Tech-invite3GPPspaceIETFspace
21222324252627282931323334353637384‑5x
Top   in Index   Prev   Next

TS 33.517
5G Security Assurance Specification (SCAS) –
Security Edge Protection Proxy (SEPP)

V19.0.0 (PDF)  2025/06  21 p.
V18.0.0  2023/06  24 p.
V17.0.0  2021/06  21 p.
V16.3.0  2021/06  19 p.
Rapporteur:
Mr. Peinado, German
Nokia Germany

full Table of Contents for  TS 33.517  Word version:  19.0.0

each clause number in 'red' refers to the equivalent title in the Partial Content
Here   Top
1Scope  p. 6
2References  p. 6
3Definitions of terms, symbols and abbreviations  p. 6
3.1Terms  p. 6
3.2Symbols  p. 6
3.3Abbreviations  p. 6
4SEPP-specific security requirements and related test cases  p. 7
4.1Introduction  p. 7
4.2SEPP-specific adaptations of security functional requirements and related test cases  p. 7
4.2.1Introduction  p. 7
4.2.2Security functional requirements on the SEPP deriving from 3GPP specifications and related test cases  p. 7
4.2.2.1Security functional requirements on the SEPP deriving from 3GPP specifications - general approach  p. 7
4.2.2.2Correct handling of cryptographic material of peer SEPPs and IPX providers  p. 7
4.2.2.3Connection-specific scope of cryptographic material by IPX-providers  p. 9
4.2.2.4Correct handling of serving PLMN ID mismatch  p. 10
4.2.2.5Confidential IEs replacement handling in original N32-f message  p. 11
4.2.2.6Correct handling of protection policy mismatch  p. 11
4.2.2.7JWS profile restriction  p. 13
4.2.2.8No misplacement of encrypted IEs in JSON object by IPX  p. 14
4.2.2.9Correct Handling of Inter-PLMN Routing  p. 15
4.2.2.10Correct Handling of Custom HTTP Header with PRINS Security  p. 16
4.2.3Technical Baseline  p. 17
4.2.3.1Introduction  p. 17
4.2.3.2Protecting data and information  p. 17
4.2.3.2.1Protecting data and information - general  p. 17
4.2.3.2.2Protecting data and information - unauthorized viewing  p. 17
4.2.3.2.3Protecting data and information in storage  p. 17
4.2.3.2.4Protecting data and information in transfer  p. 17
4.2.3.2.5Logging access to personal data  p. 17
4.2.3.3Protecting availability and integrity  p. 17
4.2.3.4Authentication and authorization  p. 17
4.2.3.5Protecting sessions  p. 17
4.2.3.6Logging  p. 18
4.2.4Operating Systems  p. 18
4.2.5Web Servers  p. 18
4.2.6Network Devices  p. 19
4.3SEPP-specific adaptations of hardening requirements and related test cases  p. 19
4.3.1Introduction  p. 19
4.3.2Technical baseline  p. 19
4.3.3Operating systems  p. 19
4.3.4Web servers  p. 20
4.3.5Network devices  p. 20
4.3.6Network functions in service-based architecture  p. 20
4.4SEPP-specific adaptations of basic vulnerability testing requirements and related test cases  p. 20
4.4.1Introduction  p. 20
4.4.2Port Scanning  p. 20
4.4.3Vulnerability scanning  p. 20
4.4.4Robustness and fuzz testing  p. 20
$Change history  p. 21

Up   Top