TR 33.862  Word version:  17.1.0

1  Scope

The present document studies the security aspects on the support of the 5GMSG Service defined in TR 23.700-24, determines key issues of potential security requirements and proposed possible security solutions to meet these security requirements.

2  References

TR 21.905: "Vocabulary for 3GPP Specifications".
TR 23.700-24: " Study on support of the 5GMSG Service".
TS 23.222: " Functional architecture and information flows to support Common API Framework for 3GPP Northbound APIs; Stage 2".
TS 33.434: "Service Enabler Architecture Layer (SEAL); Security aspects for Verticals".
TS 33.501: "Security architecture and procedures for 5G System".
TS 33.210: "Network Domain Security (NDS); IP network layer security".
TS 22.262: "Message Service within the 5G System; Stage 1 ".
TR 22.824: "Feasibility study on 5G message service for MIoT; Stage 1 ".
TS 33.535: "Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5GS)".
TS 23.502: "Procedures for the 5G System (5GS); Stage 2".
TS 33.310: "Network Domain Security (NDS); Authentication Framework (AF) (Release 16)".
TS 33.180: "Security of the Mission Critical (MC) service".

3  Definitions of terms, symbols and abbreviations

3.1  Terms

3.2  Symbols


3.3  Abbreviations

4  Overview of MSGin5G Service

TS 22.262 and TR 22.824 define the stage 1 requirements of the MSGin5G Service (message service for MIoT over 5G System), TR 23.700-24 is under progress of defining the architecture and procedures to support the MSGin5G service. The above specifications form the baseline for the present document on security aspects of MSGin5G Service for the 5G system (5GS). MSGin5G Service enables an UE sending/receiving message of text, voice, video or data to/from another UE or application server. It is basically designed for IoT device communication, including thing-to-thing communication and person-to-thing communication. The emerging IoT device communication will introduce new requirements of messaging service in terms of service capabilities, performance, charging, and security etc.
For example, for the following scenarios from TS 22.262, the contents of the messages are required to be integrity and confidentially protected. For each scenario and for different UE types (5GMSGS UE, Legacy 3GPP UE, Non-3GPP UE), whether existing security mechanisms can be used to achieve the integrity and confidentiality protection under the architecture defined by TR 23.700-24 need to be investigated.
  1. point-to-point message
  2. application-to-point message
  3. group message
  4. broadcast message

