Commit 7cffda54 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Update file EN-304-624.md

parent ec808a48
Loading
Loading
Loading
Loading
+17 −0
Original line number Diff line number Diff line
@@ -4343,6 +4343,23 @@ updatable by a recommended algorithm in the documentation.

# Annex U: Use case description

## U.1 UC1 - Product for use in Private PKI for non critical sectors
### U.1.2 General description
A private enterprise using public-key cryptography that manages a PKI internally to the enterprise. The enterprise therefore manages the policy framework, the generation of key pairs, the certification of key pairs and the purposes of keys.
In such organisations the PKI may be organised on department centric hierarchies, or on location centric hierarchies, or on organisation role hierarchies or some combination of these. Whilst the set of services to be enabled by the PKI in this use case are large they may include VPN access and management, timestamp services, disk or message encryption, email, and document access and distribution and so on. The deployment of such a private Public Key Infrastructure (PKI) is not driven by regulatory or standardized requirements but rather by the need to align with the entity’s internal policies and security practices.
Additionally, users of these PKI solutions often prioritize flexibility and ease of use over highly secure but restrictive technologies. For instance, they will not rely on Secure Cryptographic Devices (SCD) but rather have private keys stored using operating system or platform key management facilities that provide protection against unauthorised access at rest. The manufacturer shall document the protection mechanisms relied upon and their limitations. Where the platform facility supports hardware-backed protection (e.g. TPM), this should be the preferred configuration.

- EXAMPLE 1: Products deployed to support software maintenance.

- EXAMPLE 2: Products deployed to support internal IT service for network security deployments (e.g. VPN, ssh, TLS servers).

- EXAMPLE 3: User management (identification and authentication) for services like User & Device Authentication, Single Sign-On (SSO).

**Figure U.1.2: UC1 functional architecture**

![Figure U.1.2: UC1 functional architecture](media/Figures/UC_Architecture/UC1.png)


### U.1.3 UC1 - Product Functions and assets

### U.1.3.1 UC1 - List of functions