Tech-invite3GPPspaceIETFspace
21222324252627282931323334353637384‑5x

Content for  TS 23.334  Word version:  17.2.0

Top   Top   Up   Prev   Next
1…   4…   5…   5.11…   5.12…   5.14…   5.18…   5.19…   5.20…   5.21…   6…   6.1.6…   6.1.11…   6.2…   6.2.10…   6.2.10.3.1.2   6.2.10.3.2   6.2.10.4…   6.2.10.4.3…   6.2.10.5   6.2.10.6…   6.2.10A…   6.2.13…   6.2.14…   6.2.14.3   6.2.14.4…   6.2.15…   6.2.17…   6.2.17.3…   6.2.17.5…   6.2.18…   6.2.20   6.2.21…   6.2.22…   6.2.22.3…   6.2.22.3.2   6.2.23   6.2.24   6.2.25   7   8…   8.3   8.4   8.5…   8.23…

 

6.2.10.4  End-to-access-edge security for UDP based media using DTLS |R12|p. 109

6.2.10.4.1  Generalp. 109
The IMS-ALG and the IMS-AGW may support e2ae security for the UDP based media using DTLS and certificate fingerprints.
The following clauses describe extensions to the Iq signalling procedures and their interactions with SIP signalling in the control plane and with user plane procedures if the e2ae security for the UDP based media using DTLS and certificate fingerprints is supported by the IMS-ALG and the IMS-AGW and if the IMS-ALG indicated support of e2ae security for the UDPTL using DTLS and certificate fingerprints during registration.
Up
6.2.10.4.2  Session establishment from IMS access network for T.38 fax using "UDP/TLS/UDPTL"p. 109
Upon receipt of an SDP offer from the IMS access network containing T.38 fax media using the "UDP/TLS/UDPTL" transport protocol with the associated:
  • 3ge2ae SDP attribute, as defined in TS 24.229, with a value "requested";
  • fingerprint SDP attribute(s) as defined in RFC 8122;
  • DTLS association identity SDP attribute "a=tls-id" defined in RFC 8842; and
  • setup SDP attribute as defined in RFC 4145;
the IMS-ALG shall:
  • check the received value of the setup SDP attribute to determine if the IMS-AGW needs to act as DTLS client or DTLS server. When the received value is equal to:
    1. "active" the IMS-AGW needs to act as DTLS server;
    2. "passive" the IMS-AGW needs to act as DTLS client; or
    3. "actpass" the IMS-ALG shall decide if the IMS-AGW needs to act as DTLS client or DTLS server;
  • when reserving the transport addresses/resources towards the IMS access network:
    1. indicate to the IMS-AGW "UDP/DTLS" as transport protocol;
    2. if the IMS-AGW needs to act as DTLS client, include the Establish (D)TLS session information element to request the IMS-AGW to start the DTLS session setup;
    3. include the Notify (D)TLS session establishment Failure Event information element to request the IMS-AGW to report the unsuccessful DTLS session setup;
    4. include the Remote certificate fingerprint information element with the value of the received fingerprint SDP attribute(s); and
    5. include the Local certificate fingerprint Request information element to request the certificate fingerprint of the IMS-AGW;
  • indicate to the IMS-AGW "UDP" as transport protocol when reserving the transport addresses/resources towards the IMS core network; and
  • remove the setup SDP attribute and indicate the transport protocol "UDPTL" in the SDP offer towards the IMS core network.
Upon receipt of an SDP answer from the IMS core network, the IMS-ALG shall:
  • in the "m=" line indicating T.38 fax using UDPTL, change the transport protocol to "UDP/TLS/UDPTL";
  • insert the fingerprint SDP attribute with the value of the Local certificate fingerprint information element received from the IMS-AGW;
  • insert the "a=tls-id" SDP attribute containing a new DTLS association identity; and
  • insert the setup SDP attribute with the value:
    1. "active" if the IMS-ALG requested the IMS-AGW to act as DTLS client; or
    2. "passive" if the IMS-AGW shall take the DTLS server role.
The message sequence chart shown in the Figure 6.2.10.4.2.1 gives an example of a session establishment from the IMS access network with an emphasis on the additional aspects for the IMS-ALG and the IMS-AGW for the e2ae protection of the T.38 fax media using UDPTL over DTLS.
Copy of original 3GPP image for 3GPP TS 23.334, Fig. 6.2.10.4.2.1: Session setup from the IMS access network with e2ae protection of T.38 fax
Up

Up   Top   ToC