B.2 Requirements for trust model in NDS/AF
33.3103GPPAuthentication Framework (AF)Network Domain Security (NDS)TS
The following is a list of requirements for the trust model for NDS/AF:
A. Simplicity and ease of deployment. PKI brings many benefits when a large number of operators need to tunnel traffic in a mesh configuration, but its adoption should not be hindered by an unnecessarily complex technical solution. The required technical and legal operations necessary for exchanging traffic with another operator should be as easy and straightforward as possible;
B. Compatibility with existing standards. Unless there are explicit requirements why existing PKI standards should be extended to accommodate 3GPP environment, the 3GPP specifications should be accommodated to the existing standards. This allows best choice of equipment for operators and allows interoperability with non-3GPP environments;
C. Usable by both GRX and non–GRX operators. Both operators making use of GRX providers and those without (using leased lines or even the public Internet), should be able to make use of NDS/AF measures to exchange traffic securely.