1、 ETSI SR 019 050 V1.1.1 (2015-06) Electronic Signatures and Infrastructures (ESI); Rationalized framework of Standards for Electronic Registered Delivery Services Applying Electronic Signatures floppy3SPECIAL REPORT ETSI ETSI SR 019 050 V1.1.1 (2015-06) 2 Reference DSR/ESI-0019530 Keywords electroni
2、c signature, electronic registered delivery, security ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important
3、notice The present document can be downloaded from: http:/www.etsi.org/standards-search The present document may be made available in electronic versions and/or in print. The content of any electronic and/or print versions of the present document shall not be modified without the prior written autho
4、rization of ETSI. In case of any existing or perceived difference in contents between such versions and/or in print, the only prevailing document is the print of the Portable Document Format (PDF) version kept on a specific network drive within ETSI Secretariat. Users of the present document should
5、be aware that the document may be subject to revision or change of status. Information on the current status of this and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following servic
6、es: https:/portal.etsi.org/People/CommiteeSupportStaff.aspx Copyright Notification No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm except as authorized by written permission of ETSI. The content of the PDF version shal
7、l not be modified without the written authorization of ETSI. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2015. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for
8、 the benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI SR 019 050 V1.1.1 (2015-06) 3 Contents Intellectual Prope
9、rty Rights 5g3Foreword . 5g3Modal verbs terminology 5g3Introduction 5g31 Scope 7g32 References 7g32.1 Normative references . 7g32.2 Informative references 7g33 Definitions and abbreviations . 10g33.1 Definitions 10g33.2 Abbreviations . 11g34 Methodology 12g35 Features 13g36 Electronic registered del
10、ivery service model . 15g36.1 Introduction 15g36.2 Basic service model 15g36.3 Distributed service model . 17g36.4 Extended electronic registered delivery service model 18g36.5 Roles in electronic registered delivery management domains 20g36.6 Implications to standardization activities . 22g36.6.1 I
11、ntroduction. 22g36.6.2 Routing . 23g36.6.3 Capabilities/Requirements 24g36.6.4 Trust Establishment 24g36.6.5 Payload Delivery 24g36.6.6 Meta-information Exchange . 24g36.6.7 User Identity Exchange . 24g36.6.8 Evidence Exchange . 25g37 Inventory of existing specifications . 25g38 Rationalized structu
12、re for electronic registered delivery standardization documents 25g38.1 Electronic registered delivery standardization classification scheme . 25g38.2 Electronic registered delivery standardization proposal aligned with the rationalized framework and based on the model . 26g39 Analysis and work plan
13、 30g39.1 Methodology 30g39.2 Analysis and work plan for trust application service providers area 30g3Annex A: Pan-European solutions 38g3A.1 Introduction 38g3A.2 SPOCS LSP 38g3A.3 e-SENS LSP . 39g3A.4 ePSOS. 40g3A.5 PEPPOL . 41g3A.6 eCODEX 43g3A.7 e-Trustex . 44g3Annex B: Inventory 45g3ETSI ETSI SR
14、019 050 V1.1.1 (2015-06) 4 Annex C: Bibliography 46g3History 49g3ETSI ETSI SR 019 050 V1.1.1 (2015-06) 5 Intellectual Property Rights IPRs essential or potentially essential to the present document may have been declared to ETSI. The information pertaining to these essential IPRs, if any, is publicl
15、y available for ETSI members and non-members, and can be found in ETSI SR 000 314: “Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards“, which is available from the ETSI Secretariat. Latest updates are available on the ETSI We
16、b server (http:/ipr.etsi.org). Pursuant to the ETSI IPR Policy, no investigation, including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may b
17、ecome, essential to the present document. Foreword This Special Report (SR) has been produced by ETSI Technical Committee Electronic Signatures and Infrastructures (ESI). Modal verbs terminology In the present document “shall“, “shall not“, “should“, “should not“, “may“, “need not“, “will“, “will no
18、t“, “can“ and “cannot“ are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of provisions). “must“ and “must not“ are NOT allowed in ETSI deliverables except when used in direct citation. Introduction Electronic delivery services in the broad s
19、ense, i.e. services that make it possible to transmit data between third parties by electronic means, are ubiquitous in most human activities. This is potentially true also when focusing on electronic registered delivery services in the stricter sense provided by the European regulation No 910/2014
20、i.4, which adds requirements on the integrity, confidentiality, non-repudiation and indisputability of transmitted data. Obviously, these requirements apply to a wide range of contexts. The necessity of a governance on this field has been clearly recognized by the Regulation (EU) No 283/2014 i.31 (h
21、ereafter referred to as eTelNet) and by the Regulation (EE) No 910/2014 i.4 (hereafter referred to as eIDAS or eIDAS Regulation). The first document states that: “Member States should encourage local and regional authorities to be fully and effectively involved in the governance of digital service i
22、nfrastructures, and ensure that projects of common interest relating to cross-border delivery of eGovernment services take into account the EIF recommendations.“ while, in the Annex, it explicitly identifies electronic delivery among the “building blocks“ for the digital service infrastructure. Anne
23、x 2 to the Communication from the Commission to the European Parliament, the Council, the European Economic and Social Committee and the Committee of Regions Towards interoperability for European public services: “European Interoperability Framework“ (hereafter referred to as EIF) i.30 suggests that
24、 a layered approach to interoperability has to be adopted, distinguishing legal, organizational, semantic and technical (syntax, transmission) aspects. It is assumed that eIDAS Regulation i.4 aims at covering the “legal“ layer, while the other layers are covered by specific standards. The impact ass
25、essment accompanying eTelNet Regulation i.31 recognizes that: “A large number of cross-border digital services implementing exchanges between European public administrations in support of Union policies are a reality. When providing new solutions, it is important to capitalise on existing solutions
26、implemented in the context of other European initiatives, avoid duplication of work, and ensure coordination and alignment of approaches and solutions across initiatives and policies “ As a matter of fact, several electronic (either registered or not) delivery services are emerging, most of them res
27、tricted either to a member state or to a community, a business, etc. Some of these services are not homogeneous and not interoperable, mainly because of the lack of a normative and standardization base, hence hindering the emergence of electronic registered delivery as a global (or, at least, pan-Eu
28、ropean) commodity service. ETSI ETSI SR 019 050 V1.1.1 (2015-06) 6 A first attempt was already provided by Registered Electronic Mail (hereafter referred to as REM) specifications (multi-part deliverable ETSI TS 102 640 i.7 to i.15) and the related UPU specifications (CEN/TS 16326 i.5) which, howeve
29、r, were focused on a subset of features and technologies. ETSI ETSI SR 019 050 V1.1.1 (2015-06) 7 1 Scope The present document provides a proposal for a rationalized framework of standards for electronic registered delivery services, as defined by the eIDAS Regulation i.5, and fully aligned with the
30、 principles, criteria and structure of the ETSI TR 119 000 i.15: “Rationalized structure for Electronic Signature Standardization“ which describes the rationalized structure for the current and future European eSignatures standardization documents. The present document also includes a set of recomme
31、ndations for future standardization activities that target at implementing the framework of standards for electronic registered delivery. 2 References 2.1 Normative references References are either specific (identified by date of publication and/or edition number or version number) or non-specific.
32、For specific references, only the cited version applies. For non-specific references, the latest version of the referenced document (including any amendments) applies. Referenced documents which are not found to be publicly available in the expected location might be found at http:/docbox.etsi.org/R
33、eference. NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee their long term validity. The following referenced documents are necessary for the application of the present document. Not applicable. 2.2 Informative references References are
34、either specific (identified by date of publication and/or edition number or version number) or non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the referenced document (including any amendments) applies. Referenced documents wh
35、ich are not found to be publicly available in the expected location might be found at http:/docbox.etsi.org/Reference. NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee their long term validity. The following referenced documents are not
36、necessary for the application of the present document but they assist the user with regard to a particular subject area. i.1 Directive 2006/123/EC of the European Parliament and of the Council of 12 December 2006 on services in the internal market. NOTE: Available from: http:/eur-lex.europa.eu/legal
37、-content/EN/ALL/?uri=CELEX:32006L0123. i.2 Commission Decision 2009/767/EC of 16 October 2009 setting out measures facilitating the use of procedures by electronic means through the points of single contact under Directive 2006/123/EC of the European Parliament and of the Council on services in the
38、internal market. NOTE: Available from: http:/eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2009:299:0018:0054:EN:PDF. i.3 Commission Decision 2010/425/EU of 28 July 2010 amending Decision 2009/767/EC as regards the establishment, maintenance and publication of trusted lists of certification se
39、rvice providers supervised/accredited by Member States. NOTE: Available from: http:/eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2010:199:0030:0035:EN:PDF. ETSI ETSI SR 019 050 V1.1.1 (2015-06) 8 i.4 Regulation (EE) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on
40、electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC. NOTE: Available from: http:/eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32014R0910 Trusted Lists“. i.7 ETSI TS 102 640-1: “Electronic Signatures and Infrastru
41、ctures (ESI); Registered Electronic Mail (REM); Part 1: Architecture“. i.8 ETSI TS 102 640-2: “Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Part 2: Data requirements, Formats and Signatures for REM“. i.9 ETSI TS 102 640-3: “Electronic Signatures and Infrastructu
42、res (ESI); Registered Electronic Mail (REM); Part 3: Information Security Policy Requirements for REM Management Domains“. i.10 ETSI TS 102 640-4: “Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Part 4: REM-MD Conformance Profiles“. i.11 ETSI TS 102 640-5: “Electr
43、onic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Part 5: REM-MD Interoperability Profiles“. i.12 ETSI TS 102 640-6-1: “Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Part 6: Interoperability Profiles; Sub-part 1: REM-MD UPU PReM Interop
44、erability Profile“. i.13 ETSI TS 102 640-6-2: “Electronic Signatures and Infrastructures (ESI); Registered Electronic Mail (REM); Part 6: Interoperability Profiles; Sub-part 2: REM-MD BUSDOX Interoperability Profile“. i.14 ETSI TS 102 640-6-3: “Electronic Signatures and Infrastructures (ESI); Regist
45、ered Electronic Mail (REM); Part 6: Interoperability Profiles; Sub-part 3: REM-MD SOAP Binding Profile“. i.15 ETSI TR 119 000: “Electronic Signatures and Infrastructures (ESI); Rationalized structure for Electronic Signature Standardization“. i.16 IETF RFC 5751, January 2010: “ Secure/Multipurpose I
46、nternet Mail Extensions (S/MIME) Version 3.2 Message Specification“. i.17 IETF RFC 2459, January 1999: “Internet X.509 Public Key Infrastructure Certificate and CRL Profile“. i.18 ISO 32000-1: “Document management - Portable document format - Part 1: PDF 1.7“. i.19 Recommendation ITU-T X.1254/ISO/IE
47、C DIS 29115: “Information technology - Security techniques - Entity authentication assurance framework“. i.20 OASIS WS-Trust 1.4. NOTE: Available from: http:/docs.oasis-open.org/ws-sx/ws-trust/v1.4/ws-trust.html. i.21 OASIS Standard Specification (1 February 2006): “Web Services Security: SOAP Messa
48、ge Security 1.1 (WS-Security 2004)“. NOTE: Available from: https:/www.oasis-open.org/committees/download.php/16790/wss-v1.1-spec-os-SOAPMessageSecurity.pdf. i.22 OASIS Standard (15 March 2005): “Assertions and Protocols for the OASIS Security Assertion Markup Language (SAML) V2.0“. NOTE: Available f
49、rom: http:/docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf. ETSI ETSI SR 019 050 V1.1.1 (2015-06) 9 i.23 W3C Recommendation, 11 April 2013: “XML Signature Syntax and Processing Version 1.1“. NOTE: Available from: http:/www.w3.org/TR/2013/REC-xmldsig-core1-20130411/. i.24 OASIS Standard (1 October 2007): “OASIS ebXML Messaging Services Version 3.0: Part 1, Core Features“. NOTE: Available from: http:/docs.oasis-open.org/ebxml-msg/ebms/v3.0/core/os/ebms_core-3.0-spec-os.odt. i.25 IET