5.2.2.1.4 Ciphering of user data based on the security policy sent by the SMF |
Home → split gNB → 19.1.0 |
| 33523-i00 33523-i01 → 33523-i10 → 33523-i20 33523-j00  33523-j10 33523-j20 | |
| Test Name | TC-UP-DATA-CIP-SMF_gNB-CU-CP | |
| Threat Reference | TR 33.926 [4], clause S.2.2.6 -- Security Policy Enforcement. |
|
| Requirement Name | Ciphering of user data based on the security policy sent by the SMF. |
|
| Requirement Reference | TS 33.501 [3], clause 5.3.2. |
|
| Requirement Description | The gNB activates ciphering of user data based on the security policy sent by the SMF as specified in TS 33.501 [3], clause 5.3.2. |
|
| Test Purpose | To verify that activation of confidentiality protectionfor user data at the gNB is based on the security policy sent by the SMF via AMF. |
|
| Pre-Conditions |
|
|
| Execution Steps | All execution steps are to be performed two times. Once with the UP security policies' ciphering protection in step 2 set to "required" and the second time set to "not needed".
|
|
| Expected Results | Both the RRC connection Reconfiguration message and Bearer Context Setup Request message indicate that ciphering is to be used in line with the policy received from the SMF. |
|
| Expected Format of Evidence | Evidence suitable for the interface, e.g. Screenshot containing the operational results. |
|
| PDFs | 6c61973338349f737fb8f793318cd1aa | |
5.2.2.1.5 Integrity of user data based on the security policy sent by the SMF |
Home → split gNB → 19.1.0 |
| 33523-i00 33523-i01 → 33523-i10 → 33523-i20 33523-j00  33523-j10 33523-j20 | |
| Test Name | TC-UP-DATA-INT-SMF_gNB-CU-CP | |
| Threat Reference | TR 33.926 [4], clause S.2.2.6 -- Security Policy Enforcement. |
|
| Requirement Name | Integrity of user data based on the security policy sent by the SMF. |
|
| Requirement Reference | TS 33.501 [3], clause 5.3.2. |
|
| Requirement Description | The gNB activates integrity protection of user data based on the security policy sent by the SMF as specified in TS 33.501 [3], clause 5.3.2. |
|
| Test Purpose | To verify that activation of integrity protection for user data packets is based on the security policy sent by the SMF. |
|
| Pre-Conditions |
|
|
| Execution Steps | All execution steps are to be performed two times. Once with the UP security policies' ciphering protection in step 2 set to "required" and the second time set to "not needed".
|
|
| Expected Results | Both the the RRC Reconfiguration message and Bearer Context Setup Request message indicate that integrity is to be used inline with the policy received from the SMF. |
|
| Expected Format of Evidence | Evidence suitable for the interface, e.g. Screenshot containing the operational results. |
|
| PDFs | 84cf0a03f880d7c38969f0c04159fca3 | |
6.2.2.1.6 Integrity protection of user data between the UE and the gNB-CU-UP |
Home → split gNB → 19.1.0 |
| 33523-i00 33523-i01 → 33523-i10 → 33523-i20 33523-j00  33523-j10 33523-j20 | |
| Test Name | TC-UP-DATA-INT_gNB-CU-UP | |
| Threat Reference | TR 33.926 [4], clause T.2.2.4 -- User plane data integrity protection. |
|
| Requirement Name | Integrity protection of user data between the UE and the gNB-CU-UP. |
|
| Requirement Reference | TS 33.501 [3], clause 5.3.3 |
|
| Requirement Description | The gNB supports integrity protection and replay protection of user data between the UE and the gNB as specified in TS 33.501 [3], clause 5.3.3.
|
|
| Test Purpose | To verify that the user data packets are integrity protected over the NG RAN air interface. |
|
| Pre-Conditions |
|
|
| Execution Steps |
|
|
| Expected Results | Any user plane packets sent between UE and gNB-CU-UP over the NG RAN air interface after gNB-CU-UP receives the Bearer Context Setup Request is integrity protected. |
|
| Expected Format of Evidence | Evidence suitable for the interface e.g. Screenshot containing the operational results. |
|
| PDFs | 072c6f937eb17f608b2bf197c826c789 | |
6.2.2.1.7 Ciphering of user data between the UE and the gNB-CU-UP |
Home → split gNB → 19.1.0 |
| 33523-i00 33523-i01 → 33523-i10 → 33523-i20 33523-j00  33523-j10 33523-j20 | |
| Test Name | TC-UP-DATA-CIP_gNB | |
| Threat Reference | TR 33.926 [4], clause T.2.2.3 -- User plane data confidentiality protection at gNB |
|
| Requirement Name | Ciphering of user data between the UE and the gNB-CU-UP |
|
| Requirement Reference | TS 33.501 [3], clause 5.3.2 |
|
| Requirement Description | The gNB supports ciphering of user data between the UE and the gNB as specified in TS 33.501 [3], clause 5.3.2. |
|
| Test Purpose | To verify that the user data packets are confidentiality protected over the NG RAN air interface. |
|
| Pre-Conditions |
|
|
| Execution Steps |
|
|
| Expected Results | The user plane packets sent to the UE after the gNB-CU-UP receives the Bearer Context Setup Request is confidentiality protected. |
|
| Expected Format of Evidence | Evidence suitable for the interface e.g. Screenshot containing the operational results. |
|
| PDFs | ed22cd53c51422dba42b1b8fdc404516 | |