Commit 65e7eb9f authored by esou's avatar esou
Browse files

Updated the abbreviation format. Added definition of KMS and personal data....

Updated the abbreviation format. Added definition of KMS and personal data. Added sources for all definitions except PKI Software
parent f8322c8d
Loading
Loading
Loading
Loading
+351 −139
Original line number Diff line number Diff line
@@ -246,65 +246,120 @@ For the purposes of the present document, the terms given in Regulation (EU) 202

<table style="width: 100%; border-collapse: collapse;">
  <colgroup>
    <col style="width: 120pt;">
    <col style="width: 160pt;align: top">
    <col style="width: auto;">
  </colgroup>
  <tr>
    <td style="border: none;">Product</td>
    <td style="border: none;">Product with Digital Elements in the scope of the present document
    <td style="border: none; vertical-align: top;">Product</td>
    <td style="border: none; vertical-align: top;">Product with Digital Elements in the scope of the present document
    <br />
    <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng">
Cyber Resilience Act (Regulation (EU) 2024/2847)
</a>
  </td>
  </tr>
  <tr>
    <td style="border: none;">PKI Software</td>
    <td style="border: none;">Software implementing the PKI services, including, Registration, Certificate generation, Dissemination, Revocation management, Certificate status, Logging of security events, User accounts management.
    <td style="border: none; vertical-align: top;">PKI Software</td>
    <td style="border: none; vertical-align: top;">Software implementing the PKI services, including, Registration, Certificate generation, Dissemination, Revocation management, Certificate status, Logging of security events, User accounts management.
  </td>
  </tr>

  <tr>
    <td style="border: none;">Certificate</td>
    <td style="border: none;">Public key of a user, together with some other information, rendered un-forgeable by encipherment with the private key of the certification authority which issued it.
    <td style="border: none; vertical-align: top;">Certificate</td>
    <td style="border: none; vertical-align: top;">Public key of a user, together with some other information, rendered un-forgeable by encipherment with the private key of the certification authority which issued it.
    <br/>
    <a href="https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/01.05.01_60/en_31941101v010501p.pdf">
ETSI EN 319 411-1 V1.5.1
</a>
  </td>
  </tr>
  <tr>
    <td style="border: none;">Certificate Policy (CP)</td>
    <td style="border: none;">Named set of rules that indicates the applicability of a certificate to a particular community and/or class of application with common security requirements.
    <td style="border: none; vertical-align: top;">Certificate Policy (CP)</td>
    <td style="border: none; vertical-align: top;">Named set of rules that indicates the applicability of a certificate to a particular community and/or class of application with common security requirements.
    <br/>
    <a href="https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/01.05.01_60/en_31941101v010501p.pdf">
ETSI EN 319 411-1 V1.5.1
</a>
  </td>
  </tr>

  <tr>
    <td style="border: none;">Certificate Revocation List (CRL)</td>
    <td style="border: none;">Signed list indicating a set of certificates that have been revoked by the certificate issuer.
    <td style="border: none; vertical-align: top;">Certificate Revocation List (CRL)</td>
    <td style="border: none; vertical-align: top;">Signed list indicating a set of certificates that have been revoked by the certificate issuer.
    <br/>
    <a href="https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/01.05.01_60/en_31941101v010501p.pdf">
ETSI EN 319 411-1 V1.5.1
</a>
  </td>
  </tr>
  <tr>
    <td style="border: none;">Certification Authority (CA)</td>
    <td style="border: none;">Authority trusted by one or more users to create and assign certificates.
    <td style="border: none; vertical-align: top;">Certification Authority (CA)</td>
    <td style="border: none; vertical-align: top;">Authority trusted by one or more users to create and assign certificates.
    <br/>
    <a href="https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/01.05.01_60/en_31941101v010501p.pdf">
ETSI EN 319 411-1 V1.5.1
</a>
  </td>
  </tr>

  <tr>
    <td style="border: none;">Digital signature</td>
    <td style="border: none;">Data appended to, or a cryptographic transformation of a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery e.g. by the recipient.
    <td style="border: none; vertical-align: top;">Digital signature</td>
    <td style="border: none; vertical-align: top;">Data appended to, or a cryptographic transformation of a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery e.g. by the recipient.
    <br/>
    <a href="https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/01.05.01_60/en_31941101v010501p.pdf">
ETSI EN 319 411-1 V1.5.1
</a>
  </td>
  </tr>
  <tr>
    <td style="border: none;">Registration Authority (RA)</td>
    <td style="border: none;">Entity that is responsible for identification and authentication of subjects of certificates mainly
    <td style="border: none; vertical-align: top;">Registration Authority (RA)</td>
    <td style="border: none; vertical-align: top;">Entity that is responsible for identification and authentication of subjects of certificates mainly
    <br/>
    <a href="https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/01.05.01_60/en_31941101v010501p.pdf">
ETSI EN 319 411-1 V1.5.1
</a>
  </td>
  </tr>
  <tr>
    <td style="border: none;">Secure cryptographic</td>
    <td style="border: none;">device	Device which holds the user's private key, protects this key against compromise and performs signing or decryption functions on behalf of the user.
    <td style="border: none; vertical-align: top;">Secure cryptographic</td>
    <td style="border: none; vertical-align: top;">device	Device which holds the user's private key, protects this key against compromise and performs signing or decryption functions on behalf of the user.
    <br/>
    <a href="https://www.etsi.org/deliver/etsi_en/319400_319499/31941101/01.05.01_60/en_31941101v010501p.pdf">
ETSI EN 319 411-1 V1.5.1
</a>
  </td>
  </tr>
  <tr>
    <td style="border: none;">Critical entities</td>
    <td style="border: none;">Critical entities as defined by Directive (EU) 2022/2557;
    <td style="border: none; vertical-align: top;">Critical entities</td>
    <td style="border: none; vertical-align: top;">Critical entities as defined by Directive (EU) 2022/2557;
    <br />
    <a href="https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng">
Directive (EU) 2022/2557 – Resilience of Critical Entities (CER)
</a>
  </td>
  </tr>
  <tr>
    <td style="border: none; vertical-align: top;">Personal data</td>
    <td style="border: none; vertical-align: top;">any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
    <br>
      <a href="https://eur-lex.europa.eu/eli/reg/2016/679" target="_blank">
        Regulation (EU) 2016/679 (GDPR) on EUR-Lex
      </a>

  </td>
  </tr>

  <tr>
    <td style="border: none; vertical-align: top;">Cryptographic Key Management System (KMS)</td>
    <td style="border: none; vertical-align: top;">Framework and services that provide for the generation, production, establishment, control, accounting, and destruction of cryptographic keys. It includes all elements (policies, procedures, devices, and components), facilities, personnel, and information products that form the system that establishes, manages, and supports cryptographic products and services for end entities.
    <br/>
    <a href="https://csrc.nist.gov/publications/detail/sp/800/130/final">
      NIST SP 800-130 – A Framework for Designing Cryptographic Key Management Systems
      </a>

  </td>
  </tr>

‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

</table>

@@ -316,57 +371,214 @@ Void.

For the purposes of the present document, the [following] abbreviations  apply:

`AA      Authorization Authority`
`AE      Authentication Entity`
`AES     Advanced Encryption Standard`
`AID     Authentication Identifier`
`AP      Access Point`
`API     Application Programming Interface`
`AT      Authorization Ticket`
`C-ITS   Cooperative ITS`
`CA      Certification Authority`
`CARL    Certification Authority Revocation List`
`CP      Certificate Policy`
`CPOC    C-ITS-Point of Contact`
`CPS     Certification Practice Statement`
`CRA     Cyber Resilience Act`
`CRL     Certificate Revocation List`
`CRY     Cryptography`
`CSP     Cloud Service Provider / Cryptographic Service Provider`
`CSR     Certificate Signing Request`
`CTL     Certificate Trust List`
`DC      Distribution Center`
`EA      Enrolment Authority (similar to LTCA)`
`EC      Enrolment Credential (similar to LTC)`
`ECTL    Extended Certificate Trust List`
`eIDAS   Electronic Identification, Authentication and Trust Services`
`HMAC    Hash-based Message Authentication Code`
`HSM     Hardware Security Module`
`IEEE    Institute of Electrical and Electronics Engineers`
`IT      Information Technology`
`ITS     Intelligent Transport System`
`MA      Misbehaviour Authority #unsure whether this is the correct term (GDC)`
`NA      National Accreditation`
`NIS2    Network and Information Security Directive 2`
`OCSP    Online Certificate Status Protocol`
`PKC     Public Key Certificate`
`PKI     Public Key Infrastructure`
`PP      Protection Profile`
`RA      Registration Authority`
`RBAC    Role-Based Access Control`
`RCA     Root Certificate Authority`
`RCS     Remote Control System`
`SHA     Secure Hash Algorithm`
`SOTA    State of the Art`
`SP      Security Profile`
`SSP     Service Specific Permission`
`SubCA   Subordinate Certificate Authority`
`TAE     Target of Assessment`
`TLM     Trust List Manager`
`TSL     Trust-service Status List`
`TSP     Trust Service Provider`
`URL     Uniform Resource Locator`
`VCS     Version Control System`
<table style="width: 100%; border-collapse: collapse;">
  <colgroup>
    <col style="width: 60pt;">
    <col style="width: auto;">
  </colgroup>
<tr><td style="border: none; vertical-align: top;">AA</td>
<td style="border: none; vertical-align: top;">Authorization Authority</td></tr>
<tr>
  <td style="border: none; vertical-align: top;">AE</td>
  <td style="border: none; vertical-align: top;">Authentication Entity</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">AES</td>
  <td style="border: none; vertical-align: top;">Advanced Encryption Standard</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">AID</td>
  <td style="border: none; vertical-align: top;">Authentication Identifier</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">AP</td>
  <td style="border: none; vertical-align: top;">Access Point</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">API</td>
  <td style="border: none; vertical-align: top;">Application Programming Interface</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">AT</td>
  <td style="border: none; vertical-align: top;">Authorization Ticket</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">C-ITS</td>
  <td style="border: none; vertical-align: top;">Cooperative ITS</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CA</td>
  <td style="border: none; vertical-align: top;">Certification Authority</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CARL</td>
  <td style="border: none; vertical-align: top;">Certification Authority Revocation List</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CP</td>
  <td style="border: none; vertical-align: top;">Certificate Policy</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CPOC</td>
  <td style="border: none; vertical-align: top;">C-ITS-Point of Contact</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CPS</td>
  <td style="border: none; vertical-align: top;">Certification Practice Statement</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CRA</td>
  <td style="border: none; vertical-align: top;">Cyber Resilience Act</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CRL</td>
  <td style="border: none; vertical-align: top;">Certificate Revocation List</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CRY</td>
  <td style="border: none; vertical-align: top;">Cryptography</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CSP</td>
  <td style="border: none; vertical-align: top;">Cloud Service Provider / Cryptographic Service Provider</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CSR</td>
  <td style="border: none; vertical-align: top;">Certificate Signing Request</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">CTL</td>
  <td style="border: none; vertical-align: top;">Certificate Trust List</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">DC</td>
  <td style="border: none; vertical-align: top;">Distribution Center</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">EA</td>
  <td style="border: none; vertical-align: top;">Enrolment Authority (similar to LTCA)</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">EC</td>
  <td style="border: none; vertical-align: top;">Enrolment Credential (similar to LTC)</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">ECTL</td>
  <td style="border: none; vertical-align: top;">Extended Certificate Trust List</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">eIDAS</td>
  <td style="border: none; vertical-align: top;">Electronic Identification, Authentication and Trust Services</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">HMAC</td>
  <td style="border: none; vertical-align: top;">Hash-based Message Authentication Code</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">HSM</td>
  <td style="border: none; vertical-align: top;">Hardware Security Module</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">IEEE</td>
  <td style="border: none; vertical-align: top;">Institute of Electrical and Electronics Engineers</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">IT</td>
  <td style="border: none; vertical-align: top;">Information Technology</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">ITS</td>
  <td style="border: none; vertical-align: top;">Intelligent Transport System</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">MA</td>
  <td style="border: none; vertical-align: top;">Misbehaviour Authority #unsure whether this is the correct term (GDC)</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">NA</td>
  <td style="border: none; vertical-align: top;">National Accreditation</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">NIS2</td>
  <td style="border: none; vertical-align: top;">Network and Information Security Directive 2</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">OCSP</td>
  <td style="border: none; vertical-align: top;">Online Certificate Status Protocol</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">PKC</td>
  <td style="border: none; vertical-align: top;">Public Key Certificate</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">PKI</td>
  <td style="border: none; vertical-align: top;">Public Key Infrastructure</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">PP</td>
  <td style="border: none; vertical-align: top;">Protection Profile</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">RA</td>
  <td style="border: none; vertical-align: top;">Registration Authority</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">RBAC</td>
  <td style="border: none; vertical-align: top;">Role-Based Access Control</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">RCA</td>
  <td style="border: none; vertical-align: top;">Root Certificate Authority</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">RCS</td>
  <td style="border: none; vertical-align: top;">Remote Control System</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">SHA</td>
  <td style="border: none; vertical-align: top;">Secure Hash Algorithm</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">SOTA</td>
  <td style="border: none; vertical-align: top;">State of the Art</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">SP</td>
  <td style="border: none; vertical-align: top;">Security Profile</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">SSP</td>
  <td style="border: none; vertical-align: top;">Service Specific Permission</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">SubCA</td>
  <td style="border: none; vertical-align: top;">Subordinate Certificate Authority</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">TAE</td>
  <td style="border: none; vertical-align: top;">Target of Assessment</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">TLM</td>
  <td style="border: none; vertical-align: top;">Trust List Manager</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">TSL</td>
  <td style="border: none; vertical-align: top;">Trust-service Status List</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">TSP</td>
  <td style="border: none; vertical-align: top;">Trust Service Provider</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">URL</td>
  <td style="border: none; vertical-align: top;">Uniform Resource Locator</td>
</tr>
<tr>
  <td style="border: none; vertical-align: top;">VCS</td>
  <td style="border: none; vertical-align: top;">Version Control System</td>
</tr>
</table>

# 4 Product context