ETSI TS 102 023-2008 Electronic Signatures and Infrastructures (ESI) Policy requirements for time-stamping authorities (V1 2 2)《电子签名和基础结构(ESI) 对于时间标记权威性的政策需求(版本1 2 2)》.pdf
《ETSI TS 102 023-2008 Electronic Signatures and Infrastructures (ESI) Policy requirements for time-stamping authorities (V1 2 2)《电子签名和基础结构(ESI) 对于时间标记权威性的政策需求(版本1 2 2)》.pdf》由会员分享,可在线阅读,更多相关《ETSI TS 102 023-2008 Electronic Signatures and Infrastructures (ESI) Policy requirements for time-stamping authorities (V1 2 2)《电子签名和基础结构(ESI) 对于时间标记权威性的政策需求(版本1 2 2)》.pdf(33页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI TS 102 023 V1.2.2 (2008-10)Technical Specification Electronic Signatures and Infrastructures (ESI);Policy requirements for time-stamping authoritiesETSI ETSI TS 102 023 V1.2.2 (2008-10)2Reference RTS/ESI-000066 Keywords e-commerce, electronic signature, security, time-stamping, trust services
2、ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice Individual copies of the present document can b
3、e downloaded from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF). In case of dispute, the re
4、ference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documen
5、ts is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced except as authorized by written permis
6、sion. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2008. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTM, TIPHONTM, the TIPHON logo and the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members
7、. 3GPPTM is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. ETSI ETSI TS 102 023 V1.2.2 (2008-10)3Contents Intellectual Property Rights 5g3Foreword . 5g3Introduction 5g31 Scope 6g32 References 6g32.1 Normative references . 7g32.2 Informative re
8、ferences 7g33 Definitions and abbreviations . 8g33.1 Definitions 8g33.2 Abbreviations . 8g34 General concepts 9g34.1 Time-stamping services 9g34.2 Time-Stamping Authority (TSA) . 9g34.3 Subscriber . 9g34.4 Time-stamp policy and TSA practice statement . 9g34.4.1 Purpose . 10g34.4.2 Level of specifici
9、ty . 10g34.4.3 Approach 10g35 Time-stamp Policies . 10g35.1 Overview 10g35.2 Identification 10g35.3 User Community and applicability . 11g35.4 Conformance 11g36 Obligations and liability . 11g36.1 TSA obligations 11g36.1.1 General 11g36.1.2 TSA obligations towards subscribers 11g36.2 Subscriber obli
10、gations 11g36.3 Relying party obligations . 12g36.4 Liability 12g37 Requirements on TSA practices . 12g37.1 Practice and Disclosure Statements 12g37.1.1 TSA Practice statement . 12g37.1.2 TSA disclosure Statement . 13g37.2 Key management life cycle 14g37.2.1 TSA key generation 14g37.2.2 TSU private
11、key protection . 14g37.2.3 TSU public key Distribution . 15g37.2.4 Rekeying TSUs Key . 15g37.2.5 End of TSU key life cycle . 15g37.2.6 Life cycle management of cryptographic module used to sign time-stamps 15g37.3 Time-stamping . 16g37.3.1 Time-stamp token . 16g37.3.2 Clock Synchronization with UTC
12、. 16g37.4 TSA management and operation 17g37.4.1 Security management 17g37.4.2 Asset classification and management . 17g37.4.3 Personnel security . 18g37.4.4 Physical and environmental security. 19g37.4.5 Operations management . 19g37.4.6 System Access Management. 20g3ETSI ETSI TS 102 023 V1.2.2 (20
13、08-10)47.4.7 Trustworthy Systems Deployment and Maintenance . 21g37.4.8 Compromise of TSA Services 21g37.4.9 TSA termination . 22g37.4.10 Compliance with Legal Requirements 22g37.4.11 Recording of information concerning operation of time-stamping service. 23g37.5 Organizational 24g3Annex A (informat
14、ive): Potential liability in the provision of time-stamping services 25g3Annex B (informative): Model TSA disclosure statement 26g3B.1 Introduction 26g3B.2 The TSA disclosure statement structure . 27g3Annex C (informative): Coordinated Universal Time (UTC). 28g3Annex D (informative): Long term verif
15、ication of time-stamp tokens 29g3Annex E (informative): Possible for implementation architectures - time-stamping service 30g3E.1 Managed time-stamping service . 30g3E.2 Selective Alternative Quality . 31g3Annex F (informative): Bibliography . 32g3History 33g3ETSI ETSI TS 102 023 V1.2.2 (2008-10)5In
16、tellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property R
17、ights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web server (http:/webapp.etsi.org/IPR/home.asp). Pursuant to the ETSI IPR Policy, no investigation, including
18、 IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become, essential to the present document. Foreword This Technical Specification (TS) has be
19、en produced by ETSI Technical Committee Electronic Signatures and Infrastructures (ESI). Introduction In creating reliable and manageable digital evidence it becomes necessary to have an agreed upon method of associating time data to transaction so that they might be compared to each other at some l
20、ater time. The quality of this evidence is based in the process of creating and managing the data structure that represent the events and the quality of the parametric data points that anchor them to the real world. In this instance this being the time data and how it was applied. In addition, in or
21、der to verify an electronic signature, it may be necessary to prove that the digital signature from the signer was applied when the signers certificate was valid. This is necessary in two circumstances: 1) during the validity period of the signers certificate, should the signers private key be compr
22、omised and thus revoked for that reason; 2) after the end of the validity period of the signers certificate, since CAs are not mandated to process revocation status information beyond the end of the validity period of the certificates they have issued. Two generic methods exist to solve this problem
23、. One consists to use a time-mark which is an audit record kept in a secure audit trail from a trusted third party which attaches a date to a signature value. This proves that the signature was generated before the date from the time-mark. This method is not the topic of the present document. Anothe
24、r one consists to use a time-stamp which allows to prove that a datum existed before a particular time. This technique allows to prove that the signature was generated before the date contained in the time-stamp token. Policy requirements to cover that case is the primary reason of the present docum
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSITS1020232008ELECTRONICSIGNATURESANDINFRASTRUCTURESESIPOLICYREQUIREMENTSFORTIMESTAMPINGAUTHORITIESV122

链接地址:http://www.mydoc123.com/p-738664.html