You are on page 1of 42

GSM

CLP.11 -


1.0
2016 02 08

GSMA

2016 GSM

GSM

GSM

V1.0 1 41
GSM
CLP.11 -

1 4
1.1 4
1.2 GSMA 4
1.3 5
1.4 5
1.5 6
1.6 7
1.7 8
2 9
2.1 9
2.2 10
2.3 10
2.4 11
3 12
3.1 12
3.2 12
3.3 13
4 14
4.1 14
4.2 14
5 15
5.1 16
5.2 16
6 16
7 18
7.1 18
7.2 19
7.3 19
7.4 20
7.5 20
8 - 21
8.1 21
8.2 22
8.3 22
8.4 23
8.5 24
8.6 24
9 - 25
9.1 25
9.2 26
9.3 26
9.4 27

V1.0 2 41
GSM
CLP.11 -

9.5 28
9.6 28
10 - 29
10.1 29
10.2 30
10.3 30
10.4 31
10.5 32
10.6 32
A 33
B 37
B.1 37
B.2 37
B.3 38
B.4 39
B.5 39
B.6 39
B.7 40
C 41
C.1 41
C.2 41

V1.0 3 41
GSM
CLP.11 -

1
1.1
(IoT)

IT

GSMA

GSMA

1.2 GSMA
GSMA

V1.0 4 41
GSM
CLP.11 -

GSMA

CLP.11

CLP.14


CLP.12 CLP.13



1 - GSMA
GSMA
CLP.14[13]

1.3

1.4

-


-
-

V1.0 5 41

GSM
CLP.11 -

1.5

CLP.13 [4]
CLP.12 [3] CLP.13 [4]

SIM GSMA SGP.01 [2]


SIM

CLP.13 [4]

4.2
(IoT)


CLP.12 [3] CLP.13 [4]

CLP.12 [3] CLP.13 [4]

CLP.12 [3] CLP.13 [4]


3.1

(SIM)
ETSI TS 102 221
UICC
ETSI TS 102 671

V1.0 6 41
GSM
CLP.11 -

1.6


3GPP 3
API
APN
CERT
CLP GSMA
CPU
EAP
EEPROM
GBA
GPS
GSMA GSM
GUI
HIPAA
IoT
LPWA
NIST
OBD
OCTAVE
OMA
PIA
PII
RAM
SIM

V1.0 7 41
GSM
CLP.11 -

1.7

The Mobile Economy 2015
[1]
http://www.gsmamobileeconomy.com/
Embedded SIM Remote Provisioning Architecture
[2] SGP.01
http://www.gsma.com/connectedliving/embedded-sim/
IoT Security Guidelines for IoT Service Ecosystem
[3] CLP.12
www.gsma.com/connectedliving
IoT Security Guidelines for IoT Endpoint Ecosystem
[4] CLP.13
www.gsma.com/connectedliving
NIST Risk Management Framework
[5]
http://csrc.nist.gov/groups/SMA/fisma/framework.html
Introducing OCTAVE Allegro:Improving the Information Security Risk
CMU/SEI-
[6] Assessment Process
2007-TR-012
http://www.cert.org/resilience/products-services/octave/
[7]
Generic Authentication Architecture (GAA); Generic Bootstrapping
[8] TS 33.220 Architecture (GBA)
www.3gpp.org
Extensible Authentication Protocol Method for Global System for Mobile
[9] RFC 4186 Communications (GSM) Subscriber Identity Modules (EAP-SIM)
www.ietf.org
Conducting privacy impact assessments code of practice
[10] https://ico.org.uk/media/for-organisations/documents/1595/pia-code-of-
practice.pdf
Open Mobile Alliance
[11]
http://openmobilealliance.org/
oneM2M
[12]
http://www.onem2m.org/
IoT Security Guidelines for Network Operators
[13] CLP.14
www.gsma.com/connectedliving

Report of the Special Rapporteur on the promotion and protection of the


right to freedom of opinion and expression, Frank La Rue*
[14] GE.11-13201
http://www.ohchr.org/english/bodies/hrcouncil/docs/17session/A.HRC.17.27_e
n.pdf

Right to Internet Access


[15]
https://en.wikipedia.org/wiki/Right to Internet access

V1.0 8 41
GSM
CLP.11 -

[14] [15]
/

2.1

(LPWAN)


V1.0 9 41
GSM
CLP.11 -

2.2

2.3






(PII)
PII

V1.0 10 41
GSM
CLP.11 -

2.4




(TCB)
TCB





V1.0 11 41
GSM
CLP.11 -

3.1
GSMA2015 [1]

2014 36 10
2020
10 60% 2014 71
SIM 2.43
2014
3G 4G 40% 2020 70%
2G 2008 2G
90% 2014 60%2G
2013 2014 6%
GSMA
2020 3G 70% 80%4G
3G 3G 10
4G 8 2017

(LPWA)

LPWA

3.2

SIM GSMA SIM SIM


[2]
(OTA)

SIM

V1.0 12 41
GSM
CLP.11 -

3GPP GBA [8]OMA [11]oneM2M [12]

3.3
SIM
3G 4G

SIM GBA [8] EAP-SIM [9]


SIM

V1.0 13 41
GSM
CLP.11 -

[3] [4]

API

2 -

GSMA
[13]

4.1

API

CLP.12
[4]

4.2
[4]

CLP.13
[13]

V1.0 14 41
GSM
GSM
CLP.11 -

V1.0 15 41
GSM
CLP.11 -

5.1

5.2

(NIST) [5]
(CERT) OCTAVE [6]

V1.0 16 41
GSM
CLP.11 -

1996 (HIPAA)

HIPAA
app

V1.0 17 41
GSM
CLP.11 -

7.1

[3]
[4]

CERT OCTAVE [6] NIST [5]

V1.0 18 41
GSM
CLP.11 -

7.2

CERT OCTAVE [6] NIST [5]

7.3

NIST [5] CERT OCTAVE


[6]

V1.0 19 41
GSM
CLP.11 -

7.4

NIST [5] CERT OCTAVE [6]

7.5

NIST [5] CERT


OCTAVE [6]

V1.0 20 41
GSM
CLP.11 -

8 -
(HRM)

8.1

BLE+MCU

3 - HRM

HRM (BLE)

BLE BLE 4.2

HRM

V1.0 21 41
GSM
CLP.11 -

8.2

4 -

8.3

HRM

V1.0 22 41
GSM

GSM
CLP.11 -

8.4

PSK


[3] [4]




PSK

V1.0 23 41
GSM
CLP.11 -

8.5

5 -

DoS DDoS

8.6

V1.0 24 41
GSM
CLP.11 -

9 -

9.1

SD /GPS

6 -

ARM Cortex-A8 CPU


(Linux) NVRAM
SD/MMC
/GPS
GPS

(LiPo)

V1.0 25 41
GSM
CLP.11 -

9.2

LTE
LTE

LTE

7 -

9.3

V1.0 26 41
GSM

GSM
CLP.11 -

9.4


TCB
TCB
TCB
TCB
LTE Femtocell
LTE

V1.0 27 41

GSM
CLP.11 -

9.5

CPU TCB

TCB

9.6

TCB PSK TCB


[3] [4]

V1.0 28 41
GSM
CLP.11 -

10 -

10.1

8 -



(V2V) V2V

V2V
V2V

V2V

V2V

V1.0 29 41
GSM
CLP.11 -

10.2

(ML) (AI)

9-

10.3

V1.0 30 41
GSM

GSM
CLP.11 -
10.4


PKI




TCB GBA
UICC


(TPM) TPM


V1.0 31 41
GSM
CLP.11 -

10.5
GBA

TCB

10.6

CAN

V1.0 32 41
GSM
CLP.11 -

A
GSMA

/
/

/
(PIA)


-

(I)




(PIA) (II)



(III)

10- GSMA

V1.0 33 41
GSM
GSM
CLP.11 -



/



2


/







3

/



V1.0 34 41
GSM
CLP.11 -


(PIA)



PIA PIA
[10]

PIA

4 /














5
?

V1.0 35 41
GSM
CLP.11 -




/

/

V1.0 36 41
GSM
CLP.11 -

B.1


(GUI)





SIM

(CPU)
RAM
RAM
EEPROM



APN Access Point Name

OTA
SIM OTA

B.2

V1.0 37 41
GSM
CLP.11 -

V2V / V2I



ECU

TPMS
GPS



OBD-II
CD-ROM/DVD

OBD-II

/ APN
USB


WIFI &


OTA API
OTA

SIM OTA SIM OTA
API

11-



APN
OTA SIM OTA

B.3

CPU

V1.0 38 41
GSM
GSM
CLP.11 -

B.4



B.5


EEPROM
RAM

B.6

V1.0 39 41
GSM
CLP.11 -

GSMA
SIM SIM
SIM GSMA
SIM
SIM

EEPROM SIM

GUI

B.7

V1.0 40 41
GSM
CLP.11 -

C.1

1.0 2016 2 8 PRD CLP.11 PSMC Ian Smith



GSMA
&
Don A. Bailey Lab
Mouse Security

C.2



Ian Smith - GSMA

prd@gsma.com

V1.0 41 41

You might also like