How To Write A New System For A Bank Account (For A Bank)

Size: px
Start display at page:

Download "How To Write A New System For A Bank Account (For A Bank)"

Transcription

1 eidas Regulation esignature & eseal Towards Real Implementation - an Overview of & Experiences with applying CEN/ETSI Standards & Best Practices Sylvie Lacroix EEMA TrustCore meeting 25 February Brussels

2 Agenda Standardisation developments status Introduction to the M460 mandate Key points & items in each standardisation area 0. Framework 1. Signature creation and validation 2. Signature creation & other related devices 3. Cryptographic suites 4. TSPs supporting digital signatures 5. Trust application service providers 6. Trust service status list providers Testing conformance & interoperability Building a service : illustration Alignment with eidas Regulation

3 Agenda Standardisation developments status

4 M-460 Objectives: - Inventory - Rationalised structure - Gap Analysis - Work Programme - Quick fixes Rationalised structure: 6 Trust Service Status Lists Providers TSPs supporting esignature 4 Signature Creation & other related Devices 1 Signature Creation & Validation Introductory deliverables Trust Application Service Providers Cryptographic Suites Consistent numbering (x series): DD L19 xxx-z - Functional Area & Sub-Area - Document type Guidance Policy & Security Requirements Technical Specifications Conformity Assessment Testing Conformance & Interoperability

5 M460 output: framework for digital signature stds TSP issuing certificates Time Stamping Auth ies Signing services Validation services Rules & procedures Signature creation / validation protection profiles CC Protection Profiles - Smart Cards - HSM s - Signing Services 6 Trust service status lists providers TSPs supporting digital signature 4 Signature creation & other related devices 1 Signature Creation & Validation Introductory deliverables Trust application service providers Cryptographic suites List of TSP services approved (supervised) by National Bodies (e.g. Trusted lists) edelivery / Reg ed Long term preservation XAdES CAdES PAdES AdES in mobile env mt ASiC (containers) Key generation Hash functions Signature algorithms Parameters,

6 Area 0 - Framework documents Phase 1 resulted in Rationalized Framework (SR ) Phase 2 & Post Phase 2 work in progress Updating framework presentation document (TR as update of SR / approved in June 2015) Study on The framework for standardisation of signatures: Extended structure including electronic identification and authentication (TR to be updated according to Implementing Regulation (EU) 2015/1502 on LoA) Study on The framework for standardisation of signatures: Standards for AdES in mobile environments (SR published) Guidelines for SMEs & citizens (TR & TR draft) Document centralising definitions and abbreviations (TR published & under updating process) Quite all the documents in this area are new! Introductory documents of the framework for signature standardisation Replaces Expected publication Sub-areas Guidance TR The framework for standardisation of signatures: overview SR v1.1.1 published TR The framework for standardisation of signatures: Extended structure including electronic identification and authentication (new) March 2016 (hand over to CEN) SR The framework for standardisation of signatures: Standards for AdES digital signatures (new) published in mobile environments TR The framework for standardisation of signatures: Best practices for SMEs CWA Dec TR The framework for standardisation of signatures: Guidelines for citizens CWA Dec SR Rationalised framework of standards for electronic registered delivery applying (new) published electronic signatures Policies TR The framework for standardisation of signatures: Definitions and abbreviations (new) published

7 Area 1 - Signature Creation & Validation Phase 1 Quick fixes Phase 2 & Post Phase 2 work in progress Guidance on the use of standards for creation & validation of dig. sig. (new - TR ) Policy & security requirements for applications for signature creation and signature validation (new - TS on approval) Protection Profiles for signature creation & validation applications (new - EN ) C/X/PAdES & ASiC formats (baseline & additional signatures/containers profiles) Revisions and migration to ENs (EN /132/142/162 under EN Approval) Procedures for creation and validation of digital signatures New - EN (TB approved) Signature policies New - TS (published) Conformity assessment for SCA / SVA New - EN (on approval) Testing conformance & interoperability Signature formats - TS 119 1x4 Signature creation and validation Sub-areas Guidance TR Guidance on the use of standards for signature creation and validation Policy & Security Requirements TS Policy and security requirements for applications for signature creation and signature validation EN Protection profiles for signature creation and validation application Technical Specifications EN Procedures for creation and validation of AdES digital signatures EN CAdES digital signatures EN XAdES digital signatures EN PAdES digital signatures TS Architecture for AdES digital signatures in distributed environments EN Associated Signature Containers (ASiC) TS Signature policies Conformity Assessment EN Conformity assessment for signature creation & validation (applications & procedures) Testing Conformance & Interoperability TS CAdES Testing conformance & interoperability TS XAdES Testing conformance & interoperability TS PAdES Testing conformance & interoperability TS Testing conformance & interoperability of AdES in mobile environments TS ASiC Testing conformance & interoperability

8 Area 2 - Sig. & other related devices Phase 1 resulted in a work plan including new topics and revision and maintenance of existing documents Protection Profiles for SSCD: EN parts (for user managed devices, ex CWA 14169) Phase 2 work in progress Guidance on the use of related standards (TR ) Protection Profiles for TSPs: Trustworthy System supporting time Stamping (new): EN Ex CWA 14167, PP for TSP crypto module: move to EN EN & (e.g. sec. reqs. For trustworthy system managing certificates for electronic signatures) Security requirements for Trustworthy System supporting server signing: EN Security requirements for device for authentication: EN Application Interfaces for SSCDs EN

9 Area 2 - Sig. & other related devices Area 2 list of deliverables Signature creation and other related devices Sub-areas Guidance TR Guidance on the use of standards for signature creation and other related devices Policy & Security Requirements EN Protection profiles for secure signature creation device - Part 1: Overview - Part 2: Device with key generation - Part 3: Device with key import - Part 4: Extension for device with key generation and trusted communication with certificate generation application - Part 5: Extension for device with key generation and trusted communication with signature creation application - Part 6: Extension for device with key import and trusted communication with signature creation application EN Protection Profiles for TSP cryptographic modules - Part 1: Overview - Part 2: Cryptographic Module for CSP signing operations with backup Protection Profile (CMCSOB-PP) - Part 3: Cryptographic module for CSP key generation services Protection Profile (CMCKG-PP) - Part 4: Cryptographic module for CSP signing operations without backup Protection Profile (CMCSOPP) - Part 5: Protection Profile for cryptographic module for TSPs EN Protection profile for trustworthy systems supporting time stamping EN Trustworthy systems supporting server signing - Part 1: General system security requirements - Part 2: Protection Profile for QSCD for Server Signing EN Security requirements for device for authentication - Part 1: Protection profile for core functionality - Part 2: Protection profile for extension for trusted channel to certificate generation application - Part 3: Additional functionality for security targets TS Security requirements for trustworthy systems (incl. managing certificates for electronic signatures) Technical Specifications EN Application interfaces for secure elements used as qualified electronic signature (seal) creation devices - Part 1: Introduction - Part 2: Basic services - Part 3: Device authentication - Part 4: Privacy specific protocols - Part 5: Trusted eservices Conformity Assessment no requirement identified Testing Conformance & Interoperability no requirement identified

10 Area 2 application to server signing (managing key on behalf of signatories) Applicable new protection profiles (PP) for server signing: Server signing PPs: EN , (1) 3 parts Security reqs., PP for trusted sig. creation module, PP for Sig. Activation data mngt & Sig. Activation protocol Cryptographic modules for Trust Services (2) (new part 5 of EN series) For TSP operation in secure environment Multipurpose crypto module (protection of signatories keys, authentication mechanisms) Security requirements for device for authentication: EN (3) TSP Signature Creation Module (1) Crypto Module (2) Signer s SDC Sole control (1-3)

11 Area 3 - Cryptographic suites Main activities TR published in 05/2015 (under update) TS published in 11/2014 (under update) Maintenance & monitoring : collaboration ETSI - ENISA Cryptographic suites Replaces Expected publication Sub-areas Guidance TR Guidance on the use of standards for cryptographic suites (new) published Technical Specifications TS Cryptographic suites TS published Testing Conformance & Interoperability no requirement identified

12 Area 4 - TSPs supporting signatures Main activities Business Guidance (TR ) TSP Conformity Assessment EN (EN approved) TSP Policy requirements (EN approved) Revised EN : General reqmts Revised EN x TSPs issuing certificates EN Time-stamping Certificate and time-stamp profiles (EN approved) EN to -5 Certificates (natural, legal, web, qualified) EN Time-stamping Next Phase TSPs supporting digital signatures and related services Sub-areas Guidance TR Guidance on the use of standards for TSPs supporting digital signatures and related services Policy & Security Requirements EN General policy requirements for trust service providers EN Policy and security requirements for trust service providers issuing certificates - Part 1: General requirements - Part 2: Requirements for trust service providers issuing EU qualified certificates EN Policy & security requirements for trust service providers issuing time-stamps EN Policy and security requirements for trust service providers providing AdES digital signature generation services EN Policy and security requirements for trust service providers providing AdES digital signature validation services Technical Specifications EN Certificate profiles - Part 1: Overview and common data structures - Part 2: Certificate profile for certificates issued to natural persons - Part 3: Certificate profile for certificates issued to legal persons - Part 4: Certifcate profile for web site certificates - Part 5: QCStatements EN Time-stamping protocol and time-stamp token profiles EN Protocol profiles for trust service providers providing AdES digital signature generation services EN Protocol profiles for trust service providers providing AdES digital signature validation services Conformity Assessment EN Trust Service Provider Conformity Assessment - Requirements for conformity assessment bodies assessing trust service providers Testing Conformance & Interoperability no requirement identified for such a document EN : Signature Generation Service Providers Sec. Pol. Protocol Profiles EN : Signature Validation Service Providers Sec. Pol. Protocol Profiles

13 Area 5 Trust applic service providers Main activities Business Guidance (TR ) Study on e-delivery standardisation needs (SR published 06/2015) Addressing e-delivery services as defined in Regulation proposal Identify standards required to be produced Define scope and purported contents Raise recommendations Phase 3: Study on Preservation Services potentially followed by actual standardization (on going) e-registered delivery services policy requirements & profiles (EN /522) Registered Electronic Mail (REM) Services policy requirements & profiles (EN /532) + Quick fix maintenance of ETSI TS (REM) SR : Rationalised Framework of Standards for Electronic Delivery Electronic Deliver abstract model Analysis of standardisation status for e-delivery components Proposed Framework of Standards Amended Framework of Standards for Registered Proposal for e-delivery standardisation activities Drafted Being drafted Trust application service providers Sub-areas Guidance TR Guidance on the use of standards for trust application service providers SR Scoping study and framework for standardization of long term data preservation services, including preservation of/with digital signatures Policy & Security Requirements EN Policy & security requirements for trust service providers providing long term data preservation services, including preservation of/with digital signatures EN Policy & security requirements for electronic registered delivery service providers EN Policy & security requirements for registered electronic mail (REM) service providers Technical Specifications EN Long term data preservation services, including preservation of/with digital signatures EN Electronic registered delivery services: EN Registered electronic mail (REM) services: Conformity Assessment no requirement identified for such a document - relying on TS / EN Testing Conformance & Interoperability TS General requirements for technical conformance and interoperability testing for trust application service providers and the services they provide TS Testing conformance and interoperability of electronic registered delivery services: TS Testing conformance & interoperability of registered electronic mail services.

14 Area 6 - TSLs & Trusted Lists Phase 2 Published Business driven guidance (TR may 2015) Testing conformance & interoperability (TS ) Trusted Lists (TS ) V1.1.1 published June 2013 on which CD 2013/662/EU builds EU MS TL specifications (currently applicable) V2.1.1 published July 2015 on which CID (EU) 2015/1505 builds EU MS TL specifications under eidas Regulation (Art 22 (5)) Allow non-eu countries and International organisations to set-up TL s in order to facilitate (mutual) recognition of approved trust services Tools available (sustained under CEF): TLManager (EC Joinup) TL Conformance Tester (ETSI / UPC) Trust service status lists providers Replaces Expected publication Sub-areas Guidance TR Guidance on the use of standards for trust service status lists providers new published Policy & Security Requirements TS Policy & security requirements for trusted lists providers Undefined Technical Specifications TS Trusted lists TS published Conformity Assessment no requirement identified for such a document - relying on TS / EN Testing Conformance & Interoperability TS Testing conformance & interoperability of trusted lists: (new) Undefined

15 Testing conformance & interoperability Published Special Report SR formalizing plans for: Organization, definition and conduction of test events (run during the implementation and deployment of the Rationalised Framework) Production of a set of Technical Specifications defining test suites for testing interoperability and conformity against core standards of the RF. Design and implement a set of conformity testing tools. Schedule available from ETSI Publications Download Area: PAdES Plugtests May 2015 CAdES Plugtests 11 June - 10 July 2015 XAdES Plugtests planned for October 2015 (NEW) esignature Validation remote Plugtest 6-29 April 2016

16 Agenda Building a service : illustration

17 M460 Illustration: build a signature creation service Start with (Guidance on the use of applicable standards) Select appropriate signature formats (E.g. EN CAdES) test(ed) against ) Design appropriate security controls as per (Security Policy for Signature Creation Applications) Built appropriate technical controls as per (Protection Profile for Signature Creation Applications) Follow correct security policy as TSP as per and (Generic TSP security Policies security Policies for TSP generating signature ) Ask audit as per and (conformity assessment)

18 Agenda Alignment with eidas Regulation

19 Key points Mapping to eidas legal requirements Mandatory (3 dated or 1 not) vs non mandatory acts Acts for which the EC is empowered to define the technical requirements and specifications that when met will grant presumption of compliance vs acts for which the EC may/shall establish reference numbers of standards but is not empowered to determinate directly their content. (Non automatic referencing principles established by EC). ENISA s assistance: Standards assessment: Eligibility for enabling eidas compliance Study on TSPs standards IAS2 study

20 Mapping with eidas Mandatory acts: eid area s IAs are out of scope except bridge with Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015 on setting out minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to Article 8(3)) (EC emp) Commission Implementing Decision (EU) 2015/1506 of 8 September 2015 laying down specifications relating to formats of advanced electronic signatures and advanced seals to be recognised by public sector bodies pursuant to Articles 27(5) and 37(5) of Regulation conformance levels B, T or LT points to TS to 174 versions of C/P/XAdES ASiC baseline profiles (EC emp) Commission Implementing Decision (EU) 2015/1505 of 8 September 2015 laying down technical specifications and formats relating to trusted lists pursuant to Article 22(5) of Regulation Establishes EU MS TL specifications and requirements building on ETSI TS v2.1.1

21 Mapping with eidas Mandatory acts: (EC emp) Commission Implementing Regulation (EU) 2015/806 of 22 May 2015 laying down specifications relating to the form of the EU trust mark for qualified trust services QSCD (on going) Art 30 3 (no date) list of standards for the security assessment of information technology products (how to certify) Art 30 4 (D.A. - EC emp - no date) establishment of specific criteria to be met by the designated bodies Art 29 2 IA (may) list of standards for presumption of compliance with Annex II (QSCD) (what to certify)

22 Mapping with eidas QSCD complex Standards for QSCD (what to certify), of no use when not recognised under mandatory certification process (how to certify) Selecting a process may risk to limit actual devices to the ones conforming to recognised stds (e.g. by ISO (CC) or EC 765/2008) i.e. may impede activation of Art 30 3 (b) on alternatives (pros and cons) * Scope of QSCD mandatory certification is limited (recital 56) to the heart of the device (SCD protection & use): PP exists for devices managed by signatories where resp. on environment (or QSCD borders) is on signatories More difficult for devices for which TSP are managing key on behalf of signatories (must be QTSP) and/or use of devices in non-secure environments (e.g. public lockets). Transitional measure for signatures - nothing for seal (*)

23 Mapping with eidas Might be referred in IA Article 20.4 Supervision QTSP layered model Commission Implementing Decision (EU) 2015/1505 (Trusted list) Def. (18) : CAB accredited under EC Reg. 765/2008. EA established CAB accreditation framework: L1: ISO (with hooks to ISO & 17021), for accrediting CAB competencies (to assess products & services) L2: ETSI EN , reqs for CABs for assessments of (Q)TS(P)s L3: TSP audit criteria (control objective list for eidas conformity) being eidas requirements on QTSPs/QTSs L4: (not mandatory): policy and security requirements to achieve L3 (controls): e.g. ETSI 319 4x1 series Fine-tuned for the regulation (e.g. cert. status info kept beyond expiry in technical terms) Requires bridges with Assurances Levels (e.g. NCP cert. level High)

24 Mapping with eidas Supervision QTSP layered model EA model in place for CAB accreditation ISO/IEC EN (the scheme document) eidas regulation No 910/2014 No need for IA in theory CAB needs to demonstrate it meets accreditation requirements TSP needs to demonstrate it meets QTSP/QTS requirements of eidas Competent Supervisory Body needs to be convinced on CAB accreditation model TSP audited by accredited CAB meets QTSP/QTS requirements of eidas Importance of assessment scope and conformity assessment report s: Content and details / Template versus QTSP/QTS eidas requirements Transparency Legitimacy (not addressed by IA nor by ESO but likely by ACAB-c and/or by SB?)

25 Mapping with eidas Other implementing acts / may wait that industry selfregulate Standards for AdES (art 27.4) relies on: Technical specs of SCDev, certificates (e.g. level low, high), long term preservation features. Standards for establishing LoA of above components (e.g TSP practices certified as high ) Numerous standards exist. Combination complex IA Needed? Standards for Q-validation, Q-preservation, etc.

26 Mapping with eidas Non in acts while sometimes believed to be: TPS offering signature services and/or handling SCDev for the users Qualified Signature Creation is not subject to Qualification but: TSP can offer QES creation services without being Q-TSP if QSCD is managed by the TSP, TSP must be a QTSP offering a Q-Service (e.g. timestamping, certification, preservation, validation services). => but connected to IAs on QSCD, QTSP and of course, standards are recommended (e.g. EN , EN , , TS , TS )

27 Website & Stakeholders mailing list Stakeholders mailing list: Subscription via above website (via Subscribe to the newsletter ). To get news. To receive drafts. To be notified of commenting periods. Etc.

28 Useful links e-signature Standards Portal: STF web pages STF 457: STF 458: STF 459: ETSI Publications Download Area: ETSI Electronic Signatures Portal: Standardisation mandate m460 to CEN and ETSI on electronic signatures Study on Cross-Border Interoperability of esignature (CROBIES) - ( ): European Commission page on EU Member States Trusted Lists: Revision aspects of European electronic signature Directive 1999/93/EC & Draft proposal for a Regulation "on electronic identification and trusted services for electronic transactions in the internal market": Studies on an electronic identification, authentication and signature policy ( , 2013):

ETSI SECURITY WEEK EIDAS Overview CEN/ETSI esignature Standardization including standards for TSP Compliance. ETSI 2015. All rights reserved

ETSI SECURITY WEEK EIDAS Overview CEN/ETSI esignature Standardization including standards for TSP Compliance. ETSI 2015. All rights reserved ETSI SECURITY WEEK EIDAS Overview CEN/ETSI esignature Standardization including standards for TSP Compliance esignature Standards Framework Certificate Authority Time-stamping Signing Servers Validation

More information

NIST-Workshop 10 & 11 April 2013

NIST-Workshop 10 & 11 April 2013 NIST-Workshop 10 & 11 April 2013 EUROPEAN APPROACH TO OVERSIGHT OF "TRUST SERVICE PROVIDERS" Presented by Arno Fiedler, Member of European Telecommunications Standards Institute Electronic Signatures and

More information

STANDARDISIERUNG FÜR EIDAS IM MANDATE/460

STANDARDISIERUNG FÜR EIDAS IM MANDATE/460 STANDARDISIERUNG FÜR EIDAS IM MANDATE/460 TeleTrusT Signaturtag 17.09.2015 ETSI 2014. All rights reserved STANDARDISIERUNG FÜR EIDAS IM MANDATE/460 TeleTrusT Signaturtag 17.09.2015 ETSI 2014. All rights

More information

DS-05-2015: Trust eservices. The policy context: eidas Regulation

DS-05-2015: Trust eservices. The policy context: eidas Regulation DS-05-2015: Trust eservices The policy context: eidas Regulation Cybersecurity & Privacy Innovation Forum 2015 Brussels, 28 April 2015 Andrea SERVIDA DG CONNECT, European Commission Head of eidas Task

More information

Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market

Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market COM(2012)238 of 4.6.2012 ClubPSCo, Paris, 20.6.2012 Gérard GALLER

More information

ETSI TR 119 000 V0.0.3 (2014-01)

ETSI TR 119 000 V0.0.3 (2014-01) TR 119 000 V0.0.3 (2014-01) TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); Rationalised structure for Electronic Signature Standardisation COMPLETE DRAFT FOR PUBLIC REVIEW UNTIL 7 MARCH

More information

Implementation of eidas through Member States Supervisory Bodies

Implementation of eidas through Member States Supervisory Bodies Implementation of eidas through Member States Supervisory Bodies Riccardo Genghini - ETSI TC ESI & CEN-ETSI e-sign Coord. Group Chairman CA Day Berlin June 09 th, 2015 ETSI 2013. All rights reserved 2

More information

Qualified Time Stamping and eregistered Delivery Services Overall considerations

Qualified Time Stamping and eregistered Delivery Services Overall considerations eias Study on an electronic identification, authentication and signature policy Qualified Time Stamping and eregistered Delivery Services Overall considerations Building blocks for secondary legislation

More information

ETSI TC ESI PRESENTATION TO CAB FORUM. ETSI 2015. All rights reserved

ETSI TC ESI PRESENTATION TO CAB FORUM. ETSI 2015. All rights reserved ETSI TC ESI PRESENTATION TO CAB FORUM Iñigo Barreira March 2015 meeting, Cupertino ETSI 2015. All rights reserved Index ETSI Deliverables. Dates ETSI audits eidas timeline: Qualified web site certificates

More information

esignature building block Introduction to the Connecting Europe Facility DIGIT Directorate-General for Informatics

esignature building block Introduction to the Connecting Europe Facility DIGIT Directorate-General for Informatics Introduction to the Connecting Europe Facility esignature building block DIGIT Directorate-General for Informatics DG CONNECT Directorate-General for Communications Networks, Content and Technology February

More information

TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); The framework for standardization of signatures: overview

TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); The framework for standardization of signatures: overview TR 119 000 V1.2.1 (2016-04) TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); The framework for standardization of signatures: overview 2 TR 119 000 V1.2.1 (2016-04) Reference RTR/ESI-0019000v121

More information

Electronic signature and compliance assurance: what s new?

Electronic signature and compliance assurance: what s new? Electronic signature and compliance assurance: what s new? Ignacio ( Nacho ) Alamillo Domingo, CISA, CISM, ITIL-F ISACA Valencia Chapter Research Director Astrea Managing Partner March 2013 2 Table of

More information

Security framework. Guidelines for trust services providers Part 1. Version 1.0 December 2013

Security framework. Guidelines for trust services providers Part 1. Version 1.0 December 2013 Security framework Guidelines for trust services providers Part 1 Version 1.0 December 2013 European Union Agency for Network and Information Security www.enisa.europa.eu Security framework Guidelines

More information

ETSI TS 102 640-3 V1.1.1 (2008-10) Technical Specification

ETSI TS 102 640-3 V1.1.1 (2008-10) Technical Specification TS 102 640-3 V1.1.1 (2008-10) Technical Specification Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Architecture, Formats and Policies; Part 3: Information Security

More information

ETSI TS 102 640-3 V2.1.1 (2010-01) Technical Specification

ETSI TS 102 640-3 V2.1.1 (2010-01) Technical Specification TS 102 640-3 V2.1.1 (2010-01) Technical Specification Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Part 3: Information Security Policy Requirements for REM Management

More information

Expert Meeting on CYBERLAWS AND REGULATIONS FOR ENHANCING E-COMMERCE: INCLUDING CASE STUDIES AND LESSONS LEARNED. 25-27 March 2015.

Expert Meeting on CYBERLAWS AND REGULATIONS FOR ENHANCING E-COMMERCE: INCLUDING CASE STUDIES AND LESSONS LEARNED. 25-27 March 2015. Expert Meeting on CYBERLAWS AND REGULATIONS FOR ENHANCING E-COMMERCE: INCLUDING CASE STUDIES AND LESSONS LEARNED 25-27 March 2015 eidas Regulation By Alessandra Sbordoni Legal Officer, eidas Task Force

More information

Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market

Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (COM(2012 238 final) {SWD(2012) 135 final} {SWD(2012) 136 final} Andrea SERVIDA

More information

DECREE 132 of the National Security Authority. dated from 26 March 2009

DECREE 132 of the National Security Authority. dated from 26 March 2009 DECREE 132 of the National Security Authority dated from 26 March 2009 on the conditions for providing accredited certification services and requirements for an audit, the extent of an audit and the qualification

More information

ONR CEN/TS 419241. Security Requirements for Trustworthy Systems Supporting Server Signing (prcen/ts 419241:2013) DRAFT ICS 35.240.

ONR CEN/TS 419241. Security Requirements for Trustworthy Systems Supporting Server Signing (prcen/ts 419241:2013) DRAFT ICS 35.240. ICS 35.240.99 DRAFT ONR CEN/TS 419241 Security Requirements for Trustworthy Systems Supporting Server Signing (prcen/ts 419241:2013) Sicherheitsanforderungen für Vertrauenswürdige Systeme, die Serversignaturen

More information

Submitted to the EC on 03/06/2012. COMPETITIVENESS AND INNOVATION FRAMEWORK PROGRAMME ICT Policy Support Programme (ICT PSP) e-codex

Submitted to the EC on 03/06/2012. COMPETITIVENESS AND INNOVATION FRAMEWORK PROGRAMME ICT Policy Support Programme (ICT PSP) e-codex Submitted to the EC on 03/06/2012 COMPETITIVENESS AND INNOVATION FRAMEWORK PROGRAMME ICT Policy Support Programme (ICT PSP) e-codex e-justice Communication via Online Data Exchange ICT PSP call identifier:

More information

Protection Profiles for TSP cryptographic modules Part 1: Overview

Protection Profiles for TSP cryptographic modules Part 1: Overview Date: 2015-08 prts 419221-1:2015 Protection Profiles for TSP cryptographic modules Part 1: Overview Document type: Technical Specification Document language: E Contents Introduction...3 1 Scope...4 2 References...4

More information

Fact sheet: sa Certipost nv. Certipost Panel Presentation European Commission. Company. Activities based on 2 pillars: Clients.

Fact sheet: sa Certipost nv. Certipost Panel Presentation European Commission. Company. Activities based on 2 pillars: Clients. Certipost Panel Presentation European Commission Bart Callens Product and Sales Manager Document Protection Services 1 Fact sheet: sa Certipost nv Company Shareholders De Post/La Poste, 50% Belgacom, 50%

More information

Secure Information Technology Center Signature verification and digital services

Secure Information Technology Center Signature verification and digital services Secure Information Technology Center Signature verification and digital services Herbert Leitold, A-SIT Study Visit Georgian Delegation Vienna, 16 th February 2015 Zentrum für sichere Informationstechnologie

More information

ETSI TS 102 640-3 V2.1.2 (2011-09)

ETSI TS 102 640-3 V2.1.2 (2011-09) TS 102 640-3 V2.1.2 (2011-09) Technical Specification Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Part 3: Information Security Policy Requirements for REM Management

More information

Trusted e-id Infrastructures and services in EU

Trusted e-id Infrastructures and services in EU Trusted e-id Infrastructures and services in EU Recommendations for Trusted Provision of e-government services European Union Agency for Network and Information Security www.enisa.europa.eu About ENISA

More information

Draft SR 019 020 V0.0.4 (2013-11)

Draft SR 019 020 V0.0.4 (2013-11) SPECIAL REPORT Rationalised Framework of Standards for Advanced Electronic Signatures in Mobile Environment STABLE DRAFT FOR PUBLIC REVIEW UNTIL 15 JANUARY 2014 Download the template for comments: http://docbox.etsi.org/esi/open/latest_drafts/templatefor-comments.doc

More information

Technical Specification Electronic Signatures and Infrastructures (ESI); ASiC Baseline Profile

Technical Specification Electronic Signatures and Infrastructures (ESI); ASiC Baseline Profile TS 103 174 V2.2.1 (2013-06) Technical Specification Electronic Signatures and Infrastructures (ESI); ASiC Baseline Profile 2 TS 103 174 V2.2.1 (2013-06) Reference RTS/ESI-0003174v221 Keywords ASiC, electronic

More information

Regulation on electronic identification and trust services for electronic transactions in the internal market

Regulation on electronic identification and trust services for electronic transactions in the internal market Informationsgesellschaft, Telekommunikation Regulation on electronic identification and trust services for electronic transactions in the internal market Meaning of the EU-Regulation for the national legal

More information

SSLPost Electronic Document Signing

SSLPost Electronic Document Signing SSLPost Electronic Document Signing Overview What is a Qualifying Advanced Electronic Signature (QAES)? A Qualifying Advanced Electronic Signature, is a specific type of digital electronic signature, that

More information

26.3.2014 A7-0365/133

26.3.2014 A7-0365/133 26.3.2014 A7-0365/133 Amendment 133 Amalia Sartori on behalf of the Committee on Industry, Research and Energy Report A7-0365/2013 Marita Ulvskog Electronic identification and trust services for electronic

More information

trust and confidence "draw me a sheep" POLICY AND REGULATION FOR EUROPE

trust and confidence draw me a sheep POLICY AND REGULATION FOR EUROPE trust and confidence "draw me a sheep" POLICY AND REGULATION FOR EUROPE new regulation eidas... "...told him that she was the only one of her kind in all the universe" POLICY AND REGULATION FOR EUROPE

More information

ETSI SR 003 091 V1.1.2 (2013-03)

ETSI SR 003 091 V1.1.2 (2013-03) SR 003 091 V1.1.2 (2013-03) Special Report Electronic Signatures and Infrastructures (ESI); Recommendations on Governance and Audit Regime for CAB Forum Extended Validation and Baseline Certificates 2

More information

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof, 28.8.2014 Official Journal of the European Union L 257/73 REGULATION (EU) No 910/2014 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 July 2014 on electronic identification and trust services for electronic

More information

Prof. Udo Helmbrecht

Prof. Udo Helmbrecht Prof. Udo Helmbrecht Guiding EU Cybersecurity from Policy to Implementation Udo Helmbrecht Executive Director Information Security for the Public Sector 2015 Stockholm 02/09/15 European Union Agency for

More information

CEF Building blocks. Informatics. Joao Rodrigues Frade DIGIT.B4. CEF Project and Architecture Office Directorate-General for Informatics

CEF Building blocks. Informatics. Joao Rodrigues Frade DIGIT.B4. CEF Project and Architecture Office Directorate-General for Informatics CEF Building blocks Joao Rodrigues Frade DIGIT.B4 CEF Project and Architecture Office Directorate-General for AGENDA CEF at a glance CEF reuse logic CEF building blocks A fully functioning Digital Single

More information

Smart Open Services for European Patients Open ehealth initiative for a European large scale pilot of patient summary and electronic prescription

Smart Open Services for European Patients Open ehealth initiative for a European large scale pilot of patient summary and electronic prescription Smart Open Services for European Patients Open ehealth initiative for a European large scale pilot of patient summary and electronic prescription Deliverable: Work Package Document WP3.7 D.3.7.2. FINAL

More information

Secure Signature Creation Device Protect & Sign Personal Signature, version 4.1

Secure Signature Creation Device Protect & Sign Personal Signature, version 4.1 Zentrum für sichere Informationstechnologie Austria Secure Information Technology Center Austria A-1030 Wien, Seidlgasse 22 / 9 Tel.: (+43 1) 503 19 63 0 Fax: (+43 1) 503 19 63 66 A-8010 Graz, Inffeldgasse

More information

Rolling out eidas Regulation (EU) 910/2014. Boosting trust & security in the Digital Single Market

Rolling out eidas Regulation (EU) 910/2014. Boosting trust & security in the Digital Single Market Rolling out eidas Regulation (EU) 910/2014 Boosting trust & security in the Digital Single Market Trust in the Digital World 2016 Conference 15 June 2016 The Hague (NL) Andrea SERVIDA DG CONNECT, European

More information

Rubrica legale - ICT Security Maggio 2004 Autore: Daniela Rocca (SG&A) Gianluca Ramunno (Politecnico di Torino)

Rubrica legale - ICT Security Maggio 2004 Autore: Daniela Rocca (SG&A) Gianluca Ramunno (Politecnico di Torino) ubrica legale - ICT Security Maggio 2004 The standardisation effort in CEN/SSS E-Sign workshop In 1999 the European Commission launched the EESSI (Euroepan Electronic Signature Standardisation Initiative)

More information

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke Agenda eidas Regulation TR-03110 V2.20 German ID card POSeIDAS Summary cryptovision mindshare 2015: eidas

More information

View from a European Trust Service Provider Server Signing: Return of experience and certification strategy

View from a European Trust Service Provider Server Signing: Return of experience and certification strategy View from a European Trust Service Provider Server Signing: Return of experience and certification strategy January 16, 2014 - Berlin Thibault de Valroger VP Strategy & Development OPENTRUST Thibault.devalroger@opentrust.com

More information

FOR A PAPERLESS FUTURE. Petr DOLEJŠÍ Senior Solution Consultant SEFIRA Czech Republic

FOR A PAPERLESS FUTURE. Petr DOLEJŠÍ Senior Solution Consultant SEFIRA Czech Republic FOR A PAPERLESS FUTURE Petr DOLEJŠÍ Senior Solution Consultant SEFIRA Czech Republic PAPER IS EVERYWHERE WHY IS THAT? Please no more! Every large organization is typically large paper producer Banks, insurance,

More information

Secure Signature Creation Devices (SSCDs)

Secure Signature Creation Devices (SSCDs) Secure Signature Creation Devices (SSCDs) from different approaches Dr. István Zsolt BERTA istvan.berta@microsec.hu Microsec Ltd. Requirements for SSCDs Annex III of the e-signature Directive, in plain

More information

ETSI TS 102 573 V1.1.1 (2007-07)

ETSI TS 102 573 V1.1.1 (2007-07) TS 102 573 V1.1.1 (2007-07) Technical Specification Electronic Signatures and Infrastructures (ESI); Policy requirements for trust service providers signing and/or storing data for digital accounting 2

More information

LEGAL FRAMEWORK FOR E-SIGNATURE IN LITHUANIA AND ENVISAGED CHANGES OF THE NEW EU REGULATION

LEGAL FRAMEWORK FOR E-SIGNATURE IN LITHUANIA AND ENVISAGED CHANGES OF THE NEW EU REGULATION LEGAL FRAMEWORK FOR E-SIGNATURE IN LITHUANIA AND ENVISAGED CHANGES OF THE NEW EU REGULATION Aušra Kumetaitienė Head of Information Society Development Division Tomas Jakimavičius Telecommunications and

More information

Auditor view about ETSI and WebTrust criteria. Christoph SUTTER

Auditor view about ETSI and WebTrust criteria. Christoph SUTTER Auditor view about ETSI and WebTrust criteria Christoph SUTTER Outline 1. Conformity Assessment (in general) relevant standards criteria / normative document certification object (here certification service

More information

Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market

Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market [COM(2012) 238 final] {SWD(2012) 135 final} {SWD(2012) 136 final} Andrea SERVIDA

More information

ETSI TS 102 778-1 V1.1.1 (2009-07) Technical Specification

ETSI TS 102 778-1 V1.1.1 (2009-07) Technical Specification TS 102 778-1 V1.1.1 (2009-07) Technical Specification Electronic Signatures and Infrastructures (ESI); PDF Advanced Electronic Signature Profiles; Part 1: PAdES Overview - a framework document for PAdES

More information

Digital signature and e-government: legal framework and opportunities. Raúl Rubio Baker & McKenzie

Digital signature and e-government: legal framework and opportunities. Raúl Rubio Baker & McKenzie Digital signature and e-government: legal framework and opportunities Raúl Rubio Baker & McKenzie e-government concept Utilization of Information and Communication Technologies (ICTs) to improve and/or

More information

COMMISSION OF THE EUROPEAN COMMUNITIES

COMMISSION OF THE EUROPEAN COMMUNITIES EN EN EN COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 28.11.2008 COM(2008) 798 final COMMUNICATION FROM THE COMMISSION TO THE COUNCIL, THE EUROPEAN PARLIAMENT, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE

More information

EUROPEAN PARLIAMENT AND COUNCIL DIRECTIVE. on a common framework for electronic signatures

EUROPEAN PARLIAMENT AND COUNCIL DIRECTIVE. on a common framework for electronic signatures COMMISSION OF THE EUROPEAN COMMUNITIES Brussels, 29.04.1999 COM(1999) 195 fmal 98/0191(COD) Amended proposal for a EUROPEAN PARLIAMENT AND COUNCIL DIRECTIVE on a common framework for electronic signatures

More information

JA to support the ehealth Network

JA to support the ehealth Network JA to support the ehealth Network ehealth Network & ehgi Directive 2011/24/EU of the European Parliament and of the Council on the application of patients` rights in cross-border healtcare 08.05.2015 2

More information

In accordance with article 11 of the Law on Electronic Signature (Official Gazette of the Republic of Serbia No. 135/04), REGULATION

In accordance with article 11 of the Law on Electronic Signature (Official Gazette of the Republic of Serbia No. 135/04), REGULATION In accordance with article 11 of the Law on Electronic Signature (Official Gazette of the Republic of Serbia No. 135/04), the Minister of Telecommunications and Information Society hereby promulgates REGULATION

More information

ETSI TS 119 403 V2.1.1 (2014-11)

ETSI TS 119 403 V2.1.1 (2014-11) TS 119 403 V2.1.1 (2014-11) TECHNICAL SPECIFICATION Electronic Signatures and Infrastructures (ESI); Trust Service Provider Conformity Assessment - Requirements for conformity assessment bodies assessing

More information

ETSI TS 102 042 V2.4.1 (2013-02)

ETSI TS 102 042 V2.4.1 (2013-02) TS 102 042 V2.4.1 (2013-02) Technical Specification Electronic Signatures and Infrastructures (ESI); Policy requirements for certification authorities issuing public key certificates 2 TS 102 042 V2.4.1

More information

Part 2: ICT security standards and guidance documents

Part 2: ICT security standards and guidance documents Part 2: ICT security standards and guidance documents Version 3.0 April, 2007 Introduction The purpose of this part of the Security Standards Roadmap is to provide a summary of existing, approved ICT security

More information

ROADMAP. A Pan-European framework for electronic identification, authentication and signature

ROADMAP. A Pan-European framework for electronic identification, authentication and signature TITLE OF THE INITIATIVE ROADMAP A Pan-European framework for electronic identification, authentication and signature TYPE OF INITIATIVE CWP Non-CWP Implementing act/delegated act LEAD DG RESPONSIBLE UNIT

More information

Electronic Signature. István Zsolt BERTA istvan@berta.hu. Public Key Cryptographic Primi4ves

Electronic Signature. István Zsolt BERTA istvan@berta.hu. Public Key Cryptographic Primi4ves Electronic Signature István Zsolt BERTA istvan@berta.hu Public Key Cryptographic Primi4ves 1 Electronic Signatures - Contents 1. Public key cryptography primiaves 2. CerAficates, CerAficate AuthoriAes,

More information

ETSI TS 101 456 V1.4.3 (2007-05)

ETSI TS 101 456 V1.4.3 (2007-05) TS 101 456 V1.4.3 (2007-05) Technical Specification Electronic Signatures and Infrastructures (ESI); Policy requirements for certification authorities issuing qualified certificates 2 TS 101 456 V1.4.3

More information

PKI - current and future

PKI - current and future PKI - current and future Workshop for Japan Germany Information security Yuichi Suzuki yuich-suzuki@secom.co.jp SECOM IS Laboratory Yuichi Suzuki (SECOM IS Lab) 1 Current Status of PKI in Japan Yuichi

More information

CERTIFICATION PRACTICE STATEMENT UPDATE

CERTIFICATION PRACTICE STATEMENT UPDATE CERTIFICATION PRACTICE STATEMENT UPDATE Reference: IZENPE-CPS UPDATE Version no: v 5.03 Date: 10th March 2015 IZENPE 2015 This document is the property of Izenpe. It may only be reproduced in its entirety.

More information

Land Registry. Version 4.0 10/09/2009. Certificate Policy

Land Registry. Version 4.0 10/09/2009. Certificate Policy Land Registry Version 4.0 10/09/2009 Certificate Policy Contents 1 Background 5 2 Scope 6 3 References 6 4 Definitions 7 5 General approach policy and contract responsibilities 9 5.1 Background 9 5.2

More information

ETSI TS 102 778-3 V1.1.2 (2009-12) Technical Specification

ETSI TS 102 778-3 V1.1.2 (2009-12) Technical Specification TS 102 778-3 V1.1.2 (2009-12) Technical Specification Electronic Signatures and Infrastructures (ESI); PDF Advanced Electronic Signature Profiles; Part 3: PAdES Enhanced - PAdES-BES and PAdES-EPES Profiles

More information

ETSI EN 319 401 V1.1.1 (2013-01)

ETSI EN 319 401 V1.1.1 (2013-01) EN 319 401 V1.1.1 (2013-01) European Standard Electronic Signatures and Infrastructures (ESI); General Policy Requirements for Trust Service Providers supporting Electronic Signatures 2 EN 319 401 V1.1.1

More information

Study on Mutual Recognition of esignatures: update of Country Profiles Icelandic country profile

Study on Mutual Recognition of esignatures: update of Country Profiles Icelandic country profile Study on Mutual Recognition of esignatures: update of Country Profiles Icelandic country profile This report / paper was prepared for the IDABC programme by: Coordinated by: Hans Graux (time.lex), Brigitte

More information

European Electronic Identity Practices

European Electronic Identity Practices European Electronic Identity Practices Country Update of Austria Speaker: Herbert Leitold Date: 9 Nov 2004 PART I: Overview Table of contents Overview of Citizen Card initiatives and its status (Summary

More information

Digital Signatures in Reality. Tarvi Martens SK

Digital Signatures in Reality. Tarvi Martens SK Digital Signatures in Reality Tarvi Martens SK Free-flowing digital documents Estonia has deployed digitally signed documents which are recognised universally. These are: Perfectly legal For use in arbitrary

More information

Danske Bank Group Certificate Policy

Danske Bank Group Certificate Policy Document history Version Date Remarks 1.0 19-05-2011 finalized 1.01 15-11-2012 URL updated after web page restructuring. 2 Table of Contents 1. Introduction... 4 2. Policy administration... 4 2.1 Overview...

More information

ETSI TS 102 640-4 V2.1.1 (2010-01) Technical Specification

ETSI TS 102 640-4 V2.1.1 (2010-01) Technical Specification TS 102 640-4 V2.1.1 (2010-01) Technical Specification Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM) Part 4: REM-MD Conformance Profiles 2 TS 102 640-4 V2.1.1 (2010-01)

More information

ETSI EN 319 403 V2.2.2 (2015-08)

ETSI EN 319 403 V2.2.2 (2015-08) EN 319 403 V2.2.2 (2015-08) EUROPEAN STANDARD Electronic Signatures and Infrastructures (ESI); Trust Service Provider Conformity Assessment - Requirements for conformity assessment bodies assessing Trust

More information

TTP.NL Scheme. for management system certification. of Trust Service Providers issuing. Qualified Certificates for Electronic Signatures,

TTP.NL Scheme. for management system certification. of Trust Service Providers issuing. Qualified Certificates for Electronic Signatures, TTP.NL Scheme for management system certification of Trust Service Providers issuing Qualified Certificates for Electronic Signatures, Public Key Certificates, Website Certificates and / or Time-stamp

More information

Guidelines for the use of electronic signature

Guidelines for the use of electronic signature Republic of Albania National Authority for Electronic Certification Guidelines for the use of electronic signature Guide Nr. 001 September 2011 Version 1.3 Guidelines for the use of electronic signature

More information

ETSI TS 102 778 V1.1.1 (2009-04) Technical Specification

ETSI TS 102 778 V1.1.1 (2009-04) Technical Specification TS 102 778 V1.1.1 (2009-04) Technical Specification Electronic Signatures and Infrastructures (ESI); PDF Advanced Electronic Signature Profiles; CMS Profile based on ISO 32000-1 2 TS 102 778 V1.1.1 (2009-04)

More information

Implementing & Delegated Acts

Implementing & Delegated Acts Implementing & Delegated Acts Some Principles jos.dumortier@timelex.eu 1 Executive Acts: why? filling in the gaps or dealing with details jos.dumortier@timelex.eu 2 Legislative Process Commission PROPOSES

More information

DSS: tool for Europe-wide esignature interoperability. November 2015 Miguel Alvarez Rodríguez- ISA Unit

DSS: tool for Europe-wide esignature interoperability. November 2015 Miguel Alvarez Rodríguez- ISA Unit DSS: tl fr Eurpe-wide esignature interperability Nvember 2015 Miguel Alvarez Rdríguez- ISA Unit Cntext Services Directive bligatin n MS t make available administrative prcedures nline. Tw streams t facilitate

More information

Legality of Electronic Signatures and implementation of electronic building permits

Legality of Electronic Signatures and implementation of electronic building permits Legality of Electronic Signatures and implementation of electronic building permits in Republic of Macedonia CPD of ECEC E-Building Permits and Electronic Signatures 28 th January 2016 Agenda Legal background

More information

De Nieuwe Code voor Informatiebeveiliging

De Nieuwe Code voor Informatiebeveiliging De Nieuwe Code voor Informatiebeveiliging Piet Donga, ING Voorzitter NEN NC 27 - IT Security 1 Agenda Standardisation of Information security The new Code of Practice for Information Security The Code

More information

How To Understand And Understand The Certificate Authority (Ca)

How To Understand And Understand The Certificate Authority (Ca) TS 102 042 V1.1.1 (2002-04) Technical Specification Policy requirements for certification authorities issuing public key certificates 2 TS 102 042 V1.1.1 (2002-04) Reference DTS/SEC-004006 Keywords e-commerce,

More information

Electronic Signature: Conform to the CC Anytime, Anywhere, with any Device September 20, 2012

Electronic Signature: Conform to the CC Anytime, Anywhere, with any Device September 20, 2012 Electronic Signature: Conform to the CC Anytime, Anywhere, with any Device September 20, 2012 DICTAO 152, avenue Malakoff 75116 PARIS, France Tel. : +33 (0)1 73 00 26 10 Internet : www.dictao.com Agenda

More information

ETSI TR 103 123 V1.1.1 (2012-11)

ETSI TR 103 123 V1.1.1 (2012-11) TR 103 123 V1.1.1 (2012-11) Technical Report Electronic Signatures and Infrastructures (ESI); Guidance for Auditors and CSPs on TS 102 042 for Issuing Publicly-Trusted TLS/SSL Certificates 2 TR 103 123

More information

Securing Identities & Trust

Securing Identities & Trust Securing Identities & Trust Agenda About Safelayer Identities & Trust eidas (eid, Authentication and Signature) Use case: Izenpe Mobile eidas services Safelayer Demo Portal Q& A? WWW.SAFELAYER.COM 2 About

More information

IT-Security All safe and sound?

IT-Security All safe and sound? IT-Security All safe and sound? The building blocks for secure E-Government Dr. Vienna, 20.10.2014 Das E-Government Innovationszentrum ist eine gemeinsame Einrichtung des Bundeskanzleramtes und der TU

More information

Making Digital Signatures Work across National Borders

Making Digital Signatures Work across National Borders Making Digital Signatures Work across National Borders Jon Ølnes, Anette Andresen, Leif Buene, Olga Cerrato, Håvard Grindheim DNV (Det Norske Veritas), Norway DNV trusted third party for 140 years Det

More information

Egypt s E-Signature & PKInfrastructure

Egypt s E-Signature & PKInfrastructure EGYPT-MCIT ITIDA Egypt s E-Signature & PKInfrastructure Seminar on Electronic Signature Algeria 8-9 Dec. 2009 By: Hisham Mohamed Abdel Wahab Head of the E-Signature CA Licensing ITIDA- MCIT EGYPT Email:

More information

Certificate Path Validation

Certificate Path Validation Version 1.4 NATIONAL SECURITY AUTHORITY Version 1.4 Certificate Path Validation 19 th November 2006 No.: 1891/2006/IBEP-011 NSA Page 1/27 NATIONAL SECURITY AUTHORITY Department of Information Security

More information

CERTIFICATE REVIEW RECORD

CERTIFICATE REVIEW RECORD REVIEW HUNGUARD Informatics and IT R&D and General Service Provider Ltd. as a certification authority assigned by the assignment document No. 001/2010 of the Minister of the Prime Minister s Office of

More information

IAS2. ets Market analysis

IAS2. ets Market analysis IAS2 Study to support the implementation of a pan-european framework on electronic identification and trust services for electronic transactions in the internal market SMART 2012/0001 ets Market analysis

More information

e-szigno Digital Signature Application

e-szigno Digital Signature Application MICROSEC Software Development Ltd. e-szigno Digital Signature Application Microsec Software Development Ltd. www.e-szigno.hu www.microsec.hu 1031 Budapest, Záhony utca 7. (+36-1) 505-4444 Cg. 01-09-078353

More information

Best prac*ces in Cer*fying and Signing PDFs

Best prac*ces in Cer*fying and Signing PDFs over 10 years of securing identities, web sites & transactions Best prac*ces in Cer*fying and Signing PDFs Paul van Brouwershaven Business Development Director EMEA, GlobalSign @vanbroup on TwiEer INTERNATIONAL

More information

Study on Mutual Recognition of esignatures: update of Country Profiles Analysis & assessment report

Study on Mutual Recognition of esignatures: update of Country Profiles Analysis & assessment report Study on Mutual Recognition of esignatures: update of Country Profiles This report / paper was prepared for the IDABC programme by: Coordinated by: Hans Graux (time.lex), Guy Lambert (Siemens), Brigitte

More information

Landscape of eid in Europe in 2013

Landscape of eid in Europe in 2013 Landscape of eid in Europe in 2013 July 2013 Eurosmart White Paper Contents Executive Summary 3 1. Purpose of the document 3 2. EU regulation 3 3. EU Member States identification policies 4 3.1. National

More information

Code of Practice on Electronic Invoicing in the EU

Code of Practice on Electronic Invoicing in the EU CEN/WS einvoicing Phase 3 Date: 2011-11 CEN Workshop AgreementTC WI Secretariat: NEN Code of Practice on Electronic Invoicing in the EU Status: for public review (23 November 2011-23 January 2012) ICS:

More information

SECURE AND EFFICIENT PROCESSING OF ELECTRONIC DOCUMENTS IN THE CLOUD

SECURE AND EFFICIENT PROCESSING OF ELECTRONIC DOCUMENTS IN THE CLOUD SECURE AND EFFICIENT PROCESSING OF ELECTRONIC DOCUMENTS IN THE CLOUD Klaus Stranacher, Bernd Zwattendorfer, Vesna Krnjic Graz University of Technology, E-Government Innovation Center, EGIZ Inffeldgasse

More information

Smart grid cyber security certification

Smart grid cyber security certification Smart grid cyber security certification 1 Introduction On 30th September 2014 ENISA organised a workshop where the results of the report on Smart grid security certification (to be published by end of

More information

Představení nařízení EU eidas a možný přístup ČR k implementaci. Ondřej Felix Hlavní architekt egovernmentu MV

Představení nařízení EU eidas a možný přístup ČR k implementaci. Ondřej Felix Hlavní architekt egovernmentu MV Představení nařízení EU eidas a možný přístup ČR k implementaci Ondřej Felix Hlavní architekt egovernmentu MV O čem to je This Regulation seeks to enhance trust in electronic transactions in the internal

More information

ETSI TS 102 176-2 V1.2.1 (2005-07)

ETSI TS 102 176-2 V1.2.1 (2005-07) TS 102 176-2 V1.2.1 (2005-07) Technical Specification Electronic Signatures and Infrastructures (ESI); Algorithms and Parameters for Secure Electronic Signatures; Part 2: Secure channel protocols and algorithms

More information

Questions & Answers. on e-cohesion Policy in European Territorial Cooperation Programmes. (Updated version, May 2013)

Questions & Answers. on e-cohesion Policy in European Territorial Cooperation Programmes. (Updated version, May 2013) Questions & Answers on e-cohesion Policy in European Territorial Cooperation Programmes (Updated version, May 2013) This fact sheet was drafted jointly by INTERACT and European Commission (DG Regional

More information

QuoVadis Group. EUGridPMA Update September 2014

QuoVadis Group. EUGridPMA Update September 2014 QuoVadis Group EUGridPMA Update September 2014 Overview Founded in 1999 in Bermuda, with particular focus providing PKI managed services to multinational organisations More than 3,500 customers Operations

More information

AGENDA ITEM 15-16 : ELECTRONIC SIGNATURE

AGENDA ITEM 15-16 : ELECTRONIC SIGNATURE SCREENING CHAPTER 10 Country Session: 13- Content Legislation Main Points of Turkish Electronic Signature Legislation Electronic Certificate Service Providers and Market Standardization Aspect of Electronic

More information

ETSI TS 102 640-1 V2.1.1 (2010-01) Technical Specification

ETSI TS 102 640-1 V2.1.1 (2010-01) Technical Specification TS 102 640-1 V2.1.1 (2010-01) Technical Specification Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Part 1: Architecture 2 TS 102 640-1 V2.1.1 (2010-01) Reference RTS/ESI-000064-1

More information