A.11 User authentication and authorization requirements

33.1793GPPRelease 13Security of Mission Critical Push To Talk (MCPTT) over LTETS

The solution for user authentication and authorization described in the present document shall satisfy the following requirements:

Interoperability between different networks and different manufacturers’ clients and servers:

– Satisfy requirements for MCPTT roaming and migration.

Flexibility in deployment models (see 3GPP TS 23.179 [2]):

– Support all deployment models listed in 3GPP TS 23.179 [2].

Support for interchangeable MCPTT user authentication solutions:

– Allow implementations to use different means to authenticate the user, e.g. Web SSO, SIP digest, GBA, biometric identifiers, username+password.

Scalability (number of users):

– Provide efficient support for small MCPTT systems with few users, to large MCPTT systems with hundreds of thousands of users.

Extensibility:

– Be extensible to provide authorization for further mission critical services including group aware services, additional interfaces, etc.

Annex B (normative):
OpenID connect profile for MCPTT