Electronic Signatures and Infrastructures (ESI); PAdES digital signatures; Part 2: Additional PAdES signatures profiles
电子签名和基础设施(ESI);帕德斯数字签名;第2部分:附加PAdES签名配置文件
发布日期:
2016-04-01
ETSI EN 319 142-2定义了PAdES数字签名的多个配置文件,这些数字签名是嵌入在PDF文件中的数字签名。本文件包含一个PDF签名使用的概要文件,如ISO 32000-1[1]所述,基于CMS数字签名[i.6],通过提供超出ISO 32000-1[1]的额外限制,使PDF签名具有更大的互操作性。第一个配置文件与ETSI EN 319 142-1[4]无关。本文件还包含第二组概要文件,扩展了PAdES第1部分[5]中概要文件的范围,同时保留了一些增强PAdES签名互操作性的功能。
这些配置文件定义了三个级别的PAdES扩展签名,以满足增量需求,从而在长期内保持签名的有效性,以某种方式,某个级别始终满足其以下级别的所有需求。这些PAdES扩展签名比ETSI EN 319 142-1[4]中规定的PAdES基线签名具有更高的可选性。本文档还定义了第三个配置文件,用于使用嵌入在PDF文件中的用XAdES签名签名的任意XML文档。本文件中定义的配置文件提供了与ETSI TS 102 778[i]中的配置文件相同的要求。
10].PAdES数字签名的创建、增强和验证程序超出了范围,并在ETSI EN 319 102-1[i.11]中进行了规定。ETSI TR 119 100[i.9]中提供了关于创建、增强和验证PAdES数字签名(包括不同属性的使用)的指南。本文件不重复参考标准的基本要求,而是旨在最大限度地提高不同业务领域数字签名的互操作性。
ETSI EN 319 142-2 defines multiple profiles for PAdES digital signatures which are digital signatures embedded within a PDF file.The present document contains a profile for the use of PDF signatures, as described in ISO 32000-1 [1] and based on CMS digital signatures [i.6], that enables greater interoperability for PDF signatures by providing additional restrictions beyond those of ISO 32000-1 [1]. This first profile is not related to ETSI EN 319 142-1 [4].The present document also contains a second set of profiles that extend the scope of the profile in PAdES part 1 [5], while keeping some features that enhance interoperability of PAdES signatures. These profiles define three levels of PAdES extended signatures addressing incremental requirements to maintain the validity of the signatures over the long term, in a way that a certain level always addresses all the requirements addressed at levels that are below it. These PAdES extended signatures offer a higher degree of optionality than the PAdES baseline signatures specified in ETSI EN 319 142-1 [4].The present document also defines a third profile for usage of an arbitrary XML document signed with XAdES signatures that is embedded within a PDF file.The profiles defined in the present document provide equivalent requirements to profiles found in ETSI TS 102 778 [i.10].Procedures for creation, augmentation, and validation of PAdES digital signatures are out of scope and specified in ETSI EN 319 102-1 [i.11]. Guidance on creation, augmentation and validation of PAdES digital signatures including the usage of the different attributes is provided in ETSI TR 119 100 [i.9].The present document does not repeat the base requirements of the referenced standards, but instead aims to maximize interoperability of digital signatures in various business areas.