ITU-T X.805 - Security Architecture for End-to-End Communications
X.805 Security Dimensions 4-5 - Confidentiality + Communication Security

ITU-T X.805 - Security Architecture for End-to-End Communications X805-Dim4-5-Data-Confidentiality-Communication-Security-Encryption-Information-Flow-Protection: ITU-T X.805 Security Dimensions 4-5 - Data Confidentiality + Communication Security + Encryption At-Rest + In-Transit + In-Use + Information Flow Protection + Steered Communication + Anti-Tap + Anti-Eavesdrop + Post-Quantum Cryptography

Security Dimensions 4 and 5 per X.805 Clauses 6.4 and 6.5 are closely related: (1) Data Confidentiality (Dim 4) protects data from unauthorized disclosure - ensures that the data content cannot be understood by unauthorized entities. Encryption + Access Control + File Permissions + Communication Path Protection all contribute. (2) Communication Security (Dim 5) ensures that information flows ONLY between the authorized endpoints (the information is not diverted or intercepted while flowing between these endpoints) - protects the information path itself + including against masquerade of endpoints. The two Dimensions together cover all aspects of information secrecy from data-at-rest through communication-in-transit. (1) Encryption Categories: (a) Symmetric Encryption (block + stream) - AES-128/192/256 + ChaCha20 + 3DES (legacy + deprecated for new); (b) Asymmetric Encryption (RSA-2048/3072/4096 + ECDH + ECIES + X25519); (c) Hybrid Encryption (TLS + IPSec combine asymmetric for key exchange + symmetric for data); (d) Homomorphic Encryption (FHE + PHE - emerging for cloud computation on encrypted data); (e) Format-Preserving Encryption (FPE - retains format for PCI cardholder data); (f) Searchable Symmetric Encryption (SSE); (g) Post-Quantum Cryptography (PQC) - CRYSTALS-Kyber + Falcon + Dilithium + SPHINCS+ + Classic McEliece + BIKE + HQC + FrodoKEM per NIST PQC standardisation. (2) Encryption At-Rest: (a) Full Disk Encryption (FDE) - BitLocker + LUKS + Apple FileVault + AWS EBS + Azure Disk; (b) Database TDE Transparent Data Encryption (Oracle + MS SQL + MySQL + PostgreSQL); (c) Application-Level encryption + envelope encryption + field-level encryption; (d) Cloud KMS (AWS KMS + Azure Key Vault + Google Cloud KMS + HashiCorp Vault); (e) Customer-Managed Keys (CMK/CMEK) + Bring-Your-Own-Key (BYOK) + Hold-Your-Own-Key (HYOK); (f) Tokenization + Pseudonymization. (3) Encryption In-Transit: (a) TLS 1.3 + 1.2 (deprecated TLS 1.0/1.1 + SSL all versions); (b) IPSec ESP/AH + IKEv2; (c) SSH + SFTP; (d) VPN (IPSec + WireGuard + OpenVPN + SSL VPN); (e) MACsec IEEE 802.1AE Layer 2 link encryption; (f) WPA3 + WPA2-Enterprise wireless; (g) DTLS for UDP + QUIC TLS 1.3; (h) SRTP for voice/video. (4) Encryption In-Use: (a) Trusted Execution Environments (TEE) - Intel SGX + AMD SEV + ARM TrustZone + Apple Secure Enclave + Microsoft Pluton; (b) Confidential Computing per CCF Confidential Computing Consortium; (c) FHE Fully Homomorphic Encryption (Microsoft SEAL + IBM HElib + Google FHE); (d) Secure Multi-Party Computation (MPC). (5) Communication Security Mechanisms: (a) End-to-End Encryption (E2EE) - Signal Protocol + Double Ratchet + MLS RFC 9420; (b) Onion Routing + Tor; (c) Mix Networks; (d) Steered Communications + traffic flow analysis prevention; (e) Tunnelling (GRE + VXLAN + L2TP + L2F); (f) Lawful Interception capabilities + LEMF Law Enforcement Monitoring Facility + ETSI TS 103 280 + 3GPP TS 33.108. (6) Key Management: (a) Key generation + storage + rotation + distribution + destruction lifecycle; (b) HSM Hardware Security Modules - FIPS 140-3 Level 3/4; (c) Cloud KMS; (d) PKI Certificate Authorities; (e) Key Escrow + Key Recovery; (f) Quantum Key Distribution (QKD) emerging. (7) Confidentiality + Communication Security per X.805 Layers: (a) Infrastructure - link encryption + MACsec + IPSec + wireline + wireless; (b) Services - service-layer encryption + IMS encryption + Diameter TLS + Gx/S5/Gy interfaces; (c) Applications - application-layer encryption + email PGP/S/MIME + web TLS + DB encryption. (8) Confidentiality + Communication Security per X.805 Planes: (a) Management - encrypted management traffic SNMPv3 + NETCONF over SSH + RESTCONF over HTTPS + signed config; (b) Control - encrypted signalling Diameter TLS + SIP TLS + GTP-U IPSec; (c) End-User - subscriber traffic encryption + WebRTC SRTP + WhatsApp/Signal E2EE. (9) Threats Mitigated per X.805 Table 1: (a) Confidentiality - Removal (Y) + Disclosure (Y); (b) Communication Security - Removal (Y) + Disclosure (Y). (10) Standards: (a) ISO/IEC 27001 A.10 / A.8 (2022) Cryptography; (b) ISO/IEC 18033 Encryption algorithms; (c) ISO/IEC 19772 Authenticated encryption; (d) NIST SP 800-57 Key Management + SP 800-175A/B Cryptography Guidance + SP 800-38 Block Cipher Modes + SP 800-67 3DES Deprecation + SP 800-71 Quantum-Resistant Crypto + SP 800-208 Stateful Hash-Based Signatures + FIPS 140-3 + FIPS 186 + FIPS 197 AES + FIPS 198 HMAC + FIPS 202 SHA-3 + FIPS 203 ML-KEM + FIPS 204 ML-DSA + FIPS 205 SLH-DSA; (e) ETSI TS 119 312 Cryptographic Suites; (f) IETF RFCs 8446 TLS 1.3 + 4301 IPSec + 4253 SSH + 4880 OpenPGP + 5246 TLS 1.2 + 9420 MLS; (g) 3GPP TS 33.401/33.501 LTE/5G Encryption; (h) PCI DSS Req 3 + 4 + PA-DSS; (i) HIPAA Security Rule Encryption. (11) PQC Migration Roadmap: (a) NIST PQC Standardisation (final draft Aug 2023 + standards 2024); (b) Crypto-Agility - ability to swap algorithms; (c) Hybrid TLS 1.3 + Kyber for key exchange; (d) Hybrid Signature for non-repudiation; (e) Migration deadline - many organisations targeting 2030-2035; (f) Inventory of cryptographic dependencies (PQC readiness assessments); (g) Q-Day uncertainty + Harvest Now Decrypt Later threat. Coordinates with X.805 Layer 1/2/3 + Plane 1/2/3 + Threats Removal/Disclosure + Security Dimension 1 Access Control + Security Dimension 8 Privacy + ITU-T X.814 Confidentiality Framework + X.815 Integrity Framework + ITU-T Y.3517 + ISO/IEC 27001 + 27002 + 27017 + 27018 + 27033 + 27040 + NIST SP 800-57 + 800-175 + 800-38 + 800-208 + FIPS 140-3 + 186 + 197 + 202 + 203 + 204 + 205 + IETF TLS 1.3 + IPSec + SSH + MLS + 3GPP 5G AKA + PCI DSS + HIPAA + eIDAS + CCC Confidential Computing Consortium. ITU-T X.805 Security Dimensions 4 + 5 Data Confidentiality + Communication Security apply.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.