scieee AI-readable full text Open interactive document viewer

ETSI EN 319 521 v0.0.4: "Electronic Registered Delivery Services. Policy and security requirements for Electronic Registered Delivery Service Providers”.

LLaneza, Paloma,Boldrin, Luca,Fiedler, Arno,Grosslambert, Julien,Cruellas Ibarz, Juan Carlos,Tauber, Arne,Fieten, Sander,Réti, Kórnel,Foti, Santino,Olnes, Jon

Abstract

This document specifies generally applicable policy and security requirements for Electronic Registered Delivery Services Providers (ERDSP), including the services they provide

Full text

Draft ETSI EN 319 521 V0.0.4 (2017-10) Electronic Signatures and Infrastructures (ESI); Policy and security requirements for Electronic Registered Delivery Service Providers  EUROPEAN STANDARD STABLE DRAFT FOR PUBLIC REVIEW UNTIL 29 DECEMBER 2017 Download the template for comments: https://docbox.etsi.org/ESI/Open/Latest_Drafts/Template-for- comments.doc Send comments ONLY to [email protected] CAUTION: This DRAFT document is provided for information and is for future development work within the ETSI Technical Committee ESI only. ETSI and its Members accept no liability for any further use/implementation of this Specification. Approved and published specifications and reports shall be obtained exclusively via the ETSI Documentation Service at http://www.etsi.org/standards-search ETSI Draft ETSI EN 319 521 V0.0.4 (2017-10) 2 0 1 2 Reference DEN/ESI-0019521 Keywords e-commerce, electronic signature, extended validation certificat, public key, security, trust services ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex- FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N° 348 623 562 00017 - NAF 742 C Association à but non lucratif enregistrée à la Sous-Préfecture de Grasse (06) N° 7803/88 Important notice The present document can be downloaded from: http://www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at http://portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: https://portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shall not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. © European Telecommunications Standards Institute 2017. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTM and the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3GPPTM and LTE™ are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM® and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI Draft ETSI EN 319 521 V0.0.4 (2017-10) 3 Contents 3 Intellectual Property Rights ................................................................................................................................ 4 4 Foreword............................................................................................................................................................. 4 5 Modal verbs terminology ................................................................................................................................... 4 6 Introduction ........................................................................................................................................................ 4 7 1 Scope ........................................................................................................................................................ 6 8 2 References ................................................................................................................................................ 6 9 2.1 Normative references ......................................................................................................................................... 6 10 2.2 Informative references ....................................................................................................................................... 6 11 3 Definitions and abbreviations ................................................................................................................... 7 12 3.1 Definitions ......................................................................................................................................................... 7 13 3.2 Abbreviations ..................................................................................................................................................... 7 14 3.3 Notation ............................................................................................................................................................. 7 15 4 General provision on policies and practices ............................................................................................. 8 16 4.1 ERDS Practice statement ................................................................................................................................... 8 17 4.2 Terms and conditions ......................................................................................................................................... 9 18 4.3 Information security policy ................................................................................................................................ 9 19 5 General provision on ERDS ..................................................................................................................... 9 20 5.1 User content integrity and confidentiality .......................................................................................................... 9 21 5.2. Users Identification and Authentication .......................................................................................................... 10 22 5.2.1. Initial identity verification .......................................................................................................................... 10 23 5.2.1.1. Recipient identification and consignment of user content ................................................................................... 10 24 5.2.2 Authentication ............................................................................................................................................ 10 25 5.3 Time reference ................................................................................................................................................. 11 26 5.4 Events and evidence......................................................................................................................................... 11 27 5.4.1 Retention period ......................................................................................................................................... 12 28 6 Risk Assesment ...................................................................................................................................... 12 29 7 ERDSP management and operation ....................................................................................................... 12 30 7.1 Internal organization ........................................................................................................................................ 12 31 7.1.1 Organization reliability .............................................................................................................................. 12 32 7.1.2 Segregation of duties .................................................................................................................................. 12 33 7.2 Human resources ............................................................................................................................................. 12 34 7.3 Asset management ........................................................................................................................................... 12 35 7.3.1 General requirements ................................................................................................................................. 12 36 7.3.2 Media handling ........................................................................................................................................... 13 37 7.4 Access control .................................................................................................................................................. 13 38 7.5 Cryptographic controls .................................................................................................................................... 13 39 7.6 Physical and environmental security................................................................................................................ 13 40 7.7 Operation security ............................................................................................................................................ 14 41 7.8 Network security .............................................................................................................................................. 14 42 7.9 Incident management ....................................................................................................................................... 14 43 7.10 Collection of evidence for ERDSP internal services ....................................................................................... 14 44 7.11 Business continuity management ..................................................................................................................... 14 45 7.12 ERDSP termination and ERDS termination plans ........................................................................................... 15 46 7.13 Compliance ...................................................................................................................................................... 15 47 History .............................................................................................................................................................. 15 48 49 50 ETSI Draft ETSI EN 319 521 V0.0.4 (2017-10) 4 Intellectual Property Rights 51 IPRs essential or potentially essential to the present document may have been declared to ETSI. The information 52 pertaining to these essential IPRs, if any, is publicly available for ETSI members and non-members, and can be found 53 in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in 54 respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI Web 55 server (http://ipr.etsi.org). 56 Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee 57 can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web 58 server) which are, or may be, or may become, essential to the present document. 59 Foreword 60 This draft European Standard (EN) has been produced by ETSI Technical Committee Electronic Signatures and 61 Infrastructures (ESI), and is now submitted for public review before approval by TC ESI and submission for the 62 combined Public Enquiry and Vote phase of the ETSI standards EN Approval Procedure. 63 64 Proposed national transposition dates Date of latest announcement of this EN (doa): 3 months after ETSI publication Date of latest publication of new National Standard or endorsement of this EN (dop/e): 6 months after doa Date of withdrawal of any conflicting National Standard (dow): 12 months after doa 65 Modal verbs terminology 66 In the present document "shall", "shall not", "should", "should not", "may", "need not", "will", "will not", "can" and 67 "cannot" are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of 68 provisions). 69 "must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation. 70 Introduction 71 Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic 72 identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC 73 (Regulation (EU) No 910/2014 hereinafter) [i.1] provides a legal framework to facilitate cross-border recognition 74 between existing national legal systems related to electronic registered delivery services. That framework aims to open 75 new market opportunities for European Union trust service providers to offer new pan-European electronic registered 76 delivery services. 77 An “Electronic Registered Delivery Service (ERDS hereinafter)” provides secure and reliable delivery of electronic 78 messages between parties, producing evidence of the delivery process for legal accountability. Evidence can be seen as 79 a declaration by a trusted party that a specific event related to the delivery process (submission of a message, delivery of 80 a message, refusal of a message, etc…) happened at a certain time. Evidence can be immediately delivered to the 81 interested party (together with the message or separately) or can be kept in a repository for later access by interested 82 parties. It is common practice to implement evidence as digitally signed data. 83 Regulation (EU) No 910/2014 defines the so-called Qualified Electronic Registered Delivery Services (QERDS 84 hereinafter). QERDS is a special type of ERDS. Both the service and the provider providing it meet a number of 85 additional requirements that the regular ERDS and its providers do not need to meet. 86 ETSI Draft ETSI EN 319 521 V0.0.4 (2017-10) 5 The above stated ERDS concept can be implemented in diverse ways, using different formats for identifiers and 87 evidences, using different protocols for messaging, and even different message delivery models. 88 89 ETSI Draft ETSI EN 319 521 V0.0.4 (2017-10) 6 1 Scope 90 The present document specifies generally applicable policy and security requirements for Electronic Registered 91 Delivery Services Providers (ERDSP), including the services they provide. 92 The present document is applicable to: 93  The policy and security requirements of the qualified and non qualified ERDSPs; 94  the general and security requirements of the qualified and non qualified Electronic Registered Delivery 95 Services (ERDS) in terms of message integrity; protection against loss, theft, damage or any unauthorised 96 alteration of the data transmitted; sender and recipient strong identification; time reference; and proof of data’s 97 sending and receiving. 98 The present document does not specify interconnection requirements. 99 100 2 References 101 2.1 Normative references 102 References are either specific (identified by date of publication and/or edition number or version number) or 103 non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the 104 referenced document (including any amendments) applies. 105 Referenced documents which are not found to be publicly available in the expected location might be found at 106 http://docbox.etsi.org/Reference. 107 NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee 108 their long term validity. 109 The following referenced documents are necessary for the application of the present document. 110 [1] ETSI EN 319 401: "Electronic Signatures and Infrastructures (ESI); General Policy Requirements 111 for Trust Service Providers". 112 2.2 Informative references 113 References are either specific (identified by date of publication and/or edition number or version number) or 114 non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the 115 referenced document (including any amendments) applies. 116 NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee 117 their long term validity. 118 The following referenced documents are not necessary for the application of the present document but they assist the 119 user with regard to a particular subject area. 120 [i.1] Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on 121 electronic identification and trust services for electronic transactions in the internal market and 122 repealing Directive 1999/93/EC. 123 [i.2] ETSI EN 319 411-1: “Electronic Signatures and Infrastructures (ESI); Policy and security 124 requirements for Trust Service Providers issuing certificates; Part 1: General Requirements”. 125 [i.3.] ETSI EN 319 411-2: “Electronic Signatures and Infrastructures (ESI); Policy and security 126 requirements for Trust Service Providers issuing certificates; Part 2: Requirements for trust service 127 providers issuing EU qualified certificates”. 128 [i.4] ETSI EN 319 421: “Electronic Signatures and Infrastructures (ESI); Policy and Security 129 Requirements for Trust Service Providers issuing Electronic Time-Stamps”. 130 ETSI Draft ETSI EN 319 521 V0.0.4 (2017-10) 7 3 Definitions and abbreviations 131 3.1 Definitions 132 For the purposes of the present document, the terms and definitions given in ETSI EN 319 401 [1] and the following 133 apply: 134 electronic registered delivery service (ERDS): electronic service that makes possible to transmit data between the 135 sender and recipients by electronic means and provides evidence relating to the handling of the transmitted data, 136 including proof of sending and receiving the data, and that protects transmitted data against the risk of loss, theft, 137 damage or any unauthorised alterations 138 139 electronic registered delivery service provider: Trust Service Provider which provides electronic registered delivery 140 services 141 142 electronic registered delivery service practice statement: statement of the practices that an electronic registered 143 delivery service provider employs in providing an electronic delivery service 144 NOTE: See clause 4 for further information on practice statement 145 146 ERDS evidence: data generated within the electronic registered delivery service, which aims to prove that a certain 147 event has occurred at a certain time 148 user content: original data produced by the sender which has to be delivered to the recipient 149 qualified electronic registered delivery service: As specified in Regulation (EU) No 910/2014 [i.1] 150 qualified electronic registered delivery service provider: Trust Service Provider which provides qualified electronic 151 registered delivery services 152 recipient: natural or legal person to which the user content is addressed 153 sender: natural or legal person that submits the user content 154 NOTE: In the present document, recipients and senders are assumed to be natural or legal persons. 155 156 3.2 Abbreviations 157 For the purposes of the present document, the following abbreviations apply: 158 ERDS Electronic Registered Delivery Service 159 ERDSP Electronic Registered Delivery Service Provider 160 QERDS Qualified Electronic Registered Delivery Service 161 QERDSP Qualified Electronic Registered Delivery Service Provider 162 163 3.3 Notation 164 The requirements identified in the present document include: 165 a) requirements applicable to any ERDSP and ERDS provided. Such requirements are indicated by clauses 166 without any additional marking; 167 b) requirements applicable under certain conditions. Such requirements are indicated by clauses marked by 168 "[CONDITIONAL]"; 169 ETSI Draft ETSI EN 319 521 V0.0.4 (2017-10) 8 c) requirements that include several choices which ought to be selected according to the applicable situation. 170 Such requirements are indicated by clauses marked by "[CHOICE]"; 171 d) <the 3 letters REQ> - <4-5 letters type of service, whether qualified (QERDS) or non-qualified (ERDS)> < the 172 clause number> - <2 digit number - incremental>.optional<1 lowercase letter ) to distinct elements from a list> 173 All ERDS and ERDSP requirements shall apply to QERDS and QERDSP. 174 175 4 General provision on policies and practices 176 4.1 ERDS Practice statement 177 REQ-ERDS-4.1-01 All requirements from EN 319 401[1] clause 6.1 shall apply. 178 REQERDS-4.1-02 The ERDSP shall have a management body with overall responsibility for the ERDSP with final 179 authority for approving the ERDSP practice statement. 180 REQERDS-4.1-03 The ERDS set of policies and practices shall be approved by the ERDSP management, published 181 and communicated to its employees and external parties as relevant. 182 REQERDS 4.1-04 The ERDSP shall have a ERDS practice statement publicly available on its website or any other 183 electronic means of the practices and procedures used to address the requirements on both the ERDSP and the ERDS 184 provided. 185 NOTE: The ERDSP is not obliged to disclose any aspects containing sensitive information. 186 REQERDS-4.1-05 The ERDSP shall make available to subscribers and relying parties its ERDS practice statement. 187 REQERDS-4.1-06 The ERDSP shall define a review process for the practices including responsibilities for 188 maintaining the ERDS practice statement and a process to notify changes it intends to make in its ERDS practice 189 statement 190 REQERDS-4.1-07 The ERDS practice statement shall identify the obligations of all external organizations supporting 191 the provision of ERDS including the applicable policies and practices. 192 REQERDS-4.1-08 The ERDS practice statement shall specify the means used to report any modifications to user 193 content before relay and delivery. 194 In addition, for QERDSP and QERDS, the following specific requirements apply.: 195 REQ-QERDS-4.1-01 The QERDS practice statement shall Include a clear statement indicating that the policy is for 196 qualified ERDS a per Regulation (EU) No 910/2014 [i.1]; 197 REQ-QERDS-4.1-02 The QERDS practice statement shall Include the complete list of TSPs and QTSPs involved in 198 the provision of the QERDS; 199 EXAMPLE: Time-stamping service, TSPs issuing certificates… 200 REQ-QERDS-4.1-03 The QERDS practice statement shall Include a description on how the security of transmission 201 against any risk of loss, theft, damage or any unauthorised alterations, is ensured. 202 REQ-QERDS-4.1-04 The QERDS practice statement shall Include any limitations on the use of the QERDS; 203 REQ-QERDS-4.1-05 The QERDS practice statement shall Include the sender, recipient and other relying parties 204 obligations; 205 REQ-QERDS-4.1-06 The QERDS practice statement shall Describe how sender and recipient are identified and 206 authenticated to the sevice; 207 REQ-QERDS-4.1-07 The QERDS practice statement shall Include information on how to get evidence relating to the 208 handling of the transmitted data 209 REQ-QERDS-4.1-08 The QERDS practice statement shall Include any possible limitations on the evidence validity 210 period; 211 ETSI Draft ETSI EN 319 521 V0.0.4 (2017-10) 9 REQ-QERDS-4.1-09 The QERDS practice statement shall Include the retention period actually applied to the evidence 212 as per clause 5.4.1. and, where applicable, the modalities of reversibility and portability; and 213 REQ-QERDS-4.1-10 The QERDS practice statement shall State the provisions made for termination of service. 214 215 4.2 Terms and conditions 216 REQ-ERDS-4.2-01 All requirements from EN 319 401[1] clause 6.2 shall apply. 217 REQERDS-4.2-02 The terms and conditions shall indicate what is deemed to constitute a delivery of the user content 218 to the recipient. 219 REQERDS-4.2-03 The terms and conditions shall indicate if any expiracy of data availability to the recipient is 220 handled and, if applicable, how long the data are available. 221 REQERDS-4.2-04 Before entering into a contractual relationship with an ERDSP customer, the ERDSP shall inform 222 the sender of the terms and conditions regarding the ERDS. 223 i) REQERDS-4.2-05 The ERDSP shall communicate the terms and conditions through a durable (i.e. with 224 integrity over time) mean of communication, and in a human readable form. 225 ii) REQERDS-4.2-06 The terms and conditions may be transmitted electronically. 226 REQERDS-4.2-07 The ERDSP shall have evidence that the terms and conditions have been accepted by the sender. 227 228 4.3 Information security policy 229 REQ-ERDS-4.3-01 All requirements from EN 319 401[1] clause 6.3 shall apply. 230 231 5 General provision on ERDS 232 5.1 User content integrity and confidentiality 233 REQ-ERDS-5.1-01 The ERDS shall ensure that availability, integrity, and confidentiality of the user content is 234 adequately guaranteed from the sending to the reception of the user content. 235 REQEDRS-5.1-02 The confidentiality of sender/recipient identification shall be protected, especially when 236 exchanged with the sender/recipient or between distributed ERDS system components. 237 In addition, the following QERDSP and QERDS-specific requirements and guidance apply. 238  REQ-QERDS-5.1-01 User content shall be protected by an advanced electronic seal or signature issued by a 239 QTSP in such a manner as to preclude the possibility of the data being changed undetectably; 240  REQ-QERDS-5.1-02 The integrity of user content shall be protected, especially when exchanged with the 241 sender/recipient or between distributed ERDS system components. 242  REQ-QERDS-5.1-03 [Conditional] If applicable, user content should be securely retained to meet statutory 243 requirements 244  REQ-QERDS-5.1-04 [Conditional] If the ERDSP has generated a qualified electronic seal or signature on the 245 user content, then the ERDSP shall be clearly identified in the certificate used for generating such seal or 246 signature. 247  REQ-QERDS-5.1-05 [Conditional] If the qualified electronic seal or signature on the user content is 248 generated by another QTSP, then the ERDSP shall verify the validity of the generated signature or seal, and 249 check that the TSP generating the signature or seal is still qualified. 250