ITU

Available (246)

Showing 49 - 60 per page



Security Assertion Markup Language (SAML 2.0)

SAML is an XML-based framework for exchanging security information. This security information is expressed in the form of assertions about subjects, where a subject is an entity (either human or computer) that has an identity in some security domain. A single assertion might contain several different internal statements about authentication, authorization and attributes. This Recommendation defines a protocol by which clients can request assertions from SAML authorities and get a response from them. This protocol, consisting of XML-based request and response message formats, can be bound to many different underlying communications and transport protocols; SAML currently defines one binding to SOAP over HTTP. In creating their responses, SAML authorities can use various sources of information, such as external policy stores and assertions that were received as input in requests. This Recommendation defines SAML assertions elements, subjects, conditions, processing rules and statements. Additionally, it develops a comprehensive SAML metadata profile that includes associated namespace, common data types, processing rules and signature processing. Several protocol bindings such as SOAP, PAOS (reverse SOAP), HTTP redirect, HTTP POST, among others, are also developed. This Recommendation provides a comprehensive list of SAML profiles such as web browser SSO profile and single logout profile to enable the wide adoption of SAML 2.0 in the industry. Guidelines for authentication context and conformance are also provided.This Recommendation is technically equivalent and compatible with the OASIS SAML 2.0 standard.

ITU-T X.1141

ITU-T - SG17 - X.gecdsGuideline on edge computing data security

Edge computing is strongly related to 5G and UPF is the data connection point between the MEC system and 5G Network architecture. The sinking of 5G network user plane brings threats such as illegal eavesdropping, which may seriously threaten the data security in edge computing. The edge node has unique features itself and whether in the physical environment or the network, the data security will be an important problem that the edge nodes need to face. Therefore, the recommendation analyses the edge computing data security mainly from these two aspects and provides relative data security challenges and threats and data security guidelines for Edge Computing. This recommendation could help to address the data security issues in Edge Computing implementation

ITU-T - SG17 - X.gecds

Security guidelines for container in cloud computing environment

Recommendation X.1643 analyses security threats and challenges on virtualization container in cloud computing environment and specifies a reference framework with security guidelines for virtualization container in cloud.

Security requirements for Communication as a Service application environments

Recommendation ITUT X.SRCaaS recommends the security requirements of communication as a service (CaaS) application environments with the identification of the risks. The Recommendation describes the scenarios and the features of CaaS, into which multicommunication capabilities are plugged. Moreover, some special /unique risks are identified, which are caused by the unique features of CaaS. The corresponding security requirements are recommended for the following aspects: Identity fraud, orchestration security, multi devices security, countering spam, privacy protection, infrastructure attack, attack from infrastructure, Intranet attack and so on. The Recommendation refers to the common security requirements of Recommendation ITUT X.1602 to avoid duplicated work. These measures in the requirements take into account the national legal and regulatory obligations in individual member states in which the platforms operate. The work applies the methodology standardized in clause 10 of Recommendation ITU-T X.1601.

Security requirements of public infrastructure as a service (IaaS) in cloud computing

Infrastructure as a Service (IaaS) is one of the representative categories of cloud services, in which the cloud capabilities service provided to the CSC is an infrastructure capabilities type. IaaS environments and virtualized services are facing more challenges and threats than traditional information technology infrastructure and application. Platforms that share computing, storage, and network services need protections specific to the threats in the IaaS environment. If these threats are not carefully addressed, it will have very negative impact on the development of IaaS services.Recommendation ITU- X.SRIaaS aims to document the security requirements of public IaaS. This will be helpful for IaaS CSPs to improve the overall security level throughout the planning, constructing and operating stages of IaaS platform and services. This work also complements the security standardization activity related to Software Defined Networks

Security requirements of Network as a Service (NaaS) in cloud computing

Network as a Service (NaaS) is one of the representative cloud service categories, in which the capability provided to the cloud service customer (CSC) is transport connectivity and related network capabilities. NaaS services can provide any of three cloud capabilities as: NaaS application service, NaaS platform service and NaaS connectivity service. All the three kinds of NaaS service face particular security challenges such as application security vulnerabilities, security risks of network virtualization, eavesdropping, etc. Recommendation ITU-T X.SRNaaS analyses the security challenges and security requirements of NaaS application, NaaS platform and NaaS connectivity. This Recommendation could help NaaS service providers to address on the security issues. The capabilities provided by this Recommendation will take into account the national legal and regulatory obligations in individual Member States in which the NaaS services operate.The methodology of this proposal would follow the recommendations of clause 10 in Recommendation ITU-T X.1601.

Data aware networking (information centric networking) – Requirements and capabilities

This Recommendation specifies the requirements and capabilities of data aware networking (DAN) to realize the use cases and scenarios described in ITU-T Supplement 35 to Recommendation Y.3033, Data aware networking - Scenarios and use cases, which are expected to be major applications/services provided on DAN. One of the objectives reflecting emerging requirements for future networks (FNs) is data awareness as specified in ITU-T Recommendation Y.3001 - Future networks: Objectives and design goals. DAN is expected to have capabilities optimized to handle enormous amount of data and to enable users to access desired data safely, easily, quickly, and accurately, regardless of their location by making information the destination of request delivery. DAN can be rephrased as the networking whose central concern is retrieving information, i.e., information centric networking (ICN).

Proof-of-concept for data service using information centric networking in IMT-2020

This Supplement specifies a proof-of-concept for a service that provides named data such as Internet of Things (IoT) named data by information centric networking in IMT-2020. In the Supplement, an enhanced name resolution system is implemented based on distance-constrained containers to resolve from names to addresses more efficiently.