ISO/IEC 29341-13-10:2008
Information technology - UPnP Device Architecture - Part 13-10: Device Security Device Control Protocol - Device Security Service
Information technology - UPnP Device Architecture - Part 13-10: Device Security Device Control Protocol - Device Security Service
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 84
- Дата публикации:
- 28 ноября 2008 г.
- Издание:
- ISO IS 29341 edition 1 version 1
- ICS:
- 35.200
Ingrid Glavich Ingrid Glavich 2 21 1995-11-10T13:27:00Z 2008-11-17T15:26:00Z 2008-11-17T15:26:00Z 1 81 464 3 1 544 10.6845 Clean 21 0 0 MicrosoftInternetExplorer4 /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin:0cm; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman";} ISO/IEC 29341-13-10:2008(E) provides the services necessary for strong authentication, authorization, replay prevention and privacy of UPnP SOAP (simple object access protocol) actions. The series of ISO/IEC 29341 publications defines an architecture for pervasive peer-to-peer network connectivity of intelligent appliances, wireless devices and PCs. It is designed to bring easy to use, flexible, standards-based connectivity to ad-hoc or unmanaged networks whether in the home, in a small business, public spaces or attached to the Internet.
Abstract
Overview
ISO/IEC 29341-13-10:2008 - "Information technology - UPnP Device Architecture - Part 13-10: Device Security Device Control Protocol - Device Security Service" defines the UPnP Device Security Service used to protect UPnP SOAP actions. The standard specifies services and message formats that enable strong authentication, authorization, replay prevention, and privacy for communication between UPnP Control Points, Security Consoles and devices in ad-hoc or unmanaged networks (e.g., smart homes, small businesses, public spaces).
Key topics and technical requirements
- Authentication & Authorization
- Mechanisms for device and client identity management, ownership, and role-based access.
- Procedures such as TakeOwnership, GrantOwnership, RevokeOwnership to manage device owners and privileges.
- Access Control Lists (ACLs)
- ACL structures and operations (read, write, add, delete, replace) to control access to device services and actions.
- Certificates & Cryptography
- Use of certificates, certificate caching, public-key operations and canonical encodings to validate identities and signatures.
- Guidance for RSA and symmetric algorithms, padding considerations, and secure key handling.
- Session Management
- Establishment, distribution and expiration of session keys to protect message confidentiality and prevent replay attacks.
- Actions like SetSessionKeys and ExpireSessionKeys for secure session lifecycle control.
- Message Protection & Replay Prevention
- Signed and/or encrypted SOAP payloads, sequence numbering, hashing and canonicalization to ensure integrity and freshness.
- Service Modeling & XML
- XML service description, schema (Device Security Schema) and namespaces for interoperable implementation.
- Supporting Elements
- State variables, eventing moderation, common error codes, and operational "security ceremonies" for discovery and ownership transfer.
Practical applications & who uses it
- Device manufacturers building UPnP-enabled products (smart TVs, printers, routers, IoT appliances) implement this standard to secure device control interfaces.
- Firmware and embedded systems developers integrate Device Security Service APIs to manage ownership, ACLs, certificates and session keys.
- Smart home platform vendors, integrators and system architects use the standard to ensure secure peer-to-peer connectivity and interoperability.
- Network security engineers and certification testers reference the standard to validate authentication, authorization and message protection behavior.
Related standards
- ISO/IEC 29341 series (UPnP Device Architecture) - parent architecture for pervasive peer-to-peer device connectivity.
- UPnP Device Architecture and SOAP/HTTP specifications used alongside this part for full protocol implementation.
Keywords: ISO/IEC 29341-13-10:2008, UPnP device security, SOAP authentication, ACL, certificates, session keys, IoT security, smart home device security.
Технические детали
- Технический комитет
- ISO/IEC JTC 1 - Information technology
- SKU
- ISO/IEC 29341-13-10:2008
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 29341-11-1:2008
ДействующийInformation technology — UPnP Device Architecture — Part 11-1: Quality of Service Device Control Protocol - L…
Overview ISO/IEC 29341-11-1:2008 - "Information technology - UPnP Device Architecture - Part 11-1: Quality of Service Device Control Protocol - Level 2 - Quality of Service Architecture" specifies th…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…