RFC 3628 - Policy Requirements for Time-Stamping Authorities(2)

时间:2006-10-21 来源: 作者: 点击:
TheTSAshallensureconformancewiththeproceduresprescribedin thispolicy,evenwhentheTSAfunctionalityisundertakenbysub- contractors. TheTSAshallalsoensureadherencetoanyadditionalobligations indicatedinthe
  

   The TSA shall ensure conformance with the procedures prescribed in
   this policy, even when the TSA functionality is undertaken by sub-
   contractors.

   The TSA shall also ensure adherence to any additional obligations
   indicated in the time-stamp either directly or incorporated by
   reference.

   The TSA shall provide all its time-stamping services consistent with
   its practice statement.

6.1.2.  TSA Obligations Towards Subscribers

   The TSA shall meet its claims as given in its terms and conditions
   including the availability and accuracy of its service.

6.2.  Subscriber Obligations

   The current document places no specific obligations on the subscriber
   beyond any TSA specific requirements stated in the TSA’s terms and
   condition.

   NOTE:  It is advisable that, when obtaining a time-stamp token, the
   subscriber verifies that the time-stamp token has been correctly
   signed and that the private key used to sign the time-stamp token has
   not been compromised.

6.3.  Relying Party Obligations

   The terms and conditions made available to relying parties (see
   section 7.1.2) shall include an obligation on the relying party that,
   when relying on a time-stamp token, it shall:

   a) verify that the time-stamp token has been correctly signed and
      that the private key used to sign the time-stamp has not been
      compromised until the time of the verification;

      NOTE: During the TSU’s certificate validity period, the validity
      of the signing key can be checked using current revocation status
      for the TSU’s certificate.  If the time of verification exceeds
      the end of the validity period of the corresponding certificate,
      see annex C for guidance.

   b) take into account any limitations on the usage of the time-stamp
      indicated by the time-stamp policy;

   c) take into account any other precautions prescribed in agreements
      or elsewhere.

6.4.  Liability

   The present document does not specify any requirement on liability.
   In particular, it should be noticed that a TSA may disclaim or limit
   any liability unless otherwise stipulated by the applicable law.

7.  Requirements on TSA Practices

   The TSA shall implement the controls that meet the following
   requirements.

   These policy requirements are not meant to imply any restrictions on
   charging for TSA services.

   The requirements are indicated in terms of the security objectives,
   followed by more specific requirements for controls to meet those
   objectives where it is necessary to provide confidence that those
   objective will be met.

      NOTE: The details of controls required to meet an objective is a
      balance between achieving the necessary confidence whilst
      minimizing the restrictions on the techniques that a TSA may
      employ in issuing time-stamp tokens.  In the case of section 7.4
      (TSA management and operation), a reference is made to a source of
      more detailed control requirements.  Due to these factors the
      specificity of the requirements given under a given topic may
      vary.

   The provision of a time-stamp token in response to a request is at
   the discretion of the TSA depending on any service level agreements
   with the subscriber.

7.1.  Practice and Disclosure Statements

7.1.1.  TSA Practice Statement

   The TSA shall ensure that it demonstrates the reliability necessary
   for providing time-stamping services.

   In particular:

   a) The TSA shall have a risk assessment carried out in order to
      evaluate business assets and threats to those assets in order to
      determine the necessary security controls and operational
      procedures.

   b) The TSA shall have a statement of the practices and procedures
      used to address all the requirements identified in this time-stamp
      policy.

      NOTE 1: This policy makes no requirement as to the structure of
      the TSA practice statement.

   c) The TSA’s practice statement shall identify the obligations of all
      external organizations supporting the TSA services including the
      applicable policies and practices.

   d) The TSA shall make available to subscribers and relying parties
      its practice statement, and other relevant documentation, as
      necessary, to assess conformance to the time-stamp policy.

      NOTE 2: The TSA is not generally required to make all the details
      of its practices public.

   e) The TSA shall disclose to all subscribers and potential relying
      parties the terms and conditions regarding use of its time-
      stamping services as specified in section 7.1.2.

   f) The TSA shall have a high level management body with final
      authority for approving the TSA practice statement.

   g) The senior management of the TSA shall ensure that the practices
      are properly implemented.

   h) The TSA shall define a review process for the practices including
      responsibilities for maintaining the TSA practice statement.

   i) The TSA shall give due notice of changes it intends to make in its
      practice statement and shall, following approval as in (f) above,
      make the revised TSA practice statement immediately available as
      required under (d) above.

7.1.2.  TSA Disclosure Statement

   The TSA shall disclose to all subscribers and potential relying
   parties the terms and conditions regarding use of its time-stamping
   services.  This statement shall at least specify for each time-stamp
   policy supported by the TSA:

   a) The TSA contact information.

   b) The time-stamp policy being applied.

   c) At least one hashing algorithm which may be used to represent the
      datum being time-stamped. (No hash algorithm is mandated).

   d) The expected life-time of the signature used to sign the time-
      stamp token (depends on the hashing algorithm being used, the
      signature algorithm being used and the private key length).

   e) The accuracy of the time in the time-stamp tokens with respect to
      UTC.

   f) Any limitations on the use of the time-stamping service.

   g) The subscriber’s obligations as defined in section 6.2, if any.

   h) The relying party’s obligations as defined in section 6.3.

   i) Information on how to verify the time-stamp token such that the
      relying party is considered to "reasonably rely" on the time-stamp
      token (see section 6.3) and any possible limitations on the
      validity period.

   j) The period of time during which TSA event logs (see section
      7.4.10) are retained.

   k) The applicable legal system, including any claim to meet the
      requirements on time-stamping services under national law.

   l) Limitations of liability.

   m) Procedures for complaints and dispute settlement.

   n) If the TSA has been assessed to be conformant with the identified
      time-stamp policy, and if so by which independent body.

      NOTE 1: It is also recommended that the TSA includes in its
      time-stamping disclosure statement availability of its service,
      for example the expected mean time between failure of the time-
      stamping service, the mean time to recovery following a failure,
      and provisions made for disaster recovery including back-up
      services;

      This information shall be available through a durable means of
      communication.  This information shall be available in a readily
      understandable language.  It may be transmitted electronically.

      NOTE 2: A model TSA disclosure statement which may be used as the
      basis of such a communication is given in annex D. Alternatively
      this may be provided as part of a subscriber / relying party
      agreement.  These TSA disclosure statements may be included in a
      TSA practice statement provided that they are conspicuous to the
      reader.

7.2.  Key Management Life Cycle

7.2.1.  TSA Key Generation

   The TSA shall ensure that any cryptographic keys are generated in
   under controlled circumstances.

   In particular:

   a) The generation of the TSU’s signing key(s) shall be undertaken in
      a physically secured environment (see section 7.4.4) by personnel
      in trusted roles (see section 7.4.3) under, at least, dual
      control.  The personnel authorized to carry out this function
      shall be limited to those requiring to do so under the TSA’s
      practices.

   b) The generation of the TSU’s signing key(s) shall be carried out
      within a cryptographic module(s) which either:

      -  meets the requirements identified in FIPS 140-1 [FIPS 140-1]
         level 3 or higher, or

      -  meets the requirements identified in CEN Workshop Agreement
         14167-2 [CWA 14167-2], or

      -  is a trustworthy system which is assured to EAL 4 or higher in
         accordance to ISO 15408 [ISO 15408], or equivalent security
         criteria.  This shall be to a security target or protection
         profile which meets the requirements of the current document,
         based on a risk analysis and taking into account physical and
         other non-technical security measures.

   c) The TSU key generation algorithm, the resulting signing key length
      and signature algorithm used for signing time-stamp tokens key
      shall be recognized by any national supervisory body, or in
      accordance with existing current state of art, as being fit for
      the purposes of time-stamp tokens as issued by the TSA.

7.2.2.  TSU Private Key Protection

   The TSA shall ensure that TSU private keys remain confidential and
   maintain their integrity.

   In particular:

   a) The TSU private signing key shall be held and used within a
      cryptographic module which:

      -  meets the requirements identified in FIPS 140-1 [FIPS 140-1]
         level 3 or higher; or

      -  meets the requirements identified in CEN Workshop Agreement
         14167-2 [CWA 14167-2]; or

      -  is a trustworthy system which is assured to EAL 4 or higher in
         accordance to ISO 15408 [ISO 15408], or equivalent security
         criteria. This shall be a security target or protection profile
         which meets the requirements of the current document, based on
         a risk analysis and taking into account physical and other
         non-technical security measures.

      NOTE: Backup of TSU private keys is deprecated in order to
      minimize risk of key compromise.

   b) If TSU private keys are backed up, they shall be copied, stored
      and recovered only by personnel in trusted roles using, at least,
      dual control in a physically secured environment. (see section
      7.4.4).  The personnel authorized to carry out this function shall
      be limited to those requiring to do so under the TSA’s practices.

   c) Any backup copies of the TSU private signing keys shall be
      protected to ensure its confidentiality by the cryptographic
      module before being stored outside that device.

7.2.3.  TSU Public Key Distribution

   The TSA shall ensure that the integrity and authenticity of the TSU
   signature verification (public) keys and any associated parameters
   are maintained during its distribution to relying parties.

   In particular:

   a) TSU signature verification (public) keys shall be made available
      to relying parties in a public key certificate.

      NOTE: For example, TSU’s certificates may be issued by a
      certification authority operated by the same organization as the
      TSA, or issued by another authority.

   b) The TSU’s signature verification (public) key certificate shall be
      issued by a certification authority operating under a certificate
      policy which provides a level of security equivalent to, or higher
      than, this time-stamping policy.

7.2.4.  Rekeying TSU’s Key

   The life-time of TSU’s certificate shall be not longer than the
   period of time that the chosen algorithm and key length is recognized
   as being fit for purpose (see section 7.2.1c)).

   NOTE 1: The following additional considerations apply when limiting
   that lifetime:

   -  Section 7.4.10 requires that records concerning time-stamping
      services shall be held for a period of time,as appropriate, for at
      least 1 year after the expiration of the validity of the TSU’s
      signing keys.  The longer the validity period of the TSU
      certificates will be, the longer the size of the records to be
      kept will be.

   -  Should a TSU private key be compromised, then the longer the
      life-time, the more affected time-stamp tokens there will be.

   NOTE 2: TSU key compromise does not only depend on the
   characteristics of the cryptographic module being used but also on
   the procedures being used at system initialization and key export
   (when that function is supported).

7.2.5.  End of TSU Key Life Cycle

   The TSA shall ensure that TSU private signing keys are not used
   beyond the end of their life cycle.

   In particular:

   a) Operational or technical procedures shall be in place to ensure
      that a new key is put in place when a TSU’s key expires.

   b) The TSU private signing keys, or any key part, including any
      copies shall be destroyed such that the private keys cannot be
      retrieved.

   c) The TST generation system SHALL reject any attempt to issue TSTs
      if the signing private key has expired.

7.2.6.  Life Cycle Management of the Cryptographic Module used to Sign
        Time-Stamps

   The TSA shall ensure the security of cryptographic hardware
   throughout its lifecycle.

   In particular the TSA shall ensure that:

   a) Time-stamp token signing cryptographic hardware is not tampered
      with during shipment;

   b) Time-stamp token signing cryptographic hardware is not tampered
      with while stored;

   c) Installation, activation and duplication of TSU’s signing keys in
      cryptographic hardware shall be done only by personnel in trusted
      roles using, at least, dual control in a physically secured
      environment. (see section 7.4.4);

   d) Time-stamp token signing cryptographic hardware is functioning
      correctly; and

   e) TSU private signing keys stored on TSU cryptographic module are
      erased upon device retirement.

7.3.  Time-Stamping

7.3.1.  Time-Stamp Token

   The TSA shall ensure that time-stamp tokens are issued securely and
   include the correct time.

   In particular:

   a) The time-stamp token shall include an identifier for the time-
      stamp policy;

   b) Each time-stamp token shall have a unique identifier;

   c) The time values the TSU uses in the time-stamp token shall be
      traceable to at least one of the real time values distributed by a
      UTC(k) laboratory.

      NOTE 1: The Bureau International des Poids et Mesures (BIPM)
      computes UTC on the basis of its local representations UTC(k) from
      a large ensemble of atomic clocks in national metrology institutes
      and national astronomical observatories round the world.  The BIPM
      disseminates UTC through its monthly Circular T [list 1].  This is
      available on the BIPM website (www.bipm.org) and it officially
      identifies all those institutes having recognized UTC(k) time
      scales.

   d) The time included in the time-stamp token shall be synchronized
      with UTC within the accuracy defined in this policy and, if
      present, within the accuracy defined in the time-stamp token
      itself;

   e) If the time-stamp provider’s clock is detected (see section
      7.3.2c)) as being out of the stated accuracy (see section 7.1.2e))
      then time-stamp tokens shall not be issued.

   f) The time-stamp token shall include a representation (e.g., hash
      value) of the datum being time-stamped as provided by the
      requestor;

   g) The time-stamp token shall be signed using a key generated
      exclusively for this purpose.

      NOTE 2: A protocol for a time-stamp token is defined in RFC 3631
      and profiled in TS 101 861 [TS 101861].

      NOTE 3: In the case of a number of requests at approximately the
      same time, the ordering of the time within the accuracy of the TSU
      clock is not mandated.

   h) The time-stamp token shall include:

      -  where applicable, an identifier for the country in which the
         TSA is established;

      -  an identifier for the TSA;

      -  an identifier for the unit which issues the time-stamps.

7.3.2.  Clock Synchronization with UTC

   The TSA shall ensure that its clock is synchronized with UTC within
   the declared accuracy.

   In particular:

   a) The calibration of the TSU clocks shall be maintained such that
      the clocks shall not be expected to drift outside the declared
      accuracy.

   b) The TSU clocks shall be protected against threats which could
      result in an undetected change to the clock that takes it outside
      its calibration.

      NOTE 1: Threats may include tampering by unauthorized personnel,
      radio or electrical shocks.

   c) The TSA shall ensure that, if the time that would be indicated in
      a time-stamp token drifts or jumps out of synchronization with
      UTC, this will be detected (see also 7.3.1e)).

      NOTE 2: Relying parties are required to be informed of such events
      (see section 7.4.8).

   d) The TSA shall ensure that clock synchronization is maintained when
      a leap second occurs as notified by the appropriate body.  The
      change to take account of the leap second shall occur during the
      last minute of the day when the leap second is scheduled to occur.
      A record shall be maintained of the exact time (within the
      declared accuracy) when this change occurred.  See annex A for
      more details.

      NOTE 3: A leap second is an adjustment to UTC by skipping or
      adding an extra second on the last second of a UTC month.  First
      preference is given to the end of December and June, and second
      preference is given to the end of March and September.

7.4.  TSA Management and Operation

7.4.1.  Security Management

   The TSA shall ensure that the administrative and management
   procedures applied are adequate and correspond to recognized best
   practice.

   In particular:

   TSA General

   a) The TSA shall retain responsibility for all aspects of the
      provision of time-stamping services within the scope of this
      time-stamp policy, whether or not functions are outsourced to
      subcontractors.  Responsibilities of third parties shall be
      clearly defined by the TSA and appropriate arrangements made to
      ensure that third parties are bound to implement any controls
      required by the TSA.  The TSA shall retain responsibility for the
      disclosure of relevant practices of all parties.

   b) The TSA management shall provide direction on information security
      through a suitable high level steering forum that is responsible
      for defining the TSA’s information security policy.  The TSA shall
      ensure publication and communication of this policy to all
      employees who are impacted by it.

   c) The information security infrastructure necessary to manage the
      security within the TSA shall be maintained at all times.  Any
      changes that will impact on the level of security provided shall
      be approved by the TSA management forum.

      NOTE 1: See ISO/IEC 17799 [ISO 17799] for guidance on information
      security management including information security infrastructure,
      management information security forum and information security
      policies.

   d) The security controls and operating procedures for TSA facilities,
      systems and information assets providing the time-stamping
      services shall be documented, implemented and maintained.

      NOTE 2: The present documentation (commonly called a system
      security policy or manual) should identify all relevant targets,
      objects and potential threats related to the services provided and
      the safeguards required to avoid or limit the effects of those
      threats, consistent with the Risk Assessment required under
      section 7.1.1a).  It should describe the rules, directives and
      procedures regarding how the specified services and the associated
      security assurance are granted in addition to stating policy on
      incidents and disasters.

   e) TSA shall ensure that the security of information is maintained
      when the responsibility for TSA functions has been outsourced to
      another organization or entity.

7.4.2.  Asset Classification and Management

   The TSA shall ensure that its information and other assets receive an
   appropriate level of protection.

   In particular:

    - The TSA shall maintain an inventory of all assets and shall assign
      a classification for the protection requirements to those assets
      consistent with the risk analysis.

7.4.3.  Personnel Security

   The TSA shall ensure that personnel and hiring practices enhance and
   support the trustworthiness of the TSA’s operations.

   In particular (TSA general):

   a) The TSA shall employ personnel which possess the expert knowledge,
      experience and qualifications necessary for the offered services
      and as appropriate to the job function.

      NOTE 1: TSA personnel should be able to fulfill the requirement of
      "expert knowledge, experience and qualifications" through formal
      training and credentials, actual experience, or a combination of
      the two.

      NOTE 2: Personnel employed by a TSA include individual personnel
      contractually engaged in performing functions in support of the
      TSA’s time-stamping services.  Personnel who may be involved in
      monitoring the TSA services need not be TSA personnel.

   b) Security roles and responsibilities, as specified in the TSA’s
      security policy, shall be documented in job descriptions.  Trusted
      roles, on which the security of the TSA’s operation is dependent,
      shall be clearly identified.

   c) TSA personnel (both temporary and permanent) shall have job
      descriptions defined from the view point of separation of duties
      and least privilege, determining position sensitivity based on the
      duties and access levels, background screening and employee
      training and awareness.  Where appropriate, these shall
      differentiate between general functions and TSA specific
      functions.  These should include skills and experience
      requirements.

   d) Personnel shall exercise administrative and management procedures
      and processes that are in line with the TSA’s information security
      management procedures (see section 7.4.1).

      NOTE 3: See ISO/IEC 17799 [ISO 17799] for guidance.

      The following additional controls shall be applied to time-
      stamping management:

   e) Managerial personnel shall be employed who possess:

      - knowledge of time-stamping technology; and
      - knowledge of digital signature technology; and

      - knowledge of mechanisms for calibration or synchronization the
        TSU clocks with UTC; and
      - familiarity with security procedures for personnel with security
        responsibilities; and
      - experience with information security and risk assessment.

   f) All TSA personnel in trusted roles shall be free from conflict of
      interest that might prejudice the impartiality of the TSA
      operations.

   g) Trusted roles include roles that involve the following
      responsibilities:

      -  Security Officers: Overall responsibility for administering the
         implementation of the security practices.

      -  System Administrators: Authorized to install, configure and
         maintain the TSA trustworthy systems for time-stamping
------分隔线----------------------------
顶一下
(0)
0%
踩一下
(0)
0%
------分隔线----------------------------
最新评论 查看所有评论
发表评论 查看所有评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
用户名: 密码: 验证码:
推荐内容