Commit 98f34dba authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Update file EN-304-624.md

parent ad6b495d
Loading
Loading
Loading
Loading
+2 −65
Original line number Diff line number Diff line
@@ -3625,37 +3625,6 @@ Compliance with the requirement in clause K.4.1 is assessed in clause K.1.2.3.
|   V1.2    |     25 May 2026      | The update clarifies the ACM-extended route in clause K.1.1 item 2 by removing the reference to the criteria in item 2.b from item 2.a, confirming that mechanisms listed in clause K.3.2 are accepted through the K.3.2 route, while the criteria in item 2.b apply where the mechanism is not listed in clause K.3.2. The corresponding rapporteur guidance remains in clause K.3.0.

































# Annex U: Use case description

## U.1 UC1 - Product for use in Private PKI for non critical sectors
@@ -3665,9 +3634,7 @@ In such organisations the PKI may be organised on department centric hierarchies
Additionally, users of these PKI solutions often prioritize flexibility and ease of use over highly secure but restrictive technologies. For instance, they will not rely on Secure Cryptographic Devices (SCD) but rather have private keys stored using operating system or platform key management facilities that provide protection against unauthorised access at rest. The manufacturer shall document the protection mechanisms relied upon and their limitations. Where the platform facility supports hardware-backed protection (e.g. TPM), this should be the preferred configuration.

- EXAMPLE 1: Products deployed to support software maintenance.

- EXAMPLE 2: Products deployed to support internal IT service for network security deployments (e.g. VPN, ssh, TLS servers).

- EXAMPLE 3: User management (identification and authentication) for services like User & Device Authentication, Single Sign-On (SSO).

**Figure U.1.2: UC1 functional architecture**
@@ -3680,49 +3647,33 @@ Additionally, users of these PKI solutions often prioritize flexibility and ease
### U.1.3.1 UC1 - List of functions
Product audit & administration
- F.UserAccountManagement: creation, modification, rights attributions and modification of the different user accounts.

- F.NetworkConfiguration: set up of network addresses and protocols for the different product network interfaces (management, certificate generation/revocation/status requests, etc.).

- F.Non_SCD_BasedKeyManagement: software keys suppression, export, renewal.

- F.OfficerRegistrationApproval: request to the SCD for keys suppression, export, renewal.

- F.AuditEventManagement: configuration of audit events to be stored and their associated format. Search or erasure capabilities associated to stored audit events.


- F.LoggingOfSecurityEvents: for example, account access attempts, product configuration changes, and system warnings or errors.


- F.CertificateProfileManagement: administration functions to define format and default values of certificates to be signed.


Registration
- F.OnlineRegService: a remote certificate enrolment interface (or Certificate Request Service) that enables users to submit certificate signing requests (CSRs) or certificate creation requests from any network-connected device.

- F.CertificateDissemination: distributes signed certificates to subscribers; and, if applicable, stores and makes them available to relying parties.

- F.PrivateKeyExport: private key, secret key or critical data can be encrypted and then exported in the form of an encrypted file.

Certificate generation
- F.Non_SCD_BasedKeyPairGen: generates the public-private key pair.

- F.SubjectCertSignCreation: creates and signs subject certificates based on the identity and other attributes verified by the registration service.


- F.OfficerCertGenApproval: privileged users to approve and execute this issuance, when certificates are issued.


Certificate status
- F.CertificateStatus: maintains certificate status information (e.g. active, expired, revoked).


Revocation management
- F.RevocationManagement: processes revocation requests and reports to determine the necessary action to be taken; and provides updates to the certificate status service.


### U.1.3.2 UC1 - Assets


**Table: Mapping between Functions and Assets for UC1**

<div align="center">
@@ -3822,12 +3773,9 @@ Revocation management
Physical/Hardware
- POE.PartiallyControlled: partially controlled physical operational environment, none product users can access the product’s hardware it’s installed on.


Logical Software
- SOE.PartiallyControlled: partially controlled software operational environment product users can access the product’s interfaces and network data in transit.

- EC.Audit records secure storage: external hardware and software use to store audit data.

- EC.Timesource: a network server that synchronizes the clocks of devices within an IT infrastructure to ensure consistent and accurate timekeeping for security, logging, and operational purposes.


@@ -3835,7 +3783,6 @@ Logical Software
Connectivity
- COM.Local: Local communication


Distribution
- ARC.Monolithic: all components are integrated and run on a single machine or platform.

@@ -3856,15 +3803,10 @@ or

Interfaces
- I.AuditAndAdministration: interface for remote access to for product for administration and audit purposes.

- I.Registration: online registration interface receiving remote Certificates Signing Requests from subscribers.

- I.ExternalKMS: interface with external components providing cryptographic services such as signature or key management.

- I.CertificateStatus: online certificate status requests and dissemination.

- I.RevocationManagement: online access to revocation management services (certificate revocation requests).

- I.NetworkServices: Interface to local network services (secure storage, timesources, user directory

### U.1.6 UC1 - Users
@@ -3883,9 +3825,7 @@ Critical entities often need to produce their own certificates to manage sensiti
- Compliance with secure operational practices.

As a result, users of these PKI solutions do not have the same deployment flexibility as in less regulated use cases (e.g., UC1). However, they are still permitted to use products that offer diverse functionalities.

- EXAMPLE 1: Products deployed for Trust services. Software used to issue certificates for trust services including those used in electronic attribute attestation.

- EXAMPLE 2: Products deployed by telecommunications service providers used to manage proofs of identity, authorization, and encryption to enable secure access to internal services and customer-facing networks, including e.g. 5G core and edge systems, as standardized in 3GPP TS 33.501 and ETSI GS NFV 003. The product is responsible for the issuance, revocation, and overall management of certificates and certificate status information (e.g., via CRLs or OCSP).

**Figure U.2.2: UC2 functional architecture**
@@ -4033,9 +3973,11 @@ Revocation management

Physical/Hardware
- POE.FullyControlled: Fully controlled physical operational environment, where only authorized users have access to the product interfaces.

Logical Software
- SOE.FullyControlled: Fully controlled logical operational environment (segregation, least priviledged, network protection e.g. firewalls/IDS/IPS/etc.). Only authorised users can access the product interfaces and network data.

Required external components
- EC.Audit records secure storage: External hardware and software use to store audit data.
- EC.Timesource: A network server that synchronizes the clocks of devices within an IT infrastructure to ensure consistent and accurate timekeeping for security, logging, and operational purposes.

@@ -4210,12 +4152,10 @@ Connectivity

Distribution
- ARC.Monolithic: All components are integrated and run on a single machine or platform.

- ARC.Distributed:	Functions are split across multiple machines or services, often communicating over a network .
- ARC.PrivateCloud:	Product is deployed on a private cloud where HW infrastructure as well as orchestrator layer are in control of the organization  managing the PKI)

Interfaces

- I.LocalInterface:	Local interface used by the different privileged users to access the product functionalities and data.
- I.AuditAndAdministration:	Interface for remote access to for product for administration and audit purposes.
- I.CertificateGeneration:	Interface with external components providing cryptographic services such as signature or key management.
@@ -4262,11 +4202,9 @@ Certificate generation
- F.SubjectCertSignCreation:	Creates and signs subject certificates based on the identity and other attributes verified by the registration service
- F.OfficerCertGenApproval:	Privileged users to approve and execute this issuance, when certificates are issued.


Certificate status
- F.CertificateStatus: Maintains certificate status information (e.g. active, expired, revoked).


Revocation management
- F.RevocationManagement:	Processes revocation requests and reports to determine the necessary action to be taken; and provides updates to the certificate status service.
- F.OfficerRevocationApproval:	Explicit user (Officer) approval of certificate revocation requests.
@@ -4365,7 +4303,6 @@ Connectivity
Distribution
- ARC.Monolithic: All components are integrated and run on a single machine or platform.


Interfaces
- I.LocalInterface: Local interface used by the different privileged users to access the product functionalities and data.