Circular No. 12/2011/TT-NHNN on the management and use of digital signatures, certificates, and digital signature verification services of the State Bank of Vietnam

Circular No. 12/2011/TT-NHNN stipulates the management, use, issuance, extension, suspension, revocation of digital certificates, and key pair changes for the State Bank of Vietnam, applicable to organizations and individuals under the State Bank of Vietnam, credit institutions, foreign bank branches, and the National Treasury. This circular specifies the issuance, management, use, extension, suspension, revocation of digital certificates, and key pair changes.

Số hiệu12/2011/TT-NHNN
Loại văn bảnCircular
Cơ quan ban hànhState Bank of Vietnam
Người kýNguyễn Toàn Thắng — Phó Thống đốc
Cập nhật26/06/2026
NgànhBanking
Lĩnh vựcUncategorized
Ngày ban hành17/05/2011
Ngày áp dụng30/06/2011
Ngày hết hiệu lực01/02/2016
Tình trạngExpired
✦ Tóm lược thông minh

Circular No. 12/2011/TT-NHNN stipulates the management, use, issuance, extension, suspension, revocation of digital certificates, and key pair changes for the State Bank of Vietnam, applicable to organizations and individuals under the State Bank of Vietnam, credit institutions, foreign bank branches, and the National Treasury. This circular specifies the issuance, management, use, extension, suspension, revocation of digital certificates, and key pair changes.

Đối tượng áp dụng

Organizations and individuals under the State Bank of Vietnam, credit institutions; foreign bank branches; the National Treasury. Other organizations may choose to use the digital signature verification service provided by the State Bank of Vietnam in electronic transactions organized by the State Bank of Vietnam.

Các điểm cốt lõi

  • The organization providing digital signature services is the sole entity of the State Bank of Vietnam responsible for managing and operating technical equipment systems and storing subscriber information.
  • Digital certificates have a maximum validity period of 10 years for the organization providing digital signature services and 5 years for subscribers.
  • Subscribers must use a storage device for secret keys according to technical standards specified by the organization providing digital signature services.
  • Digital certificates may be suspended or revoked in specific cases, with a maximum suspension period of six months, and digital certificates that are revoked will be destroyed after the retention period expires.
  • The organization providing digital signature services must publish a list of issued, suspended, or revoked digital certificates as prescribed.

🌐 Tác động xã hội từ văn bản này

  • Enhance security and confidentiality in electronic transactions of the State Bank of Vietnam.
  • Save time and effort for organizations and individuals in managing digital certificates.
  • May incur initial costs for organizations and individuals when purchasing storage devices for secret keys.

❓ Câu hỏi thường gặp

What is the validity period of a digital certificate?

The validity period of a digital certificate does not exceed 10 years for the organization providing digital signature services and does not exceed 5 years for subscribers.

Which organization manages the provision of digital signature verification services?

The sole organization managing the provision of digital signature verification services is the organization providing digital signature services managed and operated by the Information Technology Department of the State Bank of Vietnam.

What should a subscriber do if they want to change their key pair?

Subscribers must ensure that the remaining validity period of the digital certificate is at least 30 days and submit a request for key pair change according to Form No. 6 attached to this Circular.

When can a digital certificate be revoked?

A subscriber's digital certificate may be revoked in the following cases: expiration of the validity period, request from competent state authorities, the managing organization, or due to violations of regulations on the management and use of secret keys and storage devices for secret keys.

What responsibilities does the organization providing digital signature services have?

The organization providing digital signature services has the responsibility to manage and operate technical equipment systems, store subscriber information, publish lists of issued digital certificates, and handle key pair changes for subscribers.

Toàn văn

CIRCULAR

Regulations on the management and use of digital signatures, digital certificates, and digital signature certification services of the State Bank

__________________________________________

 

Pursuant to the Law on the State Bank of Vietnam No. 46/2010/QH12 dated June 16, 2010;

Pursuant to the Law on Credit Institutions No. 47/2010/QH12 dated June 16, 2010;

Pursuant to the Law on Information Technology No. 67/2006/QH11 dated June 29, 2006;

Pursuant to the Law on Electronic Transactions No. 51/2005/QH11 dated November 29, 2005;

Pursuant to Decree No. 96/2008/NĐ-CP dated August 26, 2008 of the Government stipulating the functions, tasks, powers, and organizational structure of the State Bank of Vietnam;

Pursuant to Decree No. 26/2007/NĐ-CP dated February 25, 2007 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services;

Implementing Resolution No. 60/NQ-CP on simplifying administrative procedures within the scope of functions managed by the State Bank of Vietnam,
The State Bank of Vietnam (hereinafter referred to as the State Bank) hereby stipulates regulations on the management and use of digital signatures, digital certificates, and digital signature certification services of the State Bank as follows:

PART I

GENERAL PROVISIONS

Article 1. Scope of Regulation

This Circular stipulates the management and use of digital signatures, digital certificates, and digital signature certification services in electronic transactions of the State Bank.

Article 2. Applicability

1. Organizations and individuals under the State Bank, credit institutions; foreign bank branches; National Treasury.

2. Other organizations choosing to use the digital signature certification service of the State Bank in electronic transactions organized by the State Bank.

Article 3. Explanation of Terms

In this Circular, the following terms are understood as follows:

1. "Digital certificate" is a form of electronic certificate issued by the organization providing digital signature certification services of the State Bank.

2. "Digital signature certification service" is a type of service provided by the organization providing digital signature certification services of the State Bank. The digital signature certification service includes:

a) Creating a key pair including public and private keys for subscribers;

b) Issuing, renewing, suspending, restoring, and revoking digital certificates for subscribers;

c) Maintaining an online database of certificates;

d) Other services as prescribed by the Digital Signature Decree.

3. "Subscriber" is an organization or individual specified in Article 2 of this Circular; accepted by the organization providing digital signature certification services of the State Bank to issue digital certificates; accepting digital certificates and holding the corresponding private key recorded on the issued digital certificate.

4. "Subscriber management organization" is units under the State Bank; credit institutions, National Treasury or other organizations requesting issuance of digital certificates for their affiliated organizations and individuals and bearing responsibility according to the law on managing such organizations and individuals.

5. "Electronic transaction of the State Bank" means activities and operations conducted electronically by the State Bank.

6. "Digital Signature Decree" refers to Decree No. 26/2007/NĐ-CP dated February 15, 2007 of the Government detailing the implementation of the Law on Electronic Transactions regarding digital signatures and digital signature certification services.

Article 4. Organization providing digital signature certification services of the State Bank

1. The organization providing digital signature certification services of the State Bank (referred to as the digital signature service provider) is managed and operated by the Information Technology Department and is the sole organization of the State Bank providing digital signature certification services.

Address: No. 64 Nguyen Chi Thanh, Dong Da, Hanoi

Telephone: (04) 3835 4775 / (04) 3773 1386

Fax: (04) 3835 8135 / 3834 5180

Main office: Information Security and Management, Issuance of Digital Signatures Office (CA Office).

2. The digital signature service provider of the State Bank belongs to the category of specialized digital signature certification service providers.

Article 5. Digital Certificate

1. Content of the digital certificate:

a) Name of the digital signature service provider;

b) Name of the subscriber;

c) Name of the subscriber management organization;

d) Serial number of the digital certificate;

đ) Validity period of the digital certificate;

e) Public keys of the subscriber;

g) Digital signature of the digital signature service provider;

h) Restrictions on the purpose and scope of use of the digital certificate;

i) Restrictions on the legal liability of the digital signature service provider;

k) Other information for management, use, security, and confidentiality as prescribed by the digital signature service provider.

2. Validity period of the digital certificate:

a) Not exceeding 10 years for digital certificates of the digital signature service provider;

b) Not exceeding 5 years for digital certificates of subscribers.

Article 6. Rights and Obligations of the Parties

1. Rights and obligations of the organization providing digital signature services:

a) The organization providing digital signature services has the following rights:

- Issuing, renewing, suspending, revoking, restoring digital certificates and changing key pairs for subscribers upon request;

- Keeping a copy of the secret key belonging to the encryption key pair of the subscriber and only using this secret key when authorized by the Governor of the State Bank of Vietnam or a person authorized by the Governor of the State Bank of Vietnam;

b) The organization providing digital signature services has the following obligations:

- Managing and operating the technical equipment system for providing digital signature certification services of the State Bank of Vietnam;

- Having contingency plans to ensure the safe and continuous operation of the State Bank of Vietnam's digital signature certification service;

- Storing complete, accurate, and updating subscriber information for the management of digital certificates throughout the validity period of the digital certificate;

- Distributing keys and digital certificates to subscribers;

- Announcing lists of issued, suspended, or revoked digital certificates;

- Ensuring the security and confidentiality of the subscriber's secret key when agreeing to retain a copy of the subscriber's secret key;

- Storing subscriber digital certificate information for at least five years from the date the digital certificate was revoked;

- Organizing the destruction of expired digital certificates and related data according to Article 19 of this Circular if there is no other directive from competent state authorities;

- Guiding and facilitating the management organization and subscribers to comply with the provisions of this Circular;

c) The organization providing digital signature services does not have the obligation to check each specific electronic transaction of the subscriber.

2. Rights and obligations of the organization managing subscribers:

a) The organization managing subscribers has the following rights:

- Being provided guidance information on procedures and formalities for issuing, managing, and using digital certificates;

- Requesting the organization providing digital signature services to issue, renew, suspend, restore, revoke digital certificates or change key pairs for subscribers under its management.

b) The organization managing subscribers has the following obligations:

- Being responsible for the accuracy of the information on applications for issuing, renewing, suspending, restoring, revoking digital certificates and changing key pairs of subscribers under its management;

- Having the responsibility to send documents regarding digital certificates via postal mail or directly to the organization providing digital signature services;

- Guiding, inspecting, and facilitating subscribers under its management to use digital certificates and secret keys in accordance with the provisions of this Circular;

- Promptly notifying in writing the organization providing digital signature services to suspend or revoke the digital certificate of a subscriber in cases where the subscriber temporarily stops working, retires, or transfers to another organization; the subscriber changes jobs and does not use the issued digital certificate, and other cases arising from the needs of the subscriber management organization.

3. Rights and obligations of subscribers:

a) Subscribers have the following rights:

- Being provided guidance information on procedures and formalities for issuing, managing, and using digital certificates;

- Through their subscriber management organization to request issuance, renewal, suspension, restoration, revocation of digital certificates or change of key pairs;

- In necessary cases, subscribers may directly submit a written request to the organization providing digital signature services to suspend their digital certificate and bear legal responsibility for such a request.

b) Subscribers have the following obligations:

- Using digital certificates for the purposes registered;

- Safeguarding and using secret keys and data in the secret key storage device according to "Confidential" regulations;

- Promptly notifying the organization providing digital signature services and their subscriber management organization in case of discovering or suspecting that the digital certificate or secret key is no longer secure;

- Complying with other regulations on issuance, management, and use of digital certificates.

Chapter II

SUBSCRIBERS AND ORGANIZATIONS MANAGING SUBSCRIBERS

Article 7. Issuance of Digital Certificates

1. Individuals and organizations requesting issuance of digital certificates must satisfy the following conditions:

a) Belonging to the subject categories as prescribed in Article 2 of this Circular;

b) Agreeing with the regulations for subscribers as stipulated in this Circular.

2. The application dossier for issuance of digital certificates includes:

The request letter for issuance of digital certificates from the subscriber management organization sent to the digital signature service provider (in accordance with Form No. 7 attached to this Circular), accompanied by the certificate request form (in accordance with Form No. 1 attached to this Circular) of individuals and organizations under the subscriber management organization.

3. In cases where the subscriber creates their own key pair, the subscriber must create the key pair within the time frame specified in the approval notice for issuance of digital certificates. If the subscriber does not have the conditions to create the key pair within the specified timeframe, the subscriber management organization must send a letter to the digital signature service provider requesting an extension of the key creation period for the subscriber.

4. Subscribers must use secure key storage devices according to technical standards prescribed by the digital signature service provider.

Article 8. Extension of Digital Certificates

1. Digital certificates requested for extension must ensure at least 30 days remaining validity period.

2. The subscriber management organization sends the subscriber's extension request form (in accordance with Form No. 2 attached to this Circular) to the digital signature service provider.

3. Each digital certificate can be extended no more than three times, with each extension period not exceeding five years.

Article 9. Suspension of Digital Certificates

1. A subscriber’s digital certificate will be suspended in the following cases:

a) At the written request of the subscriber (in accordance with Form No. 3 attached to this Circular) in cases where the secret key has been exposed or suspected to be exposed; the secure key storage device is lost, illegally copied, or other security breaches occur;

b) At the written request of state agencies with competent authority;

c) At the written request of the subscriber management organization;

d) There is sufficient evidence to determine that the subscriber has violated the provisions of this Circular;

e) The digital signature service provider discovers any errors or incidents that may affect the subscriber's rights or the security of the digital signature certification system.

2. The maximum suspension period for a digital certificate is six months.

Article 10. Revocation of Digital Certificates

1. A subscriber's digital certificate shall be revoked in the following cases:

a) The digital certificate has expired;

b) At the written request of state agencies with competent authority;

c) At the written request of the subscriber management organization;

d) The subscriber management organization or the subscriber has been dissolved or declared bankrupt in accordance with the law;

e) There is sufficient evidence to determine that the subscriber has violated the regulations on managing and using secret keys and secure key storage devices as stipulated in this Circular;

2. After the retention period expires, revoked digital certificates shall be destroyed in accordance with Article 19 of this Circular unless otherwise instructed by competent state authorities.

Article 11. Key Pair Change

1. Subscribers who wish to change their key pair must ensure that the remaining validity period of the digital certificate is at least 30 days.

2. The subscriber management organization sends the subscriber's key pair change request form (in accordance with Form No. 6 attached to this Circular) to the digital signature service provider.

Article 12. Verification of Digital Signatures

1. Before accepting a digital signature from the signer, the recipient must verify the following information:

a) The validity, scope of use, and liability limits of the digital certificate and digital signature of the signer and the service provider of digital signatures;

b) The digital signature must be created using the secret key corresponding to the public key on the digital certificate of the signer.

2. The recipient shall bear all losses arising in the following cases:

a) Failure to comply with the provisions of Clause 1 of this Article;

b) Having knowledge or being informed about the untrustworthiness of the digital certificate and the signer's secret key.

Chapter III

DIGITAL SIGNATURE SERVICE PROVIDER

Article 13. Issuance and Renewal of Digital Certificates

Service providers of digital signatures shall be responsible for:

1. Providing organizations and individuals applying for issuance or renewal of digital certificates with the following information:

a) The scope and limitations of use of the digital certificate, security requirements, and other information that may affect the rights and interests of the applicant organizations and individuals;

b) Requirements for subscribers in creating, storing, and using secret keys;

c) Other contents prescribed by service providers to ensure the security of the digital signature service system.

2. Within five working days from the date of receiving complete and valid applications for issuance or renewal of digital certificates, service providers of digital signatures shall be responsible for examining and issuing or renewing digital certificates for subscribers if they meet the conditions, or providing a refusal notice specifying the reasons for refusal if the conditions are not met.

3. Announcing the list of newly issued digital certificates for subscribers within the time frame specified in Article 18 of this Circular.

Article 14. Suspension and Revocation of Digital Certificates

Service providers of digital signatures shall be responsible for:

1. Ensuring that the channel for receiving requests for suspension or revocation of digital certificates operates 24 hours a day, seven days a week.

2. Storing information related to the suspension or revocation of digital certificates for at least five years from the date of suspension or revocation of the digital certificate.

3. When there is sufficient basis for suspending or revoking a digital certificate, the service provider of digital signatures must immediately suspend or revoke the digital certificate, and simultaneously notify the subscriber and publish the list of suspended or revoked certificates according to the provisions of Article 18 of this Circular.

Article 15. Restoration of Digital Certificates

1. Service providers of digital signatures shall be responsible for considering the restoration of digital certificates for subscribers in the following cases:

a) At the request in writing from competent state agencies;

b) At the request for restoration of the digital certificate from the subscriber or the subscriber manager (according to Form No. 4 attached to this Circular) in cases where the subscriber or the subscriber manager previously requested the suspension of the digital certificate;

c) The suspension period of the digital certificate according to the suspension request has expired;

d) The digital certificate was suspended according to points d and đ of Clause 1, Article 9 of this Circular, and the violations, errors, or incidents have been rectified.

2. Within five working days from the date of receiving complete application files as prescribed, service providers of digital signatures shall be responsible for restoring digital certificates for subscribers if they meet the conditions, or providing a refusal notice if the conditions are not met.

Article 16. Creation and Provision of Keys

1. A key pair of a subscriber may be created by:

a) The subscriber themselves;

b) The service provider of digital signatures upon a written request from the subscriber or the subscriber manager.

2. In the case of self-creation of a key pair, the subscriber must follow the key creation regulations of the service provider of digital signatures.

3. In the case where the service provider of digital signatures creates a key pair for the subscriber, the secret key must be transferred to the subscriber through a secure and confidential method.

Article 17. Change of Subscriber Key Pair

Service providers of digital signatures shall be responsible for:

1. Ensuring that the channel for receiving requests for changing key pairs operates 24 hours a day, seven days a week.

2. Within five working days from the date of receiving complete and valid applications for changing keys, service providers of digital signatures shall examine and change the key pair for subscribers if they meet the conditions, and distribute the key according to the provisions of Article 16 of this Circular, or provide a refusal notice if the conditions are not met.

3. Storing information related to the activity of changing key pairs for at least five years from the date of change.

Article 18. Updating and Publishing Information

1. The organization providing digital signature services shall be responsible for maintaining on their electronic news page the following information 24 hours a day and 7 days a week:

a) Circulars certifying digital signatures and digital certificates;

b) List of active, suspended, and revoked digital certificates of subscribers;

c) Other necessary information.

2. Time to update the database of digital certificates of the organization providing digital signature services:

a) Within eight working hours from the completion time of the issuance procedures for newly issued digital certificates;

b) Immediately after completing the suspension, revocation of digital certificates or key pair changes.

Article 19. Destruction of Digital Certificates

1. Principles of destruction:

a) Ensuring complete destruction of information on paper and storage devices;

b) The destruction committee consists of representatives from the subscriber management organization and relevant departments involved in the management and use of digital certificates. The committee conducts the destruction of digital certificates and related data, and prepares a destruction record with the main contents: type of destroyed document; method of destruction; conclusion and signatures of the committee members.

2. Methods of destruction:

a) Destroying paper documents by shredding them beyond recovery or completely burning them;

b) Erasing all digital certificate and related data information on storage devices beyond recovery.

3. Content of destruction:

a) Digital certificate data, key pairs;

b) Other data related to the issuance, management, and use of digital certificates.

Chapter IV

IMPLEMENTING PROVISIONS

Article 20. Violations, Handling of Violations, Complaints, and Dispute Resolution

The determination of violations and handling of violations, complaints, and dispute resolution regarding digital signatures and digital signature certification services provided by organizations offering digital signature services, subscribers, and subscriber management organizations shall be carried out in accordance with the provisions of the Decree on Digital Signatures and other relevant laws.

Article 21. Effective Date

This Circular takes effect from June 30, 2011, and replaces Decision No. 04/2008/QD-NHNN dated February 21, 2008, issued by the Governor of the State Bank of Vietnam on the Regulations for the Issuance, Management, and Use of Digital Signatures, Digital Certificates, and Digital Signature Certification Services of the State Bank of Vietnam.

Article 22. Responsibility for enforcement

1. The Department of Information Technology is responsible for:

a) Guide, monitor, and inspect the implementation of this Circular by units under the State Bank of Vietnam, credit organizations, foreign bank branches, and other organizations using the State Bank of Vietnam's digital signature certification services.

b) Study and implement the integration of digital signatures into the activities and banking operations of the State Bank of Vietnam.

2. Banking inspection agencies have the responsibility to cooperate with the Department of Information Technology to inspect the compliance with this Circular by credit institutions and foreign bank branches.

3. The Internal Audit Department is responsible for conducting internal audits and internal audits of the implementation of this Circular by units under the State Bank of Vietnam.

4. Heads of units under the State Bank of Vietnam, Governors of provincial and centrally-administered city branches of the State Bank of Vietnam, Chairmen of the Board of Directors, General Directors (Directors) of credit organizations, foreign bank branches, National Treasury, and heads of other organizations using the State Bank of Vietnam's digital signature certification services are responsible for organizing the implementation and inspection of compliance with this Circular at their respective units in accordance with its provisions./.

Văn bản gốc (PDF)

Mở PDF trong tab mới ↗

Bản đồ quan hệ

12/2011/TT-NHNN
Circular No. 12/2011/TT-NHNN on the management and use of digital signatures, certificates, and digital signature verification services of the State Bank of Vietnam
Expired

Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.