您的浏览器禁用了JavaScript(一种计算机语言,用以实现您与网页的交互),请解除该禁用,或者联系我们。 [美国国家电信和信息管理局]:2015年csmac频谱管理数据库小组委员会建议草案 - 发现报告

2015年csmac频谱管理数据库小组委员会建议草案

报告封面

Draft RecommendationsFebruary , 2015 Question we are addressing:"How can sensitive and government classified operations be includedand protected using a database-driven sharing approach, particularly one that strives toward real-timeresponses?" Draft Recommendations: Recommendation 1: The NTIA should start sharing now using informationthat is non-sensitive.oBackground:Effective sharing can be implemented now on case-by-case basis.For example, reasonable protection zones based on powerlevels and sensitivity, while not optimal, can be a starting pointfor sharing that likely doesn't require sensitive informationdisclosure.oThe NTIA should leverage characteristics of federal systems that aresufficient to permit sharing while not compromising their sensitivecharacteristics (e.g.; record the characteristics needed for sharing as dataelements to be used as a baseline to creating a Spectrum Access System(SAS)).oThe NTIA should find solutions that work by band and by system;don’ttry to find a single solution (e.g.; document the models and simulationsused in a repository for later incorporation into the SAS.).oThe NTIA should implement the SAS concept in the 3.5 GHz band within36 months. This is consistent with the time horizon being consideredwithin the FCC’s rulemakings and with the PCAST recommendations.oThe NTIA should monitor current research on sharing methodologies(e.g., DARPA’sShared Spectrum Access for Radar and Communications(SSPARC) program).oSee reference document on information needed for sharing (link). Recommendation 2: The NTIA should begin a path to implement federalSAS/black box technique to address federal data sharing concerns as paralleltrack to sharing now, but it should not be a constraint to getting started withsharing.oA federal SAS is a“black box”system where commercial SAS requests are made to use or share specific spectrum and the federal SAS returns aresponse that allows the sharing to take place without exposing sensitive data on federal systems. This is similar to what was done in 70/90 GHzband. [See Tools section below]oNITA should also study data obfuscation techniques (e.g., protectionzones) as a possible alternative to data classification in order to protectsensitive data yet support bi-directional sharing.oThe NTIA should monitor development of commercial SASs in thecontext of the FCC’s 3.55 GHz rulemaking.oPros: Protects sensitivefederalinformationwhile permitting sharingthrough operation of the commercial SAS.Promotesactualsharing (asopposed to protection zones) and draws maximum benefit from SAS.oCons: Lacks sufficient transparency. Will take significant time, effort andbudget to implement and industry cannot wait. Federal SAS may need tointerface directly with devices or device controllers, may increase networkoverhead.oConclusion: Black box and data obfuscation may be feasible, but shouldnot overused to solve all cases and should not be required to commencesharing. Recommendation 3: The NTIA should establish itself as an intermediarybetween industry and the Federal Government in facilitating dialogue and ifnecessary seek authority to ensure data is not overclassied and not a barrierto spectrum sharing.oBackground: The issue of data classification has been identified as one of themost significant barriers to broad-scale spectrum sharing Whileproper data classification is imperative to protect national security,this often appears as a means to thwart sharing where otherwisefeasible.Designations such as “For Official Use Only” (FOUO),“Unclassified, Special Handling”and now“ControlledUnclassified Information (CUI)”seem to be overused.While NTIA has a responsibility to enforce proper spectrummanagement data classification, it also has a responsibility to ensurespectrum is efficiently used including spectrum sharing. The NTIA inits role as facilitator of spectrum sharing is uniquely positioned toadvocate for the appropriate and not excessive classification ofinformationoNTIA should engage the Information Security Oversight Office (ISOO) ofthe National Archives and Research Administration (NARA) to helpreconcile this matter and potentially obtain addition authority, possibly inEO 13526 and 32 CFR Part 2001 on security classification matters inregards to spectrum management.oNTIA should take a formal position on the state of data classification andits impact on the ability to facilitate efficient spectrum sharing and updatethat periodically.oNTIA should study data classification procedures to determine whetherthese procedures should be revised in light of new approaches to sharing(e.g., SAS). NTIA should engage Committee on National Security Systems (CNSS) to for policy and technical advice on developingspectrum access systems that protect properly classified information whileproviding unclassified information to spectrum users to assist in sharing.oThere may also be other ways to provide information sufficient for sharingwhile not exposing sensitive data. For example