Committed to connecting the world

WTISD

Sep23-summary

​​​​

Executive Summary

Meeting of ITU-T SG17 'Security', Goyang, 29 August – 8 September 2023

Hot topics of this meeting (summarizing its input & output)

  • Software supply chain security
  • Cybersecurity – Threat intelligence, Zero Trust
  • AI security
  • IoT security
  • 5G security
  • Cloud security
  • Quantum based security

1        Meeting Output (meeting statistics see Annex E below)

  • Output standards (28, see Annex A):
    • TAP approval (4): Details are in Annex A a).
    • TAP not approved (3): Details are in Annex A b).
    • TAP determined (8): 6 new and 1 revised Recommendations, and 1 Amendments. Details are in Annex A c).
    • AAP consented (10): 5 new and 4 revised Recommendations, and 1 Corrigendum for AAP Last Call. Details are in Annex A d).
    • Agreed (6): 1 new Supplement and 5 new Technical Report. Details are in Annex A e).
  • New work items (28, see Annex C).
  • Work item discontinued (1, see Annex D).
  • ITU Workshop on “Zero trust and software supply chain security" was held successfully on 28 August 2023
  • SG17 subgroups
    • JCAs:
      • JCA-IdM: continued with revised ToR, and held its 32nd meeting on Friday 1 Sep 2023
      • JCA-COP: remain dormant​
    • Correspondence Groups
      • CG-SG17-wtsa24-prep: continued
      • CG-secapa (Correspondence Group on Security Capability and Architecture): continued with revised ToR

2        Next SG17 meetings

2.1       a virtual SG17 interim security coordination meeting (date to be decided, before 1st SG17 meeting in 2024)

2.2       5th SG17 meeting: South Africa, Geneva Tuesday 20 February – Friday 1 March 2024 (dates to be confirmed by South Africa host) (9 working days, physical meeting with remote participation)

  • ITU workshop on “security and privacy for generative AI “, Monday 19 Feb 2024, 09:30-17:30
  • Open and extended management team meeting on Monday 19 Feb 2024, 19:00-21:00.
  • 33rd JCA-IdM meeting on Friday 23 Feb 2024, 14:30-16:00
  • 25 Candidate texts for action, details see Annex B.

2.3       6th SG17 meeting: July Aug/Sep 2024, Geneva (dates and venue to be confirmed)

2.4       Interim RGMs

7 Questions plan to hold the following 10 RGMs before next SG17 meeting:

#
QDatePlace/HostSubject/objective
1.                 2/1715-16 November 2023MyWorkspace
  • prepare texts for action in next SG17 meeting: X.5Gsec-netec, X.5Gsec-srocvs, TR.5Gsec-bsf and TR.zt-acp.
  • review all work items and identify future topics for Q2/17
2.                 3/17

14 Nov

10:00-12:00 (CET)

 

MyWorkspace
  • Sup-cdc, X.gsm-cdc
3.                 3/17

29 Nov

11:00-13:00 (CET)

MyWorkspace
  • X.1053-rev, X.shcd
4.                 4/17tbcMyWorkspace
  • To work on X.stie and X.taeii texts (TD1262, TD1261) determined in this SG17 meeting, consider Russian Federation's written statements addressed to SG17 chairman for inclusion in SG17 meeting reports.
5.                 10/1729 -30 November 2023Paris, France/SIA
  • progress all the work of Q10/17
6.                 11/1711-15 Dec 2023Nanning (China)
  • Generic technologies (such as Directory, PKI, formal languages, object identifiers) to support secure applications.
7.                 13/1723-24 November 2023Seoul / Korea (Republic of) (with remote participation)
  • Prepare the final texts for X.itssec-5 and X.evtol-sec
  • Address all work items and future topics.
8.                 15/17

22-24 November (tentative)

 

Tokyo (Japan) / NICT & Toshiba (with remote participation)
  • Only QKD related Wis
9.                 15/1723 Oct 2023 (tentative)MyWorkspace
  • Comments resolution for X.sec_QKDN_tn
10.              15/1720 Dec 2023MyWorkspace
  • Wis in the incubation queue


Annex A
Actions taken on Recommendations, and other texts at SG17 closing plenary on 8 September 2023

a)    TAP Recommendations approved (WTSA-20 Resolution 1)

#QAcronymTitleNew / RevisedEditor(s)Location of textA.5 or A.25 justificationEquivalent
e.g., ISO/IEC
1.       2/17X.1817
(X.5Gsec-message)
Security requirements for 5G message serviceNewHang DONG, Le YU, Hongyang ZHANGTD1381TD934-
2.       6/17X.1333 Cor. 1Corrigendum 1 to X.1333: Security guidelines for use of remote access tools in Internet-connected control systemsCor.Gunhee LEER34--
3.       7/17X.1454 (X.sles)*
Security Measures for Location Enabled Smart Office ServicesNewHang DONG,
Feng GAO,
Jae Hoon NAH, Junjie XIA
TD985  
4.       8/17X.1645
(X.nssa-cc)
Requirements of network security situational awareness platform for cloud computingNewMaofei CHEN, Huamin JIN, Zhaoji LIN, Laifu WANG, Yi ZHANGTD1323--

Note: * TAP approval postponed from last SG17 meeting (Feb/Mar 2023).  

b) TAP Recommendations not approved (WTSA-20 Resolution 1)

#QAcronymTitleNew / RevisedEditor(s)Location of TextEquivalent
e.g., ISO/IEC
Start of workDeterminedDecision
1        6/17X.1353
(X.ztd-iot)*
Security methodology for zero-touch deployment in massive IoT based on blockchainNewXin KANG, Haiguang WANG, Weidong WANGR35 2020-09(2022-09 /) 2023-03
For further study before any SG17 decision
2        7/17X.1471
(X.websec-7)
Reference monitor for online analytics servicesNewJongyoul Park,
Junjie Xia,
Hyungjin Lim,
Jah Hoon Nah
R36 2014-092023-03For next SG17 meeting to consider re-determination
3        7/17X.1771
(X.rdda)
Requirements for data de-identification assuranceNewFeng Gao,
 I Seok Kang, Soonseok Kim,
Jihun Kim, Byunghoon Lee, Yunsik Park, Hyungjin Lim,
Heung Youl Youm
R37 2019-01         2023-03Agreed as X.Sup39 (see Table e) #3 below)

Note: * TAP re-determined by last SG17 meeting (Feb/Mar 2023)​.

c) TAP Recommendations determined (WTSA-20 Resolution 1)

#QAcronymTitleNew / RevisedEditor(s)Location of TextA.5 or A.25 justificationEquivalent
e.g., ISO/IEC
1         2/17X.1818
(X.5Gsec-ctrl)
Security controls for operation and maintenance of IMT-2020 network systemsNewAyumu KUBOTA, Koji NAKAO, Yutaka MIYAKETD1379--
2         4/17X.1221
(X.stie)
Structured threat information expressionNewMichael ROSA, Duncan SPARRELLTD1262TD808OASIS STIX Version 2.1
3         4/17X.1222
(X.taeii)
Trusted automated exchange of intelligence informationNewMichael ROSA, Duncan SPARRELLTD1261TD808OASIS TAXII Version 2.1
4         6/17X.1352AmdAmendment to X.1352: Security requirements for Internet of things devices and gatewaysNewHeung Youl YoumTD1451  
5         7/17X.1150
(X.saf-dfs)
Security assurance framework for digital financial servicesNewJacques FRANCOEUR,
Jun Hyung PARK, Sungchae PARK, Heung Youl YOUM
TD1389--
6         10/17X.1280
(X.oob-sa)
Framework for out-of-band server authentication using mobile devicesNewIl Jin JUNG,
Sujung PARK, Heejun SHIN, Jonghyun WOO
TD1424--
7         10/17X.1281
(X.osia)
Open Standard Identity APIs (OSIA) specification version 6.1.0NewAbbie BarbirTD1238TD1298OSIA 6.1.0
8         13/17X.1373revSecure software update capability for intelligent transportation system communication devicesRevAram CHO,
Sang-Woo LEE,
Koji NAKAO, Seungwook PARK
TD1337--

d)    AAP Recommendations consented (Recommendation ITU-T A.8)

 Q/17AcronymTitleNew/RevEditor(s)TextA.5 or A.25 justificationEquivalent
e.g., ISO/IEC
1         4/17X.1220 (X.spmoh)Security framework for storage protection against malware attacks on hostsNewBongchan KIM,
Jonghyun KIM,
Sujung PARK,
Heejun SHIN,
Jonghyun WOO
TD1333- 
2         4/17X.1236
(X.sr-ctea)
Security requirements and countermeasures for targeted email attacksNewChunghan KIM,
Jonghyun KIM,
Sujung PARK
TD1330 --
3         7/17X.1282
(X.scpa)
Security measures for Countering Password Related Online AttacksNewHang DONG,
Feng GAO,
Jung Yeon HWANG, Lijun LIU,
Jae Hoon NAH,
Qin QIU
TD1353  
4         10/17X.1095
(X.pet-auth)
Entity authentication service for pet animals using telebiometricsNewJae-Sung (Jason) Kim, Taeheon KimTD1387--
5         11/17X.509 Cor. 2Information Technology – Open systems Interconnection – The Directory – Public-key and attribute certificate frameworks : Corrigendum 2    Cor.Erik AndersenTD1320-ISO/IEC 9594-8
6         11/17X.510revInformation technology – Open Systems Interconnection – The Directory: Protocol specifications for secure operationsRevErik AndersenTD1288-ISO/IEC 9594-11
7         11/17X.590 (X.jss)JSON Signature Scheme (JSS)NewBret Jordan,
Mark Mcfadden
TD1327TD1328 
8         11/17Z.161Methods for Testing and Specification (MTS); The Testing and Test Control Notation version 3; Part 1: TTCN-3 Core LanguageRevDieter HogrefeTD1269TD1270ETSI ES 201 873-1 V4.15.1 (2023-04)
9         11/17Z.166Methods for Testing and Specification (MTS); The Testing and Test Control Notation version 3; Part 6: TTCN-3 Control Interface (TCI)RevDieter HogrefeTD1269TD1270ETSI ES 201 873-6 V4.14.1 (2023-04)
10      11/17Z.171Methods for Testing and Specification (MTS); The Testing and Test Control Notation version 3; Part 11: Using JSON with TTCN-3RevDieter HogrefeTD1269TD1270ETSI ES 201 873-11 V4.10.1 (2023-04)

 

e)   Non-normative texts (Technical Report, Supplement, Implementers' Guide, etc) agreed


 #Q/17AcronymTitleNew / RevEditor(s)Text
 1
2/17TR.cpn-col-secTechnical Report: Security consideration of collaboration of multiple computing power networksNewXiongwei JIA,
Zhaoji LIN,
Keng LI,
Yuwei WANG
TD1342
 2
6/17TR.ba-iotTechnical Report: Broadcast authentication schemes for IoT system
NewKoji NAKAOTD1455
 3
7/17X.sup39
(ex X.rdda)
Supplement Recommendation ITU- T X.1148 - Requirements for data de-identification assuranceNewI Seok Kang,
Heung Youl Youm, Soonseok Kim,
Hyung Jin Lim
TD1456
 4
7/17TR.sgfdmTechnical Report: FHE-based data collaboration in machine learningNewJihoon Cho,
Jae Hoon Nah,
Donggeon Yhee
TD1425
 5
11/17TR.x509ac4scTechnical Report: A use case of X.509 Attribute Certificate for Supply ChainNewTakao KojimaTD1377
 6
14/17TR.qs-dltTechnical Report: Guidelines for quantum-safe DLT systemNewFuwen LIU,
Ke WANG,
Bo YANG, Heung Youl YOUM
TD1347


 

Annex B
Recommendations planned for action in 1st SG17 meeting in 2024

a)           TAP Recommendations planned for TAP approval (WTSA-20 Resolution 1) - see Annex A Table c)

#QAcronymTitleNew / RevisedEditor(s)Location of TextEquivalent
e.g., ISO/IEC
Timing
  1.  
7/17X.1471
(X.websec-7)
Reference monitor for online analytics services

NewHyungjin LIM, J
ae Hoon NAH, Jongyoul PARK, Junjie XIA
R36 ​​
2024-Q1
Note: This work item will need to be re-determined

b)           TAP Recommendations planned for TAP determination (WTSA-20 Resolution 1)

#Q(1)AcronymTitleNew / RevisedEditor(s)Location of TextEquivalent
e.g., ISO/IEC
Timing
1         2/17X.5Gsec-netecSecurity capabilities of network layer for 5G edge computingNewYifu WANG,
Chen ZHANG,
Bei ZHAO
TD1396 2024-Q1
2         2/17X.5Gsec-srocvsSecurity requirements for the operation of 5G core network to support vertical servicesNewFeng GAO,
Ming HE,
Guorong LIU,
Jun SHEN
TD1329 2024-Q1
3         4/17X.sgc_rcsGuidelines for countering spam over RCS messagingNewHuamin JIN,
Shuai WANG,
Haodi ZHANG, Yanbin ZHANG
TD1358 2024-Q1
4         4/17X.tsfppTechnical security framework for protection of users' personal information while countering mobile messaging spamNewFeng GAO,
Wei LIU, 
Junjie XIA,
Bo YU,
 Chen ZHANG, Yanbin ZHANG
TD1339 2024-Q1
5         6/17X.1353 (X.ztd-iot)*
Security methodology for zero-touch deployment in massive IoT based on blockchainNew Xin KANG, Haiguang WANG, Weidong WANGTD1338  2024-Q1
6         

6/17X.sc-iotSecurity Controls for Internet of Things (IoT) systemsNew

Koji Nakao,

Liu Lijun

TD1464 2024-Q1
7
​7/17
​X.1471
(X.websec-7)*
​Reference monitor for online analytics services
​New
​Hyungjin LIM, J
ae Hoon NAH, Jongyoul PARK, Junjie XIA
R36

​2024-Q1
8        10/17X.1250revBaseline capabilities for enhanced global identity management and interoperabilityRevAbbie BARBIRTD1410 2024-Q1
9         10/17X.gpwdThreat Analysis and guidelines for securing password and password-less authentication solutionsNewAbbie BARBIRTD1409 2024-Q1
10         13/17X.evtol-secSecurity guidelines for an electric vertical take-off and landing vehicle (eVTOL) in an urban air mobility environmentNewAram CHO,
Sang-Woo LEE, Seungwook PARK
TD1345 2024-Q1
11     13/17X.itssec-5Security guidelines for vehicular edge computingNewSang-Woo LeeTD1365 2024-Q1

Notes:

(1)     In case of joint Question activity, the lead Question is given without parentheses and other Questions are shown in parentheses; such entries are only shown in the table against the lead Question. 

 *    for TAP re-determination.

c)           AAP Recommendations planned for AAP consent (Recommendation ITU-T A.8)

#Q(1)AcronymTitleNew / RevisedEditor(s)Location of TextEquivalent
e.g., ISO/IEC
Timing
1         7/17X.1144revThe revision of eXtensible Access Control Markup Language (XACML) 3.0RevJae Hoon NAH,
Duncan Sparrell
TD1033 2024-Q1
2         7/17X.guide-cddSecurity guidelines for combining de-identified data using trusted third partyNewHeung Youl Youm, Sungchae Park,
Jae Nam Ko
TD1407 2024-Q1
3         7/17X.sg-dtnSecurity Guidelines for Digital Twin NetworkNewMeiling CHEN,
Jing SHAO,
Li SU,
Ke WANG
TD1362 2024-Q1
4         7/17X.smsrcSecurity Measures for Smart Residential CommunityNewFeng GAO,
Jae Hoon NAH, Junjie XIA,
Longjun ZHAO,
Feng ZHANG
TD1419 2024-Q1
5         11/17X.508
(X.pki-em)
Public-key infrastructure: Establishment and maintenanceNewErik AndersenTD1290ISO/IEC 9594-122024-Q1
6         15/17X.1715AmdAmendments to X.1715: Security requirements and measures for integration of quantum key distribution network and secure storage networkNewKaoru KENYOSHITD1434 2024-Q1
7         15/17X.sec_QKDN_AAAuthentication and authorization in QKDN using quantum safe cryptographyNewKaoru KENYOSHI, Kazunori TANIKAWATD1435 2024-Q1
8         15/17X.sec_QKDN_CMSecurity requirements and measures for quantum key distribution networks – control and managementNewTaesang CHOI, Hyungsoo KIM, Matthieu LEGRÉ, Kazunori TANIKAWA,
Chun Seok YOON
TD1436 2024-Q1
9         15/17X.sec-QKDN-tnSecurity requirements and designs for quantum key distribution networks – trusted nodeNewQiang Huang, Minghan Li,
Jiajun Ma,
Hao Qin
TD1438 2024-Q1

d)           Non-normative texts (Technical Report, Supplement, Implementers' Guide, etc) planned for agreement

#​​

Q/17AcronymTitleNew / RevisedEditor(s)Location of textEquivalent
e.g., ISO/IEC
Timing
​1
2/17TR.5Gsec-bsfTechnical Report: Guidelines of Built-in Security Framework for the Telecommunications NetworkNewXiaoting HUANG,
 Li SU,
Ke WANG
TD1475-2024-03
2​2/17TR.zt-acpTechnical Report: Guidelines for zero trust based access control platform in telecommunication networkNewJing HUANG,
Wei LIU,
Xu WANG,
Junzhi YAN,
Heung Youl YOUM
TD1472-2024-03
​3
7/17X.suppl.uc-dccSupplement to X.1152: Use cases for digital COVID-19 certificatesNewDaeun HYEON,
Sungchae PARK,
Heung Youl YOUM
TD1450-2024-03
4​15/17TP.inno-2.0Technical Paper: Description of the incubation mechanism and ways to improve itRevArnaud TADDEITD1458-2024-03


 

Annex C
New work items

The following new work items were agreed to be added to the SG17 Work Programme:

#Orig.
Q
Work itemTitleEditorTimingTDC
1.       Q1/17X.cs-raCyber Security Reference ArchitectureN. Kishor NARANG, Pushpendra Kumar SINGH,
Preetika SINGH
2025-Q4TD1401C330
2.       Q2/17X.5Gsec-asra*Guidelines and Technical Requirements for 5G Network Asset Security Risk AnalysisTian Tian,
Jing Wang,
Daoli Su,
Qin Qiu
2025-Q3TD1370 C419
3.       Q3/17X.1053revInformation security controls based on ITU-T X.1051 for small and medium-sized telecommunication organizations    Chang Oh,
Heung Youl Youm,
Thaib Mustafa
2025-09TD1433C392
4.       Q3/17X.gsm-cdcGuidelines on Security Metrics for CDCHiroshi Takechi2025-04TD1452 C400
5.       Q3/17X.shcd*Framework for Security Human Capability Development

Thaib Mustafa,

Lee Hwee Hsiung,

Norkhadhra Nawawi,
Khairul Ekhwan

2025-09TD1437 C426
6.       Q4/17X.sf-dtea*Security framework for detecting targeted email attacksHyunmin Shin,
Chunghan Kim,
Jonghyun Kim, Sujung Park
2025-09TD1334C387
7.       Q6/17X.sr-iiot*Security requirements for the industrial Internet of things based smart manufacturing reference modelJong-Hyouk Lee,
Taeyang Lee,
Jinsue Lee
2025-09TD1368C446
8.       Q7/17X.tg-fdma*Technical guidelines for fraud detection of malicious applications in mobile devices

Xiaoyuan BAI,

Jin PENG,

Weidong WANG,

Zhiyuan HU,

Wenbiao ZHAO

2025-3QTD1349C438
9.       Q7/17X.srgsdcs*Security requirements and guidelines of sensing and data collection system for city infrastructure

Junjie Xia,

Feng Gao,

Mengxiang Han,

Jae Hoon Nah

2025-3QTD1418C452
10.    Q7/17X.sgdfs-us*Security guidelines for DFS applications based on USSD and STKVincent Mwesigwa2024-3QTD1421C404
11.    Q8/17X.scr-cnaSecurity requirements of sandboxed container runtime for cloud native applicationsZeya Zhu,
Linze Wu,
Shiqi Li,
Ye Tao
2026-09TD1470C411
12.    Q8/17X.sgscSecurity guidelines for serverless computingShiqi Li,
Yong Feng,
Ye Tao,
Xiaoyuan Bai
2025-09TD1376C340
13.    Q8/17X.sg-tc*Security guidelines of trusted cloud servicesLu Chen,
Ye Tao,
Dongxin Liu
2025-09TD1411C424
14.    Q8/17X.srapi-cc*Security requirements of application programming interface (API) for cloud computingLaifu Wang,
Maofei Chen, Dongxin Liu 
2026-02TD1390C406
15.    Q8/17TR.fcnsc**Framework for cloud native based security collaboration mechanism among cloud service providersLinghao Zhang, Xuan Zha,
 Zhengwei Chang, Lin Chen
2026-06TD1403C472
16.    Q10/17X.sup-sat-dfs**Supplement to ITU-T X.1254: Implementation of secure authentication technologies for digital financial services

Heung Youl Youm,

Sungchae Park,

Junhyung Park

2024-9TD1394C365
17.    Q10/17X.sup-ekyc-dfs**Supplement to ITU-T X.1254: e-KYC use cases in digital financial services

Heung Youl Youm,

Sungchae Park,

Daeun Hyeon

2024-9TD1417 C364
18.    Q10/17X.afotak*Authentication framework based on One-Time Authentication Key using Distributed Ledger TechnologyHyungseung Ko,
Seung Ju Jeon,
Heung Youl Youm, 
Sungchae Park,
Hun Joo Chang
2025-9TD1463C349
19.    Q13/17X.af-sec*Evaluation methodologies for anonymization techniques using face images in autonomous vehiclesYousik Lee, 
Sang-Woo Lee, Jaehoon Nah 

2026-09

 

TD1351C394
20.    Q13/17X.fod-sec*Security guidelines for feature on demand (FoD) service in a connected vehicle environmentChanghun Jung, Jiyong Han,
Seungwook Park

2026-09

 

 

TD1341C378
21.    Q10/17 (,Q14/17)X.accsadlt*Access security authentication based on DLT

Thaib Mustafa,

Norkhadhra Nawawi,

Radhilufti Madehi,

Ariff Olan Kholid

2025-9TD1457C402
22.    Q14/17X.dlt-shareSecurity requirements for data application software based on DLT to achieve statisticsGaoshan Zhang, Qiuli Mei,
Hang Dong
2025-9TD1399C398
23.    Q14/17X.DLT-dgiSecurity requirements of DLT gateway for interoperabilityYoungjin Kim,
Jung Yeon Hwang, Xiongwei Jia
2025-9TD1367C348
24.    Q15/17X.1715AmdAmendment to X.1715: Security requirements and measures for integration of quantum key distribution network and secure storage networkKaoru Kenyoshi2024-Q1TD1434 
25.    Q15/17TR.kdc_qkdn**Key distribution center based approaches in the service layer to manage keys supplied by QKDNFuwen Liu2025-08TD1479C430
26.    Q15/17X.sr-ai*Security requirements for AI systems

Heung Youl Youm

 

2026-09TD1348C357
27.    Q15/17X.ssc-sra*Guidelines for Software Supply Chain Security AuditLizhu Su 2026-09TD1384C416
28.    Q15/17X.rm-sup*Risk management on the security of software supply-chain for telecommunication organizationsChen ZHANG 2026-09TD1400C448

 


Annex D
Work items discontinued

QuestionAcronymTitle
10/17
X.1251rev
Framework for user control of digital identity


 

Annex E
SG17 meeting Statistics

 participantscountriesMember StatesSector MembersSG17 AssociatesAcademiaInvited Experts
Announced4805246    
Final356433735466
  • Meeting input and organization

Table of SG17 statistics of this and some past meetings

 

2023-09

2023-03

2022-09

2022-05*

C

153

119

104

101

LS/i

60

70

55

72

LS/o

25

23

20

20

TD

415

394

342

331

Note * - fully virtual meeting

  • Contributions: 153 – record high, DDP: 98%.
    • APT 136 (89%) (= China 58.5 + Korea 53.5 + Japan 14 + India 7 + Singapore 1 + Malaysia 2)
    • Americas 12 (8%)) (= US 9 + Brazil 2 + Canada 1)
    • AFR 4 (South Africa 2 + Mali 1+ Uganda 1)
    • RCC 1 (= Russia 1)
    • EUR (0), LAM (0), ARAB (0). 
  • LS: matrix in TD1100
  • incoming 60 - stable
  • Outgoing 25 - stable
  • TDs: 415 –higher than normal​