Security Layer 2 Services per X.805 Clause 7.2: The Services Security Layer is concerned with security of network services that service providers offer to their customers - encompasses the protection of the basic network connectivity services + supplementary value-added services. (1) Services Layer Components: (a) Basic Connectivity Services - dedicated line + dial-up + DSL + cable broadband + FTTH; Frame Relay + ATM + MPLS; IP VPN + Layer 2 VPN + Layer 3 VPN + SD-WAN; (b) Mobile Services - 2G GSM + 3G UMTS + 4G LTE + 5G NSA/SA + Voice over LTE (VoLTE) + SMS + Mobile data; (c) Voice Services - PSTN + ISDN + SIP Trunking + Hosted PBX + Voice over IP (VoIP) + WebRTC; (d) Quality of Service (QoS) services + tiered service level; (e) Value-Added Services - Toll-Free (800/888) + Calling Card + International Direct Dial + Premium Rate; (f) Messaging Services - SMS + MMS + RCS + IM + Email + Push Notifications; (g) Network Services - DNS + DHCP + NTP + LDAP + AAA RADIUS/Diameter + IMS; (h) Cloud Network Services - VPC + Transit Gateway + Cloud Interconnect + Direct Connect + ExpressRoute; (i) Content Services - CDN + IPTV + OTT video + streaming; (j) Emergency Services - E911 + 112 + IMS-based ELS Emergency Location Service. (2) Services Layer Security Per Dimension: (a) Access Control - Service authorization + AAA + subscriber provisioning + service-specific access policy; (b) Authentication - subscriber authentication + SIM AKA + EAP-SIM/AKA + 5G AKA + AAA RADIUS/Diameter + IMS Authentication SIP Digest + Trusted Mobile Subscriber Identity; (c) Non-Repudiation - CDR Call Detail Records + signed transactions + AAA accounting records; (d) Data Confidentiality - service-level encryption + L2/L3 VPN encryption + SRTP for voice + WhatsApp/Signal E2EE; (e) Communication Security - dedicated VPN + virtual private networks + IMS path security + GTP-U tunnel security; (f) Data Integrity - service data integrity + signed control messages + Diameter signature; (g) Availability - service redundancy + 99.999% + 5G URLLC + emergency service priority; (h) Privacy - subscriber identifier protection + 5G SUPI/SUCI concealment + call detail privacy + subscriber lookup minimisation. (3) Telecom Services-Specific Security: (a) IMS Security - per 3GPP TS 33.203 + AKA Authentication + Authorization for IMS access + SIP Digest authentication + TLS for SIP signalling + IPSec for IMS access; (b) 5G Security per 3GPP TS 33.501 - 5G AKA + EAP-AKA + SUPI/SUCI concealment + Network Function (NF) authentication + Service-Based Architecture (SBA) security + NRF authorization + N32 inter-PLMN security via SEPP Security Edge Protection Proxy + PRINS + TLS + IPSec; (c) VoLTE Security per 3GPP TS 33.328 - IMS Media Plane + DTLS-SRTP + KMS Key Management Service; (d) 5G NSA Roaming Security - DRA Diameter Routing Agent + DEA Diameter Edge Agent + Diameter Signaling Firewall (DSF); (e) SS7/SIGTRAN Security - SS7 firewall + Diameter security + GSMA FS.11/FS.19; (f) STIR/SHAKEN Signed Caller Identity - RFC 8224 + 8225 + 8226 + ATIS-1000074 + ITU-T Q.3057 + ROBOCALL Mitigation. (4) Voice/Video Communication Security: (a) SIP TLS + SIPS; (b) DTLS-SRTP for media; (c) ZRTP for opportunistic E2EE; (d) MIKEY Multimedia Internet KEYing + KMS; (e) WebRTC Identity provider + DTLS-SRTP; (f) Lawful Intercept exceptions; (g) E911 Phase 1/2 Location + ALI Automatic Location Identification + NG911. (5) DNS Security: (a) DNSSEC - signed DNS records + chain of trust + KSK Key Signing Key + ZSK Zone Signing Key; (b) DoT DNS over TLS RFC 7858; (c) DoH DNS over HTTPS RFC 8484; (d) DoQ DNS over QUIC RFC 9250; (e) Encrypted SNI (ESNI / ECH); (f) DNS Firewall + Response Policy Zones (RPZ); (g) DNS Sinkholing + Threat Intelligence Feeds; (h) DDoS protection for authoritative DNS; (i) Anycast DNS hosting (Cloudflare + Google + Quad9 + AWS Route 53 + Azure DNS). (6) VPN Security: (a) IPSec ESP/AH + IKEv2; (b) WireGuard; (c) OpenVPN; (d) SSL VPN; (e) GRE + L2TP encrypted tunnels; (f) SD-WAN + SASE Secure Access Service Edge + ZTNA Zero Trust Network Access; (g) Cloud VPN (AWS VPN + Azure VPN + Google Cloud VPN); (h) Site-to-Site + Client-to-Site + Cloud-to-Cloud. (7) AAA Security: (a) RADIUS RFC 2865 + RadSec TLS + EAP methods; (b) Diameter RFC 6733 + AVP + TLS/DTLS; (c) TACACS+ for device admin; (d) AAA roaming + roaming consortia; (e) Subscriber Identity Module (SIM/USIM/eSIM) + Authentication Center (AuC) + HSS Home Subscriber Server. (8) Threats per X.805 Table 1 mitigated at Services: All 5 threats mitigated. (9) Standards: (a) 3GPP TS 33.501 5G Security + TS 33.117 SCAS + TS 33.310 NDS/AF + TS 33.203 IMS + TS 33.328 IMS Media; (b) ETSI TS 187 003 IMS Security + ETSI TS 102 232 LI; (c) GSMA NESAS + GSMA FS.11/19 SS7/Diameter; (d) IETF SIP RFC 3261 + SIPS + RFC 8224 STIR + RFC 8225 PASSporT + RFC 8226 SHAKEN; (e) IETF DNS Security RFC 4033/4034/4035 DNSSEC + 7858 DoT + 8484 DoH; (f) ITU-T Y.2701 NGN Security + Y.2704; (g) NIST SP 800-46 Telework + SP 800-77 IPSec + SP 800-95 Web Service Security; (h) ATIS-1000074 STIR/SHAKEN + ATIS-1000086 SHAKEN Cert Mgmt. Coordinates with X.805 Layer 1/3 + Plane 1/2/3 + 8 Dimensions + Threats All-5 + 3GPP TS 33-Series + GSMA NESAS + ETSI TS 187 003 + IETF SIP/STIR/SHAKEN/DNS + ITU-T Y.2701 + NIST SP 800-46/77/95. ITU-T X.805 Security Layer 2 Services applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.