4.2.2.1 Does not exist in this document version |
Home → NEF → 20.1.0 |
4.2.2.1 |
Home → NEF → 17.0.0 |
|  33519-h00 → 33519-i00 33519-j00 33519-k00 → 33519-k10 | |
| Test Name | TC_CP_AUTH_AF_NEF | |
| Threat Reference | TR 33.926 [5], clause I.2.2.2, No authorization on northbound APIs |
|
| Requirement Name | Authorization on application function |
|
| Requirement Reference | TS 33.501 [2], clause 12.4 |
|
| Requirement Description | "The NEF shall authorize the requests from Application Function using OAuth-based authorization mechanism, the specific authorization mechanisms shall follow the provisions given in RFC 6749 [43]" as specified in TS 33.501 [2], clause 12.4. |
|
| Test Purpose | To verify that the NEF can authenticate application function and establish TLS connection towards the application server with certificate based authentication, and may authenticate application function and establish TLS connection towards the application server with pre-shared key based authentication. |
|
| Pre-Conditions |
|
|
| Execution Steps |
|
|
| Expected Results | Only one TLS connection is established at step 2. |
|
| Expected Format of Evidence | Evidence suitable for the interface, e.g., Screenshot containing the operational results. 4.2.2.1.2 Authorization on northbound APIs |
|
| PDFs | c7cf2cb5b58fe60e563899f2a4ac8fbf | |
4.2.2.1(2) Does not exist in this document version |
Home → NEF → 20.1.0 |
4.2.2.1(2) |
Home → NEF → 17.0.0 |
|  33519-h00 → 33519-i00 33519-j00 33519-k00 → 33519-k10 | |
| Test Name | TC_CP_AUTHOR_AF_NEF | |
| Threat Reference | TR 33.926 [5], clause I.2.2.2, No authorization on northbound APIs |
|
| Requirement Name | Authorization on application function |
|
| Requirement Reference | TS 33.501 [2], clause 12.4 |
|
| Requirement Description | "The NEF shall authorize the requests from Application Function using OAuth-based authorization mechanism, the specific authorization mechanisms shall follow the provisions given in RFC 6749 [43]" as specified in TS 33.501 [2], clause 12.4. |
|
| Test Purpose | To verify that the NEF can authorize application function. |
|
| Pre-Conditions |
|
|
| Execution Steps | Test 1: without token:
Test 2: With incorrect token:
|
|
| Expected Results | The invoking of NEF northbound API A succeeds, while the invoking of NEF northbound API B fails. |
|
| Expected Format of Evidence | Evidence suitable for the interface, e.g., Screenshot containing the operational results. |
|
| PDFs | f97dab867481a8c2e0d724d7ecf92a8e | |
4.2.2.1.1 |
Home → NEF → 20.1.0 |
| 33519-h00 → 33519-i00 33519-j00 33519-k00 →  33519-k10 | |
| Test Name | TC_CP_AUTH_AF_NEF | |
| Threat Reference | TR 33.926 [5], clause I.2.2.1, No authentication on application function |
|
| Requirement Name | Authentication on application function |
|
| Requirement Reference | TS 33.501 [2], clause 5.9.2.3, and clause 12.2 |
|
| Requirement Description | Mutual authentication between the NEF and Application Function is supported as specified in TS 33.501 [2], clause 5.9.2.3. For authentication between NEF and an Application Function that resides outside the 3GPP operator domain, mutual authentication based on client and server certificates is performed between the NEF and AF using TLS and Certificate based authentication follows the profiles given in TSĀ 33.210 [7], clause 6.2 as specified in TS 33.501 [2], clause 12.2. |
|
| Test Purpose | To verify that the NEF can authenticate application function and establish TLS connection towards the application server with certificate based authentication, and may authenticate application function and establish TLS connection towards the application server with pre-shared key based authentication. |
|
| Pre-Conditions |
|
|
| Execution Steps |
|
|
| Expected Results | Only one TLS connection is established at step 2. |
|
| Expected Format of Evidence | Evidence suitable for the interface, e.g., Screenshot containing the operational results. |
|
| PDFs | 4b48bba65c804cd980401459ac5f050b | |
4.2.2.1.2 |
Home → NEF → 20.1.0 |
| 33519-h00 → 33519-i00 33519-j00 33519-k00 →  33519-k10 | |
| Test Name | TC_CP_AUTHOR_AF_NEF | |
| Threat Reference | TR 33.926 [5], clause I.2.2.2, No authorization on northbound APIs |
|
| Requirement Name | Authorization on application function |
|
| Requirement Reference | TS 33.501 [2], clause 12.4 |
|
| Requirement Description | The NEF authorizes the requests from Application Function using OAuth-based authorization mechanism, the specific authorization mechanisms follow the provisions given in RFC 6749 [8], as specified in TS 33.501 [2], clause 12.4. |
|
| Test Purpose | To verify that the NEF can authorize application function. |
|
| Pre-Conditions |
|
|
| Execution Steps | Test 1: valid token:
Test 2: without token:
Test 3: with incorrect token:
Test 4: with correct token for different API:
|
|
| Expected Results | The invocation of NEF northbound API A succeeds in Test 1 and fails in Test 2 to Test 4. |
|
| Expected Format of Evidence | Evidence suitable for the interface, e.g., Screenshot containing the operational results. |
|
| PDFs | 02e342789f7dc15efdcaa15cf7fdc47c | |