RFC 3628 - Policy Requirements for Time-Stamping Authorities(3)

时间:2006-10-21 来源: 作者: 点击:
management. -SystemOperators:ResponsibleforoperatingtheTSAtrustworthy systemsonaday-to-daybasis.Authorizedtoperformsystem backupandrecovery. -SystemAuditors:Authorizedtoviewarchivesandauditlogsof the
  
         management.

      -  System Operators: Responsible for operating the TSA trustworthy
         systems on a day-to-day basis.  Authorized to perform system
         backup and recovery.

      -  System Auditors: Authorized to view archives and audit logs of
         the TSA trustworthy systems.

   h) TSA personnel shall be formally appointed to trusted roles by
      senior management responsible for security.

   i) The TSA shall not appoint to trusted roles or management any
      person who is known to have a conviction for a serious crime or
      other offense which affects his/her suitability for the position.
      Personnel shall not have access to the trusted functions until any
      necessary checks are completed.

      NOTE 4: In some countries it may not be possible for TSA to obtain
      information on past convictions without the collaboration of the
      candidate employee.

7.4.4.  Physical and Environmental Security

   The TSA shall ensure that physical access to critical services is
   controlled and physical risks to its assets minimized.

   In particular (general):

   a) For both the time-stamping provision and the time-stamping
      management:

      -  physical access to facilities concerned with time-stamping
         services shall be limited to properly authorized individuals;
      -  controls shall be implemented to avoid loss, damage or
         compromise of assets and interruption to business activities;
         and
      -  controls shall be implemented to avoid compromise or theft of
         information and information processing facilities.

   b) Access controls shall be applied to the cryptographic module to
      meet the requirements of security of cryptographic modules as
      identified in clauses 7.2.1 and 7.2.2.

   c) The following additional controls shall be applied to time-
      stamping management:

      -  The time-stamping management facilities shall be operated in an
         environment which physically protects the services from
         compromise through unauthorized access to systems or data.

      -  Physical protection shall be achieved through the creation of
         clearly defined security perimeters (i.e., physical barriers)
         around the time-stamping management.  Any parts of the premises
         shared with other organizations shall be outside this
         perimeter.

      -  Physical and environmental security controls shall be
         implemented to protect the facility that houses system
         resources, the system resources themselves, and the facilities
         used to support their operation.  The TSA’s physical and
         environmental security policy for systems concerned with time-
         stamping management shall address as a minimum the physical
         access control, natural disaster protection, fire safety
         factors, failure of supporting utilities (e.g., power,
         telecommunications), structure collapse, plumbing leaks,
         protection against theft, breaking and entering, and disaster
         recovery.

      -  Controls shall be implemented to protect against equipment,
         information, media and software relating to the time-stamping
         services being taken off-site without authorization.

      NOTE 1: See ISO/IEC 17799 [ISO 17799] for guidance on physical and
      environmental security.

      NOTE 2: Other functions may be supported within the same secured
      area provided that the access is limited to authorized personnel.

7.4.5.  Operations Management

   The TSA shall ensure that the TSA system components are secure and
   correctly operated, with minimal risk of failure:

   In particular (general):

   a) The integrity of TSA system components and information shall be
      protected against viruses, malicious and unauthorized software.

   b) Incident reporting and response procedures shall be employed in
      such a way that damage from security incidents and malfunctions
      shall be minimized.

   c) Media used within the TSA trustworthy systems shall be securely
      handled to protect media from damage, theft, unauthorized access
      and obsolescence.

      NOTE 1: Every member of personnel with management responsibilities
      is responsible for planning and effectively implementing the
      time-stamp policy and associated practices as documented in the
      TSA practice statement.

   d) Procedures shall be established and implemented for all trusted
      and administrative roles that impact on the provision of time-
      stamping services.

   Media handling and security

   e) All media shall be handled securely in accordance with
      requirements of the information classification scheme (see section
      7.4.2).  Media containing sensitive data shall be securely
      disposed of when no longer required.

   System Planning

   f) Capacity demands shall be monitored and projections of future
      capacity requirements made to ensure that adequate processing
      power and storage are available.

   Incident reporting and response

   g) The TSA shall act in a timely and coordinated manner in order to
      respond quickly to incidents and to limit the impact of breaches
      of security.  All incidents shall be reported as soon as possible
      after the incident.

   The following additional controls shall be applied to time-stamping
   management:

   Operations procedures and responsibilities

   h) TSA security operations shall be separated from other operations.

      NOTE 2: TSA security operations’ responsibilities include:

         -  operational procedures and responsibilities;
         -  secure systems planning and acceptance;
         -  protection from malicious software;
         -  housekeeping;
         -  network management;
         -  active monitoring of audit journals, event analysis and
            follow-up;
         -  media handling and security;
         -  data and software exchange.

   These operations shall be managed by TSA trusted personnel, but, may
   actually be performed by, non-specialist, operational personnel
   (under supervision), as defined within the appropriate security
   policy, and, roles and responsibility documents.

7.4.6.  System Access Management

   The TSA shall ensure that TSA system access is limited to properly
   authorized individuals.

   In particular (general):

   a) Controls (e.g., firewalls) shall be implemented to protect the
      TSA’s internal network domains from unauthorized access including
      access by subscribers and third parties.

      NOTE 1: Firewalls should also be configured to prevent all
      protocols and accesses not required for the operation of the TSA.

   b) The TSA shall ensure effective administration of user (this
      includes operators, administrators and auditors) access to
      maintain system security, including user account management,
      auditing and timely modification or removal of access.

   c) The TSA shall ensure that access to information and application
      system functions is restricted in accordance with the access
      control policy and that the TSA system provides sufficient
      computer security controls for the separation of trusted roles
      identified in TSA’s practices, including the separation of
      security administrator and operation functions.  Particularly, use
      of system utility programs is restricted and tightly controlled.

   d) TSA personnel shall be properly identified and authenticated
      before using critical applications related to time-stamping.

   e) TSA personnel shall be accountable for their activities, for
      example by retaining event logs (see section 7.4.10).

   The following additional controls shall be applied to time-stamping
   management:

   f) The TSA shall ensure that local network components (e.g., routers)
   are kept in a physically secure environment and that their
   configurations are periodically audited for compliance with the
   requirements specified by the TSA.

   g) Continuous monitoring and alarm facilities shall be provided to
   enable the TSA to detect, register and react in a timely manner upon
   any unauthorized and/or irregular attempts to access its resources.

   NOTE 2: This may use, for example, an intrusion detection system,
   access control monitoring and alarm facilities.

7.4.7.  Trustworthy Systems Deployment and Maintenance

   The TSA shall use trustworthy systems and products that are protected
   against modification.

   NOTE: The risk analysis carried out on the TSA’s services (see
   section 7.1.1) should identify its critical services requiring
   trustworthy systems and the levels of assurance required.

   In particular:

   a) An analysis of security requirements shall be carried out at the
      design and requirements specification stage of any systems
      development project undertaken by the TSA or on behalf of the TSA
      to ensure that security is built into IT systems.

   b) Change control procedures shall be applied for releases,
      modifications and emergency software fixes of any operational
      software.

7.4.8.  Compromise of TSA Services

   The TSA shall ensure in the case of events which affect the security
   of the TSA’s services, including compromise of TSU’s private signing
   keys or detected loss of calibration, that relevant information is
   made available to subscribers and relying parties.

   In particular:

   a) The TSA’s disaster recovery plan shall address the compromise or
      suspected compromise of TSU’s private signing keys or loss of
      calibration of a TSU clock, which may have affected time-stamp
      tokens which have been issued.

   b) In the case of a compromise, or suspected compromise or loss of
      calibration the TSA shall make available to all subscribers and
      relying parties a description of compromise that occurred.

   c) In the case of compromise to a TSU’s operation (e.g., TSU key
      compromise), suspected compromise or loss of calibration the TSU
      shall not issue time-stamp tokens until steps are taken to recover
      from the compromise

   d) In case of major compromise of the TSA’s operation or loss of
      calibration, wherever possible, the TSA shall make available to
      all subscribers and relying parties information which may be used
      to identify the time-stamp tokens which may have been affected,
      unless this breaches the privacy of the TSAs users or the security
      of the TSA services.

      NOTE:  In case the private key does become compromised, an audit
      trail of all tokens generated by the TSA may provide a means to
      discriminate between genuine and false backdated tokens.  Two
      time-stamp tokens from two different TSAs may be another way to
      address this issue.

7.4.9.  TSA Termination

   The TSA shall ensure that potential disruptions to subscribers and
   relying parties are minimized as a result of the cessation of the
   TSA’s time-stamping services, and in particular ensure continued
   maintenance of information required to verify the correctness of
   time-stamp tokens.

   In particular:

   a) Before the TSA terminates its time-stamping services the following
      procedures shall be executed as a minimum:

      -  the TSA shall make available to all subscribers and relying
         parties information concerning its termination;

      -  TSA shall terminate authorization of all subcontractors to act
         on behalf of the TSA in carrying out any functions relating to
         the process of issuing time-stamp tokens;

      -  the TSA shall transfer obligations to a reliable party for
         maintaining event log and audit archives (see section 7.4.10)
         necessary to demonstrate the correct operation of the TSA for a
         reasonable period;

      -  the TSA shall maintain or transfer to a reliable party its
         obligations to make available its public key or its
         certificates to relying parties for a reasonable period;

      -  TSU private keys, including backup copies, shall be destroyed
         in a manner such that the private keys cannot be retrieved.

   b) The TSA shall have an arrangement to cover the costs to fulfill
      these minimum requirements in case the TSA becomes bankrupt or for
      other reasons is unable to cover the costs by itself.

   c) The TSA shall state in its practices the provisions made for
      termination of service.  This shall include:

      - notification of affected entities;
      - transferring the TSA obligations to other parties.

   d) The TSA shall take steps to have the TSU’s certificates revoked.

7.4.10.  Compliance with Legal Requirements

   The TSA shall ensure compliance with legal requirements.

   In particular:

   a) The TSA shall ensure that the requirements of the European data
      protection Directive [Dir 95/46/EC], as implemented through
      national legislation, are met.

   b) Appropriate technical and organizational measures shall be taken
      against unauthorized or unlawful processing of personal data and
      against accidental loss or destruction of, or damage to, personal
      data.

   c) The information contributed by users to the TSA shall be
      completely protected from disclosure unless with their agreement
      or by court order or other legal requirement.

7.4.11.  Recording of Information Concerning Operation of Time-Stamping
         Services

   The TSA shall ensure that all relevant information concerning the
   operation of time-stamping services is recorded for a defined period
   of time, in particular for the purpose of providing evidence for the
   purposes of legal proceedings.

   In particular:

   General

   a) The specific events and data to be logged shall be documented by
      the TSA.

   b) The confidentiality and integrity of current and archived records
      concerning operation of time-stamping services shall be
      maintained.

   c) Records concerning the operation of time-stamping services shall
      be completely and confidentially archived in accordance with
      disclosed business practices.

   d) Records concerning the operation of time-stamping services shall
      be made available if required for the purposes of providing
      evidence of the correct operation of the time-stamping services
      for the purpose of legal proceedings.

   e) The precise time of significant TSA environmental, key management
      and clock synchronization events shall be recorded.

   f) Records concerning time-stamping services shall be held for a
      period of time after the expiration of the validity of the TSU’s

      signing keys as appropriate for providing necessary legal evidence
      and as notified in the TSA disclosure statement (see section
      7.1.2).

   g) The events shall be logged in a way that they cannot be easily
      deleted or destroyed (except if reliably transferred to long-term
      media) within the period of time that they are required to be
      held.

      NOTE: This may be achieved, for example, through the use of
      write-only media, a record of each removable media used and the
      use of off-site backup.

   h) Any information recorded about subscribers shall be kept
      confidential except as where agreement is obtained from the
      subscriber for its wider publication.

   TSU key management

   i) Records concerning all events relating to the life-cycle of TSU
      keys shall be logged.

   j) Records concerning all events relating to the life-cycle of TSU
      certificates (if appropriate) shall be logged.

   Clock Synchronization

   k) Records concerning all events relating to synchronization of a
      TSU’s clock to UTC shall be logged.  This shall include
      information concerning normal re-calibration or synchronization of
      clocks use in time-stamping.

   l) Records concerning all events relating to detection of loss of
      synchronization shall be logged.

7.5.  Organizational

   The TSA shall ensure that its organization is reliable.

   In particular that:

   a) Policies and procedures under which the TSA operates shall be
      non-discriminatory.

   b) The TSA shall make its services accessible to all applicants whose
      activities fall within its declared field of operation and that
      agree to abide by their obligations as specified in the TSA
      disclosure statement.

   c) The TSA is a legal entity according to national law.

   d) The TSA has a system or systems for quality and information
      security management appropriate for the time-stamping services it
      is providing.

   e) The TSA has adequate arrangements to cover liabilities arising
      from its operations and/or activities.

   f) It has the financial stability and resources required to operate
      in conformity with this policy.

      NOTE 1: This includes requirements for TSA termination identified
      in section 7.4.9.

   g) It employs a sufficient number of personnel having the necessary
      education, training, technical knowledge and experience relating
      to the type, range and volume of work necessary to provide time-
      stamping services.

      NOTE 2: Personnel employed by a TSA include individual personnel
      contractually engaged in performing functions in support of the
      TSA’s time-stamping services.  Personnel who may be involved only
      in monitoring the TSA services need not be TSA personnel.

   h) It has policies and procedures for the resolution of complaints
      and disputes received from customers or other parties about the
      provisioning of the time-stamping services or any other related
      matters.

   i) It has a properly documented agreement and contractual
      relationship in place where the provisioning of services involves
      subcontracting, outsourcing or other third party arrangements.

8.  Security Considerations

   When verifying time-stamp tokens it is necessary for the verifier to
   ensure that the TSU certificate is trusted and not revoked.  This
   means that the security is dependent upon the security of the CA that
   has issued the TSU certificate for both issuing the certificate and
   providing accurate revocation status information for that
   certificate.

   When a time-stamp is verified as valid at a given point of time, this
   does not mean that it will necessarily remain valid later on.  Every
   time, a time-stamp token is verified during the validity period of
   the TSU certificate, it must be verified again against the current
   revocation status information, since in case of compromise of a TSU

   private key, all the time-stamp tokens generated by that TSU become
   invalid.  Annex C provides guidance about the long term verification
   of time-stamp tokens.

   In applying time-stamping to applications, consideration also needs
   to be given to the security of the application.  In particular, when
   applying time-stamps it is necessary to ensure that the integrity of
   data is maintained before the time-stamp is applied.  The requester
   ought to really make sure that the hash value included in the time-
   stamp token matches with the hash of the data.

9.  Acknowledgments

   The development of this document was supported by ETSI and the
   European Commission.  Special thanks are due to Franco Ruggieri for
   his valuable inputs.

10.  References

10.1.  Normative References

   [RFC 2119]     Bradner, S. "Key words for use in RFCs to Indicate
                  Requirement Levels", BCP 14, RFC 2119, March 1997.

   [TF.460-5]     ITU-R Recommendation TF.460-5 (1997): Standard-
                  frequency and time-signal emissions.

   [TF.536-1]     ITU-R Recommendation TF.536-1 (1998): Time-scale
                  notations.

   [CWA 14167-2]  CEN Workshop Agreement 14167-2: Cryptographic Module
                  for CSP Signing Operations - Protection Profile
                  (MCSO-PP).

   [FIPS 140-1]   FIPS PUB 140-1 (1994): Security Requirements for
                  Cryptographic Modules.

   [ISO 15408]    ISO/IEC 15408 (1999) (parts 1 to 3): Information
                  technology - Security techniques and Evaluation
                  criteria for IT security.

10.2.  Informative References

   [CWA 14172]    CEN Workshop Agreement 14172: EESSI Conformity
                  Assessment Guidance.

   [Dir 95/46/EC] Directive 95/46/EC of the European Parliament and of
                  the Council of 24 October 1995 on the protection of
                  individuals with regard to the processing of personal
                  data and on the free movement of such data.

   [Dir 99/93/EC] Directive 1999/93/EC of the European Parliament and of
                  the Council of 13 December 1999 on a Community
                  framework for electronic signatures.

   [ISO 17799]    ISO/IEC 17799: Information technology Code of practice
                  for information security management

   [RFC 3126]     Pinkas, D., Ross, J. and N. Pope, "Electronic
                  Signature Formats for long term electronic
                  signatures", RFC 3126, September 2001.

   [RFC 3161]     Adams, C., Cain, P., Pinkas, D. and R. Zuccherato,
                  "Internet X.509 Public Key Infrastructure Time-Stamp
                  Protocol (TSP)", RFC 3161, August 2001.

   [TS 101733]    ETSI Technical Specification TS 101 733 V.1.2.2
                  (2000-12) Electronic Signature Formats.  Note: copies
                  of ETSI TS 101 733 can be freely downloaded from the
                  ETSI web site www.etsi.org.

   [TS 101861]    ETSI Technical Specification TS 101 861 V1.2.1.
                  (2001-11).  Time stamping profile.  Note: copies of
                  ETSI TS 101 861 can be freely downloaded from the ETSI
                  web site www.etsi.org.

   [TS 102023]    ETSI Technical Specification TS 102 023.  Policy
                  requirements for Time-Stamping Authorities.  Note:
                  copies of ETSI TS 102 023 can be freely downloaded
                  from the ETSI web site www.etsi.org.

   [X.208]        CCITT Recommendation X.208: Specification of Abstract
                  Syntax Notation One (ASN.1), 1988.

Annex A (informative): Coordinated Universal Time

   Coordinated Universal Time (UTC) is the international time standard
   that became effective on January 1, 1972.  UTC has superseded
   Greenwich Mean Time (GMT), but in practice they are never more than 1
   second different.  Hence many people continue to refer to GMT when in
   fact they operate to UTC.

   Zero (0) hours UTC is midnight in Greenwich, England, which lies on
   the zero longitudinal meridian.  Universal time is based on a 24 hour
   clock, therefore, afternoon hours such as 4 pm UTC are expressed as
   16:00 UTC (sixteen hours, zero minutes).

   International Atomic Time (TAI) is calculated by the Bureau
   International des Poids et Mesures (BIPM) from the readings of more
   than 200 atomic clocks located in metrology institutes and
   observatories in more than 30 countries around the world.
   Information on TAI is made available every month in the BIPM Circular
------分隔线----------------------------
顶一下
(0)
0%
踩一下
(0)
0%
------分隔线----------------------------
最新评论 查看所有评论
发表评论 查看所有评论
请自觉遵守互联网相关的政策法规,严禁发布色情、暴力、反动的言论。
评价:
表情:
用户名: 密码: 验证码:
推荐内容