These regulations specify the technical characteristics of specialized electronic signatures for official use to serve the management of long-term digital archival materials. They include requirements regarding structure, standards, and validity period for electronic signature certification services, as well as the responsibilities of agencies, organizations, and individuals when using such services.
Đối tượng áp dụng
Party and State agencies and related organizations shall use specialized electronic signature certification services for the verification of long-term digital archival materials.
Các điểm cốt lõi
- Provisions concerning the structure of electronic signatures (CAdES, XAdES, PAdES) and technical standards for them.
- Requirement to use secure encryption algorithms such as RSA with a minimum key length of 256 bits and SHA-256 or higher.
- Set the validity period until 2027 for current encryption algorithms.
- Responsibilities of state administrative agencies in guiding, organizing implementation, and inspecting compliance with these regulations.
- Requirements to comply with conformity assessment and declaration of conformity regulations when using specialized electronic signature certification services.
🌐 Tác động xã hội từ văn bản này
- Enhance security and efficiency in managing long-term digital archival materials.
- Minimize information security risks and ensure compliance with laws when using specialized electronic signatures in managing long-term digital archival materials.
❓ Câu hỏi thường gặp
Does this regulation apply to non-state organizations?
Although primarily guiding Party and State agencies, these regulations can also be referred to for ensuring information security when using specialized electronic signatures in managing long-term digital archival materials.
Which encryption algorithms are recommended for use?
Encryption algorithms such as RSA with a minimum key length of 256 bits and SHA-256 or higher are recommended for use to ensure information security.
What is the validity period for current encryption algorithms?
Current encryption algorithms have a validity period until 2027 according to these regulations.
Toàn văn
CIRCULAR
ISSUING "NATIONAL TECHNICAL REGULATION ON AUTHENTICATION OF LONG-TERM DIGITAL DOCUMENT ARCHIVES OF PARTY AND STATE AGENCIES"
Pursuant to the Law on Standards and Technical Regulations dated June 29, 2006;
Pursuant to the Law on Electronic Transactions dated June 22, 2023;
Pursuant to the Law on Archives dated June 21, 2024;
Pursuant to Decree No. 127/2007/NĐ-CP dated August 1, 2007 of the Government detailing implementation of certain provisions of the Law on Standards and Technical Regulations; Decree No. 78/2018/NĐ-CP dated May 16, 2018 of the Government amending and supplementing certain articles of Decree No. 127/2007/NĐ-CP dated August 1, 2007 of the Government detailing implementation of certain provisions of the Law on Standards and Technical Regulations;
Pursuant to Decree No. 09/2014/NĐ-CP dated January 27, 2014 of the Government stipulating functions, tasks, powers, and organizational structure of the General Office for Official Communications under the Government;
Pursuant to Decree No. 01/2022/NĐ-CP dated November 30, 2022 of the Government stipulating functions, tasks, powers, and organizational structure of the Ministry of National Defense; Decree No. 03/2025/NĐ-CP dated February 28, 2025 of the Government amending and supplementing certain articles of Decree No. 01/2022/NĐ-CP dated November 30, 2022 of the Government stipulating functions, tasks, powers, and organizational structure of the Ministry of National Defense;
Pursuant to Decree No. 68/2024/NĐ-CP dated June 25, 2024 of the Government stipulating electronic signatures for official use;
At the proposal of the Director of the General Office for Official Communications under the Government;
The Minister of National Defense issues this Circular to provide regulations on the national technical standard for authentication of long-term digital document archives of party and state agencies.
Article 1. Attached to this Circular is the national technical standard for authentication of long-term digital document archives of party and state agencies.
Designation: QCVN 16:2025/BQP.
Article 2. This Circular takes effect from September 2, 2025.
Article 3. The Director of the General Office for Official Communications under the Government, heads of agencies, units, organizations, and individuals concerned shall be responsible for implementing this Circular.
MINISTER
(signed)
General Phan Van Giang
QCVN 16:2025/BQP
NATIONAL TECHNICAL REGULATION ON AUTHENTICATION OF LONG-TERM DIGITAL DOCUMENT ARCHIVES OF PARTY AND STATE AGENCIES
National technical regulation on authentication long-term in digital document archives of party and state agencies
TABLE OF CONTENTS
1 GENERAL PROVISIONS
1.1 Scope of Application
1.2 Applicability
1.3 References
1.4 Definitions
1.5 Abbreviations
1.6 Symbols
2 TECHNICAL PROVISIONS
2.1 Provisions on the format of electronic signatures
2.1.1 Format of electronic signature
2.1.2 Information that must be included in the formats of electronic signatures
2.2 Provisions on the format of data for long-term authentication
2.3 Provisions on cryptographic algorithms
2.3.1 Provisions on cryptographic algorithms used
2.3.2 Provisions on the duration of use of cryptographic algorithms
3 MANAGEMENT PROVISIONS
4 RESPONSIBILITIES OF AGENCIES, ORGANIZATIONS, AND INDIVIDUALS
5 IMPLEMENTATION ORGANIZATION
REFERENCES
Foreword
National technical regulation QCVN 16:2025/BQP was compiled by the Department of Digital Certification and Information Security - General Office for Official Communications under the Government, reviewed by the General Office for Official Communications under the Government, examined by the Ministry of Science and Technology, and issued by the Minister of National Defense pursuant to Circular No. 76/2025/TT-BQP dated July 18, 2025.
NATIONAL TECHNICAL REGULATION ON AUTHENTICATION OF LONG-TERM DIGITAL DOCUMENT ARCHIVES OF PARTY AND STATE AGENCIES
National technical regulation on authentication long-term in digital document archives of party and state agencies
1 GENERAL PROVISIONS
1.1 Scope of Application
This national technical regulation specifies the limits of technical characteristics for authentication activities in archival operations involving digitally signed archival documents using official electronic signature certificates.
1.2 Applicability
This national technical regulation applies to agencies, organizations, and individuals involved in managing and using official electronic signature certification services in archival operations involving digitally stored documents.
1.3 References
The following reference documents are necessary for the application of this regulation. In case these reference documents are amended, supplemented, or replaced, the latest version shall apply.
ISO 14533-1:2022, Processes, data elements, and documentation in commerce, industry, and administration - Long-term signature record, Part 1: Advanced Electronic Signature Record CMS (CAdES).
ISO 14533-2:2021, Processes, data elements, and documentation in commerce, industry, and administration - Long-term signature record, Part 2: Advanced Electronic Signature Record XML (XadES).
ISO 14533-3:2017, Processes, data elements, and documentation in commerce, industry, and administration - Long-term signature record, Part 3: Long-term signature record for Advanced Electronic Signature PDF (PAdES).
ISO 14533-4:2019, Processes, data elements, and documentation in commerce, industry, and administration - Long-term signature record, Part 4: Object Identifier Attributes pointing to existence evidence (external) used in long-term signature formats (PoEAttributes).
TCVN 11816-3:2017 (ISO/IEC 10118-3:2004) "Information technology - Security techniques - Hash functions - Part 3: Dedicated hash functions".
RFC 3161 Recommendation, Time Stamping Protocol (TSP).
RFC 6960 Recommendation, Online Certificate Status Protocol (OCSP).
National Institute of Standards and Technology (NIST) Standard, FIPS 186-4, Digital Signature Standard (DSS), July 2013.
National Institute of Standards and Technology (NIST) Standard, FIPS 180-4, Secure Hash Standard (SHS), August 2015.
National Institute of Standards and Technology (NIST) Standard, FIPS 202, SHA-3 Standard: Permutation-based and extendable-output-length hash functions, August 2015.
Internet Engineering Task Force (IETF) Standard, Data Protection Using Cryptography on Block Storage Devices, October 2018.
1.4 Definitions
In this regulation, the following terms are understood as follows:
1.4.1. Format of data for long-term authentication
Is a structured type of data referenced to records, archival documents to prove existence (start time of storage), integrity of those records, and documents.
1.4.2. Cryptography
Are specific rules and conventions used to change the form of information representation to ensure confidentiality, authenticity, and integrity of the content.
1.4.3. Cryptographic technique
Is a method and means applying cryptography to protect information.
1.4.4. Encryption
Is the process of using cryptographic techniques to change the form of information representation.
1.4.5. Decryption
Is the reverse transformation of the corresponding encryption process.
1.4.6. Key
Is a sequence of characters controlling the operation of cryptographic transformation.
1.4.7. Asymmetric cryptography
A cryptographic key in which the key used for encryption or decryption consists of two components: a public key and a private key, with the characteristic that it is easy to calculate the public key if the private key is known, but it is computationally infeasible to calculate the private key from the public key.
1.4.8. Hash algorithm
An algorithm that transforms an input data string of arbitrary length into a fixed-length output data string.
1.4.9. Service provider for specialized official digital signature services
The National Electronic Certification and Information Security Agency under the Government Official Secretariat.
1.4.10. Digital signature certificate
A digital signature certificate for a digital signature.
1.5 Abbreviations
|
Abbreviation |
English name |
Vietnamese name |
|
EC |
Elliptic Curve |
Elliptic curve |
|
ECDSA |
Elliptic Curve Digital Signature Algorithm |
Elliptic curve-based digital signature algorithm |
|
FIPS |
Federal Information Processing Standards |
Federal information processing standards (United States) |
|
FIPS PUB |
Federal Information Processing Standards Publication |
Federal information processing standards publication (United States) |
|
NIST |
National Institute of Standards and Technology |
National Institute of Standards and Technology (United States) |
|
QCVN |
|
National technical regulation (Vietnam) |
|
RFC |
Request for Comments |
Technical specification published by the Internet Engineering Task Force (IETF) |
|
RSA |
Rivest - Shamir - Adleman |
RSA algorithm, method of encrypting and certifying electronic information invented by scientists Rivest, Shamir, and Adleman |
|
SHA |
Secure Hash Algorithm |
Secure hash algorithm |
|
TCVN |
|
National technical standard (Vietnam) |
1.6 Symbols
|
Code |
Description |
|
nlen |
For the RSA algorithm: nlen is the bit length of the modulus; For the ECDSA algorithm: nlen is the bit length of the order of the generator element |
2 TECHNICAL PROVISIONS
2.1 Provisions on the format of electronic signatures
2.1.1 Format of electronic signature
Use the following digital signature formats:
Table 1 - List of permitted digital signature formats
|
Serial number |
Type |
Reference |
|
1 |
CAdES |
ISO 14533-1:2022 |
|
2 |
XadES |
ISO 14533-2:2021 |
|
3 |
PAdES |
ISO 14533-3:2017 |
2.1.2 Information that must be included in the formats of electronic signatures
- The specialized official digital signature certificate of the entity performing the digital signing and the certificate revocation list (CRL) or online certificate status (OCSP) published by the service provider for specialized official digital signature services at the time of storage;
- Intermediate specialized official digital signature certificate (if any) and the certificate revocation list (CRL) or online certificate status (OCSP) published by the service provider for specialized official digital signature services at the time of storage;
- Root specialized official digital signature certificate and the certificate revocation list (CRL) or online certificate status (OCSP) published by the service provider for specialized official digital signature services at the time of storage.
- Valid timestamp before the time of storage; the timestamp server address published by the service provider for specialized official digital signature services.
2.2 Provisions on the format of data for long-term authentication
Use the following data format for long-term authentication of stored documents:
Table 2 - Permitted data format for long-term authentication of stored documents
|
Serial number |
Type |
Reference |
|
1 |
PoEAttributes |
ISO 14533-4:2019 |
2.3 Provisions on cryptographic algorithms
2.3.1 Provisions on cryptographic algorithms used
2.3.1.1 Asymmetric cryptographic algorithm
Use the algorithms listed below:
Table 3 - List of permitted asymmetric cryptographic algorithms
|
Serial number |
Algorithm |
Reference |
|
1 |
RSA |
[FIPS 186-4], [SP 800-56B Rev. 2] |
|
2 |
ECDSA |
[FIPS 186-4] |
2.3.1.2 Hash algorithm
Use the hash algorithms listed below:
Table 4 - List of permitted hash algorithms
|
Serial number |
Algorithm |
Reference |
|
1 |
SHA-256, SHA-384, SHA-512/256, SHA-512 |
[TCVN 11816-3], [FIPS 180-4] |
|
2 |
SHA3-256, SHA3-384, SHA3-512 |
[FIPS 202] |
2.3.2 Provisions on the duration of use of cryptographic algorithms
2.3.2.1 Asymmetric cryptographic algorithm
Use the asymmetric cryptographic algorithm must comply with the following regulations:
Table 5 - Regulations on technical characteristics and application period for asymmetric cryptographic algorithms
|
Serial number |
Algorithm |
Parameter size in bits |
Used until year |
Reference document |
|
1 |
RSA |
nlen ≥ 3072 |
2027 |
QCVN 15:2023/BQP |
|
2 |
ECDSA |
nlen ≥ 256 |
2027 |
QCVN 15:2023/BQP |
|
NOTE: The security parameter standards, generation algorithms, specific parameters for RSA and ECDSA algorithms in this technical regulation apply according to FIPS 186-4 standard. |
||||
2.3.2.2 Hash algorithm
Use the hash algorithm must comply with the following regulations:
Table 6 - Regulations on technical characteristics and application period for hash algorithms
|
Serial number |
Algorithm |
Used until year |
Reference document |
|
1 |
SHA-256, SHA-384, SHA-512/256, SHA-512 |
2027 |
QCVN 15:2023/BQP |
|
2 |
SHA3-256, SHA3-384, SHA3-512 |
2027 |
QCVN 15:2023/BQP |
3 MANAGEMENT PROVISIONS
3.1 The technical characteristics limits of specialized official digital signatures specified in this technical regulation serve the management of long-term digital archival documents according to the Law on Archiving No. 33/2024/QH15 dated June 21, 2024.
3.2 The specialized official digital signature certification service within the scope of regulation in Section 1.1 of this technical regulation must meet the technical requirements of this technical regulation.
3.3 The inspection and evaluation activities of the use of specialized official digital signatures for long-term archival document authentication of Party and State agencies shall be carried out in accordance with the provisions of the Government Decree No. 68/2024/NĐ-CP dated June 25, 2024 on specialized official digital signatures.
4 RESPONSIBILITIES OF AGENCIES, ORGANIZATIONS, AND INDIVIDUALS
4.1 Relevant agencies, organizations, and individuals when using the specialized official digital signature certification service for authentication in archival operations of Party and State agencies must comply with the provisions of this technical regulation.
4.2 Relevant agencies, organizations, and individuals are responsible for implementing the provisions on conformity certification, declaration of conformity, and subject themselves to inspection by state management authorities in accordance with current regulations.
5 IMPLEMENTATION ORGANIZATION
5.1 The Government Official Secretariat directs the National Electronic Certification and Information Security Agency to guide and organize the implementation of management according to this technical regulation.
5.2 In case the legal normative documents stipulated in this technical regulation are changed, supplemented, or replaced, they shall be implemented according to the new documents. In case the referenced standards in this technical regulation are changed, supplemented, or replaced, they shall be implemented according to the guidance of the Ministry of Defense.
5.3 During the implementation of this technical regulation, if there are issues arising or difficulties, relevant agencies, units, organizations, and individuals shall promptly reflect them in writing to the Ministry of Defense (through the Government Official Secretariat) for consideration and decision.
REFERENCES
[1]. National Institute of Standards and Technology, Special Publication 800-131A “Transitioning the Use of Cryptographic Algorithms and Key Lengths”, March 2019.
[2]. ISO 17068:2017 Information and documentation - Trusted third party repository for digital records
[3]. ISO 14721:2012 The Reference Model for an Open Archival Information System (OAIS)
[4]. Recommendation ITU-T X.509 (2008)/ISO/IEC 9594-8 (2008): "Information technology - Open Systems Interconnection - The Directory: Public-key and Attribute Certificate frameworks".
[5]. ETF RFC 3280 (2002): "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile".
[6]. IETF RFC 2560 (1999): "X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP".
[7]. IETF RFC 3852 (2004): "Cryptographic Message Syntax (CMS)"
[8]. IETF RFC 3161 (2001): "Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP)"
[9]. Recommendation ITU-T X.680 (2008): "Information technology - Abstract Syntax Notation One (ASN.1): Specification of basic notation"
[10]. Recommendation ITU-T X.501 (2008)/ISO/IEC 9594-1 (2008): "Information technology - Open Systems Interconnection - The Directory: Models"
[11]. IETF RFC 3370 (2002): "Cryptographic Message Syntax (CMS) Algorithms"
[12]. Recommendation ITU-T F.1: "Operational provisions for the international public telegram service"
[13]. Recommendation ITU-T X.500: "Information technology - Open Systems Interconnection - The Directory: Overview of concepts, models and services"
[14]. IETF RFC 3281 (2002): "An Internet Attribute Certificate Profile for Authorization"
[15]. Recommendation ITU-T X.208 (1988): "Specification of Abstract Syntax Notation One (ASN.1)"
[16]. IETF RFC 5035 (2007): "Enhanced Security Services (ESS) Update: Adding CertID Algorithm Agility"
[17]. IETF RFC 4998 (2007): "Evidence Record Syntax (ERS)"
[18]. ETSI TS 101 733: "Electronic Signatures and Infrastructures (ESI); CMS Advanced Electronic Signatures (CAdES)"
[19]. W3C/IETF Recommendation: "XML-Signature Syntax and Processing"
[20]. IETF RFC 2119: "Key words for use in RFCs to Indicate Requirement Levels"
[21]. ETSI TR 102 038: "TC Security - Electronic Signatures and Infrastructures (ESI); XML format for signature policies"
[22]. IETF RFC 3261: "Internet X.509 Public Key Infrastructure Time-Stamp protocol"
[23]. ISO 32000-1: "Document management - Portable document format - Part 1: PDF 1.7". http://www.adobe.com/devnet/acrobat/pdfs/PDF32000_2008.pdf
[24]. ETSI EN 319 122-1: "Electronic Signatures and Infrastructures (ESI); CAdES digital signatures; Part 1: Building blocks and CAdES baseline signatures"
[25]. IETF RFC 5652 (2009): "Cryptographic Message Syntax (CMS)"
[26]. IETF RFC 5280 (2008): "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile"
[27]. IETF RFC 6960 (2013): "X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP"
[28]. W3C Recommendation (May 2008): "Canonical XML Version 1.1"
[29]. IETF RFC 5816 (2010): "ESSCertlDv2 Update for RFC 3161"
[30]. IETF RFC 2315: "PKCS #7: Cryptographic Message Syntax Version 1.5"
[31]. ETSI EN 319 142-1: "Electronic Signatures and Infrastructures (ESI); PAdES digital signatures; Part 1: Building blocks and PAdES baseline signatures"
[32]. ETSI EN 319 132-1: "Electronic Signatures and Infrastructures (ESI); XAdES digital signatures; Part 1: Building blocks and XAdES baseline signatures"
[33]. ETSI EN 319 132-2: "Electronic Signatures and Infrastructures (ESI); XAdES digital signatures; Part 2: Extended XAdES signatures"
Văn bản gốc (PDF)
Tải văn bản
Bản đồ quan hệ
Bấm vào một văn bản để mở. Viền đỏ = quan hệ làm thay đổi hiệu lực.
Bản dịch
Văn bản này có sẵn ở các ngôn ngữ sau: