This Circular details the provision, management, and use of specialized digital signature certification services for Party agencies, State agencies, and political-social organizations. It includes the responsibilities of related parties such as the Government Cryptographic Agency, service providers, direct managing agencies, and subscribers. This Circular takes effect from February 18, 2020, and replaces Circular No. 08/2016/TT-BQP.
적용 범위
Party agencies, State agencies, political-social organizations, and related parties in the provision, management, and use of specialized digital signature certification services.
핵심 사항
- Detailed provisions on the responsibilities of the Government Cryptographic Agency
- Requirement to ensure absolute security of the private key of the digital certificate
- Provisions on receiving, transferring, and recovering digital certificates, and devices storing the private key
- Responsibility for managing application files for issuance, extension, change of information content, and recovery of digital certificates
- Requirement to use digital certificates for their intended purpose and comply with regulations
🌐 이 문서의 사회적 영향
- Ensuring information security in electronic transactions of Party agencies and State agencies
- Enhancing the effectiveness of management and use of specialized digital signatures
- Promoting the development of information technology applications in government operations
❓ 자주 묻는 질문
Which Circular does this Circular replace?
This Circular replaces Circular No. 08/2016/TT-BQP issued by the Minister of National Defense.
When does this Circular take effect?
This Circular takes effect from February 18, 2020.
전문
CIRCULAR
H||| guiding the provision, management, and use of digital signature authentication services ||
|| ||Government
Pursuant to the Law on Cryptography dated November 26, 2011;
||| based on Decree No. 164/2017/ND-CP dated December 30, 2017 of the Government|| At the proposal of the General Staff;
Decree No. ||| based on Decree No. 09/2014/ND-CP dated January 17, 2014 of the Government||||| detailing the functions, tasks, powers, and organizational structure of the Government Cryptographic Agency;
||||| based on Decree No. 130/2018/ND-CP dated September 27, 2018 of the Government||||| detailing the implementation of the Law on Electronic Transactions regarding digital signatures ||| and digital signature authentication services;
||||| At the request of the Director of the Government Cryptographic Agency,
||| The Minister of National Defense issues this Circular to guide the provision, management, and use of digital signature authentication services for the Government. || ||||| This Circular applies to agencies, organizations, and individuals related to the activities of providing, managing, and using digital signature authentication services for the Government.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
||| This Circular guides the provision, management, and use of digital signature authentication services specifically for the Government.
Article 2. Applicability
||| This Circular applies to agencies, organizations, and individuals related to the activities of providing, managing, and using digital signature authentication services specifically for the Government.
Article 3. Explanation of Terms
In this Circular, the following terms shall be understood as follows:
||| "Directly managing agency or organization" means an entity with legal personality and its own seal, belonging to Party and State agencies directly managing users of digital signature authentication services specifically for the Government.
||| "Authentication request" refers to new issuance, extension, change of information content, revocation of digital certificates, and recovery of key storage devices.
||| "Information registration and management system for authentication requests" is an electronic system supporting the registration and management of digital signature authentication services specifically for the Government on a network environment.
||| Article 4. Organization providing digital signature authentication services specifically for the Government
||| 1. The organization providing digital signature authentication services specifically for the Government is the Digital Authentication and Information Security Bureau under the Government Cryptographic Agency.
||| 2. Contact information:
||| Digital Authentication and Information Security Bureau.
||| Address: No. 23 Nguyen Huu Tho Street, Thanh Xuan District, Hanoi City
||| Telephone/Fax: 024.3773.8668
||| Email address: [email protected]
||| Website: http://ca.gov.vn
||| Electronic document exchange identifier: 000.05.07.G11
||| Article 5. Sending and receiving authentication request documents
||| 1. Sending and receiving authentication request documents between directly managing agencies or organizations and the Digital Authentication and Information Security Bureau shall be carried out through paper documents or electronically signed documents in accordance with the law.
||| 2. Sending and receiving electronically signed authentication request documents between directly managing agencies or organizations and the Digital Authentication and Information Security Bureau shall be conducted via the Information Registration and Management System for Authentication Requests or the National Document Interconnection Network.
||| a) Electronically signed authentication request documents sent and received through the Information Registration and Management System for Authentication Requests or the National Document Interconnection Network have legal equivalence to paper documents and replace the sending and receiving of paper documents.
||| b) Electronically signed authentication request documents not covered by point a of Clause 2 of this Article sent and received through the Information Registration and Management System for Authentication Requests or the National Document Interconnection Network serve only for information and reference purposes and do not replace the sending and receiving of paper documents. In such cases, directly managing agencies or organizations must provide the original paper document at the time of receiving the digital certificate and key storage device.
Article 6. Sending and Receiving Secret Key Storage Devices
The sending and receiving of secret key storage devices between subscribers, direct management agencies, organizations, the Directorate for Digital Certification and Information Security shall be carried out directly, through specialized organizations, or through postal service units in accordance with the provisions of the law.
Article 7. Sending and Receiving Requests for Certification and Secret Key Storage Devices within the Ministry of National Defense, Ministry of Public Security, and Ministry of Foreign Affairs
The sending and receiving of requests for certification and secret key storage devices between direct management agencies within the Ministry of National Defense, Ministry of Public Security, and Ministry of Foreign Affairs and the Directorate for Digital Certification and Information Security shall be conducted through specialized organizations under the Ministry of National Defense, Ministry of Public Security, and Ministry of Foreign Affairs.
Chapter II
GUIDANCE ON FILES AND FORMS FOR PROVIDING AND MANAGING SERVICES
GOVERNMENT DIGITAL SIGNATURE CERTIFICATION
Article 8. Issuing New Digital Certificates
1. Issuing new digital certificates for individuals:
a) Individuals submit a request for issuing a new digital certificate according to Form 01 attached to this Circular to the direct management agency;
b) The direct management agency submits a request for issuing a new digital certificate according to Form 02 attached to this Circular to the Directorate for Digital Certification and Information Security.
2. Issuing new digital certificates for agencies and organizations:
a) The authorized person of the agency or organization in accordance with the law on seal management and use, who is assigned to manage the agency's or organization's digital certificate, submits a request for issuing a digital certificate according to Form 03 attached to this Circular to the direct management agency;
b) The direct management agency submits a request for issuing a new digital certificate according to Form 04 attached to this Circular to the Directorate for Digital Certification and Information Security.
3. Issuing new digital certificates for devices, services, software:
a) The authorized person of the agency or organization in accordance with the law on seal management and use, who is assigned to manage the device's, service's, or software's digital certificate, submits a request for issuing a digital certificate according to Form 05 attached to this Circular to the direct management agency;
b) The direct management agency submits a request for issuing a new digital certificate according to Form 06 attached to this Circular to the Directorate for Digital Certification and Information Security.
4. After handing over the secret key storage device to the subscriber, the direct management agency submits a request for the effective date of the digital certificate according to Form 13 attached to this Circular to the Directorate for Digital Certification and Information Security.
Article 9. Extending and Changing Information in Digital Certificates
1. Subscribers submit a request for extending or changing information in digital certificates according to Form 07 attached to this Circular to the direct management agency;
2. The direct management agency submits a request for extending or changing information in digital certificates according to Form 08 attached to this Circular to the Directorate for Digital Certification and Information Security.
Article 10. Revoking Digital Certificates and Retrieving Secret Key Storage Devices
1. Revoking digital certificates:
a) Subscribers submit a request for revoking digital certificates according to Form 09 attached to this Circular to the direct management agency;
b) The direct management agency submits a request for revoking digital certificates according to Form 10 attached to this Circular to the Directorate for Digital Certification and Information Security.
2. Retrieving secret key storage devices:
a) The direct management agency is responsible for retrieving secret key storage devices of expired digital certificates or revoked digital certificates, and transferring them to the Directorate for Digital Certification and Information Security. A record of the transfer of secret key storage devices after the expiration of digital certificates or their revocation according to Form 14 attached to this Circular;
b) In case of loss of secret key storage devices, the direct management agency must immediately prepare a confirmation record according to Form 15 attached to this Circular and send it to the Directorate for Digital Certification and Information Security.
Article 11. Restoration of Key Storage Devices
1. The subscriber shall submit a request for restoration of key storage devices according to Form 11 attached hereto to the directly managing agency or organization.
2. The directly managing agency or organization shall send a request for restoration of key storage devices according to Form 12 attached hereto to the National Agency for Digital Certification and Network Information Security or an organization authorized by the National Agency for Digital Certification and Network Information Security.
Chapter III
RESPONSIBILITIES OF AGENCIES, ORGANIZATIONS AND INDIVIDUALS
Article 12. Responsibilities of Party and State Agencies
1. To establish and promulgate regulations on the management and use of specialized government digital signature certification services within their jurisdiction.
2. Annually report on the implementation and use of specialized government digital signature certification services during the year and develop plans and requirements for use in the following year for subscribers under their management in accordance with guidelines from the Government Cryptographic Department.
3. Manage, guide, and inspect subscribers during the implementation, management, and use of digital certificates, key storage devices, and specialized government digital signature certification services within their jurisdiction.
4. Take the lead and coordinate with the National Agency for Digital Certification and Network Information Security to organize training and instruction on the deployment and use of digital certificates, key storage devices, and specialized government digital signature certification services.
5. The heads of agencies and organizations: the Central Party Office and its affiliated advisory and support bodies under the Central Committee of the Communist Party of Vietnam; the National Ethnic Council; the Committees of the National Assembly; the National Assembly Office; the President's Office; Ministries, ministerial-level agencies, and agencies under the Government; the Supreme People's Procuratorate; the Supreme People's Court; the State Audit Agency; provincial and municipal party committees under central authority; Provincial People's Councils, Municipal People's Councils, and other organizations as prescribed by competent authorities shall direct and authorize subordinate specialized agencies to implement the contents stipulated in Clauses 1, 2, 3, and 4 of this Article.
Article 13. Responsibilities of the Government Cryptographic Department
1. Assist the Minister of Defense in state management of specialized government digital signature certification services; organize the provision of digital signature certification, verification, and information security in electronic transactions serving Party and State agencies.
2. Coordinate with Party and State agencies to develop regulations on the management and use of specialized government digital signature certification services.
3. Guide and inspect relevant organizations and individuals regarding registration, provision, management, and use of specialized government digital signature certification services.
4. Coordinate and support related agencies to integrate specialized government digital signature certification services into information technology applications to ensure information security, verification, and confidentiality.
5. Research and apply technologies related to specialized government digital signature certification services suitable for information technology applications serving agencies and organizations.
6. Lead and coordinate with related agencies to allocate personnel, funding, and office space to implement tasks, manage and maintain operations, and ensure the provision of digital certificates, key storage devices, and specialized government digital signature certification services based on actual needs of Party and State agencies, ensuring safety and continuity.
7. Manage and direct the National Agency for Digital Certification and Network Information Security to effectively provide digital certificates, key storage devices, and specialized government digital signature certification services based on plans and requirements of agencies and organizations.
8. Assist the Minister of Defense in monitoring and inspecting the implementation of this Circular.
Article 14. Responsibilities of Organizations Providing Government-Specific Digital Signature Certification Services
1. Ensuring absolute security for the private key of digital certificates and handling situations during the provision and management of digital certificates.
2. Managing and operating the technical infrastructure of the digital signature certification system to ensure the safe and continuous provision of digital signature certification services.
3. Updating and accurately storing all information on certification requests according to the provisions of the law.
4. Ensuring channels for receiving requests for issuance, extension, change of content, revocation of digital certificates, and recovery of devices storing private keys; updating and maintaining 24 hours a day, 7 days a week online databases regarding digital certificate policies, regulations on the provision, management, and use of digital signature certification services and digital certificates of the National Digital Certification and Information Security Department, lists of valid digital certificates, revoked digital certificates, and other necessary information.
5. Managing, operating, maintaining, and organizing guidance for agencies and organizations using the Registration and Management System for Certification Requests.
Article 15. Responsibilities of Directly Managing Agencies and Organizations
1. Based on requirements for ensuring safety and verifying information in electronic transactions serving their own tasks, examining and confirming documents and being responsible for the accuracy of information proposed for issuance, extension, change of content, revocation of digital certificates, and recovery of devices storing private keys for organizations and individuals under their management.
2. Receiving and transferring digital certificates and devices storing private keys to subscribers according to regulations.
3. Recovering devices storing private keys of organizations and individuals under their transfer to the National Digital Certification and Information Security Department.
4. Updating, managing, and storing records of requests for issuance, extension, change of content, revocation of digital certificates, and recovery of devices storing private keys of subscribers within their management scope according to the provisions of the law.
5. Inspecting the deployment and use of digital certificates, devices storing private keys, and government-specific digital signature certification services within their management scope.
6. Regularly and urgently reporting on the situation of providing, managing, and using government-specific digital signature certification services according to the requirements of competent authorities.
Article 16. Responsibilities of Cryptographic Organizations Subordinate to the Ministry of National Defense, Ministry of Public Security, and Ministry of Foreign Affairs
1. Annually advising the heads of the respective ministries to develop plans and needs for applying government-specific digital signature certification services for subscribers under their management to ensure safety and verification of information in electronic transactions.
2. Developing and submitting to competent authorities for promulgation regulations and rules on the management and use of government-specific digital signature certification services within their management scope.
3. Being responsible for the accuracy of information proposed for issuance, extension, change of content, revocation of digital certificates, and recovery of devices storing private keys; documents proposing application according to Models 2, 4, 6, 8, 10, 12, 14, and 15 attached to this Circular.
4. Receiving digital certificates and devices storing private keys transferred from the National Digital Certification and Information Security Department to directly managing agencies and organizations.
5. Receiving digital certificates and devices storing private keys recovered from directly managing agencies and organizations and transferred to the National Digital Certification and Information Security Department.
6. Updating, managing, and storing records of requests for issuance, extension, change of content, revocation of digital certificates, and recovery of devices storing private keys of subscribers within their management scope according to the provisions of the law.
7. Leading and coordinating with the National Digital Certification and Information Security Department to organize training and instruction on deploying and using digital certificates, devices storing private keys, and government-specific digital signature certification services for subscribers within their management scope.
8. Guiding and inspecting subscribers during the deployment, management, and use of digital certificates, devices storing private keys, and government-specific digital signature certification services.
9. Coordinating with the National Digital Certification and Information Security Department to integrate government-specific digital signature certification services into information technology applications to ensure safety, verification, and information security.
10. Statistics, inspection, and management of issuance, extension, change of content, revocation of digital certificates, and recovery of devices storing private keys of agencies and organizations within the management scope of the respective ministry, and regularly reporting once a year before October 31 each year or urgently reporting to the Government Cryptographic Office (through the National Digital Certification and Information Security Department).
Article 17. Obligations of the Subscriber
1. Provide accurate and complete information related to the issuance, extension, and change of the content of the digital certificate.
2. Accept the digital certificate and the device storing the secret key from the directly managing agency or organization in accordance with regulations.
3. Timely notify the directly managing agency or organization to recover the digital certificate in accordance with Clause 1, Article 10 of this Circular.
4. Hand over the device storing the secret key for recovery to the directly managing agency or organization in accordance with Clause 2, Article 10 of this Circular.
5. Request the restoration of the device storing the secret key in cases where the device storing the secret key is locked in accordance with Article 11 of this Circular.
6. Use the digital certificate for its intended purpose and comply with procedures and regulations on the management and use of digital signatures, digital certificates, devices storing secret keys, and specialized government digital signature verification services.
7. Manage the device storing the secret key in accordance with the provisions of the law.
Chapter IV
IMPLEMENTING PROVISIONS
Article 18. Effective Date
This Circular takes effect from February 18, 2020. It replaces Circular No. 08/2016/TT-BQP dated February 1, 2016, issued by the Minister of National Defense, stipulating the provision, management, and use of specialized government digital signature verification services for Party agencies, State agencies, and political-social organizations.
Article 19. Responsibility for Implementation
1. The Director of the Government Cryptographic Bureau, heads of agencies, units, organizations, and individuals concerned shall be responsible for implementing this Circular.
2. In case of difficulties or obstacles during implementation, agencies, units, organizations, and individuals are requested to report to the Government Cryptographic Bureau for consolidation and reporting to the Minister of National Defense./.
원본 문서(PDF)
관계도
문서를 클릭하면 열립니다. 빨간 테두리=효력을 변경하는 관계.