Committed to connecting the world

WTISD

Executive Summary, March 2023

​​​​​​ ​Executive Summary

Meeting of ITU-T SG17 'Security', Geneva, 21 February – 3 March 2023

Hot topics ​

1.  ​Meeting outputs (meeting statistics see Annex E below)

2.  ​​Next SG17 meetings 

3.  ​​Interim RGMS 

7 Questions plan to hold the following 9 RGMs before next SG17 meeting:

#
Q/17 Date Place/Host Subject/objective

1

2/17

18-19 May 2023

​Seoul, Korea
​(Hosted by SCH University)

 

  • ​​To prepare texts for action in next SG17 meeting: X.5Gsec-ctrl and TR.cpn-col-sec.
  • To review all work items and identify future topics for Q2/17

 

2
3/17
13 April 2023

e-meeting
  • ​X.1​051rev2

3
3/1713 -14 June 2023e-meeting

X.sup-cdc (Clause 7: Context: CDC in the bigger context of operational security)


4
4/1729 June 2023e-meeting
  • To address and discuss X.stie and X.taeii
5
10/176 June 2023e-meeting
  • progress all the work of Q10/17
6
11/17 ​20 - 24 March 2023

 

Wien, Austria
  • Generic technologies (such as Directory, PKI, formal languages, object identifiers) to support secure applications.
7
13/17
14 - 15 June 2023
e-meeting
  • prepare the final texts for X.itssec-5, X.1373rev
  • address all work items and future topics.
8
15/1730 May - 1 June 2023
Singapore
(Hosted by IMDA/NUS)
  • QKD related WIs
9  15/177 June 2023e-meeting
  • X.icd-schemas


Annex A

Actions taken on Recommendations, and other texts at SG17 closing plenary on 3 March 2023

a)    TAP Recommendations approved (WTSA-20 Resolution 1)

# Q Acronym Title New / Revised Editor(s​) Location of text Equivalent
e.g., ISO/IEC
Start of work Timing
1.       
2/17X.1815 (X.5Gsec-ecs)Security guidelines and requirements for IMT-2020 edge computing servicesNewFeng GAO, Jae Hoon NAH, Junjie XIA, Bo YU, Xiaojun ZHUANG TD1015 2019-012022-09
2.       2/17X.1816 (X.5Gsec-ssl)Guidelines and requirements for classifying security capabilities in IMT-2020 network sliceNewZhiyuan HU, Li SU, Ke WANG, Bo YANG TD915 2020-092022-09
3.       8/17,
(14/17)
X.1411 (X.BaaS-sec)Guidelines on blockchain as a service (BaaS) securityNewNan MENG, Kyeong Hee OH, Zixiang WANG, Xuan ZHA R20  2019-092022-09
4.       8/17X.1644 (X.sgdc)Security guidelines for distributed cloudNewMark MCFADDEN, Ye TAO, Lei XU, Laifu WANG R2 2019-012022-09
5.       13/17X.1380 (X.edr-sec)Security guidelines for cloud-based data recorders in automotive environmentsNewSang-Woo LEE,
Seungwook PARK
R22 2018-032022-09
6.       13/17X.1381 (X.eivn-sec)Security guidelines for Ethernet-based In-Vehicle networksNewSang-Woo LEE, You-Sik LEE TD917 2018-092022-09
7.       13/17X.1382 (X.fstiscv)Guidelines for sharing security threat information on connected vehiclesNewMin SHU, Wenlei WANG,
Xiaochun YUN, Yunwei ZHAO
TD918 2018-092022-09
8.       13/17X.1383 (X.srcd)Security requirements for categorized data in vehicle-to-everything (V2X) communicationNewTakamasa ISOHARA, Nan MENG, Yaping SUN, Huirong TIAN TD919 2018-092022-09
9.       14/17X.1410 (X.sa-dsm)Security architecture for data-sharing management based on the distributed ledger technologyNewFeng GAO,
Zhiyuan HU,
Min SHU,
Yunwei ZHAO
TD900 2020-092022-09

b)   TAP Recommendations not approved (WTSA-20 Resolution 1)

#QAcronymTitleNew / RevisedEditor(s)Location of TextEquivalent
e.g., ISO/IEC
Start of workDetermined Decision
1        6/17X.1353
(X.ztd-iot)
Security methodology for zero-touch deployment in massive IoT based on blockchainNew
Xin KANG, Haiguang WANG, Weidong WANGR18 
2020-092022-09Re-determined (see Table c) #3 below)
2        7/17X.1454 (X.sles)Security measures for location enabled smart office service NewHao Dong,
Feng Gao,
Jae Hoon Nah, Junjie Xia
R19 2019-092022-09Postponed to next SG17 meeting

​​c) TAP Recommendations determined (WTSA-20 Resolution 1)

# Q Acronym Title New / Revised Editor(s) Location of Text Equivalent
e.g., ISO/IEC
Start of work Timing
1         2/17X.1817
(X.5Gsec-message)
Security requirements for 5G message serviceNewHang DONG,
Le YU,
Hongyang ZHANG

TD939

(A.5 in TD934)

 2021-042023-03
2         6/17X.1333 Cor. 1Corrigendum 1 to X.1333: Security guidelines for use of remote access tools in Internet-connected control systemsNewGunhee Lee
TD958 2023-022023-03
3         6/17X.1353
(X.ztd-iot)
Security methodology for zero-touch deployment in massive IoT based on blockchainNewXin KANG, Haiguang WANG,
Weidong WANG
TD937 2020-092022-09
4         7/17X.1471
(X.websec-7)
Reference monitor for online analytics servicesNewJongyoul Park,
Junjie Xia,
Hyungjin Lim,
Jah Hoon Nah
TD936 2014-092023-03
5         7/17X.1771
(X.rdda)
Requirements for data de-identification assuranceNewFeng Gao,
 I Seok Kang, Soonseok Kim,
Jihun Kim, Byunghoon Lee, Yunsik Park, Hyungjin Lim,
Heung Youl Youm
TD1012 2019-01 2023-03
6         8/17X.1645
(X.nssa-cc)
Requirements of network security situational awareness platform for cloud computingNewMaofei CHEN, Huamin JIN,
Zhaoji LIN,
Laifu WANG,
Yi ZHANG
TD965 2019-092023-03

d)    AAP Recommendations consented (Recommendation ITU-T A.8)

# Q(1) Acronym Title New / Revised Editor(s) Location of Text Equivalent
e.g., ISO/IEC
Start of work Timing
1         4/17X.1219
(ex X.arc-ev)
Functional requirements for a secured process to evaluate technical vulnerabilitiesNew

Wei Li,
Shan Xue,
Chen Zhang

TD930  2019-082023-03
2         10/17X.1278.2 (X.ctap21)Client to authenticator protocol version 2.1NewAbbie Barbir TD886 (A.5 in TD887)FIDO CTAP2.12022-052023-03
3         10/17X.1277.2 (X.uaf12)Universal authentication framework version 1.2NewAbbie Barbir TD888 (A.5 in TD889)FIDO UAF1.22022-052023-03
4         14/17X.1412
(X.srscm-dlt)
Security Requirements for Smart Contract Management based on the distributed ledger technologyNewKepeng Li,
Kyeong Hee Oh, Dong Bin Choi, Yang Wu, Min Shu
TD920 2020-092023-02

e)   Non-normative texts (Technical Report, Supplement, Implementers' Guide, etc) agreed

#​ Q Acronym Title New / Revised Editor(s) Location of text Equivalent
e.g., ISO/IEC
Start of work Timing
  1.  
6/17TR.ibc-cdGuidelines for identity based cryptosystems used for cross-domain secure communicationsNewFuwen Liu,
Li Su,
Junzhi Yan,
Bo Yang
TD956 2021-042023-03

Annex B

Recommendations planned for action in SG17 Aug/Sep 2023 meeting

a)       TAP Recommendations planned for TAP approval (WTSA-20 Resolution 1)

# Q Acronym Title New / Revised Editor(s) Location of Text Equivalent
e.g., ISO/IEC
Start of work Timing
  1.  
7/17X.1454 (X.sles)*Security measures for location enabled smart office servicesNewJunjie Xia,
Feng Gao,
Jae Hoon Nah,
Hang Dong
TD985 2019-092022-09

b)       TAP Recommendations planned for TAP determination (WTSA-20 Resolution 1)

# Q(1) Acronym Title New / Revised Editor(s) Location of Text Equivalent
e.g., ISO/IEC
Start of work Timing
1         2/17X.5Gsec-ctrl*Security controls for operation and maintenance of 5G network systemsNewAyumu KUBOTA, Koji NAKAO, Yutaka MIYAKE TD1016  2022-09
 2023-09
2         4/17X.spmoh*Security framework for storage protection against malware attacks on hosts
New

Jonghyun Woo,
Bongchan Kim
Heejun Shin
Jonghyun Kim
Sujung Park

TD929  2022-05
2023-09
3         4/17X.sr-ctea*Security requirements and countermeasures for targeted email attacksNew

Chunghan Kim
Jonghyun Kim
Sujung Park

TD924  2022-05
2023-09
4         4/17X.stie*Structured Threat Information ExpressionNewMichael ROSA, Duncan SPARRELL TD972OASIS STIX Version 2.12022-092023-09
5         4/17X.taeii*Trusted Automated Exchange of Intelligence InformaNewMichael ROSA, Duncan​​ SPARRELL
TD971OASIS TAXII Version 2.12022-092023-09
6         6/17X.sc-iot*Security Controls for Internet of Things (IoT) systemsNew

Koji Nakao,
Liu Lijun

TD1032 2018-092023-09
7         10/17X.oob-sa*Framework for out-of-band server authentication using mobile devicesNewIl Jin JUNG,
Sujung PARK, Heejun SHIN, Jonghyun WOO
TD1044  2022-01
 2023-09
8         13/17X.itssec-5*Security guidelines for vehicular edge computingNewSang-Woo Lee TD981 2017-092023-09
9         13/17X.1373rev*Secure softwa​re update capability for intelligent transportation system communication devicesRevisedKoji Nakao,
Sang-Woo Lee,
Aram Cho,
Seungwook Park
TD997 2018-082023-09

Notes:
(1)     In case of joint Question activity, the lead Question is given without parentheses and other Questions are shown in parentheses; such entries are only shown in the table against the lead Question.

c)       AAP Recommendations planned for AAP consent (Recommendation ITU-T A.8)

# Q(1) Acronym Title New / Revised Editor(s) Location of Text Equivalent
e.g., ISO/IEC
Start of work Timing
1         7/17X.1144revThe revision of eXtensible Access Control Markup Language (XACML) 3.0RevJae Hoon NAH,
Duncan Sparrell
TD1033 2020-032023-09
2         7/17X.guide-cddSecurity guidelines for combining de-identified data using trusted third partyNewHeung Youl Youm, Sungchae Park,
Jae Nam Ko
TD978 2021-042023-09
3         7/17X.saf-dfsSecurity assurance framework for digital financial servicesNewJacques Francoeur, Jun Hyung Park, Sungchae Park, Heung Youl Youm TD966 2021-082023-09
4         7/17X.scpaSecurity measures for Countering Password Related Online AttacksNewHang Dong,
Qin Qiu, Lijun Liu,
Jung Yeon Hwang,
Feng Gao,
Jae Hoon Nah
TD1056 2019-082023-09
5         10/17X.pet-authEntity authentication service for pet animals using telebiometricsNewJae-Sung (Jason) Kim, Taeheon Kim TD944 2020-032023-09
6         10/17X.osiaOpen Standard Identity APIs (OSIA) specification version 6.1.0NewAbbie Barbir TD703 2023-032023-09
7         11/17X.508
(X.pki-em)
Public-key infrastructure: Establishment and maintenanceNewErik Andersen TD955ISO/IEC 9594-122012-082023-09
8         11/17X.510 Amd.1

Information technology – Open Systems Interconnection –

The Directory: Protocol specifications for secure operations

NewErik Andersen TD954ISO/IEC 9594-112020-082023-09
9         15/17X.sec-QKDN-tnSecurity requirements and designs for quantum key distribution networks - trusted nodeNewQiang Huang, Minghan Li,
Jiajun Ma, Hao Qin
TD1021 2019-082023-09

 d)      Non-normative texts (Technical Report, Supplement, Implementers' Guide, etc) planned for agreement

# Q Acronym Title New / Revised Editor(s) Location of text Start of work Timing
1.       2/17TR.cpn-col-secTechnical Report: Security consideration of collaboration of multiple computing power networksNew

Xiongwei Jia,
Zhaoji Lin,
Keng Li,
Yuwei Wang

TD9602022-052023-09
2.       6/17TR.ba-iotTechnical Report: Broadcast authentication schemes for IoT systemNewKoji Nakao TD9772022-052023-09
3.       7/17TR.sgfdmTechnical Report: FHE-based data collaboration in machine learningNewJihoon Cho, Jae Hoon Nah, Donggeon Yhee TD10352020-032023-09
4.       14/17TR.qs-dltTechnical Report: Guidelines for quantum-safe DLT systemNew

Fuwen Liu,

Ke Wang,

Bo Yang,

Heung Youl Youm

TD9382020-092023-09
5.       15/17TP.inno-2.0Technical Paper: Description of the incubation mechanism and ways to improve itRevArnaud Taddei TD9912023.022023-09

Annex C

New work items

The following new work items were agreed to be added to the SG17 Work Programme:

# Question NWI Approval TD Title C
1.       1/17TR.SUSSrevAgreement TD1040Successful use of security standards 
2.       4/17TR.verm*Agreement TD1002Technical Report: Framework for Verification of Messages C210
3.       4/17X.st-ssc*TAP TD980Security threats of software supply chain C239
4.       6/17X.mt-integrity*TAP TD983 Security guidelines for mobile terminal integrity protection C273
5.       6/17X.mt-feature*TAP TD984Security features to assess mobile terminal security C226
6.       6/17X.suppl.tig-iotsec**Agreement TD950Supplement to X.1352 (X.suppl.tig-iotsec) “Technical Implementation guidelines for IoT devices and gateway" C240
7.       7/17X.srgsc*TAP TD942Security Requirements and guidelines of application and service for smart city platform C280
8.       8/17X.asm-cc*TAP TD988 Requirements of Attack Surface Management for cloud computing C287
9.       8/17X.sfrms*TAP TD996Security framework and requirements of microservice for cloud computing using container technology C274
10.    10/17X.bvmAAP TD1014Requirements for biometric variability management C253
11.    10/17X.osiaAAP TD1036Open Standards Identity APIs (OSIA) version 6.1.0 TD703
12.    11/17X.jssAAP TD925JSON Signature Scheme (JSS) C217
13.    11/17X.509 Cor.2
AAP TD949​​
Technical Corrigendum to X.509: LDAP schema for attribute certificates TD874
14.    13/17X.ota-secAAP TD1010Implementation and evaluation of security functions to support over-the-air (OTA) update capability in connected vehicles C250
15.    14/17X.DLT-ccs-frAAP TD962Security requirements and framework of cross-chain service for DLT systems C277
16.    15/17TR.hyb-qsafe**Agreement TD1020Technical Report: Overview of key management of hybrid approaches for quantum-safe communications C256
17.    15/17X.sec_ QKD_profrAAP TD1019 Framework of quantum key distribution (QKD) protocols in QKD network C269, ​​C321​
18.    15/17TP.inno-2.0**Agreement TD991Technical Paper:  Description of the incubation mechanism and ways to improve it C216
19.    15/17X.dtnsAAP TD995Guidelines of using digital twin of network for network security C303
20.    15/17X.gcspcc*TAP TD964Guidelines of developing of cybersecurity simulation platform based on cloud computing C314
21.    15/17X.SecaaSAAP TD970 Security threats to be identified in the domain of security as a service C299
22.    15/17X.so-sapAAP TD941Guidelines for security orchestration of service access process C302
23.    15/17TR.srsec**Agreement TD1007Technical Report: Security aspects of segment routing IPv6 for the convergence of computing and network for telecommunication operators C286

Annex D

Discontinued work items​​

Question Acronym Title
8/17X.sr-cphrSecurity requirements for cloud-based platform to support low latency and high reliability application scenarios

Annex E

SG17 meeting statistics

·       Participants (TD677R1)

  participants countries Member States Sector Members SG17 Associates Academia Invited Experts
Announced3325848 
   
Final 325 54 48  30  2  4  13

·       Meeting input and organization

Table of SG17 statistics of this and some past meetings

 

2023-03

2022-09

2022-05*

C

119

104

101

LS/i

70

55

72

LS/o

23

20

20

TD

394

342

331

Note * - fully virtual meeting

·       Contributions: 119 – steady increasing, DDP: 98%.

    • APT 100.5 (84%) (= China 46.5 + Korea 39 + Japan 10 + India 3 + Singapore 1 + Malaysia 1)
    • Americas 14 (12%)) (= US 4)
    • AFR 2 (Mali, Ghana)
    • EUR 1.5 (= UK 1.5)
    • RCC 1 (= Russia 1)
    • LAM (0), ARAB (0). 

·       LS: matrix in TD699

  • incoming 61 - stable
  • Outgoing 24 - stable

·       TDs: 394​ – higher than normal