Commit e330eb10 authored by Sammy Haddad's avatar Sammy Haddad
Browse files

Update file EN-304-624.md

parent 6e21e290
Loading
Loading
Loading
Loading
+1 −12
Original line number Diff line number Diff line
@@ -3911,7 +3911,6 @@ Interfaces

- I.LocalInterface:	Local interface used by the different privileged users to access the product functionalities and data.
- I.AuditAndAdministration:	Interface for remote access to for product for administration and audit purposes.

- I.CertificateGeneration:	Interface with external components providing cryptographic services such as signature or key management.
- I.CertifcateStatus:	Online certificate status requests and dissemination.
- I.RevocationManagement:	Online access to revocation management services (certificate revocation requests).
@@ -3953,7 +3952,6 @@ Product audit & administration

Certificate generation
- F.SCD_BasedKeyPairGen:	Request the generation of the public-private key pair to an external SCD.

- F.SubjectCertSignCreation:	Creates and signs subject certificates based on the identity and other attributes verified by the registration service
- F.OfficerCertGenApproval:	Privileged users to approve and execute this issuance, when certificates are issued.

@@ -3965,6 +3963,7 @@ Certificate status
Revocation management
- F.RevocationManagement:	Processes revocation requests and reports to determine the necessary action to be taken; and provides updates to the certificate status service.
- F.OfficerRevocationApproval:	Explicit user (Officer) approval of certificate revocation requests.

### U.4.3.1 UC4 - Assets
**Table: Mapping between Functions and Assets for UC4**

@@ -4097,25 +4096,21 @@ Product audit & administration
- F.LoggingOfSecurityEvents:	For example, account access attempts, product configuration changes, and system warnings or errors.
- F.CertificateProfileManagement:	Administration functions to define format and default values of certificates to be signed.


Registration
- F.OnlineRegService:	A remote certificate enrolment interface (or Certificate Request Service) that enables users to submit certificate signing requests (CSRs) or certificate creation requests from any network-connected device.
- F.CertificateDissemination:	Distributes signed certificates to subscribers; and, if applicable, stores and makes them available to relying parties.
- F.OfficerRegistrationApproval:	Explicit user (Officer) approval of registration requests.


Certificate generation
- F.SCD_BasedKeyPairGen:	Request the generation of the public-private key pair to an external SCD.
- F.SubjectCertSignCreation:	Creates and signs subject certificates based on the identity and other attributes verified by the registration service
- F.OfficerCertGenApproval:	Privileged users to approve and execute this issuance, when certificates are issued.
- F.PseudonymCertIssuance:	Issuance of pseudonym certificates derived from long-term certificates Those certificates shall not include user identification data.


Revocation management
- F.RevocationManagement:	Processes revocation requests and reports to determine the necessary action to be taken; and provides updates to the certificate status service.
- F.OfficerRevocationApproval:	Explicit user (Officer) approval of certificate revocation requests.


### U.5.3.1 UC5 - Assets

**Table: Mapping between Functions and Assets for UC5**
@@ -4212,16 +4207,13 @@ Physical/Hardware
- POE.FullyControlled:	Fully controlled physical operational environment, where only authorized users have access to the product interfaces.
- POE.SCD: The environment provides a Secure Cryptographic Device (often taking the form of an Hardware Security Module) to generate keys and provide signature support.


Logical Software
- SOE.FullyControlled: Fully controlled logical operational environment (segregation, least priviledged, network protection e.g. firewalls/IDS/IPS/etc.). Only authorised users can access the product interfaces and network data.


External component
- EC.Timesource:	A network server that synchronizes the clocks of devices within an IT infrastructure to ensure consistent and accurate timekeeping for security, logging, and operational purposes.
- EC.UserDirectory:	A directory server that centrally stores, organizes, and provides access to user, group, and resource information (e.g., authentication credentials, contact details) for networked systems and applications.


Connectivity
- COM.Public: Public communication
- COM.Local: Local communication
@@ -4231,7 +4223,6 @@ Connectivity
Distribution
- ARC.Distributed: Functions are split across multiple machines or services, often communicating over a network .


Interfaces
- I.LocalInterface:	Local interface used by the different privileged users to access the product functionalities and data.
- I.AuditAndAdministration:	Interface for remote access to for product for administration and audit purposes.
@@ -4241,7 +4232,6 @@ Interfaces
- I.RevocationManagement:	Online access to revocation management services (certificate revocation requests).
- I.NetworkServices:	Interface to local network services (secure storage, timesources, user directory


### U.5.6 UC5 - Users

In this UC the product should be able to defined user profile restriction on function associated to the following role:
@@ -4251,7 +4241,6 @@ In this UC the product should be able to defined user profile restriction on fun
- U.Auditor:	Authorized to monitor and review product operations logs to ensure compliance and security.
- U.End_User:	Individuals or systems that request certificates or check certificate status for authentication, encryption, or digital signing purposes.


# Annex: Bibliography

<br />