Cart (0)
  • No items in cart.
Total
$0
There is a technical issue about last added item. You can click "Report to us" button to let us know and we resolve the issue and return back to you or you can continue without last item via click to continue button.
Filters:
FORMAT
EDITION
to
PUBLISHER
(1)
(317)
(572)
(43)
(234)
(969)
(643)
(2114)
(64)
(92448)
(54)
(535)
(117)
(31)
(20)
(19)
(92811)
(3)
(17)
(1)
(351)
(300)
(6023)
(239)
(16)
(5)
(1621)
(16)
(18)
(28)
(4)
 
(6)
(7)
(115)
(3)
(57)
(5)
(5)
(1)
(1)
(2)
(23)
(26)
(27)
(13)
(61)
(24)
(22)
(7)
(8)
(20)
(1)
(3)
(50)
(6)
(31)
CONTENT TYPE
 Act
 Admin Code
 Announcements
 Bill
 Book
 CADD File
 CAN
 CEU
 Charter
 Checklist
 City Code
 Code
 Commentary
 Comprehensive Plan
 Conference Paper
 County Code
 Course
 DHS Documents
 Document
 Errata
 Executive Regulation
 Federal Guideline
 Firm Content
 Guideline
 Handbook
 Interpretation
 Journal
 Land Use and Development
 Law
 Legislative Rule
 Local Amendment
 Local Code
 Local Document
 Local Regulation
 Local Standards
 Manual
 Model Code
 Model Standard
 Notice
 Ordinance
 Other
 Paperback
 PASS
 Periodicals
 PIN
 Plan
 Policy
 Product
 Program
 Provisions
 Requirements
 Revisions
 Rules & Regulations
 Standards
 State Amendment
 State Code
 State Manual
 State Plan
 State Standards
 Statute
 Study Guide
 Supplement
 Technical Bulletin
 All
  • BSI
    PD CEN/TS 419261:2015 Security requirements for trustworthy systems managing certificates and time-stamps
    Edition: 2015
    $497.46
    / user per year

Description of PD CEN/TS 419261:2015 2015

1.1 General

This Technical Specification establishes security requirements for TWSs that can be used by a TSP in order to issue QCs and Non-Qualified Certificates (NQCs) as well as electronic time-stamps in accordance with Dir. 1999/93/EC and with [Reg. 910/2014/EU ].

Security requirements for the Subject Device Provision Service, which includes SCDev/QSCD provision to subjects, are defined in this TS. However, requirements specific to SCDev/QSCD devices, as used by subjects of the TSP, are outside the scope of this TS. These requirements are defined as Common Criteria [CC] Protection Profiles (PP) in the EN 419211 series.

Recommendations for the cryptographic algorithms to be supported by TWSs are provided in ETSI/TS 119 312 .

Although this TS is based on the use of public key cryptography, it does not require or define any particular communication protocol or format for electronic signatures, certificates, certificate revocation lists, certificate status information and time-stamp tokens. It only assumes certain types of information to be present in the certificates in accordance with Annex I of Dir. 1999/93/EC and of [Reg. 910/2014/EU ]. Interoperability between TSP systems and subject systems is outside the scope of this document.

The use of TWSs that are already compliant to relevant security requirements of this TS should support TSPs in reducing their burden to establish conformance of their policy to ETSI TS 119 411‑1 , 119 411-2, and 119 421 (or equivalent ENs to be subsequently published) and in meeting the Annex I and Annex II requirements of Dir. 1999/93/EC as well as the requirements from Annex I and Article 24.2 (e) of [Reg. 910/2014/EU ].

1.2 European Regulation-specific

The main focus of this document is on the requirements in Article 24.2 (e) of [Reg. 910/2014/EU ] whilst still facilitating the meeting of requirements in Dir. 1999/93/EC , Annex II (f). In considering [Reg. 910/2014/EU ] it is important to take into account the following requirements of particular relevance to TSP trustworthy systems:

  1. Article 24.2 (f) – “use trustworthy systems to store data provided to it, in a verifiable form so that:

    1. they are publicly available for retrieval only where the consent of the person to whom the data relates has been obtained,

    2. only authorised persons can make entries and changes to the stored data,

    3. the data can be checked for authenticity”;

  2. Article 24.2 (g) – “take appropriate measures against forgery and theft of data”;

  3. Article 24.2 (h) – “record and keep accessible for an appropriate period of time, including after the activities of the qualified trust service provider have ceased, all relevant information concerning data issued and received by the qualified trust service provider, in particular, for the purpose of providing evidence in legal proceedings and for the purpose of ensuring continuity of the service. Such recording may be done electronically”;

  4. Article 24.2 (j) – “ensure lawful processing of personal data in accordance with Directive 95/46/EC ”;

  5. Article 24.2 (k) – “in case of qualified trust service providers issuing qualified certificates, establish and keep updated a certificate database”;

  6. Article 24.3 – “If a qualified trust service provider issuing qualified certificates decides to revoke a certificate, it shall register such revocation in its certificate database and publish the revocation status of the certificate in a timely manner, and in any event within 24 hours after the receipt of the request. The revocation shall become effective immediately upon its publication”;

  7. Article 24.4 – "With regard to paragraph 3, qualified trust service providers issuing qualified certificates shall provide to any relying party information on the validity or revocation status of qualified certificates issued by them. This information shall be made available at least on a per certificate basis at any time and beyond the validity period of the certificate in an automated manner that is reliable, free of charge and efficient”;

  8. Article 42.1 – “A qualified electronic time stamp shall meet the following requirements:

    1. it binds the date and time to data in such a manner as to reasonably preclude the possibility of the data being changed undetectably;

    2. it is based on an accurate time source linked to Coordinated Universal Time; and

    3. it is signed using an advanced electronic signature or sealed with an advanced electronic seal of the qualified trust service provider, or by some equivalent method”;

  9. Annexes I, III, IV – requirements on data in qualified certificates



About BSI

BSI Group, also known as the British Standards Institution is the national standards body of the United Kingdom. BSI produces technical standards on a wide range of products and services and also supplies certification and standards-related services to businesses.

GROUPS