The TSA shall ensure conformance with the procedures prescribed in
this policy, even when the TSA functionality is undertaken by sub-
contractors.
The TSA shall also ensure adherence to any additional obligations
indicated in the time-stamp either directly or incorporated by
reference.
The TSA shall provide all its time-stamping services consistent with
its practice statement.
6.1.2. TSA Obligations Towards Subscribers
The TSA shall meet its claims as given in its terms and conditions
including the availability and accuracy of its service.
6.2. Subscriber Obligations
The current document places no specific obligations on the subscriber
beyond any TSA specific requirements stated in the TSA’s terms and
condition.
NOTE: It is advisable that, when obtaining a time-stamp token, the
subscriber verifies that the time-stamp token has been correctly
signed and that the private key used to sign the time-stamp token has
not been compromised.
6.3. Relying Party Obligations
The terms and conditions made available to relying parties (see
section 7.1.2) shall include an obligation on the relying party that,
when relying on a time-stamp token, it shall:
a) verify that the time-stamp token has been correctly signed and
that the private key used to sign the time-stamp has not been
compromised until the time of the verification;
NOTE: During the TSU’s certificate validity period, the validity
of the signing key can be checked using current revocation status
for the TSU’s certificate. If the time of verification exceeds
the end of the validity period of the corresponding certificate,
see annex C for guidance.
b) take into account any limitations on the usage of the time-stamp
indicated by the time-stamp policy;
c) take into account any other precautions prescribed in agreements
or elsewhere.
6.4. Liability
The present document does not specify any requirement on liability.
In particular, it should be noticed that a TSA may disclaim or limit
any liability unless otherwise stipulated by the applicable law.
7. Requirements on TSA Practices
The TSA shall implement the controls that meet the following
requirements.
These policy requirements are not meant to imply any restrictions on
charging for TSA services.
The requirements are indicated in terms of the security objectives,
followed by more specific requirements for controls to meet those
objectives where it is necessary to provide confidence that those
objective will be met.
NOTE: The details of controls required to meet an objective is a
balance between achieving the necessary confidence whilst
minimizing the restrictions on the techniques that a TSA may
employ in issuing time-stamp tokens. In the case of section 7.4
(TSA management and operation), a reference is made to a source of
more detailed control requirements. Due to these factors the
specificity of the requirements given under a given topic may
vary.
The provision of a time-stamp token in response to a request is at
the discretion of the TSA depending on any service level agreements
with the subscriber.
7.1. Practice and Disclosure Statements
7.1.1. TSA Practice Statement
The TSA shall ensure that it demonstrates the reliability necessary
for providing time-stamping services.
In particular:
a) The TSA shall have a risk assessment carried out in order to
evaluate business assets and threats to those assets in order to
determine the necessary security controls and operational
procedures.
b) The TSA shall have a statement of the practices and procedures
used to address all the requirements identified in this time-stamp
policy.
NOTE 1: This policy makes no requirement as to the structure of
the TSA practice statement.
c) The TSA’s practice statement shall identify the obligations of all
external organizations supporting the TSA services including the
applicable policies and practices.
d) The TSA shall make available to subscribers and relying parties
its practice statement, and other relevant documentation, as
necessary, to assess conformance to the time-stamp policy.
NOTE 2: The TSA is not generally required to make all the details
of its practices public.
e) The TSA shall disclose to all subscribers and potential relying
parties the terms and conditions regarding use of its time-
stamping services as specified in section 7.1.2.
f) The TSA shall have a high level management body with final
authority for approving the TSA practice statement.
g) The senior management of the TSA shall ensure that the practices
are properly implemented.
h) The TSA shall define a review process for the practices including
responsibilities for maintaining the TSA practice statement.
i) The TSA shall give due notice of changes it intends to make in its
practice statement and shall, following approval as in (f) above,
make the revised TSA practice statement immediately available as
required under (d) above.
7.1.2. TSA Disclosure Statement
The TSA shall disclose to all subscribers and potential relying
parties the terms and conditions regarding use of its time-stamping
services. This statement shall at least specify for each time-stamp
policy supported by the TSA:
a) The TSA contact information.
b) The time-stamp policy being applied.
c) At least one hashing algorithm which may be used to represent the
datum being time-stamped. (No hash algorithm is mandated).
d) The expected life-time of the signature used to sign the time-
stamp token (depends on the hashing algorithm being used, the
signature algorithm being used and the private key length).
e) The accuracy of the time in the time-stamp tokens with respect to
UTC.
f) Any limitations on the use of the time-stamping service.
g) The subscriber’s obligations as defined in section 6.2, if any.
h) The relying party’s obligations as defined in section 6.3.
i) Information on how to verify the time-stamp token such that the
relying party is considered to "reasonably rely" on the time-stamp
token (see section 6.3) and any possible limitations on the
validity period.
j) The period of time during which TSA event logs (see section
7.4.10) are retained.
k) The applicable legal system, including any claim to meet the
requirements on time-stamping services under national law.
l) Limitations of liability.
m) Procedures for complaints and dispute settlement.
n) If the TSA has been assessed to be conformant with the identified
time-stamp policy, and if so by which independent body.
NOTE 1: It is also recommended that the TSA includes in its
time-stamping disclosure statement availability of its service,
for example the expected mean time between failure of the time-
stamping service, the mean time to recovery following a failure,
and provisions made for disaster recovery including back-up
services;
This information shall be available through a durable means of
communication. This information shall be available in a readily
understandable language. It may be transmitted electronically.
NOTE 2: A model TSA disclosure statement which may be used as the
basis of such a communication is given in annex D. Alternatively
this may be provided as part of a subscriber / relying party
agreement. These TSA disclosure statements may be included in a
TSA practice statement provided that they are conspicuous to the
reader.
7.2. Key Management Life Cycle
7.2.1. TSA Key Generation
The TSA shall ensure that any cryptographic keys are generated in
under controlled circumstances.
In particular:
a) The generation of the TSU’s signing key(s) shall be undertaken in
a physically secured environment (see section 7.4.4) by personnel
in trusted roles (see section 7.4.3) under, at least, dual
control. The personnel authorized to carry out this function
shall be limited to those requiring to do so under the TSA’s
practices.
b) The generation of the TSU’s signing key(s) shall be carried out
within a cryptographic module(s) which either:
- meets the requirements identified in FIPS 140-1 [FIPS 140-1]
level 3 or higher, or
- meets the requirements identified in CEN Workshop Agreement
14167-2 [CWA 14167-2], or
- is a trustworthy system which is assured to EAL 4 or higher in
accordance to ISO 15408 [ISO 15408], or equivalent security
criteria. This shall be to a security target or protection
profile which meets the requirements of the current document,
based on a risk analysis and taking into account physical and
other non-technical security measures.
c) The TSU key generation algorithm, the resulting signing key length
and signature algorithm used for signing time-stamp tokens key
shall be recognized by any national supervisory body, or in
accordance with existing current state of art, as being fit for
the purposes of time-stamp tokens as issued by the TSA.
7.2.2. TSU Private Key Protection
The TSA shall ensure that TSU private keys remain confidential and
maintain their integrity.
In particular:
a) The TSU private signing key shall be held and used within a
cryptographic module which:
- meets the requirements identified in FIPS 140-1 [FIPS 140-1]
level 3 or higher; or
- meets the requirements identified in CEN Workshop Agreement
14167-2 [CWA 14167-2]; or
- is a trustworthy system which is assured to EAL 4 or higher in
accordance to ISO 15408 [ISO 15408], or equivalent security
criteria. This shall be a security target or protection profile
which meets the requirements of the current document, based on
a risk analysis and taking into account physical and other
non-technical security measures.
NOTE: Backup of TSU private keys is deprecated in order to
minimize risk of key compromise.
b) If TSU private keys are backed up, they shall be copied, stored
and recovered only by personnel in trusted roles using, at least,
dual control in a physically secured environment. (see section
7.4.4). The personnel authorized to carry out this function shall
be limited to those requiring to do so under the TSA’s practices.
c) Any backup copies of the TSU private signing keys shall be
protected to ensure its confidentiality by the cryptographic
module before being stored outside that device.
7.2.3. TSU Public Key Distribution
The TSA shall ensure that the integrity and authenticity of the TSU
signature verification (public) keys and any associated parameters
are maintained during its distribution to relying parties.
In particular:
a) TSU signature verification (public) keys shall be made available
to relying parties in a public key certificate.
NOTE: For example, TSU’s certificates may be issued by a
certification authority operated by the same organization as the
TSA, or issued by another authority.
b) The TSU’s signature verification (public) key certificate shall be
issued by a certification authority operating under a certificate
policy which provides a level of security equivalent to, or higher
than, this time-stamping policy.
7.2.4. Rekeying TSU’s Key
The life-time of TSU’s certificate shall be not longer than the
period of time that the chosen algorithm and key length is recognized
as being fit for purpose (see section 7.2.1c)).
NOTE 1: The following additional considerations apply when limiting
that lifetime:
- Section 7.4.10 requires that records concerning time-stamping
services shall be held for a period of time,as appropriate, for at
least 1 year after the expiration of the validity of the TSU’s
signing keys. The longer the validity period of the TSU
certificates will be, the longer the size of the records to be
kept will be.
- Should a TSU private key be compromised, then the longer the
life-time, the more affected time-stamp tokens there will be.
NOTE 2: TSU key compromise does not only depend on the
characteristics of the cryptographic module being used but also on
the procedures being used at system initialization and key export
(when that function is supported).
7.2.5. End of TSU Key Life Cycle
The TSA shall ensure that TSU private signing keys are not used
beyond the end of their life cycle.
In particular:
a) Operational or technical procedures shall be in place to ensure
that a new key is put in place when a TSU’s key expires.
b) The TSU private signing keys, or any key part, including any
copies shall be destroyed such that the private keys cannot be
retrieved.
c) The TST generation system SHALL reject any attempt to issue TSTs
if the signing private key has expired.
7.2.6. Life Cycle Management of the Cryptographic Module used to Sign
Time-Stamps
The TSA shall ensure the security of cryptographic hardware
throughout its lifecycle.
In particular the TSA shall ensure that:
a) Time-stamp token signing cryptographic hardware is not tampered
with during shipment;
b) Time-stamp token signing cryptographic hardware is not tampered
with while stored;
c) Installation, activation and duplication of TSU’s signing keys in
cryptographic hardware shall be done only by personnel in trusted
roles using, at least, dual control in a physically secured
environment. (see section 7.4.4);
d) Time-stamp token signing cryptographic hardware is functioning
correctly; and
e) TSU private signing keys stored on TSU cryptographic module are
erased upon device retirement.
7.3. Time-Stamping
7.3.1. Time-Stamp Token
The TSA shall ensure that time-stamp tokens are issued securely and
include the correct time.
In particular:
a) The time-stamp token shall include an identifier for the time-
stamp policy;
b) Each time-stamp token shall have a unique identifier;
c) The time values the TSU uses in the time-stamp token shall be
traceable to at least one of the real time values distributed by a
UTC(k) laboratory.
NOTE 1: The Bureau International des Poids et Mesures (BIPM)
computes UTC on the basis of its local representations UTC(k) from
a large ensemble of atomic clocks in national metrology institutes
and national astronomical observatories round the world. The BIPM
disseminates UTC through its monthly Circular T [list 1]. This is
available on the BIPM website (www.bipm.org) and it officially
identifies all those institutes having recognized UTC(k) time
scales.
d) The time included in the time-stamp token shall be synchronized
with UTC within the accuracy defined in this policy and, if
present, within the accuracy defined in the time-stamp token
itself;
e) If the time-stamp provider’s clock is detected (see section
7.3.2c)) as being out of the stated accuracy (see section 7.1.2e))
then time-stamp tokens shall not be issued.
f) The time-stamp token shall include a representation (e.g., hash
value) of the datum being time-stamped as provided by the
requestor;
g) The time-stamp token shall be signed using a key generated
exclusively for this purpose.
NOTE 2: A protocol for a time-stamp token is defined in RFC 3631
and profiled in TS 101 861 [TS 101861].
NOTE 3: In the case of a number of requests at approximately the
same time, the ordering of the time within the accuracy of the TSU
clock is not mandated.
h) The time-stamp token shall include:
- where applicable, an identifier for the country in which the
TSA is established;
- an identifier for the TSA;
- an identifier for the unit which issues the time-stamps.
7.3.2. Clock Synchronization with UTC
The TSA shall ensure that its clock is synchronized with UTC within
the declared accuracy.
In particular:
a) The calibration of the TSU clocks shall be maintained such that
the clocks shall not be expected to drift outside the declared
accuracy.
b) The TSU clocks shall be protected against threats which could
result in an undetected change to the clock that takes it outside
its calibration.
NOTE 1: Threats may include tampering by unauthorized personnel,
radio or electrical shocks.
c) The TSA shall ensure that, if the time that would be indicated in
a time-stamp token drifts or jumps out of synchronization with
UTC, this will be detected (see also 7.3.1e)).
NOTE 2: Relying parties are required to be informed of such events
(see section 7.4.8).
d) The TSA shall ensure that clock synchronization is maintained when
a leap second occurs as notified by the appropriate body. The
change to take account of the leap second shall occur during the
last minute of the day when the leap second is scheduled to occur.
A record shall be maintained of the exact time (within the
declared accuracy) when this change occurred. See annex A for
more details.
NOTE 3: A leap second is an adjustment to UTC by skipping or
adding an extra second on the last second of a UTC month. First
preference is given to the end of December and June, and second
preference is given to the end of March and September.
7.4. TSA Management and Operation
7.4.1. Security Management
The TSA shall ensure that the administrative and management
procedures applied are adequate and correspond to recognized best
practice.
In particular:
TSA General
a) The TSA shall retain responsibility for all aspects of the
provision of time-stamping services within the scope of this
time-stamp policy, whether or not functions are outsourced to
subcontractors. Responsibilities of third parties shall be
clearly defined by the TSA and appropriate arrangements made to
ensure that third parties are bound to implement any controls
required by the TSA. The TSA shall retain responsibility for the
disclosure of relevant practices of all parties.
b) The TSA management shall provide direction on information security
through a suitable high level steering forum that is responsible
for defining the TSA’s information security policy. The TSA shall
ensure publication and communication of this policy to all
employees who are impacted by it.
c) The information security infrastructure necessary to manage the
security within the TSA shall be maintained at all times. Any
changes that will impact on the level of security provided shall
be approved by the TSA management forum.
NOTE 1: See ISO/IEC 17799 [ISO 17799] for guidance on information
security management including information security infrastructure,
management information security forum and information security
policies.
d) The security controls and operating procedures for TSA facilities,
systems and information assets providing the time-stamping
services shall be documented, implemented and maintained.
NOTE 2: The present documentation (commonly called a system
security policy or manual) should identify all relevant targets,
objects and potential threats related to the services provided and
the safeguards required to avoid or limit the effects of those
threats, consistent with the Risk Assessment required under
section 7.1.1a). It should describe the rules, directives and
procedures regarding how the specified services and the associated
security assurance are granted in addition to stating policy on
incidents and disasters.
e) TSA shall ensure that the security of information is maintained
when the responsibility for TSA functions has been outsourced to
another organization or entity.
7.4.2. Asset Classification and Management
The TSA shall ensure that its information and other assets receive an
appropriate level of protection.
In particular:
- The TSA shall maintain an inventory of all assets and shall assign
a classification for the protection requirements to those assets
consistent with the risk analysis.
7.4.3. Personnel Security
The TSA shall ensure that personnel and hiring practices enhance and
support the trustworthiness of the TSA’s operations.
In particular (TSA general):
a) The TSA shall employ personnel which possess the expert knowledge,
experience and qualifications necessary for the offered services
and as appropriate to the job function.
NOTE 1: TSA personnel should be able to fulfill the requirement of
"expert knowledge, experience and qualifications" through formal
training and credentials, actual experience, or a combination of
the two.
NOTE 2: Personnel employed by a TSA include individual personnel
contractually engaged in performing functions in support of the
TSA’s time-stamping services. Personnel who may be involved in
monitoring the TSA services need not be TSA personnel.
b) Security roles and responsibilities, as specified in the TSA’s
security policy, shall be documented in job descriptions. Trusted
roles, on which the security of the TSA’s operation is dependent,
shall be clearly identified.
c) TSA personnel (both temporary and permanent) shall have job
descriptions defined from the view point of separation of duties
and least privilege, determining position sensitivity based on the
duties and access levels, background screening and employee
training and awareness. Where appropriate, these shall
differentiate between general functions and TSA specific
functions. These should include skills and experience
requirements.
d) Personnel shall exercise administrative and management procedures
and processes that are in line with the TSA’s information security
management procedures (see section 7.4.1).
NOTE 3: See ISO/IEC 17799 [ISO 17799] for guidance.
The following additional controls shall be applied to time-
stamping management:
e) Managerial personnel shall be employed who possess:
- knowledge of time-stamping technology; and
- knowledge of digital signature technology; and
- knowledge of mechanisms for calibration or synchronization the
TSU clocks with UTC; and
- familiarity with security procedures for personnel with security
responsibilities; and
- experience with information security and risk assessment.
f) All TSA personnel in trusted roles shall be free from conflict of
interest that might prejudice the impartiality of the TSA
operations.
g) Trusted roles include roles that involve the following
responsibilities:
- Security Officers: Overall responsibility for administering the
implementation of the security practices.
- System Administrators: Authorized to install, configure and
maintain the TSA trustworthy systems for time-stamping