Device Centric Cloud Signature Solution under eIDAS Regulation

P. Scurtu, V. Patriciu
{"title":"Device Centric Cloud Signature Solution under eIDAS Regulation","authors":"P. Scurtu, V. Patriciu","doi":"10.32754/JMT.2020.2.08","DOIUrl":null,"url":null,"abstract":"Digital Object Identifier 10.32754/JMT.2020.2.08 49 1Abstract—Under the new eIDAS Regulation qualified electronic signatures are equivalent, from a legal stand, to handwritten signature. Traditional signature solutions make use of cryptographic materials stored in secure devices in possession of clients, while remote or cloud signatures solutions rely on a trusted service provider which manages the private keys and produces signatures in a remote manner. This shifts the weight of dealing with the keys off clients and moves this duty to a specialist in the field. As opposed to a classical Qualified Electronic Signature, a cloud-based solution has to solve a set of specific problems: the integrity of the data submitted must be ensured, the user’s intent of creating a digital signature must be demonstrated and the owner of the cryptographic key must be the only entity capable of using this cryptographic material. A device centric solution based on a simple mobile device application is proposed. This solution leverages the advancements in device technology such as the inclusion of Trusted Execution Environments (TEEs) on end user terminals. Furthermore, in comparison to similar solutions, the costs have been reduced by replacing cryptographic solutions based on SMS messages or cryptographic tokens with a device native implementation.","PeriodicalId":315050,"journal":{"name":"Journal of Military Technology","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-12-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Military Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.32754/JMT.2020.2.08","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Digital Object Identifier 10.32754/JMT.2020.2.08 49 1Abstract—Under the new eIDAS Regulation qualified electronic signatures are equivalent, from a legal stand, to handwritten signature. Traditional signature solutions make use of cryptographic materials stored in secure devices in possession of clients, while remote or cloud signatures solutions rely on a trusted service provider which manages the private keys and produces signatures in a remote manner. This shifts the weight of dealing with the keys off clients and moves this duty to a specialist in the field. As opposed to a classical Qualified Electronic Signature, a cloud-based solution has to solve a set of specific problems: the integrity of the data submitted must be ensured, the user’s intent of creating a digital signature must be demonstrated and the owner of the cryptographic key must be the only entity capable of using this cryptographic material. A device centric solution based on a simple mobile device application is proposed. This solution leverages the advancements in device technology such as the inclusion of Trusted Execution Environments (TEEs) on end user terminals. Furthermore, in comparison to similar solutions, the costs have been reduced by replacing cryptographic solutions based on SMS messages or cryptographic tokens with a device native implementation.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
eIDAS法规下以设备为中心的云签名解决方案
摘要-根据新的eIDAS法规,从法律立场来看,合格的电子签名等同于手写签名。传统的签名解决方案使用存储在客户端拥有的安全设备中的加密材料,而远程或云签名解决方案依赖于可信任的服务提供商,该服务提供商管理私钥并以远程方式生成签名。这就把处理客户钥匙的重担转移到了该领域的专家身上。与经典的合格电子签名相反,基于云的解决方案必须解决一系列具体问题:必须确保提交的数据的完整性,必须证明用户创建数字签名的意图,并且加密密钥的所有者必须是唯一能够使用该加密材料的实体。提出了一种基于简单移动设备应用的以设备为中心的解决方案。该解决方案利用了设备技术的进步,例如在终端用户终端上包含可信执行环境(tee)。此外,与类似的解决方案相比,通过使用设备本地实现替换基于SMS消息或加密令牌的加密解决方案,降低了成本。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Effect of Different Bracing Systems on the Performance of Metallic Tower Techniques Used for Geospatial Big Data Collection, Storage and Analysis Study on the Use of 3D Scanning as a Verification Method in Technical Quality Control Long-term Preservation of Digital Signatures: a Need-to-have or a Nice-to-have? GPU-Based Normalized Compression Distance for Satellite Images
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1