ETSI TR 102 512 V1.1.1 (2006-08)

Technical Report

Terrestrial Trunked Radio (TETRA);


Security requirements analysis for

modulation enhancements to TETRA

Contents


1 Scope

2 References

3 Definitions and abbreviations

3.1 Definitions

3.2 Abbreviations

4 Communications security model

4.1 Introduction

4.2 General model identifying security relationships

4.3 TVRA development model

5 Security objectives

5.1 General objectives

5.2 Objectives from the legislative framework

5.2.1 Privacy

5.2.2 Data protection

5.2.3 Security order

5.2.4 Lawful Interception

5.2.5 Contract

5.3 Summary

6 Vulnerability analysis

6.1 Introduction

6.2 TETRA system under evaluation

6.3 TETRA use cases (security scenarios)

6.3.1 Point to point communication within single TETRA SwMI

6.3.2 Point to multipoint communication within single TETRA SwMI

6.3.3 Broadcast communication within single TETRA SwMI

6.3.4 Point to point communication within multiple TETRA SwMIs

6.3.5 Point to multipoint communication within multiple TETRA SwMIs

6.3.6 Broadcast communication within multiple TETRA SwMIs

6.4 Overview of existing TETRA security measures

6.4.1 Security analysis and recommendation

6.4.2 Air interface capabilities Security profiles or classes Authentication Over the air key management support Encryption Over the Air enable and disable

6.4.3 Crypto capabilities TAA1 TEAx Overview TEA1 TEA2 TEA3 TEA4

6.5 System capabilities not covered by existing TETRA security measures

6.5.1 PEI Overview Objectives Threats and threat agents Summary of unwanted incidents

6.5.2 ISI

ETSI 4 ETSI TR 102 512 V1.1.1 (2006-08) 6.5.3 IP

6.5.4 Application level security

7 Identification of requirements for countermeasures

7.1 Overview

7.2 TETRA air interface modifications

7.2.1 Outline of modifications to TETRA air interface security


Foreword This Technical Report (TR) has been produced by ETSI Technical Committee Terrestrial Trunked Radio (TETRA).

1 Scope The present document updates the threat analysis presented in ETR 086-3 [1] with respect to new services and capabilities offered by the enhancements to TETRA that aim to provide alternative modulation schemes with a view to offering higher data transmission rates.

NOTE: The analysis provided by ETR 086-3 [1] remains valid and the recommendations made by that document remain in force.

In clause 7 the analysis identifies security extensions required for EN 300 392-7 [3].

2 References

For the purposes of this Technical Report (TR), the following references apply:

[2] ISO/IEC 9798-2: "Information technology - Security techniques - Entity authentication:

Part 2: Mechanisms using symmetric encipherment algorithms".

[16] Common Methodology for Information Technology Security Evaluation; Evaluation methodology;

July 2005; Version 3.0 Revision 2 (CCMB-2005-07-004).

[21] Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications - OJ L 201, 31.07.2002).

–  –  –

[24] ITU-T Recommendation v.24: "List of definitions for interchange circuits between data terminal equipment (DTE) and data circuit-terminating equipment (DCE)".

–  –  –

3.1 Definitions For the purposes of the present document, the terms and definitions given in ETR 086-3 [1] apply.

3.2 Abbreviations

For the purposes of the present document, the following abbreviations apply:

4.1 Introduction

In the context of the present document, security means to be assured that the risk of a weakness being exploited either intentionally or unintentionally is low.

Many standards include aspects of security, such as:

The goals of security and of evaluation are:

• to provide product owners with confidence that countermeasures bring the risk to assets to an acceptable level;

• to implement assurance techniques which give confidence that countermeasures bring the risk to assets to an acceptable level;

• to ensure that evaluation provides evidence of assurance giving confidence that countermeasures bring the risk to assets to an acceptable level.

The standardization process plays a significant role in achieving these objectives. Firstly, in order to ensure that the requirements identified in a standard are expressed accurately, clearly and unambiguously, a standard is critically reviewed by its potential implementors. Such review, along with other validation techniques, helps to provide the assurance that any specified countermeasures will, in fact, minimize risk. Secondly, a protocol standard is accompanied by a conformance test specification which can be used in the evaluation process to provide evidence that any countermeasures required by the protocol standard have been implemented correctly in a product.

4.2 General model identifying security relationships Figure 1 shows a generic system model and the relationship of its components to each other. In order to assess a system it is necessary to identify the system components as these form the assets of the system under threat that may require protection by means of countermeasures.

4.3 TVRA development model In order to allow visibility there should be a clearly visible path identifying "Objective" to "Requirement" and of "Vulnerability" to "Threat" to "Risk".

–  –  –

Figure 2: Structure of security analysis and development in standards documents For the purposes of analysis, all assets should be considered to have weaknesses.

–  –  –

5.1 General objectives The objectives to be met for systems in general, and for systems where the initial link is by radio in particular, where

such systems are provisioned for commercial purposes, are summarized in the following bullets:

• to be able to prove the of identity of users and networks;

• to ensure confidentiality of communication;

• to ensure integrity of communication;

• to ensure the rights of privacy of the system's users;

NOTE: This is an objective that is maintained in law.

• to ensure the correct charging of the system's users;

• security management:

- The complex security functions within the network call for sophisticated control and management. The management functions are security critical themselves and, therefore, subject to security requirements.

5.2 Objectives from the legislative framework Operators of TETRA networks, and manufacturers of TETRA equipment, have an objective to ensure compliance with the legislative framework of the region in which they operate.

Telecommunications networks and systems are expected to operate within a particular legislative framework. Within Europe the Framework Directive [19] (comprising the Privacy Directive [21], the Authorisation Directive [18], the Access Directive [17] and the Universal Service Directive [20]) identifies a number of areas for which compliance is required and which are highlighted in the clauses that follow.

5.2.1 Privacy Privacy legislation is of increasing importance; there are strong restrictions in many countries with regard to storage and visibility of data. Therefore, when offering a TETRA service, or when designing data processing functions and defining the kind of data being generated or stored within TETRA systems, TETRA service providers should consider the relevant national data protection laws.

The definition of privacy for TETRA includes:

• privacy of information: keeping information exchanged between TETRA service functions away from third parties;

• limitations on collection, storage and processing of personal data: personal data may only be collected, stored and processed if there is a relationship between the data and the actual provision of TETRA services;

• disclosure: the obligation of a network and service providers to keep information concerning customers away from third parties;

• inspection and correction: the right of the customer to inspect and correct information about himself stored by the service and/or network provider.

Privacy legislation mostly concerns the security objectives regarding "confidentiality" and "integrity". For TETRA special concern in this respect should be paid to the contents of personal data in the TETRA service profile. These data and the access conditions to it for the service provider's personnel, the subscriber and the user himself should be limited, in accordance with the relevant European guidelines and national laws.

This legislation will mostly concern the security objectives regarding "accountability", "confidentiality" and "integrity".

5.2.2 Data protection Data protection measures are those measures made to cover the security of data over and above those dealing purely with privacy and cover the access to and use of data volunteered for any transaction to a third party. Additional protection measures may be necessary to ensure that measures related to data retention and lawful interception remain lawful.

This legislation will mostly concern the security objectives regarding "accountability", "confidentiality" and "integrity".

5.2.3 Security order

National laws concerning the security order:

• demand proper protection of information and infrastructure to ensure the availability and the integrity of the telecommunication network;

• may restrict the usage of cryptographic methods.

This legislation will mostly concern the security objectives regarding "confidentiality", "integrity" and "availability".

5.2.4 Lawful Interception Lawful interception means the obligation of the network operator to co-operate and provide information in case of criminal investigations (see TS 101 331 [10]).

This legislation will mostly influence the security objectives regarding "confidentiality".

5.2.5 Contract It should be possible to use information concerning the contract for communication services between two entities in case of a dispute in a court of law.

This legislation will mostly influence the security objectives regarding "accountability" and "integrity".

5.3 Summary

The objectives listed above can be summarized to the following main security objectives:

- confidentiality of TETRA service data, of TETRA management data, and of communications using TETRA;

- integrity of TETRA service data, of TETRA management data, and of communications using TETRA;

- availability of all TETRA services and of all TETRA management functions; and

- accountability for all TETRA service invocations and for all TETRA management activities.

Therefore the TVRA and security measures will only be based on these objectives.

6.1 Introduction

The vulnerability analysis for TETRA is presented in accordance with the guidance given in ETR 332 [11] and ISO/IEC 15408-3 [14] to ensure that the system strength can be independently evaluated.

A deployment of a TETRA system is analysed for possible threats. The base for this analysis is the TETRA system as developed to date for TETRA with those extensions required for the data rate extensions for an update of the TETRA air interface. Where existing security measures are available they have been included into the analysis in order to identify threats to the existing countermeasures.

The analysis is made for both private and public systems. The impacts of connection of the TETRA system to public or private fixed networks are included in the analysis.

A potential threat is doing no harm unless there is a corresponding weakness in the system and until the point in time when a weakness is exploited by the intruder. Thus, the threats must be evaluated, i.e. it should be attempted to characterize them according to cost/effort involved (occurrence likelihood) and according to potential benefit/damage that can be done (impact value).

For the risk assessment, the occurrence likelihood of threats is estimated with values from "1" to "3". The meaning of a

