Long-term archiving of electronically signed documents in Hungary



Similar documents
e-szigno Digital Signature Application

Digital Signature Verification using Historic Data

CERTIFICATION PRACTICE STATEMENT UPDATE

Secure Signature Creation Devices (SSCDs)

PKI - current and future

E-signature in the Austrian cadastral process

Electronic Signature. István Zsolt BERTA Public Key Cryptographic Primi4ves

Guidelines for the use of electronic signature

Best prac*ces in Cer*fying and Signing PDFs

HKUST CA. Certification Practice Statement

OB10 - Digital Signing and Verification

Long term electronic signatures or documents retention

Study on Mutual Recognition of esignatures: update of Country Profiles Icelandic country profile

ACT. of 15 March 2002

Business Issues in the implementation of Digital signatures

How to Time Stamp PDF and Microsoft Office 2010/2013 Documents with the Time Stamp Server

User Guide of edox Archiver, the Electronic Document Handling Gateway of

Digital Signature Service. e-contract.be BVBA 2 september 2015

The Challenge Handling a lot of paper documents

Submitted to the EC on 03/06/2012. COMPETITIVENESS AND INNOVATION FRAMEWORK PROGRAMME ICT Policy Support Programme (ICT PSP) e-codex

e-justice in Hungary Ferenc Zombor Deputy State Secretary Responsible for EU and International Justice Cooperation

Arkansas Department of Information Systems Arkansas Department of Finance and Administration

ETSI TR V1.1.1 ( )

Ericsson Group Certificate Value Statement

Mobile OTPK Technology for Online Digital Signatures. Dec 15, 2015

The Estonian ID Card and Digital Signature Concept

Brocade Engineering. PKI Tutorial. Jim Kleinsteiber. February 6, Page 1

INDEPENDENT AUDIT REPORT BASED ON THE REQUIREMENTS OF ETSI TS Aristotle University of Thessaloniki PKI ( WHOM IT MAY CONCERN

Digital legal archiving

esign Online Digital Signature Service

Hungarian Electronic Public Administration Interoperability Framework (MEKIK) Technical Standards Catalogue

State of Arkansas Policy Statement on the Use of Electronic Signatures by State Agencies June 2008

Digital Certificates (Public Key Infrastructure) Reshma Afshar Indiana State University

Public Key Infrastructure for a Higher Education Environment

Office of Inspector General

Securing Service Access with Digital Certificates

Estonie Loi sur la signature électronique Entrée en vigueur le 15 décembre 2000

DIRECTOR GENERAL OF THE LITHUANIAN ARCHIVES DEPARTMENT UNDER THE GOVERNMENT OF THE REPUBLIC OF LITHUANIA

Fact sheet: sa Certipost nv. Certipost Panel Presentation European Commission. Company. Activities based on 2 pillars: Clients.

UNCITRAL United Nations Commission on International Trade Law Introduction to the law of electronic signatures

XML Advanced Electronic Signatures (XAdES)

Number of relevant issues

White Paper. Cloud Signing vs. Smartcard Signing

THE LAW OF THE REPUBLIC OF ARMENIA ON ELECTRONIC DOCUMENT AND ELECTRONIC SIGNATURE CHAPTER 1. GENERAL PROVISIONS. Article 1. The subject of the Law

The DoD Public Key Infrastructure And Public Key-Enabling Frequently Asked Questions

Certificate Path Validation

Public Key Infrastructure (PKI)

CERTIFICATES USER GUIDE

Digital Signatures in Reality. Tarvi Martens SK

Merchants and Trade - Act No 28/2001 on electronic signatures

The Supreme Court of Hawaii seeks public comment regarding proposals of the Hawaii Court Records Rules and Hawaii Electronic Filing and Service Rules.

Qualified Electronic Signatures Act (SFS 2000:832)

Introduction. About Image-X Enterprises. Overview of PKI Technology

APPLICATION FOR DIGITAL CERTIFICATE

Profession Practice Advice for the Profession

SYMANTEC NON-FEDERAL SHARED SERVICE PROVIDER PKI SERVICE DESCRIPTION

CERTIFICATION PRACTICE STATEMENT (CPS) SECURITY DATA SEGURIDAD EN DATOS Y FIRMA DIGITAL, S.A. Version 2.0

Processo Civile Telematico (On-line Civil Trial)

Concept of Electronic Approvals

TERMS OF USE FOR PUBLIC LAW CORPORATION PERSONAL CERTIFICATES FOR QUALIFIED DIGITAL SIGNATURE

SECURE DIGITAL SIGNATURES FOR APPRAISERS

DIGITAL SIGNATURE AS A TOOL TO ACHIEVE COMPETITIVE ADVANTAGE OF ORGANIZATION

CERTIMETIERSARTISANAT and ELECTRONIC SIGNATURE SERVICE SUBSCRIPTION CONTRACT SPECIFIC TERMS AND CONDITIONS

LAW OF MONGOLIA ON ELECTRONIC SIGNATURE

Apple Corporate Certificates Certificate Policy and Certification Practice Statement. Apple Inc.

An introduction to EJBCA and SignServer

Certum QCA PKI Disclosure Statement

Adding e to life Conveniences and Complexities

Adobe PDF for electronic records

Digital Signature: Efficient, Cut Cost and Manage Risk. Formula for Strong Digital Security

GEOSURE PROTECTION PLAN

24-7 Electronic Signature White Paper

White Paper. Digital signatures from the cloud Basics and Applications

Registration Practices Statement. Grid Registration Authority Approved December, 2011 Version 1.00

Federal Electronic Signature Law. (Signature Law - SigG)

Digital Signing without the Headaches

Microsoft Trusted Root Certificate: Program Requirements

Electronic Archive Information System

Future directions of the AusCERT Certificate Service

CERTIFICATE POLICIES (CP) Legal Person Certificate ICE SECURITY DATA SEGURIDAD EN DATOS Y FIRMA DIGITAL, S.A. CP

Incorporating Digital Signing & Encryption in Transactions in the Payment System of Sri Lanka

E-TUGRA INFORMATIC TECHNOLOGIES AND SERVICES CORP (E-TUGRA)

CERTIFICATE POLICIES (CP) Natural Person Certificate ICE SECURITY DATA SEGURIDAD EN DATOS Y FIRMA DIGITAL, S.A. CP

SSL BEST PRACTICES OVERVIEW

Electronic Signatures and Trusted Archival Services

Signature policy for TUPAS Witnessed Signed Document

CERTIFICATE POLICIES (CP) Public Functionary Certificate ICE SECURITY DATA SEGURIDAD EN DATOS Y FIRMA DIGITAL, S.A. CP

Publicly trusted certification authorities (CAs) confirm signers identities and bind their public key to a code signing certificate.

Implementation of qualified electronic signatures in the process of creating project and technical documentation. Austria. January 28 th 2016

Electronic Signature Law,

Neutralus Certification Practices Statement

TR-GRID CERTIFICATION AUTHORITY

National Register of Associations. Number CIF G

L A W ON ELECTRONIC DOCUMENT I. GENERAL PROVISIONS. Scope of the Law

e-tuğra CERTIFICATE POLICY E-Tuğra EBG Bilişim Teknolojileri ve Hizmetleri A.Ş. Version: 3.1 Validity Date: September, 2013 Update Date: 30/08/2013

Land Registry. Version /09/2009. Certificate Policy

Controller of Certification Authorities of Mauritius

CCBE POSITION ON THE PROPOSED ELECTRONIC IDENTITY AND

SECURITY IN ELECTRONIC COMMERCE MULTIPLE-CHOICE QUESTIONS

Transcription:

Long-term archiving of electronically signed documents in Hungary Dr. István Zsolt BERTA, PhD, MBA, CISA Microsec Ltd. HUNGARY istvan.berta@microsec.hu www.e-szigno.hu http://www.e-szigno.hu

Microsec Ltd. Founded in 1984, owned by six Hungarian individuals IT service provider of the Ministry of Justice (from 1990) Certification authority and time stamping authority (from 2002), issuing qualified certificates and timestamps (from 2005) We developed an application for the creation and verification of XAdES electronic signatures (e-szignó) We provide long-term archiving service for electronically signed documents (from 2007) 2

Hungarian law on electronic signatures It is based on EC directive 1999/93 Defines four electronic signature related services : issuance of digital certificates, issuance of signature creation devices, time stamping, long-term archiving. Providers of each service can qualified or non-qualified. Qualified service providers are supervised by the National Communications Authority Qualified signatures are assumed to be created by the signatory unless the opposite is proven Signatures archived by a qualified long-term archiving service provider are assumed to be valid unless the opposite is proven It does not cover other aspects of PKI (encryption, authentication) 3

The situation of PKI in Hungary Four commercial certificate authorities issue qualified certificates and timestamps One long-term archiving service provider (Microsec Ltd.) The Hungarian public administration has a dedicated root CA for public administration purposes only Regulations for e-signatures within the public administration: certificate profile, certificate policy, signature format (XAdES) Very few PKI applications in the public administration Hardy any e-billing applications due to awkward and/or conflicting (accounting e-signature) regulations Promising applications in the Hungarian jurisdiction... 4

Electronic firm registry system 5

Firm registry in Hungary The Hungarian firm registry is maintained by registry courts. Lawyers represent companies at registry courts (e.g. when founding a company) Registry courts communicate with other organizations (Tax Authority, Central Statistical Office, banks, etc.) 6

Electronic firm registry procedures From September 2005, lawyers are allowed to submit firm registry requests with qualified signatures to the registry courts. Such a request is an e-dossier containing: the request in an XML form, scanned documents of the firm with scanned handwritten signatures, electronic document with the electronic signature of the lawyer s client (very rare case), electronically signed statements from the Hungarian Treasury claiming that the necessary fees were paid, the entire e-dossier is signed with the lawyer s qualified electronic signature. 7

A signed request 8

Electronic firm registry procedures (2) official decision, signed by the judge dec judge at a registry court signed receipt req rcpt lawyer req Ministry of Justice firm registry service request signed by the lawyer 9

What do lawyers need for using it? A computer, Internet access, e-mail address, a scanner, a smart card (SSCD) and a qualified certificate, access to a time stamping service, a signature creation application for creating XAdES-T signatures, a permission from the Hungarian Bar Association. 10

Organizations connected to the system Organizations connected to the system include: Tax Authority (e.g. tax numbers are acquired automatically, notification on forcible collection, etc.) Central Statistical Office (statistical numbers are acquired automatically) Hungarian Treasury (electronically signed verifications on the payment of fees) All banks and financial institutions (a company s account number is automatically reported to the firm registry)... Communication with these organizations is based on (advanced) electronic signatures. These messages are created and processed by machines (except for the case of some smaller financial institutions). 11

Benefits of the electronic registry system The process became much faster data is entered only once, in the electronic system, certain requests must be processed in 2 days (30 days in the paper-based case) For lawyers: No queuing, open 24 hours a day Significantly less fees Submitting 3 or 4 requests a year electronically already covers the cost of the qualified electronic signature. It is expected that the use of this electronic system for firm registry requests shall become mandatory from 2008. 12

Problems There are problems with third parties (banks, other authorities) accepting the official decisions in an electronic form (with the qualified electronic signature of a judge). Some registry courts print the electronic documents for working. 13

In numbers... Currently 400 lawyers participate in the system (out of the 2-3000 lawyers who deal with company registration) 2000 electronic requests arrive monthly (out of 16000), it was less than 200 a year ago 14

The role of Microsec We developed and we operate the systems in the Ministry of Justice and at the registry courts. We developed and operate the software that other organizations user for interfacing with the system. We developed the signature creation applications. We supplied most lawyers with smart cards, certificates and we provide most of them with time stamping service. 15

Electronic signing and archiving at Hungarian notaries 16

Notaries and electronic signatures From 2006, all Hungarian notaries (and vice-notaries) are capable of creating qualified electronic signatures. Each Hungarian notary (and vice-notary) has: a smart card (SSCD), a qualified certificate, access to time stamping and OCSP services, a signature creation application (e-szignó) Notaries are capable of creating archive electronic signatures (XAdES-A format, using OCSP) 17

Why is long-term archiving necessary? An electronic signature is a mathematical transformation. This transformation is easy with a private key, it is hard without it. PKI provides means for proving that the private key was in possession of the right person at the time of signing. The validity of an electronic signature may become improvable if: the time of signing is not known (i.e. the signature is not time stamped), the certificate of the TSA expires, the certificate of the TSA gets revoked, or an algorithm used for signing or time stamping becomes insecure. This problem can be solved by placing additional time stamps (with a different TSA key or with different technology) on signed documents. 18

Long-term archiving at notaries All notarial deeds are signed with the qualified signature of the notary; The e-dossiers containing the signed deeds are archived in a (qualified) long-term archive; Paper-based notarial deeds are scanned, signed by notary and sent into our long-term archive; Electronic notarial deeds (there are very few of them yet) are directly sent into our long-term archive. Current legislation allows a notary to access the documents archived from the same office only; this may change in the future. 19

The long-term archiving service of Microsec Signed documents are submitted (and later accessed) through an SSL connection. Our long-term archiving service is based on the principles of the LTANS IETF working group. Encrypted documents are stored, they can be decrypted with the decryption key of corresponding notarial offices and by the archiving service (this latter is a very rare event). Our archiving service time stamps archived signatures regularly (or when necessary) and thus guarantees the long-term validity of electronic signatures. Archived documents contain PDFs. The long-term archiving service retains tools for displaying the PDFs exactly the same way even after a long period of time. 20

The role of Microsec We supplied all notaries with SSCD smart cards and qualified certificates. We provide them with time stamping and OCSP services. We provide them the necessary signature creation applications. We provide the long-term archiving service. 21

Summary There are certain applications in the Hungarian jurisdiction, where electronic signatures are successfully used. In the Hungarian firm registry system, companies can be registered in a purely electronic way, using qualified electronic signatures. Hungarian notaries use qualified electronic signatures for the long-term archiving of notarial deeds. Microsec Ltd. provided most of the software, hardware and the PKI services for these applications. 22

Long-term archiving of electronically signed documents in Hungary Dr. István Zsolt BERTA, PhD, MBA, CISA Microsec Ltd. HUNGARY istvan.berta@microsec.hu www.e-szigno.hu http://www.e-szigno.hu