Commit beaf8acc authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Annex U - Structure proposition

parent 80b16631
Loading
Loading
Loading
Loading
+64 −0
Original line number Diff line number Diff line
@@ -1946,6 +1946,70 @@ updatable by a recommended algorithm in the documentation.
- The verdict FAIL shall be assigned otherwise.


# Annex U: Use case description

## A.1 UC1 - Product for use in Private PKI for non critical sectors
### A.1.2 General description (?) 
A private enterprise using public-key cryptography that manages a PKI internally to the enterprise. The enterprise therefore manages the policy framework, the generation of key pairs, the certification of key pairs and the purposes of keys.
In such organisations the PKI may be organised on department centric hierarchies, or on location centric hierarchies, or on organisation role hierarchies or some combination of these. Whilst the set of services to be enabled by the PKI in this use case are large they may include VPN access and management, timestamp services, disk or message encryption, email, and document access and distribution and so on. The deployment of such a private Public Key Infrastructure (PKI) is not driven by regulatory or standardized requirements but rather by the need to align with the entity’s internal policies and security practices.
Additionally, users of these PKI solutions often prioritize flexibility and ease of use over highly secure but restrictive technologies. For instance, they will not rely on Secure Cryptographic Devices (SCD) but rather have private keys stored using operating system or platform key management facilities that provide protection against unauthorised access at rest. The manufacturer shall document the protection mechanisms relied upon and their limitations. Where the platform facility supports hardware-backed protection (e.g. TPM), this should be the preferred configuration.

TO DO Include in the description an overview of what is presented in the next subsections (env., archi, users.).

TO DO - Include UC1 functional figure 

### UC1 - Product Functions

--- Product functions

Product audit & administration 
- F.UserAccountManagement
- F.Network_Configuration
- F.None_SCDBasedKeyManagement
- F.OfficerRegistrationApproval
- F.AuditEventManagement
- F.LoggingOfSecurityEvents 
- F.CertificateProfileManagement

Registration
- F.OnlineRegService
- F.CertificateDissemination
- F.PrivateKeyExport

Certificate generation
- F.NoneSCD_BasedKeyPairGen
- F.SubjectCertSignCreation
- F.OfficerCertGenApproval

Certificate status
- F.CertificateStatus 

Revocation management
- F.RevocationManagement 
- F.OfficerRevocationApproval

### UC1 - Operational Environment

Physical/Hardware
- POE.PartiallyControlled 
- POE.SCD

Logical Software
- SOE.PartiallyControlled
- EC.Audit records secure storage
- EC.Timesource
- EC.Annuary

Connectivity
- COM.Local

### UC1 - Distribution of Security Functions
TODO
### UC1 - Users
In this UC the product should be able to defined user profile restriction on function associated to the following role:

- U.Administrator

# Annex: Bibliography