Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March Electronic Signature infrastructure for Europe Riccardo Genghini Cen/Isss Ws E-Sign Chairman
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March Dr. Riccardo Genghini - SNG Notary Public in Milan – Italy Uninfo STP Chair 2002 Cen – ISSS E Sign Chair 2001 Liberty Alliance Member ETSI Member IT Law research since Notary Public in Milan – Italy Uninfo STP Chair 2002 Cen – ISSS E Sign Chair 2001 Liberty Alliance Member ETSI Member IT Law research since
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March Definition of 5.1 (QES) Qualified Electronic Signatures have a functional definition in the 1999/93/EC directive: They have to “satisfy the legal requirements of a signature in relation to data in electronic form in the same manner as a handwritten signature satisfies those requirements in relation to paper-based data” (art. 5.1). So they are what ever it is a human signature for the given legal system (i.e. possibly not binding) Qualified Electronic Signatures have a functional definition in the 1999/93/EC directive: They have to “satisfy the legal requirements of a signature in relation to data in electronic form in the same manner as a handwritten signature satisfies those requirements in relation to paper-based data” (art. 5.1). So they are what ever it is a human signature for the given legal system (i.e. possibly not binding)
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March Definition of 5.2 (ES) Non qualified electronic signatures are “data in electronic form which are attached to or logically associated with other electronic data and which serve as a method of authentication” (art. 2.1) This definition includes many different kind of signatures: access control, data origin authentication, data validation, time-stamping, and any other way of “marking data” not necessarily related to the human act of signing Non qualified electronic signatures are “data in electronic form which are attached to or logically associated with other electronic data and which serve as a method of authentication” (art. 2.1) This definition includes many different kind of signatures: access control, data origin authentication, data validation, time-stamping, and any other way of “marking data” not necessarily related to the human act of signing
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March EESSI SG European Telecommunications Standards Institute Industry and business, assisted by European standard bodies EESSI European Electronic Signature Standardization Initiative Comitèe Europèen de Normation Information Society Standardisation System
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March CEN WORKSHOP AGREEMENTS AREA D1-D2 CWA “Security Requirements for Trustworthy Systems Managing Certificates for Electronic Signatures” CWA “Security of cryptographic modules” CWA “ Cryptographic Module for CSP Key Generation Services – Protection Profile CMCKG-PP
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March AREA F CWA “Security Requirements for Secure Signature Creation Devices” EAL4 CWA ““Security Requirements for Secure Signature Creation Devices” EAL4+” AREA G1-G2 CWA “Security Requirements for Secure Signature Creation Systems” CWA “Procedures for Electronic Signature Verification” CEN WORKSHOP AGREEMENTS
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March AREA V CWA “Conformity Assessment Guidance - Part. 1 – General” CWA “Conformity Assessment Guidance – Part 2 – Certification Authority services and processes” CWA – “Conformity Assessment Guidance – Part 3 – Trustworthy systems managing certificates for electronic signatures” CWA – “Conformity Assessment Guidance – Part 4 – Signature creation applications and procedures for electronic signature verification” CWA – “Conformity Assessment Guidance – Part 5 – Secure Signature Creation Devices” CEN WORKSHOP AGREEMENTS
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March AREA AA1-AA2 CWA “Guidelines for the implementation of Secure Signature Creation Devices” CWA “General Requirements for Electronic Signatures” CEN WORKSHOP AGREEMENTS
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March CEN WORKSHOP AGREEMENTS Area AB (work in progress): Team 1 Technical Report on advanced and non advanced electronic signatures and their informative value (relevance as legal evidence)
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March CEN WORKSHOP AGREEMENTS Area K (work in progress): Team 2 CWA XXXXX “Application Interface for Smartcards used as Secure Signature Creation Device”
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March CEN WORKSHOP AGREEMENTS Area L (work in progress): Team 3 “Harmonised provision of Trusted Service Provider status information”
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March CEN WORKSHOP AGREEMENTS AREA V (ongoing work): Team 5 Guidance on conformity assessment of Signature Creation Devices supporting non-qualified electronic signatures (5.2 signatures) against the Protection Profile specified in the CWA of Area AA2 (CWA Part 6). Guidance on conformity assessment of Cryptographic Modules for CSP Signing Operations against the Protection Profile specified in CWA of Area D2 (MCSO-PP) (CWA Part 7). Guidance on conformity assessment of CSPs issuing public key certificates against the Policy Requirements specified by ETSI STF 178 Task 2 (CWA Part 8). Guidance on conformity assessment of Time-Stamping Authorities against the Policy Requirements specified by ETSI STF 178 Task 1 (CWA Part 9).
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March CEN WORKSHOP AGREEMENTS Maintenance of approved EESSI deliverables: Team 4 Deadline 2Q – 3Q 2003 Opportunity in Vienna to network and discuss technical issues between the IETF and EESSI experts
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March ETSI ESI TS - TR Phase 3 Publications (1/2) Policy requirements for time-stamping authorities TR (January 2003) Identification of requirements for attribute certification - TR (December 2002) Electronic Signature formats version TS v (September 2002) XML format for signature policies - TR (April 2002) Policy requirements for time-stamping authorities - TS (April 2002) Policy requirements for certification authorities issuing public key certificates - TS (April 2002) Policy requirements for certification authorities issuing qualified certificates - TS v (April 2002)TR TR TS v 1.4.0TR TS TS TS v 1.2.1
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March ETSI ESI TS - TR Phase 3 Publications (2/2) Provision of harmonized Trust Service Provider status information - TR (April 2002) FAQ (March 2002) International Harmonization of Policy Requirements for CAs issuing Certificates - TR (March 2002) Time stamping profile - TS v1.2.1 (March 2002) Signature Policies Report - TR (February 2002) XML Advanced Electronic Signatures (XAdES) - TS (February 2002) Electronic Signature Formats - TS v (February 2002) TR FAQTR TS v1.2.1TR TS TS v 1.3.1
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March ETSI ESI TS - TR Phase 1 and 2 Publications Time Stamping Profile - TS v (September 2001) Qualified Certificate Profile - TS v (June 2001) Policy requirement for certification authorities issuing qualified certificates TS v (December 2000) Qualified Certificate Profile - TS v (December 2000) Electronic Signature Formats - TS v (December 2000) Electronic Signature Formats - ETSI ES v (May 2000) TS v 1.1.1TS v 1.2.1TS v 1.1.1TS v 1.1.1TS v ETSI ES v 1.1.3
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March ETSI ESI TS - TR Being processed for publication Signature policy for extended business model - TR TR Pre study on Certificate Profiles TR TR Maintenance of ETSI standards from EESSI phase 2 and 3 TR TR Opportunity in Vienna to network and discuss technical issues between the IETF and EESSI experts
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March ETSI ESI TS - TR Approved Following a request from the EESSI Steering Committee, it was agreed to create a Work Item to publish the EESSI "Algo Paper" as a special report of TC ESI. Under Approval There are currently no deliverables in this phase Draft for public comment There are currently no deliverables in this phase Notice !!! XML interoperability event in Sophia Antipolis (France) 4Q 2003
Riccardo Genghini - Ws E-Sign Chairman – IETF PKIX San Francisco March Cen-ISSS E-Sign - ETSI ESI EESSI: CEN: ETSI: Sign up for the two mailing lists on the respective Web Pages