This Decree stipulates on services for authenticating specialized electronic signatures for official duties, including contents such as the scope of application, operational range, management, and use of services. This Decree takes effect from August 15, 2024.
Đối tượng áp dụng
State agencies, organizations within the political system, and individuals related to the use of electronic signatures in electronic transactions.
Các điểm cốt lõi
- Definition of services for authenticating specialized electronic signatures for official duties
- Provisions on issuance, extension, change of information content, revocation of certificates, and recovery of devices storing secret keys
- Responsibilities of relevant parties in managing and using services
- Transition from old regulations to this new Decree
- Effective date
🌐 Tác động xã hội từ văn bản này
- Enhancing information security in electronic transactions between state agencies
- Continuing administrative reform on the electronic environment
- Ensuring the legal validity and effectiveness of electronic signatures in official activities
❓ Câu hỏi thường gặp
What does this Decree replace?
Replacing some provisions of Decree No. 45/2020/NĐ-CP and Decree No. 156/2016/NĐ-CP on services for authenticating specialized electronic signatures for the Government.
When does this Decree take effect?
This Decree takes effect from August 15, 2024.
Toàn văn
|
THE GOVERNMENT |
SOCIALIST REPUBLIC OF VIET NAM |
|
Number: 68/2024/NĐ-CP |
Hanoi, June 25, 2024 |
DECREE
REGULATIONS ON SPECIALIZED DIGITAL SIGNATURES FOR PUBLIC SERVICE
On the basis of Law on Government Organization dated June 19, 2015; Law Amending and Supplementing Certain Provisions of the Law on Government Organization and the Law on Local Administration dated November 22, 2019;
On the basis of The Cryptography Law dated November 26, 2011;
On the basis of The Electronic Transactions Law dated June 22, 2023;
"Based on the proposal of the Minister of National Defense;"
The Government issues this Decree to regulate specialized digital signatures for public service.
PART I
GENERAL PROVISIONS
Article 1. Scope of Regulation
This Decree details regulations on services for authenticating specialized digital signatures for public service; the provision, management, and use of specialized digital signatures for public service, digital signature certificates for public service, and services for authenticating specialized digital signatures for public service.
Article 2. Applicability
1. State agencies; political organizations; socio-political organizations; public service units.
2. Civil servants, public officials, employees, members of the people's armed forces, and personnel working in cryptographic agencies.
3. Other agencies, organizations, and individuals related to the activities of providing, managing, and using specialized digital signatures for public service, digital signature certificates for public service, and services for authenticating specialized digital signatures for public service.
Article 3. Explanation of Terms
In this Decree, the following terms are understood as follows:
1. Secret key is a key in an asymmetric cryptography system pair used to create digital signatures.
2. Public key is a key in an asymmetric cryptography system pair used to verify digital signatures created with the corresponding secret key in the pair.
3. Subscriber is an agency, organization, or individual who has been issued a digital signature certificate for public service, accepts such a certificate, and retains the corresponding secret key recorded on the digital signature certificate for public service issued.
4. Service provider for authenticating specialized digital signatures for public service is the National Digital Authentication and Information Security Agency under the Government Cryptographic Agency.
5. Secret key storage device is a dedicated physical device containing the subscriber's secret key.
6. Direct management agency or organization is an entity with legal personality and its own seal that directly manages subscribers using services for authenticating specialized digital signatures for public service.
7. Authentication request includes new issuance, renewal, modification of information content, revocation of digital signature certificates for public service, and recovery of secret key storage devices.
8. Registration and management system for authentication requests is an electronic system supporting registration and management of services for authenticating specialized digital signatures for public service over a network environment.
9. CSCA - Country Signing Certification Authority is a component of the specialized digital signature authentication system serving the issuance of digital certificates for passport and electronic ID card chip issuance.
10. DS - Document Signer is a component signing data chip in the personalization system of the passport and electronic ID card chip issuing authority.
11. IS - Inspection System is hardware and software systems serving the inspection of passports and electronic ID cards with embedded chips.
12. CVCA - Country Verifying Certification Authority is a component of the specialized digital signature authentication system serving the issuance of digital certificates for passport and electronic ID card chip inspection.
13. DVCA - Document Verifier Certification Authority is an intermediate component of CVCA to issue specialized digital signature certificates for public service to IS.
14. HSM - Hardware Security Module is a centralized secret key storage device for subscribers.
15. PKI Token is a device storing each subscriber's secret key and digital signature certificate.
16. SIM PKI is a mobile phone SIM card capable of storing a subscriber's secret key for signing data messages on mobile devices.
17. Centralized digital signature solution is a digital signature solution not using hardware devices (PKI Token, SIM PKI), where the secret keys of subscribers are centrally stored on the HSM of the service provider for authenticating specialized digital signatures for public service.
18. CRL - Certificate Revocation List is a list of revoked digital signature certificates for public service.
19. OCSP - Online Certificate Status Protocol is a service for checking the current status of digital signature certificates for public service.
Article 4. Sending and receiving authentication request documents and secret key storage devices
1. The sending and receiving of authentication request documents between direct management agencies and organizations providing specialized public service digital signature authentication services shall be conducted through electronic signed documents in accordance with laws on archiving work via the Registration and Management System for Authentication Requests or the National Document Interconnection Network.
2. The sending and receiving of secret key storage devices between subscribers, direct management agencies, and organizations providing specialized public service digital signature authentication services shall be carried out directly or through Confidential Organizations or postal service providers in accordance with the law.
Article 5. Sending and receiving authentication request documents and secret key storage devices within the Ministry of National Defense, the Ministry of Public Security, and the Ministry of Foreign Affairs
The sending and receiving of authentication request documents and secret key storage devices between direct management agencies within the Ministry of National Defense, the Ministry of Public Security, and the Ministry of Foreign Affairs and organizations providing specialized public service digital signature authentication services shall be conducted through Confidential Organizations subordinate to these ministries.
Chapter II
SPECIALIZED PUBLIC SERVICE DIGITAL SIGNATURE AUTHENTICATION SERVICES
SPECIALIZED GOVERNMENT USE
Article 6. Specialized public service digital signature authentication services
Specialized public service digital signature authentication services provided by organizations offering such services include:
1. Creating and distributing key pairs.
2. Issuing specialized public service digital signature certificates.
3. Renewing specialized public service digital signature certificates.
4. Modifying information contained in specialized public service digital signature certificates.
5. Revoking specialized public service digital signature certificates.
6. Restoring secret key storage devices.
7. Announcing and maintaining online databases of specialized public service digital signature certificates.
8. Online verification of specialized public service digital signature certificates.
9. Issuing timestamps.
Article 7. Content of specialized public service digital signature certificates
1. Name of the organization providing specialized public service digital signature authentication services.
2. Name of the subscriber.
3. Certificate number of the specialized public service digital signature.
4. Validity period of the specialized public service digital signature certificate.
5. Public key.
6. Digital signature of the organization providing specialized public service digital signature authentication services.
7. Restrictions on the purpose and scope of use of the specialized public service digital signature certificate.
Article 8. Creation and distribution of key pairs
1. Organizations providing specialized public service digital signature authentication services create key pairs (public keys and private keys) for subscribers.
2. Public keys are linked to specialized public service digital signature certificates and are published online on the website of the organization providing specialized public service digital signature authentication services.
3. Private keys corresponding to each specialized public service digital signature certificate of subscribers are stored on secret key storage devices and delivered to subscribers using secure methods. In cases where centralized signing solutions are used, private keys of subscribers are centrally stored on HSM devices of the organization providing specialized public service digital signature authentication services.
Article 9. Validity period of specialized electronic signature certificate for public service
1. The validity period of the specialized electronic signature certificate for public service provided by the organization offering specialized electronic signature certification services is twenty years.
2. The validity period of the specialized electronic signature certificate for public service for new subscribers is a maximum of five years.
3. The validity period of the specialized electronic signature certificate for public service for subscribers whose validity period has been extended may be extended for a maximum of three years.
4. For the specialized electronic signature certificate for public service used for issuing and checking electronic passports with embedded chips, the validity period of the certificate shall be as prescribed in Article 23 of this Decree. For the specialized electronic signature certificate for public service used for issuing and checking electronic identity cards with embedded chips, the validity period of the certificate shall be as prescribed in Article 26 of this Decree.
Article 10. Conditions for issuing new specialized electronic signature certificates for public service
1. Conditions for issuing new specialized electronic signature certificates for public service to individuals
a) Must be an individual of agencies and organizations specified in Article 2 of this Decree and have a need for electronic transactions;
b) Have a written request from the directly managing agency or organization.
2. Conditions for issuing new specialized electronic signature certificates for public service to agencies and organizations
a) Must be an agency or organization with legal personality as specified in Article 2 of this Decree;
b) Have a decision on establishment of the agency or organization or confirmation from the head of the directly superior agency or organization;
c) Have a written request from the directly managing agency or organization.
3. Conditions for issuing new specialized electronic signature certificates for public service to devices, services, software
a) Devices, services, software must belong to or be managed by agencies and organizations with legal personality as specified in Article 2 of this Decree;
b) Have a written request from the directly managing agency or organization.
Article 11. Documents, procedures, and formalities for issuing specialized electronic signature certificates for public service
1. Request for issuance of specialized electronic signature certificate for public service
a) Specialized electronic signature certificate for public service for individuals
The directly managing agency or organization shall submit a written request for issuance of the specialized electronic signature certificate for public service according to Model No. 01 attached to this Decree to the organization providing specialized electronic signature certification services.
b) Specialized electronic signature certificate for public service for agencies and organizations
The directly managing agency or organization shall submit a written request for issuance of a new specialized electronic signature certificate for public service according to Model No. 02 attached to this Decree to the organization providing specialized electronic signature certification services.
c) Specialized electronic signature certificate for public service for devices, services, software
The directly managing agency or organization shall submit a written request for issuance of a new specialized electronic signature certificate for public service according to Model No. 03 attached to this Decree to the organization providing specialized electronic signature certification services.
2. Within three working days from the date of receiving complete documents, the organization providing specialized electronic signature certification services shall be responsible for reviewing the documents, organizing the creation of key pairs, creating the specialized electronic signature certificate for public service, ensuring the storage device for secret keys for subscribers. Notify the time and place to receive the storage device for secret keys to the directly managing agency or organization; or send account information to the subscriber in case of implementing centralized digital signature solutions.
In case of not accepting the request for issuance of the specialized electronic signature certificate for public service, the organization providing specialized electronic signature certification services shall notify in writing the reasons to the directly managing agency or organization.
3. The directly managing agency or organization shall be responsible for receiving the storage device for secret keys from the organization providing specialized electronic signature certification services; immediately after transferring the storage device for secret keys to the subscriber, send a notification according to Model No. 07 attached to this Decree to the organization providing specialized electronic signature certification services for management purposes.
Article 12. Conditions for extending the validity period of specialized electronic signature certificates for official duties
1. A specialized electronic signature certificate for official duties can only be extended once and must still have at least 30 days remaining before its expiration date.
2. The directly managing agency or organization must submit a written request to extend the validity period of the specialized electronic signature certificate for official duties.
Article 13. Documents, procedures, and formalities for extending the validity period of specialized electronic signature certificates for official duties
1. The directly managing agency or organization must submit a written request to extend the validity period of the specialized electronic signature certificate for official duties according to Model No. 04 attached as an appendix to this Decree to the organization providing specialized electronic signature certification services for official duties.
2. Within three working days from the date of receipt of a valid extension request for the specialized electronic signature certificate, the organization providing specialized electronic signature certification services for official duties shall be responsible for extending the validity period of the specialized electronic signature certificate for the subscriber and notify the directly managing agency or organization.
In case the request to extend the validity period of the specialized electronic signature certificate for official duties is not accepted, the organization providing specialized electronic signature certification services for official duties shall notify in writing, specifying the reasons, to the directly managing agency or organization.
Article 14. Conditions for changing information content in specialized electronic signature certificates for official duties
1. A specialized electronic signature certificate for official duties requiring changes to information content must still have at least 30 days remaining before its expiration date. Changing the information content in a specialized electronic signature certificate for official duties does not alter its validity period.
2. The directly managing agency or organization must submit a written request to change the information content in the specialized electronic signature certificate for official duties.
Article 15. Cases for changing information content in specialized electronic signature certificates for official duties
1. For specialized electronic signature certificates for official duties of individuals
a) Change of the agency or organization of employment where the information is inconsistent with the information in the specialized electronic signature certificate for official duties;
b) Change of the official email address information.
2. For specialized electronic signature certificates for official duties of agencies or organizations
Change of name or place of operation of the agency or organization where the information is inconsistent with the information in the specialized electronic signature certificate for official duties.
3. For specialized electronic signature certificates for official duties of devices, services, or software
Change of name or upgrade of version or enhancement of features of the device, service, or software where the information is inconsistent with the information in the specialized electronic signature certificate for official duties.
Article 16. Documents, procedures, and formalities for changing information content in specialized electronic signature certificates for official duties
1. The directly managing agency or organization must submit a written request to change the information content in the specialized electronic signature certificate for official duties according to Model No. 04 attached as an appendix to this Decree to the organization providing specialized electronic signature certification services for official duties.
2. Within three working days from the date of receipt of a valid request to change the information content in the specialized electronic signature certificate for official duties, the organization providing specialized electronic signature certification services for official duties shall be responsible for changing the information content in the specialized electronic signature certificate for the subscriber and notify the directly managing agency or organization.
In case the request to change the information content in the specialized electronic signature certificate for official duties is not accepted, the organization providing specialized electronic signature certification services for official duties shall notify in writing, specifying the reasons, to the directly managing agency or organization.
Article 17. Cases for Revoking Digital Signature Certificates for Official Use
1. For all types of digital signature certificates for official use
a) The digital signature certificate for official use has expired;
b) At the request in writing of the subscriber and confirmed by the directly managing agency or organization in cases where the secret key is disclosed or suspected to be disclosed; the device storing the secret key is damaged, lost, or other security breaches occur;
c) At the request in writing from agencies conducting litigation proceedings, public security agencies;
d) At the request in writing from the directly managing agency or organization.
2. For digital signature certificates for official use of individuals
a) The cases stipulated in Clause 1 of this Article;
b) An individual changes their job position and the information about the new job position does not match the information in the digital signature certificate for official use;
c) An individual retires, resigns, or passes away.
3. For digital signature certificates for official use of agencies and organizations
a) The cases stipulated in Clause 1 of this Article;
b) The agency or organization is dissolved, split, or merged.
4. For digital signature certificates for official use of devices, services, software
a) The cases stipulated in Clause 1 of this Article;
b) The device, service, or software ceases operation.
Article 18. Competence to Propose the Revocation of Digital Signature Certificates for Official Use
1. The service provider of digital signature certification for official use automatically revokes the digital signature certificate for official use when it expires.
2. In all cases of revoking digital signature certificates for official use that do not fall under the case of expiration of the digital signature certificate, the directly managing agency or organization must promptly submit a written proposal to revoke the digital signature certificate for official use to the service provider of digital signature certification for official use.
3. In the case where the subscriber is an individual who retires, resigns, transfers to another agency, or passes away; the directly managing agency or organization of the subscriber has the authority to propose the revocation of the digital signature certificate for official use to the service provider of digital signature certification for official use.
4. In the case where the subscriber is an organization that is dissolved, split, or merged; the directly managing agency or organization of that organization has the authority to propose the revocation of the digital signature certificate for official use to the service provider of digital signature certification for official use.
5. Agencies conducting litigation proceedings, public security agencies.
6. Proposals to revoke digital signature certificates for official use submitted to the service provider of digital signature certification for official use must be done as quickly as possible in writing.
Article 19. Documentation, Procedure, and Formalities for Revoking Digital Signature Certificates for Official Use
1. Documentation for revoking digital signature certificates for official use includes one of the following documents
a) A document proposing the revocation of the digital signature certificate for official use from the directly managing agency or organization;
b) A document proposing the revocation of the digital signature certificate for official use from agencies conducting litigation proceedings, public security agencies.
2. Procedure and formalities for revoking digital signature certificates for official use
a) The directly managing agency or organization must submit a document proposing the revocation of the digital signature certificate for official use according to Model No. 05 attached to this Decree to the service provider of digital signature certification for official use;
b) Within one working day from the date of receiving the proposal to revoke the digital signature certificate for official use, the service provider of digital signature certification for official use must render the digital signature certificate for official use invalid and announce the revocation of the digital signature certificate for official use on its electronic information website; at the same time, notify the directly managing agency or organization in writing.
Article 20. Recovery of secret key storage devices after the expiration of the validity period of specialized public service digital certificate or the recovery of the specialized public service digital certificate.
1. The secret key storage device managed by the subscriber shall be recovered when the specialized public service digital certificate expires or the specialized public service digital certificate is recovered.
2. The subscriber shall have the responsibility to hand over the secret key storage device to the directly managing agency or organization when the specialized public service digital certificate expires or the specialized public service digital certificate is recovered.
3. Within five working days from the date of receipt of the notice to recover the specialized public service digital certificate, the directly managing agency or organization shall have the responsibility to recover the secret key storage device of the subscriber and transfer it to the organization providing specialized public service digital signature certification services. The record of delivery and receipt of the secret key storage device after the expiration of the validity period of the specialized public service digital certificate or the recovery of the specialized public service digital certificate shall be made according to Model No. 08 attached to this Decree.
4. In case the secret key storage device is lost, the directly managing agency or organization must establish a confirmation record according to Model No. 09 attached to this Decree and immediately send it to the organization providing specialized public service digital signature certification services.
Article 21. Issuance of a new specialized public service digital certificate after the expiration of the old certificate or the recovery of the old certificate.
1. If the subscriber has the need for issuance of a new specialized public service digital certificate after the old certificate expires or the old certificate is recovered and meets the conditions stipulated in Article 10 of this Decree, they will be considered for issuance of a new specialized public service digital certificate.
2. The procedures and formalities are the same as those for the first issuance of a specialized public service digital certificate.
Article 22. Restoration of secret key storage devices managed by subscribers.
1. In the event of restoring a secret key storage device.
The secret key storage device will be locked if the wrong password is entered more than the number of times set by the organization providing specialized public service digital signature certification services. To restore the operation of the secret key storage device, the restoration procedure of the secret key storage device must be carried out.
2. Documents for restoring a secret key storage device.
A request from the directly managing agency or organization to restore the secret key storage device for the subscriber.
3. Procedures and formalities for restoring a secret key storage device.
a) The directly managing agency or organization shall submit a request to restore the secret key storage device according to Model No. 06 attached to this Decree to the organization providing specialized public service digital signature certification services;
b) Within one working day from the date of receipt of a valid request to restore the secret key storage device, the organization providing specialized public service digital signature certification services shall carry out the restoration of the secret key storage device and simultaneously notify the directly managing agency or organization.
In case the request to restore the secret key storage device is not accepted, the organization providing specialized public service digital signature certification services shall notify in writing with detailed reasons to the directly managing agency or organization.
Chapter III
PROVISION OF SERVICES FOR THE CERTIFICATION OF SPECIALIZED PUBLIC SERVICE DIGITAL SIGNATURES
TO SUPPORT THE ISSUE AND VERIFICATION OF PASSPORTS
AND ELECTRONIC IDENTITY CARDS WITH CHIP
Section 1.
PROVISION OF SERVICES FOR THE CERTIFICATION OF SPECIALIZED PUBLIC SERVICE DIGITAL SIGNATURES
TO SUPPORT THE ISSUE AND VERIFICATION OF PASSPORTS WITH CHIP
ELECTRONIC CHIP EMBODIED PASSPORT
Article 23. Duration of Effectiveness of Specialized Digital Signature Certificates for Official Duties Used for Issuing and Checking Electronic Chip Passports
Clause 1. Duration of effectiveness of specialized digital signature certificates for official duties used for issuing electronic chip passports
Point a) The duration of effectiveness of the specialized digital signature certificate for official duties of CSCA is a maximum of 15 years, the corresponding secret key has a maximum validity period of 05 years;
Point b) The duration of effectiveness of the specialized digital signature certificate for official duties of DS is a maximum of 10 years, the corresponding secret key has a maximum validity period of 03 months or issues up to 100,000 electronic chip passports.
Clause 2. Duration of effectiveness of specialized digital signature certificates for official duties used for checking electronic chip passports
Point a) The duration of effectiveness of the specialized digital signature certificate for official duties of CVCA is a maximum of 03 years, the corresponding secret key has a maximum validity period of 03 years;
Point b) The duration of effectiveness of the specialized digital signature certificate for official duties of DVCA is a maximum of 03 months, the corresponding secret key has a maximum validity period of 03 months;
Point c) The duration of effectiveness of the specialized digital signature certificate for official duties of IS is a maximum of 01 month, the corresponding secret key has a maximum validity period of 01 month.
Article 24. Registration, Sending, Receiving Authentication Requests
Clause 1. Registration of specialized digital signature authentication services for official duties
The agency responsible for registering specialized digital signature authentication services for official duties used for issuing and checking electronic chip passports is an organization under the Ministry of National Defense, Ministry of Public Security, and Ministry of Foreign Affairs (hereinafter referred to collectively as the Competent Agency), which performs the task of managing and controlling entry, exit, transit, and residence in accordance with the provisions of the law.
Clause 2. Sending, Receiving Authentication Requests
The sending and receiving of authentication requests between the Competent Agency; organizations under the Ministry of National Defense, Ministry of Public Security, and Ministry of Foreign Affairs and the service provider of specialized digital signature authentication services for official duties shall be carried out through the System for Managing the Lifecycle of Specialized Digital Signature Certificates for Official Duties used for passport issuance and management.
Article 25. Procedures and Formalities for Issuing and Revoking Specialized Digital Signature Certificates for Official Duties Used for Issuing and Checking Electronic Chip Passports
Clause 1. Issuance of Specialized Digital Signature Certificates for Official Duties Used for Digitally Signing Passport Issuance
Point a) The Competent Agency implements key generation, creates authentication request DS, uses the specialized digital signature certificate for official duties of the signing organization to sign the authentication request DS and sends it to the subordinate organization under the main ministry;
Point b) Upon receipt of a valid authentication request DS, the subordinate organization under the main ministry is responsible for using the specialized digital signature certificate for official duties of the signing organization to sign the authentication request and send it to the service provider of specialized digital signature authentication services for official duties;
Point c) Upon receipt of a valid authentication request, the service provider of specialized digital signature authentication services for official duties is responsible for creating the specialized digital signature certificate for official duties DS and sending the result back to the Competent Agency; at the same time, notifying the subordinate organization under the main ministry.
Clause 2. Issuance of Specialized Digital Signature Certificates for Official Duties Used for Checking Electronic Chip Passports
Point a) Issuance of Vietnam's DVCA Specialized Digital Signature Certificate for Official Duties to Foreign Countries
The Competent Agency receives requests for issuance of Vietnam's DVCA specialized digital signature certificate from foreign countries, uses the specialized digital signature certificate for official duties of the signing organization to sign the authentication request and sends it to the subordinate organization under the main ministry;
Upon receipt of a valid authentication request, the subordinate organization under the main ministry is responsible for using the specialized digital signature certificate for official duties of the signing organization to sign the authentication request and send it to the service provider of specialized digital signature authentication services for official duties;
Upon receipt of a valid request for issuance of the specialized digital signature certificate for official duties, the service provider of specialized digital signature authentication services for official duties is responsible for creating the specialized digital signature certificate for official duties DVCA and sending the result back to the Competent Agency; at the same time, notifying the subordinate organization under the main ministry.
Point b) Acceptance of Foreign DVCA Specialized Digital Signature Certificates
The service provider of specialized digital signature authentication services for official duties generates keys, creates authentication requests for foreign DVCA and sends them to the subordinate organization under the main ministry;
Upon receipt of an authentication request, the subordinate organization under the main ministry is responsible for using the specialized digital signature certificate for official duties of the signing organization to sign the authentication request and send it to the Competent Agency;
The Competent Agency sends the authentication request to foreign countries, simultaneously receives the authentication results from foreign countries and sends them to the subordinate organization under the main ministry;
Upon receipt of the authentication results, the subordinate organization under the main ministry is responsible for sending the service provider of specialized digital signature authentication services for official duties to create DVCA for foreign countries.
Clause 3. Issuance of Specialized Digital Signature Certificates for Official Duties for IS
Point a) The Competent Agency generates keys, creates authentication requests for IS, uses the digital signature certificate of the signing organization to sign the authentication request and sends it to the subordinate organization under the main ministry;
Point b) Upon receipt of a valid authentication request, the subordinate organization under the main ministry is responsible for using the digital signature certificate of the signing organization to sign the authentication request and send it to the service provider of specialized digital signature authentication services for official duties;
Point c) Upon receipt of a valid request for issuance of the digital signature certificate, the service provider of specialized digital signature authentication services for official duties is responsible for creating the digital signature certificate for IS and sending the result back to the Competent Agency; at the same time, notifying the subordinate organization under the main ministry.
Clause 4. Procedures and Formalities for Revoking Specialized Digital Signature Certificates for Official Duties Used for Issuing and Checking Electronic Chip Passports are implemented according to the provisions of Article 19 of this Decree.
Section 2.
PROVISION OF SERVICES FOR THE CERTIFICATION OF SPECIALIZED PUBLIC SERVICE DIGITAL SIGNATURES
TO SUPPORT THE ISSUE AND VERIFICATION OF PASSPORTS WITH CHIP
ELECTRONIC CHIP IDENTITY CARDS
Article 26. Validity period of dedicated digital signature certificates for official use serving the issuance and verification of electronic identity cards with chips
1. Validity period of dedicated digital signature certificates for official use serving the issuance of electronic identity cards with chips
a) The validity period of the dedicated digital signature certificate for official use of CSCA is a maximum of twenty-seven years, and the corresponding secret key has a maximum validity period of five years;
b) The validity period of the dedicated digital signature certificate for official use of DS is a maximum of twenty-two years, and the corresponding secret key has a maximum validity period of three months or issues up to one hundred thousand electronic identity cards with chips.
2. Validity period of dedicated digital signature certificates for official use serving the verification of electronic identity cards with chips
Point a) The duration of effectiveness of the specialized digital signature certificate for official duties of CVCA is a maximum of 03 years, the corresponding secret key has a maximum validity period of 03 years;
Point b) The duration of effectiveness of the specialized digital signature certificate for official duties of DVCA is a maximum of 03 months, the corresponding secret key has a maximum validity period of 03 months;
Point c) The duration of effectiveness of the specialized digital signature certificate for official duties of IS is a maximum of 01 month, the corresponding secret key has a maximum validity period of 01 month.
Article 27. Sending and receiving authentication requests
The sending and receiving of authentication requests between the Identity Management Agency under the Ministry of Public Security, and subordinate Cryptographic Organizations under the Ministry of Public Security with organizations providing dedicated digital signature certification services for official use shall be conducted through the dedicated digital signature certificate lifecycle management system for official use serving the issuance and management of electronic identity cards with chips.
Article 28. Procedures and formalities for issuing and revoking dedicated digital signature certificates for official use serving the issuance and verification of electronic identity cards with chips
1. Issuing dedicated digital signature certificates for official use serving the signing of electronic identity cards with chips
a) The Identity Management Agency under the Ministry of Public Security shall generate keys, create authentication requests for DS, sign the authentication request for DS using the dedicated digital signature certificate for official use of the organization, and send it to the subordinate Cryptographic Organization under the Ministry of Public Security;
b) Upon receiving a valid authentication request for DS, the subordinate Cryptographic Organization under the Ministry of Public Security shall sign the authentication request using the dedicated digital signature certificate for official use of the organization and send it to the organization providing dedicated digital signature certification services for official use;
c) Upon receiving a valid authentication request, the organization providing dedicated digital signature certification services for official use shall issue a dedicated digital signature certificate for official use for DS and send the result back to the Identity Management Agency under the Ministry of Public Security; simultaneously, notify the subordinate Cryptographic Organization under the Ministry of Public Security.
2. Issuing dedicated digital signature certificates for official use serving the verification of electronic identity cards with chips
a) The Identity Management Agency under the Ministry of Public Security shall generate keys, create authentication requests for IS, sign the authentication request using the dedicated digital signature certificate for official use of the organization, and send it to the subordinate Cryptographic Organization under the Ministry of Public Security;
b) Upon receiving a valid authentication request, the subordinate Cryptographic Organization under the Ministry of Public Security shall sign the authentication request using the dedicated digital signature certificate for official use of the organization and send it to the organization providing dedicated digital signature certification services for official use;
c) Upon receiving a valid request for issuance of a dedicated digital signature certificate, the organization providing dedicated digital signature certification services for official use shall issue a dedicated digital signature certificate for IS and send the result back to the Identity Management Agency under the Ministry of Public Security; simultaneously, notify the subordinate Cryptographic Organization under the Ministry of Public Security.
3. Procedures and formalities for revoking dedicated digital signature certificates for official use serving the issuance and verification of electronic identity cards shall be carried out in accordance with the provisions of Article 19 of this Decree.
Chapter IV
USE OF DEDICATED DIGITAL SIGNATURES FOR OFFICIAL USE,
DEDICATED DIGITAL SIGNATURE CERTIFICATES FOR OFFICIAL USE AND SERVICES
AUTHENTICATION OF DEDICATED DIGITAL SIGNATURES FOR OFFICIAL USE
Article 29. Procedure for creating specialized electronic signature for official duties
1. Verify the validity of the specialized electronic signature certificate for official duties in accordance with the provisions of Article 31 of this Decree.
2. Verify the legitimacy of the verification path in accordance with the provisions of Article 32 of this Decree.
3. Use the corresponding private key of the specialized electronic signature certificate for official duties of the subject performing the signing to create the specialized electronic signature for official duties.
4. In cases where laws stipulate that electronic messages must have time stamps, such electronic messages shall be deemed to comply if they are attached with a time stamp corresponding to the specialized electronic signature for official duties created; the server address for the time stamp is published by the organization providing specialized electronic signature certification services.
5. Display information about the specialized electronic signature for official duties in accordance with relevant laws.
Article 30. Procedure for verifying specialized electronic signatures for official duties
A specialized electronic signature for official duties is valid when it meets the following conditions:
1. Ensuring the integrity of signed data by verifying the specialized electronic signature for official duties corresponding to the public key of the specialized electronic signature certificate for official duties.
2. The information of the subject performing the signing is consistent with the specialized electronic signature certificate for official duties.
3. The signing time must be consistent with the content of the signed data and the verification process complies with this Decree.
4. Ensuring the validity of the specialized electronic signature certificate for official duties of the signing subject in accordance with the provisions of Article 31 of this Decree.
5. Ensuring the legitimacy of the verification path in accordance with the provisions of Article 32 of this Decree.
Article 31. Verification of the validity of the specialized electronic signature certificate for official duties
1. The specialized electronic signature certificate for official duties is valid when it meets the following conditions:
a) It has an effective period at the time of signing;
b) It is consistent with the scope of use of the specialized electronic signature certificate for official duties, the legal responsibility of the signing subject, and meets the verification conditions stipulated in this Decree;
c) The status of the specialized electronic signature certificate for official duties is checked according to the provisions of Clause 2 of this Article and remains active at the time of signing.
2. Check the status of the specialized electronic signature certificate for official duties through the list of revoked specialized electronic signature certificates for official duties (CRL) or through the online status of the specialized electronic signature certificate for official duties (OCSP) published by the organization providing specialized electronic signature certification services at the time of signing.
Article 32. Verification of the legitimacy of the verification path
1. Verify the validity of the specialized electronic signature certificate for official duties in the verification path in accordance with the provisions of Article 31 of this Decree, ensuring that the following specialized electronic signature certificates for official duties are valid at the time of signing:
a) The specialized electronic signature certificate for official duties of the subject performing the signing;
b) Intermediate specialized electronic signature certificate for official duties (if any);
c) Root specialized electronic signature certificate for official duties.
2. The root specialized electronic signature certificate for official duties in the verification path must be consistent with the root specialized electronic signature certificate for official duties published by the organization providing specialized electronic signature certification services.
Article 33. Technical requirements and functions for dedicated electronic signature software for public service and verification of dedicated electronic signatures for public service
Dedicated electronic signature software for public service and verification of dedicated electronic signatures for public service is an independent software program or a component (Module) of software with the function of creating electronic signatures and verifying the validity of dedicated electronic signatures for public service, meeting the following conditions:
1. Complying with national technical standards and regulations on electronic signatures as stipulated by law.
2. The electronic signature software has the function of generating dedicated electronic signatures for public service, complying with the procedures specified in Article 29 of this Decree.
3. The software for verifying dedicated electronic signatures for public service has the function of verifying dedicated electronic signatures for public service, complying with the procedures specified in Article 30 of this Decree.
4. It has the function of notifying (in writing or by symbol) the subject of electronic signature creation and verification about the success or failure of the electronic signature process.
Chapter V
RESPONSIBILITIES OF AUTHORITIES, ORGANIZATIONS AND INDIVIDUALS
Article 34. Responsibilities for implementing, managing, and using dedicated electronic signature certification services for public service
1. Heads of agencies and organizations: Central Party Office and its affiliated advisory and assisting bodies under the Central Committee of the Communist Party of Vietnam; National Ethnic Council and Committees of the National Assembly; National Assembly Office; President's Office; Ministries, bodies at ministerial level, and bodies under the Government; Supreme People's Procuracy; Supreme People's Court; State Audit Agency; central bodies of mass organizations; provincial party committees directly under the Central Committee; Provincial People's Councils, People's Committees of centrally governed cities, and other organizations as prescribed by competent authorities shall be responsible for:
a) Establishing and promulgating regulations and rules on the management and use of dedicated electronic signatures for public service, dedicated electronic signature certificates, key storage devices, and dedicated electronic signature certification services within their jurisdiction;
b) Annually reporting on the situation of work related to the management, implementation, and use of dedicated electronic signatures for public service, dedicated electronic signature certificates, key storage devices, and dedicated electronic signature certification services; simultaneously developing plans and needs for the next year for subscribers under their management according to the guidelines of the Government Cryptographic Department;
c) Managing, guiding, and inspecting subscribers during the implementation, management, and use of dedicated electronic signatures for public service, dedicated electronic signature certificates, key storage devices, and dedicated electronic signature certification services within their jurisdiction;
d) Organizing training and instruction on the implementation and use of dedicated electronic signatures for public service, dedicated electronic signature certificates, key storage devices, and dedicated electronic signature certification services for subscribers within their jurisdiction;
đ) Taking the lead in organizing support from the organization providing dedicated electronic signature certification services for the registration, management, and use of dedicated electronic signatures for public service, dedicated electronic signature certificates, key storage devices, and dedicated electronic signature certification services for subscribers within their jurisdiction; organizing the renewal and modification of information in dedicated electronic signature certificates, and restoring key storage devices for subscribers within their jurisdiction when needed.
2. Persons specified in Clause 1 of this Article may delegate authority to subordinate functional agencies to implement the contents specified in Points a, b, c, d, đ of Clause 1 of this Article.
Article 35. Responsibilities of the Minister of National Defense
The Minister of National Defense shall be responsible for directing the Government Cryptographic Agency to implement state management over specialized digital signatures for official duties, specifically:
1. Developing and proposing policies, organizing the implementation of strategies, plans, and policies for the development of specialized digital signature certification services for official duties.
2. Leading the drafting and submitting to competent authorities for promulgation of normative legal documents on specialized digital signatures for official duties; technical standards, technical requirements, economic and technical norms, product and service quality in activities related to providing, managing, and using specialized digital signatures for official duties, specialized digital signature certificates for official duties, and specialized digital signature certification services according to the law.
3. Managing reporting and statistical work on the situation of providing, managing, and using specialized digital signature certification services for official duties; managing security monitoring of information systems serving the provision of specialized digital signature certification services for official duties; summarizing, concluding, and evaluating results.
4. Managing time-stamping services for specialized digital signatures for official duties.
5. Managing and organizing the construction, exploitation, and development of infrastructure for specialized digital signature certification; issuing and recalling specialized digital signature certificates.
6. Promoting and disseminating policies and laws on specialized digital signatures for official duties.
7. Managing training, capacity building, and human resource development in the field of specialized digital signatures for official duties.
8. Inspecting, supervising, handling complaints, accusations, and dealing with violations concerning specialized digital signatures for official duties according to the law.
9. International cooperation on specialized digital signatures for official duties.
Article 36. Responsibilities of Organizations Providing Specialized Digital Signature Certification Services for Official Duties
1. Advising the Government Cryptographic Agency to assist the Minister of National Defense in implementing state management over specialized digital signatures for official duties according to the law; ensuring the provision of specialized digital signature certificates for official duties, secret key storage devices, and specialized digital signature certification services for official duties to ensure safety and effectiveness based on plans and needs of relevant agencies and organizations.
2. Advising and assisting the Government Cryptographic Agency in guiding procedures and practices regarding the provision, management, and use of specialized digital signature certification services for official duties. Cooperating with relevant agencies and organizations to establish regulations and rules on the management and use of specialized digital signatures for official duties, specialized digital signature certificates for official duties, secret key storage devices, and specialized digital signature certification services for official duties.
3. Ensuring absolute security of secret keys and handling situations during the provision, management, and use of specialized digital signatures for official duties, specialized digital signature certificates for official duties, and specialized digital signature certification services for official duties.
4. Managing and operating technical infrastructure of the system providing specialized digital signature certification services for official duties, information systems ensuring safe and continuous provision of specialized digital signature certification services for official duties.
5. Updating and accurately storing information on certification requests according to the law.
6. Ensuring communication channels for receiving certification requests; updating and maintaining 24 hours a day, 7 days a week online databases on policies for specialized digital signature certificates for official duties, regulations on the provision, management, and use of specialized digital signature certification services for official duties, specialized digital signature certificates for official duties provided by organizations providing specialized digital signature certification services for official duties, lists of valid specialized digital signature certificates for official duties, revoked specialized digital signature certificates for official duties, and other necessary information.
7. Guiding and inspecting relevant organizations and individuals on registration, provision, management, and use of specialized digital signatures for official duties, specialized digital signature certificates for official duties, and specialized digital signature certification services for official duties.
8. Organizing training and instruction on deployment and use of specialized digital signatures for official duties, specialized digital signature certificates for official duties, secret key storage devices, and specialized digital signature certification services for official duties for authorized agencies and organizations under Clause 2, Article 34 of this Decree and other related entities.
9. Guiding and transferring support tools for renewing and changing information in specialized digital signature certificates for official duties, restoring secret key storage devices for authorized agencies and organizations under Clause 2, Article 34 of this Decree.
10. Cooperating and supporting relevant agencies and organizations to integrate specialized digital signature certification services for official duties into information technology applications to ensure authentication and information security.
11. Cooperating with national electronic certification service providers to build and deploy models and solutions for interconnection between organizations providing specialized digital signature certification services for official duties and national electronic certification service providers to ensure compliance with legal provisions for checking the validity of specialized digital signatures for official duties.
12. Researching, applying, and deploying appropriate authentication and electronic signature technologies suitable for information technology applications serving agencies and organizations specified in Article 2 of this Decree.
Article 37. Responsibilities of Direct Management Agencies and Organizations
1. Based on requirements to ensure security and verify information in electronic transactions serving their own tasks, they shall examine and confirm documents and be responsible for the accuracy of the information proposed for issuance, extension, change of content, revocation of specialized public service digital certificates, and recovery of key storage devices for agencies, organizations, and individuals under their management.
2. They shall accept and transfer specialized public service digital certificates and key storage devices to subscribers and be responsible for managing and using key storage devices and specialized public service digital certificate verification services effectively within their management scope.
3. They shall recover key storage devices from agencies, organizations, and individuals under their management and hand them over to the Service Provider for specialized public service digital certificate verification services.
4. They shall update, manage, and store records for requests for issuance, extension, change of content, revocation of specialized public service digital certificates, and recovery of key storage devices of subscribers within their management scope.
5. They shall guide, inspect, and evaluate the implementation and use of specialized public service digital signatures, specialized public service digital certificates, key storage devices, and specialized public service digital signature verification services within their management scope.
6. They shall periodically and urgently report on the provision, management, and use of specialized public service digital signature verification services according to the requirements of competent authorities.
Article 38. Responsibilities of Subordinate Cryptographic Organizations under the Ministry of National Defense, Ministry of Public Security, and Ministry of Foreign Affairs
1. Annually, they shall assist the heads of their respective ministries in drafting plans and needs for applying specialized public service digital signature verification services for subscribers under their management to ensure security and verify information in electronic transactions.
2. They shall draft and submit to competent authorities for promulgation regulations and guidelines on the management and use of specialized public service digital signatures, specialized public service digital certificates, and specialized public service digital signature verification services within their management scope.
3. They shall be responsible for the accuracy of the information proposed for issuance, extension, change of content, revocation of specialized public service digital certificates, and recovery of key storage devices.
4. They shall accept specialized public service digital certificates and key storage devices transferred from the Service Provider for specialized public service digital signature verification services to direct management agencies and organizations.
5. They shall accept key storage devices recovered from direct management agencies and organizations and hand them over to the Service Provider for specialized public service digital signature verification services.
6. They shall update, manage, and store records for requests for issuance, extension, change of content, revocation of specialized public service digital certificates, and recovery of key storage devices of subscribers within their management scope.
7. They shall take the lead and coordinate with the Service Provider for specialized public service digital signature verification services to organize training sessions for the deployment and use of specialized public service digital signatures, specialized public service digital certificates, key storage devices, and specialized public service digital signature verification services for subscribers within their management scope.
8. They shall guide and inspect subscribers during the deployment, management, and use of specialized public service digital signatures, specialized public service digital certificates, key storage devices, and specialized public service digital signature verification services.
9. They shall establish, manage, and operate technical systems and ensure connectivity with the Service Provider for specialized public service digital signature verification services to support the provision of services such as checking the status of specialized public service digital certificates (OCSP, CRL), issuing time stamps (TSA), and other authorized services in dedicated data transmission networks of their respective ministries.
10. They shall cooperate with the Service Provider for specialized public service digital signature verification services to integrate these services into information technology applications to ensure authentication and information security.
11. They shall compile and manage the issuance, extension, change of content, revocation of specialized public service digital certificates, and recovery of key storage devices of agencies, organizations, and individuals within the management scope of their respective ministries and report annually before October 31 or urgently through the Service Provider for specialized public service digital signature verification services to the Government Cryptographic Office.
Article 39. Obligations of the Subscriber
1. Provide accurate and complete information related to the issuance, extension, change of content, revocation of specialized electronic signature certificates for public service, and recovery of key storage devices.
2. Accept specialized electronic signature certificates for public service and key storage devices from directly managing agencies or organizations in accordance with regulations.
3. Promptly notify directly managing agencies or organizations to revoke specialized electronic signature certificates for public service in accordance with Article 17 of this Decree.
4. Hand over recovered key storage devices to directly managing agencies or organizations in accordance with Clause 2 of Article 20 of this Decree.
5. Request the recovery of key storage devices when such devices are locked in accordance with Article 22 of this Decree.
6. Manage key storage devices in accordance with the provisions of the law.
7. Use specialized electronic signature certificates for public service for their intended purposes and comply with procedures and regulations on the management and use of specialized electronic signatures for public service, specialized electronic signature certificates for public service, key storage devices, and specialized electronic signature certification services.
Chapter VI
IMPLEMENTING PROVISIONS
Article 40. Amendment and Replacement of Certain Provisions of Relevant Decrees
1. Replace the phrase "specialized government electronic signature certification service" with the phrase "specialized public service electronic signature certification service" in Clause 1 and Clause 2 of Article 30 of Decree No. 45/2020/NĐ-CP dated April 8, 2020, of the Government on the implementation of administrative procedures in the electronic environment.
2. Replace the phrase "electronic certificate provided by an organization providing specialized electronic signature certification services for political system agencies" with the phrase "specialized public service electronic signature certificate provided by an organization providing specialized public service electronic signature certification services" in Clause 1 of Article 14 of Decree No. 156/2016/NĐ-CP dated November 21, 2016, of the Government amending and supplementing certain provisions of Decree No. 27/2007/NĐ-CP dated February 23, 2007, of the Government on electronic transactions in financial activities.
Article 41. Effective Date
This Decree takes effect from August 15, 2024.
Article 42. Transitional Provisions
1. Electronic certificates issued until the date this Decree takes effect shall remain valid and continue to be implemented in accordance with relevant regulations and have equivalent value to specialized electronic signature certificates under this Decree.
2. Applications and responsibilities for managing and storing applications for new issuance, extension, change of content, revocation of electronic certificates, and recovery of key storage devices completed before the date this Decree takes effect shall continue to be implemented in accordance with relevant regulations and have equivalent value to the provisions set out in this Decree.
3. Agencies and organizations authorized to recover key storage devices until the date this Decree takes effect shall continue to perform such duties until there is a written change by the competent authority.
Article 43. Responsibility for Implementation
The Minister, Heads of Ministries, Heads of Government Agencies, Chairpersons of People's Committees of provinces and centrally governed cities, and related organizations and individuals are responsible for implementing this Decree./.
|
Place of Receipt: |
PRIME MINISTER |
Văn bản gốc (PDF)
Tải văn bản
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.
Bản dịch
Văn bản này có sẵn ở các ngôn ngữ sau: