
)*+,,*
-./
!
))0+)01++,
=!
)(+
42!
*,0
STLF-NA-TRD-REQ-2500 The SATLIFE system shall support the integration of IPSec NAT Traversal
and also modified Negotiation of NAT-Traversal in the IKE for IPv4 traffic
through NATs. When using IPv6 this modification is not required and
traditional end-to-end IPSec can be achieved
NA - -
STLF-NA-TRD-REQ-2510 The System shall include a Network Firewall to provide a secure environment
for the satellite services
T NERA: By design
STLF_IF_RCST_NAT
INDRA
STLF-NA-TRD-REQ-2520 The System Firewall shall provide NAT facility to access to other networks.
This will help to conserve precious IP addresses and could offer load
balancing.
T NERA: By design
STLF_IF_RCST_NAT
INDRA
STLF-NA-TRD-REQ-2530 The System Firewall shall allow secure access to the Internet from within
existing private networks, and the ability to expand and reconfigure TCP/IP
networks without being concerned about a shortage of IP addresses
T NERA: By design
STLF_IF_RCST_NAT
INDRA
STLF-NA-TRD-REQ-2540 Firewalls/NAT shall allow that users behind them can interoperate with other
Internet users, for example considering the use of Firewall Control Protocol
(FCP, IETF MidCom group) that enables Hop-by-hop signaling security
support.
T NERA: By design
STLF_IF_RCST_NAT
INDRA
STLF-NA-TRD-REQ-2550 For the software download to the terminals, the SAT-LIFE System shall
support encrypted and authenticated downloads either at the network level
(IPSec) or application level.
NA - -
STLF-NA-TRD-REQ-2560 Secure channels shall be supported between the NMC and the terminals
and RSGW in the SATLIFE system
NA - -
STLF-NA-TRD-REQ-2570 The SATLIFE System shall be support DVB-CA security mechanisms for
Video Broadcasting and Software download
NA - -
STLF-NA-TRD-REQ-2580 The System shall provide terminals with individual DVB security mechanisms
in the forward/return links, as specified in ETSI EN 301 790
NA - -
STLF-NA-TRD-REQ-2590 The RCST IDU shall support on-the-fly encryption/decryption of MPE payload NA - -
STLF-NA-TRD-REQ-2600 From the different key exchange protocols proposed in the standard [9] the
security protocol supported in SatLife System shall be Explicit Key Exchange
(EKE).
T STLF_IF_RCST_MGMT_AUTH STLF_IO_SEC_RCST
STLF_IO_SEC_RSGW
STLF-NA-TRD-REQ-2610 The negotiation phase (sign-on phase) shall be "per connection", instead of
"per terminal".
T STLF_IF_RCST_MGMT_AUTH STLF_IO_SEC_RCST
STLF_IO_SEC_RSGW
STLF-NA-TRD-REQ-2620 The security connection procedure occurs after the RCST passed the DVB-
RCS logon, and allows the NCC and the RCST to:
· negotiate security parameters; this is the negotiation step of the security
connection procedure
· agree on initial session keys and authenticate the RCST; this is the key
exchange step of the security connection procedure.
T STLF_IF_RCST_MGMT_AUTH STLF_IO_SEC_RCST
STLF_IO_SEC_RSGW
Kommentare zu diesen Handbüchern