The 3GPP Mobile Network Authentication and Key Agreement (AKA) is the primary authentication mechanism for devices wishing to access mobile networks. RFC 4187 (EAP-AKA) made the use of this mechanism possible within the Extensible Authentication Protocol (EAP) framework. RFC 5448 (EAP-AKA') was an improved version of EAP-AKA. This memo replaces the specification of EAP-AKA'. EAP-AKA' was defined in RFC 5448 and updated EAP-AKA RFC 4187. As such this document obsoletes RFC 5448 and updates RFC 4187. EAP-AKA' differs from EAP-AKA by providing a key derivation function that binds the keys derived within the method to the name of the access network. The key derivation function has been defined in the 3rd Generation Partnership Project (3GPP). EAP-AKA' allows its use in EAP in an interoperable manner. EAP-AKA' also updates the algorithm used in hash functions, as it employs SHA-256 / HMAC- SHA-256 instead of SHA-1 / HMAC-SHA-1 as in EAP-AKA. This version of EAP-AKA' specification specifies the protocol behaviour for both 4G and 5G deployments, whereas the previous version only did this for 4G.
This document describes a number of use cases illustrating security and privacy aspects of 5G networks. Based on similarities in technical, service and/or business-model related aspects, the use cases are grouped into use case clusters covering a wide variety of deployments including, for example, the Internet of Things, Software Defined Networks and virtualization, ultra-reliable and standalone operations. The use cases address security and privacy enhancements of current networks as well as security and privacy functionality needed by new 5G features. Each use case is described in a common format where actors, assumptions and a sequence of steps characterising the use case are presented together with a short analysis of the security challenges and the properties of a security solution. Each use case cluster description is concluded with a “5G Vision” outlining the associated enhancements in security and privacy anticipated in 5G networks and systems. A summary of the 5G visions and conclusions are provided at the end of the document.
This deliverable (D2.4) of the 5G-ENSURE project describes a draft security architecture for 5G networks. The focus lies on a logical and functional architecture and omits (most) aspects related to physical/deployment architecture. This focus is motivated by general trends such as network de-perimetrization as well as 5G systems’ strong dependency on software defined networking and virtualization in general. Furthermore, this focus has reduced the otherwise strong interdependency between this architecture task and the trust modelling and risk analysis tasks in 5G-ENSURE. Still, each of these three tasks have at the time of writing produced initial draft documents, which will then be re-used in a second iteration of all three tasks, producing updated, final versions.
This memo specifies an Authentication and Key Agreement (AKA) based one-time password generation mechanism for Hypertext Transfer Protocol (HTTP) Digest access authentication. The HTTP Authentication Framework includes two authentication schemes: Basic and Digest. Both schemes employ a shared secret based mechanism for access authentication. The AKA mechanism performs user authentication and session key distribution in Universal Mobile Telecommunications System (UMTS) networks. AKA is a challenge- response based mechanism that uses symmetric cryptography.
Hannes Tschofenig, Vesa Torvinen, Pasi Eronen Abstract This paper investigates the possibility to establish security associations between the data sender and one (or more) intermediate middleboxes to address some open issues for standard path-coupled NAT/Firewall traversal. We provide some thoughts on mobility handling and address the aspect of data origin authentication and an even more secure version source authentication.
This document defines new functionality for negotiating the security mechanisms used between a Session Initiation Protocol (SIP) user agent and its next-hop SIP entity. This new functionality supplements the existing methods of choosing security mechanisms between SIP entities.
Information technology (IT) has radically improved many aspects of organisational activities. Computer-based information systems (CBIS) are constantly developed more effective and efficient. Development of a new CBIS is justified by higher quality of work, more efficient work processes, and more flexible work practices. However, introduction of the new IS can produce a variety of problems. This paper describes the problems observed in the use of a library CBIS in a Finnish scientific library. The results of the study illustrate well the environment which should be understood by the designers of computer-based information systems. One important prerequisite of good (re)design is a wide understanding of the problems that may prevent effective use of a CBIS. In this study we introduce a classification based on the problems which were found in the case. The classification describes the causes and effects of the observed problems.
From the perspective of librarianship some alarming, rather global changes have taken place in the library field. Firstly, the increasing use of information technology (IT) in publishing is a challenge for the libraries. For example, electronic publications have already radically changed the traditional domain of the library, causing uncertainty among employees as they have to modify their work practices. Secondly, the development of IT has made it possible for the customers to take over traditional tasks of librarians. The tendency to increase self services can be seen as a threat for the proficiency of librarians. In this article we report experiences and perspectives of different stakeholders from an interpretive case study of a Finnish academic library. The case study illustrates well the environment which should be understood by management when planning the solutions for organisation and IT.
Requirements engineering is usually defined as a process in which detailed descriptions of a future software system are created. However, system requirements depend on the ways in which the organization and its potential futures are argued. One future will lead to one kind of systems while another future may require other kind of systems. From this perspective, requirements engineering should precede a process of organizational development and learning. In this paper, a prototype of a method for such process is presented.
In this paper IS requirement analysis is discussed from the perspective of work transformation. A process modelling approach, which treat computer systems as a part of human activity, is introduced. In this way the object of analysis and design should be on the work organisation rather than on the software product. Four case examples are used to illustrate the connection between changing organisational structure and ISs. The process modelling approaches as such are capable of creating new work arrangements. However, the innovations of more radical work transformation can not be reached as a result of process based problem analysis. A mechanism to analyse the activity on more generic level is needed. One possible construction of such mechanism is suggested.
In this paper we present a role based approach to the analysis of computer-based information systems (ISs). The concept of work role is a good tool for representing work and division of labour, and the computer supported tasks make no exception of this. Relationships between actors, roles, tasks and computer systems are discussed from the act-oriented perspective. Role based analysis of an activity brings the problems of competence, responsibility and co-operation with the ISs into the surface.
Felix Klaedtke合作论文数ETH Zurich
Computer Science Department
Universitatstr. 6
CNB F 107.1
CH-8092 Zurich, Switzerland2