S3-140709 3GPP TSG-SA3 (Security) Meeting #75 12 – 16 May 2014, Sapporo, Japan CR-Form-v11 CHANGE REQUEST CR 0206 rev - Current version: 33.203 12.5.0 For HELP on using this form: comprehensive instructions can be found at http://www.3gpp.org/Change-Requests. Proposed change affects: UICC apps ME X Radio Access Network Core Network X Title: Description of authentication requirements in new Annex on TS 33.203 Source to WG: Source to TSG: China Mobile, Huawei SA3 Work item code: IMS_WebRTC Date: 2014-05-05 B Category: Release: Rel-12 Use one of the following categories: F (correction) A (mirror corresponding to a change in an earlier release) B (addition of feature), C (functional modification of feature) D (editorial modification) Detailed explanations of the above categories can be found in 3GPP TR 21.900. Use one of the following releases: Rel-4 (Release 4) Rel-5 (Release 5) Rel-6 (Release 6) Rel-7 (Release 7) Rel-8 (Release 8) Rel-9 (Release 9) Rel-10 (Release 10) Rel-11 (Release 11) Rel-12 (Release 12) Rel-13 (Release 13) Reason for change: According to agreed authenticaiton mechniasm, the authenticaiton requirements for different interfaces are required. Summary of change: Requirements are defined based on corresponding text in the TR. Add a security requirement to section X.2.2, X.3.2, and X.4.2 to clarifiy the authentication requirement for interfaces including W1, W2, and W4. Consequences if not approved: It lacks the authentication requiremens of WebRTC access to IMS in Rel-12. Clauses affected: Other specs affected: (show related CRs) Other comments: Y N X Other core specifications X Test specifications X O&M Specifications TS/TR ... CR ... TS/TR ... CR ... TS/TR ... CR ... X.2 Authentication of WebRTC IMS Client with IMS subscription re-using existing IMS authentication mechanisms X.2.2 Requirements - REQ x: For the reference interface W1 (WIC to WWSF), one way authentication (WIC needs to authenticate WWSF) is needed. For the interface W2 (WIC to eP-CSCF), the mutual authentication is required. Editor’s note: Include the requirements pertaining to this scenario here, cf. clause 5 of TR 33.871. X.3 Authentication of WebRTC IMS Client with IMS subscription using web credentials X.3.2 Requirements - REQ y: For the reference interfaces W1 (WIC to WWSF), W2 (WIC to eP-CSCF), and W4, if present, (WWSF to WAF), the mutual authentication is required. Editor’s note: Include the requirements pertaining to this scenario here, cf. clause 5 of TR 33.871. Assignment of IMS identities to WebRTC IMS Client from pool of IMS subscriptions held by WWSF X.4.2 Requirements - REQz: For the reference interfaces W2 (WIC to eP-CSCF), and W4, if present, (WWSF to WAF), the mutual authentication is required. And as for the W1, mutual authentication is needed, except for the anonymous usecase. In the anonymous usercase, one way authentication (WIC needs to authenticate WWSF) is needed. Editor’s note: Include the requirements pertaining to this scenario here, cf. clause 5 of TR 33.871.