{"title":"Qualified Electronic Signature SaaS Solution for Google Docs & Google Sheets Documents","authors":"Iulian Aciobanitei, I. Luculescu, Mihai-Lica Pura","doi":"10.1109/COMM48946.2020.9142002","DOIUrl":null,"url":null,"abstract":"Qualified e lectronic s ignatures ( QES) a re legally equated with handwritten signatures and are the main mechanism to ensure the authenticity and integrity of electronic data. In E.U., adoption of QES services became easier from the user’s perspective, thanks to the adoption of the Regulation (EU) No 910/2014 (the \"eIDAS\" Regulation) which enables cloud QES. According to the new legislative definitions f rom t he eIDAS Regulation, the signatory is no longer required to own a hardware cryptographic device to obtain a QES, but the secure signature creation device can be managed by the issuing certification authority, namely the trust service provider (TSP). The sole control of the user over her/his private keys stored and used in the cloud shall be assured through the remote signature protocol exposed by the TSP, compliant to corresponding ETSI standards.Thanks to their interoperable character, services exposed by the TSPs are suitable for integration in different document management platforms. However, the full potential of cloud QES has not been reached yet. In order to sustain the adoption of QES, this paper proposes a Software-as-a-Service (SaaS) solution to enable platforms like Google Docs and Google Sheets to directly apply QES on the documents created and used in the cloud. The implemented proof of concept is compliant with the two main signature creation standards: Cloud Signature Consortium (CSC) and OASIS Digital Signature Service (DSS).This paper presents the architecture and implementation details of the proposed solution and also the main challenges encountered during the development of the SaaS platform to offer remote QES services.This paper presents the architecture and implementation details of the proposed solution. Also, we present the main challenges encountered during the development of the SaaS platform to offer QES services.","PeriodicalId":405841,"journal":{"name":"2020 13th International Conference on Communications (COMM)","volume":"28 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 13th International Conference on Communications (COMM)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COMM48946.2020.9142002","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
Qualified e lectronic s ignatures ( QES) a re legally equated with handwritten signatures and are the main mechanism to ensure the authenticity and integrity of electronic data. In E.U., adoption of QES services became easier from the user’s perspective, thanks to the adoption of the Regulation (EU) No 910/2014 (the "eIDAS" Regulation) which enables cloud QES. According to the new legislative definitions f rom t he eIDAS Regulation, the signatory is no longer required to own a hardware cryptographic device to obtain a QES, but the secure signature creation device can be managed by the issuing certification authority, namely the trust service provider (TSP). The sole control of the user over her/his private keys stored and used in the cloud shall be assured through the remote signature protocol exposed by the TSP, compliant to corresponding ETSI standards.Thanks to their interoperable character, services exposed by the TSPs are suitable for integration in different document management platforms. However, the full potential of cloud QES has not been reached yet. In order to sustain the adoption of QES, this paper proposes a Software-as-a-Service (SaaS) solution to enable platforms like Google Docs and Google Sheets to directly apply QES on the documents created and used in the cloud. The implemented proof of concept is compliant with the two main signature creation standards: Cloud Signature Consortium (CSC) and OASIS Digital Signature Service (DSS).This paper presents the architecture and implementation details of the proposed solution and also the main challenges encountered during the development of the SaaS platform to offer remote QES services.This paper presents the architecture and implementation details of the proposed solution. Also, we present the main challenges encountered during the development of the SaaS platform to offer QES services.
合格的电子签名(QES)在法律上等同于手写签名,是确保电子数据真实性和完整性的主要机制。在欧盟,由于采用了支持云QES的法规(EU) No 910/2014(“eIDAS”法规),从用户的角度来看,采用QES服务变得更加容易。根据eIDAS法规的新立法定义,签署人不再需要拥有硬件加密设备来获得QES,但安全签名创建设备可以由颁发证书的颁发机构,即信任服务提供商(TSP)管理。通过TSP公开的符合相应ETSI标准的远程签名协议,确保用户对其在云中存储和使用的私钥的唯一控制权。由于tsp具有互操作特性,因此它们公开的服务适合集成到不同的文档管理平台中。然而,云QES的全部潜力尚未得到充分发挥。为了维持QES的采用,本文提出了一个软件即服务(SaaS)解决方案,使Google Docs和Google Sheets等平台能够直接将QES应用于在云中创建和使用的文档。实现的概念验证符合两个主要的签名创建标准:云签名联盟(CSC)和OASIS数字签名服务(DSS)。本文介绍了所提出的解决方案的体系结构和实现细节,以及在开发提供远程QES服务的SaaS平台过程中遇到的主要挑战。本文给出了该解决方案的体系结构和实现细节。此外,我们还介绍了在开发提供QES服务的SaaS平台期间遇到的主要挑战。