Tech-invite3GPPspaceIETFspace
21222324252627282931323334353637384‑5x

Content for  TS 33.501  Word version:  18.4.0

Top   Top   Up   Prev   Next
1…   4…   5…   5.3…   5.9…   5.10…   6…   6.1.3…   6.1.4…   6.2…   6.2.2…   6.3…   6.4…   6.5…   6.6…   6.7…   6.8…   6.9…   6.10…   6.11   6.12…   6.13   6.14…   6.15…   6.16…   7…   7A…   7A.2.3…   7B…   8…   9…   10…   11…   12…   13…   13.2.2…   13.2.4…   13.3…   13.4…   14…   15…   16…   A…   B…   C…   D…   E…   F…   G…   I…   I.9…   J…   K…   M…   N…   O…   P…   R   S…   T…   U…   V…   W…   X…   Y…   Z…

 

K (Normative)  Security for 5GLAN services |R16|p. 266

K.1  Generalp. 266

5GLAN services are described in TS 23.501 and TS 23.502.

K.2  Authentication and authorizationp. 266

For authentication and authorization of a UE in 5G LAN communication, the secondary authentication procedures between UE and external data networks via the 5G Network as described in clause 11 shall apply.

K.3  Handling of UP security policyp. 266

To reduce incremental complexity added by security, all PDU sessions associated with a specific 5G LAN group should have the same UP security policy.

L (Normative)  Security for TSC service |R16|p. 267

L.1  Generalp. 267

The 5G TSC service is described in TS 23.501. It allows the 5G System to be integrated transparently as a bridge in an IEEE TSN network [75], where the 5GS system acts as one or more TSN Bridges of a TSN network.

L.2  Access security for a 5GS TSC-enabled UEp. 267

A 5GS TSC-enabled UE accesses the 5G network as described in this document except where differences are provided in the following clauses.

L.3  Protection of user plane data in TSC including (g)PTP control messages in bridge modep. 267

After the 5GS TSC-enabled UE is authenticated and data connection is set up, any data received from a TSC bridge or another 5GS TSC-enabled UE shall be transported between DS-TT (in the UE) and NW-TT (in the UPF) in a protected way using the mechanisms for UP security as described in clause 6.6.
The UP security enforcement information shall be set to "required" for data transferred from gNB to a 5GS TSC-enabled UE. This is also applicable to the (g)PTP messages sent in the user plane.
Up

L.4  Exposure of time synchronisation |R17|p. 267

Any AF that has knowledge of deterministic application requirements is able to request TSC services from the 5GS by interfacing with NEF, and as authorized, can be notified of pertinent network events. The security solution as described in clause 12 shall apply.

Up   Top   ToC