4.2.1.2.6 Protecting data and information -- Data masking on integration analysis |
Home → NWDAF → 20.1.0 |
| 33521-h00 → 33521-h10 33521-h20 33521-i00 33521-j00 → 33521-k00 →  33521-k10 | |
| Test Name | TC_DATA_MASKING | |
| Threat Reference | TR 33.926 [ 4], clause 5.3.6.7, Personal Identification Information Violation |
|
| Requirement Name | Data masking on integration analysis about personal data |
|
| Requirement Reference | In accordance with industry best practice.. |
|
| Requirement Description | NWDAF can collect data from OAM, MDAF and/or 5GC NFs (e.g. AMF) etc. for analytics purposes. Since personal data of the users could be involved , there is a potential privacy impact. As the NWDAF can expose its service operations with a request for bulked data, anonymization of data fields shall be applied to avoid exposing undesired information, aggregation levels. |
|
| Test Purpose | Verify that no privacy-related information of the subscribers is disclosed to any entity who is not authorized to access such information. |
|
| Pre-Conditions | Privacy information list (contains e.g. PII, location data, network identifiers, session information; should be specified based on local policy, regulation and others).
The following entities are operational, integrated and simulated:
The data producer is configured to receive and accept subscription requests from the NWDAF for events according to TS 29.552 [6], clause 5.5.1.1. |
|
| Execution Steps |
|
|
| Expected Results | The analytics results do not reveal subscriber permanent identifier nor any other data listed on the Privacy information list. |
|
| Expected Format of Evidence | Evidence suitable for the interface, e.g. screenshot, pcap trace, log files containing the results. |
|
| PDFs | 910f575dd12365a62a614d0418ed112b | |
4.2.1.2.6 Protecting data and information -- Data masking on integration analysis |
Home → NWDAF → 20.0.0 |
| 33521-h00 → 33521-h10 33521-h20 33521-i00 33521-j00 →  33521-k00 → 33521-k10 | |
| Test Name | TC_DATA_MASKING | |
| Threat Reference | TR 33.926 [ 4], clause 5.3.6.7, Personal Identification Information Violation |
|
| Requirement Name | Data masking on integration analysis about personal data |
|
| Requirement Reference | In accordance with industry best practice.. |
|
| Requirement Description | NWDAF can collect data from OAM, MDAF and/or 5GC NFs (e.g. AMF) etc. for analytics purposes. Since personal data of the users could be involved , there is a potential privacy impact. As the NWDAF can expose its service operations with a request for bulked data, anonymization of data fields shall be applied to avoid exposing undesired information, aggregation levels. |
|
| Test Purpose | Verify that no privacy-related information of the subscribers is disclosed to any entity who is not authorized to access such information. |
|
| Pre-Conditions | Privacy information list (contains e.g. PII, location data, network identifiers, session information; should be specified based on local policy, regulation and others).
The following entities are operational, integrated and simulated:
The data producer is configured to receive and accept subscription requests from the NWDAF for events according to TS 29.552 [6], clause 5.5.1.1. |
|
| Execution Steps |
|
|
| Expected Results | The analytics results do not reveal subscriber permanent identifier nor any other data listed on the Privacy information list. |
|
| Expected Format of Evidence | Evidence suitable for the interface, e.g. screenshot, pcap trace, log files containing the results. |
|
| PDFs | 910f575dd12365a62a614d0418ed112b | |
4.2.1.2.7 |
Home → NWDAF → 20.1.0 |
| 33521-h00 → 33521-h10 33521-h20 33521-i00 33521-j00 → 33521-k00 →  33521-k10 | |
| Test Name | TC_NWDAF_ANALYTICS_ID_AUTHZ | |
| Threat Reference | TR 33.926 [4], threats related to "Privilege Escalation" and "Unauthorized Service Access". |
|
| Requirement Name | Fine-grained authorization for analytics services |
|
| Requirement Reference | In accordance with TS 33.501 [7], clauses X.8, X.9, and X.12. |
|
| Requirement Description | The NF Service Producer authenticates the NF Service Consumer and verifies the access token and ensures that the Analytics ID is included in the access token. |
|
| Test Purpose | To verify that the NWDAF, when acting as an NF service producer, can perform fine-grained authorization control based on the Analytics ID claim in an access token within procedures such as Nnwdaf_RoamingAnalytics_Subscribe/Request. The test ensures that a service consumer is only able to access the specific analytics type(s) it is authorized for.
|
|
| Pre-Conditions |
|
|
| Execution Steps |
|
|
| Expected Results |
|
|
| Expected Format of Evidence | Logs, network traces (e.g., .pcap files), or screenshots of the relevant interface messages. The evidence must clearly show:
|
|
| PDFs | 664e55782a18cc91b8311c07032f89e0 | |
4.2.1.2.8 |
Home → NWDAF → 20.1.0 |
| 33521-h00 → 33521-h10 33521-h20 33521-i00 33521-j00 → 33521-k00 →  33521-k10 | |
| Test Name | TC_NWDAF_MLMODEL_ACCESS_CONTROL | |
| Threat Reference | TR 33.926 [4], threats related to "Unauthorized Access to Critical Assets" and "Model Poisoning". |
|
| Requirement Name | Analytics ID-level access control for ML model assets in MTLF provisioning |
|
| Requirement Reference | In accordance with TS 33.501 [7], clauses X.9 and X.10. |
|
| Requirement Description | The NWDAF containing the MTLF verifies that the Analytics ID contained within the access token's scope matches the Analytics ID associated with the requested ML model asset. |
|
| Test Purpose | To verify that the NWDAF, when acting as an MTLF (NF service producer), can perform fine-grained authorization control based on the Analytics ID claim in an access token within the Nnwdaf_MLModelProvision_Subscribe procedure. The test ensures that a service consumer is only able to access the specific ML model asset(s) it is authorized for.
|
|
| Pre-Conditions |
|
|
| Execution Steps |
|
|
| Expected Results |
|
|
| Expected Format of Evidence | Logs, network traces (e.g., .pcap files), or screenshots of the relevant interface messages. The evidence must clearly show:
|
|
| PDFs | 21e0109f21387319c2e85afa1716d4aa | |