Electronic Signatures and Infrastructures (ESI); Electronic Signature Formats

The task will address the evaluation of the change requests by the EC concerning ETSI-EESSI standards, based on conclusions of the EC-led evaluation of EESSI deliverables and discussions, comments by the A9-Commettee. Although the formal requests has, as of yet, not been communicated to the EESSI, it became already clear that the focus of change proposals concerns TS 101 733, in particular to allow implementers and users to have more flexibility in chosing their options among the alternative formats. Another issue is to separate the format and policy parts of the standard. Any changes of TS 101 733 will propagate through the associated standards RFC  and TS 101 903, and the W3C-version of the latter, all based on TS 101 733. In order to maintain internationalisation of the base standard, the revised versions have to be submitted to IETF, respectively W3C.

Elektronski podpisi in infrastruktura (ESI) – Formati elektronskega podpisa

General Information

Status
Published
Publication Date
30-Apr-2005
Current Stage
6060 - National Implementation/Publication (Adopted Project)
Start Date
01-May-2005
Due Date
01-May-2005
Completion Date
01-May-2005

Buy Standard

Technical specification
TS ETSI/TS 101 733 V1.5.1:2005
English language
93 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)

SLOVENSKI STANDARD
SIST-TS ETSI/TS 101 733 V1.5.1:2005
01-maj-2005
Elektronski podpisi in infrastruktura (ESI) – Formati elektronskega podpisa
Electronic Signatures and Infrastructures (ESI); Electronic Signature Formats
Ta slovenski standard je istoveten z: TS 101 733 Version 1.5.1
ICS:
35.040 Nabori znakov in kodiranje Character sets and
informacij information coding
SIST-TS ETSI/TS 101 733 V1.5.1:2005 en
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

---------------------- Page: 1 ----------------------

SIST-TS ETSI/TS 101 733 V1.5.1:2005

---------------------- Page: 2 ----------------------

SIST-TS ETSI/TS 101 733 V1.5.1:2005

ETSI TS 101 733 V1.5.1 (2003-12)
Technical Specification


Electronic Signatures and Infrastructures (ESI);
Electronic Signature Formats

---------------------- Page: 3 ----------------------

SIST-TS ETSI/TS 101 733 V1.5.1:2005
 2 ETSI TS 101 733 V1.5.1 (2003-12)



Reference
RTS/ESI-000017
Keywords
electronic signature, security, e-commerce
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - NAF 742 C
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° 7803/88

Important notice
Individual copies of the present document can be downloaded from:
http://www.etsi.org
The present document may be made available in more than one electronic version or in print. In any case of existing or
perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF).
In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive
within ETSI Secretariat.
Users of the present document should be aware that the document may be subject to revision or change of status.
Information on the current status of this and other ETSI documents is available at
http://portal.etsi.org/tb/status/status.asp
If you find errors in the present document, send your comment to:
editor@etsi.org
Copyright Notification
No part may be reproduced except as authorized by written permission.
The copyright and the foregoing restriction extend to reproduction in all media.

© European Telecommunications Standards Institute 2003.
All rights reserved.

TM TM TM
DECT , PLUGTESTS and UMTS are Trade Marks of ETSI registered for the benefit of its Members.
TM
TIPHON and the TIPHON logo are Trade Marks currently being registered by ETSI for the benefit of its Members.
TM
3GPP is a Trade Mark of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners.
ETSI

---------------------- Page: 4 ----------------------

SIST-TS ETSI/TS 101 733 V1.5.1:2005
 3 ETSI TS 101 733 V1.5.1 (2003-12)
Contents
Intellectual Property Rights.7
Foreword.7
Introduction .7
1 Scope.8
2 References.9
3 Definitions and abbreviations.10
3.1 Definitions.10
3.2 Abbreviations.12
4 Overview.12
4.1 Major parties.13
4.2 Signatures policies.13
4.3 Electronic signature formats.14
4.3.1 Basic Electronic Signature (BES).14
4.3.2 Explicit Policy Electronic Signatures (EPES) .16
4.4 Electronic signature formats with validation data .16
4.4.1 Electronic Signature with Time (ES-T) .17
4.4.2 ES with Complete validation data references (ES-C) .17
4.4.3 Extended electronic signature formats.19
4.4.3.1 EXtended Long Electronic Signature (ES-X Long).19
4.4.3.2 EXtended Electronic Signature with Time Type 1 (ES-X Type 1).19
4.4.3.3 EXtended Electronic Signature with Time Type 2 (ES-X Type 2).20
4.4.3.4 EXtended Long Electronic Signature with Time (ES-X Long Type 1 or 2) .20
4.4.4 Archival Electronic Signature (ES-A) .21
4.5 Arbitration.21
4.6 Validation process.22
5 Electronic signature attributes .22
5.1 General syntax.22
5.2 Data content type.23
5.3 Signed-data content type .23
5.4 SignedData type.23
5.5 EncapsulatedContentInfo type.23
5.6 SignerInfo type.23
5.6.1 Message digest calculation process .24
5.6.2 Message signature generation process .24
5.6.3 Message signature verification process.24
5.7 Basic ES mandatory present attributes .24
5.7.1 Content type.24
5.7.2 Message digest.24
5.7.3 Signing certificate reference attributes .24
5.7.3.1 ESS signing certificate attribute definition .24
5.7.3.2 Other signing certificate attribute definition .25
5.8 Additional mandatory attributes for Explicit Policy-based Electronic Signatures .26
5.8.1 Signature policy identifier .26
5.9 CMS imported optional attributes .27
5.9.1 Signing time.27
5.9.2 Countersignature.27
5.10 ESS imported optional attributes.27
5.10.1 Content reference attribute.27
5.10.2 Content identifier attribute.28
5.10.3 Content hints attribute.28
5.11 Additional optional attributes defined in the present document .28
5.11.1 Commitment type indication attribute .28
5.11.2 Signer location attribute.30
ETSI

---------------------- Page: 5 ----------------------

SIST-TS ETSI/TS 101 733 V1.5.1:2005
 4 ETSI TS 101 733 V1.5.1 (2003-12)
5.11.3 Signer attributes attribute.30
5.11.4 Content time-stamp.30
5.12 Support for multiple signatures .31
5.12.1 Independent signatures.31
5.12.2 Embedded signatures.31
6 Additional Electronic Signature validation attributes .31
6.1 Electronic Signature Time-stamped (ES-T) .32
6.1.1 Signature time- stamp attribute definition .32
6.2 Complete validation reference data (ES-C).33
6.2.1 Complete certificate references attribute definition.33
6.2.2 Complete Revocation References attribute definition .33
6.2.3 Attribute certificate references attribute definition .35
6.2.4 Attribute revocation references attribute definition .35
6.3 Extended validation data (ES-X).35
6.3.1 Time-stamped validation data (ES-X Type 1 or Type 2).36
6.3.2 Long validation data (ES-X Long, ES-X Long Type 1 or 2).36
6.3.3 Certificate values attribute definition.36
6.3.4 Revocation values attribute definition .37
6.3.5 ES-C time-stamp attribute definition .37
6.3.6 Time-stamped certificates and crls references attribute definition .38
6.4 Archive validation data.38
6.4.1 Archive time-stamp attribute definition.38
7 Other standard data structures .40
7.1 Public-key certificate format.40
7.2 Certificate revocation list format.40
7.3 OCSP response format.40
7.4 Time-stamp token format .40
7.5 Name and attribute formats .40
7.6 Attribute certificate.41
8 Conformance requirements.41
8.1 Basic Electronic Signature (BES) .41
8.2 Explicit Policy-based Electronic Signature .41
8.3 Verification using time-stamping .42
8.4 Verification using secure records .42
Annex A (normative): ASN.1 definitions.43
A.1 Signature format definitions using X.208 (1988) ASN.1 syntax .43
A.2 Signature format definitions using X.680 (1997) ASN.1 syntax .48
Annex B (informative): Extended forms of Electronic Signatures .55
B.1 Extended forms of validation data.55
B.1.1 ES-X Long.55
B.1.2 ES-X Type 1.56
B.1.3 ES-X Type 2.57
B.1.4 ES-X Long Type 1 and ES-X Long Type 2 .58
B.2 Timestamp extensions.58
B.3 Archive validation data (ES-A).59
B.4 Example validation sequence .60
B.5 Additional optional features .63
Annex C (informative): General description .64
C.1 The signature policy.64
C.2 Signed information.65
C.3 Components of an electronic signature .65
ETSI

---------------------- Page: 6 ----------------------

SIST-TS ETSI/TS 101 733 V1.5.1:2005
 5 ETSI TS 101 733 V1.5.1 (2003-12)
C.3.1 Reference to the signature policy .65
C.3.2 Commitment type indication .65
C.3.3 Certificate identifier from the signer .66
C.3.4 Role attributes.66
C.3.4.1 Claimed role.66
C.3.4.2 Certified role.66
C.3.5 Signer location.67
C.3.6 Signing time.67
C.3.7 Content format.67
C.3.8 Content cross referencing.67
C.4 Components of validation data.67
C.4.1 Revocation status information.67
C.4.1.1 CRL information.68
C.4.1.2 OCSP information.68
C.4.2 Certification path.68
C.4.3 Time-stamping for long life of signatures .69
C.4.4 Time-stamping for long life of signature before CA key compromises .69
C.4.4.1 Time-stamping the ES with complete validation data (ES-X Type 1) .70
C.4.4.2 Time-stamping certificates and revocation information references (ES-X Type 2).70
C.4.5 Time-stamping for archive of signature .71
C.4.6 Reference to additional data .71
C.4.7 Time-stamping for mutual recognition.72
C.4.8 TSA key compromise.72
C.5 Multiple signatures.72
Annex D (informative): Data protocols to interoperate with TSPs.73
D.1 Operational protocols.73
D.1.1 Certificate retrieval.73
D.1.2 CRL retrieval.73
D.1.3 OnLine certificate status.73
D.1.4 Time-stamping.73
D.2 Management protocols.73
D.2.1 Request for certificate revocation.73
Annex E (informative): Security considerations.74
E.1 Protection of private key .74
E.2 Choice of algorithms.74
Annex F (informative): Example structured contents and MIME .75
F.1 General description.75
F.2 Header information.75
F.3 Content encoding.76
F.4 Multi-part content.76
F.5 S/MIME.76
Annex G (informative): Relationship to the European Directive and EESSI.79
G.1 Introduction.79
G.2 Electronic signatures and the directive.79
G.3 ETSI electronic signature formats and the directive .80
G.4 EESSI standards and classes of electronic signature.80
G.4.1 Structure of EESSI standardization .80
G.4.2 Classes of electronic signatures.80
G.4.3 EESSI classes and the ETSI electronic signature format .81
ETSI

---------------------- Page: 7 ----------------------

SIST-TS ETSI/TS 101 733 V1.5.1:2005
 6 ETSI TS 101 733 V1.5.1 (2003-12)
Annex H (informative): APIs for the generation and verification of electronic signatures tokens.82
H.1 Data framing.82
H.2 IDUP-GSS-APIs defined by the IETF .83
H.3 CORBA security interfaces defined by the OMG.83
Annex I (informative): Cryptographic algorithms.85
I.1 Digest algorithms.85
I.1.1 SHA-1.85
I.1.2 MD5.85
I.1.3 General.85
I.2 Digital signature algorithms.86
I.2.1 DSA.86
I.2.2 RSA.86
I.2.3 General.86
Annex J (informative): Guidance on naming.88
J.1 Allocation of names.88
J.2 Providing access to registration information.88
J.3 Naming schemes.89
J.3.1 Naming schemes for individual citizens.89
J.3.2 Naming schemes for employees of an organization .89
Annex K (informative): Bibliography.90
Hist
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.