General Information

Abstract

To consider Security issues which arise from the interconnection of two or more INs, when the interface of interconnection is from the SCF or SDF in one network to an SSF in another network. This work will be fed in to a revision of WI NA-061204. The proposed use of such interfaces in CAMEL phase 1, and other talk of such interfaces being used prompts careful study of the security implications, which have not previously been addressed.  Reference documents: DTR/NA-061203 and DTR/NA-061204.

Status
Published
Publication Date
31-Dec-2004
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
01-Jan-2005
Due Date
01-Jan-2005
Completion Date
01-Jan-2005

Buy Documents

Technical report

SIST-TP ETSI/TR 101 510-1 V1.1.1:2005

English language (12 pages)
Preview
Preview
e-Library read for
×1 day

Overview

SIST-TP ETSI/TR 101 510-1 V1.1.1:2005 is an international standard published by the Slovenian Institute for Standardization (SIST). It addresses security aspects related to the interconnection of Intelligent Network (IN) elements, specifically between the Switching Control Function (SCF) and the Service Switching Function (SSF) in different networks. The primary focus is on Capability Set 1 (CS1) based operations within telecommunication networks, and it is aligned with CAMEL phase 1 implementations.

This standard highlights the need to evaluate and mitigate security risks when two or more IN-structured networks are interconnected, particularly due to the extension of control and resource management across administrative boundaries.

Key Topics

The document concentrates on several important areas essential for secure interconnection of IN components, including:

  • SCF - SSF Interconnection: Defines relationships and operational flows between SCF (which controls the services) and SSF (which enables switching), especially when these functions sit in different network domains.
  • CS1 Operations Subset: Focuses on a defined group of CS1-based operations relevant to interconnection scenarios, such as:
    • initialDP, connect, releaseCall, eventReportBCSM, requestReportBCSMEvent, continue, activityTest
  • Security Threats: Identifies threats like masquerading, unauthorized access, eavesdropping, replay attacks, repudiation, denial of service, and unauthorized activity.
  • Countermeasures: Suggests approaches for securing SCF-SSF communication, such as:
    • Controlled network topology
    • Strong authentication mechanisms
    • Multi-level access controls
    • Ensuring message integrity and confidentiality
    • Event logging, accountability, and non-repudiation
    • Proactive network security management
    • Security-focused operations and maintenance routines

Applications

This standard is highly relevant for:

  • Telecommunications Operators: Especially those deploying IN services across multiple administrative domains or interconnecting their platforms with other operators.
  • Network Security Architects: Those responsible for designing secure network interconnections and ensuring compliance with international standards.
  • System Integrators and Vendors: Organizations delivering solutions that must interoperate securely in multi-network IN environments, including those implementing CAMEL phase 1.
  • Regulatory Authorities: Overseeing the safety and reliability of public switched telephone networks (PSTN) and helping to standardize best practices for secure IN operation.

Practical benefits include:

  • Reducing the risk of unauthorized service manipulation and denial of service attacks in inter-network scenarios
  • Ensuring confidentiality and integrity of signaling messages during SCF-SSF interactions
  • Supporting regulatory compliance and operational auditing requirements

Related Standards

Explore these related standards and references for broader context and implementation guidance:

  • ETSI TR 101 510-2: Focuses on security for CS2-based operations.
  • ITU-T Q.1211, Q.1214, Q.1218, Q.1221, Q.1224: ITU-T Recommendations covering foundational aspects of IN capability sets and their distributed functional planes.
  • ETR 339, TR 101 365: Analyze IN interconnection business and security threat analysis.
  • ETS 300 374-1, EN 301 140-1: Protocol specifications for IN Application Part (INAP) for CS1 and CS2.
  • CAMEL Standards: For implementations in mobile enhanced logic environments.

Conclusion

SIST-TP ETSI/TR 101 510-1 V1.1.1:2005 provides crucial guidance on the secure interconnection of Intelligent Network entities between telecom networks, helping operators and vendors manage security risks and ensure robust, interoperable service delivery. Adopting the recommended measures supports the integrity and availability of advanced telecommunication services while aligning with international best practices.

Buy Documents

Technical report

SIST-TP ETSI/TR 101 510-1 V1.1.1:2005

English language (12 pages)
Preview
Preview
e-Library read for
×1 day

Get Certified

Connect with accredited certification bodies for this standard

ANCE

Mexican certification and testing association.

EMA Mexico Verified

Intertek Slovenia

Intertek testing, inspection, and certification services in Slovenia.

UKAS Slovenia Verified

LNE (Laboratoire National de Métrologie et d'Essais)

French national laboratory for metrology and testing.

COFRAC France Verified

Sponsored listings

Frequently Asked Questions

SIST-TP ETSI/TR 101 510-1 V1.1.1:2005 is a technical report published by the Slovenian Institute for Standardization (SIST). Its full title is "Intelligent Network (IN); Security aspects of Switching Control Function (SCF) - Service Switching Function (SSF) interconnection between networks; Part 1: Capability Set 1 (CS1) based operations". This standard covers: To consider Security issues which arise from the interconnection of two or more INs, when the interface of interconnection is from the SCF or SDF in one network to an SSF in another network. This work will be fed in to a revision of WI NA-061204. The proposed use of such interfaces in CAMEL phase 1, and other talk of such interfaces being used prompts careful study of the security implications, which have not previously been addressed. Reference documents: DTR/NA-061203 and DTR/NA-061204.

To consider Security issues which arise from the interconnection of two or more INs, when the interface of interconnection is from the SCF or SDF in one network to an SSF in another network. This work will be fed in to a revision of WI NA-061204. The proposed use of such interfaces in CAMEL phase 1, and other talk of such interfaces being used prompts careful study of the security implications, which have not previously been addressed. Reference documents: DTR/NA-061203 and DTR/NA-061204.

SIST-TP ETSI/TR 101 510-1 V1.1.1:2005 is classified under the following ICS (International Classification for Standards) categories: 33.040.35 - Telephone networks. The ICS classification helps identify the subject area and facilitates finding related standards.

SIST-TP ETSI/TR 101 510-1 V1.1.1:2005 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


SLOVENSKI STANDARD
01-januar-2005
Inteligentno omrežje (IN) – Varnostni vidiki funkcije krmiljenja storitev (SCF) –
Funkcija komutacije storitve (SSF) medsebojnega povezovanja omrežij – 1. del:
Operacije na podlagi prvega nabora zmožnosti (CS1)
Intelligent Network (IN); Security aspects of Switching Control Function (SCF) - Service
Switching Function (SSF) interconnection between networks; Part 1: Capability Set 1
(CS1) based operations
Ta slovenski standard je istoveten z: TR 101 510-1 Version 1.1.1
ICS:
33.040.35 Telefonska omrežja Telephone networks
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

Technical Report
Intelligent Network (IN);
Security aspects of Switching Control Function (SCF) -
Service Switching Function (SSF)
interconnection between networks;
Part 1: Capability Set 1 (CS1) based operations

2 ETSI TR 101 510-1 V1.1.1 (2000-01)
Reference
DTR/SPAN-061208-1
Keywords
CS1,IN, interworking, security
ETSI
Postal address
F-06921 Sophia Antipolis Cedex - FRANCE
Office address
650 Route des Lucioles - Sophia Antipolis
Valbonne - FRANCE
Tel.:+33492944200 Fax:+33493654716
Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88
Internet
secretariat@etsi.fr
Individual copies of this ETSI deliverable
can be downloaded from
http://www.etsi.org
If you find errors in the present document, send your
comment to: editor@etsi.fr
Important notice
This ETSI deliverable may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network
drive within ETSI Secretariat.
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.
© European Telecommunications Standards Institute 2000.
All rights reserved.
ETSI
3 ETSI TR 101 510-1 V1.1.1 (2000-01)
Contents
Intellectual Property Rights.4
Foreword .4
Introduction .4
1 Scope.5
2 References.5
3 Definitions and abbreviations .5
3.1 Definitions.5
3.2 Abbreviations .6
4 Functionality .6
4.1 SSF .6
4.2 SCF.6
4.3 SSF-SCF Interconnection.7
5 Security considerations of operations .8
5.1 initialDP .8
5.2 connect .8
5.3 releaseCall .8
5.4 eventReportBCSM .8
5.5 requestReportBCSMEvent .8
5.6 continue .9
5.7 activityTest .9
6 Security countermeasures.9
6.1 Topology .9
6.2 Authentication .9
6.3 Access control .9
6.4 Integrity .10
6.5 Confidentiality.10
6.6 Non Repudiation.10
6.7 Accountability and auditing.10
6.8 Network security management .10
6.9 Testing and operation maintenance .10
Bibliography.11
History.12
ETSI
4 ETSI TR 101 510-1 V1.1.1 (2000-01)
Intellectual Property Rights
IPRs essential or potentially essential to the present document may have been declared to ETSI. The information
pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found
in SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect
of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server
(http://www.etsi.org/ipr).
Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee
can be given as to the existence of other IPRs not referenced in SR 000 314 (or the updates on the ETSI Web server)
which are, or may be, or may become, essential to the present document.
Foreword
This Technical Report (TR) has been produced by ETSI Technical Committee Services and Protocols for Advanced
Networks (SPAN).
The present document is part 1 of a multi-part TR covering the Intelligent Network (IN); Security aspects of Switching
Control Function (SCF) - Service Switching Function (SSF) interconnection between networks, as identified below:
Part 1: "Capability Set 1 (CS1) based operations".
Part 2: "Capability Set 2 (CS2) based operations".
Introduction
Under IN CS1 & CS2, the IN SCP to SSP relationship, or Service Control to Switch, is confined to a single network operator's
domain and may actually be physically co-located as an SSCP. To optimize performance, the switch requires little security,
particularly if implemented within a `single unit` or SSCP. By not using the local processor for security, switch performance
may be optimized toward call processing with security and network protection measures provided at the Service Control Point.
In the case of inter-connected networks, direct implementation of the Inter-network Control to Switch relationship would require
appropriate security and authentication measures to be provided and managed at each SSF.
Within a single network, potential conflict between multiple SCFs is avoided by their management within a common domain.
When two networks are interconnected two (or more) SCFs in different domains can potentially control the same resource
(SSF). Then some secure resource allocation and management procedure must be deployed. Suitable mechanisms have not yet
been standardized. Network operators may prefer the option of utilizing the established inter-network SCF to SCF security
procedures and route inter-network service switching signalling messages via each Network's Service Control Point. In this case
appropriate security and authentication measures would be provided and managed at each SCF.
ETSI
5 ETSI TR 101 510-1 V1.1.1 (2000-01)
1 Scope
The present document describes security aspects in conjunction with the interconnection of two IN structured networks.
The present document concentrates on the SCF - SSF interconnection.
The purpose of the present document is to describe the security aspects of interconnection of SCF to SSF. The
operations considered in this interconnection are a subset of CS1. For the time being CAMEL is the only application of
SCF - SSF interconnection, therefore the present document considers only CAMEL phase 1 operations. A later edition
may also consider other CS1 operations.
Future parts of the present document will investigate the security aspects of operation sets that are a subset of CS2 and
CS3.
2 References
The following documents contain provisions which, through reference in this text, constitute provisions of the present
document.
• References are either specific (identified by date of publication, edition number, version number, etc.) or
non-specific.
• For a specific reference, subsequent revisions do not apply.
• For a non-specific reference, the latest version applies.
• A non-specific reference to an ETS shall also be taken to refer to later versions published as an EN with the same
number.
[1] ITU-T Recommendation Q.1228 (1997): "CD-ROM - Interface Recommendation for intelligent
network Capability Set 2".
3 Definitions and abbreviations
3.1 Definitions
For the purposes of the present document, the following terms and definitions apply:
masquerade ("spoofing"): pretence of an entity to be a different entity. This may be a basis for other threats like
unauthorized access or forgery.
unauthorized access: entity attempts to access data in violation to the security policy in force.
eavesdropping: breach of confidentiality by monitoring communication.
loss or corruption of information: integrity of data (transferred) is compromised by unauthorized deletion, insertion,
modification, reordering, replay or delay.
replay of information: repetition of previously valid commands and responses with the intention of corrupting service
or causing an overload.
repudiation: denial by one of the entities involved in a communication of having participated in all or part of the
communication.
forgery: entity fabricates information and claims that such information was received from another entity or sent to
another entity.
denial of service: prevention of authorized access to resources or the delaying of time critical operations.
ETSI
6 ETSI TR 101 510-1 V1.1.1 (2000-01)
unauthorized activity: attacker performs activities for which he has no pe
...