Overview
ISO/IEC TR 13594:1995 - "Information technology - Lower layers security" is a technical report that describes cross‑layer architectural concepts and guidance for providing security services in the lower layers of the OSI Reference Model (Transport, Network, Data Link, Physical). Published as a Type 3 Technical Report (identical to ITU‑T Recommendation X.802), it clarifies how security protocols and mechanisms are placed, interact between layers, and support higher‑layer security requirements.
Key topics and technical requirements
- Cross‑layer security model: Architectural concepts common to the lower layers and the basis for interactions between layer‑specific security protocols.
- Placement of security protocols: Guidance on where to locate security mechanisms in Transport, Network, Data Link and Physical layers and how placement affects function and interoperability.
- Security associations (SA): Definition of Security Associations and SA‑Attributes (the set of parameters required to control lower‑layer security), including establishment, modification and teardown.
- Security PDU structure & QoS: Common security PDU formats, determination of security services and mechanisms, and how security interacts with Quality of Service (QoS) requirements.
- Management functions: Security policy, association management, key management, and security audit considerations for lower‑layer protocols.
- Operational issues: Influence on existing protocols (e.g., PDU size, concatenation), error handling, reflection protection, and guidance on use of (N‑1) layers to enhance N‑layer security.
- Special concerns: Security labelling, security domains, security of routing and traffic flow confidentiality.
- Rules and attributes: Use of Agreed Sets of Security Rules (ASSR) and guidelines for defining SA‑Attributes.
Practical applications and users
This report is practical guidance for:
- Network architects and protocol designers - when designing or revising lower‑layer security protocols and deciding protocol placement.
- Security engineers and system integrators - implementing secure devices, configuring SA‑Attributes, and integrating lower‑layer security with upper‑layer policies.
- Vendors of network equipment - ensuring interoperability and that device initialization, key management and placement options conform to cross‑layer security expectations.
- Standards developers and auditors - harmonizing new specifications with existing OSI/ITU‑T security models.
Typical use cases include deciding where to apply encryption/authentication in a stack, defining SA parameters for link or network protection, and managing keys and policies across devices and subnets.
Related standards
Keywords: ISO/IEC TR 13594, lower layers security, OSI lower layers, security associations, SA‑Attributes, transport layer security, network layer security protocol, security PDU, traffic flow confidentiality, key management.