Telia Research AB György Endersz 2000-09-26 1 European Electronic Signature Standardisation Initiative EESSI Workshop Barcelona, 2000-09-26 György Endersz,

Slides:



Advertisements
Similar presentations
Universal Electronic Signatures Tarvi Martens ESTONIA.
Advertisements

WTO, Trade and Environment Division
Security standardization for Health Informatics ITU-T eHealth conference Geneva Dr Gunnar O. Klein convenor of ISO/TC 215/WG 4 Security Karolinska.
© ITU Telecommunication Development Bureau (BDT) – E-Strategy Unit.. Page - 1 Seminar on Standardization and ICT Development for the Information.
Bundesamt für Sicherheit in der Informationstechnik EESSI - WS May , 2000, Paris, Folie 1/18Klaus J. Keus, BSI Electronic Signatures in Germany,
A S I A P A C I F I C N E T W O R K I N F O R M A T I O N C E N T R E IEPG March 2000 APNIC Certificate Authority Status Report.
Practical Digital Signature Issues. Paving the way and new opportunities. Juan Carlos Cruellas – DSS-X co-chair Stefan Drees - DSS-X.
WP4 – Task 4.4 LCA Activities
Quality Label and Certification Processes Vienna Summit 11 April 2014 Karima Bourquard Director of Interoperability IHE-Europe.
Telia Research AB György Endersz European Electronic Signature Standardisation Initiative EESSI Budapest Seminar at the Hungarian Communication.
1 European Standardisation and the Identification of ICT Technical Specifications 13th XBRL Europe Day Rome, 6 May 2014 Antonio Conte, Project Manager.
Policy interoperability in electronic signatures Andreas Mitrakas EESSI International event, Rome, 7 April 2003.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
Summary of ETSI/ESI activities Andrea Caccia ETSI/ESI TB member Note: This document expresses only the views of its author.
Jaroslav Pinkava May 2001 Certification Authority in Praxis. Security Aspects. Conference Security and Protection of Information Ing. Jaroslav Pinkava,
© ETSI 2012 All rights reserved EUROPEAN UNION MANDATE/460 Kloster Banz Presented by Arno Fiedler, Member of European Telecommunications Standards.
Implementation of Electronic Signature Law Kęstutis Andrijauskas Information Society Development Committee under the Government of the Republic.
TechSec WG: Related activities overview Information and discussion TechSec WG, RIPE-45 May 14, 2003 Yuri Demchenko.
1 Bridge/Gateway CA Project Status Gzim OCAKOGLU European Commission – DG ENTR / IDABC Reykjavik – 27 May 2005.
21 mai 2015 Bridges between Certification Authorities.
PAPERLESS BUSINESS in GEORGIAN FINANCIAL SECTOR NANA ENUKIDZE - Advisor to the Governor.
M.Sc. Hrvoje Brzica Boris Herceg, MBA Financial Agency – FINA Ph.D. Hrvoje Stancic, assoc. prof. Faculty of Humanities and Social Sciences Long-term Preservation.
EESSI European Electronic Signature Standardisation Initiative
Legal Issues on PKI & qualified electronic certificates. THIBAULT VERBIEST Attorney-at-law at the Brussels and Paris Bar Professor at the Universities.
Information security An introduction to Technology and law with focus on e-signature, encryption and third party service Yue Liu Feb.2008.
EESSI Overview - 1August 2002 EESSI European Electronic Signature Standardisation Initiative Implementing Electronic Signature.
Resource PKI: Certificate Policy & Certification Practice Statement Dr. Stephen Kent Chief Scientist - Information Security.
European Electronic Signature Standardization
European Signatures versus Global SignaturesRome, 7 April, 2003 EESSI open specifications and interoperability The state of the art in Italy Giovanni Manca.
István Rényi Communication Authority, Hungary Panel 2: „ Development and market uptake of standards of the EESSI programme” Republic.
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
Copyright, 1996 © Dale Carnegie & Associates, Inc. Digital Certificates Presented by Sunit Chauhan.
Long-term Archive Service Requirements draft-ietf-ltans-reqs-00.txt.
National Smartcard Project Work Package 8 – Security Issues Report.
8 Nob 06 / CEN/ISSS ETSI STF 305: Procedures for Handling Advanced Electronic Signatures on Digital Accounting CEN/ISSS Workshop.
"certification service provider" Electronic Signatures
S New Security Developments in DICOM Lawrence Tarbox, Ph.D Chair, DICOM WG 14 (Security) Siemens Corporate Research.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
Conformity Assessment and Accreditation Mike Peet Chief Executive Officer South African National Accreditation System.
6. Strategic Plan : Implementing GEOSS Validating the way forward: Review of feedback from Plenary.
Conformance Mark Skall Lynne S. Rosenthal National Institute of Standards and Technology
HEPKI-PAG Policy Activities Group David L. Wasley University of California.
DICOM and ISO/TC215 Hidenori Shinoda Charles Parisot.
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March Electronic Signature infrastructure for Europe Riccardo Genghini Cen/Isss.
A Brief Overview of draft-ietf-sidr-cp-01.txt draft-ietf-sidr-cps-rirs-01.txt draft-ietf-sidr-cps-isp-00.txt Steve Kent BBN Technologies.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
UNECE – SIDA “ SOUTH EAST EUROPE REGULATORY PROJECT” FIRST MEETING OF REGULATORS FROM SOUTH EAST EUROPEAN COUNTRIES PRESENTATIONFROM THE REPUBLIC OF MACEDONIA.
EESSI June 2000Slide 1 European Electronic Signature Standardization Hans Nilsson, iD2 Technologies, Sweden.
Jimmy C. Tseng Assistant Professor of Electronic Commerce
“Trust me …” Policy and Practices in PKI David L. Wasley Fall 2006 PKI Workshop.
E-SIGNED DocFlow SYSTEM in GEORGIAN FINANCIAL SECTOR NANA ENUKIDZE – E-Business Development Consultant.
Harmonised use of accreditation for assessing the competence of various Conformity Assessment Bodies Dr Andreas Steinhorst, EA ERA workshop 13 April 2016,
OASIS Juan Carlos Cruellas – UPC Stefan Drees - DSS-X co-chair Nick Pope – Thales eSecurity OASIS Digital Signature Services and ETSI standards Juan Carlos.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 10 – Information society and media.
OASIS Digital Signature Services and ETSI standards Juan Carlos Cruellas – UPC Stefan Drees - DSS-X co-chair Nick Pope – Thales.
INSPIRE and the role of Spatial Data Interest Communities (SDIC)
66 items – 70% of circulated products
TeleTrusT Initiatives for PKI Solutions
REPARIS Workshop Vienna
Keith Dickerson Chairman, ICTSB
Session II: System authority for ERTMS 4RP Trackside approval
Formats for long term signatures
Public Key Infrastructure Using X.509 (PKIX) Working Group
Draft ETSI TS Annex C Presented by Michał Tabor for PSD2 Workshop
PKI Services for the Public Sector of the EU Member States
Jørgen Friis, ETSI VP SES
Hans Dufourmont Eurostat Unit E4 – Structural Funds
Hans Dufourmont Eurostat Unit E4 – Structural Funds
Overview of the recommendations on software updates
Presentation transcript:

Telia Research AB György Endersz European Electronic Signature Standardisation Initiative EESSI Workshop Barcelona, György Endersz, Telia Research AB, Sweden Chairman ETSI ESI Working Group Status & International Issues

Telia Research AB György Endersz The Program and the Actors (Who is Who) European Directive for Electronic Signatures (“The Directive”) provides a common framework for electronic signatures. Harmonization of the aspects: - legal - trust - technical Industry and business, assisted by European standard bodies, will provide a framework for an open, market-oriented implementation of the Directive Information & Communications Technologies Standards Board: co-operation between European standards bodies Article 9 Committee, as defined by the Directive

Telia Research AB György Endersz EESSI SG EESSI: European Electronic Signature Standardization Initiative European Telecommunications Standards Institute

Telia Research AB György Endersz EESSI Program Implementation All deliverables to be published by the end of 2000 ETSI ESI Working Group Participants, funded Specialist Task Force of 8 Result: ETSI Technical Specifications 4Q2000 Chairman: CEN/ISSS E-SIGN Workshop 70 participants, funded Expert Team of 12 Result: CEN Workshop Agreements 4Q2000 Chairman:

Telia Research AB György Endersz Directive “on a Community framework for electronic signatures, 13 Dec ‘99” Ensures legal recognition of electronic signatures Security and quality requirements in Annexes I-III Qualified certificates+secure signature-creation device+ advanced signatures hand-written signature Other signatures recognised as well (Art 5.2) Voluntary accreditation of service providers (tScheme, NL.TTP, Italy, Austria, Germany, Spain….) Technology-neutral framework To be in place within 18 months

Telia Research AB György Endersz Annexes of the Directive Annex I: Requirements for qualified certificates Annex II: Requirements for certification-service-providers issuing qualified certificates Annex III: Requirements for secure signature-creation devices Annex IV: Recommendations for secure signature verification

Telia Research AB György Endersz EESSI Standards overview Signature creation process and environment Signature validation process and environment Signature format and syntax Creation device Requirements for CSPs Trustworthy system Certification Service Provider User/signer Relying party/ verifier CEN E-SIGN ETSI ESI Qualified certificate Time Stamp

Telia Research AB György Endersz Requirements for Certification Service Providers (CSPs) Functional, quality and security requirements expressed in Certificate Policy and security controls Consistent requirements to provide the basis for implementation, audit and approval Current work responds to Directive requirements for CSPs issuing Qualified Certificates, Annex II Requirements for other class(es) to meet market needs

Telia Research AB György Endersz Baseline Requirements Security Management PKI Organisational Obligations & Liability Issuing CSP Relying Party Subscriber RADirectory Qualified Certificate Policies - QCP Public - QCP Public + SSCD - Framework for other QCPs

Telia Research AB György Endersz Requirements for CSPs: Main Parts Obligations and liability Requirements on CSP practice - Key Management Life Cycle - Certificate Life Cycle - CSP Management & Operation - Organisational Definition of QC policies Annex: Cross-references to Directive and to RFC 2527

Telia Research AB György Endersz Trustworthy Systems for CSPs Technical security requirements for products and technology components used by CSPs to create certificates for the use of advanced signatures. To meet security requirements stated in the work area „Requirements for CSPs“. Seek consistent overlap of specifications. Describe requirements as one or more Protection Profiles using Common Criteria. The use of FIPS is considered for the cryptographic module requirements.

Telia Research AB György Endersz Profile for Qualified Certificate (QC) Standard for the use of X.509 public key certificates as qualified certificates European profile based on current IETF PKIX draft as required by Annex I of the Directive. Mandates that the certificate is indicated as a QC either by policy identifier or QC extension. Base IETF PKIX standard in IETF approval process. Ended IESG last call period 22 September. Draft Technical Specification for approval by ETSI SEC in 4Q2000

Telia Research AB György Endersz Qualified Certificate Statements The profile uses a private extension defined in the IETF Qualified Certificates profile, to include the following explicit statements of the Issuer: Statement claiming that the certificates is issued as a Qualified certificate Statement regarding limits on the value of transactions for which the certificate can be used Statement indicating the duration of the retention period during which registration information is archived

Telia Research AB György Endersz SSCD: the trusted element at the user EU-directive requires SSCD to be evaluated and „confirmed“ by national bodies A specific Common Criteria Protection Profile will address appropriateness It reflects the requirements regulated in Annex III of the signature Directive It is aimed to remain technology neutral as long as security is not impaired Use of SSCD to be represented in QC SSCD: Secure Signature Creation Device

Telia Research AB György Endersz The Scenario TOE The SSCD is the device „getting in touch“ with the private key. The SSCD comprises the whole lifecycle. The SSCD assumes an appropriate environment for its application. Trusted paths are offered to meet security requirements.

Telia Research AB György Endersz Electronic Signature Formats Defines interoperable syntax and encoding for signature, validation data and signature policy. Builds on exiting PKI and digital signature standards Published as ETSI Standard (ES) in May Amended version without mandatory time stamp for approval as ETSI Technical Specification in 4Q2000 Submitted to IETF in July 2000 as Informational/Experimental RFCs, in two parts, based on the ES Co-operative implementation project in preparation to validate standard and provide free software Aim: to harmonise development with XML signatures. First working draft of XML-version: September 2000

Telia Research AB György Endersz ES = The ETSI Electronic Signature as generated by the signer. ETSI Electronic Signature Signers Structures

Telia Research AB György Endersz ES-T = The ETSI Timestamp Electronic Signature. Timestamp attribute may be absent, if secure records prove the time of the ES ES-C = The ETSI complete Electronic Signature with references to all information needed to check its validity ETSI ES-T and ES-C Verifiers Structures Unsigned attributes added for long term verification

Telia Research AB György Endersz Format and Protocol for Time Stamp Profile based on current IETF PKIX draft Time stamps used for signature validation, e.g. in ES Electronic Signature Formats Harmonisation of ISO-IETF activities: IETF draft may become a compatible subset of the ISO specifications Draft Technical Specification to be approved by ETSI SEC in 4Q2000

Telia Research AB György Endersz EESSI Orientations The standards should support different classes of requirements reflecting market needs for different security/quality levels In this model the standards, where applicable, will offer alternative levels Consistent sets chosen from the alternatives will meet a class of requirement, as illustrated in the following examples Input by stakeholders needed

Telia Research AB György Endersz Non-Public or Extended Policies Public Use with SSCD Electronic Signature + Validation Data Electronic Signature +Val Data +Time stamp Lower Level Qualified Level Higher Level Lower Level Qualified Level EESSI Standard Qualified Certificate Policy Electronic Signature Format Qualified Certificate Format Time-stamping Protocol Security Requirements for Trustworthy Systems SSCD Qualified Certificate Profile Time Stamping Profile Option Within Standard Qualified Electronic Signature

Telia Research AB György Endersz Non-Public or Extended Policies Public Use with SSCD Electronic Signature + Validation Data Electronic Signature +Val Data +Time stamp Lower LevelQualified Level Higher Level Lower Level Qualified Level EESSI Standard Qualified Certificate Policy Electronic Signature Format Qualified Certificate Format Time-stamping Protocol Security Requirements for Trustworthy Systems SSCD Qualified Certificate Profile Time Stamping Profile Option Within Standard Qualified Electronic Signature with Long-term Validity

Telia Research AB György Endersz Non-Public or Extended Policies Public Use with SSCD Electronic Signature + Validation Data Electronic Signature +Val Data +Time stamp Lower Level Qualified LevelHigher Level Lower Level Qualified Level EESSI Standard Qualified Certificate Policy Electronic Signature Format Qualified Certificate Format Time-stamping Protocol Security Requirements for Trustworthy Systems SSCD Qualified Certificate Profile Profile from IETF Timestamp Protocol Option Within Standard Electronic Signature Using Qualified Certificate

Telia Research AB György Endersz International Issues Recognition of conformance to SSCD requirements Cross-recognition of “certification policy” On-line validation of CSP status Harmonization of interoperability standards

Telia Research AB György Endersz Cross-recognition of conformance to SSCD requirements In general: CC MRA: Arrangement on the Mutual Recognition of CC Certificates in the Field of IT Security The Directive: Designated Body (Art. 3.4) issues statement that the SSCD conforms to Annex III requirements Can be based on certificate obtained by the CC MRA but formally independent decision

Telia Research AB György Endersz Cross-recognition of ‘certification policy’ The aim is establishment of trust, optimally at the time of the transaction policy mapping Cross recognition provides equivalent quality. Can be represented in machine-readable form Cross-certification, the “bridge-CA” concept “Foreign” certificates = qualified certificates if…. Review and update of cryptographic requirements will affect cross-recognition at the international level

Telia Research AB György Endersz On-line validation of CSP status National schemes include procedures to make such information available, e.g. CSP not bale to fulfill obligations, failed audit, etc Agreed, simple formats and mechanisms are needed to store and retrieve such information Not addressed yet: gray zone between accreditation/approval and technical interoperation

Telia Research AB György Endersz Harmonization of interoperability standards Profiles based on IETF RFCs: Qualified Certificate and Time Stamp: the consistency issue Partial interoperability of ISO and IETF standards for time stamping ES Formats standard: harmonisation of activities - on Signing Policy with IETF and - on XML version of ES Formats with W3C and EDI/XML

Telia Research AB György Endersz Other Issues Identification of subjects: in person? Management of cryptographic requirements Requirements for other than QC: alternative trust levels. Impact on SSCD, CSP Policy and trustworthy system The need for unique, permanent, borderless electronic identity

Telia Research AB György Endersz Events Calendar Drafts of amended ES Format, Qualified Certificate and Time Stamp posted by on Web-site for public consultation 22 September. Comments period ends 13 October. Drafts of SSCD, Trustworthy Systems, Signature Creation and Verification posted on Web-site for public consultation end of September. Comments period ends 31 October. EESSI Workshop in Barcelona, 26 September. Co-located with the Information Security Solutions Europe (ISSE) conference, September CEN/ISSS E-Sign meeting: 2-3 October, Barcelona ESI WG meeting: October, Milan CEN/ISSS E-Sign WS and ETSI ESI WG meetings, including Joint session, November, Brussels

Telia Research AB György Endersz References ETSI: Sign up from Web-site to open El Sign mailing list CEN: EESSI: ISSE Conference & Workshops: