Commit f2d02721 authored by esou's avatar esou
Browse files

Update UC3, UC4 and UC5 name

parent b69aee5a
Loading
Loading
Loading
Loading
+11 −20
Original line number Diff line number Diff line
@@ -703,13 +703,13 @@ The product contains a number of assets that need privileged access to use. The
PKIs can take many forms and the present document does not aim to cover all possible services and their implementations but uses the use cases to assist in identifying the product requirements for these implementations. The uses cases considered are:
- **UC1**: Private PKI for non critical entities.
- **UC2**: Private PKI for critical entities.
- **UC3**: Open or public PKI for critical entities.
- **UC4**: Open or Public basic PKI.
- **UC5**: Multi-authority PKI.
- **UC3**: Public PKI for critical entities.
- **UC4**: Public basic PKI for critical entities.
- **UC5**: Multi-authority PKI for critical entities.

The following subsections present the use cases overviews, full details for use cases descriptions (functions, assets, interfarces, etc.) can be found in Annex U.

### 4.6.1 Product for use in Private PKI for non critical sectors (UC1)
### 4.6.1 Private PKI for non critical sectors (UC1)

A private enterprise using public-key cryptography that manages a PKI internally to the enterprise. The enterprise therefore manages the policy framework, the generation of key pairs, the certification of key pairs and the purposes of keys.
In such organisations the PKI may be organised on department centric hierarchies, or on location centric hierarchies, or on organisation role hierarchies or some combination of these. Whilst the set of services to be enabled by the PKI in this use case are large they may include VPN access and management, timestamp services, disk or message encryption, email, and document access and distribution and so on. The deployment of such a private Public Key Infrastructure (PKI) is not driven by regulatory or standardized requirements but rather by the need to align with the entity’s internal policies and security practices.
@@ -721,7 +721,7 @@ Additionally, users of these PKI solutions often prioritize flexibility and ease

- EXAMPLE 3: User management (identification and authentication) for services like User & Device Authentication, Single Sign-On (SSO).

### 4.6.2 Product for use in Private PKI for critical entities (UC2)
### 4.6.2 Private PKI for critical entities (UC2)

Critical entities often need to produce their own certificates to manage sensitive IT and network services. These services include VPNs, remote SSH connections, timestamp services, disk or message encryption, and PDF signatures. The deployment of such a private Public Key Infrastructure (PKI) is governed by regulatory or standardized requirements, which impose strict constraints, such as:
- Network and physical security,
@@ -735,7 +735,7 @@ As a result, users of these PKI solutions do not have the same deployment flexib

- EXAMPLE 2: Products deployed by telecommunications service providers used to manage proofs of identity, authorization, and encryption to enable secure access to internal services and customer-facing networks, including e.g. 5G core and edge systems, as standardized in 3GPP TS 33.501 and ETSI GS NFV 003. The PKI product is responsible for the issuance, revocation, and overall management of certificates and certificate status information (e.g., via CRLs or OCSP).

### 4.6.3  Open or public PKI for critical entities (UC3)
### 4.6.3  Public PKI for critical entities (UC3)

PKI product used to support certification management services (registration, certificate generation, revocation and status management) provided within very large multi-site company or provided by a CA to the public, and where a compromise carries a significant risk of impact to the security of remote or unknown users, other products, networks or services, or to the health, security or safety of the public.

@@ -743,7 +743,7 @@ Such PKIs are deployed in highly controlled environments, including robust physi

- EXAMPLE 1: Products deployed for a PKI used in large enterprise or critical entities (e.g, eIDAS where in the context of the present document ETSI EN 319 411-1 [] defines requirements on security hardware elements of the PKI and requirement of software elements of the PKI for use in eIDAS).

### 4.6.4 Product for use in Open or Public basic PKI (UC4)
### 4.6.4 Public basic PKI for critical entities. (UC4)

PKI product used to support certification services (certificate generation, revocation and status management) provided within very large multi-site company or provided by a CA to the public, and where a compromise carries a significant risk of impact to the security of remote or unknown users, other products, networks or services, or to the health, security or safety of the public.

@@ -751,7 +751,7 @@ Such PKIs are deployed in highly controlled environments, including robust physi

- EXAMPLE 1: Products deployed for Trust services. Software used to issue certificates for trust services including those used in electronic attribute attestation.

### 4.6.5 Product for use in multi-authority PKI (UC5)
### 4.6.5 Multi-authority PKI for critical entities.
In general terms the multi-authority model separates the entity responsible for authentication from the entity responsible for authorisation of specific services, in like manner to the model of Kerberos [[i.5](#_ref_i_5)] but applied to a public key system.

The multi-authority PKI is intended to combine multiple authorities in a single (extended) domain, sharing resources, and enforcing minimisation of identifying data. In like manner to Kerberos the certificate model in multi-authority PKI enables anonymous or pseudonymous proof of authority. The product in multi-authority PKIs is expected to be able to generate and distribute signed attestations of authority, to verify any received attestation of authority, and to maintain the status of stored public keys.
@@ -4433,7 +4433,7 @@ In this UC the product should be able to defined user profile restriction on fun
- U.Auditor


## U.3 UC3 - Open or public PKI for critical entities
## U.3 UC3 - Public PKI for critical entities

### U.3.1 General description (?)
PKI product used to support certification management services (registration, certificate generation, revocation and status management) provided within very large multi-site company or provided by a CA to the public, and where a compromise carries a significant risk of impact to the security of remote or unknown users, other products, networks or services, or to the health, security or safety of the public.
@@ -4567,10 +4567,6 @@ TODO
  </tr>






</table>

</div>
@@ -4580,11 +4576,6 @@ TODO








### U.3.4 UC3 - Operational Environment


@@ -4629,7 +4620,7 @@ In this UC the product should be able to defined user profile restriction on fun



## U.4 UC4 - Product for use in Open or Public basic PKI
## U.4 UC4 - Product for use in Critical Public basic PKI

### U.4.1 General description (?)

@@ -4812,7 +4803,7 @@ In this UC the product should be able to defined user profile restriction on fun



## U.5 UC5 - Product for use in multi-authority PKI
## U.5 UC5 - Product for use in Critical Multi-Authority PKI

### U.5.1 General description (?)