TTA °£Ç๰ - ICT Standard Weekly

Ȩ > Ç¥ÁØÈ­ Âü¿© > TTA°£Ç๰ > ICT Standard Weekly

±â¼úÇ¥ÁØÀ̽´

´Ù¿î·Îµå (2017-11È£)
Æ®À§ÅÍ ÆäÀ̽ººÏ ¹ÌÅõµ¥ÀÌ

[oneM2M] oneM2M ÀÇ Trust Enablement Function(TEF) Ç¥Áع®¼­ °³¹ß ÇöȲ

New Template

1. TEF ±Ô°ÝÀÇ Á¤ÀÇ ¹× ÀÛ¾÷ Ç׸ñ °³¿ä

¡Û ÀÛ¾÷Ç׸ñ WI-0057 ¡°TEF Interface ½ÂÀΡ± : oneM2M TP#24 (2016.7)

- TEF(Trust Enabling Function)´Â oneM2MÀÇ »ýÅÂ°è ±¸Á¶ ¾È¿¡¼­ Á¤ÀǵǴ entityµé°£ÀÇ security¿Í trust¸¦ ¼ö¸³ÇÏ´Â ¸ñÀûÀ¸·Î ¿î¿µµÇ´Â ±â´ÉÀ» Á¤ÀÇÇÑ´Ù. TEF¿¡´Â MEF(M2M Enrolment Function)¿Í MAF(M2M Authorization Function)°¡ Æ÷ÇԵǸç, ÀÌ´Â oneM2M ÀÇ Trust Enabling Architecture(TS-0001)¿¡ Á¤ÀǵǴ ºÎºÐÀÌ´Ù.

- TP#24¿¡ Á¦ÃâµÇ¾î ½ÂÀÎµÈ ÇØ´ç ÀÛ¾÷Ç׸ñ(WI-0057)Àº Ä÷ÄÄÀÌ ÁÖµµÇϰí ÀÖÀ¸¸ç, ±âÁ¸¿¡ TS-0001(Functional Architecture) ¹× TS-0003(Security Solution)¿¡¼­ Á¤ÀÇÇϰí ÀÖ´Â TEF¸¦ ±¸Ã¼È­ÇÏ¿© TS ±Ô°Ý ¹®¼­·Î °³¹ßÇÏ´Â ÀÛ¾÷À» ÁøÇà ÁßÀÌ´Ù.

 

¡Û MEF¿Í MAF °£ ÇÁ·ÎÅäÄÝ Á¤ÀÇ ³»¿ë

- TS-0001 ¹®¼­¿¡ ÀÇÇϸé, M2M »ýŰ迡¼­ MEF´Â M2M node¸¦ ¿î¿µÇϱâ Àü M2M »ç¾÷ÀÚÀÇ ¼­ºñ½º¿¡ M2M ³ëµå¿Í ÀÀ¿ëÀ» enrolment(µî·Ï)Çϰí configurationÇÏ´Â ±â´ÉÀ» ´ã´çÇÑ´Ù. ÇÑÆí MAF´Â M2M ¼­ºñ½º ¿î¿µ Áß CSE¿Í AEÀÇ identification ¹× authentication, Á¾´Ü °£ primitives º¸¾È, Á¾´Ü °£ data º¸¾È µîÀ» °¡´ÉÇÏ°Ô ÇÏ´Â Á᫐ ±â´ÉÀ» ÁöÁ¤ÇÑ´Ù.

- MAF¿Í MEF´Â ¼­·Î ½Å·ÚÇÏ´Â ÁÖüµé (M2M »ç¾÷ÀÚ È¤Àº 3rd party)¿¡ ÀÇÇØ ¿î¿µµÇ´Â °ÍÀ¸·Î (ÇöÀç±îÁö´Â) Á¤Àǵǰí ÀÖ´Ù. À̵é°ú AE, CSE µî°ú´Â ¼­·Î »óÈ£¿î¿µÀÌ °¡´ÉÇØ¾ß Çϸç ÀÌµé °£ÀÇ ÂüÁ¶ Á¡ Á¤ÀÇ, »õ·Î¿î ÀϺΠresource-type Á¤ÀÇ, resource-type specific CRUD procedure ¹× data types of the resource attributesÀº Ãß°¡·Î Á¤ÀǵǾî¾ß ÇÔÀÌ ±âÁ¸ÀÇ ¹®¼­¿¡ Àû½ÃµÇ¾î ÀÖ´Ù.

 

¡Û MEF¿Í MAF °£ ÇÁ·ÎÅäÄÝ Á¤ÀÇ ³»¿ë

- WI-0057Àº »ó±â Ãß°¡·Î Á¤ÀÇÇØ¾ß ÇÒ »çÇ×µé°ú ÇÔ²² TEF¿¡¼­ ¿î¿µµÉ ÇÁ·ÎÅäÄÝ primitiveµéÀ» °³¹ßÇÑ´Ù. TS-0003Àº M2M entityµé(AE ¿Í CSE µî)°ú MEF(M2M Enrolment Function) ¹× MAF (M2M Authorization Function) °£ ¿¬µ¿À» ÀüÁ¦ÇÑ security ÇÁ·¹ÀÓ¿öÅ©¸¦ Á¤ÀÇÇϰí Àִµ¥, (TS-0003 Security °³¿ä: º°Ã· Âü°í) ÇØ´ç ÇÁ·¹ÀÓ¿öÅ©´Â ´ÙÀ½ÀÇ security ÇÁ·¹ÀÓ¿öÅ©¸¦ ÁöÁ¤ Çϰí ÀÖ´Ù.

¤ý MEF-based Remote Security Provisioning Frameworks (RSPF)

¤ý MAF-based Security Association Establishment Framework (MAF-based SAEF)

¤ý End-to-End Security of Primitives (ESPrim)

¤ý End-to-End Security of Data (ESData)

- ÀÌ Áß MEF-based RSPF´Â MEF¿Í MAF °£ »óÈ£Åë½ÅÀ» ÇÊ¿ä·Î ÇÑ´Ù. »ó±âÀÇ security ÇÁ·¹ÀÓ¿öÅ©´Â ´ë°³ÀÇ °æ¿ì (D)TLS¿¡ ±â¹ÝÇϰí ÀÖÀ¸³ª TEF °£ ÀϺΠÆÄ¶ó¹ÌÅÍ´Â Àü´ÞÀÌ °ï¶õÇÏ¿© À̸¦ Ãß°¡·Î Á¤ÀÇÇØ¾ß ÇÑ´Ù´Â °ÍÀÌ ÀÛ¾÷Ç׸ñÀÇ ¿äÁ¡ÀÌ´Ù. ÀÌ¿¡ µû¶ó Mcc¿Í Mca¿¡ ¿î¿µÇÒ º°µµÀÇ ÇÁ·ÎÅäÄÝÀ» Á¤ÀÇÇÑ´Ù.

 

¡Û ÀÛ¾÷ ÀÏÁ¤

- WIÀÇ ½ÂÀÎ ÀÌÈÄ TP28¿¡¼­ freeze, TP29¿¡¼­ ½ÂÀÎÇÏ´Â ÀÏÁ¤À» ¸ñÇ¥·Î ÃßÁø ÁßÀ̸ç, ¿¹Á¤´ë·Î ÁøÇàµÇ¸é ÇØ´ç ±Ô°ÝÀº rel-3 ±Ô°Ý ¹®¼­·Î Æ÷Ç﵃ °ÍÀ¸·Î ¿¹»óµÈ´Ù.

- Lead WGÀº SEC(WG4)À̸ç TS ¹®¼­(TEF Interface Specification)·Î °³¹ß ÁßÀε¥, º» ÀÛ¾÷ Ç׸ñÀ» Á¦¾È ÇÑ Ä÷ÄÄÀÌ ¶óÆ÷ÅÍ/¿¡µðÅÍ·Î ÁøÇà ÁßÀÌ´Ù.

 

2. TEF ±â´ÉÀÇ µ¶¸³È­ ¹æ½ÄÀ» Áö¿øÇÏ´Â ÀÛ¾÷ Ç׸ñ °³Á¤

¡Û oneM2M TP#25/ SEC WG (2016.10)¿¡¼­ ÀÛ¾÷Ç׸ñ WI-0057 revision

- 2016³â 10¿ù¿¡ Ä÷ÄÄÀº ÀÛ¾÷ Ç׸ñÀÇ revisionÀ» Á¦ÃâÇÏ¿´À¸¸ç, À̸¦ ÅëÇØ TEF modelingÀÇ option 3À» Ãß°¡ÇÏ¿´´Ù. ÀÌ´Â ¡°stand-alone TEF entity ¹æ½Ä¡±À» Ãß°¡ Á¦¾ÈÇÑ °ÍÀ¸·Î, ¾Æ·¡ [±×¸² 1]¿¡ º¸ÀÌ´Â ¿¹¿Í °°ÀÌ ±âÁ¸ÀÇ SEC CSF¿Í º°µµ·Î TE CSF¸¦ ±¸ÇöÇÏ´Â °ÍÀ» Á¦¾ÈÇÏ¿© ½ÂÀεǾú´Ù.

- ¶Ç ÀÌ·Î ÀÎÇØ Trust enabling CSF°¡ »ý±ä °Í¿¡ ´ëÀÀÇÏ´Â message flowÀÇ update¿Í ÇâÈÄ ÃßÁø ¹æÇâÀ» Á¤¸®ÇÏ¿´´Ù


 [±×¸² 1] TEFÀÇ ±¸Çö ¹æ½Ä (CSF±â¹ÝÀÇ ±¸Çö option - SEC CSF ÀÇ ³»ºÎ ȤÀº ¿ÜºÎ¿¡ ±¸Çö)

Ref: SEC-2016-0165R1

 

3. TP#26 (2016.12)ÀÇ TEF °ü·Ã À̽´ ¹× Ç¥ÁØÈ­ ÁøÇà Á¤µµ

¡Û oneM2M TP#26¿¡ Á¦ÃâµÈ 3°³ÀÇ ¹®¼­ äÅÃ

- TP26¿¡¼­´Â Ä÷ÄÄÀÌ Á¦ÃâÇÑ skeleton ¹®¼­, scope ¹®¼­, main body - base line ¹®¼­°¡ ¸ðµÎ ½ÂÀεǾú°í, SEC/ARC joint sessionÀ» ÅëÇÑ interface discussionÀ» ÁøÇàÇÏ¿´´Ù. À̸¦ ÅëÇØ ÇÕÀÇÇÑ ÀÏÁ¤À¸·Î TP26¿¡ µÚÀ̾ (SEC26.1 µî Ãß°¡È¸ÀǸ¦ ÅëÇØ) ¡°MAF and MAF Interface Specification¡±draft¸¦ ¸¸µé °ÍÀ» ¿¹°íÇÏ¿´´Ù.

- ÇöÀç ¹öÀüÀÇ body¿¡¼­´Â MAF¿Í MAF client °£ÀÇ ÂüÁ¶Á¡Àº Mmaf·Î, MEF¿Í MEFclients °£ÀÇ reference point´Â Mmef·Î ÇÏ¿©, À̸¦ Á¤ÀÇÇÏ´Â TS¸¦ °³¹ßÇϰí ÀÖ´Ù. Ãß°¡µÇ´Â MAF ±â´É°ú ÇØ´ç interface Mmaf°¡ [±×¸² 2]¿Í °°ÀÌ Á¦½ÃµÇ¾î ÀÖ´Ù.


[
±×¸² 2] TS-0003 (Security Solution) oneM2M security ±¸Á¶ °³¿ä

 

4. oneM2M TP#27 (2017.2)ÀÇ TEF ÁøÇà

¡Û DM based MEF (SEC-0017R2, Ä÷ÄÄ)

- 2017³â 2¿ù (TP#27)¿¡ Ä÷ÄÄÀº TS-0032 v0.0.2(MAF&MEF)¿¡ ´ëÇØ ÀÔ·ÂÇϰí resource type¿¡ ´ëÇÑ Á¤ÀǸ¦ ÁøÇàÇÏ¿´´Ù.

- Ä÷ÄÄÀÌ ÀÔ·ÂÇÑ ±â°í¼­°¡ Á¦¾ÈÇÏ´Â °ÍÀº MEF interfaceÀÇ resource Á¤ÀǶó°í º¼ ¼ö Àִµ¥, ÇØ´ç ³»¿ëÀÌ Æ¯È÷ MAS WGÀÇ device configuration ¹®¼­¿¡ ¿µÇâÀ» ÁֹǷΠÀ̸¦ »óÈ£ Á¶À²/µ¿±âÈ­½ÃŰ´Â ÀÛ¾÷ÀÌ Áß¿äÇÏ°Ô ´Ù·ç¾îÁ³°í, MAS WG °úÀÇ Çù·Â ¼¼¼Ç¿¡¼­ ³íÀǵǾú´Ù.

- MAS WG ÀÇ TS-0022(WI-0030)Àº 2017³â 2¿ù ¾à 85%ÀÇ ¿Ï¼ºÀ²À» º¸À̰í ÀÖÀ¸¸ç ÇöÀç ¹®¼­ ±¸Á¶¸¦ ÀϺΠÁ¶Á¤Çϰí authentication profile, credential µî¿¡ ´ëÇÑ ºÎºÐÀ» Á¤¸®Çϰí ÀÖ´Ù.

- QualcommÀº MEFÀÇ ¿î¿ë¿¡ ÀÖ¾î MEF client°¡ µî·ÏÀ» À§ÇØ ÀÓÀÇ ½ÃÁ¡¿¡ credentialÀ» ÇÊ¿ä·Î ÇÒ ¼ö ÀÖ´Ù´Â Á¡À» ÁöÀûÇÏ¿© management of credentialÀÌ ÇÊ¿äÇϸç, ÀÌ´Â remote management¿¡ ÇØ´çÇÔÀ» Àû½ÃÇÑ´Ù.

- ÇØ´ç ³»¿ëÀº TS-0022 °¡ Á¤ÀÇÇϰí ÀÖ´Â resource type Áß <mgmtObj> ºÎºÐÀ» ÂüÁ¶ÇÏ¿©, ´ÙÀ½ ³»¿ëÀ» ¹Ý¿µÇØ ÁÙ °ÍÀ» Á¦¾ÈÇÏ¿´´Ù.

- ±âº»ÀûÀ¸·Î, MEF ´Â 3°¡Áö Á¾·ùÀÇ interactionÀ» Áö¿ø°¡´É

¤ý Mmaf <symmKeyReg> operation

¤ý EST (RFC7030)À» »ç¿ëÇÏ´Â certification µî·Ï(MEF´Â EST ¼­¹ö¿ªÇÒ)

¤ý ±âŸ DM ±â´É »ç¿ë 

- ±×¿Ü MAS¿ÍÀÇ µ¿±âÈ­¸¦ À§ÇÑ actionÀÌ Á¦¾ÈµÇ¾ú°í, TS-22 ¹× TS-32ÀÇ ¿µÇâ, TS-01·ÎÀÇ ¿µÇâµî¿¡ ´ëÇØ Ãß°¡·Î °ËÅäÇÒ °ÍÀÌ ¿ä±¸µÇ¾ú´Ù.

 

[º°Ã·] oneM2M ÀÇ security ±¸Á¶ °³¿ä

¡Û oneM2M Security Solution ±Ô°Ý¼­ TS-0003À» ÂüÁ¶

- TS-0003Àº M2M security architecture¸¦ ´ÙÀ½ ±×¸²°ú °°ÀÌ Á¤ÀÇ

- security layers:

¤ý security serviced layer, security function layer, secure environment abstraction layer, secure environments layer·Î ³ª´®.

¤ý ÀÌÁß secure function layer°¡ Mcc ¹× Mca ÀÎÅÍÆäÀ̽º ¿¡ ³ªÅ¸³ª´Â 6°¡Áö ±â´É ÁýÇÕÀÓ (Identification, Authentication, Authorization, Security Association, Sensitive Data Handling and Security Administration.)

¤ý secure service layer ´Â Access management, sensitive data handling, security association

establishment, security administration, identity protection ÀÇ ¼­ºñ½º¸¦ Á¦°øÇÔ

 

 

- layer °£ »óÈ£ÀÛ¿ë:

¤ý M2M CSEµé °£ÀÇ ÀýÂ÷ ÀÌÀü¿¡ ÇϺÎÀÇ Network Service LayerÀÇ connectivity setupÀÌ ÀÌ·ç¾îÁü. À̷κÎÅÍ ½ÃÀÛÇÏ¿© CSE °èÃþÀÇ µ¶¸³ÀûÀÎ Security Provisioning and Security Association Establishment procedure°¡ °¡µ¿µÊ

¤ý Service layer ·¹º§¿¡¼­´Â ÀÌ °á°ú TLS ȤÀº DTLS ¼¼¼ÇÀÌ ¸¸µé¾îÁ® ÀÎÁ¢ÇÑ(hop-by-hop) AE/CSE °£ÀÇ µ¥ÀÌÅÍ ±³È¯À» º¸È£ÇÑ´Ù. ¸¸ÀÏ untrusted Áß°£³ëµå¸¦ ÅëÇØ Á¤º¸¸¦ Àü¼ÛÇÒ ¶§ ÇÁ¶óÀ̹ö½Ã¸¦ º¸È£ÇÒ Çʿ䰡 ÀÖ´Â AE µéÀº ±×µé °£ direct security associationÀ» Áö¿øÇÏ¿© ±³È¯µÇ´Â ÀÚ¿øÀÇ ¾Ïȣȭ¸¦ ÇÒ ¼ö ÀÖÀ½.

- Enrolment phase:

¤ý M2M ÀåÄ¡´Â ÀϹÝÀûÀ¸·Î provisioning°ú configuration ÀÌÈÄ operation¿¡ µé¾î°¨. ÀÌÀÇ °úÁ¤À» ½ÇÇöÇÏ´Â µ¥´Â ¸î °¡Áö ¹æ¹ý°ú °æ¿ì°¡ ÀÖÀ¸³ª ±âº»ÀûÀ¸·Î M2M service provider¸¦ ¼±ÅÃÇÏ¿© Á¢¼ÓÇÏ´Â °ÍÀÌ ÇÙ½É. À̶§ 3rd party ȤÀº UN-SP domain¿¡¼­ À̵éÀÇ enrolment¸¦ Áö¿øÇÏ´Â ±â´ÉÀÌ MEF ¹× MAF

¤ý Security Association Establishment Framework ¿¡ µû¸£¸é ´ÙÀ½°ú °°Àº ÀýÂ÷µéÀÌ °¡´ÉÇÔ

(1) Provisioned Symmetric Key Association Establishment Framework

(2) Certificate-based Security Association Establishment Framework

(3) M2M Authentication Function (MAF) Security Association Establishment Framework

¾ÈÀ翵 (Çѱ¹ÀüÀÚÅë½Å¿¬±¸¿ø(ETRI) Ã¥ÀÓ¿¬±¸¿ø, ahnjy@etri.re.kr)

* º» ±ÛÀº ÀúÀÚÀÇ ÀǰßÀÏ »Ó TTA ±â°üÀÇ ÀÔÀå°ú´Â ¹«°üÇÕ´Ï´Ù.