PKI related technologies



Similar documents
e-szigno Digital Signature Application

Electronic invoicing. e-slog implementation in practice, expected impacts and future development. mag. Aljoša Jerman Blažič SETCCE

Long term electronic signatures or documents retention

Digital Signatures. Stefanie García Laule Security Product Management SAP AG

OB10 - Digital Signing and Verification

Digital Signature Verification using Historic Data

How to Time Stamp PDF and Microsoft Office 2010/2013 Documents with the Time Stamp Server

Electronic Commerce in Slovenian Economy. Dušan Zupančič

Compliance Response Edition 07/2009. SIMATIC WinCC V7.0 Compliance Response Electronic Records / Electronic Signatures. simatic wincc DOKUMENTATION

HIPAA Security Regulations: Assessing Vendor Capabilities and Negotiating Agreements re: PKI and Security

An introduction to EJBCA and SignServer

Best prac*ces in Cer*fying and Signing PDFs

Digital Signature: Efficient, Cut Cost and Manage Risk. Formula for Strong Digital Security

Effective and Compliant Storage

PKI - current and future

GlobalSign Enterprise Solutions

Number of relevant issues

d3 Document Management Solution

CERTIFICATION PRACTICE STATEMENT UPDATE

2009 ikeep Ltd, Morgenstrasse 129, CH-3018 Bern, Switzerland (

Exploring ADSS Server Signing Services

XML Advanced Electronic Signatures (XAdES)

iq.suite Crypt - Server-based encryption - Efficient encryption for Lotus Domino

U.S. FDA Title 21 CFR Part 11 Compliance Assessment of SAP Records Management

LOGICAL DATA MODEL FOR DISSEMINATION OF SPATIAL DATA

Technical Description. DigitalSign 3.1. State of the art legally valid electronic signature. The best, most secure and complete software for

<Insert Picture Here> Oracle Security Developer Tools (OSDT) August 2008

CLOUDSERVICES

PBS Information Lifecycle Management Solutions for SAP NetWeaver Business Intelligence 3.x and 7.x

BizTalk Server Adapters

Mobile OTPK Technology for Online Digital Signatures. Dec 15, 2015

Archiving for legal purposes. How to implement the new Belgian legislation to destroy physical invoices and use an electronic archive

Datasheet FUJITSU Security Solution Compliant Archiving SecDocs V2.3

Alliance Key Manager Solution Brief

White Paper. Digital signatures from the cloud Basics and Applications

OFFICE OF THE CONTROLLER OF CERTIFICATION AUTHORITIES TECHNICAL REQUIREMENTS FOR AUDIT OF CERTIFICATION AUTHORITIES

Electronic Signature. István Zsolt BERTA Public Key Cryptographic Primi4ves

Smart Plug-in for Siebel

Key Considerations for Documentation Management Technology. Learning from Local Experience

Global eid Developments. Detlef Eckert Chief Security Advisor Microsoft Europe, Middle East, and Africa

How To Use The Signamus Cloud Service For Business

Long-term archiving of electronically signed documents in Hungary

Annex 1. Production cycle of legal bills (E-Law) 23 rd November Federal Chancellery of Austria Brigitte Barotanyi

Embedding digital signature technology to other systems - Estonian practice. Urmo Keskel SK, DigiDoc Product Manager

Key & Data Storage on Mobile Devices

Digital Signing without the Headaches

1. What is Long-Term Docs... 5

PBS ContentLink. Easy and Flexible Connection between Storage, SharePoint and SAP Solutions

Communiqué 4. Standardized Global Content Management. Designed for World s Leading Enterprises. Industry Leading Products & Platform

Oracle WebCenter Content

UNDERSTANDING PKI: CONCEPTS, STANDARDS, AND DEPLOYMENT CONSIDERATIONS, 2ND EDITION

Digital certificates for public services

Full Compliance Contents

Certification Practice Statement

Global Client Access Managed Communications Solutions. JPMorgan - Global Client Access. Managed Internet Solutions (EC Gateway)

DJIGZO ENCRYPTION. Djigzo white paper

ECS SMART DOCUMENT PROCESSING

How To Understand And Understand The Basic Principles Of An Ansper System

Guardium Change Auditing System (CAS)

josh Archive! the software for archiving documents

NEMA Standards Publication PS 3 Supplement 41. Digital Imaging and Communications in Medicine (DICOM) Digital Signatures

CIPHERMAIL ENCRYPTION. CipherMail white paper

The syslog-ng Premium Edition 5LTS

Study on Mutual Recognition of esignatures: update of Country Profiles Icelandic country profile

ARBES ECM A MODERN ENTERPRISE SYSTEM. Designed for Digitalizing, Preparing, Managing, Archiving and Collaborating on Documents and Content.

PAdES signatures in itext and the road ahead. Paulo Soares

Data Protection: From PKI to Virtualization & Cloud

LDAPCON Sébastien Bahloul

edocumentus Solutions IBM maximo DMS for MAXIMO

PBS Analysis Tools. Effective Database Analysis for SAP ERP and SAP BW. Dr. Klaus Zimmer, PBS Software GmbH

PE Training and Event Management. SAP ERP Central Component

In accordance with article 11 of the Law on Electronic Signature (Official Gazette of the Republic of Serbia No. 135/04), REGULATION

Bank s Requirements for participating in CTS. Mumbai- Implementation Meeting. Mumbai- 18 th Jan. 2013

Djigzo encryption. Djigzo white paper

Fast, Easy to use and On-demand A Content Platform from the 21st Century

Finding the Leak Access Logging for Sensitive Data. SAP Product Management Security

How To Control A Record System

A Noval Approach for S/MIME

SecureVault Online Backup Service FAQ

JobScheduler. Architecture and Mode of Operation. Software for Open Source

AGENDA ITEM : ELECTRONIC SIGNATURE

REGISTRATION AUTHORITY (RA) POLICY. Registration Authority (RA) Fulfillment Characteristics SECURITY DATA SEGURIDAD EN DATOS Y FIRMA DIGITAL, S.A.

THIN CLIENT USAGE IN LONG-TERM ARCHIVATION ENVIRONMENT

SapphireIMS Business Service Monitoring Feature Specification

The Impact of 21 CFR Part 11 on Product Development

The PBS Portfolio in Practice. Walter Steffen, PBS Software GmbH

PkBox Technical Overview. Ver

Multi Source Input Multi Channel Output

Secure your Docker images

MySQL Security: Best Practices

Axway Validation Authority Suite

USING JE THE BE NNIFE FITS Integrated Performance Monitoring Service Availability Fast Problem Troubleshooting Improved Customer Satisfaction

The syslog-ng Premium Edition 5F2

Domino Certification Authority and SSL Certificates

ELECTRONIC PRESENTATION AND E-SIGNATURE FOR ELECTRONIC FORMS, DOCUMENTS AND BUSINESS RECORDS ALPHATRUST PRONTO ENTERPRISE PLATFORM

Processo Civile Telematico (On-line Civil Trial)

CERTIFICATE REVIEW RECORD

Securing Distribution Automation

Transcription:

PKI related technologies Tadej Pukl head of marketing and sales SETCCE

Agenda SETCCE short company introduction Results and partners SETCCE s products and services SETCCE s products in business practice ekeeper trusted archive service

Company introduction SEcurity Technology Competence CEntre Ljubljana, Slovenia, EU 15 people Young team Highly educated, experienced and motivated Over 10 years experience in PKI

Company introduction Software development through research projects Research: EU-projects in telecommunications security and privacy protection Software: Introduction of digital signature in business and governmental processes Objecticve: fully de-materialized business processes A wide range of technologies and components Mission: bridging the gap technology transfer from research projects into industry / commercial sector

Company introduction Legislative environment Act on electronic commerce and electronic signature (+ revisions). Act on value added tax Accounting standards (Slovenian) archiving act

Company introduction Act on electronic commerce and electronic signature (+ revisions): In force since 2000 Based on European directives (1999/93/EC, 2000/31/EC) Framework for equalisation of paper and electronic format of documents (Qualified) Digital signature Management of digitally signed electronic documents

Company introduction SETCCE s products: Compliant with EU s and local legislation Compliant with global standards Highest level of security Related to Public Key Infrastructure Introduction of digital signature (and supporting technologies) in current business practice

Company introduction SETCCE s products: Specialized components intended for system integrators and developers... Upgrades / add-ons to existing applications and information systems Recognized and used worldwide

SETCCE s reference list Some of our partners: ncipher H&S Software AG S&T SRC.SI ZZi Institute Jozef Stefan University of Ljubljana, Faculty of electrical engineering Univeristy of Stuttgart IAIK, Austria T-Systems Telenor, Norway Slovenian Chamber of Commerce etc....and still looking for fruitful long-term partnerships...

SETCCE s reference list Most important users of SETCCE s technology: VeriSign, Inc. Halcom ( Slovenian banks) SiOL d.o.o. Datalab tehnologije d.d. Valmesa Property&Asset Valuations Slovenian Ministry of Defense Dafolo S/A H&S Software AG Chinese gov t: tax authority, ZhuHai Sella bank, Italy Italian Chamber of Commerce (Infocamere) Simobil Vodafone, etc.

SETCCE s products and services

SETCCE s products proxsign product range

SETCCE s products (www. (www.proxsign.com) Components and software development kits for: Digital signing (W3C XMLDSig standard, XADES and PKCS7) + verification of signatures Encryption (asymmetric - W3C XMLEnc), Timestamping (RFC3161 and XML by Entrust) Instant integration! Widely used in the banking sector, ERP systems, real-estate companies, telecomm operators, governments, etc.

SETCCE s products (www. (www.proxsign.com) Practical examples: Integration into ERP systems for digital signing of single electronic invoices or any other documents (one by one) In ERP systems: verification of incoming digitally signed electronic invoices Integration into workflows (non-disputalbe audit-trail) Digital signing of payment orders in e-banking Pharmaceutical industry (tracing drugs from the production plant to the end-user) Timestamp client, encryption tool, W3C-recognized

SETCCE s products WebSign

SETCCE s products (WebSign) Workflow systems: Instant generation of XML electronic forms (based on pre-set templates) Secure exchange between involved parties In the process each party can fill in the e-forms and apply digital signatures Based on web-browser technology Fully configurable (no limits) Output = digitally signed XML document (optional stylesheet). No paper! Used in governmentnal processes (MoD), employment agencies, telecomm operators

SETCCE s products (WebSign) Practical examples: Signing of electronic contracts (ISPs) over the internet, signing of annexes, self-provisioning, etc. Student employment agencies (filling in, signing and exchange of work reports) Ministry of defense (requests for working tools for newly employeed,...)

SETCCE s products ebiller

SETCCE s products (ebiller) Electronic mass- invocing systems: Automated generation of documents (XML, TXT,..., e-invoices or any other documents) Multiple controls and checkpoints are integrated Automated digital signing of generated documents Automated generation of messages (S/MIME, SOAP, HTTP) Automated distribution Used by ISPs, telecomms, banking industry

SETCCE s products (ebiller) Practical examples: Mass generation and distribution of monthly invoices for users of mobile telephony and internet services Monthly banking acount statements

SETCCE s products ekeeper

SETCCE s products (ekeeper) Trusted electronic archive service: Storage of digitally signed and non-signed electronic content According to the legislation Not really an archive, but rather en electronic notary An upgrade for existing DMSs, or as an independent instance on top of a FS or existing e-archive Also available as a DMS-bundle Used in governmental processes, telecomm operators, ISPs, banking sector

SETCCE s products (ekeeper) Practical examples:...to be continued later

SETCCE s products Certification authorities: WWW.SI-CA.ORG Set-up of the first CA in Slovenia in 1995 Part of EuroPKI Still functioning No business case in Slovenia Experimental and demonstration purposes

SETCCE s products Custom-projects: For large end-customers Integration of SETCCE s technologies into cusomers applications Custom development of new applications Consultancy and educational projects

Bottom-line Conclusion: output/result is always a digitally signed document! Total elimination of paper documents from a business process! Questions: how do we store/archive the output? how do we manage the output?...electronic documents have some limitations!

Bottom-line Answer =... ekeeper

SETCCE ekeeper General definitions Formal requirements (integrated in ekeeper) Functional requirements What is ekeeper? What does ekeeper do? How ekeeper works Infrastructure / implementation Extra features Technology

General definitions Archiving is a set of procedures of submission, retrieval, preservation, maintenance, professional management and usage of documentary and archival material, which is not used for current business anymore. Such procedures need to be performed over periods defined by formal and legislative requirements. (i.e. archiving is much more than storage) An archive is a collection of records and documents that have historical, cultural, scientific or business value and are stored on physical media.

Formal requirements for ekeeper Electronic records must be kept so that: Data or content is accessible and usable at any time, Archived content is preserved in its original form or in any other form that undeniably represents the original data, The origin, time, location and the owner of an electronic record or message are undeniably identifiable...see next page

Formal requirements for ekeeper Electronic records must be kept so that: Technology and procedures used must prevent any sort of modification, alteration or deletion of record, data or content integrity is guaranteed at any time, Complementary data and means for security attributes (e.g. digital signatures) are preserved for the same archiving period as records Procedures and means for extending the validity of electronic attributes are accordingly implemented.

Functional requirements for ekeeper Trusted archive service must have the following basic operations: Submit data objects to archive Retrieve archived data objects Delete archived data objects Specify an archive period for submitted data objects Extend or shorten the archive period for an archived data object Specify metadata associated with an archived data object Specify an archive policy under which the submitted data should be handled

Functional requirements for ekeeper Trusted archive service accepts Raw data Digitally signed data Time stamped data Encrypted data

What is ekeeper? A solution for long-term electronic archiving A replacement for costly hardware solutions (Centera) Based on national and international legislation and directives for long term documents preservation Based on global technical directions and standardization initiatives (IETF LTAP Protocol, encryption and hashing algorithms...) An upgrade of existing DMSs Provides long term stability of Documents Digital signatures Designed for critical and heavy loaded environments

What does ekeeper do? It provides evidence that an archived document: existed at a certain (clearly defined) time in the past has not been compromised since it was digitally signed (or since it was submitted to the archive if it was not signed) is still legally valid and will remain so for the whole archival period still bears a valid digital signature (if applied). Validity of the signature will be maintained throughout the whole archival period! In other words: ekeeper can demonstrate inegrity and legal validity of archived digital content for the complete archival period

How ekeeper works Archival period (time) C.A.=conservation attributes!

How ekeeper works Archived documents are left intact! Conservation Attributes are created upon entry Conservation Attributes are used to demonstrate documents validity and integrity Conservation Attributes are refreshed periodically Timestamping is used (DSE!) Documents validity is assured

Infrastructure Supporting infrastructure of trusted archive service Communication network (and PKI) Security mechanisms Time stamping service Data storage or document management system Application systems and services

Infrastructure Certification authorities DMS / Data storage ncipher DSE (internal or outsourced)

Extra features (competitive advantage)! Grouping of archived documents to minimize the cost of timestamping! De-grouping without re-timestamping Privacy protection upon verification of documents ekeeper is a substitute for dedicated hardware archiving solutions

Platform ekeeper Client C++ / Java based Integrated LTAP (long-term archive protocol) Supported modes Conservation attributes generation and storage Conservation attributes generation and storage + document storage Application programming interface included

Platform ekeeper Server Java based Integrated LTAP Supported modes Conservation attributes generation and storage Conservation attributes generation and storage + document storage Interfaces DB interface (Oracle, mysql, MSSQL ) HSM interface (ncipher) TCP/IP or SOAP interface

Operation requirements Platforms Microsoft Windows, Linux, Solaris, HP-UX, AIX Databases (conservation attributes) Oracle, mysql, MSSQL, DB2 Supported document management systems/environments IBM Lotus Domino/Notes, EMC Documentum, H&S PAM Storage SAP R/3, Navision

Standards Implemented standards Data structures W3C XML Interaction IETF LTAP W3C SOAP Integrity evidence SHA1, SHA256, SHA384, SHA512 RIPEMD160 Signatures RSA PKCS#7 W3C XMLDSig ETSI/W3C XAdES Evidence record IETF RFC3161 Entrust XMLTS

Contact SETCCE Jamova 39 1000 Ljubljana Slovenia, EU ++386 (0)1 477 3861 info@setcce.org www.setcce.org