management.
- System Operators: Responsible for operating the TSA trustworthy
systems on a day-to-day basis. Authorized to perform system
backup and recovery.
- System Auditors: Authorized to view archives and audit logs of
the TSA trustworthy systems.
h) TSA personnel shall be formally appointed to trusted roles by
senior management responsible for security.
i) The TSA shall not appoint to trusted roles or management any
person who is known to have a conviction for a serious crime or
other offense which affects his/her suitability for the position.
Personnel shall not have access to the trusted functions until any
necessary checks are completed.
NOTE 4: In some countries it may not be possible for TSA to obtain
information on past convictions without the collaboration of the
candidate employee.
7.4.4. Physical and Environmental Security
The TSA shall ensure that physical access to critical services is
controlled and physical risks to its assets minimized.
In particular (general):
a) For both the time-stamping provision and the time-stamping
management:
- physical access to facilities concerned with time-stamping
services shall be limited to properly authorized individuals;
- controls shall be implemented to avoid loss, damage or
compromise of assets and interruption to business activities;
and
- controls shall be implemented to avoid compromise or theft of
information and information processing facilities.
b) Access controls shall be applied to the cryptographic module to
meet the requirements of security of cryptographic modules as
identified in clauses 7.2.1 and 7.2.2.
c) The following additional controls shall be applied to time-
stamping management:
- The time-stamping management facilities shall be operated in an
environment which physically protects the services from
compromise through unauthorized access to systems or data.
- Physical protection shall be achieved through the creation of
clearly defined security perimeters (i.e., physical barriers)
around the time-stamping management. Any parts of the premises
shared with other organizations shall be outside this
perimeter.
- Physical and environmental security controls shall be
implemented to protect the facility that houses system
resources, the system resources themselves, and the facilities
used to support their operation. The TSA’s physical and
environmental security policy for systems concerned with time-
stamping management shall address as a minimum the physical
access control, natural disaster protection, fire safety
factors, failure of supporting utilities (e.g., power,
telecommunications), structure collapse, plumbing leaks,
protection against theft, breaking and entering, and disaster
recovery.
- Controls shall be implemented to protect against equipment,
information, media and software relating to the time-stamping
services being taken off-site without authorization.
NOTE 1: See ISO/IEC 17799 [ISO 17799] for guidance on physical and
environmental security.
NOTE 2: Other functions may be supported within the same secured
area provided that the access is limited to authorized personnel.
7.4.5. Operations Management
The TSA shall ensure that the TSA system components are secure and
correctly operated, with minimal risk of failure:
In particular (general):
a) The integrity of TSA system components and information shall be
protected against viruses, malicious and unauthorized software.
b) Incident reporting and response procedures shall be employed in
such a way that damage from security incidents and malfunctions
shall be minimized.
c) Media used within the TSA trustworthy systems shall be securely
handled to protect media from damage, theft, unauthorized access
and obsolescence.
NOTE 1: Every member of personnel with management responsibilities
is responsible for planning and effectively implementing the
time-stamp policy and associated practices as documented in the
TSA practice statement.
d) Procedures shall be established and implemented for all trusted
and administrative roles that impact on the provision of time-
stamping services.
Media handling and security
e) All media shall be handled securely in accordance with
requirements of the information classification scheme (see section
7.4.2). Media containing sensitive data shall be securely
disposed of when no longer required.
System Planning
f) Capacity demands shall be monitored and projections of future
capacity requirements made to ensure that adequate processing
power and storage are available.
Incident reporting and response
g) The TSA shall act in a timely and coordinated manner in order to
respond quickly to incidents and to limit the impact of breaches
of security. All incidents shall be reported as soon as possible
after the incident.
The following additional controls shall be applied to time-stamping
management:
Operations procedures and responsibilities
h) TSA security operations shall be separated from other operations.
NOTE 2: TSA security operations’ responsibilities include:
- operational procedures and responsibilities;
- secure systems planning and acceptance;
- protection from malicious software;
- housekeeping;
- network management;
- active monitoring of audit journals, event analysis and
follow-up;
- media handling and security;
- data and software exchange.
These operations shall be managed by TSA trusted personnel, but, may
actually be performed by, non-specialist, operational personnel
(under supervision), as defined within the appropriate security
policy, and, roles and responsibility documents.
7.4.6. System Access Management
The TSA shall ensure that TSA system access is limited to properly
authorized individuals.
In particular (general):
a) Controls (e.g., firewalls) shall be implemented to protect the
TSA’s internal network domains from unauthorized access including
access by subscribers and third parties.
NOTE 1: Firewalls should also be configured to prevent all
protocols and accesses not required for the operation of the TSA.
b) The TSA shall ensure effective administration of user (this
includes operators, administrators and auditors) access to
maintain system security, including user account management,
auditing and timely modification or removal of access.
c) The TSA shall ensure that access to information and application
system functions is restricted in accordance with the access
control policy and that the TSA system provides sufficient
computer security controls for the separation of trusted roles
identified in TSA’s practices, including the separation of
security administrator and operation functions. Particularly, use
of system utility programs is restricted and tightly controlled.
d) TSA personnel shall be properly identified and authenticated
before using critical applications related to time-stamping.
e) TSA personnel shall be accountable for their activities, for
example by retaining event logs (see section 7.4.10).
The following additional controls shall be applied to time-stamping
management:
f) The TSA shall ensure that local network components (e.g., routers)
are kept in a physically secure environment and that their
configurations are periodically audited for compliance with the
requirements specified by the TSA.
g) Continuous monitoring and alarm facilities shall be provided to
enable the TSA to detect, register and react in a timely manner upon
any unauthorized and/or irregular attempts to access its resources.
NOTE 2: This may use, for example, an intrusion detection system,
access control monitoring and alarm facilities.
7.4.7. Trustworthy Systems Deployment and Maintenance
The TSA shall use trustworthy systems and products that are protected
against modification.
NOTE: The risk analysis carried out on the TSA’s services (see
section 7.1.1) should identify its critical services requiring
trustworthy systems and the levels of assurance required.
In particular:
a) An analysis of security requirements shall be carried out at the
design and requirements specification stage of any systems
development project undertaken by the TSA or on behalf of the TSA
to ensure that security is built into IT systems.
b) Change control procedures shall be applied for releases,
modifications and emergency software fixes of any operational
software.
7.4.8. Compromise of TSA Services
The TSA shall ensure in the case of events which affect the security
of the TSA’s services, including compromise of TSU’s private signing
keys or detected loss of calibration, that relevant information is
made available to subscribers and relying parties.
In particular:
a) The TSA’s disaster recovery plan shall address the compromise or
suspected compromise of TSU’s private signing keys or loss of
calibration of a TSU clock, which may have affected time-stamp
tokens which have been issued.
b) In the case of a compromise, or suspected compromise or loss of
calibration the TSA shall make available to all subscribers and
relying parties a description of compromise that occurred.
c) In the case of compromise to a TSU’s operation (e.g., TSU key
compromise), suspected compromise or loss of calibration the TSU
shall not issue time-stamp tokens until steps are taken to recover
from the compromise
d) In case of major compromise of the TSA’s operation or loss of
calibration, wherever possible, the TSA shall make available to
all subscribers and relying parties information which may be used
to identify the time-stamp tokens which may have been affected,
unless this breaches the privacy of the TSAs users or the security
of the TSA services.
NOTE: In case the private key does become compromised, an audit
trail of all tokens generated by the TSA may provide a means to
discriminate between genuine and false backdated tokens. Two
time-stamp tokens from two different TSAs may be another way to
address this issue.
7.4.9. TSA Termination
The TSA shall ensure that potential disruptions to subscribers and
relying parties are minimized as a result of the cessation of the
TSA’s time-stamping services, and in particular ensure continued
maintenance of information required to verify the correctness of
time-stamp tokens.
In particular:
a) Before the TSA terminates its time-stamping services the following
procedures shall be executed as a minimum:
- the TSA shall make available to all subscribers and relying
parties information concerning its termination;
- TSA shall terminate authorization of all subcontractors to act
on behalf of the TSA in carrying out any functions relating to
the process of issuing time-stamp tokens;
- the TSA shall transfer obligations to a reliable party for
maintaining event log and audit archives (see section 7.4.10)
necessary to demonstrate the correct operation of the TSA for a
reasonable period;
- the TSA shall maintain or transfer to a reliable party its
obligations to make available its public key or its
certificates to relying parties for a reasonable period;
- TSU private keys, including backup copies, shall be destroyed
in a manner such that the private keys cannot be retrieved.
b) The TSA shall have an arrangement to cover the costs to fulfill
these minimum requirements in case the TSA becomes bankrupt or for
other reasons is unable to cover the costs by itself.
c) The TSA shall state in its practices the provisions made for
termination of service. This shall include:
- notification of affected entities;
- transferring the TSA obligations to other parties.
d) The TSA shall take steps to have the TSU’s certificates revoked.
7.4.10. Compliance with Legal Requirements
The TSA shall ensure compliance with legal requirements.
In particular:
a) The TSA shall ensure that the requirements of the European data
protection Directive [Dir 95/46/EC], as implemented through
national legislation, are met.
b) Appropriate technical and organizational measures shall be taken
against unauthorized or unlawful processing of personal data and
against accidental loss or destruction of, or damage to, personal
data.
c) The information contributed by users to the TSA shall be
completely protected from disclosure unless with their agreement
or by court order or other legal requirement.
7.4.11. Recording of Information Concerning Operation of Time-Stamping
Services
The TSA shall ensure that all relevant information concerning the
operation of time-stamping services is recorded for a defined period
of time, in particular for the purpose of providing evidence for the
purposes of legal proceedings.
In particular:
General
a) The specific events and data to be logged shall be documented by
the TSA.
b) The confidentiality and integrity of current and archived records
concerning operation of time-stamping services shall be
maintained.
c) Records concerning the operation of time-stamping services shall
be completely and confidentially archived in accordance with
disclosed business practices.
d) Records concerning the operation of time-stamping services shall
be made available if required for the purposes of providing
evidence of the correct operation of the time-stamping services
for the purpose of legal proceedings.
e) The precise time of significant TSA environmental, key management
and clock synchronization events shall be recorded.
f) Records concerning time-stamping services shall be held for a
period of time after the expiration of the validity of the TSU’s
signing keys as appropriate for providing necessary legal evidence
and as notified in the TSA disclosure statement (see section
7.1.2).
g) The events shall be logged in a way that they cannot be easily
deleted or destroyed (except if reliably transferred to long-term
media) within the period of time that they are required to be
held.
NOTE: This may be achieved, for example, through the use of
write-only media, a record of each removable media used and the
use of off-site backup.
h) Any information recorded about subscribers shall be kept
confidential except as where agreement is obtained from the
subscriber for its wider publication.
TSU key management
i) Records concerning all events relating to the life-cycle of TSU
keys shall be logged.
j) Records concerning all events relating to the life-cycle of TSU
certificates (if appropriate) shall be logged.
Clock Synchronization
k) Records concerning all events relating to synchronization of a
TSU’s clock to UTC shall be logged. This shall include
information concerning normal re-calibration or synchronization of
clocks use in time-stamping.
l) Records concerning all events relating to detection of loss of
synchronization shall be logged.
7.5. Organizational
The TSA shall ensure that its organization is reliable.
In particular that:
a) Policies and procedures under which the TSA operates shall be
non-discriminatory.
b) The TSA shall make its services accessible to all applicants whose
activities fall within its declared field of operation and that
agree to abide by their obligations as specified in the TSA
disclosure statement.
c) The TSA is a legal entity according to national law.
d) The TSA has a system or systems for quality and information
security management appropriate for the time-stamping services it
is providing.
e) The TSA has adequate arrangements to cover liabilities arising
from its operations and/or activities.
f) It has the financial stability and resources required to operate
in conformity with this policy.
NOTE 1: This includes requirements for TSA termination identified
in section 7.4.9.
g) It employs a sufficient number of personnel having the necessary
education, training, technical knowledge and experience relating
to the type, range and volume of work necessary to provide time-
stamping services.
NOTE 2: Personnel employed by a TSA include individual personnel
contractually engaged in performing functions in support of the
TSA’s time-stamping services. Personnel who may be involved only
in monitoring the TSA services need not be TSA personnel.
h) It has policies and procedures for the resolution of complaints
and disputes received from customers or other parties about the
provisioning of the time-stamping services or any other related
matters.
i) It has a properly documented agreement and contractual
relationship in place where the provisioning of services involves
subcontracting, outsourcing or other third party arrangements.
8. Security Considerations
When verifying time-stamp tokens it is necessary for the verifier to
ensure that the TSU certificate is trusted and not revoked. This
means that the security is dependent upon the security of the CA that
has issued the TSU certificate for both issuing the certificate and
providing accurate revocation status information for that
certificate.
When a time-stamp is verified as valid at a given point of time, this
does not mean that it will necessarily remain valid later on. Every
time, a time-stamp token is verified during the validity period of
the TSU certificate, it must be verified again against the current
revocation status information, since in case of compromise of a TSU
private key, all the time-stamp tokens generated by that TSU become
invalid. Annex C provides guidance about the long term verification
of time-stamp tokens.
In applying time-stamping to applications, consideration also needs
to be given to the security of the application. In particular, when
applying time-stamps it is necessary to ensure that the integrity of
data is maintained before the time-stamp is applied. The requester
ought to really make sure that the hash value included in the time-
stamp token matches with the hash of the data.
9. Acknowledgments
The development of this document was supported by ETSI and the
European Commission. Special thanks are due to Franco Ruggieri for
his valuable inputs.
10. References
10.1. Normative References
[RFC 2119] Bradner, S. "Key words for use in RFCs to Indicate
Requirement Levels", BCP 14, RFC 2119, March 1997.
[TF.460-5] ITU-R Recommendation TF.460-5 (1997): Standard-
frequency and time-signal emissions.
[TF.536-1] ITU-R Recommendation TF.536-1 (1998): Time-scale
notations.
[CWA 14167-2] CEN Workshop Agreement 14167-2: Cryptographic Module
for CSP Signing Operations - Protection Profile
(MCSO-PP).
[FIPS 140-1] FIPS PUB 140-1 (1994): Security Requirements for
Cryptographic Modules.
[ISO 15408] ISO/IEC 15408 (1999) (parts 1 to 3): Information
technology - Security techniques and Evaluation
criteria for IT security.
10.2. Informative References
[CWA 14172] CEN Workshop Agreement 14172: EESSI Conformity
Assessment Guidance.
[Dir 95/46/EC] Directive 95/46/EC of the European Parliament and of
the Council of 24 October 1995 on the protection of
individuals with regard to the processing of personal
data and on the free movement of such data.
[Dir 99/93/EC] Directive 1999/93/EC of the European Parliament and of
the Council of 13 December 1999 on a Community
framework for electronic signatures.
[ISO 17799] ISO/IEC 17799: Information technology Code of practice
for information security management
[RFC 3126] Pinkas, D., Ross, J. and N. Pope, "Electronic
Signature Formats for long term electronic
signatures", RFC 3126, September 2001.
[RFC 3161] Adams, C., Cain, P., Pinkas, D. and R. Zuccherato,
"Internet X.509 Public Key Infrastructure Time-Stamp
Protocol (TSP)", RFC 3161, August 2001.
[TS 101733] ETSI Technical Specification TS 101 733 V.1.2.2
(2000-12) Electronic Signature Formats. Note: copies
of ETSI TS 101 733 can be freely downloaded from the
ETSI web site www.etsi.org.
[TS 101861] ETSI Technical Specification TS 101 861 V1.2.1.
(2001-11). Time stamping profile. Note: copies of
ETSI TS 101 861 can be freely downloaded from the ETSI
web site www.etsi.org.
[TS 102023] ETSI Technical Specification TS 102 023. Policy
requirements for Time-Stamping Authorities. Note:
copies of ETSI TS 102 023 can be freely downloaded
from the ETSI web site www.etsi.org.
[X.208] CCITT Recommendation X.208: Specification of Abstract
Syntax Notation One (ASN.1), 1988.
Annex A (informative): Coordinated Universal Time
Coordinated Universal Time (UTC) is the international time standard
that became effective on January 1, 1972. UTC has superseded
Greenwich Mean Time (GMT), but in practice they are never more than 1
second different. Hence many people continue to refer to GMT when in
fact they operate to UTC.
Zero (0) hours UTC is midnight in Greenwich, England, which lies on
the zero longitudinal meridian. Universal time is based on a 24 hour
clock, therefore, afternoon hours such as 4 pm UTC are expressed as
16:00 UTC (sixteen hours, zero minutes).
International Atomic Time (TAI) is calculated by the Bureau
International des Poids et Mesures (BIPM) from the readings of more
than 200 atomic clocks located in metrology institutes and
observatories in more than 30 countries around the world.
Information on TAI is made available every month in the BIPM Circular