Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

DigiDoc

From Wikipedia, the free encyclopedia
File format family
DigiDoc
DigiDoc³
Filename extension
.asice, .bdoc, .ddoc .cdoc
Internet media type
application/vnd.etsi.asic-e+zip, application/x-bdoc, application/x-cdoc, application/x-p12d
Developed byRIA (ria.ee)
Latest release
.asice
2014-06-05
Type of formatDigital signature
Container forany file format
Extended fromASiC
StandardEVS 821:2014
Open format?Yes (implementations)
Free format?No (standard text)

DigiDoc (Digital Document) is a family ofdigital signature- andcryptographic computing file formats utilizing apublic key infrastructure. It currently has three generations of sub formats,DDOC- , a later binary basedBDOC and currently usedASiC-E format that is supposed to replace the previous generation formats. DigiDoc was created and is developed and maintained byRIA[1] (Riigi Infosüsteemi Amet,Information System Authority of Estonia).

The format is used tolegally sign and optionally encrypt file(s) like text documents as part ofelectronic transactions. All operations are done using anational id-card, ahardware token, that has a chip with digitalPKIcertificates to verify a person's signaturemathematically. Signed file is acontainer holding actual signed, unmodified files and hence operation does not require any support from software that created those files.

Format container and its signatures can be created using application like qDigiDoc or aweb service with user's web browser with signingextension. When an application is used, container is typically exchanged between signing parties as an email attachment until everyone has signed it and have their own complete copy.

Web services also utilize identity cards for session authentication using an authentication certificate which is also stored on the id-card.

Technical description

[edit]

DigiDoc container contains actual files andmetadata, including ahash that represents those files. When signing, software sends content hash using standardisedPKCS 11 interface to the user's id-card. After verifying the user's PIN, id-card signs the hash internally and returns a signature which is then stored into DigiDoc container.

During the signing, the certificate validity of each signing party is checked, and a signed timestamp is retrieved, using anOCSP service. The signed timestamp makes it possible to prove later at what time a document was signed (as the timestamp is derived from the document hash) and that each signing certificate was not incertificate revocation list at the time of signing. Any signatures prior to the revocation are still valid (therefore, documents do not have to be resigned when the user receives new certificates).

ASiC-E

[edit]

ASiC-E (Associated Signature Containers) and itsextended variant is the latest DigiDoc container format. Usedfile extension is.asice.

BDOC

[edit]

BDOC (Binary Document), of which the latest version is 2.1, is based onETSI's ASiC signature container standards. It is official Estonian national standardEVS 821:2014.[2] Files use the.bdoc file extension.

DDOC

[edit]

DDOC (Digical document) is the first generation DigiDoc format. Files use the.ddoc file extension.

Software

[edit]

The most widely used application is the qDigiDoc graphical desktop software that runs onMicrosoft Windows,Apple Mac OSX and on variousLinux distributions. qDigiDoc isOpen Source Software that can be freely downloaded and installed. Applications also exist for Apple iPad tablet devices and Windows phones.

CurrentlyEstonian- andFinnish government issued cards work with qDigiDoc 3.x and later versions.

Software libraries

[edit]

Multiple programming languages are supported to create applications and services utilizing DigiDoc-format, includingC++, C, Java,.NET,

See also

[edit]

References

[edit]
  1. ^ria.ee Public Key Infrastructure PKIArchived 2015-02-24 at theWayback MachineCompetences of RIA: Is responsible for the functioning, development and management of the ID card base software. Is responsible for the mutual capacity of international electronic identities or the cross-country functioning, development and management of software solutions. Participates in work groups and in the development of the state’s PKI. Assures the existence of the user interface service of the ID card base software (www.id.ee). Referred at 2015-02-24
  2. ^evs.ee EVS 821:2014 - BDOC Format for Digital SignaturesThe present document defines XML formats for advanced electronic signatures that remain valid over long periods and incorporates additional useful information for common use cases. This includes evidence to its validity even if the signer or verifying party later attempts to deny (repudiates) the validity of the signature. Referred: 2016-04-13

External links

[edit]
Retrieved from "https://en.wikipedia.org/w/index.php?title=DigiDoc&oldid=1280441420"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2025 Movatter.jp