if real time implementations of FIGS are used. The information should be transferred from the VPLMN to the HPLMN over appropriate communication lin