130 likes | 307 Views
Crypto Algorithms - Catalog National and European Appointments. Harmonised Crypto Requirements * Process *Status Klaus J. KEUS Head of Unit / Member of EESSI SG Bundesamt für Sicherheit in der Informationstechnik (BSI/GISA). Crypto Algorithms - Catalog of European Appointments.
E N D
Crypto Algorithms - Catalog National and European Appointments Harmonised Crypto Requirements * Process *Status Klaus J. KEUS Head of Unit / Member of EESSI SG Bundesamt für Sicherheit in der Informationstechnik (BSI/GISA)
Crypto Algorithms - Catalog of European Appointments • Status Quo / Problems / Objectives • Solution: contents - technical - organisational • Process / Procedure / Interfaces • The Road Ahead
Crypto Algorithms - Catalog of European Appointments European Status Quo • A common security level as basic condition for mutual recognition • Compliancy with the requirements from article 3 (5) of the directive (EESSI: CEN/ISSS: e-sign, ETSI TC SEC) • Fulfillment of the requirements following • Annex III (WA „F“) • Annex II (f) (WA „D“) • Annex II (CSP Policy: WA „C“) • Guaranty of interoperability
Crypto Algorithms - Catalog of European Appointments Task I Accountability, Competence, Responsibility Technical Political Procedural (permanent)
Crypto Algorithms - Catalog of European Appointments Task II • Provision of the requirements • Procedure of adoption • Procedure of publication • Procedure of periodical review and update • Procedure of incident case handlings
Crypto Algorithms - Catalog of European Appointments Objective I: technical • Restriction to technical issues • Results are independent from • specific technology • specific products • specific applications • Implementable • Verifiable by running interoperability tests • Technical up to date
Crypto Algorithms - Catalog of European Appointments Objective II: political • Publication by EC • Adoption by all EU-MS • Integration of European wide responsibilities and knowhow from business, industry, administration and research • Consideration of European and international standards, experiences and relevant products • Consideration of current trends
Crypto Algorithms - Catalog of European Appointments Solution I: organisational Solution -1 - • Installation of a European expert team with representatives from • Business • Industry • Research • Standardisation • Security Agency (national) • Based on available standards und reports • Consideration of current trends
Crypto Algorithms - Catalog of European Appointments Solution II: organisational Solution - 2 - Phase 1: Preparation of a proposal by a European expert team of 9 members, responsible for: first proposal / periodical review process / incident case handling incl. editorial tasks Phase 2: Publication of the proposal and integration of all European experts in the evaluation process Phase 3: Review Process No official approval process mandatory!!
Crypto Algorithms - Catalog of European Appointments Solution III: technical solution -1 - • Technical reports • Requirements for: • Signature algorithms • Hash algorithms • Fixing of parameters • Padding • Key generation • Entropy • No key management issues
Crypto Algorithms - Catalog of European Appointments Solution IV: technical solution - 2 - • Proposals concerning procedure • General neutral description of proposals, no solution specific detailed proposals • General proposals concerning further processing and procedures in A9C • Proposals concerning publication • Proposals concerning treatment of special cases / incident case handling
Crypto Algorithms - Catalog of European Appointments Interface Overview A9C European Experts (EALEC) Expert Group (ALGO) ICTSB EESSI-SB Security Agencies User Research Standard. bodies
Crypto Algorithms - Catalog of European Appointments Satus Quo / Road Ahead End of June 2001 Jan. 10th of 2001 End of April Delivery of the 1. official agreed version to EC and A9C 1. Meeting Interim Version 1.0 for expert discussion (planned) Periodical review maximum 2 times a year (tends to 1* (as implemented in Germany))