Tech-invite3GPPspaceIETFspace
21222324252627282931323334353637384‑5x
Top   in Index   Prev   Next

TS 33.511
Security Assurance Specification (SCAS)
for the Next Generation
Node B (gNodeB) Network Product Class

V19.3.0 (PDF)2025/09  … p.
V18.3.0  2024/03  26 p.
V17.6.0  2024/03  25 p.
V16.12.0  2024/03  24 p.
Rapporteur:
Mr. Wong, Marcus
Huawei Tech.(UK) Co.. Ltd

full Table of Contents for  TS 33.511  Word version:  19.2.0

Here   Top

 

1  Scopep. 6

The present document contains objectives, requirements and test cases that are specific to the gNB network product class. It refers to the Catalogue of General Security Assurance Requirements and formulates specific adaptions of the requirements and test cases given there, as well as specifying requirements and test cases unique to the gNB network product class.

2  Referencesp. 6

3  Definitions of terms and abbreviationsp. 6

4  gNodeB-specific security requirements and related test casesp. 7

4.1  Introductionp. 7

4.2  gNodeB-specific security functional adaptations of requirements and related test casesp. 7

4.2.1  Introductionp. 7

4.2.2  Security functional requirements on the gNodeB deriving from 3GPP specifications and related test casesp. 7

4.2.2.1  Security functional requirements on the gNodeB deriving from 3GPP specifications - TS 33.501 [2]p. 7

4.2.2.1.1  Integrity protection of RRC-signallingp. 7
4.2.2.1.2  Integrity protection of user data between the UE and the gNBp. 8
4.2.2.1.3Void
4.2.2.1.4  RRC integrity check failurep. 9
4.2.2.1.5  UP integrity check failurep. 9
4.2.2.1.6  Ciphering of RRC-signallingp. 10
4.2.2.1.7  Ciphering of user data between the UE and the gNBp. 10
4.2.2.1.8  Replay protection of user data between the UE and the gNBp. 11
4.2.2.1.9  Replay protection of RRC-signallingp. 12
4.2.2.1.10  Ciphering of user data based on the security policy sent by the SMFp. 13
4.2.2.1.11  Integrity of user data based on the security policy sent by the SMFp. 14
4.2.2.1.12  AS algorithms selectionp. 15
4.2.2.1.13  Key refresh at the gNBp. 15
4.2.2.1.14  Bidding down prevention in Xn-handoversp. 16
4.2.2.1.15  AS protection algorithm selection in gNB changep. 17
4.2.2.1.16  Control plane data confidentiality protection over N2/Xn interfacep. 18
4.2.2.1.17  Control plane data integrity protection over N2/Xn interfacep. 18
4.2.2.1.18  Key update at the gNB on dual connectivityp. 18
4.2.2.1.19  UP security activation in Inactive scenariop. 19
4.2.2.1.20  User plane data confidentiality protection over N3/Xn interfacep. 20
4.2.2.1.21  User plane data integrity protection over N3/Xn interfacep. 20
4.2.2.1.22  Checking expiry certificatep. 21
4.2.2.1.23  Peer certificate checkingp. 21

4.2.3  Technical Baselinep. 22

4.2.4  Operating systemsp. 23

4.2.5  Web serversp. 23

4.2.6  Network devicesp. 23

4.2.7Void

4.3  gNodeB-specific adaptations of hardening requirements and related test cases.p. 24

4.4  gNodeB-specific adaptations of basic vulnerability testing requirements and related test casesp. 24

$  Change historyp. 26


Up   Top