TS 33.221  Word version:  16.0.0

1  Scope

The present document describes subscriber certificate distribution by means of generic bootstrapping architecture (GBA) TS 33.220. Subscriber certificates support services whose provision the mobile operator assists, as well as services that are offered by the mobile operator.
The scope of this specification presents signalling procedures for support of issuing certificates to subscribers and the standard format of certificates and digital signatures. It is not intended to duplicate existing standards being developed by other groups on these topics, and will reference these where appropriate.

2  References

3  Definitions and abbreviations

3.1  Definitions

For the purposes of the present document, the following terms and definitions apply.
Subscriber certificate:
a certificate issued to a subscriber. It contains the subscriber's own public key and possibly other information such as the subscriber's identity in some form.
CA certificate:
A Certificate Authority signs all certificates that it issues with its private key. The corresponding Certificate Authority public key is itself contained within a certificate, called a CA Certificate.

3.2  Abbreviations

For the purposes of the present document, the following abbreviations apply:
Anonymity Key
Authentication and Key Agreement
Bootstrapping Transaction Identifier
Binary Large Object
Bootstrapping Server Function
Certificate Authority
Certificate Management Messages over CMS
Certificate Management Protocols
Cryptographic Message Syntax
Generic Authentication Architecture
Generic Bootstrapping Architecture
Home Subscriber System
Integrity Key
Mobile Network Operator
Network Application Function
Public-Key Cryptography Standards
Public Key Infrastructure
User Equipment

