magnifying icon Panier

Votre panier est vide
Login

Login

CONNECTÉ EN TANT QUE

Aide

Enquête de satisfaction

ENQUÊTE DE SATISFACTION

Newsletter

Offre de formation continue gratuite "Normalisation"

OFFRE DE FORMATION CONTINUE GRATUITE "NORMALISATION"

Normalisation

Projets de norme en enquête publique

PROJETS DE NORME EN ENQUÊTE PUBLIQUE

Organismes de normalisation

ORGANISMES DE NORMALISATION

  • Normes nationales

  • Normes européennes

  • Normes internationales


Publication

 
Aperçu partiel gratuit
Prix
Langue
 
ILNAS-EN 419241-1:2018 Edition 07/2018
Systèmes fiables de serveur de signature électronique - Partie 1: Exigences de sécurité générales du système
  •   
  •   
  •   
  •  
  • 64.7 / exemplaire
  •  
 

Résumé

1.1 General This document specifies security requirements and recommendations for Trustworthy Systems Supporting Server Signing (TW4S) that generate digital signatures. The TW4S is composed at least of one Server Signing Application (SSA) and one Signature Creation Device (SCDev) or one remote Signature Creation Device. A remote SCDev is a SCDev extended with remote control provided by a Signature Activation Module (SAM) executed in a tamper protected environment. This module uses the Signature Activation Data (SAD), collected through a Signature Activation Protocol (SAP), in order to guarantee with a high level of confidence that the signing keys are used under sole control of the signer. The SSA uses a SCDev or a remote SCDev in order to generate, maintain and use the signing keys under the sole control of their authorized signer. Signing key import from CAs is out of scope. So when the SSA uses a remote SCDev, the authorized signer remotely controls the signing key with a high level of confidence. A TW4S is intended to deliver to the signer or to some other application, a digital signature created based on the data to be signed. This standard: - provides commonly recognized functional models of TW4S; - specifies overall requirements that apply across all of the services identified in the functional model; - specifies security requirements for each of the services identified in the TW4S; - specifies security requirements for sensitive system components which may be used by the TW4S. This standard is technology and protocol neutral and focuses on security requirements. 1.2 Outside of the scope The following aspects are considered outside of the scope of this document: - other trusted services that may be used alongside this service such as certificate issuance, signature validation service, time-stamping service and information preservation service; - any application or system outside of the TW4S (in particular the signature creation application including the creation of advanced signature formats); - signing key and signing certificate import from CAs; - the legal interpretation of the form of signature (e.g. electronic signature, electronic seal, qualified or otherwise). 1.3 Audience This standard specifies security requirements that are intended to be followed by: - providers of TW4S systems; - Trust Service Providers (TSP) offering a signature creation service.

Statut

Standard - Actif

Origine

Comité technique :
CEN/TC 224 : Identification personnelle, signature électronique, cartes et leurs systèmes et fonctionnements associés

Mise en application

début du vote sur le projet    30/03/2017   date de ratification (dor)    30/04/2018
fin du vote sur le projet    22/06/2017   date d'annonce (doa)    30/10/2018
début du vote sur le projet final    01/02/2018   date de publication (dop)    31/01/2019
fin du vote sur le projet final    29/03/2018   date de retrait (dow)    31/01/2019


Publication au Journal officiel
du Grand-Duché de Luxembourg
17/09/2018
Référence Mémorial A N° 834

Relations

Relations avec d'anciennes normes
CEN/TS 419241:2014

Classification internationale pour les normes (codes ICS) :

35.030 : IT Security

magnifying icon Panier

Votre panier est vide


Attention:
Les normes DIN ne peuvent être téléchargées qu’une seule fois! Après le téléchargement, elles ne seront plus disponibles dans l’eBibliothèque.
Continuer avec le téléchargement?