- F.SCD_BasedKeyPairGen: Request the generation of the public-private key pair to an external SCD.
- F.SubjectCertSignCreation: Creates and signs subject certificates based on the identity and other attributes verified by the registration service
- F.OfficerCertGenApproval: Privileged users to approve and execute this issuance, when certificates are issued.
@@ -3965,6 +3963,7 @@ Certificate status
Revocation management
- F.RevocationManagement: Processes revocation requests and reports to determine the necessary action to be taken; and provides updates to the certificate status service.
- F.OfficerRevocationApproval: Explicit user (Officer) approval of certificate revocation requests.
### U.4.3.1 UC4 - Assets
**Table: Mapping between Functions and Assets for UC4**
- F.LoggingOfSecurityEvents: For example, account access attempts, product configuration changes, and system warnings or errors.
- F.CertificateProfileManagement: Administration functions to define format and default values of certificates to be signed.
Registration
- F.OnlineRegService: A remote certificate enrolment interface (or Certificate Request Service) that enables users to submit certificate signing requests (CSRs) or certificate creation requests from any network-connected device.
- F.CertificateDissemination: Distributes signed certificates to subscribers; and, if applicable, stores and makes them available to relying parties.
- F.OfficerRegistrationApproval: Explicit user (Officer) approval of registration requests.
Certificate generation
- F.SCD_BasedKeyPairGen: Request the generation of the public-private key pair to an external SCD.
- F.SubjectCertSignCreation: Creates and signs subject certificates based on the identity and other attributes verified by the registration service
- F.OfficerCertGenApproval: Privileged users to approve and execute this issuance, when certificates are issued.
- F.PseudonymCertIssuance: Issuance of pseudonym certificates derived from long-term certificates Those certificates shall not include user identification data.
Revocation management
- F.RevocationManagement: Processes revocation requests and reports to determine the necessary action to be taken; and provides updates to the certificate status service.
- F.OfficerRevocationApproval: Explicit user (Officer) approval of certificate revocation requests.
### U.5.3.1 UC5 - Assets
**Table: Mapping between Functions and Assets for UC5**
@@ -4212,16 +4207,13 @@ Physical/Hardware
- POE.FullyControlled: Fully controlled physical operational environment, where only authorized users have access to the product interfaces.
- POE.SCD: The environment provides a Secure Cryptographic Device (often taking the form of an Hardware Security Module) to generate keys and provide signature support.
Logical Software
- SOE.FullyControlled: Fully controlled logical operational environment (segregation, least priviledged, network protection e.g. firewalls/IDS/IPS/etc.). Only authorised users can access the product interfaces and network data.
External component
- EC.Timesource: A network server that synchronizes the clocks of devices within an IT infrastructure to ensure consistent and accurate timekeeping for security, logging, and operational purposes.
- EC.UserDirectory: A directory server that centrally stores, organizes, and provides access to user, group, and resource information (e.g., authentication credentials, contact details) for networked systems and applications.
Connectivity
- COM.Public: Public communication
- COM.Local: Local communication
@@ -4231,7 +4223,6 @@ Connectivity
Distribution
- ARC.Distributed: Functions are split across multiple machines or services, often communicating over a network .
Interfaces
- I.LocalInterface: Local interface used by the different privileged users to access the product functionalities and data.
- I.AuditAndAdministration: Interface for remote access to for product for administration and audit purposes.
- I.NetworkServices: Interface to local network services (secure storage, timesources, user directory
### U.5.6 UC5 - Users
In this UC the product should be able to defined user profile restriction on function associated to the following role:
@@ -4251,7 +4241,6 @@ In this UC the product should be able to defined user profile restriction on fun
- U.Auditor: Authorized to monitor and review product operations logs to ensure compliance and security.
- U.End_User: Individuals or systems that request certificates or check certificate status for authentication, encryption, or digital signing purposes.