Overview
ISO/IEC 10745:1995 - Information technology - Open Systems Interconnection - Upper layers security model - defines an architectural security model for the OSI upper layers (Application, Presentation, Session). It provides a basis for development of application‑independent services and protocols that implement security for upper‑layer communication, without prescribing specific algorithms or protocol encodings. The text is identical to ITU‑T Recommendation X.803.
Key topics and requirements
- Scope and intent
- Specifies security aspects of communication in the upper OSI layers and how those layers support OSI security services.
- Targets application‑independent solutions to minimize application‑specific security code.
- Core concepts
- Security policy, secure interaction rules, and security domains - rules that govern when and how different domains interoperate securely.
- Security associations and security state - relationships and state information maintained between peers (including application‑association and relay security associations).
- Security exchange and security exchange items - how security information is transferred between AE‑invocations.
- Architecture elements
- Positioning of security services and mechanisms within Application, Presentation, and Session layers.
- Definition of security exchange functions and security transformations (composition of system security functions used to protect data).
- Notions such as protecting presentation context and protecting transfer syntax.
- Services and mechanisms (logical areas - standard does not mandate techniques)
- Authentication, access control, non‑repudiation, integrity, confidentiality.
- Interaction patterns between Application ↔ Presentation ↔ Session layers and use of lower‑layer services.
- Management
- Requirement for management of security information (security management information) in upper layers.
- Limitations
- Not an implementation or conformance specification; it does not define OSI protocols or crypto techniques.
Practical applications and users
Who benefits from ISO/IEC 10745:
- Security architects and systems designers creating secure OSI‑based application protocols.
- Standards developers and protocol designers mapping security services into upper‑layer protocols.
- Product vendors building middleware, secure presentation/serialization, or application service elements (ASEs).
- Security auditors and compliance teams assessing architectural placement of security controls.
Practical uses include designing secure application associations, defining presentation contexts with protecting transfer syntaxes, and specifying how authentication/access control/integrity/confidentiality are provided without embedding application‑specific mechanisms.
Related standards
Keywords: ISO/IEC 10745, upper layers security, OSI security model, security associations, application layer security, presentation layer protection, session layer security.