Ȩ > Ç¥ÁØÈ Âü¿© > TTA°£Ç๰ > ICT Standard Weekly
[oneM2M] oneM2M ÀÇ Trust Enablement Function(TEF) Ç¥Áع®¼ °³¹ß ÇöȲ
1. TEF ±Ô°ÝÀÇ Á¤ÀÇ ¹× ÀÛ¾÷ Ç׸ñ °³¿ä
¡Û ÀÛ¾÷Ç׸ñ WI-0057 ¡°TEF Interface ½ÂÀΡ± : oneM2M TP#24 (2016.7)
- TEF(Trust Enabling Function)´Â oneM2MÀÇ »ýÅÂ°è ±¸Á¶ ¾È¿¡¼ Á¤ÀǵǴ entityµé°£ÀÇ security¿Í trust¸¦ ¼ö¸³ÇÏ´Â ¸ñÀûÀ¸·Î ¿î¿µµÇ´Â ±â´ÉÀ» Á¤ÀÇÇÑ´Ù. TEF¿¡´Â MEF(M2M Enrolment Function)¿Í MAF(M2M Authorization Function)°¡ Æ÷ÇԵǸç, ÀÌ´Â oneM2M ÀÇ Trust Enabling Architecture(TS-0001)¿¡ Á¤ÀǵǴ ºÎºÐÀÌ´Ù.
- TP#24¿¡ Á¦ÃâµÇ¾î ½ÂÀÎµÈ ÇØ´ç ÀÛ¾÷Ç׸ñ(WI-0057)Àº Ä÷ÄÄÀÌ ÁÖµµÇϰí ÀÖÀ¸¸ç, ±âÁ¸¿¡ TS-0001(Functional Architecture) ¹× TS-0003(Security Solution)¿¡¼ Á¤ÀÇÇϰí ÀÖ´Â TEF¸¦ ±¸Ã¼ÈÇÏ¿© TS ±Ô°Ý ¹®¼·Î °³¹ßÇÏ´Â ÀÛ¾÷À» ÁøÇà ÁßÀÌ´Ù.
¡Û MEF¿Í MAF °£ ÇÁ·ÎÅäÄÝ Á¤ÀÇ ³»¿ë
- TS-0001 ¹®¼¿¡ ÀÇÇϸé, M2M »ýŰ迡¼ MEF´Â M2M node¸¦ ¿î¿µÇϱâ Àü M2M »ç¾÷ÀÚÀÇ ¼ºñ½º¿¡ M2M ³ëµå¿Í ÀÀ¿ëÀ» enrolment(µî·Ï)Çϰí configurationÇÏ´Â ±â´ÉÀ» ´ã´çÇÑ´Ù. ÇÑÆí MAF´Â M2M ¼ºñ½º ¿î¿µ Áß CSE¿Í AEÀÇ identification ¹× authentication, Á¾´Ü °£ primitives º¸¾È, Á¾´Ü °£ data º¸¾È µîÀ» °¡´ÉÇÏ°Ô ÇÏ´Â Á᫐ ±â´ÉÀ» ÁöÁ¤ÇÑ´Ù.
- MAF¿Í MEF´Â ¼·Î ½Å·ÚÇÏ´Â ÁÖüµé (M2M »ç¾÷ÀÚ È¤Àº 3rd party)¿¡ ÀÇÇØ ¿î¿µµÇ´Â °ÍÀ¸·Î (ÇöÀç±îÁö´Â) Á¤Àǵǰí ÀÖ´Ù. À̵é°ú AE, CSE µî°ú´Â ¼·Î »óÈ£¿î¿µÀÌ °¡´ÉÇØ¾ß Çϸç ÀÌµé °£ÀÇ ÂüÁ¶ Á¡ Á¤ÀÇ, »õ·Î¿î ÀϺΠresource-type Á¤ÀÇ, resource-type specific CRUD procedure ¹× data types of the resource attributesÀº Ãß°¡·Î Á¤ÀǵǾî¾ß ÇÔÀÌ ±âÁ¸ÀÇ ¹®¼¿¡ Àû½ÃµÇ¾î ÀÖ´Ù.
¡Û MEF¿Í MAF °£ ÇÁ·ÎÅäÄÝ Á¤ÀÇ ³»¿ë
- WI-0057Àº »ó±â Ãß°¡·Î Á¤ÀÇÇØ¾ß ÇÒ »çÇ×µé°ú ÇÔ²² TEF¿¡¼ ¿î¿µµÉ ÇÁ·ÎÅäÄÝ primitiveµéÀ» °³¹ßÇÑ´Ù. TS-0003Àº M2M entityµé(AE ¿Í CSE µî)°ú MEF(M2M Enrolment Function) ¹× MAF (M2M Authorization Function) °£ ¿¬µ¿À» ÀüÁ¦ÇÑ security ÇÁ·¹ÀÓ¿öÅ©¸¦ Á¤ÀÇÇϰí Àִµ¥, (TS-0003 Security °³¿ä: º°Ã· Âü°í) ÇØ´ç ÇÁ·¹ÀÓ¿öÅ©´Â ´ÙÀ½ÀÇ security ÇÁ·¹ÀÓ¿öÅ©¸¦ ÁöÁ¤ Çϰí ÀÖ´Ù.
¤ý MEF-based Remote Security Provisioning Frameworks (RSPF)
¤ý MAF-based Security Association Establishment Framework (MAF-based SAEF)
¤ý End-to-End Security of Primitives (ESPrim)
¤ý End-to-End Security of Data (ESData)
- ÀÌ Áß MEF-based RSPF´Â MEF¿Í MAF °£ »óÈ£Åë½ÅÀ» ÇÊ¿ä·Î ÇÑ´Ù. »ó±âÀÇ security ÇÁ·¹ÀÓ¿öÅ©´Â ´ë°³ÀÇ °æ¿ì (D)TLS¿¡ ±â¹ÝÇϰí ÀÖÀ¸³ª TEF °£ ÀϺΠÆÄ¶ó¹ÌÅÍ´Â Àü´ÞÀÌ °ï¶õÇÏ¿© À̸¦ Ãß°¡·Î Á¤ÀÇÇØ¾ß ÇÑ´Ù´Â °ÍÀÌ ÀÛ¾÷Ç׸ñÀÇ ¿äÁ¡ÀÌ´Ù. ÀÌ¿¡ µû¶ó Mcc¿Í Mca¿¡ ¿î¿µÇÒ º°µµÀÇ ÇÁ·ÎÅäÄÝÀ» Á¤ÀÇÇÑ´Ù.
¡Û ÀÛ¾÷ ÀÏÁ¤
- WIÀÇ ½ÂÀÎ ÀÌÈÄ TP28¿¡¼ freeze, TP29¿¡¼ ½ÂÀÎÇÏ´Â ÀÏÁ¤À» ¸ñÇ¥·Î ÃßÁø ÁßÀ̸ç, ¿¹Á¤´ë·Î ÁøÇàµÇ¸é ÇØ´ç ±Ô°ÝÀº rel-3 ±Ô°Ý ¹®¼·Î Æ÷Ç﵃ °ÍÀ¸·Î ¿¹»óµÈ´Ù.
- Lead WGÀº SEC(WG4)À̸ç TS ¹®¼(TEF Interface Specification)·Î °³¹ß ÁßÀε¥, º» ÀÛ¾÷ Ç׸ñÀ» Á¦¾È ÇÑ Ä÷ÄÄÀÌ ¶óÆ÷ÅÍ/¿¡µðÅÍ·Î ÁøÇà ÁßÀÌ´Ù.
2. TEF ±â´ÉÀÇ µ¶¸³È ¹æ½ÄÀ» Áö¿øÇÏ´Â ÀÛ¾÷ Ç׸ñ °³Á¤
¡Û oneM2M TP#25/ SEC WG (2016.10)¿¡¼ ÀÛ¾÷Ç׸ñ WI-0057 revision
- 2016³â 10¿ù¿¡ Ä÷ÄÄÀº ÀÛ¾÷ Ç׸ñÀÇ revisionÀ» Á¦ÃâÇÏ¿´À¸¸ç, À̸¦ ÅëÇØ TEF modelingÀÇ option 3À» Ãß°¡ÇÏ¿´´Ù. ÀÌ´Â ¡°stand-alone TEF entity ¹æ½Ä¡±À» Ãß°¡ Á¦¾ÈÇÑ °ÍÀ¸·Î, ¾Æ·¡ [±×¸² 1]¿¡ º¸ÀÌ´Â ¿¹¿Í °°ÀÌ ±âÁ¸ÀÇ SEC CSF¿Í º°µµ·Î TE CSF¸¦ ±¸ÇöÇÏ´Â °ÍÀ» Á¦¾ÈÇÏ¿© ½ÂÀεǾú´Ù.
- ¶Ç ÀÌ·Î ÀÎÇØ Trust enabling CSF°¡ »ý±ä °Í¿¡ ´ëÀÀÇÏ´Â message flowÀÇ update¿Í ÇâÈÄ ÃßÁø ¹æÇâÀ» Á¤¸®ÇÏ¿´´Ù.
Ref: SEC-2016-0165R1
3. TP#26 (2016.12)ÀÇ TEF °ü·Ã À̽´ ¹× Ç¥ÁØÈ ÁøÇà Á¤µµ
¡Û oneM2M TP#26¿¡ Á¦ÃâµÈ 3°³ÀÇ ¹®¼ äÅÃ
- TP26¿¡¼´Â Ä÷ÄÄÀÌ Á¦ÃâÇÑ skeleton ¹®¼, scope ¹®¼, main body - base line ¹®¼°¡ ¸ðµÎ ½ÂÀεǾú°í, SEC/ARC joint sessionÀ» ÅëÇÑ interface discussionÀ» ÁøÇàÇÏ¿´´Ù. À̸¦ ÅëÇØ ÇÕÀÇÇÑ ÀÏÁ¤À¸·Î TP26¿¡ µÚÀÌ¾î¼ (SEC26.1 µî Ãß°¡È¸ÀǸ¦ ÅëÇØ) ¡°MAF and MAF Interface Specification¡±draft¸¦ ¸¸µé °ÍÀ» ¿¹°íÇÏ¿´´Ù.
- ÇöÀç ¹öÀüÀÇ body¿¡¼´Â MAF¿Í MAF client °£ÀÇ ÂüÁ¶Á¡Àº Mmaf·Î, MEF¿Í MEFclients °£ÀÇ reference point´Â Mmef·Î ÇÏ¿©, À̸¦ Á¤ÀÇÇÏ´Â TS¸¦ °³¹ßÇϰí ÀÖ´Ù. Ãß°¡µÇ´Â MAF ±â´É°ú ÇØ´ç interface Mmaf°¡ [±×¸² 2]¿Í °°ÀÌ Á¦½ÃµÇ¾î ÀÖ´Ù.
[±×¸² 2] TS-0003 (Security Solution) oneM2M security ±¸Á¶ °³¿ä
4. oneM2M TP#27 (2017.2)ÀÇ TEF ÁøÇà
¡Û DM based MEF (SEC-0017R2, Ä÷ÄÄ)
- 2017³â 2¿ù (TP#27)¿¡ Ä÷ÄÄÀº TS-0032 v0.0.2(MAF&MEF)¿¡ ´ëÇØ ÀÔ·ÂÇϰí resource type¿¡ ´ëÇÑ Á¤ÀǸ¦ ÁøÇàÇÏ¿´´Ù.
- Ä÷ÄÄÀÌ ÀÔ·ÂÇÑ ±â°í¼°¡ Á¦¾ÈÇÏ´Â °ÍÀº MEF interfaceÀÇ resource Á¤ÀǶó°í º¼ ¼ö Àִµ¥, ÇØ´ç ³»¿ëÀÌ Æ¯È÷ MAS WGÀÇ device configuration ¹®¼¿¡ ¿µÇâÀ» ÁֹǷΠÀ̸¦ »óÈ£ Á¶À²/µ¿±âȽÃŰ´Â ÀÛ¾÷ÀÌ Áß¿äÇÏ°Ô ´Ù·ç¾îÁ³°í, MAS WG °úÀÇ Çù·Â ¼¼¼Ç¿¡¼ ³íÀǵǾú´Ù.
- MAS WG ÀÇ TS-0022(WI-0030)Àº 2017³â 2¿ù ¾à 85%ÀÇ ¿Ï¼ºÀ²À» º¸À̰í ÀÖÀ¸¸ç ÇöÀç ¹®¼ ±¸Á¶¸¦ ÀϺΠÁ¶Á¤Çϰí authentication profile, credential µî¿¡ ´ëÇÑ ºÎºÐÀ» Á¤¸®Çϰí ÀÖ´Ù.
- QualcommÀº MEFÀÇ ¿î¿ë¿¡ ÀÖ¾î MEF client°¡ µî·ÏÀ» À§ÇØ ÀÓÀÇ ½ÃÁ¡¿¡ credentialÀ» ÇÊ¿ä·Î ÇÒ ¼ö ÀÖ´Ù´Â Á¡À» ÁöÀûÇÏ¿© management of credentialÀÌ ÇÊ¿äÇϸç, ÀÌ´Â remote management¿¡ ÇØ´çÇÔÀ» Àû½ÃÇÑ´Ù.
- ÇØ´ç ³»¿ëÀº TS-0022 °¡ Á¤ÀÇÇϰí ÀÖ´Â resource type Áß <mgmtObj> ºÎºÐÀ» ÂüÁ¶ÇÏ¿©, ´ÙÀ½ ³»¿ëÀ» ¹Ý¿µÇØ ÁÙ °ÍÀ» Á¦¾ÈÇÏ¿´´Ù.
- ±âº»ÀûÀ¸·Î, MEF ´Â 3°¡Áö Á¾·ùÀÇ interactionÀ» Áö¿ø°¡´É
¤ý Mmaf <symmKeyReg> operation
¤ý EST (RFC7030)À» »ç¿ëÇÏ´Â certification µî·Ï(MEF´Â EST ¼¹ö¿ªÇÒ)
¤ý ±âŸ DM ±â´É »ç¿ë
- ±×¿Ü MAS¿ÍÀÇ µ¿±âȸ¦ À§ÇÑ actionÀÌ Á¦¾ÈµÇ¾ú°í, TS-22 ¹× TS-32ÀÇ ¿µÇâ, TS-01·ÎÀÇ ¿µÇâµî¿¡ ´ëÇØ Ãß°¡·Î °ËÅäÇÒ °ÍÀÌ ¿ä±¸µÇ¾ú´Ù.
[º°Ã·] oneM2M ÀÇ security ±¸Á¶ °³¿ä
¡Û oneM2M Security Solution ±Ô°Ý¼ TS-0003À» ÂüÁ¶
- TS-0003Àº M2M security architecture¸¦ ´ÙÀ½ ±×¸²°ú °°ÀÌ Á¤ÀÇ
- security layers:
¤ý security serviced layer, security function layer, secure environment abstraction layer, secure environments layer·Î ³ª´®.
¤ý ÀÌÁß secure function layer°¡ Mcc ¹× Mca ÀÎÅÍÆäÀ̽º ¿¡ ³ªÅ¸³ª´Â 6°¡Áö ±â´É ÁýÇÕÀÓ (Identification, Authentication, Authorization, Security Association, Sensitive Data Handling and Security Administration.)
¤ý secure service layer ´Â Access management, sensitive data handling, security association
establishment, security administration, identity protection ÀÇ ¼ºñ½º¸¦ Á¦°øÇÔ
- layer °£ »óÈ£ÀÛ¿ë:
¤ý M2M CSEµé °£ÀÇ ÀýÂ÷ ÀÌÀü¿¡ ÇϺÎÀÇ Network Service LayerÀÇ connectivity setupÀÌ ÀÌ·ç¾îÁü. À̷κÎÅÍ ½ÃÀÛÇÏ¿© CSE °èÃþÀÇ µ¶¸³ÀûÀÎ Security Provisioning and Security Association Establishment procedure°¡ °¡µ¿µÊ
¤ý Service layer ·¹º§¿¡¼´Â ÀÌ °á°ú TLS ȤÀº DTLS ¼¼¼ÇÀÌ ¸¸µé¾îÁ® ÀÎÁ¢ÇÑ(hop-by-hop) AE/CSE °£ÀÇ µ¥ÀÌÅÍ ±³È¯À» º¸È£ÇÑ´Ù. ¸¸ÀÏ untrusted Áß°£³ëµå¸¦ ÅëÇØ Á¤º¸¸¦ Àü¼ÛÇÒ ¶§ ÇÁ¶óÀ̹ö½Ã¸¦ º¸È£ÇÒ Çʿ䰡 ÀÖ´Â AE µéÀº ±×µé °£ direct security associationÀ» Áö¿øÇÏ¿© ±³È¯µÇ´Â ÀÚ¿øÀÇ ¾Ïȣȸ¦ ÇÒ ¼ö ÀÖÀ½.
- Enrolment phase:
¤ý M2M ÀåÄ¡´Â ÀϹÝÀûÀ¸·Î provisioning°ú configuration ÀÌÈÄ operation¿¡ µé¾î°¨. ÀÌÀÇ °úÁ¤À» ½ÇÇöÇÏ´Â µ¥´Â ¸î °¡Áö ¹æ¹ý°ú °æ¿ì°¡ ÀÖÀ¸³ª ±âº»ÀûÀ¸·Î M2M service provider¸¦ ¼±ÅÃÇÏ¿© Á¢¼ÓÇÏ´Â °ÍÀÌ ÇÙ½É. À̶§ 3rd party ȤÀº UN-SP domain¿¡¼ À̵éÀÇ enrolment¸¦ Áö¿øÇÏ´Â ±â´ÉÀÌ MEF ¹× MAF
¤ý Security Association Establishment Framework ¿¡ µû¸£¸é ´ÙÀ½°ú °°Àº ÀýÂ÷µéÀÌ °¡´ÉÇÔ
(1) Provisioned Symmetric Key Association Establishment Framework
(2) Certificate-based Security Association Establishment Framework
(3) M2M Authentication Function (MAF) Security Association Establishment Framework
* º» ±ÛÀº ÀúÀÚÀÇ ÀǰßÀÏ »Ó TTA ±â°üÀÇ ÀÔÀå°ú´Â ¹«°üÇÕ´Ï´Ù.