Qualified Electronic Signature / Seal Creation Devices
Total Page:16
File Type:pdf, Size:1020Kb
Prime minister Agence nationale de la sécurité des systèmes d’information Qualified electronic signature / seal creation devices Criteria for assessing compliance with the eIDAS regulation Based on French version 1.0 of 16 November 2017 VERSION HISTORY DATE VERSION DOCUMENT CHANGES EDITOR 20/06/2016 0.9 Working version for comments. ANSSI Version for application on 16 November 2017. Amendments: 16/11/2017 - Addition of contact details of ANSSI; ANSSI 1.0 - Details on certification maintenance ; - Definitions of the sponsor certification commitments Comments on this document should be sent to: Agence nationale de la sécurité des systèmes d’information SGDSN/ANSSI 51 boulevard de La Tour-Maubourg 75700 Paris 07 SP [email protected] Creation devices for qualified electronic signatures and seals – Criteria for assessing compliance with the eIDAS regulation Version Date Circulation criterion Page 1.0 16/11/2017 PUBLIC 2/14 CONTENTS I. Introduction ........................................................................................................................................................ 4 I.1. Subject ........................................................................................................................................................ 4 I.2. Legal framework ......................................................................................................................................... 4 I.3. Updating ..................................................................................................................................................... 4 I.4. Acronyms.................................................................................................................................................... 5 II. Requirements relating to qualified electronic signature /seal creation devices .................................................. 6 II.1. Assignment process of the conformity certificate ...................................................................................... 6 II.1.1. Conformity certificate request ............................................................................................................ 6 II.1.2. Form of the conformity certificate ...................................................................................................... 6 II.1.3. Validity of the conformity certificate ................................................................................................. 6 II.2. Criteria for assessing the compliance of QSCD ......................................................................................... 7 II.3. QSCD certification conformity terms ......................................................................................................... 8 II.3.1. When the electronic signature creation data or electronic seal creation data is held in an entirely user-managed environment ................................................................................................................................. 8 a. Conformity certificate issuance .................................................................................................................. 8 b. Conformity certificate maintenance ........................................................................................................... 8 II.3.2. When the electronic signature creation data or electronic seal creation data is managed by a qualified PSCO on behalf of the user ................................................................................................................. 9 a. Conformity certificate issuance ..................................................................................................................... 9 b. Conformity certificate maintenance ............................................................................................................. 10 Appendices ............................................................................................................................................................... 11 I. Appendix 1 Documentary references ........................................................................................................... 11 II. Appendix 2 Commitments relating to the security follow-up of the product ............................................... 12 III. Appendix 3 Implementation example of a QSCD implemented by a qualified TSP .............................. 13 Creation devices for qualified electronic signatures and seals – Criteria for assessing compliance with the eIDAS regulation Version Date Circulation criterion Page 1.0 16/11/2017 PUBLIC 3/14 I. Introduction I.1. Subject The purpose of this document is to describe the attribution procedure by ANSSI of conformity certificates for qualified electronic signature creation devices (QSCD) in accordance with article 30 of the [eIDAS] regulation and for qualified electronic seal (QSCD) under article 39 of the [eIDAS] regulation. The [eIDAS] regulation specifies that in order to create a “qualified” electronic signature or electronic seal, the electronic signature and seal creation devices must themselves be qualified. The requirements which apply to these devices are mentioned in Appendix II of the [eIDAS] regulation. The conformity of these devices to the requirements of the [eIDAS] regulation is nationally certified by a certification body. In France, ANSSI, has been designated as a certification body by the note from the French authorities [DESIGNATION]. The following chapters specify the conditions for obtaining a conformity certificate for a QSCD. Appendix II provides an implementation example of a QSCD when the creation data of an electronic signature or electronic seal is managed by a qualified TSP on behalf of the user. This document repeals the SIG/P/01.1 procedure, reference 872/SGDN/DCSSI/SDR of 7th April 2003. I.2. Legal framework The qualified electronic signature and seal creation devices, certified in accordance with the present procedure, and appearing on the list published by the European Commission, are presumed to meet the requirements of Appendix II of the [eIDAS] regulation. Advanced electronic signatures, based on a qualified electronic signature certificate, and created using a qualified electronic signature creation device, are qualified electronic signatures, benefiting from the legal effects provided for in article 25 of the [eIDAS] regulation and in article 1367 of the French Civil Code. Advanced electronic seals, based on a qualified electronic seal certificate, and created using a qualified electronic seal creation device, are qualified electronic seals, benefiting from the legal effects provided for in article 35 of the [eIDAS] regulation. I.3. Updating The opportunity to update this document is evaluated by ANSSI and can in particular result from a change in the regulatory or standards framework linked to the [eIDAS] regulation or from a change in the state of the art. ANSSI specifies the effective date of each update and the particulars for transition where applicable. Creation devices for qualified electronic signatures and seals – Criteria for assessing compliance with the eIDAS regulation Version Date Circulation criterion Page 1.0 16/11/2017 PUBLIC 4/14 I.4. Acronyms The acronyms used in this reference document are: ANSSI Agence Nationale de la Sécurité des Systèmes d’Information (National Cybersecurity Agency of France). CC Common Criteria. HSM Hardware Security Module. QSCD Qualified electronic Signature/Seal Creation Device. SSCD Secure Signature Creation Device. SOG-IS Senior Officials Group-Information System Security. TSP Trust Service Provider. Creation devices for qualified electronic signatures and seals – Criteria for assessing compliance with the eIDAS regulation Version Date Circulation criterion Page 1.0 16/11/2017 PUBLIC 5/14 II. Requirements relating to qualified electronic signature /seal creation devices II.1. Assignment process of the conformity certificate II.1.1. Conformity certificate request The conformity certificate request is addressed to the Qualification and Approval Unit of ANSSI ([email protected]). This request must be addressed with the elements on which the decision of the conformity certification is based on (for example, the device certification report under the Common Criteria). The Industrial Policy and Assistance Unit of ANSSI ([email protected]) is the privileged point of contact for any question relating to the procedure of conformity certification for a new device. II.1.2. Form of the conformity certificate The conformity certificate issued by ANSSI is based on a distinct and complementary process from the security certificate delivered for the product itself. The conformity certificate indicates the functions for which it has been issued and the certification report relating to the security certificate on which it is based. This conformity certificate may include restrictions of use which must be imperatively respected, especially during the preparation, the delivery and the implementation of the device. In the case of the conformity certification of a QSCD used in the environment of a qualified TSP, ensuring the generation and the management of signature creation data (respectively seal) on the behalf of the signatory (respectively the seal creator), a partial conformity certificate can be issued for the sole product. This conformity certificate must be completed after the verification of the QSCD implementation in the environment of